The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Blocking DoS attacks

Prev Next

A Sensor can be configured to block traffic when statistical anomalies occur. Blocking DoS traffic is more involved than blocking normal exploits because the source is often unclear. For example, the success of a distributed attack might depend on the quantity of compromised hosts generating traffic together, rather than a single host generating a significant volume on its own. This complicates the blocking process because a Sensor cannot merely block hosts that individually generate large volumes of traffic. Moreover, DoS attack tools typically generate traffic with spoofed IP addresses, so attempting to block them gains nothing and wastes resources.

Instead, Trellix IPS classifies source IP addresses as IP profiles to differentiate between good and bad hosts. It then uses these IP profiles to determine a blocking scheme for the Sensor .

Note

  • The Sensor must be in detection mode to detect and block attacks.

  • You can block DoS attacks only when the Sensor is deployed in the inline mode.