Rebranding Updates
This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Virtual Intrusion Prevention System (formerly, McAfee Virtual Network Security Platform) as usual.
You will notice the following changes:
Product Name - Virtual Network Security Platform is renamed to Trellix Virtual Intrusion Prevention System. All features and options prefixed with product name are renamed with the new product name.
FQDN - The fully qualified domain names (FQDNs) to access the resources related to Trellix and Skyhigh Security products have been updated. So, users are recommended to update the Destination URLs in their Firewall configuration to ensure uninterrupted communication. For more information on the updated destination URLs, refer to the section Set the desktop firewall in Trellix Intrusion Prevention System 10.1.10 Product Guide.
Note
The Trellix IPS products are in the process of rebranding from McAfee. So, users might be viewing mixed branding elements at a few places across the products and documentation.
Note
Rebranding changes are not applicable for products (both hardware and software) that have reached End of Sale and currently under support period threshold. For more information, see KB96058.
New features
This release of Trellix Virtual IPS includes the following new features:
Integration with Multi-Vector Virtual Execution (MVX) Engine
Multi-Vector Virtual Execution (MVX) Engine is a signature-less, dynamic analysis engine that inspects suspicious network traffic to identify attacks that evade traditional signature-based and policy-based defenses. The MVX engine detects zero-day, multiflow, and other evasive attacks with dynamic, signature-less analysis in a safe, virtual environment. It stops infection and compromise phases of the cyberattack kill chain by identifying never-before-seen exploits and malware.
Starting with this release of 10.1, Trellix vIPS offers integration capabilities with Trellix Virtual Execution (VX) appliances which utilize Multi-Vector Virtual Execution (MVX) engine's technology to perform malware analysis. MVX serves as an additional malware engine for all the supported file types in the Advanced Malware Policies. You can select this engine along with any of the other malware engines.
To enable integration with MVX:
At Global level: Devices → <Admin Domain Name> → Global → IPS Device Settings → MVX Integration.
At Device level: Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → MVX Integration.
To select MVX malware engine in an Advanced Malware policy, go to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware. You can enable inspection by MVX for all supported file types that is, Executables, MS Office Files, PDF Files, Compressed Files, Android Application Package, Java Archive, and Flash Files.
Use the Manager to view the following information with respect to files submitted for malware analysis to MVX Engine:
Dashboard tab: Use the Top Malware Files monitor to view the blocked and unblocked detections together or filter them out separately. Additionally, you can filter data based on the confidence level of the detection as well.
Analysis tab: The following enhancements are supported in the Malware Files page:
The overall malware confidence for a file is derived based on the results from MVX and any other malware engines configured.
If applicable, you can view the MVX‑specific details for a particular type. This is similar to how you view the details for other engines.
In the Malware Files page, click
next to the confidence level of MVX to view the results reported by MVX. You can also download a file that contains all the reports for the malware from MVX. This file contains detailed analysis result data and can be opened with any text editor.
Devices tab: You can view the statistics of the malware detected for a given device under Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics → Advanced Malware Analysis tab. The By Malware Engine option displays the malware detected data based on the malware engines configured for the device. This includes the malware detected data associated with the MVX engine.
A list of Sensor CLI commands have been added to support the MVX engine integration.
The following Sensor CLI commands are added:
Normal Mode | |
Command | Description |
|---|---|
show mvx config | This command displays the MVX configuration details. |
show mvx stats | This command displays statistics specifics to MVX engine analysis. |
show mvx status | This command displays the connection status of the MVX engine. |
A list of Sensor CLI commands have been updated to support the MVX engine integration.
The following Sensor CLI commands are updated:
Normal Mode | |
Command | Description |
|---|---|
clearmalwarecache | This command now allows users to clear MVX related cache entries made in the Sensor. |
clrstat | This command now clears all the statistics counters in the Sensor including the MVX counters. |
show malwareenginestats | This command now displays the malware engine statistics related to MVX. |
show malwarefilestats | This command now displays the malware file statistics related to MVX. |
The following Sensor CLI commands are updated:
Debug Mode | |
Command | Description |
|---|---|
set malwareEngine | This command now allows users to enable or disable MVX engine. |
show malwareclientstats | The command now displays the malware client statistics in the scan engines including MVX engine for all supported file types. |
show malwareEngine status | This command now displays the status of the MVX engine. |
show malwareserverstats | This command now displays the malware server statistics in all scan engines including MVX engine for all supported file types. |
For more information on MVX integration and malware scanning using MVX, refer to Trellix Intrusion Prevention System 10.1.10 Integration Guide and Trellix Intrusion Prevention System 10.1.10 Product Guide.
Device Manager support in Trellix IPS Central Manager
Starting with this release of 10.1, IPS Central Manager comes with the Device Manager page which displays all devices that are connected to each Manager configured with it, such as NS-series Sensors, M-series Sensors, Virtual IPS Sensors, and NTBA Appliances. The Device Manager grid view provides real-time visibility into the device details, that include general device information, faults status and system health, thus offering a consolidated view of all devices available on individual Managers.
To view the Device Manager page in Central Manager, navigate to Devices → Manager Management → Device Manager. For more information, refer Device Manager in Trellix IPS Central Manager in Trellix Intrusion Prevention System 10.1.10 Product Guide.
Enhancements
This release of Trellix Intrusion Prevention System includes the following enhancements:
Support for Extended Master Secret (EMS) Extension
Starting with this release, the Sensor supports Extended Master Secret (EMS) Extension for SSL decryption as per RFC 7627.
Note
EMS Extension is currently supported for Known-key and Agent based decryption methods under Inbound SSL Decryption.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MariaDB upgrade
Starting with this release of 10.1, the IPS Manager uses MariaDB version 10.5.16 that includes additional security against new vulnerabilities and bug fixes.
JDK upgrade
Starting with this release of 10.1, the IPS Manager uses JDK version 1.8u342 that includes additional security against new vulnerabilities.
Apache Log4j library upgrade
Starting with this release of 10.1, the IPS manager uses Apache Log4j version 2.17.1 that includes additional security and bug fixes.