The present invention provides a technology including, for example, a
packet relay processing section to carry out packet relay, a packet
sampling section to carry out packet sampling, a flow statistics counting
section to take statistics of each flow, and a flow statistics generating
section to generate a NetFlow export datagram, wherein the flow
statistics counting section collectively counts the number of the packets
or bytes received per unit time when the number does not exceed a
threshold value and individually counts the number for each flow when the
number exceeds the threshold value, and thereby a flow of abnormal
traffic which is suspected to be DoS attack is efficiently detected with
small amounts of resources (mainly memories).