A new Sensor runs for its first 48 hours in learning mode. After 48 hours, the Sensor automatically changes to detection mode, having established a baseline of the normal traffic pattern for the network, or a long-term profile. The assumption is that there are no DoS attacks during those first 48 hours.
After moving to detection mode, the Sensor continues to gather statistical data and update its long-term profile. In this way, the long-term profile evolves with the network. The Sensor also builds short time profiles with a time window of a few minutes.
Learning mode profiles can be managed in the DoS Data Management page of the Manager. DoS profile learning can be rebuilt (re-learned) or reloaded at this level. Refer to the topic Manage DoS profiles for more information.
Subinterfaces and individual CIDR hosts within a VLAN tag or CIDR block can be created and protected against DoS attacks with specific learning-mode settings. This is useful in preventing a server in your DMZ or other location from being shutdown by a DoS attack. A separate profile is created for each resource.
The statistical method uses statistical data gathered over a time window to create normal short-term and long-term profiles. DoS attacks are detected when there are anomalies between the traffic pattern in normal profiles and network traffic. Statistical anomalies in traffic are monitored by the Sensor with reference to learned data on normal traffic.
The Sensor uses the following checks and counter checks to ensure accuracy of detection:
Counter profile contamination
Source IP address classification
Note
If there is a change in the routing scheme, Trellix recommends instructing the Sensor to relearn the network so that it can create a new baseline.