The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Where signatures fit

Prev Next

Signatures tie together elements of flows, protocol parsing, and packet search framework to derive specific fingerprints for network traffic from smaller building blocks. In essence, signatures are like DNA tests. They can identify both specific people and relatives of that person. In the intrusion-detection case, the relatives might be a collection of buffer overflow attacks against a certain piece of software, and the particular person would be a specific piece of exploit code.

While the two are not greatly different, Trellix IPS adopts a convention of differentiating between anomaly-based attack signatures (not to be confused with anomaly-based detection for DoS attacks) and signatures pertaining to a specific attack. The main difference is that while anomaly-based signatures examine the network for unexpected or non-conforming behavior, signatures pertaining to specific attacks will often look for a very particular indicator, such as a flag with a particular value, or a specific string's presence. Signature-based anomaly attacks know what to expect in normal traffic, and trigger when they get something else. Normal attack signatures look for specific misbehavior. When defining attacks to detect and protect from vulnerabilities, a blended set of signatures are often defined which check for behavioral anomalies as well as specific exploit strings. Using this mechanism, all possible attempts to exploit the vulnerability can be detected.