At the highest level, the Trellix IPS addresses UDP and TCP traffic based on the concept of a flow. Flows are defined by their protocol (either UDP or TCP), source and destination ports, and IP addresses of their endpoints. UDP does not contain the concept of state that TCP does, so the Sensor implements a timer-based flow context for UDP traffic. After dividing traffic into flows, the Sensor makes use of port mapping, or in the case of traffic running on non-standard ports, intelligent protocol identification, to pass each flow to the appropriate protocol parsing mechanism.
It is also worth noting that Trellix IPS provides you with the ability to specify whether your signature will look at the complete flow, one direction of the flow, or restrict itself to data occurring within single packets of the flow. Precise control of this detection window is necessary for accurate detection of attacks.