DDOS
Distributed denial of service
- Entity
- DESTINATION
- Window
- 1 s, read against 5 s and 60 s
Counted rate thresholds fire the detector; source-distribution and baseline statistics raise its confidence but never fire it on their own. A flood is attributed to the target rather than to one of the spoofed sources, because a flood spread over 250 sources is one event and attributing it to a single address would scatter the incident.
| Field | Value | Note |
|---|---|---|
| SYN_FLOOD_RATE | syn_rate_1s ≥ 500 and syn_ratio_5s ≥ 0.5 | |
| UDP_FLOOD_RATE | udp_rate_1s ≥ 1000 and udp_ratio_5s ≥ 0.5 | |
| FLOW_RATE_EXCEEDED | flows_per_sec_1s ≥ 1000 | |
| PACKET_RATE_EXCEEDED | packets_per_sec_1s ≥ 20000 | |
| AMPLIFICATION_RATIO | amplification_ratio_5s ≥ 5 and UDP-dominated |
Evidence fields
- unique_src_ips_5s
- src_ip_entropy_5s
- amplification_ratio_5s
- *_baseline_mean
Limit and recorded evidence — DDOS
With no warm baseline the result carries BASELINE_COLD and severity is capped below critical — without a baseline the system cannot claim traffic is abnormal for this host. Under origin-only capture the amplification ratio is unavailable and the detector never fabricates one.
| Field | Value | Note |
|---|---|---|
| Entry gate | flow_count_1s ≥ 20 | A rate computed from a nearly-empty window cannot trigger anything. |
| DISTRIBUTED_SOURCES | ≥ 50 unique sources and ≥ 4 bits of source entropy | Corroboration only — raises confidence, never fires alone. |
| BASELINE_EXCEEDED | Observed ≥ 10× the destination's EWMA baseline | |
| Measured | syn_rate_1s 1 970/s · unique_src_ips_5s 254 · src_ip_entropy_5s 7.99 bits | On a synthetic 250-source SYN flood. Severity HIGH. A measured fixture result, not a capacity claim. |
| Confidence | 0.5 + 0.4 × normalise_exceedance(observed, threshold) | Plus at most 0.10 for corroboration, capped at 0.99. The normaliser is log-scaled, so a 100× flood stays distinguishable from a 4× one. |
Drawn from docs/DETECTORS.md · docs/ALERT_SCHEMA.md