<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-015-02-0488</article-id>
      <article-id pub-id-type="publisher-id">29318</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>C.2.0 - General</subject>
          <subject>C.2.3 - Network Operations</subject>
          <subject>G.3 - PROBABILITY AND STATISTICS</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>A New Detection Method for Distributed Denial-of-Service Attack Traffic based on Statistical Test</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Chen</surname>
            <given-names>Chin-Ling</given-names>
          </name>
          <email xlink:type="simple">clchen@mail.npic.edu.tw</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">National Pingtung Institute of Commerce, Pingung, Taiwan</addr-line>
        <institution>National Pingtung Institute of Commerce</institution>
        <addr-line content-type="city">Pingung</addr-line>
        <country>Taiwan</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Chin-Ling Chen (<email xlink:type="simple">clchen@mail.npic.edu.tw</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2009</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>28</day>
        <month>01</month>
        <year>2009</year>
      </pub-date>
      <volume>15</volume>
      <issue>2</issue>
      <fpage>488</fpage>
      <lpage>504</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/D047BF0B-F013-5FF3-9E08-79D2792EDDB4">D047BF0B-F013-5FF3-9E08-79D2792EDDB4</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/7000653">7000653</uri>
      <permissions>
        <copyright-statement>Chin-Ling Chen</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>This study has proposed a new detection method for DDoS attack traffic based on two-sample t-test. We first investigate the statistics of normal SYN arrival rate (SAR) and confirm it follows normal distribution. The proposed method identifies the attack by testing 1) the difference between incoming SAR and normal SAR, and 2) the difference between the number of SYN and ACK packets. The experiment results show that the possibilities of both false positives and false negatives are very low. The proposed mechanism is also demonstrated to have the capability of detecting DDoS attack quickly.</p>
      </abstract>
    </article-meta>
  </front>
</article>
