The integration between Trellix IPS and GTI can be described using the three-part framework shown below.

The top-most tier represents Trellix IPS sending the threat data to GTI. GTI queries the threat data from the Trellix Intrusion Prevention System Sensors that are deployed in real-world settings.
The middle tier represents the bidirectional communications that occurs between Trellix IPS and GTI. Trellix IPS queries the cloud, and the cloud renders the latest reputation or categorization intelligence to Trellix IPS so that it can take an action.
Finally, the bottom tier represents GTI (IP Reputation, URL Reputation, and File Reputation) that ensures threat intelligence services like file reputation, web reputation, URL reputation, web categorization, message reputation, and network connection reputation. GTI Queries the threat data from Trellix IPS Sensors. With each query, the cloud system learns something new about the subject of the query. This information is then combined with data from other threat vectors to understand cyber threats from all angles and identify threat relationships, such as malware used in network intrusions, websites embedded in malware code, websites hosting malware, callback activity associations, and more.
The IP Reputation component of GTI helps in SmartBlocking and Connection Limiting.
SmartBlocking activates blocking when high confidence signatures are matched, thus minimizing the possibility of false positives.
Connection limiting policies consist of a set of rules that enable the Sensors to limit the number of connections a host can establish or a connection rate.
When GTI is enabled, the attacks can be detected both for inbound and outbound traffics.
Inbound traffic is that traffic received on the port designated as "Outside" (that is, originating from outside the network) in In-line or Tap mode. Typically, inbound traffic is destined to the protected network, such as an enterprise intranet.
Outbound traffic is that traffic sent by a system in your intranet, and is on the port designated as "Inside" (that is, originating from inside the network) in In-line or Tap mode.
The IP Reputation is applicable for every connection but it is used differently for inbound and outbound connections:
- For outbound connection– When GTI is enabled for IP reputation, any "High risk IP" based on IP/port will be smart blocked based on the combination of both IP reputation and BTP signature value.
- For inbound connection – When GTI is enabled and Connection Limiting rules are configured, you can block the malicious traffic received on the inbound connections. For example, you can deploy a IPS Sensor in front of a web server, and enable GTI along with Connection Limiting rules to limit access to the server and prevent DoS attacks.