TrellixNetwork Security

    Intrusion Prevention System

    Signature and signature-less IPS that holds line rate up to 100 Gbps.

    Trellix Intrusion Prevention System (IPS) is a next-generation IDPS that layers multiple signature and signature-less detection engines to block sophisticated malware, DoS, and zero-day attacks across the network. It scales past 30 Gbps in a single device and to 100 Gbps stacked, without the throughput collapse that hits other IPS solutions under strict policy. Faltrox tunes and operates it as part of your managed defence.

    Overview

    What Intrusion Prevention System is

    Trellix Intrusion Prevention System (IPS) is a next-generation intrusion detection and prevention system that layers multiple signature and signature-less detection engines to block sophisticated malware, DoS, and zero-day attacks inline. It moves beyond traditional pattern matching with full protocol analysis, threat reputation, and behavioural analysis, so it stops the stealthy attacks that evade signature-only defences.

    It scales past 30 Gbps in a single device and to 100 Gbps stacked, and — unusually — preserves performance regardless of security settings, where many IPS products lose up to half their throughput under strict policy. It was the first IDPS to combine threat prevention with Layer 7 visibility of over 2,000 applications, and integrates with Trellix Intelligent Sandbox, ePO, and Enterprise Security Manager. Faltrox tunes and operates it as part of your managed defence.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    High-Throughput Networks

    Line-rate inspection from 30 Gbps in one device to 100 Gbps stacked, without a throughput cliff.

    02

    Data Centre & Perimeter

    Inline protection for internet-facing perimeter and east-west data-centre traffic.

    03

    Encrypted Traffic

    Inbound and outbound SSL decryption inspects encrypted flows with no sensor performance impact.

    04

    2,000+ Applications

    Layer 7 visibility of over 2,000 applications and protocols informs what you allow on the network.

    05

    DoS & DDoS

    Threshold, heuristic, and self-learning detection defend availability alongside confidentiality.

    06

    Botnet C2

    DNS/DGA callback detection, sinkholing, and a C2 database break the attacker’s path home.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Inspect

      A single-pass, protocol-based inspection architecture on carrier-class hardware performs deep inspection without collapsing throughput.

    2. 02

      Detect

      Multiple signature and signature-less engines combine full protocol analysis, threat reputation, and behavioural analysis to identify threats.

    3. 03

      Verdict

      Integration with Trellix Intelligent Sandbox validates suspect files, reducing the false alerts that plague signature-only IPS.

    4. 04

      Block

      Confirmed attacks are blocked inline at line rate, with host quarantine and rate limiting for risky hosts.

    5. 05

      Correlate

      Integration with ePO and Enterprise Security Manager adds device, user, and posture context for real-time event correlation.

    Capabilities

    Key capabilities

    Multi-Engine Detection

    Full protocol analysis, threat reputation, and behavioural analysis combine with signature matching to detect malware callbacks, DoS, and zero-day attacks that evade traditional pattern matching.

    Line-Rate Performance

    Single-pass, protocol-based inspection on carrier-class hardware holds real-world inspection up to 100 Gbps, and preserves performance regardless of security settings — where rivals can lose up to 50% throughput under strict policy.

    Application Awareness

    The first IDPS to combine threat prevention with Layer 7 visibility of 2,000+ applications and protocols, so you decide what runs on your network from evidence, not assumption.

    Inbound & Outbound SSL Decryption

    Inspects encrypted traffic with Diffie-Hellman and ECDH cipher support via an agent-based shared-key solution, with no impact on sensor performance and no extra licence.

    Intelligent Sandbox Integration

    Integrates with Trellix Intelligent Sandbox for static code analysis, dynamic malware sandboxing, and machine learning that catches evasive zero-days and ransomware.

    DoS / DDoS Prevention

    Threshold and heuristic detection, host-based connection limiting, and self-learning profile-based detection defend availability alongside confidentiality.

    Botnet & Callback Protection

    DNS/DGA fast-flux callback detection, DNS sinkholing, heuristic bot detection, and a command-and-control database break the attacker’s path home.

    High Availability

    Active-active and active-passive modes with stateful failover, external and built-in fail-open, and disaster recovery of critical configuration — so inline protection does not become a single point of failure.

    Specifications

    Technical detail

    Single-Device Throughput
    More than 30 Gbps
    Stacked Throughput
    Up to 100 Gbps (NS9500 stacking)
    Appliance Series
    NS7500 and NS9500; virtual appliances available
    Application Visibility
    Layer 7 for 2,000+ applications and protocols
    Signatures
    Trellix, user-defined, open-source, and native Snort (NS-series)
    Management
    IPS Manager — tiered management up to 1,000 sensors; RADIUS/LDAP

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Intrusion Prevention System for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01Will turning on full security policy tank our throughput?

    That is the specific weakness Trellix IPS claims to avoid. Its single-pass architecture preserves performance regardless of security settings, where many IPS products lose up to 50% throughput when you prioritise security over speed. You do not have to choose between coverage and line rate.

    02Can it inspect encrypted traffic?

    Yes — inbound and outbound SSL decryption is included, supporting Diffie-Hellman and elliptic-curve ciphers through an agent-based shared-key approach with no sensor performance impact and no additional licence fee.

    03Does it work with our existing Snort rules?

    The NS-series has native support for Snort signatures alongside Trellix, user-defined, and open-source signatures, so existing rule investment carries over rather than being thrown away.

    04How does it scale as our network grows?

    The NS7500 and NS9500 let you buy for today and scale throughput later via a software licence, and you can stack multiple NS9500 appliances to add capacity — up to 100 Gbps — without a forklift replacement.

    05How is this different from Network Security or NDR?

    IPS is inline prevention — it blocks known and signature-detectable attacks at line rate. Network Security adds signature-less MVX sandbox detection behind it, and NDR adds encrypted-traffic detection and response. They layer; Faltrox scopes which combination your traffic and risk profile need.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us