Contents and detection

A list of the improvements for the Contents and Detection that have been introduced in this release.

  • Improved the handling of files with spaces when Sandbox extracts and unarchives files.
  • Improved the SIGN:TRAFFIC-MALFORMED alerts for UDP and GOOSE packets, considering now legitimate declared packet lengths that are smaller than the real packet.
  • The risk for the SIGN:PROTOCOL-INJECTION alert has been lowered to 6. It now also belongs to the High security profile.
  • Improved secure shell (SSH) banner detections are now enabled by default.
  • The firmware version used in the Common Platform Enumeration (CPE)s for ONVIF nodes detected passively or through Smart Polling is now more accurate.
  • Improved the concurrency of storage operations for the quarantine directory for Sandbox.
  • Increased the likelihood for node_cpes for onvif to 0.8.