A method for detecting spoofed communication traffic based on semantic aggregation model of directed heterogeneous graph

Through a camouflage communication traffic detection method based on the semantic aggregation model of directed heterogeneous graphs, combined with a multi-head graph self-attention network and deep learning model, the problem of difficulty in detecting camouflage communication traffic in the existing technology is solved, and higher recognition accuracy and network security supervision are achieved.

CN116032560BActive Publication Date: 2025-05-13NANJING UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211608242.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-14
Publication Date
2025-05-13
Estimated Expiration
2042-12-14

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and identify illegal encryption agents and malware that utilize camouflage communication technology, especially in the context of technologies such as Transport Layer Security Protocol (TLS), Virtual Private Network (VPN), and Anonymous Communication Technology (Tor). These camouflage communication tools make traditional traffic analysis technologies difficult to play a role.

Method used

The camouflage communication traffic detection method based on the directed heterogeneous graph semantic aggregation model is adopted. By extracting the spatiotemporal and spatial dimensional features of the camouflage communication traffic and combining the deep learning model of the multi-head graph self-attention network, the suspicious semantic model of the camouflage communication target is carried out from three levels: message format, behavioral form, and environmental semantics, the comprehensive judgment of camouflage communication detection is realized.

Benefits of technology

This method can deeply explore the multi-dimensional spatiotemporal characteristics of traffic, improve the recognition accuracy of camouflage communication traffic, enhance the supervision of illegal encryption agents and malware, and effectively maintain network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032560B_ABST
    Figure CN116032560B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for detecting disguised communication traffic based on a directed heterogeneous graph semantic convergence model, the method comprising: extracting data packet length sequences, inter-packet delay sequences, and adjacent packet load frequency domain vector similarity sequences for disguised communication traffic samples, and constructing an overall feature matrix of traffic samples; constructing a traffic structure graph based on a KNN algorithm, and realizing the identification of disguised traffic in combination with a multi-head graph self-attention convolutional neural network model; constructing a hierarchical directed heterogeneous graph global semantic convergence model, and converging the semantics within and between layers to realize the comprehensive decision of disguised communication service nodes. On the one hand, the present invention can identify disguised communication traffic well by deeply mining the multi-dimensional spatiotemporal characteristics of traffic and combining the current mainstream deep learning model; on the other hand, by constructing a global suspicious semantic convergence model of disguised communication service nodes, the recognition accuracy can be further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular to a method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model. Background Art

[0002] The rapid development of network technology, while promoting the digital transformation of the country's economy, politics, and life, also enables illegal network activities, such as illegal encryption agents and malicious software, to circumvent the network censorship system, which undoubtedly makes today's cyberspace governance more severe.

[0003] Early port-based and deep packet inspection technologies can better review plaintext traffic data. With the development of technologies such as Transport Layer Security (TLS), Virtual Private Networks (VPN), and Anonymous Communication Technology (Tor) in recent years, traditional traffic analysis technologies have become difficult to play a role. Currently, the rampant illegal encrypted proxy services generally use camouflaged communication technologies such as protocol obfuscation and behavior simulation to cover up their own behavior. These illegal encrypted proxy tools generally disguise their own proxy traffic as normal network traffic such as TCP, HTTP, and HTTPS. In terms of malicious code, attackers not only mimic malicious code traffic as HTTPS protocol traffic, but also use various public resource servers such as social networking sites and code hosting platforms to build communication channels. Since these public resource services are widely spread and have a large number of users, the difficulty of detection is further increased.

[0004] In summary, studying detection methods for disguised communication technology is of great significance to strengthening my country's cyberspace governance capabilities and enhancing defense against malicious code attacks. Summary of the invention

[0005] The purpose of the present invention is to address the problems existing in the prior art and provide a disguised communication traffic detection method based on a directed heterogeneous graph semantic convergence model. On the one hand, the method extracts the spatiotemporal dimensional characteristics of the disguised communication traffic and combines it with a deep learning model of a multi-head graph self-attention network to perform traffic identification. On the other hand, the suspicious semantics of the disguised communication target are modeled from three levels: message format, behavior form, and environmental semantics, so as to achieve a comprehensive judgment on the detection of disguised communication.

[0006] The technical solution to achieve the purpose of the present invention is: a method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model, comprising the following steps:

[0007] Step 1: Divide the input traffic sample into N session traffic based on the five-tuple information, and perform marking, grouping, and numbering preprocessing operations on the traffic according to the traffic type; the five-tuple is the source address, destination address, source port, destination port, and protocol five-tuple;

[0008] Step 2: extract the length and direction sequence of data packets numbered 1 to M, the same-direction packet delay sequence, the round-trip packet delay sequence, the packet arrival time sequence, and the frequency domain vector similarity sequence of adjacent packet loads flow by flow, and construct the overall feature matrix of the traffic samples;

[0009] Step 3, based on the overall feature matrix generated in step 2, a flow graph is constructed using the KNN algorithm, and the adjacency matrix is ​​used to characterize the flow graph structure;

[0010] Step 4: Use the basic autoencoder to compress the high-dimensional sparse feature matrix generated in step 2 to obtain a low-dimensional dense feature matrix, and then combine it with the adjacency matrix generated in step 3 to build a multi-head graph self-attention convolutional neural network model to preliminarily identify disguised communication traffic;

[0011] Step 5: Extract key field fingerprint information of the camouflage protocol flow by flow to characterize suspicious semantics at the message format level;

[0012] Step 6: Based on the packet length and direction sequence and the inter-packet delay sequence extracted in step 2, suspicious semantic representation is performed at the behavioral morphology level;

[0013] Step 7, for the suspicious service node's open port status and port traffic distribution, two environmental semantic levels of disguised communication target elements are characterized by suspicious semantics;

[0014] Step 8: Based on the suspicious semantic representations of the disguised communication elements at each layer in steps 5 to 7, a hierarchical directed graph suspicious semantic aggregation model is constructed to achieve a comprehensive judgment on the disguised communication service node.

[0015] Compared with the prior art, the present invention has the following significant advantages:

[0016] 1) The traffic structure diagram is constructed through the KNN algorithm, which integrates the traffic characteristics themselves with the structural characteristics of the traffic and fully explores the spatiotemporal characteristics of the traffic.

[0017] 2) A detection model based on a multi-head graph self-attention network combined with an autoencoder is proposed. First, the model compresses and reduces the dimensionality of high-dimensional sparse features to obtain low-dimensional dense features, thereby improving the performance of model training. Secondly, the multi-head attention mechanism allows automatic learning of the deep-level feature similarity between each vertex and its neighboring nodes to determine the weight of node feature fusion, which avoids a lot of manual intervention and solves the defect of the traditional GCN model that over-relies on the graph structure and ignores the characteristics of the node itself.

[0018] 3) Suspicious semantic representation is performed on the three levels of message format, behavior pattern, and environmental semantics of the disguised communication service node, and a hierarchical global semantic aggregation model is constructed, which can more comprehensively extract the disguised communication elements of suspicious service nodes, thereby further improving the detection accuracy.

[0019] In general, the present invention can identify disguised communication traffic well by deeply mining the multi-dimensional spatiotemporal characteristics of traffic, combining the current mainstream deep learning model and building a global suspicious semantic aggregation model of disguised communication service nodes. The above method is of great significance for strengthening the supervision of disguised communication traffic such as illegal encrypted proxies and malware, and maintaining network security.

[0020] The present invention is further described in detail below in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 This is a flow chart of the method for detecting camouflaged communication traffic based on a multi-head graph self-attention neural network.

[0022] Figure 2 Schematic diagram of the semantic aggregation model based on hierarchical directed heterogeneous graph. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0024] Figure 1 The flowchart of the method for detecting camouflaged communication traffic based on multi-head graph self-attention mechanism is shown in FIG. The method includes the following steps:

[0025] The input sample is disguised communication traffic such as illegal encrypted proxy.

[0026] Spatiotemporal feature extraction module: Based on the five-tuple information, the traffic samples are pre-processed by session diversion and other operations, and the length and direction sequence of the first M data packets, the same-direction packet delay sequence, the round-trip packet delay sequence, the packet arrival time sequence, and the adjacent packet load frequency domain vector similarity sequence are extracted to construct the overall feature matrix of the traffic samples;

[0027] Traffic structure diagram construction module: Calculate the similarity matrix between each flow based on cosine similarity, select the first k similar nodes according to the KNN algorithm to construct the traffic structure diagram, and realize the effective fusion of the traffic characteristics and the similarity characteristics between multiple flows;

[0028] Spatiotemporal feature dimensionality reduction module: The basic autoencoder is used to compress the original high-dimensional sparse spatiotemporal features to obtain low-dimensional dense abstract features, which are used as the input of the subsequent multi-head graph self-attention neural network model.

[0029] Traffic identification module: Based on the low-dimensional dense feature matrix and adjacency matrix of nodes, the multi-head graph self-attention neural network model is used to realize the feature extraction and traffic identification of disguised communication traffic.

[0030] Figure 2 Schematic diagram of a semantic aggregation model based on a hierarchical directed heterogeneous graph. The method includes the following steps:

[0031] Layering of camouflage strategies and extraction of target elements: Extracting camouflage communication modeling elements from three levels: message format, behavior form, and environmental semantic camouflage;

[0032] Hierarchical aggregation of semantic representations of target feature nodes: Suspicious semantic representations are performed on target feature nodes at each layer to form a global suspicious semantic model description, and suspicion aggregation is performed between and within layers.

[0033] Specifically, the present invention provides a method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model, the method comprising the following steps:

[0034] Step 1: Divide the input traffic sample into N session traffic based on the five-tuple information, and perform marking, grouping, and numbering preprocessing operations on the traffic according to the traffic type; the five-tuple is the source address, destination address, source port, destination port, and protocol five-tuple;

[0035] Step 2: extract the length and direction sequence of data packets numbered 1 to M, the same-direction packet delay sequence, the round-trip packet delay sequence, the packet arrival time sequence, and the frequency domain vector similarity sequence of adjacent packet loads, and construct the overall feature matrix X of the traffic sample;

[0036] Step 3: Based on the feature matrix X generated in step 2, the flow graph G is constructed using the KNN algorithm, and the adjacency matrix A is used to characterize the flow graph structure;

[0037] Step 4: Use the basic autoencoder to compress the high-dimensional sparse feature matrix X generated in step 2 to obtain a low-dimensional dense feature matrix Y. Then, combine it with the adjacency matrix A generated in step 3 to build a multi-head graph self-attention convolutional neural network model to preliminarily identify disguised communication traffic.

[0038] Step 5: Extract key field fingerprint information of the camouflage protocol flow by flow to characterize suspicious semantics at the message format level;

[0039] Step 6: Based on the packet length and direction sequence and the inter-packet delay sequence extracted in step 2, suspicious semantic representation is performed at the behavioral morphology level;

[0040] Step 7, performing suspicious semantic characterization on disguised communication target elements at the environmental semantic level such as the open port status of the suspicious service node and the port traffic distribution;

[0041] Step 8: Based on the suspicious semantic representations of the disguised communication elements at each layer in steps 5 to 7, a hierarchical directed graph suspicious semantic aggregation model is constructed to achieve a comprehensive judgment on the disguised communication service node.

[0042] Furthermore, while the input traffic is being diverted in step 1, the byte information such as IP, port, and MAC are all set to 0.

[0043] Furthermore, in step 1, before numbering, data packets with a payload length of 0 need to be removed.

[0044] Furthermore, step 2 constructs the overall feature matrix of the traffic sample, specifically:

[0045] M is the number of effective load data packets extracted from each flow. This value can be taken as the minimum number of data packets in all session flows. Extract the load length of data packets numbered 1 to M flow by flow, and mark the length of uplink data packets as positive numbers and the length of downlink data packets as negative numbers. Extract time features including uplink inter-packet delay, downlink inter-packet delay, round-trip delay, and packet arrival time flow by flow. Extract the load bit sequence of nbytes before adjacent packets flow by flow and perform DFT transformation to obtain frequency domain vectors. Calculate the Person correlation coefficient and KL divergence value between the frequency domain vectors of adjacent packets as the feature sequence to measure the similarity of load between packets. Concatenate the above sequences in order as the feature vectors of each session flow, and finally construct the overall feature matrix X of the flow sample. N*d , where N is the number of session flows, and d is the dimension of the feature vector of each flow;

[0046] Furthermore, step 3 constructs a KNN flow graph G based on the feature matrix X of the flow samples generated in step 2. Specifically, the cosine similarity between the feature vectors of each flow is used as a distance measure, each flow is regarded as a graph vertex, and the KNN algorithm is used to select the first K vertices with the highest similarity of each vertex for edge connection, and finally the flow structure graph G(V,E) is constructed. Based on the constructed KNN graph, the adjacency matrix A describing the graph structure relationship is obtained N*N , if there is an edge between the vertices, it is 1, otherwise it is 0.

[0047] Furthermore, step 4 constructs a multi-head graph self-attention convolutional neural network model to preliminarily identify disguised communication traffic, specifically:

[0048] The high-dimensional sparse feature matrix X is used as the input of the autoencoder. The m-layer encoder generates compressed features as the input of the decoder. The decoder reconstructs the original features based on the loss function loss, and finally generates a low-dimensional compressed feature matrix Y. The number of layers L and the number of attention heads H of the multi-head graph self-attention neural network need to be adjusted in specific experiments. The input of the network mainly includes the feature matrix Y representing the characteristics of the traffic itself and the adjacency matrix A of the structural relationship between the traffic. The weight coefficients of the node aggregation of adjacent nodes are determined through the multi-head self-attention mechanism, and finally a feature representation that integrates the characteristics of itself and adjacent nodes is obtained. Finally, the traffic nodes are classified through the softmax function, cross entropy loss function and gradient descent;

[0049] Furthermore, the suspicious semantic representation at the message format level in step 5 specifically includes:

[0050] In the case of disguising as HTTP protocol, the suspicious semantics of the Host field are represented from four aspects: matching the legitimacy of the domain name format, detecting and judging the DGA domain name, judging whether the top-level domain name is a free or low-cost domain name, and judging whether the domain name is bound to an IP and is consistent with the current traffic destination IP, to obtain a representation vector.

[0051] In the case of disguising as TLS protocol, the suspicious semantics are mainly characterized for the SNI extension field, encryption suite list, and TLS1.2 certificate key fields, as follows: The representation of SNI is basically the same as the Host field, but if the TLS Client Hello does not have an SNI extension field, the default suspicion of the four aspects is 0. The suspicion of the encryption suite list is mainly characterized by the proportion of encryption suites that are not officially recommended by IANA. The suspicious semantics of the TLS1.2 certificate field are mainly characterized by judging whether the certificate authority is a free CA or a major overseas cloud service provider, and whether the certificate validity period is reversed;

[0052] Furthermore, the extraction of packet length and direction sequence and inter-packet delay sequence in step 6 can be performed using time series clustering, direction sequence comparison, and time distribution KL divergence to perform suspicious semantic characterization;

[0053] Furthermore, in step 7, suspicious semantic representation is performed on the disguised communication target element at the environment semantic level of the suspicious service node, specifically including:

[0054] For open ports via To characterize suspicious semantics, A is a set of L normal node open ports {A1,…,A L}, B is the set of N ports with historically confirmed masquerading communication targets {B1,…,B N}, C is the set of open ports of the current service node. iis the suspicious weight coefficient of port i, which can be calculated based on the ratio of the open probability of the port in the disguised communication node and the open probability in the normal node, and can also be set based on manual experience.

[0055] For the port traffic distribution, the top N ports with the largest traffic proportion of suspicious service nodes are selected through full traffic analysis, and the uplink and downlink traffic ratio vector {v1,…,v n} as the port traffic distribution feature representation, and further adopt cosine similarity as the port traffic distribution similarity between it and normal and disguised nodes, and calculate the suspicious semantic representation using a method similar to the open port set;

[0056] Furthermore, in step 8, a hierarchical directed graph suspicious semantic aggregation model is constructed to achieve comprehensive judgment of service nodes, such as Figure 2 As shown, the suspicious semantic representations of each layer need to converge to the new node in the layer, then perform semantic convergence on the upper layer and converge layer by layer to the semantic convergence end point.

[0057] On the one hand, the present invention can identify disguised communication traffic well by deeply mining the multi-dimensional spatiotemporal characteristics of traffic and combining the current mainstream deep learning model; on the other hand, by constructing a global suspicious semantic aggregation model of disguised communication service nodes, the recognition accuracy can be further improved. The above method is of great significance for strengthening the supervision of disguised communication traffic such as illegal encrypted proxies and malware and maintaining network security.

[0058] The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.

Claims

1. A method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model, characterized in that: The method comprises the following steps: Step 1: Divide the input traffic sample into N session traffic based on the five-tuple information, and perform marking, grouping, and numbering preprocessing operations on the traffic according to the traffic type; the five-tuple is the source address, destination address, source port, destination port, and protocol five-tuple; Step 2: extract the length and direction sequence of data packets numbered 1 to M, the same-direction packet delay sequence, the round-trip packet delay sequence, the packet arrival time sequence, and the frequency domain vector similarity sequence of adjacent packet loads flow by flow, and construct the overall feature matrix of the traffic samples; Step 3, based on the overall feature matrix generated in step 2, a flow graph is constructed using the KNN algorithm, and the adjacency matrix is ​​used to characterize the flow graph structure; Step 4: Use the basic autoencoder to compress the high-dimensional sparse feature matrix generated in step 2 to obtain a low-dimensional dense feature matrix, and then combine it with the adjacency matrix generated in step 3 to build a multi-head graph self-attention convolutional neural network model to preliminarily identify disguised communication traffic; Step 5: Extract key field fingerprint information of the camouflage protocol flow by flow to characterize suspicious semantics at the message format level; Step 6: Based on the packet length and direction sequence and the inter-packet delay sequence extracted in step 2, suspicious semantic representation is performed at the behavioral morphology level; Step 7, for the suspicious service node's open port status and port traffic distribution, two environmental semantic levels of disguised communication target elements are characterized by suspicious semantics; Step 8: Based on the suspicious semantic representations of the disguised communication elements at each layer in steps 5 to 7, a hierarchical directed graph suspicious semantic aggregation model is constructed to achieve a comprehensive judgment on the disguised communication service node.

2. According to claim 1, the method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model is characterized in that: In step 1, while the input traffic is being diverted, the byte information such as IP, port, and MAC are all set to 0.

3. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1 is characterized in that: In step 1, before numbering, remove the data packets with a payload length of 0.

4. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1 is characterized in that: Step 2 constructs the overall feature matrix of the traffic sample, specifically: M is the number of effective load data packets extracted from each flow, and this value is first taken as the minimum number of data packets in all session flows; the payload length of data packets with sequence numbers from 1 to M is extracted flow by flow, and the length of uplink data packets is marked as a positive number, and the length of downlink data packets is marked as a negative number; the time characteristics including uplink inter-packet delay, downlink inter-packet delay, round-trip delay and packet arrival time are extracted flow by flow; Extract the load bit sequence of nbytes before adjacent packets flow by flow and perform DFT transformation to obtain frequency domain vectors. Calculate the Person correlation coefficient and KL divergence value between the frequency domain vectors of adjacent packets as the feature sequence to measure the load similarity between packets. Concatenate the above sequences in order as the feature vector of each session flow, and finally construct the overall feature matrix X of the flow sample N*d , where N is the number of session flows and d is the dimension of the feature vector of each flow.

5. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: Step 3 constructs a KNN traffic graph G based on the feature matrix X of the traffic samples generated in step 2, specifically: According to the cosine similarity between the feature vectors of each flow, each flow is regarded as a graph vertex. The KNN algorithm is used to select the first K vertices with the highest similarity of each vertex for edge connection, and finally the flow structure graph G(V,E) is constructed; based on the constructed KNN graph, the adjacency matrix A describing the graph structure relationship is obtained. N*N , if there is an edge between the vertices, it is 1, otherwise it is 0.

6. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: Step 4 builds a multi-head graph self-attention convolutional neural network model to preliminarily identify disguised communication traffic, specifically: The high-dimensional sparse feature matrix X is used as the input of the autoencoder, and the m-layer encoder generates compressed features as the input of the decoder. The decoder reconstructs the original features based on the loss function loss, and finally generates a low-dimensional compressed feature matrix Y; the input of the network includes the feature matrix Y representing the characteristics of the traffic itself and the adjacency matrix A of the structural relationship between the traffic; the weight coefficients of the node aggregation of adjacent nodes are determined through the multi-head self-attention mechanism, and finally the feature representation that integrates the characteristics of itself and adjacent nodes is obtained; finally, the traffic nodes are classified through the softmax function, cross entropy loss function and gradient descent method.

7. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: The suspicious semantic representations at the message format level in step 5 include: In the case of disguising as HTTP protocol, the suspicious semantics of the Host field are characterized from four aspects: matching the legality of the domain name format, detecting and judging the DGA domain name, judging whether the top-level domain name is a free or low-cost domain name, and judging whether the domain name is bound to an IP and is consistent with the current traffic destination IP, and a representation vector is obtained; In the case of disguising as TLS protocol, suspicious semantics are characterized for SNI extension field, encryption suite list, and TLS1.2 certificate key fields, as follows: the representation of SNI is consistent with the Host field, but if the TLS Client Hello does not have an SNI extension field, the default suspicion of the four aspects is 0; the suspicion of the encryption suite list is characterized by the proportion of encryption suites that are not officially recommended by IANA; the suspicious semantics of the TLS1.2 certificate field are characterized by judging whether the certificate authority is a free CA or a major overseas cloud service provider, and whether the certificate validity period is reversed.

8. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: In step 6, time series clustering, directional sequence alignment, and time distribution KL divergence are used to perform suspicious semantic representation of behavioral morphology.

9. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: In step 7, suspicious semantic representation is performed on the disguised communication target elements at the environmental semantic level of the suspicious service node, specifically including: For open ports, To characterize suspicious semantics, A is a set of L normal node open ports {A1,…,A L }, B is the set of N ports with historically confirmed masquerading communication targets {B1,…,B N }, C is the set of open ports of the current service node; w i is the suspicious weight coefficient of port i; For port traffic distribution, we filter out the top N ports with the highest traffic share of suspicious service nodes through full traffic analysis, and use the traffic uplink and downlink ratio vector {v1,…,v n } is used as the port traffic distribution feature representation, and cosine similarity is used as the similarity between its port traffic distribution and that of normal and disguised nodes.

10. The method for detecting camouflaged communication traffic based on a directed heterogeneous graph semantic convergence model according to claim 1, characterized in that: The hierarchical directed graph suspicious semantic aggregation model described in step 8 is constructed to achieve comprehensive judgment on service nodes. It is necessary for the suspicious semantic representations of each layer to converge to the new node in the layer, and then perform semantic aggregation on the upper layer and converge layer by layer to the semantic aggregation end point.

Citation Information

Patent Citations

  • Encryption protocol identification method based on active service detection engine technology

    CN111200543A

  • VPN communication behavior analysis method based on flow multi-scale spatial-temporal feature fusion

    CN114301636A