Skip to main content
Version: 2.10.1

Appendix 1 - Basic DDoS Attack Types

Attack Types and Indicators​

Attack TypeTextual identifier
Abnormal ICMP traffic1-ICMP
Abnormal TCP traffic1-TCP
Abnormal UDP traffic1-UDP
Abnormal new IP addresses arrival rate2
Abnormal network traffic entropy value3
SYN flood4-SYN
SYN-ACK flood4-SYN-ACK
ACK flood4-ACK
PSH - ACK flood4-PSH-ACK
FIN/RST flood4-FIN/RST
TCP-based application level protocol (e.g. HTTP) flood7-TCP-<protocol>
UDP-based application level protocol (e.g. DNS) flood7- UDP-<protocol>
"Tsunami" SYN flood7-TSU-<protocol>
"Low and Slow" attack9 - LS
TCP SYN flood from a relatively small attacking population1-TCP:4-SYN
TCP SYN-ACK flood from a relatively small attacking population1-TCP:4-SYN-ACK
TCP FIN/RST flood from a relatively small attacking population1-TCP:4-FIN/RST
TCP SYN flood from a large attacking population1-TCP:4-SYN:2
TCP SYN-ACK flood from a large attacking population1-TCP:4-SYN-ACK:2
TCP FIN/RST flood from a large attacking population1-TCP:4-FIN/RST:2
TCP SYN flood from a vast attacking population1-TCP:4-SYN:2:3
TCP SYN-ACK flood from a vast attacking population1-TCP:4-SYN-ACK:2:3
TCP FIN/RST flood from a vast attacking population1-TCP:4-FIN/RST:2:3
UDP flood from a large attacking population1-UDP:2
UDP flood from a vast attacking population1-UDP:2:3
ICMP flood from a large attacking population1-ICMP:2
ICMP flood from a vast attacking population1-ICMP:2:3
Application level TCP flood attack7-TCP-<protocol>:1-TCP
Application level UDP flood attack7-UDP-<protocol>:1-UDP
Application level TCP "Tsunami" flood attack7-TSU-<protocol>:1-TCP