The Manager software has a web-based user interface for configuring and managing Trellix IPS. Users connect to the Manager server from a supported client using a supported browser, the details of which are in the Trellix Intrusion Prevention System Installation Guide. The Manager functions are configured and managed through a GUI application, which includes complementary interfaces for alerts, system status, system configuration, report generation, and fault management. All interfaces are logically parts of the Manager program.
The Manager user interface has five main tabs:
Dashboard — The Dashboard is the first page displayed after the user logs on to the system. Options available within the page are determined by the current user's assigned roles. The Dashboard enables you to view all the critical information regarding Trellix IPS deployment in the same page. The Dashboard is very user configurable. You can configure the information that you want to view, the timeframe for which you want to view the information, the frequency with which the Dashboard must auto-refresh, and so on. All these information can be customized to view for a particular admin domain. You can select the admin domain from the Domain drop-down list to display data for the selected admin domain.
Some of the information displayed on the dashboard includes:
Release announcements
Information regarding the frequently seen malicious activities on your network. This includes things, such as the most downloaded malware, most callback activity, the most targeted hosts, the most detected attack and so on.
System faults of Trellix IPS components which show whether all those are functioning properly, the number of unacknowledged alerts in the system, and the configuration options available to the current user
Manager-related details, such as the version, signature set version, users logged on to the Manager, and so on
Information like whether the devices are up-to-date
Analysis — This tab presents the options using which you can view the granular details of all the malicious activities on your network. The intention here is to provide you all the critical information needed for further analysis for the selected admin domain.
One of the key options on the Analysis tab is the Attack Log, which displays the alerts triggered by the Sensors. The Attack Log page displays the hosts detected on your network as well as the detected security events that violate your configured security policies. The Attack Log provides powerful drill-down capabilities to enable you to see all of the details on a particular alert, including its type, source and destination addresses, and packet logs where applicable.
Policy — All the major features in Trellix IPS are policy based. For example, to block exploit and recon attacks, you use the IPS and the recon policies; for Firewall, you use the Firewall policies; for QoS, you use the QoS policies and so on. The Policy tab provides the options to manage all these policies and other related functionality.
Devices — You can use the same instance of the Manager to manage both the physical and virtual devices. The Devices tab provides all system configuration options, and facilitates adding and configuration of your devices - Sensors, NTBA Appliances, HA pairs of Sensors, etc. This tab provides configuration options on per device basis as well. Access to various activities is based on the current user's role(s) and privileges, administrative domains, attack policies and responses, user-created signatures, and system reports.
Manager — This tab provides the configuration options related to the Manager software. This includes managing administrative domains, users, and roles, downloading signature sets and other software such as Sensor software, integrating the Manager with other Trellix products, maintenance activities such as database backups, and so on.
Other key features of Manager include:
Integration with other Trellix products — You can integrate Trellix IPS with other Trellix products to provide you with a comprehensive network security solution.
Trellix ePolicy Orchestrator - On-premises — Trellix ePolicy Orchestrator - On-premises is a scalable platform for centralized policy management and enforcement of your system security products, such as anti-virus, desktop firewall, and anti-spyware applications. You can integrate Trellix IPS with ePO - On-prem 5.0 and above. The integration enables you to query the ePO - On-prem server from the Manager for viewing details of a network host.
Trellix Global Threat Intelligence — Trellix Global Threat Intelligence is a global threat correlation engine and intelligence base of global messaging and communication behavior including reputation, volume, trends, email, web traffic and malware. By having Trellix Global Threat Intelligence integration, you can report, filter, and sort hosts involved in attacks based on their network reputation and the country of the attack origin.
Trellix Intelligent Sandbox — Trellix Intelligent Sandbox is an on-premise appliance that facilitates detection and prevention of malware. Trellix Intelligent Sandbox provides protection from known, near-zero day, and zero-day malware without compromising on the quality of service to your network users.
Trellix Intelligent Virtual Execution (IVX) — Intelligent Virtual Execution (IVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The IVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.
Trellix IPS offers integration capability with Intelligent Virtual Execution - Server and Intelligent Virtual Execution - Cloud which utilize IVX engine's technology to perform malware analysis.
Trellix Network Investigator — Network Investigator (NI) is a security analytics solution that allows the analysis of alerts and network metadata gathered from all devices connected to it. Network Investigator can ingest alerts and collect Layer 7 metadata from other Trellix products, including Network Security (NX), Packet Capture (PX), and Endpoint Security (HX), and provides a high-level view of the network metadata gathered over customizable dashboards supporting multiple configurations. It thus enables users to have a metadata-based view of network activities and search indexed metadata from various network protocols, which allows them to zero down on threat information critical for performing further investigation.
Trellix IPS offers integration capability with Trellix Network Investigator using which it exports netflows and Layer 7 metadata from IPS Sensors, and alert data from IPS Manager to NI, as per the configuration and filter parameters set by the user. The alert data, L7 metadata information, and net flow records exported by Trellix IPS are displayed on the Dashboard of NI's Web UI which users can review and utilize further for the detection and analysis of network threats.
For more information on all the above mentioned integration options, see Trellix Intrusion Prevention System Integration Guide.
Integration with third-party products — Trellix IPS enables the use of multiple third-party products for analyzing faults, alerts, and generated packet logs.
Fault/Alert forwarding and viewing — You have the option to forward all fault management events and actions, as well as IPS alerts to a third-party application. This enables you to integrate with third-party products that provide trouble ticketing, messaging, or any other response tools you may want to incorporate. Fault and/or alert forwarding can be sent to the following ways:
Syslog Server — forward IPS alerts and system faults
SNMP Server (NMS) — forward IPS alerts and system faults
Java API — forward IPS alerts
Packet log viewing — View logged packets/flows using third-party software, such as Wireshark.