Terminology

Prev Next

This section covers terminology related to SmartVision:

Trellix Network Security terminology

The following terms apply to all Network Security appliances, which include SmartVision sensors and Network Security sensors and integrated appliances:

MVX engine

Trellix's patented MVX engine. The engine accurately confirms zero-day and targeted advanced persistent threat (APT) attacks. The threat verification performed by the MVX engine enables the Network Security appliance to protect your client systems against known malware as well as zero-day malware attacks, while triggering near-zero false positive alerts.

Network Security appliance

A Trellix appliance that protects network clients against malware attacks that use either OS exploits or Web infections as HTTP-based propagation vectors. Using its signature-based and signature-less internal rules engines, the Network Security appliance provides turnkey client vulnerability coverage. The appliance automatically detects HTTP attack vulnerabilities in client systems and applications, detects infected hosts, and blocks unauthorized outbound transmissions across multiple protocols.

  • A Network Security hardware appliance that has a local MVX engine can send objects to the local engine for detonation and analysis. When installed in a TrellixMVX environment, the appliances can be configured to operate with or without the local MVX engine.

  • A Network Security appliance that does not have or does not use a local MVX engine operates in a TrellixMVX deployment only. It enrolls with a remote MVX service that detonates and analyzes the extracted objects. The remote service can be either an on-premises MVX cluster or the cloud MVX service (mvx.trellixcloud.com) in the Trellix public cloud.

For the complete list of appliances, see Supported appliances.

Victim/attacker and source/destination nomenclature

In the Network Security Web UI, Victim/Attacker is used in table views (such as the Alerts page) and in headers in detail views (such as the Alert Details page). Source/Destination fields containing packet data collected in PCAP files are included in detail views.

Note

In email notifications and downloaded XML files, the values in the source and destination fields are switched. For example, the source IP address in the Web UI is shown as the destination IP address in email notifications and downloaded XML files.

Trellix MVX terminology

Many of the following terms are specific to the deployment type (cloud or on-premises).

broker node

A compute node designated to receive submissions from authenticated sensors in the MVX cluster and manage the submissions in a queue. Other compute nodes pull submissions from the queue, perform the MVX analysis, and send the verdict to the sensors through the brokers. Compare with cloud broker for a cloud deployment.

A broker node is also called an MVX Smart Grid Broker.

cloud broker

The entity in the cloud MVX service (mvx.trellixcloud.com) that receives submissions from authenticated sensors enrolled in the cloud MVX service. Compare with broker node for an on-premises deployment.

A cloud Intelligent Virtual Execution - Server broker is also called an MVX Smart Grid Broker.

compute node

A group of Intelligent Virtual Execution - Server appliances in an on-premises MVX cluster. One or two compute nodes are designated broker nodes. Compute nodes perform MVX analysis on behalf of Network Security sensors that are enrolled with the cluster.

A compute node is also called an MVX Smart Grid Element.

cloud MVX

The MVX service that is hosted in the Trellix public cloud. It analyzes the suspect objects submitted by Network Security sensors that are enrolled in the cloud MVX service. Objects are submitted and results are returned over an encrypted connection.

enrollment

The authentication of sensors and brokers with a TrellixMVX enrollment service to ensure secure communication. In a cloud deployment, sensors and brokers enroll with the cloud MVX service. In an on-premises deployment, sensors and brokers enroll with an on-premises MVX cluster.

MVX cluster

An on-premises cluster of at least one Central Management System appliance and multiple compute nodes, at least one of which is designated a broker node. The Central Management System appliance provides the enrollment service for the cluster. The broker nodes receive submissions from enrolled sensors and return the results of the analysis performed by compute nodes.

An MVX cluster is also called an MVX Smart Grid.

Network Security integrated appliance

A hardware Network Security appliance with its MVX engine enabled. Suspect findings are analyzed by its local MVX engine. In a TrellixMVX deployment, you can configure a hardware Network Security appliance to operate as a sensor by disabling the local MVX engine. Compare with Network Security sensor.

Network Security sensor

A Network Security appliance that does not have or does not use a local MVX analysis engine and submits its suspect findings to Trellix MVX for analysis. In a cloud deployment, analysis is performed by the cloud MVX service. In an on-premises deployment, MVX analysis performed by a compute node in the MVX cluster.

A Network Security sensor is also called a Network Smart Node.

Network Security virtual appliance

An instance of the Network Security appliance system image that does not have an MVX engine. It is designed to function as a sensor in a TrellixMVX deployment.

SmartVision terminology

The following terms are used in the SmartVision user interfaces and in this guide:

SmartVision

Technology that enables a Network Security appliance to detect post-exploitation attacker activities and data theft activities in an internal or private network. To detect post-infection attacks, correlates interesting network events from multiple event stream feeds. To detect data exfiltration (data theft), monitors the egress traffic of specified internal hosts for unusual data uploads.

SmartVision appliance

A Network Security appliance in a TrellixMVX deployment and functioning with modules activated. It can be a SmartVision Edition appliance, a SmartVision-enabled Network Security sensor, or a SmartVision-enabled Network Security integrated appliance. A SmartVision appliance is typically deployed in the network core to detect the type of attacker activity that begins after initial exploitation.

SmartVision Edition appliance

A Network Security hardware or virtual appliance with the SmartVision feature enabled. It is a component of the Trellix solution,

You can configure a hardware SmartVision appliance to operate as a sensor by disabling the local MVX engine.

SmartVision rules

Trellix's post-exploitation detection rules that are downloaded to the appliance through security content updates.