Traffic anomaly detection using multi-flows and multi-parameters in backbone network
Yingjie Zhou · Microcomputer Information · 2010
Anomaly detection in backbone network faces two problems:anomaly traffic is relatively small and real-time detection is difficult to implement.Aiming at these two difficulties,this paper proposed a detection method of traffic anomaly based on multi-flows and multi-parameters.Our method classified network traffic into several sub-flows which are closely related to network anomaly,extracted a variety of traffic features and packets features,and then detected traffic anomaly through multi-flows and multi-parameters.The detection results in Internet2's real data show that the proposed method can effectively detect flood attacks and port scans,these results almost equal to the results of the offline analysis.