Flow anomaly detection method based on multi-order Markov chain
A technology of Markov chain and detection method, which is applied in the direction of instruments, character and pattern recognition, digital transmission system, etc., and can solve the problems of limited scope of application and high computing overhead
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0023] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments.
[0024] A network flow is a sequence of packets with the same quintuple over a period of time. Therefore, the behavior of network traffic can be described by packets. The present invention adopts the clustering method to determine the state of each data packet in the network flow and generate a state sequence, the Markov chain of the Markov model is represented by the network flow, and the Markov chain is represented by the state of the data packet in the network flow The state of the traffic, so as to construct the normal behavior profile of the traffic, which can well identify the abnormal network traffic.
[0025] For this reason, the specific embodiment of the present invention proposes a kind of traffic anomaly detection method based on multi-order Markov chain, refer to figure 1 , including the following steps S1-S4:
[0026] S1. Using th...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com