Best Practices In Network Behavior Analysis: Part 2 of 2
Posted in NetFlow on December 5th, 2009 by mike@plixer.comHere is part 1 of this blog.
Detecting DDoS Attacks
A DDos attack is a tricky monster because it can look like legitimate traffic. We have come up with an algorithm for detecting DDoS attacks that from our tests seems to be accurate. We say this because it largely reduces the risk of false positives. It involves flow volumes, byte sizes and standard deviations. Although it is fairly complicated, it will still need modifications as DDoS behavior morphs over time.
Scrutinizer Product Manager
Follow Me on Twitter
