File Protect 11.0.0 Release Notes

Prev Next

Note

Release 11.0.0 is the current release after 10.0.5 for File Protect.

New features and changes

This section describes new features or enhancements in the File Protect 11.0.0 release.

Support OS Upgrade to Alma Linux 9.2

The File Protect appliance has received a base upgrade from CentOS 7 to Alma Linux 9.2 to ensure continuous support and deliver improved stability, security, and performance.

Support for custom IOC feed via the Web UI

The third-party feed tab now features dedicated "Allowed Lists" and "Blocked Lists" in the File Protect Web UI. You can now add URLs, MD5 or SHA-256 hashes, and regex URLs to both the allowed and blocked lists. These additions are designed to optimize the appliance's detection efficacy and expedite analysis times.

Regex pattern matching in custom URL rules

Regular expression pattern matching is now implemented for custom blocklists and allowlists thereby enhancing the capacity to define URL rules. This feature provides increased flexibility for superior threat management through both the Command Line Interface (CLI) and the Web User Interface (Web UI).

Integration of external threat intelligence feeds through the TAXII protocol.

The File Protect appliance now incorporates third-party threat intelligence feeds from TAXII servers utilizing STIX 2.x/TAXII 2.1 via both the Web UI and CLI. Upon configuration, the system autonomously retrieves feeds, encompassing URLs and file hashes for all products and domain IPs for File Protect, at predetermined intervals based on the established synchronization frequency. Presently, the system permits the configuration of a solitary TAXII server, featuring customizable API roots, credentials, CA certificates, synchronization frequency, and STIX indicator types.

On-premise S3 storage support for enhanced web UI functionality

The File Protect appliance web user interface now provides the ability to create and add on-premises S3 storage configurations, functionality that was previously limited to the command-line interface. Additionally, the Scan page now includes support for creating scans that target on-premises S3 storage

Support for pGTI Integration

The File Protect appliance now supports Private Global Threat Intelligence (pGTI) integration, enabling it to leverage Trellix's private cloud server for URL and file reputation verdicts. pGTI, which uses REST APIs and certificate-based authentication, maintains reputations based on Trellix security platform submissions. File Protect can now query pGTI for file and URL reputation assessments during analysis.

New, modified and deprecated CLI commands

New CLIs

The CLI commands in this section were added in this release.

Regex pattern matching in custom URL rules CLIs

  • [no] analysis custom blacklist regex url <pattern> : Adds a rule to a custom blacklist based on the regex URL with specified pattern.

  • [no] analysis custom whitelist regex url <pattern> : Adds a rule to a custom whitelist based on the regex URL with specified pattern.

  • show analysis custom blacklist regex urls : Displays the custom blacklist containing all the regex URLs.

  • show analysis custom whitelist regex urls : Displays the custom whitelist containing all the regex URLs.

CLIs for managing threat intel feeds - TAXII

  • [no] taxii server <TAXII server name> api-root: Configures the API root for the TAXII server.

  • [no] taxii server <TAXII server name>: Configures a TAXII server.

  • [no] taxii server <TAXII server name> api-root collection-id: Configures the API root with a collection ID for the TAXII server.

  • [no] taxii server<TAXII server name> api-root username password : Configures the API root username and password for the TAXII server.

  • [no] taxii server <TAXII server name> discovery-url: Configures the TAXII server discovery URL.

  • [no] taxii server <TAXII server name>enable: Enables the TAXII server.

  • [no] taxii server <TAXII server name> pagination-limit: Configures the pagination limit for the TAXII server.

  • [no] taxii server<TAXII server name> root-ca: Configures the root CA for the TAXII server.

  • [no] taxii server <server name> root-ca ca-chain: Configures the root CA and CA chain for the TAXII server.

  • [no] taxii server <TAXII server name> sync-frequency: Set the TAXII server sync frequency in minutes (10-1440).

  • [no] taxii server <TAXII server name> username password: Configure the TAXII server username and password.

  • [no] taxii server <TAXII server name> validate config: Validates the TAXII server configuration.

  • [no] show taxii server: Displays the configuration of a TAXII server.

  • [no]analysis custom stix indicator-type <type> enable: Enables the indicator type for STIX format intel feeds. Only the configured indicator patterns with indicator-type configured are synced.

CLIs for managing threat intel feeds - STIX format

  • [no]analysis custom stix indicator-type <type> enable : Enables the indicator type for STIX format intel feeds.

  • show analysis custom stix indicator-types : Displays the indicator types for STIX format intel feeds.

CLIs for pGTI integration

  • analysis pgti baseurl <pgti_url>: Configures the URL address of the pGTI server

  • no analysis pgti baseurl: Deletes the URL address of the pGTI server

  • analysis pgti apikey certificate <cert_name> ca-list <ca-chain-cert_name>: Generates the API key for communicating with the pGTI server using the API

  • no analysis pgti apikey: Deletes the pGTI API key and the corresponding certificate name and ca_chain name config used for generating the certificates

  • [no] analysis pgti enable: Enables/disables the integration with the pGTI server

  • show analysis pgti: Displays the configuration details regarding the pGTI integration

Deprecated CLIs

CLIs to configure proxy

  • fmps proxy fqdn <fqdn>

  • fmps proxy port <port>

  • fmps proxy username <username>

  • fmps proxy password <password>

  • fmps proxy enable

Note

You can use the CLIs below to configure proxy instead:

  • fenet proxy host <fqdn:port>: Configures FQDN port.

  • fenet proxy auth basic user <user>: Configures user.

  • fenet proxy auth basic password <password>: Configures the password.

  • [no] fenet proxy enable: Enables or disables FENET proxy.

Resolved issues

The following issues were resolved in the File Protect 11.0.0 release.

Tracking number

Summary

COM-31520, COM-31516

Vulnerability Validation for CVE-2023-5869

Resolution for the vulnerability designated as CVE-2023-5869 was implemented in PostgreSQL 14.10 binaries. In the present release, version 11.0.0, PostgreSQL 14.11 is deployed, thereby incorporating the necessary fixes from version 14.10 and effectively mitigating the aforementioned vulnerability.

COM-31572

Fixes vulnerability issues caused by CVE-2023-48795.

COM-62576

Custom blacklist URL processing now automatically converts between HTTPS and HTTP when adding a URL, considering both variations in subsequent processing.

COM-62706

Fixes an issue wherein certificate uploads to the File Protectappliance were failing due to erroneous value inputs.

COM-62823

In the latest OS version, the 'ping' command response for non-registered hosts has changed from "unknown host" to the more generic "system error" to improve security hardening.

FMPS-2828

Fixes an issue that necessitated the configuration of two distinct proxies instead of a singular proxy.

FMPS-2921

Fixes a typing error in File Protect scan edit option.

FMPS-2926

Fixes an issue where files scanned by Fileshare, and subsequently released from quarantine through manual intervention, failed to be added to the whitelist.

Known Issues

The following issues are known in the File Protect 11.0.0 release.

Tracking number

Summary

COM-63527

Instead of originating from the designated live interface (ether2), the sandbox analysis traffic is incorrectly originating from the management interface (ether1).

FMPS-2963

Releasing multiple quarantined files at once fails. Only some files are released, while others remain in the UI and re-trying to release them causes an error. Workaround: You need to release one file at a time.

FMPS-2964

After performing a scan and releasing any quarantined file, the respective fe-quarantined file still appears at the source.

WEBUI-14964

The STIX feed upload must only accept valid STIX 1.0 (XML) and STIX 2.0/2.1 (JSON) formats. The current implementation incorrectly allows other file formats to be uploaded.

Upgrade support

The Trellix File Protect 11.0.0 release requires a reboot for the update to take effect. You can upgrade your FX appliance to 11.0.0 from release 9.0.0 or later.

After an upgrade to version 11.0.0, the dashboard will not retain prior data for Analysis Statistics and File Analysis Statistics.

After an upgrade to version 11.0.0, the dashboard statistics may not be accurate for the first three hours. Scan statistics are not affected.

Created log archive files will not be preserved on upgrade to 11.0.0. Please have a backup of logs before the upgrade.

Note

After an upgrade to version 11.0.0, certain processes will be in a pending state until new security content is downloaded and installed. See the following section, Download the security content bundle.

Download the security content bundle

After the upgrade, certain processes will be in a pending state until new security content is downloaded and installed. The security content is downloaded and installed automatically for online customers. Offline customers must manually download and install the new security content after upgrading appliances to release 11.0.0.

Downloading content from the DTI offline update portal

If you download File Protect 11.0.0 security content from the DTI Offline Update Portal, use the SCNET-9.0 channel of the portal.

Caution

Downloading security content from a different channel will result in a loss of detection.

For details, see the Trellix DTI Offline Update Portal User Guide.

YARA rules supported versions

YARA rules support version 4.5.0.

Important

Before you upgrade an File Protect appliance to the 11.0.0 release, modify any custom YARA rules to YARA 4.5.0. For details about YARA 4.5.0, see YARA's Documentation, Release 4.5.0 by Victor Alvarez.

Enabling access to intel context