Detection Theory and Application Based on Flow Spectrum for Network Traffic Threat
Author:
Affiliation:

Clc Number:

TP393

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    With the rapid development of network technology, frequent cyber attacks, especially advanced persistent threats (APTs), seriously affect national security and social stability. Under the continuous evolution of encryption, obfuscation, and camouflage techniques, intelligent analysis of network traffic is considered an effective means to improve threat detection capability. However, when processing massive volumes of network traffic data, existing methods still suffer from high analysis complexity and weak model interpretability. Flow spectrum adopts domain transformation as a unified solution by constructing a more accurate, highly separable, and observable description space for network flow data, thereby enabling efficient characterization, representation and analysis of network behaviors and effectively addressing the above issues. Inspired by the atomic spectrum, this study proposes a novel flow spectrum scheme. The core idea is achieve a concrete representation of network behaviors by mapping network flows into a one-dimensional spectral space, and to detect network traffic threats through flow spectrum comparison, in which the design of an effective flow spectrum decomposer is crucial. In this study, the flow spectrum decomposer is constructed based on a semi-supervised autoencoder and is trained by jointly performing reconstruction and classification tasks, enabling spectral line distributions of different network behaviors to exhibit strong separability. The proposed scheme is validated on the NSL-KDD, UNSW-NB15, and CIC-DDoS2019 datasets. Experimental results show that the proposed scheme achieves high detection accuracy for network threat behaviors while providing differentiated representations for various network traffic behaviors, significantly enhancing network behavior observability and improving the interpretability of threat detection methods. Therefore, the proposed flow spectrum scheme is effective for network traffic threat detection.

    Reference
    Related
    Cited by
Get Citation

杨璐铭,王勇军,柳林,付绍静,赵宝康,苏金树.基于流谱的网络流量威胁检测理论及应用.软件学报,,():1-20

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:June 18,2025
  • Revised:November 20,2025
  • Adopted:
  • Online: April 22,2026
  • Published:
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063