Flow feature confusion method based on AI virtual human

The AI-driven virtual human agent generates obfuscated traffic, which solves the user privacy problem that traffic fingerprint tracking is difficult to protect in the prior art, and realizes all-weather traffic feature obfuscation and privacy protection.

CN120433965AInactive Publication Date: 2025-08-05INTELLIGENT UNBOUNDED (CHENGDU) TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510499403.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-08-05
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing traffic fingerprint tracking technology is difficult to overcome by traditional device fingerprint camouflage schemes. Advertisers can identify and track users by analyzing the dynamic signal characteristics of network traffic, resulting in users' privacy leakage on the Internet.

Method used

The AI-driven virtual human agent generates obfuscated traffic. By configuring the basic attributes and behavioral strategies of virtual humans, it simulates human visiting the target site, generates characteristic traffic, uses containerized environment and browser fingerprint disguise, and dynamically adjusts behavioral parameters in combination with LLM drivers to generate fake traffic to interfere with traffic analysis.

Benefits of technology

Effectively interfere with and confusing user tracking based on traffic signal characteristics, enhance the ability to combat traffic fingerprint analysis, protect users' privacy at the Internet, and virtual people can generate confusing traffic around the clock and continuously interfere with traffic signal characteristics analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433965A_ABST
    Figure CN120433965A_ABST
Patent Text Reader

Abstract

The invention discloses a flow feature confusion method based on an AI virtual human, and the method comprises the steps: S1, configuring the basic attributes of the virtual human and a preset behavior strategy, and automatically obtaining the fingerprints of Internet access equipment of a user; s2, virtual human environment fingerprint camouflage is carried out by configuring a containerized operation environment and adjusting browser fingerprints; s3, dynamically generating behavior parameters for determining a virtual human online task based on LLM drive of preset parameters; and S4, the virtual human calls a local browser driver on line based on the behavior parameters obtained in the S3, simulates human to access the target site and generates feature traffic. According to the method, the virtual human Agent is driven by the AI, the mixed flow is generated by autonomously acting on the network, the user identification and tracking technology of the network access target based on the flow signal characteristics is effectively interfered, the signal statistics characteristics of the user internet surfing flow can be effectively mixed, and the method is suitable for the network privacy protection requirements in various scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security, and in particular relates to a traffic feature obfuscation method based on AI virtual humans. Background Art

[0002] To deliver more targeted advertising, internet advertisers are constantly seeking new user identification and tracking technologies. Currently, two main fingerprinting tracking methods are used: host fingerprinting and traffic fingerprinting. Host fingerprinting is an identification method based on the attributes of the internet device, typically including browser request headers, cookies, fonts, and display engines. Due to the static nature of host fingerprinting, this information can be easily modified or erased by users through technical means. To overcome the limitations of this method, internet advertisers have begun using traffic fingerprinting to identify users. Instead of relying on the static attributes of the internet device, traffic fingerprinting is constructed by analyzing the dynamic signal characteristics of network traffic. For example, traffic time series characteristics, target distribution characteristics, and frequency domain characteristics (such as traffic spectrum analysis) are used. These signal characteristics often directly reflect users' online behavior and are therefore highly stable and difficult to tamper with.

[0003] As an ordinary Internet user, traditional device fingerprint disguise solutions (such as browser incognito mode) are no longer able to resist tracking technology based on traffic fingerprints. To address this problem, this patent proposes a traffic feature obfuscation method based on a virtual human. Summary of the Invention

[0004] This application aims to overcome the problems of existing technologies by disclosing a traffic feature obfuscation method based on an AI-powered virtual human. This method uses an AI-driven virtual human agent to autonomously generate obfuscated traffic on the network. This effectively interferes with and obfuscates user tracking methods based on traffic signal characteristics. This method significantly enhances the ability to combat traffic fingerprint analysis, thereby effectively protecting users' online privacy.

[0005] The purpose of this application is achieved through the following technical solutions:

[0006] A traffic feature obfuscation method based on an AI virtual human, the traffic feature obfuscation method based on an AI virtual human comprising:

[0007] S1. Configure the basic attributes and preset behavior strategies of the virtual human, and automatically obtain the fingerprint of the user's online device;

[0008] S2, configure the containerized runtime environment and adjust the browser fingerprint to disguise the virtual human environment fingerprint;

[0009] S3, based on the preset parameters, LLM drives the dynamic generation of behavioral parameters to determine the virtual human's online tasks;

[0010] S4. The virtual human calls the local browser driver online based on the behavioral parameters obtained in S3, simulating humans visiting the target site and generating characteristic traffic.

[0011] According to a preferred embodiment, step S1 includes:

[0012] S11. Configure the basic attributes of the virtual person, including: gender, age, nationality, occupation, interests and hobbies;

[0013] S12. Configure the virtual human behavior strategy, including: activity time, target site, action interval rhythm, keywords and themes;

[0014] S13. Obtain user device fingerprints, including operating system version, browser header, time zone, language, and automation characteristics.

[0015] According to a preferred embodiment, the virtual human environment fingerprint in step S2 is disguised as: cloning the static fingerprint of the real user's Internet access device that joins the virtual human, and the static fingerprint includes: browser header, hardware characteristics, operating system version, and language environment.

[0016] According to a preferred embodiment, step S3 includes:

[0017] S31, constructing prompt words that meet the characteristics of the virtual human based on the preset virtual human parameters as LLM driving input;

[0018] S32. LLM drives autonomous generation of virtual human behavior parameters, including: language, target site, activity time, operation rhythm, search keywords, and access content preferences.

[0019] According to a preferred embodiment, step S4 includes:

[0020] S41, the virtual human loads the behavior parameters and executes the task list cyclically;

[0021] S42, determine whether the task is within the specified execution time range, if not, wait for the task execution interval time and put the task back into the task cycle list; if it is, enter S43;

[0022] S43, verify whether the task behavior policy configuration changes dynamically. If so, add the corresponding task to the task scheduling management engine and proceed to S46; if not, proceed to S44;

[0023] S44, obtaining the user's browser fingerprint and verifying whether the fingerprint is consistent with the browser driver. If they are inconsistent, the browser driver performs fingerprint disguise once and then enters S45. If they are consistent, directly enters S45;

[0024] S45, calling the browser driver to asynchronously execute the virtual human task and returning the browser window session handle of the current task;

[0025] S46, the task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded the execution time. If so, the corresponding browser window is closed and the process proceeds to S47; if not, the process continues to wait for the virtual human to execute the task.

[0026] S47, judging whether the virtual human has successfully executed this subtask, if successful, then ending this subtask, if unsuccessful, then returning the task to the task loop queue and entering S41.

[0027] According to a preferred embodiment, the process of generating characteristic traffic in step S4 includes: integrating traffic generated by the network behavior of the virtual human Agent and real traffic generated by the user into a traffic obfuscation module with a preset obfuscation strategy to generate characteristic traffic.

[0028] According to a preferred embodiment, step S4 further includes: the virtual human intelligently and adaptively adjusts the obfuscation strategy of the virtual human traffic and the real user traffic according to the current network environment, user operation behavior and potential threat scenarios.

[0029] According to a preferred embodiment, the obfuscation strategy includes:

[0030] 1) Traffic filling: injecting fake network packets into normal traffic to fill idle time periods, increase the uncertainty and randomness of traffic, and mask the actual communication pattern;

[0031] 2) Delayed traffic sending: A random delay is set before the request is sent to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the actual time pattern of communication behavior;

[0032] 3) Forging traffic, generating irrelevant traffic regularly or randomly, simulating the diverse network behaviors of normal users, confusing traffic analysis systems and reducing the distinguishability of traffic characteristics;

[0033] 4) Traffic pattern imitation, disguising sensitive communication traffic as typical non-sensitive traffic;

[0034] 5) Multi-channel distribution: split the original traffic into several small traffic segments and transmit them through different paths or protocols.

[0035] According to a preferred embodiment, the irrelevant traffic includes: HTTP request, video traffic or DNS query.

[0036] According to a preferred embodiment, the process of disguising sensitive communication traffic as typical non-sensitive traffic includes disguising file transfer as video streaming.

[0037] The aforementioned main solution of this application and its further options can be freely combined to form multiple solutions, all of which can be adopted and protected by this application. After understanding the solution of this application, those skilled in the art will understand that there are many combinations based on existing technology and common knowledge, all of which are technical solutions to be protected by this application, and these are not exhaustive here.

[0038] Beneficial effects of this application:

[0039] Through this method, when a user visits a target website, a virtual person associated with them can generate fake traffic to mask the user's traffic signal characteristics, preventing advertisers from identifying and tracking them through traffic signal characteristics. The virtual person can generate obfuscated traffic 24 / 7, even after the user logs off, continuously interfering with the target's traffic signal analysis. This significantly enhances the ability to combat traffic fingerprinting, effectively protecting users' online privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 This is a flowchart of the method for implementing traffic feature obfuscation based on a virtual person in this application;

[0041] Figure 2 This is a schematic diagram of the behavioral characteristics of virtual humans optimized based on LLM driving in this application;

[0042] Figure 3 This is a schematic diagram of the autonomous action process of the browser driven by the virtual human in this application;

[0043] Figure 4 This is a schematic diagram of the operating environment structure of the virtual human behavior engine of this application. DETAILED DESCRIPTION

[0044] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other unless they conflict.

[0045] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0046] refer to Figure 1As shown, the present application discloses a traffic feature obfuscation method based on AI virtual humans, which mainly includes the user configuring the basic attributes, fingerprints, target sites and behavior strategies of the virtual humans, the virtual human Agent engine generating network behaviors and the browser driving the execution of network operations, and the real traffic generated by the user and the traffic generated by the virtual humans entering the traffic obfuscation engine together, and the obfuscated traffic generated after traffic obfuscation is integrated into the Internet.

[0047] Specifically, the traffic feature obfuscation method based on AI virtual human in this application includes the following steps.

[0048] Step 1: Configure the avatar's basic attributes. First, the user must define the avatar's basic attributes, such as gender, nationality, occupation, and interests. These attributes can be entered manually or quickly generated based on predefined templates. They determine the avatar's identity and directly influence its online activities and behavior.

[0049] Step 2: Obtain user environment fingerprint. After completing the basic attribute settings, obtain the real user's Internet device environment fingerprint configuration, such as the browser header (User-Agent, Accept-Language, Referer), time zone and language (time, time zone, language), and shielding automation features.

[0050] Step 3: Configure the virtual human behavior strategy. Users need to pre-configure the target site and behavior strategy for the virtual human to visit:

[0051] a) Target site configuration: Specify the sites that the virtual person needs to visit, such as social media, news websites, or specific search engines.

[0052] b) Behavioral strategy configuration: Define the virtual person's operating mode, activity time (active all day or during a specified time period), content access tendency (browsing news, watching videos, or social interaction), and behavior rhythm (fast-paced operation or simulating more natural user habits).

[0053] Step 4: Virtual human environment fingerprint camouflage, based on the virtual human simulating the user browser environment in the virtual container environment. The core of the environment fingerprint camouflage lies in the consistency of the user environment, browser fingerprint camouflage and traffic fingerprint obfuscation.

[0054] Specifically, this method, based on a virtual human simulating a user's browser environment within a virtual container environment to generate obfuscated traffic, focuses on achieving environmental consistency, browser fingerprinting, and traffic fingerprint obfuscation. By configuring a containerized runtime environment and adjusting browser fingerprint characteristics, advertisers can effectively be blinded to the actual source of traffic, mistaking the traffic generated by the virtual human for real user behavior data. This method uses traffic obfuscation technology to mask the traffic signal characteristics of real online users, thereby preventing advertisers from building accurate user profiles based on the dynamic signal characteristics of network traffic.

[0055] 1) Environmental consistency: By deploying a virtualized browser environment in a container, it maintains a high degree of consistency with the hardware, network, and software configurations of the host environment, including but not limited to operating system version, display resolution, language settings, time zone configuration, and network protocol stack characteristics.

[0056] 2) Browser fingerprint camouflage: This aims to dynamically adjust key browser features to evade detection and enhance traffic camouflage. Specific actions include but are not limited to the following:

[0057] a. Modify or dynamically generate the User-Agent string to disguise the browser version and device type;

[0058] b. Accept-Language camouflage, matching the target user's language preference, such as zh-CN, zh; q = 0.8;

[0059] c. Dynamically adjust the regional time zone settings to keep the browser's local time consistent with the geographical location;

[0060] d. Disable the webdriver flag or modify the automation tool flag such as navigator.webdriver property;

[0061] e. Adjusting hardware features such as Canvas, WebGL, and audio fingerprints to generate fake data;

[0062] 3) Traffic fingerprint obfuscation: Traffic fingerprint obfuscation adjusts traffic characteristics at the network level, uses proxy servers or tunneling technology to ensure consistency with the user's exit IP address, uses virtual human agents to intelligently call virtual browsers to generate obfuscated traffic, and allows virtual humans to autonomously execute and dynamically adjust virtual human task execution strategies, further improving the traffic obfuscation effect.

[0063] Step 5: Invoke the LLM driver to optimize the virtual human's behavior strategy. The virtual human LLM driver, the core of this method, connects the LLM model driver and the browser driver, seamlessly integrating all modules. The LLM intelligently optimizes the virtual human's behavior strategy based on pre-set target sites and behavior strategies, assigning the virtual human to perform specific tasks (such as visiting a website or performing an action within a certain time period).

[0064] Specifically, the LM model autonomously generates behavioral parameters that determine the virtual person's online tasks based on preset parameters. When the virtual person performs tasks and generates characteristic traffic, if these preset parameters are fixedly used to mechanically generate traffic, it is easy for the opponent to identify it. Therefore, it is necessary to use the virtual person LLM to drive real-time dynamic loading and adjustment of task execution parameters.

[0065] Specifically, Figure 2 As shown, by loading the preset configuration of virtual human related features, including virtual human basic attribute configuration, behavior strategy configuration, target site configuration and user online behavior habits, a large model-driven input is constructed through a specific prompt word engineering template.

[0066] The LLM driver outputs the execution parameters of the virtual person, including: the native language used (such as Chinese, English, etc.), the target site (Baidu, Taobao, Weibo, etc.), activity schedule (such as active time period), task execution interval rhythm (such as click interval, scrolling speed), network search engine keywords, preferences and topics for accessed content (such as the frequency of visits to certain specific websites or content types), access frequency, etc.

[0067] Step 6: The virtual human autonomously calls the browser driver to perform tasks and generates virtual human obfuscated traffic. The virtual human engine drives the remote browser to perform real browser operations. The virtual human autonomously performs network tasks such as browsing, searching, and watching videos, constructing complex behavior patterns and network traffic patterns more similar to those generated by ordinary netizens.

[0068] The virtual person's online behavior is driven by a locally running Chrome browser, simulating human behavior when accessing target sites. The virtual person's behavior can also be flexibly adjusted based on the dynamic network environment, ensuring that their actions are more natural and logical, and difficult for tracking systems to identify as non-human activity.

[0069] Virtual agents can operate independently and continuously around the clock. Even when real users are offline, they can continue to conduct online activities and generate network traffic. Virtual agents are independent of real-time human user behavior and can continuously generate seemingly real online activity without human intervention. This feature allows virtual agents to effectively confuse tracking technologies based on real-time user behavior monitoring, ensuring that advertisers cannot accurately target and track users' online behavior.

[0070] Specific implementation process, such as Figure 3 As shown. Includes:

[0071] Step a: Dynamically load the virtual human behavior parameters optimized by LLM intelligence;

[0072] Step b: Traverse the subtask execution loop list;

[0073] Step c: Determine whether the task is within the specified execution time range. If not, wait for the task execution interval and then put the task back into the task loop list; if it is within the execution time range, proceed to the next step;

[0074] Step d: Dynamically load the virtual human behavior strategy configuration and determine whether it has changed. If so, add this task to the task scheduling management engine; if not, proceed to the next step;

[0075] Step e: Obtain the user's browser fingerprint and verify whether the fingerprint is consistent with the browser driver. If not, perform a browser driver fingerprint disguise;

[0076] Step f: Call the browser driver to asynchronously execute the virtual human task, generate real obfuscated traffic, and return the browser window session handle corresponding to the current task;

[0077] Step g: The task scheduling management engine obtains the handle of the task execution browser window and uniformly manages and schedules the virtual human behavior, including calculating the task execution time, action rhythm, updating and closing tasks, etc.

[0078] Step h: The task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded the execution time. If so, the corresponding window is closed through the browser session unique handle; if not, it continues to wait for the virtual human to execute the task;

[0079] Step i: Determine whether the virtual human of this subtask is executed successfully and generates the expected specific traffic. If successful, end this subtask; if unsuccessful, return the task to the task loop queue.

[0080] Step j: Determine whether there are any tasks to be executed in the loop list. If so, continue to loop and execute the next virtual human task. If not, end this autonomous action process.

[0081] The traffic generated by the network behavior of the virtual human agent and the real traffic generated by the user are integrated into the traffic obfuscation module. The virtual human autonomously executes and dynamically adjusts the virtual human task execution strategy based on predefined traffic fingerprint characteristics to reduce the significance of traffic characteristics and prevent the user's true intentions from being identified and analyzed in the network.

[0082] Furthermore, the virtual human intelligently and adaptively adjusts the obfuscation strategy of virtual human traffic and real user traffic according to the current network environment, user operation behavior and potential threat scenarios to achieve maximum anonymity.

[0083] Preferably, the main network behavior obfuscation strategies include:

[0084] 1) Traffic filling refers to injecting fake network packets on top of normal traffic to fill idle time periods, increase the uncertainty and randomness of traffic, and mask the actual communication pattern;

[0085] 2) Delayed traffic sending refers to setting a random delay before sending a request to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the actual time pattern of communication behavior;

[0086] 3) Forged traffic is the periodic or random generation of irrelevant traffic (such as HTTP requests, video traffic, or DNS queries) to simulate the diverse network behavior of normal users, confusing traffic analysis systems and reducing the distinguishability of traffic characteristics;

[0087] 4) Traffic pattern imitation is to disguise sensitive communication traffic as some typical non-sensitive traffic (such as disguising file transfer as video streaming);

[0088] 5) Multi-channel distribution divides the original traffic into multiple small traffic segments and transmits them through different paths or protocols, reducing the characteristic significance of concentrated traffic in a single channel, thereby avoiding centralized analysis and tracking.

[0089] The virtual human behavior traffic obfuscation environment and the real user environment are in the same secure access gateway environment. The traffic generated by the two is further obfuscated through the traffic obfuscation module, which increases the difficulty for advertisers to profile the communication traffic and meets the user network behavior privacy protection needs in various scenarios.

[0090] Step 7: At the same time, the user performs actual work and business on a computer in a real Internet environment and generates network traffic that requires privacy protection. The traffic generated by the virtual person and the real traffic generated by the user enter the local gateway together and are integrated into the target website together.

[0091] Step 8: The system will log the virtual person's operation behavior, mainly including the sites visited, the behaviors performed, and the traffic characteristics generated. The virtual execution of tasks can be displayed through a visualization tool (vnc).

[0092] Internet advertisers analyze the dynamic signal characteristics of users' network traffic, which directly reflect their online habits and preferences. This allows them to easily build user profiles and accurately target advertising. The core goal of the virtual human behavior engine is to intelligently blend virtual human traffic into advertisers' or third-party tracking and analysis of real users' network behavior, thereby achieving traffic anonymization and privacy protection.

[0093] Through this method, when a user visits a target website, a virtual person associated with them can generate fake traffic to mask the user's traffic signal characteristics, preventing advertisers from identifying and tracking them through traffic signal characteristics. The virtual person can generate obfuscated traffic 24 / 7, even after the user logs off, continuously interfering with the target's traffic signal analysis. This significantly enhances the ability to combat traffic fingerprinting, effectively protecting users' online privacy.

[0094] like Figure 4 As shown, the virtual human behavior engine and real user online behavior can run simultaneously without interfering with each other. Users can customize the virtual human's basic attributes and behavior strategies based on their needs. The virtual human behavior engine simulates the device fingerprint of real users and uses the Large Language Model (LLM) to optimize the virtual human's behavior strategies, ensuring that its online behavior is more similar to that of real users. Ultimately, automated browser technology drives the virtual human to simulate real user operations, generating network traffic that is indistinguishable from that of real users.

[0095] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application should be included in the scope of protection of the present application.

Claims

1. A traffic feature obfuscation method based on AI virtual human, characterized in that: The traffic feature obfuscation method based on AI virtual human includes: S1. Configure the basic attributes and preset behavior strategies of the virtual human, and automatically obtain the fingerprint of the user's online device; S2, configure the containerized runtime environment and adjust the browser fingerprint to disguise the virtual human environment fingerprint; S3, based on the preset parameters, LLM drives the dynamic generation of behavioral parameters to determine the virtual human's online tasks; S4. The virtual human calls the local browser driver online based on the behavioral parameters obtained in S3, simulating humans visiting the target site and generating characteristic traffic.

2. The traffic feature obfuscation method based on AI virtual human according to claim 1, characterized in that: Step S1 includes: S11. Configure the basic attributes of the virtual person, including: gender, age, nationality, occupation, interests and hobbies; S12. Configure the virtual human behavior strategy, including: activity time, target site, action interval rhythm, keywords and themes; S13. Obtain user device fingerprints, including operating system version, browser header, time zone, language, and automation characteristics.

3. The traffic feature obfuscation method based on AI virtual human according to claim 1, characterized in that: In step S2, the virtual person's environmental fingerprint is disguised as: cloning the static fingerprint of the real user's Internet access device that is connected to the network with the virtual person, and the static fingerprint includes: browser header, hardware characteristics, operating system version, and language environment.

4. The traffic feature obfuscation method based on AI virtual human according to claim 1, characterized in that: Step S3 includes: S31, constructing prompt words that meet the characteristics of the virtual human based on the preset virtual human parameters as LLM driving input; S32. LLM drives autonomous generation of virtual human behavior parameters, including: language, target site, activity time, operation rhythm, search keywords, and access content preferences.

5. The traffic feature obfuscation method based on AI virtual human according to claim 1, characterized in that: Step S4 includes: S41, the virtual human loads the behavior parameters and executes the task list cyclically; S42, determine whether the task is within the specified execution time range, if not, wait for the task execution interval time and put the task back into the task cycle list; if it is, enter S43; S43, verify whether the task behavior policy configuration changes dynamically. If so, add the corresponding task to the task scheduling management engine and proceed to S46; if not, proceed to S44; S44, obtaining the user's browser fingerprint and verifying whether the fingerprint is consistent with the browser driver. If they are inconsistent, the browser driver performs fingerprint disguise once and then enters S45. If they are consistent, directly enter S45; S45, calling the browser driver to asynchronously execute the virtual human task and returning the browser window session handle of the current task; S46, the task scheduling engine determines whether the task behavior parameters have changed or whether the task has exceeded the execution time. If so, the corresponding browser window is closed and the process proceeds to S47; if not, the process continues to wait for the virtual human to execute the task. S47, judging whether the virtual human has successfully executed this subtask, if successful, ending this subtask, if unsuccessful, returning the task to the task loop queue and entering S41.

6. The traffic feature obfuscation method based on AI virtual human according to claim 1, characterized in that: The process of generating characteristic traffic in step S4 includes: integrating the traffic generated by the network behavior of the virtual human Agent and the real traffic generated by the user into the traffic obfuscation module of the preset obfuscation strategy to generate characteristic traffic.

7. The traffic feature obfuscation method based on AI virtual human according to claim 6, characterized in that: Step S4 also includes: the virtual human intelligently and adaptively adjusts the obfuscation strategy of the virtual human traffic and the real user traffic according to the current network environment, user operation behavior and potential threat scenarios.

8. The traffic feature obfuscation method based on AI virtual human according to claim 6, characterized in that: The obfuscation strategies include: 1) Traffic filling: injecting fake network packets into normal traffic to fill idle time periods, increase the uncertainty and randomness of traffic, and mask the actual communication pattern; 2) Delayed traffic sending: A random delay is set before the request is sent to disrupt the time series characteristics of the original traffic, making it difficult for traffic analysis tools to identify the actual time pattern of communication behavior; 3) Forging traffic, generating irrelevant traffic regularly or randomly, simulating the diverse network behaviors of normal users, confusing traffic analysis systems and reducing the distinguishability of traffic characteristics; 4) Traffic pattern imitation, disguising sensitive communication traffic as typical non-sensitive traffic; 5) Multi-channel distribution: split the original traffic into several small traffic segments and transmit them through different paths or protocols.

9. The traffic feature obfuscation method based on AI virtual human according to claim 8, characterized in that: The irrelevant traffic includes: HTTP requests, video traffic or DNS queries.

10. The traffic feature obfuscation method based on AI virtual human according to claim 8, characterized in that: Disguising sensitive communications as typical non-sensitive traffic includes disguising file transfers as video streams.

Citation Information

Cited By

  • Code protection method and electronic equipment

    CN122471409A

  • Code protection method and electronic device

    CN122471409B