Using the Advanced Malware policies, you can prevent DoS attacks that involve malware execution. An Advanced Malware policy is a set of rules that scans the traffic across your network, and determines how to respond to malware detected in the network. An effective policy is one that is customized to the network environment being monitored.
To prevent DoS attacks through botnet, Trellix IPS provides heuristics based Advanced Callback Detection feature to protect customer networks from both known and 0‑day bots. This can be enabled per VIDS for a Sensor. Enable the heuristics based Advanced Callback Detection feature, which detects bot activity by correlating multiple attacks across different flows. Attacks are correlated by observing a host for a given period of time.
In addition to what is explained above, malicious bot command and control servers' activity can be detected. Detecting bot command and control server activity is a key feature of the Advanced Callback Detection. Trellix IPS monitors networks for bot attacks and protects the network by updating the reputation of the newly identified bot masters in the cloud, using Trellix GTI.
For more information on Advanced Malware and Callback Detection features, see the chapters Advanced Malware Detection and Advanced Callback Detection respectively.