New features
This release of the Trellix Intrusion Prevention System includes the following new feature:
Introducing Trellix Intrusion Prevention System Sensor - NS9600
This release of 11.1 introduces Trellix's next-generation IPS NS9600 Sensor model. The NS9600 Sensor operates at 20 Gbps, 40 Gbps, and 60 Gbps throughput depending on the license purchased. This release also offers the solution of stacking two NS9600 Sensors to achieve scalability. 120 Gbps throughput license is required for a NS9600 stack of 2 nodes to run.
The NS9600 Sensors are 1RU units equipped with the following components:
4 QSFP28 /QSFP+ 100/40 Gigabit Ethernet ports in built-in G0 module
Three slots for pluggable and hot swappable I/O modules:
In G1 and G2 (any combination of the interface modules can be used):
4-port 100/40 Gigabit SR MTP/MPO interface module
4-port 100/40 Gigabit SR MTP/MPO interface module with built-in fail open
4-port 40 Gigabit LR4 interface module with built-in fail open
4-port 100 Gigabit LR4 interface module with built-in fail open
4-port 100/40 Gigabit BiDi interface module with built-in fail open
Important
4-port 100/40 Gigabit with internal fail open interface modules (that is, 100/40 Gigabit SR MTP/MPO, 40 Gigabit LR4, 100 Gigabit LR4, and 100/40 Gigabit BiDi) are supported in NS9600 Sensors running on 11.1 Update 8 version or later.
Important
If you have configured 100/40 Gigabit SR MTP/MPO or BiDi with internal fail-open network interface modules with the 100 Gbps speed and you want to reconfigure the speed to 40 Gbps, you may have to click Disable and then Enable the ports once or twice and refresh the Monitoring Ports tab to bring up the ports. This also applies to 100/40 Gigabit SR MTP/MPO interface module.
In G1, G2, and G3 (any combination of the interface modules can be used):
6-port RJ45 10/1 Gigabit with internal fail-open interface module
8-port 10/1 Gigabit SM (8.5 micron) with internal fail-open interface module
8-port 10/1 Gigabit MM (50 or 62.5 micron) with internal fail-open interface module
Caution
Apart from the network interface modules mentioned above, no other interface modules are compatible with the NS9600 Sensor.
QSFP28 (MM and SM) and QSFP+ (MM and SM) transceiver modules are supported in NS9600 Sensor models.
Note
Transceiver modules are supported in the built-in G0 module only.
One console port
Two external USB ports for Storage/Rescue applications
One RJ-45 10 Gbps/1 Gbps Management port
One RJ-45 10 Gbps/1 Gbps Response port
The front and rear panel LEDs provide status information for the health of the Sensor and the activity on its ports
NS9600 licensing: In case of the NS9600 (standalone and in fail-over pair), a new license with a higher throughput is required to increase the throughput of the Sensor.
For NS9600 stack (2-node) or stacked Sensors in fail-over setup, you can combine multiple licenses of different capacity to achieve the throughput required and assign them to the stack. For example, you can import and assign any combination of licenses (20 + 40 + 60 Gbps) or, (60 + 60 Gbps) to achieve the throughput requirement of 120 Gbps. For more information, see Managing licenses in Trellix Intrusion Prevention System 11.1.x Installation Guide.
Unsupported features: Note that the following features are not supported in NS9600 Sensors:
NS9600 standalone | NS9600 stack (2-node) |
|---|---|
|
|
For more detailed information, see Trellix Intrusion Prevention System NS9600 Sensor Hardware Guide and Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements
Enhanced security measures for proxy-based SSL/TLS decryption
Starting with this release of 11.1, enhanced security measures have been implemented to bolster both inbound and outbound proxy-based SSL/TLS decryption. The new features include the following:
Proxy-based SSL decryption is supported on NS9600 (standalone and stack), NS9500 (standalone), NS7600, NS7500, and NS3600 Sensors.
Support for jumbo frame parsing.
SSL decryption exclusions apply to both inbound and outbound SSL decryption.
Support for 4096-bit RSA and up to 521-bit ECDSA certificates.
HTTP2 traffic inspection with TLS is supported.
Note
The re-signing CA certificate must be created for server authentication and added to the browser as a trusted authority without purpose limitations.
The "Outbound" Block Flow configuration will apply to "Inbound" and may block inbound flow if an internal web server uses expired/untrusted CA certificates. Thus, an exception rule with the specific internal web server IP should be added to allow inbound flow without decryption when block flow is configured.
Once Inbound proxy is enabled, all Inbound traffic will be decrypted; However, it is recommended to create a proxy rule for Inbound SSL decryption.
License requirements for proxy-based SSL decryption
Model | System license | SSL license | Virtual license |
|---|---|---|---|
NS9600 (standalone and stack), NS7600, and NS3600 Sensors | Requires a separate system license for each throughput per device. | Requires one SSL license per device, regardless of throughput. | NA |
NS9500 (standalone) and NS7500 Sensors | Requires a separate system license for each throughput per device. | Requires an SSL license based on the device system license. | NA |
A new command show ssl proxy is included to support the SSL enhancements.
For more information, see Managing licenses for proxy based SSL decryption and SSL decryption support for NS-series and Virtual IPS Sensors in Trellix Intrusion Prevention System 11.1.x Product Guide.
Support for SMB and DCERPC layer 7 data collection and SmartVision attack related L7 metadata and alerts export to Trellix Network Investigator
Starting with this release of 11.1, Trellix IPS supports collecting layer 7 data for SMB (SMBv1 and SMBv2) and DCERPC protocols (over TCP). It also exports the SmartVision attack related L7 metadata related to these protocols from IPS Sensors and alerts from IPS Manager, when the integration between Trellix IPS and Trellix NI is enabled. The SmartVision alerts and L7 metadata collected for SMB and DCERPC protocol traffic and exported to NI further enhances its SmartVision capabilities for detecting malicious activities, such as malware lateral movement, data exfiltration, and beaconing.
Consider the following if you want to enable the detection and export of SmartVision attacks related L7 metadata and alerts related to SMB and DCERPC protocols to NI:
You need to use Manager and Sensor(s) running on 11.1 Update 8 and later, along with a compatible signature set (11.10.28.4 and above) that includes SMB and DCERPC related attack signatures.
Manager running on 11.1 Update 8 and later includes additional L7 data fields for SMB (under the netbios-ss section) and DCERPC protocols in the Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Advanced → L7 Data Collection page. These L7 fields related to SMB and DCERPC protocols are applicable only for Sensors running on 11.1 Update 8 version or later and can be customized accordingly.
Note
DCERPC L7 data collection is supported over TCP only.
When Trellix IPS and Trellix NI is integrated, Manager sends all relevant alert data (including SmartVision attacks) to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later send only SmartVision attack-related L7 metadata to NI.
For more information on layer 7 data collection, see Enable Layer 7 Data Collection for an interface or sub-interface in Trellix Intrusion Prevention System 11.1.x Product Guide.
For more information on SmartVision attacks, see Harnessing SmartVision attacks for effective threat detection and response in Trellix Intrusion Prevention System 11.1.x Product Guide.
Database pruning enhancements in the Manager
With this release of 11.1, a few enhancements have been made in the Trellix IPS Manager to speed up and optimize the task of database pruning. From this release onwards, the Manager creates and maintains a separate (active) partition for iv_alert_data, iv_alert, and iv_packetlog tables that stores alert and packet log data based on user configuration (that is, number of days or number of alerts configured). When the alert pruning activity is triggered (as per the configuration performed on Manager → <Admin Domain Name> → Maintenance → database Pruning → Alert Pruning page), all data is deleted at once, thus speeding up the database pruning process.
Support for script files for advanced malware detection
Starting with this release of 11.1, Trellix IPS supports script files to be scanned while configuring an advanced malware policy. It is available for configuration under the File Scanning Options section in the Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware page. To know the list of advanced malware file extensions supported by signature sets, refer to KB96988.
After configuring the advanced malware policy, you need to assign it to the required Sensor monitoring resources such as ports, interfaces, and sub-interfaces. You must do a configuration and signature set update for any changes in the policy to take effect.
For more information, see Add an Advanced Malware policy in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements around SSL key push failure in the Manager
Previously, the reason for SSL key push failure was undetermined. With this release of 11.1, a thorough analysis revealed that the failures were due to missing or corrupted certificates. Additionally, SSL key push would fail when a new shared secret key was issued. This enhancement provides a clear resolution in the Manager, displaying the reason for the SSL key push failure.
For more information, see Deploy pending changes to a device in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements in the NS3600 Sensor
Starting with this release of 11.1, the NS3600 Sensor includes enhancements to display the temperature status of the power supply unit.
Sample output for NS3600 Sensor with chassis version 0.1:
intruShell@NS3600> show powersupply
==== PSU Status ====
PSU Model: FSP300-50RFB
PSU Firmware: 001
Vin: 230.00 V
Vout: 12.14 V
Iout: 5.64 A
Pin: 92.00 W
Pout: 83.00 W
Ambient Temp: 30.00 C
PSU1 Temp: 33.00 C
PSU2 Temp: 25.00 C
Fan Speed: 3148 rpm
Status: OK
Vout Status: OK
Iout Status: OK
Temp Status: OK
Power Supply PRESENT health = OKFor more information, see show powersupply in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhanced support for latency troubleshooting
With this release of 11.1, Trellix IPS introduces a significant improvement to latency troubleshooting, providing a streamlined solution for diagnosing performance-related issues. It addresses common latency-related problems such as slow application response, packet drops, network slowdowns, and delayed file transfers/database operations.
You can use the latency-troubleshooting command to add, delete, list the configured commands, modify the frequency of execution, and collect logs from the trace in debug mode.
The following commands are available:
Parameter | Syntax | Description | |
|---|---|---|---|
start |
| Starts latency troubleshooting | |
status |
| Check the current status of latency troubleshooting | |
stop |
| Stops latency troubleshooting | |
command | add |
| Add a command to the list |
delete |
| Delete a command from the list | |
list |
| Lists all added commands | |
run |
| Run latency troubleshooting once | |
set | frequency |
| Modify the frequency of run |
rollover_limit |
| Sets the number of logs to retain | |
For more information, see latency-troubleshooting in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
Navigation Path | Prior to 11.1.19.61 | 11.1.19.61 and later |
|---|---|---|
Devices → <Admin Domain Name> → Manager Management | The Synchronize Policies menu Policy tab shows the synchronization status for all the Managers added to your Central Manager. | The Policy tab from Devices → <Admin Domain Name> → Manager Management → Synchronization shows the synchronization status for all the Managers added to your Central Manager. |
Devices → <Admin Domain Name> → Manager Management | The Synchronize Faults menu from Devices → <Admin Domain Name> → Manager Management → Synchronize Faults allows automatic synchronization of faults between the Managers and the Central Manager. | The Faults tab from Devices → <Admin Domain Name> → Manager Management → Synchronization allows automatic synchronization of faults between the Managers and the Central Manager. |
Manager → <Admin Domain Name> → Users and Roles → Roles | On clicking
| On clicking
|
Manager → <Admin Domain Name> → Setup → Central Manager |
|
|
Manager → <Admin Domain Name> → Setup → Proxy Server | One of the fields available is User Name. | The field is renamed to Login Name. |
Manager → <Admin Domain Name> → Reporting → Preferences | The Preferences page includes the following:
| The Preferences page includes the following:
|
Manager → <Admin Domain Name> → Reporting → Configuration Reports | During the configuration of any report:
| During the configuration of any report:
|
Manager → <Admin Domain Name> → Integration → TLC |
|
|
Manager → <Admin Domain Name> → Integration → HP Network Automation | A note regarding customized message appears in the Message Preference field. | A tooltip regarding customized message appears in the Message Preference field. |
Apart from the terminology updates mentioned above, this release of Manager (11.1.19.61 and later) displays the following changes:
The following pages have been removed, and consequently, all associated UI configuration options, buttons, and related dashboards have been removed from the other pages in the Manager:
Network Forensics page (in Analysis → Network Forensics)
Endpoint Executables page (in Analysis → Endpoint Executables)
NTBA Quarantine Events page (in Manager → <Admin Domain Name> → Setup → Notification)
Related dashboards that have been removed: Top Applications (NTBA), Top Destinations (NTBA), Top Endpoint Executables (NTBA), Top Files (NTBA), Top Sources (NTBA), and Top URLs (NTBA).
The Reconnaissance Policy configuration report has been removed from Manager → <Admin Domain Name> → Reporting → Configuration Reports page.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
Apache Solr upgrade
Starting with this release, the IPS Manager uses Apache Solr version 8.11.4 that includes additional security against new vulnerabilities and bug fixes.
JDK upgrade
Starting with this release of 11.1, the IPS Manager uses JDK version 1.8u432-b06 which includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, the Tomcat server used in the Manager is upgraded to version 9.0.102. This server update provides a collection of security fixes.
.png)
.png)
.png)
.png)
.png)