Malicious traffic detection method

By extracting network traffic data and calculating detection characteristics, and using detection algorithms for analysis, the problem that existing malicious traffic detection methods are difficult to identify malicious traffic in complex network environments is solved, and more accurate malicious traffic identification and network security guarantee are achieved.

CN120034364APending Publication Date: 2025-05-23LIAONING UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510114145.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing malicious traffic detection methods are difficult to keenly capture subtle changes in traffic characteristics when facing complex network environments, and are prone to misjudgment or misjudgment, resulting in potential huge threats to network security.

Method used

By extracting network traffic data, the detection characteristics of malicious traffic are calculated, such as the cross entropy of recent traffic, the average packet size of recent packets, and the average packet time interval of recent packets are analyzed using detection algorithms, including the most recent variance, median and distance calculations, to accurately identify malicious traffic.

Benefits of technology

It realizes accurate identification of malicious traffic in complex network environments, reduces misjudgments and misjudgments, and improves the stability and reliability of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FDA0005257404060000011
    Figure FDA0005257404060000011
  • Figure FDA0005257404060000012
    Figure FDA0005257404060000012
  • Figure FDA0005257404060000013
    Figure FDA0005257404060000013
Patent Text Reader

Abstract

The invention provides a malicious traffic detection method, and belongs to the field of network security. The method comprises the following steps: step 1, extracting flow data for detection; step 2, calculating detection features of malicious traffic for detection by a detection algorithm, wherein the detection features comprise an average traffic size, an average packet size and an average packet time interval; and step 3, detecting existence of malicious traffic through a detection algorithm. According to the method, malicious traffic under a complex network condition can be detected by comprehensively considering the nearest variance, median and distance calculation of characteristics such as the nearest traffic cross entropy, the nearest average packet size, the nearest average packet time interval and the like. Abnormal conditions in the network traffic can be accurately identified from different angles, and safe and stable operation of the network is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A malicious traffic detection method, characterized by: Here are the steps: Step 1: Extract traffic data for detection; Step 2: Calculate the detection features of malicious traffic for detection algorithm, including average traffic size, average packet size, and average packet time interval; Step 3: Detect the presence of malicious traffic through detection algorithms.

2. The malicious traffic detection method according to claim 1, characterized in that: The flow data in step 1 is captured by an agent program through a network interface or a network card, and the data is filtered according to the type of data to be captured and the filtering conditions.

3. The malicious detection method according to claim 1, characterized in that: The detection features in step 2 include: In the sliding window m, each window time slice is divided into n time slices, and the features are calculated as follows: (1) Recent traffic cross entropy: Among them, x i represents the network traffic value in the i-th time slice, α is the attenuation factor. Since the recent traffic in the network traffic has a greater analytical value, the value range of α is from 0 to 1. i =0, then a n-i x i log(x) i )=0; (2) Recent average packet size: Among them, y i represents the average packet size of the network in the i-th time slice, and α is the decay factor, because the recent average packet size in the network traffic has greater analytical value; (3) Recent average packet time interval: Among them, t i It represents the average packet time interval of the network in the i-th time slice, and α is the decay factor, because the most recent average packet time interval in the network traffic has a greater analytical value.

4. The malicious traffic detection method according to claim 1, characterized in that: The calculation process of the detection algorithm in step 3 is as follows: (1) Calculate the nearest variance of the sample: For each sample, calculate the nearest variance of its sample, denoted as nvar(x1),nvar(x2),...,nvar(x m ); The sample variance is calculated as: Among them, x i represents the eigenvalue in the sample, μ i represents the most recent mean of the traffic in the i-th time slice, n represents the traffic sample size, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; The recent mean is defined as follows: Among them, x i represents the eigenvalue in the sample, μ i represents the most recent mean of the traffic in the i-th time slice, n represents the traffic sample size, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; Among them, nvar(x i ) is the nearest variance value of the feature, a i is the weight adjustment parameter; (2) Calculate the median: For each sample in each time slice, divide it into n parts on average, and calculate the median in each part, denoted as med(1), med(2), ..., med(n); The median is the value in the middle of a set of data after sorting them from small to large. To calculate the most recent overall median: multiply all medians by the attenuation factor raised to the power of ni and divide by the number of samples n to get the most recent overall median med_all; The nearest overall median for each feature is calculated as: Among them, med(i) represents the median of each sample, n represents the number of samples, and α is the decay factor, because the most recent traffic in the network traffic has greater analytical value; (3) Calculate the distance: For each median, calculate the distance between the median and the nearest median of the population, denoted as d1, d2, ..., d n ; The distance calculation formula is: d i =|with(i)-with_all| (8) Among them, med(i) represents the median of each sample, and med_all represents the overall median. Among them, d i is the distance between the median of the feature and the nearest median of the population, a i is the weight adjustment parameter, mmed is the median eigenvalue of the current window; (4) Calculate the weight of the most recent traffic using the following formula: Among them, i represents the i-th feature, n represents the sample size, α is the attenuation factor, and a and b are parameter adjustment factors. It is calculated based on the distance between each sample and its corresponding value, which measures the difference between the flow data and the expected flow data; Through the above calculation, if the F value is greater than the threshold, it is considered that malicious traffic has exploded; if the F value is less than the threshold, it is considered that malicious traffic does not exist.