A flow identification method, model training method and related devices

By sending VPN software traffic identification models suitable for different regions under the guidance of geographic area information, the cloud server solves the problem of inaccurate VPN traffic identification in the existing technology, realizes region-specific traffic identification, and improves the identification effect and user experience.

CN116016364BActive Publication Date: 2025-09-30SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211725549.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-09-30
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

Existing VPN traffic identification models do not consider the differences in traffic characteristics in different regions, resulting in poor identification results and a poor user experience.

Method used

Under the guidance of geographic area information, the cloud server sends the VPN software traffic identification model of the corresponding region, and receives regional traffic for identification based on the model. Traffic collection and model training are performed in multiple pre-selected regions in advance to obtain VPN software traffic identification models suitable for each region.

Benefits of technology

It achieves precise identification based on differences in regional characteristics, improving the accuracy of VPN traffic identification and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116016364B_ABST
    Figure CN116016364B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a traffic identification method, a model training method, and related devices, which are applied to a traffic management system deployed in a preselected area. The traffic identification method includes: sending geographic area information to a cloud server to instruct the cloud server to issue a virtual private network (VPN) software traffic identification model corresponding to the geographic area information based on the geographic area information; receiving the VPN software traffic identification model sent by the cloud server; and receiving the traffic in the area corresponding to the geographic area information based on the VPN software traffic identification model to identify the traffic sent by the VPN software.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the VPN field, and in particular to a traffic identification method, a model training method, and related devices. Background Art

[0002] A virtual private network (VPN) is defined as a temporary, secure connection established over a public network (usually the Internet). It's a secure, stable tunnel through a chaotic public network and a dedicated data communications network technology. To identify VPN traffic for a specific version of VPN software, existing solutions rely on a fixed traffic identification model.

[0003] However, traffic characteristics vary in different regions, and existing solutions do not take these differences into account. Therefore, the traffic identification model in existing solutions has poor and inaccurate identification of VPN traffic, resulting in a poor user experience. Summary of the Invention

[0004] The embodiments of the present application provide a traffic identification method, a model training method and related devices.

[0005] A traffic identification method is applied to a traffic management system deployed in a preselected area, the method comprising:

[0006] Sending the geographic area information to a cloud server to instruct the cloud server to issue a virtual private network (VPN) software traffic identification model corresponding to the geographic area information based on the geographic area information;

[0007] Receiving the VPN software traffic identification model sent by the cloud server;

[0008] The traffic of the region corresponding to the geographic area information is received based on the VPN software traffic identification model to identify the traffic sent by the VPN software.

[0009] Optionally, the traffic management system includes a collector, the collector includes a crawler module and the VPN software, and the method further includes the following steps applied to the collector:

[0010] Starting the VPN software according to the received VPN software startup command;

[0011] Access the website through the crawler module and monitor the access traffic to generate monitoring traffic;

[0012] Determine the source port number of the VPN software through the process name of the VPN software;

[0013] Based on the monitored traffic, identifying the traffic generated by the VPN software according to the source port number, and marking the traffic generated by the VPN software with a VPN traffic label;

[0014] The traffic generated by the VPN software is uploaded to the cloud server, so that a VPN software traffic recognition model suitable for the preselected region is trained by the cloud server.

[0015] A model training method, comprising:

[0016] Based on the cloud server, traffic characteristics of the virtual private network (VPN) collected traffic corresponding to multiple pre-selected regions are obtained;

[0017] Training based on the traffic characteristics to obtain VPN software traffic identification models corresponding to the plurality of pre-selected regions;

[0018] The VPN software traffic identification model is uploaded to the cloud server.

[0019] Optionally, also include:

[0020] VPN software traffic identification model for each pre-selected region:

[0021] Based on the cloud server, obtaining new current VPN traffic characteristics;

[0022] Obtaining the latest current VPN software traffic identification model, where the current VPN software traffic identification model is a model trained in a previous model training cycle;

[0023] detecting the current VPN software traffic identification model according to the current VPN traffic characteristics to determine whether the current VPN software traffic identification model is invalid;

[0024] If it is not invalid, after the first time interval, return to the step of obtaining a new current VPN traffic feature based on the cloud server and continue to execute;

[0025] If it has failed, training is performed based on the current VPN traffic characteristics to update the current VPN software traffic identification model.

[0026] Optionally, the performing training based on the current VPN traffic characteristics and updating the current VPN software traffic identification model includes:

[0027] Determining VPN traffic characteristics within a time window of a second duration, wherein the time window includes the current VPN traffic characteristics;

[0028] The current VPN software traffic identification model is updated based on VPN traffic characteristics within the time window.

[0029] A traffic identification device is applied to a traffic management system deployed in a preselected area, the device comprising:

[0030] a sending unit, configured to send the geographical area information to a cloud server, so as to instruct the cloud server to send a virtual private network (VPN) software traffic identification model corresponding to the geographical area information according to the geographical area information;

[0031] a receiving unit, configured to receive the VPN software traffic identification model sent by the cloud server;

[0032] The identification unit is configured to receive traffic of the region corresponding to the geographic area information based on the VPN software traffic identification model to identify traffic sent by the VPN software.

[0033] A model training device, comprising:

[0034] A feature unit is used to obtain, based on a cloud server, traffic features of virtual private networks (VPNs) collected from multiple pre-selected regions.

[0035] A training unit, configured to obtain VPN software traffic identification models corresponding to the plurality of preselected regions through training based on the traffic characteristics;

[0036] The uploading unit is used to upload the VPN software traffic identification model to the cloud server.

[0037] A flow identification device, comprising:

[0038] CPU, memory and input / output interfaces;

[0039] The memory is a transient storage memory or a persistent storage memory;

[0040] The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the aforementioned method.

[0041] A model training device, comprising:

[0042] CPU, memory and input / output interfaces;

[0043] The memory is a transient storage memory or a persistent storage memory;

[0044] The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the aforementioned method.

[0045] A computer-readable storage medium includes instructions. When the instructions are executed on a computer, the computer is caused to execute the aforementioned method.

[0046] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:

[0047] The geographic region information is sent to a cloud server, which then receives a VPN software traffic identification model from the cloud server. Traffic from the region corresponding to the geographic region information is then received based on the VPN software traffic identification model to identify traffic sent by the VPN software. Traffic is collected in multiple preselected regions to train VPN software traffic identification models for each region. Based on the geographic region information, the cloud server then sends the VPN software traffic identification model for the corresponding region, which is then used to identify VPN software traffic. This approach takes into account the varying traffic characteristics of different regions, generating corresponding models for each region to achieve effective and accurate traffic identification, providing a better user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 A schematic diagram of an embodiment of the traffic identification method of the present application;

[0049] Figure 2 This is a schematic diagram of an embodiment of the model training method of this application;

[0050] Figure 3 This is the overall structure diagram of this application;

[0051] Figure 4 This is a schematic diagram of the collector structure of this application;

[0052] Figure 5 This is a schematic diagram of the model training part of this application;

[0053] Figure 6 This is a schematic diagram of another embodiment of the present application;

[0054] Figure 7 An example schematic diagram is provided for updating the model of this application;

[0055] Figure 8 Update another embodiment diagram of the model of this application;

[0056] Figure 9 This is a schematic diagram of another embodiment of the traffic identification method of the present application;

[0057] Figure 10 This is a schematic diagram of another embodiment of the traffic identification method of the present application;

[0058] Figure 11 This is a schematic diagram of another embodiment of the model training method of the present application;

[0059] Figure 12 This is a schematic diagram of another embodiment of the model training method of the present application. DETAILED DESCRIPTION

[0060] The embodiments of the present application provide a traffic identification method, a model training method and related devices.

[0061] Existing solutions use a fixed traffic identification model to identify VPN traffic. However, this results in poor and inaccurate VPN traffic identification. To address these issues, the traffic identification method, model training method, and related devices provided in this application can directly or indirectly address these issues, providing a better user experience.

[0062] The following describes the traffic identification method, model training method and related devices of this application. Figure 1 An embodiment of the traffic identification method of the present application is applied to a traffic management system deployed in a preselected area, including:

[0063] 101. Sending the geographic area information to the cloud server to instruct the cloud server to issue a virtual private network (VPN) software traffic identification model corresponding to the geographic area information based on the geographic area information;

[0064] The geographic region information is sent to the cloud server so that the cloud server can send the VPN software traffic identification model corresponding to the geographic region information. Specifically, there may be multiple pre-selected regions, each with its own corresponding geographic region information. The geographic region information of the desired region is sent to the cloud server to instruct the cloud server to find the corresponding pre-trained VPN software traffic identification model.

[0065] 102. Receive the VPN software traffic identification model sent by the cloud server;

[0066] Receive the VPN software traffic identification model sent by the cloud server. Specifically, the cloud server finds the model corresponding to the geographic area information and sends the VPN software traffic identification model. In this way, the VPN software traffic identification model for the required area can be obtained.

[0067] 103. Receive traffic from a region corresponding to the geographic region information based on a VPN software traffic identification model to identify traffic sent by the VPN software.

[0068] The VPN software traffic identification model receives traffic from the region corresponding to the geographic region information to identify traffic sent by the VPN software. The VPN software traffic identification model corresponds to the geographic region information and is a region-specific model. Using this model for VPN traffic identification is effective.

[0069] In this embodiment of the present application, geographic region information is sent to a cloud server, which then receives a VPN software traffic identification model from the cloud server. Traffic in the region corresponding to the geographic region information is then received based on the VPN software traffic identification model to identify traffic sent by the VPN software. Traffic is collected in multiple preselected regions to train VPN software traffic identification models for each region. Based on the geographic region information, the cloud server then sends the VPN software traffic identification model for each region, which is then used to identify VPN software traffic. This takes into account the varying traffic characteristics of different regions, obtaining corresponding models for each region to achieve effective and accurate traffic identification, providing a better user experience.

[0070] See also Figure 2 , an embodiment of the model training method of the present application includes:

[0071] 201. Based on the cloud server, obtain traffic characteristics of virtual private networks (VPNs) corresponding to multiple pre-selected regions;

[0072] Based on the cloud server, traffic characteristics of VPN collected traffic corresponding to multiple pre-selected regions are obtained. Specifically, the latest VPN collected traffic corresponding to each pre-selected region can be downloaded from the cloud server, and then feature extraction can be performed on the VPN collected traffic to obtain corresponding traffic characteristics. These traffic characteristics are stored in a database, and relevant information is compiled. Alternatively, during the collection process, the cloud server does not receive the VPN collected traffic itself, but rather the traffic characteristics obtained through feature extraction. The traffic characteristics corresponding to each pre-selected region are then directly obtained from the cloud server.

[0073] 202. Training based on traffic characteristics to obtain VPN software traffic identification models corresponding to multiple pre-selected regions;

[0074] Based on traffic characteristics, VPN software traffic identification models corresponding to multiple pre-selected regions are trained. Traffic characteristics corresponding to each pre-selected region are obtained, and then a corresponding VPN software traffic identification model is trained based on these traffic characteristics. Specifically, the model is trained using traffic characteristics within the first time window to obtain the VPN software traffic identification model. The time window can be defined as needed and is not specifically limited here.

[0075] 203. Upload the VPN software traffic identification model to the cloud server.

[0076] After obtaining the VPN software traffic identification model, upload it to a cloud server. Alternatively, upload it to a network disk or a selected server and distribute it to different terminals based on demand. The specifics are not limited here.

[0077] In this embodiment, after obtaining traffic characteristics from a cloud server, a VPN software traffic identification model is trained based on these characteristics. Finally, the VPN software traffic identification models corresponding to multiple pre-selected regions are uploaded to the cloud server. By training the traffic characteristics corresponding to each pre-selected region, a VPN software traffic identification model corresponding to each region is generated. This allows for the consideration of the varying traffic characteristics of different regions, enabling the training of corresponding models by region. This ensures effective and accurate traffic identification in the subsequent traffic identification process, providing a better user experience.

[0078] The traffic identification method and model training method of this application are described in detail below.

[0079] See also Figure 3 The overall architecture of this application is primarily divided into a data collection component and a model training component. The data collection component comprises collectors within the traffic management system. Collectors are deployed in multiple preselected regions. These local collectors regularly collect non-VPN and VPN traffic data and transmit the collected data to the model training component. The training server data model training component utilizes traffic from various locations to train the optimal VPN software traffic recognition model for each region.

[0080] See also Figure 4 The collector of this application is also called a host machine, which includes a main control unit, a crawler unit and an upload unit. The main control unit is used to control the other two units, as well as some basic operations such as traffic deletion and computer restart. The crawler unit is used to control the opening and closing of the VPN software and the switching of the VPN protocol, as well as random access to the website and traffic monitoring. The upload unit is mainly used to upload tagged traffic data. The host machine is an isolated component deployed in a physical host (such as a virtual machine or container). Each host machine can deploy one or more VPN software. In this embodiment, the collector collects traffic on a daily basis.

[0081] See also Figure 5The model training part of this application includes data download, data processing, failure detection, and model construction. Specifically, the traffic collected by the collector is uploaded to a network disk or cloud server. After obtaining the traffic from the network disk or cloud server, feature extraction is performed, and then preprocessing is performed to detect model failures. If failure occurs, proportional sampling is performed to train a qualified model.

[0082] See also Figure 6 , another embodiment of the present application includes:

[0083] 601. Start the VPN software according to the received VPN software start command;

[0084] Start the VPN software according to the received VPN software startup command. Specifically, the collector in the traffic management system receives the VPN software startup command and starts the specified VPN software and VPN protocol according to the parameters in the startup command. The VPN software can be automatically started according to the absolute path or relative path of the VPN software, and the specific path is not limited here. For the modification of the VPN protocol, it is necessary to adapt it according to different VPN software. When facing VPN software with a plain text protocol configuration file, the file can be directly modified to modify the protocol. When facing VPN software with a ciphertext protocol configuration file, the keyboard and mouse operations can be simulated to modify the protocol. In addition, after the VPN software is started, port monitoring, traffic monitoring and website crawling will be started at the same time.

[0085] 602. Access the website through the crawler module and monitor the access traffic to generate monitoring traffic;

[0086] After the crawler module is activated, it accesses the website and monitors the access traffic to generate monitoring traffic. Tools (Selenium + Chromedriver) can be used to randomly access various websites to generate access traffic. Simultaneously, the access traffic is monitored to obtain monitoring traffic, which is stored in the form of a PCAP file. Specifically, the VPN software protocol's a priori characteristics can be used to monitor and obtain monitoring traffic. For example, some protocols only have TCP flows, and some protocols have port number 443. The a priori characteristics can be converted into Berkeley Packet Filter (BPF) statements for monitoring to reduce the amount of traffic.

[0087] 603. Determine the source port number of the VPN software based on the process name of the VPN software;

[0088] Determine the VPN software's source port number using its process name. Specifically, first find the corresponding process identification number (PID) based on the VPN software's process name. Then, use the PID to find the source port number requested by the process. Record the port's open and close timestamps based on a preset polling period. This polling period can have multiple, identical or different periods, such as a second-per-second polling mode. This ultimately creates a JSON-formatted file containing a list of source port numbers and their corresponding timestamps.

[0089] 604. Based on the monitored traffic, identify the traffic generated by the VPN software according to the source port number, and add a VPN traffic label to the traffic generated by the VPN software;

[0090] Based on the monitored traffic, VPN software traffic is identified based on the source port number and a VPN traffic label is added to the traffic. Specifically, the monitored traffic is filtered based on the source port number and corresponding timestamp data. VPN software traffic, which is stored in a PCAP format file, is then labeled with the corresponding VPN traffic label. Labels are divided into primary and secondary labels. Primary labels indicate whether the traffic is VPN traffic, while secondary labels indicate other traffic attributes, such as the VPN software name, date, or location.

[0091] 605. Uploading the traffic generated by the VPN software to the cloud server so that the cloud server can train a VPN software traffic recognition model suitable for the preselected region;

[0092] The traffic generated by the VPN software is uploaded to the cloud server, so that the cloud server can train a VPN software traffic recognition model suitable for the pre-selected region. Specifically, the traffic can be uploaded to the cloud server using a shared folder to provide the prerequisites for subsequent model training.

[0093] 606. Based on the cloud server, obtain traffic characteristics of the virtual private network (VPN) collected traffic corresponding to the plurality of pre-selected regions;

[0094] Based on the cloud server, traffic characteristics of VPN collected traffic corresponding to multiple pre-selected regions are obtained. Specifically, the latest VPN collected traffic corresponding to each pre-selected region can be downloaded from the cloud server, and then feature extraction can be performed on the VPN collected traffic to obtain corresponding traffic characteristics. These traffic characteristics are stored in a database, and relevant information is compiled. Alternatively, during the collection process, the cloud server does not receive the VPN collected traffic itself, but rather the traffic characteristics obtained through feature extraction. The traffic characteristics corresponding to each pre-selected region are then directly obtained from the cloud server.

[0095] 607. Train the traffic characteristics to obtain VPN software traffic identification models corresponding to the preselected regions.

[0096] Based on traffic characteristics, VPN software traffic identification models corresponding to multiple pre-selected regions are trained. Traffic characteristics corresponding to each pre-selected region are obtained, and then a corresponding VPN software traffic identification model is trained based on these traffic characteristics. Specifically, the model is trained using traffic characteristics within the first time window to obtain the VPN software traffic identification model. The time window can be defined as needed and is not specifically limited here.

[0097] 608. Upload the VPN software traffic identification model to the cloud server;

[0098] After obtaining the VPN software traffic identification model, upload it to a cloud server. Alternatively, upload it to a network disk or a selected server and distribute it to different terminals based on demand. The specifics are not limited here.

[0099] 609. Determine whether to update the current VPN software traffic identification model based on the new current VPN traffic characteristics;

[0100] Based on the new current VPN traffic characteristics, a decision is made as to whether to update the current VPN software traffic identification model. Furthermore, based on the cloud server, new current VPN traffic characteristics are obtained. The latest current VPN software traffic identification model is obtained, wherein the current VPN software traffic identification model is the model obtained by training in the previous model training cycle. The current VPN software traffic identification model is then tested based on the current VPN traffic characteristics to determine whether the current VPN software traffic identification model has expired. If it has not expired, the current VPN software traffic identification model is not processed, and new current VPN traffic characteristics are obtained again after a first time interval. If it has expired, the VPN traffic characteristics within a time window of a second time window are determined, wherein the time window includes the current VPN traffic characteristics. Based on the VPN traffic characteristics within the time window, the current VPN software traffic identification model is then updated.

[0101] Specifically, after downloading the new current VPN traffic characteristics, the latest locally stored VPN software traffic identification model is tested for failure using the current VPN traffic characteristics. Pre-set evaluation metrics are used to determine whether the model is failure-free, such as whether the false alarm rate is above 90%. If the model is not failure-free, it continues to be used. If it is failure-free, the model is marked as failure and the identification results are saved to the log. The test log is then checked to see if any models are marked as failure-free. Furthermore, the model is checked to see if the traffic characteristics meet the number of days in the time window but the corresponding model has not been trained. The model to be trained is added to the training list. For each model to be trained, traffic characteristics from different dates within the required range are sampled at a preset ratio based on the corresponding time window, traffic characteristics, and related information. After sampling, a dataset is constructed and the model is trained using the dataset within the preset parameter range. The parameter information is saved. The trained VPN software traffic identification model is evaluated. If any metrics are poor, such as a detection rate below 95%, the training parameter range and the flow ratio for different dates are adjusted, and the model training is rescheduled until training is complete. After training is completed, the VPN software traffic identification model is uploaded to the cloud server.

[0102] The following provides two specific methods for updating the VPN software traffic identification model.

[0103] 1. Please refer to Figure 7 t represents a time window and the corresponding range of traffic characteristics, and d represents the traffic characteristics for a day. First, the first model, model1, is trained using the traffic characteristics of the first time window, t1. In steps ①, ②, and ③, model1 is the latest, current model. In step ①, the latest traffic characteristics are d1. Model1 is tested using d1. If the detection rate and false alarm rate of model1 for d1 exceed the preset threshold, model1 remains the latest model. In step ②, the latest traffic characteristics are d2. Model1 is tested using d2. If the detection rate and false alarm rate of model1 for d2 remain above the preset threshold, model1 remains the latest model. In step ③, di is the latest traffic characteristics. Model1 is tested using di. If the detection rate and false alarm rate of model1 for di remain below the preset threshold, model1 is no longer the latest model starting from step ④. Next, in step ④, the time window is slid, and the latest time window, t2, including di, is used to train the latest model, model2. In step ⑤, the latest traffic characteristics are the new d1, and the latest model is model2. The above process is repeated and will not be further described here.

[0104] 2. Please refer to Figure 8t represents a time window and the corresponding range of traffic characteristics, and trainingperiod represents a training cycle. First, the first model, model1, is trained using the traffic characteristics of the first time window, t1. Then, after one training cycle, the time window automatically slides to cover the latest traffic characteristics, forming the second time window, t2. The traffic characteristics within t2 are then used to train model2. Then, after another training cycle, the third time window, t3, is trained to obtain model3. This is followed by t4 and model4, and so on. This is not detailed here.

[0105] 610. Send the geographic area information to the cloud server to instruct the cloud server to issue a virtual private network (VPN) software traffic identification model corresponding to the geographic area information based on the geographic area information;

[0106] The geographic region information is sent to the cloud server so that the cloud server can send the VPN software traffic identification model corresponding to the geographic region information. Specifically, there may be multiple pre-selected regions, each with its own corresponding geographic region information. The geographic region information of the desired region is sent to the cloud server to instruct the cloud server to find the corresponding pre-trained VPN software traffic identification model.

[0107] 611. Receive the VPN software traffic identification model sent by the cloud server;

[0108] Receive the VPN software traffic identification model sent by the cloud server. Specifically, the cloud server finds the model corresponding to the geographic area information and sends the VPN software traffic identification model. In this way, the VPN software traffic identification model for the required area can be obtained.

[0109] 612. Receive traffic from the region corresponding to the geographic area information based on the VPN software traffic identification model to identify traffic sent by the VPN software.

[0110] The VPN software traffic identification model receives traffic from the region corresponding to the geographic region information to identify traffic sent by the VPN software. The VPN software traffic identification model corresponds to the geographic region information and is a region-specific model. Using this model for VPN traffic identification is effective.

[0111] In this embodiment, after training models for each geographic region, the geographic region information is sent to a cloud server, which then receives a VPN software traffic identification model from the cloud server. Traffic in the region corresponding to the geographic region information is then received based on the VPN software traffic identification model to identify traffic sent by the VPN software. Traffic is collected in multiple preselected regions to train VPN software traffic identification models for each region. Based on the geographic region information, the cloud server then sends the VPN software traffic identification model for each region. VPN software traffic identification is then achieved using these models. This approach takes into account the varying traffic characteristics of different regions, deriving corresponding models for each region to achieve effective and accurate traffic identification, providing a better user experience.

[0112] The flow identification device and model training device of this application are described below. Figure 9 An embodiment of the traffic identification device of the present application is applied to a traffic management system deployed in a preselected area, and the device includes:

[0113] The sending unit 901 is configured to send the geographical area information to the cloud server, so as to instruct the cloud server to send a virtual private network (VPN) software traffic identification model corresponding to the geographical area information according to the geographical area information;

[0114] A receiving unit 902 is configured to receive the VPN software traffic identification model sent by the cloud server;

[0115] The identification unit 903 is configured to receive traffic of the region corresponding to the geographic area information based on the VPN software traffic identification model to identify traffic sent by the VPN software.

[0116] In this embodiment of the present application, a sending unit 901 transmits geographic region information to a cloud server, causing a receiving unit 902 to receive a VPN software traffic identification model sent by the cloud server. Subsequently, an identification unit 903 receives traffic from the region corresponding to the geographic region information based on the VPN software traffic identification model to identify traffic sent by the VPN software. Traffic is collected in multiple preselected regions to train VPN software traffic identification models for the corresponding regions. Then, based on the geographic region information, the cloud server transmits the VPN software traffic identification model for the corresponding region. This model is then used to identify VPN software traffic. This takes into account the varying traffic characteristics of different regions, obtaining corresponding models by region to achieve effective and accurate traffic identification, providing a better user experience.

[0117] The functions and processes performed by each unit in the flow identification device of this embodiment are the same as those described above. Figure 1 、 Figure 3、 Figure 4 and Figure 6 The functions and processes performed by the medium flow identification device are similar and will not be repeated here.

[0118] Figure 10 It is a structural diagram of a flow identification device provided in an embodiment of the present application. The flow identification device 1000 may include one or more central processing units (CPU) 1001 and a memory 1005, and the memory 1005 stores one or more applications or data.

[0119] Memory 1005 can be volatile or persistent storage. The program stored in memory 1005 can include one or more modules, each of which can include a series of instruction operations on the flow identification device. Furthermore, the central processing unit 1001 can be configured to communicate with memory 1005 and execute the series of instruction operations in memory 1005 on the flow identification device 1000.

[0120] The traffic identification device 1000 may also include one or more power supplies 1002, one or more wired or wireless network interfaces 1003, one or more input and output interfaces 1004, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0121] The CPU 1001 can execute the aforementioned Figure 1 、 Figure 3 、 Figure 4 and Figure 6 The operations performed by the flow identification device in the illustrated embodiment will not be described in detail here.

[0122] See also Figure 11 , an embodiment of the model training device of the present application includes:

[0123] The feature unit 1101 is used to obtain, based on the cloud server, traffic features of the virtual private network (VPN) collected traffic corresponding to the plurality of pre-selected regions;

[0124] A training unit 1102 is configured to obtain VPN software traffic identification models corresponding to the plurality of preselected regions through training based on the traffic characteristics;

[0125] The uploading unit 1103 is configured to upload the VPN software traffic identification model to the cloud server.

[0126] In this embodiment, after the feature unit 1101 obtains traffic features from the cloud server, the training unit 1102 trains the VPN software traffic identification model based on the traffic features to generate a VPN software traffic identification model. Finally, the upload unit 1103 uploads the VPN software traffic identification models corresponding to multiple pre-selected regions to the cloud server. By training the VPN software traffic identification models for each pre-selected region, the model corresponding to each region is generated. This allows for the consideration of the varying traffic features in different regions, enabling the training of models based on the region. This ensures effective and accurate traffic identification in the subsequent traffic identification process, providing a better user experience.

[0127] The functions and processes performed by each unit in the model training device of this embodiment are the same as those in the aforementioned Figure 2 、 Figure 3 、 Figure 5 、 Figure 6 、 Figure 7 and Figure 8 The functions and processes performed by the model training device are similar and will not be repeated here.

[0128] Figure 12 It is a structural diagram of a model training device provided in an embodiment of the present application. The model training device 1200 may include one or more central processing units (CPU) 1201 and a memory 1205, and the memory 1205 stores one or more applications or data.

[0129] Memory 1205 may be volatile or persistent storage. The program stored in memory 1205 may include one or more modules, each of which may include a series of instruction operations in the model training device. Furthermore, central processing unit 1201 may be configured to communicate with memory 1205 and execute the series of instruction operations in memory 1205 on model training device 1200.

[0130] The model training device 1200 may also include one or more power supplies 1202, one or more wired or wireless network interfaces 1203, one or more input and output interfaces 1204, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0131] The CPU 1201 can execute the aforementioned Figure 2 、 Figure 3 、 Figure 5 、 Figure 6 、 Figure 7 and Figure 8The operations performed by the model training device in the illustrated embodiment will not be described in detail here.

[0132] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0133] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0134] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0135] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0136] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A flow identification method, characterized in that: Applied to a traffic management system deployed in a preselected area, the method comprises: Sending the geographic area information to a cloud server to instruct the cloud server to issue a virtual private network (VPN) software traffic identification model corresponding to the geographic area information based on the geographic area information; Receiving the VPN software traffic identification model sent by the cloud server; The traffic of the region corresponding to the geographic area information is received based on the VPN software traffic identification model to identify the traffic sent by the VPN software.

2. The flow identification method according to claim 1, characterized in that: The traffic management system includes a collector, which includes a crawler module and the VPN software. The method further includes the following steps applied to the collector: Starting the VPN software according to the received VPN software startup command; Access the website through the crawler module and monitor the access traffic to generate monitoring traffic; Determine the source port number of the VPN software through the process name of the VPN software; Based on the monitored traffic, identifying the traffic generated by the VPN software according to the source port number, and marking the traffic generated by the VPN software with a VPN traffic label; The traffic generated by the VPN software is uploaded to the cloud server, so that a VPN software traffic recognition model suitable for the preselected region is trained by the cloud server.

3. A model training method, characterized in that: include: Based on a cloud server, traffic characteristics of virtual private networks (VPNs) corresponding to the plurality of pre-selected regions are obtained, wherein the cloud server is the cloud server involved in the traffic identification method according to claim 1; Training based on the traffic characteristics to obtain VPN software traffic identification models corresponding to the plurality of pre-selected regions; Uploading the VPN software traffic identification model to the cloud server; The method of obtaining traffic characteristics of virtual private network (VPN) traffic corresponding to a plurality of pre-selected regions based on a cloud server includes: The VPN collected traffic corresponding to each of the preselected regions is downloaded from the cloud server, and features of the VPN collected traffic are extracted to obtain corresponding traffic features.

4. The model training method according to claim 3, characterized in that Also includes: VPN software traffic identification model for each pre-selected region: Based on the cloud server, obtaining new current VPN traffic characteristics; Obtaining the latest current VPN software traffic identification model, where the current VPN software traffic identification model is a model trained in a previous model training cycle; detecting the current VPN software traffic identification model according to the current VPN traffic characteristics to determine whether the current VPN software traffic identification model is invalid; If it is not invalid, after the first time interval, return to the step of obtaining a new current VPN traffic feature based on the cloud server and continue to execute; If it has failed, training is performed based on the current VPN traffic characteristics to update the current VPN software traffic identification model.

5. The model training method according to claim 4, characterized in that The training based on the current VPN traffic characteristics and updating the current VPN software traffic identification model includes: Determining VPN traffic characteristics within a time window of a second duration, wherein the time window includes the current VPN traffic characteristics; The current VPN software traffic identification model is updated based on VPN traffic characteristics within the time window.

6. A flow identification device, characterized in that: Applicable to a traffic management system deployed in a preselected area, the device comprises: a sending unit, configured to send the geographical area information to a cloud server, so as to instruct the cloud server to send a virtual private network (VPN) software traffic identification model corresponding to the geographical area information according to the geographical area information; a receiving unit, configured to receive the VPN software traffic identification model sent by the cloud server; The identification unit is configured to receive traffic of the region corresponding to the geographic area information based on the VPN software traffic identification model to identify traffic sent by the VPN software.

7. A model training device, characterized in that: include: a feature unit, configured to obtain, based on a cloud server, traffic features of virtual private networks (VPNs) collected from a plurality of preselected regions, wherein the cloud server is the cloud server involved in the traffic identification method according to claim 1; A training unit, configured to obtain VPN software traffic identification models corresponding to the plurality of preselected regions through training based on the traffic characteristics; an uploading unit, configured to upload the VPN software traffic identification model to the cloud server; The method of obtaining traffic characteristics of virtual private network (VPN) traffic corresponding to a plurality of pre-selected regions based on a cloud server includes: The VPN collected traffic corresponding to each of the preselected regions is downloaded from the cloud server, and features of the VPN collected traffic are extracted to obtain corresponding traffic features.

8. A flow identification device, characterized in that: include: CPU, memory and input / output interfaces; The memory is a transient storage memory or a persistent storage memory; The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the method according to any one of claims 1 to 2.

9. A model training device, characterized in that: include: CPU, memory and input / output interfaces; The memory is a transient storage memory or a persistent storage memory; The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the method according to any one of claims 3 to 5.

10. A computer-readable storage medium, characterized in that The method comprises instructions, which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 5.