An IPS policy is composed of three classes of attributes:
Policy state attributes
Rule match attributes
Rule exclusion and inclusion attributes
Policy state attributes
Policy state attributes are maintained by the system to track the current state of a default or custom IPS policy. They are inherent to every IPS policy.
Note
Policy state attributes are not used to select IPS rules, and they are not directly configurable.
The system maintains the following attributes to track the state of an IPS policy:
active
Indicates whether the IPS policy is active on one or more monitoring interfaces.
writeable
Indicates whether the IPS policy is configurable. Only custom IPS policies are configurable.
modified_date
Date and time at which the IPS policy was last modified.
version
IPS policy format internal version number.
Rule match attributes
When you apply an IPS policy to a monitoring interface, the system selects from its database the IPS rules whose attributes match those specified by the policy. For more information, see Editing the rule match attributes of an IPS policy (CLI).
Required rule match attributes
The system requires that IPS policies include the following rule match attributes. Default IPS policies contain fixed combinations of the required rule match attributes only. You can create custom IPS policies that specify any valid settings for these attributes.
attack_target
The policy matches vulnerabilities or IPS rules oriented toward client systems, server systems, or both:
client—Matches rules oriented toward client systems.
server—Matches rules oriented toward server systems.
min-severity
The policy matches vulnerabilities or IPS rules that cover attacks of the specified severity level or greater. Range: 1 through 10.
max-severity
The policy matches vulnerabilities or IPS rules that cover attacks of the specified severity level or less. Range: 1 through 10.
Optional rule match attributes
Custom IPS policies can include optional rule match attributes.
Category
The policy matches vulnerabilities or IPS rules that cover attacks of the specified attack category:
brute_forcecommand_executioncross-site_scriptingdenial_of_servicedirectory_traversalexploitinformation_disclosurepolicy_bypassprivilege_escalationreconnaissanceother
Subcategory
If a category match attribute is specified, you can narrow the category match to rules that cover the specified type of attack subcategory.
brute_force:
telnet-bfftp-bfvnc-bfmysql-bfsmb-bfrsh-bfpostgresql-bfrlogin-bf
command_execution:
input_validation_errordirectory_traversal
cross-site_scripting:
input_validation_errorother
denial_of_service:
input_validation_errorresource_exhaustionother
directory_traversal:
information_disclosureinput_validation_error
exploit:
code_executioncommand_executioncommand_injectiondesign_weaknessdirectory_traversalinformation_leakageinput_validation_errorother
policy_bypass:
authentication_weakness
reconnaissance:
authentication_weaknessinformation_disclosureother
other:
pingsweeptcp_portscanudp_portscan
Protocol
The policy matches vulnerabilities or IPS rules related to the specified network protocols. For protocols that use encryption, the IPS-enabled rules engine inspects the initial negotiation messages only. At the time of this software release, IPS rules detect threats that exploit the following protocols:
AgentX, Arkeia Network Backup Client, Autonomy Connected Backup, Avaya WinPDM, BakBone NetVault, BigAnt Server, Blue Coat BCAAA, CA ARCserve, CA eTrust, CA License, CA Products, CA Products Discovery Service, Cisco UCM, Citrix, CUPS, CVS, DCE‑RPC, DHCP, Digium Asterisk, DNS, EMC, eSignal, Ethereal, Flexera FlexNet manager, FTP, Fujitsu SystemcastWizard, GAIM, Ganglia Meta Daemon, GDS DB, GE Proficy, GIMP, GIOP, HP Data Protector, HP Intelligent Mgmt Center, HP LeftHand Virtual SAN, HP Mercury, HP OpenView, HP Operations Agent, HP StorageWorks, HTTP, http, IAX2, IBM DB2, IBM Director, IBM SolidDB, IBM Tivoli, ICMP, ICQ, IEC 61131, IMAP, Intellicom NetBiter Config, IPSwitch WS_FTP, IRC, ISAKMP, iSCSI, KADM5, Kerberos, KPASSWD, LANDesk Management Suite, LDAP, LLMNR, LPD, McAfee ePO, Microsoft TMG, MMS, MS Host Integration Server, MSN Messenger, NCP, NDMP, NetBIOS, NFS, NMAP, NNTP, Novell Netware, Novell ZENworks, NTP, Oracle WebLogic, POP3, Portmap, Quest Software Big Brother, RADIUS, RAW, RDP, RIM BlackBerry Server, Rlogin, RMI, RPC, RSH, RTMP, RTSP, sadmind, SADMIND, SAP MaxDB, SAP NetWeaver, SCADA, Siemens SIMATIC WinCC, SIP, SKINNY, SMB, SMS, SMTP, SNMP, SOCKS, SpamAssassin, SQL, Squid Proxy, SSH, SSL, Symantec, TDS, Telnet, TFTP, Timbuktu, TLS, TNS, TrendMicro, Trillian IM, Unisys BIS, VMware, VNC, WCCP, WHO, WINS, Yahoo Messenger, and Zend Technologies Zend Server.
Note
This list is dynamic and subject to expansion as the FireEye Research Labs team discovers new vulnerabilities and responds by updating threat detection algorithms and delivering new IPS rules.
Rule exclusion and inclusion attributes
Custom IPS policies can include rule exclusion and inclusion attributes. Include these attributes if you want the policy to exclude or include individual IPS rules when selecting rules from its database. Rule exclusion and inclusion attributes override the rule sections of rule match attributes.
exclude
Exclude the IPS rule that contains the specified signature ID. This attribute overrides the match attributes of the policy.
include
Include the IPS rule that contains the specified signature ID.
For details, see Editing the rule inclusion and exclusion attributes of an IPS Policy (Web UI) and Editing the rule inclusion and exclusion attributes of an IPS policy (CLI).