Trellix appliances automatically push anonymous data to and pull security information from the Dynamic Threat Intelligence (DTI) cloud.
Note
All Trellix devices upload information using a secure (HTTPS) connection to
cloud.fireeye.com. By default, managed appliances communicate with the DTI cloud through the managing Central Management System appliance.
No customer-specific or proprietary information is exchanged. Two types of data are shared: real-time system statistics and threat intelligence information.
For information about the licenses required to share this data, see About support and content license sharing combinations.
Real-Time statistics
The following real-time statistics are anonymized and uploaded to the DTI cloud:
License information―Status of the licenses on the device.
Appliance health―Environmental information relating to all components such as fans and hard disk drive with System Activity Report data.
Traffic Measurements―Traffic throughput statistics and capacity monitoring.
Statistics of critical sub-systems capacity―Interface status, packet counts, number of flows, broken or asymmetric flows, binaries, packet loss, protocol-based stats, memory usage, and Kernel-level information.
Threat intelligence information
The following threat intelligence information is shared with the DTI cloud:
Timestamp―The timestamp can be used as a reference for other events and can provide additional information about the attack and the methods used.
URL―List of malicious URLs contacted during traffic analysis in the Virtual execution (VX) engine.
MD5―An MD5 hash is generated for information such as IP addresses or MAC addresses. The MD5 hash enables Trellix to maintain the data for analysis without the data being traceable or recognizable in its original form. The information is important for correlation of multiple threats on a common host.
File types―File types used in the course of an attack. Trellix determines the entry point, the payload, and the methods used.
Information that Is not uploaded to the DTI cloud
The following information is NOT uploaded to the DTI cloud:
No customer-specific information
No proprietary information
No packet captures
Benefits of sharing data with the DTI cloud
Uploading data to the DTI cloud provides the following benefits:
Participating Trellix appliances share malware intelligence in real time.
The Trellix Customer Support team can provide you with proactive operational monitoring and support. This monitoring and support includes the identification of targeted attacks.
The Trellix Research Labs team processes the collection of shared data to extract the malicious content. Updated security content, some of which is developed using anonymous customer data, is included in the security content delivered to the DTI cloud for distribution to licensed Trellix appliances and compute nodes.
The Trellix DTI cloud itself employs technology to detect zero-day callbacks.
Note
You are not required to upload data in order to receive any benefits of the DTI cloud. Your EX appliance can download and install updated security content, even if it does not upload data.