まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)のアップデート @ 各種機能追加や、RHEL7のSELinuxで、パケットインスペクションが動作しない対応

Deep Security Linux Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)

Deep Security Agent - 20.0.0-7119 (20 LTS Update 2023-05-29):What's new in Deep Security Agent? | Deep Security

Deep Security Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)
Release date: May 29, 2023
Build number: 20.0.0-7119

Enhancements

  • MQTT connection credentials were entered in the Deep Security Agent log file (ds_agent.log) in certain scenarios. SEG-174560/C1WS-13282
  • Updated Deep Security Agent to reduce the amount of redundant data sent when Activity Monitoring is enabled. DS-77657
  • Deep Security Agent crashed some systems when they were out of memory. SF06704797/SEG-175243/DSSEG-7875
  • Agent self-protection now secures the Advanced TLS inspection process (ds_nuagent), preventing local users with administrator privileges from stopping it. DS-74080

Resolved issues

  • Deep Security Agent only reported a single Anti-Malware event for an infected compressed file, even if it contained multiple infected files. DS-76339
  • After replacing a connection, Deep Security Agent reported metrics as though it was still connected to the old connection for up to 4 minutes. DS-77453
  • When Anti-Malware was enabled, Deep Security Agent caused high CPU usage on some systems. DS-77758
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)

Deep Security Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)
Release date: May 29, 2023
Build number: 20.0.0-7119

Enhancements

  • Updated Deep Security Agent to reduce data usage when generating Activity Monitoring events or when operating while integrated with Trend Micro Vision One. DS-77622
  • When Application Control is enabled, MSI file installations fail on some systems. SF06509811/SEG-170485/DS-76906
  • Agent self-protection now secures the Advanced TLS inspection process (ds_nuagent), preventing local users with administrator privileges from stopping it. DS-74080
  • Deep Security Agent 20.0.0-7119+ now supports FIPS mode for the dsa-connect service for Workload Security customers on Windows platforms that support FIPS mode as detailed here: Supported features by platform. C1WS-7467

Resolved issues

  • Deep Security Agent only reported a single Anti-Malware event for an infected compressed file, even if it contained multiple infected files. DS-76339
  • After replacing a connection, Deep Security Agent reported metrics as though it was still connected to the old connection for up to 4 minutes. DS-77453
  • If Advanced TLS traffic inspection was enabled, rebooting the operating system sometimes caused Deep Security Agent to get stuck on the "stopping services" screen. SF06494167/SEG-170082/DS-76880
  • The Deep Security Notifier service (ds_notifier) caused a memory leak during agent updates on some systems. SF06454240/SEG-167684/DSSEG-7863

Known issues

  • Upgrading to Deep Security Agent version 20.0.0-6860, 20.0.0-6690, or 20.0.0-7119 using the Deep Security Manager console sometimes results in upgrade failure. After the upgrade failure, the Deep Security Agent service stops and may show "Agent Offline" from the manager console. For more details, see https://success.trendmicro.com/dcx/s/solution/000293284?language=en_U. SEG-177789, SEG-177748, SEG-178496, SEG-178742, SEG-177423, SEG-178470, SEG-178940, SEG-178956
What's new in Deep Security Agent? | Deep Security

Deep Security UNIX Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)

Deep Security Agent - 20.0.0-7119 (20 LTS Update 2023-05-29)
Release date: May 29, 2023
Build number: 20.0.0-7119

Enhancements

  • Updated Deep Security Agent for Solaris to add an option to enable collecting interface latency metrics on Azure Data Explorer dashboards. DS-77025

Resolved issues

  • MQTT connection credentials were entered in the Deep Security Agent log file (ds_agent.log) in certain scenarios. SEG-174560/C1WS-13282
  • Deep Security Agent only reported a single Anti-Malware event for an infected compressed file, even if it contained multiple infected files. DS-76339
  • After replacing a connection, Deep Security Agent reported metrics as though it was still connected to the old connection for up to 4 minutes. DS-77453
What's new in Deep Security Agent? | Deep Security