You can deploy Intelligent Sandbox as standalone or integrated with other products.
Standalone deployment — This is a simple way of deploying Intelligent Sandbox. In this case, it is not integrated with other externally installed Trellix products. When deployed as a standalone Appliance, you can manually submit the suspicious files using the web application. Or, you can submit the samples using an FTP client. This deployment option is used, for example, during the testing and evaluation phase, to fine-tune configuration, and to analyze suspicious files in an isolated network segment. Also, research engineers might use the standalone deployment option for detailed analysis of malware.
Integration with Trellix Intrusion Prevention System— This deployment involves integrating Intelligent Sandbox with Network Security Platform, Sensor and Manager.
Based on how you have configured the corresponding Advanced Malware policy, an inline Sensor detects a file download and sends a copy of the file to Intelligent Sandbox for analysis. If Intelligent Sandbox detects a malware within a few seconds, the Sensor can block the download. The Manager displays the results of the analysis from Intelligent Sandbox.
If requires more time for analysis, the Sensor allows the file to be downloaded. If Intelligent Sandbox detects a malware after the file has been downloaded, it informs Network Security Platform, and you can use the Sensor to quarantine the host until it is cleaned and remediated. You can configure the Manager to update all Sensors about this malicious file. So, if that file is downloaded again anywhere in your network, your Sensors might block it.
For information about how to integrate Trellix Intrusion Prevention System and Trellix Intelligent Sandbox, see the latest Trellix Intrusion Prevention System Integration Guide.
Integration with Skyhigh Security Secure Web Gateway (SWG) — You can configure Intelligent Sandbox as another engine for antimalware protection. When your network user downloads a file, the native McAfee Gateway antimalware Engine on Secure Web Gateway (SWG) scans the file and determines a malware score. Based on this score and the file type, Secure Web Gateway sends a copy of the file to Intelligent Sandbox for deeper inspection and dynamic analysis. A progress page informs your users that the requested file is being analyzed for malware. Based on the malware severity level reported by Intelligent Sandbox, Secure Web Gateway determines if the file is allowed or blocked. If it is blocked, the reasons are displayed for your users. You can view the details of the malware that was detected in the log file.
This design makes sure that only those files that require an in-depth analysis are sent to Intelligent Sandbox. This balances your users' experience in terms of download speed and security. Secure Web Gateway hosted over IPv6 device can integrate with Intelligent Sandbox IPv6 address. For information about how to integrate Intelligent Sandboxand Secure Web Gateway, see the Skyhigh Security Secure Web Gateway Product Guide, version 7.4.
Integration with TePO ePO - On-prem — This integration enables Intelligent Sandbox to retrieve information regarding the target host. Knowing the operating system on the target host, enables it to select a similar virtual environment for dynamic analysis.
Dynamic analysis requires the suspicious file to be executed for a specific time period. During this time, the malware is likely to have reached the intended target. You can then take the needed remedial steps to clean the affected host.
This integration also enables you to identify the other hosts detected by the same malware and take the appropriate remedial steps.
How the deployment options address the four major aspects of antimalware process cycle:
Detection of file download: When a user accesses a file, the inline Trellix Intrusion Prevention System Sensor or Secure Web Gateway detects this and sends a copy of the file to Intelligent Sandbox for analysis.
Analysis of the file for malware: Even before the user fully downloads the file, Intelligent Sandbox can detect a known malware using sources that are local to it or on the cloud.
Block future downloads of the same file: Every time Intelligent Sandbox detects a medium, high, or high severity malware, it updates its local black list.
Identify and remediate affected hosts: Integration with Trellix Intrusion Prevention System enables you to quarantine the host until it is cleaned up and remediated.