The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Correct identification — significance subject to user sensitivity (also known as noise)

Prev Next

There is another type of event which you may not be interested in, due to the perceived severity of the event. For example, Trellix IPS will detect a UDP-based host sweep when a given host sends UDP packets to a certain number of distinct destinations within a given time interval. Although you can tune this detection by configuring the threshold and the interval according to their sensitivity, it's still possible that some or all of the host IPs being scanned are actually not live. Some users will consider these alerts as noise, others will take notice because it indicates possible reconnaissance activity. Another example of noise would be if someone attempted an IIS-based attack against your Apache Web server. This is a hostile act, but it will not actually harm anything except wasting some network bandwidth. But the attack attempted can help a would-be attacker to learn something new that they can use against your network (for Example, an attack failed can help zero in on the type of web server you use). Relevance analysis involves the analysis of the vulnerability relevance of real-time alerts, using the vulnerability data imported to Manager database. The imported vulnerability data can be from supported vulnerability scanners such as Nessus. You can better manage this type of events through policy customization or installing attack filters.

The noise-to-incorrect-identification ratio can be fairly high, particularly in the following conditions:

  • The configured policy includes a lot of Informational alerts or scan alerts which are based on request activities (such as the All Inclusive policy).

  • Deployment links where there is a lot of hostile traffic, such as in front of a firewall

  • overly coarse traffic VIDS definition that contains very disparate applications, for example, a highly aggregated link in dedicated interface mode

Users can effectively manage the noise level by defining appropriate VIDS and customize the policy accordingly. For dealing with exceptional hosts, such as a dedicated pentest machine, alert filters can also be used.