CN108199863A - 一种基于两阶段序列特征学习的网络流量分类方法及系统 - Google Patents
一种基于两阶段序列特征学习的网络流量分类方法及系统 Download PDFInfo
- Publication number
- CN108199863A CN108199863A CN201711205047.1A CN201711205047A CN108199863A CN 108199863 A CN108199863 A CN 108199863A CN 201711205047 A CN201711205047 A CN 201711205047A CN 108199863 A CN108199863 A CN 108199863A
- Authority
- CN
- China
- Prior art keywords
- network flow
- data packet
- sequence
- vector
- flow
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/24—Traffic characterised by specific attributes, e.g. priority or QoS
- H04L47/2441—Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F18/00—Pattern recognition
- G06F18/20—Analysing
- G06F18/24—Classification techniques
- G06F18/241—Classification techniques relating to the classification model, e.g. parametric or non-parametric approaches
- G06F18/2413—Classification techniques relating to the classification model, e.g. parametric or non-parametric approaches based on distances to training or reference patterns
- G06F18/24133—Distances to prototypes
- G06F18/24137—Distances to cluster centroïds
- G06F18/2414—Smoothing the distance, e.g. radial basis function networks [RBFN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/50—Network service management, e.g. ensuring proper service fulfilment according to agreements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/02—Capturing of monitoring data
- H04L43/026—Capturing of monitoring data using flow identification
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Engineering & Computer Science (AREA)
- Data Mining & Analysis (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Bioinformatics & Cheminformatics (AREA)
- Evolutionary Computation (AREA)
- Physics & Mathematics (AREA)
- Evolutionary Biology (AREA)
- General Physics & Mathematics (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Bioinformatics & Computational Biology (AREA)
- Artificial Intelligence (AREA)
- Life Sciences & Earth Sciences (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201711205047.1A CN108199863B (zh) | 2017-11-27 | 2017-11-27 | 一种基于两阶段序列特征学习的网络流量分类方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201711205047.1A CN108199863B (zh) | 2017-11-27 | 2017-11-27 | 一种基于两阶段序列特征学习的网络流量分类方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108199863A true CN108199863A (zh) | 2018-06-22 |
CN108199863B CN108199863B (zh) | 2021-01-22 |
Family
ID=62573137
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201711205047.1A Active CN108199863B (zh) | 2017-11-27 | 2017-11-27 | 一种基于两阶段序列特征学习的网络流量分类方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108199863B (zh) |
Cited By (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109063777A (zh) * | 2018-08-07 | 2018-12-21 | 北京邮电大学 | 网络流量分类方法、装置及实现装置 |
CN109361619A (zh) * | 2018-12-27 | 2019-02-19 | 北京天融信网络安全技术有限公司 | 一种流量分类方法及电子设备 |
CN109376797A (zh) * | 2018-11-20 | 2019-02-22 | 大连理工大学 | 一种基于二进制编码器和多哈希表的网络流量分类方法 |
CN109379377A (zh) * | 2018-11-30 | 2019-02-22 | 极客信安(北京)科技有限公司 | 加密恶意流量检测方法、装置、电子设备及存储介质 |
CN111209933A (zh) * | 2019-12-25 | 2020-05-29 | 国网冀北电力有限公司信息通信分公司 | 基于神经网络和注意力机制的网络流量分类方法和装置 |
CN111565311A (zh) * | 2020-04-29 | 2020-08-21 | 杭州迪普科技股份有限公司 | 网络流量特征生成方法及装置 |
CN111756757A (zh) * | 2020-06-28 | 2020-10-09 | 南方电网科学研究院有限责任公司 | 一种僵尸网络检测方法和装置 |
CN112104570A (zh) * | 2020-09-11 | 2020-12-18 | 南方电网科学研究院有限责任公司 | 流量分类方法、装置、计算机设备和存储介质 |
CN114338437A (zh) * | 2022-01-13 | 2022-04-12 | 北京邮电大学 | 网络流量分类方法、装置、电子设备及存储介质 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101841440A (zh) * | 2010-04-30 | 2010-09-22 | 南京邮电大学 | 基于支持向量机与深层包检测的对等网络流量识别方法 |
CN102685016A (zh) * | 2012-06-06 | 2012-09-19 | 济南大学 | 互联网流量区分方法 |
CN106355101A (zh) * | 2015-07-15 | 2017-01-25 | 中国科学院声学研究所 | 一种面向简易存储服务的透明文件加解密系统及其方法 |
CN106790019A (zh) * | 2016-12-14 | 2017-05-31 | 北京天融信网络安全技术有限公司 | 基于特征自学习的加密流量识别方法及装置 |
-
2017
- 2017-11-27 CN CN201711205047.1A patent/CN108199863B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101841440A (zh) * | 2010-04-30 | 2010-09-22 | 南京邮电大学 | 基于支持向量机与深层包检测的对等网络流量识别方法 |
CN102685016A (zh) * | 2012-06-06 | 2012-09-19 | 济南大学 | 互联网流量区分方法 |
CN106355101A (zh) * | 2015-07-15 | 2017-01-25 | 中国科学院声学研究所 | 一种面向简易存储服务的透明文件加解密系统及其方法 |
CN106790019A (zh) * | 2016-12-14 | 2017-05-31 | 北京天融信网络安全技术有限公司 | 基于特征自学习的加密流量识别方法及装置 |
Non-Patent Citations (1)
Title |
---|
WEI WANG,MING ZHU等: "End-to-end Encrypted Traffic Classification with One-dimensional Convolution Neural Networks", 《IEEE》 * |
Cited By (13)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109063777A (zh) * | 2018-08-07 | 2018-12-21 | 北京邮电大学 | 网络流量分类方法、装置及实现装置 |
CN109376797A (zh) * | 2018-11-20 | 2019-02-22 | 大连理工大学 | 一种基于二进制编码器和多哈希表的网络流量分类方法 |
CN109379377B (zh) * | 2018-11-30 | 2020-12-08 | 极客信安(北京)科技有限公司 | 加密恶意流量检测方法、装置、电子设备及存储介质 |
CN109379377A (zh) * | 2018-11-30 | 2019-02-22 | 极客信安(北京)科技有限公司 | 加密恶意流量检测方法、装置、电子设备及存储介质 |
CN109361619A (zh) * | 2018-12-27 | 2019-02-19 | 北京天融信网络安全技术有限公司 | 一种流量分类方法及电子设备 |
CN111209933A (zh) * | 2019-12-25 | 2020-05-29 | 国网冀北电力有限公司信息通信分公司 | 基于神经网络和注意力机制的网络流量分类方法和装置 |
CN111565311B (zh) * | 2020-04-29 | 2022-02-25 | 杭州迪普科技股份有限公司 | 网络流量特征生成方法及装置 |
CN111565311A (zh) * | 2020-04-29 | 2020-08-21 | 杭州迪普科技股份有限公司 | 网络流量特征生成方法及装置 |
CN111756757A (zh) * | 2020-06-28 | 2020-10-09 | 南方电网科学研究院有限责任公司 | 一种僵尸网络检测方法和装置 |
CN112104570A (zh) * | 2020-09-11 | 2020-12-18 | 南方电网科学研究院有限责任公司 | 流量分类方法、装置、计算机设备和存储介质 |
CN112104570B (zh) * | 2020-09-11 | 2023-09-05 | 南方电网科学研究院有限责任公司 | 流量分类方法、装置、计算机设备和存储介质 |
CN114338437A (zh) * | 2022-01-13 | 2022-04-12 | 北京邮电大学 | 网络流量分类方法、装置、电子设备及存储介质 |
CN114338437B (zh) * | 2022-01-13 | 2023-12-29 | 北京邮电大学 | 网络流量分类方法、装置、电子设备及存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN108199863B (zh) | 2021-01-22 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108199863A (zh) | 一种基于两阶段序列特征学习的网络流量分类方法及系统 | |
Janarthanan et al. | Feature selection in UNSW-NB15 and KDDCUP'99 datasets | |
US10742669B2 (en) | Malware host netflow analysis system and method | |
CN109951444B (zh) | 一种加密匿名网络流量识别方法 | |
CN108200006A (zh) | 一种基于层次化时空特征学习的网络流量分类方法及装置 | |
WO2020159439A1 (en) | System and method for network anomaly detection and analysis | |
CN107370752B (zh) | 一种高效的远控木马检测方法 | |
CN110417729B (zh) | 一种加密流量的服务与应用分类方法及系统 | |
CN107819698A (zh) | 一种基于半监督学习的网络流量分类方法、计算机设备 | |
CN105306296B (zh) | 一种基于lte信令的数据过滤处理方法 | |
CN110796196A (zh) | 一种基于深度判别特征的网络流量分类系统及方法 | |
CN111224994A (zh) | 一种基于特征选择的僵尸网络检测方法 | |
CN104767692A (zh) | 一种网络流量分类方法 | |
CN103973589B (zh) | 网络流量分类方法及装置 | |
CN109831422A (zh) | 一种基于端到端序列网络的加密流量分类方法 | |
Coelho et al. | BACKORDERS: using random forests to detect DDoS attacks in programmable data planes | |
Salman et al. | Data representation for CNN based internet traffic classification: a comparative study | |
Almarshdi et al. | Hybrid Deep Learning Based Attack Detection for Imbalanced Data Classification. | |
CN107483451A (zh) | 基于串并行结构网络安全数据处理方法及系统、社交网络 | |
Chen et al. | Ride: Real-time intrusion detection via explainable machine learning implemented in a memristor hardware architecture | |
Zhao et al. | Edge intelligence based identification and classification of encrypted traffic of Internet of Things | |
Singhal et al. | State of the art review of network traffic classification based on machine learning approach | |
Yang et al. | Botnet detection based on machine learning | |
CN114358177B (zh) | 一种基于多维度特征紧凑决策边界的未知网络流量分类方法及系统 | |
CN113746707A (zh) | 一种基于分类器及网络结构的加密流量分类方法 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20210818 Address after: 100190, No. 21 West Fourth Ring Road, Beijing, Haidian District Patentee after: INSTITUTE OF ACOUSTICS, CHINESE ACADEMY OF SCIENCES Address before: 100190, No. 21 West Fourth Ring Road, Beijing, Haidian District Patentee before: INSTITUTE OF ACOUSTICS, CHINESE ACADEMY OF SCIENCES Patentee before: BEIJING INTELLIX TECHNOLOGIES Co.,Ltd. Effective date of registration: 20210818 Address after: Room 1601, 16th floor, East Tower, Ximei building, No. 6, Changchun Road, high tech Industrial Development Zone, Zhengzhou, Henan 450001 Patentee after: Zhengzhou xinrand Network Technology Co.,Ltd. Address before: 100190, No. 21 West Fourth Ring Road, Beijing, Haidian District Patentee before: INSTITUTE OF ACOUSTICS, CHINESE ACADEMY OF SCIENCES |
|
TR01 | Transfer of patent right |