At the highest level, the Sensor addresses UDP and TCP traffic based on the concept of a flow. Flows are defined by their protocol (UDP/TCP), the source and destination ports, and IP addresses of their endpoints. As you might be aware, UDP does not contain the concept of "state" that TCP does. So the Sensor implements a timer-based flow context for UDP traffic. After dividing traffic into flows, the Sensor makes use of port mappings or, in the case of traffic running on non-standard ports, intelligent protocol identification, to pass each flow to the appropriate protocol parsing mechanism.
For a custom attack, you can specify whether the Sensor should look at the complete flow, one direction of the flow, or restrict itself to data occurring within single packets of the flow. Precise control of this detection window is necessary for accurate detection of attacks.