Knowing the terminologies can enable you to understand how to use the application identification feature better.
Application category
Trellix categorizes similar applications into categories. Based on its functions and features, an application could belong to multiple categories. For example, Skype could belong to instant messaging, file sharing, and voice over categories.
Typically, a category consists of applications that you would want to handle in a similar manner. Therefore, categories can reduce the number of Firewall access rules that you would require. For example, you can create a rule to block the webmail category instead of creating separate rules for each webmail application.
Application capability
Using Trellix IPS, you cannot only control specific applications but also specific features of applications. For example, you can block the file transfer feature of Yahoo! Messenger while allowing its other features. To provide such granular control, Trellix creates signatures for some of the critical and common features of applications. These features for which signatures exist are referred to as application capabilities.
Functionally, Trellix IPS treats an application capability as an application itself. This is because application capabilities also can belong to an application category. This category could be different from the category to which the parent application belongs. However, a Firewall access rule for an application may affect a rule written for a corresponding application capability. For example, consider that you have a rule to allow Yahoo! Messenger followed by a rule blocking file transfer through Yahoo! Messenger. Now, a user will be able to use Yahoo! Messenger's file transfer functionality because this traffic matches the first rule that allows Yahoo! Messenger.
Application capabilities are listed along with the applications in the Rule Objects page.
Risk
For you to understand the impact of applications and Application Capabilities on your network, Trellix Advanced Research Center rates them as high, medium, or low risk. Risk is calculated based on the following factors:
Vulnerability of an application or application capability to attacks.
The probability of an application or application capability to deliver malware.