The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

What is a DoS profile?

Prev Next

A DoS profile is an analysis of network traffic with reference to the normal traffic flow captured during the learning period of a Sensor. A DoS Profile displays the current status of DoS learning mode policies applied to a Sensor, as well as its interfaces and subinterfaces. In DoS learning mode, a profile is built to determine a normal traffic pattern. Once this profile is learned, the Sensor alerts for traffic that is outside of the normal parameters. The profile is continually being built, thus baseline levels adjust over time.

The Manager displays the learning mode status values for the Sensor and each interface, respectively. This is particularly useful if you have changed policy application per interface and you want to determine if the new profile is being built or if it is actively detecting abnormal traffic conditions.

Denial of Service management, profiles, and filters are supported in all individual NS-series Sensor models and individual Sensor models in HA Pair. From 11.1 Update 9 release onwards, this feature is supported in a stack or stack HA setup, at the member Sensor level.

In a stack, each node behaves and learns DoS profiles independently; they learn the DoS profiles based on the traffic each of them processes irrespective of the node in which the traffic ingresses. Since the DoS learning is independent, the resulting actions based on the DoS learning are also independent per node. That is, if a DoS bin in the profile is marked as block in one node, the other node could still forward traffic on the subnets of that bin, till it also learns that subnet to block.

DoS profiles of the selected Sensor are displayed in the DoS Profiles page.

Note

DoS parameters are configured within each IPS policy or by creating a custom DoS policy at the interface or subinterface level.