What's New Parent topic

The following tables provide an overview of new features available in IMSS 9.1 Patch 1.

IMSS 9.1 Patch 1 New Features

New Feature
Description
URL Analysis
In addition to suspicious files in email messages, IMSS submits suspicious URLs included in email messages (subject, body and attachments) to Virtual Analyzer for further analysis.
To protect you from malicious URLs, IMSS first compares URLs in email messages with known malicious URLs in the Web reputation database, and then further analyzes URLs at the time of click. However, untested URLs may pass the first two layers of analysis. IMSS provides enhanced protection by leveraging the URL sandbox available in Virtual Analyzer to perform sandbox simulation and analysis.

IMSS 9.1 New Features

New Feature
Description
Cloud Pre-Filter Integration
Cloud Pre-Filter is a hosted email security service that can filter all of your email messages before they reach your network. Pre-filtering your email messages can save you time and money.
Data Loss Prevention
Data Loss Prevention safeguards an organization's confidential and sensitive data-referred to as digital assets-against accidental disclosure and intentional theft.
Integration with Virtual Analyzer
Virtual Analyzer is an isolated virtual environment used to manage and analyze samples in Deep Discovery Analyzer. IMSS allows you to define rules to send suspicious messages, including attachments, to Virtual Analyzer for analysis.
To achieve better load balancing and failover capabilities, IMSS allows you to add multiple servers for Virtual Analyzer. You can also enable, disable and delete Virtual Analyzer servers on the IMSS management console.
End-User Quarantine Single Sign-on (SSO)
IMSS now allows users to log on once to their domain and then to End-User Quarantine (EUQ) without re-entering their domain name and password.
Dashboard and Widgets
Real-time summaries have been replaced with a dashboard and widgets. This will provide administrators with more flexibility when viewing IMSS data. The Summary screen has been renamed System Status and appears in the left menu.
Web Reputation Enhancement
The Web Reputation filter has been enhanced to enable detection of URLs that have not been rated by Trend Micro. This functionality helps increase protection against advanced threats that leverage short-lived malicious websites.
Enhanced Smart Protection
IMSS supports both Trend Micro Smart Protection Network and Smart Protection Server as smart protection sources. Smart Protection Servers are supported to localize smart protection services to the corporate network to reduce outbound traffic and optimize efficiency.
Social Engineering Attack Protection
Social Engineering Attack Protection detects suspicious behaviors related to social engineering attacks in email messages. When Social Engineering Attack Protection is enabled, the Trend Micro Antispam Engine scans for suspicious behaviors in several parts of each email transmission, including the email header, subject line, body, attachments, and the SMTP protocol information. If the Antispam Engine detects behaviors associated with social engineering attacks, the Antispam Engine returns details about the message to IMSS for further action, policy enforcement, or reporting.
Known Host Support
Known hosts include trusted mail transfer agents (MTAs) and the Cloud Pre-Filter that are deployed before IMSS on your network. IMSS enables you to specify known hosts to exempt them from Sender Filtering and graymail scanning.
Graymail
Graymail refers to solicited bulk email messages that are not spam. IMSS manages graymail separately from common spam to allow administrators to identify graymail messages. IP addresses specified in the graymail exception list bypass scanning.
Multiple LDAP Servers
IMSS supports using more than one LDAP server and has support for more LDAP server types.
Advanced Anti-Malware Protection
The Advanced Threat Scan Engine (ATSE) uses a combination of pattern-based scanning and aggressive heuristic scanning to detect document exploits and other threats used in targeted attacks.
Time-of-Click Protection
IMSS provides time-of-click protection against malicious URLs in email messages. If you enable Time-of-Click Protection, IMSS rewrites URLs in email messages for further analysis. Trend Micro analyzes those URLs at the time of click and will block them if they are malicious.
Connected Threat Defense
Configure IMSS to subscribe to the suspicious object lists on the Trend Micro Control Manager server. Using the Control Manager console, you can specify customized actions for objects detected by the suspicious object lists to provide custom defense against threats identified by endpoints protected by Trend Micro products specific to your environment.
Control Manager facilitates the investigation of targeted attacks and advanced threats using suspicious objects. Files and URLs that have the potential to expose systems to danger or loss will be detected.
Report Delivery Through Email
IMSS allows you to send newly generated reports and archived reports through email. Detailed views of reports will be included.
EUQ Distribution List Management
The web-based EUQ service allows end users to manage the spam quarantine of distribution lists that they belong to.
LDAPS Support
IMSS supports LDAP over SSL (LDAPS) that provides users a secure and encrypted channel to communicate with LDAP servers.
Command & Control (C&C) Contact Alert Services
Command & Control (C&C) Contact Alert Services provides IMSS with enhanced detection and alert capabilities to mitigate the damage caused by advanced persistent threats and targeted attacks.
EUQ Digest Inline Action Links
IMSS enables users to apply actions to quarantined messages through links in the EUQ digest.

IMSS 7.1 SP2 New Features

New Feature
Description
Audit Log Enhancement
Audit logs record various administrator operations and provide a way to query activities of specified administrator accounts.
Note
Note
As an enhanced log category of system events, Audit log replaces Admin activity on the IMSS management console.
Attachment Keyword Expression enhancement
Keyword expressions configured for IMSS policies are enhanced to apply not only to attachment content but also to attachment names.
Attachment Names Supported by Message Tracking Logs
Message tracking logs include attachment names as a new attribute. Multiple attachment names can be specified to query message tracking logs.
Logon Notice Support
Customizable logon notices are available both on the administrator logon page and End-User Quarantine logon page.

IMSS 7.1 SP1 New Features

New Feature
Description
Marketing Email Management
Administrators can manage marketing messages separately from common spam. To allow end users to receive wanted marketing messages, email addresses and IP addresses specified in the marketing message exception list bypass scanning.
Smart Scan
Smart Scan facilitates a more efficient scanning process by offloading a large number of threat signatures previously stored on the IMSS server to the cloud.
IPv6 Support
IMSS supports the following IPv6 features in IPv6 networks and proxies:
  • SMTP routing and POP3 connections
  • Trend Micro services:
    • Web Reputation Services
    • Product Registration
    • ActiveUpdate
    • Smart Feedback
  • Trend Micro Control Manager
  • IP address imports and exports in IPv6 format
  • Notifications
  • Logs and reports with relevant SMTP IPv6 information
Keyword & Expression Enhancements
To improve visibility of triggered keywords and expressions, the entity name (where the keyword expression appears in a message) and the matched expressions now appear in the policy event log query details page. Administrators can also add a description to new keyword expressions for better tracking.
SMTP Authentication Support for End-User Quarantine
SMTP authentication provides users another option for enabling the End-User Quarantine feature.
Email Alias Support
The User Quarantine now has the option to allow end users to retrieve quarantined email messages with alias email addresses.

IMSS 7.1 New Features

New Feature
Description
Common Policy Objects
Several information objects that can be used by all policies have been removed from policy creation and given their own areas for configuration:
  • Address Groups
  • Keywords & Expressions
  • Policy Notifications
  • Stamps
  • DKIM Approved List
  • Web Reputation Approved List
Web Reputation
Protect your clients from malicious or suspicious URLs embedded in email messages with Web reputation.
NRS Terminology Change
Network Reputation Service (NRS) has been changed to Email Reputation Service (ERS).
Detection Capability Enhancement
Use DomainKeys Identified Mail (DKIM) enforcement, with the DKIM Approved List, in policies to assist in phishing protection and to reduce the number of false positives regarding domains.
X-Header Support
Insert X-Headers into email messages to track and catalog the messages.
Expanded File Scanning Support
Scanning support for Microsoft® Office 2007 and Adobe® Acrobat® 8 documents.
New Migration Tools
New tools provided to help customers migrating from previous product versions.

IMSS 7.0 New Features

New Feature
Description
Multiple Antivirus and Malware Policies
Multiple IMSS policies with LDAP support help you configure filtering settings that apply to specific senders and receivers based on different criteria.
Centralized Logging and Reporting
A consolidated, detailed report provides top usage statistics and key mail usage data. Centralized logging allows administrators to quickly audit message-related activities.
Centralized Archive and Quarantine Management
An easy way to search multiple IMSS quarantine and archive areas for messages.
Scalable Web End-User Quarantine (Web EUQ)
Multiple Web EUQ services offer end-users the ability to view quarantined email messages that IMSS detected as spam. Together with EUQ notification, IMSS will help lower the cost of helpdesk administrative tasks.
Multiple Spam Prevention Technologies
Three layers of spam protection:
  • Email reputation filters connections from spam senders when establishing SMTP sessions.
  • IP Profiler helps protect the mail server from attacks with smart profiles (SMTP IDS).
  • Trend Micro Antispam engine detects and takes action on spam.
IntelliTrap
IntelliTrap provides heuristic evaluation of compressed files that helps reduce the risk that a virus in a compressed file will enter your network through email.
Delegated Administration
LDAP-integrated account management allows users to assign administrative rights for different configuration tasks.
Easy Deployment with Configuration Wizard
An easy-to-use configuration wizard to get IMSS up and running.
Advance MTA Functions
Opportunistic TLS, domain based delivery, and other MTA functions help IMSS handle email efficiently and securely.
Migration
Easy upgrade process ensures that settings will be migrated with minimum effort during setup.
Mail Auditing and Tracking
Detailed logging for all messages tracks and identifies message flow related issues.
Integration with Trend Micro Control Manager™
Perform log queries on Email Reputation Services from Control Manager, in addition to other supported features.