The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

DoS attacks defended against by Trellix IPS

Prev Next

In Trellix IPS, DoS attacks are classified into two main categories based on their design.

Volume-based attacks are largely bandwidth attacks. When a DoS attack is launched, it is detected as a significant change in the statistical composition of the network traffic. For example, a typical network might consist of 70 percent TCP and a 30 percent mix of UDP and ICMP. A significant and unusual variation in the statistical mix is a signal of a new attack.

In a flood attack, server or network resources are exhausted by a flood of packets. Since a single site perpetrating a flood attack can be identified and isolated easily, a more sophisticated approach, a DDoS attack, is used for many flood attacks.

Attacks, such as SYN floods, use packets to exhaust critical server resources to prevent legitimate clients from connecting to the server. A DDoS attack utilizes a number of machines in a coordinated manner. These machines, known as zombies, are machines that have been compromised and are under the attackers’ control. By deploying zombies, hackers can stage large coordinated attacks. As attacks originate from a large number of PCs spread across a wide network, it is extremely difficult to separate legitimate traffic from attack traffic.

The sophistication required and barrier to launch these DDoS attacks has been greatly reduced through the availability of packaged tools that are freely available on the Internet. Some examples of these packaged tools are Tribe Flood Network and Stacheldraht.