The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Implementing the Heuristic Web Application Server Inspection option

Prev Next

Heuristic Web Application Server Protection is the outcome of an extensive and ongoing research by Trellix. You can enable this feature at the interface and subinterface levels. When you enable this feature, the Sensor inspects HTTP and HTTPS traffic on the corresponding interfaces and subinterfaces for SQL injections. For HTTPS traffic, you must have enabled decryption and shared the server keys with the Sensor.

The following options are available when you enable Heuristic Web Application Server Protection:

  • You can enable heuristic analysis for all HTTP traffic seen at a specific interface/ subinterface or you can enable it only for specific website paths. So, for heuristic analysis, the Sensor considers only those HTTP requests that contain these paths. In the Manager, these paths are referred to as Website Paths to Protect. Specifying paths optimizes the performance of the feature.

  • You can enable the default heuristic detection mechanism for the protected website Paths. The Sensor considers each reserved SQL keyword in the normalized HTTP requests to the protected website paths. It considers factors such as the number of keywords in the query and the syntax of the query to determine if it is an attack. Because the research for heuristic analysis is ongoing, Trellix might tune the heuristic rules and algorithm from time to time. The changes are available to you when you update the signature set.

    When the Sensor detects an attack through the default heuristic detection mechanism, it raises an alert for HTTP: SQL Injection Attack Detected (Trellix IPS attack ID: 0x4029d300).

  • You can augment the default heuristic detection mechanism with specific strings. The Sensor treats these strings as blocked tokens. When it detects any of these strings in the HTTP requests to the protected website paths, it considers it as an attack. For example, you can specify the names of stored procedures because these are not expected in an HTTP request. In the Manager, these blocked tokens are referred to as Blocked Text.

    When the Sensor detects a blocked text, it raises an alert for HTTP: Stored Procedure Name Detected by SQL Injection Heuristic Engine (Trellix IPS attack ID: 0x00011200).

High-level steps for implementing the Heuristic Web Application Server Protection

  1. Make sure the web application servers that you want to protect are connected to the appropriate Sensor monitoring ports.

  2. For the Sensor to inspect HTTPS traffic, make sure that you have enabled SSL decryption and that you have imported the required SSL keys into the Sensor.

  3. If required, create the subinterfaces for your web application servers.

  4. Make sure that you have applied the required IPS policies to the interfaces or subinterfaces to which the web application servers are connected. Also, make sure that the following attacks are present and enabled in those IPS policies:

    1. HTTP: SQL Injection Attack Detected (Trellix IPS attack ID: 0x4029d300)

    2. HTTP: Stored Procedure Name Detected by SQL Injection Heuristic Engine (Trellix IPS attack ID: 0x00011200)

    Configure the required response actions for the above-listed attacks.

  5. Configure the Heuristic Web Application Server Inspection options at the admin domain.

  6. Configure and enable Heuristic Web Application Server Protection for the required interfaces and subinterfaces.

  7. Monitor Attack Log for alerts related to SQL injections.