Last Modified: 12/10/2015
Apply the appropriate exceptions to your named policy for Host IPS before installing the OS update in your production environment.
Apply the exceptions to the Host IPS policy before installing an OS patch or SP while the Host IPS client has IPS enabled and running in Prevent High severity reaction mode.
For example, three exceptions are required for a Windows XP SP1 to SP2 upgrade when the Host IPS client is in Prevent High severity reaction mode. The exceptions are signatures 885, 850, and 3747 (this is on a workstation; additional server signatures could apply on a server).
The process for applying the exceptions should be defined as drive:\*\i386\update\update.exe
NOTE: The * wildcard is for the dynamically created parent folder (for example: d:\813959b0c311cb6685d\i386\update\update.exe).
Steps to perform before applying an OS patch or SP to a Host IPS client running in Prevent High severity reaction mode:
Run an OS patch or SP on a selected test computer in Warning mode to identify any events that may be triggered.
Create appropriate exceptions and retest to ensure no other signatures are triggered.
Apply exceptions to production Host IPS clients before rolling out patch updates.
See the Host Intrusion Prevention 8.0 Product Guide (PD22894) for details on this new feature.