If you are upgrading the Sensor from version 10.1 or 11.1 to version 11.1.5.22, read the following sections carefully.
Integration with Trellix Detection as a Service
Until the previous release, Trellix IPS offered integration capability with Trellix Virtual Execution which utilizes Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis.
Starting with this release of 11.1, Trellix IPS also offers integration capability with Trellix Detection as a Service which utilizes the MVX engine's technology to perform malware analysis on cloud.
To enable integration with Detection as a Service (DaaS):
At Global level: Navigate to → → → → , select Enable MVX Integration checkbox, choose Enable DaaS radio button and configure the details for the integration.
At Device level: Navigate to → → → → → .
You may select the Inherit Settings? checkbox to inherit the integration configuration from the corresponding admin domain.
Or,
Select Enable MVX Integration checkbox, choose Enable DaaS radio button and configure the details for integration.
To select MVX malware engine in an Advanced Malware policy, go to → → → → . You can enable inspection by MVX for all supported file types that is, Executables, MS Office Files, PDF Files, Compressed Files, Android Application Package, Java Archive, and Flash Files.
Use the Manager to view the following information with respect to files submitted for malware analysis to MVX Engine:
Dashboard tab: Use the Top Malware Files monitor to view the blocked and unblocked detections together or filter them out separately. Additionally, you can filter data based on the confidence level of the detection as well.
Analysis tab: The following enhancements are supported in the Malware Files page:
The overall malware confidence for a file is derived based on the results from MVX and any other malware engines configured.
If applicable, you can view the MVX‑specific details for a particular type. This is similar to how you view the details for other engines.
In the Malware Files page, click
next to the confidence level of MVX to view the results reported by MVX. You can also download a file that contains all the reports for the malware from MVX. This file contains detailed analysis result data and can be opened with any text editor.
Devices tab: You can view the statistics of the malware detected for a given device under → → → → → → tab. The By Malware Engine option displays the malware detected data based on the malware engines configured for the device. This includes the malware detected data associated with the MVX engine.
A list of Sensor CLI commands have been updated to support DaaS integration.
The following Sensor CLI commands are updated:
Command | Description (If DaaS is configured) |
|---|---|
| This command can now display the DaaS configuration details. |
| This command earlier displayed statistics related to VX analysis. Starting with this release, the command now has the functionality to display statistics related to DaaS analysis as well. |
| This command now displays the connection status of the MVX engine as enabled even if DaaS is configured. |
| This command now allows users to clear MVX related cache entries made in the Sensor which includes DaaS entries as well. |
| This command now clears all the statistics counters in the Sensor including the MVX counters associated with DaaS. |
| This command now displays the malware engine statistics related to DaaS under MALWARE STATISTICS FOR MVX ENGINE section. |
| This command now displays the malware file statistics related to DaaS. |
Command | Description (If DaaS is configured) |
|---|---|
| This command now enables or disables MVX engine. |
| The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types. |
| This command now displays the status of the MVX engine as enabled even if DaaS is configured. |
| This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types. |
Support for SHA256 hash type in Allowed and Blocked File Hashes
Starting with this release of 11.1, Trellix IPS offers capability to add SHA256 hashes to the Allowed and Blocked lists of the File Hashes under → → → → .
Note
The Manager running on 11.1 Update 1 or later releases supports addition of up to 400,000 hash entries (allowed and blocked hashes combined) with a limit of 200,000 per hash type. Manager prior to 11.1 Update 1 release supports addition of only MD5 hashes up to 100,000 entries (allowed and blocked hashes combined).
Sensors prior to 11.1 Update 1 release do not support SHA256 hashes. The maximum number of hashes supported (allowed and blocked hashes combined) by these Sensors is 100,000.
Sensors running on 11.1 Update 1 or later releases support both SHA256 and MD5 hashes. NS-series Sensors support a maximum of 200,000 hashes for each hash type while IPS-VM600 Sensors support a maximum of 100,000 hashes for each hash type. If the Manager has both NS-series and virtual Sensors, entries over 100,000 in each hash type are pushed only to the NS-series Sensors. The push fails on virtual Sensors and a fault is raised which can be noticed in the Faults ( → → → ) tab.
In case of heterogeneous environments, if the total MD5 hash entries exceed 100,000:
A limit exceed error can be seen in filetransfer.log during a bulk (full) update.
A fault will be raised in the Faults tab and error count will be incremented at the Sensor level during an incremental update. Refer to
show ab statscommand for more information.Note
A Full update is triggered when the total entries are more than 4000; else, an incremental update is triggered to all the Sensors connected to the Manager.
In case MD5 and SHA256 hashes of the same file are added, the MD5 hash takes precedence over SHA256 hash of the file during analysis.
Allow whitelisting of domains under the Sensor load
Starting with this release of 11.1, when the datapath processors on the Sensor are experiencing a high number of queued packets to be processed, the traffic from domains in the whitelist is skipped for inspection.