Integration with Multi-Vector Virtual Execution (MVX) Engine
Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.
Starting with this release of 10.1, Trellix IPS offers integration capabilities with Trellix Virtual Execution (VX) appliances which utilize Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis. MVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.
A list of Sensor CLI commands have been added to support the MVX engine integration.
The following Sensor CLI commands are added:
| Command | Description |
|---|---|
| show mvx config | This command displays the MVX configuration details |
| show mvx stats | This command displays statistics specifics to MVX engine analysis. |
| show mvx status | This command displays the connection status of the MVX engine. |
A list of Sensor CLI commands have been updated to support the MVX engine integration.
The following Sensor CLI commands are updated:
| Command | Description |
|---|---|
| clearmalwarecache | This command now allows users to clear MVX related cache entries made in the Sensor. |
| clrstat | This command now clears all the statistics counters in the Sensor including the MVX counters. |
| show malwareenginestats | This command now displays the malware engine statistics related to MVX. |
| show malwarefilestats | This command now displays the malware file statistics related to MVX. |
The following Sensor CLI commands are updated:
| Command | Description |
|---|---|
| set malwareEngine | This command now allows users to enable or disable MVX engine. |
| show malwareclientstats | The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types. |
| show malwareEngine status | This command now displays the status of the MVX engine. |
| show malwareserverstats | This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types. |
Sensor Commands
Along with MVX commands documented above, the following Sensor CLI commands are added:
| Command | Description |
|---|---|
| clear afo dst-mac | This command clears the previously configured destination MAC address on the specified port-pairs. |
| set afo port-pair and dst-mac | This command is used to configure the destination MAC address in the heartbeat packets sent by the Active Fail-Open (AFO) kit. These packets will be used by Sensor to determine the status of the AFO kit. |
| show afo status | This command displays the MAC address detected in the Heartbeat packets sent by the Active Fail-Open (AFO) kit, followed by the current AFO kit state. |