Abstract
The Internet carries an expandable amount of information and services, which lead to a huge number of exchange traffic every day. This immoderate scalability brings some disturbance in the network. Flash Crowd attacks which is a DDoS-based attacks, that utilizing legitimate HTTP request
to overwhelm victim resources considered a major disturbing attack to the online services users and providers. The attacker floods the victim with service requests that generated by (DDoS tools). The difficulty to detect the Flash Crowd attacks becomes more when Flash Event is also in present.
For the reason of the alikeness of the two anomalies (Flash Crowd attack and the legitimate Flash Crowd), the attack can fly under the detection system. This proposal aims to present a framework to detect Flash Crowd attacks that run in same time of Flash Crowd event. The purpose of this proposal
is expected to improve the detection method of Flash Crowd Attacks and minimize the false positive and false negative requests.