Network port traffic abnormality detection method and system
A technology for traffic anomalies and network ports, which is applied in the field of network port traffic anomaly detection, and can solve problems such as website and equipment loss
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Publication Date
- 2018-09-04
Smart Images

Figure 1 
Figure 2 
Figure 3
Abstract
Description
technical field
[0001] The invention relates to the fields of big data, network security, deep learning, etc., and relates to a method and system for detecting network port traffic anomalies, which uses passive analysis methods of wide area network traffic to discover and profile network abnormal events such as DDoS, botnets, and virus propagation. Background technique
[0002] Today's Internet faces many security threats. For example, Distributed Denial of Service (DDoS, Distributed Denial of Service) attacks have caused serious losses to the websites and devices of many organizations. DDoS refers to the use of client / server technology to combine multiple computers as an attack platform to launch DDoS attacks on one or more targets, thereby multiplying the power of denial of service attacks.
[0003] DDoS attacks are often initiated by a botnet. A botnet is a controlled network of hosts infected with bots. The attacker sends instructions to the zombie host through the co...
Examples
Embodiment Construction
[0076] In order to make the above objects, features and advantages of the present invention more comprehensible, the present invention will be further described in detail in conjunction with the accompanying drawings and specific embodiments.
[0077] The traffic collection module of cNetS is implemented by a high-performance server, loaded with multiple 10 network cards, and runs the DPDK framework to realize high-speed traffic collection. The network traffic is exported by the backbone network router and imported through mirroring. The traffic collection module summarizes the traffic into a NetFlow summary format and outputs it to the cPortMon and cHostMon modules, exports summary fields such as the domain name, source and destination IP, and timestamp for the DNS response packet and outputs them to the cNameMon module, and exports URL, source and destination IP and other summaries for the HTTP request packet The information is output to the cLinkMon module.
[0078] The su...