Email Security - Server (EX) 10.0.1 Release Notes

Prev Next

New features and changes

This section describes new features in the Trellix Email Security - Server release 10.0.1

  • New load balancing method for multiple next hops to help identify accepting next hop server

    Record the actual IP of the next hop MTA in case of multiple next-hops when EX is configured to load balance across multiple next-hop MTAs. This is a DNS-based intelligent load balancer for next-hop MTAs.

  • Support QR code decoding

    Enhanced detection by decoding and supported extracting URLs for analysis from QR codes present in PDF, image, HTML attachments along with inline image and HTML present in email bodies.

  • Support configurable MVX analysis - Force execution for selective domain or email ID

    Provides the capability to configure recipient domains and recipient email addresses using CLI. It also enables users to create the policy for which they want to force the execution of attachment and URLs.

  • Exclude deferred queue from congestion control

    CLI support has been provided to:

    • Include/exclude deferred queue from the congestion control check.

    • Configure the threshold of deferred queue for congestion control.

  • Modify Email subject for malicious/riskware emails

    Enhanced customer notifications that allowed users to customize email subject for malicious and riskware emails.

  • 3rd Party Feeds now support STIX 2.1, STIX 2.0 feed format

    In 10.0.1, the 3rd Party feeds support is enhanced by adding capability to parse and validate STIX 2.0 , STIX 2.1 spec version JSONs along with pre-existing STIX 1.0.

New, modified, or deprecated CLI commands

New commands

  • Riskware quarantine handling CLIs

    The new CLI now stores all the riskware emails to /data/email-analysis/riskware-alerts directory whereas, earlier the emails were stored in /data/email-analysis/quarantine2 directory. Now, you can also separate policies for /data/email-analysis/riskware-alerts directory and control it using CLIs.

    • email-analysis riskware-alert size <size in GB>

    • no email-analysis riskware-alert cleanup keep <no. of days>

  • MTA Load balancer CLIs

    • email-analysis mta adv-load-balancer enable

    • no email-analysis mta adv-load-balancer enable

  • Exclude deferred queue from congestion control CLIs

    Excludes the deferred queue from congestion control algorithm.

    • [no] email-analysis policy congestion deferred exclude

      Include/exclude the deferred queue from the check.

    • email-analysis policy congestion deferred threshold <number>

      Configure the threshold of deferred queue.

  • Modify email subject for malicious/riskware emails CLIs

    Support to modify the email subject when the email is riskware or malicious.

    • [no] email-analysis policy re-write-subject enable

      Enable/disable re-writing email subject for malicious and riskware emails in monitor mode and for riskware emails in block mode.

    • email-analysis policy re-write-subject malicious <text>

      Text provided will be prepended to the email subject for malicious emails in monitor mode.

    • email-analysis policy re-write-subject riskware <text>

      Text provided will be prepended to the email subject for riskware emails in monitor/block mode.

  • Force execution for selective domain or email ID CLIs

    Provides user configurations for recipient domains and recipient email address. Creates policy for force analysis and associates policy with domain and email address. Forces execution and ignores duplicate check forURLs and attachments during analysis.

    • email-analysis policy user-policy <policy-name>

      Creates the policy with default parameters.

    • [no] email-analysis policy user-policy <policy-name> force-analyze enable

      Creates the policy with force-analyze as enabled/disabled.

    • no email-analysis policy user-policy <policy-name>

      Deletes the policy if it’s not associated with any domain or recipient-address.

    • no email-analysis policy user-policy <policy-name> force

      Deletes the policy forcefully.

    • show email-analysis policy user-policy

      Displays all the policies.

    • show email-analysis policy user-policy <policy-name>

      Displays specific policy.

    • [no] email-analysis domain <domain-name> policy <policy-name>

      Associates/disassociates the policy with domain.

    • show email-analysis domain <domain-name>

      Displays the policy associated with the domain.

    • [no] email-analysis recipient-address <recipient-address> policy <policy-name>

      Associates/disassociates the policy with recipient-address.

    • show email-analysis recipient-address

      Display the recipient-addresses associated with the policy.

  • New CLI to reset all DTI services credentials

    • fenet dti credentials reset factory-default

      Resets credentials of all the existing DTI services to factory settings.

Resolved Issues

The following issues were resolved in the Email Security - Server 10.0.1 release.

Tracking number

Summary

COM-30687

The 10.0.1 appliance has upgraded Apache httpd to 2.4.56 to address a known vulnerability (CVE-2022-36760) for products including Malware Analysis, Central Management SystemEmail Security — Server, File Protect, Network Security, and Intelligent Virtual Execution - Server.

COM-31166

Fixes an issue where honey credentials username was not allowing double hyphen or underscore.

COM-31481

Fixes an issue that, by default, upgraded all the Email Security - Server appliance applications to the high-security factory default cipher-lists.

COM-31508

Fixes the network connectivity issues for DUED functionality.

COM-31649

Fixes an issue when a submission occurs repeatedly which is flagged as a duplicate even when it is included in the allow/block list after the initial submission.

COM-31615

The EX appliances are not vulnerable to CVE-2023-5072.

COM-31650

Fixes an issue that prevented the "show alerts type all detail concise timeframe <>" CLI from displaying alert details.

EMPS-13070

Enhanced detection by decoding. Extracting URLs from QR codes is now sent to URL Analyzer for further analysis.

EMPS-17283

WebUI error that occurred when an email file was deleted from the disk has been removed.

EMPS-17309

Fixes an issue with custom search that was not working after upgrading to Bona.

EMPS-17350

Fixes an issue with the received time label that was read as "Received time (UTC)" earlier. Now it reads as "Received time". UTC was removed from the label since it sets to local time when appliance timezone is changed to UTC.

EMPS-17356

Fixes an issue with Yara Rules displaying only 25 rules when more than 25 custom rules are installed.

EMPS-17372

Fixes an issue with Custom Rules detection not working on ALLOW/BLOCK as expected for non-english rules.

EMPS-17386

Detection Improvements: enhancements have been made to extract urls from html file.

EMPS-17398

Detection Improvements: SNMPD triggers failed due to DUED. This issue is resolved.

EMPS-17401

Enhanced safeguards by performing routine checks to kill runaway and children process. If timeouts are not honored, it causes CPU spikes.

EMPS-17416

Fixes the issue by updating postfix with SMTP smuggling patch.

EMPS-17421

Fixes the issue by refactoring code to skip mail-to addresses from being analysed.

EMPS-17433

An issue with Relay access getting denied and TAP Mode not working after an upgrade to Bona.

EMPS-17456

Introduced a CLI that enables users to change the names of subscribers when the subscribers do not prefer auto rename of invalid names.

EMPS-17472

Fixes an issue that shows delay status of EX FAUDE consistent across users/roles.

WEBUI-14981

Fixes an issue with duplicate row for last segment in the report.

WEBUI-14882

Fixes an issue with date range component.

WEBUI-14371

Fixes an issue with the popup display. The issue was resolved by overwrittting Muse component.

Known issues

The following issues are known in the Email Security - Server 10.0.1 release.

Tracking number

Summary

COM-30405

SAML Response decoding sometimes fails with IDP.

The appliance displays a "bad encoding" error when the system's IDP response contains carriage return and newline characters.

COM-30655

During the concurrent execution of the alert purge, database backup operations exhibit prolonged duration.

Workaround: Stagger the scheduling of database backup and alert purge processes to avoid simultaneous execution.

COM-30656

The negation symbol "!" is not functioning as expected when placed before the hostname or username in the deny user list.

COM-30659

Alert details might be missing from the report generated during alert purging.

COM-31165

The GI settings API does not currently enforce a limit of 10 inputs for a field.

EMPS-16677

In eQ tab, "Download Email" should save as queueID of email instead as email.txt.

EMPS-17220

There could be websocket connection breaks between the headless chrome and python library due to issues with headless chrome. This will be reconciled automatically and connection would be reestablished.

EMPS-17213

On upgrading to 11.0.0, Alert summary count and redirection counts are not consistent for Total Malicious Emails, Malicious URLs, and Malicious Attachments.

EMPS-17272

In downloaded report, the url field for riskware object is still showing http instead of hxxp.

WEBUI-14371

The View Email window in the eQuarantine tab has misalignment issues.

WEBUI-14964

Third-party feeds permit the upload of arbitrary files with STIX type from both the UI and WSAPI.

WEBUI-14972

In Settings > 3rd Party Feeds tab, the Allow option is disabled for feeds type URL. To enable allow action, you can click on other feeds type and select the URL again.

WEBUI-14981

Email Hourly Stat Report should display the Tot_dup in a more better way.

WEBUI-15000

For smartvision alerts generated earlier to 9.1.3 releases, base events details and events summary information will not be displayed in Central Management System.

Disable SAML in a Helix environment

SAML and HelixConnect are mutually exclusive. If the HelixConnect client is enabled on the Email Security - Server appliance, you must disable SAML authentication and authorization. Otherwise, the appliance will not come up after a system reboot.

For more information, see the Helix Integration Guide for Trellix devices.

  • In the Software Requirements section, see “HelixConnect Client Software Requirements”.

  • In the HelixConnect Troubleshooting section, see “Disabling SAML Authentication and Authorization”.

Upgrade support

The Trellix Email Security - Server 10.0.0 release requires a reboot for the update to take effect. You can upgrade your EX appliance to 10.0.1 from release 9.0.0 or later.

After an upgrade to version 10.0.1, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

Created Log archive files will not be preserved on upgrade to 10.0.1. Please have a backup of logs before upgrade.

Important

When you upgrade an Email Security appliance to 10.0.1, FireEye Advanced URL Defense Engine (FAUDE) and email feature extraction are enabled, even if they were previously disabled. See "Enabling or Disabling Advanced URL Defense" and "Enabling or Disabling Email Feature Extraction Using the CLI" in the

Email Security — Server Edition User Guide.

Note

After an upgrade to version 10.0.1, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, "Download the security content bundle".

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 10.0.4.

Downloading content from the DTI offline update portal

If you download Email Security - Server 10.0.0 security content from the DTI Offline Update Portal, use the SCNET-8.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

Upgrading IPMI 3.11 and BIOS 1.9 firmware for specific platforms

The EX 3500 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. (COM-21016, COM-25601)

For detailed instructions about upgrading IPMI, see the System Administration Guide.

To upgrade IPMI to version 3.11:

Note

IPMI network and password settings revert to factory defaults after this upgrade, and IPMI logs are deleted. Make a note of your settings and back up your IPMI logs.

Do not shut down or remove power from the appliance during the upgrade.

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # ipmi firmware update latest

  3. Confirm the upgrade:

    hostname (config) # show ipmi

If the upgrade fails, try the steps again.

If IPMI functions are not fully restored, perform a full power cycle (cold shutdown) on the appliance:

  1. Stop the reload process:

    hostname (config) # reload halt

  2. Disconnect all power cables for 2 minutes.

  3. After 2 minutes, reconnect power cables and restart the appliance.

To upgrade the BIOS to version 1.9:

  1. Go to CLI configuration mode.

    hostname > enable

    hostname # configure terminal

  2. Begin the upgrade:

    hostname (config) # system bios firmware update latest

    Note

    Do not shut down or remove power from the appliance during the upgrade.

  3. Confirm the upgrade:

    hostname (config) # show system bios

  4. Stop the reload process:

    hostname (config) # reload halt

  5. Disconnect all power cables for 2 minutes.

  6. After 2 minutes, reconnect power cables and restart the appliance.

YARA rules supported versions

YARA rules support version 4.3.2.

Important

Before you upgrade an Email Security - Server appliance to the 10.0.0 release, modify any custom YARA rules to YARA 4.3.2. For details about YARA 4.3.2, see YARA's Documentation, Release 4.3.2 by Victor Alvarez.