Trellix IPS recommends the following while performing Vulnerability Assessment:
- Always use the latest signatures available for your vulnerability assessment (VA) software. This will help ensure the assessment is accurate.
- Where possible, scan all hosts you expect Trellix IPS to protect. This will help increase the probability that a relevancy status of "Unknown" really means that the attack is not relevant.
- If the scan traffic between the Vulnerability Manager server and the hosts being scanned passes through a Sensor monitoring port, the Sensor may consider it as attack traffic and take the corresponding response action such as quarantining the Vulnerability Manager server. To prevent this:
- Create ACLs to exclude all traffic from the Vulnerability Manager server from attack inspection. For information, see Configuring ACL rules, Trellix Intrusion Prevention System Product Guide.
- If you have configured Quarantine, add the Vulnerability Manager server to the Quarantine Exceptions list. This prevents the Vulnerability Manager server being quarantined.
- Replace old reports with new reports on a routine basis (weekly or monthly). Given the frequency with which new attacks appear, reports can become obsolete quickly, and render VA integration ineffective.
- Replacing an old report with a new one might result in similar alerts having different relevance values. For example, if Trellix IPS uses an initial scanner report to analyze one alert and an updated scanner report to analyze the next, it may correctly draw different conclusions for each. To avoid confusion, consider acknowledging (or purging) all existing alerts each time you replace reports.