Behavior pattern recognition method and device based on network flow analysis and medium
By adopting the architecture of combining Mamba network and fully connected neural network in network traffic behavior recognition, the problems of gradient vanishing, low model training efficiency and high complexity of Transformer in the existing technology are solved, and efficient and accurate behavior pattern recognition is achieved.
Patent Information
- Application Number
- CN202510211599.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art has gradient disappearance or explosion in network traffic behavior recognition, low model training efficiency, and high-complex resource consumption problems of Transformer, which is difficult to effectively apply in large-scale data.
The behavior pattern recognition method based on Mamba network is adopted. By converting network traffic data into multiple sets of time series data, embedding and normalizing it, the feature vector is determined and behavior pattern recognition is performed using the architecture combined with the fully connected neural network and the Mamba network.
It improves the efficiency and accuracy of behavioral pattern recognition, reduces the computational complexity and resource requirements, enhances the model's ability to distinguish different traffic behavior patterns, and improves the credibility of the identification results through the probability distribution decision mechanism.
Smart Images

Figure CN120145186A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security and behavior recognition, and particularly to a behavior pattern recognition method, device and medium based on network traffic analysis. Background Art
[0002] As the core carrier of Internet communication, network traffic can objectively record the time series trajectories of user behavior patterns, service interaction characteristics, and potential abnormal activities. In the fields of network security monitoring, service quality optimization, etc., real-time behavior recognition of network traffic has become a key means to ensure the security and reliability of the system.
[0003] In recent years, deep learning technology has been gradually applied to the task of network traffic behavior recognition. The mainstream methods mainly rely on time series modeling architectures, including recurrent neural networks (RNNs), long short-term memory networks (LSTMs), and Transformers. Although the existing methods have played a certain role in network traffic behavior recognition, they are still difficult to apply in large-scale data, specifically manifested as follows:
[0004] 1. The problem of time-dependent decay in long sequence modeling of the RNN / LSTM architecture. The above two types of models are prone to gradient vanishing or explosion when dealing with long-time-span dependencies, and it is difficult to effectively retain long-distance context information.
[0005] 2. Insufficient model training efficiency and hardware adaptability. The serial recursive calculation mechanism of RNN / LSTM has a low utilization rate of GPU parallel computing resources, and the training speed is limited in large-scale traffic data scenarios.
[0006] 3. The defect of high complexity resource consumption of Transformer. The self-attention mechanism of Transformer needs to calculate the correlation between each pair of sequence elements, and its computational complexity is O(n 2 ), where n is the sequence length. This computational overhead will significantly increase the memory and computational resource requirements when dealing with long sequences or large-scale data, restricting its application in scenarios with high real-time requirements or limited resources. Summary of the Invention
[0007] The present invention provides a behavior pattern recognition method, device and medium based on network traffic analysis to solve at least one of the above technical problems.
[0008] The present invention adopts the following technical solutions:
[0009] First aspect, the present invention provides a behavior pattern recognition method based on network traffic analysis, the method comprising: converting the network traffic data to be analyzed into multiple sets of time series data; performing embedding processing on each set of time series data to obtain a one-dimensional vector corresponding to each set of time series data; stacking the one-dimensional vectors corresponding to the multiple sets of time series data in chronological order into a set of multi-dimensional data; determining a feature vector corresponding to the multi-dimensional data according to a preset Mamba network; using a preset fully connected neural network to determine the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vector corresponding to the multi-dimensional data.
[0010] In a feasible implementation manner, performing embedding processing on each set of time series data includes:
[0011] determining an encoding dimension according to the numerical distribution range of the traffic data sizes in the multiple sets of time series data; mapping each set of time series data to a corresponding sparse vector through one-hot encoding operation, the dimension of the sparse vector being equal to the encoding dimension; converting the sparse vector to a one-dimensional vector through a dimensionality reduction operation.
[0012] In a feasible implementation manner, using a preset fully connected neural network to determine the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vectors corresponding to the multiple sets of time series data includes: inputting the feature vectors corresponding to the multiple sets of time series data into the preset fully connected neural network, the fully connected neural network including multiple hidden layers, and each hidden layer performing feature transformation using the ReLu function; at the output layer of the fully connected neural network, calculating the probability distribution of the behavior patterns corresponding to the multiple sets of time series data using the Softmax function; according to the probability distribution, selecting the behavior pattern with the highest probability as the behavior pattern corresponding to the network traffic data to be analyzed.
[0013] In a feasible implementation manner, converting the network traffic data to be analyzed into multiple sets of time series data includes: grouping the network traffic data to be analyzed according to a preset time interval according to the timestamps of the network traffic data to be analyzed to generate multiple sets of network traffic data; calculating the traffic data sizes corresponding to each set of network traffic data; determining the traffic types corresponding to each set of network traffic data; integrating the traffic data sizes and traffic types corresponding to each set of network traffic to generate the time series data corresponding to each set of network traffic.
[0014] In a feasible implementation manner, before converting the network traffic data to be analyzed into multiple sets of time series data, the method further includes: performing data cleaning on the network traffic data to be analyzed, the data cleaning including at least one of removing outliers and removing duplicate values; supplementing the missing values in the network traffic data to be analyzed through an interpolation method.
[0015] In a feasible implementation, the missing values in the network traffic data to be analyzed are supplemented by interpolation method, including: determining the interpolation node corresponding to the missing value according to the source node IP, destination node IP and timestamp corresponding to the missing value; constructing an interpolation polynomial based on the Lagrange interpolation formula; and calculating the interpolation result corresponding to the missing value by using the interpolation polynomial to supplement the missing value.
[0016] In a feasible implementation, after stacking the one-dimensional vectors corresponding to multiple groups of time series data into a group of multi-dimensional data, the method further includes: determining the maximum value and the minimum value in the multi-dimensional data; and normalizing the multi-dimensional data according to the following formula:
[0017]
[0018] where x represents the current data value, min represents the minimum value, max represents the maximum value, and y represents the value after normalization processing.
[0019] In a feasible implementation, after determining the behavior pattern corresponding to the network traffic data to be analyzed, the method further includes: judging whether the behavior pattern corresponding to the network traffic data to be analyzed belongs to an abnormal behavior pattern; if so, generating an abnormal behavior report according to the network traffic data to be analyzed, and sending the abnormal behavior report to a preset terminal.
[0020] In a second aspect, the present invention further provides a behavior pattern recognition device based on network traffic analysis, characterized in that the device specifically includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute a behavior pattern recognition method based on network traffic analysis according to any one of the above embodiments.
[0021] In a third aspect, the present invention further provides a non-volatile computer storage medium, on which computer executable instructions are stored, characterized in that the computer executable instructions are set to be able to execute a behavior pattern recognition method based on network traffic analysis according to any one of the above.
[0022] A behavior pattern recognition method, device and medium based on network traffic analysis provided by the present invention have the following beneficial effects:
[0023] 1. The present invention utilizes the Mamba network to process network traffic data converted into a time series format. The Mamba network utilizes a simple and effective selection mechanism. For data with a long time span, it can filter out irrelevant information while retaining necessary and relevant data, and it is difficult to have the phenomenon of gradient disappearance or gradient explosion. At the same time, both the Mamba network and the fully connected neural network can utilize the parallel computing resources of the GPU for training, and the training speed is significantly improved compared with RNN / LSTM. The Mamba network calculates efficiently through recursive or convolutional operations, achieving a nearly linear relationship between the computational complexity and the sequence length, and significantly reducing the computational cost compared with the Transformer. At the same time, each group of time series data is embedded, and each group of time series data is converted into a one-dimensional vector, further reducing the subsequent computational complexity, thereby reducing the computational cost and improving the efficiency of behavior pattern recognition.
[0024] 2. By setting the multi-hidden layer structure of the fully connected neural network combined with the ReLU activation function, the present invention can perform complex non-linear transformations on the feature vectors, enhancing the model's ability to distinguish different traffic behavior patterns. At the same time, the application of the Softmax function in the output layer can map the feature vectors into a probability distribution, intuitively reflecting the likelihood of each behavior pattern. Thus, by selecting the behavior pattern with the highest probability as the final recognition result, the scientific nature and accuracy of the recognition process are ensured. This decision-making mechanism based on probability distribution not only improves the credibility of the recognition result but also provides a clearer basis for subsequent traffic management and security analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. In the drawings:
[0026] Figure 1 It is a flowchart of a behavior pattern recognition method based on network traffic analysis provided by the present invention;
[0027] Figure 2 It is a schematic structural diagram of a behavior pattern recognition device based on network traffic analysis provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] To enable those skilled in the art to better understand the technical solutions in the present invention, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0029] The method in the present invention will be described in detail below with reference to the drawings.
[0030] Figure 1 The flowchart of a behavior pattern recognition method based on network traffic analysis provided by the present invention is as Figure 1 shown. A behavior pattern recognition method based on network traffic analysis in the present invention at least includes the following execution steps:
[0031] Step 101: Convert the network traffic data to be analyzed into multiple sets of time series data.
[0032] Network traffic data refers to the collection of various data packets transmitted through network devices (such as routers, switches, etc.) during network communication. These data packets contain rich information, such as the source node IP address, destination node IP address, transmission protocol, data packet size, transmission timestamp, etc. Network traffic data is an intuitive reflection of the network operation status, which records the communication behaviors and interaction processes among various devices in the network. Converting network traffic data into time series data is because network traffic is dynamic and continuous in time. Through the structure of time series, the change rules and trends of data in the time dimension can be clearly captured, facilitating the extraction of time-related features, and at the same time providing a unified and standardized data format for subsequent embedding processing and model training, thereby improving the accuracy and efficiency of behavior pattern recognition.
[0033] Specifically, first, according to the timestamp information in the network traffic data, group the data at a preset time interval, such as seconds, minutes, or hours, to generate multiple sets of network traffic data. Then, calculate the size of the traffic data corresponding to each set of network traffic data, such as counting the total number of bytes or the number of data packets in each set of data. Next, determine the traffic type corresponding to each set of network traffic data, such as TCP traffic, UDP traffic, or other specific protocol traffic. Finally, integrate the traffic data size and traffic type of each set of network traffic data to form the corresponding time series data, which can reflect the characteristic changes of network traffic at different time intervals and provide a basis for subsequent behavior pattern recognition.
[0034] In a feasible implementation, due to the large quantity and wide distribution of network traffic data, combined with various uncontrollable factors, there are a large number of duplicate values, missing values, and outliers in the collected data, making it difficult to directly perform data mining and feature engineering analysis. To improve data quality to better adapt to subsequent modeling analysis, it is necessary to perform preprocessing operations on the data. Specifically, first, data cleaning is performed on the network traffic data to be analyzed, including removing outliers and duplicate values in the data. Then, the missing values in the network traffic to be analyzed are supplemented by interpolation method.
[0035] Further, the specific steps for supplementing missing values are as follows: First, based on the source node IP address, destination node IP address, and timestamp information corresponding to the missing values, accurately locate the position of the missing values in the network traffic data, thereby determining the interpolation nodes. This process is the basis of the interpolation method. By clarifying the context information of the missing values, it can provide an accurate reference point for subsequent interpolation calculations. Then, based on the Lagrange interpolation formula, construct an interpolation polynomial. Lagrange interpolation is a classic interpolation method that constructs a polynomial function through known data points, making the values of this function at these data points equal to the actual values. This method can generate an interpolation polynomial that can reflect the data change trend based on the existing network traffic data points. Finally, use the constructed interpolation polynomial to calculate the interpolation result corresponding to the missing value, and use this result to supplement the missing part in the original data. In this way, not only can the missing data be filled, but also the overall trend and characteristics of the data can be maintained, avoiding analysis biases caused by missing values.
[0036] Step 102: Perform embedding processing on each group of time series data to obtain a one-dimensional vector corresponding to each group of time series data.
[0037] Embedding processing is a technique that maps original data into a low-dimensional or high-dimensional space, aiming to convert complex data structures into numerical vector forms while retaining their important features and internal relationships. Through embedding processing, non-numerical data or high-dimensional data can be converted into numerical vectors that are easier for the model to process, thereby providing a more effective data representation for subsequent analysis and modeling.
[0038] Specifically, first, determine the coding dimension according to the numerical distribution range of the traffic data sizes in multiple groups of time series data. This step is to select an appropriate coding space size according to the actual distribution of the data, ensuring that subsequent coding operations can effectively represent the features of the data, while avoiding information loss or redundancy problems caused by too large or too small coding dimensions.
[0039] Next, through one-hot encoding operation, each group of time series data is mapped to a corresponding sparse vector, and the dimension of the sparse vector is equal to the determined encoding dimension. One-hot encoding is a method of converting discrete features into numerical vectors, which can represent features such as the magnitude of traffic data in time series in the form of sparse vectors, enabling the model to better process these features while retaining the original information of the data.
[0040] Finally, the sparse vector is converted into a one-dimensional vector through dimensionality reduction operation. The purpose of dimensionality reduction operation is to compress the high-dimensional sparse vector into a low-dimensional one-dimensional vector, reduce the complexity of data, improve the calculation efficiency, remove redundant information at the same time, extract more representative features, and provide concise and effective input data for the subsequent behavior pattern recognition model.
[0041] Step 103: Stack the one-dimensional vectors corresponding to multiple groups of time series data in chronological order into a group of multi-dimensional data.
[0042] Stacking the one-dimensional vectors corresponding to multiple groups of time series data into a group of multi-dimensional data aims to combine the one-dimensional vectors after embedding processing in chronological order to form a multi-dimensional data structure with a time dimension. In this way, the time order information of time series data can be retained, and the one-dimensional vectors at multiple time points can be integrated together to provide richer context information for subsequent feature extraction and behavior pattern recognition. This multi-dimensional data structure can better reflect the behavior characteristics and their dynamic changes of network traffic at different time points, thus providing strong support for the model to analyze and recognize the behavior patterns of network traffic.
[0043] In a feasible implementation manner, in order to further optimize the data processing flow and improve the processing efficiency and accuracy of the model for feature vectors, after stacking the one-dimensional vectors corresponding to multiple groups of time series data into multi-dimensional data, the multi-dimensional data will also be normalized. The specific steps are as follows: First, determine the maximum value and minimum value in the multi-dimensional data. These two values are the key parameters for normalization processing and are used to define the range and scale of the data. By calculating the maximum value and minimum value in the multi-dimensional data, a benchmark can be provided for subsequent normalization operations.
[0044] Next, normalize the multi-dimensional data according to the following formula:
[0045]
[0046] Among them, x represents the current data value, min represents the minimum value, max represents the maximum value, and y represents the value after normalization. Through this formula, each eigenvalue in the multi-dimensional data is scaled between 0 and 1, thereby eliminating the differences in dimension and numerical range between different features and avoiding the dominant effect of some features with too large numerical ranges on model training.
[0047] Step 104: Determine the feature vector corresponding to the multi-dimensional data according to the preset Mamba network.
[0048] The Mamba network is an efficient neural network architecture that can process multi-dimensional time series data and extract its features. By inputting the multi-dimensional data into the Mamba network, the network will use its internal hierarchical structure and feature extraction mechanism to deeply process the data, thereby generating feature vectors that can effectively represent the behavior patterns of network traffic. These feature vectors not only retain the dynamic characteristics of the time series data but also further enhance the expression ability and discrimination of the features through the optimized design of the Mamba network, providing high-quality inputs for subsequent behavior pattern recognition.
[0049] Step 105: Use the preset fully connected neural network to determine the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vector corresponding to the multi-dimensional data.
[0050] Specifically, first, input the feature vector corresponding to the multi-dimensional data into the preset fully connected neural network. This network contains multiple hidden layers, and each hidden layer performs a non-linear transformation on the feature vector through the ReLU function to extract higher-level feature representations. The role of the ReLU function is to introduce non-linearity, enabling the network to learn complex feature relationships, avoiding the vanishing gradient problem, and improving the training efficiency of the network. At the output layer of the fully connected neural network, the Softmax function is used to calculate the probability distribution of the behavior patterns corresponding to multiple sets of time series data. The Softmax function maps the features of the output layer to the probability space, such that each behavior pattern corresponds to a probability value, and the sum of these probability values is 1. In this way, the possibility of each behavior pattern in the current network traffic data can be quantified.
[0051] Finally, according to the probability distribution, select the behavior pattern with the highest probability as the behavior pattern corresponding to the network traffic data to be analyzed. This process realizes the mapping from the feature vector to the specific behavior pattern, thereby completing the recognition of the network traffic behavior pattern. Through the multi-layer feature extraction of the fully connected neural network and the probability calculation of the Softmax function, the behavior patterns in the network traffic data can be effectively recognized, providing strong support for network management and security analysis.
[0052] In a feasible implementation manner, after identifying a behavior pattern, it is determined whether the pattern belongs to an abnormal behavior. If it is determined to be an abnormal behavior, an abnormal behavior report is generated and sent to a preset terminal to promptly detect and handle abnormal activities in the network and enhance network security.
[0053] Based on the same inventive concept, the present invention also provides a behavior pattern recognition device based on network traffic analysis, and its structure is as Figure 2 shown.
[0054] Figure 2 The structural schematic diagram of a behavior pattern recognition device based on network traffic analysis provided by the present invention. As Figure 2 shown, the behavior pattern recognition device 200 based on network traffic analysis in the present invention specifically includes: at least one processor 201; and a memory 203 communicatively connected to the at least one processor (connected through a bus 202); wherein, the memory 203 stores instructions that can be executed by the at least one processor 201, so that the at least one processor 201 can execute a behavior pattern recognition method based on network traffic analysis as described in the above embodiment.
[0055] In one or more possible implementation manners of the present invention, the foregoing processor is configured to execute: converting the network traffic data to be analyzed into multiple sets of time series data; performing embedding processing on each set of time series data to obtain a one-dimensional vector corresponding to each set of time series data; stacking the one-dimensional vectors corresponding to the multiple sets of time series data in chronological order into a set of multi-dimensional data; determining a feature vector corresponding to the multi-dimensional data according to a preset Mamba network; using a preset fully connected neural network to determine the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vector corresponding to the multi-dimensional data.
[0056] In addition, the present invention also provides a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are configured to be able to execute a behavior pattern recognition method based on network traffic analysis as described in any one of the above embodiments.
[0057] In one or more possible implementation manners of the present invention, the foregoing computer-executable instructions are configured to execute: converting the network traffic data to be analyzed into multiple sets of time series data; performing embedding processing on each set of time series data to obtain a one-dimensional vector corresponding to each set of time series data; stacking the one-dimensional vectors corresponding to the multiple sets of time series data in chronological order into a set of multi-dimensional data; determining a feature vector corresponding to the multi-dimensional data according to a preset Mamba network; using a preset fully connected neural network to determine the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vector corresponding to the multi-dimensional data.
[0058] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for relevant details.
[0059] The devices and methods provided in this application correspond one by one. Therefore, the devices also have beneficial technical effects similar to those of their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices will not be elaborated here.
[0060] Those skilled in the art should understand that the embodiments of this application can be provided as methods, devices, systems, or computer program products. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code.
[0061] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, commodity or device comprising the element.
[0062] The above are only the embodiments of this application and are not used to limit this application. For those skilled in the art, various changes and modifications can be made to this application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this application shall be included within the protection scope of this application.
Claims
1. A behavior pattern recognition method based on network traffic analysis, characterized in that: The method comprises: Convert the network traffic data to be analyzed into multiple sets of time series data; Embedding processing is performed on each group of time series data to obtain a one-dimensional vector corresponding to each group of time series data; In chronological order, stacking the one-dimensional vectors corresponding to the multiple groups of time series data into a group of multidimensional data; Determine, according to a preset Mamba network, a feature vector corresponding to the multidimensional data; Using a preset fully connected neural network, the behavior pattern corresponding to the network traffic data to be analyzed is determined according to the feature vector corresponding to the multi-dimensional data.
2. According to the behavior pattern recognition method based on network traffic analysis according to claim 1, it is characterized in that: Each group of time series data is embedded, including: Determine the encoding dimension according to the numerical distribution range of the flow data size in the multiple groups of time series data; By one-hot encoding, mapping each group of time series data into a corresponding sparse vector, the dimension of the sparse vector being equal to the encoding dimension; The sparse vector is converted into a one-dimensional vector through a dimensionality reduction operation.
3. The behavior pattern recognition method based on network traffic analysis according to claim 1 is characterized in that: Using a preset fully connected neural network, determining the behavior pattern corresponding to the network traffic data to be analyzed according to the feature vectors corresponding to the multiple groups of time series data, including: Inputting feature vectors corresponding to the multiple groups of time series data into the preset fully connected neural network, wherein the fully connected neural network includes multiple hidden layers, and each hidden layer uses a ReLu function to perform feature transformation; In the output layer of the fully connected neural network, a Softmax function is used to calculate the probability distribution of the behavior patterns corresponding to the multiple groups of time series data; According to the probability distribution, the behavior pattern with the highest probability is selected as the behavior pattern corresponding to the network traffic data to be analyzed.
4. The behavior pattern recognition method based on network traffic analysis according to claim 1 is characterized in that: Convert the network traffic data to be analyzed into multiple sets of time series data, including: Grouping the network traffic data to be analyzed at preset time intervals according to the timestamps of the network traffic data to be analyzed to generate multiple groups of network traffic data; Calculate the traffic data size corresponding to each group of network traffic data; Determine the traffic type corresponding to each group of network traffic data; The flow data sizes and flow types corresponding to the various groups of network flows are integrated to generate time series data corresponding to the various groups of network flows.
5. The behavior pattern recognition method based on network traffic analysis according to claim 1 is characterized in that: Before converting the network traffic data to be analyzed into multiple groups of time series data, the method further includes: Performing data cleaning on the network traffic data to be analyzed, wherein the data cleaning includes at least one of removing abnormal values and removing duplicate values; The missing values in the network traffic data to be analyzed are supplemented by interpolation method.
6. The behavior pattern recognition method based on network traffic analysis according to claim 5 is characterized in that: The missing values in the network traffic data to be analyzed are supplemented by interpolation method, including: Determine the interpolation node corresponding to the missing value according to the source node IP address, the destination node IP address and the timestamp corresponding to the missing value; Based on the Lagrange interpolation formula, construct the interpolation polynomial; The interpolation polynomial is used to calculate the interpolation result corresponding to the missing value to supplement the missing value.
7. The behavior pattern recognition method based on network traffic analysis according to claim 1 is characterized in that: After stacking the one-dimensional vectors corresponding to the multiple groups of time series data into a group of multi-dimensional data, the method further includes: Determining the maximum and minimum values in the multidimensional data; The multidimensional data is normalized according to the following formula: Among them, x represents the current data value, min represents the minimum value, max represents the maximum value, and y represents the value after normalization.
8. The method for identifying behavior patterns based on network flow analysis according to claim 1, characterized in that: After determining the behavior pattern corresponding to the network traffic data to be analyzed, the method further includes: Determine whether the behavior pattern corresponding to the network traffic data to be analyzed is an abnormal behavior pattern; If yes, an abnormal behavior report is generated according to the network traffic data to be analyzed, and the abnormal behavior report is sent to a preset terminal.
9. A behavior pattern recognition device based on network traffic analysis, characterized in that: The device specifically includes: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute the behavior pattern recognition method based on network traffic analysis according to any one of claims 1-8.
10. A non-volatile computer storage medium having computer executable instructions stored thereon, characterized in that: The computer executable instructions are configured to execute a behavior pattern recognition method based on network traffic analysis according to any one of claims 1-8.