The invention discloses a DDoS
attack detection method based on a network traffic
application layer. The method comprises the following steps: selecting three parameters including a flow change rate,a new source
IP address change rate and a source
IP address request allocation rate to analyze network flow. Therefore, the DDoS
attack traffic is distinguished from the FC traffic. The
system is provided with a network flow analysis module, a DDoS
attack detection module and an
attack response module. When network flow changes suddenly, the network flow analysis module sends a warning
signal to the DDoS attack detection module. The DDoS attack module is used for judging whether an FC attack or a DDoS attack occurs. When the DDoS attack is detected, the DDoS attack is detected. The
attack response module is activated to filter malicious traffic and maintain uninterrupted service for a real user, the similarity between
application layer DDoS attack traffic and FC traffic can be effectivelyrecognized, main characteristics of the
application layer DDoS attack traffic and FC traffic are selected for distinguishing, the
false alarm rate and the missing report rate are reduced, the cost islow, and application and popularization are facilitated.