This section details the best practices that you must follow when you use Snort Custom Attacks:
Do not use a Snort Custom Attack if there is an equivalent available in the signature set.
Make sure that the content option value is more than one byte. If you import a rule with a one-byte content, it will fail to import. The longer the content value, the accurate the detection will be. However, the maximum length of a content or uricontent for NS-series Sensors is 256 bytes.
Make sure the content option does not contain any generic values identified by Trellix IPS (some examples are listed below). Such rules can severely impact Sensor performance.
GET
POST
Host
User-Agent
For better accuracy and performance, Trellix recommends that you use the Custom Attack Editor to create custom attack definitions as opposed to importing Snort rules.
If you are using byte_test or byte_jump, use them in relation to a content match.
Specify the classtype or priority to all rules. This enables the Manager to determine the severity for the rule. Understand how the Manager categorizes a Snort Custom Attack to publish it in the rule sets.
If you are importing the Snort rules, import them from files that are accordingly named. For example, import HTTP rules from a file named http.rules file. In these rules, do not specify the destination port; the Sensor automatically detects protocols running on non-standard ports and applies the rule to the corresponding traffic. If you specify a port number, the Sensor applies the rule only to the traffic destined for that port.
If you create the Snort rule in the Custom Attack Editor, or if you import it from a generically named file (like myrules.rules), it is very important that you specify the destination port number.
Specify the revision number for all rules.
For TCP rules, specify the flow.
In a rule, do not specify the same value for more than one Content option. For example, do not use a Snort Custom Attack such as the following: alert tcp any any -> 10.1.1.1 80 (msg:"Example rule"; content:"private"; content:"private"; priority:1;sid:20209;rev:1;).