Research Article

Integrating Traffics with Network Device Logs for Anomaly Detection

Table 1

Details of the TCP flags.

TCP flagsTCP handshake situation
ACK, URG, FIN, RST values
The destination IP repeatedly responds with ACK = 1
The destination IP only has ACK = 1, SYN = 1 and FIN=1
The source IP only has SYN = 1