CN104753733B - The detection method and device of exception of network traffic data - Google Patents

The detection method and device of exception of network traffic data Download PDF

Info

Publication number
CN104753733B
CN104753733B CN201310753088.XA CN201310753088A CN104753733B CN 104753733 B CN104753733 B CN 104753733B CN 201310753088 A CN201310753088 A CN 201310753088A CN 104753733 B CN104753733 B CN 104753733B
Authority
CN
China
Prior art keywords
data
real
traffic data
abnormal
detection
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN201310753088.XA
Other languages
Chinese (zh)
Other versions
CN104753733A (en
Inventor
丁伟
杨魁
张凯
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing ZTE New Software Co Ltd
Original Assignee
Nanjing ZTE New Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nanjing ZTE New Software Co Ltd filed Critical Nanjing ZTE New Software Co Ltd
Priority to CN201310753088.XA priority Critical patent/CN104753733B/en
Publication of CN104753733A publication Critical patent/CN104753733A/en
Application granted granted Critical
Publication of CN104753733B publication Critical patent/CN104753733B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The invention discloses a kind of detection method and device of exception of network traffic data.Wherein, this method comprises: according to default detection cycle and historical data, the baseband model for detecting exception of network traffic data is constructed;Real-time traffic data are carried out abnormality detection according to baseband model.By the invention it is possible to which adjusting network equipment measurement for user provides technical support, the detection accuracy of exception of network traffic data is improved.

Description

The detection method and device of exception of network traffic data
Technical field
The present invention relates to the communications fields, in particular to a kind of detection method and device of exception of network traffic data.
Background technique
In a communication network, many information can be provided for user by carrying out depth analysis to network flow, such as: when congestion Section, data period, abnormal traffic detection etc., these information can provide further technical support for user optimization network.
Currently, the network operator of network generally detects network, analysis of history data traffic according to real-time traffic, however, existing Detection and analysis means have some limitations: (1) means of numerical analysis is few, generally by statistical presentation data, no Can sufficiently excavate out historical data periodicity (for example, detection for the data on flows of the festivals or holidays with the obvious period), It cannot obtain the section of normal data.(2) trend prediction analysis of missing data, cannot be based on the variation tendency pair of historical data Exception of network traffic data point carries out comprehensive descision.
Aiming at the problem that network flow detection mode deposits certain limitation in the related technology, effective solution is not yet proposed at present Certainly scheme.
Summary of the invention
The present invention provides a kind of detection method and device of exception of network traffic data, at least to solve the above problems.
According to an aspect of the invention, there is provided a kind of detection method of exception of network traffic data, comprising: according to pre- If detection cycle and historical data, the baseband model for detecting exception of network traffic data is constructed;According to baseband model to reality When data on flows carry out abnormality detection.
Preferably, default detection cycle includes following one: year, the moon, week, day, hour.
Preferably, according to default detection cycle and historical data, the base band for detecting exception of network traffic data is constructed Model, comprising: be made of according to the mean value of year, the moon, week, day or hour and variance and weight information calculating multiple pairs of points Base band, wherein include: each upper and lower two points to point;The baseband model in corresponding predetermined period is constructed according to base band.
Preferably, real-time traffic data are carried out abnormality detection according to baseband model, comprising: judge that real-time traffic data are It is no in the base band of baseband model, if it is judged that be it is yes, determine that real-time traffic data are non-abnormal datas, if it is determined that It as a result is no, it is determined that real-time traffic data are doubtful abnormal datas;Data are carried out to doubtful abnormal data using ARIMA algorithm Trend determines doubtful abnormal number in the case where the data variation trend of doubtful abnormal data meets ARIMA algorithm According to being non-abnormal data, otherwise, it determines doubtful abnormal data is abnormal data.
Preferably, after determining that real-time traffic data are non-abnormal data, further includes: using real-time traffic data as new Historical data to construct new baseband model.
Preferably, after determining that real-time traffic data are non-abnormal data, further includes: by SNMP Trap interface Network management workstation reports abnormality alarming information.
According to another aspect of the present invention, a kind of detection device of exception of network traffic data is provided, comprising: building mould Block, for constructing the baseband model for detecting exception of network traffic data according to detection cycle and historical data is preset;Detection Module, for being carried out abnormality detection according to baseband model to real-time traffic data.
Preferably, default detection cycle includes following one: year, the moon, week, day, hour.
Preferably, building module includes: computing unit, for according to the mean value and variance of year, the moon, week, day or hour with And weight information calculates the base band being made of multiple pairs of points, wherein includes: each upper and lower two points to point;Construction unit is used for The baseband model in corresponding predetermined period is constructed according to base band.
Preferably, detection module includes: first processing units, for judging whether real-time traffic data are located at baseband model Base band in, if it is judged that be it is yes, determine that real-time traffic data are non-abnormal datas, if it is judged that be it is no, then really Determining real-time traffic data is doubtful abnormal data;The second processing unit, for being carried out using ARIMA algorithm to doubtful abnormal data Data variation trend prediction determines doubtful different in the case where the data variation trend of doubtful abnormal data meets ARIMA algorithm Regular data is non-abnormal data, otherwise, it determines doubtful abnormal data is abnormal data.
Through the invention, periodicity analysis is carried out using to flow through a network historical data, obtains history base band data model, According to the mode that whether there is abnormal data in base band data model inspection network flow, solves network flow in the related technology Detection mode deposits the problem of certain limitation, adjusts network equipment measurement for user and provides technical support, has reached raising net The effect of the detection accuracy of network Traffic Anomaly data.
Detailed description of the invention
The drawings described herein are used to provide a further understanding of the present invention, constitutes part of this application, this hair Bright illustrative embodiments and their description are used to explain the present invention, and are not constituted improper limitations of the present invention.In the accompanying drawings:
Fig. 1 is the detection method flow chart of exception of network traffic data according to an embodiment of the present invention;
Fig. 2 is the structural block diagram of the detection device of exception of network traffic data according to an embodiment of the present invention;
Fig. 3 is the structural block diagram of the detection device of preferred network Traffic Anomaly data according to an embodiment of the present invention;
Fig. 4 is the structural schematic diagram of the detection device of exception of network traffic data according to the preferred embodiment of the invention;
Fig. 5 is the baseband model detection schematic diagram of router exceptional data point according to an embodiment of the present invention;
Fig. 6 is trend prediction schematic diagram according to an embodiment of the present invention.
Specific embodiment
Hereinafter, the present invention will be described in detail with reference to the accompanying drawings and in combination with Examples.It should be noted that not conflicting In the case of, the features in the embodiments and the embodiments of the present application can be combined with each other.
The embodiment of the present invention provides a kind of exception of network traffic detection device for user.Firstly, using Fourier transform point It is periodical to analyse network flow historical data, history of forming base band data model;Then judge whether data to be tested pass through base band Mode determine that the data carry out trend prediction with the presence or absence of doubtful abnormal point, and then to doubtful abnormal point, to accomplish to prevent to miss Sentence.Finally, issuing the user with warning information if detecting exceptional data point.
Present embodiments provide a kind of detection method of exception of network traffic data.Fig. 1 is according to an embodiment of the present invention The detection method flow chart of exception of network traffic data, as shown in Figure 1, this method mainly includes the following steps that (step S102- step Rapid S104):
Step S102 constructs the base for detecting exception of network traffic data according to default detection cycle and historical data Band model;
Step S104 carries out abnormality detection real-time traffic data according to baseband model.
By above-mentioned each step, periodicity analysis can be carried out to flow through a network historical data, obtain history base band number According to model, according to whether there is abnormal data in base band data model inspection network flow.
In the present embodiment, default detection cycle may include following one: year, the moon, week, day, hour.
In the present embodiment, step S102 can be realized in this way: first according to year, the moon, week, day or small When mean value and variance and weight information calculate the base band being made of multiple pairs of points, wherein include: each two up and down to point Point;The baseband model in corresponding predetermined period is constructed further according to base band.
In the present embodiment, step S104 can be realized in this way: whether first judge real-time traffic data In the base band of baseband model, if it is judged that be it is yes, determine that real-time traffic data are non-abnormal datas, if it is determined that knot Fruit is no, it is determined that real-time traffic data are doubtful abnormal datas;It then, can be using ARIMA algorithm to doubtful abnormal data Data variation trend prediction is carried out, in the case where the data variation trend of doubtful abnormal data meets ARIMA algorithm, determines and doubts It is non-abnormal data like abnormal data, otherwise, it determines doubtful abnormal data is abnormal data.
In the present embodiment, after determining that real-time traffic data are non-abnormal data, further includes: by real-time traffic data New baseband model is constructed as new historical data.
In the present embodiment, after determining that real-time traffic data are non-abnormal data, further includes: pass through SNMP Trap Network management workstation reports abnormality alarming information on interface.
A kind of detection device of exception of network traffic data is present embodiments provided, for realizing above-mentioned exception of network traffic The detection method of data.Fig. 2 is the structural block diagram of the detection device of exception of network traffic data according to an embodiment of the present invention, such as Shown in Fig. 2, the device mainly includes: building module 10 and detection module 20.Wherein, in the present embodiment, module 10 is constructed, is used According to detection cycle and historical data is preset, the baseband model for detecting exception of network traffic data is constructed;Detection module 20, for being carried out abnormality detection according to baseband model to real-time traffic data.
In the present embodiment, default detection cycle may include following one: year, the moon, week, day, hour.
Fig. 3 is the structural block diagram of the detection device of preferred network Traffic Anomaly data according to an embodiment of the present invention, such as Fig. 3 Shown, in the detection device (can also be referred to as system) of preferred network Traffic Anomaly data, building module 10 may include: Computing unit 12, for being calculated according to the mean value and variance and weight information of year, the moon, week, day or hour by multiple pairs of point structures At base band, wherein each to point include: up and down two points;Construction unit 14, for constructing corresponding predetermined period according to base band Interior baseband model.
In the detection device of preferred network Traffic Anomaly data, detection module 20 may include: first processing units 22, For judging whether real-time traffic data are located in the base band of baseband model, if it is judged that be it is yes, determine real-time traffic number According to being non-abnormal data, if it is judged that being no, it is determined that real-time traffic data are doubtful abnormal datas;The second processing unit 24, for carrying out data variation trend prediction to doubtful abnormal data using ARIMA algorithm, become in the data of doubtful abnormal data In the case that change trend meets ARIMA algorithm, determine that doubtful abnormal data is non-abnormal data, otherwise, it determines doubtful exception number According to being abnormal data.
Using the detection method and device of exception of network traffic data provided by the above embodiment, flow through a network can be gone through History data carry out periodicity analysis, obtain history base band data model, according in base band data model inspection network flow whether There are abnormal data, the detection accuracy for improving exception of network traffic data is achieved the effect that.
Inspection below with reference to fig. 4 to fig. 6 and preferred embodiment to exception of network traffic data provided by the above embodiment Method and device is surveyed to be further described in more detail and illustrate.
Fig. 4 is the structural schematic diagram of the detection device of exception of network traffic data according to the preferred embodiment of the invention, such as Shown in Fig. 4, this preferred embodiment provide exception of network traffic data detection device include following component (or be referred to as Module):
(1) baseband model component, for obtaining the baseband model of data on flows by the study to historical data.Specifically Ground, the model can be first with the periodicity of Fourier transform analysis data, further according to the mean value of the sampling of data point in the period The weight information for calculating each period with variance is calculated, to construct the baseband model of a historical data.
(2) Data Detection component calculates whether the data pass through baseband model group for inputting a data to be detected For part according to the history base band calculated in baseband model, the data point that will exceed base band range regards as doubtful exceptional data point (due to and it is uncertain must be exceptional data point, need to carry out further comprehensive descision, so referred to as doubtful abnormal data Point).
(3) prediction component, is found out the doubtful abnormal data corresponding time for being gone out according to Data Detection component detection Corresponding historical data, then trend prediction is carried out with ARIMA algorithm to the historical data, if prediction result and doubtful abnormal number According to close, then illustrate the non-exception of this data, otherwise, illustrate this data exception.
(4) alarm component, for being reported in a manner of alarm for the abnormal data that detected in prediction component Grade network management.
(5) model enhances component automatically, and the data for examining in Data Detection component, prediction component are non-abnormal numbers In the case where, historical data, the model parameter for the history base band that can timely update in this way, by prediction group can be added in this data This parameter is transmitted to baseband model component by part, to ensure that the model parameter of baseband model component is constantly updated, is preferably improved The detection accuracy of Data Detection component.
Fig. 5 is the baseband model detection schematic diagram of router exceptional data point according to an embodiment of the present invention, such as Fig. 5 institute Show, the baseband model testing process of the router exceptional data point includes:
Step 1, the historical traffic data (data volume is bigger, and effect is better) of the network equipments such as router acquisition is obtained, is excavated The periodicity of data and each period specific gravity, find strongest periodicity by Fourier transform.It periodically can also be by user Oneself definition, if user understands the periodic regularity of data, it is possible to specify the specific gravity in each period.For what is largely cleaned Historical data, and the most fine granularity of historical data is hour, can be by the period of Fourier transform detection history data, to going through History data, need per year, the moon, week, day historical data is sampled, and the mean and variance of statistical sampling data, according to system Meter come out year, the moon, week, day variance can determine the weight information of year, the moon, week, day.Periodic weight calculation by according to The data from the sample survey of different cycles calculates variance, and the small weight of variance is high.If user is well understood by the periodicity of data, week The weight of phase can also be by being manually entered.Here historical data can be NetFlow data on flows, in order to make it easy to understand, Please refer to table 1.
Table 1, NetFlow data on flows structure table
Name Type Remark
TimeLevel iht Time
Sequence iht Sequence
MinStartTime bigInt Time started
MaxEndTime bigint End time
ExporterIp bigint Superinverse report zhang drinks router address
SrcIp bigint Source Ip
DstIp bigint Purpose Ip
NextHopIp bigint Next-hop
SrcPort smallint Source port
DstPort smallint Destination port
Packets bigint Packet
Octets bigint Flow
Protocol smallint Agreement
Step 2, baseband model is constructed.It calculates according to year, the moon, week, the mean value of day and variance and weight information and to form one It is a by the base band of multiple multipair points (upper and lower two points are constituted), the mode of this analysis to historical data in this way Form a history baseband model.For example, the most fine granularity of historical data is hour, history number is detected by Fourier transform According to period be 24 hours, be divided into and year, the moon, week, day historical data sample calculation mean variance and weight formed by History base band in period.
Step 3, data to be tested are obtained.Obtain the data on flows of online in real time by network equipments such as routers, it can be with Using the partial data as input data to be detected.
Step 4, abnormality detection.To Outlier mining is entered, judge whether data have an exception by detection components, in utilization Baseband model is stated, monitoring point is judged whether within the scope of base band, if test point is located inside base band, then it is assumed that the point is non-different Chang Dian, it is possible to further enter the historical data that baseband model calculates next time for the non-abnormal data as historical data In range, in this way it is possible to form the new baseband model of enhancing.
Step 5, comprehensive descision is predicted.In order to make it easy to understand, please also refer to Fig. 6 here, (Fig. 6 is to implement according to the present invention The trend prediction schematic diagram of example), the doubtful exceptional data point of the output result of Data Detection component is inputted into trend prediction component, is become Gesture prediction component can be predicted according to the variation tendency of data, in practical applications, can be carried out using ARIMA algorithm pre- It surveys, finally determines whether to be exceptional data point by way of this.
Step 6, alarm notification.After determining that doubtful exceptional data point is strictly exceptional data point, so that it may will be abnormal Data point inputs alarm component (can also be referred to as event notification component), is responsible for passing through exception information by alarm component various The interface of form is issued to subscriber.For example, abnormal letter can be reported to network management workstation by SNMP Trap interface Breath.
By the realization of above preferred embodiment, network equipment measurement can be adjusted for user and provide technical support, mentioned The high detection accuracy of exception of network traffic data.
It should be noted that above-mentioned modules can be realized by hardware.Such as: a kind of processor, including Above-mentioned modules, alternatively, above-mentioned modules are located in a processor.
In another embodiment, a kind of software is additionally provided, the software is for executing above-described embodiment and preferred reality Apply technical solution described in mode.
In another embodiment, a kind of storage medium is additionally provided, above-mentioned software is stored in the storage medium, it should Storage medium includes but is not limited to: CD, floppy disk, hard disk, scratch pad memory etc..
It can be seen from the above description that the present invention realizes following technical effect: to flow through a network historical data into Row periodicity analysis obtains history base band data model, abnormal according to whether there is in base band data model inspection network flow Data solve the problems, such as that network flow detection mode deposits certain limitation in the related technology, adjust the network equipment for user and survey Amount provides technical support, has achieved the effect that the detection accuracy for improving exception of network traffic data.
Obviously, those skilled in the art should be understood that each module of the above invention or each step can be with general Computing device realize that they can be concentrated on a single computing device, or be distributed in multiple computing devices and formed Network on, optionally, they can be realized with the program code that computing device can perform, it is thus possible to which they are stored It is performed by computing device in the storage device, and in some cases, it can be to be different from shown in sequence execution herein Out or description the step of, perhaps they are fabricated to each integrated circuit modules or by them multiple modules or Step is fabricated to single integrated circuit module to realize.In this way, the present invention is not limited to any specific hardware and softwares to combine.
The foregoing is only a preferred embodiment of the present invention, is not intended to restrict the invention, for the skill of this field For art personnel, the invention may be variously modified and varied.All within the spirits and principles of the present invention, made any to repair Change, equivalent replacement, improvement etc., should all be included in the protection scope of the present invention.

Claims (6)

1. a kind of detection method of exception of network traffic data characterized by comprising
According to default detection cycle and historical data, the baseband model for detecting exception of network traffic data is constructed;
Real-time traffic data are carried out abnormality detection according to the baseband model;
Wherein, the default detection cycle includes: year, the moon, week, day and hour;
Wherein, according to default detection cycle and historical data, the baseband model for detecting exception of network traffic data is constructed, is wrapped It includes: being made of according to the calculating of the weight information of the mean value of data from the sample survey and variance and the default detection cycle multiple pairs of points Base band, wherein the data from the sample survey be per year, the moon, week, day and hour data that historical data is sampled, each It include: upper and lower two points to point;The baseband model in the default detection cycle is constructed according to the base band.
2. the method according to claim 1, wherein being carried out according to the baseband model to real-time traffic data different Often detection, comprising:
Judge whether the real-time traffic data are located in the base band of the baseband model, if it is judged that be it is yes, determine institute Stating real-time traffic data is non-abnormal data, if it is judged that being no, it is determined that the real-time traffic data are doubtful exceptions Data;
Data variation trend prediction is carried out to the doubtful abnormal data using ARIMA algorithm, in the doubtful abnormal data In the case that data variation trend meets the ARIMA algorithm, determine that the doubtful abnormal data is non-abnormal data, otherwise, Determine that the doubtful abnormal data is abnormal data.
3. according to the method described in claim 2, it is characterized in that, determine the real-time traffic data be non-abnormal data it Afterwards, further includes:
The real-time traffic data are constructed into new baseband model as new historical data.
4. according to the method in claim 2 or 3, which is characterized in that determining that the real-time traffic data are abnormal datas Later, further includes:
Abnormality alarming information is reported by network management workstation on SNMP Trap interface.
5. a kind of detection device of exception of network traffic data characterized by comprising
Module is constructed, for constructing the base for detecting exception of network traffic data according to detection cycle and historical data is preset Band model;
Detection module, for being carried out abnormality detection according to the baseband model to real-time traffic data;
Wherein, the default detection cycle includes: year, the moon, week, day and hour;
Wherein, the building module includes: computing unit, for the mean value and variance and the default inspection according to data from the sample survey The weight information for surveying the period calculates the base band that is made of multiple pairs of points, wherein the data from the sample survey be per year, the moon, week, day and small When data that historical data is sampled, include: each two points up and down to point;Construction unit, for according to Base band constructs the baseband model in the default detection cycle.
6. device according to claim 5, which is characterized in that the detection module includes:
First processing units, for judging whether the real-time traffic data are located in the base band of the baseband model, if sentenced Disconnected result be it is yes, determine that the real-time traffic data are non-abnormal datas, if it is judged that being no, it is determined that the real-time streams Measuring data is doubtful abnormal data;
The second processing unit, for carrying out data variation trend prediction to the doubtful abnormal data using ARIMA algorithm, in institute State doubtful abnormal data data variation trend meet the ARIMA algorithm in the case where, determine that the doubtful abnormal data is Non- abnormal data, otherwise, it determines the doubtful abnormal data is abnormal data.
CN201310753088.XA 2013-12-31 2013-12-31 The detection method and device of exception of network traffic data Expired - Fee Related CN104753733B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201310753088.XA CN104753733B (en) 2013-12-31 2013-12-31 The detection method and device of exception of network traffic data

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201310753088.XA CN104753733B (en) 2013-12-31 2013-12-31 The detection method and device of exception of network traffic data

Publications (2)

Publication Number Publication Date
CN104753733A CN104753733A (en) 2015-07-01
CN104753733B true CN104753733B (en) 2019-08-13

Family

ID=53592881

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201310753088.XA Expired - Fee Related CN104753733B (en) 2013-12-31 2013-12-31 The detection method and device of exception of network traffic data

Country Status (1)

Country Link
CN (1) CN104753733B (en)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107231268B (en) * 2016-03-25 2020-05-01 北京京东尚科信息技术有限公司 Method and device for testing website performance
CN106899601A (en) * 2017-03-10 2017-06-27 北京华清信安科技有限公司 Network attack defence installation and method based on cloud and local platform
CN109428786B (en) * 2017-09-04 2021-02-02 中国电信股份有限公司 Network performance monitoring method and device and computer readable storage medium
CN107370766B (en) * 2017-09-07 2020-09-11 杭州安恒信息技术股份有限公司 Network flow abnormity detection method and system
CN107733921A (en) * 2017-11-14 2018-02-23 深圳中兴网信科技有限公司 Network flow abnormal detecting method, device, computer equipment and storage medium
CN108804703B (en) * 2018-06-19 2021-09-17 北京焦点新干线信息技术有限公司 Data anomaly detection method and device
CN109039728B (en) * 2018-07-24 2021-08-03 烽火通信科技股份有限公司 BFD-based flow congestion detection method and system
TWI704784B (en) * 2018-12-25 2020-09-11 安華聯網科技股份有限公司 Device, method and non-transitory tangible machine-readable medium for traffic monitoring
CN110505196B (en) * 2019-07-02 2021-08-31 中国联合网络通信集团有限公司 Internet of things network card abnormality detection method and device
CN113708987B (en) * 2020-05-22 2023-07-25 浙江大学 Network anomaly detection method and device
CN112653589A (en) * 2020-07-13 2021-04-13 福建奇点时空数字科技有限公司 Network data flow abnormity detection method based on host data flow characteristic extraction
CN114640606A (en) * 2020-12-01 2022-06-17 中移物联网有限公司 Abnormity processing method and controller for Internet of things card terminal
CN114338284A (en) * 2021-12-24 2022-04-12 深圳尊悦智能科技有限公司 5G intelligent gateway of Internet of things

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101155085A (en) * 2006-09-29 2008-04-02 中兴通讯股份有限公司 Method and device for real-time flux prediction and real-time flux monitoring and early warning
CN101651568A (en) * 2009-07-01 2010-02-17 青岛农业大学 Method for predicting network flow and detecting abnormality
CN101729301A (en) * 2008-11-03 2010-06-09 中国移动通信集团湖北有限公司 Monitor method and monitor system of network anomaly traffic
CN102014031A (en) * 2010-12-31 2011-04-13 湖南神州祥网科技有限公司 Method and system for network flow anomaly detection
CN102130800A (en) * 2011-04-01 2011-07-20 苏州赛特斯网络科技有限公司 Device and method for detecting network access abnormality based on data stream behavior analysis

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100617310B1 (en) * 2004-09-25 2006-08-30 한국전자통신연구원 Apparatus for detecting abnormality of traffic in network and method thereof

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101155085A (en) * 2006-09-29 2008-04-02 中兴通讯股份有限公司 Method and device for real-time flux prediction and real-time flux monitoring and early warning
CN101729301A (en) * 2008-11-03 2010-06-09 中国移动通信集团湖北有限公司 Monitor method and monitor system of network anomaly traffic
CN101651568A (en) * 2009-07-01 2010-02-17 青岛农业大学 Method for predicting network flow and detecting abnormality
CN102014031A (en) * 2010-12-31 2011-04-13 湖南神州祥网科技有限公司 Method and system for network flow anomaly detection
CN102130800A (en) * 2011-04-01 2011-07-20 苏州赛特斯网络科技有限公司 Device and method for detecting network access abnormality based on data stream behavior analysis

Also Published As

Publication number Publication date
CN104753733A (en) 2015-07-01

Similar Documents

Publication Publication Date Title
CN104753733B (en) The detection method and device of exception of network traffic data
CN102130800B (en) Device and method for detecting network access abnormality based on data stream behavior analysis
US7969893B2 (en) List-based alerting in traffic monitoring
US10003506B2 (en) Automatic discovery and enforcement of service level agreement settings
CN107409064A (en) For supporting the method and system of anormal detection in network
CN107070714B (en) A kind of SDN network abnormality monitoring method
CN105721184A (en) Network link quality monitoring method and apparatus
CN106537443B (en) System and method for classifying in situ sensor response data patterns indicative of grid anomaly severity
US20190149440A1 (en) Traffic analytics service for telemetry routers and monitoring systems
WO2016033897A1 (en) Network link monitoring method and device, network system and storage medium
CN104836694B (en) Method for monitoring network and device
Marais et al. A review of the topologies used in smart water meter networks: A wireless sensor network application
JP2008283621A (en) Apparatus and method for monitoring network congestion state, and program
CN108370333A (en) System, method and the node that can be measured for Segment routing net neutral
CN103281256A (en) Network tomography-based end-to-end path packet loss rate detection method
CN105763387A (en) Network traffic monitoring method and device
Song et al. Real-time anomaly traffic monitoring based on dynamic k-NN cumulative-distance abnormal detection algorithm
Nie et al. Passive diagnosis for WSNs using data traces
Perdices et al. On the modeling of multi-point RTT passive measurements for network delay monitoring
Kreuger et al. Scalable in-network rate monitoring
Argon et al. Inferring the periodicity in large-scale Internet measurements
CN103906100B (en) A kind of determination method and apparatus of repeater
CN104980962B (en) A kind of determination method and device in field testing period
JP6488197B2 (en) Anomaly detection method, anomaly detection apparatus, and network system
CN104754604B (en) A kind of monitoring LTE is to the WLAN method, apparatus interfered and system

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
TA01 Transfer of patent application right
TA01 Transfer of patent application right

Effective date of registration: 20190715

Address after: 210012 Nanjing, Yuhuatai District, South Street, Bauhinia Road, No. 68

Applicant after: Nanjing Zhongxing Software Co.,Ltd.

Address before: 518057 Nanshan District science and technology, Guangdong Province, South Road, No. 55, No.

Applicant before: ZTE Corp.

GR01 Patent grant
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20190813

Termination date: 20211231