A method and device for all-network target-free intelligent traffic classification DDOS monitoring
By combining machine learning and big data analytics with K-means clustering and random forest classifiers, Netflow traffic is classified in multiple levels, solving the problem that traditional DDoS detection methods cannot adapt to new attack methods and achieving efficient DDoS detection and defense.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITECHS
- Filing Date
- 2024-09-18
- Publication Date
- 2026-06-02
AI Technical Summary
Traditional DDoS detection methods rely on static rules and feature matching, which cannot be updated and adapted to new attack methods in a timely manner, resulting in decreased detection accuracy and slow response speed, making it difficult to effectively monitor untargeted DDoS attacks across the entire network.
By employing machine learning and big data analytics, and through real-time monitoring and dynamic adjustments, the system utilizes K-means clustering and random forest classifiers to perform multi-level classification of Netflow traffic, identify abnormal traffic and trigger alarms, and update the system in conjunction with the baseline model.
It improves the accuracy and response speed of DDoS detection, reduces false alarms and false negatives, enhances the overall network security protection capabilities and operational efficiency, reduces maintenance costs, and ensures the stability and reliability of the entire network service.
Smart Images

Figure CN119382925B_ABST