The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Correct identification — significance subject to user sensitivity (also known as noise)

Prev Next

There is another type of event that you may not be interested in, due to the perceived severity of the event. For example, Trellix IPS will detect a UDP-based host sweep when a given host sends UDP packets to a certain number of distinct destinations within a given time interval. Although you can tune this detection by configuring the threshold and the interval according to their sensitivity, it's still possible that some or all of the host IPs being scanned are actually not live. Some users will consider these alerts as noise, others will take notice because it indicates possible reconnaissance activity. Another example of noise would be if someone attempted an IIS-based attack against your Apache Web server. This is a hostile act, but it will not actually harm anything except wasting some network bandwidth. Again, a would-be attacker learns something he can use against your network: the fact that the attack failed can help him zero in on the type of Web server you use. Users can also better manage this type of events through policy customization or installing ignore rules.

The noise-to-incorrect-identification ratio can be fairly high, particularly in the following conditions:

  • The configured policy includes many Informational alerts, or scan alerts which are based on request activities (such as the Default Testing and Default Exclude Informational)

  • Deployment links where there is much hostile traffic, such as in front of a firewall

  • Overly coarse traffic VIDS definition that contains disparate applications. For example, a highly aggregated link in dedicated interface mode

Users can effectively manage the noise level by defining appropriate VIDS and customize the policy accordingly. For dealing with exceptional hosts, such as a dedicated pen test machine, ignore rules can also be used.