New features and changes
This section describes new features in the Trellix Email Security - Server release 10.0.1
New load balancing method for multiple next hops to help identify accepting next hop server
Record the actual IP of the next hop MTA in case of multiple next-hops when EX is configured to load balance across multiple next-hop MTAs. This is a DNS-based intelligent load balancer for next-hop MTAs.
Support QR code decoding
Enhanced detection by decoding and supported extracting URLs for analysis from QR codes present in PDF, image, HTML attachments along with inline image and HTML present in email bodies.
Support configurable MVX analysis - Force execution for selective domain or email ID
Provides the capability to configure recipient domains and recipient email addresses using CLI. It also enables users to create the policy for which they want to force the execution of attachment and URLs.
Exclude deferred queue from congestion control
CLI support has been provided to:
Include/exclude deferred queue from the congestion control check.
Configure the threshold of deferred queue for congestion control.
Modify Email subject for malicious/riskware emails
Enhanced customer notifications that allowed users to customize email subject for malicious and riskware emails.
3rd Party Feeds now support STIX 2.1, STIX 2.0 feed format
In 10.0.1, the 3rd Party feeds support is enhanced by adding capability to parse and validate STIX 2.0 , STIX 2.1 spec version JSONs along with pre-existing STIX 1.0.
New, modified, or deprecated CLI commands
New commands
Riskware quarantine handling CLIs
The new CLI now stores all the riskware emails to
/data/email-analysis/riskware-alertsdirectory whereas, earlier the emails were stored in/data/email-analysis/quarantine2directory. Now, you can also separate policies for/data/email-analysis/riskware-alertsdirectory and control it using CLIs.email-analysis riskware-alert size <size in GB>no email-analysis riskware-alert cleanup keep <no. of days>
MTA Load balancer CLIs
email-analysis mta adv-load-balancer enableno email-analysis mta adv-load-balancer enable
Exclude deferred queue from congestion control CLIs
Excludes the deferred queue from congestion control algorithm.
[no] email-analysis policy congestion deferred excludeInclude/exclude the deferred queue from the check.
email-analysis policy congestion deferred threshold <number>Configure the threshold of deferred queue.
Modify email subject for malicious/riskware emails CLIs
Support to modify the email subject when the email is riskware or malicious.
[no] email-analysis policy re-write-subject enableEnable/disable re-writing email subject for malicious and riskware emails in monitor mode and for riskware emails in block mode.
email-analysis policy re-write-subject malicious <text>Text provided will be prepended to the email subject for malicious emails in monitor mode.
email-analysis policy re-write-subject riskware <text>Text provided will be prepended to the email subject for riskware emails in monitor/block mode.
Force execution for selective domain or email ID CLIs
Provides user configurations for recipient domains and recipient email address. Creates policy for force analysis and associates policy with domain and email address. Forces execution and ignores duplicate check forURLs and attachments during analysis.
email-analysis policy user-policy <policy-name>Creates the policy with default parameters.
[no] email-analysis policy user-policy <policy-name> force-analyze enableCreates the policy with force-analyze as enabled/disabled.
no email-analysis policy user-policy <policy-name>Deletes the policy if it’s not associated with any domain or recipient-address.
no email-analysis policy user-policy <policy-name> forceDeletes the policy forcefully.
show email-analysis policy user-policyDisplays all the policies.
show email-analysis policy user-policy <policy-name>Displays specific policy.
[no] email-analysis domain <domain-name> policy <policy-name>Associates/disassociates the policy with domain.
show email-analysis domain <domain-name>Displays the policy associated with the domain.
[no] email-analysis recipient-address <recipient-address> policy <policy-name>Associates/disassociates the policy with recipient-address.
show email-analysis recipient-addressDisplay the recipient-addresses associated with the policy.
New CLI to reset all DTI services credentials
fenet dti credentials reset factory-defaultResets credentials of all the existing DTI services to factory settings.
Resolved Issues
The following issues were resolved in the Email Security - Server 10.0.1 release.
Tracking number | Summary |
|---|---|
COM-30687 | The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server. |
COM-31166 | Fixes an issue where honey credentials username was not allowing double hyphen or underscore. |
COM-31481 | Fixes an issue that, by default, upgraded all the Email Security - Server appliance applications to the high-security factory default cipher-lists. |
COM-31508 | Fixes the network connectivity issues for DUED functionality. |
COM-31649 | Fixes an issue when a submission occurs repeatedly which is flagged as a duplicate even when it is included in the allow/block list after the initial submission. |
COM-31615 | The EX appliances are not vulnerable to CVE-2023-5072. |
COM-31650 | Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details. |
EMPS-13070 | Enhanced detection by decoding. Extracting URLs from QR codes is now sent to URL Analyzer for further analysis. |
EMPS-17283 | WebUI error that occurred when an email file was deleted from the disk has been removed. |
EMPS-17309 | Fixes an issue with custom search that was not working after upgrading to Bona. |
EMPS-17350 | Fixes an issue with the received time label that was read as "Received time (UTC)" earlier. Now it reads as "Received time". UTC was removed from the label since it sets to local time when appliance timezone is changed to UTC. |
EMPS-17356 | Fixes an issue with Yara Rules displaying only 25 rules when more than 25 custom rules are installed. |
EMPS-17372 | Fixes an issue with Custom Rules detection not working on ALLOW/BLOCK as expected for non-english rules. |
EMPS-17386 | Detection Improvements: enhancements have been made to extract urls from html file. |
EMPS-17398 | Detection Improvements: SNMPD triggers failed due to DUED. This issue is resolved. |
EMPS-17401 | Enhanced safeguards by performing routine checks to kill runaway and children process. If timeouts are not honored, it causes CPU spikes. |
EMPS-17416 | Fixes the issue by updating postfix with SMTP smuggling patch. |
EMPS-17421 | Fixes the issue by refactoring code to skip mail-to addresses from being analysed. |
EMPS-17433 | An issue with Relay access getting denied and TAP Mode not working after an upgrade to Bona. |
EMPS-17456 | Introduced a CLI that enables users to change the names of subscribers when the subscribers do not prefer auto rename of invalid names. |
EMPS-17472 | Fixes an issue that shows delay status of EX FAUDE consistent across users/roles. |
WEBUI-14981 | Fixes an issue with duplicate row for last segment in the report. |
WEBUI-14882 | Fixes an issue with date range component. |
WEBUI-14371 | Fixes an issue with the popup display. The issue was resolved by overwrittting Muse component. |
Known issues
The following issues are known in the Email Security - Server 10.0.1 release.
Tracking number | Summary |
|---|---|
COM-30405 | SAML Response decoding sometimes fails with IDP. The appliance displays a "bad encoding" error when the system's IDP response contains carriage return and newline characters. |
COM-30655 | During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration. Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution. |
COM-30656 | The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list. |
COM-30659 | Alert details might be missing from the report generated during alert purging. |
COM-31165 | The GI settings API does not currently enforce a limit of 10 inputs for a field. |
EMPS-16677 | In eQ tab, "Download Email" should save as queueID of email instead as email.txt. |
EMPS-17220 | There could be websocket connection breaks between the headless chrome and python library due to issues with headless chrome. This will be reconciled automatically and connection would be reestablished. |
EMPS-17213 | On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments. |
EMPS-17272 | In downloaded report, the url field for riskware object is still showing http instead of hxxp. |
WEBUI-14371 | The View Email window in the eQuarantine tab has misalignment issues. |
WEBUI-14964 | Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI. |
WEBUI-14972 | In Settings > 3rd Party Feeds tab, the Allow option is disabled for feeds type URL. To enable allow action, you can click on other feeds type and select the URL again. |
WEBUI-14981 | Email Hourly Stat Report should display the Tot_dup in a more better way. |
WEBUI-15000 | For smartvision alerts generated earlier to 9.1.3 releases, base events details and events summary information will not be displayed in Central Management System. |
Disable SAML in a Helix environment
SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.
For more information, see the Helix Integration Guide for Trellix devices.
In the Software Requirements section, see “HelixConnect Client Software Requirements”.
In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.
Upgrade support
The Trellix Email Security - Server 10.0.0 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 10.0.1 from release 9.0.0 or later.
After an upgrade to version 10.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.
Created Log archive files will not be preserved on upgrade to 10.0.1. Please have a backup of logs before upgrade.
Important
When you upgrade an Email Security appliance to 10.0.1, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the
Email Security — Server Edition User Guide.
Note
After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".
Download the security content bundle
After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.
Downloading content from the DTI offline update portal
If you download Email Security - Server 10.0.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.
Caution
Downloading security content from a different channel will result in a loss of detection.
For details, see the Trellix DTI Offline Update Portal User Guide.
Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms
The EX 3500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)
For detailed instructions about upgrading IPMI, see the System Administration Guide.
To upgrade IPMI to version 3.11:
Note
IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.
Do not shut down or remove power from the appliance during the upgrade.
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
ipmi firmware update latestConfirm the upgrade:
hostname (config) #
show ipmi
If the upgrade fails, try the steps again.
If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:
Stop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
To upgrade the BIOS to version 1.9:
Go to CLI configuration mode.
hostname >
enablehostname #
configure terminalBegin the upgrade:
hostname (config) #
system bios firmware update latestNote
Do not shut down or remove power from the appliance during the upgrade.
Confirm the upgrade:
hostname (config) #
show system biosStop the reload process:
hostname (config) #
reload haltDisconnect all power cables for 2 minutes.
After 2 minutes, reconnect power cables and restart the appliance.
YARA rules supported versions
YARA rules support version 4.3.2.
Important
Before you upgrade an Email Security - Server appliance to the 10.0.0 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.