The Trellix Dynamic Threat Intelligence (DTI) network (cloud) provides subscriber platforms with the latest intelligence on advanced cyber attacks and malware callback destinations. This enables Trellix products to proactively recognize new threats and block attacks. The DTI cloud is also used to enable automatic software updates. Finally, a connection to the DTI cloud is required to use the license update feature.
Threat intelligence
The Trellix DTI cloud interconnects Trellix platforms deployed within customer networks, technology partner networks, and service provider networks around the world. The Trellix DTI cloud serves as a global distribution hub to efficiently share automatically generated threat intelligence such as new malware profiles, vulnerability exploits, and obfuscation tactics, as well as new threat findings from the Trellix APT Discovery Center and verified third-party security feeds. By leveraging the Trellix DTI cloud, the Trellix Threat Prevention Platform is more efficient at detecting unknown zero-day, highly targeted attacks used in cybercrime, cyber espionage, and cyber reconnaissance as well as known malware.
Note
A subscription to the Trellix DTI cloud service is required before you can use the features described in this section.
When the DTI cloud receives threat intelligence from customers and partners from around the world, this information is analyzed and distributed to all customers with a DTI cloud subscription. The information includes:
New malware profiles
Vulnerability exploits
Obfuscation tactics
New threat findings from the Trellix Labs and verified third-party security feeds
Each customer controls what information is shared with and received from the DTI cloud.
.png)
Automatic license updates
The license update feature enables the NX appliance with basic network connectivity to automatically download licenses from the DTI network and install them. This feature provides the following benefits:
Minimal initial configuration—The license update feature is enabled with the configuration jump-start wizard during the initial system configuration. This means the feature can be fully functional after the jump-start wizard is completed.
Simplified license management—There is no need to contact Trellix for license keys when new features are added or when licenses are renewed, because the new licenses are automatically downloaded and installed.
Scalability—Organizations, such as those with a large number of appliances, can benefit from all appliances being updated automatically, instead of entering license keys manually on each appliance, one at a time.
You can enable automatic license updates on the NX appliance using the configuration wizard or the CLI.
How it works
The license update feature, if enabled, downloads and applies licenses to which the customer is contractually entitled. If an active license for a feature is already installed and the licensing service downloads an active license for the feature, the installed license is replaced by the downloaded license only if the downloaded license offers new functionality, a later expiry date, or was part of a more recent customer order. This process is automatic; however, you can also explicitly update licenses.
The license update feature will not:
Install a downloaded license that would cause a feature to become temporarily unlicensed.
Remove a feature license if there is no newly ordered replacement for it.
If you experience issues with a license retrieved from an automatic update, you can use the command no fenet license update enable to disable the automatic update process and you can use the command license install <cr> to manually install your older license key or keys.
You can synchronize the system time to the DTI server time to prevent a feature from being temporarily unlicensed due to time differences. This is a one-time synchronization, but it can be repeated.
When an appliance is managed by the Central Management System appliance, the Central Management System appliance acts as a proxy between the managed appliance and the licensing service. The license update feature must still be enabled on the managed appliance. In such an integrated environment, the Central Management System appliance acts as the DTI server for the managed appliances, so the licensing service uses the Central Management System DTI network credentials instead of the appliance's credentials.
System health monitoring and software updates
When connected to the DTI cloud, the Network Security appliance regularly provides system and diagnostic information to the DTI cloud. This information is then analyzed to ensure that the appliance is operating as expected.
The system and diagnostics checks include the following:
System Image Version
Guest Image Profiles
System Processes
Hardware State
Network State
If problems are found, the customer is alerted. If a new system image or guest image profile is available, administrators can choose to download it and then update the appliance.
Note
No customer-specific proprietary information is included this system and diagnostic information exchange.