首页> 外国专利> A METHOD FOR DETECTING ABNORMAL PATTERNS OF NETWORK TRAFFIC BY ANALYZING LINEAR PATTERNS AND INTENSITY FEATURES

A METHOD FOR DETECTING ABNORMAL PATTERNS OF NETWORK TRAFFIC BY ANALYZING LINEAR PATTERNS AND INTENSITY FEATURES

机译:一种分析线性特征和强度特征的网络流量异常特征的方法

摘要

The present invention relates to a method for detecting an abnormal phenomenon on a network traffic based a linear pattern and intensity features, which detects the abnormal phenomenon of a network with a linear pattern formed by dots in a two dimensional image, by extracting an IP address and a port from traffic data transmitted on the network and mapping the extracted IP address and port as dots of the two dimensional image. The method of the present invention includes the steps of: (a) extracting an IP address and a port of a transmitter and an IP address and a port of a receiver from each header file of numerous traffic data; (b) mapping the IP address and the port to one dot of a two dimensional image, where the two dimensional image comprises an IP address image of the transmitter, an IP address image of the receiver and a port image, and both coordinate axes of the IP address image correspond to a class of each IP address, and both coordinate axes of the port image correspond to a class of each IP address; (c) extracting a straight line pattern formed by dots mapped in the two dimensional image; and (d) obtaining a feature value of detecting the abnormal phenomenon of the network, using the length or number of linear patterns. By the method for detecting the abnormal phenomenon of the network traffic like the above, it is possible to detect normal traffic and an abnormal phenomenon such as DDoS and Dos etc rapidly with a very high accurate detection rate automatically through simple comparison of patterns, by extracting and analyzing the patterns in the two dimensional image by mapping the IP address/port of the network traffic to the image.
机译:基于线性图案和强度特征的网络流量异常现象检测方法技术领域本发明涉及一种基于线性图案和强度特征的网络流量异常现象检测方法,其通过提取IP地址来检测由二维图像中的点形成的线性图案的网络异常现象。从网络上传输的流量数据中提取一个端口,并将提取的IP地址和端口映射为二维图像的点。本发明的方法包括以下步骤:(a)从大量业务数据的每个头文件中提取发射机的IP地址和端口以及接收机的IP地址和端口; (b)将IP地址和端口映射到二维图像的一个点上,其中该二维图像包括发送器的IP地址图像,接收器的IP地址图像和端口图像,以及两个坐标轴IP地址图像对应于每个IP地址的类别,端口图像的两个坐标轴对应于每个IP地址的类别。 (c)提取由映射在二维图像中的点形成的直线图案; (d)利用线性图案的长度或数量获得检测网络异常现象的特征值。通过如上所述的用于检测网络流量的异常现象的方法,通过简单的模式比较,通过提取,可以以非常高的准确检测率自动快速检测正常流量以及诸如DDoS和Dos等异常现象。通过将网络流量的IP地址/端口映射到该图像来分析二维图像中的图案。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号