流量分析是统计用户通信量和检测异常流量的基础。传统的网络流量检测工具仅仅使用TCP/UDP/IP包头信息,因为TCP 或者UDP 端口号可能被不同的应用使用,故它们不能有效地识别不同应用的流量。本文论述了Netflow 流量分析技术的特点和工作原理,并探讨了Netflow 的应用和发展。 关键词:网络管理;流量分析; Netflow Abstract: Traffic analyzing is essential for accounting user traffic and detecting anomaly traffic. Since conventional traffic analyzing tools use only TCP/UDP/IP header information, they cannot effectively classify diverse application traffic, because TCP or UDP port numbers could be used by different applications. This article discusses the characteristics and working theory of Netflow, and probes into the application and development of it. Key words: network management; traffic analysis; netflow