All DDoS Definitions
DDoS Testing Definition

Mean Time to Detect (MTTD)

Mean time to detect (MTTD) is a metric, one of the timing numbers a thorough DDoS test is built to measure. It is the average elapsed time from the first attack packet to the moment monitoring and detection systems recognize that an attack is under way. MTTD is the front half of total time-to-mitigation: nothing can be filtered until the attack is seen, so detection latency sets the floor on how fast any mitigation, automatic or human, can begin to engage.

Mean time to detect: the front half of time to mitigation attack traffic on the wire MTTD decision + divert scrubbing engaged attack unseen, origin exposed first attack packet detected divert begins Time to mitigation = MTTD + decision + divert; detection latency sets the floor on how fast anything can engage. A test launches a controlled attack and records exactly when alarms first register it, exposing blind spots a slow ramp can hide in. BlackNeuron
Diagram of mean time to detect: the elapsed time from the first attack packet to detection, the front half of total time to mitigation, during which the origin is exposed

Why it matters in DDoS testing

Detection that fires in seconds and detection that fires in minutes produce very different outage durations from the identical attack. MTTD is what turns "we have monitoring" into a measured number rather than an assumption. A test launches a controlled attack and records exactly when alarms, anomaly baselines, or operators first register it, exposing blind spots where a slow-ramp or low-rate flood slips under the detection threshold entirely.

How detection latency factors into overall resilience is examined in DDoS resilience testing.