Important
On a Network Security sensor or sensor-enabled Network Security integrated appliance, the sensor extracts the suspicious or malicious objects and URLs that need to be analyzed by the MVX cluster in a TrellixMVX deployment. Sensors enrolled with the MVX cluster submit these objects and URLs to any Intelligent Virtual Execution - Server compute node in the MVX cluster for further analysis. The Intelligent Virtual Execution - Server compute node returns the results of the analysis over the SSH connection to the sensor. You can view the results of the analysis on the Alerts > Alerts > Alerts page, Alerts > Alerts > Hosts page, or the Alerts > Alerts > Callback Activity page in the sensor Web UI.
The alerts provided by the Network Security appliance identify incidents correlated with phases of the malware infection life cycle. For example, when a browser renders all the content on a legitimate Web page, the full page view often contains advertisements from third-party carriers. Attackers can post a fake advertisement with a zero-day exploit on the legitimate safe site. When exploit content is delivered by the browser, the first-stage analysis component of the Network Security MVX engine identifies the content as either suspicious or malicious. The Network Security sends the full page view of the Web page, including the exploit, to the MVX engines for detonation and second-stage analysis.
The Network Security virtual environment is exploited as the content is rendered. This exploit may cause the browser to download a second-stage malware binary, known as dropper code. This binary is usually fetched from another website that is completely independent from the advertisement infrastructure, but that blends in to appear as though it is delivering ad content.
The browser, as instructed by the initial exploit, unpacks the malware binary and executes it in order to load the attacker’s full malware toolkit into the Network Security MVX analysis engine. After the malware binary is loaded into the virtual victim machine, the binary instructs the MVX to transmit network callback traffic to the attacker, signaling that it is ready to be controlled remotely by the attacker. However, because the MVX operates in an isolated and virtualized network, this traffic remains internal to the appliance.
The Network Security appliance then collects the network traffic generated by the MVX and creates a dynamic network rule to identify the same callback traffic across the monitored network. When the malware binary transmits network callback traffic to the CnC attacker, the Network Security appliance blocks the callback traffic. The appliance captures all files created or modified during MVX analysis for further forensics. This process requires advanced debugging parameters to be configured. The appliance posts the zipped files on the Alerts page, generates an Alert incident, and sends notification(s) to the administrator so the administrator can remediate the infection on the infected host in the actual enterprise network.
Further attempts to reach the CnC server are blocked for the infected host, and new clients are alerted to the attack.
Monitored Alert Types
This section describes the activity alert types theTrellix appliance monitors and the response when these alert types are detected.
Callback Activity
Callback activity alerts are generated when the appliance observes outbound communications associated with a remote CnC server, indicating that there is an established connection between an infected host and the CnC server.
The activity can include botnet/malware command and control communications, uploads of confidential information, and downloads of secondary payloads (such as keyloggers or spyware).
Response
Immediately quarantine or clean the infected host.
Host Infections
Host infection alerts indicate that the appliance has detected malware in the act of infecting a host. The appliance MVX engine has either observed the full infection, including the exploitation of an application vulnerability and a malware/payload transfer to the host, or it has simply observed a malware binary being transferred to the host via an unknown exploit. The exploit can be a Web browser-based exploit or a network services-based exploit.
Usually Web infection attacks pass through the firewall and other perimeter security devices because a Web browser inside the organization initiated an outbound connection to what turns out to be a malicious (usually external) website.
A network services exploit is an attempt to infect a computer via a known or unknown vulnerability in the Windows operating system.
For novel or zero-day attacks, the name shown on the Alerts page indicates whether the novel attack was a browser-based attack (Exploit.Browser), an unknown malicious binary (Malware.Binary), or an unknown network services exploit (such as Exploit.Msrpc).
Response
Click Alerts to view the alert details associated with the infected host. If you see at least one malware callback alert with a host that also has a Web infection, there is a very high probability that the host is infected.
For suspected browser-based infections, use the following method to confirm the infection:
Confirm that OS anomaly changes found on the appliance correspond to those on the actual host. Viewing the OS anomaly details associated with a Web Infection event shows registry changes, file system changes, and processes that have been started as a result of the infection. If suspicious-looking changes in theTrellix analysis match changes on the actual host, then the infection can be confirmed.
Immediately patch or otherwise remediate the infected system.
If a malware callback event was detected (involving the infected host), prevent the CnC server from communicating with all hosts in your network.
Infection life cycle phases and alert types
Each alert type may contain many events. The Network Security appliance classifies the infection life cycle in two phases. The exploitation and dropping of malicious code is the Infection Phase. The callback and extraction or theft of sensitive data and documents is the Callback Phase. Some MVX engine execution events are relevant to both phases.
Infection Phase (Alert Type) [Event] | Callback Phase (Alert Type) [Event] |
|---|---|
Web Infection (Exploit.Browser) [web-infection][os-change-anomaly] [vm-malware-execution] | CnC (CnC Rule or SigMatch) (CnC Communication) [vm-signature-match][os-change-anomaly] [vm-malware-execution] |
Binary Analysis (Malware.Binary) [malware-object][checksum-match] [os-change-anomaly][vm-malware-execution] | Domain Name (DNS Match) [domain-match][os-change-anomaly] [vm-malware-execution] |
Infection Match (Local.Infection) [infection.match][malware-object] [web-infection][os-change-anomaly] [vm-malware-execution] | URL & non-HTTP Callback (CnC Communication URL, and so forth.) [malware-callback] [os-change-anomaly] [vm-outbound-call] [vm-malware-execution] |