This scenario is about creating a Custom Attack Definition that uses string pattern match to detect any HTTP GET requests in the request URL for a specific string.
In order to write a proper Native Trellix IPS Format Custom Attack for this example, you must identify several key elements:
Application protocol: HTTP
Where to look: URL
Detection window: request
Request method: get
String to match: LpEhZWWuLc0AwAAeHB3DAAAABA
To create the attack definition for this example:
In the Custom Attack Editor, click
.The New Custom Attack interface opens.
.png)
Select one of the options from the State drop-down menu.
You can specify a name such as " Custom Exploit: String Pattern Match" as the Name.
The letters "UDS" (user-defined signature) are appended to the front of the name upon completion; thus, this attack appears as "UDS-Custom Exploit: String Pattern Match" in the Custom Attack Editor, as well as the attack database when you save in the Manager server.
Type a description for your attack. This area can be used for your notes or other specific information pertinent to your new attack.
You can select Medium (5) as the Severity because this example scenario does not necessarily involve malicious activity.
Select Advanced Protection Options/Web Application Server as the Protection Category.
Select Custom Exploit (Signature-Based) from the Detection Type drop-down menu for the attack.
Click Next.
.png)
In the Matching Criteria section, select Protocol as the Criterion and select http as the protocol.
When you subsequently save this attack definition in the Manager server, it will be part of every rule set which includes Medium-severity, HTTP attacks (must match both severity and protocol).
.png)
Attack details configuration is complete. Continue to create signature.