This section details the best practices that you must follow when you use Snort Custom Attacks:
- Do not use a Snort Custom Attack if there is an equivalent available in the signature set.
- Make sure that the content option value is more than one byte. If you import a rule with a one-byte content, it will fail to import. The longer the content value, the accurate the detection will be. However, the maximum length of a content or uricontent for NS-series Sensors is 256 bytes.
- Make sure the content option does not contain any generic values identified by
Trellix IPS (some examples are listed below). Such rules can severely impact Sensor performance.
- GET
- POST
- Host
- User-Agent
- For better accuracy and performance, Trellix recommends that you use the Custom Attack Editor to create custom attack definitions as opposed to importing Snort rules.
- If you are using byte_test or byte_jump, use them in relation to a content match.
- Specify the classtype or priority to all rules. This enables the Manager to determine the severity for the rule. Understand how the Manager categorizes a Snort Custom Attack to publish it in the rule sets.
- If you are importing the Snort rules, import them from files that are accordingly named. For example, import HTTP rules from a file named http.rules file. In these rules, do not specify the destination port; the Sensor automatically detects protocols running on non-standard ports and applies the rule to the corresponding traffic. If you specify a port number, the Sensor applies the rule only to the traffic destined for that port.
- If you create the Snort rule in the Custom Attack Editor, or if you import it from a generically named file (like myrules.rules), it is very important that you specify the destination port number.
- Specify the revision number for all rules.
- For TCP rules, specify the flow.
- In a rule, do not specify the same value for more than one Content option. For example, do not use a Snort Custom Attack such as the following: alert tcp any any -> 10.1.1.1 80 (msg:"Example rule"; content:"private"; content:"private"; priority:1;sid:20209;rev:1;).