A Sensor can be configured to block traffic when statistical anomalies occur. Blocking DoS traffic is more involved than blocking normal exploits because the source is often unclear. For example, the success of a distributed attack might depend on the quantity of compromised hosts generating traffic together, rather than a single host generating a significant volume on its own. This complicates the blocking process because a Sensor cannot merely block hosts that individually generate large volumes of traffic. Moreover, DoS attack tools typically generate traffic with spoofed IP addresses, so attempting to block them gains nothing and wastes resources.
Instead, Trellix IPS classifies source IP addresses as IP profiles to differentiate between good and bad hosts. It then uses these IP profiles to determine a blocking scheme for the Sensor .
Note
The Sensor must be in detection mode to detect and block attacks.
You can block DoS attacks only when the Sensor is deployed in the inline mode.