In addition to the mechanics of the signature itself, Trellix IPS requires a few other pieces of information, as described below, to do its job properly:
Detection Window - The detection window is the portion of the traffic flow that the Sensor should check against an attack definition for matches. The detection window may be one of the following:
Packet - All of the signature tests (and thus all protocol fields) must occur in a single packet on the network.
Request - All of the signature tests must occur in the request direction of the flow. (Useful if the protocol is bidirectional and might include the same data or commands in either direction.)
Response - Identical to request, but used to examine only response-direction traffic
Flow - When the detection window is set to flow, all conditions can be fulfilled by traffic flowing in either direction. Tests are still subject to any ordering imposed by the structure of the signature or flow direction implied by the field being tested.
Note
It is possible to create a correct signature that will never trigger if the detection window is set incorrectly. This should be one of the first items you check when troubleshooting a custom attack definition.
Benign Trigger Probability - This is a measure of the confidence with which you believe the signature can identify a network event. A high benign trigger probability (BTP) implies that a signature may be prone to false positives. When creating the signature, you should set the BTP to "Low" to ensure that your signatures are selected by the Default Policy.