Detecting network anomalies based on NetFlow time series

Lizhi Peng · Computer Engineering and Applications Journal · 2008

Network traffic shows periodicity and stability when network works normally,but network anomaly would break this rule.This paper presents a novel method which can find out network anomalies based on NetFlow time series sliding window.Using the time-series-based anomaly finding theory,the method realizes real-time finding network anomalies and making announcement of anomalies.To prevent an anomaly from persistent announcement and disturbing following detection,this paper also presents two ways to ignore announced anomalies.The results show that the method differentiates anomalies efficiently.

Read the paper · More papers on PaperTik