TrellixNetwork Security

    Network Security

    Signature-less MVX sandboxing that catches the zero-day the firewall waved through.

    Trellix Network Security sits in the path of internet traffic behind your firewall, IPS, and secure web gateway to catch the advanced, targeted, and evasive attacks those miss. At its core is Multi-Vector Virtual Execution (MVX) — a signature-less dynamic analysis engine — plus machine-learning correlation engines built from thousands of hours of incident response. Faltrox deploys it clientless and operates the alerts.

    Overview

    What Network Security is

    Trellix Network Security sits in the path of internet traffic — behind your firewall, IPS, and secure web gateway — to catch the advanced, targeted, and evasive attacks those defences miss. At its core is Multi-Vector Virtual Execution (MVX), a signature-less dynamic analysis engine that detonates suspicious traffic in a safe virtual environment, plus machine-learning correlation engines built from thousands of hours of incident response.

    It detects zero-day, multi-flow, and other evasive attacks with high accuracy and few false positives, and the SmartVision engine extends that to east-west lateral movement across the network. It deploys clientless with no rules or tuning to get started, in integrated or distributed form, on-premises or in AWS and Azure. Faltrox deploys it and operates the alerts, so strong detection does not require standing up a large operations effort.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Internet Traffic

    Inspects inbound and outbound internet traffic for exploits, malware, and callbacks in real time.

    02

    Multi-OS Endpoints

    Consistent protection for Windows, macOS, and Linux across 160+ analysed file types.

    03

    Lateral Movement

    SmartVision detects suspicious east-west traffic, data exfiltration, and web shells across the network.

    04

    Zero-Day & Evasive Attacks

    The signature-less MVX sandbox catches never-before-seen exploits that signature defences wave through.

    05

    Encrypted Traffic

    Built-in TLS 1.3 decryption on appliances gives visibility into encrypted traffic at no extra licence.

    06

    AWS & Azure

    Available as virtual and public-cloud appliances for cloud internet-access points.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Position

      Deployed behind existing firewall, IPS, and SWG appliances, it inspects the traffic those defences pass as clean.

    2. 02

      Detonate

      The signature-less MVX engine detonates suspicious files, objects, and URLs in a safe virtual environment for a definitive verdict.

    3. 03

      Correlate

      Machine-learning and correlation engines and the SmartVision analytics engine detect obfuscated, targeted, and lateral-movement attacks.

    4. 04

      Validate

      MVX validates alerts from conventional signature matching and applies riskware categorisation to prioritise genuine breaches.

    5. 05

      Respond

      Inline blocking stops attacks, and correlation with Email Security, Network Forensics, and Endpoint Security coordinates containment.

    Capabilities

    Key capabilities

    MVX Engine

    A signature-less, dynamic analysis engine detonates suspicious traffic in a safe virtual environment to catch zero-day, multiflow, and evasive attacks that signature- and policy-based defences never see.

    ML Correlation Engines

    Multiple machine-learning, AI, and correlation engines detect obfuscated and targeted attacks using contextual rules from front-line incident response — covering client-side, server-side, lateral movement, and post-exploitation traffic.

    SmartVision Lateral-Movement Detection

    Detects suspicious east-west traffic from the data centre to remote branches, with data-exfiltration detection, JA3 encrypted-communication identification, web shell detection, and full kill-chain coverage.

    Alert Validation

    MVX validates alerts raised by conventional signature matching and applies riskware categorisation, so genuine breach attempts are separated from adware and spyware and triaged first.

    Built-In TLS 1.3 Decryption

    Optional TLS 1.3 decryption is available on appliances with no additional licence fee, giving visibility into encrypted traffic without a separate purchase.

    Flexible Deployment Modes

    Out-of-band TAP/SPAN monitoring, inline monitoring, inline active blocking, or out-of-band TCP resets — plus active high-availability on selected models for network or device failure.

    Distributed MVX Architecture

    Integrated all-in-one appliances or distributed Smart Nodes with a shared MVX Smart Grid or Trellix Cloud MVX, scaling from one node to thousands with N+1 fault tolerance.

    Portfolio Correlation

    Central Management correlates with Email Security, Network Forensics adds packet capture per alert, and Endpoint Security contains the endpoints Network Security flags.

    Specifications

    Technical detail

    Prevention Throughput
    250 Mbps to 10 Gbps inline blocking
    Integrated Appliances
    50 Mbps to 5 Gbps
    Physical Smart Node
    50 Mbps to 10 Gbps
    Virtual / Public Cloud
    50 Mbps to 8 Gbps (AWS and Azure)
    File Type Analysis
    160+ file types; up to 3,300 unique attachments/hour
    Certifications
    Common Criteria, FIPS 140-2, SOC 2, US DHS SAFETY Act

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Network Security for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01We already have a next-gen firewall and IPS — why add this?

    Network Security is designed to sit behind exactly those and catch what they miss. Firewalls and signature-based IPS stop known attacks; the MVX sandbox catches never-before-seen exploits and evasive malware by detonating suspicious traffic in a virtual environment. It is a different detection method, not a duplicate.

    02Does it require agents or heavy tuning to deploy?

    The integrated appliance is clientless and deploys quickly without rules, policies, or tuning to get started. That is one reason it suits organisations that want strong detection without standing up a large operations effort — which Faltrox then runs on top of.

    03Can it catch attackers already inside the network?

    Yes — the SmartVision engine is built for east-west, server-facing traffic, detecting lateral movement, data exfiltration, and web shells from the data centre out to branch offices, with full kill-chain coverage mapped to MITRE ATT&CK.

    04How does it handle encrypted traffic?

    It offers built-in TLS 1.3 decryption on appliances with no additional licence fee, and JA3 detection in SmartVision for identifying malicious encrypted communication without full decryption.

    05Can we start small and grow without re-buying?

    Yes. It supports cost-free migration from an integrated to a distributed deployment, and the shared MVX Smart Grid or Cloud MVX scales from a single node to thousands, so growth in branches or traffic does not mean replacing what you own.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us