The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS features

Prev Next

The key features of IPS are as follows:

  • Network Security: protection from client-directed HTTP-based malware

  • Network Security with IPS: client and host protection across multiple protocols

  • Automatic correlation and verification of identified threats

  • Detection of reconnaissance activity and brute-force attacks

  • Automatic protection from advanced evasion techniques

Network Security: Protection from client-directed HTTP-based malware

The standard Network Security appliance, without IPS features enabled, protects network clients against malware attacks that use either OS exploits or Web infections as HTTP-based propagation vectors. Using its signature-based and signature-less internal rules engines, the Network Security appliance provides turnkey client vulnerability coverage. The appliance automatically detects HTTP attack vulnerabilities in client systems and applications, detects infected hosts, and blocks unauthorized outbound transmissions across multiple protocols.

The Network Security subsystem builds its database of security content rules in several ways:

Locally generated and custom rules

Based on the Web traffic that the Network Security appliance monitors in your network, the appliance's rules engines continuously expand the appliance's database of organically generated content rules. Each rule specifies a malware fingerprint, criteria for matching the rule to monitored data packets, and the actions that the appliance is to take on matched traffic. You can also create custom rules so that your appliance detects and generates alerts for specific traffic patterns that you identify.

Enterprise-wide rules

If you use FireEye's Central Management System appliance to centrally manage multiple Network Security appliances, Email Security — Server appliances, and security content updates, Network Security content rules are shared among your integrated appliances.

Dynamically generated rules

Using malware intelligence information shared by customers that connect to FireEye's Dynamic Threat Intelligence (DTI) cloud, FireEye analyzes code for malicious intent and creates a fingerprint of all confirmed malware. If you enable a network connection from your Network Security appliance to the DTI cloud, FireEye automatically pushes dynamically generated content rules to your appliance in real time.

Note

All FireEye appliances can download security content, software updates, and software patches from the FireEye DTI cloud. You can also choose to send anonymized threat intelligence information from the Network Security appliance to the global subscriber base via the DTI cloud.

The patented Multi-Vector Virtual Execution (MVX) engine, the core of all FireEye platforms, accurately confirms zero-day and targeted advanced persistent threat (APT) attacks. The threat verification performed by the MVX engine enables the standard Network Security appliance to protect your client systems against known malware as well as zero-day malware attacks, while triggering near-zero false positive alerts.

Network Security with IPS: Client and host protection across multiple protocols

IPS features extend the Network Security appliance's scope of protection beyond client-centric HTTP-based malware. IPS features use signature-based content rules to detect client-centric and server-centric attacks over multiple protocols. To activate IPS processing, you apply a set of IPS security content rules to the network traffic that passes through the monitoring interfaces. The characteristics of the security content rules applied at an interface are determined by the IPS policy you select for that traffic flow.

IPS features include a set of default IPS policies that specify basic IPS rule-selection criteria. The default policies support initial baseline profiling and all basic deployment scenarios. As an option—based on the profile of IPS alerts triggered, the content of your Web traffic, and your corporate Web use policies—you can create custom IPS policies to fine-tune the selection of IP rules applied to your network traffic.

The default IPS policies select IPS rules using the following criteria:

  • Attack target (client, server, or both) to which the IPS rule applies

  • Attack severity level range (1 ‑ 10 or smaller) to which the IPS rule applies

A custom IPS policy enables you to specify fine-grained criteria for selecting IPS rules:

  • Additional match criteria (attack protocol, category, or category and subcategory)

  • Explicit exclusion or inclusion of specific rules based on signature ID

Just as you can with standard Network Security content rules, you can share dynamically created IPS rules across centrally managed Network Security appliances in the enterprise. Similarly, you can automatically download dynamically created IPS rules to the appliance database. You can also enable a global option that automatically re-evaluates active IPS policies against new IPS rules and then adds matched new rules at the active monitoring interfaces.

Automatic correlation and verification of identified threats

To minimize false positive alerts, an IPS-enabled platforms verifies IPS events (threats detected by IPS rules) by using event correlation and aggregation algorithms. The algorithms compare the characteristics of client-targeted IPS events against those of attacks verified by standard Network Security features. When an algorithm correlates an IPS event with an MVX-verified malware alert, the platform generates an IPS alert for the IPS event.

The platform inspects the other IPS events in the MVX engine, using the same vulnerability execution environment as the original session that contained the matched traffic. If the result of MVX verification shows the IPS event to be non‑malicious, the platform categorizes the even as non-attack.

Detection of reconnaissance activity and brute-force attacks

The IPS-enabled platform can detect reconnaissance activity and brute-force attacks.

The IPS-enabled rules engine uses IPS brute-force rules to detect repeated failed login attempts. The engine also detects common password-stealing and password-guessing mechanisms, such as dictionary attack. When a brute-force attack is found, the platform triggers a brute-force event.

An IPS-enabled platform can detect reconnaissance activity in progress early in the threat life cycle before intruders gain a full understanding of your network. The platform detects ping sweeps and port scans that target ports, hosts, or networks. When suspicious activity reaches a threshold, the platform triggers a ping sweep event or a port scan event.

Automatic protection from advanced evasion techniques

Persistent, well-funded attackers commonly use advanced evasion techniques (AETs) to bypass firewalls and network intrusion detection systems and gain undetected access to target systems. An AET combines several different known evasion methods to create a new hacking method. It works by subdividing malicious code and then sending the fragments, disguised, across multiple protocols. Signature-based content rules alone are not effective against AETs.

When deployed inline, an IPS-enabled platform prevents exploits and attacks that have been disguised by AETs. Before the platform applies policy-selected signature rules to your monitored traffic, its IPS-enabled rules engine preprocesses the traffic, detecting instances of AETs and modifying the content to normalize the disguised threats.

An inline-deployed IPS-enabled platform with monitoring interfaces configured for inline blocking prevents network attacks disguised by the following advanced evasion techniques that attempt to bypass signature rules:

IP fragmentation attack

IP packet stream preprocessing within the IPS-enabled rules engine reassembles IP fragments into proper packet sequences based on a Windows-specific endpoint behavior.

Note

On a standard Network Security appliance, detection and normalization of IP fragmentation attacks is performed by preprocessing within the appliance's signature rules engine.

TCP stream segmentation

TCP packet stream preprocessing within the IPS-enabled rules engine reorders and reassembles TCP segments into proper packet sequences based on a Windows-specific endpoint behavior.

Note

On a standard Network Security appliance, detection and normalization of TCP segmentation attacks is performed by preprocessing within the appliance's signature rules engine.

HTTP URL obfuscation

HTTP preprocessing within the IPS-enabled rules engine performs URL decoding in order to detect and normalize HTTP URLs that employ the following encoding techniques:

• Hexadecimal, binary, DWORD, and octal encoding

• Escape encoding

• Unicode encoding

• UTF-8 encoding

• Path character transformations and expansions

HTML encodings

HTML preprocessing within the IPS-enabled rules engine detects and normalizes malicious HTML documents that use the following techniques:

• Chunked encoding

• GZIP compression

• Base 64 character encoding of binary data