结合企业内部信息技术网络特点,提出了用时间窗比较进行网络异常流量检测的新算法.将新算法同已有的静态、动态检测算法相结合,提出了网络异常流量综合检测模型.该模型可通过不同方法和角度进行比较,以发现网络中是否存在异常流量.通过实际实现和测试验证了模型的有效性.
A new algorithm of the network anomaly traffic detection by using time windows comparing method is proposed based on the feature of enterprise information technology (IT) network traffic. Then, combining the new algorithm, the present static detection algorithm and the dynamic detection algorithm, the integrated detection model of network anomaly traffic is proposed. The model can check the network anomaly traffic by comparison methods by different ways and from different views. Finally, the availability of model is validated by implementation and testing of model in real environment.