You can define the snort variables in Trellix IPS and then use it in the rules.
Task
- Define the variables with the appropriate values in a file.
-
Import the file into the Sensor.
To define the variables in a file:
-
Create a text file and change its file extension to .rules or .conf.
Assume that you have named it variables.conf
-
In the text file, define the variables as explained below
- Use the
var keyword to define a variable for a file path, IP addresses, and ports.
For example, var RULE_PATH ../rules.
In this example, RULE_PATH is the variable name and its value is the relative path to a folder named "rules".
- Use the ipvar keyword to define a variable for IP addresses. Some examples are:
- ipvar INSIDE_NETWORK [10.1.1.0/24, !10.1.1.22, 11.1.1.1, 12.1.1.0/24]
- ipvar EXAMPLE1 [$INSIDE_NETWORK, !10.1.1.23]
- ipvar EXAMPLE2 [$EXAMPLE1]
- ipvar EXAMPLE3 [1.1.1.1, 2.2.2.0/24, ![2.2.2.2, 2.2.2.3]]
- Use the portvar keyword to define the port numbers
For example, portvar EXAMPLE_PORTS [100, 102, 150:160, !155]
In this example, the value of EXAMPLE_PORTS is 100, 102, 150 through 160 except 155.
- Use the
var keyword to define a variable for a file path, IP addresses, and ports.
- Save the variables.conf file.
To import the variables file into Sensor:- In the Custom Attack Editor, from the Snort Format tab, click Snort Variables. Alternatively, to import select Other Actions → Import.
-
Locate variables.conf and click
Open.
If you do not see the conf file at the location where you saved, check the Files of Type field in the Open dialog.
-
Click
Open.
The Import Status may show zero for all the fields. Click OK.
- Select Snort Format to make sure the variables are imported with the values you specified in the variables.conf file.
- If a variable that you imported is already available in the database, it is assigned the value from the current import.
-
Create a text file and change its file extension to .rules or .conf.