By analyzing and processing of real-time data packets,real-time ratio of SYN and TCP and rate of UDP and ICMP are computed. Three forms of DDos attack: SYNFlood,UDPFlood,ICMPFlood are detected based on the threshold of system during normal operation. The system automatic counts the received data packets and finds out their sources after three seconds over the threshold. According to the information entropy algorithm,random counterfeit IP attack source or a single attack source is analyzed.
Journal of Hebei Software Institute