Trellix IPS attack definitions contain an attribute that indicates whether an attack is considered Recommended for Blocking (RFB) by Trellix. A flag may be set in any cloned policy to block on the RfSB attacks within the policy.
The attack signatures within a single attack definition can be composed of several different attacks. Each attack has a different Benign Trigger Probability (BTP) value (ranging from 0 to 7). The attack definition can contain a very specific signature (lower BTP) and a more generic signature (higher BTP). The attack confidence values are inversely related to the Benign Trigger Probability (BTP) values of attack signatures. For example, a BTP value of 2 indicates that there is low possibility of the attack being a false-positive.
If you manually select Enable Blocking or Inherit (Enable Blocking) is selected by default, the Sensor blocks traffic that matches any signature in the attack, regardless of the BTP value of the signature.
If you select Enable SmartBlocking, the Sensor blocks traffic only when the traffic has at least one signature, with BTP value equal to or lower than 2.
You can additionally enable GTI IP Reputation (evaluates the risk of the IP address and port combined) to be used as a factor while Smart Blocking. When this option is enabled, the Sensor considers the GTI reputation of the source while making its blocking decision. If the GTI reputation of the source IP or port is High Risk, the Sensor effectively treats the matched signature as if its BTP was one level lower than it actually is. In such a case, the Sensor treats a matched signature that has a BTP value of 3 as if it had a BTP value of 2, and then evaluate blocking against the threshold. A source with a Minimal Risk IP or port will have no effect on the evaluation.