Research Article

Smart Detection: An Online Approach for DoS/DDoS Attack Detection Using Machine Learning

Table 3

Extracted variables.

#VariableDetail

01ip_protoNormalized protocol number
02ip_len_meanMean of IP length
03ip_len_medianMedian of IP length
04ip_len_varVariance of IP length
05ip_len_stdStand. deviation of IP length
06ip_len_entropyEntropy of IP length
07ip_len_cvCoeff. of variation of IP length
08ip_len_cvqQuantile coeff. of IP length
09ip_len_rteRate change of IP length
10sport_meanMean of src port
11sport_medianMedian of src port
12sport_varVariance of src port
13sport_stdStand. deviation of src port
14sport_entropyEntropy of src port
15sport_cvCoeff. of variation of src port
16sport_cvqQuantile coeff. of src port
17sport_rteRate change of src port
18dport_meanMean of dest. port
19dport_medianMedian of dest. port
20dport_varVariance of dest. port
21dport_stdStand. deviation of dest. port
22dport_entropyEntropy of dest. port
23dport_cvCoeff. of variation of dest. port
24dport_cvqQuantile coeff. of dest. port
25dport_rteRate change of dest. port
26tcp_flags_meanMean of TCP flags
27tcp_flags_medianMedian of TCP flags
28tcp_flags_varVariance of TCP flags
29tcp_flags_stdStand. deviation of TCP flags
30tcp_flags_entropyEntropy of TCP flags
31tcp_flags_cvCoeff. of variation of TCP flags
32tcp_flags_cvqQuantile coeff. of TCP flags
33tcp_flags_rteRate change of TCP flags