- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- IPS Rule Threat Prevalence
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPS Rule Threat Prevalence
Hi All,
I have one customer CP where in Threat Profiles-> IPS Advanced Section Threat Prevalence with Rare and Absolute tags are set to inactive. I wonder what is meaning of Threat Prevalence tags as I couldn`t find any information about them. The only thing I got that Rare tag is for Low Confidence and based on that I assumed Absolute must be Confidence High, but High Confidences are not all inactive.
Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My interpretation is that Threat Prevalence is how relevant the particular threat is to a typical environment today. A Threat Prevalence of Obsolete probably indicates that the threat is against obsolete systems and applications (think Windows NT, Windows XP, etc. - essentially software that has not been supported in a VERY long time). As mentioned in my IPS Immersion Class, these Additional Activations will never forcibly reactivate a protection that does not meet the current Confidence, Performance Impact, & Severity criteria for the IPS profile. As such the "Protections to Activate" Window is not generally very useful. However the "Protections to Deactivate" window CAN be useful, as it can deactivate numerous protections that currently meet the three criteria but are not relevant to your environment at all, and save the firewall overhead associated with looking for matches on those signatures.
If you'd like to see for yourself which IPS Protections are tagged with the "Obsolete" designation you can search for them as shown in this screenshot which shows a protection that dates from 1999:
CET (Europe) Timezone Course Scheduled for July 1-2
