Enhancing SmartVision capabilities is integral to Trellix Network Detection and Response (NDR) initiative, in which Trellix IPS serves as a Sensor to bolster these capabilities within the NDR framework.
Trellix IPS now includes SmartVision attacks, a new set of native IPS attack definitions that enhance the detection and correlation capabilities for the NDR framework. These attacks generate base events that allow for more comprehensive and effective analysis and correlation of network activities and potential threats, when the integration between Trellix IPS and Trellix Network Investigator (NI) is enabled.
The attack definitions related to SmartVision attacks are incorporated into the IPS signature set as native IPS attack definitions. When a compatible signature set that include SmartVision attack signatures is imported and deployed in the IPS Manager, those are automatically added in default IPS policies (barring Default DoS and Reconnaissance Only policy) in the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS page with the severity level set to Low and higher.
Here's a break-down of how the Manager and Sensor work together for the detection and export of SmartVision attacks to NI:
Any Manager running on 11.1 update 7 software version or later performs conditional/dynamic signature set compilation and sends SmartVision attack signatures to only Sensors that are running on 11.1 update 7 software version and later, and have integration with Trellix NI enabled.
Any Manager running on 11.1 update 8 software version and later includes additional L7 data fields for SMB and DCERPC protocols in the Layer 7 Data Collection page. The L7 fields related to SMB (under netbios-ss section in the Layer 7 Data Collection page) and DCERPC protocols are applicable only for Sensors running on 11.1 Update 8 version or later and can be customized accordingly.
Note
DCERPC L7 data collection is supported over TCP only.
Note
To know more about the L7 fields available for configuration, see Enable Layer 7 Data Collection for an interface or subinterface.
When any alert/attack is detected in any customer network environment, Manager sends all relevant alert data in JSON format to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send SmartVision attack-related L7 metadata to NI. NI consumes these base event alerts from Manager, L7 metadata from the Sensors, and displays alerts/incidents on the NI Dashboard.
Important
Currently, IPS Sensors export L7 metadata related to HTTP, HTTPS, HTTP2, SMTP, FTP, DNS, SMB, and DCERPC protocols to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send only SmartVision attack-related L7 metadata to NI. For more information, see the chapter Integration with Trellix Network Investigator.
These data help Trellix NI to correlate events identify indicators of compromise along the attacker kill chain, particularly for lateral movement. It can, for example, identify the types of malicious network activities that take place inside a customer network after the victim’s system has been compromised, when the attacker has already gained a foothold in the network and is beginning to move laterally within the network or steal data. This enables the effective detection and handling of potential malicious threats within the customer network, significantly strengthening the overall security posture.
Note
This feature is supported in Manager and Sensor running on 11.1 Update 7 versions or later, along with a compatible signature set (11.10.23.3 and above) that includes SmartVision attack signatures. To learn more about SmartVision attack signatures, see article 000014030.
For the detection and export of SmartVision attack related alerts and L7 metadata related to SMB and DCERPC protocols to NI, you need to use Manager and Sensors running on 11.1 Update 8 version or later, along with a compatible signature set (11.10.28.4 and above).