Following is the procedure and process flow while integrating Trellix IPS with IVX.
Before you begin, make sure you configured the sandbox and it in active state.
Note
If you are configuring the IVX appliance, make a note of the IP addresses and the user credentials of the IVX broker nodes. Also, whether CA signed or Self-signed certificate is configured on the node. For more information, refer to the respective product documentation.
Note
If you are configuring IVX Cloud, create an API key in the IVX Cloud portal and make a note of it. For more information, refer to the respective product documentation.
You can configure IVX integration details at the admin domain level and/ or the device level.
If you are configuring a Trellix VX appliance, verify that the:
Manager to IVX Authentication Status is Successful
Sensor to IVX Authentication Status is Successful
If you are configuring IVX Cloud, verify that the:
Service Status is Running
Sensor to IVX Cloud Authentication Status is Running
You enable IVX as one of the malware engines in the corresponding Advanced Malware policy. For the sake of explanation, assume that you have enabled all the engines for all the file types.
Note
Trellix IPS follows down selection logic for file analysis. The file is submitted to the engines in order of their placement. Refer to Step no. 8 for the sequence. Based on the engine response, ` that you have configured high-severity malware to be blocked by the Sensor. Trellix GTI File Reputation reports a file as high-severity malware. Then, the Sensor blocks this file even before receiving the results from the IVX engine.
You have applied this Advanced Malware policy to the required inline ports.
Note
The appliance can be used with SPAN and tap ports. However, similar to other malware engines, response actions, such as Block and Send TCP Reset, might not have the desired effect since the file might have reached the target host.
If the Sensor detects a supported file type being transferred over HTTP, FTP or SMTP (encoded using Base64 only), it extracts the file and checks it against its allow list and then its block list.
Assume that the file's hash value is not listed in the Sensor's allow or block list. The Sensor stores the file on the disk as the user downloads it. The Sensor holds the last packet from the user for 6 seconds, while it awaits the results from any of the configured malware engines.
Based on the sandbox analysis, Trellix IPS determines the analysis method and the reports to be generated:
If the sandbox responds with a malware score using cached result that meets the Action Thresholds for alerting in the Advanced Malware policy, the Sensor raises MALWARE: Malicious File Detected by IVX alert and takes the other configured response actions.
If the sandbox does not respond with a malware score from cached result, the Sensor uploads the file to the sandbox and raises an informational alert: MALWARE: File Submitted to IVX for Analysis. The Manager polls the Sandbox for the file analysis result and updates the alert as malicious/clean.
Note
The Sensor maintains a cache of the files that were submitted to it earlier. The sandbox too maintains a cache of the files submitted earlier and the info can be referred by any Sensor device connected to it. This way, any file that comes for analysis is directly compared with the files saved in the Sensor and Sandbox cache. If there is a file match, the Sensor takes an action automatically without having to re-analyze it, thereby saving the analysis time.
Recall that the Sandbox must respond within the file scan timeout for the Sensor to function as explained above.
Note
In Trellix VX deployments, file submission timeouts might be seen for large files if:
The Trellix VX appliance is placed in a remote location
There is a latency in the network
To avoid such time outs, it is recommended to deploy the Trellix VX appliance near the Sensor and maintain proper network connectivity.
Note
For IVX Cloud deployments, latency can be observed depending on the geographical location of the customer since the service is hosted at a single source.
Trellix IPS performs malware analysis on files in the following sequence:
NS-series: → → → → →
The Manager polls the sandbox for the submitted files as mentioned in Step no. 7. When the results are received, the Manager updates the record in the Malware Files page.
If you had configured the Add to Block List action threshold in the Advanced Malware policy, the Manager can include the MD5 hash of this file in the block list of all its Sensors. Therefore, when the same file is detected by any of the Sensors, it is blocked by that Sensor itself. This reduces the chances of such malware entering your network again.
Note
In case MD5 entries limit has reached, the Manager adds SHA256 hash value(s) of the malware file(s) to its block list and sends the same hash value(s) to the Sensor through incremental or full update.
Note
Trellix recommends that you verify how the Advanced Malware feature works for a period of time, fine-tune it until it functions as expected, and only then enable the Add to Block List action threshold in the Advanced Malware policies.
What happens in case of MDR?
You configure IVX in the Active Manager. It takes 15 minutes for this configuration to be copied to the Secondary Manager. Alternatively, you can use the Retrieve Configuration feature in the Standby Manager to immediately copy the MDR configuration.
Note
The sandbox configuration cannot be manually made on the Manager which is in Standby mode. The Save button is hidden from the users and an Informational message is displayed on the IVX Integration page of the Standby Manager for the same.
When a Sensor submits a file to the sandbox, it informs both the Managers. So, both the Managers query the appliance separately for the results of the file.
Every 10 minutes, both the Managers cross-check their malware report data from the sandbox and ensure that the data is synchronized.
What happens in case of Sensors in failover?
When you configure the integration for the failover Sensors, both the Sensors establish separate communication channels with the sandbox. So, the sandbox considers them to be different users. It sends the update only to the Sensor that submitted the file.
The file is extracted only by the Sensor that detected it. If a Sensor goes down within the packet hold time interval, based on the port configuration, the file might be forwarded without malware analysis or dropped.
If the Sensor goes down after the packet hold time interval but before the file session time interval, the update from sandbox is lost since it is sent only to the Sensor that submitted the file.