When configuring an attack object, you can specify the connection
flow of the attack. Using a single flow (instead of Both)
improves performance and increases detection accuracy.
Control (detects the attack in the initial connection
that is established persistently to issue commands, requests, and
so on.)
Auxiliary (detects the attack in the response connection
established intermittently to transfer requested data)
Both (detects the attack in the initial and response connections)