CICFlowMeter icon indicating copy to clipboard operation
CICFlowMeter copied to clipboard

How you executed DRDoS attacks includes NTP, DNS...? Why these attacks in CICDDoS2019 dataset have random ports?

Open theYTQ opened this issue 4 years ago • 1 comments

For example, this is DRDoS_NTP, and its port is not 123. image This is DRDoS_SNMP, and its port is not 161. image

theYTQ avatar Nov 11 '20 04:11 theYTQ

I also see many records with zero SYN FLAG COUNTS in the SYN attack files. Maybe the attack records includes records after the service dies? CICIDS2019 included reflection attack. (NTP/DNS are reflection attacks, probably the reason for random ports.)

Magic-Doufu avatar May 23 '22 02:05 Magic-Doufu