Important
On a Network Security sensor or sensor-enabled Network Security integrated appliance, the Intelligent Virtual Execution - Server compute node detects malicious events in a TrellixMVX deployment. The Intelligent Virtual Execution - Server compute node returns the results of the analysis over the SSH connection to the sensor, and it also determines the level of severity.
When a malicious event is detected, the Network Security MVX detection and analysis engines also determine the level of severity. An attack can include a combination of events—an initial infection, binary drop, as well as a callback—that together contribute to determining the severity of the attack.
A callback is an event in which the host is infected and the malware is attempting to call back to a command and control (CnC) server. For a callback, the severity is always critical because it is likely to involve attempted data theft. If the event is a Web infection and a malware object is found on the host, Network Security assigns a severity level of major. For an infection match or domain match alone, Network Security assigns a minor severity level. However, when major and minor severity calculations are aggregated per event, the severity level may increase.
Severity is closely linked to the infection life cycle and Network Security provides visibility into the details of every stage of the infection life cycle. Severity determinations are shown on the Alerts page per incident. Note the colors in the severity column, and how they represent the severity of each incident:
Critical (red) for malware callbacks.
Major (yellow) for Web infections and malware objects.
Low or Minor (blue) for domain match and infection match incidents.