You can create custom signature-based attack definitions to prevent exploit based DoS attacks. Using the Custom Attack Editor, you can define correlated attacks using these individual attack definitions. For example, Custom Attacks that check for URI can be further correlated to test for multiple occurrences in a defined time interval to raise a correlated attack. The correlation methods supported are the following:
Brute force
Host sweep
Port scan
Service sweep
Fingerprinting
When traffic passing through the Sensor exceeds the threshold count set for the Custom Reconnaissance Attack within a configured Interval, the Sensor raises an alert to the Manager. You can then opt to take the response actions, such as blocking or quarantining the host.