Relevance analysis involves the analysis of the vulnerability relevance of real-time alerts using the vulnerability data imported into the Manager database. The imported vulnerability data can be from Vulnerability Manager or other supported vulnerability scanners such as Nessus.
Vulnerability assessment reports from the scanners contain vulnerabilities detected in a specific host(s) in the network. For example, a vulnerability assessment report will display that the host 10.1.1.x is vulnerable to buffer overflow attack, along with the CVE ID /BugTraq ID of the attack. Manager uses the imported scan report to determine whether the host identified is vulnerable to that particular attack.
The attack cache in Manager stores the CVE ID of the attacks detected by the Sensor. In the case of relevance analysis, the CVE ID of the vulnerability in the imported report is compared to the CVE ID in the attack cache in Manager. If a matching record is found, the corresponding alert is marked as Relevant. This record is used by the alert correlation module during alert processing to check for the relevancy type, and also used to update the Relevance field in the Attack Log.
The status of relevance analysis can be viewed in the Attack Log page. The Relevance column is displayed when it is selected from the Columns drop-down list.
You can also view the alerts sorted by Relevance category in the Attack Log page. For more information, see the section Attack Log in the Trellix Intrusion Prevention System Product Guide.
Marking alerts from vulnerable hosts as relevant helps the network administrator to easily view and sort alerts by relative relevance.
The relevancy analysis lookup is done for real-time alerts by either importing the vulnerability data from Vulnerability Manager database, running an on demand scan, or manual import. You can opt to configure the lookup for relevancy from Vulnerability Manager database instead of the relevancy cache in the Manager.