The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack definitions

Prev Next

Attack definitions tie together elements of the above-described framework to derive specific "fingerprints" for network traffic from smaller building blocks.

In essence, attack definitions are like DNA tests. They can identify both specific people and relatives of that person. In the IPS case, the relatives may be a collection of buffer overflow attacks against a certain piece of software, and the particular person would be a specific piece of exploit code.

While the two are not greatly different, Trellix IPS adopts a convention of differentiating between attacks based on abnormality and attacks based on specific traffic. The main difference is while anomaly-based attack detection process examines the network for unexpected or non-conforming behavior, specific attack definitions will often look for a very particular indicator, such as a flag with a particular value, or a specific string's presence. Anomaly attacks know what to expect in normal traffic, and are triggered when they get something else. Normal attack definitions look for specific misbehavior. The custom attacks that you define must check for behavioral anomalies as well as specific exploit strings. Thus, all possible attempts to exploit a vulnerability can be detected.