New features
This release of the Trellix Intrusion Prevention System does not include any new features.
Enhancements
This release of the Trellix Intrusion Prevention System includes the following enhancements:
vIPS license enhancements
In this release of 11.1, the following license improvements are included:
Enable license(s) assignment at the vIPS Clusters level.
Support for the auto-assignment of license(s).
Support for multiple assignments and unassignments of license(s).
The Manager includes Capacity and License options in the vIPS Clusters tab and the <Cluster_Name> summary page.
Option
Definition
Capacity
Displays the total capacity of license required for all member Sensors in the cluster.
License
Displays the license(s) status of the cluster.
Auto-assignment of license(s) to the Sensor:
If sufficient license(s) are available in the pool, the license(s) will be auto-assigned to the Sensor. However, if enough license(s) are unavailable in the pool, the partial assignment of license(s) will not be permitted.
When a standalone Sensor or a member Sensor is registered successfully, and enough license(s) are available in the pool, the license(s) will be auto-assigned to the standalone Sensor or a member Sensor.
When you upgrade the Manager, and enough license(s) are available in the pool, the license(s) will be auto-assigned to the Sensor.
Manual assignment of license(s) to the Sensor:
You can assign a license by clicking the
icon. However, you cannot perform the license assignment if the cluster is empty. In such scenarios, the
icon will be hidden.The license(s) status can be one of the following options:
Required: The reason can be one of the following:The license(s) has not been assigned.
The license(s) are assigned, but their capacity is less than the cluster's configured capacity.
Note
If a combination of expired and insufficient licenses exists, the insufficient license takes a higher priority.
Present: The sufficient license(s) are present and valid.
Expired: The license(s) are assigned, but one or more licenses have expired.
Grace Period: The assigned license(s) have expired and are now running on a grace period.Note
A grace period of 30 days is provided to subscription-based system licenses after they expire.
For more information, see Managing Devices in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
IPS support for multiple IVX brokers
Previously, IPS allowed users to integrate with a single IVX appliance broker node for malware analysis of files. Starting with this release of 11.1, IPS allows users to configure up to 5 IVX appliance broker nodes under the cluster. The Sensor submits files to the broker nodes in round robin manner for analysis and result polling, meaning better file submission rate and high availability are achieved.
Also, users can now configure broker nodes on IPv6 addresses unlike the earlier releases which supported only IPv4 communications.
In case of failed Manager-IVX or Sensor-IVX authentication, users can now view failure reason on the Manager UI which allows them to take corrective actions to attain successful authentication.
Note
At Device level, if you are inheriting admin domain configuration, make sure that both the Manager and the Sensor are running on software version 11.1 Update 4 or later. In case of heterogeneous scenarios where you are on a 11.1 Update 4 Manager and an older Sensor that supports only one broker node on IPv4, make sure you have added only one IPv4 broker address at Global level. If you have added an IPv6 address and the settings get inherited to the older Sensor, the file detection will not happen.
Note
It is highly recommended that you upgrade both the Manager and Sensor to 11.1 Update 4 or later releases to utilize multiple brokers which are connected over IPv4 and IPv6 addresses.
The following Sensor CLI commands are added:
Command | Description |
|---|---|
| This command performs lookup on the entered SHA256 hash and returns details such as the verdict, report id, and the query time. |
| This command displays the IVX Cloud configuration details. |
| This command displays statistics specific to IVX Cloud. |
| This command displays the connection status of the IVX Cloud. |
The following Sensor CLI commands are updated:
Command | Description |
|---|---|
| This command now displays the configuration details of all the IVX broker nodes attached to the Sensor. |
| This command now displays the statistics specific to the IVX broker nodes attached to the Sensor. |
| This command now displays the connection status of the IVX broker nodes attached to the Sensor. |
The following Sensor CLI command is updated:
Command | Description |
|---|---|
| This command now displays the IVX broker node management configuration. |
For more information on IVX integration, refer to the section Integrating Trellix IPS and IVX in Trellix Intrusion Prevention System 11.1.x Integration Guide.
Device software deployment improvements in the Manager
In this release of 11.1, several enhancements have been made on the IPS Manager to improve and speed up the device software deployment operations. This is to cater to the bulk deployment requirements of network environments where large or very large number of Sensors are deployed. The Manager takes the following actions while handling bulk Sensor software upgrade requests:
The Manager reserves 100 GB under required free disk space for Manager operations and considers an additional file size of 1.2 GB to be generated for each software deployment request. When the Manager receives the software deployment requests in batches, it checks the number of Sensors selected, and calculates the free disk space required to complete the deployment operation. If there is insufficient disk space, an error message is displayed in the UI stating the available disk space and space required to complete the upgrade task. This enables the Manager to maintain optimal performance, secure sufficient disk space to keep other processes running, and avoid any software upgrade failure scenario.
Software deployments are critical operations and performed under approved/scheduled maintenance window. If the Manager receives multiple deployment requests in queue along with device software update requests, such as signature file and SSL keys deployments, it prioritizes the software deployment requests ahead of all other requests. It also performs disk usage optimization for each deployment to help you perform more deployments at a faster speed, and complete the critical task of software deployments within the approved/scheduled maintenance time.
Note
Very large Sensor deployments mean that the number of Sensors deployed is more than 100. Large Sensor deployments have Sensors numbering between 36 and 100+.
For more information, refer to the section Large Sensor deployments in Trellix Intrusion Prevention System 11.1.x Product Guide.
Deployment of IPS Manager on Kernel-based Virtual Machine (KVM)
Starting with this release of 11.1, users can deploy IPS Manager on Kernel-based Virtual Machine (KVM) using the respective qcow2 image available in the Trellix Download Server.
Refer to the table KVM server requirements for MLOS in the Installation Parameters section to understand the server requirements for Manager deployments on KVM.
For more information, refer to the section Create a Manager instance using qcow2 file in Trellix Intrusion Prevention System 11.1.x Installation Guide.
Support for external file reputation through Trellix Threat Intelligence Exchange (TIE)
Starting with this release of 11.1, IPS allows users to integrate an external file reputation provider to the existing list of TIE providers. This will allow the sensor to receive a reputation score for the file from the External Provider.
For more information, refer to the sections How the integration works and Viewing Threat Intelligence Exchange detection in the Manager in Trellix Intrusion Prevention System 11.1.x Integration Guide.
Support for C5/M5 controller instances in AWS
This release of 11.1 includes the capability to support c5.xlarge or m5.xlarge controller instances in AWS.
For more information, see Considerations in Trellix Virtual Intrusion Prevention System 11.1.x Product Guide.
Cache implementation for Trellix Threat Intelligence Exchange (TIE) / Global Threat Intelligence (GTI) File Reputation
Starting with this release of 11.1, caching support is extended to Trellix TIE/GTI File Reputation service. Following Sensor CLI commands are updated for TIE/GTI cache implementation:
Command | Description |
|---|---|
| This command now allows users to clear cache entries related to TIE/GTI engine made in the Sensor. |
| This command now enables or disables malware cache for TIE/GTI engine. |
Command | Description |
|---|---|
| This command now includes an entry called |
Note
Either Trellix GTI or TIE server can be configured with Trellix IPS solution at a time.
For more information, see the sections IPS CLI Commands - Normal Mode and IPS CLI Commands - Debug Mode in Trellix Intrusion Prevention System 11.1.x Product Guide.
Rebranding updates
This is solely for informational purpose, there is no action required.
You will notice the following changes:
Product name
Trellix Vector Execution is renamed to Trellix Intelligent Virtual Execution - Server (Trellix VX/ IVX) and Trellix Detection as a Service is renamed to Trellix Intelligent Virtual Execution Cloud (Trellix IVX Cloud/ IVX Cloud). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.
Trellix Investigation Analysis is renamed to Trellix Network Investigator (NI). The associated software, hardware, features, and options bearing the old product name are renamed to the new product name.
Terminology updates in the UI
This release contains the following terminology updates in the Manager UI:
Navigation Path | Prior to 11.1.7.71 | 11.1.7.71 and later |
|---|---|---|
→ → → → | Enable Enable MVX Integration check-box and select Enable VX.
| Enable Enable IVX Integration check-box and select Enable IVX.
|
→ → → → | Disable Inherit Settings? check-box, enable Enable MVX Integration check-box, and select Enable VX.
| Disable Inherit Settings? check-box, enable Enable IVX Integration check-box, and select Enable IVX.
|
IPS CLI enhancements
The following Sensor CLI commands are updated:
Command | Description |
|---|---|
| This command has been updated with respect to the rebranding changes made on MVX. If users plan to delete cache entries of IVX, they need to issue the command |
| This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable or disable malware cache of IVX engine, they need to use the syntax |
The following Sensor CLI command is updated:
Command | Description |
|---|---|
| This command has been updated with respect to the rebranding changes made on MVX. If users plan to enable/disable the IVX malware engine for Advanced Malware inspection, they need to issue the syntax |
| The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI. |
| The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI. |
| The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI. |
| The syntax and output of this command have been updated with respect to rebranding changes made on Trellix NI. |
Note
Apart from the above listed commands, a few more commands have been updated where the output displays the rebranding changes. As these changes do not have impact over the commands you input, they have not been listed here.
For more information, see CLI Commands in Trellix Intrusion Prevention System 11.1.x Product Guide.
Updated platform, environment, or operating system support
This release provides the following enhancements related to platforms, environments, or operating systems:
JDK upgrade
Starting with this release of 11.1, the IPS Manager uses JDK version 8u392 that includes additional security against new vulnerabilities.
Apache Tomcat server upgrade
Starting with this release of 11.1, Tomcat server used in the IPS Manager is upgraded to version 9.0.83 which provides a collection of security fixes.
.png)
.jpg)