What is the Threat Intelligence Gateway (TIG)?
High-scale, high-efficiency blocking of known threats at the perimeter, based on reputation: IP/Proto/Port, Domain, URL, TLS cert / JA3. A TIG can consumed and enforce 4+ million Indicators in memory with line-rate performance at 10Gbps+ TIGs are purpose-built devices, with a stateless approach to filtering a stream of traffic. They use intelligence about known threats to make a first-pass triage to filter out threats that can be dealt with automatically. This frees up other security assets (e.g. NGFW), people, and resources to tackle more complex threats. Examples of TIP vendors include Bandura, Centrepedal, Ixia. NETSCOUT Arbor Edge Defense has TIG-like functionality.