Protocols, Smart Polling, and Arc

A list of the improvements for Protocols, Smart Polling and Arc that have been introduced in this release.

  • ENG-346: Added a timeframe chart to display the latest 100 alert occurrences over time. This chart highlights the first occurrence of an alert and shows dots for each subsequent occurrence.
  • ENG-538: You can now configure directory exclusions for malware detections.
  • ENG-563: The Windows Remote Management (WinRM) Smart Polling strategy is now available to Arc sensors.
  • ENG-640: Fixed an issue with Ovation import.
  • ENG-687: Fixed the display of alert occurrences. Improved the UX for zooming out to the original scale.
  • ENG-790: Added support for HiCONiS protocol.
  • ENG-828: Introduced detection for Aconis MPM device operations.
  • ENG-1328: Ported the secure shell (SSH) strategy to Go to make it available to Arc.
  • ENG-1513: The SSH Smart Polling strategy now verifies the host key before attempting authentication. This security feature can be enabled from the Features page in the administration section of Guardian.
  • ENG-1552: Addressed a potential memory consumption problem in Smart Polling hypertext transfer protocol (HTTP) and hypertext transfer protocol secure (HTTPS) strategies.
  • N2OS-16662: The connected Guardian now automatically renews the Remote Collector certificates, provided they were issued by Nozomi Networks.
  • N2OS-17021: Added support for the Automation Direct KOP protocol to enable asset identification and information extraction for these devices.
  • N2OS-17221: Added support for the Automation Direct Productivity1000 protocol to enable asset identification and information extraction for these devices.
  • N2OS-17235: Enhanced S7plus protocol detection to detect program changes.
  • N2OS-17236: Improved detection of firmware transfer on S7Plus protocol.
  • N2OS-17377: Improved asset representation of devices with multiple interfaces and the same internet protocol (IP) address. Added two configuration options for the check_multiple_macs_same_ip setting:
    1. check_multiple_macs_same_ip group_by_ip groups nodes with the same IP address and distinct media access control (MAC) addresses into a single asset when the check_multiple_macs_same_ip enable configuration option is set to true.
    2. check_multiple_macs_same_ip require_confirmed_macs enables the check_multiple_macs_same_ip feature only on nodes that have confirmed MAC addresses.
  • N2OS-17511: It is now possible to disable the aggregation of nodes into assets based on the device identifier (ID) on a per‑protocol basis. This can be configured using the new notify_device_id protocols setting.