SmartVision capabilities

Prev Next

Trellix expands the detection capabilities of the Network Security appliance beyond detecting and blocking initial breaches. SmartVision detects the activities of attackers already resident in the network core. A combination of standard Network Security appliances and appliances can be deployed to detect malicious activity and correlate indicators of compromise along the entire attacker kill chain.

Detection of post-exploitation attacker activities

Standard Network Security appliances detect early phases of Web-based attacks: initial exploitation, malware binary download, and command and control (CnC) callback. They detect attack vulnerabilities in client systems and applications, detect infected hosts, and can block unauthorized outbound transmissions across multiple protocols. To provide this detection, the appliance extracts malware and objects that are transferred over HTTP and FTP and submits them to the MVX engine for detonation. Standard Network Security detection focuses on the traffic that is entering and leaving the network.

SmartVision features focus primarily on traffic in the core of the network: workstation to workstation or workstation to data center. SmartVision appliances detect the types of malicious network activities that take place inside a corporate network after the victim’s system has been compromised, when the attacker has already gained a foothold in the network and is beginning to move laterally within the network or steal data.

SmartVision extends the Network Security MVX analysis capabilities to detect malware, objects, and post-exploitation tools (such as password dumpers) that are transferred over the SMB protocols. Attackers frequently use SMB and SMB 2 to carry out their objectives, hiding malicious activity among normal network traffic.

SmartVision also relies on intrusion detection system (IDS) rules, which identify known weak indicators of compromise. A new correlation engine analyzes and correlates weak indicators from disparate sources and generates alerts when post-infection attacker activity is detected. IDS rules are developed in conjunction with and based on threat intelligence gathered by Trellix Incident Response Services and Trellix as a Service.

To monitor east-west traffic (traffic between hosts in the internal or private network and servers), appliances are deployed on server-side network infrastructure. When deployed in this topology, the appliance has visibility to the traffic between compromised hosts and servers in the internal network.

Types of attacks detected

SmartVision analyzes SMB v1 and v2, DCERPC, WinRM, MS-SQL, and other TCP-based protocols commonly used in lateral movement.

Object types such as .exe, .dll, .com, .ps1, and bat are submitted for analysis. detects the following types of malicious activities:

Internal reconnaissance

After gaining access to one machine in a network, an attacker needs to learn its location and the firewalls or other devices between it and its goal. This information can be obtained by downloading and executing custom or open source tools. To reduce the risk of detection, an attacker can leverage built-in tools such as commercial vulnerability scanning applications that may be part of your scheduled enterprise security hygiene.

Execution

Attackers leverage tools such as PowerShell and TaskScheduler to connect to remote systems, modify the registry, access event logs, and execute commands.

Persistence

After gaining access to a system, malware often establishes itself as a persistent presence on that system. The attacker can re-infect a machine or maintain remote access even after system interruptions such as a system restart, user logout, and loss of credentials.

Privilege escalation

An attacker can gain access to a network by exploiting a network security behavior or a vulnerability in an operating system or application. Leveraging the privileges held by a valid application or local user, the attacker obtains an elevated level of access to resources.

Credential access

Using widely available credential-stealing tools, attackers can steal the plain-text user names and passwords of those who visit the site. Meanwhile, the attacker has covertly downloaded a credentials-dumping utility such as Mimikatz. Using the SMB protocol to blend in with valid network traffic, dumper utilities transfer stolen credentials from the compromised network to an easily accessed third-party Web site.

Lateral movement

In order to gain additional privileges and persist within the network, attackers can transfer malware to other hosts within the network.

Data exfiltration detection

When the data theft detection module is enabled, the appliance monitors the egress traffic of specified network hosts. If the appliance observes uncharacteristic data uploads from a monitored host, it generates a alert.