This central point of this section is the IPS policy, but conceptually it is relevant to some of the other security policies of Trellix IPS as well.
The pre-defined IPS policies are provided as a generic starting point; you will want to customize one of these policies for your needs. So, the first step in tuning is to clone the most appropriate policy for your network and your goals, and then customize it. (You can also edit the policy directly.) Some things to remember when tuning your policies:
We ask that you set your expectations appropriately regarding the elimination of false positives and noise. A proper Trellix IPS implementation includes multiple tuning phases. False positives and excess noise are routine for the first 3 to 4 weeks. Once properly tuned, however, they can be reduced to a rare occurrence.
When initially deployed, Trellix IPS frequently exposes unexpected conditions in the existing network and application configuration. What may at first seem like a false positive might actually be the manifestation of a misconfigured router or Web application, for example.
Before you begin, be aware of the network topology and the hosts in your network, so you can enable the policy to detect the correct set of attacks for your environment.
Take steps to reduce false positives and noise from the start. If you allow a large number of "noisy" alerts to continue to sound on a very busy network, parsing and pruning the database can quickly become cumbersome tasks. It is preferable to all parties involved to put energy into preventing false positives than into working around them. One method may be is to disable all alerts that are obviously not applicable to the hosts you will protect. For example, if you use only Apache Web servers, you may want to disable IIS-related attacks.
For more information on IPS policy tuning best practices, refer to Effective policy tuning practices.