| With the rapid prevalence of the internet and the process of the information, Campus Network plays an important role in school, such as E-government affairs, On-line learning, Info Diffusion and so on. But there are some problems in it, namely the network traffic is none effective supervision and control, it results in Some of the abnormal application impacting on the normal network environment to increase the additional burden to Campus Network such as P2P flow increase. so it is necessary to do traffic detection and classification in Campus Network, for the control of it.Now, the mature traffic detection method is deep packet inspection (DPI). This method is mainly based on the characteristics of the packet payload match. Many mature products also use the technology. Foreign manufacturers such as allot, cisco, etc. Domestic producers such as Nanjing Greatbit, Beijing Kuan Guang telecom, They all have products based on this technology. But the DPI method has its own shortcomings. Encrypted data and "unknown" traffic can not be detected. Now, Software updates so quickly. This method can not meet the requirements gradually.To solve these problems. This paper presents a traffic detection based of host's behavior. Not detection the payload of packet. but research the connection characteristics of host communications. According the characteristics to do classification of traffic. In addition, in order to meet the high traffic characteristics of the campus network. According to the communication characteristics of P2P applications, use a UDP-based heuristic detection method as a complement. Experimental results show, The method is effective, can meet the needs of the campus network traffic detection. |