A port scan, an HTTP flood and a botnet, in 9.9 million packets.
| Attack | Flows | Caught | Minutes |
|---|---|---|---|
| Port scan | 158,924 | 99.7% | 13 of 26 |
| DDoS (HTTP flood) | 128,027 | 99.9% | 21 of 21 |
| Botnet (Ares) | 1,966 | 23.9% | 387 of 592 |
- Normal flows wrongly flagged, check-in rule aside
- 22 of 380,557
- Flagged by the check-in rule (one polling server)
- 1,441
- Normal machines with a false alarm that day
- 5 of 7

