The Attack tab enables you to name your attack and type a description.
Option | Definition |
|---|---|
State | Select the state of the custom attack. The choices are Published and Staged. |
Name | The name you assign to the attack. "UDS" is automatically prefixed before every created attack name. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor, as well as in the attack database when you subsequently save the attack in the Manager server. |
Description | Use this area for notes and other pertinent information.
|
Severity | Select a severity from the drop-down list. Choices are as follows:
|
Protection Category | You must choose a Protection Category from the available options. The Protection Category indicates the intent of the attack and the intended target. For example, you can choose Client Protection/Operating Systems for an attack targeting vulnerabilities in client operating systems. In this example, Client Protection is the category and Operating Systems is a subcategory. The list of Protection Categories is pre-defined and provided by Trellix Advanced Research Center. You cannot modify it. This list is updated when you update the Signature Set. |
Detection Type | Select the type of detection from the options that relisted. |
Attack Target | Select the appropriate attack target. |
Blocking | Select the appropriate blocking. You can either block only the attack packet or the entire flow. |
Non-editable Fields | |
Benign Trigger Probability | This is an indication of the probability that the Snort Custom Attack will alert on traffic that may not be an attack. The default value is Medium, which you cannot modify. |
Attack Category | This column indicates the type of attack. |
Trellix IPS ID | The numeric ID assigned for the attack by the Manager for database archival. The Manager assigns the ID after you save it in the Manager server. For Snort Custom Attacks, the IDs begin with 0xe. For Snort Custom Attacks created in the Central Manager, the IDs begin with 0xee. |
Supported Device Types | You can apply a Custom Attack signature for just the available device types. The value for this field depends on what you select for the corresponding rule. You cannot edit this field at the attack level, but the Manager modifies it accordingly when you change it for the corresponding rule. |
Last Updated | Displays the time at which the signature was last updated |