The Trellix Intrusion Prevention System (IPS) is included with the TrellixNetwork Security solution. The Network Security appliance detects known and zero-day attack vulnerabilities in and exploits delivered to client machines in your network via HTTP.
With IPS features activated, the Network Security appliance capabilities expand to detect Web-borne threats that use a variety of protocols to attack clients, servers, or both. Policy-based selection of the security content rules in the appliance's IPS rules database, combined with automatic correlation of detected threats and verified attacks, ensure that IPS alerts point to actionable activity.
Trellix IPS features enable you to deploy a FireEye Network Security network threat prevention platform as a single-device, multiphase solution that protects your network from attacks across multiple protocols. The combination of signature-based and signatureless technologies protects against known and unknown threats, reduces false alerts, and highlights attacks hidden within the noise.