Selection of parameter for SYN flood source-end detection

Bo Yang, Xueyuan Wang · 2011

DDoS attack has always been a major threat for information security. Among the DDoS methods, SYN flood is the most common. Having realized the complexity and difficulty in dest-end detection, scholars switched their focus on `source-end detection'. And CUSUM is considered an efficient method in source-end detection. However, now there is no guidance about how to set the parameters in CUSUM, which dramatically affects the outcome of the detection. So this article discusses the selection of this parameter, to provide reference for further research.

Read the paper · More papers on PaperTik