This study proposed a new detection method for DoS attack traffic based on the statistics of arrival rate. We first investigate the statistics of arrival rates of normal packets. Our analytical results show that the arrival rate of normal packets can be can be modeled by normal distribution. We then set up a threshold for maximum arrival rate to detect DoS flood traffic. The experiment results show that the possibilities of both false positives and false negatives are very low. The proposed mechanism is demonstrated to have the capability of detecting DoS attack quickly and accurately.