Research Article

A Traffic Cluster Entropy Based Approach to Distinguish DDoS Attacks from Flash Event Using DETER Testbed

Table 5

Comparative analysis of source and traffic cluster entropy for normal, flash, and attack traffic.

Source address entropy rangeTraffic cluster entropy rangeTraffic received by server

Normal traffic 3.815607–4.1259172.728398–2.772241210 kbps–260 kbps
Normal traffic with UDP and TCP attacks3.815607–6.3788212.714725–5.526648400 kbps–440 kbps
Flash traffic5.290918–5.7218892.701708–2.776293375 kbps–450 kbps