The present invention relates to the field of an
intranet traffic
monitoring system and an IP white
list building method, and aims to provide an IP white
list building method based on
intranet traffic. The method comprises: first capturing the
network data packets communicating between an
intranet and an
extranet; extracting the information in the data packet headers (including the quintet information, the
generation time and data packet sizes); using the information in the data packet headers to form a
network data stream with the
network data packets and at the same time, saving the information of the
data stream in a
database as the basic data to build a white
list; and finally, using the rules proposed by the method of the invention to establish the IP white list, wherein the rules include: judging whether the uplink / downlink ratio of the
data stream satisfies the condition or not; judging whether the number of accessing times by the user of the IPs of the same intranet to the IPs of the external network satisfies the condition for a certain period of time or not; judging whether the number of accessing times by the how many IPs of the intranet to the IPs of the same
extranet in a certain period of time satisfies the condition or not; and judging whether the accessing behavior by IPs of
extranet meets condition or not in a non-working period. Unlike the traditional IP white list building method, the white list can be generated by the method with high efficiency. The calculation cost and
time cost in doing so are low. The generated white list is highly targeted and credible, effectively reducing the data amount required by an internal
network security monitoring system.