Once DoS attacks have been detected, Trellix IPS offers the following methods to block various types of DoS Attacks.
Attack | Recommendation | Comments |
|---|---|---|
TCP SYN | SYN Cookies Statistical Anomaly | You can configure SYN cookies in the Manager to accurately block all attack traffic, while allowing all legitimate traffic. TCP SYN or TCP FIN inbound or outbound attacks can be blocked by configuring the policy to block the TCP SYN or FIN Volume too high attack in both inbound and outbound directions. When used within an enterprise, Firewall access rules can be configured in the Manager to allow traffic only from known sources. Configuring SYN cookies is more effective and deterministic compared to statistical anomaly. |
TCP Full Connect | Connection Limiting with Trellix GTI Integration enabled Statistical Anomaly | You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation, and geo-location. Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective. When used within an enterprise, Firewall access rules can be configured in the Manager to allow traffic only from known sources. |
TCP ACK/FIN/RST | Stateful TCP Statistical Anomaly | This attack can be blocked by setting the TCP Flow Violation to DENY_NO_TCB in the Manager. TCP SYN or TCP FIN inbound or outbound attacks can be blocked by configuring policy to block the TCP SYN or FIN Volume too high attack in both inbound and outbound directions. TCP RST attacks can be blocked by configuring the policy to block the TCP RST Volume too high attack in both inbound and outbound directions. Alternatively, TCP RST flood can be blocked by setting the TCP Flow. Trellix recommends that you use stateful TCP to prevent these attacks. |
DNS Flood | DNS Protect Connection Limiting with Trellix GTI Integration enabled Statistical Anomaly | You can mitigate DNS flood attacks by using DNS spoof protection feature that can be enabled through CLI commands on the Sensor. You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation and geo-location. UDP flood attacks can also be blocked by configuring the policy to block the UDP Packet Volume too high attack in both inbound and outbound directions. Statistical anomaly is based on data learnt over a time window. If performance with TCP is acceptable, use DNS Protect, which is more deterministic. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective. |
UDP Flood | Connection Limiting with Trellix GTI Integration enabled Statistical Anomaly | You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation and geo-location. UDP Flood attacks can be blocked by configuring the policy to block the UDP Packet Volume too high attack in both inbound and outbound directions. Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective. Firewall access rules can be configured in the Manager to block UDP traffic that is not expected to be seen with the network. |
ICMP Flood | Connection Limiting with Trellix GTI Integration enabled Statistical Anomaly | You can define a threshold value to limit the connection rate or the number of active connections from each source. In addition to this, you can also define rules to limit access based on the connection rate, external hosts’ reputation, and geo-location. ICMP Flood attacks can be blocked by configuring the policy to block the ICMP Packet Volume too high and ICMP Echo Request or Reply Volume too high attacks in both inbound and outbound directions. Statistical anomaly is based on data learnt over a time window. For immediate prevention of connection based DoS attacks, Connection Limiting would be more effective. Firewall access rules can be configured in the Manager to block ICMP traffic that is not expected to be seen with the network. |
Non TCP/UDP/ICMP Flood | Statistical Anomaly | Non TCP/UDP/ICMP attacks can be blocked by configuring the policy to block the Non-TCP-UDP-ICMP Volume too high attack in both inbound and outbound directions. |
Exploit DoS attacks | Trellix IPS Signatures | Exploit attacks can be blocked by configuring policies to block the exploit attacks (more than 3000) listed in the IPS Policies, for both inbound and outbound traffic. |
Application Level Flood | Custom Reconnaissance Attack Definition | Use correlated attack definition, which is based on the individual attack definitions. For example, custom attacks that check for URI can be further correlated to test for multiple occurrences in a defined time interval to raise a correlated attack. |
Trellix IPS uses specific methods to prevent DoS attacks. These methods work independently but can also be applied in combination.