STIGQter STIGQter: STIG Summary:

Trend Micro TippingPoint IDPS Security Technical Implementation Guide

Version: 2

Release: 2 Benchmark Date: 24 Oct 2024

CheckedNameTitle
SV-242167r856969_ruleTo protect against unauthorized data mining, the TPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-242168r856970_ruleTo protect against unauthorized data mining, the TPS must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-242169r856971_ruleTo protect against unauthorized data mining, the TPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-242170r856972_ruleTo protect against unauthorized data mining, the TPS must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-242171r856973_ruleTo protect against unauthorized data mining, the TPS must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-242172r856974_ruleTo protect against unauthorized data mining, the TPS must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-242173r840498_ruleThe Trend Micro TippingPoint Security Management System (SMS) must be configured to send security IPS policy to the Trend Micro Threat Protection System (TPS).
SV-242175r710068_ruleThe Trend Micro TPS must immediately use updates made to policy filters, rules, signatures, and anomaly analysis algorithms for traffic detection and prevention functions which are all contained in the Digital Vaccine (DV) updates.
SV-242176r1028382_ruleThe TPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis.
SV-242177r710074_ruleThe TPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis.
SV-242186r710101_ruleIn the event of a logging failure caused by the lack of audit record storage capacity, the SMS must continue generating and storing audit records, overwriting the oldest audit records in a first-in-first-out manner using Audit Log maintenance.
SV-242187r710104_ruleThe SMS and TPS must provide log information in a format that can be extracted and used by centralized analysis tools.
SV-242188r1028381_ruleThe SMS must be configured to remove or disable nonessential capabilities on SMS and TPS, which are not required for operation or not related to IDPS functionality.
SV-242189r839149_ruleThe TPS must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment.
SV-242190r839150_ruleThe TPS must block any prohibited mobile code at the enclave boundary when it is detected.
SV-242191r710116_ruleThe TPS must fail to a secure state which maintains access control mechanisms when the IDPS hardware, software, or firmware fails on initialization/shutdown or experiences a sudden abort during normal operation (also known as "Fail closed").
SV-242192r997619_ruleThe TPS must protect against or limit the effects of known types of denial-of-service (DoS) attacks by employing signatures.
SV-242193r997620_ruleThe TPS must block outbound traffic containing known and unknown denial-of-service (DoS) attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic.
SV-242194r840196_ruleThe TPS must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages.
SV-242195r840193_ruleThe TPS must block malicious ICMP packets by properly configuring ICMP signatures and rules.
SV-242196r1018783_ruleThe TPS must automatically install updates to signature definitions, detection heuristics, and vendor-provided rules.
SV-242197r1018784_ruleThe SMS must install updates on the TPS for application software files, signature definitions, detection heuristics, and vendor-provided rules when new releases are available in accordance with organizational configuration management policy and procedures.
SV-242198r839154_ruleThe TPS must block malicious code.
SV-242199r1018785_ruleThe TPS must generate a log record so an alert can be configured to, at a minimum, the system administrator when malicious code is detected.
SV-242201r856976_ruleThe TPS must detect network services that have not been authorized or approved by the ISSO or ISSM, at a minimum, through use of a site-approved TPS device profile.
SV-242202r856977_ruleThe IDPS must generate an alert to the ISSM and ISSO, at a minimum, when unauthorized network services are detected.
SV-242203r856978_ruleThe IDPS must continuously monitor inbound communications traffic for unusual/unauthorized activities or conditions.
SV-242204r856979_ruleThe TPS must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions.
SV-242205r971533_ruleThe TPS must send an alert to, at a minimum, the ISSM and ISSO when intrusion detection events are detected which indicate a compromise or potential for compromise.
SV-242206r971533_ruleThe site must register with the Trend Micro TippingPoint Threat Management Center (TMC) in order to receive alerts on threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected which indicate a compromise or potential for compromise.