The primary function of a device is to analyze traffic on the selected network segments and to respond when an attack is detected. The device examines the header and data portion of every network packet, looking for patterns and behavior in the network traffic that indicate malicious activity. The device examines packets and matches the packets against the applied policies. These policies determine what attacks to watch for, and how to respond with countermeasures if an attack is detected.
If an attack is detected, a physical or a Virtual IPS Sensor responds according to its configured policy. A Sensor can perform many types of attack responses, including generating alerts and packet logs, resetting TCP connections, “scrubbing” malicious packets, and even blocking attack packets entirely before they reach the intended target.
In addition to its primary function of preventing exploit, recon, and DoS attacks, a Sensor can also do the following:
- Detect malware— A Sensor uses various methods to inspect files being downloaded for embedded malware. If a malware is detected, the Sensor blocks the download and takes further response actions.
- Enforce Firewall access rules— You can define Firewall access rules (similar to ACLs) in the Manager. Then you can configure a Sensor to enforce these rules on your network.
- Provide and facilitate Quality of Service (QoS)— You can configure a physical Sensor to provide QoS using the rate limiting technique. Additionally, a physical Sensor can facilitate Differentiated Services and IEEE 802.1p by differentiating traffic and tagging them accordingly.
- Provide connection limiting services— Based on how you configure, a Sensor can limit the number of connections a host can establish. One of the advantages of connection limiting is that it can minimize connection-based DoS attacks.
- Export NetFlow data— If Network Threat Behavior Analysis (NTBA) is deployed, you can configure a Sensor to export NetFlow data to the NTBA Appliance.