The attack prevention mechanism of Trellix IPS is very powerful, but may also be difficult to understand. A good analogy is to that of a DNA test. DNA testing allows biology experts to obtain a DNA sample from a member of a species, and use the sample to determine the individual from which the particular sample came. Trellix IPS provides much of the same capability, but oriented toward detecting and accurately identifying network events. As an example, Trellix IPS's detection mechanisms can allow your signature to identify every HTTP traffic flow, every HTTP traffic flow using the GET mechanism, every HTTP traffic flow using GET with /cgi-bin/calendar.pl as the path, and even every GET with that path and a parameter named month with a value of February.
This is why Trellix IPS supports the aggregation of multiple conditions into every attack. Each signature or rule within an attack can be more or less specific so as to identify everything from generic network activity that affects a given platform in a particular way to a specific piece of code that has very specific and identifiable effects. Based on their specificity and severity, signatures and rules are assigned different confidence and severity values.
When a network event occurs that matches an existing attack definition, the rule or signature(s) (generic and specific) within that attack definition may be triggered. When alert throttling is enabled, the Sensor correlates the multiple triggering events automatically to raise a single alert with the highest confidence level.