“…The traffic of DDoS flooding attacks launched by a Botnet is quite different from flow crowds. Kong et al [56] identified some statistical features to discriminate DDoS flooding attacks from flash crowds, such as the number of unique source addresses in each interval, the number of increased source addresses in adjacent interval, the average of the number of packets sent by source addresses in each interval, and the standard of the number of packets sent by source addresses in each interval. With these features, traffic is classified by employing some supervised methods.…”