The paper presents a selected indicators and algorithms which the passed Netflow-based anomaly detection technology were analyzed and the Netflow data of the compus network was studied from different grain-size and different angle for a long time. Then integration-indicators and Time Window Comparision Algorithms were introduced Integration-indicators which remove the non-stationary factors can reflect the characteristics of network traffic in addition to the non-stationary factors. The anomaly detection system based on intergration-indicators and Time Window-Comparison Algorithm was produced....