Activity monitoring platform monitor suspicious activities, such as spam, scanning, exploring, binary download, etc. Communication clustering module and activity clustering module process separately according to their monitoring log. 活动监测平台负责检测可疑的活动,例如扫描、垃圾邮件、漏洞利用、二进制下载等等。通信聚类模块和活动聚类模块根据监测平台产生的日志文件分别进行各自的聚类过程。