Integration with ePO - On-prem for OS profiling

Prev Next

When you integrate Intelligent Sandbox with ePO - On-prem, you can correctly identify the target host environment and use the corresponding analyzer VM for dynamic analysis.

OS profiling requires a VM profile with the default name. To determine the analyzer VM for a file submitted by Network Security Platform or McAfee Web Gateway, Intelligent Sandbox uses the following sources of information in the same order of priority:

  1. Intelligent Sandbox queries ePO - On-prem for the operating system of a host based on its IP address. If information from this source or the corresponding analyzer VM is not available, it goes to the next source.

  2. If Device Profiling is enabled, the Sensor provides the operating system and application details when forwarding a file for analysis. If information from this source or the corresponding analyzer VM is not available, it goes to the next source.

  3. From the analyzer profile in the corresponding user record, Intelligent Sandbox determines the VM profile. If information from this source or if the corresponding analyzer VM is not available, it goes to the next source.

  4. You can select a VM profile in your setup as the default.

When Intelligent Sandbox receives host information for a particular IP address from ePO - On-prem, it caches this detail.

  • The cached IP address to host information data has a time to live (TTL) value of 48 hours.

  • For the first 24 hours, Intelligent Sandbox uses just the host information in the cache.

  • For the second 24 hours, Intelligent Sandbox uses the host information from the cache but also queries ePO - On-prem and updates its cache. This updated information is valid for the next 48 hours.

  • If the cached information is more than 48 hours old, it treats it as if there is no cached information for the corresponding IP address. That is, it attempts to find the information from other sources and also sends a query to ePO - On-prem.

The following explains how Intelligent Sandbox collaborates with ePO - On-prem.

  1. Trellix IPS or Web Gateway sends a file to Intelligent Sandbox for analysis. When Trellix IPS sends a file, the IP address of the target host is also sent.

  2. Intelligent Sandbox checks its cache to see if there is a valid operating system mapped to that IP address.

  3. If it is the first time that a file for that IP address is being analyzed, there is no information in the cache. So, it determines the analyzer VM from the device profiling information in case of Trellix IPS and user record in case of McAfee Web Gateway. Simultaneously, it sends a query to ePO - On-prem for host information based on the IP address.

  4. ePO - On-prem forwards the host information to Intelligent Sandbox, which is cached for further use.