The main components on the edge node for north-south malware prevention perform the following functions: - IDS/IPS engine: Extracts files and relays events and data to the security hub North-south malware prevention uses the file extraction features of the IDS/IPS engine that runs on NSX Edge for north-south traffic. - Security hub: Collects file events, obtains verdicts for known files, sends files for local and cloud-based analysis, and sends information to the security analyzer - RAPID: Provides local analysis of the file - ASDS Cache: Caches reputation and verdicts of known files