Currently, users face several challenges when securing a network. The more diverse your network, the larger the operational difficulties, and the harder it is to ensure that your security system is aware of the most recent detections or risks prevalent on the network. Majority of the security administrators today face these challenges.
Cost of distributing DAT files across all endpoints in the network
Inability to customize black, white, and gray policies for your network
Impact of security products on network performance and system resources
Need for proactive protection from zero-day malware using reputations, prevalence, and flexible policies
These difficulties are a result of several devices in the network and the addition of new security systems to address different threats. Trellix IPS protects against threats orchestrated by several file types. To be able to achieve a security framework in which more security systems are able to share security awareness and provide adaptive security, you must have a medium that addresses such communication with ease. Trellix DXL is a bidirectional communications framework that enables security intelligence and adaptive security. Threat Intelligence Exchange uses Trellix DXL that serves as a local repository of file reputations.
Benefits of integrating with Threat Intelligence Exchange and Trellix DXL
As a product, Threat Intelligence Exchange has been built to offer you the following benefits:
Comprehensive threat intelligence: Security administrators are able to send file hashes of suspicious files to Threat Intelligence Exchange. Threat Intelligence Exchange uses threat intelligence from global data sources, such as Global Threat Intelligence, with local threat intelligence provided by real-time, and historical event data coming from endpoints, gateways, and other security components.
Immediate visibility into the presence of advanced targeted attacks: When file reputation of a file is found as malicious after scanning through a security component like Intelligent Sandbox, you are able to communicate this information through Trellix DXL and dynamically contribute to Threat Intelligence Exchange. Shared insights provide deeper awareness of threats targeting an organization. Attacks are discovered through the endpoints, gateways, and other security components that act in unison.
Proactive threat protection: Threat information gathered through endpoints and gateways can be propagated quickly through Trellix DXL, ensuring all integrated security products proactively immunize against newly detected threats.
Lowered cost of ownership: While improving security, the cost of ownership is lowered by extending existing security detection, prevention, and analytic technology investments to protect your organization as soon as a threat is revealed.
Important terminologies and components
The integration between Trellix IPS, Trellix DXL, and Threat Intelligence Exchange comprises several components. These components and their brief descriptions are listed.
Sensor – Any NS-series or Virtual IPS Sensor.
Threat Intelligence Exchange server – It is a repository of file reputation details which security products across the network access. By providing file reputation, it enables a security administrator to take corrective action.
ePO - On-prem – A management console for endpoints across the network. The Sensor is configured as an endpoint on the network.
Trellix Agent – A management infrastructure extension which is loaded on an endpoint. An endpoint loaded with Trellix Agent is known as a managed endpoint. In the context of this integration, ePO - On-prem considers the Sensor as a managed endpoint.
Trellix DXL (DXL) – DXL is a real-time, bidirectional, communications infrastructure which provides the framework that enables context (situational awareness, commands, events, etc.) to be shared between different Trellix products. It is also an adaptive security system of interconnected services that communicate and share information to make real-time, accurate security decisions by individual security products, and as a collective solution. Network, endpoint, database, application, and other security solutions are meant to use DXL to operate as one synchronized, real-time, context aware, and adaptive security system.
DXL broker – A network of DXL brokers (brokers) make up the DXL framework. Brokers act as liaisons between the Sensor and the Threat Intelligence Exchange server. In general, they are responsible for routing messages efficiently from senders to receivers. When the Threat Intelligence Exchange server and DXL brokers are set up, the administrator is prompted for ePO - On-prem credentials. When the administrator provides these credentials, the broker registers itself with ePO - On-prem. In this way, the ePO - On-prem server is aware of every DXL broker in the network.
DXL client – A client that is loaded on the Sensor by bundling with Trellix Agent. The Sensor communicates to the DXL framework through the DXL client which consists of broker IP addresses. ePO - On-prem considers the Sensor an endpoint. The connection between the DXL client and DXL brokers is a persistent SSL connection, implying that communication between the Sensor and the DXL framework is always open and secure with no time wasted to establish or end a connection.