Views:

Recommendation

Identifying trusted domains and services in the network not only ensures detection of unauthorized domains, applications, or services, but also avoids unnecessary detections of trusted domains and services that become a distraction for important detections that need more attention.

Therefore, Trend Micro recommends:

  • Checking with the customers and registering all their trusted network domains and dedicated servers for specific services that they use internally or consider trustworthy.
  • Exporting all the current network configuration via Export function as backup.

Configuration

 
Deep Discovery Inspector supports suffixmatching for registered domains. For instance, adding domain.com adds one.domain.com, two.domain.com.

To register trusted domains (up to 1,000 entries), do the following:

  1. Go to Administration > Network Groups and Assets > Registered Domains.

    Go to Registered Domains

  2. In the Domain field, specify a domain name to be registered. Registered domain names appear in the Defined Registered Domains section.

    specify a domain name to be registered

    As an optional step, you may click Analyze to display the detected domains that DDI had already observed in the network. This simplifies the process of trusted domain registration.

    Analyze option

  3. Click Add.

    Click Add

To register trusted services (up to 1,000 entries), do the following:

  1. Go to Administration > Network Groups and Assets > Registered Services.

    Registered Services

  2. Select a service from the drop-down list.

    Select service from drop down list

    As an optional step, you may click Analyze to display the detected services that DDI had already observed in the network. This simplifies the process of trusted service registration.

    Analyze option_Registered Services

    Analyze option_Review network cofig

  3. In the Server name field, specify a server name.
  4. In the IP address field, specify an IPV4/IPV6 IP address.

     
    IP address ranges cannot be specified
  5. Click Add.