Attack subcategories are the specific, inherent system flaws that can be exploited by attackers familiar with a vulnerability or malware. A known vulnerability poses a threat to the system; the attacking party exploits this threat with an attack that is designed to affect some part of the vulnerable system. The following table captures some of the Attack subcategories:
Category | Description |
|---|---|
Trellix Intelligent Sandbox | This kind of alert indicates that a malicious file transfer is detected on network by Trellix Intelligent Sandbox Engine. |
Arbitrary Command execution | An attacker can execute system commands and scripts, like getting a directory listing on a system, thus stealing and destroying data. The attacker who is able to access a user's system can exploit the vulnerability and install malicious software and use the system to launch attacks on other systems. |
Audit | Any networking event deemed to be of interest to the security analyst. Examples include invocation of particular applications or use of particular commands in certain applications. |
Backdoor | Depending on the confidence level of the triggers, this can either be some attempts at contacting a backdoor process or the occurrence of actual backdoor two-way conversation. If the latter has occurred, it means that a backdoor process exists in your network, the backdoor user is in your network, or both are inside your network, depending on the locations of the communication endpoints. |
Bot | It refers to a group of computers running or executing a program that allows an attacker to control the system remotely and make users execute commands like DOS. These commands are taken place in the IRC channel. A 'bot' is a type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'. Attackers are able to access lists of 'zombie' PC's and activate them to help execute DoS (Denial of Service) attacks against Web sites, host phishing attack Websites or send out thousands of spam email messages. A bot worm is a self-replicating malware program that resides in current memory (RAM), turns infected computers into zombies (or bots) and transmits itself to other computers. A bot worm may be created with the ultimate intention of creating a botnet that functions as a vehicle for the spread of viruses, Trojans and spam. |
Botnet | It refers to a group of computers that has been infected by Bots in a network. |
Brute Force | Brute force attacks are performed using programs, such as password crackers, to try different sets of passwords so as to guess the right one. |
Buffer Overflow | This kind of alerts indicates attempts at exploiting software vulnerabilities where manipulation of buffer spaces can result in overwriting of unintended memory areas. Such overwriting can have different consequences depending on if the areas are executable or not. If not, it can cause malfunction of the software, thus denial of service; if yes, it can lead to execution of arbitrary machine code within the context of the current process which can lead to much more severe security breach. |
Code/Script Execution | It refers to a vulnerability which can be exploited by malicious people to compromise a user's system. An attacker can execute malicious programs or code on a user's system. Successful exploitation allows execution of arbitrary code and possibly takes complete control of the affected system. Attacker can run code with elevated permissions. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights. |
Command Shell | Traffic activities indicating interactive shells under Unix or Windows operating systems, and so forth |
Covert Channel | Any communication activities that are deemed unintended by the communication channel being monitored |
Custom Fingerprinting | It refers to the detection of malicious files using known hashes (MD5 or SHA256). MD5 and SHA256 hashes can be added to the Manager based on requirements. |
DDoS Agent Activity | Known DDoS attack tools use various patterns of communication among attackers or handlers, and attacking agents or zombies. Detection of these activities is a good sign that either someone is attempting to contact DDoS agents, or there may be real attackers or agent processes in the monitored networks. |
DoS | Well-crafted packets, for example, with invalid/inconsistent TCP/UDP/IP header values, aiming at crashing the target TCP/IP stack or causing high resource consumption. |
Endpoint Intelligence Agent | This kind of alert indicates that a malicious file transfer is detected on network by McAfee Endpoint Intelligence Agent. |
Evasion Attempt | This kind of alert indicates a sequence of packets or bytes in the traffic signifying a specific attempt at evading an IDS. For example, FTP attacks are known to use escape control character sequences to hide attack payload and TCP-based RPC attacks may use record format to split up attack payload. |
File Mismatch | It refers to a file that has been given an extension which does not match its actual file type and/or content type. For example, a file with .exe extension (executable) downloaded with a text/plain content type. |
OS Fingerprinting | Well-defined sequence of packets, each of which is typically a probe attempt itself, launched against a given destination IP address, typically aiming at identifying the target operating system or host type. |
Gateway Anti-Malware | It refers to a malware that has been detected in a file analyzed by the Gateway Anti-Malware (GAM) advanced malware engine, which is the same Anti-Malware Engine found in Trellix Endpoint products, but it is optimized for network analysis. |
GTI File Reputation | It refers to a malware that has been detected in a file analyzed by the Trellix Global Threat Intelligence. |
Host Sweep | Well-defined sequence of packets sweeping through a range of destination IP addresses, typically aiming at identifying live hosts |
Malicious Flash Analysis Engine | This kind of alert indicates that a malicious file transfer is detected by Flash Analysis Engine. |
Malware Being Redownloaded | This kind of alert indicates that an action to redownload a known malware that has been blocked. |
Multi-Attack Correlation | It refers to the categories of attacks which use Multiple Attack Correlation mechanism. Multi-AID attacks can correlate attacks to identify zero-day, DoS, and Bot behavior. |
Multi-Attack Known Bot | Multiple attack correlation used for known Bots |
Multi-Attack Heuristic Bot | Multiple attack correlation used for zero day attack detection |
Non-standard Port | Any traffic activities suggesting that a standard protocol running over non-standard ports according to specifications. |
Trellix IPS Analysis | This kind of alert indicates that a malicious file transfer is detected by Trellix Advanced Malware engine. |
Over Threshold | Any of the well-defined traffic thresholds has been crossed. Examples include ICMP packet rate, IP fragment rate, and so forth. |
PDF Emulation | This kind of alert indicates that a malicious file transfer is detected by JavaScript Emulation engine. |
Phishing | It is an email-fraud method in which the perpetrators send out legitimate looking email in attempt to gather personal and financial information from recipients. Typically, the messages appear to come from well-known and trustworthy websites. Websites that are frequently spoofed by phishers include oBey, MSG, Yahoo, etc. "Phishing" is a form of Internet fraud that aims to steal valuable information, such as credit cards, social security numbers, user IDs, and passwords. A fake website is created that is similar to that of a legitimate organization, typically a financial institution such as a bank or insurance company. An email is sent requesting that the recipient access the fake website (which is usually a replica of a trusted site) and enter their personal details, including security access codes. |
Port Scan | Well-defined sequence of packets sweeping through a range of destination ports on a given IP, typically aiming at identifying open ports on the target host. |
Privileged Access | Privileged access indicates the most serious type of successful exploitation, where unauthorized access to privileged accounts has been obtained. For example, a successful buffer overflow on a Unix server may open a root shell for the attacker. Alternatively, the attacker may have achieved successful permission elevation from a legitimate user account, or from a remote access compromise. Privileged access allows the attacker to potentially take complete control of the compromised system. |
Probe | Probes of specific service or host, typically based on specially constructed packets, for example unusual flag settings |
Protocol Violation | Unusual application protocol behaviors, including invalid field values or invalid command sequences, and so forth |
Potentially Unwanted Program | A Potentially Unwanted Program (PUP) is a program that may be unwanted, despite the possibility that users consented to download it. PUBs include spyware, adhere, and dialers, and are often downloaded in conjunction with a program that the user wants. Trellix differentiates PUPs from other types of malware, such as viruses, Trojans, and worms, which can be safely assumed to be unwanted by the user. |
Read Exposure | With a successful attack, this suggests that a breach of confidentiality has occurred. Examples include directory traversal, dump of file content such as CGI script, or read of other sensitive data files such as password and database records. |
Remote Access | Remote access indicates a potentially successful exploitation in which unauthorized access has been obtained. For example, a successful buffer overflow on a Windows server may open a Windows command shell for the attacker. The remote access does not have to be for a privileged user to begin with, but an attacker may be able to perform further attacks to achieve permission elevation once remote access is obtained. |
Restricted Access | Any activities related to using any network resources that are explicitly forbidden, for example, emails to/from particular addresses and browsing of specific URLs. |
Restricted Application | Any activities related to running network applications that are forbidden by policy. Examples include running an IRC or music share server on the corporate network without authorization. |
Sensitive Content | Any content keyword matches that are deemed to indicate transmission of sensitive information, for example, document with "Company Confidential" marking. |
Service Sweep | An alert indicates that a client scans for services on your network or sub network, thus leading to increased bandwidth corruption and increase in network traffic. It is usually generated by a P2P client. A Service Sweep is an attempt to determine if a service is running on a range of machines. The hacker will pick one port (usually 25-SMTP, 80-HTTP, or 139-NetBIOS SSN) and a range of IP addresses. A Ping Sweep is an attempt to see which machines in a network are on and responding. The easiest way to detect these in a trace is to look for ARP packets. So, create a filter looking for ARP requests. |
Shellcode Execution | This kind of alert indicates the most severe form of buffer overflow attacks, that is, a buffer overflow attack carrying shellcode payload. Shellcode is a general term used for a piece of executable code that, upon successful execution on the target system, modifies the target's configuration or behavior for malicious purposes. |
Statistical Deviation | Indicates that a significant change was detected in the packet rate for a particular traffic measure. For example, if in your normal flow of traffic, TCP SYN packets make up between 23–28% of the traffic, a short-term measure of TCP SYN traffic at 40% may indicate a DoS attack. |
TIE File Reputation | This kind of alert indicates that a malicious file transfer is detected by Trellix Threat Intelligence Exchange (TIE), which takes advantage of Trellix Data Exchange Layer to consolidate threat information, including malware confidence, infection timelines, and prevalence. TIE data sources include Global Threat Intelligence (GTI), Trellix Intelligent Sandbox, and ePolicy Orchestrator (ePO). |
Trojan | Refers to a malicious program that works in the background and perform malicious actions. For example, the Trojan could allow full access of the affected system to the creator. Trojans are usually packaged in innocuous file downloads or links. |
Unassigned | This category is for attacks that fall outside the scope of the known subcategories in the Trellix IPS environment. For example, if an attacker comes along a Van Eck device and starts conducting Tempest attacks, "unassigned" would be the description. |
Unauthorized IP | Any traffic activities suggesting existence of IP addresses that are not known to be authorized for the protected network. |
Virus | Any network event or payload specifically related to a virus. Virus can inflict many different types of damage to its target, ranging from stealing or destroying information to installing backdoor processes. However, a virus relies on other carriers, for example, email, to propagate through the network. |
Worm | Any network event or payload specifically related to worm activities. A worm can inflict many different types of damages to its target, ranging from stealing or destroying information to installing backdoor processes. The worm differs from a virus in that it can propagate itself through the network. |
Write Exposure | With a successful attack, this suggests that a breach of integrity and/or authenticity of data has occurred. Examples include creation/removal of files and modification of files for system configuration or user passwords. With write exposures, there is often more severe indirect impact, for example, breach of access control by adding an illegal user account records. |