Real-time network abnormal behavior detecting system and method based on big data
A real-time network and detection system technology, applied in the field of network security management, can solve the problems of not being able to provide data for full flow analysis, unsatisfactory stream processing performance, and low collection efficiency, so as to facilitate management, retrieval and query, and detection Intuitive results
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0073] A real-time network abnormal behavior detection system based on big data, such as Figure 1~2 As shown, it includes the traffic collection layer, data pipeline layer, real-time computing layer, data storage layer, data analysis layer, and application layer.
[0074] As a preferred solution, the traffic collection layer includes a mirrored traffic collection module that collects traffic mirrored from the switch, a local file collection module that collects local files, and a network probe that collects sensor data Acquisition module. The three modules can all provide traffic collection services. The traffic collection services include data packet capture services, data packet analysis services, local order placement services, data feature extraction services, data stream serialization services, and data sending services.
[0075] The traffic collection layer captures data packets through the data packet capture service, and then preprocesses the collected data, and then tran...
Embodiment 2
[0116] A real-time network abnormal behavior detection method based on big data includes a traffic collection layer, a data pipeline layer, a real-time computing layer, a data storage layer, a data analysis layer, and an application layer, and specifically includes the following steps:
[0117] S1: The traffic collection layer collects traffic data from the data source and preprocesses the data, then sends the preprocessed data to the distributed messaging system in the data pipeline layer, and saves the original data packets in the data storage layer;
[0118] S2: The real-time computing layer obtains preprocessed data from the distributed messaging system, obtains basic features from the data and extracts statistical features, and then adds the statistical features and protocol features to the basic features to form a total Features, and then save the total features in the data storage layer;
[0119] S3: The data analysis layer obtains the total features from the data storage laye...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com