STIGQter STIGQter: STIG Summary: Intrusion Detection and Prevention Systems Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 28 Oct 2025:

The IPS must block outbound traffic containing known and unknown denial-of-service (DoS) attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.

DISA Rule

SV-206881r1140706_rule

Vulnerability Number

V-206881

Group Title

SRG-NET-000192

Rule Version

SRG-NET-000192-IDPS-00140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the IPS to block outbound traffic containing known and unknown DoS attacks, by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.

Check Contents

If the device being reviews is an IDS, this is not applicable.

Verify the IPS blocks outbound traffic containing known and unknown DoS attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.

If the IPS does not block outbound traffic containing known and unknown DoS attacks, by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic, this is a finding.

Vulnerability Number

V-206881

Documentable

False

Rule Version

SRG-NET-000192-IDPS-00140

Severity Override Guidance

If the device being reviews is an IDS, this is not applicable.

Verify the IPS blocks outbound traffic containing known and unknown DoS attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.

If the IPS does not block outbound traffic containing known and unknown DoS attacks, by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic, this is a finding.

Check Content Reference

M

Target Key

2918