This paper proposes a terminal sliding mode observer for detecting the anomaly intrusions in TCP/IP networks.
A nonsingular terminal sliding mode manifold and a second-order sliding mode control strategy are designed respectively to make the observer track the fluid-flow model of the TCP/IP behaviors in the router level. The second-order sliding mode technique is utilized to soften the switching control signal, which is used to estimate the queue length dynamics representing a distributed anomaly in the TCP/IP network. The simulations are presented to validate the proposed method.