CN102111312B - 基于多尺度主成分分析的网络异常检测方法 - Google Patents
基于多尺度主成分分析的网络异常检测方法 Download PDFInfo
- Publication number
- CN102111312B CN102111312B CN 201110075666 CN201110075666A CN102111312B CN 102111312 B CN102111312 B CN 102111312B CN 201110075666 CN201110075666 CN 201110075666 CN 201110075666 A CN201110075666 A CN 201110075666A CN 102111312 B CN102111312 B CN 102111312B
- Authority
- CN
- China
- Prior art keywords
- traffic matrix
- component analysis
- matrix
- reconstruct
- flow
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 110
- 238000004458 analytical method Methods 0.000 title claims abstract description 36
- 239000011159 matrix material Substances 0.000 claims abstract description 184
- 238000000034 method Methods 0.000 claims abstract description 90
- 230000002123 temporal effect Effects 0.000 claims abstract description 20
- 230000009466 transformation Effects 0.000 claims abstract description 19
- 238000000354 decomposition reaction Methods 0.000 claims abstract description 11
- 238000000513 principal component analysis Methods 0.000 claims description 85
- 230000002159 abnormal effect Effects 0.000 claims description 46
- 238000005259 measurement Methods 0.000 claims description 41
- 238000012360 testing method Methods 0.000 claims description 33
- 239000013598 vector Substances 0.000 claims description 22
- 230000005856 abnormality Effects 0.000 claims description 18
- 230000008569 process Effects 0.000 claims description 13
- 238000010998 test method Methods 0.000 claims description 11
- 206010000117 Abnormal behaviour Diseases 0.000 claims description 10
- 230000008859 change Effects 0.000 claims description 10
- 238000001914 filtration Methods 0.000 claims description 6
- 230000007246 mechanism Effects 0.000 claims description 6
- 230000009467 reduction Effects 0.000 claims description 6
- 230000007774 longterm Effects 0.000 claims description 3
- 230000001932 seasonal effect Effects 0.000 claims description 3
- 238000004422 calculation algorithm Methods 0.000 abstract description 118
- 230000006870 function Effects 0.000 description 34
- 238000012795 verification Methods 0.000 description 12
- 230000006399 behavior Effects 0.000 description 9
- 238000013450 outlier detection Methods 0.000 description 8
- 230000002547 anomalous effect Effects 0.000 description 6
- 230000002045 lasting effect Effects 0.000 description 5
- ZEFNOZRLAWVAQF-UHFFFAOYSA-N Dinitolmide Chemical compound CC1=C(C(N)=O)C=C([N+]([O-])=O)C=C1[N+]([O-])=O ZEFNOZRLAWVAQF-UHFFFAOYSA-N 0.000 description 4
- 230000000630 rising effect Effects 0.000 description 4
- 238000010586 diagram Methods 0.000 description 3
- 238000011160 research Methods 0.000 description 3
- 230000008901 benefit Effects 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 2
- 238000006243 chemical reaction Methods 0.000 description 2
- 230000007812 deficiency Effects 0.000 description 2
- 230000002950 deficient Effects 0.000 description 2
- 238000012544 monitoring process Methods 0.000 description 2
- ABEXEQSGABRUHS-UHFFFAOYSA-N 16-methylheptadecyl 16-methylheptadecanoate Chemical compound CC(C)CCCCCCCCCCCCCCCOC(=O)CCCCCCCCCCCCCCC(C)C ABEXEQSGABRUHS-UHFFFAOYSA-N 0.000 description 1
- 241000764238 Isis Species 0.000 description 1
- 238000012550 audit Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000012512 characterization method Methods 0.000 description 1
- 238000000205 computational method Methods 0.000 description 1
- 125000004122 cyclic group Chemical group 0.000 description 1
- 230000003247 decreasing effect Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 238000005417 image-selected in vivo spectroscopy Methods 0.000 description 1
- 238000012739 integrated shape imaging system Methods 0.000 description 1
- 230000004807 localization Effects 0.000 description 1
- 239000002574 poison Substances 0.000 description 1
- 231100000614 poison Toxicity 0.000 description 1
- 231100000572 poisoning Toxicity 0.000 description 1
- 230000000607 poisoning effect Effects 0.000 description 1
- 238000006116 polymerization reaction Methods 0.000 description 1
- 238000003672 processing method Methods 0.000 description 1
- 238000011158 quantitative evaluation Methods 0.000 description 1
- 230000000717 retained effect Effects 0.000 description 1
- 238000005070 sampling Methods 0.000 description 1
- 238000010206 sensitivity analysis Methods 0.000 description 1
- 238000000926 separation method Methods 0.000 description 1
- 230000003595 spectral effect Effects 0.000 description 1
- 238000007619 statistical method Methods 0.000 description 1
- 238000013179 statistical model Methods 0.000 description 1
- 238000011426 transformation method Methods 0.000 description 1
- 238000013519 translation Methods 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
- 238000005303 weighing Methods 0.000 description 1
Images
Abstract
Description
序号 | 持续时间 | 间隔时间(分钟) | 测度 | 矩阵形式 | 数据集 |
1 | 2003.12.15-12.21 | 5 | 字节数 | 2010×121 | B |
2 | 2003.12.15-12.21 | 5 | 分组数 | 2010×121 | P |
3 | 2003.12.15-12.21 | 5 | 流数 | 2010×121 | F |
异常类型 | 特征 |
阿尔法 | 点到点之间不寻常的高速字节传输 |
(分布式)拒绝服务攻击 | 单源或多源对单个目的地的洪泛攻击 |
突发流 | 大量客户同时访问某一Web站点 |
入口/出口移动 | BGP策略变化引起流量出口点的变化 |
Claims (9)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN 201110075666 CN102111312B (zh) | 2011-03-28 | 2011-03-28 | 基于多尺度主成分分析的网络异常检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN 201110075666 CN102111312B (zh) | 2011-03-28 | 2011-03-28 | 基于多尺度主成分分析的网络异常检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN102111312A CN102111312A (zh) | 2011-06-29 |
CN102111312B true CN102111312B (zh) | 2013-05-01 |
Family
ID=44175346
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN 201110075666 Expired - Fee Related CN102111312B (zh) | 2011-03-28 | 2011-03-28 | 基于多尺度主成分分析的网络异常检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN102111312B (zh) |
Families Citing this family (28)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102890286B (zh) * | 2011-07-18 | 2014-08-13 | 成都理工大学 | 一种放射性能谱平滑方法 |
CN102664772B (zh) * | 2012-04-25 | 2015-03-04 | 东北大学 | 一种动态环境下网络流量异常的多尺度侦测方法 |
WO2017067615A1 (en) * | 2015-10-23 | 2017-04-27 | Nec Europe Ltd. | Method and system for supporting detection of irregularities in a network |
CN105681312B (zh) * | 2016-01-28 | 2019-03-05 | 李青山 | 一种基于频繁项集挖掘的移动互联网异常用户检测方法 |
CN105954223A (zh) * | 2016-04-28 | 2016-09-21 | 南京富岛信息工程有限公司 | 一种提高汽油性质预测精度的方法 |
CN106101060B (zh) * | 2016-05-24 | 2021-02-12 | 新华三技术有限公司 | 一种信息检测方法及装置 |
CN108011740B (zh) * | 2016-10-28 | 2021-04-30 | 腾讯科技(深圳)有限公司 | 一种媒体流量数据处理方法和装置 |
US10581915B2 (en) | 2016-10-31 | 2020-03-03 | Microsoft Technology Licensing, Llc | Network attack detection |
US9768928B1 (en) * | 2016-12-16 | 2017-09-19 | Futurewei Technologies, Inc. | High dimensional (HiDi) radio environment characterization and representation |
CN106941490B (zh) * | 2017-03-20 | 2017-10-27 | 湖南友道信息技术有限公司 | 基于双向二维主成分分析的在线网络流量异常检测方法 |
CN106878995B (zh) * | 2017-04-27 | 2020-02-07 | 重庆邮电大学 | 一种基于感知数据的无线传感器网络异常类型鉴别方法 |
CN107026763B (zh) * | 2017-06-02 | 2019-11-26 | 广东电网有限责任公司中山供电局 | 一种基于流量分解的数据通信网流量预测方法 |
CN107239448B (zh) * | 2017-06-07 | 2019-03-22 | 长沙学院 | 一种解释性主成分分析方法 |
EP3673636A1 (en) * | 2017-08-25 | 2020-07-01 | Oxford University Innovation Limited | Detection of Anomalous Systems |
CN107846402B (zh) * | 2017-10-30 | 2019-12-13 | 北京邮电大学 | 一种bgp稳定性异常检测方法、装置及电子设备 |
CN108650218B (zh) * | 2018-03-22 | 2019-10-08 | 平安科技(深圳)有限公司 | 网络流量监测方法、装置、计算机设备及存储介质 |
CN109040084B (zh) * | 2018-08-13 | 2021-03-12 | 广东电网有限责任公司 | 一种网络流量异常检测方法、装置、设备及存储介质 |
CN109164351A (zh) * | 2018-09-03 | 2019-01-08 | 北京许继电气有限公司 | 基于时间序列的物联网设备监测数据分析方法和系统 |
CN110138614B (zh) * | 2019-05-20 | 2022-02-11 | 湖南友道信息技术有限公司 | 一种基于张量模型的在线网络流量异常检测方法及系统 |
CN110266552B (zh) * | 2019-08-15 | 2020-04-21 | 华为技术有限公司 | 流量异常检测的方法、模型训练方法和装置 |
CN111401950A (zh) * | 2020-03-12 | 2020-07-10 | 上海数川数据科技有限公司 | 基于小波特征聚类的广告流量反作弊方法及装置 |
CN112291226B (zh) * | 2020-10-23 | 2022-05-27 | 新华三信息安全技术有限公司 | 一种网络流量的异常检测方法及装置 |
CN112511372B (zh) * | 2020-11-06 | 2022-03-01 | 新华三技术有限公司 | 一种异常检测方法、装置及设备 |
CN113702769B (zh) * | 2021-08-30 | 2022-10-14 | 国家电网有限公司 | 基于监测数据空时相关性的配电网异常监测与定位方法 |
CN114366122A (zh) * | 2021-12-09 | 2022-04-19 | 山东师范大学 | 一种基于eeg脑机接口的运动想象分析方法及系统 |
CN114760131B (zh) * | 2022-04-15 | 2024-03-01 | 中国人民解放军国防科技大学 | 一种面向返回式编程流量的特征提取方法、装置及设备 |
CN116933016B (zh) * | 2023-09-19 | 2023-11-24 | 交通运输部公路科学研究所 | 基于车路协同的自动驾驶信息安全测试方法及系统 |
CN117041017B (zh) * | 2023-10-08 | 2024-01-05 | 北京金信润天信息技术股份有限公司 | 数据中心的智能运维管理方法及系统 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1996888A (zh) * | 2006-12-15 | 2007-07-11 | 华为技术有限公司 | 一种网络流量异常的检测方法及检测装置 |
CN101848160A (zh) * | 2010-05-26 | 2010-09-29 | 钱叶魁 | 在线检测和分类全网络流量异常的方法 |
-
2011
- 2011-03-28 CN CN 201110075666 patent/CN102111312B/zh not_active Expired - Fee Related
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1996888A (zh) * | 2006-12-15 | 2007-07-11 | 华为技术有限公司 | 一种网络流量异常的检测方法及检测装置 |
CN101848160A (zh) * | 2010-05-26 | 2010-09-29 | 钱叶魁 | 在线检测和分类全网络流量异常的方法 |
Non-Patent Citations (7)
Title |
---|
《Anomaly Detection of Network Traffic Based on Wavelet Packet》;Jun Gao et al.;《Asia-Pacific Conference on Communications, 2006.》;20060901;1-5 * |
《ODC——在线检测和分类全网络流量异常的方法》;钱叶魁等;《通信学报》;20110131;第32卷(第1期);111-119 * |
diagnosis》.《International Conference on Information Acquisition, 2004.》.2004,135-139. * |
JunGaoetal..《AnomalyDetectionofNetworkTrafficBasedonWaveletPacket》.《Asia-PacificConferenceonCommunications 2006.》.2006 |
Zhiqiang Geng et al..《A wavelet-based adaptive MSPCA for process signal monitoring & * |
ZhiqiangGengetal..《Awavelet-basedadaptiveMSPCAforprocesssignalmonitoring&diagnosis》.《InternationalConferenceonInformationAcquisition 2004.》.2004 |
钱叶魁等.《ODC——在线检测和分类全网络流量异常的方法》.《通信学报》.2011,第32卷(第1期),111-119. |
Also Published As
Publication number | Publication date |
---|---|
CN102111312A (zh) | 2011-06-29 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN102111312B (zh) | 基于多尺度主成分分析的网络异常检测方法 | |
Adarsh et al. | Trend analysis of rainfall in four meteorological subdivisions of southern India using nonparametric methods and discrete wavelet transforms | |
Joshi et al. | Analysis of trends and dominant periodicities in drought variables in India: a wavelet transform based approach | |
Liu et al. | Stochastic subspace identification for output‐only modal analysis: application to super high‐rise tower under abnormal loading condition | |
US8725676B1 (en) | State change detection | |
CN104717106B (zh) | 一种基于多变量序贯分析的分布式网络流量异常检测方法 | |
CN106872958B (zh) | 基于线性融合的雷达目标自适应检测方法 | |
US8832017B2 (en) | System and method to define, validate and extract data for predictive models | |
Bevacqua et al. | Advancing research on compound weather and climate events via large ensemble model simulations | |
Foresti et al. | Retrieval of analogue radar images for ensemble nowcasting of orographic rainfall | |
DelSole et al. | Average predictability time. Part II: Seamless diagnoses of predictability on multiple time scales | |
Feng et al. | Data mining for abnormal power consumption pattern detection based on local matrix reconstruction | |
Mahan et al. | White Noise Test: detecting autocorrelation and nonstationarities in long time series after ARIMA modeling. | |
Yusof et al. | Volatility modeling of rainfall time series | |
Xie et al. | Data fault detection for wireless sensor networks using multi-scale PCA method | |
de Guenni et al. | Predicting monthly precipitation along coastal Ecuador: ENSO and transfer function models | |
CN105227689A (zh) | 基于局部时延分布相似性度量的目标ip定位算法 | |
CN104237861A (zh) | 一种未知杂波背景下的cfar检测门限获取方法 | |
CN102664772B (zh) | 一种动态环境下网络流量异常的多尺度侦测方法 | |
Kumar et al. | Daily rainfall statistics of TRMM and CMORPH: A case for trans-boundary Gandak River basin | |
Torkamani et al. | Detection of system changes due to damage using a tuned hyperchaotic probe | |
Khokhlov et al. | Signatures of low-dimensional chaos in hourly water level measurements at coastal site of Mariupol, Ukraine | |
Vidrio-Sahagún et al. | Stationary hydrological frequency analysis coupled with uncertainty assessment under nonstationary scenarios | |
De La Chevrotière et al. | A data-driven method for improving the correlation estimation in serial ensemble Kalman filters | |
Yu et al. | Using new neighborhood-based intensity-scale verification metrics to evaluate WRF precipitation forecasts at 4 and 12 km grid spacings |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C53 | Correction of patent of invention or patent application | ||
CB03 | Change of inventor or designer information |
Inventor after: Qian Yekui Inventor after: Ye Lixin Inventor after: Yin Feng Inventor after: Wan Mingjie Inventor after: Chen Likai Inventor after: Zuo Jun Inventor after: Liu Guiqi Inventor after: Jiang Guansheng Inventor before: Qian Yekui Inventor before: Liu Fengrong Inventor before: Hao Qiang Inventor before: Zuo Jun Inventor before: Yin Feng Inventor before: Shang Wenzhong Inventor before: Jiang Guansheng |
|
COR | Change of bibliographic data |
Free format text: CORRECT: INVENTOR; FROM: QIAN YEKUI LIU FENGRONG HAO QIANG ZUO JUN YIN FENG SHANG WENZHONG JIANG GUANSHENG TO: QIAN YEKUI YE LIXIN YIN FENG WAN MINGJIE CHEN LIKAI ZUO JUN LIU GUIQI JIANG GUANSHENG |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20221221 Address after: No. 451, Huangshan Road, Shushan District, Hefei City, Anhui Province, 230071 Patentee after: CHINESE PEOPLE'S LIBERATION ARMY ARMY ARTILLERY AIR DEFENSE ACADEMY Address before: 450,052 Missile Weapon Teaching and Research Office of Air Defense Command College, No. 24, Jianshe East Road, Zhengzhou City, Henan Province Patentee before: Qian Yekui |
|
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20130501 |
|
CF01 | Termination of patent right due to non-payment of annual fee |