Research Article

OverWatch: A Cross-Plane DDoS Attack Defense Framework with Collaborative Intelligence in SDN

Table 2

Features extracted from different packets.

Packet type#Feature description

TCP1Fraction of TCP packets with SYN flag set
2Fraction of TCP packets with ACK flag set
3Entropy of src IP addresses
4Entropy of dst IP addresses
5Entropy of src ports
6Entropy of dst ports
7Entropy of TCP sequences

UDP8Fraction of dst port 1024 UDP packets
9Fraction of dst port 1024 UDP packets
10Entropy of src IP addresses
11Entropy of dst IP addresses
12Entropy of length for UDP packets

ICMP13Entropy of src IP addresses
14Entropy of dst IP addresses
15Entropy of TTL values
16Fraction of ICMP packets in total