Network flow anomaly detection method

An anomaly detection and network traffic technology, applied in data exchange networks, digital transmission systems, electrical components, etc., can solve problems such as infeasibility, difficulty in simulating traffic data by statistical methods, and difficulty in determining thresholds, resulting in false positives and false negatives. , to achieve the effect of good security, good real-time performance and strong adaptability

Inactive Publication Date: 2020-03-06
NORTH CHINA ELECTRIC POWER UNIV (BAODING) +2
View PDF5 Cites 17 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0013] (1) The SVM algorithm is difficult to implement for large-scale training samples: because SVM uses quadratic programming to solve support vectors, and solving quadratic programming will involve the calculation of m-order matrices (m is the number of samples), when the number of m is very large The storage and calculation of the matrix will consume a lot of machine memory and computing time when it is large
[0014] (2) Traditional traffic modeling based on SVM only considers the modeling of a small number of dimensional features, and cannot adapt to the complex network traffic environment composed of multiple protocols, multiple applications, and multiple types of terminals
[0023] (2) It is difficult to determine the threshold to balance the false positive rate and false positive rate
[0024] (3) This type of method needs to obtain the statistical distribution of traffic data, but at present, the traffic data generated by many abnormal behaviors is difficult to simulate with pure statistical methods
[0025] (4) Most statistical anomaly detection techniques regard normal network behavior as a quasi-static process, and this assumption is not feasible in many network anomaly detection

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Network flow anomaly detection method
  • Network flow anomaly detection method
  • Network flow anomaly detection method

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0078] In order to better understand the present invention, the content of the present invention is further illustrated below in conjunction with the examples, but the content of the present invention is not limited to the following examples.

[0079] The invention provides a network traffic abnormality detection method, which strengthens the network situation security monitoring, improves the automatic security early warning capability, and achieves the purpose of enhancing network security.

[0080] In order to solve the problems of the technologies described above, the technical scheme adopted in the present invention is as follows:

[0081] A network traffic anomaly detection method, the quantitative expression of cyberspace security situation includes the following steps:

[0082] (1) Flow feature collection and situation feature index extraction;

[0083] (2) Adaptive learning and abnormal analysis for situational characteristics;

[0084] (3) Network abnormal situatio...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a network traffic anomaly detection method. Quantitative expression of a network space safety situation comprises the following steps: (1) traffic feature collection and situation feature index extraction; (2) self-adaptive learning and anomaly analysis for situation features are carried out; and (3) detecting and alarming the abnormal situation of the network. The method is realized through a network boundary flow collection and feature depiction index system. According to the method, a plurality of dimension characteristic indexes are continuously mined from network traffic in real time, and network space and traffic characteristics thereof are described in real time; on one hand, real-time or quasi-real-time monitoring, early warning and emergency response requirements of a network situation can be ensured, on the other hand, fine-grained description of network traffic characteristics can be realized through a small log scale, and a high-quality basic information source is provided for subsequent traffic anomaly analysis and detection and safety early warning; compared with a traditional method, the method has obvious advantages in the aspects of real-time performance, description accuracy, data scale and data quality.

Description

technical field [0001] The invention relates to a network traffic abnormality detection method, which belongs to the field of network monitoring. Background technique [0002] Faced with the continuous growth of the current network scale, the increasingly complex network structure, and the diversity and heterogeneity of access network devices, network security issues are becoming more and more important. Anomaly detection in network security event flow is a proactive detection technology, which can not only detect external intrusion behavior, but also detect unauthorized behavior of internal users, which has become a very important part of network security technology. . Existing methods for network anomaly detection include the following: [0003] 1. Support vector machine (SVM) technology: [0004] The support vector machine method is a machine learning method based on the statistical learning theory VC dimension and the principle of structural risk minimum, and seeks th...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/24H04L12/26
CPCH04L41/0631H04L41/142H04L43/08H04L43/16H04L63/1425
Inventor 吴克河李佳玮程瑞李为韩淑宇朱亚运崔文超朱朝阳周亮缪思薇唐志军陈锦山何金栋
Owner NORTH CHINA ELECTRIC POWER UNIV (BAODING)
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products