The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

DoS attack detection mechanism

Prev Next

Trellix IPS provides an integrated hardware and software solution, which delivers comprehensive protection from known, first strike (unknown), DoS, and DDoS attacks from several hundred Mbps to multi-gigabit speeds.

The Trellix IPS architecture employs a combination of threshold-based, self-learning, profile-based detection techniques to detect DoS and DDoS attacks.

With threshold-based detection, you can configure data traffic limits to ensure your servers will not become unavailable due to overload. These thresholds are selected based on coverage of different DDoS attacks and on the availability of statistics that will help the users to configure them. Meanwhile, self-learning methodologies enable Trellix IPS to study the patterns of network usage and traffic over time; thus understanding the wide variety of lawful, though unusual, usage patterns that might occur during legitimate network operations. The learning algorithm takes into account sudden bursts that is common in all network traffic, and differentiates it from the real onset of DDoS traffic. In addition to learning the intensity behavior, it also learns the correlational behavior of different types of packets, which reliably captures TCP/IP protocol behavior, route configuration, and so on. Highly accurate DoS detection techniques are essential because popular websites and networks do experience legitimate and sometimes unexpected traffic surges during external events, or for a particularly compelling new program, service, or application.

The combination of these two techniques yields the highest accuracy of detection for the full spectrum of DoS and DDoS attacks, when hundreds or even thousands of hosts are co-opted by a malicious programmer to strike against a single victim.

Once DoS/DDoS attacks have been detected, Trellix IPS offers methods to block various types of DoS Attacks.