Self adaptive network traffic sampling method for anomaly detection
An adaptive network and anomaly detection technology, applied in the field of sampling technology, can solve the problems of large storage space, low processing speed, sampling distortion, etc., and achieve the effect of saving storage space, improving processing speed, and simple algorithm
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0029] The following describes in detail by implementing the present invention in an IDS device. During implementation, an adaptive sampling module needs to be set in the IDS, which completes the sampling and statistics functions of network data packets.
[0030] The steps of the present invention are:
[0031] Step 1. Start the program, initialize the system parameters, and use the predefined sampling probability p 0 Packets are sampled until the second time interval is reached. Clear the arrays used to record the flow size and the number of sampled packets in the time interval respectively. The initial values of the system parameters are as follows:
[0032] p 0
ε
T
T 1
T 2
0.9
0.001
10
15sec
30min
[0033] Step 2, capturing TCP / IP packets on the network in a bypass listening mode;
[0034] Step 3. Quickly classify the newly arrived data packets according to the flow identifier, and hash the flow ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com