Examining ASR rules
We will talk about the general philosophy behind ASR rules, followed by each of the rules, and how we group them.
The philosophy behind ASR rules
In general, from a usability point of view, the HIPS is expected to fulfill two key objectives. Primarily, it should allow the creation of behavior-based rules for blocking specific activities, and it should provide a way to mitigate or manage the adverse impact in case of a false positive (FP). Exclusions are usually the most common method used for the same. So, the aim is to provide organizations with the control and flexibility required for managing the security posture of protected assets. This makes HIPS the obvious choice for ASR. Therefore, as a common industry practice, security providers (SPs) have been building platforms that allow the creation and management of rules and exclusions, and organizations are often seen making use of them throughout their tenures with their providers.
However, there are...