All networks working from layer 2 through layer 7 experience some amount of latency. Latency monitor provides a means to reduce latency introduced by the Sensor, when the amount of traffic seen on the network substantially exceeds the Sensor capacity. Sensor latency can be due to various factors such as the policies configured, protocols, content, applications, type of traffic flowing through the Sensor, and so on. The Inspection Options Policies configured also adds to the latency. The following features consume Sensor resources which results in latency:
HTTP Response Traffic Scanning
Traffic Inspection
Callback Activity
Advanced Malware Policies
SSL decryption
The latency can be reduced or varied, if Sensors detect the latency condition. Whenever there is a latency in the network, the Sensor performs the following functions:
Raises an alert in the Manager whenever there is a latency in processing the packets
Mitigates latency by switching to layer 2 mode
Latency monitor is available in all NS-series Sensor models.
Latency monitor feature configured monitors the time consumed for processing the packets. If the number of packets exceeds the threshold for which processing time is high, it is considered as a condition of latency. You can configure latency monitor as alert-only mode or layer 2 mode. When latency is detected, based on the configuration, an alert is raised in the Manager for the alert-only mode. If it is configured for mitigation, the latency is mitigated before an alert is raised in the Manager.
Latency monitor feature is disabled by default. The feature has to be enabled only when there is latency in the network introduced by the Sensor. If the feature is kept enabled, there is a possibility of some attacks not being detected by the Sensor.
To mitigate latency, the Sensor switches to layer 2 mode based on the sensitivity level configured. This takes less than a second after latency is detected. After latency is mitigated, the Sensor switches back to inline mode, depending on the time configured using the CLI command latency-monitor restore-inline. For example, if the latency-monitor restore-inline command is configured for 10 minutes, the Sensor tries to switch back to online mode (from layer 2) after 10 minutes.
Note
If the Sensor is not configured to return to inline mode automatically, it has to be manually restored to inline mode from layer 2 mode using the CLI command
latency-monitor restore-inline.
Trellix IPS provides latency monitoring at three different sensitivity levels. The sensitivity levels configured in latency monitor checks for latency in two different stages:
Stage 1
High sensitivity — Checks for latency in every incoming packet before processing
Medium sensitivity — Checks for latency in every alternate packet before processing
Low sensitivity — Does not check for latency
In the above scenarios, if latency is not detected, the packets are forwarded for further processing to stage 2.
Stage 2
Once latency is detected, the packets are processed through multiple phases taking optimized measures internally to handle high latency. If latency is mitigated by this process, the Sensor returns to normal processing. If latency is not mitigated, the Sensor switches to layer 2 mode if configured.
The time consumed for processing each packet is calculated when the packet is being processed by the Sensor. The calculations are based on the following parameters:
Number of packets for which the latency is high
Duration for which this latency condition persists
This duration for which the latency condition is monitored depends on the configured sensitivity level. Latency is detected based on the following sensitivity level thresholds configured:
High latency — If latency is experienced (high) for 1/6th of a second for every 50 packets
Medium latency – If latency is experienced for 2/6th of a second for every 100 packets
Low latency – If latency is experienced (persists) for 3/6th of a second for every 150 packets
When latency is detected, the Sensor switches to latency management mode trying to mitigate latency by optimizing processes. During this mode, the situation is continuously monitored to check if the latency is mitigated. Optimization of processes may include turning off the attack detection and packets being forwarded without attack detection. The Sensor switches to layer 2 mode, if enabled, when latency is not mitigated even after running the optimization processes.
The following CLI commands for Oversubscription are deprecated:
set oversubscription enableset oversubscription disableshow oversubscription status
Trellix recommends that you use latency monitoring instead.