msg
In the msg rule option, you indicate the alert message. It is a simple text string that utilizes the \ as an escape character to indicate a discrete character such as a semi-colon.
Syntax:
msg: "<message text>";
When you create a Snort Custom Attack in the Custom Attack Editor, the Manager assigns the attack and rule name, which you cannot edit directly. The format of the name is as below:
Snort: <text entered for msg option> (sid: <sid value>)
The argument of the msg option features in the attack and rule name that the Manager assigns. Changing the msg argument or sid value and saving the rule will change the attack and rule name accordingly.
reference
In a rule, you can use the reference keyword to include references related to the corresponding attack traffic. For example, it could be the bugtraq or CVE id of known vulnerabilities. It could also be the address of a website that provides the details of the attack.
The following are the supported systems that you can specify in the reference option:
bugtraq
CVE
Trellix IPS ID
Arachnids
URL
Syntax:
reference:<id system>, id;
Examples:
reference: bugtraq, 514;
reference: url, www.microsoft.com/technet/security/bulletin/MS99-034.mspx;
You can view the references that are currently available in the Manager.
gid
gid stands for generator id and is not relevant in Trellix IPS. So, do not use them in your rules.
sid
sid stands for Snort rule ID. You must specify a unique sid for each Snort rule in the Manager. For Snort Custom Attacks that failed to import, the Manager assigns -1 as the sid.
Syntax:
sid:<sid value>;
rev
This enables you to identify any revisions of an existing rule. It is not a mandatory option, but Snort Custom Attacks without the rev option are converted with a warning. When you edit a Snort Custom Attack in the Manager, you can modify the rev value for your reference.
If you want to re-import a Snort Custom Attack with the same sid, then you can change the rev value and import it. The Manager overwrites the existing Snort Custom Attack with the one that you last imported.
Syntax:
rev:<revision integer>;
classtype
This is one of the options that you can use to categorize a Snort rule. In the Snort rules provided by Snort.org, the classtypes with the default priority are defined in the classification.config file. You can use these classtypes by importing the classification.config file into the Manager. Alternatively, you can define your own in a .config file and import it into the Manager. If you are defining your own classtype, then make sure you also assign a priority to the classtype.
Note
A rule must have a classtype or a priority.
Note
You can view the classification types that are currently available in the Manager.
Syntax for using a classtype in a rule is as follows. This assumes that the class name is available in the Manager database:
classtype: <class name>;
Syntax (for defining a classtype in a .conf file):
config classification: <class name>,<class description>,<default priority>
Example:
config classification: attempted-user,Attempted User Privilege Gain,1
priority
Using the priority option you can assign a severity to the rule. This overrides the default severity defined in the classtype.
The Manager assigns the severity for a Snort custom attack based on the following:
A priority 1 Snort attack definition is assigned a severity of High.
A priority 2 Snort attack definition is assigned a severity of Medium.
A priority of 3 or higher is assigned a severity of Low.
Syntax:
priority: <integer value>;