A Network Traffic Anomaly Detection Method Based on Cycle Prediction and Learning
An anomaly detection and network traffic technology, applied in the field of network security, can solve problems such as increasing algorithm complexity and predicting false alarm rate, and achieves the effect of avoiding excessive false alarm rate, reducing false alarm rate, and avoiding abnormal false alarm.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Publication Date
- 2021-08-13
Smart Images

Figure 1 
Figure 2
Abstract
Description
technical field
[0001] The invention discloses a network traffic anomaly detection method based on cyclic prediction and learning, which is used for detecting network traffic anomalies and belongs to the field of network security. Background technique
[0002] With the continuous development of the Internet, the scale of the network is expanding day by day, and the number of network services carried by it is gradually increasing. Network security has become a growing concern. Abnormal network traffic refers to the network traffic pattern that adversely affects the normal use of the network. Network scanning, DDOS attacks, network worms, malicious downloads, physical link damage, etc. will all cause abnormal network traffic. Abnormal network traffic is often accompanied by serious consequences, such as occupation of network resources, network congestion, resulting in packet loss and increased delay; occupation of device system resources (CPU, memory, etc.), and network facil...
Examples
Embodiment
[0060] The present invention uses hardware probes to collect data traffic. The network traffic data in this experiment comes from the normal traffic data collected in CERNET in 2017. We select the TCP downstream traffic characteristic index (TCPINBYTES characteristic index) for implementation. The embodiment selects the TCPINBYTES raw data part from 9:42 to 10:30 on November 12, the time period is one minute, and L=10.