一种基于流聚类的流量异常检测方法、系统、设备及介质
By employing a flow clustering-based approach, real-time incremental clustering, and frequency domain analysis, the problem of relying on attack labels in existing technologies is solved, enabling efficient detection of network traffic in new power systems and identification of zero-day attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA YANGTZE POWER
- Filing Date
- 2024-05-09
- Publication Date
- 2026-07-17
AI Technical Summary
Existing traffic anomaly detection methods rely on a large number of attack tags, making it difficult to effectively detect zero-day attacks and failing to fully utilize the interactive information between network traffic, resulting in low detection accuracy and low processing efficiency.
A flow-based clustering method is adopted to obtain the feature vector of network traffic, perform real-time incremental clustering and construct frequency domain feature vectors, and combine density peak clustering and DBSCAN algorithm to determine the anomaly of network traffic.
It enables efficient real-time correlation analysis of network traffic, detects zero-day attacks, eliminates the need for a large number of attack tags, and improves detection accuracy and processing efficiency.
Smart Images

Figure CN118432897B_ABST