This topic covers the following information:
IPS rules tailored to your environment
Identification of events and alerts for custom IPS rules
IPS rules tailored to your environment
IPS-enabled platforms use IPS content rules to provide signature-based detection of client-centric and server-centric attacks over multiple protocols. You can create your own IPS content rules that can detect specific intruder signatures found in the data packets in your network traffic.
Custom IPS rules can include descriptions of malware families based on textual or binary patterns contained in samples of identified families. The custom IPS rule descriptions consist of a set of strings and a Boolean expression that determines the rule’s logic.
Like IPS events (potential network threats) detected using Trellix-provided or locally generated IPS rules, IPS events detected using custom IPS rules are confirmed by automatic correlation with client-centric attacks already verified by the signature-less Network Security appliance rules engines that use the Multi-Vector Execution (MVX) engine on the appliance.
Identification of events and alerts for custom IPS rules
When a Trellix IPS rule or a custom IPS rule triggers, the signature name is displayed in the Rule column of the IPS Events page or in the Last Malware column of the Hosts tab. Unlike rule names for Trellix-provided or locally generated IPS rule names, however, custom IPS rule names displayed in the IPS Events page or in the Hosts tab are not linked to IPS rule description pages.