Arbor Sightline / Detection Modelling / 60s Window

Fast Flood
Calculator

Work out whether a Fast Flood alert fires — and exactly how many seconds it takes — from the configured high severity threshold and the observed volume of attack traffic.

Trigger Time = ( High Severity Threshold × 60 ) ÷ Attack Traffic Volume
Input Values
Gbps
Gbps
Scenarios
Result
Awaiting input
Enter a severity threshold and an attack volume.
Trigger Time
—s
Margin in Window
—s
Volume to Breach
—
Cumulative attack traffic against the severity threshold over a 60 second window
Cumulative traffic Threshold volume 60s window close
Breakdown
01 — THRESHOLD

A high severity threshold of 100 Gbps means the destination must receive 6,000 Gb within the 60 second window before the threshold is considered breached.

02 — ACCUMULATION

At an attack traffic volume of 200 Gbps, that same 6,000 Gb arrives after just 30 s.

03 — OUTCOME

Because 30 s falls inside the 60 second window, Fast Flood fires at 30 s instead of waiting for the configured severity duration.

Sensitivity Matrix

How the trigger time moves as the attack traffic volume varies around 200 Gbps, with the severity threshold held at 100 Gbps.

Attack Traffic Volume Δ Trigger Time Margin in Window Fast Flood
Rule of thumb — Fast Flood can only fire when the attack traffic volume exceeds the high severity threshold. At exactly the threshold rate it takes the full 60 seconds; below it, the window closes first.

What Fast Flood does

With Fast Flood enabled, Sightline raises an alert the moment the high severity threshold is breached inside a 60 second window — it does not wait out the configured severity duration.

The threshold is a rate, so the equivalent volume for the window is threshold × 60. Traffic accumulates at the attack rate until it reaches that volume.

Worked example

Severity threshold 100 Gbps, attack traffic 200 Gbps. The window's threshold volume is 6,000 Gb; at 200 Gbps that arrives after 30 seconds, so Fast Flood triggers at 30 s.

If the threshold is not breached within 60 seconds, Fast Flood does not apply — the alert instead raises normally once the configured severity duration elapses.