An IPS policy is one of the many types of security policies used in Trellix IPS. A Sensor uses the assigned IPS policy to determine if the detected traffic is free of attacks according to that policy. An IPS policy is for detecting exploit attacks, policy violations, and DoS attacks. Also, the IPS policy determines how a Sensor responds when it detects traffic that violates an IPS policy.
The main components of an IPS policy are the attack set profiles and the Attack definitions. An IPS policy is essentially a set of attack definitions for various protocols (HTTP, UDP), operating systems (Windows, NT, Solaris), and other types of information transmitted across your network. In addition to other anomalies in the detected traffic, the Sensor also checks if that traffic matches with what is defined in an attack. If a match is found, that means the corresponding attack was attempted.
In an IPS policy, an attack set profile for inbound and an attack set profile for outbound is specified. It can be the same attack set profile for both inbound and outbound or different ones. The attack set profiles specified in the IPS policy determine the attack definitions to be included in the IPS policy.
Note
There are quite a few predefined IPS policies provided for you to deploy Trellix IPS out-of-the box. You can use them or create your own.
To create and use IPS policies, familiarize yourself with the terminologies discussed here.
Attack Set Profile— The best practice is to create multiple, specific IPS policies that focus on the specific needs of unique zones in your network, rather than a one-size-fits-all policy for the entire network. Therefore, the attack definitions are internally classified based on:
Whether they are exploits, malwares, policy violation, and so on
The relevant protocols, such as FTP, HTTP, RADIUS, and so on
The relevant operating systems
The applications such as Skype and Google Search that attacks are relevant for
The chances of attacks being false-positives
In an attack set profile, you can specify the categories of attacks that must be included and the categories that must be excluded. Then when you specify this attack set profile in the IPS Policy, the Manager processes the Signature Set and identifies the attack definitions according to what you specified in the attack set profile. Only these attack definitions are included in the IPS policy. You can also create rules to choose attacks to be explicitly blocked by the Sensor as per your network requirements while creating an attack set profile. The configuration options on the Attacks to Block tab enables you to select minimum severity, categories, and subcategories of attacks which should be explicitly blocked by the Sensors. It works on the subset of data that comes in the form of Include rule(s) set on the Attacks to Include/Exclude tab. In other words, rules created on the Attacks to Block tab determine the attack definitions that are automatically set to be blocked in the corresponding IPS policy. For more formation, refer to the section Defining and using user-customizable blocking strategy to make self-adaptable IPS policies.
In the Manager, there are several provided attack set profiles which match the preconfigured policies. You can view, clone (copy), and customize these attack set profiles for your own use.
Rules— You specify the categories of attacks to be included and excluded, along with categories and/or subcategories of attacks to be blocked in an attack set profile. To do so, you define rules in an attack set profile. Each rule in a set is either an include rule, exclude rule, or a rule to block specific attacks.
An include rule which should always start an attack set profile is a set of parameters that encompasses a broad range of well-known attacks for detection. An exclude rule removes elements from the include rule to focus the policy's attack set profile. By broadening (includes) and narrowing (excludes) the rules, you can enable detection for the attacks that affect the intended environment.
If you have an exclude rule, an include rule added afterward might negate the exclusion For example, if you specify an exclude rule for the DNS protocol, then later include multiple protocols including DNS, the exclusion rule is negated.
You can also define rules of blocking during attack set profile configuration, that include one or more categories and subcategories of attacks and the minimum severity level, as per your own blocking strategy. These rules determine the attack definitions that are automatically set to be blocked in the corresponding IPS policy.
Signature Set— This is the complete set of attack definitions developed and provided by Trellix Advanced Research Center. The Signature Set enables Trellix IPS to properly detect and protect against malicious activity. The Manager and the Sensors must be frequently updated with the latest signatures and software patches made available to you via the Update Server.
Attack definitions and signatures— Note that as you interact with Trellix IPS policies, you encounter the term attack, not signature. Trellix IPS defines an attack as being comprised of one or more signatures, thresholds, anomaly profiles, or correlation rules, where each method is used to detect an attempt to exploit a particular vulnerability in a system. These signatures and checks might contain specific means for identifying a specific known exploit of the vulnerability, or more generic detection methods that aid in detecting unknown exploits for the vulnerability. Combined in an attack, the signatures provide for maximum accuracy and coverage in attack detection.
Custom Attacks— There could be unique security requirements that would not be possible to be covered in the Trellix-supplied signature set. For such cases, you have the option of developing your own attack definitions. Such user-defined attacks are referred to as custom attack definitions or custom attacks. The Manager factors in the Custom Attacks as well when it calculates the attack definitions to be included according to an attack set profile. Custom Attacks are exclusively covered in the Custom attacks.