In the threshold mode, the Sensor monitors the network traffic for packet floods, such as too many IP fragments, transmitting through from a source to a destination as detected within a Sensor interface or subinterface. When configuring the DoS policy or customizing at the interface or subinterface level, you must specify the count and interval rate in seconds, for the threshold attacks you want to detect. The Sensor sends an alert, if configured to do so in the DoS policy, when the traffic exceeds the customized thresholds for an enabled attack. You can also enable a notification for an attack if it warrants special attention. For threshold-based attacks, a Sensor monitors both inbound and outbound traffic.
This method requires that you to fully understand your typical traffic pattern to pick good threshold values; otherwise it can produce false alarms due to traffic fluctuations, such as flash crowds — for example, everyone logging on the network at 9 a.m.— or other legitimate increased traffic.
Note
Although default values are provided for thresholds and intervals, you must configure the actual thresholds and intervals for each DoS threshold mode attack you want to detect. Customization of DoS thresholds works best after researching the current levels to be defended for each DoS threshold. This helps you to determine exactly what counts and intervals are best for protecting your network.
The threshold method involves specifying the count and interval thresholds while configuring a DoS policy in the Manager. When the threshold is crossed, the DoS attack is detected.
Threshold value and interval can be customized in the Manager for threshold attacks, such as:
Inbound Link Utilization (Bytes/Sec) Too High
Too Many Inbound ICMP Packets
Too Many Inbound IP Fragments
Too Many Inbound Large ICMP packets
Too Many Inbound Large UDP packets
Too Many Inbound Rejected TCP Packets
Too Many Inbound TCP Connections
Too Many Inbound TCP SYNs
Too Many Inbound UDP Packets