TIE Reputation check for email attachments

Prev Next

TSME now provides additional threat detection capability by leveraging the TIE reputation check for attachments that are coming through emails at gateway and mailbox levels. When you enable the TIE Reputation check, you can select file types that should be submitted for TIE reputation score.

What is TIE?

Threat Intelligence Exchange increases the protection and detection capabilities in real time by performing a comprehensive and advanced file reputation check, and prevents the threat spreading. The TIE server quickly analyzes the attachments at the gateway and mailbox level. For information about Threat Intelligence Exchange, see Threat Intelligence Exchange Product Guide.

The TIE reputation is based on two variants:

  • Certification reputation

  • File reputation

TIE validates the file for certificate reputation score first. If only the certificate reputation is known malicious, the file reputation score is considered.

How TSME works with TIE

When TIE is enabled in the policy settings, after applying File Filtering rules, TSME checks the reputation of the email attachments with the TIE server. Based on the TIE reputation for the file, the scores are mapped to one of these categories, and TSME takes action according to the configuration defined for that category:

  • Known trusted - 99

  • Most likely trusted - 85

  • Might be trusted - 70

  • Unknown - 50

  • Might be malicious- 30

  • Most likely malicious - 15

  • Known malicious - 1

When you configure an action for a specific category, the same action is applied for all categories that have a TIE reputation score lower than the specified category. By default, Take actions at and below is set to Might Be Malicious.

For example, when you set Take action at and below to Unknown and action as Replace with Alert for files that have a score of 50, all attachments with a TIE reputation score of 50 or less are replaced with an alert message. You can also select secondary actions for alert.

The reputation scores are locally cached and TSME can use the updated local cache for reputation checks.

When TIE is disabled, scanning action is taken according to the policy settings. When TIE is enabled but the TIE server is unreachable, and the local cache doesn't contain entries for the file, the reputation check from TIE is skipped and email is scanned according to the policy settings.

For more information about how the reputation score is mapped, see the TIE Product Guide.

TSME sends only the following file types for TIE reputation check:

  • exe

  • pdf

  • Microsoft Office documents

For a list of supported file types, see KB89578.

Note

When the email contains a compressed attachment, the compressed file is extracted and only the supported file types in the attachment are sent for TIE reputation check. For a list of supported compressed file types, see KB89577.

For other types of files and post TIE reputation check, TSME scans the attachments according to the policy settings. When you release the quarantined item under TIE detections, the file is only scanned for viruses before allowing it. You can view the number of files detected by TIE and the number of files sent to ATD check information on the Dashboard page.

Filtering File types for TIE

Use this feature to filter file types that need to be submitted for TIE Reputation score. You can either submit the attached PDF in the mail or select all any of the other files including Microsoft Word, Microsoft Excel, or Microsoft Powerpoint for TIE Reputation check.

For example: if you want to submit scanning request only for PDFs and Microsoft Excel files, click the checkbox of both of these files.

When you select File types for TIE Reputation, TSME sends only those files for File Reputation score.

  • You can configure File types for TIE Reputation from Settings & DiagnosticsTIE Settings.

You can also enable the Intelligent Sandbox detection on selected reputation categories of files and based on the size of the attachment.

When a file is checked for TIE reputation, TIE returns the reputation score and might recommend the file for analysis. TSME sends the file to Intelligent Sandbox based on the category and file size configured in the settings. If there is a revised reputation score for the file, the local cache is updated with that reputation score. The revised score will be used from the next lookup. The default setting for Take action at and below is Might Be Malicious and File Size is 8 MB.

Trellix recommends that you:

  • Deploy a TIE server in secondary configuration to process all TIE reputation requests from TSME in the same data center as your Exchange server. This enables the TIE server to process maximum email attachments per second in a dedicated infrastructure.

    Note

    Each email attachment sent for TIE reputation will invoke maximum of 2 TIE requests.

  • The reputation traffic is reduced when the TSME servers cache the reputations locally. But, since TSME clears the local cache after service restart, spikes might be experienced.

  • Estimate the requests coming from TSME using the dashboard counters in TSME. For information about how to measure requests per second coming to a TIE server, view the Throughput under Performance Status in the TIE Server Topology Management page under Server Settings in ePO - On-prem. You can also view the TIE Server New Files in the TIE Server Data Cleanup page.