|国家预印本平台
首页|基于NetFlow和sFlow融合的异常分析检测系统

基于NetFlow和sFlow融合的异常分析检测系统

n Anomaly Analysis System Based on Fusion of NetFlow and sFlow

中文摘要英文摘要

为了解决单一协议所造成的数据信息覆盖不全面和对网络正常状态的分析问题,首先,研究分析了NetFlow和sFlow数据格式及功能,结合二者的特点提出一种基于NetFlow和sFlow协议字段融合方法,并通过与基于单一协议的方法实验对比验证了融合方法的优势。其次,根据网络异常的特征分析及基于网络流异常检测方法的研究,并结合融合网络流数据的特征,提出了基于NetFlow和sFlow网络流融合的异常检测方法。该方法结合网络流异常检测方法的特点,设置网络正常状态的监测,并将异常进行分类检测,达到自动有效地监测当前网络。最后对基于NetFlow和sFlow异常检测系统进行功能分析,且研究了其结构,对各个模块进行了设计与实现。并结合实验网络对系统进行部署,验证该系统的各模块的作用和优势。

In order to solve the problem of incomplete coverage of single protocol data and information and analyze the normal state of the network, first of all, this dissertation researches and analyzes data format and function analysis of the protocol of NetFlow and sFlow. Combining the characteristics of the two protocols, a fusion method based on NetFlow and sFlow protocol field is proposed, and is proven to have advantages compared with the fusion methods based on a single protocol through experiments. Secondly, according the analysis of network abnormal phenomena characteristics and the research of anomaly detection methods based on network flow, combining the characteristics of the fusion data of network flow, this dissertation proposes an anomaly detection method based on fusion of NetFlow and sFlow network flow. Combing the characteristics of network flow anomaly detection method, the proposed method sets the monitoring of normal network and made classification to detect abnormal phenomena, in order to monitor the current network automatically and effectively. Finally, this dissertation analyzes the function of system based on NetFlow and sFlow, and studying the system's structure, designing and implementing each module. Then we make deployments towards system according to the experimental network, to verify the function of each module and advantage.

王慧强、郭方方、李冰洋、陈欣、修龙亭

通信无线通信

网络流协议字段融合异常检测网络安全

Network flowProtocol field fusionAnomaly detectionNetwork security

王慧强,郭方方,李冰洋,陈欣,修龙亭.基于NetFlow和sFlow融合的异常分析检测系统[EB/OL].(2013-12-13)[2025-08-16].http://www.paper.edu.cn/releasepaper/content/201312-330.点此复制

评论