The invention discloses a DDoS
attack detecting method and a DDoS
attack detecting
system of a multi-tenant
cloud computing system. The method comprises the following steps: arranging a detecting
server at a control node of a multi-tenant
cloud computing system, and establishing a detecting proxy for each computing node; counting, by the detecting proxy, a number of data packets transmitted by each
virtual machine to different destination IP addresses at an i period of time according to flow data collected at the i period of time; calculating, by the detecting proxy, a flow entropy
variation value of each
virtual machine according to the statistics data, if the flow entropy
variation value transmitted by the
virtual machine I to the destination IP is greater than the set flow entropy variation threshold value, judging the data flow as a suspicious DDoS
attack flow, and transmitting the data flow to the detecting
server; identifying, by the detecting
server, a potential attack flow according to a data destination
IP address, a tenant identifier aggregation destination address and a ratio of an aggregation result in total flow; and if a relative entropy of two potential attack flows is less than a set threshold value, judging as the DDoS attack flow.