Intrusion rule updates
An intrusion rule update is a cumulative package that provides new and modified intrusion and preprocessor rules, and modifies the policies that use them.
Intrusion rule update versions
As new vulnerabilities become known, the Talos Intelligence Group releases intrusion rule updates. Keep intrusion rules up to date. Each update replaces the previous version, and you can import only an update that is newer than the currently installed version.
Contents of intrusion rule updates
An intrusion rule update can contain these types of content:
-
Rules and rule states: An update can add, modify, or delete intrusion and preprocessor rules. The default state of a new rule can differ between system-provided intrusion policies. For example, a new rule can be enabled in the Security over Connectivity policy and disabled in the Connectivity over Security policy. An update can also change the default state of an existing rule.
-
Rule categories: An update can contain new rule categories. Importing the update adds all new categories.
-
Preprocessor and advanced settings: An update can change advanced settings in system-provided intrusion policies and preprocessor settings in system-provided network analysis policies. It can also change the default values of advanced preprocessing and performance options in access control policies.
-
Variables: An update can change the default values of existing variables without overriding customized values. It also adds new variables.
Policy changes from intrusion rule updates
Intrusion rule updates can affect system-provided and custom network analysis and intrusion policies, as well as the access control policies that use them. The effects depend on the policy type.
-
System-provided policies: Changes to system-provided network analysis and intrusion policies and advanced access control settings take effect after you redeploy the configuration.
-
Custom policies: Every custom network analysis and intrusion policy is based directly or indirectly on a system-provided policy. For each custom policy, you can prevent rule updates from automatically applying changes from its base policy. You can then apply the base-policy changes manually on a schedule independent of rule update imports. Updates do not override customized settings.
Caution | Importing an intrusion rule update discards all cached changes to network analysis and intrusion policies. Before you import an update, use the Rule Updates page to identify policies with cached changes and the users who made them. |
Scheduled intrusion rule updates
Initial configuration creates a daily schedule for intrusion rule updates. Review the schedule and adjust the frequency as needed. Refer to Schedule intrusion rule updates.
Deployment after intrusion rule updates
Deploy configuration changes after an intrusion rule update for the update’s changes to take effect. You can configure an import to deploy automatically to affected devices. Automatic deployment is especially useful when you allow updates to modify system-provided base intrusion policies.
Caution | Although a rule update by itself does not restart Snort when you deploy, other changes you have made may. Restarting Snort briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or scalability. Interface configurations determine whether traffic drops or passes without inspection during the interruption. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection. |