Distributed denial-of-service (DDoS) flooding attacks are still great threat to the network security, although methodologies and tools have been implemented to combat this problem. In this paper, a variation of Lyapunov exponent is proposed to detect anomalies in network traffic, based on entropy. Experimental results show that our approach outperforms entropy-based method while reflecting relationship between source IPs and destination IPs, which is enabled by the possibility of combining their entropies.