A network traffic anomaly detection method and detection system
By extracting IP-side characteristic curves from historical data and combining them with real-time monitoring, network traffic anomalies can be identified, solving the problem of high false alarm rates in traditional detection methods and achieving more efficient network attack identification and processing.
Patent Information
- Application Number
- CN202510409822.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-04-02
AI Technical Summary
Traditional network traffic anomaly detection methods have high false alarm rates and are difficult to deal with new attack methods.
By extracting access features of different IP terminals from historical interaction data, identifying the strongest characteristic curve, and combining it with real-time monitored network traffic, confirming whether the period of excessive traffic is an abnormal period, using characteristic curve combination and similarity verification to identify abnormal data items, and finally confirming the attack characteristics through the number of registry tables of the transmission protocol.
It improves the accuracy of network traffic anomaly detection, reduces false alarm rates, enables timely identification and handling of network attacks, and reduces operating costs and recovery time.
Smart Images

Figure CN120263474B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network anomaly detection, and in particular to a network traffic anomaly detection method and detection system. Background Art
[0002] With the rapid development of information technology, the Internet plays a vital role in all areas of modern society. From business operations and financial transactions to all aspects of daily life, people's dependence on the Internet is increasing day by day. Against this background, the scale and complexity of network traffic have shown explosive growth, making network traffic anomaly detection a key link in ensuring network security and stable operation.
[0003] In enterprise networks, large amounts of business data, such as financial data, customer information, and R&D materials, are transmitted over the network. Any abnormal network traffic may indicate a hacker attack, malware intrusion, or internal system failure. For example, hackers may launch a DDoS attack, causing a sudden surge in network traffic, paralyzing enterprise servers and disrupting business operations. This not only causes direct financial losses but can also damage the company's reputation and customer trust through data leaks. According to relevant statistics, some companies that have suffered serious cyberattacks have faced costs of millions or even tens of millions of yuan to recover, and recovery can take weeks or even months.
[0004] Traditional methods for detecting anomalies in network traffic have many limitations. Rule-based detection methods rely on a pre-set rule base, and are often unable to effectively detect emerging attack methods and anomalies because the rule base is not updated in a timely manner. While statistical-based detection methods can detect some anomalies based on the statistical characteristics of historical data, they are easily affected by normal fluctuations in network traffic, resulting in a high false alarm rate. This causes network administrators to waste a lot of time and energy dealing with a large number of false alarms, while potentially missing out on real security threats. Summary of the Invention
[0005] In view of the shortcomings of the existing technology, the present invention provides a network traffic anomaly detection method and detection system, which solves the problem of high false alarm rate in traditional network traffic anomaly monitoring methods.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A method for detecting network traffic anomalies, comprising the following steps:
[0007] Step 1: From the historical interaction data, the access characteristics associated with multiple different IP terminals associated with this network server are divided into features to identify the strongest characteristic curves associated with different IP terminals. The specific sub-steps are:
[0008] S11. Different IP terminals associated with the server are marked as pending terminals, historical interaction data associated with the different pending terminals is identified, and historical traffic data of no less than 12 hours is extracted from the historical interaction data. Based on the time sequence, a historical traffic change curve belonging to the pending terminal is generated;
[0009] S12. Based on different historical traffic change curves associated with different pending endpoints, the maximum and minimum values are selected to determine the historical traffic interval corresponding to the pending endpoint. The historical traffic interval is then divided equally into three interval segments. The largest interval segment is then selected from the three equally divided interval segments and used as the characteristic segment of the pending endpoint. The largest interval segment is also the value segment where the maximum value is located.
[0010] S13. Locate a partial curve segment belonging to the characteristic segment from the historical flow change curve. If multiple groups of partial curve segments exist, average the historical flow of different partial curve segments to confirm the average characteristics, and select the partial curve segment associated with the maximum average characteristic as the strongest characteristic curve of the pending end. If only one group of partial curve segments exists, select this partial curve segment as the strongest characteristic curve of the pending end.
[0011] Step 2: Monitor the network traffic generated by this network server in real time, and based on the real-time monitored traffic process, identify the period of excessive traffic, and based on the interactive IP terminals associated with the excessive traffic period, combine the strongest characteristic curves of the interactive IP terminals to assess whether the excessive traffic period is an abnormal period. The specific method is as follows:
[0012] S21. Monitor the network traffic associated with the network server per unit time in real time, and compare the real-time monitored network traffic with a threshold value. A moment when the network traffic is greater than Y1 is recorded as an excess traffic moment, where Y1 is a preset value. Otherwise, no calibration is performed on the moment, and the specific period associated with consecutive excess traffic moments is recorded as an excess traffic period.
[0013] S22. Based on the calibrated excess traffic period, identify the IP terminals that interact with data within the excess traffic period, extract the strongest characteristic curve associated with the corresponding IP terminal, and confirm the total characteristic curve segment:
[0014] The total duration of the excess flow period is recorded as the characteristic duration. From different strongest characteristic curves, a section with a time range of the characteristic duration is selected and recorded as the characteristic section. If the total duration of the strongest characteristic curve is ≤ the characteristic duration, then this strongest characteristic curve is recorded as the characteristic section.
[0015] The characteristic segments associated with the strongest characteristic curves are combined, the initial moments of the characteristic segments are corrected to the same moment, the network traffic at the same moment after subsequent correction is summed, and the summed network traffic segment is recorded as the characteristic total segment. Different characteristic segments are combined to form different characteristic total segments.
[0016] S23. Based on the generated multiple different characteristic total segments, the curve segments associated with the periods of excessive traffic are recorded as standard curve segments. The different characteristic total segments are then verified against the standard curve segments to ensure that the initial time of the characteristic total segment coincides with the initial time of the standard curve. The network traffic values of the standard curve segments are determined to have consistently remained within the numerical range of the characteristic total segment. If so, the characteristic total segment is calibrated as a standard-compliant segment; otherwise, no calibration is performed.
[0017] If there is no set of standard sections among several different sets of characteristic total sections, the confirmed excessive flow period will be marked as an abnormal period, otherwise no marking will be performed;
[0018] Step 3: Based on the identified abnormal period, confirm the interaction data items associated with the abnormal period, and identify and confirm the abnormal data items based on the different network traffic characteristics associated with different interaction data items. The specific method is as follows:
[0019] S31. Confirm different data items that are interacting with traffic during the abnormal period, calibrate traffic fluctuation curves associated with the different data items during the abnormal period, and record the calibrated traffic fluctuation curves for the different data items as pending curves.
[0020] S32. Perform similarity check between the undetermined curve and the pre-stored attack characteristic fluctuation curve: Place the fluctuation curves of different attack characteristics and the undetermined curve in the same two-dimensional coordinate system, and perform horizontal translation on the undetermined curve. During the horizontal translation process, identify the standard process with the longest overlapping line length, and mark the total length of the overlapping lines in the standard process as ZL. i , where i represents different attack features, and the total length of the curve to be determined is calibrated as Zx, using: Zb i =Zx÷ZL i Confirm the percentage value Zb associated with this attack feature i , and identify whether: Zb i If ≥90% of the attack features exist, the interaction data item associated with the undetermined curve will be marked as an abnormal data item. If not, no marking will be performed.
[0021] Step 4: Based on the identified abnormal data item, confirm the transmission protocol associated with the abnormal data item, confirm the number of registry records from the transmission protocol, and confirm the attack characteristics based on the number of registry records generated during the actual registration process. The specific method is as follows:
[0022] Confirm the number of records in the registry from the transmission protocol associated with the abnormal data item and mark it as G1;
[0023] Then register the abnormal data items that have completed data interaction, and the registered data is stored in a preset storage interval. After the abnormal data items are registered, record the total number of registered tables G2, and identify whether G1 and G2 are the same value. If so, no processing is required. If not, mark this abnormal data item as an attack data item, delete the data registered in the storage interval, and display it through the display terminal.
[0024] Preferably, a network traffic anomaly detection system includes:
[0025] The feature analysis end divides the access features associated with multiple different IP ends associated with this network server from the historical interaction data and identifies the strongest feature curves associated with different IP ends;
[0026] The abnormal period confirmation terminal monitors the network traffic generated by the network server in real time, and based on the real-time monitored traffic process, identifies the period of excessive traffic, and combines the strongest characteristic curves of the interactive IP terminals associated with the excessive traffic period to assess whether the excessive traffic period is an abnormal period;
[0027] The data item anomaly identification terminal confirms the interaction data items associated with the abnormal period based on the marked abnormal period, and identifies and confirms the abnormal data items based on the different network traffic characteristics associated with different interaction data items;
[0028] The attack signature confirmation end confirms the transmission protocol associated with the abnormal data item based on the marked abnormal data item, confirms the number of registry records from the transmission protocol, and performs attack signature confirmation based on the number of registry records generated during the actual registration process.
[0029] The present invention provides a method and system for detecting network traffic anomalies. Compared with the existing technology, it has the following advantages:
[0030] The present invention identifies different network features associated with different IP terminals from historical data, and then confirms the corresponding strongest feature curve from the identified different network features. It then monitors the network traffic in real time, and based on the specific process of real-time monitoring, confirms the specific time period of network traffic anomaly. It then combines the features of the specific network traffic to identify whether the corresponding IP terminal will generate a corresponding traffic anomaly stage under the highest traffic interaction state. Based on the data features generated by different IP terminals in historical data, the accuracy of determining data traffic anomaly is further improved. The determination is not based on a specific numerical benchmark, but is determined based on past interaction features, thereby improving the accuracy of the traffic anomaly detection process.
[0031] Based on the confirmed abnormal period, the data items with data interaction in the corresponding period are verified with the attack characteristics recorded in the past to confirm whether the traffic interaction curve has the same characteristics. Based on the confirmed specific characteristics, anomaly verification detection is performed to identify the specific attack characteristics and perform real-time processing to achieve better anomaly detection results. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 Schematic diagram of the process of the present invention;
[0033] Figure 2 It is a schematic diagram of the principle framework of the present invention. DETAILED DESCRIPTION
[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0035] First embodiment
[0036] See also Figure 1 , this application provides a network traffic anomaly detection method, comprising the following steps:
[0037] Step 1: From the historical interaction data, the access characteristics associated with multiple different IP terminals associated with this network server are characterized and divided to confirm the strongest characteristic curve associated with different IP terminals. Specifically, different IP terminals have different network traffic data, and therefore different network change characteristics. When the network change characteristics are generated, corresponding network traffic value fluctuations will be generated, causing the traffic characteristics of the network server to change. Therefore, traffic calibration and characteristic division can be performed based on the corresponding network characteristics to specifically confirm the strongest characteristic curve of network traffic. The specific sub-steps for confirmation are:
[0038] S11. Different IP terminals associated with the server are marked as pending terminals, historical interaction data associated with the different pending terminals is identified, and historical traffic data of no less than 12 hours is extracted from the historical interaction data. Based on the time sequence, a historical traffic change curve belonging to the pending terminal is generated;
[0039] S12. Based on different historical traffic change curves associated with different pending endpoints, the maximum and minimum values are selected to determine the historical traffic interval corresponding to the pending endpoint. The historical traffic interval is then divided equally into three interval segments. The largest interval segment is then selected from the three equally divided interval segments and used as the characteristic segment of the pending endpoint. The largest interval segment is also the value segment where the maximum value is located.
[0040] S13. Locate the partial curve segments belonging to this characteristic segment from the historical traffic change curve. If there is only one group of partial curve segments, use this partial curve segment as the strongest characteristic curve of the pending terminal. If there are multiple groups of partial curve segments, perform average processing on the historical traffic of different partial curve segments, confirm the average characteristics, and select the partial curve segment associated with the maximum average characteristic as the strongest characteristic curve of the pending terminal. Specifically, different characteristic segments have different characteristic manifestations, and the strongest characteristic curve is confirmed for each pending terminal. In the specific confirmation process, the strongest characteristic is specifically confirmed for each different pending terminal. Therefore, different pending terminals have different characteristic manifestations, which facilitates subsequent confirmation of network traffic anomalies.
[0041] Step 2: Monitor the network traffic generated by the network server in real time, and based on the real-time monitored traffic process, identify the period of excessive traffic, and combine the strongest characteristic curves of the interactive IP terminals associated with the excessive traffic period to assess whether the excessive traffic period is an abnormal period. The specific method of assessment is as follows:
[0042] S21. Monitor the network traffic associated with the network server per unit time in real time, and compare the real-time monitored network traffic with a threshold value. A moment when the network traffic exceeds Y1 is recorded as an excess traffic moment, where Y1 is a preset value, the specific value of which is determined by the operator based on experience. Otherwise, no calibration is performed on the moment, and the specific period associated with consecutive excess traffic moments is recorded as an excess traffic period.
[0043] S22. Based on the calibrated excess traffic period, identify the IP terminals that interact with data within the excess traffic period, extract the strongest characteristic curve associated with the corresponding IP terminal, and confirm the total characteristic curve segment:
[0044] The total duration of the excess flow period is recorded as the characteristic duration. From different strongest characteristic curves, a section with a time range of the characteristic duration is selected and recorded as the characteristic section. If the total duration of the strongest characteristic curve is ≤ the characteristic duration, then this strongest characteristic curve is recorded as the characteristic section.
[0045] The characteristic segments associated with different strongest characteristic curves are combined, the initial moments of the characteristic segments are corrected to the same moment, the network traffic belonging to the same moment after subsequent correction is summed, and the network traffic segment after summation is recorded as a characteristic total segment, and different characteristic segments are combined to form different characteristic total segments (because several characteristic segments can be confirmed in one strongest characteristic curve, the characteristic total segments confirmed between each different characteristic segment are different, for example: the confirmed characteristic duration is 3 minutes, the duration of one strongest characteristic curve is 4 minutes, and the duration of another strongest characteristic curve is 3 minutes, then the other strongest characteristic curve is directly marked as a characteristic segment, and the initial "one strongest characteristic curve" can be divided into multiple different characteristic segments, for example: the curve segment of 0-3 minutes, the curve segment of 1-4 minutes, etc. will all be recorded as corresponding characteristic segments, then in the random combination process, different characteristic total segments can be combined to form);
[0046] S23. Based on the generated multiple different characteristic total segments, the curve segments associated with the periods of excessive traffic are recorded as standard curve segments. The different characteristic total segments are then verified against the standard curve segments to ensure that the initial time of the characteristic total segment coincides with the initial time of the standard curve. The network traffic values of the standard curve segments are determined to have consistently remained within the numerical range of the characteristic total segment. If so, the characteristic total segment is calibrated as a standard-compliant segment; otherwise, no calibration is performed.
[0047] If there is no set of standard sections among several different sets of characteristic total sections, the confirmed excessive flow period will be marked as an abnormal period, otherwise no marking will be performed;
[0048] Specifically, the period of excessive traffic is the specific period when the corresponding network traffic exceeds the set value. During this period, based on the network traffic characteristics generated by different IP ends in the past, the corresponding characteristic segments are confirmed, and based on the characteristic analysis process of the corresponding characteristic total segments, it is assessed whether the abnormal traffic segment generated by the period of excessive traffic is within the traffic characteristics of the corresponding IP end. If so, no processing is required, which means that there is no abnormality in the corresponding period of excessive traffic. Otherwise, it means that there may be abnormal behavior in the corresponding abnormal traffic period.
[0049] Step 3: Based on the marked abnormal time period, the interaction data items associated with the abnormal time period are confirmed, and based on the different network traffic characteristics associated with different interaction data items, the abnormal data items are identified and confirmed. Specifically, the corresponding cloud library contains historical attack characteristics, and the attack characteristics have different attack traffic changes. Combined with the different interaction characteristics of different data items in this period, the abnormal data items are identified and marked to determine whether the corresponding data items are similar to past attack characteristics and perform real-time assessment. The specific method of confirmation is as follows:
[0050] S31. Confirm different data items that are interacting with traffic during the abnormal period, calibrate traffic fluctuation curves associated with the different data items during the abnormal period, and record the calibrated traffic fluctuation curves for the different data items as pending curves.
[0051] S32. Perform similarity check on the curve to be determined and the pre-stored attack characteristic fluctuation curve: Place the fluctuation curves of different attack characteristics and the curve to be determined in the same two-dimensional coordinate system, and make the curve to be determined shift horizontally (the network traffic associated with its vertical axis is a fixed value, so only horizontal shift can be performed). During the horizontal shift process, identify the standard process with the longest overlapping line length, and mark the total length of the overlapping lines in the standard process as ZL. i , where i represents different attack features, and the total length of the curve to be determined is calibrated as Zx, using: Zb i =Zx÷ZL i Confirm the percentage value Zb associated with this attack feature i , and identify whether: Zb i If ≥90% of the attack features exist, the interaction data item associated with the undetermined curve will be marked as an abnormal data item. If not, no marking will be performed.
[0052] Specifically, after the corresponding abnormal data items are specifically identified, a comprehensive assessment can be conducted based on the registration items generated by such data items in the actual interaction process to determine whether such data items contain attack behaviors, and relevant abnormal signals can be displayed in a timely manner, and abnormal data generated by such interaction processes can be deleted in a timely manner;
[0053] Step 4: Based on the identified abnormal data item, confirm the transmission protocol associated with the abnormal data item, confirm the number of registry records from the transmission protocol, and confirm the attack characteristics based on the number of registry records generated during the actual registration process. The specific method for confirmation is as follows:
[0054] Confirm the number of records in the registry from the transmission protocol associated with the abnormal data item and mark it as G1;
[0055] Then, the abnormal data item that has completed the data interaction is registered, and the registered data is stored in a preset storage interval. After the abnormal data item is registered, the total number of registered items G2 is recorded, and it is identified whether G1 and G2 are the same value. If so, no processing is required. If not, the abnormal data item is marked as an attack data item, and the data registered in the storage interval is deleted and displayed on the display terminal;
[0056] Specifically, if there is a problem with the corresponding data item, there will generally be a hidden registration item, which will not be displayed in the corresponding transmission protocol, but will be hidden. It can only be displayed after the corresponding data item is registered. Therefore, in order to make accurate divisions here, the registration method is used to evaluate the number of registration tables to determine whether the number of corresponding registration tables is consistent, so as to perform specific feature display and achieve a more accurate judgment effect.
[0057] Second embodiment
[0058] Combine Figure 2 , a network traffic anomaly detection system, comprising:
[0059] The feature analysis end divides the access features associated with multiple different IP ends associated with this network server from the historical interaction data and identifies the strongest feature curves associated with different IP ends;
[0060] The abnormal period confirmation terminal monitors the network traffic generated by the network server in real time, and based on the real-time monitored traffic process, identifies the period of excessive traffic, and combines the strongest characteristic curves of the interactive IP terminals associated with the excessive traffic period to assess whether the excessive traffic period is an abnormal period;
[0061] The data item anomaly identification terminal confirms the interaction data items associated with the abnormal period based on the marked abnormal period, and identifies and confirms the abnormal data items based on the different network traffic characteristics associated with different interaction data items;
[0062] The attack signature confirmation end confirms the transmission protocol associated with the abnormal data item based on the marked abnormal data item, confirms the number of registry records from the transmission protocol, and performs attack signature confirmation based on the number of registry records generated during the actual registration process.
[0063] Some of the data in the above formulas are dimensionless and numerically calculated. Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art.
[0064] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A method for detecting anomaly in network traffic, characterized in that: The following steps are involved: Step 1: From the historical interaction data, perform feature segmentation on the access features associated with multiple different IP terminals associated with the network server, and identify the strongest feature curves associated with different IP terminals; Step 2: Monitor the network traffic generated by this network server in real time, and based on the real-time monitored traffic process, identify the period of excessive traffic, and based on the interactive IP terminals associated with the excessive traffic period, combine the strongest characteristic curves of the interactive IP terminals to assess whether the excessive traffic period is an abnormal period. The specific method is as follows: S21. Monitor the network traffic associated with the network server per unit time in real time, and compare the real-time monitored network traffic with a threshold value. A moment when the network traffic is greater than Y1 is recorded as an excess traffic moment, where Y1 is a preset value. Otherwise, no calibration is performed on the moment, and the specific period associated with consecutive excess traffic moments is recorded as an excess traffic period. S22. Based on the calibrated excess traffic period, identify the IP terminals that interact with data within the excess traffic period, extract the strongest characteristic curve associated with the corresponding IP terminal, and confirm the total characteristic curve segment: The total duration of the excess flow period is recorded as the characteristic duration. From different strongest characteristic curves, a section with a time range of the characteristic duration is selected and recorded as the characteristic section. If the total duration of the strongest characteristic curve is ≤ the characteristic duration, then this strongest characteristic curve is recorded as the characteristic section. The characteristic segments associated with the strongest characteristic curves are combined, the initial moments of the characteristic segments are corrected to the same moment, the network traffic at the same moment after subsequent correction is summed, and the summed network traffic segment is recorded as the characteristic total segment. Different characteristic segments are combined to form different characteristic total segments. S23. Based on the generated multiple different characteristic total segments, the curve segments associated with the periods of excessive traffic are recorded as standard curve segments. The different characteristic total segments are then verified against the standard curve segments to ensure that the initial time of the characteristic total segment coincides with the initial time of the standard curve. The network traffic values of the standard curve segments are determined to have consistently remained within the numerical range of the characteristic total segment. If so, the characteristic total segment is calibrated as a standard-compliant segment; otherwise, no calibration is performed. If there is no set of standard sections among several different sets of characteristic total sections, the confirmed excessive flow period will be marked as an abnormal period, otherwise no marking will be performed; Step 3: Based on the marked abnormal time period, the interaction data items associated with the abnormal time period are confirmed, and based on different network traffic characteristics associated with different interaction data items, the abnormal data items are identified and confirmed.
2. A method for detecting network traffic anomalies according to claim 1, characterized in that: In step 1, the specific sub-steps for confirming the strongest characteristic curve are: S11. Different IP terminals associated with the server are marked as pending terminals, historical interaction data associated with the different pending terminals is identified, and historical traffic data of no less than 12 hours is extracted from the historical interaction data. Based on the time sequence, a historical traffic change curve belonging to the pending terminal is generated; S12. Based on different historical traffic change curves associated with different pending endpoints, the maximum and minimum values are selected to determine the historical traffic interval corresponding to the pending endpoint. The historical traffic interval is then divided equally into three interval segments. The largest interval segment is then selected from the three equally divided interval segments and used as the characteristic segment of the pending endpoint. The largest interval segment is also the value segment where the maximum value is located. S13. Lock the partial curve segments belonging to this characteristic segment from the historical flow change curve. If there are multiple groups of partial curve segments, perform average processing on the historical flow of different partial curve segments, confirm the mean feature, and select the partial curve segment associated with the maximum mean feature as the strongest characteristic curve of this undetermined end.
3. A method for detecting network traffic anomalies according to claim 2, characterized in that: In step S13, if there is only one group of partial curve segments, this partial curve segment is used as the strongest characteristic curve of the undetermined end.
4. A method for detecting network traffic anomalies according to claim 1, characterized in that: In step 3, the specific method of confirming the abnormal data item is: S31. Confirm different data items that are interacting with traffic during the abnormal period, calibrate traffic fluctuation curves associated with the different data items during the abnormal period, and record the calibrated traffic fluctuation curves for the different data items as pending curves. S32. Perform similarity check between the undetermined curve and the pre-stored attack characteristic fluctuation curve: Place the fluctuation curves of different attack characteristics and the undetermined curve in the same two-dimensional coordinate system, and perform horizontal translation on the undetermined curve. During the horizontal translation process, identify the standard process with the longest overlapping line length, and mark the total length of the overlapping lines in the standard process as ZL. i , where i represents different attack features, and the total length of the curve to be determined is calibrated as Zx, using: Zb i =Zx÷ZL i Confirm the percentage value Zb associated with this attack feature i , and identify whether: Zb i If ≥90% of the attack features exist, the interaction data item associated with the undetermined curve is marked as an abnormal data item. If not, no calibration is performed.
5. A method for detecting network traffic anomalies according to claim 1, characterized in that: Also includes: Step 4: Based on the identified abnormal data item, confirm the transmission protocol associated with the abnormal data item, confirm the number of registry records from the transmission protocol, and confirm the attack characteristics based on the number of registry records generated during the actual registration process.
6. A method for detecting network traffic anomalies according to claim 5, characterized in that: In step 4, the specific method of confirming the attack characteristics is: Confirm the number of records in the registry from the transmission protocol associated with the abnormal data item and mark it as G1; Then register the abnormal data items that have completed data interaction, and the registered data is stored in a preset storage interval. After the abnormal data items are registered, record the total number of registered tables G2, and identify whether G1 and G2 are the same value. If so, no processing is required. If not, mark this abnormal data item as an attack data item, delete the data registered in the storage interval, and display it through the display terminal.
7. A network traffic anomaly detection system, the detection system operates according to a network traffic anomaly detection method according to any one of claims 1 to 6, characterized in that: include: The feature analysis end divides the access features associated with multiple different IP ends associated with this network server from the historical interaction data and identifies the strongest feature curves associated with different IP ends; The abnormal period confirmation terminal monitors the network traffic generated by the network server in real time, and based on the real-time monitored traffic process, identifies the period of excessive traffic, and combines the strongest characteristic curves of the interactive IP terminals associated with the excessive traffic period to assess whether the excessive traffic period is an abnormal period; The data item anomaly identification terminal confirms the interaction data items associated with the abnormal period based on the marked abnormal period, and identifies and confirms the abnormal data items based on the different network traffic characteristics associated with different interaction data items; The attack signature confirmation end confirms the transmission protocol associated with the abnormal data item based on the marked abnormal data item, confirms the number of registry records from the transmission protocol, and performs attack signature confirmation based on the number of registry records generated during the actual registration process.
Citation Information
Patent Citations
Traffic abnormity alarm method and device, electronic equipment and storage medium
CN115174254A