A method and device for all-network target-free intelligent traffic classification DDOS monitoring

By combining machine learning and big data analytics with K-means clustering and random forest classifiers, Netflow traffic is classified in multiple levels, solving the problem that traditional DDoS detection methods cannot adapt to new attack methods and achieving efficient DDoS detection and defense.

CN119382925BActive Publication Date: 2026-06-02CHINA UNITECHS

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITECHS
Filing Date
2024-09-18
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Traditional DDoS detection methods rely on static rules and feature matching, which cannot be updated and adapted to new attack methods in a timely manner, resulting in decreased detection accuracy and slow response speed, making it difficult to effectively monitor untargeted DDoS attacks across the entire network.

Method used

By employing machine learning and big data analytics, and through real-time monitoring and dynamic adjustments, the system utilizes K-means clustering and random forest classifiers to perform multi-level classification of Netflow traffic, identify abnormal traffic and trigger alarms, and update the system in conjunction with the baseline model.

Benefits of technology

It improves the accuracy and response speed of DDoS detection, reduces false alarms and false negatives, enhances the overall network security protection capabilities and operational efficiency, reduces maintenance costs, and ensures the stability and reliability of the entire network service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382925B_ABST
    Figure CN119382925B_ABST
Patent Text Reader

Abstract

The application discloses a method and device for full-network target-free intelligent traffic classification DDOS monitoring, wherein the method comprises the following steps: collecting Netflow traffic sent by a routing device in a full network in real time; after cleaning and normalizing the collected Netflow traffic, extracting feature information thereof, calculating the statistics of the features, and then constructing a baseline model by using an adaptive learning technique according to historical data and traffic patterns; using a K-means clustering algorithm to preliminarily classify the Netflow traffic and identify normal traffic and potential abnormal traffic; using a random forest classifier to further classify the preliminary classification results in detail and accurately identify DDoS attacks in abnormal traffic; combining the classification results with the baseline model to identify DDoS attack traffic, triggering an alarm and executing a defense measure at the same time; and updating the baseline model after the alarm is disposed. The method and device can timely discover abnormal traffic and respond, improving the accuracy and effectiveness of DDoS attack detection.
Need to check novelty before this filing date? Find Prior Art