What's new

Prev Next

New features

This release of the Trellix Intrusion Prevention System does not include any new features.

Enhancements

This release of the Trellix Intrusion Prevention System includes the following enhancements:

vIPS license enhancements

In this release of 11.1, the following license improvements are included:

  • Enable license(s) assignment at the vIPS Clusters level.

  • Support for the auto-assignment of license(s).

  • Support for multiple assignments and unassignments of license(s).

  • The Manager includes Capacity and License options in the vIPS Clusters tab and the <Cluster_Name> summary page.

    Option

    Definition

    Capacity

    Displays the total capacity of license required for all member Sensors in the cluster.

    License

    Displays the license(s) status of the cluster.

    Auto-assignment of license(s) to the Sensor:

    If sufficient license(s) are available in the pool, the license(s) will be auto-assigned to the Sensor. However, if enough license(s) are unavailable in the pool, the partial assignment of license(s) will not be permitted.

    • When a standalone Sensor or a member Sensor is registered successfully, and enough license(s) are available in the pool, the license(s) will be auto-assigned to the standalone Sensor or a member Sensor.

    • When you upgrade the Manager, and enough license(s) are available in the pool, the license(s) will be auto-assigned to the Sensor.

    Manual assignment of license(s) to the Sensor:

    You can assign a license by clicking the GUID-AD58F10B-F37A-45AA-A55D-0DD7A02B2AA1-low.png icon. However, you cannot perform the license assignment if the cluster is empty. In such scenarios, the GUID-AD58F10B-F37A-45AA-A55D-0DD7A02B2AA1-low.png icon will be hidden.

    The license(s) status can be one of the following options:

    • GUID-89BC390A-3C39-40F9-BCC2-CF115261968D-low.pngRequired: The reason can be one of the following:

      • The license(s) has not been assigned.

      • The license(s) are assigned, but their capacity is less than the cluster's configured capacity.

      Note

      If a combination of expired and insufficient licenses exists, the insufficient license takes a higher priority.

    • GUID-C395F07B-D0CD-480A-BCC2-FB886010F5DD-low.pngPresent: The sufficient license(s) are present and valid.

    • GUID-7B2E01C8-BD1B-4E8F-8F61-6FC4E27E8413-low.jpgExpired: The license(s) are assigned, but one or more licenses have expired.

    • GUID-D70B49BB-3DC3-44A9-98BE-B347D2898838-low.pngGrace Period: The assigned license(s) have expired and are now running on a grace period.

      Note

      A grace period of 30 days is provided to subscription-based system licenses after they expire.

For more information, see Managing Devices in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

IPS support for multiple IVX brokers

Previously, IPS allowed users to integrate with a single IVX appliance broker node for malware analysis of files. Starting with this release of 11.1, IPS allows users to configure up to 5 IVX appliance broker nodes under the cluster. The Sensor submits files to the broker nodes in round robin manner for analysis and result polling, meaning better file submission rate and high availability are achieved.

Also, users can now configure broker nodes on IPv6 addresses unlike the earlier releases which supported only IPv4 communications.

In case of failed Manager-IVX or Sensor-IVX authentication, users can now view failure reason on the Manager UI which allows them to take corrective actions to attain successful authentication.

Note

At Device level, if you are inheriting admin domain configuration, make sure that both the Manager and the Sensor are running on software version 11.1 Update 4 or later. In case of heterogeneous scenarios where you are on a 11.1 Update 4 Manager and an older Sensor that supports only one broker node on IPv4, make sure you have added only one IPv4 broker address at Global level. If you have added an IPv6 address and the settings get inherited to the older Sensor, the file detection will not happen.

Note

It is highly recommended that you upgrade both the Manager and Sensor to 11.1 Update 4 or later releases to utilize multiple brokers which are connected over IPv4 and IPv6 addresses.

The following Sensor CLI commands are added:

Normal Mode

Command

Description

ivx lookup sha256

This command performs lookup on the entered SHA256 hash and returns details such as the verdict, report id, and the query time.

show ivxcloud config

This command displays the IVX Cloud configuration details.

show ivxcloud stats

This command displays statistics specific to IVX Cloud.

show ivxcloud status

This command displays the connection status of the IVX Cloud.



The following Sensor CLI commands are updated:

Normal Mode

Command

Description

show ivx config

This command now displays the configuration details of all the IVX broker nodes attached to the Sensor.

show ivx stats brokerid

This command now displays the statistics specific to the IVX broker nodes attached to the Sensor.

show ivx status brokerid

This command now displays the connection status of the IVX broker nodes attached to the Sensor.



The following Sensor CLI command is updated:

Debug Mode

Command

Description

show mgmtcfg

This command now displays the IVX broker node management configuration.



For more information on IVX integration, refer to the section Integrating Trellix IPS and IVX in Trellix Intrusion Prevention System 11.1.x Integration Guide.

Device software deployment improvements in the Manager

In this release of 11.1, several enhancements have been made on the IPS Manager to improve and speed up the device software deployment operations. This is to cater to the bulk deployment requirements of network environments where large or very large number of Sensors are deployed. The Manager takes the following actions while handling bulk Sensor software upgrade requests:

  • The Manager reserves 100 GB under required free disk space for Manager operations and considers an additional file size of 1.2 GB to be generated for each software deployment request. When the Manager receives the software deployment requests in batches, it checks the number of Sensors selected, and calculates the free disk space required to complete the deployment operation. If there is insufficient disk space, an error message is displayed in the UI stating the available disk space and space required to complete the upgrade task. This enables the Manager to maintain optimal performance, secure sufficient disk space to keep other processes running, and avoid any software upgrade failure scenario.

  • Software deployments are critical operations and performed under approved/scheduled maintenance window. If the Manager receives multiple deployment requests in queue along with device software update requests, such as signature file and SSL keys deployments, it prioritizes the software deployment requests ahead of all other requests. It also performs disk usage optimization for each deployment to help you perform more deployments at a faster speed, and complete the critical task of software deployments within the approved/scheduled maintenance time.

Note

Very large Sensor deployments mean that the number of Sensors deployed is more than 100. Large Sensor deployments have Sensors numbering between 36 and 100+.

For more information, refer to the section Large Sensor deployments in Trellix Intrusion Prevention System 11.1.x Product Guide.

Deployment of IPS Manager on Kernel-based Virtual Machine (KVM)

Starting with this release of 11.1, users can deploy IPS Manager on Kernel-based Virtual Machine (KVM) using the respective qcow2 image available in the Trellix Download Server.

Refer to the table KVM server requirements for MLOS in the Installation Parameters section to understand the server requirements for Manager deployments on KVM.

For more information, refer to the section Create a Manager instance using qcow2 file in Trellix Intrusion Prevention System 11.1.x Installation Guide.

Support for external file reputation through Trellix Threat Intelligence Exchange (TIE)

Starting with this release of 11.1, IPS allows users to integrate an external file reputation provider to the existing list of TIE providers. This will allow the sensor to receive a reputation score for the file from the External Provider.

For more information, refer to the sections How the integration works and Viewing Threat Intelligence Exchange detection in the Manager in Trellix Intrusion Prevention System 11.1.x Integration Guide.

Support for C5/M5 controller instances in AWS

This release of 11.1 includes the capability to support c5.xlarge or m5.xlarge controller instances in AWS.

For more information, see Considerations in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.

Cache implementation for Trellix Threat Intelligence Exchange (TIE) / Global Threat Intelligence (GTI) File Reputation

Starting with this release of 11.1, caching support is extended to Trellix TIE/GTI File Reputation service. Following Sensor CLI commands are updated for TIE/GTI cache implementation:

Normal Mode

Command

Description

clearmalwarecache

This command now allows users to clear cache entries related to TIE/GTI engine made in the Sensor.

malwarecache

This command now enables or disables malware cache for TIE/GTI engine.



Debug Mode

Command

Description

show malwareserverstats

This command now includes an entry called Artemis Cache hit Cnt to display the number of times TIE/GTI cache is being read.



Note

Either Trellix GTI or TIE server can be configured with Trellix IPS solution at a time.

For more information, see the sections IPS CLI Commands - Normal Mode and IPS CLI Commands - Debug Mode in Trellix Intrusion Prevention System 11.1.x Product Guide.

Rebranding updates

This is solely for informational purpose, there is no action required.

You will notice the following changes:

Product name

  • Trellix Vector Execution is renamed to Trellix Intelligent Virtual Execution - Server (Trellix VX/ IVX) and Trellix Detection as a Service is renamed to Trellix Intelligent Virtual Execution Cloud (Trellix IVX Cloud/ IVX Cloud). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.

  • Trellix Investigation Analysis is renamed to Trellix Network Investigator (NI). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.

Terminology updates in the UI

This release contains the following terminology updates in the Manager UI:

Navigation Path

Prior to 11.1.7.71

11.1.7.71 and later

Devices <Admin Domain Name> Global IPS Device Settings IVX Integration

Enable Enable MVX Integration check-box and select Enable VX.

  • To add a broker node, enter the details of the broker node and click Save.

  • To edit a broker node, update the details and click Save.

Enable Enable IVX Integration check-box and select Enable IVX.

  • Click Add IVX Cluster. To add broker nodes, click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon located at the at the bottom-left corner of the page. The Add Broker Node panel opens to the right of the page. Enter the broker node details and click Add. Then, click Next. In the IVX Integration parent page, click Save.

  • To modify a broker node in the cluster, double-click the cluster. Double-click the broker node that you want to modify. The Add Broker Node panel opens to the right of the page. Update the IVX broker details and click Update. Then, click Next. In the IVX Integration parent page, click Save.

  • To delete a broker node in the cluster, double-click the cluster. Choose the broker node that you want to delete and click GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg. Then, click Next. In the IVX Integration parent page, click Save.

Devices <Admin Domain Name> Devices Setup IVX Integration

Disable Inherit Settings? check-box, enable Enable MVX Integration check-box, and select Enable VX.

  • To add a broker node, enter the details of the broker node and click Save.

  • To edit a broker node, update the details and click Save.

Disable Inherit Settings? check-box, enable Enable IVX Integration check-box, and select Enable IVX.

  • Click Add IVX Cluster. To add broker nodes, click the GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png icon located at the at the bottom-left corner of the page. The Add Broker Node panel opens to the right of the page. Enter the broker node details and click Add. Then, click Next. In the IVX Integration parent page, click Save.

  • To modify a broker node in the cluster, double-click the cluster. Double-click the broker node that you want to modify. The Add Broker Node panel opens to the right of the page. Update the IVX broker details and click Update. Then, click Next. In the IVX Integration parent page, click Save.

  • To delete a broker node in the cluster, double-click the cluster. Choose the broker node that you want to delete and click GUID-C5DB3A60-0A1C-4C8F-83A6-37EAFFF00433-low.jpg. Then, click Next. In the IVX Integration parent page, click Save.

IPS CLI enhancements

The following Sensor CLI commands are updated:

Normal Mode

Command

Description

clearmalwarecache

This command has been updated with respect to the rebranding changes made on MVX. If users plan to delete cache entries of IVX, they need to issue the command clearmalwarecache ivx.

malwarecache

This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable or disable malware cache of IVX engine, they need to use the syntax malwarecache <enable | disable> ivx.



The following Sensor CLI command is updated:

Debug Mode

Command

Description

set malwareEngine

This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable/disable the IVX malware engine for Advanced Malware inspection, they need to issue the syntax set malwareEngine ivx <enable | disable.

show ni status

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

getnistats

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

clearnistats

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.

ninetflowstat

The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI.



Note

Apart from the above listed commands, a few more commands have been updated where the output displays the rebranding changes. As these changes do not have impact over the commands you input, they have not been listed here.

For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 8u392 that includes additional security against new vulnerabilities.

Apache Tomcat server upgrade

Starting with this release of 11.1, Tomcat server used in the IPS Manager is upgraded to version 9.0.83 which provides a collection of security fixes.