Abstract:This paper presents the abnormal traffic identification model based on network protocol; analyzes the network data layer combining with network protocol analysis and network intrusion detection technology; discovers the abnormal traffic IP address set through frequent IP address clustering, and counts the amount of abnormal data packets. With the simulation test of DDOS attack, it is proved that the model has high recognition ability and has good performance in terms of efficiency and calculation.