basically, what smart defense does is going one step further than stateful inspection. It looks "deep" inside the packet to check for virus and the like. Just think of of smartdefense as a scale down version of IDS. You do need to purchase a subscription service to get update. It's a piece of crap, IMHO. If you want good IDS and prevention, I would strongly recommend NetScreen IDP (Intrusion Dectection and Prevention). NetScreen IDP is much better than the new CheckPoint Interspect (IDS).