Flow detection is an enhancement to DDoS protection that supplements the DDoS policer hierarchies. When you enable flow detection by including the flow-detection statement at the [edit system ddos-protection global] hierarchy level, a limited amount of hardware resources are used to monitor the arrival rate of host-bound flows of control traffic. This behavior makes flow detection highly scalable compared to filter policers, which track all flows and therefore consume a considerable amount of resources.
Flows that violate a DDoS protection policer are tracked as suspicious flows; they become culprit flows when they violate the policer bandwidth for the duration of a configurable detection period. Culprit flows are dropped, kept, or policed to below the allowed bandwidth level. Suspicious flow tracking stops if the violation stops before the detection period expires.
This feature is supported on the following products/applications:
MX5
MX10
MX40
MX80
MX104
MX150
MX204
MX240
MX304
MX480
MX960
MX2010
MX2020
MX10003
MX10008
MX10016
vMX
Reference link: https://apps.juniper.net/feature-explorer/feature-info.html?fKey=5690&fn=DDoS+Protection+Flow+Detection