The invention relates to a lightweight network flow storage and management method and
system based on flow clustering, and belongs to the field of
computer network security, and the method comprises the steps: deploying a Zeek monitoring component and P4 equipment at a network boundary and a core node, and carrying out the
structural analysis of a multi-source weblog; based on
data source and flow feature clustering and grading
processing, dividing into a key flow, a common flow and a secondary flow; hierarchical forwarding and
priority scheduling of the logs are realized through Filebeat and Kafka; a hierarchical storage architecture of a core flow layer, a main
service flow layer and an archiving flow layer is constructed based on ClickHouse, and efficient retrieval and
traceability analysis are realized through a
materialized view and a multi-dimensional index. According to the invention,
flexible scheduling and grading
processing of traffic can be realized in a high-
concurrency network environment, the overall
throughput efficiency and security
situation awareness capability of the
system are improved, real-time performance and storage
cost control are both considered, and the method is suitable for
threat monitoring and
event tracing scenes in a large-scale network environment.