My personal opinion is that since UA is defined as untrusted, TEEP architecture cannot make sure its trustworthiness. So in some sense it seems the DOS attack cannot be totally denied. But if we could create secure channel betwen TEE and TAM or use some encryption format like COSE to encode the network data, the server side of this TEE device could discard those malicious network flow. As to TEEP broker, since it is for transparent forwarding and is also not trusted, it maybe not reliable to block malicious traffic.