The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How Trellix IPS -GTI Integration for URL Reputation works

Prev Next

The URL reputation, if enabled, checks the reputation of the URLs in the HTTP and HTTPS header fields present in the layer 7 of the TCP/IP stack.

The Sensor constructs the URLs from the headers of HTTP and HTTPS request and sends them to the cloud based GTI server for a reputation lookup. The GTI server processes the URL reputation request and returns a reputation score to the Sensor. The reputation score indicates the malicious score of the URL. An alert is generated in the Manager if the reputation score exceeds the configured threshold value.

The Sensor constructs the URLs from the following fields:

  • Fields in the HTTP header:

    • HTTP_URI

    • HTTP_HOST

    • HTTP_Referrer

  • Fields in the SSL header:

    • CN field in the SSL certificate. Only first certificate in certificate chain will be scanned.

    • Host-Name field in the SNI extension of the "Client Hello" SSL handshake message

The following image shows the communication between the Sensor, the Manager, and the GTI server for looking up the URL reputation score.

GUID-F490CF07-D614-406F-8574-D612E7C355B7-low.png

A single HTTP(S) request can generate more than one URL reputation lookup in certain scenarios. For example, consider the case where the HTTP request message has the HTTP_REFERER header. In this case, the Trellix IPS performs 2 lookups, one for the HTTP_HOST / HTTP_URI values and another for the HTTP_REFERER value. This provides reputation scores for both the website being visited as well the referrer to the website.

Note

In case of a persistent HTTP traffic, there will be multiple HTTP requests going over the same HTTP connection. The Trellix IPS performs URL reputation lookup for each HTTP request.

The Sensor sends the constructed URLs to the GTI server for lookup but does not hold the packet flow. If the response is received from the GTI server while the flow is active, and the reputation score is equal to or above the configured threshold, an alert is generated. Based on the response action configured for the attack in the Manager, the URL is either blocked or an alert is sent to the Manager.

If blocking is configured for the attack, subsequent packets in the flow are dropped. If the response from the GTI server is received after the flow has terminated, no action is taken on the response. Flow is maintained to the Sensor till it reaches the 2MSL timeout after the closure of the TCP connection through the TCP_FIN handshake.

Note

The 2MSL timeout setting is used in various functions of the Manager. Trellix recommends you to not change the value of the setting as it might impact the behavior of other functions in the Manager.

High-level flow of the URL reputation check

The following flowchart describes the high-level flow of the URL reputation check:

GUID-5C5C7B0F-C666-422C-9452-BD7D666A0B94-low.png

Note

Trellix IPS can have a maximum number of outstanding URL requests to GTI which is equal to 20% of the flow capacity of the Sensor model.