The Manager/Central Manager is enhanced to reduce the compilation and deployment time of the signature set. The compilation time is the duration required by the Manager to create the signature set file to be deployed to the Sensor. The deployment time is the sum of compilation time - the time required to transfer signature set file from the Manager to the Sensor and the time required to apply the signature set file to the Sensor. The reduction in signature set compile/deploy time reduces the duration of signature set processes in the Manager.
Note
To achieve faster signature set compilation/deployment, the Sensor software version must be running on software version 10.1 or above.
The following table provides the test conditions for the Signature set compilation/deployment enhancement:
For example, in a Windows 2016 Manager server with 8 CPU cores, 500 GB HDD, and 32 GB RAM, the time consumed for signature set based processes before and after the signature set deploy and compile enhancement are as follows:
| Task
Manager server specifications |
Policies |
Sensor models |
|---|---|---|
|
VM-based Windows 2016 R2 32GB RAM 8 x 2.6 GHz CPU cores 500GB Hard Disk Drive 16 GB allocated for JVM (by default) |
IPS Policy: Default Testing with 1000 UDS and Default malware policy Advanced Malware Policy: All Malware Engines Enabled |
NS-series Sensors Virtual IPS Sensors |
|
Linux based Manager server appliance 64GB RAM 20 CPU cores 1 TB Hard Disk Drive 16 GB allocated for JVM (by default) |
The following table provides the test results for the Signature set compilation/deployment enhancement:
| Task | Reduction in time required to complete the task |
|---|---|
| Manager Installation/Upgrade/Restart |
70-80 % |
| Manual import of a signature set |
50-60 % |
| (Optional) Test compilation of one snort or UDS attacks |
70-80 % |
| (Optional) Saving one thousand snort or UDS attacks |
70-80 % |
| Deploy the signature set to the Sensors |
50-60 % |
| Failover pair Sensor software upgrade using the Manager GUI |
25-35 % |
For example, consider you are deploying or upgrading the Manager, followed by a manual signature set upgrade, and deployment of Sensor software and signature set to the Sensors. The total downtime required for the completion of these tasks is reduced proportionally according to the percentage in the above table as applicable in your network. If you have any user-defined or snort attacks configured, the time required to Test Compile or Save these attacks is also reduced considerably.
The Sigperf.log file available under the System files tab in the Manager → <Admin Domain Name> → Troubleshooting → Logs page provides a detailed log regarding the signature set process in the Manager with the time stamp.
Note
The above ranges are obtained from the Trellix test environment and may differ from your network depending on parameters like the internet speed, geo-location, Sensor models, etc.