Trellix IPS uses binning to detect statistical anomalies and prevent DoS attacks.
The Sensor builds a profile for each tracked packet type in each direction. Within each source IP profile, the entire IP address space is divided into a maximum of 128 mutually exclusive IP address blocks, or bins, much in the same way CIDR addressing divides the address space. Each bin is uniquely identified by a prefix and prefix length (from 2 to 32 bits). An IP address falls into a bin when the first ‘n’ number of bits of the address matches the bin's prefix. The Sensor then associates each source IP address with a particular bin in the appropriate profile.
Each bin has the following two properties:
The percentage of long-term good traffic originating from the source IP addresses that belongs to this bin.
The percentage of the overall IP address space that the IP range in this bin occupies.
With the source IP addresses properly classified, the Sensor can protect a network from DoS attacks. When a statistical anomaly occurs, the Sensor takes the following actions on the source IP profile in question:
The Sensor blocks all packets with source IP addresses in the bins that occupy a large percentage of the IP space, but represent a small percentage of the long-term traffic. This combats attacks that are generated with random, wide-ranging, spoofed source IP addresses.
The Sensor blocks all packets with source IP addresses in the bins that occupy a large percentage of the short-term traffic together with a significantly higher percentage of short-term traffic than historically seen. This combats attacks that are initiated from a handful of networks with authentic source IP addresses.
The Sensor does not block packets with source IP addresses in the bins that occupy a small percentage of the IP space and represent a high percentage of the long-term traffic. This protects against blocking hosts that are known to be good.
The exception to the third criterion is when the traffic also meets the second criterion. In other words, source IP addresses from the good bins are blocked if their short-term traffic level is significantly higher than their peak long-term level. This combats attacks that are initiated from good hosts that have recently been compromised.
Source IP addresses classification is more effective than using devices such as firewalls that limits the rate of SYN packets on the network to block DoS attacks. The key difference in such an approach and Trellix IPS is that a rate-limiting device blocks traffic randomly. Good traffic has the same probability of being blocked as attack traffic. On the other hand, source IP address classification used by Trellix IPS attempts to differentiate good traffic from attack traffic, so attack traffic is more likely to be blocked.
Note
The statistical anomaly method is effective in preventing most attacks; however, there are some chances of false positives.