What's new

Prev Next

New features

This release of Trellix Intrusion Prevention System does not include any new features.

Enhancements

This release of Trellix Intrusion Prevention System includes the following enhancements:

Defining and enforcing user-specific blocking strategy to make self-adaptable IPS policies

Previously, if users wanted any attack to be blocked as per their blocking strategy, they had to identify all matching attacks during IPS Policy configuration, bulk edit them, and manually set the Sensor Actions to Enable Blocking. Also, they had to identify the attack signatures that were added or modified in a new signature set release and reconfigure their IPS policies to enable the Sensor blocking response action for the attack signatures that matched their blocking criteria.

Starting with this release of 11.1, Trellix IPS Manager offers a more simplified and automated IPS policy management mechanism for blocking attacks. It enables users to define and store one or more customizable rules for blocking attacks as per their network requirements during attack set profile configuration. When the same attack set profile is used in the IPS policy, the Manager automatically correlates the blocking criteria set by the user with the new and existing attack signatures. This enables IPS policies to automatically block attacks that match the user's blocking strategy and makes them self-adaptable to any new signature set release.

This automated IPS policy management for blocking attacks minimizes the need to manually edit the IPS policies for the blocking of attacks. Moreover, as the attack set profile mapped to the IPS policy stores the user-defined blocking criteria for attacks, it is automatically applied to any new/modified attack definitions included in any signature set update that match the set criteria. This eliminates the requirement of repeated manual intervention and provides user-customizable and automated attack blocking mechanism that helps users maintain their network security posture.

You need to perform the following steps to automate the process of blocking attacks in the Manager and Sensor:

  • Create or edit an attack set profile that includes rules for blocking attacks as per your blocking strategy. On the Attacks to Block tab during attack set profile configuration, you can create one or more rules with the categories, subcategories and minimum severity level of attacks that you want to be explicitly blocked by the Sensor.

  • Once the attack set profile with your blocking criteria is configured, you can use the same attack set profile during IPS policy configuration. Double-clicking any attack that falls under your blocking criteria and is set to be automatically blocked shows the Block field under Sensor Actions - Response to be Inherit (Enable Blocking). This Sensor response action is only visible for attacks that are set to be automatically blocked in the selected attack set profile.

    Important

    If you wish, you can override the automatic blocking behavior of any attack by manually setting the Sensor blocking action during IPS policy configuration. Sensor response actions customized in the IPS policy always takes precedence over automatic blocking of attacks criteria set in the Attack Set Profiles page.

  • Once the desired IPS policy is mapped to the attack set profile that includes the rules for attack blocking, you need to enforce the IPS policy at the interface and sub-interface level for the required Sensor(s).

  • You need to then deploy these configuration changes to the required devices in the admin domain level or at a device level.

When the policy and rule updates are applied to the required Sensor(s), those automatically block all attacks that match your blocking criteria as set in the attack set profile and send an alert to the Manager.

Note

  • Automating the blocking of attacks as per user-defined blocking strategy is available in both Trellix IPS Manager and Central Manager from 11.1 Update 3 release onwards.

  • The default or preconfigured attack set profiles are read-only. So, the rules for blocking can be created for custom attack set profiles only.

For more information, refer to the section Defining and using user-customizable blocking strategy to make self-adaptable IPS policies in Trellix Intrusion Prevention System 11.1.x Product Guide.

Forwarding MITRE Attack Details to Syslog and SNMP servers

Starting with this release of 11.1, users can configure the Manager to forward MITRE attack details to Syslog and SNMP servers. The variables introduced to forward MITRE attack details are IV_TACTIC, IV_TECHNIQUE, IV_SUBTECHNIQUE, and IV_TTPID. Users can choose the appropriate variables while configuring the Notification Profile.

For more information, refer to the section Add a Syslog notification profile to forward alerts in Trellix Intrusion Prevention System 11.1.x Product Guide.

Updated platform, environment, or operating system support

This release provides the following enhancements related to platforms, environments, or operating systems:

MariaDB upgrade

Starting with this release of 11.1, the IPS Manager uses MariaDB version 10.6.14 that includes additional security against new vulnerabilities.

JDK upgrade

Starting with this release of 11.1, the IPS Manager uses JDK version 8u372 that includes additional security against new vulnerabilities.