Trellix supplies a set of preconfigured attack set profiles that correspond to the preconfigured IPS policies as well. You can use these attack set profiles to create specific IPS policies according to your requirements. That is, you can clone these attack set profiles and modify them to create custom IPS Policies. These pre-defined attack set profiles are available in the Attack Set Profiles page, which you can access from the Policy tab.
Attack set profiles | Designed to Protect Against: |
|---|---|
Default Detection | All attacks. |
Default DoS and Reconnaissance Only | All signatures are disabled by default. This policy is provided for the scenario where a substream of traffic needs to be ignored by the IPS. |
Default Exclude Informational | All attacks, including those with known noisy signatures, but omitting Informational severity attacks. This policy differs from Default as it alerts for every attack in the Trellix IPS database, including those with noisy signatures. This enables expert security personnel to fully analyze their network traffic. Informational "attacks" are not enabled. |
Default Prevention | All attacks and Trellix-recommended blocking of selected attacks |
Default Testing | Similar to above, with the exception that Informational-level alerts are included. |
DMZ | All attack types except for those exploits using TFTP, Telnet, RIP, NETBIOS, NFS, and WINS. |
DNS Server | All Reconnaissance and DoS attacks, generic backdoors, and exploits using the DNS protocol. |
File Server | All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, NFS/RPC, and NETBIOS/SMB protocols. |
Inside Firewall | All attack types except for those exploits using TFTP, Telnet, and RIP. |
Internal Segment | All attacks except for exploits using RIP and routing protocol attacks. |
Linux Server | All attacks where the impacted operating system includes Linux. |
Mail Server | All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, SMTP, POP3, and IMAP protocols. |
Outside Firewall | All attacks except for Reconnaissance category. |
Solaris Server | All attacks where the impacted operating system includes Solaris. |
UNIX Family | |
UNIX Server | All attacks where the impacted operating system includes UNIX. |
Web Server | All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, HTTP, and FTP protocols. |
Windows and Solaris Server | All attacks where the impacted operating system includes Windows or Solaris. |
Windows and UNIX Server | All attacks where the impacted operating system includes Windows or UNIX. |
Windows Family | |
Windows Server | All attacks where the impacted operating system includes Windows. |
Windows, Linux, and Solaris Server | All attacks where the impacted operating system includes Windows, Linux, or Solaris. |