Method and system for simulating real traffic under network target range

CN117135063BActive Publication Date: 2026-09-18BEIJING CHANGYANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310950645.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2026-09-18
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

然而,在模拟互联网等场景中,Openstack并不能模拟类似在互联网中存在着的文本,音频,视频,游戏等真实流量

Benefits of technology

[0028] Based on preset internet traffic and user-generated traffic in the network range, an initial training set is constructed, labeled with source IP, destination IP, source port, destination port, service type, packet size, and content characteristics. A random forest model is trained based on the initial training set. The trained random forest model is used to classify real-time collected internet traffic to obtain random traffic. The features of the random traffic are modified, and the modified random traffic is input into the virtual bridge of the network range as background traffic. This greatly improves the realism, randomness, and complexity of traffic simulation in the network range, enhances the efficiency of the training scenario, and enables personnel and organizations to better utilize the network range for various network security-related learning, research, testing, competitions, and exercises, thereby improving network security countermeasure capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117135063B_ABST
    Figure CN117135063B_ABST
Patent Text Reader

Abstract

The application provides a method and system for simulating real traffic in a network range, based on preset Internet traffic and traffic generated by users in the network range, an initial training set including source IP, destination IP, source port, destination port, service type, packet size and content features as labels is constructed; a random forest model is trained based on the initial training set; real-time collected Internet traffic is classified based on the trained random forest model to obtain random traffic; the features of the random traffic are modified, and the modified random traffic is input into a virtual bridge of the network range as background traffic, greatly improving the authenticity, randomness and complexity of traffic simulation in the network range, improving the efficiency of the training scene, and enabling personnel and institutions to better apply the network range for various network security-related learning, research, testing, competition, exercise and other behaviors, thereby improving network security confrontation capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing service platform technology, and in particular to a method and system for simulating real traffic in a network test range. Background Technology

[0002] A cyber range is an advanced tool designed to simulate and reproduce the operational state and environment of real cyberspace, thereby helping individuals and organizations improve their cybersecurity capabilities. Virtualization technology is a crucial support for cyber ranges, and OpenStack, as a leading representative of virtualization technology, is the preferred choice for cyber ranges due to its open-source and mature characteristics. However, in scenarios simulating the internet, OpenStack cannot simulate real traffic such as text, audio, video, and games that exist on the internet. This is a problem that needs to be addressed, because simulating the internet is essential in a cyber range. A simulated internet environment can more realistically simulate the real-world cybersecurity situation, enabling individuals and organizations to better prepare for and respond to cybersecurity challenges. In such an environment, personnel can engage in various cybersecurity-related activities such as learning, research, testing, competitions, and exercises, thereby improving their cybersecurity capabilities. Summary of the Invention

[0003] To address the aforementioned technical problems, this application provides a method for simulating real traffic in a network test range, comprising:

[0004] S1. Based on the preset Internet traffic and user-generated traffic in the network range, construct an initial training set with labels including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics;

[0005] S2. Train a random forest model based on the initial training set;

[0006] S3. Based on the trained random forest model, classify the real-time collected Internet traffic to obtain random traffic;

[0007] S4. Modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network range as background traffic.

[0008] In some specific embodiments, the construction of the initial training set in step S1 includes classifying the preset Internet traffic and user-generated traffic in the network range based on the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics using a traffic capture tool.

[0009] In some specific embodiments, step S2, which involves training the random forest model based on the initial training set, specifically includes the following steps:

[0010] S21. Based on the initial training set, a second training set is obtained by sampling with replacement several times.

[0011] S22. Based on the second training set, a number of features are randomly selected to construct a second feature group, wherein the number of features in the selected second feature group is less than the number of features in the original training set;

[0012] S23. Obtain a decision tree based on the second training set and the selected corresponding features;

[0013] S24. Repeat steps S21 to S23 until the number of decision trees reaches the target number, thus obtaining the random forest model.

[0014] In some specific embodiments, the real-time collected Internet traffic in step S3 is obtained by receiving traffic generated in the Internet from the mirror port of the receiving switch.

[0015] In some specific embodiments, the trained random forest model described in step S3 classifies the real-time collected Internet traffic based on the absolute majority voting method, including predicting a label from the set of category labels using the decision tree of the random forest model, and representing the prediction output as an N-dimensional vector.

[0016]

[0017] Dimension N includes the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics of the traffic.

[0018] In some specific embodiments, step S4 modifies the characteristics of the random traffic based on OpenFlow's flow table.

[0019] In some specific embodiments, step S4 further includes modifying several features in a preset traffic template and generating corresponding traffic to obtain random traffic input into the virtual bridge of the network range as background traffic. This alternative method of obtaining random traffic allows users of the network range to customize the required traffic input.

[0020] According to a second aspect of the present invention, a system for simulating real traffic in a network test range is proposed, the system comprising:

[0021] The training set construction module is configured to build an initial training set based on preset Internet traffic and user-generated traffic in a network range, including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics as labels.

[0022] The model training module is configured to train a random forest model based on the initial training set;

[0023] The traffic acquisition module is configured to classify real-time collected Internet traffic based on a trained random forest model to obtain random traffic;

[0024] The traffic generation module is configured to modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network range as background traffic.

[0025] According to a third aspect of the present invention, an electronic device is provided, comprising: one or more processors; and a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any implementation of the first aspect.

[0026] According to a fourth aspect of the invention, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the method as described in any implementation of the first aspect.

[0027] This invention proposes a ship early warning system based on maritime target detection, the technical advantages of which are:

[0028] Based on preset internet traffic and user-generated traffic in the network range, an initial training set is constructed, labeled with source IP, destination IP, source port, destination port, service type, packet size, and content characteristics. A random forest model is trained based on the initial training set. The trained random forest model is used to classify real-time collected internet traffic to obtain random traffic. The features of the random traffic are modified, and the modified random traffic is input into the virtual bridge of the network range as background traffic. This greatly improves the realism, randomness, and complexity of traffic simulation in the network range, enhances the efficiency of the training scenario, and enables personnel and organizations to better utilize the network range for various network security-related learning, research, testing, competitions, and exercises, thereby improving network security countermeasure capabilities. Attached Figure Description

[0029] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated in and constitute a part of this specification. The drawings illustrate embodiments and, together with the description, serve to explain the principles of this application. Other embodiments and many anticipated advantages of these embodiments will be readily recognized as they become better understood through reference to the following detailed description. Elements in the drawings are not necessarily to scale. The same reference numerals refer to corresponding similar parts.

[0030] Figure 1This is a flowchart of a method for simulating real traffic in a network test range according to an embodiment of this application;

[0031] Figure 2 This is a flowchart of the training of a random forest model according to a specific embodiment of this application;

[0032] Figure 3 This is a framework diagram of a system for simulating real traffic in a network range, according to a specific embodiment of this application.

[0033] Figure 4 This is a system framework diagram of a specific embodiment of this application, including a domain name resolution module, a virtual machine injection module, and a traffic monitoring module;

[0034] Figure 5 This is a schematic diagram of the structure of a computer device suitable for implementing electronic devices according to embodiments of the present invention. Detailed Implementation

[0035] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0036] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0037] A method for simulating real traffic in a network test range according to an embodiment of this application Figure 1 This is a flowchart of a method for simulating real traffic in a network test range according to an embodiment of this application, as follows: Figure 1 As shown, the method includes:

[0038] S1. Based on the preset Internet traffic and user-generated traffic in the network range, construct an initial training set with labels including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics;

[0039] In some specific embodiments, the construction of the initial training set in step S1 includes classifying the preset Internet traffic and user-generated traffic in the network range based on the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics using a traffic capture tool.

[0040] S2. Train a random forest model based on the initial training set;

[0041] In some specific embodiments, Figure 2This is a flowchart of the training of a random forest model according to a specific embodiment of this application, as shown below. Figure 2 As shown, training a random forest model based on the initial training set specifically includes the following steps:

[0042] S21. Based on the initial training set, a second training set is obtained by sampling with replacement several times.

[0043] S22. Based on the second training set, a number of features are randomly selected to construct a second feature group, wherein the number of features in the selected second feature group is less than the number of features in the original training set;

[0044] S23. Obtain a decision tree based on the second training set and the selected corresponding features;

[0045] S24. Repeat steps S21 to S23 until the number of decision trees reaches the target number, thus obtaining the random forest model.

[0046] S3. Based on the trained random forest model, classify the real-time collected Internet traffic to obtain random traffic;

[0047] In some specific embodiments, the real-time collected internet traffic in step S3 is obtained by receiving internet traffic generated in the internet through a mirror port of a receiving switch. A mirror port is configured on the switch to mirror network traffic to the traffic collection device, and the tcpdump tool is used to classify the traffic based on multiple dimensions such as protocol type, service type, port, and MAC address.

[0048] In some specific embodiments, the trained random forest model described in step S3 classifies the real-time collected Internet traffic based on the absolute majority voting method, including predicting a label from the set of category labels using the decision tree of the random forest model, and representing the prediction output as an N-dimensional vector.

[0049]

[0050] Dimension N includes the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics of the traffic.

[0051] The absolute majority voting method specifically involves predicting a category if more than half of the votes are cast, otherwise rejecting the prediction. This is calculated using the following formula:

[0052]

[0053] S4. Modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network range as background traffic.

[0054] In some specific embodiments, step S4 modifies the characteristics of the random traffic based on OpenFlow's flow table.

[0055] In some specific embodiments, step S4 further includes modifying several features in a preset traffic template and generating corresponding traffic to obtain random traffic input into the virtual bridge of the network testbed as background traffic. Using a pre-collected traffic template, the tcpwrite tool is used to rewrite several features, and the tcpreplay tool is used to generate the traffic, allowing users of the network testbed to customize the required traffic input.

[0056] Figure 3 This is a framework diagram of a system for simulating real traffic in a network test range, as described in a specific embodiment of this application. Figure 3 As shown, the system includes a training set construction module 301, a model training module 302, a traffic acquisition module 303, and a traffic generation module 304. The training set construction module 301 is configured to construct an initial training set based on preset internet traffic and user-generated traffic in a network testbed, using labels including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics. The model training module 302 is configured to train a random forest model based on the initial training set. The traffic acquisition module 303 is configured to classify real-time collected internet traffic based on the trained random forest model to obtain random traffic. The traffic generation module 304 is configured to modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network testbed as background traffic.

[0057] In some optional embodiments, the training set construction module 301, the model training module 302, and the traffic acquisition module 303 can constitute a traffic learning module. Figure 4 This is a system framework diagram of a specific embodiment of this application, including a domain name resolution module, a virtual machine injection module, and a traffic monitoring module, as shown below. Figure 4 As shown, the above system may further include:

[0058] The Domain Name Resolution module is configured to resolve domain names that require targeted resolution in simulated internet scenarios within a network testbed. This is primarily achieved by modifying the relevant source code of the OpenStack Neutron component, adjusting the domain name resolution process, and introducing the IP addresses and domain names requiring targeted resolution. This module utilizes dnsmasq as the domain name resolution tool, leveraging the characteristics of Linux namespaces to create a separate dnsmasq process for each scenario, providing domain name resolution support, and supporting real-time addition and deletion of domain name resolution entries, greatly improving the module's usability.

[0059] Virtual Machine Injection Module: This module is configured to modify the virtual machine's domain name resolution functions, enabling it to connect to the domain name resolution module. This is primarily achieved by modifying the relevant source code of the OpenStackNova components using the cloud-init tool. This involves modifying the virtual machine's initialization configuration file, including but not limited to local domain name resolution configurations, pointing the virtual machine's domain name server IP to the domain name resolution module, and injecting the modified configuration into the virtual machine to achieve virtual machine-side domain name resolution configuration.

[0060] Traffic monitoring and control module: Configured to monitor and filter domain name resolution-related traffic, and block other domain name resolution services that may exist in the usage scenario. This function is mainly implemented at the network layer, using relevant traffic monitoring tools to filter and block domain name resolution traffic, thereby achieving targeted control of domain name resolution. The virtual network cards of the virtual machines in this application are all connected to virtual bridges supporting the OpenFlow protocol. Through the OpenFlow protocol, the source IP, destination IP, source port, destination port, and type of traffic in the bridge are identified, discarding traffic related to domain name resolution services that may be created by ordinary users, and forwarding domain name resolution-related traffic generated by virtual machines in different scenarios to the domain name resolution module.

[0061] As an example, a network testbed is constructed to simulate a real network environment. In this network environment, there is a website with the domain name www.example.com, which needs to be resolved to the virtual machine's IP address 192.168.1.100. First, the domain name resolution module resolves www.example.com to the IP address 192.168.1.100. Then, based on the virtual machine injection module, the domain name resolution-related configuration information is injected into the virtual machine. When a user on the virtual machine accesses www.example.com, the virtual machine will automatically resolve to the corresponding IP address 192.168.1.100. Simultaneously, the traffic learning module and traffic generation module simulate real-world internet traffic such as text, audio, video, and games to improve the efficiency of the training scenario. Furthermore, the traffic monitoring module monitors the domain name resolution-related traffic in the scenario to ensure that only www.example.com is resolved to the IP address 192.168.1.100 in the network environment, avoiding interference from other domain name resolution services.

[0062] Through the above methods, a more realistic network environment can be simulated in the network range, thereby better testing the performance and security of network applications. The virtual machine injection module automatically sets the domain name resolution settings of the virtual machine during creation, eliminating the need for manual intervention and greatly improving the efficiency of scenario construction. The traffic monitoring module can monitor and filter domain name resolution-related traffic in the scenario, effectively preventing interference from other domain name resolution services in the scenario. Furthermore, users can adjust the domain name resolution process according to their needs, introducing IPs and domain names that require targeted resolution, making the method and system of this invention highly flexible and adaptable. By introducing a random forest model, the relevant traffic characteristics of the Internet and the network range can be learned in real time, simulating real Internet traffic in the network range, greatly improving the realism, randomness, and complexity of traffic occurrence and simulation, and enhancing the efficiency of the training scenario. This application is also based on OpenStack components, possessing a relatively mature architecture and functions, and is easy to maintain and upgrade. The system provided in this embodiment can help network security researchers conduct simulation experiments better and improve the level of network security research.

[0063] The following is for reference. Figure 5 It shows a schematic diagram of the structure of a computer system 500 suitable for implementing electronic devices according to embodiments of the present application. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0064] like Figure 5 As shown, the computer system 500 includes a central processing unit (CPU) 501, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 502 or programs loaded from storage section 508 into random access memory (RAM) 503. RAM 503 also stores various programs and data required for the operation of system 500. CPU 501, ROM 502, and RAM 503 are interconnected via bus 504. Input / output (I / O) interface 505 is also connected to bus 504.

[0065] The following components are connected to I / O interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a liquid crystal display (LCD) and speakers, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card and a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to I / O interface 505 as needed. A removable medium 511, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 510 as needed so that computer programs read from it can be installed into storage section 508 as needed.

[0066] Specifically, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable storage medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by central processing unit (CPU) 501, it performs the functions defined in the methods of this application. It should be noted that the computer-readable storage medium of this application can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable storage medium other than a computer-readable storage medium that can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. Program code contained on a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0067] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0068] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0069] The modules described in the embodiments of this application can be implemented in software or in hardware.

[0070] In another aspect, this application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: construct an initial training set based on preset Internet traffic and user-generated traffic in a network range, including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics as labels; train a random forest model based on the initial training set; classify real-time collected Internet traffic based on the trained random forest model to obtain random traffic; modify the characteristics of the random traffic, and input the modified random traffic into the virtual bridge of the network range as background traffic.

[0071] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A method for simulating real traffic in a network test range, characterized in that, include: S1. Based on the preset Internet traffic and user-generated traffic in the network range, construct an initial training set with labels including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics; S2. Train a random forest model based on the initial training set; S3. Classify the real-time collected Internet traffic based on the trained random forest model to obtain random traffic; wherein, the real-time collected Internet traffic is obtained by receiving the traffic generated in the Internet through the mirror port of the receiving switch. S4. Modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network test range as background traffic; wherein, the random traffic is modified based on the flow table of OpenFlow; and based on the preset traffic template, several characteristics in the traffic template are modified and corresponding traffic is generated to obtain random traffic input into the virtual bridge of the network test range as background traffic. The method further includes: S5. For domain names that require targeted resolution in simulated Internet scenarios under network test ranges, the relevant source code of the OpenStackNeutron component is modified to adjust the domain name resolution process and introduce the IP address and domain name that need targeted resolution; dnsmasq is used as the domain name resolution tool, and the characteristics of Linux namespaces are used to create a separate dnsmasq process for each scenario. S6. Modify the domain name resolution related functions of the virtual machine to enable the virtual machine to connect to the domain name resolution service; specifically, this includes: modifying the relevant source code of the OpenStackNova component, using the cloud-init tool to modify the initialization configuration file of the virtual machine, the initialization configuration file includes the local domain name resolution related configuration of the virtual machine, pointing the domain name resolution server IP of the virtual machine to the domain name resolution service provided by the dnsmasq process, and injecting the modified initialization configuration file into the virtual machine; S7. Monitor and filter domain name resolution-related traffic, and block other domain name resolution services in the usage scenario; specifically, this includes: using relevant traffic monitoring tools at the network layer to filter and block domain name resolution traffic; wherein, the virtual network cards of the virtual machines are all connected to virtual bridges that support the OpenFlow protocol. Through the OpenFlow protocol, the source IP, destination IP, source port, destination port, and type of traffic in the bridge are identified, and traffic related to other domain name resolution services is discarded. Furthermore, the domain name resolution-related traffic generated by the virtual machines in different scenarios is forwarded to the domain name resolution service provided by the dnsmasq process.

2. The method for simulating real traffic in a network test range according to claim 1, characterized in that, The construction of the initial training set in step S1 includes classifying the preset Internet traffic and user-generated traffic in the network range based on the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics using a traffic capture tool.

3. The method for simulating real traffic in a network test range according to claim 1, characterized in that, Step S2, which involves training a random forest model based on the initial training set, specifically includes the following steps: S21. Based on the initial training set, a second training set is obtained by sampling with replacement several times. S22. Based on the second training set, a number of features are randomly selected to construct a second feature group, wherein the number of features in the selected second feature group is less than the number of features in the original training set; S23. Obtain a decision tree based on the second training set and the selected corresponding features; S24. Repeat steps S21 to S23 until the number of decision trees reaches the target number, thus obtaining the random forest model.

4. The method for simulating real traffic in a network test range according to claim 3, characterized in that, Step S3 describes the trained random forest model classifying real-time collected internet traffic based on the absolute majority voting method. This includes predicting a label from the set of category labels using the decision tree of the random forest model, and representing the prediction output as an N-dimensional vector. Dimension N includes the source IP, destination IP, source port, destination port, service type, packet size, and content characteristics of the traffic.

5. A system for simulating real traffic in a network test range using the method described in any one of claims 1-4, characterized in that, The system includes: The training set construction module is configured to build an initial training set based on preset Internet traffic and user-generated traffic in a network range, including source IP, destination IP, source port, destination port, service type, packet size, and content characteristics as labels. The model training module is configured to train a random forest model based on the initial training set; The traffic acquisition module is configured to classify real-time collected Internet traffic based on a trained random forest model to obtain random traffic; The traffic generation module is configured to modify the characteristics of the random traffic and input the modified random traffic into the virtual bridge of the network range as background traffic.

6. An electronic device, comprising: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Network scene simulation background flow generation and management method and device

    CN110289984A

  • Classification processing method and system for information interaction data

    CN115456070A