An application identification method, device and equipment

By grouping, aggregating, and filtering the external data representation XDR of the user face, and using a gradient optimization algorithm to determine a preset threshold, the problem of the inability to identify multiple types of user applications in the existing technology is solved, and accurate identification and perception evaluation of user front-end applications are achieved.

CN115993987BActive Publication Date: 2026-07-21CHINA MOBILE GROUP DESIGN INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GROUP DESIGN INST
Filing Date
2021-10-18
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively identify multiple types of user applications, cannot accurately assess the intuitive perception of end users' use of services, and cannot exclude background traffic that does not affect user perception.

Method used

By grouping, aggregating, and filtering external data representations (XDRs) of the user face, and using a gradient optimization algorithm to determine preset thresholds, XDRs related to background advertisements and heartbeats are excluded, forming an analysis process of user-application duration-foreground application, thereby improving the accuracy of front-end application perception assessment.

Benefits of technology

It enables accurate identification and perception assessment of user front-end applications, improving the accuracy of perception of user front-end applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115993987B_ABST
    Figure CN115993987B_ABST
Patent Text Reader

Abstract

The application discloses an application identification method, device and equipment, and the method comprises the following steps: grouping external data representation (XDR) of a user plane to obtain a plurality of XDR groups; performing aggregation processing on XDR in each XDR group in the plurality of XDR groups to obtain aggregated XDR; performing screening on the aggregated XDR to obtain XDR of an application; and identifying the application according to the XDR of the application to obtain an identification result. Through the above method, the beneficial effect of identifying a foreground application is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication service technology, and specifically to an application identification method, apparatus, and device. Background Technology

[0002] For user control plane signaling flows, based on user number information and time sequence, XDRs (External Data Representations) of multiple signaling interfaces are associated, and the content is merged to form an XDR containing information from multiple interfaces. On the other hand, for the association and synthesis of user plane XDRs involving user applications, only page browsing services are involved, and the methods used can only apply special fields of specific protocols. This fails to achieve the synthesis and identification of multiple types of user applications, does not identify user-preferred foreground applications, and does not exclude background traffic that does not affect user experience. Therefore, it cannot accurately evaluate the end-user's actual perception of the service and cannot reflect the user's experience when using foreground applications. Summary of the Invention

[0003] In view of the above problems, embodiments of the present invention are proposed to provide an application identification method, apparatus and device that overcomes or at least partially solves the above problems.

[0004] According to one aspect of the present invention, an application identification method is provided, comprising:

[0005] The external data representation XDR of the user plane is grouped to obtain multiple XDR groups;

[0006] The XDRs in each of the plurality of XDR groups are aggregated to obtain aggregated XDRs;

[0007] The aggregated XDRs are filtered to obtain the applicable XDRs;

[0008] The application is identified based on its XDR, and the identification result is obtained.

[0009] According to another aspect of the present invention, an application identification device is provided, comprising:

[0010] The grouping module is used to group the external data representation XDR of the user plane into multiple XDR groups;

[0011] The aggregation module is used to aggregate the XDRs in each of the plurality of XDR groups to obtain aggregated XDRs;

[0012] The filtering module is used to filter the aggregated XDRs to obtain the applicable XDRs;

[0013] The identification module is used to identify the application based on the application's XDR and obtain the identification result.

[0014] According to another aspect of the present invention, a computing device is provided, comprising: a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other through the communication bus;

[0015] The memory is used to store at least one executable instruction, which causes the processor to perform the operation corresponding to the application identification method described above.

[0016] According to another aspect of the present invention, a computer storage medium is provided, the storage medium storing at least one executable instruction that causes a processor to perform an operation corresponding to the application identification method described above.

[0017] According to the solution provided in the above embodiments of the present invention, multiple XDR groups are obtained by grouping the external data representation (XDR) of the user plane; the XDRs in each of the multiple XDR groups are aggregated to obtain aggregated XDRs; the aggregated XDRs are filtered to obtain the application's XDR; and the application is identified based on the application's XDR to obtain the identification result. This achieves the beneficial effect of identifying applications based on user plane XDRs, improving the accuracy of user perception of foreground applications.

[0018] The above description is merely an overview of the technical solutions of the embodiments of the present invention. In order to better understand the technical means of the embodiments of the present invention and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of the present invention more obvious and understandable, specific implementation methods of the embodiments of the present invention are described below. Attached Figure Description

[0019] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0020] Figure 1 A flowchart of the application identification method provided in an embodiment of the present invention is shown;

[0021] Figure 2 A flowchart illustrating a specific application identification method provided in an embodiment of the present invention is shown;

[0022] Figure 3 This diagram illustrates a polymerized XDR of one application of the method provided in an embodiment of the present invention.

[0023] Figure 4 This invention provides an overall flowchart for determining a preset threshold according to an embodiment of the invention.

[0024] Figure 5 A flowchart illustrating the method for determining a preset threshold provided in an embodiment of the present invention is shown;

[0025] Figure 6 This diagram illustrates the first step of the process for determining the inflection point of a curve according to an embodiment of the present invention.

[0026] Figure 7 This diagram illustrates the second step of the process for determining the inflection point of a curve according to an embodiment of the present invention.

[0027] Figure 8 This diagram illustrates the third step of the process for determining the inflection point of a curve according to an embodiment of the present invention.

[0028] Figure 9 A schematic diagram of the application identification device provided in an embodiment of the present invention is shown;

[0029] Figure 10 A schematic diagram of the structure of a computing device provided in an embodiment of the present invention is shown. Detailed Implementation

[0030] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0031] Figure 1 A flowchart of the application identification method provided in an embodiment of the present invention is shown. Figure 1 As shown, the method includes the following steps:

[0032] Step 11: Group the external data representation (XDR) of the user plane to obtain multiple XDR groups;

[0033] Step 12: Perform aggregation processing on the XDRs in each of the multiple XDR groups to obtain aggregated XDRs;

[0034] Step 13: Filter the converged XDRs to obtain the applicable XDRs;

[0035] Step 14: Identify the application based on its XDR and obtain the identification result.

[0036] In this embodiment, the external data representation (XDR) of the user face is grouped to obtain multiple XDR groups; the XDRs in each of the multiple XDR groups are aggregated to obtain aggregated XDRs; the aggregated XDRs are filtered to obtain application XDRs; based on the application XDRs, the applications are identified to obtain identification results; thus, based on user XDRs as samples, and according to the XDRs of application categories, a gradient optimization algorithm is used to aggregate and correlate them in the spatiotemporal dimensions, which can exclude XDRs related to background advertisements, heartbeats, etc., thereby forming an analysis process from user-application duration-foreground application to preferred application, improving the accuracy of the evaluation of user perception of foreground applications.

[0037] In an optional embodiment of the present invention, step 11 may include:

[0038] Step 111: Group the external data representation (XDR) of the user plane according to the type or subtype of the application to obtain multiple XDR groups.

[0039] Specifically, based on the APP_TYPE and APP_SUBTYPE fields in the XDR, applications with the same type and subtype are grouped together to obtain multiple XDR groups.

[0040] In this embodiment, a user may have multiple concurrent services over a period of time, with applications running in the foreground and heartbeat packets, message reminders, or other background applications running in the background. Since each service is different, it is necessary to group the user's XDR first.

[0041] In another optional embodiment of the present invention, step 12 may include:

[0042] Step 121: Obtain the time interval between two temporally adjacent XDRs in any XDR group among the plurality of XDR groups;

[0043] Step 122: Based on the time interval and the first preset threshold, perform convergence processing on all two adjacent XDRs in each XDR group to obtain converged XDRs.

[0044] In another optional embodiment of the present invention, step 122 may include:

[0045] Step 1225: Based on the time interval and the first preset threshold, perform convergence processing on all adjacent XDRs in each XDR group of all XDR groups to obtain converged XDRs, including:

[0046] Step 1226: If the time interval is less than a first preset threshold, merge the two adjacent XDRs to obtain a new XDR. The start time of the new XDR is the earliest start time of the two adjacent XDRs, and the end time is the latest end time of the two adjacent XDRs. Otherwise, output the first XDR among the two adjacent XDRs. Use the new XDR or the first XDR as the converged XDR.

[0047] like Figure 2 As shown, in this embodiment, the XDRs in any XDR group among the multiple XDR groups need to be sorted in chronological order from first to last, and the XDR data in each group are processed separately in sequence.

[0048] Taking one group of XDRs as an example, the other groups of XDRs will wait for the processing of this group of XDRs to be completed before they are processed. The specific processing steps are as follows:

[0049] First, select the two earliest XDRs in the XDR data of the group according to the time sequence; if there is only one XDR in the group or only the last XDR is left, then directly output the only XDR in the group or the last XDR left, and then directly enter the next group of XDRs for processing.

[0050] Second, calculate the time interval between the two selected XDRs; if the times of the two XDRs overlap, then record the time interval between the two selected XDRs as 0; if the times of the two XDRs do not overlap, then subtract the start time of the previous timestamp from the start time of the later timestamp, and record it as the time interval between the two selected XDRs.

[0051] Third, determine whether the time interval between the two XDRs is less than the first preset threshold; if the time interval between the two XDRs is less than the first preset threshold, then merge the two XDRs to obtain the converged XDR between the two XDRs; if the time interval between the two XDRs is not less than the first preset threshold, then use the previous XDR as the converged XDR; where merging two XDRs means taking the start time of the previous XDR on the timestamp and the end time of the next XDR on the timestamp as the start time and end time of the new converged XDR.

[0052] Fourth, after obtaining the aggregated XDR, if there is still XDR data in the group, return to step one; if there is no XDR data in the group, proceed to process the next group of XDRs until all groups of XDR data have been processed.

[0053] Figure 3The diagram illustrates an aggregated XDR for a game according to an embodiment of the present invention, wherein T is a first preset threshold, specifically 1.5 minutes. The game merges all two XDRs with a time interval of less than 1.5 minutes into one aggregated XDR by using the first preset threshold and the four steps described above.

[0054] In addition, the output aggregated XDR will also record other data after different classes of the same application are merged according to the rules in the above steps, including: session duration, XDR duration, uplink and downlink traffic, etc., but not limited to those mentioned above.

[0055] Figure 4 The following is an overall flowchart of the preset threshold determination provided by an embodiment of the present invention, as shown in the figure. Figure 4 As shown, the preset threshold is determined using a "gradient optimization algorithm". First, a nonlinear regression algorithm is used to convert the discrete sampling points of the first training sample set into a continuous function. Then, an inflection point identification algorithm is used to obtain the inflection point of the function, forming a "gradient optimization algorithm" for determining the optimal threshold value.

[0056] Since it is impossible to obtain information on whether the overall session has ended from the sub-session XDR, it is necessary to determine whether the XDR has ended. This is done by determining whether the arrival time interval of each sub-session XDR in the same session is less than a preset threshold. That is, if no new sub-session XDR arrives after waiting for the preset threshold, then the session is considered to have ended.

[0057] Therefore, it is necessary to accurately determine the optimal preset threshold. The inflection point of the curve is the point where the curve bends significantly, especially from a high slope to a low slope (flat or nearly flat) or other directions. The inflection point is the optimal point for decision-making. For example, when there is an increasing function and a trade-off between revenue (vertical y-axis) and cost (horizontal x-axis): the inflection point is where revenue no longer increases rapidly, where further increases in cost are no longer worthwhile, and where revenue diminishes.

[0058] Therefore, in this embodiment, the inflection point algorithm is used to select the preset threshold during the multi-XDR association and aggregation process. This solves the problem of setting the preset threshold size. It prevents the completeness of the indicator statistics from being affected due to the preset threshold being set too small, resulting in the process of a single session being counted separately for several indicators; or the business behaviors of different sessions being merged due to the preset threshold being set too large, resulting in the calculated application time exceeding the actual usage.

[0059] In another optional embodiment of the present invention, the first preset threshold in step 122 is determined by the following process:

[0060] Step 1221: Obtain the first training sample set, which includes multiple XDRs;

[0061] Step 1222: Using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, we obtain the linear equation: f1(X)=a1X+b1; where a1 and b1 are the coefficients of the linear equation.

[0062] Step 1223: Perform nonlinear regression on the linear equation f1(X) to fit it into a curve equation: Y1=f1(X)=a2X m +b2X m-1 +c2X m-2 +...+d2X+e, where m is a positive integer, a2, b2, c2, d2 are all coefficients of the curve equation Y1, and e is a natural number;

[0063] Specifically, through a nonlinear regression algorithm, the variable X is transformed into (X... 4 ,X 3 ,X 2 By using a regression algorithm, f1(X) is fitted into the curve equation Y1.

[0064] Step 1224: Take the inflection point value of the curve corresponding to Y1 as the first preset threshold value.

[0065] like Figure 5 As shown in this embodiment, if the curve corresponding to Y1 has no inflection point, the distribution of X is analyzed using the cumulative distribution function to ultimately determine the first preset threshold value, as follows:

[0066] First, divide X into several equally divided intervals;

[0067] Second, count the number of samples falling within each interval;

[0068] Third, calculate the cumulative percentage of samples falling within each interval;

[0069] Fourth, the CDF distribution map is obtained, and the point corresponding to the sample percentage of P1% is taken, where P1 is the training result of the first sample.

[0070] An example of choosing the first preset threshold value T1:

[0071] Taking user A's application as an example, the XDR (data points) of application A's business data across all users on the network over multiple days are used as the training sample set. The time interval between the arrival of sub-sessions in the XDR is used as the X-axis, and the cumulative number of samples is used as the Y-axis, resulting in the following: Figure 3The results show that the points represent the arrival time interval distribution of XDR samples for application A, the curve is the fitted curve f(x) obtained by the nonlinear regression algorithm, and the intersection of the two vertical lines is the inflection point T1 position (1.5 minutes) given by the inflection point identification algorithm based on the analysis of f(x). That is, all two XDRs with time intervals less than 1.5 minutes for application A are merged into one XDR, and the aggregated XDR is formed by segmenting and aggregating the XDRs classified in the above steps.

[0072] After processing the segmented and aggregated XDR records, the output includes the start / end time, session duration / XDR duration, uplink / downlink traffic, etc., of the same application size category after being merged according to the above rules.

[0073] In the above embodiments of the present invention, the inflection point of the fitted curve f(t) is defined as the point where the curve bends significantly, particularly when analyzing the curve from a high slope to a low slope (flat or nearly flat) or other directions. Figure 7 The output result f(x) obtained from the regression analysis, Figure 8 To obtain the slope distribution of f(x) by taking the derivative of f(x), from... Figure 8 It is evident that the transition of f'(x) from a high slope to a low slope occurs rapidly within the interval of x (6 to 14), representing the interval where the inflection point lies. From the definition of an inflection point, it can be seen as a turning point where the slope changes from rapid increase to decrease (or in another direction). By analyzing the changes in slope, the location of the inflection point can be identified. Figure 9 Taking the second derivative of f(x), we can see that the slope changes relatively smoothly before and after x in the interval of 6 to 14. A sharp peak appears between 6 and 14, indicating that the slope changes from rapid increase to decrease. The peak value of f(x) is the position of the inflection point.

[0074] In another optional embodiment of the present invention, step 13 may include:

[0075] Step 131: Determine the target converged XDR that is either not in the application's gray list or is in the application's white list;

[0076] Specifically, the gray list of applications is mainly based on broad application categories, which may include: other services, unclassified services, security and antivirus, app stores, MMS, public data traffic, etc., but is not limited to the above. The white list of applications is mainly based on specific application subcategories, which may include: Suikang Code, but is not limited to these.

[0077] Step 132: Obtain the applied XDR based on the duration of the target convergence XDR and the second preset threshold.

[0078] In this embodiment, firstly, an aggregated XDR is taken and filtered according to the gray list or white list of the above application. Aggregated XDRs in the gray list are deleted, while aggregated XDRs in the white list are retained.

[0079] Next, it is determined whether the duration of the converged XDR is greater than the preset threshold T2. If the duration of the converged XDR is greater than the preset threshold, the converged XDR is retained. If the duration of the converged XDR is not greater than the preset threshold, the filtering of the second XDR begins. The second preset threshold may vary for different application categories due to their different business attributes. For example:

[0080] Shopping, navigation, reading, travel, finance, microblogging community: 3 minutes;

[0081] Music, live video, videos, animation: 10 minutes;

[0082] Cloud storage service, browsing and downloading, P2P service: 5 minutes;

[0083] Game: minutes;

[0084] Payment, instant messaging: 0.5 minutes;

[0085] Finally, the aggregated XDRs of the filtered output, which are "XDRs of foreground applications", are aggregated again by application size category tags to obtain the total usage time of each foreground application.

[0086] In another optional embodiment of the present invention, step 14 may include: sorting the total usage time of each user’s foreground application by duration, and outputting the application with the higher duration as the user’s preferred foreground application.

[0087] In another optional embodiment of the present invention, the second preset threshold in step 132 is determined by the following process:

[0088] Step 1321: Obtain the second training sample set, which includes multiple XDRs;

[0089] Step 1322: Using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, we obtain the linear equation: f2(X)=a3X+b3; where a3 and b3 are the coefficients of the linear equation.

[0090] Step 1323: Perform nonlinear regression on the linear equation f2(X) to fit it into a curve equation: Y2=f2(X)=a4X m +b4X m-1 +c4X m-2+...+d4X+e, where m is a positive integer, a4, b4, c4, d4 are the coefficients of the curve equation Y2, and e is a natural number;

[0091] Step 1324: Take the inflection point value of the curve corresponding to Y2 as the second preset threshold value.

[0092] In this embodiment, the second preset threshold operates on the same principle as the first preset threshold. Similarly, if the curve corresponding to Y2 has no inflection point, the distribution of X is analyzed using the cumulative distribution function to ultimately determine the second preset threshold value, as follows:

[0093] First, divide X into several equally divided intervals;

[0094] Second, count the number of samples falling within each interval;

[0095] Third, calculate the cumulative percentage of samples falling within each interval;

[0096] Fourth, the CDF distribution map is obtained, and the point corresponding to the sample size percentage P2% is taken, where P2 is the training result of the second sample.

[0097] In the above embodiments of the present invention, the XDR of large / small application categories is used to perform spatiotemporal dimension aggregation and association, and the XDR related to background advertisements, heartbeats, etc. are excluded, forming an analysis process from user-application duration-foreground application to preferred application, which can improve the accuracy of the evaluation of the user's perception of the foreground application.

[0098] Figure 9 A schematic diagram of the application identification device 90 provided in an embodiment of the present invention is shown. Figure 9 As shown, the device includes:

[0099] Grouping module 91 is used to group the external data representation XDR of the user plane to obtain multiple XDR groups;

[0100] The aggregation module 92 is used to aggregate the XDRs in each XDR group among the plurality of XDR groups to obtain aggregated XDRs;

[0101] The filtering module 93 is used to filter the aggregated XDRs to obtain the applied XDRs;

[0102] The identification module 94 is used to identify the application based on the application's XDR and obtain the identification result.

[0103] Optionally, the grouping module 91 is further configured to group the external data representation (XDR) of the user plane according to the type or subtype of the application to obtain multiple XDR groups.

[0104] Optionally, the aggregation module 92 is further configured to obtain the time interval between two temporally adjacent XDRs in any XDR group among the plurality of XDR groups;

[0105] Based on the time interval and the first preset threshold, all two adjacent XDRs in each XDR group are converged to obtain converged XDRs.

[0106] Optionally, the first preset threshold is determined through the following process:

[0107] Obtain a first training sample set, which includes multiple XDRs;

[0108] Using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, we obtain the linear equation: f1(X)=a1X+b1; where a1 and b1 are the coefficients of the linear equation.

[0109] The linear equation f(X) is subjected to nonlinear regression to fit a curve equation: Y1=f1(X)=a2X m +b2X m-1 +c2X m-2 +...+d2X+e, where m is a positive integer, a2, b2, c2, d2 are all coefficients of the curve equation Y1, and e is a natural number;

[0110] The inflection point value of the curve corresponding to Y1 is taken as the first preset threshold value.

[0111] Optionally, the aggregation module 92 is further configured to, if the time interval is less than a first preset threshold, merge the two adjacent XDRs to obtain a new XDR, wherein the start time of the new XDR is the earliest start time of the two adjacent XDRs and the end time is the latest end time of the two adjacent XDRs; otherwise, output the first XDR among the two adjacent XDRs; and use the new XDR or the first XDR as the aggregated XDR.

[0112] Optionally, the filtering module 93 is further configured to determine the target converged XDR that is not in the application's gray list or is in the application's white list;

[0113] The applied XDR is obtained based on the duration of the target converged XDR and the second preset threshold.

[0114] Optionally, the second preset threshold is determined through the following process:

[0115] Obtain a second training sample set, which includes multiple XDRs;

[0116] Using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, we obtain the linear equation: f2(X)=a3X+b3; where a3 and b3 are the coefficients of the linear equation.

[0117] The linear equation f2(X) is subjected to nonlinear regression to fit a curve equation: Y2=f2(X=a4X m +b4X m -1 +c4X m-2 +...+d4X+e, where m is a positive integer, a4, b4, c4, d4 are the coefficients of the curve equation Y2, and e is a natural number;

[0118] The inflection point value of the curve corresponding to Y2 is taken as the second preset threshold value.

[0119] It should be noted that this embodiment is a device embodiment corresponding to the above method embodiment. All implementation methods in the above method embodiment are applicable to this device embodiment and can achieve the same technical effect.

[0120] This invention provides a non-volatile computer storage medium storing at least one executable instruction that can execute the application identification method in any of the above method embodiments.

[0121] Figure 10 The diagram shows a structural schematic of a computing device provided in an embodiment of the present invention. The specific embodiments of the present invention do not limit the specific implementation of the computing device.

[0122] like Figure 10 As shown, the computing device may include a processor, a communications interface, memory, and a communications bus.

[0123] The processor, communication interface, and memory communicate with each other via a communication bus. The communication interface is used to communicate with other network elements, such as clients or other servers. The processor executes programs, specifically the steps described in the application identification method embodiment for computing devices.

[0124] Specifically, the program may include program code, which includes computer operation instructions.

[0125] The processor may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention. The computing device includes one or more processors, which may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0126] Memory is used to store programs. Memory may include high-speed RAM, and may also include non-volatile memory, such as at least one disk drive.

[0127] Specifically, the program can be used to cause the processor to execute the application identification method in any of the above method embodiments. The specific implementation of each step in the program can be found in the corresponding descriptions of the steps and units in the above application identification method embodiments, and will not be repeated here. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the devices and modules described above can be referred to the corresponding process descriptions in the foregoing method embodiments, and will not be repeated here.

[0128] The algorithms or displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The required structure for constructing such systems is apparent from the above description. Furthermore, the embodiments of the present invention are not directed to any particular programming language. It should be understood that the embodiments of the present invention described herein can be implemented using various programming languages, and the above description of specific languages ​​is for the purpose of disclosing the best mode of implementation of the embodiments of the present invention.

[0129] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0130] Similarly, it should be understood that, in order to streamline the embodiments of the invention and aid in understanding one or more of the various inventive aspects, features of the embodiments of the invention are sometimes grouped together in a single embodiment, figure, or description thereof in the above description of exemplary embodiments of the invention. However, this disclosure should not be construed as reflecting an intention that the claimed embodiments of the invention require more features than are expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of the invention.

[0131] Those skilled in the art will understand that modules in the device of the embodiments can be adaptively changed and placed in one or more devices different from that embodiment. Modules, units, or components in the embodiments can be combined into a single module, unit, or component, and further, they can be divided into multiple sub-modules, sub-units, or sub-components. Except where at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or units of any method or device so disclosed. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.

[0132] Furthermore, those skilled in the art will understand that although some embodiments herein include certain features included in other embodiments but not others, combinations of features from different embodiments are intended to be within the scope of the invention and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.

[0133] The various component embodiments of the present invention can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components according to the embodiments of the present invention. The embodiments of the present invention can also be implemented as device or apparatus programs (e.g., computer programs and computer program products) for performing part or all of the methods described herein. Such programs implementing the embodiments of the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0134] It should be noted that the above embodiments are illustrative of the present invention and not restrictive of the invention, and that those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. Embodiments of the present invention can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be construed as limiting the order of execution.

Claims

1. An application recognition method, characterized in that, The method includes: External data representations (XDRs) on the user plane are grouped according to application type or subtype to obtain multiple XDR groups; The XDRs in each of the plurality of XDR groups are aggregated to obtain aggregated XDRs; The step of performing convergence processing on the XDRs in each of the plurality of XDR groups to obtain converged XDRs further includes: obtaining the time interval between two temporally adjacent XDRs in any XDR group; and performing convergence processing on all two adjacent XDRs in each XDR group according to the time interval and a first preset threshold to obtain converged XDRs. The first preset threshold is determined through the following process: acquiring a first training sample set including multiple XDRs; using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, obtaining a linear equation: f1(X) = a1X + b1; where a1 and b1 are the coefficients of the linear equation; performing nonlinear regression on the linear equation f(X) to fit it into a curve equation: Where m is a positive integer, a2, b2, c2, d2 are all coefficients of the curve equation Y1, and e is a natural number; the inflection point value of the curve corresponding to Y1 is taken as the first preset threshold; The aggregated XDRs are filtered to obtain the applicable XDRs; The step of filtering the converged XDRs to obtain the application's XDR further includes: determining the target converged XDR that is not in the application's gray list or is in the application's white list, and obtaining the application's XDR based on the duration of the target converged XDR and a second preset threshold; The application is identified based on its XDR, and the identification result is obtained.

2. The application identification method according to claim 1, characterized in that, Based on the time interval and a first preset threshold, all two adjacent XDRs in each XDR group of all XDR groups are converged to obtain converged XDRs, including: If the time interval is less than a first preset threshold, the two adjacent XDRs are merged to obtain a new XDR. The start time of the new XDR is the earliest start time of the two adjacent XDRs, and the end time is the latest end time of the two adjacent XDRs. Otherwise, the first XDR of the two adjacent XDRs is output. The new XDR or the first XDR is used as the converged XDR.

3. The application identification method according to claim 1, characterized in that, The second preset threshold is determined through the following process: Obtain a second training sample set, which includes multiple XDRs; Using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, we obtain the linear equation: f2(X)=a3X+b3; where a3 and b3 are the coefficients of the linear equation. The linear equation f2(X) is subjected to nonlinear regression to fit a curve equation: Where m is a positive integer, a4, b4, c4, d4 are all coefficients of the curve equation Y2, and e is a natural number; The inflection point value of the curve corresponding to Y2 is taken as the second preset threshold.

4. An application identification device, characterized in that, The device includes: The grouping module is used to group external data representations (XDRs) on the user plane according to the application type or subtype, resulting in multiple XDR groups. The aggregation module is used to aggregate the XDRs in each of the plurality of XDR groups to obtain aggregated XDRs; The aggregation module is further configured to: obtain the time interval between two temporally adjacent XDRs in any XDR group among the plurality of XDR groups; and perform aggregation processing on all two adjacent XDRs in each XDR group among all XDR groups according to the time interval and a first preset threshold to obtain aggregated XDRs. The first preset threshold is determined through the following process: acquiring a first training sample set including multiple XDRs; using the time interval between the arrival of sub-sessions of each XDR as the X-axis and the cumulative number of XDRs as the Y-axis, obtaining a linear equation: f1(X) = a1X + b1; where a1 and b1 are the coefficients of the linear equation; performing nonlinear regression on the linear equation f(X) to fit it into a curve equation: Where m is a positive integer, a2, b2, c2, d2 are all coefficients of the curve equation Y1, and e is a natural number; the inflection point value of the curve corresponding to Y1 is taken as the first preset threshold; The filtering module is used to filter the aggregated XDRs to obtain the applicable XDRs; The filtering module is further used to: determine the target converged XDR that is not in the application's gray list or is in the application's white list, and obtain the application's XDR based on the duration of the target converged XDR and a second preset threshold; The identification module is used to identify the application based on the application's XDR and obtain the identification result.

5. A computing device, comprising: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction, which causes the processor to perform the operation corresponding to the application identification method as described in any one of claims 1-3.

6. A computer storage medium storing at least one executable instruction that causes a processor to perform an operation corresponding to the application identification method as described in any one of claims 1-3.