A traffic identification method, device, equipment and storage medium
Patent Information
- Application Number
- CN202310201881.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-28
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2043-02-28
AI Technical Summary
其中,基于端口的应用识别是基于报文的源或者目的端口进行应该识别,但该识别非法不够严谨,无法识别仿冒端口或者非致命端口的流量;而基于内容的应用识别,是通过匹配流量中模式串来实现,但是该非法无法识别加密等无明文特征的P2P流量
[0018] The traffic identification method, apparatus, device, and storage medium provided in this application embodiment generate a load length feature of the data packet based on the load length of the current data packet of the traffic to be identified; the load length feature is matched with a preset length feature library, which includes set length features of P2P traffic of various applications identified in the past; if the set length feature of the target application in the length feature library is successfully matched, and the current matching success rate of the traffic to be identified is not lower than a set matching rate threshold, then the traffic to be identified is confirmed as P2P traffic of the target application. In this way, traffic identification is performed using load length features, and the accuracy of the traffic identification result is indicated by the matching rate of the traffic identification. Furthermore, the application to which the traffic to be identified belongs can be identified, thus improving the accuracy of the application identification result.
Smart Images

Figure CN116232725B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a traffic identification method, apparatus, device and storage medium. Background Technology
[0002] With the widespread application of P2P (Peer-to-Peer) technology, P2P data traffic is gradually accounting for an increasingly larger proportion of network traffic. Data shows that P2P applications already account for 60% to 80% of ISP traffic, becoming the largest consumer of network bandwidth. Therefore, the security detection of P2P traffic has become a hot issue in network security.
[0003] Currently, there are two main methods for P2P traffic detection: port-based application identification and content-based application identification. Port-based application identification identifies traffic based on the source or destination port of the packet, but this method is not rigorous enough and cannot identify traffic from spoofed or non-critical ports. Content-based application identification, on the other hand, matches pattern strings in the traffic, but this method cannot identify P2P traffic with encrypted or other plaintext features.
[0004] Therefore, how to accurately identify the P2P traffic of an application is one of the technical issues worth considering. Summary of the Invention
[0005] In view of this, this application provides a traffic identification method, apparatus, device, and storage medium for accurately identifying the P2P traffic of an application.
[0006] Specifically, this application is implemented through the following technical solution:
[0007] According to a first aspect of this application, a traffic identification method is provided, comprising:
[0008] For the current data packet of the traffic to be identified, a payload length feature of the data packet is generated based on the payload length of the data packet;
[0009] The load length feature is matched with a preset length feature library, which includes the set length features of P2P traffic of each application identified in history.
[0010] If the target application's set length feature is successfully matched in the length feature library, and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold, then the traffic to be identified is confirmed as the target application's P2P traffic.
[0011] According to a second aspect of this application, a traffic flow identification device is provided, comprising:
[0012] The generation module is used to generate the payload length feature of the data packet based on the payload length of the current data packet of the traffic to be identified.
[0013] The matching module is used to match the load length characteristics with a preset length characteristic library, which includes the set length characteristics of P2P traffic of each application identified in history.
[0014] The confirmation module is used to confirm that the traffic to be identified is the P2P traffic of the target application if the matching module successfully matches the set length feature of the target application in the length feature library and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold.
[0015] According to a third aspect of this application, an electronic device is provided, including a processor and a machine-readable storage medium storing a computer program executable by the processor, the processor being prompted by the computer program to perform the method provided in the first aspect of the embodiments of this application.
[0016] According to a fourth aspect of this application, a machine-readable storage medium is provided, which stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method provided in the first aspect of the embodiments of this application.
[0017] The beneficial effects of the embodiments of this application are as follows:
[0018] The traffic identification method, apparatus, device, and storage medium provided in this application embodiment generate a load length feature of the data packet based on the load length of the current data packet of the traffic to be identified; the load length feature is matched with a preset length feature library, which includes set length features of P2P traffic of various applications identified in the past; if the set length feature of the target application in the length feature library is successfully matched, and the current matching success rate of the traffic to be identified is not lower than a set matching rate threshold, then the traffic to be identified is confirmed as P2P traffic of the target application. In this way, traffic identification is performed using load length features, and the accuracy of the traffic identification result is indicated by the matching rate of the traffic identification. Furthermore, the application to which the traffic to be identified belongs can be identified, thus improving the accuracy of the application identification result. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating a traffic identification method provided in an embodiment of this application;
[0020] Figure 2 This is a schematic diagram of the structure of a flow identification device provided in an embodiment of this application;
[0021] Figure 3 This is a schematic diagram of the hardware structure of an electronic device implementing a traffic identification method according to an embodiment of this application. Detailed Implementation
[0022] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.
[0023] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used herein are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the corresponding listed items.
[0024] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0025] The traffic identification method provided in this application will be described in detail below.
[0026] See Figure 1 , Figure 1 This is a flowchart of a traffic identification method provided in this application. This method can be applied to electronic devices, including but not limited to network security devices. For ease of description, the implementation of the traffic identification method by a network security device is illustrated as an example. When implementing the above method, the network security device may include the following steps:
[0027] S101. For the current data packet of the traffic to be identified, generate the load length feature of the data packet based on the load length of the data packet.
[0028] In this step, the same data stream is continuously sent to the network security device. Therefore, in order to accurately identify the data stream (denoted as the traffic to be identified) and provide corresponding security protection, this embodiment proposes to perform traffic identification processing on a data packet-by-packet basis.
[0029] Specifically, when a data packet of traffic to be identified is captured and recorded as the current data packet, the network security device will identify the data packet, thereby parsing and determining the packet length, and then generating the payload length characteristic of the data packet. For example, if the payload length in the data packet is 100, then the payload length characteristic is 100, and so on.
[0030] S102. Match the load length feature with a preset length feature library, which includes the set length features of P2P traffic of each application identified in history.
[0031] In this step, to facilitate and quickly identify the traffic to be identified, a length feature database is pre-built, containing the payload length characteristics (denoted as the above-mentioned set length characteristics) of the data packets of the identified P2P traffic from each application. Thus, during this traffic identification process, the network security device can match the payload length characteristics of the data packets with the set length characteristics of each application in the length feature database.
[0032] S103. If the target application's set length feature is successfully matched in the length feature library, and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold, then the traffic to be identified is confirmed as the P2P traffic of the target application.
[0033] In this step, it can be determined whether the payload length characteristics of the current data packet meet the matching conditions with the set length characteristics of each application in the length feature database. When the matching conditions are met with the set length characteristics of the target application, the match is confirmed to be successful. Furthermore, to ensure the accuracy of traffic identification results, this embodiment also proposes that each time traffic identification is performed, the matching success rate of the traffic to be identified is calculated based on the previous traffic identification results. That is, when a match is successfully made with the set length characteristics of the target application, the current matching rate of the traffic to be identified is determined based on the current matching success rate and the previous matching results of the traffic to be identified. Thus, when the current matching rate is determined to be no less than the set matching rate threshold, it indicates that the data packets in the traffic to be identified have hit the set packet length of the target application a relatively large number of times, thereby concluding that the traffic to be identified belongs to the P2P traffic of the target application. This not only enables traffic identification but also improves the accuracy of the traffic identification results.
[0034] At the same time, it can also identify the application to which the traffic to be identified belongs, thereby facilitating the implementation and deployment of application-based services.
[0035] Optionally, the above-mentioned matching rate threshold can be configured according to the actual situation, for example, it can be set to 70%, but this application does not limit its specific value.
[0036] By implementing the traffic identification method provided in this application, for the current data packet of the traffic to be identified, a load length feature of the data packet is generated based on the load length of the data packet; the load length feature is then matched with a preset length feature library, which includes the set length features of P2P traffic of various applications identified in the past; if the set length feature of the target application in the length feature library is successfully matched, and the current matching success rate of the traffic to be identified is not lower than a set matching rate threshold, then the traffic to be identified is confirmed as P2P traffic of the target application. In this way, traffic identification is performed using load length features, and the accuracy of the traffic identification result is indicated by the matching rate of the traffic identification. Furthermore, the application to which the traffic to be identified belongs can be identified, thus improving the accuracy of the application identification result.
[0037] Optionally, based on the above embodiments, this embodiment proposes that step S101 can be performed according to the following process: identifying the message direction of the data packet; when the message direction is a request direction, matching the load length feature with the first set length feature of the request direction in the P2P traffic of each application in the preset length feature library to obtain a first matching result; when the message direction is a response direction, matching the load length feature with the second set length feature of the response direction in the P2P traffic of each application in the preset length feature library to obtain a second matching result.
[0038] Specifically, to ensure the accuracy and speed of the identification results, this embodiment first distinguishes the message direction of the current data packet during feature matching, that is, determines whether the data packet is a request-direction or response-direction message. Then, after identifying the request-direction, it is compared with the length feature library. Correspondingly, in constructing the length feature library in this embodiment, the set length features for the request direction and the set message length for the response direction of each application are also distinguished. For ease of explanation, the length feature library is described using two sub-feature libraries: a first sub-feature library and a second sub-feature library. The load length features that can characterize the application and indicate that it belongs to P2P in the pre-identified P2P traffic request direction of each application are written into the first sub-feature library; similarly, the load length features that can characterize the application and indicate that it belongs to P2P in the pre-identified P2P traffic response direction of each application are written into the second sub-feature library. Then, the length feature library is constructed based on the first and second sub-feature libraries.
[0039] Based on this, once the message direction of the current data packet is identified, if the message direction is a request direction, the payload length feature can be matched with the set length feature of each application in the first sub-feature library to obtain the aforementioned first matching result. When the first matching result includes a successful match, the first matching result also includes the matched application; if the match is unsuccessful, the first matching result is a failed match.
[0040] Similarly, when the current data packet's packet direction is identified as a response direction, the payload length feature can be matched with the set length feature of each application in the second sub-feature library to obtain the aforementioned second matching result. If the second matching result includes a successful match, it also includes the matched application; if the match is unsuccessful, the second matching result is considered a failed match.
[0041] By executing the matching process, the matching result of the current data packet can be obtained quickly.
[0042] To better understand this embodiment, we will take the current data packet as the request direction and the payload length feature as 100 as an example, denoted as req160. The applications and features included in the first sub-feature library of the request direction and the second sub-feature library of the response direction are shown in Table 1:
[0043] Table 1
[0044]
[0045]
[0046] Based on this, it can be concluded that req160 matches application 2 in the first sub-feature library, so the first matching result includes a successful match and application 2. The matching method for the response direction is similar to that for the request direction, and will not be described in detail here.
[0047] It is worth noting that there may be cases where multiple applications have the same set length characteristics. However, this application also calculates the matching success rate of the traffic to be identified. That is, when multiple applications are matched, each application will have a corresponding matching success rate. In this way, the matching success rate of each matched application will be assigned, and then the application with a matching success rate greater than the set matching rate threshold will be selected. This can also ensure the accuracy of traffic identification results and application identification results.
[0048] Furthermore, in practical applications, the same data stream may exhibit slight deviations in load length under different network environments. To ensure the accuracy of traffic identification results, a tolerance range is set. Based on this, when the deviation between the load length characteristic and the set length characteristic is within the set tolerance range, it can be confirmed that the load length characteristic matches the set length characteristic.
[0049] Specifically, statistical analysis shows that the set fault tolerance range is approximately within 3 bytes. If the allowed jitter deviation is 3, then when the deviation between the load length feature and the set length feature is within 3 bytes, it can be confirmed that the load length feature matches the set length feature. For example, if the length feature library contains req400, then req398, req399, req397, req401, req402, and req403 can all match req400.
[0050] Optionally, based on the above embodiments, in this embodiment, the current matching success rate of the traffic to be identified can be determined by the following method: if the first matching result is a successful match of the first set length feature of the target application, or the second matching result is a successful match of the second set length feature of the target application, then the number of successful matches of the target application based on the traffic to be identified is updated; the ratio between the number of matches and the feature length of the target application is rounded down to obtain the current matching success rate of the traffic to be identified.
[0051] Specifically, the number of successful matches mentioned above includes the first number of successful matches in the request direction and the second number of successful matches in the response direction, and then the matching success rate is calculated according to the following formula:
[0052] Match success rate = int((number of successful first matches + number of successful second matches) * 100 / number of length features + 0.5)
[0053] The number of length features mentioned above refers to the number of defined length features applied in the length feature library. The 0.5 mentioned above is used to round the integer result.
[0054] For example, if the length features of a certain application include req68, res228, req300, req132, res100, res20, req20, req436, res20, req160, req160, and res1204, then the number of length features of that application is 12.
[0055] To better understand this embodiment, the data packets from the first data packet to the current data packet in the traffic to be identified are: req68, req228, req308, req100, req132, req20, req436, req20, req180, req20, req180, req1204. The set length characteristics of a certain application included in the first sub-feature library of the length feature library are: req68, req300, req132, req436, req160, req160; the set length characteristics of the same application included in the second sub-feature library of the same length feature library are: req228, req100, req20, req20, req20, req1204. We can conclude that the number of successful first matches in the direction of the traffic request is 3; the number of successful second matches in the direction of the response is 6. Therefore, the matching success rate is int((3+6)*100 / 12+0.5)=75%.
[0056] It should be noted that this implementation does not restrict the order in which the above messages appear.
[0057] Optionally, when identifying applications based on length features, the rules for forming load length features of P2P traffic are pre-analyzed. Different application traffic corresponds to different set length features, thus forming different rules, which in turn constitute the aforementioned length feature library. To better understand the aforementioned length feature library, the following application is used as an example, and its rules in the length feature library are as follows:
[0058] Rule-ID:122
[0059] Rule-Name: Application
[0060] L4-protocol:tcp
[0061] [Direction:request,dsize:309-313]
[0062] [Direction:request,dsize:28-32]
[0063] [Direction:request,dsize:66-70]
[0064] [Direction:request,dsize:270-274]
[0065] [Direction:response,dsize:114-118]
[0066] [Direction:response,dsize:28-32]
[0067] [Direction:response,dsize:33-37]
[0068] Based on this, if the target application's set length feature is successfully matched in the length feature library, but the current matching success rate of the traffic to be identified is lower than the set matching rate threshold, then the next data packet of the traffic to be identified is obtained. Further, the next data packet is used as the current data packet, and the step of generating the load length feature of the data packet based on the load length of the current data packet of the traffic to be identified is continued.
[0069] Specifically, when the matching success rate of the traffic to be identified is lower than the set matching rate threshold when the traffic identification is performed according to the above formula, it is possible that the number of current packets is relatively small, and it is necessary to continue to identify traffic based on subsequent data packets. On this basis, the data packets of the traffic to be identified are obtained again, and then the traffic identification method provided in any embodiment of this application is continued.
[0070] Optionally, when identifying traffic to be identified, generally only the first few data packets are needed to identify the traffic and its application. Even if the traffic to be identified is encrypted, only the first few data packets are needed for traffic identification. Based on this principle, step S101 can be performed as follows: determine the cumulative number of times the data packets of the traffic to be identified have been acquired; when the cumulative number is lower than a set threshold, generate a payload length feature of the data packets for the current data packets of the traffic to be identified, based on the payload length of the data packets.
[0071] Specifically, after receiving the data packet of the traffic to be identified, the cumulative number of times the data packet of the traffic to be identified has been acquired can be counted. That is, the cumulative acquisition count is updated according to the data packet received this time, that is, the current cumulative acquisition count = cumulative acquisition count + 1. Based on this, it is determined whether the current cumulative acquisition count is greater than a set threshold. If it is not greater than the set threshold, it indicates that the number of packets processed previously may not be sufficient to accurately identify the traffic to be identified. Based on this, traffic identification processing can be performed based on the current data packet, that is, load length feature extraction is performed in step S101.
[0072] Based on this, the traffic identification method provided in this embodiment also includes the following process: when the current matching success rate of the traffic to be identified is lower than the set matching rate threshold, and the cumulative number of acquisitions is not lower than the set number of acquisitions threshold, then it is determined that the traffic to be identified is not P2P traffic.
[0073] Specifically, when it is determined that the cumulative number of acquisitions is greater than the set threshold, it indicates that the number of message processing operations for traffic identification based on the traffic to be identified is sufficient. If the traffic to be identified still cannot be accurately identified based on these data messages, then it can be directly determined that the traffic to be identified does not belong to P2P traffic, and further confirmed that the traffic to be identified is not P2P traffic of a certain application.
[0074] It should be noted that for encrypted P2P traffic, the fixed number of interaction messages that can be used for traffic identification are concentrated in the first 48 messages of the traffic. Therefore, the threshold for the number of times mentioned above can be set to 48, etc.
[0075] Furthermore, packets with a payload length of 1000 or more are classified as large packets, those between 500 and 1000 are classified as medium packets, and the rest are classified as small packets. The detection requirements for large packets are that they meet one of the following conditions: the number of large packets must be at least 4; the number of medium packets must be at least 15 (the number of medium packets includes both large and medium packets). Therefore, during traffic identification, the number of packets in the traffic to be identified must meet one of the above conditions for it to be considered potentially P2P traffic; if the traffic to be identified does not meet this condition, it indicates that the traffic to be identified does not belong to P2P traffic, and other types of traffic identification processing can be performed on the traffic to be identified.
[0076] Based on any of the above embodiments, the traffic identification method provided in this embodiment may further include the following method: when the current data packet is the first packet of the traffic to be identified, the IP address and port are extracted from the data packet; the extracted IP address and port are matched with the application relationship between the application and the IP address and port recorded in the application list; when the match is successful, the traffic to be identified is confirmed to be the P2P traffic of the matched application; when the match is unsuccessful, the load length feature of the data packet is generated based on the load length of the current data packet of the traffic to be identified.
[0077] Specifically, to further improve the speed of traffic identification, this embodiment also provides another traffic identification scheme. When the first data packet of the traffic to be identified is received, traffic identification can be performed based on the packet header information. Specifically, the IP address and port are extracted from the packet header information. Then, the extracted IP address and port are matched with the IP addresses and ports corresponding to each P2P application recorded in the application list. If a match is successful, the application to which the traffic belongs is the P2P traffic. If no match is found, it indicates that the traffic to be identified is a new data stream. Therefore, to identify the traffic, the above traffic identification method can be applied to the traffic to be identified to accurately identify it.
[0078] Based on this, the traffic identification method provided in this embodiment may further include the following process: when it is confirmed that the traffic to be identified is P2P traffic of the target application, the target IP address and target port of the target application are obtained; the correspondence between the target application, the target IP address and the target port is written into the application list.
[0079] Specifically, in practical applications, the same application may have multiple data streams. Therefore, to avoid quickly identifying the traffic to be identified when the application's traffic arrives, this embodiment proposes that after identifying the traffic to be identified as P2P traffic of the target application based on any of the above embodiments, the correspondence between the target IP address and the target port of the target application can be written into the application list. In this way, when subsequent traffic of the application arrives, traffic identification can be performed first based on the application list. After identifying the traffic to be identified, it is not necessary to execute the above traffic identification method, thereby improving the speed of traffic identification. If no traffic is identified, then the traffic identification method provided by any of the above embodiments of this application is executed. In this way, the identification of the traffic to be identified can be achieved, and the accuracy of the traffic identification results can also be improved.
[0080] It is worth noting that the above application list identification method can be applied to applications with low application protocol trustworthiness. For applications with higher application protocol trustworthiness requirements, the load length feature identification method can be used to improve the accuracy of traffic identification results and application identification rate, which facilitates application business deployment.
[0081] Based on the same inventive concept, this application also provides a flow identification device corresponding to the above-described flow identification method. Specific implementation details of this flow identification device can be found in the above description of the flow identification method, and will not be elaborated upon here.
[0082] See Figure 2 , Figure 2 This application provides an exemplary embodiment of a traffic identification device, comprising:
[0083] The generation module 201 is used to generate a load length feature of the data packet based on the load length of the current data packet of the traffic to be identified.
[0084] The first matching module 202 is used to match the load length feature with a preset length feature library, the length feature library including the set length features of P2P traffic of each application identified in history.
[0085] The confirmation module 203 is used to confirm that the traffic to be identified is the P2P traffic of the target application if the matching module successfully matches the set length feature of the target application in the length feature library and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold.
[0086] In the traffic identification device provided in this embodiment, for the current data packet of the traffic to be identified, a load length feature of the data packet is generated based on the load length of the data packet. This load length feature is then matched against a preset length feature library, which includes set length features of P2P traffic from historically identified applications. If a match is successfully made with the set length feature of the target application in the length feature library, and the current matching success rate of the traffic to be identified is not lower than a set matching rate threshold, then the traffic to be identified is confirmed as P2P traffic of the target application. In this way, traffic identification is performed using load length features, and the accuracy of the traffic identification result is indicated by the matching rate. Furthermore, the application to which the traffic to be identified belongs can be identified, thus improving the accuracy of application identification results.
[0087] Optionally, based on the above embodiments, in this embodiment, the first matching module 202 is specifically used to identify the message direction of the data packet; when the message direction is a request direction, the load length feature is matched with the first set length feature of the request direction in the P2P traffic of each application in the preset length feature library to obtain a first matching result; when the message direction is a response direction, the load length feature is matched with the second set length feature of the response direction in the P2P traffic of each application in the preset length feature library to obtain a second matching result.
[0088] Further, the first matching module 202 is specifically used to determine the current matching success rate of the traffic to be identified according to the following method: if the first matching result is a successful match of the first set length feature of the target application, or the second matching result is a successful match of the second set length feature of the target application, then the number of successful matches based on the traffic to be identified to the target application is updated; the ratio between the number of matches and the feature length of the target application is rounded down to obtain the current matching success rate of the traffic to be identified.
[0089] Based on this, the traffic identification device provided in this embodiment also includes:
[0090] The first acquisition module (not shown in the figure) is used to acquire the next data packet of the traffic to be identified if the first matching module 202 successfully matches the set length feature of the target application in the length feature library, but the current matching success rate of the traffic to be identified is lower than the set matching rate threshold.
[0091] The aforementioned generation module 201 is further configured to use the next data packet as the current data packet, and continue to execute the step of generating the load length feature of the data packet based on the load length of the current data packet of the traffic to be identified.
[0092] Based on the above embodiments, in this embodiment, the generation module 201 is specifically used to determine the cumulative number of times the data packets of the traffic to be identified are acquired; when the cumulative number of times is lower than a set threshold, the load length feature of the data packet is generated for the current data packet of the traffic to be identified based on the load length of the data packet.
[0093] Furthermore, the aforementioned confirmation module 203 is specifically used to determine that the traffic to be identified is not P2P traffic when the first matching module 202 confirms that the current matching success rate of the traffic to be identified is lower than the set matching rate threshold and the cumulative number of acquisitions is not lower than the set number of acquisitions threshold.
[0094] Based on any of the above embodiments, the traffic identification device provided in this embodiment further includes:
[0095] An extraction module (not shown in the figure) is used to extract the IP address and port from the data packet when the current data packet is the first packet of the traffic to be identified;
[0096] The second matching module (not shown in the figure) is used to match the extracted IP address and port with the application relationship between the application and the IP address and port recorded in the application list;
[0097] The confirmation module 203 is further configured to confirm that the traffic to be identified is the P2P traffic of the matching application when the matching result of the second matching module is a successful match;
[0098] The generation module 201 is further configured to, when the matching result of the second matching module is unsuccessful, execute the step of generating the load length feature of the data packet based on the load length of the current data packet of the traffic to be identified.
[0099] Based on this, the traffic identification device provided in this embodiment also includes:
[0100] The second acquisition module (not shown in the figure) is used to acquire the target IP address and target port of the target application when it is confirmed that the traffic to be identified is the P2P traffic of the target application.
[0101] The writing module (not shown in the figure) is used to write the correspondence between the target application, the target IP address and the target port into the application list.
[0102] Based on the same inventive concept, embodiments of this application provide an electronic device, which may, but is not limited to, include network security identification. For example... Figure 3 As shown, the electronic device includes a processor 301 and a machine-readable storage medium 302. The machine-readable storage medium 302 stores a computer program executable by the processor 301. The processor 301 is prompted by the computer program to execute the traffic identification method provided in any embodiment of this application. Furthermore, the electronic device also includes a communication interface 303 and a communication bus 304, wherein the processor 301, the communication interface 303, and the machine-readable storage medium 302 communicate with each other via the communication bus 304.
[0103] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0104] The communication interface is used for communication between the aforementioned electronic devices and other devices.
[0105] The machine-readable storage medium 302 described above can be a memory, which may include random access memory (RAM), DDR SRAM (Double Data Rate Synchronous Dynamic Random Access Memory), or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0106] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0107] For embodiments of electronic devices and machine-readable storage media, since the methods involved are basically similar to those described in the foregoing method embodiments, the description is relatively simple, and relevant details can be found in the descriptions of the method embodiments.
[0108] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0109] The specific implementation process of the functions and roles of each unit / module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0110] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units / modules described as separate components may or may not be physically separate. The components shown as units / modules may or may not be physical units / modules, that is, they may be located in one place or distributed across multiple network units / modules. Some or all of the units / modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0111] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A traffic flow identification method, characterized in that, include: For the current data packet of the traffic to be identified, a payload length feature of the data packet is generated based on the payload length of the data packet; The load length feature is matched with a preset length feature library, which includes the set length features of P2P traffic of each application identified in history. If the target application's set length feature is successfully matched in the length feature library, and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold, then the traffic to be identified is confirmed as the P2P traffic of the target application. Matching the load length feature with a preset length feature library includes: Identify the message direction of the data packet; When the message direction is a request direction, the load length feature is matched with the first set length feature of the request direction in the P2P traffic of each application in the preset length feature library to obtain the first matching result. When the message direction is the response direction, the load length feature is matched with the second set length feature of the response direction in the P2P traffic of each application in the preset length feature library to obtain the second matching result. The current matching success rate of the traffic to be identified is determined using the following method: If the first matching result is a successful match of the first set length feature of the target application, or the second matching result is a successful match of the second set length feature of the target application, then the number of successful matches of the target application based on the traffic to be identified is updated. The ratio between the number of successful matches and the number of length features of the target application is rounded down to obtain the current matching success rate of the traffic to be identified. The number of length features is the number of set length features of the target application in the length feature library.
2. The method according to claim 1, characterized in that, Also includes: If the target application's set length feature is successfully matched in the length feature library, but the current matching success rate of the traffic to be identified is lower than the set matching rate threshold, then the next data packet of the traffic to be identified is obtained. The next data packet is taken as the current data packet, and the step of generating the payload length feature of the data packet based on the payload length of the current data packet for the traffic to be identified continues.
3. The method according to claim 2, characterized in that, For the current data packet of the traffic to be identified, based on the payload length of the data packet, a payload length feature of the data packet is generated, including: Determine the cumulative number of times the data packets of the traffic to be identified have been acquired; When the cumulative number of acquisitions is lower than the set threshold, the load length feature of the data packet is generated based on the load length of the data packet for the current data packet of the traffic to be identified.
4. The method according to claim 3, characterized in that, Also includes: When the current matching success rate of the traffic to be identified is lower than the set matching rate threshold, and the cumulative number of acquisitions is not lower than the set number of acquisitions threshold, then the traffic to be identified is determined not to be P2P traffic.
5. The method according to claim 1, characterized in that, Also includes: When the current data packet is the first packet of the traffic to be identified, the IP address and port are extracted from the data packet; The extracted IP addresses and ports are matched with the application relationships between applications and IP addresses and ports recorded in the application list; When a match is successful, the traffic to be identified is confirmed to be P2P traffic of the matching application; If no match is found, the process is executed to generate the payload length feature of the data packet based on the payload length of the current data packet for the traffic to be identified.
6. The method according to claim 5, characterized in that, Also includes: When it is confirmed that the traffic to be identified is the P2P traffic of the target application, the target IP address and target port of the target application are obtained; Write the correspondence between the target application, target IP address, and target port into the application list.
7. A flow rate identification device, characterized in that, include: The generation module is used to generate the payload length feature of the data packet based on the payload length of the current data packet of the traffic to be identified. The first matching module is used to match the load length characteristics with a preset length characteristic library, which includes the set length characteristics of P2P traffic of each application identified in history. The confirmation module is used to confirm that the traffic to be identified is the P2P traffic of the target application if the matching module successfully matches the set length feature of the target application in the length feature library and the current matching success rate of the traffic to be identified is not lower than the set matching rate threshold. The first matching module is specifically used to identify the message direction of the data packet; when the message direction is a request direction, the load length feature is matched with the first preset length feature of the request direction in the P2P traffic of each application in the preset length feature library to obtain a first matching result; when the message direction is a response direction, the load length feature is matched with the second preset length feature of the response direction in the P2P traffic of each application in the preset length feature library to obtain a second matching result. The first matching module is specifically used to determine the current matching success rate of the traffic to be identified in the following manner: if the first matching result is a successful match of the first set length feature of the target application, or the second matching result is a successful match of the second set length feature of the target application, then the number of successful matches of the target application based on the traffic to be identified is updated. The ratio between the number of successful matches and the number of length features of the target application is rounded down to obtain the current matching success rate of the traffic to be identified. The number of length features is the number of set length features of the target application in the length feature library.
8. The apparatus according to claim 7, characterized in that, Also includes: The extraction module is used to extract the IP address and port from the data packet when the current data packet is the first packet of the traffic to be identified; The second matching module is used to match the extracted IP addresses and ports with the application relationships between applications and IP addresses and ports recorded in the application list; The confirmation module is further configured to confirm that the traffic to be identified is the P2P traffic of the matching application when the matching result of the second matching module is a successful match; The generation module is further configured to, when the matching result of the second matching module is unsuccessful, execute the step of generating the load length feature of the data packet based on the load length of the current data packet of the traffic to be identified.
9. An electronic device, characterized in that, The method includes a processor and a machine-readable storage medium storing a computer program executable by the processor, which is prompted by the computer program to perform the method according to any one of claims 1-6.
10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores a computer program that, when invoked and executed by a processor, causes the processor to perform the method according to any one of claims 1-6.
Citation Information
Patent Citations
Peer-to-peer application identification processing method and peer-to-peer application identification processing device
CN104660636A