McAfee HISCDE-AB-IA Product Guide - Page 88

About the IPS Policy tab, Customizing IPS Policy options

Page 88 highlights

Working with Host Intrusion Prevention Clients Overview of the Windows client The Application Information section displays: • The IP address that the traffic pretends to come from. • Information about the program that generated the spoofed traffic. • The time and date when Host Intrusion Prevention intercepted the traffic. The Connection Information section provides further networking information. In particular, Local Address shows the IP address that the application is pretending to have, while Remote Address shows your actual IP address. When Host Intrusion Prevention detects spoofed network traffic, it blocks both the traffic and the application that generated it. About the IPS Policy tab Use the IPS Policy tab to configure the IPS feature, which protects against host intrusion attacks based on signature and behavioral rules. From this tab you can enable or disable functionality and configure client exception rules. For more details on IPS policies, see Configuring IPS policies. IPS Policy tab displays exception rules relevant to the client and provides summary and detailed information for each rule. Table 16: IPS Policy tab This column... Displays Exception The name of the exception. Signature The name of the signature against which the exception is created. Application The application that this rule applies to, including the program name and executable file name. Customizing IPS Policy options Options at the top of the tab control settings delivered by the server-side IPS policies after the client interface is unlocked. Task 1 In the Host IPS client console, click the IPS Policy tab. 2 Select or deselect an option as needed. Select... Enable Host IPS Enable Network IPS Enable Adaptive Mode Automatically block attackers To do this... Enable host intrusion prevention protection. Enable network intrusion prevention protection. Enable adaptive mode to automatically create exceptions to intrusion prevention signatures. Block network intrusion attacks automatically for a set period of time. Indicate the number of minutes in the min. field. 88 McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154

The Application Information section displays:
The IP address that the traffic pretends to come from.
Information about the program that generated the spoofed traffic.
The time and date when Host Intrusion Prevention intercepted the traffic.
The Connection Information section provides further networking information. In particular, Local
Address shows the IP address that the application is pretending to have, while Remote Address
shows your actual IP address.
When Host Intrusion Prevention detects spoofed network traffic, it blocks both the traffic and
the application that generated it.
About the IPS Policy tab
Use the IPS Policy tab to configure the IPS feature, which protects against host intrusion attacks
based on signature and behavioral rules. From this tab you can enable or disable functionality
and configure client exception rules. For more details on IPS policies, see
Configuring IPS
policies
.
IPS Policy tab displays exception rules relevant to the client and provides summary and detailed
information for each rule.
Table 16: IPS Policy tab
Displays
This column...
The name of the exception.
Exception
The name of the signature against which the exception is
created.
Signature
The application that this rule applies to, including the
program name and executable file name.
Application
Customizing IPS Policy options
Options at the top of the tab control settings delivered by the server-side IPS policies after the
client interface is unlocked.
Task
1
In the Host IPS client console, click the
IPS Policy
tab.
2
Select or deselect an option as needed.
To do this...
Select...
Enable host intrusion prevention protection.
Enable Host IPS
Enable network intrusion prevention protection.
Enable Network IPS
Enable adaptive mode to automatically create
exceptions to intrusion prevention signatures.
Enable Adaptive Mode
Block network intrusion attacks automatically for a set
period of time. Indicate the number of minutes in the
min. field.
Automatically block attackers
Working with Host Intrusion Prevention Clients
Overview of the Windows client
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
88