The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attributes of IPS policies

Prev Next

An IPS policy is composed of three classes of attributes:

  • Policy state attributes

  • Rule match attributes

  • Rule exclusion and inclusion attributes

Policy state attributes

Policy state attributes are maintained by the system to track the current state of a default or custom IPS policy. They are inherent to every IPS policy.

Note

Policy state attributes are not used to select IPS rules, and they are not directly configurable.

The system maintains the following attributes to track the state of an IPS policy:

active

Indicates whether the IPS policy is active on one or more monitoring interfaces.

writeable

Indicates whether the IPS policy is configurable. Only custom IPS policies are configurable.

modified_date

Date and time at which the IPS policy was last modified.

version

IPS policy format internal version number.

Rule match attributes

When you apply an IPS policy to a monitoring interface, the system selects from its database the IPS rules whose attributes match those specified by the policy. For more information, see Editing the rule match attributes of an IPS policy (CLI).

Required rule match attributes

The system requires that IPS policies include the following rule match attributes. Default IPS policies contain fixed combinations of the required rule match attributes only. You can create custom IPS policies that specify any valid settings for these attributes.

attack_target

The policy matches vulnerabilities or IPS rules oriented toward client systems, server systems, or both:

  • client—Matches rules oriented toward client systems.

  • server—Matches rules oriented toward server systems.

min-severity

The policy matches vulnerabilities or IPS rules that cover attacks of the specified severity level or greater. Range: 1 through 10.

max-severity

The policy matches vulnerabilities or IPS rules that cover attacks of the specified severity level or less. Range: 1 through 10.

Optional rule match attributes

Custom IPS policies can include optional rule match attributes.

Category

The policy matches vulnerabilities or IPS rules that cover attacks of the specified attack category:

  • brute_force

  • command_execution

  • cross-site_scripting

  • denial_of_service

  • directory_traversal

  • exploit

  • information_disclosure

  • policy_bypass

  • privilege_escalation

  • reconnaissance

  • other

Subcategory

If a category match attribute is specified, you can narrow the category match to rules that cover the specified type of attack subcategory.

brute_force:

  • telnet-bf

  • ftp-bf

  • vnc-bf

  • mysql-bf

  • smb-bf

  • rsh-bf

  • postgresql-bf

  • rlogin-bf

command_execution:

  • input_validation_error

  • directory_traversal

cross-site_scripting:

  • input_validation_error

  • other

denial_of_service:

  • input_validation_error

  • resource_exhaustion

  • other

directory_traversal:

  • information_disclosure

  • input_validation_error

exploit:

  • code_execution

  • command_execution

  • command_injection

  • design_weakness

  • directory_traversal

  • information_leakage

  • input_validation_error

  • other

policy_bypass:

  • authentication_weakness

reconnaissance:

  • authentication_weakness

  • information_disclosure

  • other

other:

  • pingsweep

  • tcp_portscan

  • udp_portscan

Protocol

The policy matches vulnerabilities or IPS rules related to the specified network protocols. For protocols that use encryption, the IPS-enabled rules engine inspects the initial negotiation messages only. At the time of this software release, IPS rules detect threats that exploit the following protocols:

AgentX, Arkeia Network Backup Client, Autonomy Connected Backup, Avaya WinPDM, BakBone NetVault, BigAnt Server, Blue Coat BCAAA, CA ARCserve, CA eTrust, CA License, CA Products, CA Products Discovery Service, Cisco UCM, Citrix, CUPS, CVS, DCE‑RPC, DHCP, Digium Asterisk, DNS, EMC, eSignal, Ethereal, Flexera FlexNet manager, FTP, Fujitsu SystemcastWizard, GAIM, Ganglia Meta Daemon, GDS DB, GE Proficy, GIMP, GIOP, HP Data Protector, HP Intelligent Mgmt Center, HP LeftHand Virtual SAN, HP Mercury, HP OpenView, HP Operations Agent, HP StorageWorks, HTTP, http, IAX2, IBM DB2, IBM Director, IBM SolidDB, IBM Tivoli, ICMP, ICQ, IEC 61131, IMAP, Intellicom NetBiter Config, IPSwitch WS_FTP, IRC, ISAKMP, iSCSI, KADM5, Kerberos, KPASSWD, LANDesk Management Suite, LDAP, LLMNR, LPD, McAfee ePO, Microsoft TMG, MMS, MS Host Integration Server, MSN Messenger, NCP, NDMP, NetBIOS, NFS, NMAP, NNTP, Novell Netware, Novell ZENworks, NTP, Oracle WebLogic, POP3, Portmap, Quest Software Big Brother, RADIUS, RAW, RDP, RIM BlackBerry Server, Rlogin, RMI, RPC, RSH, RTMP, RTSP, sadmind, SADMIND, SAP MaxDB, SAP NetWeaver, SCADA, Siemens SIMATIC WinCC, SIP, SKINNY, SMB, SMS, SMTP, SNMP, SOCKS, SpamAssassin, SQL, Squid Proxy, SSH, SSL, Symantec, TDS, Telnet, TFTP, Timbuktu, TLS, TNS, TrendMicro, Trillian IM, Unisys BIS, VMware, VNC, WCCP, WHO, WINS, Yahoo Messenger, and Zend Technologies Zend Server.

Note

This list is dynamic and subject to expansion as the FireEye Research Labs team discovers new vulnerabilities and responds by updating threat detection algorithms and delivering new IPS rules.

Rule exclusion and inclusion attributes

Custom IPS policies can include rule exclusion and inclusion attributes. Include these attributes if you want the policy to exclude or include individual IPS rules when selecting rules from its database. Rule exclusion and inclusion attributes override the rule sections of rule match attributes.

exclude

Exclude the IPS rule that contains the specified signature ID. This attribute overrides the match attributes of the policy.

include

Include the IPS rule that contains the specified signature ID.

For details, see Editing the rule inclusion and exclusion attributes of an IPS Policy (Web UI) and Editing the rule inclusion and exclusion attributes of an IPS policy (CLI).