NS-series Sensors can identify the applications being used in your network and act on them. So, you can allow or block specific applications on your network. For example, you can block just the connections to Facebook from your network while allowing all other HTTP and HTTPS traffic. Using advanced Quality of Service (QoS) policies, you can also control the bandwidth allocated for applications on your network.
In addition to controlling the applications on your network, you can also view the Internet applications that are accessed from your network. Related details such as the network bandwidth consumed by specific applications is now available. You can also check if these applications generated any attacks.
Application identification is used in the following features: Firewall policies involving applications, QoS policies involving applications, and Top Applications (IPS)/(NTBA) monitor. So, to use these features effectively, you need to understand how application identification works.
With respect to the application identification feature of Trellix IPS, the following are referred to as applications:
Network connections over a specific protocol, for example, HTTP, DHCP, and FTP.
A specific computer application accessed over a network, for example, Facebook, Yahoo! Instant Messenger, and Gmail.
Trellix creates signatures for applications based on an ongoing research. This involves creating signatures for applications for which there were no signatures earlier. This also involves removing signatures for invalid and obsolete applications. These application signatures enable the Sensors to accurately detect the applications on your network.
The application signatures are bundled as part of the regular signature set that the Trellix IPS Update Server downloads to the Manager. So, if the Manager is connected to the Trellix IPS Update Server, the application database of your Trellix IPS remains up-to-date.