The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

DoS attack prevention methods

Prev Next

Once DoS attacks have been detected, Trellix IPS offers the following methods to block various types of DoS Attacks.

DoS attack prevention recommendations

Attack

Recommendation

Comments

TCP SYN

SYN Cookies

Statistical Anomaly

You can configure SYN cookies in the Manager to accurately block all attack traffic, while allowing all legitimate traffic.

TCP SYN or TCP FIN inbound or outbound attacks can be blocked by configuring the policy to block the TCP SYN or FIN Volume too high attack in both inbound and outbound directions.

When used within an enterprise, Firewall access rules can be configured in the Manager to allow traffic only from known sources.

Configuring SYN cookies is more effective and deterministic compared to statistical anomaly.

TCP Full Connect

Connection Limiting with Trellix GTI Integration enabled

Statistical Anomaly

You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation, and geo-location.

Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective.

When used within an enterprise, Firewall access rules can be configured in the Manager to allow traffic only from known sources.

TCP ACK/FIN/RST

Stateful TCP

Statistical Anomaly

This attack can be blocked by setting the TCP Flow Violation to DENY_NO_TCB in the Manager.

TCP SYN or TCP FIN inbound or outbound attacks can be blocked by configuring policy to block the TCP SYN or FIN Volume too high attack in both inbound and outbound directions.

TCP RST attacks can be blocked by configuring the policy to block the TCP RST Volume too high attack in both inbound and outbound directions.

Alternatively, TCP RST flood can be blocked by setting the TCP Flow.

Trellix recommends that you use stateful TCP to prevent these attacks.

DNS Flood

DNS Protect

Connection Limiting with Trellix GTI Integration enabled

Statistical Anomaly

You can mitigate DNS flood attacks by using DNS spoof protection feature that can be enabled through CLI commands on the Sensor.

You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation and geo-location.

UDP flood attacks can also be blocked by configuring the policy to block the UDP Packet Volume too high attack in both inbound and outbound directions.

Statistical anomaly is based on data learnt over a time window. If performance with TCP is acceptable, use DNS Protect, which is more deterministic. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective.

UDP Flood

Connection Limiting with Trellix GTI Integration enabled

Statistical Anomaly

You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation and geo-location.

UDP Flood attacks can be blocked by configuring the policy to block the UDP Packet Volume too high attack in both inbound and outbound directions.

Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective.

Firewall access rules can be configured in the Manager to block UDP traffic that is not expected to be seen with the network.

ICMP Flood

Connection Limiting with Trellix GTI Integration enabled

Statistical Anomaly

You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation, and geo-location.

ICMP Flood attacks can be blocked by configuring the policy to block the ICMP Packet Volume too high and ICMP Echo Request or Reply Volume too high attacks in both inbound and outbound directions.

Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective.

Firewall access rules can be configured in the Manager to block ICMP traffic that is not expected to be seen with the network.

Non TCP/UDP/ICMP Flood

Statistical Anomaly

Non TCP/UDP/ICMP attacks can be blocked by configuring the policy to block the Non-TCP-UDP-ICMP Volume too high attack in both inbound and outbound directions.

Exploit DoS attacks

Trellix IPS Signatures

Exploit attacks can be blocked by configuring policies to block the exploit attacks (more than 3000) listed in the IPS Policies, for both inbound and outbound traffic.

Application Level Flood

Custom Reconnaissance Attack Definition

Use correlated attack definition, which is based on the individual attack definitions. For example, custom attacks that check for URI can be further correlated to test for multiple occurrences in a defined time interval to raise a correlated attack.



Trellix IPS uses specific methods to prevent DoS attacks. These methods work independently but can also be applied in combination.