Contents and detection
A list of the improvements for the Contents and Detection that have been introduced in this release.
- Improved the handling of files with spaces when Sandbox extracts and unarchives files.
- Improved the
SIGN:TRAFFIC-MALFORMED
alerts for UDP and GOOSE packets, considering now legitimate declared packet lengths that are smaller than the real packet. - The risk for the
SIGN:PROTOCOL-INJECTION
alert has been lowered to 6. It now also belongs to the High security profile. - Improved secure shell (SSH) banner detections are now enabled by default.
- The firmware version used in the Common Platform Enumeration (CPE)s for ONVIF nodes detected passively or through Smart Polling is now more accurate.
- Improved the concurrency of storage operations for the quarantine directory for Sandbox.
- Increased the likelihood for
node_cpes
foronvif
to 0.8.