VPN Tunnel Website Fingerprint Analysis Method Based on Zero-Shot Learning

Through the VPN tunnel website fingerprint analysis method based on zero-sample learning, using genetic fingerprint and dynamic time regularization algorithm, the problems of complex tunnel settings and frequent training of models in the existing technology are solved, and efficient cross-tunnel website recognition and robustness are achieved.

CN114417978BActive Publication Date: 2025-05-30Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111603522.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-24
Publication Date
2025-05-30
Estimated Expiration
2041-12-24

AI Technical Summary

Technical Problem

Existing website fingerprint analysis methods require attackers to reproduce the user's tunnel settings and collect large amounts of training samples, especially the traffic that includes monitoring and non-monitoring websites, resulting in time consumption and frequent model retraining, and tunnel encapsulation and network noise changes affect the effectiveness of the classifier.

Method used

The VPN tunnel website fingerprint analysis method based on zero-sample learning is adopted. By collecting and monitoring website traffic, extracting genetic fingerprints, using k-NN classifiers for classification, using dynamic time regular algorithm to measure the distance of gene fingerprints, selecting the best samples for training, and using adaptive thresholds for website recognition in the classification stage.

Benefits of technology

It realizes training classifiers without monitoring website samples, which can work across tunnels, reduce the time-consuming of data collection and model retraining, and is robust to tunnel packaging and network noise, improving recognition accuracy and generalization capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417978B_ABST
    Figure CN114417978B_ABST
Patent Text Reader

Abstract

The present invention provides a VPN tunnel website fingerprint analysis method based on zero-shot learning. The method includes: a training phase and a classification phase; the training phase includes: Step A1: Collect traffic samples of each monitored website; Step A2: Extract features from the traffic samples of each monitored website to generate gene fingerprints of each traffic sample in the monitored website; Step A3: Select and generate n samples from the gene fingerprints of each monitored website for training a k-NN classifier; the classification phase includes: Step B1: Capture traffic samples to be tested on the link between the user and the VPN tunnel proxy; Step B2: Perform data packet de-encapsulation, feature extraction, and time sampling on the traffic samples to be tested to generate unknown gene fingerprints; Step B3: Use the trained k-NN classifier to predict the label of the unknown gene fingerprint.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for analyzing website fingerprints of VPN tunnels based on zero-shot learning. Background Art

[0002] Website fingerprinting (WF) is a method for analyzing encrypted traffic that can break the anonymity provided by encrypted tunnels. WF utilizes the unique patterns presented by each website in network traffic, namely packet time and length, and these patterns are learned by a machine learning classifier. Existing WF attacks require the attacker to be able to reproduce the user's tunnel settings and collect a sufficient number of training samples by accessing websites themselves. In addition, the training data needs to include both the websites that the attacker is interested in, i.e., monitored sites (MS), and other websites that the victim may access, i.e., unmonitored sites (UMS). These prerequisites extend the time required for the attacker to generate a usable classifier. Since website content is updated or encrypted tunnels are changed, website traffic changes regularly over time, so the attacker needs to re-collect data and train the classifier frequently to avoid significant concept drift. Summary of the Invention

[0003] Aiming at the problem that traditional WF attacks need to rely on UMS traffic, the present invention provides a method for analyzing website fingerprints of VPN tunnels based on zero-shot learning.

[0004] The present invention provides a method for analyzing website fingerprints of VPN tunnels based on zero-shot learning, including: a training stage and a classification stage;

[0005] The training stage includes:

[0006] Step A1: Collect traffic samples of each monitored website;

[0007] Step A2: Extract features from the traffic samples of each monitored website to generate gene fingerprints of each traffic sample in the monitored website;

[0008] Step A3: Select and generate n samples from the gene fingerprints of each monitored website for training a k-NN classifier;

[0009] The classification stage includes:

[0010] Step B1: Capture traffic samples to be tested on the link between the user and the VPN tunnel proxy;

[0011] Step B2: Perform packet de-encapsulation, feature extraction, and time sampling on the traffic samples to be tested to generate unknown gene fingerprints;

[0012] Step B3: Use the trained k-NN classifier to predict the label of the unknown gene fingerprint.

[0013] Further, step A2 specifically includes:

[0014] Given a traffic sample b = {(t i , d i , s i )}, generate the corresponding gene fingerprint G(b) = {g(t i )} according to formula (1):

[0015]

[0016] where i ∈ [1:n] represents the data packet index, t i is the timestamp when the i-th data packet is observed, d i ∈ {in, out} is used to indicate whether the i-th data packet belongs to a downlink data packet or an uplink data packet, and s i is the byte length of the i-th data packet.

[0017] Further, step A3 specifically includes:

[0018] Step A3.1: Perform time sampling processing on all gene fingerprints of each monitored website to generate new gene fingerprints for that monitored website;

[0019] Step A3.2: For the new gene fingerprints of each monitored website, use the dynamic time warping algorithm to measure the distance between any two new gene fingerprints;

[0020] Step A3.3: Sort all the new gene fingerprints based on the total distance, and select the n samples with the smallest total distance from them for training the k-NN classifier.

[0021] Further, step A3.1 specifically includes:

[0022] Given a sampling time interval δ, perform time sampling processing on the given gene fingerprint G(b) = (g(t 1 ), g(t 2 ), …, g(t n )) according to formula (2) to obtain new gene fingerprints

[0023]

[0024] Further, step A3.2 specifically includes:

[0025] Take two new gene fingerprints and The distance between them is defined as the cost of the optimal alignment path, expressed as formula (3):

[0026] D(b,b′)=min p∈P C(p) (3)

[0027] Where c(x k ,y k ) is the alignment cost of the aligned and elements, and P is the set of all alignment paths between the gene fingerprints and .

[0028] Furthermore, step A3.3 specifically includes:

[0029] For website w, based on the total distance sort the traffic samples b∈B w and select n samples with the smallest total distance; B w represents the sample set corresponding to website w.

[0030] Furthermore, for the open-world scenario, in the training stage, step A3 is:

[0031] Select and generate n samples from the gene fingerprints of each monitored website, use the selected n samples to represent the monitored website, and calculate the adaptive threshold of each monitored website;

[0032] Correspondingly, in the classification stage, step B3 is:

[0033] Calculate the distance between the sample to be tested and the n samples. If the distance from the traffic sample to be tested to the nearest sample is less than the adaptive threshold of a certain monitored website, then the traffic sample to be tested belongs to that monitored website; otherwise, it belongs to a non-monitored website.

[0034] Furthermore, step A3 specifically includes:

[0035] For website w, for each traffic sample b∈B w calculate the minimum intra-class distance and the minimum inter-class distance and take the average of the ρ quantile of {D in (b)} and the (1-ρ) quantile of {D out (b)} as the adaptive threshold of website w; where D(b,b′) represents the distance between the new gene fingerprints and corresponding to two different traffic samples b and b′ respectively, and B wDenote the sample set corresponding to website w, and ρ ∈ [0, 1] is a hyperparameter.

[0036] Advantages of the present invention:

[0037] The VPN tunnel website fingerprint analysis method based on zero - shot learning proposed by the present invention classifies websites by utilizing the intrinsic features of websites and according to the similarity between gene fingerprints, allows training a classifier without UMS samples, and enables the trained classifier to work across tunnels. Brief Description of the Drawings

[0038] Figure 1 It is a schematic diagram of the VPN tunnel website fingerprint analysis scenario provided by an embodiment of the present invention;

[0039] Figure 2 It is a schematic flow diagram of the VPN tunnel website fingerprint analysis method based on zero - shot learning provided by an embodiment of the present invention;

[0040] Figure 3 It is a schematic diagram of DTW alignment and regularization path of gene fingerprints provided by an embodiment of the present invention;

[0041] Figure 4 It is a schematic diagram of closed - world recognition accuracy provided by an embodiment of the present invention;

[0042] Figure 5 It is a schematic diagram of open - world attack performance provided by an embodiment of the present invention. Detailed Embodiments

[0043] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] The scenario targeted by the present invention is as Figure 1 shown. The attacker does not need to pre - construct all possible encrypted tunnels to collect training data, nor does it need to crawl each UMS to construct a real open world.

[0045] Embodiment 1

[0046] Combined with Figure 1 and Figure 2 shown, an embodiment of the present invention provides a VPN tunnel website fingerprint analysis method based on zero - shot learning, which is applied to a closed - world scenario. The method includes the following steps:

[0047] Training phase:

[0048] S101: Collect traffic samples from each monitoring website;

[0049] S102: Extract features from the traffic samples of each monitoring website to generate gene fingerprints for each traffic sample in the monitoring website;

[0050] As an implementable manner, this step includes the following sub-steps:

[0051] Given a traffic sample b = {(t i , d i , s i )}, generate the corresponding gene fingerprint G(b) = (g(t i )} according to formula (1):

[0052]

[0053] where i ∈ [1:n] represents the data packet index, t i is the timestamp when the i-th data packet is observed, d i ∈ {in, out} is used to indicate whether the i-th data packet belongs to a downstream data packet or an upstream data packet, and s i is the byte length of the i-th data packet.

[0054] S103: Elect and generate n samples from the gene fingerprints of each monitoring website for training the k-NN classifier;

[0055] As an implementable manner, this step includes the following sub-steps:

[0056] S1031: Perform time sampling processing on all the gene fingerprints of each monitoring website to generate new gene fingerprints for the monitoring website;

[0057] Specifically, given a sampling time interval δ, perform time sampling processing on the given gene fingerprint G(b) = (g(t 1 ), g(t 2 ), …, g(t n )) according to formula (2) to obtain a new gene fingerprint

[0058]

[0059] S1032: For the new gene fingerprints of each monitoring website, use the dynamic time warping algorithm to measure the distance between any two new gene fingerprints;

[0060] Specifically, the two new gene fingerprints and The distance between them is defined as the cost of the optimal alignment path, expressed by Equation (3):

[0061] D(b, b′) = min p∈P C(p) (3)

[0062] Wherein, c(x k , y k ) is the alignment cost of the aligned elements, P is the set of all alignment paths between the gene fingerprints and . The set of all alignment paths between the gene fingerprints and .

[0063] The sampling points are mapped from one fingerprint to another fingerprint so that the starting point and the ending point match and increase monotonically over time. Such an alignment can be described as an alignment path p = (p 1 , p 2 , …, p l ), where p k = (x k , y k ) ∈ [1:n] × [1:m], k ∈ [1:l]. The alignment path satisfies two conditions: the boundary condition, that is, p 1 = (1, 1), p l = (n, m); and the step-by-step condition, that is, (x k+1 - x k , y k+1 - y k ) ∈ {(1, 0), (0, 1), (1, 1)}, k ∈ [1:l - 1]. The Sakoe-Chiba window is used to constrain the alignment path. That is to say, the alignment path p must run along the window |x k - y k | ≤ wmin(n, m), where w is the window size, k ∈ [1:l]. In this embodiment, the Euclidean distance is used as the element alignment cost.

[0064] The optimal alignment path runs along the low-cost "valley" corresponding to the best alignment between the two fingerprints, as Figure 3 shown.

[0065] S1033: Sort all the new gene fingerprints based on the total distance, and select n samples with the smallest total distance from them for training the k-NN classifier.

[0066] Specifically, for website w, based on the total distance sort the traffic samples b ∈ B w , and select n samples with the smallest total distance; B wDenote the sample set corresponding to website w.

[0067] Classification stage:

[0068] S104: Capture the traffic samples to be tested on the link between the user and the VPN tunnel proxy;

[0069] S105: Perform data packet de-encapsulation, feature extraction, and time sampling on the traffic samples to be tested to generate unknown gene fingerprints;

[0070] Specifically, when loading a website through a VPN tunnel, the proxy tool will change the characteristics of the traffic. The length and quantity of tunnel data packets are affected by the data encapsulation format. Therefore, it is necessary to de-encapsulate each data packet (subtract the encapsulation byte count) before fingerprint extraction.

[0071] Specifically, first use the operation in step S102 to generate the gene fingerprints of the traffic samples to be tested, and then use the operation in step S1031 to generate its new gene fingerprints, denoted as unknown gene fingerprints.

[0072] S106: Use the trained k-NN classifier to predict the label of the unknown gene fingerprint.

[0073] Embodiment 2

[0074] Based on the above embodiment, combined with Figure 1 and Figure 2 as shown, the embodiment of the present invention further provides a VPN tunnel website fingerprint analysis method based on zero-shot learning, which is applied to an open-world scenario and includes the following steps:

[0075] The training stage includes:

[0076] S201: Collect the traffic samples of each monitored website;

[0077] S202: Perform feature extraction on the traffic samples of each monitored website to generate the gene fingerprints of each traffic sample in the monitored website; This step can specifically refer to the above embodiment and will not be elaborated here.

[0078] S203: Elect and generate n samples from the gene fingerprints of each monitored website, and use the elected n samples to represent the monitored website; and calculate the adaptive threshold of each monitored website;

[0079] As an implementable manner, taking website w as an example, this step includes the following sub-steps:

[0080] S2031: Perform time sampling processing on all the gene fingerprints of website w to generate new gene fingerprints of website w;

[0081] S2032: For the new gene fingerprints of website w, use the dynamic time warping algorithm to measure the distance between any two new gene fingerprints;

[0082] Specifically, for two new gene fingerprints and the distance between them is defined as the cost of the optimal warping path, expressed as formula (3):

[0083] D(b, b′) = min p∈P C(p) (3)

[0084] where c(x k , y k ) is the element alignment cost of aligning and , and P is the set of all warping paths between gene fingerprints and .

[0085] S2033: Sort all the new gene fingerprints based on the total distance, select the n samples with the smallest total distance from them, and use these n elected samples to represent the monitored website;

[0086] Specifically, for website w, based on the total distance sort the traffic samples b ∈ B w and select n samples with the smallest total distance; B w represents the sample set corresponding to website w.

[0087] S2034: For website w, calculate the minimum intra-class distance w and the minimum inter-class distance for each traffic sample b ∈ B and take the average of the ρ quantile of {D in (b)} and the (1 - ρ) quantile of {D out (b)} as the adaptive threshold of website w; where D(b, b′) represents the distance between the new gene fingerprints and corresponding to two different traffic samples b and b′ respectively, B w represents the sample set corresponding to website w, and ρ ∈ [0, 1] is a hyperparameter.

[0088] The classification stage includes:

[0089] S205: Capture the traffic samples to be tested on the link between the user and the VPN tunnel proxy;

[0090] S206: Decapsulate data packets, extract features, and perform time sampling on the to-be-tested traffic sample to generate an unknown gene fingerprint. For the specific implementation of this step, please refer to the above embodiments and will not be elaborated here.

[0091] S207: Calculate the distances between the to-be-tested sample and the n samples selected in step S2033. If the distance from the to-be-tested traffic sample to the nearest sample is less than the adaptive threshold of a certain monitoring website, then the to-be-tested traffic sample belongs to this monitoring website; otherwise, it belongs to a non-monitoring website.

[0092] The VPN tunnel website fingerprint analysis method based on zero-shot learning provided by the embodiments of the present invention is a WF attack method that uses zero-shot learning to reduce time-consuming data collection and model retraining tasks. An attacker only needs to collect MS traffic in a typical Ethernet channel to achieve cross-tunnel open-world classification. Moreover, this attack is robust to tunnel encapsulation and network noise.

[0093] To verify the performance of the GF attack method of the present invention, the present invention also provides the following experimental data.

[0094] (1) Data collection

[0095] In this experiment, websites were selected from the top 2000 websites ranked by Alexa in May 2021. After removing the websites with loading failures, there were 1809 valid websites, among which 952 used HTTPS by default. Existing research work has proven that it is difficult for WF attacks to classify websites containing dynamic content, such as updated videos and random recommendations. Therefore, in this experiment, the top 100 websites without dynamic content were used as MS, and the remaining 1709 were used as UMS. It should be noted that the UMS traffic collected in this experiment was only used in the test phase, so it did not need to reach the million level to support open-world training.

[0096] The data collection environment of this experiment included a client and a VPN proxy. Among them, the client was a Windows 10 20H2 desktop computer, and the proxy was an Ubuntu 20.04 cloud server with a kernel version of 5.8.0 located in different cities. Three commonly used VPN tunnel tools were used to build encrypted tunnels, and the default settings were as shown in Table 1. On the client, the Chrome browser (version 90.0) was driven by Selenium WebDriver to access websites. This allows for a more realistic website access than using command-line tools because using WebDriver can simulate the browsing behavior of real users.

[0097] Table 1 VPN tunnel settings

[0098]

[0099] We used tshark to capture the traffic generated by each access. The packets in each traffic sample are represented as a series of triples (timestamp, direction, payload length) and saved to a CSV file. Finally, we created a total of 7 traffic datasets, which are divided into the following three groups for illustration:

[0100] MS-ETH: An Ethernet traffic dataset for closed-world and open-world training, including 1,000 traffic samples captured in Ethernet (100 MS × 10 accesses).

[0101] MS-SSH / SS / VPN: A VPN tunnel traffic dataset for closed-world and open-world testing, including 3,000 traffic samples captured on VPN tunnels (3 types of tunnels × 100 MS × 10 accesses).

[0102] UMS-SSH / SS / VPN: A dataset only for open-world testing, including 5,127 samples captured on VPN tunnels (3 types of tunnels × 1709 UMS × 1 access).

[0103] (2) Comparison methods

[0104] To comprehensively demonstrate the performance of the GF attack, we selected 3 representative WF attacks for comparison and re-evaluated these methods on our dataset.

[0105] CUMUL (Panchenko, A., Lanze, F., Pennekamp, J., Engel, T., Zinnen, A., Henze, M., Wehrle, K.: Website fingerprinting at internet scale. In: 23rd Annual Network and Distributed System Security Symposium. The Internet Society (2016)): The CUMUL attack uses an SVM classifier to classify the cumulative packet length features. This method subtracts the uplink packet length from the downlink packet length to accumulate the sum sequence as a feature. The final feature set contains 100 points inserted from the sequence and 4 statistical features of the total number of bidirectional packets and bytes.

[0106] DF (Sirinam, P., Imani, M., Juárez, M., Wright, M.: Deep fingerprinting: Undermining website fingerprinting defenses with deep learning. In: 2018 ACM SIGSAC Conference on Computer and Communications Security. pp. 1928–1943. ACM (2018)): The DF attack is based on a deep CNN model and takes the sequence features of packet directions as input. We follow the hyperparameter selection process of DF to achieve its best performance.

[0107] DDTW (Feghhi, S., Leith, D. J.: A web traffic analysis attack using only timing information. IEEE Trans. Inf. Forensics Secur. 11(8), 1747–1759 (2016)): The DDTW attack uses only packet timing information. This method aligns the timestamp sequences of upstream packets using the DTW algorithm, then obtains the optimal path distance based on the F - distance, and uses a k - NN classifier to identify websites.

[0108] (3) Closed - world evaluation

[0109] We first evaluate the attack performance in the closed - world scenario, where users can only access the monitored websites. We use classification accuracy as the performance metric. The classifier for each attack is trained on the MS - ETH dataset and tested on the MS - SSH / SS / VPN datasets.

[0110] We first tune the hyperparameters in GF to achieve the best performance. The influence of the sampling interval δ and the number of nearest neighbors k is as Figure 4 (a) shown, where the window size w = 0.6 and the number of samples n = 6. The convexity of the curve reflects the fact that a too - small δ will lead to overfitting, while a very large δ will lose fingerprint information. We finally determine δ = 20 ms (50 samples per second) and k = 1 to achieve a more balanced accuracy for each tunnel.

[0111] Figure 4(b) shows the recognition accuracy results. The GF attack achieved at least 94.1% accuracy, outperforming all other methods and showing good cross-tunnel generalization ability. These results illustrate the limitations of existing attacks. Since the features on which they are based change significantly across different VPN tunnels, these attacks can only achieve high accuracy in the same tunnel where the classifier is trained. Although CUMUL uses similar features to GF, the uplink traffic and statistical features reduce the cross-tunnel generalization ability.

[0112] In addition, we show the computational complexity of different methods by recording the time for feature extraction, training, and testing. All code was run on an Intel i7-6700 CPU with 32GB of memory. We used an NVIDIA RTX 2060 with 6GB of GPU memory to accelerate the training and testing of DF, and accelerated other attack methods by calling the underlying C library through Cython. The feature extraction and model training times were measured on the MS-ETH dataset, and the model prediction time was measured on the MS-SSH dataset. The results shown in Table 2 indicate that while DF requires the least preparation time (extraction + training), the complexity of GF is lower than that of CUMUL and DDTW. For testing, GF takes longer than CUMUL and DF because it needs to compare samples with each sample. Overall, GF has a reasonable time complexity.

[0113] Table 2 Comparison of time complexity

[0114]

[0115] (4) Open-world evaluation

[0116] Next, we evaluate the performance of the WF attack in a more realistic open-world scenario. In this scenario, users can access all websites on the Internet, and the attacker attempts to determine whether the traffic is generated by MS. Considering this is a binary classification task, we use the true positive rate (TPR), false positive rate (FPR), and precision as performance metrics. The classifier is trained on the MS-ETH dataset and tested on a combination of monitored and unmonitored datasets (e.g., MS-SSH + UMS-SSH). It should be noted that, compared with the settings in previous studies (the above 3 representative WF attacks), UMS samples are not included in the training set.

[0117] In the open world, our adaptive threshold turns the model into a 1-NN classifier, i.e., prediction based on the nearest neighbor. We have verified the good performance of the classifier when k = 1. In Figure 5(a), we show the impact of the optimal threshold quantile ρ on the error rate. It can be seen that when the threshold ρ = 0.9, a relatively balanced false negative rate and false positive rate can be achieved, where the FPR for each tunnel remains around 9%.

[0118] For a horizontal comparison with other attack methods, we implemented similar adaptive thresholds using their respective similarity metrics (prediction confidence in CUMUL and DF, F - distance in DDTW) in each attack and took ρ = 0.9. We first examined the influence of the number of non - monitored websites on the error rate. As Figure 5 (b) shows, as the number of UMS increases, the FPR of all WF attacks increases. Among them, DDTW and DF have the lowest and highest FPRs respectively, and the GF attack maintains a relatively low FPR, close to that of DDTW. In Table 3, we report the attack performance in the open world. The evaluation is based on the combination of each VPN tunnel MS dataset and UMS dataset. The results show that the GF attack always performs best in terms of TPR and precision, with at least 80.9% TPR and 83.3% precision on 1,709 UMS. Although the error rate of GF is slightly higher than that of DDTW, it maintains a maximum FPR of 10.5%.

[0119] Table 3 Open - world performance

[0120]

[0121] The gene fingerprint (GF) attack proposed by the present invention utilizes the intrinsic characteristics of websites and classifies websites according to the similarity between gene fingerprints, allowing the classifier to be trained without UMS samples and enabling the trained classifier to work across tunnels.

[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. Zero - sample learning - based VPN tunnel website fingerprint analysis method, Characterized in that, It includes: A training stage and a classification stage; The training stage includes: Step A1: Collect traffic samples of each monitored website; Step A2: Extract features from the traffic samples of each monitored website to generate gene fingerprints of each traffic sample in the monitored website; Step A2 specifically includes: Given a traffic sample \(b = \{(t i , d i , s i )\}\), generate the corresponding gene fingerprint \(G(b)=\{g(t i )\}\) according to formula (1): where \(i\in[1:n]\) represents the data packet index, \(t\) i is the timestamp at which the \(i\)-th data packet is observed, \(d\) i \(\in\{in,out\}\) is used to indicate whether the \(i\)-th data packet is a downstream data packet or an upstream data packet, and \(s\) i is the byte length of the \(i\)-th data packet; Step A3: Select and generate n samples from the gene fingerprints of each monitored website for training a k - NN classifier; Step A3 specifically includes: Step A3.1: Perform time sampling processing on all gene fingerprints of each monitored website to generate new gene fingerprints of the monitored website; Step A3.2: For the new gene fingerprints of each monitored website, use the dynamic time warping algorithm to measure the distance between any two new gene fingerprints; Step A3.3: Sort all the new gene fingerprints based on the total distance, and select the n samples with the smallest total distance from them for training the k - NN classifier; The classification stage includes: Step B1: Capture the traffic samples to be tested on the link between the user and the VPN tunnel proxy; Step B2: Perform data packet de - encapsulation, feature extraction, and time sampling on the traffic samples to be tested to generate unknown gene fingerprints; Step B3: Use the trained k - NN classifier to predict the label of the unknown gene fingerprint.

2. The zero - sample learning - based VPN tunnel website fingerprint analysis method according to claim 1, Characterized in that, Step A3.1 specifically includes: Given a sampling time interval δ, according to formula (2), for the given gene fingerprint G(b) = (g(t 1 ), g(t 2 ), …, g(t n )) perform time sampling processing to obtain a new gene fingerprint 3. The zero - sample learning - based VPN tunnel website fingerprint analysis method according to claim 1, Characterized in that, Step A3.2 specifically includes: Define the distance between two new gene fingerprints and as the cost of the optimal alignment path, expressed as formula (3): D(b,b′) = min p∈P C(p) (3) Among them, c(x k ,y k ) is the alignment and element alignment cost, and P is the set of all regular paths between and the gene fingerprints.

4. The zero - sample learning - based VPN tunnel website fingerprint analysis method according to claim 2, Characterized in that, Step A3.3 specifically includes: For website w, based on the total distance sort the traffic samples b ∈ B w and select n samples with the minimum total distance; B w represents the sample set corresponding to website w.

5. The zero - sample learning - based VPN tunnel website fingerprint analysis method according to claim 1, Characterized in that, For an open - world scenario, in the training stage, step A3 is: Select and generate n samples from the gene fingerprints of each monitored website, use the selected n samples to represent the monitored website, and calculate the adaptive threshold of each monitored website; Correspondingly, in the classification stage, step B3 is: Calculate the distance between the traffic sample to be tested and the n samples. If the distance from the traffic sample to be tested to the nearest sample is less than the adaptive threshold of a certain monitored website, then the traffic sample to be tested belongs to this monitored website; otherwise, it belongs to a non - monitored website.

6. The zero - sample learning - based VPN tunnel website fingerprint analysis method according to claim 5, Characterized in that, Step A3 specifically includes: For website w, for each traffic sample b ∈ B w Calculate the minimum intra-class distance and the minimum inter-class distance and take the average of the ρ-th quantile of {D in (b)} and the (1 - ρ)-th quantile of {D out (b)} as the adaptive threshold for this website w; where D(b, b′) represents the distance between the new gene fingerprints corresponding to two different traffic samples b and b′ respectively and and, B w represents the sample set corresponding to website w, and ρ ∈ [0, 1] is a hyperparameter