DoS related alerts are raised when a Sensor detects volume-based DoS attacks, vulnerability based DoS attacks, and attacks by DDoS attack tools. Trellix IPS uses attack signatures to detect communication between many known DDoS attack tools, and also to detect vulnerability-based attacks. Alerts are raised in the Attack Log when such attacks are detected.
In the case of volume-based attacks, Sensor looks for statistical anomalies in short-term and long-term profiles. The Sensor compares the short-term profile against the long-term profile. If there is a significant difference in the traffic levels, an alert is generated, and the Sensor blocks traffic with statistical anomalies if configured to do so.
The Sensor raises an alert when it detects one of two varieties of statistical anomalies:
Categorical or imbalance anomalies
Volume anomalies
Note
Statistical anomalies are the result of an attack when the long-term profiles accurately reflect the normal traffic for a given network. However variations in network traffic, due interventions such as changes in the routing scheme, can cause anomalies. In such cases you must rebuild the profile from scratch using the Rebuild the DoS Profiles (start the learning process from scratch) option in the DoS Data Management page. For more information, refer to the topic Manage DoS profiles.
Categorical (or imbalance) anomalies
Certain types of packets are intrinsically related. Without ICMP echo reply, for example, ICMP echo request would be of little use. Similarly, without FIN and RST, you would be able to begin a TCP connection, but not end it.
Trellix IPS detects two types of categorical anomalies:
ICMP echo anomalies (echo request and echo reply)
TCP control segment anomalies (SYN, SYN ACK, FIN, and RST)
Trellix IPS records the distribution of these types of packets in its long-term profile. A significant change in the distribution of these packet types in the short term is a reliable indication of malicious behavior.
For example, Network A might have 50 echo replies for every 50 echo requests, whereas Network B might have only 40 replies for 60 requests. In this case, the distribution would be 50 percent / 50 percent and 40 percent / 60 percent, respectively. In practice, distribution differs from network to network, but usually maintains a relatively consistent average over an extended period. A sudden and drastic (short-term) change in the distribution of ICMP echo packets or TCP control packets is historically indicative of malicious behavior, if not an outright attack.
Volume anomalies
Trellix IPS also tracks rapid increases in the volume, or intensity, of traffic.
To simplify the analysis of volume anomalies, the self-learning algorithm categorizes all packets into one of the following eight types:
IP fragment
ICMP echo (request and reply)
All other ICMP
UDP
TCP SYN and FIN
TCP RST
Non-TCP/UDP/ICMP
Percentiles
One of the methods that the Trellix IPS uses to deal with volume anomalies is to establish thresholds based on packet rate and burst size for different packet types. Changes to these established thresholds indicate threats and are dealt with accordingly.
To measure volume changes over time, Trellix IPS establishes two percentiles for each of the packet types. For a given packet type, the Sensor looks at the distribution of the following:
Short-term packet rate
Traffic burst size
The Sensor analyzes these distributions to establish thresholds that the short-term averages must not typically exceed. For example, Trellix IPS might determine that, for a given packet type, 95 percent of the short-term profiles averaged a rate of X packets per second or fewer, and a packet size of Y bytes or smaller. When the average rate exceeds X packets per second and the pocket size exceeds Y bytes, Trellix IPS analyzes the significance of change. If the change is significant and matched a threat perception, an alert is raised.
Note
Only one statistical anomaly alert is sent per attack every two minutes.