Can Symantec Endpoint Protection detect malicious outbound traffic with Network Intrusion Prevention component?
Last Updated August 31, 2017
You would like to know if SEP (Symantec Endpoint Protection) client can detect and block both inbound and outbound traffic matching IPS signatures.
SEP Network Intrusion Prevention monitors both inbound and outbound traffic.
Monitoring outbound traffic is important since Network Intrusion Prevention can also trigger the Virus and Antispyware Protection to quarantine or delete a process running locally if it initiates malicious traffic matching an IPS signature.
This can be useful also in discovering when a system is infected, not only in case of worms but also for systems sending botnet traffic, downloading other malwares, etc...
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe