When you save a custom attack in the Manager server, the Manager categorizes the attack to include it in the applicable rule sets. One of the criterion that the Manager uses to categorize an attack is the application layer protocol that the attack is intended for. For Native Trellix IPS Format Custom Attacks, you can specify this when creating the attack. For Snort Custom Attacks, the Manager identifies it by itself.
Understand how the Manager identifies the impact protocol for a Snort Custom Attack, to ensure if a Snort Custom Attack is published in the policies it is intended for.
How the Manager identifies the impact protocol is explained below:
First, it tries to use the name of the rules file from which you imported the Snort Custom Attack. For example, if you imported it from ftp.rules, the impact protocol for that attack is identified is FTP. Depending on other criteria for classification, the Manager includes the attack definition in the Rule Sets that include FTP.
If the rules file name starts with web, for example web-attacks.rules or web-client.rules, then the identified protocol is HTTP.
As a best practice, do not specify the destination port number in the rules if you import rules from files named after the protocol. If you do, the Sensor restricts its search to those port numbers.
If the Manager is unable to identify the protocol by the first method, it identifies the protocol based on the destination port number in the rule. This assumes that the destination port number is a standard port number. For example, if you import a rule from a generically named rules file but the destination port is 80, the identified protocol is HTTP.
The Manager uses this method when you import a rule from a generically named rules file (for example, myrules.rules or when you create the rule in the Custom Attack Editor.
As a best practice, specify the destination port number (standard or otherwise) if you import the rules from a generically named file. This can improve Sensor performance because even if the protocol is not identified, the Sensor looks for the pattern only for the matching destination protocol.