Scenario
This is about creating a Custom Attack Definition that uses pattern matching to detect any HTTP GET requests in the URI patch for a specific CGI script. This scenario is useful because it illustrates the simplest method of configuring a custom attack definition with proper syntax, defined options, and case sensitivity.
Creation of such an attack definition is also a good example of activity that may not be a malicious attack; rather, you could create such an instance and use it to track requests for sensitive information.
In order to write a proper Native Trellix IPS Format Custom Attack or a Snort Custom Attack for this example, you must identify several key elements:
Application protocol: HTTP
Where to look: URI path
Detection window: request
Request method: get
String to match: cgi.bin/trillion.pl or cgi.bin/trilliant.pl, where only "pl" is case insensitive
When you have all of the required elements to properly identify the activity, attack definition can be successful.
To create a custom attack definition:
Open the Custom Attack Editor.
Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.