McAfee HISCDE-AB-IA Product Guide - Page 86

Windows client alerts, Responding to Intrusion alerts

Page 86 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client Task For option definitions, click ? in the interface. 1 In the Host IPS console, select Help | Troubleshooting, and click Functionality. 2 In the HIPS Engines dialog box, deselect one or more engines. To disable all engines, deselect Enable/Disable all engines. NOTE: SQL and HTTP appear in the list only if the client is running a server operating system. 3 Click OK. 4 After the problem has been resolved, reselect all deselected engines in the HIPS Engines dialog box. Windows client alerts A user can encounter several types of alert messages and needs to react to them. These include intrusion detection, firewall, and spoof detection alerts. Firewall alerts appear only when the client is in learn mode for these features. Responding to Intrusion alerts If you enable IPS protection and the Display pop-up alert option, an alert appears automatically when Host Intrusion Prevention detects a potential attack. If the client is in adaptive mode, this alert appears only if the Allow Client Rules option is disabled for the signature that caused the event to occur. The Intrusion Information tab displays details about the attack that generated the alert, including a description of the attack, the user/client computer where the attack occurred, the process involved in the attack, and the time and date when Host Intrusion Prevention intercepted it. In addition, a generic administrator-specified message can appear. You can ignore the event by clicking Ignore, or create an exception rule for the event by clicking Create Exception. The Create Exception button is active only if the Allow Client Rules option is enabled for the signature that caused the event to occur. If the alert is the result of a Host IP signature, the exception rule dialog box is prefilled with the name of the process, user, and signature. You can select All Signatures or All Processes, but not both. The user name is always included in the exception. If the alert is the result of a Network IPS signature, the exception rule dialog box is prefilled with the signature name and the host IP address. You can optionally select All Hosts. In addition, you can click Notify Adminto send information about the event to the Host Intrusion Prevention administrator. This button is active only if the Allow user to notify administrator option is enabled in the applied Client UI policy. Select Do not show any alerts for IPS Events to stop displaying IPS Event alerts. To have the alerts reappear after selecting this option, select Display pop-up alert in the Options dialog box. NOTE: This intrusion alert also appears for firewall intrusions if a firewall rule is matched that has the Treat rule match as an intrusion option selected. 86 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

Task
For option definitions, click
?
in the interface.
1
In the Host IPS console, select
Help | Troubleshooting
, and click
Functionality
.
2
In the HIPS Engines dialog box, deselect one or more engines. To disable all engines,
deselect
Enable/Disable all engines
.
NOTE:
SQL and HTTP appear in the list only if the client is running a server operating
system.
3
Click
OK
.
4
After the problem has been resolved, reselect all deselected engines in the HIPS Engines
dialog box.
Windows client alerts
A user can encounter several types of alert messages and needs to react to them. These include
intrusion detection, firewall, and spoof detection alerts. Firewall alerts appear only when the
client is in learn mode for these features.
Responding to Intrusion alerts
If you enable IPS protection and the Display pop-up alert option, an alert appears automatically
when Host Intrusion Prevention detects a potential attack. If the client is in adaptive mode, this
alert appears only if the Allow Client Rules option is disabled for the signature that caused the
event to occur.
The Intrusion Information tab displays details about the attack that generated the alert, including
a description of the attack, the user/client computer where the attack occurred, the process
involved in the attack, and the time and date when Host Intrusion Prevention intercepted it. In
addition, a generic administrator-specified message can appear.
You can ignore the event by clicking
Ignore,
or create an exception rule for the event by
clicking
Create Exception
. The Create Exception button is active only if the Allow Client Rules
option is enabled for the signature that caused the event to occur.
If the alert is the result of a Host IP signature, the exception rule dialog box is prefilled with
the name of the process, user, and signature. You can select
All Signatures
or
All Processes
,
but not both. The user name is always included in the exception.
If the alert is the result of a Network IPS signature, the exception rule dialog box is prefilled
with the signature name and the host IP address. You can optionally select
All Hosts
.
In addition, you can click
Notify Admin
to send information about the event to the Host Intrusion
Prevention administrator. This button is active only if the Allow user to notify administrator
option is enabled in the applied Client UI policy.
Select
Do not show any alerts for IPS Events
to stop displaying IPS Event alerts. To have
the alerts reappear after selecting this option, select
Display pop-up alert
in the Options
dialog box.
NOTE:
This intrusion alert also appears for firewall intrusions if a firewall rule is matched that
has the Treat rule match as an intrusion option selected.
Working with Host Intrusion Prevention Clients
Overview of the Windows client
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
86