A time-relevant network traffic anomaly detection approach

Zheng-mao ZHUANG,Xing-shu CHEN,Guo-lin SHAO,Xiao-ming YE
DOI: https://doi.org/10.6040/j.issn.1671-9352.1.2016.030
2017-01-01
Abstract:Server behavior characteristics in a time of dynamic correlation characteristics of a clustering method based on the distribution ratio, clustering and density deviation combined to construct a temporal correlation server traffic anomaly detection model. Through the campus network server traffic and long-term observation study found that server traffic characteristics and dynamic correlation time, based on this condition, this article extract the feature server traffic flow at the present time and combines the features of the current moment of time associated with dynamic, using K-means clustering algorithm to detect the outliers of the flow characteristics, and find abnormal server traffic. Experimental results show that the model can effectively detect abnormal server traffic even in the real-world environment. The longer the model applies, the stronger adaptable the algorithm is.
What problem does this paper attempt to address?