A method for detecting a suspicious packet flow in a packet-switched
network comprises the computer-implemented step of receiving a first
packet in which the SYN bit but not the ACK or RST bit of the packet's
TCP header is set. If a specified first time has elapsed, a packet
counter associated with the destination address of the flow is
incremented. A determination as to whether the packet counter is greater
than a specified threshold values is made. If the packet counter is
greater than the threshold value, a notification message is generated. In
one embodiment, information identifying a packet flow is aggregated to an
aggregation cache based on the destination address of the flow.