A method for identifying and classifying encrypted traffic based on deep learning model

By combining the deep learning methods of residual networks and time domain convolutional networks, the spatial and temporal characteristics of encrypted traffic are automatically extracted, and the problem of low classification performance and accuracy of traffic recognition in the prior art is solved, and higher classification accuracy and efficiency are achieved.

CN115378701BActive Publication Date: 2025-05-16NANJING TECH UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211004055.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-22
Publication Date
2025-05-16
Estimated Expiration
2042-08-22

AI Technical Summary

Technical Problem

In the prior art, the classification performance and classification accuracy of the encrypted network traffic recognition method are low, and it is difficult to quickly and accurately classify encrypted traffic without infringing on user privacy.

Method used

Using a deep learning-based method, combining residual network (ResNet) and time domain convolutional network (TCN), the characteristics of encrypted traffic are automatically extracted from the two aspects of spatial characteristics and temporal characteristics, and the ResNet-TCN framework is built for traffic classification.

Benefits of technology

It improves the identification and classification accuracy of encrypted traffic, achieves higher classification performance, and meets the conditions of not infringing on user privacy, solving the problems of low identification accuracy and efficiency in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378701B_ABST
    Figure CN115378701B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for identifying and classifying encrypted traffic based on a deep learning model. The method first pre-processes the original data, then extracts spatiotemporal features using the ResNet‑TCN model in the spatiotemporal dimension, and uses ResNet to learn spatial features. ResNet solves the problem of gradient vanishing and difficulty in training in deep networks; in the time dimension, the TCN network is used to learn the potential timing features between encrypted traffic; and the trained model is used to identify and classify encrypted network traffic. The present invention improves the accuracy of encrypted traffic identification and classification, achieves higher classification performance, and solves the problems of low accuracy and efficiency of existing encrypted network traffic identification and classification methods using CNN and RNN.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a network encryption traffic classification method oriented to deep learning, and belongs to the field of computer artificial intelligence. Background Art

[0002] With the increasing development of Internet communication technology in recent years, the network has become a part of people's work and life. In today's network management system, network traffic classification is a key task, and the main goal is to predict network data flow protocols and application types.

[0003] In recent years, with the rapid development of the demand for protecting the privacy and security of transmitted data and users, more and more application protocols have begun to use encryption technology to send data, the proportion of encrypted traffic in the network has also increased dramatically, and encryption technology has become more and more complex. Encrypted traffic classification has been considered one of the most important network security directions since the birth of the Internet. However, due to the popularity of encryption technology and the rapid growth of network throughput, it has become increasingly difficult to quickly and accurately classify encrypted traffic. On the other hand, the emergence of encryption technology has also increased the possibility of various malicious traffic and abnormal network traffic. Hacker attacks also use encryption technology to carry out a large number of malicious attacks. When a large amount of encrypted traffic appears in the network, how to quickly classify the encrypted traffic and further conduct refined traffic analysis will become very important.

[0004] According to development, encrypted traffic classification technology can be divided into three categories: the first, port-based identification method is the earliest network traffic classification technology, which uses the port number in the data packet header to distinguish the type of network traffic, which is simple, direct, and efficient, and does not involve user privacy and security; the second, based on deep packet inspection (DPI), uses the relevant protocol feature strings in the detected network traffic to match; the third, based on machine learning identification method, machine learning (ML) is mainly used to solve the problem of encrypted traffic classification, but it requires a lot of labor and domain knowledge, and machine learning has limitations. The quality of the selected features usually affects the final effect of the classifier, resulting in low accuracy of the final encrypted traffic classification.

[0005] Deep learning has made significant progress in recent years. The feature extraction and selection of deep learning (DL)-based methods are automatically completed through training. This feature makes deep learning-based methods a very ideal traffic classification method. Another feature of deep learning-based methods is that compared with traditional machine learning methods, deep learning has a higher learning ability.

[0006] In recent years, machine learning methods have been used in network traffic identification and classification. Compared with traditional methods, deep learning has better classification accuracy and scalability, but it also has shortcomings. Therefore, it is necessary to propose a method that can accurately classify encrypted network traffic. Summary of the invention

[0007] The problem to be solved by the present invention is that the classification performance and classification accuracy of the encrypted network traffic identification method in the prior art are low. A method is proposed which can automatically extract and utilize the characteristics of encrypted traffic from both spatial characteristics and temporal characteristics to classify encrypted traffic, thereby improving the identification and classification capabilities of encrypted traffic.

[0008] In order to solve the above technical problems, the present invention adopts the following technical solutions:

[0009] The present invention proposes a method for identifying and classifying encrypted traffic based on deep learning, which specifically includes the following steps:

[0010] A method for identifying and classifying encrypted traffic based on a deep learning model, characterized by comprising the following steps:

[0011] Step 1: Preprocess the original traffic data to obtain an encrypted traffic data vector used as an input of a network encrypted traffic classification model;

[0012] Step 2: Build a network encryption traffic classification model based on residual network ResNet and time domain convolutional network TCN;

[0013] Step 3: Extract the spatial features of encrypted traffic data through the ResNet model; extract the temporal features of encrypted traffic data through the TCN model;

[0014] In the step 2, a ResNet-TCN framework is constructed, and learning and training are performed;

[0015] The ResNet-TCN framework includes the residual network ResNet and the time domain convolutional network TCN, where:

[0016] 1) The network structure of the residual network ResNet is based on the data transmission direction, including input layer, convolution layer, multiple residual blocks, pooling layer and fully connected layer; multiple residual blocks are stacked; each residual block is composed of two 3*3 convolutional networks connected in series; the definition expressions of these units are as follows:

[0017] y l =h(x l )+F(x l , w t )

[0018] x l+1 =f(yl )

[0019] where x l and x l+1 is the input and output of the lth unit, F(·) is the residual function, h(x l ) is the identity mapping, w t is a set of weights associated with the lth residual unit, f(y l ) is the activation function.

[0020] The input encrypted traffic data is output after multiple convolutions; however, after multiple layers of convolution, information loss may occur. Therefore, the data needs to be padded to ensure that every piece of information is taken into account. The size of the padding is related to the size of the convolution kernel.

[0021] There is usually only one pooling layer connected to the last residual block in the ResNet model. The output of the pooling layer is expressed as:

[0022]

[0023] Among them, M l represents the size of the lth pooling layer, and down(·) represents the downsampling function.

[0024] In the output layer, the output is added to the input; finally, the spatial features of the encrypted traffic data are extracted;

[0025] 2) The network structure of the time domain convolutional network (TCN) is composed of the first layer of dilated causal convolution, weight normalization, activation function ReLU and Dropout, and the second layer of dilated causal convolution, weight normalization, activation function ReLU and Dropout; the output of the first layer is the input of the second layer; in each layer, according to the data transmission direction, it is dilated causal convolution, weight normalization, activation function ReLU and Dropout;

[0026] Among them, causal convolution is for one-dimensional data input X∈R and filter F=(f 1 , f 2 ,…,f k ), sequence X=(X 1 ,X 2 ,…,X T ), in X t The causal convolution at is defined as:

[0027]

[0028] However, causal convolution has certain difficulties in dealing with tasks with longer histories, and the receptive field of dilated convolution grows exponentially. For one-dimensional data input X∈R and filter F=(f1 , f 2 ,…,f k ), sequence X=(X 1 ,X 2 ,…,X T ), in X t The dilated convolution with a dilation factor d at is defined as:

[0029]

[0030] Because dilated convolution is used, padding (usually 0) is required for each layer. The padding size is (K-1)d, where K represents the filter size and d is the dilation factor. Weight normalization speeds up the operation by rewriting the weights of the deep network. The activation function ReLU() increases the nonlinearity of the network to prevent the gradient from disappearing. The function is defined as follows:

[0031] f(x) = max(0, x)

[0032] Add dropout to prevent overfitting. In an n-layer convolutional neural network, the following definition is given:

[0033]

[0034] Among them, * represents the convolution operation, is a nonlinear activation function, K i is the convolution kernel, i∈{1, 2, ..., n}, and X is the input.

[0035] 4) The data processed by ResNet is used as input and sent to TCN to extract time series features;

[0036] After the output of the last layer of TCN and ResNet is concatenated, the obtained features are classified using the fully connected classification, and the prediction results are output by the softmax function.

[0037] Softmax is defined as follows:

[0038]

[0039] Among them, x i is the output value of the i-th neuron, d is the number of output categories, Represents the sum of all values.

[0040] Compared with the prior art, the present invention adopts the above technical solution and has the following advantages:

[0041] 1. In the spatial dimension, the convolutional layer of the ResNet algorithm model is used to extract effective features, and ResNet is used to solve the problem of gradient vanishing and difficulty in training deep networks; in the temporal dimension, the TCN network is used to learn the potential timing characteristics between network encrypted traffic.

[0042] The method of combining two networks is used to extract features from the spatial and temporal aspects of the data, which improves the recognition accuracy of the model; at the same time, it also meets the requirements of identifying encrypted traffic without infringing user privacy. This method solves the technical problems of low recognition accuracy and efficiency caused by the existing encrypted traffic recognition method using CNN and RNN.

[0043] 2. TCN time domain convolutional network has better parallelism and can perform convolution in parallel, which can largely avoid gradient vanishing and gradient explosion. TCN is used in the encrypted traffic classification model to reduce the amount of calculation to a certain extent. The receptive field size can be adjusted by the number of layers, expansion factor and filter size, and more information can be learned; the Dropout layer prevents overfitting and improves the operation speed of the model;

[0044] 3. The deep learning model has a certain improvement in accuracy compared to the traditional machine learning model. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 It is a flow chart of the present invention as a whole;

[0046] Figure 2 It is a flow chart of the original flow (data) preprocessing of the present invention;

[0047] Figure 3 It is a deep residual network architecture diagram of the present invention;

[0048] Figure 4a to Figure 4c It is a time domain convolutional network architecture diagram of the present invention, wherein:

[0049] Figure 4a It is the causal convolution structure diagram,

[0050] Figure 4b It is the dilated causal convolution structure diagram,

[0051] Figure 4c It is the residual connection structure diagram. DETAILED DESCRIPTION

[0052] The technical solution of the present invention is further described in detail below in conjunction with the accompanying drawings:

[0053] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as those generally understood by those skilled in the art in the art to which the present invention belongs. It should also be understood that those terms such as those defined in common dictionaries should be understood to have the meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless defined as herein.

[0054] Under the above conditions, the steps of the network traffic classification method based on deep learning are as follows: Figure 1 As shown. Specifically including the following steps:

[0055] refer to Figure 2 ,Step 1: preprocess the original traffic data to obtain the encrypted traffic data vector used as the ,input of the deep learning model;

[0056] Step 1.1, import the data in the data set, the sample data set is the network encrypted traffic data in the original format, and process the data;

[0057] Step 1.2: First, the original traffic data in the data set is segmented to generate data that meets the input conditions;

[0058] The segmentation method is: according to a certain granularity, the continuous original traffic is segmented into multiple discrete traffic units to generate data that meets the input conditions. A flow refers to a data packet with the same source IP, source port, destination IP, destination port and transport protocol. A session refers to a bidirectional flow. Compared with a flow, a session contains more traffic feature information, so the remote traffic is divided into discrete sessions, and the output format is saved in pcap format.

[0059] Step 1.3: Segment the traffic data. Data cleaning mainly deals with data loss and data redundancy problems in the original data. For example, fields such as IP, MAC address, port number, etc. in the data will bring noise to data feature learning and need to be cleaned.

[0060] Clean up the same traffic data and delete the data information in the data set that is not related to the traffic characteristics. This data will occupy the space of other valid information, including fields such as MAC address, IP, port number, etc., to prevent the model from overfitting. These fields will bring noise to the learning of data features and may even affect the final classification results.

[0061] Step 1.4, the processed data, the obtained data file is normalized and the data needs to be reconstructed. Because the training data input to the neural network needs to be of a fixed size, the processed traffic file is sized uniformly according to a fixed byte. If it is larger than the set fixed byte, the subsequent bytes are deleted. If it is smaller than the fixed byte, 00 is used to fill in the fixed byte. Normalization is to transform the data, scale the eigenvalues ​​proportionally to a specific range, and finally obtain a csv file.

[0062] The normalized mathematical expression is as follows:

[0063]

[0064] Among them, X i represents the value of the current sample, X max represents the maximum value of the sample, X min Indicates the minimum sample value.

[0065] refer to Figure 3 ,Step 2: Build a network encryption traffic classification model based on residual network ResNet and time domain convolutional network TCN, extract the spatial features of the data through the ResNet model, and extract the temporal features of the data through the TCN model;

[0066] Step 2.1: Build the ResNet-TCN framework, use the cross loss function to determine the closeness between the actual output (probability) and the expected output (probability), and use the Adam optimizer. The calculation method of cross entropy is as follows:

[0067] H(p,q)=-∑ x (p(x)logq(x)+(1-p(x))log(1-q(x)))

[0068] The learning rate StepLR is adjusted at equal intervals. After each training step_size epoch, the learning rate is adjusted to lr = lr * gamma, with initial lr = 0.005 and gamma = 0.98.

[0069] refer to Figure 3 , Step 2.2, the ResNet residual network is composed of a series of residual blocks, mainly including input layer, convolution layer, pooling layer and fully connected layer. The residual block is composed of two 3*3 convolutional networks connected in series. The input is convolved multiple times, and then the output is added to the input.

[0070] The entire network is constructed by stacking residual blocks and using a shortcut connection method. The shortcut is dimensionally processed by a 1*1 convolution kernel. The output feature matrix shape of the main branch and the shortcut must be the same. The output matrices must be the same to be added. The spatial features are extracted through the ResNet model.

[0071] refer to Figure 4a to Figure 4c , step 2.3, the TCN time-domain convolutional network, its network structure is mainly composed of two layers of dilated causal convolution, weight normalization, activation function ReLU, and Dropout;

[0072] The dilated convolution allows the network to go back to (K-1)d time steps, making the receptive field of each layer grow exponentially. d represents the parameter of the dilated convolution, i represents the i-th level of the network (starting from 0), and d = O(2 i ); In the TCN layer, the dilation coefficients are set to (1, 2, 4, 8).

[0073] Figure 4c In the example above, the last residual connection is a 1*1 convolution block, which enables the network to transfer information across layers and ensure the consistency of input and output. The output is defined as follows:

[0074] H(x)=F(x)+x

[0075] Among them, F(x) represents the output of x after convolution, and x represents the initial input.

[0076] Step 2.4: The TCN temporal convolutional network is used to splice the output of the last layer in the ResNet network together, classify the obtained features using the fully connected classification, and output the prediction results by the softmax function. The data processed by ResNet is used as input and sent to TCN to extract time series features.

[0077] Step 3: Use the sample data as the input of the classification model, and verify the classification effect of the model through the model training and testing process;

[0078] Step 3.1, store the data processed in step 1.4 independently as a csv file;

[0079] Step 3.2, divide the data set into training set, validation set and test set in a ratio of 7:2:1; the validation set is used to adjust the hyperparameters and decide whether to stop training based on whether the model is overfitting;

[0080] Step 3.3: Send the processed data to ResNet to extract spatial features, and send the data processed by ResNet as input to TCN to extract temporal features;

[0081] Step 3.4: Train the model on the training set and adjust the hyperparameters based on the results on the validation set. After the model training is completed, evaluate the final model effect on the test set.

[0082] In the application scenario of the present invention, taking network encrypted traffic as an example, when an encrypted traffic data set is obtained, the data set is first segmented and cleaned to remove the noise caused by data loss and data redundancy in the original data, and normalized, and reconstructed to obtain a csv file, and the data set is divided into a training set, a validation set, and a test set in a ratio of 7:2:1; the training test set and the validation set are sent to the ResNet-TCN model for training, and the validation set is used for training, the validation set is used to adjust the hyperparameters, and finally the model evaluates its performance on the test set.

[0083] The principle of low accuracy and efficiency in identifying encrypted traffic using CNN and RNN in the prior art and the technical principle of this method are explained as follows:

[0084] Ordinary convolutional neural networks (CNNs) have too many overall parameters and require a lot of memory and computing power, which makes the training very slow, and the number of layers must be continuously increased until the entire receptive field is covered. However, as the depth of the network increases, overfitting is prone to occur, and as the network deepens, higher training errors will occur.

[0085] The residual module in the ResNet-TCN model can train deeper networks. The residual module establishes a direct link between the input and output, so that the newly added layer only needs to learn new features based on the original input layer, improving the degradation problem. The modular structure also reduces the design space of the network. The dropout layer added to the module also reduces the amount of computation.

[0086] RNNs cannot perform large-scale parallel processing, so all intermediate results must be saved until the entire task is completed.

[0087] ResNet-TCN can perform large-scale parallel processing, and the training and verification time will be shortened. The dilated causal convolution in the model makes the size of the receptive field more flexible by changing the dilation coefficient, and controls the length of the model. In addition, the propagation path of TCN is different from the time direction of the sequence, which avoids the gradient explosion and gradient vanishing problems that often occur in RNN.

[0088] The 1D ResNet-TCN model can better learn traffic features, because network traffic data is essentially sequential data, a one-dimensional byte stream organized by a hierarchical structure; ResNet is used to learn the spatial features of data, and TCN is used to learn the temporal features of data. Compared with simply learning temporal or spatial features, the classification accuracy and efficiency are guaranteed, and the parameter scale of the model is reduced. The entire model has a clear hierarchical relationship, and the layers are progressive to ensure the expressiveness of the output features.

[0089] From the above description, it can be seen that the present invention improves the accuracy of encrypted traffic identification and classification, achieves higher classification performance, and solves the problems of low accuracy and efficiency of existing encrypted network traffic identification and classification methods using CNN and RNN.

[0090] The above descriptions are only partial embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A method for identifying and classifying encrypted traffic based on a deep learning model, characterized by: The following steps are involved: Step 1: Preprocess the original traffic data to obtain an encrypted traffic data vector used as an input of a network encrypted traffic classification model; Step 2: Build a network encryption traffic classification model based on residual network ResNet and time domain convolutional network TCN; Step 3: Extract the spatial features of encrypted traffic data through the ResNet model; Extract the time characteristics of encrypted traffic data through the TCN model; In the step 2, a ResNet-TCN framework is constructed, and learning and training are performed; The ResNet-TCN framework includes the residual network ResNet and the time domain convolutional network TCN, where: 1) The network structure of the residual network ResNet is based on the data transmission direction, including input layer, convolution layer, multiple residual blocks, pooling layer and fully connected layer; each residual block is composed of two 3*3 convolution networks connected in series; multiple residual blocks are stacked; The input encrypted traffic data is output after multiple convolutions; in the output layer, the output is added to the input; finally, the spatial features of the encrypted traffic data are extracted; 2) The network structure of the time domain convolutional network (TCN) is composed of the first layer of dilated causal convolution, weight normalization, activation function ReLU and Dropout, and the second layer of dilated causal convolution, weight normalization, activation function ReLU and Dropout; the output of the first layer is the input of the second layer; in each layer, according to the data transmission direction, it is dilated causal convolution, weight normalization, activation function ReLU and Dropout; 3) The data processed by ResNet is used as input and sent to TCN to extract time series features; After the output of the last layer of TCN and ResNet is concatenated, the obtained features are classified using the fully connected classification, and the prediction results are output by the softmax function.

2. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 1 is characterized in that The data preprocessing step of step one includes: Step 1.1, import the data in the data set for data processing; the sample data set is a data set of network encrypted traffic data in original format; Step 1.2: Split the original traffic data in the data set; Step 1.3: Clean the segmented data; Step 1.4: Normalize the data; The data is reconstructed and the processed traffic files are sized uniformly according to fixed bytes. If the size is larger than the set fixed bytes, the bytes after that are deleted. If the size is smaller than the fixed bytes, 00 is added to the fixed bytes. Normalization is to transform the data and scale the characteristic values ​​to a specific range to obtain a csv file.

3. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 1 is characterized in that In the residual network ResNet, adjacent residual blocks are connected using shortcuts. The shortcut is dimensionally processed using a 1*1 convolution kernel. The main branch and the shortcut have the same output feature matrix shape and are added together after the output matrix is ​​the same.

4. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 1, characterized in that The output of the last layer of the ResNet network is processed by a 1*1 convolution block and then concatenated with the output of the TCN to be output as the network encrypted traffic classification model.

5. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 1, characterized in that In the step 2, the sample data is used as the input of the network encryption traffic classification model, and the classification effect of the model is verified through the model training and testing process.

6. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 2, Its characteristic is that in the step 2: First, store the data processed in step 1.4 independently as a csv file; Next, the data set is divided into training set, validation set and test set in a ratio of 7:2:

1. The validation set is used to adjust the hyperparameters and determine whether to stop training based on whether the model is overfitting. Then, the data processed in step 1 is sent to ResNet to extract spatial features, and the data processed by ResNet is used as input and sent to TCN to extract temporal features; Finally, the model is trained on the training set, and the hyperparameters are adjusted according to the results on the validation set. After the model training is completed, the final effect of the model is evaluated on the test set.

7. The method for identifying and classifying encrypted traffic based on a deep learning model according to claim 1, characterized in that In the training of the network encrypted traffic classification model, the cross loss function is used to determine the closeness between the actual output and the expected output; The Adam optimizer is used during training; During the learning period of the network encrypted traffic classification model, the learning rate StepLR is adjusted at equal intervals.

Citation Information

Patent Citations

  • Network malicious encrypted traffic identification method and system

    CN112949702A

  • Encrypted network traffic identification and classification method based on deep learning

    CN114257428A