Based on the protocol behavior of TCP SYN SYN/ACK pairs
an adaptive detection method is proposed to detect SYN flooding attacks at source-end networks.In this method
the simple moving average algorithm is used to smooth the input statistical data
and the detection threshold is automatically adjusted according to on-line estimations of the mean and variance of the test statistic.Moreover
threshold violations are consecutively cumulated to reduce the disturbance of burst of network abnormalities.Performance analysis and simulation results show the minimum attack traffic that can be detected is about 30% of the legitimate traffic
with the probability of false alarm less than 10
-6
and probability of a miss during the attacks less than 10
-2
under the requirement that the detection delay be within 6 sampling periods.