まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security Agent 20.0.0-3964 (Linux/Windows/UNIX) (20 LTS Update 2022-03-01) がリリース @ Debian 11とRed Hat 8の追加、Threat Intelligence機能の追加みたい

Deep Security Linux Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)

Deep Security Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)
Release date: March 1, 2022
Build number: 20.0.0-3964

New features

  • Threat Intelligence: Threat Intelligence (formerly known as "Connected Threat Defense") provides enhanced malware protection for new and emerging threats. For more information, visit Detect emerging threats using Threat Intelligence.

Enhanced platform support

  • Deep Security Agent (version 20.0.0-3964+) is now supported on these platforms:
    • Red Hat 8 (AWS ARM-Based Graviton 2) (this requires Deep Security Manager version 20.0.605+)
    • Debian 11 (this requires Deep Security Manager version 20.0.605+)

Enhancements

  • Updated Deep Security Agent to exclude suspicious characters (such as $) found in strings from the "Original IP (XFF)" field for Intrusion Prevention events. SEG-129905/DS-68989

Resolved issues

  • With real-time Integrity Monitoring enabled, Integrity Monitoring delete events were not being generated after editing a file and then deleting it. DS-69057
  • Deep Security Agent caused high CPU usage for systems protecting containers. Container protection can now be enabled or disabled in Deep Security Manager (from Computer (or Policy) > Settings > Container Protection). SEG-115751/DSSEG-7334
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)

Deep Security Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)
Release date: March 1, 2022
Build number: 20.0.0-3964

New features

  • Threat Intelligence: Threat Intelligence (formerly known as "Connected Threat Defense") provides enhanced malware protection for new and emerging threats. For more information, visit Detect emerging threats using Threat Intelligence.

Enhancements

  • Updated Deep Security Agent to exclude suspicious characters (such as $) found in strings from the "Original IP (XFF)" field for Intrusion Prevention events. SEG-129905/DS-68989

Resolved issues

  • Deep Security Agent accepted policy change parameters even if the self-protection password verification did not pass. SF05177188/SEG-129643/DS-69293
  • Deep Security Agent sometimes went offline unexpectedly after activation. SEG-130280
  • With Intrusion Prevention enabled, issues establishing an SSL connection caused "Unsupported SSL Version" events. SF04955719/SEG-127437/DS-68689
  • Deep Security Agent was generating unexpected "Log File Delete Error" system events. DS-69641
  • Deep Security Agent sometimes created unnecessary "User (Created/Deleted)" or "Group (Added/Removed/Updated)" events. DS-62413
What's new in Deep Security Agent? | Deep Security

Deep Security UNIX Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)

Deep Security Agent - 20.0.0-3964 (20 LTS Update 2022-03-01)
Release date: March 1, 2022
Build number: 20.0.0-3964

New features

  • Threat Intelligence: Threat Intelligence (formerly known as "Connected Threat Defense") provides enhanced malware protection for new and emerging threats. For more information, visit Detect emerging threats using Threat Intelligence.

Enhancements

  • Updated Deep Security Agent to exclude suspicious characters (such as $) found in strings from the "Original IP (XFF)" field for Intrusion Prevention events. SEG-129905/DS-68989
What's new in Deep Security Agent? | Deep Security