Device profiling (also referred to as OS fingerprinting) is a method by which Trellix IPS collects information about a remote computing device to decipher its operating system and device type. Trellix IPS carries out device profiling by using DHCP DISCOVER and REQUESTS, HTTP User Agent field, and TCP SYN and SYN + ACK packets.
If device profiling is enabled, the following Trellix products, when integrated, participate in device profiling:
IPS
NTBA
ePO - On-prem
Device profiling can be carried out in three ways:
Active device profiling
Passive device profiling
Device profiling using ePO - On-prem
Active device profiling involves querying a device and observing its responses. Active device profiling systems gain access to information, such as MAC addresses, operating system, and device type. In Trellix IPS, this method of profiling is used by NTBA. For information about device profiling using NTBA, refer to the Trellix Intrusion Prevention System Product Guide.
Passive device profiling involves collecting information without invasive device querying. Information is collected from one or more Sensors. It uses DHCP DISCOVER and REQUESTS, HTTP User Agent field, and TCP SYN and SYN + ACK to gather operating system information about a device. The operating system information about a specific device is displayed in the Attack Log. In Trellix IPS, this method of profiling is used by IPS Sensors.
Device profiling using ePO - On-prem functions by making use of communication established Trellix Agent and ePO - On-prem. When Trellix Agent is installed on any system, that system comes to be known as a managed host and passes device, operating system and other event details at regular intervals to ePO - On-prem. When ePO - On-prem is integrated with the Manager, it passes on information necessary for device profiling.