Integration with Multi-Vector Virtual Execution (MVX) Engine
Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.
Starting with this release of 10.1, Trellix IPS offers integration capabilities with Trellix Virtual Execution (VX) appliances which utilize Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis. MVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.
To enable integration with MVX:
- At Global level: Devices → <Admin Domain Name> → Global → IPS Device Settings → MVX Integration.
- At Device level: Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → MVX Integration.
To select MVX malware engine in an Advanced Malware policy, go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware. You can enable inspection by MVX for all supported file types that is, Executables, MS Office Files, PDF Files, Compressed Files, Android Application Package, Java Archive, and Flash Files.
Use the Manager to view the following information with respect to files submitted for malware analysis to MVX Engine:
Dashboard tab: Use the Top Malware Files monitor to view the blocked and unblocked detections together or filter them out separately. Additionally, you can filter data based on the confidence level of the detection as well.
Analysis tab: The following enhancements are supported in the Malware Files page:
-
The overall malware confidence for a file is derived based on the results from MVX and any other malware engines configured.
- If applicable, you can view the MVX‑specific details for a particular type. This is similar to how you view the details for other engines.
- In the
Malware Files page, click
next to the confidence level of MVX to view the results reported by MVX. You can also download a file that contains all the reports for the malware from MVX. This file contains detailed analysis result data and can be opened with any text editor.
Devices tab: You can view the statistics of the malware detected for a given device under Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics → Advanced Malware Analysis tab. The By Malware Engine option displays the malware detected data based on the malware engines configured for the device. This includes the malware detected data associated with the MVX engine.
A list of Sensor CLI commands have been added to support the MVX engine integration.
The following Sensor CLI commands are added:
| Command | Description |
|---|---|
| show mvx config | This command displays the MVX configuration details |
| show mvx stats | This command displays statistics specifics to MVX engine analysis. |
| show mvx status | This command displays the connection status of the MVX engine. |
A list of Sensor CLI commands have been updated to support the MVX engine integration.
The following Sensor CLI commands are updated:
| Command | Description |
|---|---|
| clearmalwarecache | This command now allows users to clear MVX related cache entries made in the Sensor. |
| clrstat | This command now clears all the statistics counters in the Sensor including the MVX counters. |
| show malwareenginestats | This command now displays the malware engine statistics related to MVX. |
| show malwarefilestats | This command now displays the malware file statistics related to MVX. |
The following Sensor CLI commands are updated:
| Command | Description |
|---|---|
| set malwareEngine | This command now allows users to enable or disable MVX engine. |
| show malwareclientstats | The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types. |
| show malwareEngine status | This command now displays the status of the MVX engine. |
| show malwareserverstats | This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types. |
Monitoring Sensor Health
Starting with this release of 10.1, the Health Status page is designed to monitor the Sensor health and take necessary actions, if required. You can access the Health Status page from Devices → <Admin Domain Name> → Global → Sensor Health → Health Status. It provides a consolidated view of all health-related faults generated for the Sensor in Manager. You can view these faults in admin domain including those configured in the child admin domains. The Health Status page provides a cumulative view of system health, processor health, resource usage, and traffic nature of all devices configured in the Manager.
In the Health Status grid view, you can view the fault details for Overall Health, Hardware, Capacity, and Inspection elements of all configured Sensors. You can explore the summary of these parameters by clicking the hyperlink in required column.
When you double-click on a required device, the Abnormal health details of <Sensor Name> panel is displayed at the right end of the page. You can view various faults, its causes, recommended actions, and total count of same fault. You can take necessary actions for these faults by selecting Take action.
Note
This feature is not applicable for NS3x00, NS9300, and Virtual-IPS Sensors.
Device Manager support in Trellix IPS Central Manager
Starting with this release of 10.1, IPS Central Manager comes with the Device Manager page which displays all devices that are connected to each Manager configured with it, such as NS-series Sensors, M-series Sensors, Virtual IPS Sensors, and NTBA Appliances. The Device Manager grid view provides real-time visibility into the device details, that include general device information, faults status and system health, thus offering a consolidated view of all devices available on individual Managers.
To view the Device Manager page in Central Manager, navigate to Devices → Manager Management → Device Manager.