A network traffic identification method, device and electronic equipment
Patent Information
- Application Number
- CN202610663080.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-14
- Publication Date
- 2026-09-04
AI Technical Summary
然而,传统的DPI(Deep Packet Inspection,深度数据包检测)技术方案在面对QUIC广泛部署环境时往往会失效,难以针对网络流量数据进行高精度识别乃至准确识别,从而导致通信网络对网络流量业务场景的识别能力下降,大大降低了通信网络的QoS(Quality of Service,服务质量)保障能力以及安全管控能力
在本申请实施例中,通过捕获经过通信网络边缘节点的目标流量数据,可以根据上述目标流量数据,分别提取基于QUIC协议的QUIC握手连接特征以及应用交互行为特征,进而可以对该QUIC握手连接特征和应用交互行为特征进行融合,得到目标融合特征。在此基础上,根据目标融合特征,可以识别上述目标流量数据对应的业务场景类型。可见,实施本申请实施例,能够针对基于QUIC协议的加密网络流量数据,通过解析表征其协议层面特性的QUIC握手连接特征,以及表征其业务层面特性的应用交互行为特征,并对两者进行融合,以绕过报头保护机制,对上述加密网络流量数据实现有效的QUIC相关特征提取和识别。这样的网络流量识别方式,能够有机结合协议层和业务层的多维度不同特征,有效提升针对QUIC相关特征的提取成功率和识别准确性,可以在不涉及数据隐私的前提下提升通信网络对网络流量业务场景的识别能力,从而有利于在通信网络层面加强对网络流量的安全管控能力,同时保障通信网络QoS,尽可能避免了对通信网络性能的影响。
Smart Images

Figure CN122698538A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication network technology, specifically to a network traffic identification method, device, and electronic device. Background Technology
[0002] Currently, with the widespread adoption of the QUIC (Quick UDP Internet Connections) protocol, a fast transmission protocol based on UDP (User Datagram Protocol), its header protection mechanism encrypts all data except for the public header metadata. This presents challenges for the security management of communication networks. However, traditional DPI (Deep Packet Inspection) solutions often fail in environments with widespread QUIC deployment, struggling to accurately identify network traffic data. This leads to a decline in the communication network's ability to identify network traffic service scenarios, significantly reducing its QoS (Quality of Service) assurance and security management capabilities. Summary of the Invention
[0003] This application discloses a network traffic identification method, device, and electronic device, which can effectively improve the extraction and identification of QUIC-related features of network traffic data, thereby enhancing the communication network's ability to identify network traffic service scenarios and strengthening its security management capabilities while ensuring the QoS of the communication network.
[0004] The first aspect of this application discloses a network traffic identification method, including: Capture target traffic data passing through edge nodes of the communication network; Based on the target traffic data, extract the QUIC handshake connection features and application interaction behavior features based on the QUIC protocol. The QUIC handshake connection features and the application interaction behavior features are fused to obtain the target fused features; Based on the target fusion features, identify the business scenario type corresponding to the target traffic data.
[0005] The second aspect of this application discloses a network traffic identification device, comprising: Traffic capture unit is used to capture target traffic data passing through edge nodes of the communication network; The feature extraction unit is used to extract QUIC handshake connection features and application interaction behavior features based on the target traffic data, respectively. The feature fusion unit is used to fuse the QUIC handshake connection features and the application interaction behavior features to obtain the target fused features; The identification unit is used to identify the business scenario type corresponding to the target traffic data based on the target fusion features.
[0006] The third aspect of this application discloses an electronic device, including a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor enables the processor to implement any of the network traffic identification methods disclosed in the first aspect of this application.
[0007] The fourth aspect of this application discloses a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the network traffic identification methods disclosed in the first aspect of this application.
[0008] Compared with related technologies, the embodiments of this application have the following beneficial effects: In this embodiment, by capturing target traffic data passing through edge nodes of the communication network, QUIC handshake connection features and application interaction behavior features based on the QUIC protocol can be extracted from the target traffic data. These features can then be fused to obtain target fused features. Based on these target fused features, the business scenario type corresponding to the target traffic data can be identified. Therefore, implementing this embodiment allows for the effective extraction and identification of QUIC-related features from encrypted network traffic data based on the QUIC protocol. This is achieved by parsing the QUIC handshake connection features (characterizing protocol-level characteristics) and the application interaction behavior features (characterizing business-level characteristics) and fusing them, bypassing header protection mechanisms. This network traffic identification method organically combines multi-dimensional features from the protocol and business layers, effectively improving the success rate and accuracy of QUIC-related feature extraction. It enhances the communication network's ability to identify network traffic business scenarios without compromising data privacy, thereby strengthening the security control of network traffic at the communication network level, ensuring QoS, and minimizing impact on network performance. Attached Figure Description
[0009] Figure 1 This is a schematic diagram of a communication network system architecture disclosed in an embodiment of this application; Figure 2 This is a flowchart illustrating a network traffic identification method disclosed in an embodiment of this application; Figure 3This is a flowchart illustrating another network traffic identification method disclosed in an embodiment of this application; Figure 4 This is a flowchart illustrating another network traffic identification method disclosed in the embodiments of this application; Figure 5 This is a schematic diagram of the parsing process of the network traffic identification method disclosed in the embodiments of this application; Figure 6 This is a modular schematic diagram of a network traffic identification device disclosed in an embodiment of this application; Figure 7 This is a modular schematic diagram of an electronic device disclosed in an embodiment of this application. Detailed Implementation
[0010] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0011] It should be noted that the terms "comprising" and "having" and any variations thereof in the embodiments of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or devices.
[0012] This application discloses a network traffic identification method, device, and electronic device, which can effectively improve the extraction and identification of QUIC-related features of network traffic data, thereby enhancing the communication network's ability to identify network traffic service scenarios and strengthening its security management capabilities while ensuring the QoS of the communication network.
[0013] The following will be described in detail with reference to the accompanying drawings.
[0014] Please see Figure 1 , Figure 1 This is a schematic diagram of a communication network system architecture disclosed in an embodiment of this application. Figure 1 As shown, the communication network may include edge nodes and a central server, wherein multiple edge nodes ( Figure 1(Taking only one example) can be connected to the central server separately. Each edge node can be located in the same place as the central server and achieve logical isolation through cloud platform virtualization technology; or they can be located in different places so that each edge node (e.g., near a communication base station or a matching edge server) is closer to the user side to reduce latency and transmission bandwidth requirements. The central server (e.g., the core network, which can be implemented through a cloud server) is used to coordinate each edge node to meet global business needs.
[0015] It should be noted that, Figure 1 The communication network system architecture shown in this application is only a simplified framework including edge nodes and a central server. In reality, the communication network may also include other necessary processing and connection devices, which are not specifically limited in this application embodiment.
[0016] The network traffic identification method disclosed in this application can be implemented solely based on the aforementioned edge nodes, or it can be implemented partially on the edge nodes and partially on the central server. For example, the edge node may include a traffic capture layer, a feature extraction layer, a service identification layer, an identification decision layer, and a policy execution layer.
[0017] The aforementioned traffic capture layer can be used to capture target traffic data passing through edge nodes of the communication network. Optionally, the traffic capture layer may include a traffic capture module deployed on MEC (Multi-access Edge Computing) edge nodes, or a traffic capture module deployed on UPF (User Plane Function) edge nodes, such as a 5G UPF.
[0018] In some embodiments, the traffic capture layer described above may include at least a high-speed packet capture unit and a QUIC flow pre-filtering unit. The high-speed packet capture unit can be implemented in hardware using a network interface card supporting the DPDK (Data Plane Development Kit) and configured with huge page memory (e.g., 1GB pages). In software, it can capture network traffic data passing through edge nodes in a zero-copy manner using the DPDK PMD (Poll Mode Driver). The QUIC flow pre-filtering unit can perform kernel-level filtering of the network traffic data based on a certain rule set using the BPF (Berkeley Packet Filter) to further obtain the target traffic data.
[0019] The aforementioned feature extraction layer can be used to extract QUIC handshake connection features and application interaction behavior features based on the target traffic data captured by the traffic capture layer. Furthermore, the QUIC handshake connection features and application interaction behavior features can be fused to obtain target fused features. For example, the above feature extraction process can be implemented by pre-constructing suitable feature extraction pipelines using a QUIC handshake parser (e.g., a QUIC feature extraction engine) and a behavior pattern analyzer (e.g., a behavior analysis engine). Optionally, the above feature fusion process can be performed on edge nodes immediately following different feature extraction processes, or it can be performed separately on a central server; this embodiment does not impose specific limitations.
[0020] The aforementioned business identification layer can be used to identify the business scenario type corresponding to the target traffic data based on the target fusion features. This business identification layer can include a lightweight classifier (deployed on edge nodes), such as a random forest model, for coarse-grained business type identification; and a deep classifier (which can be deployed on edge nodes or a central server), such as an XGBoost (eXtreme Gradient Boosting) model or a CRF (Conditional Random Field) model, for fine-grained scenario type classification.
[0021] The aforementioned identification decision layer can be used to determine a suitable target mapping strategy from a preset policy mapping table based on the identified network traffic scenario type. For example, the target mapping strategy may include QoS policies matching the network traffic scenario type, such as specified GBR (Guaranteed Bit Rate), MBR (Maximum Bit Rate), priority, packet loss rate, latency requirements, and other indicators; it may also include security policies matching the network traffic scenario type, such as specified deep inspection levels, session timeout thresholds, abnormal behavior thresholds, and other indicators. Based on this, the aforementioned policy execution layer can be used to execute the determined target mapping strategy.
[0022] Optionally, the identification decision layer can be deployed on an edge node or on the control plane corresponding to that edge node (such as a central server or other independent control plane node, the latter of which may include a 5G control plane). Figure 1 This is shown separately in the text.
[0023] In some embodiments, the communication network may also include an optimization feedback layer, which may be deployed at edge nodes or at a central server. Figure 1(Taking the deployment on the central server as an example). This optimization feedback layer can be used to coordinate federated learning among multiple edge nodes to optimize the overall communication, aggregation strategy, and scheduling of the communication network. Furthermore, it can monitor the network status of the aforementioned edge nodes and dynamically adjust the target mapping strategy configured for those edge nodes accordingly. It can be understood that the optimization feedback results output by this optimization feedback layer can be transmitted to the aforementioned service identification layer for dynamic tuning of service identification, decision-making, and policy execution processes.
[0024] Please see Figure 2 , Figure 2 This is a flowchart illustrating a network traffic identification method disclosed in an embodiment of this application. Figure 2 As shown, the method may include the following steps: S202, Capture target traffic data passing through edge nodes of the communication network.
[0025] In this embodiment of the application, the edge node of the communication network can capture all network traffic data passing through the edge node and filter out suspicious QUIC flows as target traffic data for subsequent identification and decision-making based on the target traffic data.
[0026] For example, the aforementioned edge nodes may include UPF (e.g., 5G UPF) edge nodes or MEC edge nodes, thereby enabling traffic capture operations on the edge node to be performed through a traffic capture module deployed on the UPF or MEC edge node. Specifically, network traffic data passing through the edge node can be captured in a zero-copy manner based on the DPDK high-speed packet processing framework.
[0027] In some embodiments, the traffic capture module can also be set to a certain dynamic sampling rate. This allows it to capture network traffic data at different priorities when the system load exceeds a certain threshold (e.g., 70%, 80%), thereby reducing the system load pressure on edge nodes. For example, for low-priority network traffic (e.g., large file downloads), a lower dynamic sampling rate of 1:10 can be used to selectively capture the corresponding network traffic data; for high-priority network traffic (e.g., video conferencing), a higher dynamic sampling rate of 1:1 full sampling can be used to capture as much of the corresponding network traffic data as possible.
[0028] Furthermore, edge nodes can also preset a certain set of rules in the traffic capture module, and pre-filter the network traffic data according to the set of rules to identify suspicious QUIC flows that are abnormal.
[0029] Furthermore, for the initially screened suspicious QUIC flows, the traffic capture module can create a corresponding session tracking table, using a 5-tuple (source IP address, source port, destination IP address, destination port, and specified protocol) as the primary key to record the connection identity information unique to QUIC packets (which can be denoted as CONN_ID). For example, the session tracking table can be implemented using a hash table, where the 5-tuple and CONN_ID are used as keys, and the session state is recorded as the corresponding value.
[0030] Based on this, when a QUIC connection migration is detected in the network traffic data (at which point the source IP address changes while the CONN_ID remains unchanged), the session records before and after the migration can be automatically merged. This allows for the tracking of encrypted network traffic data originating from the same source IP address, reducing its encryption interference and improving the reliability of subsequent network traffic identification.
[0031] S204. Based on the target traffic data mentioned above, extract the QUIC handshake connection features and application interaction behavior features based on the QUIC protocol.
[0032] In this embodiment, edge nodes can extract QUIC-related features from the target traffic data using their deployed feature extraction layer (or feature extraction module). Specifically, for QUIC handshake connection features representing protocol-level characteristics, the feature extraction layer can use a QUIC feature extraction engine to parse and extract QUIC data packets from the target traffic data; for application interaction behavior features representing business-level characteristics, the feature extraction layer can use a behavior analysis engine to analyze and extract application interaction behavior patterns from the target traffic data.
[0033] For example, the aforementioned QUIC handshake connection features may include version negotiation features, connection identity (which may be denoted as connection ID or CONN_ID) features, password parameter features, packet size pattern, time interval features, etc. In some embodiments, the aforementioned password parameter features, packet size pattern, and other features directly related to the initial Initial packet in the QUIC packet can be classified as Initial packet features. Further, the aforementioned version negotiation features, connection identity features, and Initial packet features can collectively serve as header metadata features corresponding to the target traffic data. These header metadata features can be obtained by parsing the header metadata fields of the QUIC packet in the target traffic data. The aforementioned time interval features, etc., can serve as handshake timing features corresponding to the target traffic data. These handshake timing features can be obtained by recording and further determining the key handshake timing points corresponding to the aforementioned QUIC packet.
[0034] The aforementioned version negotiation features may include the QUIC version supported by the client connected to the edge node through the aforementioned Initial data packet, or the QUIC version that the central server can accept or recommend as an alternative.
[0035] The aforementioned connection identity features (i.e. connection ID features) may include the source connection identity (source connection ID, SCID) and the destination connection identity (destination connection ID, DCID) used during the QUIC connection migration process. The source connection ID and destination connection ID may have specific lengths (e.g., 8-20 bytes) and entropy distributions.
[0036] The aforementioned cryptographic parameter characteristics may include an encrypted version of the TLS (Transport Layer Security) handshake parameters contained in the Initial data packet, the length, order, and distribution pattern of which are application-specific.
[0037] The aforementioned packet size pattern can refer to the characteristic size pattern formed by the sequence of packet sizes during the QUIC handshake process (e.g., the sequence of ClientInitial packet - Server Stateless Retry packet - Client Initial packet - ServerInitial packet).
[0038] The aforementioned time interval characteristics refer to the distribution of time intervals between data packets during the QUIC handshake process, which can reflect the implementation details of the client, edge nodes, and central server.
[0039] For example, the aforementioned application interaction behavior characteristics may include packet interval timing characteristics, burst traffic patterns, traffic directionality, stream duration, data transmission rate, etc. In some embodiments, the aforementioned burst traffic patterns (which may be referred to as burst traffic characteristics) and traffic directionality (which may be referred to as traffic directionality characteristics) can be jointly used as traffic pattern characteristics corresponding to the target traffic data; the aforementioned packet interval timing characteristics, stream duration, data transmission rate, etc. can be jointly used as traffic timing characteristics corresponding to the target traffic data.
[0040] Among them, the above packet interval timing characteristics can represent the distribution of data packet arrival time intervals formed due to application layer interactions.
[0041] The above-mentioned burst traffic patterns can reflect the different burst traffic characteristics of different services such as streaming media and file downloads.
[0042] The aforementioned traffic directionality can represent the specificity of the interaction patterns between the client and edge nodes, and even the central server, in different business types.
[0043] The above-mentioned stream duration can reflect the distribution characteristics of session duration for different service types.
[0044] The aforementioned data transmission rate can reflect the pattern of change in the amount of data transmitted per unit time.
[0045] S206. The QUIC handshake connection features and application interaction behavior features are fused to obtain the target fused features.
[0046] In this embodiment of the application, in order to improve the accuracy of subsequent network traffic identification, an identification framework for business scenario types can be constructed by combining the QUIC handshake connection characteristics at the protocol level and the application interaction behavior characteristics at the business level. In particular, it can include an identification framework for fine-grained network traffic scenario types.
[0047] In some embodiments, to implement the above-described recognition framework, it is necessary to first fuse the QUIC handshake connection features and application interaction behavior features to obtain the corresponding target fused features. For example, edge nodes can obtain the corresponding initial fused features by dimensionally aligning and concatenating the QUIC handshake connection features and application interaction behavior features; then, adaptive feature weight adjustment can be applied to the initial fused features, for example, by using an adaptive weight adjustment mechanism based on stream duration, to improve recognition accuracy and robustness (stability), reduce the variance of recognition accuracy variation and resource overhead, and obtain the desired target fused features.
[0048] Based on this, the edge node or the control plane node corresponding to the edge node can perform business scenario type identification based on the target fusion features in subsequent steps, including coarse-grained business type identification and fine-grained scenario classification, thereby realizing the pipeline construction of the above identification framework.
[0049] S208. Based on the target fusion characteristics, identify the business scenario type corresponding to the above target traffic data.
[0050] In this embodiment of the application, the business scenario type identification performed on the target fusion features can include coarse-grained business type identification and fine-grained scenario classification. Among them, the coarse-grained business type can include business categories such as data traffic services, voice call services, and video call services, or it can include specified application categories (such as application categories such as instant messaging applications, music playback applications, video playback applications, and conferencing applications running on the client).
[0051] Fine-grained scenario types can include scenario classifications involving specific application interaction behaviors. For example, consider a client-side video conferencing scenario, which is characterized by bidirectional communication, low latency, and small packet bursts, with the standard deviation of the time interval between data packets typically less than 50ms and the packet size distribution entropy greater than 0.85. Alternatively, consider a client-side video-on-demand scenario, which is characterized by unidirectional communication, high throughput, and large packet continuation, with the standard deviation of the time interval between data packets typically greater than 200ms and the packet size distribution entropy less than 0.65. It can be understood that these differences in application interaction behaviors can provide key feature dimensions for fine-grained scenario classification.
[0052] Based on this, and taking into account the differences in the target fusion features, the business scenario type corresponding to the target traffic data can be effectively identified. For example, an edge node or the control plane node corresponding to the edge node can first perform coarse-grained business type identification based on the target fusion features, and then perform fine-grained scenario classification based on the identified network traffic business types to obtain the network traffic scenario type corresponding to the target fusion features.
[0053] As can be seen, the network traffic identification method described in the above embodiments can effectively extract and identify QUIC-related features from encrypted network traffic data based on the QUIC protocol by parsing the QUIC handshake connection features that characterize its protocol-level characteristics and the application interaction behavior features that characterize its service-level characteristics, and then fusing the two to bypass the header protection mechanism. This organically combines the multi-dimensional features of the protocol layer and the service layer, effectively improving the success rate and accuracy of QUIC-related feature extraction. It can enhance the communication network's ability to identify network traffic service scenarios without infringing on data privacy, thereby strengthening the security control of network traffic at the communication network level, ensuring the QoS of the communication network, and minimizing the impact on communication network performance.
[0054] Please see Figure 3 , Figure 3 This is a flowchart illustrating another network traffic identification method disclosed in an embodiment of this application. Figure 3 As shown, the method may include the following steps: S302. By using a traffic capture module deployed at the edge node of the communication network, capture all network traffic data passing through the edge node of the communication network.
[0055] Step S302 is similar to some implementations of step S202 described above, and will not be repeated here.
[0056] S304. Based on preset inspection rules, the above network traffic data is pre-filtered to obtain pre-filtered network traffic data.
[0057] In this embodiment, the traffic capture module of the edge node can implement a pre-filtering mechanism based on a certain rule set to filter out suspicious QUIC flows as target traffic data from the network traffic data it captures.
[0058] For example, the traffic capture module can build a fast filter based on L2-L4 layer (i.e., the data link layer to the transport layer of the Open Systems Interconnection (OSI) model) metadata. First, it filters out non-UDP network traffic from the aforementioned network traffic data, and then analyzes the remaining UDP network traffic. For instance, by checking whether the destination port corresponding to the network traffic data is a commonly used QUIC port (e.g., 80 / 443), whether the UDP payload length exceeds a certain threshold (e.g., the Initial packet is typically larger than 1200 bytes), and the QUIC version identifier contained in the Initial packet, QUIC packets in the network traffic data can be identified.
[0059] Based on this, filters such as BPF are used to achieve kernel-level filtering of network traffic data, which can further filter out suspicious QUIC flows as target traffic data. Then, in subsequent steps, pre-processing such as session tracking and merging can be performed on the target traffic data, so that the QUIC feature extraction engine and behavior analysis engine can continue to perform subsequent feature extraction and recognition steps.
[0060] S306. Perform session tracking and merging on the pre-filtered network traffic data to determine the target traffic data that has passed through the aforementioned communication network edge nodes.
[0061] Step S306 is similar to some implementations of step S202 described above, and will not be repeated here.
[0062] S3081. The target traffic data is parsed using the QUIC feature extraction engine to extract the QUIC handshake connection features.
[0063] In this embodiment of the application, the edge node can identify the target QUIC data packet to be parsed from the target traffic data by deploying a QUIC feature extraction engine. The target QUIC data packet is the data transmitted by the client based on the QUIC protocol after the QUIC handshake during the duration of the session.
[0064] In some embodiments, the QUIC feature extraction engine can parse the header metadata fields of the target QUIC data packet to obtain the header metadata features corresponding to those fields. For example, the QUIC feature extraction engine can extract the version field information, connection identity information, and length sequence information (corresponding to different header metadata) from the Initial packet in the target QUIC data packet, thereby determining the version negotiation feature corresponding to the version field information, the connection identity feature corresponding to the connection identity information, and the Initial packet feature corresponding to the length sequence information.
[0065] The version field information mentioned above may include the 4-byte QUIC version field value from the Initial data packet. Optionally, when a Retry data packet corresponding to the Initial data packet exists, the corresponding version negotiation sequence (e.g., the sequence of original version - suggested version - final version) can be recorded.
[0066] Based on this, version entropy can be calculated using the following formula 1 to calculate the corresponding Shannon entropy for a list of versions supported by the client (e.g., supported information specified via the Initial data packet). Obtain the required version negotiation features.
[0067] Formula 1:
[0068] in, For version Frequency of occurrence in all target QUIC packets, i.e., the entire QUIC stream.
[0069] The aforementioned connection identity information may include the source connection ID and target connection ID used during the QUIC connection migration process. By extracting the source connection ID and target connection ID from the Initial data packet, the corresponding connection ID entropy value can be further calculated. The statistical distribution of each byte of the source connection ID and target connection ID can be calculated to obtain the corresponding entropy feature vector as the required connection identity feature.
[0070] Optionally, by using a predefined pattern library, connection ID pattern recognition can also be performed on the source connection ID and target connection ID to achieve specific differentiation.
[0071] The aforementioned length sequence information can be obtained by extracting the packet length sequence for the Initial packet (e.g., the sequence of ClientInitial packet - Server Stateless Retry packet - Client Initial packet - ServerInitial packet) and calculating the corresponding packet length distribution statistics (e.g., mean, variance, kurtosis, skewness, etc.) as the required Initial packet features.
[0072] Optionally, when a Retry data packet corresponding to the Initial data packet exists, the Token field in the Retry data packet can be extracted to calculate its length and hash value for further accurate identification.
[0073] Based on this, the aforementioned version negotiation features, connection identity features, and Initial packet features can be used together as header metadata features corresponding to the header metadata fields of the aforementioned Initial data packet.
[0074] In other embodiments, the QUIC feature extraction engine can also record key handshake timing points corresponding to the target QUIC data packets, such as the first packet arrival time t0, the response time t1 of the edge node or central server, and the handshake completion time t2. Furthermore, corresponding handshake timing features can be determined based on these key handshake timing points, and the header metadata features and the handshake timing features can be used together as the QUIC handshake connection features corresponding to the target traffic data.
[0075] The handshake timing features mentioned above may include RTT estimation (Round-Trip Time Estimation, used to estimate the round-trip time of data packets between the sender and receiver) t1-t0, or handshake delay t2-t0, etc., which are not specifically limited in this application embodiment.
[0076] S3082. The application interaction behavior pattern of the target traffic data is analyzed by the behavior analysis engine to extract the application interaction behavior features.
[0077] In this embodiment, edge nodes can deploy a behavior analysis engine to analyze application interaction behavior patterns reflected in target traffic data. This analysis of application interaction behavior patterns can include at least time-series feature analysis and traffic pattern recognition.
[0078] In some embodiments, the behavior analysis engine can obtain corresponding traffic time-series characteristics by performing time-series feature analysis on target traffic data. These traffic time-series characteristics may include at least key time-frequency features and data transmission features.
[0079] For example, the aforementioned key time-frequency characteristics may include at least the proportion of primary frequency energy, the proportion of high-frequency energy, and / or energy entropy. The behavior analysis engine can extract the aforementioned key time-frequency characteristics corresponding to the target traffic data by performing packet interval time-frequency characteristic analysis on the target traffic data.
[0080] Specifically, the behavior analysis engine can record the arrival timestamp of each QUIC packet in the QUIC stream to the edge node, and calculate the corresponding consecutive packet interval time (which can be denoted as...). Based on this, wavelet transform is used to analyze the packet interval time-frequency characteristics of the above continuous packet interval time series, and the key time-frequency features corresponding to the target flow data can be extracted.
[0081] For example, the behavior analysis engine can also obtain a transmission rate time series based on the target traffic data, and obtain the aforementioned data transmission characteristics based on the transmission rate time series. For instance, the behavior analysis engine can form a corresponding transmission rate time series by calculating the amount of data transmitted per unit time (e.g., 1 second, 0.5 seconds, etc.).
[0082] Based on this, the above transmission rate time series can be fitted by a target fitting model (such as the ARIMA model, i.e., the autoregressive integral moving average model, etc.). The parameters of the fitted target fitting model can be extracted and the obtained model parameters can be used as the data transmission characteristics corresponding to the target traffic data.
[0083] Optionally, by calculating the transmission rate variation coefficient (e.g., standard deviation, mean, etc.) corresponding to the above transmission rate time series, the traffic stability of the QUIC stream can be further reflected.
[0084] In other embodiments, the behavior analysis engine can also obtain corresponding traffic pattern features by performing traffic pattern recognition on the target traffic data. These traffic pattern features may include at least burst traffic features, traffic directionality features, and state transition features.
[0085] For example, the aforementioned burst traffic characteristics can be obtained by identifying burst traffic in the target traffic data to construct a corresponding burst pattern vector. That is, the constructed burst pattern vector can be used as the burst traffic characteristics corresponding to the target traffic data.
[0086] For example, a behavior analysis engine can define a specific time window (e.g., 50ms, 100ms, etc.), count the number of packets and total bytes in the QUIC stream within that time window, and then use a sliding window algorithm (with a sliding step size of 10ms, 20ms, etc.) to calculate the instantaneous transmission rate at different times (or different time windows). This instantaneous transmission rate can be used to identify burst traffic characteristics in the target traffic data, such as burst duration, burst interval, and the ratio of peak burst rate to average rate.
[0087] Based on this, a burst pattern vector can be constructed using the aforementioned burst traffic characteristics to specifically represent the burst traffic characteristics in vector form. For example, the burst pattern vector can be represented as:
[0088] in, Indicates the average duration of an outbreak. Indicates the average burst interval. This represents the variance of the ratio of the peak burst rate to the average burst rate. It should be noted that the above burst pattern vector only shows a partial form of some burst flow characteristics. Furthermore, other indicators or parameters can be used to construct corresponding burst flow characteristics, and this application does not impose specific limitations on these methods.
[0089] For example, based on the aforementioned traffic directionality characteristics, interaction behavior or interaction pattern analysis can be performed on the traffic directionality corresponding to the target traffic data, thereby extracting the traffic directionality characteristics corresponding to the target traffic data. For instance, by calculating the ratio of uplink (i.e., traffic from the client to edge nodes, central servers, etc.) to downlink (i.e., traffic from edge nodes, central servers, etc. to the client) network traffic, a cross-correlation function can be used to describe the correlation between uplink and downlink network traffic, identifying the interaction-intensive applications running on the client. In this process, by calculating the average latency of request-response pairs, analysis of application interaction patterns can be achieved.
[0090] For example, regarding the aforementioned state transition characteristics, traffic pattern alternation records can be determined first based on the target traffic data. Then, based on the Hidden Markov Model (HMM), the traffic state transition probability can be identified for the aforementioned traffic pattern alternation records, and the state transition characteristics corresponding to the target traffic data can be determined based on the traffic state transition probability.
[0091] Specifically, the behavior analysis engine can record the alternation pattern of active and silent periods of QUIC flow, and use HMM to identify the probability of flow state transitions in order to extract state transition features such as the average duration of active periods, the average duration of silent periods, and the frequency of state transitions.
[0092] Based on this, the aforementioned traffic time-series characteristics (including key time-frequency characteristics and data transmission characteristics) and traffic pattern characteristics (including burst traffic characteristics, traffic directionality characteristics, and state transition characteristics) can be used together as the application interaction behavior characteristics corresponding to the target traffic data.
[0093] S310. Align the dimensions of the above-mentioned QUIC handshake connection features and application interaction behavior features, and then stitch them together to obtain the initial fusion features.
[0094] In some embodiments, the above-mentioned dimension alignment and feature splicing processes can be performed simultaneously, that is, during the alignment of QUIC handshake connection features and application interaction behavior features, the two are spliced together to obtain the initial fused features.
[0095] In other embodiments, the alignment of QUIC handshake connection features and application interaction behavior features can also be performed after the concatenation is complete. For example, edge nodes or central servers can deploy a feature fusion engine to concatenate A-dimensional (e.g., A=32) QUIC handshake connection features with B-dimensional (e.g., B=48) application interaction behavior features to obtain an initial fused feature of A+B dimensions (e.g., 80 dimensions).
[0096] Based on this, by handling missing values in the above initial fusion features, for example, for QUIC streams that have not completed a full handshake, the average handshake feature is calculated and used to fill in the missing values, which can obtain more standardized and neat initial fusion features, so as to ensure the stability and reliability of subsequent calculations.
[0097] S312. Calculate the feature importance weights corresponding to the initial fusion features.
[0098] S314. Adaptively adjust the initial fused features according to the feature importance weights to obtain the target fused features.
[0099] In this embodiment, on the one hand, based on the session history data obtained by integrating target traffic data within a certain period, the mutual information between the above-mentioned QUIC handshake connection features and application interaction behavior features and the specified target business scenario type (including coarse-grained network traffic service type and fine-grained network traffic scenario type) can be calculated; on the other hand, by applying the PCA (Principal Components Analysis) method to reduce the dimensionality of the above-mentioned initial fusion features, a certain proportion (e.g., 90%, 95%, etc.) of the principal components with the cumulative variance contribution rate can be retained.
[0100] Based on this, the feature importance weight corresponding to each feature dimension can be calculated using the following formula 2. .
[0101] Formula 2:
[0102] in, The importance weight of the i-th dimension feature Corresponding mutual information, Then it is The corresponding cumulative variance contribution rate of the principal component. and To optimize the parameters, in some embodiments, the values can be 0.6 and 0.4, respectively.
[0103] In some embodiments, the initial fusion feature of each dimension can be adaptively adjusted according to the aforementioned feature importance weights to obtain the target fusion feature. In other embodiments, the handshake feature weights corresponding to each initial fusion feature can be further set. W_handshake and behavioral feature weights W_behavior This allows for adaptive weighted fusion of the two to obtain the desired target fusion features.
[0104] S316. Based on the target fusion characteristics, perform coarse-grained service type identification to obtain the network traffic service type corresponding to the target fusion characteristics.
[0105] S318. Based on the above network traffic service types, perform fine-grained scenario classification according to the target fusion characteristics to obtain the network traffic scenario type corresponding to the target fusion characteristics.
[0106] Steps S316 and S318 are similar in some implementations to step S208 described above. It should be noted that a two-level classification architecture can be used for identifying the business scenario type of the target fusion features. For example, the first level of application category identification (e.g., 20 categories), i.e., coarse-grained network traffic service type identification, can use a lightweight random forest model (which can be configured with 50 trees corresponding to the aforementioned application categories); the second level of business scenario identification (e.g., more than 2000 categories), i.e., fine-grained network traffic scenario type identification, can use an XGBoost classifier.
[0107] In some embodiments, the above classification architecture can realize edge-cloud collaborative reasoning, that is, deploy a first-level classifier at the edge node to achieve fast coarse-grained recognition; for critical business (such as video conferencing, cloud gaming, etc.) or network traffic with high uncertainty, its feature summary can be extracted and uploaded to the central server, the central server performs second-level fine-grained recognition, and then the results are returned to the edge node.
[0108] Optionally, by maintaining a preset confidence threshold (e.g., 0.85) through the classifier, samples with confidence levels below this threshold can be labeled as "uncertain," and the features of these "uncertain" samples and the manually labeled results can be collected for incremental training. Furthermore, by employing knowledge distillation techniques, the knowledge of the large model on the central server can be transferred to the small models on the edge nodes to achieve an online learning and update mechanism.
[0109] Based on this, edge nodes can also be used to output the final recognition results, for example, in the following output format:
[0110] in, This indicates a coarse-grained network traffic service type. This indicates a fine-grained type of network traffic scenario. This represents the confidence score for the classification. This indicates the corresponding QoS requirements of the communication network. In some embodiments, one or more alternative identification results (which should be higher than a certain confidence threshold, such as 0.7) can also be output simultaneously to implement fault tolerance processing.
[0111] As can be seen, the network traffic identification method described in the above embodiments can effectively extract and identify QUIC-related features of encrypted network traffic data based on the QUIC protocol by parsing the QUIC handshake connection features that characterize its protocol-level characteristics and the application interaction behavior features that characterize its service-level characteristics, and then fusing the two to bypass the header protection mechanism. This organically combines the multi-dimensional features of the protocol layer and the service layer, effectively improving the success rate and accuracy of QUIC-related feature extraction. It can enhance the communication network's ability to identify network traffic service scenarios without infringing on data privacy, thereby strengthening the security control of network traffic at the communication network level, ensuring the QoS of the communication network, and minimizing the impact on the performance of the communication network. In addition, by designing a hierarchical identification and classification architecture to address the resource-constrained characteristics of the 5G edge computing environment, computationally intensive tasks can be offloaded to the cloud, while only lightweight processing capabilities are retained at the edge nodes. This helps to ensure extremely low end-to-end latency and meet the higher real-time requirements of 5G networks.
[0112] Please see Figure 4 , Figure 4 This is a flowchart illustrating another network traffic identification method disclosed in an embodiment of this application. Figure 4 As shown, the method may include the following steps: S402. By using a traffic capture module deployed at the edge node of the communication network, capture all network traffic data passing through the edge node of the communication network.
[0113] S404. Based on preset inspection rules, the above network traffic data is pre-filtered to obtain pre-filtered network traffic data.
[0114] S406. Perform session tracking and merging on the pre-filtered network traffic data to determine the target traffic data that has passed through the aforementioned communication network edge nodes.
[0115] Steps S402, S404, and S406 are similar to steps S302, S304, and S306 above, and will not be repeated here.
[0116] S408: Identify target QUIC data packets from target traffic data using the QUIC feature extraction engine.
[0117] S4101. Parse the header metadata fields of the target QUIC data packet to obtain the header metadata features corresponding to the header metadata fields.
[0118] S4102. Record the key handshake timing points corresponding to the target QUIC data packet, and determine the handshake timing characteristics based on these key handshake timing points.
[0119] Steps S408, S4101, and S4102 are partially similar to steps S3081 described above. It should be noted that the header metadata features and handshake timing features described above can be used together as the QUIC handshake connection features corresponding to the target traffic data.
[0120] S412. Standardize the above header metadata features and handshake timing features respectively, and use the obtained standardized features as the QUIC handshake connection features corresponding to the target traffic data.
[0121] In this embodiment of the application, the original header metadata features and handshake timing features (which can be denoted as...) are considered. The Z-score standardization process, as shown in Formula 3 below, can be used to obtain the corresponding standardized features. This refers to the QUIC handshake connection characteristics corresponding to the target traffic data.
[0122] Formula 3:
[0123] in, and represents the mean and standard deviation of the corresponding feature in the training set.
[0124] S4141. Using the behavior analysis engine, perform time-series feature analysis on the target traffic data to obtain traffic time-series features.
[0125] S4142. Through the behavior analysis engine, traffic pattern recognition is performed on the target traffic data to obtain traffic pattern features.
[0126] Steps S4141 and S4142 are partially similar to steps S3082 described above. It should be noted that the aforementioned traffic timing characteristics and traffic pattern characteristics can be used together as application interaction behavior characteristics corresponding to the target traffic data.
[0127] S416. Align the dimensions of the above-mentioned QUIC handshake connection features and application interaction behavior features, and then stitch them together to obtain the initial fusion features.
[0128] S418. Calculate the feature importance weights corresponding to the initial fusion features.
[0129] Steps S416 and S418 are similar to steps S310 and S312 above, and will not be described again here.
[0130] S420. Based on the adaptive fusion mechanism, determine the handshake feature weight and behavior feature weight corresponding to each initial fusion feature according to the feature importance weight.
[0131] S422. Based on the handshake feature weights and behavior feature weights corresponding to each initial fusion feature, perform weighted fusion processing on each initial fusion feature to obtain the target fusion feature.
[0132] In this embodiment, the weight ratio of the QUIC handshake connection features and application interaction behavior features can be adaptively adjusted according to the duration of the QUIC stream, and then a weighted fusion process is performed to obtain the desired target fused features. For example, the handshake feature weights corresponding to each initial fused feature are... W_handshake and behavioral feature weights W_ behavior The target fusion feature can be calculated by weighting and fusing the initial fusion features using the feature fusion formula shown in Formula 4 below. .
[0133] Formula 4:
[0134] in, This is a QUIC handshake connection feature. To define the characteristics of application interaction behavior.
[0135] For specific examples, if the QUIC stream is a short stream (e.g., duration less than 2 seconds), the handshake feature weight can be set to 0.8 and the behavior feature weight to 0.2; if the QUIC stream is a medium stream (e.g., duration 2-10 seconds), the handshake feature weight can be set to 0.5 and the behavior feature weight to 0.5; if the QUIC stream is a long stream (e.g., duration greater than 10 seconds), the handshake feature weight can be set to 0.3 and the behavior feature weight to 0.7.
[0136] S424. Perform dimensionality reduction on the target fusion features to obtain low-dimensional fusion features.
[0137] S426. Standardize the low-dimensional fusion features to obtain the corresponding recognition input vector, which is used to identify the business scenario type corresponding to the above target traffic data.
[0138] In this embodiment of the application, by performing dimensionality reduction optimization (including dimensionality reduction processing and standardization processing) on the above-mentioned target fusion features, a recognition input vector for subsequent business scenario type identification can be obtained.
[0139] For example, by applying the T-SNE (T-Distributed Stochastic Neighbor Embedding) dimensionality reduction method, the 80-dimensional target fusion feature can be reduced to a lower dimension, such as 12 dimensions; furthermore, by applying the Min-Max normalization method, the feature values of the dimensionality-reduced low-dimensional fusion feature can be scaled to... The standardized 12-dimensional fusion feature vector obtained from the interval can be used as the recognition input vector and input into the above two-level classifier for business scenario type recognition.
[0140] S428. Based on the target fusion characteristics, perform coarse-grained service type identification to obtain the network traffic service type corresponding to the target fusion characteristics.
[0141] S430. Based on the above network traffic service types, perform fine-grained scenario classification according to the target fusion characteristics to obtain the network traffic scenario type corresponding to the target fusion characteristics.
[0142] Steps S428 and S430 are similar to steps S316 and S318 above, and will not be described again here.
[0143] S432. Based on the above network traffic scenario types, determine the target mapping strategy from the policy mapping table. This target mapping strategy is applicable to the control plane corresponding to the edge node of the communication network.
[0144] S434. By monitoring the network status corresponding to the edge nodes of the communication network, the target mapping strategy is dynamically adjusted according to the network status.
[0145] In this embodiment, edge nodes or central servers can maintain a preset service-policy mapping table (hereinafter referred to as the "policy mapping table") by deploying a policy decision engine. This policy mapping table can configure appropriate QoS policies for each service scenario type, particularly for specific network traffic scenario types, such as specified GBR, MBR, priority, packet loss rate, latency requirements, and other indicators. It can also configure security policies matching the network traffic scenario type, such as specified deep inspection levels, session timeout thresholds, abnormal behavior thresholds, and other indicators. Based on this, the aforementioned policy execution layer can be used to execute the target mapping policy determined from the policy mapping table.
[0146] Furthermore, by monitoring the network status (e.g., CPU utilization, memory usage, queue depth, packet loss rate, etc.) of the edge nodes of the communication network, the target mapping strategy can be dynamically adjusted based on this network status. For example, this dynamic adjustment can be implemented using a Q-Learning-based reinforcement learning network (i.e., Deep Q-Network) to dynamically adjust the policy parameters in the target mapping strategy.
[0147] In some embodiments, federated learning optimization can be used for multiple edge nodes connected to the central server. Based on the local recognition accuracy, resource overhead and other indicators collected by each edge node, gradient masking technology is applied to upload parameter updates of important gradients (e.g., whose absolute value is greater than 0.01). The central server can then perform aggregate updates accordingly. The update formula can be shown in Formula 5 below.
[0148] Formula 5:
[0149] in, The node weights for each edge node can be determined based on the amount and quality of data at the corresponding edge node. This represents the local update data for the i-th edge node, such as specific model parameters. This corresponds to the global update data. Optionally, the central server can also perform selective model distribution, that is, only distribute the updated model parameters to the edge nodes that need to be updated.
[0150] Based on this, the effectiveness of the above target mapping strategy can be verified by monitoring its execution effect (e.g., through QoS compliance rate, QoE user satisfaction, etc.) and using A / B testing methods, so as to continuously optimize the above feature extraction and classification algorithms and form a closed-loop feedback.
[0151] Please refer to further information. Figure 5 , Figure 5 This is a schematic diagram illustrating the parsing process of the network traffic identification method disclosed in an embodiment of this application. For example... Figure 5 As shown, the network traffic identification method disclosed in this application may include steps such as traffic capture, QUIC handshake connection feature extraction, application interaction behavior feature extraction, multi-dimensional feature fusion, coarse-grained service type identification, fine-grained scenario classification, and strategy decision-making and optimization. Each of these steps may be implemented solely on edge nodes, or partially on edge nodes and partially on a central server.
[0152] As can be seen, the network traffic identification method described in the above embodiments can effectively extract and identify QUIC-related features of encrypted network traffic data based on the QUIC protocol by parsing the QUIC handshake connection features that characterize its protocol-level characteristics and the application interaction behavior features that characterize its service-level characteristics, and then fusing the two to bypass the header protection mechanism. This organically combines the multi-dimensional features of the protocol layer and the service layer, effectively improving the success rate and accuracy of QUIC-related feature extraction. It can enhance the communication network's ability to identify network traffic service scenarios without infringing on data privacy, thereby strengthening the security control of network traffic at the communication network level, ensuring the QoS of the communication network, and minimizing the impact on the performance of the communication network. In addition, by designing a layered identification architecture to address the resource-constrained characteristics of the 5G edge computing environment, computationally intensive tasks can be offloaded to the cloud, retaining only lightweight processing capabilities at the edge nodes. This helps to ensure extremely low end-to-end latency and meet the higher real-time requirements of 5G networks. Furthermore, by optimizing federated learning among multiple edge nodes, the convergence speed of federated learning can be improved, supporting the rapid iteration environment of the QUIC protocol. This is conducive to providing 5G networks with high-precision, low-latency, and fine-grained service awareness capabilities, and supporting the realization of key network functions such as network slicing and QoS assurance.
[0153] Please see Figure 6 , Figure 6 This is a modular schematic diagram of a network traffic identification device disclosed in an embodiment of this application. Figure 6 As shown, the network traffic identification device may include a traffic capture unit 601, a feature extraction unit 602, a feature fusion unit 603, and an identification unit 604, wherein: Traffic capture unit 601 is used to capture target traffic data passing through edge nodes of a communication network; The feature extraction unit 602 is used to extract QUIC handshake connection features and application interaction behavior features based on the above target traffic data, respectively. The feature fusion unit 603 is used to fuse QUIC handshake connection features and application interaction behavior features to obtain target fused features; The identification unit 604 is used to identify the business scenario type corresponding to the target traffic data based on the target fusion features.
[0154] As can be seen, the network traffic identification device described in the above embodiments can effectively extract and identify QUIC-related features of encrypted network traffic data based on the QUIC protocol by parsing the QUIC handshake connection features that characterize its protocol-level characteristics and the application interaction behavior features that characterize its service-level characteristics, and then fusing the two to bypass the header protection mechanism. This organically combines the multi-dimensional features of the protocol layer and the service layer, effectively improving the success rate and accuracy of QUIC-related feature extraction. It can enhance the communication network's ability to identify network traffic service scenarios without infringing on data privacy, thereby strengthening the security control of network traffic at the communication network level, ensuring the QoS of the communication network, and minimizing the impact on communication network performance.
[0155] In some embodiments, the feature extraction unit 602 described above can be specifically used for: The target traffic data is parsed using a QUIC feature extraction engine to extract QUIC handshake connection features; and... By using a behavior analysis engine to analyze the application interaction behavior patterns of target traffic data, application interaction behavior features are extracted.
[0156] In some embodiments, when the feature extraction unit 602 performs QUIC packet parsing on the target traffic data using the QUIC feature extraction engine to extract QUIC handshake connection features, it may specifically include: The target QUIC data packets are identified from the target traffic data using the QUIC feature extraction engine. The header metadata fields of the target QUIC data packet are parsed to obtain the header metadata features corresponding to the header metadata fields; and, Record the key handshake timing points corresponding to the target QUIC data packets, determine the handshake timing characteristics based on these key handshake timing points, and use the above header metadata characteristics and handshake timing characteristics together as the QUIC handshake connection characteristics corresponding to the target traffic data.
[0157] For example, the target QUIC data packet may at least include an initial data packet. Therefore, when the feature extraction unit 602 parses the header metadata fields of the target QUIC data packet to obtain the header metadata features corresponding to the header metadata fields, it may specifically include: Extract version field information, connection identity information, and length sequence information from the Initial data packet; The version negotiation feature corresponding to the version field information, the connection identity feature corresponding to the connection identity information, and the Initial packet feature corresponding to the length sequence information are determined respectively, and together they serve as the header metadata feature corresponding to the header metadata field of the Initial data packet.
[0158] Based on this, the feature extraction unit 602 described above can also be used for: The header metadata features and handshake timing features mentioned above are standardized, and the standardized features are used as the QUIC handshake connection features corresponding to the target traffic data.
[0159] In some embodiments, when the feature extraction unit 602 is used to perform application interaction behavior pattern analysis on target traffic data through a behavior analysis engine and extract application interaction behavior features, it may specifically include: By using a behavioral analysis engine, time-series feature analysis is performed on the target traffic data to obtain the traffic time-series characteristics; and... Traffic pattern recognition is performed on the target traffic data to obtain traffic pattern features, and the above-mentioned traffic time series features and traffic pattern features are used together as the application interaction behavior features corresponding to the target traffic data.
[0160] In some embodiments, the aforementioned traffic time-series features may include at least key time-frequency features and data transmission features. Therefore, when the feature extraction unit 602 performs time-series feature analysis on the target traffic data to obtain the traffic time-series features, it may specifically include: By performing packet interval time-frequency characteristic analysis on the target traffic data, key time-frequency features corresponding to the target traffic data are extracted. These key time-frequency features may include at least the main frequency energy proportion, the high-frequency energy proportion, and / or energy entropy; and... Based on the target traffic data, obtain the transmission rate time series; The transmission rate time series is fitted by a target fitting model, and the parameters of the fitted target fitting model are extracted to obtain the data transmission characteristics corresponding to the target traffic data.
[0161] In some embodiments, the above-mentioned traffic pattern features may include at least burst traffic features, traffic directionality features, and state transition features. Therefore, when the feature extraction unit 602 performs traffic pattern recognition on the target traffic data to obtain traffic pattern features, it may specifically include: Based on the target traffic data, burst traffic is identified, and a burst pattern vector is constructed as the burst traffic feature corresponding to the target traffic data; and, Interactive behavior analysis is performed based on the traffic directionality corresponding to the target traffic data to extract the traffic directionality features corresponding to the target traffic data; and, The traffic pattern is determined and recorded alternately based on the target traffic data; Based on the Hidden Markov Model, the state transition probability of traffic is obtained by identifying alternating traffic patterns, and the state transition features corresponding to the target traffic data are determined based on the state transition probability.
[0162] In some embodiments, the traffic capture unit 601 described above can be specifically used for: By deploying traffic capture modules at the edge nodes of the communication network, all network traffic data passing through the edge nodes of the communication network is captured; The network traffic data is pre-filtered based on preset inspection rules to obtain pre-filtered network traffic data. Session tracking and merging are performed on the pre-filtered network traffic data to identify the target traffic data passing through the edge nodes of the communication network.
[0163] In some embodiments, the feature fusion unit 603 described above can be specifically used for: The QUIC handshake connection features and application interaction behavior features mentioned above are aligned in dimensions and then spliced together to obtain the initial fused features; Calculate the feature importance weights corresponding to the initial fused features; The initial fused features are adaptively adjusted based on the feature importance weights to obtain the target fused features.
[0164] For example, when the feature fusion unit 603 adaptively adjusts the initial fused features according to the feature importance weights to obtain the target fused features, it may specifically include: Based on the adaptive fusion mechanism, the handshake feature weight and behavior feature weight corresponding to each initial fusion feature are determined according to the above feature importance weights; Based on the handshake feature weights and behavior feature weights corresponding to each initial fusion feature, the initial fusion features are weighted and fused to obtain the target fusion features.
[0165] In some embodiments, the feature fusion unit 603 described above can also be used for: The target fusion features are reduced in dimensionality to obtain low-dimensional fusion features; The low-dimensional fusion features are standardized to obtain the corresponding recognition input vector, which is used to identify the business scenario type corresponding to the target traffic data.
[0166] In some embodiments, the identification unit 604 described above can be specifically used for: Based on the target fusion features, coarse-grained service type identification is performed to obtain the network traffic service type corresponding to the target fusion features; Based on network traffic service types, fine-grained scenario classification is performed according to target fusion characteristics to obtain the network traffic scenario types corresponding to the target fusion characteristics.
[0167] For example, when the identification unit 604 is used to perform fine-grained scenario classification based on the target fusion feature according to the network traffic service type, and to obtain the network traffic scenario type corresponding to the target fusion feature, it may specifically include: Collect contextual information corresponding to the target fusion features; Based on the network traffic service types, context information, and target fusion features mentioned above, the network traffic scenario types corresponding to the target fusion features are classified and determined using a pre-trained Conditional Random Field (CRF) model.
[0168] In some embodiments, the network traffic identification device may further include a policy mapping unit (not shown). After the identification unit 604 performs fine-grained scenario classification based on the network traffic service type and target fusion features to obtain the network traffic scenario type corresponding to the target fusion features, the policy mapping unit can be used for: Based on the network traffic scenario type, the target mapping strategy is determined from the strategy mapping table. This target mapping strategy is applicable to the control plane corresponding to the edge node of the communication network. By monitoring the network status of edge nodes in the communication network, the target mapping strategy is dynamically adjusted based on the network status.
[0169] As can be seen, the network traffic identification device described in the above embodiments can also design a hierarchical identification and classification architecture to address the resource-constrained characteristics of 5G edge computing environments. It can also offload computationally intensive tasks to the cloud, retaining only lightweight processing capabilities at the edge nodes, thereby ensuring extremely low end-to-end latency and meeting the higher real-time requirements of 5G networks. Furthermore, through federated learning optimization among multiple edge nodes, the convergence speed of federated learning can be improved, supporting a rapid iteration environment for the QUIC protocol. This further facilitates providing 5G networks with high-precision, low-latency, and fine-grained service awareness capabilities, supporting the implementation of key network functions such as network slicing and QoS assurance.
[0170] Please see Figure 7 , Figure 7 This is a modular schematic diagram of an electronic device disclosed in an embodiment of this application. For example... Figure 7 As shown, the electronic device may include: Memory 701 storing executable program code; Processor 702 coupled to memory 701; The processor 702 can call the executable program code stored in the memory 701 to execute all or part of the steps in any of the network traffic identification methods described in the above embodiments.
[0171] Furthermore, embodiments of this application disclose a computer-readable storage medium storing a computer program for electronic data interchange, wherein the computer program enables a computer to execute all or part of the steps in any of the network traffic identification methods described in the above embodiments.
[0172] Furthermore, this application further discloses a computer program product that, when run on a computer, enables the computer to execute all or part of the steps in any of the network traffic identification methods described in the above embodiments.
[0173] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compactdisc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.
[0174] The foregoing has provided a detailed description of a network traffic identification method, apparatus, and electronic device disclosed in the embodiments of this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for identifying network traffic, characterized in that, include: Capture target traffic data passing through edge nodes of the communication network; Based on the target traffic data, extract the QUIC handshake connection features and application interaction behavior features based on the QUIC protocol. The QUIC handshake connection features and the application interaction behavior features are fused to obtain the target fused features; Based on the target fusion features, identify the business scenario type corresponding to the target traffic data.
2. The method according to claim 1, characterized in that, The step of extracting QUIC handshake connection features and application interaction behavior features based on the target traffic data includes: The target traffic data is parsed using a QUIC feature extraction engine to extract QUIC handshake connection features; and... The target traffic data is analyzed using a behavior analysis engine to extract application interaction behavior features.
3. The method according to claim 2, characterized in that, The step of parsing the target traffic data using a QUIC feature extraction engine to extract QUIC handshake connection features includes: The target QUIC data packet is identified from the target traffic data using a QUIC feature extraction engine. The header metadata fields of the target QUIC data packet are parsed to obtain the header metadata features corresponding to the header metadata fields; and, Record the key handshake timing points corresponding to the target QUIC data packet, determine the handshake timing features based on the key handshake timing points, and use the header metadata features and the handshake timing features together as the QUIC handshake connection features corresponding to the target traffic data.
4. The method according to claim 3, characterized in that, The target QUIC data packet includes at least an initial data packet. Parsing the header metadata fields of the target QUIC data packet to obtain header metadata features corresponding to the header metadata fields includes: For the Initial data packet, extract the version field information, connection identity information, and length sequence information respectively; The version negotiation feature corresponding to the version field information, the connection identity feature corresponding to the connection identity information, and the Initial packet feature corresponding to the length sequence information are determined respectively, and together they are used as the header metadata feature corresponding to the header metadata field of the Initial data packet.
5. The method according to claim 3, characterized in that, The method further includes: The header metadata features and the handshake timing features are standardized respectively, and the resulting standardized features are used as the QUIC handshake connection features corresponding to the target traffic data.
6. The method according to claim 2, characterized in that, The step involves analyzing the target traffic data using a behavior analysis engine to extract application interaction behavior features, including: By using a behavior analysis engine, time-series feature analysis is performed on the target traffic data to obtain traffic time-series features; and, Traffic pattern recognition is performed on the target traffic data to obtain traffic pattern features, and the traffic time sequence features and the traffic pattern features are used together as the application interaction behavior features corresponding to the target traffic data.
7. The method according to claim 6, characterized in that, The traffic time-series characteristics include at least key time-frequency characteristics and data transmission characteristics. The step of performing time-series characteristic analysis on the target traffic data to obtain the traffic time-series characteristics includes: By performing packet interval time-frequency characteristic analysis on the target traffic data, key time-frequency features corresponding to the target traffic data are extracted. These key time-frequency features include at least the main frequency energy proportion, the high-frequency energy proportion, and / or energy entropy; and... Based on the target traffic data, obtain the transmission rate time series; The transmission rate time series is fitted by a target fitting model, and the parameters of the fitted target fitting model are extracted to obtain the data transmission characteristics corresponding to the target traffic data.
8. The method according to claim 6, characterized in that, The traffic pattern features include at least burst traffic features, traffic directionality features, and state transition features. The process of identifying traffic patterns in the target traffic data to obtain the traffic pattern features includes: Based on the target traffic data, burst traffic is identified, and a burst pattern vector is constructed as the burst traffic feature corresponding to the target traffic data; and, Interactive behavior analysis is performed based on the traffic directionality corresponding to the target traffic data to extract the traffic directionality features corresponding to the target traffic data; and... Based on the target traffic data, determine the alternating recording of traffic patterns; Based on the Hidden Markov Model, the traffic state transition probability is obtained by identifying the alternating records of the traffic pattern, and the state transition feature corresponding to the target traffic data is determined according to the traffic state transition probability.
9. The method according to any one of claims 1 to 8, characterized in that, The capture of target traffic data passing through the edge nodes of the communication network includes: By deploying traffic capture modules at the edge nodes of the communication network, all network traffic data passing through the edge nodes of the communication network is captured; The network traffic data is pre-filtered based on preset inspection rules to obtain pre-filtered network traffic data. Session tracking and merging are performed on the pre-filtered network traffic data to determine the target traffic data passing through the edge nodes of the communication network.
10. The method according to any one of claims 1 to 8, characterized in that, The process of fusing the QUIC handshake connection features and the application interaction behavior features to obtain the target fused features includes: The QUIC handshake connection features and the application interaction behavior features are dimensionally aligned and then concatenated to obtain the initial fused features; Calculate the feature importance weights corresponding to the initial fused features; The initial fusion features are adaptively adjusted according to the feature importance weights to obtain the target fusion features.
11. The method according to claim 10, characterized in that, The step of adaptively adjusting the initial fused features according to the feature importance weights to obtain the target fused features includes: Based on the adaptive fusion mechanism, the handshake feature weight and behavior feature weight corresponding to each of the initial fusion features are determined according to the feature importance weights; Based on the handshake feature weights and behavior feature weights corresponding to each of the initial fusion features, the initial fusion features are weighted and fused to obtain the target fusion features.
12. The method according to claim 10, characterized in that, After adaptively adjusting the initial fused features according to the feature importance weights to obtain the target fused features, the method further includes: The target fusion features are subjected to dimensionality reduction processing to obtain low-dimensional fusion features; The low-dimensional fusion features are standardized to obtain a corresponding recognition input vector, which is used to identify the business scenario type corresponding to the target traffic data.
13. The method according to any one of claims 1 to 8, characterized in that, The step of identifying the business scenario type corresponding to the target traffic data based on the target fusion features includes: Based on the target fusion features, coarse-grained service type identification is performed to obtain the network traffic service type corresponding to the target fusion features; Based on the network traffic service type, fine-grained scenario classification is performed according to the target fusion feature to obtain the network traffic scenario type corresponding to the target fusion feature.
14. The method according to claim 13, characterized in that, The step of performing fine-grained scenario classification based on the network traffic service type and the target fusion feature to obtain the network traffic scenario type corresponding to the target fusion feature includes: Collect the context information corresponding to the target fusion features; Based on the network traffic service type, the context information, and the target fusion feature, the network traffic scenario type corresponding to the target fusion feature is classified and determined using a pre-trained Conditional Random Field (CRF) model.
15. The method according to claim 13, characterized in that, After performing fine-grained scenario classification based on the target fusion feature according to the network traffic service type to obtain the network traffic scenario type corresponding to the target fusion feature, the method further includes: Based on the network traffic scenario type, a target mapping strategy is determined from the strategy mapping table. The target mapping strategy is applicable to the control plane corresponding to the edge node of the communication network. By monitoring the network status corresponding to the edge nodes of the communication network, the target mapping strategy is dynamically adjusted according to the network status.
16. A network traffic identification device, characterized in that, include: Traffic capture unit is used to capture target traffic data passing through edge nodes of the communication network; The feature extraction unit is used to extract QUIC handshake connection features and application interaction behavior features based on the target traffic data, respectively. The feature fusion unit is used to fuse the QUIC handshake connection features and the application interaction behavior features to obtain the target fused features; The identification unit is used to identify the business scenario type corresponding to the target traffic data based on the target fusion features.
17. An electronic device, characterized in that, The system includes a memory and a processor, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the method as described in any one of claims 1 to 15.
18. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 15.