The DoS Data Management page enables you to manage the DoS learning mode policies on a Sensor.
Steps:
To open the DoS Data Management page
For individual Sensors, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Denial of Service → Data Management.
For Sensors in HA pair, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <HA Pair Node> → Troubleshooting → Denial of Service → Data Management.
(Applicable to NS9600 and NS9500 only) For Sensors in a stack and a HA pair of stack Sensors, navigate to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Denial of Service → Data Management.
The last DoS profile uploaded from the Sensor to Manager is listed under DoS Profiles on Manager.
Select one action from one of the following headings:
DoS Profile Learning
Rebuild the DoS Profiles (start the learning process from scratch) — Starts the learning process from scratch. The profile that has just been learned is erased, and a new profile is built. To start the learning process, select this option and click Update.
Typically, this is only required when:
It is known that a DoS attack occurred during the initial learning phase, contaminating the long-term profile.
There has been a significant change in network traffic, for example, an overhaul to the routing infrastructure.
Note
When a port runs in learning mode, it does not analyze traffic for DoS attacks. You can infer whether DoS attack has occurred during the initial phase or not by reading situations specific to your network.
Force the IPS Sensor into Detection Mode (bypass learning) — You can force a Sensor into detection mode before the normal 48-hour minimum learning period. This option must be reserved for testing and troubleshooting.
Tip
Trellix recommends performing a re-learn profile when there is a network change, for example if you moved Sensor from a lab environment to a production environment. Re-learning a profile is also recommended if there is a configuration change, that is you changed the CIDR block of a subinterface that causes a significant sudden traffic change to an interface or subinterface for which a profile has already been established (or in the process of initial learning). Without doing so, the Sensor might give false alarms or fail to detect attacks during a time period when it is adapting to the new network traffic conditions.
Important
Changing the learning mode of DOS profiles on one member Sensor automatically applies the same configuration to all other Sensors in a stack and/or stack HA setup, or to the other Sensor in HA setup.
There is no need to re-learn a profile when network traffic increases or decreases naturally over time (for example, an eCommerce site that is getting more and more customers; thus its web traffic increases in parallel) since the Sensor can automatically adapt to it.
DoS Data Management area.png)
DoS Profile Upload and Restoration
In most circumstances, there is no need to upload and restore profiles. The exceptions include:
The Sensor fails to detect an attack. In this case, the Sensor mistakenly learns the bad traffic pattern as good. A previous profile can be restored to replace the contaminated one, if one was saved.
The Sensor is used for testing that skews the long-term profile. To bring the Sensor back in good standing, a profile is saved, the testing is performed, and the previously saved profile is restored.
A change to the quantity of interfaces/subinterfaces is made, but the change needs to be reversed. For example, you add a new subinterface, which also changes the quantity and makeup of DoS profile. You then decide to back out of the change. Restoring a profile eliminates the requirement to go through the re-learning phase.
Note
Rebooting a Sensor does not return it to learning mode. A Sensor stores long-term data and picks up where it left off when the reboot started.
Upload a DoS Profile (device to Manager): Uploads all of the learned profiles on a Sensor's flash to Manager. To upload a Sensor's DoS profiles to Manager, do the following:
Select Upload a DoS Profile (device to Manager).
Click Update. The Upload DoS screen opens with the Upload? field checked by default.
Click Upload DoS Profiles. A pop-up displays upload status.
Click Close Window to close the status window after upload finishes.
Click Data Management to return to the main screen to view your uploaded file. One file is uploaded for all interfaces, subinterfaces, or DoS IDs of a Sensor. This file is listed in the DoS Profiles on Manager section (top) of the table.
Note
You will have to wait at least 48 hours for the first learning profile to finish before you can download a profile.
Uploading a DoS profile from a Sensor to the Manager.png)
Restore a DoS Profile (Manager to device): Downloads a DoS profile to the Sensor that has been previously uploaded (saved) to Manager using the Upload a DoS Profile (device to Manager) option. The uploaded profile is listed under the DoS Profile Upload and Restoration section. To restore a DoS profile, do the following:
Select Restore a DoS Profile (Manager to device).
Click Update.
Select a DoS profile and click Restore.
(Optional) Select a DoS profile and click Delete to delete the profile.
(Optional) Select a DoS profile and click Export to export and save the profile to a client that is not Manager server.
Restoring a DoS profile.png)