Network traffic anomaly detection method and detection system
By identifying the network feature curve of the IP end from historical data, monitoring and combining the feature curve in real time, and combining attack feature verification, the problem of high false alarm rate of traditional detection methods is solved, and more efficient network traffic anomaly detection is achieved.
Patent Information
- Application Number
- CN202510409822.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-02
AI Technical Summary
Traditional network traffic anomaly detection methods have high false alarm rates, cannot effectively detect emerging attack methods, and are easily affected by normal fluctuations in network traffic, resulting in network managers spending a lot of time and energy to deal with false alarms.
By identifying the network characteristics of different IP ends from historical data, confirming the strongest feature curve, monitoring network traffic in real time, combining the feature curves of the interactive IP end to evaluate the abnormal period, and performing similarity verification with the pre-stored attack characteristics to confirm the abnormal data items and attack characteristics.
It improves the accuracy of network traffic anomaly detection, reduces false alarm rates, can timely identify and handle real security threats, and reduces operational recovery costs and time.
Smart Images

Figure CN120263474A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network anomaly detection, and in particular to a network traffic anomaly detection method and a detection system. Background Art
[0002] With the rapid development of information technology, the Internet plays a vital role in all fields of modern society. From business operations, financial transactions to all aspects of daily life, people's dependence on the Internet is increasing day by day. Against this background, the scale and complexity of network traffic have shown explosive growth, making network traffic anomaly detection a key link in ensuring network security and stable operation.
[0003] In the enterprise network environment, a large amount of business data is transmitted through the network, such as the company's financial data, customer information, R&D materials, etc.; once the network traffic is abnormal, it may mean that it has been attacked by hackers, malware intrusion or internal system failure; for example, hackers may launch DDoS attacks, causing a sudden surge in network traffic, resulting in the paralysis of enterprise servers and business interruption, which not only causes direct economic losses, but also may damage the company's reputation and customer trust due to data leakage; according to relevant statistics, some companies that have suffered serious network attacks have to spend millions or even tens of millions of yuan to resume operations, and the recovery time may be as long as weeks or even months;
[0004] Traditional network traffic anomaly detection methods have many limitations. Rule-based detection methods rely on a pre-set rule base. New attack methods and abnormal situations are often not effectively detected because the rule base is not updated in a timely manner. Although statistical-based detection methods can detect some anomalies based on the statistical characteristics of historical data, they are easily affected by normal fluctuations in network traffic and produce a high false alarm rate, causing network managers to spend a lot of time and energy in dealing with a large number of false alarms, but may miss real security threats. Summary of the invention
[0005] In view of the deficiencies in the prior art, the present invention provides a network traffic anomaly detection method and a detection system, which solve the problem of high false alarm rate in traditional network traffic anomaly monitoring methods.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a method for detecting network traffic anomalies, comprising the following steps:
[0007] Step 1: From the historical interaction data, feature segmentation is performed on the access features associated with multiple different IP terminals associated with the network server to identify the strongest feature curves associated with different IP terminals. The specific sub-steps are:
[0008] S11. Designate the different IP endpoints associated with this server as pending endpoints, identify the historical interaction data associated with different pending endpoints, extract historical traffic data of no less than 12 hours from the historical interaction data, and generate a historical traffic change curve belonging to this pending endpoint based on the chronological relationship;
[0009] S12. Based on the different historical traffic change curves associated with different pending endpoints, select the maximum value and the minimum value from them, determine the historical traffic interval corresponding to the pending endpoint, then divide the historical traffic interval into three interval segments on average, and then select the largest interval segment from the three evenly divided interval segments, and use this largest interval segment as the characteristic segment of this pending endpoint, and its largest interval segment is the value segment where the maximum value is located;
[0010] S13. Lock the partial curve segments belonging to this characteristic segment from the historical traffic change curve. If there are multiple groups of partial curve segments, perform an average process on the historical traffic of different partial curve segments, confirm the average characteristics, and select the partial curve segment associated with the largest average characteristic as the strongest characteristic curve of this pending endpoint; if there is only one group of partial curve segments, use this partial curve segment as the strongest characteristic curve of this pending endpoint;
[0011] Step 2. Monitor the network traffic generated by this network server in real time, and based on the real-time monitored traffic process, confirm the over-limit traffic time period, and based on the interaction IP endpoints associated with the over-limit traffic time period, combine the strongest characteristic curves of the interaction IP endpoints to evaluate whether this over-limit traffic time period is an abnormal time period. The specific method is as follows:
[0012] S21. Monitor the network traffic associated with the network server per unit time in real time, and compare and verify the real-time monitored network traffic with the threshold: Mark the moment when the network traffic > Y1 as the over-limit traffic moment, where Y1 is a preset value. Conversely, do not perform any marking on the moment. Mark the specific time period associated with the continuously occurring over-limit traffic moments as the over-limit traffic time period;
[0013] S22. Based on the designated over-limit traffic time period, confirm the IP endpoints with data interaction within the over-limit traffic time period, extract the strongest characteristic curves associated with the corresponding IP endpoints, and confirm the total characteristic curve segments:
[0014] Denote the total duration of the over-limit traffic time period as the characteristic duration. Select partial curve segments with a time range of the characteristic duration from different strongest characteristic curves and denote them as characteristic curve segments. If the total duration of the strongest characteristic curve ≤ the characteristic duration, then denote this strongest characteristic curve as the characteristic curve segment;
[0015] Combine the characteristic curve segments associated with different strongest characteristic curves, correct the initial moments of the characteristic curve segments to the same moment, sum the network traffic belonging to the same moment after subsequent correction, and denote the network traffic segment after the summation process as the total characteristic curve segment. Different total characteristic curve segments are formed by combining different characteristic curve segments;
[0016] S23. According to the multiple different total characteristic curve segments formed, denote the curve segment associated with the overvalue traffic period as the standard curve segment, and check the different total characteristic curve segments against the standard curve segment to make the initial moment of the total characteristic curve segment coincide with the initial moment of the standard curve: Identify whether the network traffic value of the standard curve segment has not exceeded the numerical range of the total characteristic curve segment all the time. If so, label this total characteristic curve segment as a qualified curve segment; if not, do not perform any labeling;
[0017] If none of several groups of different total characteristic curve segments is a qualified curve segment, label the confirmed overvalue traffic period as an abnormal period; otherwise, do not perform any labeling;
[0018] Step 3. Based on the labeled abnormal period, confirm the interaction data items associated with this abnormal period, and identify and confirm the abnormal data items based on the different network traffic characteristics associated with different interaction data items. The specific method is as follows:
[0019] S31. Confirm the different data items that are in the process of traffic interaction within the abnormal period, and label the traffic fluctuation curves associated with different data items within this abnormal period. Denote the labeled traffic fluctuation curves regarding different data items as the pending curves;
[0020] S32. Check the similarity between the pending curves and the pre-stored attack characteristic fluctuation curves: Place the fluctuation curves belonging to different attack characteristics and the pending curves in the same two-dimensional coordinate system, and translate the pending curves horizontally. During the horizontal translation process, confirm the standard process with the longest total length of the overlapping line segments. Denote the total length of the overlapping line segments in the standard process as ZL i , where i represents different attack characteristics, and denote the total length of the pending curve as Zx. Use: Zb i =Zx÷ZL i to confirm the occupancy ratio Zb associated with this attack characteristic i , and identify whether there is an attack characteristic with: Zb i ≥90%. If so, label the interaction data item associated with this pending curve as an abnormal data item; if not, do not perform any labeling;
[0021] Step 4: Based on the calibrated abnormal data items, confirm the transmission protocol associated with this abnormal data item, confirm the number of registry records from within the transmission protocol, and confirm the attack characteristics based on the number of registry forms generated during the actual registration process. The specific method is as follows:
[0022] Confirm the number of records in the registry from the transmission protocol associated with the abnormal data item and calibrate it as G1;
[0023] Then register the abnormal data items that have completed data interaction. The registered data is stored in a preset storage area. After the abnormal data items are registered, record the total number of registry forms G2, and identify whether G1 and G2 are the same value. If so, no processing is required. If not, mark this abnormal data item as an attack data item, delete the data registered in the storage area, and display it through the display terminal.
[0024] Preferably, a network traffic anomaly detection system includes:
[0025] A feature analysis terminal that divides the access features associated with multiple different IP terminals associated with this network server from historical interaction data and confirms the strongest feature curve associated with different IP terminals;
[0026] An abnormal time period confirmation terminal that monitors the network traffic generated by this network server in real time, confirms the over-limit traffic time period based on the real-time monitored traffic process, and combines the strongest feature curves of the interactive IP terminals associated with the over-limit traffic time period to evaluate whether this over-limit traffic time period is an abnormal time period;
[0027] A data item anomaly identification terminal that confirms the interactive data items associated with this abnormal time period based on the calibrated abnormal time period, and identifies and confirms abnormal data items based on the different network traffic characteristics associated with different interactive data items;
[0028] An attack characteristic confirmation terminal that, based on the calibrated abnormal data items, confirms the transmission protocol associated with this abnormal data item, confirms the number of registry records from within the transmission protocol, and confirms the attack characteristics based on the number of registry forms generated during the actual registration process.
[0029] The present invention provides a network traffic anomaly detection method and detection system. Compared with the prior art, it has the following beneficial effects:
[0030] The present invention identifies different network characteristics associated with different IP addresses from historical data, then confirms the corresponding strongest characteristic curve from the identified different network characteristics. Subsequently, it monitors network traffic in real time, and based on the specific process of real-time monitoring, confirms the specific time period of network traffic anomalies. Then, it combines the characteristics of specific network traffic to identify whether a corresponding traffic anomaly stage will occur when the corresponding IP address is in the highest traffic interaction state. Based on the data characteristics generated by different IP addresses in historical data, it further improves the accuracy of determining data traffic anomalies. Instead of making a determination based on a specific numerical benchmark, it is determined based on past interaction characteristics, thus improving the accuracy in the process of detecting traffic anomalies;
[0031] Based on the confirmed anomaly time period, check the data items with data interaction within the corresponding time period against the attack characteristics recorded in the past, confirm whether the traffic interaction curve has the same characteristics, and perform anomaly verification and detection based on the confirmed specific characteristics, identify specific attack characteristics and perform real-time processing to achieve a better anomaly detection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 is a schematic flowchart of the method of the present invention;
[0033] Figure 2 is a schematic diagram of the principle framework of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0035] The First Embodiment
[0036] Please refer to Figure 1 , this application provides a method for detecting network traffic anomalies, including the following steps:
[0037] Step 1: From historical interaction data, perform feature partitioning on the access characteristics associated with multiple different IP addresses associated with this network server, and confirm the strongest characteristic curve associated with different IP addresses. Specifically, for different IP addresses, there are different network traffic data, so there are different network change characteristics. After the network change characteristics are generated, corresponding network traffic value fluctuations will occur, causing changes in the traffic characteristics of the network server. Therefore, traffic calibration and feature partitioning can be performed based on the corresponding network characteristics to specifically confirm the strongest characteristic curve of network traffic. The specific sub-steps for confirmation are as follows:
[0038] S11. Designate the different IP endpoints associated with this server as pending endpoints, identify the historical interaction data associated with different pending endpoints, extract historical traffic data of no less than 12 hours from the historical interaction data, and generate a historical traffic change curve belonging to this pending endpoint according to the chronological relationship.
[0039] S12. Based on the different historical traffic change curves associated with different pending endpoints, select the maximum value and the minimum value from them, determine the historical traffic range corresponding to the pending endpoint, then evenly divide the historical traffic range into three interval segments, and then select the largest interval segment from the three evenly divided interval segments. Take this largest interval segment as the characteristic segment of this pending endpoint, and its largest interval segment is the value segment where the maximum value is located.
[0040] S13. Lock the partial curve segments belonging to this characteristic segment from the historical traffic change curve. If there is only one group of partial curve segments, take this partial curve segment as the strongest characteristic curve of this pending endpoint. If there are multiple groups of partial curve segments, perform mean processing on the historical traffic of different partial curve segments, confirm the mean characteristics, and select the partial curve segment associated with the largest mean characteristic as the strongest characteristic curve of this pending endpoint. Specifically, for different characteristic segments, there are different characteristic manifestations, and the strongest characteristic curve is confirmed for each pending endpoint. From the specific confirmation process, the strongest characteristics are specifically confirmed for each different pending endpoint. Therefore, different pending endpoints have different characteristic displays, which is convenient for subsequent confirmation of network traffic anomalies.
[0041] Step 2. Monitor the network traffic generated by this network server in real time, and based on the real-time monitored traffic process, confirm the over-valued traffic period. Based on the interactive IP endpoints associated with the over-valued traffic period, combine the strongest characteristic curves of the interactive IP endpoints to evaluate whether this over-valued traffic period is an abnormal period. The specific method for evaluation is as follows:
[0042] S21. Monitor the network traffic associated with the network server per unit time in real time, and compare and verify the real-time monitored network traffic with the threshold: Mark the moment when the network traffic > Y1 as the over-valued traffic moment, where Y1 is a preset value, and its specific value is determined by the operator according to experience. Conversely, do not mark any moment. Record the specific period associated with consecutive over-valued traffic moments as the over-valued traffic period.
[0043] S22. Based on the designated over-valued traffic period, confirm the IP endpoints with data interaction within the over-valued traffic period, extract the strongest characteristic curves associated with the corresponding IP endpoints, and confirm the total characteristic curve segments:
[0044] Record the total duration of the super-value traffic period as the characteristic duration. Select a partial curve segment within the range of the characteristic duration from different strongest characteristic curves and record it as the characteristic curve segment. If the total duration of the strongest characteristic curve ≤ the characteristic duration, then record this strongest characteristic curve as the characteristic curve segment;
[0045] Combine the characteristic curve segments associated with different strongest characteristic curves. Correct the initial moments of the characteristic curve segments to the same moment. Sum the network traffic belonging to the same moment after subsequent correction, and record the network traffic segment after the summation process as the total characteristic curve segment. Different combinations of characteristic curve segments form different total characteristic curve segments (since several characteristic curve segments can be identified within one strongest characteristic curve, the total characteristic curve segments identified between each different characteristic curve segment are different. For example, if the identified characteristic duration is 3 minutes, the duration of one strongest characteristic curve is 4 minutes, and the duration of another strongest characteristic curve is 3 minutes, then the other strongest characteristic curve is directly designated as the characteristic curve segment, and the "one strongest characteristic curve" at its start can be divided into multiple different characteristic curve segments. For example, the curve segments from 0 - 3 minutes, 1 - 4 minutes, etc. will all be recorded as the corresponding characteristic curve segments. Then, during the random combination process, different total characteristic curve segments can be formed);
[0046] S23. According to the multiple different total characteristic curve segments formed, record the curve segment associated with the super-value traffic period as the standard curve segment. Check the different total characteristic curve segments against the standard curve segment to make the initial moment of the total characteristic curve segment coincide with the initial moment of the standard curve: Identify whether the network traffic value of the standard curve segment has never exceeded the value range of the total characteristic curve segment. If so, then designate this total characteristic curve segment as a qualified curve segment. If not, then do not make any designation;
[0047] If none of the several groups of different total characteristic curve segments are qualified curve segments, then designate the identified super-value traffic period as an abnormal period. Otherwise, do not make any designation;
[0048] Specifically, the super-value traffic period is the specific period when the corresponding network traffic exceeds the set value. Within such a period, based on the network traffic characteristics generated by different past IP addresses, relevant confirmation of the corresponding characteristic curve segments is carried out, and based on the characteristic analysis process of the corresponding total characteristic curve segment, it is evaluated whether the traffic abnormal segment generated during the super-value traffic period is within the traffic characteristics of the corresponding IP address. If so, then no processing is required, indicating that there is no abnormality in the corresponding traffic super-value period. Otherwise, it indicates that there may be abnormal behavior in the corresponding traffic abnormal period.
[0049] Step 3: Based on the calibrated abnormal time period, confirm the interaction data items associated with this abnormal time period, and identify and confirm abnormal data items based on the different network traffic characteristics associated with different interaction data items. Specifically, there are historical attack characteristics in the corresponding cloud library, and there are different attack traffic change situations for the attack characteristics. Combining the different interaction characteristics of different data items during this time period, identify and calibrate abnormal data items to determine whether the corresponding data items are similar to past attack characteristics, and conduct real-time evaluation. The specific method for confirmation is as follows:
[0050] S31. Confirm the different data items that are in the process of traffic interaction during the abnormal time period, and calibrate the traffic fluctuation curves associated with different data items during this abnormal time period. Denote the calibrated traffic fluctuation curves of different data items as the to-be-determined curves;
[0051] S32. Perform a similarity check between the to-be-determined curve and the pre-stored attack characteristic fluctuation curves: Place the fluctuation curves belonging to different attack characteristics and the to-be-determined curve in the same two-dimensional coordinate system, and make the to-be-determined curve perform a horizontal translation (since the network traffic associated with its vertical axis is a fixed value, only horizontal translation can be performed). During the horizontal translation process, confirm the standard process with the longest overlapping line length, and calibrate the total length of the overlapping line length in the standard process as ZL i , where i represents different attack characteristics, and calibrate the total line length of the to-be-determined curve as Zx, and use: Zb i = Zx÷ZL i Confirm the occupancy ratio Zb associated with this attack characteristic i , and identify whether there is: Zb i ≥90% of the attack characteristics. If so, calibrate the interaction data item associated with this to-be-determined curve as an abnormal data item. If not, do not perform any calibration;
[0052] Specifically, after the corresponding abnormal data item is specifically determined, subsequently, based on the registration items generated by such data items during the actual interaction process, comprehensively evaluate whether there is an attack behavior for such data items in sequence, display the relevant abnormal signals in a timely manner, and delete the abnormal data generated by such interaction processes in a timely manner;
[0053] Step 4: Based on the calibrated abnormal data item, confirm the transmission protocol associated with this abnormal data item, confirm the number of registry records from the transmission protocol, and confirm the attack characteristics according to the number of registry tables generated during the actual registration process. The specific method for confirmation is as follows:
[0054] Confirm the number of records in the registry from the transmission protocol associated with the abnormal data item and calibrate it as G1;
[0055] Register the abnormal data items that have completed data interaction. The registered data is stored in a preset storage area. After the abnormal data items are registered, record the total number of registry tables G2, and identify whether G1 and G2 are the same value. If so, no processing is required. If not, mark this abnormal data item as an attack data item, delete the data registered in the storage area, and display it through the display terminal;
[0056] Specifically, if there are problems with the corresponding data items, there are generally hidden registration items, which are not displayed in the corresponding transmission protocol but are hidden, and can only be displayed after the corresponding data items are registered. Therefore, in order to make accurate divisions here, the registration method is used to evaluate the relevant number of registry tables to determine whether the corresponding number of registry tables is consistent, so as to display specific features and achieve a more accurate judgment effect.
[0057] Second Embodiment
[0058] Combined with Figure 2 , a network traffic anomaly detection system includes:
[0059] A feature analysis terminal divides the access features associated with multiple different IP terminals associated with this network server from historical interaction data, and confirms the strongest feature curve associated with different IP terminals;
[0060] An abnormal time period confirmation terminal monitors the network traffic generated by this network server in real time, and based on the real-time monitored traffic process, confirms the over-value traffic time period, and combines the strongest feature curves of the interaction IP terminals based on the interaction IP terminals associated with the over-value traffic time period to evaluate whether this over-value traffic time period is an abnormal time period;
[0061] A data item anomaly identification terminal confirms the interaction data items associated with this abnormal time period based on the marked abnormal time period, and identifies and confirms abnormal data items based on the different network traffic features associated with different interaction data items;
[0062] An attack feature confirmation terminal confirms the transmission protocol associated with this abnormal data item based on the marked abnormal data item, confirms the number of registry records in the transmission protocol, and confirms the attack features according to the number of registry tables generated during the actual registration process.
[0063] Some of the data in the above formula are numerically calculated after removing their dimensions, and the content not described in detail in this specification belongs to the prior art well known to those skilled in the art.
[0064] The above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for detecting abnormal network traffic, characterized in that, It includes the following steps: Step 1: From the historical interaction data, perform feature partitioning on the access features associated with multiple different IP addresses associated with this web server, and confirm the strongest feature curves associated with different IP addresses; Step 2: Perform real-time monitoring on the network traffic generated by this web server, and based on the real-time monitored traffic process, confirm the over-value traffic period. Then, based on the interacting IP addresses associated with the over-value traffic period, combine the strongest feature curves of the interacting IP addresses to evaluate whether this over-value traffic period is an abnormal period; Step 3: Based on the calibrated abnormal period, confirm the interaction data items associated with this abnormal period, and based on the different network traffic features associated with different interaction data items, identify and confirm the abnormal data items.
2. The network traffic anomaly detection method according to claim 1, characterized in that, In the above Step 1, the specific sub-steps for confirming the strongest feature curve are as follows: S11: Mark the different IP addresses associated with this server as pending terminals, identify the historical interaction data associated with different pending terminals, extract historical traffic data of no less than 12 hours from the historical interaction data, and generate a historical traffic change curve belonging to this pending terminal according to the chronological relationship; S12: Based on the different historical traffic change curves associated with different pending terminals, select the maximum value and the minimum value therefrom, determine the historical traffic range corresponding to the pending terminal, then evenly divide the historical traffic range into three interval segments, and then select the largest interval segment from the three evenly divided interval segments, and use this largest interval segment as the feature segment of this pending terminal, and its largest interval segment is the value segment where the maximum value is located; S13: Lock the partial curve segments belonging to this feature segment from the historical traffic change curve. If there are multiple groups of partial curve segments, perform mean processing on the historical traffic of different partial curve segments, confirm the mean feature, and select the partial curve segment associated with the largest mean feature as the strongest feature curve of this pending terminal.
3. The network traffic anomaly detection method according to claim 2, characterized in that In the above Step S13, if there is only one group of partial curve segments, use this partial curve segment as the strongest feature curve of this pending terminal.
4. A network traffic anomaly detection method according to claim 1, characterized in that, In the above Step 2, the specific method for evaluating whether this over-value traffic period is an abnormal period is as follows: S21: Perform real-time monitoring on the network traffic associated with the web server per unit time, and compare and verify the real-time monitored network traffic with the threshold: Mark the moment when the network traffic > Y1 as the over-value traffic moment, where Y1 is a preset value. Conversely, do not perform any marking on the moment. Mark the specific period associated with consecutive over-value traffic moments as the over-value traffic period; S22: Based on the calibrated over-value traffic period, confirm the IP addresses with data interaction within the over-value traffic period, extract the strongest feature curves associated with the corresponding IP addresses, and confirm the total feature curve segments: Record the total duration of the over-value traffic period as the feature duration, select partial curve segments with a time range of the feature duration from different strongest feature curves and record them as feature curve segments. If the total duration of the strongest feature curve ≤ the feature duration, then record this strongest feature curve as the feature curve segment; Combine the characteristic curve segments associated with different strongest characteristic curves, correct the initial moments of the characteristic curve segments to the same moment, sum the network traffic belonging to the same moment after subsequent correction, and record the network traffic segment after the summation process as the total characteristic curve segment. Different total characteristic curve segments are formed by combining different characteristic curve segments; S23. According to the multiple different total characteristic curve segments formed, record the curve segment associated with the over-value traffic period as the standard curve segment, and verify the different total characteristic curve segments with the standard curve segment to make the initial moment of the total characteristic curve segment coincide with the initial moment of the standard curve: Identify whether the network traffic value of the standard curve segment has never exceeded the value range of the total characteristic curve segment. If so, label this total characteristic curve segment as a qualified curve segment; if not, do not perform any labeling; If none of the several groups of different total characteristic curve segments are qualified curve segments, label the confirmed over-value traffic period as an abnormal period; otherwise, do not perform any labeling.
5. A network traffic anomaly detection method according to claim 1, characterized in that In step three, the specific method for confirming abnormal data items is as follows: S31. Confirm the different data items that are in the process of traffic interaction during the abnormal period, and label the traffic fluctuation curves associated with different data items during this abnormal period. Record the labeled traffic fluctuation curves of different data items as the pending curves; S32. Perform a similarity check between the curve to be determined and the pre-stored attack feature fluctuation curve: Place the fluctuation curves belonging to different attack features and the curve to be determined in the same two-dimensional coordinate system, and horizontally translate the curve to be determined. During the horizontal translation process, confirm the standard process with the longest overlapping line length, and calibrate the total length of the overlapping line length in the standard process as ZL i , where i represents different attack features, and calibrate the total line length of the curve to be determined as Zx, and use: Zb i = Zx÷ZL i to confirm the occupancy ratio Zb associated with this attack feature i , and identify whether there is an attack feature with: Zb i ≥90%. If there is, calibrate the interaction data item associated with this curve to be determined as an abnormal data item. If not, do not perform any calibration.
6. The network traffic anomaly detection method according to claim 1, wherein It further includes: Step four. Based on the labeled abnormal data items, confirm the transmission protocol associated with this abnormal data item, confirm the number of registry records from the transmission protocol, and confirm the attack characteristics according to the number of registry records generated during the actual registration process.
7. A network traffic anomaly detection method according to claim 6, characterized in that, In step four, the specific method for confirming the attack characteristics is as follows: Confirm the number of registry records from the transmission protocol associated with the abnormal data item and label it as G1; Then register the abnormal data items that have completed data interaction. The registered data is stored in a preset storage area. After the abnormal data items are registered, record the total number of registry records G2, and identify whether G1 and G2 are the same value. If so, do not perform any processing; if not, label this abnormal data item as an attack data item, delete the data registered in the storage area, and display it through the display terminal.
8. A network traffic anomaly detection system, which operates according to the network traffic anomaly detection method described in any one of claims 1-7, characterized in that, It includes: A characteristic analysis terminal that divides the access characteristics associated with multiple different IP addresses associated with this network server from historical interaction data and confirms the strongest characteristic curves associated with different IP addresses; An abnormal period confirmation terminal that monitors the network traffic generated by this network server in real time, confirms the over-value traffic period based on the real-time monitored traffic process, and combines the strongest characteristic curves of the interactive IP addresses based on the interactive IP addresses associated with the over-value traffic period to evaluate whether this over-value traffic period is an abnormal period; A data item abnormality identification terminal that confirms the interactive data items associated with this abnormal period based on the labeled abnormal period, and identifies and confirms abnormal data items based on the different network traffic characteristics associated with different interactive data items; The attack feature confirmation end, based on the calibrated abnormal data items, confirms the transmission protocol associated with this abnormal data item, confirms the number of registry records from within the transmission protocol, and conducts attack feature confirmation according to the number of registry tables generated during the actual registration process.
Citation Information
Patent Citations
Method and device for determining attack destination IP of DDOS attack
CN106899608A
Method for monitoring network traffic abnormity
CN107733737A
Method and device for detecting DDOS (Distributed Denial of Service) attacks, and detection server
CN109617868A
Low-delay and safe vehicle-mounted intrusion detection method based on deep learning
CN113162902A
Traffic abnormity alarm method and device, electronic equipment and storage medium
CN115174254A
Cited By
Software running state monitoring method based on software safe running
CN120811653A