What's new

Prev Next

New features

This release of Trellix Intrusion Prevention System includes the following new features:

MITRE based attack view in Trellix IPS Manager

Starting with this release of 11.1, the Analysis<Admin Domain Name>Attack Log page includes Mitre Attack Details column header which displays the adversarial Tactic, Technique, Sub-Technique and Technique/Sub-Technique ID for each alert. When looking for a specific tactic, technique, or sub-technique, you can enter any related keyword for them in the Quick Search field, or apply them as filter in the column level in Attack Log. The Description tab that appears on double-clicking an attack or alert now contains collapsible subsection named Mitre Attack Details which displays the matching Tactic, Technique, Sub-Technique, and Technique/Sub-Technique ID for the attack or alert.

Note

Mitre Attack Details column in Attack Log is available in both Trellix IPS Manager and Central Manager.

This 11.1 release also includes MITRE ATTACK View page in the Manager that enables you to view and analyze attacks and alerts detected by the network security appliance in the MITRE ATT&CK matrix format. It offers a unified, comprehensive view of all adversarial tactics, techniques, sub-techniques, including those that match with the attack entries in the MITRE matrix structure. It also provides you with further drill-down capabilities, such as applying filters based on the attack severity level or IP address, and delving into any specific technique/sub-technique to view only the attacks that fall under those categories. You can access this page from Analysis<Admin Domain Name>MITRE ATTACK View.

Note

Mitre attack related details are not shown for older alerts.

Note

The MITRE ATTACK View page is not available in Trellix IPS Central Manager.

For more information, refer MITRE ATTACK View of attack details in Trellix Intrusion Prevention System 11.1.x Product Guide.

Enhancements

This release of Trellix Intrusion Prevention System includes the following enhancements:

Configure rsyslog server communication with a different port in Linux-based Manager

Starting with this release of 11.1, you can establish communication by defining the required port using semanage. You can define the required port for rsyslog server connection in Linux-based Manager for UDP, TCP, and TCP over SSL protocols. To establish rsyslog connection using a required port, execute semanage port -a -t syslogd_port_t -p <protocol> <port number>. This command creates a new policy to allow the newly defined ports for the rsyslog service/configuration.

For more information, refer How to configure rsyslog server in Linux-based Manager in Trellix Intrusion Prevention System Manager Appliance Product Guide.

Scheduler Details update

Starting with this release of 11.1, Scheduler Details page is exposed in the Manager to view overall scheduled process. You can access this page from Manager<Admin Domain Name> MaintenanceScheduler Details. It includes data backups, database maintenance, file maintenance, and other actions. Based on this information, you can choose an appropriate time for the backup you are currently scheduling.

For more information, refer Scheduler Details in Trellix Intrusion Prevention System 11.1.x Product Guide.

Interface name update in Port Throughput Usage

Starting with this release of 11.1, the Manager provides a capability to view interface name by selecting the required interface displayed at the bottom of the chart. You can access these details from Devices<Admin Domain Name>Devices<Device Name>TroubleshootingPerformance Charts. Click Throughput tab and select Port Throughput Usage Mbps from drop-down. For any selected interface, you can view the details of Port <port number> (Interface: <interface name>), Port throughput rate in Mbps, and time in MMM DD HH:MM:SS YYYY.

For more information, refer Performance metrics in Trellix Intrusion Prevention System 11.1.x Product Guide.

Terminology updates in the UI

This release contains the following terminology updates in the Manager UI:

Navigation Path

Prior to 11.1.7.3

11.1.7.3 and later

Devices<Admin Domain Name> GlobalCommon Device SettingsNTP

Select Enable NTP, configure the required NTP server(s) and click Save.

Select Enable NTP and click GUID-5FF7B5BA-AE98-4E18-8FEE-0795F91111DE-low.jpg to configure NTP server. After adding the details, click Save.

To remove any configured NTP server, deselect the Enable NTP and click Save.

Note

The Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority.

To remove any configured NTP server, select the checkbox beside NTP Server-<number> and click GUID-5DBFC0B8-D423-4F05-80BA-0F029C708A57-low.jpg.

Note

The Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority.

Devices<Admin Domain Name> Devices<Device Name>SetupNTP

Select Enable NTP, configure the required NTP server(s) and click Save.

Select Enable NTP and click GUID-5FF7B5BA-AE98-4E18-8FEE-0795F91111DE-low.jpg to configure NTP server. After adding the details, click Save.

To remove any configured NTP server, deselect Enable NTP and click Save.

Note

The Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority.

To remove any configured NTP server, select the checkbox beside NTP Server-<number> and click GUID-5DBFC0B8-D423-4F05-80BA-0F029C708A57-low.jpg.

Note

The Manager allows you to configure a maximum of two NTP servers with the same IP address format (i.e., IPv4 or IPv6). If you configure both NTP servers, NTP Server-1 takes a higher priority.

Manager<Admin Domain Name>Integration

To enable automatic import of Vulnerability Assessment Report, go to Manager<Admin Domain Name>Integration Vulnerability Assessment Non-MVM Report Import.

To enable automatic import of Vulnerability Assessment Report, go to Manager<Admin Domain Name>Integration Vulnerability Assessment Report Import.

Manager shell commands

The following Manager shell command is added:

Command

Description

semanage port -a -t syslogd_port_t -p <protocol> <port number>

This command creates a new policy to allow the newly defined ports for the rsyslog service/configuration.

For more information, see Manager Shell Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MLOS upgrade

Starting with this release of 11.1, the IPS Manager uses MLOS version 3.9.1 that includes additional security against new vulnerabilities.

Apache Solr upgrade

With this release the IPS Manager uses Apache Solr version 8.11.2 that includes additional security against new vulnerabilities.

Apache Tomcat upgrade

Starting with this release of 11.1, the IPS Manager uses Tomcat version 9.0.68 that includes additional security against new vulnerabilities and bug fixes.

Discontinued features

This release no longer supports the following:

Support for 9.1 and 9.2 software

Starting with this release of 11.1, support for 9.1 and 9.2 software has been deprecated. Any deployments containing these software will not be supported.

Note

If you plan to upgrade your deployments from 9.x to 11.1, you need to first upgrade your deployments to 10.1.7.65 (for Manager) and 10.1.7.155 (for Sensor) and then upgrade to 11.1. Refer to Release Information section in the following release notes to upgrade your existing 9.x deployments to 10.1.

vIPS 10.1.7.65-10.1.7.155 Virtual IPS Release Notes

Integration with McAfee Vulnerability Manager

Starting with this release of 11.1, McAfee Vulnerability Manager integration has been removed since it reached End Of Life (EOL).

Integration with Host Intrusion Prevention

Starting with this release of 11.1, Host Intrusion Prevention integration has been removed since it reached EOL.