The Sensor provides the ability to define threshold values to limit the maximum simultaneous connections to web servers, minimizing connection-based DoS attacks on your network. The number of active HTTP connections coming to the server that are less than or equal to the defined threshold value are allowed, whereas the connections exceeding the threshold are dropped.
The connections to the web servers are limited based on the defined threshold value. The threshold value is defined as maximum simultaneous connections.
After the threshold is defined, the Sensor limits the maximum connections based on the configured values. An alert is sent each time the connections exceed the defined threshold value and excess connections are dropped. This ensures that the web servers do not become unavailable due to overload.
The Sensor provides you with a defense mechanism to recover from a DoS attack. You can configure the option to prevent slow connection web server attacks.
The logic behind this option is that the HTTP protocol is designed for short connections. Five minutes is assumed to be a long time and a connection alive for more than five minutes is assumed to be a slow connection. When this option is enabled, the Sensor sends a TCP reset to clear the 10 percent (of the configured threshold) of the oldest active connections, alive for more than five minutes. This option works only when your web resources are under a DoS attack. For example, if the configured threshold is 10000, then 1000 active connections are closed. If the Sensor finds that there are only 500 connections alive for more than five minutes, then only 500 are closed. This leads to some amount of recovery from a connection flood. The client receives no indication of a connection drop. It appears to be a connection timeout.
Note
Trellix recommends that if your environment requires long term HTTP connections, do not use this option.
To understand the working of the DoS inspection options on the web server side, consider the following scenario where the Sensor is deployed in the inline mode.
Configure the threshold for Maximum Simultaneous Connections Allowed to All Web Servers with a value of 10000.
Enable Slow-Connection Attack Prevention.
Push the configuration changes to the Sensor.
The Sensor monitors the connection requests to the web servers and detects an upsurge of connection requests. Once the connection threshold is reached, the Sensor raises an alert. All connections beyond the configured threshold of 10000 are dropped. You can view the alert details in the Attack Log.
The Sensor scans the active connections and identifies the connections alive for more than five minutes as slow.
The Sensor sends a TCP reset to clear 10 percent of the oldest active connections, that is, 1000 active connections.
Use the
show l7ddosstatcommand to verify the connection details.