New features
This release of Trellix Intrusion Prevention System includes the following new features:
MITRE based attack view in Trellix IPS Manager
Starting with this release of 11.1, the → → page includes Mitre Attack Details column header which displays the adversarial Tactic, Technique, Sub-Technique and Technique/Sub-Technique ID for each alert. When looking for a specific tactic, technique, or sub-technique, you can enter any related keyword for them in the Quick Search field, or apply them as filter in the column level in Attack Log. The Description tab that appears on double-clicking an attack or alert now contains collapsible subsection named Mitre Attack Details which displays the matching Tactic, Technique, Sub-Technique, and Technique/Sub-Technique ID for the attack or alert.
Note
Mitre Attack Details column in Attack Log is available in both Trellix IPS Manager and Central Manager.
This 11.1 release also includes MITRE ATTACK View page in the Manager that enables you to view and analyze attacks and alerts detected by the network security appliance in the MITRE ATT&CK matrix format. It offers a unified, comprehensive view of all adversarial tactics, techniques, sub-techniques, including those that match with the attack entries in the MITRE matrix structure. It also provides you with further drill-down capabilities, such as applying filters based on the attack severity level or IP address, and delving into any specific technique/sub-technique to view only the attacks that fall under those categories. You can access this page from → → .
Note
Mitre attack related details are not shown for older alerts.
Note
The MITRE ATTACK View page is not available in Trellix IPS Central Manager.
For more information, refer MITRE ATTACK View of attack details in Trellix Intrusion Prevention System 11.1.x Product Guide.
Enhancements
This release of Trellix Intrusion Prevention System includes the following enhancements:
Configure rsyslog server communication with a different port in Linux-based Manager
Starting with this release of 11.1, you can establish communication by defining the required port using semanage. You can define the required port for rsyslog server connection in Linux-based Manager for UDP, TCP, and TCP over SSL protocols. To establish rsyslog connection using a required port, execute semanage port -a -t syslogd_port_t -p <protocol> <port number>. This command creates a new policy to allow the newly defined ports for the rsyslog service/configuration.
For more information, refer How to configure rsyslog server in Linux-based Manager in Trellix Intrusion Prevention System Manager Appliance Product Guide.
Scheduler Details update
Starting with this release of 11.1, Scheduler Details page is exposed in the Manager to view overall scheduled process. You can access this page from → → → . It includes data backups, database maintenance, file maintenance, and other actions. Based on this information, you can choose an appropriate time for the backup you are currently scheduling.
For more information, refer Scheduler Details in Trellix Intrusion Prevention System 11.1.x Product Guide.
Interface name update in Port Throughput Usage
Starting with this release of 11.1, the Manager provides a capability to view interface name by selecting the required interface displayed at the bottom of the chart. You can access these details from → → → → → . Click Throughput tab and select Port Throughput Usage Mbps from drop-down. For any selected interface, you can view the details of Port <port number> (Interface: <interface name>), Port throughput rate in Mbps, and time in MMM DD HH:MM:SS YYYY.
For more information, refer Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.
Terminology updates in the UI
This release contains the following terminology updates in the Manager UI:
Navigation Path | Prior to 11.1.7.3 | 11.1.7.3 and later |
|---|---|---|
→ → → → | Select Enable NTP, configure the required NTP server(s) and click Save. | Select Enable NTP and click |
To remove any configured NTP server, deselect the Enable NTP and click Save. NoteThe Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority. | To remove any configured NTP server, select the checkbox beside NTP Server-<number> and click NoteThe Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority. | |
→ → → → → | Select Enable NTP, configure the required NTP server(s) and click Save. | Select Enable NTP and click |
To remove any configured NTP server, deselect Enable NTP and click Save. NoteThe Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority. | To remove any configured NTP server, select the checkbox beside NTP Server-<number> and click NoteThe Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority. | |
→ → | To enable automatic import of Vulnerability Assessment Report, go to → → → → . | To enable automatic import of Vulnerability Assessment Report, go to → → → . |
Manager shell commands
The following Manager shell command is added:
Command | Description |
|---|---|
| This command creates a new policy to allow the newly defined ports for the rsyslog service/configuration. |
For more information, see Manager Shell Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
MLOS upgrade
Starting with this release of 11.1, the IPS Manager uses MLOS version 3.9.1 that includes additional security against new vulnerabilities.
Apache Solr upgrade
With this release the IPS Manager uses Apache Solr version 8.11.2 that includes additional security against new vulnerabilities.
Apache Tomcat upgrade
Starting with this release of 11.1, the IPS Manager uses Tomcat version 9.0.68 that includes additional security against new vulnerabilities and bug fixes.
Discontinued features
This release no longer supports the following:
Support for 9.1 and 9.2 software
Starting with this release of 11.1, support for 9.1 and 9.2 software has been deprecated. Any deployments containing these software will not be supported.
Note
If you plan to upgrade your deployments from 9.x to 11.1, you need to first upgrade your deployments to 10.1.7.65 (for Manager) and 10.1.7.155 (for Sensor) and then upgrade to 11.1. Refer to Release Information section in the following release notes to upgrade your existing 9.x deployments to 10.1.
Integration with McAfee Vulnerability Manager
Starting with this release of 11.1, McAfee Vulnerability Manager integration has been removed since it reached End Of Life (EOL).
Integration with Host Intrusion Prevention
Starting with this release of 11.1, Host Intrusion Prevention integration has been removed since it reached EOL.
.jpg)
.jpg)