一种基于流聚类的流量异常检测方法、系统、设备及介质

By employing a flow clustering-based approach, real-time incremental clustering, and frequency domain analysis, the problem of relying on attack labels in existing technologies is solved, enabling efficient detection of network traffic in new power systems and identification of zero-day attacks.

CN118432897BActive Publication Date: 2026-07-17CHINA YANGTZE POWER

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA YANGTZE POWER
Filing Date
2024-05-09
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing traffic anomaly detection methods rely on a large number of attack tags, making it difficult to effectively detect zero-day attacks and failing to fully utilize the interactive information between network traffic, resulting in low detection accuracy and low processing efficiency.

Method used

A flow-based clustering method is adopted to obtain the feature vector of network traffic, perform real-time incremental clustering and construct frequency domain feature vectors, and combine density peak clustering and DBSCAN algorithm to determine the anomaly of network traffic.

Benefits of technology

It enables efficient real-time correlation analysis of network traffic, detects zero-day attacks, eliminates the need for a large number of attack tags, and improves detection accuracy and processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118432897B_ABST
    Figure CN118432897B_ABST
Patent Text Reader

Abstract

本发明提供的一种基于流聚类的流量异常检测方法、系统、设备及介质,包括以下步骤:步骤1,获取当前时刻对应的多条网络流量,并提取每条网络流量对应的源I P、目的I P、源端口、目的端口、字节数和时间戳,并组成每条网络流量对应的特征向量;步骤2,根据得到的特征向量将获取得到的当前时刻对应的多条网络流量实时增量聚类至流量簇;步骤3,构建每个流量簇的频域特征向量;步骤4,根据得到的频域特征向量判断当前时刻对应的每条网络流量是否为异常流量;本发明的算法时间复杂度较低,能够实现对新型电力系统信息网络海量流量的实时关联分析,极大的提高了流量分析处理的效率。
Need to check novelty before this filing date? Find Prior Art