In recent times, the design of the network protocols (mechanism to send and receive data to end applications) has exposed vulnerabilities that allow data to bypass information security devices to deliver an exploit or attack to target networks. The network traffic uses encoding or encryption techniques to evade detection. Trellix IPS provides a mechanism to perform advanced inspection on such traffic. Using Advanced Traffic Inspection, the following traffic segments are decoded/reassembled:
The SMTP protocol specification does not address the transfer of binary data, so binary data is encoded to that end. Base64/Quoted-printable encoded PDF files in SMTP traffic can now be inspected to detect threats or anomalies.
The HTTP response traffic might contain chunked payloads. Such payload chunks can be reassembled, facilitating the detection of any threats or anomalies.
The HTTP response traffic might contain encoded PDF files. Such encoded files in the HTTP response traffic can be inspected to detect any threats or anomalies.
MS RPC/SMB traffic can be fragmented, segmented, or both. Such data can be reassembled to detect any threats or anomalies.
Note
When Advanced Traffic Inspection is enabled in a deployment with 90 percent good traffic and 10 percent traffic that uses evasions, the Sensor throughput could drop by approximately 5 percent.