Overview
Deep Security IPS (host-based) protects individual workloads (EC2, on‑prem servers, VMs, containers) at the OS/application layer. It blocks exploits at the host, applies virtual patching to shield known vulnerabilities, and enforces workload-specific policies with minimal performance impact. Ideal for east‑west traffic, legacy/patch‑constrained systems, and environments needing workload-level compliance and forensics.
Cloud IPS (network-based) delivers one‑click, natively integrated IPS rule groups via AWS Network Firewall, applying partner‑managed rules across VPC boundaries without appliances or routing changes. It reduces operational overhead, scales with traffic, and provides continuously updated protections at the network perimeter and central inspection points. Best for north‑south traffic, multi‑account VPCs, and teams seeking fast time-to-protection with managed rules.
Use cases
Network Security
Network and application security teams have particular protection and compliance requirements. With Network Security solutions, teams can create a secure infrastructure for devices, applications, users, and partners. Achieving the protection needs for workloads in a secure environment.
Continuous Monitoring
Deep Security and Cloud IPS deliver advanced IPS and HIPS to continuously validate cloud security controls and harden mission‑critical workloads. With real-time exploit detection, virtual patching, and integrity enforcement, they provide proactive protection across hosts and network traffic, helping agencies reduce risk, stop threats early, and maintain operational readiness in the cloud.
Cloud Workload Protection Platform (CWPP)
Deep Security and Cloud IPS empower customers to accelerate their cloud strategy with scalable, proactive intrusion prevention and workload protection on AWS. This is ideal for organizations that need to strengthen compliance, stop advanced threats, and confidently unlock faster, more secure cloud growth.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Products included
Features and programs
Financing for AWS Marketplace purchases
Pricing
Custom pricing options
Integration guide
Cloud IPS is natively integrated with AWS Network Firewall as partner‑managed rule groups you subscribe to via AWS Marketplace; activation happens directly in the AWS console with no appliances or routing changes, and usage is metered per GB inspected across supported regions (mapped by rule group ARNs and Marketplace API Identifier dimensions). Deep Security IPS integrates at the host layer via a lightweight agent on EC2/VMs/containers, providing virtual patching and workload‑level IPS; it exposes REST APIs and integrates with tooling like SIEM/DevOps pipelines to centralize policy and compliance reporting across hybrid environments.