This paper gives a novel traffic feature for identifying abnormal variation of traffic under DDOS\r\nflood attacks. It is the histogram of the maxima of the bounded traffic rate on an interval-byinterval\r\nbasis. We use it to experiment on the traffic data provided by MIT Lincoln Laboratory\r\nunder Defense Advanced Research Projects Agency DARPA in 1999. The experimental results\r\nprofitably enhance the evidences that traffic rate under DDOS attacks is statistically higher than\r\nthat of normal traffic considerably. They show that the pattern of the histogram of the maxima of\r\nbounded rate of attack-contained traffic greatly differs from that of attack-free traffic. Besides, the\r\npresent traffic feature is simple in mathematics and easy to use in practice.
Loading....