BIG Intelligent Threat Prevention System

An intelligent defense appliance powered by deep learning and behavioral analytics, designed to inspect network traffic in real time and accurately identify and automatically block known and unknown threats.

Product Overview

The BIG Intelligent Threat Prevention System (IPS) is a next-generation network intrusion prevention system. It combines traditional signature matching with advanced AI deep-learning algorithms to perform deep packet inspection (DPI) on network traffic. Unlike conventional firewalls that rely primarily on passive defense, the system proactively detects and blocks worms, viruses, trojans, DoS/DDoS attacks, SQL injection, XSS, and other network threats in real time.

Intelligent threat detection and prevention system

To address increasingly prevalent zero-day exploits and encrypted-traffic attacks, the system uses behavioral analysis and traffic DNA profiling to deliver highly accurate detection and protection. As an active-defense shield for enterprise networks, it not only blocks attacks precisely but also provides detailed attack-tracing analysis to help safeguard digital transformation initiatives.

Intelligent threat prevention capabilities

Core Capabilities

AI-Powered Detection and Awareness

Integrates threat intelligence and AI models to conduct comprehensive Layer 2 to Layer 7 traffic analysis. Continuously trained machine learning algorithms identify subtle anomalies, malicious-code variants, and unknown attack behavior with a very low false-positive rate.

High-Performance Real-Time Blocking

A dedicated hardware architecture enables microsecond-level threat response and blocking. When a threat is detected, the system can immediately terminate the connection to help protect critical business systems while maintaining low network latency.

Comprehensive Application Protection

The built-in web application protection module helps defend against OWASP Top 10 threats, including SQL injection, XSS, and CSRF, protecting web servers and databases. Botnet detection capabilities also help prevent internal hosts from being compromised.

Encrypted Traffic Visibility

Powerful SSL/TLS decryption capabilities expose hidden threats in encrypted traffic without materially affecting performance. Encrypted traffic fingerprinting can also identify malicious communications without decryption, reducing security blind spots.

Automated Collaborative Defense

The system can integrate with the BIG Security Situation Awareness Platform to automatically receive and execute global defense policies, forming an integrated cloud-network-endpoint defense framework. When a threat is identified at one point, blocking policies can be synchronized across the network in real time.

Compliance Assurance

Supports intrusion-prevention requirements under relevant regulations and standards, including China’s MLPS 2.0 framework. Built-in compliance report templates can automatically generate security operations reports to simplify security audits and compliance checks.

Deployment Scenarios

The BIG Intelligent Threat Prevention System is suitable for complex network environments and provides a robust security barrier for critical information infrastructure.

  • Internet Gateway Protection: Deployed behind an enterprise internet gateway to filter malicious traffic and block intrusion attempts from external sources.
  • Data Center Perimeter Protection: Deployed near a core switch in an IDC environment to protect server clusters from attacks and help prevent data leakage.
  • Internal Network Segmentation: Deployed between different internal security zones, such as office and production networks, to prevent threats from spreading laterally.
  • Branch Connectivity Protection: Deployed at branch access nodes to secure WAN communications and help build a secure SD-WAN environment.

The appliance supports flexible deployment. It can be deployed inline in transparent bridge mode for real-time blocking, or connected in out-of-band mirror mode for detection and alerting only, without changing the existing network topology.

Threat prevention deployment scenarios