Network abnormal traffic detection method and device, electronic equipment and storage medium

By acquiring and analyzing the port traffic information of network equipment, and combining the preset traffic interval for abnormal detection and path identification, the problem of poor network abnormal positioning efficiency in the prior art is solved, and fast and accurate abnormal positioning is achieved.

CN120034466APending Publication Date: 2025-05-23NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510184206.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the prior art, operation and maintenance personnel need to manually discover network abnormalities and troubleshoot and locate them, resulting in poor network abnormality positioning efficiency.

Method used

By obtaining the port traffic information of the network device, abnormal detection is performed in combination with the preset traffic interval of the network device, abnormal traffic type and time are identified, and abnormal traffic paths are identified based on this information.

Benefits of technology

It realizes the rapid and accurate determination of the location and situation of network traffic abnormalities, without manually discovering abnormalities and checking network links, significantly improving the location efficiency of network abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034466A_ABST
    Figure CN120034466A_ABST
Patent Text Reader

Abstract

The invention relates to a network abnormal traffic detection method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining the port traffic information of network equipment, carrying out the anomaly detection based on the port traffic information in combination with a preset traffic interval corresponding to the network equipment, obtaining an abnormal traffic type and abnormal traffic time, and carrying out the detection of the abnormal traffic according to the abnormal traffic time. Target traffic information, a first traffic upper limit number and a first traffic lower limit number corresponding to the first target device are obtained, then abnormal traffic types are adopted, abnormal traffic path identification is carried out in combination with the target traffic information, the first traffic upper limit number and the first traffic lower limit number, and an abnormal traffic path result is obtained; therefore, the position and the condition of the abnormal flow can be quickly and accurately determined through the abnormal flow path result, the purposes of not manually finding the abnormity and checking the network link are achieved, and the problem of poor network abnormity positioning efficiency caused by the fact that the abnormity needs to be manually found in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technology, and in particular to a method, device, electronic device and storage medium for detecting abnormal network traffic. Background Art

[0002] With the development of the Internet, the network has become one of the most important infrastructures for information systems in various industries, and its maintenance quality is directly related to the stable operation of information systems. Once a network fails, all services carried on it will be affected, which will cause significant losses to network operators. In network operation and maintenance, traffic mutations due to network attacks or system anomalies are common network failures. Traditional methods to solve network traffic anomalies usually require maintenance personnel to manually discover network traffic anomalies and check network links according to the specific circumstances of network traffic anomalies to find out the specific abnormal location and cause. This method not only requires maintenance personnel to discover anomalies in a timely manner, but also requires them to check and locate them one by one according to network links, resulting in poor efficiency in locating network anomalies. Summary of the invention

[0003] The present application provides a method, device, electronic device and storage medium for detecting abnormal network traffic, so as to solve the problem of poor efficiency in locating network anomalies in the existing related technologies, which requires operation and maintenance personnel to manually discover anomalies and conduct investigations to locate the abnormal network locations.

[0004] In a first aspect, the present application provides a method for detecting abnormal network traffic, comprising:

[0005] Get port traffic information of network devices;

[0006] Based on the port traffic information, anomaly detection is performed in combination with a preset traffic interval corresponding to the network device to obtain an abnormal traffic type and abnormal traffic time;

[0007] According to the abnormal traffic time, obtaining target traffic information, a first traffic upper limit quantity, and a first traffic lower limit quantity corresponding to a first target device, wherein the first target device is a device having a traffic transmission relationship with the network device;

[0008] The abnormal traffic type is used in combination with the target traffic information, the first traffic upper limit quantity, and the first traffic lower limit quantity to identify the abnormal traffic path and obtain an abnormal traffic path result.

[0009] Optionally, acquiring target traffic information, a first traffic upper limit quantity, and a first traffic lower limit quantity corresponding to the first target device according to the abnormal traffic time includes:

[0010] Obtaining traffic transmission relationship information corresponding to network devices;

[0011] Determine at least one of the first target devices according to the traffic transmission relationship information;

[0012] For each of the first target devices, obtaining historical traffic information, the first traffic upper limit, and the first traffic lower limit corresponding to the first target device;

[0013] The historical traffic information matching the abnormal traffic time is determined as the target traffic information.

[0014] Optionally, the abnormal traffic type is used to identify an abnormal traffic path in combination with the target traffic information, the first traffic upper limit quantity, and the first traffic lower limit quantity to obtain an abnormal traffic path result, including:

[0015] Extracting a first target flow quantity from the target flow information;

[0016] Determine a first target traffic type corresponding to the first target device by using the first target traffic quantity, the first traffic upper limit quantity, and the first traffic lower limit quantity;

[0017] In a case where the first target traffic type matches the abnormal traffic type, determining the first target device as a traffic path device;

[0018] The abnormal traffic path result is generated according to the traffic path device.

[0019] Optionally, generating the abnormal traffic path result according to the traffic path device includes:

[0020] Determining a flow transmission direction between the flow path device and the network device;

[0021] Determining a second target device corresponding to the traffic path device according to the traffic transmission direction;

[0022] Determine a second target flow type corresponding to the second target device based on a second target flow quantity, a second flow upper limit quantity, and a second flow lower limit quantity corresponding to the second target device;

[0023] In the case where the second target traffic type matches the abnormal traffic type, determining the second target device as a traffic path device, and returning to execute the step of determining the traffic transmission direction between the traffic path device and the network device;

[0024] In the case where the second target traffic type does not match the abnormal traffic type, the abnormal traffic path result is generated according to the traffic path device set corresponding to the traffic transmission direction.

[0025] Optionally, generating the abnormal traffic path result according to the traffic path device set corresponding to the traffic transmission direction includes:

[0026] Obtain device port information corresponding to each of the flow path devices in the flow path device set;

[0027] The result is generated based on the device port information, combined with the port traffic information and the abnormal traffic time, to obtain the abnormal traffic path result.

[0028] Optionally, the second traffic upper limit is greater than the second traffic lower limit, and determining the second target traffic type corresponding to the second target device based on the second target traffic amount, the second traffic upper limit, and the second traffic lower limit corresponding to the second target device includes:

[0029] In a case where the first target flow rate is greater than the first flow rate upper limit, determining a preset flow rate abnormal increase type as the target flow rate type;

[0030] When the first target flow quantity is less than the first flow lower limit quantity, a preset flow abnormal reduction type is determined as the target flow type.

[0031] Optionally, performing anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device to obtain an abnormal traffic type and an abnormal traffic time includes:

[0032] Extracting the port flow quantity from the port flow information;

[0033] Determine a preset flow rate upper limit quantity and a preset flow rate lower limit quantity corresponding to the preset flow rate interval, wherein the preset flow rate upper limit quantity is greater than the preset flow rate lower limit quantity;

[0034] In the case where the port flow quantity is greater than the preset flow upper limit quantity, determining the preset flow abnormal increase type as the abnormal flow type;

[0035] In the case where the port flow quantity is less than the preset flow lower limit quantity, determining the preset flow abnormal reduction type as the abnormal flow type;

[0036] In a case where the abnormal traffic type is the abnormal traffic increase type or the abnormal traffic decrease type, a port traffic time corresponding to the port traffic information is acquired, and the port traffic time is determined as the abnormal traffic time.

[0037] In a second aspect, the present application provides a device for detecting abnormal network traffic, comprising:

[0038] An acquisition module is used to obtain port flow information of network devices;

[0039] An anomaly detection module, used to perform anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device, to obtain an abnormal traffic type and abnormal traffic time;

[0040] A target module, configured to obtain target flow information, a first flow upper limit quantity, and a first flow lower limit quantity corresponding to a first target device according to the abnormal flow time, wherein the first target device is a device having a flow transmission relationship with the network device;

[0041] The path identification module is used to use the abnormal traffic type, in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to perform abnormal traffic path identification to obtain an abnormal traffic path result.

[0042] In a third aspect, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;

[0043] Memory, used to store computer programs;

[0044] The processor is used to implement the method for detecting abnormal network traffic as described in any one of the first aspects when executing the program stored in the memory.

[0045] According to a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method for detecting abnormal network traffic as described in any one of the first aspects is implemented.

[0046] The embodiment of the present application obtains the port traffic information of the network device, and performs anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device, to obtain the abnormal traffic type and abnormal traffic time, and based on the abnormal traffic time, obtains the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device, the first target device being a device that has a traffic transmission relationship with the network device, and then uses the abnormal traffic type and in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify the abnormal traffic path, and obtains the abnormal traffic path result; thereby, the location and situation of the traffic anomaly can be quickly and accurately determined through the abnormal traffic path result, so as to achieve the purpose of not having to manually discover anomalies and troubleshoot network links, and solves the problem of poor network anomaly positioning efficiency in the existing related technology that requires operation and maintenance personnel to manually discover anomalies and troubleshoot and locate the network anomaly location, thereby effectively improving the efficiency of locating network anomalies. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 A flowchart of a method for detecting abnormal network traffic provided by an embodiment of the present application;

[0048] Figure 2 A schematic diagram of an application scenario of a method for detecting abnormal network traffic provided in an embodiment of the present application;

[0049] Figure 3 A schematic diagram of another application scenario of a method for detecting abnormal network traffic provided in an embodiment of the present application;

[0050] Figure 4 A schematic diagram of another application scenario of a method for detecting abnormal network traffic provided in an embodiment of the present application;

[0051] Figure 5 A schematic diagram of another application scenario of a method for detecting abnormal network traffic provided in an embodiment of the present application;

[0052] Figure 6 A schematic diagram of the structure of a device for detecting abnormal network traffic provided in an embodiment of the present application;

[0053] Figure 7 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention, not for limiting the scope of protection of the present invention.

[0055] As an indispensable part of informatization, the importance of network maintenance is also increasing. The network is usually built by multiple network devices, such as switches, routers, terminal devices, servers, etc. During the operation and maintenance process, the network may have abnormal traffic due to network attacks or system abnormalities. Traffic abnormality means that the traffic in the network has increased or decreased abnormally. Traffic abnormality will cause data leakage and transmission paralysis of the network operation and maintenance party, thereby causing significant losses to the network operation and maintenance party; therefore, in order to ensure the normal operation of the network, the existing related technologies usually arrange operation and maintenance personnel to manually monitor the network. The specific method of manual monitoring can include manually checking the network operation status and promptly discovering traffic abnormalities.

[0056] Although manual monitoring of the network by operation and maintenance personnel can help discover traffic anomalies, manual monitoring is inefficient and cannot detect and locate traffic anomalies in a timely manner. In addition, as network links continue to expand, the number of network devices that operation and maintenance personnel need to monitor is increasing, resulting in a further reduction in the efficiency of manual monitoring.

[0057] In order to solve the problem of poor efficiency in locating network anomalies in the existing related technologies, which requires operation and maintenance personnel to manually discover anomalies and check network links, the present application provides a method, device, electronic device and storage medium for detecting network abnormal traffic, by obtaining port traffic information of a network device, and performing anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device, to obtain an abnormal traffic type and an abnormal traffic time, and according to the abnormal traffic time, obtain target traffic information, a first traffic upper limit quantity and a first traffic lower limit quantity corresponding to a first target device, wherein the first target device is a device that has a traffic transmission relationship with the network device, and then use the abnormal traffic type, in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify an abnormal traffic path, and obtain an abnormal traffic path result; thereby, the location and situation of the traffic anomaly can be quickly and accurately determined through the abnormal traffic path result, so as to achieve the purpose of not having to manually discover anomalies and check network links, and solve the problem of poor efficiency in locating network anomalies in the existing related technologies, which requires operation and maintenance personnel to manually discover anomalies and check and locate the location of network anomalies, thereby effectively improving the efficiency of locating network anomalies.

[0058] Figure 1 A flow chart of a method for detecting abnormal network traffic provided in an embodiment of the present application. The method can be applied to one or more electronic devices such as network equipment, network control systems, etc. In addition, the execution subject of the method can be hardware or software. When the above-mentioned execution subject is hardware, the execution subject can be one or more of the above-mentioned electronic devices. For example, a single electronic device can execute the method, or multiple electronic devices can cooperate with each other to execute the method. When the above-mentioned execution subject is software, the method can be implemented as multiple software or software modules, or as a single software or software module. No specific limitation is made here.

[0059] like Figure 1 As shown, a method for detecting abnormal network traffic provided by an embodiment of the present application may specifically include the following steps:

[0060] Step S110: Obtain port traffic information of the network device.

[0061] Among them, the network device can represent a device with specific network traffic transmission capabilities, such as switches, routers and other devices, and the port traffic information can represent the traffic of data transmitted by a specific port in the network device. For example, the port traffic information can include the port traffic corresponding to each port of the network device. This embodiment does not make specific limitations on this.

[0062] Specifically, the network device in this embodiment may include one or more ports, and the port traffic information may include the traffic transmission corresponding to each port of the network device. For example, network device A includes 5 ports, namely port A1, port A2, port A3, port A4, and port A5. At this time, the port traffic information of the network device may include port traffic X1 corresponding to port A1, port traffic X2 corresponding to port A2, port traffic X3 corresponding to port A3, port traffic X4 corresponding to port A4, and port traffic X5 corresponding to port A5. Of course, the above is only an example, and this embodiment does not make any specific limitations on this.

[0063] Step S120: Based on the port traffic information, anomaly detection is performed in combination with a preset traffic interval corresponding to the network device to obtain the abnormal traffic type and abnormal traffic time.

[0064] Specifically, after obtaining the port traffic information, the preset traffic interval corresponding to the network device can be determined, and the preset traffic difference indicates the interval of pre-configured normal traffic corresponding to the network device; thereby, anomaly detection can be performed based on the port traffic information combined with the preset traffic interval, wherein the anomaly detection can indicate a detection to determine whether there is an anomaly in the traffic represented by the port traffic information, specifically, it can be determined whether the traffic represented by the port traffic information is within the preset traffic interval; when the traffic represented by the port traffic information is not within the preset traffic interval, it means that the current port traffic information is abnormal, and at this time, the abnormal situation of the port traffic information can be analyzed to determine the abnormal traffic type and abnormal traffic time, the abnormal traffic type can indicate the type of abnormality to which the port traffic information belongs, and the abnormal traffic time can indicate the specific time corresponding to the port traffic information.

[0065] Specifically, the abnormal traffic type in this embodiment can be an abnormal traffic increase type or an abnormal traffic decrease type, wherein the abnormal traffic increase type can indicate that the traffic represented by the current port traffic information belongs to an abnormal increase type, and the abnormal traffic decrease type can indicate that the traffic represented by the current port traffic information belongs to an abnormal increase type. Of course, the abnormal traffic type can also include other types, which are not specifically limited in this embodiment.

[0066] Step S130: According to the abnormal traffic time, the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device are obtained, and the first target device is a device that has a traffic transmission relationship with the network device.

[0067] Specifically, after obtaining the abnormal traffic type and abnormal traffic time, the first target device corresponding to the network device can be determined, wherein the first target device can be a device that has a traffic transmission relationship with the network device, that is, the first target device can represent a device that sends traffic to the network device, or a device that receives the traffic output by the network device. After determining the first target device, the target traffic information, the first traffic upper limit quantity, and the first traffic lower limit quantity corresponding to the first target device can be obtained, wherein the target traffic information represents the traffic volume of a specific port in the first target device transmitting data during the abnormal traffic time, the first traffic upper limit quantity can represent the traffic upper limit value of the first target device during normal data transmission, and the first traffic lower limit quantity can represent the traffic lower limit value of the first target device during normal data transmission.

[0068] It should be noted that the method for obtaining the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device may be to obtain the configuration information corresponding to the first target device, the configuration information representing the pre-configured information of the first target device, such as the device identification, device parameters, the first traffic upper limit quantity and the first traffic lower limit quantity, so that the first traffic upper limit quantity and the first traffic lower limit quantity can be extracted from the configuration information; of course, the configuration information corresponding to the first target device can be adjusted according to demand, that is, by adjusting the configuration information of the first target device, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device can be adjusted.

[0069] In addition, in this embodiment, the network device and the first target device are relative, that is, the same specific device can be used as a network device and also as a first target device. For example, the network link includes router A, router B, switch X and switch Y, and the network link relationship is router A→switch X→switch Y→router B. At this time, when detecting switch X, switch X can be used as a network device, and router A and router Y can be used as first target devices. When detecting switch Y, switch Y can be used as a network device, and switch X and router B can be used as first target devices. Of course, the above is only an example for illustration, and this embodiment does not make specific limitations on this.

[0070] Step S140: using the abnormal traffic type, combining the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify the abnormal traffic path, and obtain the abnormal traffic path result.

[0071] Specifically, after obtaining the abnormal traffic type, target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity, the abnormal traffic type can be used in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify the abnormal traffic path and obtain the abnormal traffic path result, wherein the traffic path identification can represent the process of identifying the transmission path of the abnormal traffic, the abnormal traffic path result can represent the specific transmission process of the abnormal traffic, and the abnormal traffic path result can include information such as the traffic path, sending time, and service category, which is not specifically limited in this embodiment.

[0072] It should be noted that in the process of identifying abnormal traffic paths, it is possible to determine whether there is a traffic anomaly in the first target device through the target traffic information, the first traffic upper limit and the first traffic lower limit. When there is a traffic anomaly in the first target device, the first target traffic type corresponding to the first target device can be determined; then it is determined whether the abnormal traffic type matches the first target traffic type. When the abnormal traffic type matches the first target traffic type, it means that the first target device exists in the same type of abnormality as the network device. At this time, other devices that have a traffic transmission relationship with the first target device can be determined. Subsequently, the other devices can be determined as the first target devices and the process returns to step S130 until the first target traffic type of the first target device does not match the abnormal traffic type. At this time, all first target devices can be integrated to obtain the abnormal traffic path result.

[0073] It can be seen that the present application obtains the port traffic information of the network device, and performs anomaly detection based on the port traffic information and in combination with the preset traffic interval corresponding to the network device, to obtain the abnormal traffic type and abnormal traffic time, and according to the abnormal traffic time, obtains the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device, the first target device is a device that has a traffic transmission relationship with the network device, and then uses the abnormal traffic type, in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify the abnormal traffic path, and obtains the abnormal traffic path result; thereby, the location and situation of the traffic anomaly can be quickly and accurately determined through the abnormal traffic path result, so as to achieve the purpose of not having to manually discover anomalies and troubleshoot network links, and solves the problem of poor network anomaly positioning efficiency in the existing related technology that requires operation and maintenance personnel to manually discover anomalies and troubleshoot and locate the network abnormality location, thereby effectively improving the efficiency of locating network anomalies.

[0074] In an optional embodiment of the present application, based on the abnormal traffic time, the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device are obtained, including: obtaining the traffic transmission relationship information corresponding to the network device; determining at least one first target device based on the traffic transmission relationship information; for each first target device, obtaining the historical traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device; and determining the historical traffic information matching the abnormal traffic time as the target traffic information.

[0075] In the process of obtaining the target flow information, the first flow upper limit quantity and the first flow lower limit quantity corresponding to the first target device according to the abnormal flow time, the present embodiment can obtain the flow transmission relationship information corresponding to the network device, and the flow transmission relationship information can indicate the flow transmission relationship between various devices associated with the network device in the current network architecture, such as a network device topology diagram, a network structure relationship diagram, etc.; thereby, at least one first target device is determined based on the flow transmission relationship information, and specifically, a device with data transmission with each port of the network device can be determined as the first target device based on the flow transmission relationship information; and then, for each first target device, the historical flow information, the first flow upper limit quantity and the first flow lower limit quantity corresponding to the first target device can be obtained, wherein the historical flow information can indicate the flow and the first upper limit quantity transmitted by each port of the first target device within the historical time; then, the historical time can be extracted from the historical flow information, and it can be determined whether the historical time matches the abnormal flow time, so as to determine the historical flow information matching the abnormal flow time as the target flow information.

[0076] It should be noted that, in the process of determining at least one first target device according to the traffic transmission relationship information, the present embodiment may first determine the port identifier of the network device, determine the target identifier having a traffic transmission relationship with the port identifier according to the port identifier combined with the traffic transmission relationship information, and determine the device corresponding to the target identifier as the first target device; Figure 2As shown, the port identifiers included in the network device S11 include the outgoing traffic port identifier P11, the incoming traffic port identifier P12, the incoming traffic port identifier P12, and the incoming traffic port identifier P13. Then, through the traffic transmission relationship information, it can be determined that the outgoing traffic port identifier P11 has a traffic transmission relationship with the incoming traffic port identifier P1, the incoming traffic port identifier P12 has a traffic transmission relationship with the outgoing traffic port identifier P15, the incoming traffic port identifier P13 has a traffic transmission relationship with the outgoing traffic port identifier P16, and the incoming traffic port identifier P14 has a traffic transmission relationship with the outgoing traffic port identifier P17. At this time, the device R1 corresponding to the ingoing traffic port identifier P1, the device S11 corresponding to the outgoing traffic port identifier P15, the device S12 corresponding to the outgoing traffic port identifier P16, and the device S13 corresponding to the outgoing traffic port identifier P17 can be determined as the first target device, so that the determined first target devices are all devices that have a traffic transmission relationship with the network device S11. Of course, other determination methods can also be used, and this embodiment does not specifically limit this.

[0077] In addition, in the process of determining whether the historical time matches the abnormal flow time, the present embodiment can determine the time difference between the calculated historical time and the abnormal flow time, and determine whether the time difference is less than the preset time difference threshold. If the time difference is less than the preset time difference threshold, it can be determined that the historical time matches the abnormal flow time. If the time difference is not less than the preset time difference threshold, it can be determined that the historical time does not match the abnormal flow time. Of course, other determination methods can also be used, and this embodiment does not specifically limit this.

[0078] In an optional embodiment of the present application, an abnormal traffic type is used, combined with target traffic information, a first traffic upper limit quantity, and a first traffic lower limit quantity to perform abnormal traffic path identification to obtain an abnormal traffic path result, including: extracting the first target traffic quantity from the target traffic information; using the first target traffic quantity, the first traffic upper limit quantity, and the first traffic lower limit quantity to determine the first target traffic type corresponding to the first target device; when the first target traffic type matches the abnormal traffic type, determining the first target device as a traffic path device; and generating an abnormal traffic path result based on the traffic path device.

[0079] In the process of identifying the abnormal traffic path in this embodiment, the first target traffic quantity can be extracted from the target traffic information. The first target traffic quantity can represent the value of the data traffic transmitted by a specific port in the first target device, that is, one or more first target traffic quantities can be extracted from the target traffic information; thereby, the first target traffic quantity, the first traffic upper limit quantity, and the first traffic lower limit quantity can be used to determine the first target traffic type corresponding to the first target device. The first target traffic type can represent the type of traffic transmission corresponding to the first target device, and the first target traffic type can be a traffic abnormal increase type or a traffic abnormal decrease type, wherein the traffic abnormal increase type or the traffic abnormal decrease type corresponds to the traffic abnormality corresponding to the aforementioned abnormal traffic type. The increase type or the traffic anomaly decrease type is similar to the type, which will not be repeated here; then it can be determined whether the first target traffic type matches the abnormal traffic type. When the first target traffic type does not match the abnormal traffic type, it means that the current traffic situation of the first target device does not match the traffic anomaly of the network device, that is, the two do not have an abnormal correlation, and there is no need to execute subsequent steps at this time; and when the first target traffic type matches the abnormal traffic type, it means that the current traffic situation of the first target device matches the traffic anomaly of the network device, that is, the two have an abnormal correlation, and the first target device can be determined as a traffic path device; then the various traffic path devices can be integrated to generate an abnormal traffic path result.

[0080] It should be noted that, in the present embodiment, the first target flow quantity, the first flow upper limit quantity and the first flow lower limit quantity are used to determine the first target flow type corresponding to the first target device. The first target flow quantity and the first flow upper limit quantity can be compared. If the first target flow quantity is greater than the first flow upper limit quantity, it means that the current first target device has an abnormal flow higher than the preset upper limit. At this time, the abnormal flow increase type can be determined as the first target flow type; if the first target flow quantity is not greater than the first flow upper limit quantity, it means that the current first target device does not have an abnormal flow higher than the preset upper limit. At this time, the first target flow quantity and the first flow lower limit quantity can be compared. If the first target flow quantity is less than the first flow upper limit quantity, it means that the current first target device does not have an abnormal flow higher than the preset upper limit. In the case of the lower limit of the quantity, it means that the current first target device has an abnormality that the flow is lower than the preset lower limit. At this time, the abnormal flow reduction type can be determined as the first target flow type; in addition, if the first target device contains multiple ports, the first target flow quantity corresponding to each port can perform the aforementioned steps of determining the first target flow type. If the first target flow quantities corresponding to the first target device are not greater than the first flow upper limit quantity and not less than the first flow lower limit quantity, it means that the first target flow quantities corresponding to each port of the current first target device are all within the normal flow value range, that is, there is no flow abnormality in each port of the current first target device. At this time, the normal flow type can be determined as the first target flow type. Of course, the above is only an example for illustration, and this embodiment does not make specific limitations on this.

[0081] In an optional embodiment of the present application, an abnormal traffic path result is generated based on the traffic path device, including: determining the traffic transmission direction between the traffic path device and the network device; determining the second target device corresponding to the traffic path device based on the traffic transmission direction; determining the second target traffic type corresponding to the second target device based on the second target traffic quantity, the second traffic upper limit quantity and the second traffic lower limit quantity corresponding to the second target device; when the second target traffic type matches the abnormal traffic type, determining the second target device as the traffic path device, and returning to execute the step of determining the traffic transmission direction between the traffic path device and the network device; when the second target traffic type does not match the abnormal traffic type, generating the abnormal traffic path result based on the set of traffic path devices corresponding to the traffic transmission direction.

[0082] In the process of generating an abnormal traffic path result based on the traffic path device in this embodiment, the traffic transmission direction between the traffic path device and the network device can be determined. The traffic transmission direction can indicate the direction of data traffic transmission between the traffic path device and the network device, for example, the traffic transmission direction indicates that the data traffic is transmitted from the network device to the traffic path device, or from the traffic path device to the network device; thereby, the second target device corresponding to the traffic path device can be determined based on the traffic transmission direction, and the second target device can indicate a device that has a data transmission relationship with the traffic path device in the traffic transmission direction; further, the second target traffic quantity, the second traffic upper limit quantity, and the second traffic lower limit quantity corresponding to the second target device can be obtained, and the second target traffic type corresponding to the second target device can be determined based on the second target traffic quantity, the second traffic upper limit quantity, and the second traffic lower limit quantity, and the second target traffic type can indicate the type of traffic transmission corresponding to the second target device, wherein the traffic abnormal increase type or the traffic abnormal decrease type is The low type is similar to the abnormal flow increase type or the abnormal flow decrease type in the aforementioned embodiment, and will not be described in detail here; then it can be determined whether the second target flow type matches the abnormal flow type. When the second target flow type matches the abnormal flow type, it means that the current flow situation of the second target device matches the abnormal flow situation of the network device, that is, the two have an abnormal correlation. At this time, the second target device can be determined as a flow path device, and the step of determining the flow transmission direction of the flow path device and the network device is returned to be executed, so as to determine one or more flow path devices in the same flow transmission direction; and when the second target flow type does not match the abnormal flow type, it means that the current flow situation of the second target device does not match the flow anomaly of the network device, that is, the two do not have an abnormal correlation, and there is no need to perform other operations on the second target device. At this time, the abnormal flow path result can be generated according to the flow path device set corresponding to the flow transmission direction.

[0083] It should be noted that, in this embodiment, the second flow upper limit quantity is greater than the second flow lower limit quantity, and based on the second target flow quantity, the second flow upper limit quantity and the second flow lower limit quantity corresponding to the second target device, the second target flow type corresponding to the second target device is determined, which may include the following sub-steps: when the first target flow quantity is greater than the first flow upper limit quantity, the preset flow abnormal increase type is determined as the target flow type; when the first target flow quantity is less than the first flow lower limit quantity, the preset flow abnormal decrease type is determined as the target flow type.

[0084] In the present embodiment, in the process of determining the second target flow type corresponding to the second target device, the second target flow quantity and the second flow upper limit quantity can be compared. When the second target flow quantity is greater than the second flow upper limit quantity, it indicates that the current second target device has an abnormal flow higher than the preset upper limit. At this time, the abnormal flow increase type can be determined as the second target flow type; when the second target flow quantity is not greater than the second flow upper limit quantity, it indicates that the current second target device does not have an abnormal flow higher than the preset upper limit. At this time, the second target flow quantity and the second flow lower limit quantity can be compared. When the second target flow quantity is less than the second flow lower limit quantity, it indicates that the current second target device has an abnormal flow lower than the preset lower limit. At this time, the abnormal flow reduction type can be determined as the second target flow type; in addition, if the second target device includes multiple ports, the second target flow quantity corresponding to each port can perform the aforementioned step of determining the second target flow type. If each second target flow quantity corresponding to the second target device is not greater than the second flow upper limit quantity and not less than the second flow lower limit quantity, it indicates that the second target flow quantity corresponding to each port of the current second target device is within the normal flow value range, that is, each port of the current second target device does not have an abnormal flow. At this time, the normal flow type can be determined as the second target flow type. Of course, the above is only an example to illustrate the effect, and this embodiment does not make any specific limitation to this.

[0085] In one example, if Figure 3 As shown, in the case where the network device is switch S11, the first target device corresponding to switch S11 can be determined as router R1, switch S111, switch S112, and switch S113; when the first target device is router R1 and router R1 is determined as a traffic path device, the traffic transmission direction between the traffic path device and the network device is determined to be from switch S11 to router R1, and the second target devices corresponding to router R1 in this traffic transmission direction are router R2 and router R3, and then the step of "determining the second target traffic type corresponding to the second target device based on the second target traffic quantity, the second traffic upper limit quantity, and the second traffic lower limit quantity corresponding to the second target device" can be performed for router R2 and router R3 respectively. If the second target traffic type corresponding to router R2 matches the abnormal traffic type, the second target device, that is, router R2, can be determined as a traffic path device again, and the step of determining the traffic transmission direction between the traffic path device and the network device is returned, that is, the device of the output object of router R2 is continuously judged whether it can be determined as a traffic path device, until the second target traffic type matches the abnormal traffic type, as shown in FIG. Figure 3In the router R3 or switch S19, or the border device, that is, the port directly connected to the server device; if the second target traffic type of the router R3 does not match the abnormal traffic type, then it is not necessary to perform other steps on the router R3, that is, the traffic path device set determined in other branches in the direction of traffic transmission can be obtained, such as Figure 3 The flow path device set corresponding to the flow transmission direction shown in the figure includes router R1, router R2, switch S22, switch S221 and two edge devices. In addition, the flow path device set corresponding to other flow transmission directions is similar to the above, which will not be repeated here. Figure 3 The network device is shown as a flow path device set corresponding to the flow transmission direction on the right side of the switch S11, which may include the switch S111 and two edge devices. Of course, the above is only an example, and this embodiment does not make any specific limitation to this.

[0086] In an optional embodiment of the present application, an abnormal traffic path result is generated based on a traffic path device set corresponding to the traffic transmission direction, including: obtaining device port information corresponding to each traffic path device in the traffic path device set; generating results based on the device port information, combining the port traffic information and the abnormal traffic time, to obtain an abnormal traffic path result.

[0087] In the process of generating abnormal traffic path results based on the traffic path device set corresponding to the traffic transmission direction in this embodiment, since it may include one or more traffic path device sets corresponding to the traffic transmission direction, at this time, for each traffic path device set, the device port information corresponding to each traffic path device in the traffic path device set can be obtained, and the device port information represents the port where the transmission traffic abnormality occurs; thereby, the result can be generated based on the device port information, combined with the port traffic information and the abnormal traffic time, to obtain the abnormal traffic path result.

[0088] It should be noted that the device port information in this embodiment is the port information determined in the aforementioned steps of "determining the first target flow type corresponding to the first target device by using the first target flow quantity, the first flow upper limit quantity and the first flow lower limit quantity" and "determining the second target flow type corresponding to the second target device based on the second target flow quantity, the second flow upper limit quantity and the second flow lower limit quantity corresponding to the second target device". Figure 3As shown, in the case where the first target device is the switch S111, for the first target flow quantities corresponding to the ports P27, P28, P29 and P15 of the switch S111, respectively, the steps of determining whether the first target flow quantity is greater than the first flow upper limit quantity and whether it is less than the first flow lower limit quantity are performed, and in the case where the first target flow quantity is greater than the first flow upper limit quantity or less than the first flow lower limit quantity, the port corresponding to the first target flow quantity is determined as an abnormal port, so that the port information corresponding to the abnormal port is determined as the device port information. For example, the ports P12, P27 and P28 of the switch S111 are abnormal ports. At this time, the device port information can include the port information corresponding to the ports P12, P27 and P28. The method for determining the device port information corresponding to the flow path devices in other flow path device sets is the same as the aforementioned type and will not be repeated here.

[0089] In one example, if Figure 3As shown, in the case where the network device is switch S11, switch S11 has two traffic transmission directions, namely the left traffic transmission direction and the right traffic transmission direction. If the traffic path device set corresponding to the left traffic transmission direction includes router R1, router R2, switch S22, switch S221 and two edge devices, the traffic path device set corresponding to the right traffic transmission direction includes switch S111 and two edge devices; at this time, the device port information corresponding to each traffic path device in the traffic path device set corresponding to the left traffic transmission direction is obtained, and the device port information that can be obtained is: port P11 of switch S11, port P1 and port P3 of router R1, port P7 and port P10 of router R2, port P20 and port P21 of switch S22, port P22, port P23 and port P24 of switch S221; the device port information corresponding to each traffic path device in the traffic path device set corresponding to the right traffic transmission direction is obtained. The device port information corresponding to the traffic path device can be obtained as follows: port P12 of switch S11, port P15 and port P27 of switch S111. The abnormal traffic path is: P27→P15→P12→P11→P1→P3→P7→P10→P20→P21→P22→P23 and P24. On this basis, the result is generated by combining the port traffic quantity and abnormal traffic time in the port traffic information. The abnormal traffic path result is that the traffic sent by business A to business B suddenly increased by 500M at 1:10-20 am on November 6. The traffic source is the two edge devices corresponding to ports P27 and P28 of switch S111, and the traffic destination is the two edge devices corresponding to ports P23 and P24 of switch S221. The specific abnormal traffic path is: P27→P15→P12→P11→P1→P3→P7→P10→P20→P21→P22→P23.

[0090] In an optional embodiment of the present application, anomaly detection is performed based on port traffic information in combination with a preset traffic interval corresponding to the network device to obtain an abnormal traffic type and an abnormal traffic time, including: extracting the port traffic quantity from the port traffic information; determining a preset traffic upper limit quantity and a preset traffic lower limit quantity corresponding to the preset traffic interval, the preset traffic upper limit quantity being greater than the preset traffic lower limit quantity; when the port traffic quantity is greater than the preset traffic upper limit quantity, determining a preset traffic abnormal increase type as the abnormal traffic type; when the port traffic quantity is less than the preset traffic lower limit quantity, determining a preset traffic abnormal decrease type as the abnormal traffic type; when the abnormal traffic type is a traffic abnormal increase type or a traffic abnormal decrease type, obtaining the port traffic time corresponding to the port traffic information, and determining the port traffic time as the abnormal traffic time.

[0091] In this embodiment, in the process of performing anomaly detection based on port traffic information and combining with the preset traffic interval corresponding to the network device to obtain the abnormal traffic type and abnormal traffic time, the port traffic quantity can be extracted from the port traffic information, and the port traffic quantity can represent the value of the data traffic transmitted in the network device, that is, one or more first target traffic quantities can be extracted from the port traffic information; then the preset traffic upper limit quantity and the preset traffic lower limit quantity corresponding to the preset traffic interval can be determined, and the preset traffic upper limit quantity is greater than the preset traffic lower limit quantity, wherein the preset traffic upper limit quantity can represent the preset traffic quantity with the largest value in the preset traffic interval, and the preset traffic lower limit quantity can represent the preset traffic quantity with the smallest value in the preset traffic interval; thereby, the port traffic quantity and the preset traffic upper limit quantity can be compared, and when the port traffic quantity is greater than the preset traffic upper limit quantity, it indicates that the current network device has an abnormality in which the traffic is higher than the preset upper limit, and at this time, the traffic abnormal increase type can be determined as the abnormal traffic type; when the port traffic quantity is not greater than the preset traffic upper limit quantity, it indicates that the current network device does not have a high traffic. If there is an abnormality with a preset upper limit, the port flow quantity and the preset lower flow limit can be compared. When the port flow quantity is less than the preset lower flow limit, it means that the current network device has an abnormality in that the flow is lower than the preset lower limit. At this time, the abnormal flow reduction type can be determined as the abnormal flow type; in addition, if the network device contains multiple ports, the port flow quantity corresponding to each port can execute the aforementioned steps of determining the abnormal flow type until the port flow quantity corresponding to each port is traversed. At this time, when the port flow quantity corresponding to each port of the network device is not greater than the preset upper flow limit and not less than the preset lower flow limit, it means that the port flow quantity corresponding to each port of the current network device is within the normal flow value range, that is, there is no flow abnormality in each port of the current network device, and there is no need to execute subsequent steps at this time; and if the abnormal flow type is an abnormal flow increase type or an abnormal flow reduction type, the port flow time corresponding to the port flow quantity can be obtained, that is, the port flow time corresponding to the port flow information, and the port flow time can be determined as the abnormal flow time.

[0092] For example, Figure 2 The switch S11 shown includes port P11, port P12, port P13, and port P14. From the port flow information corresponding to the switch S11, the port flow quantity corresponding to each port is extracted, and the aforementioned comparison step is performed for the port flow quantity corresponding to each port, and it is determined that the port flow quantity corresponding to port P11 and port P12 is greater than the preset flow upper limit quantity. At this time, the port flow time corresponding to the port flow information can be obtained, and the port flow time can be determined as the abnormal flow time. Of course, the above is only an example for illustration, and this embodiment does not make specific limitations on this.

[0093] In specific implementation, Figure 4 As shown, the following modules can be included in the network abnormal traffic detection system:

[0094] 1) Traffic monitoring module: monitors the traffic size of the network device port through the SNMP protocol, thereby obtaining the port traffic information of the network device and storing the port traffic information in the database.

[0095] 2) Traffic sampling module: The network traffic components are sampled through the sflow protocol, and the traffic content on each network device port is analyzed. The analysis results are expressed as a four-tuple <source IP address, destination IP address, traffic size, sampling time>, and the results are stored in the database.

[0096] 3) Traffic anomaly detection module: used to perform anomaly detection based on port traffic information and in combination with the preset traffic interval corresponding to the network device, and obtain the abnormal traffic type and abnormal traffic time; for example, the traffic size in the future period (such as 1 day) is predicted through the historical traffic size, including the preset traffic upper limit and the preset traffic lower limit corresponding to the preset traffic interval, and an alarm message is generated when the real-time traffic exceeds the upper limit or the lower limit, and the traffic source or destination is further analyzed to form abnormal traffic path information. That is, according to the abnormal traffic time, the target traffic information, the first traffic upper limit and the first traffic lower limit corresponding to the first target device can be obtained, and the first target device is a device that has a traffic transmission relationship with the network device; and the abnormal traffic type is used to identify the abnormal traffic path in combination with the target traffic information, the first traffic upper limit and the first traffic lower limit to obtain the abnormal traffic path result.

[0097] 4) Business detection module: Based on the port and time of abnormal traffic output by the traffic anomaly detection module, that is, the abnormal traffic path result, it can be combined with sflow sampling data to confirm the source and destination IP in the traffic and the business to which it belongs, and push specific alarm information to network maintenance personnel.

[0098] In addition, combined Figure 2 The network is taken as an example to illustrate the specific anomaly detection and location process:

[0099] (1) The traffic monitoring module collects the traffic size information of all switch and router ports in real time and stores it in the database.

[0100] (2) The traffic sampling module samples the traffic of all switch and router ports, analyzes the source and destination IP information, and stores it in the database.

[0101] (3) Traffic anomaly detection module reads the historical traffic information of the device in the database and predicts the current traffic. After comparing it with the real-time traffic, it confirms whether abnormal traffic is generated. For example, Figure 2 The port traffic information of the network device router R1 includes the inbound traffic of the P1 port of the R1 device. The specific traffic is as follows Figure 5 As shown, the intervals included in the upper and lower curves are the preset flow intervals corresponding to the network device R1, and the middle curve is the port flow quantity represented by the port flow information. When the port flow quantity represented by the port flow information exceeds the preset flow interval, as shown in FIG. Figure 5 As shown, at this time, the abnormal traffic type and abnormal traffic time corresponding to the network device R1 are determined, and subsequent steps are executed.

[0102] like Figure 6 As shown, the present application also discloses an embodiment, providing a device for detecting abnormal network traffic, including:

[0103] An acquisition module 610 is used to acquire port flow information of a network device;

[0104] Anomaly detection module 620, used to perform anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device, to obtain an abnormal traffic type and abnormal traffic time;

[0105] A target module 630 is used to obtain target flow information, a first flow upper limit quantity, and a first flow lower limit quantity corresponding to a first target device according to the abnormal flow time, wherein the first target device is a device having a flow transmission relationship with the network device;

[0106] The path identification module 640 is used to identify the abnormal traffic path by using the abnormal traffic type in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to obtain an abnormal traffic path result.

[0107] In an optional embodiment of the present application, the target module 630 may include:

[0108] A first acquisition unit, used to acquire flow transmission relationship information corresponding to the network device;

[0109] A first determining unit, configured to determine at least one of the first target devices according to the traffic transmission relationship information;

[0110] A second acquisition unit is used to acquire, for each of the first target devices, historical traffic information corresponding to the first target device, the first traffic upper limit quantity, and the first traffic lower limit quantity;

[0111] The second determining unit is used to determine the historical flow information matching the abnormal flow time as the target flow information.

[0112] In an optional embodiment of the present application, the path identification module 640 may include:

[0113] A first extraction unit, configured to extract a first target flow quantity from the target flow information;

[0114] a third determining unit, configured to determine a first target traffic type corresponding to the first target device by using the first target traffic quantity, the first traffic upper limit quantity, and the first traffic lower limit quantity;

[0115] a fourth determining unit, configured to determine the first target device as a traffic path device when the first target traffic type matches the abnormal traffic type;

[0116] A generating unit is used to generate the abnormal flow path result according to the flow path device.

[0117] In an optional embodiment of the present application, the generating unit may include:

[0118] A first determining subunit is used to determine the flow transmission direction between the flow path device and the network device;

[0119] A second determining subunit, configured to determine a second target device corresponding to the traffic path device according to the traffic transmission direction;

[0120] A third determining subunit is used to determine the second target flow type corresponding to the second target device based on the second target flow quantity, the second flow upper limit quantity and the second flow lower limit quantity corresponding to the second target device;

[0121] a fourth determining subunit, configured to determine the second target device as a traffic path device when the second target traffic type matches the abnormal traffic type, and return to execute the step of determining the traffic transmission direction between the traffic path device and the network device;

[0122] The first generating subunit is used to generate the abnormal traffic path result according to the traffic path device set corresponding to the traffic transmission direction when the second target traffic type does not match the abnormal traffic type.

[0123] In an optional embodiment of the present application, the first generating subunit may include:

[0124] An acquiring subunit, configured to acquire device port information corresponding to each of the flow path devices in the flow path device set;

[0125] A second generation subunit, configured to generate a result based on the device port information, in combination with the port traffic information and the abnormal traffic time, to obtain the abnormal traffic path result.

[0126] In an alternative embodiment of the present application, the second traffic upper limit quantity is greater than the second traffic lower limit quantity, and the third determination subunit may include:

[0127] A fifth determination subunit, configured to determine a preset traffic abnormal increase type as the target traffic type when the first target traffic quantity is greater than the first traffic upper limit quantity;

[0128] A sixth determination subunit, configured to determine a preset traffic abnormal decrease type as the target traffic type when the first target traffic quantity is less than the first traffic lower limit quantity.

[0129] In an alternative embodiment of the present application, the abnormal detection module 620 may include:

[0130] A second extraction unit, configured to extract the port traffic quantity from the port traffic information;

[0131] A fifth determination unit, configured to determine a preset traffic upper limit quantity and a preset traffic lower limit quantity corresponding to the preset traffic interval, where the preset traffic upper limit quantity is greater than the preset traffic lower limit quantity;

[0132] A sixth determination unit, configured to determine a preset traffic abnormal increase type as the abnormal traffic type when the port traffic quantity is greater than the preset traffic upper limit quantity;

[0133] A seventh determination unit, configured to determine a preset traffic abnormal decrease type as the abnormal traffic type when the port traffic quantity is less than the preset traffic lower limit quantity;

[0134] An eighth determination unit, configured to obtain the port traffic time corresponding to the port traffic information and determine the port traffic time as the abnormal traffic time when the abnormal traffic type is the traffic abnormal increase type or the traffic abnormal decrease type.

[0135] The implementation processes of the functions and effects of each module in the above device are specifically detailed in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0136] Such as Figure 7As shown, an embodiment of the present application provides an electronic device, including a processor 710, a communication interface 720, a memory 730 and a communication bus 740, wherein the processor 710, the communication interface 720, and the memory 730 communicate with each other through the communication bus 740;

[0137] Memory 730, for storing computer programs;

[0138] In one embodiment of the present application, the processor 710 is used to execute the program stored in the memory 730 to implement the network abnormal traffic detection method provided by any of the aforementioned method embodiments, by obtaining the port traffic information of the network device, based on the port traffic information, combined with the preset traffic interval corresponding to the network device to perform anomaly detection, obtain the abnormal traffic type and abnormal traffic time, and according to the abnormal traffic time, obtain the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device, the first target device is a device that has a traffic transmission relationship with the network device, and then use the abnormal traffic type, combined with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to identify the abnormal traffic path, and obtain the abnormal traffic path result; thereby, the location and situation of the traffic anomaly can be quickly and accurately determined through the abnormal traffic path result, so as to achieve the purpose of not having to manually discover the anomaly and troubleshoot the network link, and solve the problem of poor network anomaly positioning efficiency in the existing related technology that requires operation and maintenance personnel to manually discover the anomaly and troubleshoot and locate the network abnormal location, thereby effectively improving the network anomaly positioning efficiency.

[0139] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network abnormal traffic detection method provided by any of the aforementioned method embodiments are implemented, by obtaining the port traffic information of the network device, based on the port traffic information, combined with the preset traffic interval corresponding to the network device, an abnormal traffic type and abnormal traffic time are obtained, and according to the abnormal traffic time, the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity corresponding to the first target device are obtained, the first target device is a device that has a traffic transmission relationship with the network device, and then the abnormal traffic type is used to identify the abnormal traffic path in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to obtain the abnormal traffic path result; thereby, the location and situation of the traffic anomaly can be quickly and accurately determined through the abnormal traffic path result, so as to achieve the purpose of not having to manually discover the anomaly and troubleshoot the network link, and solve the problem of poor network anomaly positioning efficiency in the existing related technology that requires operation and maintenance personnel to manually discover the anomaly and troubleshoot and locate the network abnormal location, thereby effectively improving the network anomaly positioning efficiency.

[0140] The above-described apparatus, device and medium embodiments are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0141] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0142] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used herein may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described herein are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative steps may be used.

[0143] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A method for detecting abnormal network traffic, characterized in that: include: Get port traffic information of network devices; Based on the port traffic information, anomaly detection is performed in combination with a preset traffic interval corresponding to the network device to obtain an abnormal traffic type and abnormal traffic time; According to the abnormal traffic time, obtaining target traffic information, a first traffic upper limit quantity, and a first traffic lower limit quantity corresponding to a first target device, wherein the first target device is a device having a traffic transmission relationship with the network device; The abnormal traffic type is used in combination with the target traffic information, the first traffic upper limit quantity, and the first traffic lower limit quantity to identify the abnormal traffic path and obtain an abnormal traffic path result.

2. The method for detecting abnormal network traffic according to claim 1, characterized in that: The acquiring, according to the abnormal traffic time, target traffic information corresponding to the first target device, a first traffic upper limit quantity, and a first traffic lower limit quantity, includes: Obtaining traffic transmission relationship information corresponding to network devices; Determine at least one of the first target devices according to the traffic transmission relationship information; For each of the first target devices, obtaining historical traffic information, the first traffic upper limit, and the first traffic lower limit corresponding to the first target device; The historical traffic information matching the abnormal traffic time is determined as the target traffic information.

3. The method for detecting abnormal network traffic according to claim 1, characterized in that: The abnormal traffic type is used to identify the abnormal traffic path in combination with the target traffic information, the first traffic upper limit quantity, and the first traffic lower limit quantity to obtain the abnormal traffic path result, including: Extracting a first target flow quantity from the target flow information; Determine a first target traffic type corresponding to the first target device by using the first target traffic quantity, the first traffic upper limit quantity, and the first traffic lower limit quantity; In a case where the first target traffic type matches the abnormal traffic type, determining the first target device as a traffic path device; The abnormal traffic path result is generated according to the traffic path device.

4. The method for detecting abnormal network traffic according to claim 3, characterized in that: The generating the abnormal traffic path result according to the traffic path device includes: Determining a flow transmission direction between the flow path device and the network device; Determining a second target device corresponding to the traffic path device according to the traffic transmission direction; Determine a second target flow type corresponding to the second target device based on a second target flow quantity, a second flow upper limit quantity, and a second flow lower limit quantity corresponding to the second target device; In the case where the second target traffic type matches the abnormal traffic type, determining the second target device as a traffic path device, and returning to execute the step of determining the traffic transmission direction between the traffic path device and the network device; In the case where the second target traffic type does not match the abnormal traffic type, the abnormal traffic path result is generated according to the traffic path device set corresponding to the traffic transmission direction.

5. The method for detecting abnormal network traffic according to claim 4, characterized in that: The generating the abnormal traffic path result according to the traffic path device set corresponding to the traffic transmission direction includes: Obtain device port information corresponding to each of the flow path devices in the flow path device set; The result is generated based on the device port information, combined with the port traffic information and the abnormal traffic time, to obtain the abnormal traffic path result.

6. The method for detecting abnormal network traffic according to claim 4, characterized in that: The second traffic upper limit is greater than the second traffic lower limit, and determining the second target traffic type corresponding to the second target device based on the second target traffic amount, the second traffic upper limit, and the second traffic lower limit corresponding to the second target device includes: In a case where the first target flow rate is greater than the first flow rate upper limit, determining a preset flow rate abnormal increase type as the target flow rate type; When the first target flow quantity is less than the first flow lower limit quantity, a preset flow abnormal reduction type is determined as the target flow type.

7. The method for detecting abnormal network traffic according to claim 1, characterized in that: The abnormality detection is performed based on the port traffic information and in combination with the preset traffic interval corresponding to the network device to obtain the abnormal traffic type and abnormal traffic time, including: Extracting the port flow quantity from the port flow information; Determine a preset flow rate upper limit quantity and a preset flow rate lower limit quantity corresponding to the preset flow rate interval, wherein the preset flow rate upper limit quantity is greater than the preset flow rate lower limit quantity; In the case where the port flow quantity is greater than the preset flow upper limit quantity, determining the preset flow abnormal increase type as the abnormal flow type; In the case where the port flow quantity is less than the preset flow lower limit quantity, determining the preset flow abnormal reduction type as the abnormal flow type; In a case where the abnormal traffic type is the abnormal traffic increase type or the abnormal traffic decrease type, a port traffic time corresponding to the port traffic information is acquired, and the port traffic time is determined as the abnormal traffic time.

8. A device for detecting abnormal network traffic, characterized in that: include: An acquisition module is used to obtain port flow information of network devices; An anomaly detection module, used to perform anomaly detection based on the port traffic information and in combination with a preset traffic interval corresponding to the network device, to obtain an abnormal traffic type and abnormal traffic time; A target module, configured to obtain target flow information, a first flow upper limit quantity, and a first flow lower limit quantity corresponding to a first target device according to the abnormal flow time, wherein the first target device is a device having a flow transmission relationship with the network device; The path identification module is used to use the abnormal traffic type, in combination with the target traffic information, the first traffic upper limit quantity and the first traffic lower limit quantity to perform abnormal traffic path identification to obtain an abnormal traffic path result.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; The processor is used to implement the method for detecting abnormal network traffic as described in any one of claims 1 to 7 when executing the program stored in the memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for detecting abnormal network traffic as described in any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Message forwarding method and device of power system, computer equipment and program product

    CN120567946A