Malicious traffic detection method
By extracting network traffic data and calculating detection characteristics, and using detection algorithms for analysis, the problem that existing malicious traffic detection methods are difficult to identify malicious traffic in complex network environments is solved, and more accurate malicious traffic identification and network security guarantee are achieved.
Patent Information
- Application Number
- CN202510114145.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-23
AI Technical Summary
Existing malicious traffic detection methods are difficult to keenly capture subtle changes in traffic characteristics when facing complex network environments, and are prone to misjudgment or misjudgment, resulting in potential huge threats to network security.
By extracting network traffic data, the detection characteristics of malicious traffic are calculated, such as the cross entropy of recent traffic, the average packet size of recent packets, and the average packet time interval of recent packets are analyzed using detection algorithms, including the most recent variance, median and distance calculations, to accurately identify malicious traffic.
It realizes accurate identification of malicious traffic in complex network environments, reduces misjudgments and misjudgments, and improves the stability and reliability of network security.
Smart Images

Figure FDA0005257404060000011 
Figure FDA0005257404060000012 
Figure FDA0005257404060000013
Abstract
Claims
1. A malicious traffic detection method, characterized by: Here are the steps: Step 1: Extract traffic data for detection; Step 2: Calculate the detection features of malicious traffic for detection algorithm, including average traffic size, average packet size, and average packet time interval; Step 3: Detect the presence of malicious traffic through detection algorithms.
2. The malicious traffic detection method according to claim 1, characterized in that: The flow data in step 1 is captured by an agent program through a network interface or a network card, and the data is filtered according to the type of data to be captured and the filtering conditions.
3. The malicious detection method according to claim 1, characterized in that: The detection features in step 2 include: In the sliding window m, each window time slice is divided into n time slices, and the features are calculated as follows: (1) Recent traffic cross entropy: Among them, x i represents the network traffic value in the i-th time slice, α is the attenuation factor. Since the recent traffic in the network traffic has a greater analytical value, the value range of α is from 0 to 1. i =0, then a n-i x i log(x) i )=0; (2) Recent average packet size: Among them, y i represents the average packet size of the network in the i-th time slice, and α is the decay factor, because the recent average packet size in the network traffic has greater analytical value; (3) Recent average packet time interval: Among them, t i It represents the average packet time interval of the network in the i-th time slice, and α is the decay factor, because the most recent average packet time interval in the network traffic has a greater analytical value.
4. The malicious traffic detection method according to claim 1, characterized in that: The calculation process of the detection algorithm in step 3 is as follows: (1) Calculate the nearest variance of the sample: For each sample, calculate the nearest variance of its sample, denoted as nvar(x1),nvar(x2),...,nvar(x m ); The sample variance is calculated as: Among them, x i represents the eigenvalue in the sample, μ i represents the most recent mean of the traffic in the i-th time slice, n represents the traffic sample size, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; The recent mean is defined as follows: Among them, x i represents the eigenvalue in the sample, μ i represents the most recent mean of the traffic in the i-th time slice, n represents the traffic sample size, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; Among them, nvar(x i ) is the nearest variance value of the feature, a i is the weight adjustment parameter; (2) Calculate the median: For each sample in each time slice, divide it into n parts on average, and calculate the median in each part, denoted as med(1), med(2), ..., med(n); The median is the value in the middle of a set of data after sorting them from small to large. To calculate the most recent overall median: multiply all medians by the attenuation factor raised to the power of ni and divide by the number of samples n to get the most recent overall median med_all; The nearest overall median for each feature is calculated as: Among them, med(i) represents the median of each sample, n represents the number of samples, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; (3) Calculate the distance: For each median, calculate the distance between the median and the nearest median of the population, denoted as d1, d2, ..., d n ; The distance calculation formula is: d i =|with(i)-with_all| (8) Among them, med(i) represents the median of each sample, and med_all represents the overall median. Among them, d i is the distance between the median of the feature and the nearest median of the population, a i is the weight adjustment parameter, mmed is the median eigenvalue of the current window; (4) Calculate the weight of the most recent traffic using the following formula: Among them, i represents the i-th feature, n represents the sample size, α is the attenuation factor, and a and b are parameter adjustment factors. It is calculated based on the distance between each sample and its corresponding value, which measures the difference between the flow data and the expected flow data; Through the above calculation, if the F value is greater than the threshold, it is considered that malicious traffic has exploded; if the F value is less than the threshold, it is considered that malicious traffic does not exist.