まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security 12.0 update 13 (Deep Security 12.0U13)リリース @ 累積修正対応と、VMware NSX 6.4.8サポートやサードのアンチマルウエア対応とか #deepsecurity #trendmicro

Deep Security Manager 12.0 update 13
Release date: October 1, 2020
Build number: 12.0.480

Enhancements

  • The pager numbers, phone numbers, or mobile numbers listed on the Users Properties page of Deep Security Manager can be configured to be more than 30 digits. SEG-80854/SF03098096/DSSEG-5890
  • Deep Security verifies the signature on the Deep Security Agent to ensure that the software files have not changed since the time of signing. DSSEG-5874

Resolved issues

  • Some Intrusion Prevention rules were designed to operate exclusively in "Detect Only" mode, however you were able to change their behavior on the policy and computer pages. SEG-83700/SF03456778/DSSEG-5998
  • The "Ransomware Event History" widget on the dashboard displayed incorrect information. SEG-86045/SF03618147/DSSEG-6142
  • The MasterAdmin could not create a scheduled task for all computers. SEG-86413/SF03320936/DSSEG-6131
What's new in Deep Security Manager? | Deep Security

Deep Security Linux Agent 12.0 update 13

Deep Security Agent - 12.0 update 13
Release date: October 1, 2020
Build number: 12.0.0-1373

Enhancements

  • Improved Anti-Malware compatibility with third-party security protections. SEG-84563/03564043/DSSEG-6039
  • Upgraded VMware NetX SDK to support VMware NSX 6.4.8
  • Deep Security verifies the signature on the Deep Security Agent to ensure that the software files have not changed since the time of signing. DSSEG-5935
  • If there are multiple IPs in the "X-Forwarded-For" tag of the HTTP header, the 1st IP among them will be retrieved. DSSEG-6183
  • Updated the Integrity Monitoring scan completion time in Deep Security Manager events to display in seconds with a thousands separator. SEG-83194/SF03429936/DSSEG-6029

Resolved issues

  • Real-time Anti-Malware with filesystem hooking enabled did not work on older kernel versions. SEG-82411/DSSEG-5991
  • Deep Security Agent sometimes crashed when the "Scan for Integrity" scan was running. SEG-82795/03462751/DSSEG-6008
  • The dsa_query command didn't display Anti-Malware patterns correctly. DSSEG-6073
  • Deep Security Anti-Malware kernel modules were not unloaded successfully when ds_agent services stopped. SEG-83209/SF03512620/DSSEG-6043
  • When Anti-Malware and Application Control were enabled, stopping the ds_agent service could cause high CPU usage. SEG-85738/SF03595067/DSSEG-6157
  • The Deep Security Agent event "9105: Enable Relay Web Server Failed" occurred when the agent stopped. SEG-79615/03326180/DSSEG-6022
  • An executable that was created and executed quickly was blocked by Application Control while in maintenance mode. DSSEG-6173
  • When Anti-Malware real-time scans were enabled in Linux, the system sometimes crashed because of a compatibility issue with third-party security software based on kernel system call hooking. SEG-88135/SF03700563/DSSEG-6247
  • "Out of Connection" Firewall events occurred when the network engine was set to "Tap mode". SEG-87155/SF03644367/DSSEG-6270
  • Some Intrusion Prevention events did not include the XFF header. SEG-81986/03419140/DSSEG-5936

Notices

  • Deep Security Appliance 9.5 has reached End of Support and can't be upgrade to this release. DSSEG-5938
What's new in Deep Security Agent? | Deep Security

Deep Security UNIX Agent 12.0 update 13

Deep Security Agent - 12.0 update 13
Release date: October 1, 2020
Build number: 12.0.0-1373

Enhancements

  • Deep Security verifies the signature on the Deep Security Agent to ensure that the software files have not changed since the time of signing. DSSEG-5935
  • Updated the Integrity Monitoring scan completion time in Deep Security Manager events to display in seconds with a thousands separator. SEG-83194/SF03429936/DSSEG-6029
  • If there are multiple IPs in the "X-Forwarded-For" tag of the HTTP header, the 1st IP among them will be retrieved. DSSEG-6183

Resolved issues

  • Deep Security Agent sometimes crashed when the "Scan for Integrity" scan was running. SEG-82795/03462751/DSSEG-6008
  • An executable that was created and executed quickly was blocked by Application Control while in maintenance mode. DSSEG-6173
  • When using Deep Security Agent on Solaris, the port scanning feature of the Integrity Monitoring module did not work because the agent did not have access to information on the user ID under which a given port was opened. This prevented storage of any listening port information. The port scanning feature on Solaris agents has been modified to store the string "n/a" for the userid. This allows the remaining port information to be stored and used in the port scanning function. However, exclusions and inclusions based on User ID still do not function correctly because this information is not available. DSSEG-6151
  • "Out of Connection" Firewall events occurred when the network engine was set to "Tap mode". SEG-87155/SF03644367/DSSEG-6270
  • Some Intrusion Prevention events did not include the XFF header. SEG-81986/03419140/DSSEG-5936
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent 12.0 update 13

Deep Security Agent - 12.0 update 13
Release date: October 1, 2020
Build number: 12.0.0-1373

Enhancements

  • Deep Security verifies the signature on the Deep Security Agent to ensure that the software files have not changed since the time of signing. DSSEG-5935
  • Updated the Integrity Monitoring scan completion time in Deep Security Manager events to display in seconds with a thousands separator. SEG-83194/SF03429936/DSSEG-6029

Resolved issues

  • Deep Security Agent crashed unexpectedly because it was unable to detect the Docker engine version on Windows Servers. DSSEG-6075
  • Deep Security Notifier sometimes turned the Antivirus status in the Windows action center on and off, which caused high CPU usage. SEG-73189/SF03037857/DSSEG-6004
  • Deep Security Agent sometimes crashed when the "Scan for Integrity" scan was running. SEG-82795/03462751/DSSEG-6008
  • An executable that was created and executed quickly was blocked by Application Control while in maintenance mode. /DSSEG-6173
  • If there are multiple IPs in the "X-Forwarded-For" tag of the HTTP header, the 1st IP among them will be retrieved. /DSSEG-6183
  • "Out of Connection" Firewall events occurred when the network engine was set to "Tap mode". SEG-87155/SF03644367/DSSEG-6270
  • Some Intrusion Prevention events did not include the XFF header. SEG-81986/03419140/DSSEG-5936
What's new in Deep Security Agent? | Deep Security