The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use of traffic normalization

Prev Next

Traffic normalization — available when the system is operating in inline mode — removes any traffic protocol ambiguities, protecting the end systems by cleaning up potentially harmful traffic in real time. Traffic normalization consists of two Sensor techniques: cleaning up malformed packets, and dropping illegal packets, for example, packets where the IP header is smaller than 20 bytes, IP fragments are smaller than 64KB, and so on. Traffic normalization also thwarts any attempts to evade the system while boosting attack detection accuracy. This feature, also known as protocol scrubbing or packet scrubbing, allows Trellix IPS systems to prevent hackers from fingerprinting a host system. Attackers often send abnormal traffic in the hope that the end system responds in a way that allows them to determine what environments and technologies are deployed at a particular site. This makes it easier to launch subsequent attacks against known vulnerabilities in host network hardware or software resources.

Specifically, when enabled, normalization does the following:

  • When the TCP Timestamp option is not negotiated in the SYN/SYN_ACK packet for a connection, but appears in any of the packets for the rest of the connection, the TCP Timestamp is removed from the headers of these packets.

  • The MSS option is permitted only in the SYN/SYN_ACK packets for a TCP connection. If any other packets in the flow contain the MSS option, the Sensor removes it.

In both cases, Trellix IPS performs an incremental checksum of the TCP header and regenerates the CRC integrity check value.

Note

Packet scrubbing must be manually enabled. On the Devices tab, select the Domain, click Devices tab, and select the Sensor. Then, go to Setup → Advanced → Protocol Settings and enable Normalization On/Off Option; dropping of illegal packets is a default Sensor behavior.