Research Article

Multiple-Features-Based Semisupervised Clustering DDoS Detection Method

Box 1

XML file structure.
<packet>
<section>20</section>//Packet ID
<section>202.77.162.213</section> //Source IP
<section>49212</section> //Source Port
<section>172.16.115.20</section>//Destination IP
<section>23</section>//Destination Port
<section>49212 &gt; telnet [PSH, ACK] Seq=124 Ack=89 Win=33580 Len=1 TSV=190937
TSER=9429952</section>//Payload
</packet>