McAfee HISCDE-AB-IA Product Guide - Page 45

Configuring IPS application protection rules, Menu | Policy | Policy Catalog

Page 45 highlights

Configuring IPS Policies Define IPS protection updated, every process listed in the information cache of running processes is compared against the updated list. If the list indicates that a process should be hooked and it's not already hooked, that process is hooked. If the lists indicate that a process should not be hooked and it is already hooked, that process is unhooked. The process hooking lists can be viewed and edited on the Application Protection Rules tab. The client user interface, unlike the view on the IPS Rules policy, shows a static list of all hooked application processes. NOTE: To prevent injection of a DLL into an executable when using hook:set_windows_hook, include the executable in the Application Protection List. Configuring IPS application protection rules Edit, add, and delete rules and move rules to another policy from the Application Protection Rules tab of the IPS Rules policy. Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog and select Host Intrusion Prevention: IPS in the Product list and IPS Rules in the Category list. The list of policies appears. 2 Under Actions, click Edit to make changes on the IPS Rules page, then click the Application Protection Rules tab. 3 Perform any of the following operations: To... Find an application rule in the list Edit an application rule Add an application rule Delete an application rule Copy an application rule to another policy Do this... Use the filters at the top of the application list. You can filter on rule status, inclusion, or specific text that includes process name, process path, or computer name. Click Clear to remove filter settings. Under Actions, click Edit. Click New. Under Actions, click Delete. Select a rule and click Copy To to copy it to another policy. Indicate the policy to which to copy the rule and click OK. NOTE: You can copy several rules at one time by selecting all the rules before clicking Copy To. 4 Click Save to save any changes. Creating application protection rules If the IPS Rules policy does not have an application protection rule that you need in your environment, you can create one. Task For option definitions, click ? in the interface. 1 On the IPS Rules policy Application Protection Rules tab, do one of the following: McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

updated, every process listed in the information cache of running processes is compared against
the updated list. If the list indicates that a process should be hooked and it’s not already hooked,
that process is hooked. If the lists indicate that a process should not be hooked and it is already
hooked, that process is unhooked.
The process hooking lists can be viewed and edited on the Application Protection Rules tab.
The client user interface, unlike the view on the IPS Rules policy, shows a static list of all hooked
application processes.
NOTE:
To prevent injection of a DLL into an executable when using hook:set_windows_hook,
include the executable in the Application Protection List.
Configuring IPS application protection rules
Edit, add, and delete rules and move rules to another policy from the Application Protection
Rules tab of the IPS Rules policy.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
and select
Host Intrusion Prevention: IPS
in
the
Product
list and
IPS Rules
in the
Category
list. The list of policies appears.
2
Under
Actions
, click
Edit
to make changes on the
IPS Rules
page, then click the
Application Protection Rules
tab.
3
Perform any of the following operations:
Do this...
To...
Use the filters at the top of the application list. You can
filter on rule status, inclusion, or specific text that
Find an application rule in the list
includes process name, process path, or computer
name. Click
Clear
to remove filter settings.
Under
Actions
, click
Edit
.
Edit an application rule
Click
New
.
Add an application rule
Under
Actions
, click
Delete
.
Delete an application rule
Select a rule and click
Copy To
to copy it to another
policy. Indicate the policy to which to copy the rule and
click
OK
.
NOTE:
You can copy several rules at one time by
selecting all the rules before clicking
Copy To
.
Copy an application rule to another policy
4
Click
Save
to save any changes.
Creating application protection rules
If the IPS Rules policy does not have an application protection rule that you need in your
environment, you can create one.
Task
For option definitions, click
?
in the interface.
1
On the IPS Rules policy
Application Protection Rules
tab, do one of the following:
Configuring IPS Policies
Define IPS protection
45
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5