Research Article

A SYN Flood Attack Detection Method Based on Hierarchical Multihead Self-Attention Mechanism

Table 2

CICDDoS2019 dataset.

FeaturesDescribe

Source/destination portSource/destination port
Flow bytes/sThe number of packet bytes transmitted per second
Flow packets/sThe number of packets transmitted per second
Flow IAT meanAverage rate
Fwd PSH flagsThe number of times the PSH flag is set in a forward transmitted packet
Bwd PSH flagsThe number of times the PSH flag is set in a packet transmitted in reverse
Fwd URG flagsThe number of times the URG flag is set in a forward transmitted packet
Bwd URG flagsThe number of times the URG flag is set in reverse packet
FIN flag countThe number of packages with FIN
SYN flag countThe number of packages with SYN
RST flag countThe number of packets with RST
PSH flag countThe number of packages with PUSH
ACK flag countThe number of packets with ACK
URG flag countThe number of packages with URG
act_data_pkt_fwdPackets with a TCP data payload of at least 1 byte in the forward direction
Active meanAverage time a stream is active before it is idle
Active stdStandard deviation time for a stream to be active before it is idle