Computer network flow intelligent monitoring system
Through the adaptive early warning threshold calculation method, the early warning threshold of network traffic is dynamically adjusted, and the false alarm problem caused by fixed thresholds in the prior art is solved, and efficient monitoring of network traffic and accurate identification of abnormal traffic is achieved.
Patent Information
- Application Number
- CN202510463926.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, network traffic monitoring uses fixed thresholds for early warning, resulting in false alarms easily during peak network traffic, while abnormal traffic cannot be effectively identified during non-peak periods.
Adaptive early warning threshold calculation method is adopted, and the periodically updated time window and weight calculation is used to dynamically adjust the early warning threshold value, and combine the network traffic change coefficient and window change coefficient to realize the adaptive early warning threshold calculation.
It effectively reduces the false alarm rate during peak periods of network traffic, improves the abnormal traffic recognition capability during off-peak periods, and realizes efficient monitoring of network traffic.
Smart Images

Figure CN120281685A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular, to an intelligent monitoring system for computer network traffic. Background Art
[0002] Network traffic monitoring is a technology that captures, analyzes, and records the data flow in a network in real time to evaluate network performance, ensure security, and optimize resource allocation. Network traffic monitoring usually includes monitoring the size of network traffic within a statistical period (e.g., 1 minute). By setting a fixed threshold in advance, when the network traffic per unit time exceeds the threshold, a warning is issued. This way of monitoring the size of network traffic has certain disadvantages. When the threshold is set too small, false alarms are easily triggered during the peak period of computer network traffic, and when the threshold is set too large, effective network traffic warnings cannot be achieved during the non-peak period of computer network traffic. Summary of the Invention
[0003] The purpose of the present invention is to disclose an intelligent monitoring system for computer network traffic to solve the technical problems raised in the background art.
[0004] To achieve the above purpose, the present invention provides the following technical solutions:
[0005] The present invention provides an intelligent monitoring system for computer network traffic, including a collection module, an analysis module, and a warning module;
[0006] The collection module is used to statistically calculate the network traffic of the monitored computer using a set statistical period;
[0007] The analysis module is used to analyze the network traffic to obtain an adaptive warning threshold;
[0008] The warning module is used to issue a warning in accordance with a set warning method when the network traffic is higher than the warning threshold;
[0009] Among them, the analysis module includes a range calculation unit and a threshold calculation unit;
[0010] The range calculation unit is used to periodically determine a time window for calculating an adaptive warning threshold;
[0011] The threshold calculation unit is used to calculate an adaptive warning threshold based on the time window.
[0012] Furthermore, it further includes a database module;
[0013] The collection module is also used to send the statistically calculated network traffic of the computer to the database module;
[0014] The database module is used to store the network traffic sent by the collection module.
[0015] Further, it further includes a display module;
[0016] The display module is used to read the network traffic of the computer from the database module and display the network traffic of the computer in a preset display manner.
[0017] Further, periodically determining a time window of network traffic for calculating an adaptive warning threshold includes:
[0018] Let T represent a preset time period;
[0019] Every time a time period T elapses, recalculate the time window for calculating the adaptive warning threshold.
[0020] Further, the calculation process of the time window includes:
[0021] Let W k and W k+1 represent the time windows used in the k-th and k + 1-th time periods respectively;
[0022] After the k-th time period ends, use the following formula to obtain the time window used in the k + 1-th time period:
[0023] W k+1 = W k +(λ × vsa k,k-1 +(1 - λ) × vsb k,k-1 ) × prW
[0024] λ is the first weight, vsa k,k-1 represents the network traffic change coefficient, vsb k,k-1 is the window change coefficient, and prW is the preset duration.
[0025] Further, the calculation formula of the network traffic change coefficient is:
[0026]
[0027] N1 and N2 respectively represent the total number of network traffic statistics obtained in the k-th and k - 1-th time periods; trafval i represents the i-th network traffic statistic obtained in the k-th time period, trafval j represents the j-th network traffic statistic obtained in the k - 1-th time period, and NR represents normalizing the variables in the parentheses.
[0028] Further, the calculation formula of the window change coefficient is:
[0029] vsb k,k-1= NR(W k -W k-1 )
[0030] W k-1 represents the time window used in the (k - 1)-th time period, and NR represents normalizing the variables in the parentheses.
[0031] Furthermore, calculating the adaptive warning threshold based on the time window includes:
[0032] Using t end,k to represent the end moment of the k-th time period, then the network traffic statistically obtained in the time interval [t end,k -W k+1 , t end,k is saved to the sequence Lnet in the order of the statistical time from early to late;
[0033] Calculating the adaptive warning threshold using the following formula:
[0034]
[0035] NL represents the total number of network traffic in Lnet, trafval NL represents the NL-th network traffic in Lnet, trafval z represents the z-th network traffic in Lnet, ampl represents a preset amplification factor, warthre represents the adaptive warning threshold, and μ represents the second weight.
[0036] Furthermore, when the network traffic is higher than the warning threshold, warning is carried out according to the set warning method, including:
[0037] In the (k + 1)-th time period, when the network traffic statistically obtained by the acquisition module is greater than warthre, warning is carried out according to the set warning method.
[0038] Furthermore, warning is carried out according to the set warning method, including:
[0039] Warning is carried out by sending an email or a text message to the computer network administrator.
[0040] Beneficial effects:
[0041] Different from the existing method of using a fixed threshold for network traffic warning, the present invention updates the adaptive warning threshold periodically, so that the warning threshold can adaptively change with the changing trend of network traffic, and realizes the warning of abnormal traffic peaks. In this way, the probability of false warning events triggered during the peak period of network traffic can be effectively reduced, and effective identification of abnormal traffic can also be achieved during the non-peak period of network traffic, and the network traffic of the computer can be effectively monitored. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0043] Figure 1 It is a schematic diagram of an intelligent monitoring system for computer network traffic of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0045] Refer to Figure 1 , the present invention provides an intelligent monitoring system for computer network traffic, including a collection module, an analysis module, and a warning module;
[0046] The collection module is used to statistically collect the network traffic of the monitored computer at a set statistical period;
[0047] The analysis module is used to analyze the network traffic and obtain an adaptive warning threshold;
[0048] The warning module is used to give a warning according to the set warning method when the network traffic is higher than the warning threshold;
[0049] Among them, the analysis module includes a range calculation unit and a threshold calculation unit;
[0050] The range calculation unit is used to periodically determine the time window for calculating the adaptive warning threshold;
[0051] The threshold calculation unit is used to calculate the adaptive warning threshold based on the time window.
[0052] Different from the traditional fixed - threshold network traffic warning method, the present invention updates the adaptive warning threshold periodically, enabling the threshold to be dynamically adjusted according to the changing trend of network traffic. This adaptive mechanism can effectively identify abnormal traffic peaks, reduce the false - alarm probability during peak hours, and improve the detection ability of abnormal traffic during off - peak hours, thus achieving efficient monitoring of network traffic.
[0053] In the present invention, the set statistical period can be 5 seconds, 10 seconds, 20 seconds, etc. It can be adjusted according to the monitoring requirements. The higher the security level, the smaller the statistical period can be set.
[0054] The acquisition module can use tools such as ElastiFlow and NetFlow to perform statistics on network traffic. ElastiFlow is a network traffic analysis tool based on the Elastic Stack (Elasticsearch, Logstash, and Kibana), mainly used for collecting and visualizing network traffic data. It supports multiple traffic types, including Netflow v5 / v9, sFlow, and IPFIX, and can help users monitor and analyze network traffic.
[0055] Furthermore, it also includes a database module;
[0056] The acquisition module is also used to send the statistically obtained network traffic of the computer to the database module;
[0057] The database module is used to store the network traffic sent by the acquisition module.
[0058] For example, databases such as MySQL and Oracle can be used to store the network traffic sent by the acquisition module.
[0059] Furthermore, it also includes a display module;
[0060] The display module is used to read the network traffic of the computer from the database module and display the network traffic of the computer in a preset display manner.
[0061] For example, the network traffic over a period of time can be displayed in the form of a line chart to show the changing trend of network traffic to the computer network administrator.
[0062] Another example is that the network traffic can be statistically analyzed by time periods (such as divided into three time periods: morning, noon, and evening), and the proportion of network traffic in different time periods can be visually displayed in the form of a pie chart.
[0063] Furthermore, periodically determining the time window of the network traffic used to calculate the adaptive warning threshold includes:
[0064] Let \(T\) represent a preset time period;
[0065] Every time a time period \(T\) passes, the time window used to calculate the adaptive warning threshold is recalculated.
[0066] In the present invention, the value of \(T\) can be 10 minutes, 20 minutes, etc. Similarly, the higher the network security requirements, the smaller the value of \(T\) can be set.
[0067] Furthermore, the calculation process of the time window includes:
[0068] Let \(W\) k and \(W\) k+1 represent the time windows used in the \(k\)-th and \((k + 1)\)-th time periods respectively;
[0069] After the \(k\)-th time period ends, use the following formula to obtain the time window used in the \((k + 1)\)-th time period:
[0070] \(W\) k+1 =\(W\) k +(λ×vsa k,k-1 +(1 - λ)×vsb k,k-1 )×prW
[0071] λ is the first weight, vsa k,k-1 represents the network traffic change coefficient, vsb k,k-1 is the window change coefficient, and prW is the preset duration.
[0072] When calculating the time window in the present invention, by weighting the network traffic change coefficient and the window change coefficient, it can be made that when the value of the network traffic change coefficient is smaller and the value of the window change coefficient is smaller, the \((k + 1)\)-th time window is correspondingly smaller; when the value of the network traffic change coefficient is larger and the value of the window change coefficient is larger, the \((k + 1)\)-th time window is correspondingly larger. The calculation process of the time window realizes comprehensive consideration of different types of data, can make the time window more adaptable to the change trend of network traffic, and thus makes the calculated warning threshold more accurate.
[0073] In the present invention, the first weight can be 0.7. The preset duration can be 1 minute.
[0074] Furthermore, the calculation formula of the network traffic change coefficient is:
[0075]
[0076] \(N1\) and \(N2\) respectively represent the total network traffic statistics obtained in the \(k\)-th and \((k - 1)\)-th time periods; trafval iIndicates the i-th network traffic statistic obtained in the k-th time period, trafval j Indicates the j-th network traffic statistic obtained in the (k - 1)-th time period. NR represents normalizing the variables in the parentheses. When performing normalization, it can be processed by maximum value normalization, that is, dividing the variables in the parentheses by the maximum network throughput allowed by the computer to obtain the normalized value.
[0077] In the present invention, the network traffic change coefficient is obtained by comparing the change amplitudes of network traffic in two adjacent time periods. When the change amplitude of the network traffic in the k-th time period is less than that in the (k - 1)-th time period, the network traffic change coefficient is positive, indicating that the network traffic is in a trend of decreasing change amplitude, so that the calculation window can be reduced to improve the speed of obtaining the adaptive warning threshold; when the change amplitude of the network traffic in the k-th time period is greater than that in the (k - 1)-th time period, the network traffic change coefficient is negative, indicating that the network traffic is in a trend of increasing change amplitude, so that the calculation window can be enlarged, and the warning threshold can be calculated based on more network traffic to improve the accuracy of obtaining the adaptive warning threshold.
[0078] Furthermore, the calculation formula for the window change coefficient is:
[0079] vsb k,k-1 =NR(W k -W k-1 )
[0080] W k-1 Represents the time window used in the (k - 1)-th time period. NR represents normalizing the variables in the parentheses. When performing normalization, it can be processed by dividing the variables in the parentheses by the maximum value in the nearest 10 time windows to obtain the normalized value.
[0081] The window change coefficient is considered from another aspect. It not only considers the change amplitude of network traffic, but also can reduce the effectiveness of the warning threshold calculated in the case of sudden changes in the change amplitude of network traffic, and can effectively reduce the influence degree of the process of network traffic surging and then returning to normal in a short time on the calculation result of the warning threshold.
[0082] Furthermore, calculating the adaptive warning threshold based on the time window includes:
[0083] Use t end,k To represent the end time of the k-th time period, then the time interval [t end,k -W k+1 ,t end,kThe network traffic obtained by internal statistics is saved to the sequence Lnet in the order of the statistics time from early to late;
[0084] Calculate the adaptive warning threshold using the following formula:
[0085]
[0086] NL represents the total number of network traffic in Lnet, trafval NL represents the NLth network traffic in Lnet, trafval z represents the zth network traffic in Lnet, ampl represents the preset amplification factor, warthre represents the adaptive warning threshold, and μ represents the second weight.
[0087] The adaptive warning threshold of the present invention is calculated based on the network traffic obtained by statistics within the time interval warthre. Therefore, for the zth network traffic in Lnet, when the position difference between the zth network traffic trafval z and the last network traffic in Lnet is larger and the numerical difference is larger, the influence of trafval z on the calculation result of warthre is smaller. Thus, the warning threshold can be adaptively determined based on the change of network traffic in the recent period of time, so that the warning threshold can change with the change of network traffic and has stronger adaptability.
[0088] In the present invention, when the network traffic is saved to the sequence Lnet in the order of the statistics time from early to late, the following rules are followed:
[0089] For example, if three network traffics netflow21, netflow22, and netflow23 are obtained by statistics at 15:20, 21, and 22 minutes, then netflow21 ranks first in Lnet and netflow23 ranks last in Lnet.
[0090] The preset amplification factor of the present invention can be 2. That is, in the case of the traffic change amplitude in the recent period of time, when the traffic surges by 2 times, a warning event occurs.
[0091] The second weight of the present invention can be 0.4.
[0092] Furthermore, when the network traffic is higher than the warning threshold, warning is carried out according to the set warning method, including:
[0093] In the (k + 1)th time period, when the network traffic obtained by the acquisition module statistics is greater than warthre, warning is carried out according to the set warning method.
[0094] Specifically, since statistical network traffic is continuously generated within the (k + 1)-th time interval, new generated network traffic can be continuously compared with the warning threshold to achieve network traffic monitoring.
[0095] Furthermore, warnings are issued according to the set warning method, including:
[0096] Issuing warnings by sending emails or text messages to computer network administrators.
[0097] For example, the number of the computer that triggers the network traffic warning can be sent to the computer network administrator by email or text message.
[0098] Furthermore, the acquisition module is also used to clean the collected traffic data of the computer and then perform network traffic statistics.
[0099] The purpose of data cleaning is to remove noise and incorrect data to ensure data accuracy and integrity. Data cleaning generally includes:
[0100] Removing invalid data: Filtering out incomplete or invalid data packets, such as those missing key fields (such as source IP, destination IP, port number, etc.).
[0101] Duplicate removal: Identifying and removing duplicate data packets to avoid double counting.
[0102] Format correction: Converting data into a unified format, such as converting timestamps into a unified time format and converting IP addresses into standard IPv4 or IPv6 formats.
[0103] Anomaly detection: Identifying and processing abnormal data packets, such as those that significantly deviate from the normal traffic pattern.
[0104] Through data cleaning, the accuracy of the obtained statistical results can be effectively improved.
[0105] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. An intelligent monitoring system for computer network traffic, characterized in that, It includes a collection module, an analysis module, and a warning module; The collection module is used to statistically collect the network traffic of the monitored computer with a set statistical period; The analysis module is used to analyze the network traffic and obtain an adaptive warning threshold; The warning module is used to issue a warning in accordance with the set warning method when the network traffic is higher than the warning threshold; Among them, the analysis module includes a range calculation unit and a threshold calculation unit; The range calculation unit is used to periodically determine the time window for calculating the adaptive warning threshold; The threshold calculation unit is used to calculate the adaptive warning threshold based on the time window.
2. An intelligent monitoring system for computer network traffic according to claim 1, characterized in that, It also includes a database module; The collection module is also used to send the statistically obtained network traffic of the computer to the database module; The database module is used to store the network traffic sent by the collection module.
3. An intelligent monitoring system for computer network traffic according to claim 2, characterized in that, It also includes a display module; The display module is used to read the network traffic of the computer from the database module and display the network traffic of the computer in a preset display manner.
4. An intelligent monitoring system for computer network traffic according to claim 1, characterized in that, Periodically determining the time window of the network traffic for calculating the adaptive warning threshold includes: Let T represent the preset time period; Every time a time period T passes, the time window for calculating the adaptive warning threshold is recalculated.
5. An intelligent monitoring system for computer network traffic according to claim 4, characterized in that, The calculation process of the time window includes: Let \(W_{ k}\) and \(W_{ k+1}\) denote the time windows used in the \(k\)-th and \((k + 1)\)-th time periods, respectively; k and \(W\) k+1 respectively represent the time windows used in the \(k\)-th and \(k + 1\)-th time periods; After the end of the k-th time period, use the following formula to obtain the time window used in the (k + 1)-th time period: W k+1 = W k +(λ × vsa k,k-1 +(1 - λ) × vsb k,k-1 ) × prW λ is the first weight, vsa k,k-1 represents the network traffic change coefficient, vsb k,k-1 is the window change coefficient, and prW is the preset duration.
6. An intelligent monitoring system for computer network traffic according to claim 5, characterized in that The calculation formula for the network traffic change coefficient is: N1 and N2 respectively represent the total amounts of network traffic statistically obtained in the k-th and (k-1)-th time periods; trafval i represents the i-th network traffic statistically obtained in the k-th time period, trafval j represents the j-th network traffic statistically obtained in the (k-1)-th time period, and NR represents normalizing the variables in the parentheses.
7. An intelligent monitoring system for computer network traffic according to claim 5, characterized in that, The calculation formula for the window change coefficient is: vsb k,k-1 = NR(W k - W k-1 ) W k-1 represents the time window used in the (k - 1)-th time period, and NR represents normalizing the variable in the parentheses.
8. An intelligent monitoring system for computer network traffic according to claim 5, characterized in that, Calculating the adaptive warning threshold based on the time window includes: Use t end,k to represent the end time of the k-th time period, then the network traffic statistics obtained within the time interval [t end,k - W k+1 , t end,k will be saved to the sequence Lnet in the order of the statistical time from early to late; Use the following formula to calculate the adaptive warning threshold: NL represents the total number of network traffic in Lnet, trafval NL represents the NLth network traffic in Lnet, trafval z represents the zth network traffic in Lnet, ampl represents a preset amplification factor, warthre represents an adaptive early warning threshold, and μ represents the second weight.
9. An intelligent computer network traffic monitoring system according to claim 8, characterized in that, When the network traffic is higher than the warning threshold, issuing a warning in accordance with the set warning method includes: In the (k + 1)-th time period, when the network traffic statistically obtained by the collection module is greater than warthre, a warning is issued in accordance with the set warning method.
10. An intelligent monitoring system for computer network traffic according to claim 1, characterized in that, Issuing a warning in accordance with the set warning method includes: Issuing a warning by sending an email or sending a text message to the computer network administrator.
Citation Information
Cited By
Performance self-adaption method based on flow analysis and control system
CN121239633A
Distributed pressure test monitoring system and method based on data analysis
CN121771077A