A Network Traffic Anomaly Detection Method Based on Cycle Prediction and Learning

An anomaly detection and network traffic technology, applied in the field of network security, can solve problems such as increasing algorithm complexity and predicting false alarm rate, and achieves the effect of avoiding excessive false alarm rate, reducing false alarm rate, and avoiding abnormal false alarm.

CN109768995BActive Publication Date: 2021-08-13STATE GRID GASU ELECTRIC POWER RES INST +2
7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2021-08-13

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
Patent Text Reader

Abstract

The invention discloses a network traffic abnormal detection method based on cyclic prediction and learning, belongs to the field of network security, and solves the problems of increasing the complexity of the algorithm and the prediction false alarm rate in the prior art. Based on the first continuous time period, the invention collects the sampling values ​​of the characteristic indexes in each time period, and performs smooth correction on the time series; The predicted value of the feature indicators in a continuous time period; the predicted deviation rate of the indicator in each time period is calculated based on the predicted value and the sampled value of the feature index in the second continuous time period, and the predicted deviation obtained according to all the predicted deviation rates The positive and negative values ​​of the rate; the abnormality is judged according to the predicted deviation rate of the characteristic index in the continuous time period to be judged and the positive and negative values ​​of the predicted deviation rate. The present invention is used for detecting abnormality of network traffic.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention discloses a network traffic anomaly detection method based on cyclic prediction and learning, which is used for detecting network traffic anomalies and belongs to the field of network security. Background technique

[0002] With the continuous development of the Internet, the scale of the network is expanding day by day, and the number of network services carried by it is gradually increasing. Network security has become a growing concern. Abnormal network traffic refers to the network traffic pattern that adversely affects the normal use of the network. Network scanning, DDOS attacks, network worms, malicious downloads, physical link damage, etc. will all cause abnormal network traffic. Abnormal network traffic is often accompanied by serious consequences, such as occupation of network resources, network congestion, resulting in packet loss and increased delay; occupation of device system resources (CPU, memory, etc.), and network facil...

Examples

Embodiment

[0060] The present invention uses hardware probes to collect data traffic. The network traffic data in this experiment comes from the normal traffic data collected in CERNET in 2017. We select the TCP downstream traffic characteristic index (TCPINBYTES characteristic index) for implementation. The embodiment selects the TCPINBYTES raw data part from 9:42 to 10:30 on November 12, the time period is one minute, and L=10.