Consider the following factors when selecting the Trellix IPS Snort engine:
The NS-series Sensors can support up to 5000 Snort rules. If you require support for more rules, contact Trellix Support.
\X, \P, \K, \U, \R, and \C escape sequences and backreferences are not supported.
Isdataat with rawbytes modifier is not supported.
Norm and raw modifiers are not supported in urilen.
Snort rules cannot be created on ASN1 decoded content.
If the length of the content or uricontent (token length) is more than 96 bytes and less than or equal to 256 bytes, the target device type is automatically set to NS-series.
The following PCRE constructs are not supported:
Lookahead and lookbehind assertions.
Backreferences and capturing subexpressions.
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"WEB-CLIENT Adobe Acrobat getCosObj file overwrite attempt"; flow:established,to_client; flowbits:isset,http.pdf; file_data; content:".write|28|"; nocase; content:".getCosObj|28|"; distance:0; nocase; pcre:"/([A-Z\d_]+)\.write\x28.*?\1\.getCosObj\x28/smi"; reference: cve,2011-2442; reference:url,www.adobe.com/support/security/bulletins/apsb11-24.html; classtype:attempted-user; sid:20156; rev:1;)
In this example rule, \1 is the backreference.
Subroutine references and recursive patterns.
Conditional patterns.
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-IIS ASP.NET 2.0 cross-site scripting attempt"; flow:to_server,established; content:"__LASTFOCUS="; fast_pattern:only; pcre:"/__LASTFOCUS=(?!([_a-z]\w*|) ([\x26\x3B]|$))/i"; reference:bugtraq,20337; reference:cve,2006-3436; reference:url,www.microsoft.com/technet/security /bulletin/MS06-056.mspx; classtype:attempted-user; sid:8700; rev:5;)
In this example rule, !([_a-z]\w*|)([\x26\x3B]|$) is the conditional pattern.
Unicode character properties \p{xx} and \P{xx}.
Possessive quantifiers.
The following are additional limitations regarding PCRE in Trellix IPS Snort:
In a Snort custom attack, the maximum value for repetition counter in PCRE is 256. If it exceeds this number, the error message Pattern too large is displayed.
Atomic grouping and possessive quantifiers are not supported.
Note
PCRE rules validation is included in the Custom Attack Editor. So, any rule containing invalid or unsupported PCRE options fail to import. You can find the reason in the error message. After you correct these rules, use the Test Compile feature to check if the they are valid and compatible. You can select the required attacks and select Other Actions → Test Compile.
The following constructs are not supported in Trellix IPS Snort:
ack
asn1
bidirectional operator
byte_extract
byte_jump
byte_test
cvs
dce_iface
dce_opnum
dce_stub_data
depth
distance
dnp3_ind
dnp3_obj
dsize
fast_pattern
flowbits
fragbits
fragoffset
ftpbounce
http_stat_msg
icmp_id
id
ip_proto
ipopts
isdataat
metadata
modbus_unit
offset
port / IP negation
rpc
sameip
seq
stream_size
tos
ttl
window
within
The following are not supported in Trellix IPS Snort, but an equivalent option is available in Trellix IPS:
Rules using ftpbounce keyword are not supported. However, the Trellix IPS signature sets provide adequate protection against FTP bounce attacks.
Rules to detect CVS attacks are not supported. However, Trellix IPS signature sets can protect your network against most of the CVS attacks.
Regarding Sensor response actions, you cannot use any post-detection rule options such as Logto, Session, or Tag. Instead, you can configure the required response action after the rule is saved in the Manager database. This is the same as how you would configure the response action for any other attack definition in Trellix IPS.
Preprocessor plugins are not supported.
Snort's multi-event logging (event queue) is not supported.
For event thresholding and alert suppression, you can use only the equivalent features in Trellix IPS and not the options in Snort.
Classification types
It is mandatory that you define the priority for each Snort Custom Attack. Priority is one of the parameters that the Manager uses when it categorizes a Snort Custom Attack. To specify the priority, you can either use the priority keyword directly in the rule or use a classification type in the rule. However, this classification type should either be available in the Manager or declared in a file up front. That is, the Manager must read the classification type declaration before it reads the rule that uses it.
Note
You can view the classification types that are currently available in the Manager. You can also re-submit rules for conversion with the currently available values.
Similar to macros, you can define the classification types in a .conf, .config, or .rules file and import it into the Manager.
In the .conf, .config, or .rules file, define the classification type using the syntax as shown below:
config classification:<class name>,<class description>,<default priority>
Example: config classification: brute-force,attempted brute force,1
Note the following:
The priority value 1 is mapped to a severity of high in Trellix IPS, 2 to medium, 3 to low, and 4 and above to informational.
The default priority value that you specify in a classification type can be overridden by using the priority keyword in the rule.