The primary function of a device is to analyze traffic on the selected network segments and to respond when an attack is detected. The device examines the header and data portion of every network packet, looking for patterns and behavior in the network traffic that indicate malicious activity. The device examines packets and matches the packets against the applied policies. These policies determine what attacks to watch for, and how to respond with countermeasures if an attack is detected.
If an attack is detected, a physical or a Virtual IPS Sensor responds according to its configured policy. A Sensor can perform many types of attack responses, including generating alerts and packet logs, resetting TCP connections, “scrubbing” malicious packets, and even blocking attack packets entirely before they reach the intended target.
In addition to its primary function of preventing exploit, recon, and DoS attacks, a Sensor can also do the following:
Detect malware— A Sensor uses various methods to inspect files being downloaded for embedded malware. If a malware is detected, the Sensor blocks the download and takes further response actions.
Enforce Firewall access rules— You can define Firewall access rules (similar to ACLs) in the Manager. Then you can configure a Sensor to enforce these rules on your network.
Provide connection limiting services— Based on how you configure, a Sensor can limit the number of connections a host can establish. One of the advantages of connection limiting is that it can minimize connection-based DoS attacks.
Export NetFlow and L7 metadata to Trellix NI— If Trellix Network Investigator (NI) is deployed, you can configure a Sensor to export NetFlow data and L7 metadata to the NI for detection and analysis.
Note
The Sensor generates an auditlog file that is no more than 128MB. The file is purged from the disk when the audit log is uploaded to the Manager and a new auditlog file is started with a start marker.
All the manager-sensor communications happen over TLS.