Exploit or vulnerability-based attacks are manifested in attack signatures, which Trellix IPS uses to detect specific exploit attacks.
A signature is a profile of an attack. Detection of specific attacks is possible through signatures. Trellix IPS also uses exploit signatures for DoS attacks that are not caused by traditional means such as volume overload. For example, the HTTP: Microsoft IIS...SLASH... DenialofService exploit identifies a single request that prevents older IIS servers from responding to clients until they are restarted.
The Sensor uses signatures to perform different levels of traffic processing and analysis. Trellix IPS signatures operate on a framework of flows, protocol parsing, and packet searches to detect vulnerability-based DoS attacks and attacks using DDoS attack tools. For example, Trellix IPS's detection mechanisms enable a signature to identify every HTTP traffic flow, every HTTP traffic flow using the GET mechanism, every HTTP traffic flow using GET with /cgi-bin/calendar.pl as the path and even every GET with that path and a parameter named month with a value of February.
Trellix IPS supports the aggregation of multiple signatures into every attack. Each signature within an attack can be more or less specific to identify everything from generic network activity that affects a given platform in a particular way to a specific piece of code that has very specific and identifiable effects. Based on their specificity and severity, signatures are assigned different confidence and severity values.