8Maintenance

This section describes the activities used to maintain and fine-tune a Host Intrusion Prevention deployment and includes the following topics:

„Fine-tuning a deployment

„Policy maintenance and tasks

„Running server tasks

„Setting up notifications for events

„Running reports

„Updating

Fine-tuning a deployment

After you have deployed clients with default settings, you can fine-tune and tighten security for optimum protection. Fine-tuning a deployment involves:

„Analyzing IPS events.

„Creating exception rules and trusted application rules.

„Working with client exception rules.

„Creating and applying new policies.

Analyzing IPS events

An IPS event is triggered when a security violation, as defined by a signature, is detected. It appears on the IPS Events tab with a severity level of High, Medium, Low, or Information, which maps to a reaction.

When single operation triggers two events, the event with the stronger reaction is taken.

115

Page 115
Image 115
McAfee 6.1 manual Maintenance, Fine-tuning a deployment, Analyzing IPS events, 115