Network abnormal flow analysis method
By clustering analysis of historical network traffic data and dynamically updating thresholds, the problem of difficulty in adapting to dynamic changes in network traffic in the prior art is solved, and the accuracy and efficiency of network abnormal traffic monitoring is improved.
Patent Information
- Application Number
- CN202510539615.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-06-27
AI Technical Summary
Existing threshold-based network abnormal traffic analysis methods are difficult to adapt to the dynamic changes in network traffic, which may lead to false positives or missed reports.
By obtaining historical network traffic data, performing clustering analysis to divide the data into multiple type clusters, and compute the traffic size and number of connections thresholds for each type cluster. Monitor network traffic in real time, judge whether the threshold is exceeded based on the new traffic data type, and update the threshold dynamically.
It improves the monitoring quality and efficiency of network traffic abnormalities, reduces the false alarm and missed alarm rates, and enhances the security and stability of the network.
Smart Images

Figure CN120223428A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network monitoring, and particularly to a method for analyzing network abnormal traffic. Background Art
[0003] With the rapid development of network technology, network traffic has become increasingly complex and diverse. The emergence of network abnormal traffic, such as DDoS attacks, malware propagation, etc., will seriously affect the normal operation of the network, resulting in problems such as network congestion and service interruption, bringing huge losses to network service providers and users. Network abnormal traffic analysis methods are used to monitor abnormal traffic in the network and give early warnings when abnormal situations are detected. Among them, the process of the network abnormal traffic analysis method based on thresholds is: set thresholds for indicators such as traffic size, number of data packets, data packet size, number of connections, etc., and if the threshold is exceeded, it is regarded as abnormal and a warning is given. This method is simple to implement, but has poor adaptability to dynamic changes and is prone to false alarms and missed alarms. Specifically, network traffic has the characteristics of dynamic changes, and the normal traffic ranges vary greatly in different time periods and different application scenarios. Fixed thresholds are difficult to adapt to the dynamic changes of network traffic, which may lead to misjudging normal traffic as abnormal during peak traffic periods, or failing to detect real abnormal traffic during low traffic periods. Therefore, it is necessary to provide a network abnormal traffic analysis method that can adaptively adjust thresholds to improve the monitoring efficiency of network traffic anomalies. Summary of the Invention
[0005] One object of the present invention is to solve at least the above problems and / or deficiencies, and provide at least the advantages described hereinafter.
[0006] One object of the present invention is to provide a method for analyzing network abnormal traffic, which can pre-classify network traffic data according to the distribution of network traffic data, and update the warning threshold according to the traffic size in the real-time network traffic data of each type, so as to improve the monitoring quality and monitoring efficiency of network traffic data anomalies, reduce the false alarm rate and missed alarm rate, and improve the security and stability of the network.
[0007] To achieve these objects and other advantages of the present invention, there is provided a method for analyzing network abnormal traffic, including: Step 1, obtain historical network traffic data, including traffic size data at multiple moments in a historical period; Step 2: According to the types of historical network traffic data, perform clustering analysis on the historical network traffic data to obtain multiple type clusters. Assign the traffic size data at each moment to the type cluster to which the nearest clustering center belongs, recalculate the clustering center of the corresponding type cluster, and iterate continuously until the change in the clustering center is less than the preset convergence threshold A or the preset maximum number of iterations is reached, so as to obtain the updated type clusters. Each type cluster corresponds to a network traffic data type, and each cluster contains the traffic size data at the multiple moments; Step 3: For the updated type clusters, calculate the average value of the traffic size data contained in each type cluster in a historical period as the traffic size threshold B of the type cluster; Step 4: Monitor the network traffic data in real time. When new network traffic data flows in, according to the type of the new network traffic data, assign the new traffic size data to the corresponding type cluster, and determine whether the new traffic size data exceeds the traffic size threshold B of the corresponding type cluster. If it exceeds, issue an early warning for network abnormal traffic analysis. If it does not exceed, recalculate the new average value of the traffic size data contained in the type cluster. If the change range of the new average value exceeds the first preset amplitude threshold C1, update the new average value to the traffic size threshold B of the corresponding type cluster.
[0008] Preferably, in the network abnormal traffic analysis method, in Step 1, the historical network traffic data further includes multiple connection number data at the multiple moments in the historical period; in Step 2, each type cluster contains the connection number data at the several moments; in Step 3, for each type cluster, calculate the average value of the connection number data contained in the corresponding type cluster as the connection number threshold D of the corresponding network traffic data type; in Step 4, if the size of the new traffic data does not exceed the threshold B, and the connection number data associated with the new traffic data exceeds the connection number threshold D, issue an early warning for network abnormal traffic analysis. If the connection number data associated with the new traffic data does not exceed the connection number threshold D, recalculate the new average value of the connection number data associated with the new traffic data contained in the type cluster according to the connection number data associated with the new traffic data. If the change range of the new average value of the connection number data associated with the new traffic data exceeds the second preset amplitude threshold C2, update the new average value of the connection number data associated with the new traffic data to the connection number threshold D of the corresponding type cluster.
[0009] Preferably, in the network abnormal traffic analysis method, Step 1 includes: Determine the network location of the data set, where the network location includes network devices, server sides, and border gateways; Select the data collection frequency according to the network scale, business requirements, and historical period length; Among them, for small networks with the number of nodes < 100, data of the basic performance indicators of network devices are collected every 5 - 10 minutes; the historical network traffic data are collected every 15 - 30 minutes; For medium-sized networks with 100 ≤ the number of nodes < 1000, data of the basic performance indicators of network devices are collected every 2 - 5 minutes; the historical network traffic data are collected every 10 - 15 minutes; and For large networks with the number of nodes ≥ 1000, data of the basic performance indicators of network devices are collected every 1 - 2 minutes; the historical network traffic data are collected every 5 - 10 minutes.
[0010] Preferably, in the network abnormal traffic analysis method, step one includes: Describing the relationship between the historical network traffic data and the basic performance indicators of the network device based on a multiple linear regression model, training and parameter estimation of the multiple linear regression model are carried out, and the coefficients of the multiple linear regression model are solved by the least squares method; Among them, the multiple linear regression model is: The corrected traffic volume E' = traffic volume E + β0 + β1 × CPU usage rate + β2 × C memory usage rate + β3 × port bandwidth utilization rate + Δ; Among them, β0, β1, β2, β3 are the coefficients of the multiple linear regression model, and Δ is the error term; Based on the multiple linear regression model, the traffic volume data at multiple moments are corrected.
[0011] Preferably, in the network abnormal traffic analysis method, step one includes: β0 is 5 - 10 Mbps; β1 is 20 - 30 Mbp; β2 is 15 - 20 Mbp; β3 is 30 - 3 Mbp; The error term Δ is set to follow a normal distribution with a mean of 0 and a standard deviation of 8% of the historical network traffic data.
[0012] Preferably, in the network abnormal traffic analysis method, step two includes: For small networks, the preset convergence threshold A is set between 0.01 - 0.03; for medium-sized or large networks, the preset convergence threshold A is set between 1 - 10.
[0013] Preferably, in the network abnormal traffic analysis method, step two includes: For small networks, the traffic volume threshold B is set between 50 - 100 Mbps; For a medium-sized network, the traffic volume threshold B is set between 500 - 1000 Mbps; For a large-sized network, the traffic volume threshold B is set above 1000 Mbps.
[0014] Preferably, in the network abnormal traffic analysis method, in step four, both the first preset amplitude threshold C1 and the second preset amplitude threshold C2 are set between 15% - 30%.
[0015] Preferably, in the network abnormal traffic analysis method, step 3 includes: For a small-sized network, the connection number threshold D is set between 100 - 1000; For a medium-sized network, the connection number threshold D is set between 1000 - 10000; For a large-sized network, the connection number threshold D is set above 10000.
[0016] The present invention has at least the following beneficial effects: The present invention provides a network abnormal traffic analysis method, including: Step 1, obtaining historical network traffic data, including traffic volume data at multiple moments in a historical period; Step 2, performing clustering analysis on the historical network traffic data according to the historical network traffic data type to obtain multiple type clusters, allocating the traffic volume data at each moment to the type cluster to which the nearest clustering center belongs, recalculating the clustering center of the corresponding type cluster, and continuously iterating until the change in the clustering center is less than the preset convergence threshold A or reaches the preset maximum number of iterations, so as to obtain the updated type clusters. Each type cluster corresponds to a network traffic data type, and each cluster contains the traffic volume data at the multiple moments; Step 3, for the updated type clusters, calculating the average value of the traffic volume data contained in each type cluster in a historical period as the traffic volume threshold B of the type cluster; Step 4, monitoring the network traffic data in real time. When new network traffic data flows in, according to the type of the new network traffic data, allocating the new traffic volume data to the corresponding type cluster, and determining whether the new traffic volume data exceeds the traffic volume threshold B of the corresponding type cluster. If it exceeds, an early warning of network abnormal traffic analysis is issued. If it does not exceed, recalculate the new average value of the traffic volume data contained in the type cluster. If the change amplitude of the new average value exceeds the first preset amplitude threshold C1, update the new average value to the traffic volume threshold B of the corresponding type cluster. The present invention can pre-classify the network traffic data according to the distribution of the network traffic data, and update the warning threshold according to the traffic volume in the real-time network traffic data of each type, thereby improving the monitoring quality and monitoring efficiency of the abnormal situation of the network traffic data, reducing the false alarm rate and missed alarm rate, and improving the security and stability of the network.
[0017] Other advantages, objectives and features of the present invention will be partially reflected by the following description, and partially will also be understood by those skilled in the art through the research and practice of the present invention. Brief Description of the Drawings
[0019] Figure 1 It is a flowchart of the network abnormal traffic analysis method provided by the present invention. Detailed Embodiments
[0021] The following further describes the present invention in detail with reference to the accompanying drawings, so that those skilled in the art can implement it according to the description in the specification.
[0022] As Figure 1 shown, the present invention provides a network abnormal traffic analysis method, including: Step 1: Obtain historical network traffic data: Obtain historical network traffic data, including traffic size data at multiple moments in a historical period.
[0023] Specifically, in Step 1, traffic size data at multiple moments in a historical period can be obtained through a network monitoring device or relevant data collection tools. The historical period can be set according to actual needs, such as one week, one month, etc. These data contain traffic information of the network in normal operation state and possible abnormal states, providing basic data support for subsequent analysis.
[0024] Step 2: Cluster analysis: According to the historical network traffic data type, perform cluster analysis on the historical network traffic data to obtain multiple type clusters. Assign the traffic size data of each moment to the type cluster to which the nearest cluster center belongs, recalculate the cluster center of the corresponding type cluster, and iterate continuously until the change in the cluster center is less than a preset convergence threshold A or reaches a preset maximum number of iterations, so as to obtain the updated type clusters. Each type cluster corresponds to a network traffic data type, and each cluster contains the traffic size data of the multiple moments.
[0025] In step two, cluster analysis is performed on the historical network traffic data according to the types of historical network traffic data. Common clustering algorithms such as the K-Means algorithm can be specifically used. During the clustering process, the traffic size data at each moment is assigned to the type cluster to which the nearest cluster center belongs, and then the cluster centers of the corresponding type clusters are recalculated. This process is continuously iterated until the change in the cluster center is less than the preset convergence threshold A or the preset maximum number of iterations is reached, thereby obtaining the updated type clusters. Each type cluster corresponds to a network traffic data type, and each cluster contains the traffic size data of the multiple moments. Through cluster analysis, traffic data with similar characteristics can be grouped into one category, facilitating subsequent processing and analysis for different types of traffic respectively. For example, for a home network, the traffic distribution of network traffic data within a day may exhibit different characteristics. Between 8 o'clock and 20 o'clock, some family members go out to work and only 1 family member is at home, and the traffic is relatively small, so the traffic size threshold B for determining anomalies is also relatively small; between 20 o'clock and 24 o'clock, all family members are at home and the traffic is relatively large, and the traffic size threshold B for determining anomalies is also relatively large; between 0 o'clock and 8 o'clock is the rest time and the traffic is the smallest, and the traffic size threshold B for determining anomalies is the smallest. In the above three time periods, the traffic distributions are different, so the set thresholds should also be different. Based on this, historical network traffic data for multiple days can be obtained first for clustering, and finally three network traffic data types with obvious distribution characteristics are obtained through clustering. Then, corresponding thresholds are set for each type of network traffic data.
[0026] Furthermore, the K-Means clustering algorithm can be adopted. First, determine the initial number of cluster centers K. The value of K can be determined based on historical experience or through some data analysis methods (such as the elbow method). For example, after analysis, it is found that dividing the network traffic data into 5 categories can better reflect different traffic patterns, so K is set to 5. Start the clustering iteration process. For the traffic size data at each moment, calculate its distance from each cluster center (such as the Euclidean distance), and assign it to the type cluster to which the nearest cluster center belongs. Recalculate the cluster center of each type cluster. For example, for a certain type cluster, take the average value of all traffic size data in the cluster as the new cluster center. Repeat the above steps and continuously iterate, calculating the change in the cluster center after each iteration. When the change in the cluster center is less than the preset convergence threshold A (such as 0.01) or reaches the preset maximum number of iterations (such as 100 times), stop the iteration to obtain the updated and stable type clusters.
[0027] Step 3. Calculate the traffic size threshold: For the updated type clusters, calculate the average value of the traffic size data included in each type cluster in a historical period as the traffic size threshold B for this type cluster. This threshold will serve as an important basis for subsequent judgment of whether real-time traffic is abnormal. The traffic size thresholds B for different type clusters reflect the average level of this type of traffic under normal circumstances.
[0028] Specifically, for each updated type cluster, traverse all the traffic size data in this cluster within the historical period. Calculate the average value of these data as the traffic size threshold B for this type cluster. For example, if a type cluster contains traffic size data at 1000 moments, add these data and divide by 1000 to obtain the traffic size threshold B for this type cluster.
[0029] Step 4. Real-time monitoring and judgment: Real-time monitor the network traffic data. When new network traffic data flows in, according to the type of the new network traffic data, allocate the new traffic size data to the corresponding type cluster, and judge whether the new traffic size data exceeds the traffic size threshold B of the corresponding type cluster. If it exceeds, issue an early warning for network abnormal traffic analysis. If it does not exceed, recalculate the new average value of the traffic size data included in this type cluster. If the change range of the new average value exceeds the first preset amplitude threshold C1, update the new average value to the traffic size threshold B of the corresponding type cluster.
[0030] Specifically, according to the pre-set classification method of traffic data types, determine the type cluster to which the new traffic data belongs. Compare the size of the new traffic data with the traffic size threshold B of the corresponding type cluster. If the new traffic data is greater than the threshold B, send a network abnormal traffic warning message by means of SMS, email or system pop-up window, etc., to prompt the network administrator that there may be abnormal traffic conditions. If the new traffic data does not exceed the threshold B, add this new data to the traffic data set of the corresponding type cluster and recalculate the new average value of the traffic size data of this type cluster. For example, if there were originally 100 data in this type cluster, recalculate the average value of these 101 data after adding the new data. Calculate the change range between the new average value and the original average value. If the change range exceeds the first preset amplitude threshold C1, update the new average value to the traffic size threshold B of the corresponding type cluster, indicating that the change range of the network traffic has reached a certain degree and has changed greatly, and the threshold needs to be updated to adapt to the change of the network traffic. Based on the above process, the threshold can be dynamically adjusted according to the actual change of the network traffic, improving the accuracy and adaptability of detection.
[0031] Here, the change range of the new average value refers to the difference between the new average value and the original average value, and then divided by the original average value, what is obtained is the change range of the new average value.
[0032] In summary, by performing clustering analysis on historical network traffic data, the present invention can more accurately identify different types of network traffic patterns, set corresponding thresholds for each type of traffic, and greatly improve the detection accuracy compared with the traditional single-threshold detection method, reducing the probabilities of false alarms and missed detections. In addition, during the real-time monitoring process, the present invention dynamically adjusts the thresholds according to newly incoming traffic data, can adapt to the dynamic change characteristics of network traffic, and timely discovers abnormal traffic in the network. Even when the network traffic pattern changes, it can maintain a high detection performance. Further, the method of the present invention can process complex and diverse network traffic data, has good detection effects for different types of network applications, different scales of networks, and various potential abnormal traffic behaviors, has strong versatility and adaptability, and can meet the security monitoring requirements in the current complex network environment.
[0033] In a preferred embodiment, in the network abnormal traffic analysis method, in step one, the historical network traffic data further includes multiple connection number data at multiple moments in the historical period; in step two, each type cluster includes the connection number data at the several moments; in step three, for each type cluster, calculate the average value of the connection number data included in the corresponding type cluster as the connection number threshold D for the corresponding network traffic data type; in step four, if the size of the new traffic data does not exceed threshold B, and the connection number data associated with the new traffic data exceeds the connection number threshold D, then issue a warning for network abnormal traffic analysis. If the connection number data associated with the new traffic data does not exceed the connection number threshold D, then recalculate the new average value of the connection number data associated with the new traffic data included in this type cluster according to the connection number data associated with the new traffic data. If the change range of the new average value of the connection number data associated with the new traffic data exceeds the second preset amplitude threshold C2, update the new average value of the connection number data associated with the new traffic data to the connection number threshold D for the corresponding type cluster.
[0034] The connection number thresholds D of different type clusters reflect the average connection number level of this type of traffic under normal circumstances. For each type cluster, traverse all the connection number data in this cluster during the historical period. Add these data and divide by the number of data points to obtain the connection number threshold D of this type cluster.
[0035] If the new traffic size data does not exceed threshold B and the number of connections does not exceed the connection number threshold D, then based on the new traffic size data and the number of connections, recalculate the new average values of the traffic size data and the connection number data included in this type of cluster. When the change range of the new average value of the traffic size data exceeds the first preset amplitude threshold C1, or the change range of the new average value of the connection number exceeds the second preset amplitude threshold C2 (C1 and C2 can be set respectively according to the actual situation), update the new average values to the traffic size threshold B and the connection number threshold D of the corresponding type of cluster respectively. This can enable the thresholds to be dynamically adjusted according to the actual changes in network traffic, improve the accuracy and adaptability of detection, and monitor network abnormal traffic more comprehensively from multiple dimensions.
[0036] This embodiment can also issue a warning about the abnormal situation of network traffic based on the connection number data, so as to monitor the abnormal situation of network traffic from multiple dimensions to improve the monitoring quality and monitoring efficiency.
[0037] In a preferred embodiment, in the network abnormal traffic analysis method, step one includes: determining the network location of the data set, where the network location includes network devices, server sides, and border gateways; selecting the data collection frequency according to the network scale, service requirements, and historical cycle length; for a small network with the number of nodes < 100, for the basic performance indicators of network devices, collect data every 5 - 10 minutes; collect the historical network traffic data every 15 - 30 minutes; for a medium-sized network with 100 ≤ the number of nodes < 1000, for the basic performance indicators of network devices, collect data every 2 - 5 minutes; collect the historical network traffic data every 10 - 15 minutes; and for a large network with the number of nodes ≥ 1000, for the basic performance indicators of network devices, collect data every 1 - 2 minutes; collect the historical network traffic data every 5 - 10 minutes.
[0038] For a small network with the number of nodes < 100, for the basic performance indicators of network devices, collect data every 5 - 10 minutes; collect the historical network traffic data every 15 - 30 minutes. The traffic of a small network is relatively stable. A lower data collection frequency can reduce the cost and workload of data collection while ensuring the acquisition of necessary information.
[0039] For a medium-sized network with 100 ≤ the number of nodes < 1000, for the basic performance indicators of network devices, collect data every 2 - 5 minutes; collect the historical network traffic data every 10 - 15 minutes. The traffic change of a medium-sized network is relatively complex. Appropriately increasing the data collection frequency can capture the changes in network traffic more timely.
[0040] For large networks with the number of nodes ≥ 1000, for the basic performance indicators of network devices, data is collected every 1 - 2 minutes; the historical network traffic data is collected every 5 - 10 minutes. The traffic in large networks changes rapidly and complexly. A higher data collection frequency can ensure obtaining sufficiently detailed traffic information to accurately detect abnormal traffic.
[0041] In a preferred embodiment, in the network abnormal traffic analysis method, step one includes: describing the relationship between the historical network traffic data and the basic performance indicators of the network device based on a multiple linear regression model, training and parameter estimating the multiple linear regression model, and solving the coefficients of the multiple linear regression model by the least squares method; wherein, the multiple linear regression model is: the corrected traffic volume E’ = traffic volume E + β0 + β1 × CPU usage rate + β2 × C memory usage rate + β3 × port bandwidth utilization rate + Δ; where β0, β1, β2, and β3 are the coefficients of the multiple linear regression model, and Δ is the error term; correcting the traffic volume data at the multiple moments based on the multiple linear regression model.
[0042] Specifically, substitute the traffic volume data at multiple moments in the collected historical network traffic data into the obtained multiple linear regression model to calculate the corrected traffic volume, and complete the correction of the traffic volume data in the historical network traffic data. Candidate calculations are all performed on the corrected traffic volume data. In addition, when monitoring network traffic data, it is also necessary to correct the new traffic data and then make a judgment based on the corrected traffic data.
[0043] Correcting the historical network traffic data through the multiple linear regression model eliminates the influence of the basic performance indicators of network devices on the traffic volume, obtains data that can better reflect the true network traffic situation, provides a more accurate basis for subsequent clustering analysis and threshold calculation, and further improves the accuracy of abnormal traffic detection.
[0044] In a preferred embodiment, in the network abnormal traffic analysis method, step one includes: β0 is 5 - 10 Mbps; β1 is 20 - 30 Mbp; β2 is 15 - 20 Mbp; β3 is 30 - 3 Mbp; the error term Δ is set to follow a normal distribution with a mean of 0 and a standard deviation of 8% of the historical network traffic data.
[0045] In a preferred embodiment, in the network abnormal traffic analysis method, step two includes: for small networks, the preset convergence threshold A is set between 0.01 - 0.03; for medium or large networks, the preset convergence threshold A is set between 1 - 10.
[0046] In a preferred embodiment, in the network abnormal traffic analysis method, step two includes: for a small network, the traffic volume threshold B is set between 50 - 100 Mbps; for a medium-sized network, the traffic volume threshold B is set between 500 - 1000 Mbps; for a large network, the traffic volume threshold B is set above 1000 Mbps.
[0047] In a preferred embodiment, in the network abnormal traffic analysis method, in step four, both the first preset amplitude threshold C1 and the second preset amplitude threshold C2 are set between 15% - 30%.
[0048] In a preferred embodiment, in the network abnormal traffic analysis method, step 3 includes: for a small network, the connection number threshold D is set between 100 - 1000; for a medium-sized network, the connection number threshold D is set between 1000 - 10000; for a large network, the connection number threshold D is set above 10000.
[0049] Although the embodiments of the present invention have been disclosed above, it is not limited to the applications listed in the specification and embodiments. It can be fully applied to various fields suitable for the present invention. For those familiar with the field, additional modifications can be easily achieved. Therefore, without departing from the general concept defined by the claims and the equivalent scope, the present invention is not limited to the specific details and the illustrated and described examples here.
Claims
1. A method for analyzing abnormal network traffic, characterized in that: include: Step 1: Obtain historical network traffic data, including traffic size data at multiple times in a historical period; Step 2: According to the historical network traffic data type, cluster analysis is performed on the historical network traffic data to obtain multiple type clusters, and the traffic size data at each moment is assigned to the type cluster to which the nearest cluster center belongs, and the cluster center of the corresponding type cluster is recalculated, and it is continuously iterated until the cluster center change is less than a preset convergence threshold A or reaches a preset maximum number of iterations, thereby obtaining an updated type cluster, each type cluster corresponds to a network traffic data type, and each cluster contains the traffic size data at the multiple moments; Step 3: For the updated type cluster, calculate the average value of the traffic size data contained in each type cluster in a historical period as the traffic size threshold B of the type cluster; Step 4: monitor network traffic data in real time. When new network traffic data flows in, assign the new traffic size data to the corresponding type cluster according to the type of the new network traffic data, and determine whether the new traffic size data exceeds the traffic size threshold B of the corresponding type cluster. If so, issue a network abnormal traffic analysis warning. If not, recalculate the new average value of the traffic size data contained in the type cluster. If the change amplitude of the new average value exceeds the first preset amplitude threshold C1, update the new average value to the traffic size threshold B of the corresponding type cluster.
2. The method for analyzing abnormal network traffic according to claim 1, characterized in that: In the step one, the historical network traffic data also includes multiple connection number data at the multiple moments in the historical period; in the step two, each type cluster includes the connection number data at the several moments; in the step three, for each type cluster, the average value of the connection number data included in the corresponding type cluster is calculated as the connection number threshold D of the corresponding network traffic data type; in the step four, if the size of the new traffic data does not exceed the threshold B, and the connection number data associated with the new traffic data exceeds the connection number threshold D, an abnormal network traffic analysis warning is issued, and if the connection number data associated with the new traffic data does not exceed the connection number threshold D, then based on the connection number data associated with the new traffic data, a new average value of the connection number data associated with the new traffic data contained in the type cluster is recalculated; if the change amplitude of the new average value of the connection number data associated with the new traffic data exceeds the second preset amplitude threshold C2, the new average value of the connection number data associated with the new traffic data is updated to the connection number threshold D of the corresponding type cluster.
3. The method for analyzing abnormal network traffic according to claim 1, characterized in that: The step one comprises: Determine a network location of the data set, the network location including a network device, a server, and a border gateway; Select the data collection frequency based on network size, business needs, and the length of the historical cycle; For small networks with less than 100 nodes, data on basic performance indicators of network equipment is collected every 5-10 minutes; historical network traffic data is collected every 15-30 minutes; For medium-sized networks with 100 ≤ nodes and < 100 nodes, data on basic performance indicators of network equipment is collected every 2-5 minutes; historical network traffic data is collected every 10-15 minutes; and For large networks with ≥1000 nodes, data on basic performance indicators of network devices is collected every 1-2 minutes; historical network traffic data is collected every 5-10 minutes.
4. The method for analyzing abnormal network traffic according to claim 3, characterized in that: The step one comprises: Describing the relationship between the historical network traffic data and the basic performance indicators of the network device based on a multiple linear regression model, training and parameter estimation of the multiple linear regression model, and solving the coefficients of the multiple linear regression model by the least squares method; Wherein, the multiple linear regression model is: Corrected traffic size E' = traffic size E + β0 + β1 × CPU usage + β2 × C memory usage + β3 × port bandwidth utilization + Δ; Wherein, β0, β1, β2, β3 are the coefficients of the multivariate linear regression model, and Δ is the error term; The flow rate data at the multiple moments are corrected based on the multiple linear regression model.
5. The method for analyzing abnormal network traffic according to claim 4, characterized in that: The step one comprises: β0 is 5-10Mbps; β1 is 20-30Mbp; β2 is 15-20Mbp; β3 is 30-3Mbp; The error term Δ is set to obey a normal distribution with a mean of 0 and a standard deviation of 8% of the historical network traffic data.
6. The method for analyzing abnormal network traffic according to claim 3, characterized in that: The second step comprises: For a small network, the preset convergence threshold A is set between 0.01-0.03; for a medium-sized network or a large network, the preset convergence threshold A is set between 1-10.
7. The method for analyzing abnormal network traffic according to claim 3, characterized in that: The second step comprises: For a small network, the traffic size threshold B is set between 50-100 Mbps; For a medium-sized network, the traffic size threshold B is set between 500-1000 Mbps; For a large network, the traffic size threshold B is set above 1000 Mbps.
8. The method for analyzing abnormal network traffic according to claim 3, characterized in that: In the step 4, the first preset amplitude threshold C1 and the second preset amplitude threshold C2 are both set between 15% and 30%.
9. The method for analyzing abnormal network traffic according to claim 2, characterized in that: The step 3 comprises: For a small network, the connection number threshold D is set between 100 and 1000; For a medium-sized network, the connection number threshold D is set between 1000 and 10000; For a large network, the connection number threshold D is set above 10,000.
Citation Information
Cited By
Network quality detection method and device for 5G customized network, and computer program product
CN121692271A
Traffic monitoring system based on network audio-visual new media
CN121792223A
A network-based audiovisual new media flow monitoring system
CN121792223B