Business identification method, system, device, storage medium and program product

CN117354182BActive Publication Date: 2026-09-22ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210740126.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-28
Publication Date
2026-09-22
Estimated Expiration
2042-06-28

AI Technical Summary

Technical Problem

[0003]然而,对于采取完全加密方式的网络业务,例如采用基于DoH(DNS over HTTPS)、DoQ(DNS over QUIC)的DNS协议以及基于ECH(Encrypted ClientHello)的HTTPS协议及QUIC协议进行加密的网络业务,网络流量中的DNS域名和SNI(Service Name Indication)都加密不可见,致使DPI难以获取DNS域名、SNI等常见的明文流量特征信息,导致对业务类型的识别能力下降

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117354182B_ABST
    Figure CN117354182B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a service identification method, system, device, storage medium and program product, the first domain name system message is obtained, then the first traffic information of the target service is obtained according to the first domain name system message, the first mapping relationship between the target service and the domain name information and the first traffic statistical characteristics of the target service are obtained according to the first traffic information, then the second domain name system message is obtained according to the domain name information, the second traffic information is obtained according to the second domain name system message, and the related IP address of the domain name information is obtained according to the second traffic information, the current service is identified according to the first mapping relationship, the related IP address and the first traffic statistical characteristics, and the identification capability of the DPI system for the encrypted service is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and more specifically, to a service identification method, system, device, storage medium, and program product. Background Technology

[0002] Deep Packet Inspection (DPI) technology is used to identify service categories in user internet traffic. It mainly relies on plaintext features in user traffic (such as domain names in DNS, hosts in HTTP, and SNI in HTTPS / TLS / QUIC) to quickly distinguish and identify service categories, thereby enabling network element devices or network management systems to perform various functions such as statistics, billing, and quality difference analysis by service category.

[0003] However, for network services that employ full encryption, such as those using DNS protocols based on DoH (DNS over HTTPS) and DoQ (DNS over QUIC), and HTTPS and QUIC protocols based on ECH (Encrypted ClientHello), the DNS domain names and SNI (Service Name Indication) in the network traffic are encrypted and invisible. This makes it difficult for DPI to obtain common plaintext traffic characteristic information such as DNS domain names and SNI, resulting in a decrease in its ability to identify service types. Therefore, how to enable DPI to identify services in fully encrypted user traffic is an urgent problem that needs to be discussed and solved. Summary of the Invention

[0004] This application provides a service identification method, system, device, storage medium, and program product, aiming to improve the DPI system's ability to identify encrypted services.

[0005] In a first aspect, embodiments of this application provide a service identification method, the method comprising: acquiring a first Domain Name System (DNS) message; obtaining first traffic information of a target service based on the first DNS message, the first traffic information including domain name information; obtaining a first mapping relationship between the target service and the domain name information and a first traffic statistical feature of the target service based on the first traffic information; acquiring a second DNS message based on the domain name information, obtaining second traffic information based on the second DNS message, and obtaining a related IP address of the domain name information based on the second traffic information; and performing time-series statistical feature matching based on the first mapping relationship, the related IP address, and the first traffic statistical feature to identify the current service.

[0006] Secondly, embodiments of this application provide a service identification system, comprising: a sampling module, configured to acquire a first domain name system message, and obtain first traffic information of a target service based on the first domain name system message, wherein the first traffic information includes domain name information; a training module, configured to obtain a first mapping relationship between the target service and the domain name information and a first traffic statistical feature of the target service based on the first traffic information; and a matching module, configured to acquire a second domain name system message based on the domain name information, obtain second traffic information based on the second domain name system message, obtain the relevant IP address of the domain name information based on the second traffic information, and perform time-series statistical feature matching based on the first mapping relationship, the relevant IP address, and the first traffic statistical feature to identify the current service.

[0007] Thirdly, embodiments of this application provide a service identification device, including a memory and a processor. The memory stores a program, and when the program is read and executed by the processor, it implements the service identification method of the first aspect.

[0008] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions for performing the service identification method as described in the first aspect.

[0009] Fifthly, embodiments of this application provide a computer program product, including a computer program or computer instructions, wherein the computer program or computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium, and the processor executes the computer program or computer instructions, causing the computer device to perform the business identification method as described in the first aspect. Attached Figure Description

[0010] Figure 1 A flowchart illustrating a service identification method provided in an embodiment of this application;

[0011] Figure 2 for Figure 1 Detailed flowchart of step S3000;

[0012] Figure 3 A schematic diagram of the first-level mapping relationship and the second-level mapping relationship in a service identification method provided in an embodiment of this application;

[0013] Figure 4 A schematic diagram of the first mapping relationship in a service identification method provided in an embodiment of this application;

[0014] Figure 5 for Figure 1Detailed flowchart of step S4000;

[0015] Figure 6 for Figure 1 Detailed flowchart of step S5000;

[0016] Figure 7 for Figure 6 Detailed flowchart of step S5100;

[0017] Figure 8 for Figure 7 Detailed flow diagram of step S5110;

[0018] Figure 9 A schematic diagram illustrating the fifth mapping relationship between relevant IP addresses in a service identification method provided in an embodiment of this application;

[0019] Figure 10 for Figure 6 Detailed flowchart of step S5200;

[0020] Figure 11 A schematic diagram illustrating time window division in a service identification method provided in an embodiment of this application;

[0021] Figure 12 This is a schematic diagram illustrating the value range of traffic statistical features in each time window in a service identification method provided in an embodiment of this application.

[0022] Figure 13 for Figure 10 Schematic diagram of step S5230;

[0023] Figure 14 This is a schematic diagram of a service identification system provided in an embodiment of this application. Detailed Implementation

[0024] It should be noted that although functional modules are divided in the system diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order shown in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0025] In the description of the embodiments of this application, unless otherwise expressly limited, terms such as "setting," "installing," and "connecting" should be interpreted broadly. Those skilled in the art can reasonably determine the specific meaning of the above terms in the embodiments of this application in conjunction with the specific content of the technical solution. In the embodiments of this application, terms such as "furthermore," "exemplarily," or "optionally" are used to indicate that they are examples, illustrations, or descriptions, and should not be construed as being more preferred or more advantageous than other embodiments or design solutions. The use of terms such as "furthermore," "exemplarily," or "optionally" is intended to present the relevant concepts in a specific manner.

[0026] DPI is used to identify the service category in a user's internet traffic. It mainly relies on the plaintext features in the user traffic to quickly distinguish and identify the service category, thereby enabling network element devices or network management systems to perform multiple functions such as statistics, billing, and quality difference analysis according to service category.

[0027] The mainstream protocols in the current Internet are Domain Name System (DNS), Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS), and Quick UDP Internet Connection (QUIC). Among them, DNS and HTTP are plaintext, while HTTPS and QUIC are encrypted.

[0028] In recent years, to protect user privacy and online security, more and more online services (such as websites and applications) are adopting encryption methods, leading to a growing adoption of HTTPS and QUIC. The Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols upon which HTTPS is based have also evolved, from TLS 1.2 to TLS 1.3. A significant change in TLS 1.3 is that unnecessary plaintext extension fields in the ClientHello and ServerHello messages are now encrypted, and the Certificate message itself is completely encrypted. The QUIC protocol has also evolved from the initial Google gQUIC to the formal IETF-QUIC, which completely encrypts the initial ClientHello message. The DNS protocol has evolved from plaintext to DoH (DNS over HTTPS) and DoQ (DNS over QUIC), ensuring that domain names in DNS request messages, IP addresses in DNS response messages, and domain names and aliases are no longer visible in plaintext.

[0029] Currently, while the initial ClientHello message in QUIC is entirely encrypted, its key can be calculated using the salt value and public encryption algorithm disclosed in a series of related protocols (Request For Comments, RFCs). Therefore, the content of this message is essentially publicly visible to network devices, constituting pseudo-encryption of ClientHello. However, the IETF's ECH (Encrypted ClientHello) protocol represents true encryption of ClientHello, rendering the content of TLS and QUIC ClientHello messages undecryptable and no longer visible to network devices.

[0030] For DPI (Deep Packet Indication) devices, the domain name and IP address in DNS request / response messages, the Host field in HTTP requests, and the Server Name Indication (SNI) extended field in SSL / TLS / QUIC ClientHello messages are all important features for DPI service identification and classification.

[0031] Currently, network traffic using DNS based on DoH or DoQ and QUIC with pseudo-encrypted ClientHello is already present. This forces DPI devices to decrypt the pseudo-encrypted QUIC ClientHello to obtain the SNI information for service identification. In the future, if network traffic using DNS based on DoH or DoQ and HTTPS / TLS / QUIC with true encryption based on ECH ClientHello (i.e., fully encrypted traffic) appears, DPI will be unable to use existing technologies for service identification, resulting in a significant drop in DPI identification rate and severely impacting DPI identification capabilities. DPI service identification has become a fundamental function in various network devices. With the increasing volume of user traffic in 5G networks, DPI is needed for service identification to allocate different network bearer resources to services of different priorities, ensuring resource matching with service needs and preventing resource waste while ensuring normal service operation. For example, 5G's key service, Extended Reality (XR), needs to be identified through DPI (Data Point Indicator) before network resources can be allocated to ensure its priority protection. XR is an important application in the field of network QoS / QoE (Quality of Service / Quality of Experience).

[0032] Based on this, embodiments of this application provide a service identification method, system, device, storage medium, and program product. By obtaining a first Domain Name System (DNS) message, then obtaining first traffic information of the target service based on the first DNS message, obtaining a first mapping relationship between the target service and domain name information and a first traffic statistical feature of the target service based on the first traffic information, then obtaining a second DNS message based on the domain name information, obtaining second traffic information based on the second DNS message, and obtaining the relevant IP address of the domain name information based on the second traffic information, and performing time-series statistical feature matching based on the first mapping relationship, the relevant IP address, and the first traffic statistical feature to identify the current service, thereby improving the DPI system's ability to identify encrypted services and ensuring normal service identification of the DPI in the above scenarios.

[0033] In this embodiment, the execution entity of the service identification method is a service identification system, which includes a service identification device. This device can be a standalone DPI device, a gateway / router / firewall with built-in DPI functionality, etc. The sampling target of the service identification method can be network terminal devices such as mobile phones and tablets.

[0034] Reference Figure 1 , Figure 1 The flowchart of a service identification method provided in an embodiment of this application includes, but is not limited to, steps S1000, S2000, S3000, S4000 and S5000.

[0035] Step S1000: Obtain the first domain name system message.

[0036] In some embodiments, the sampling terminal is configured as a plaintext DNS server. The sampling terminal initiates various services to the DNS server and sends query requests to the DNS server. Based on the response message returned by the DNS server, the first domain name system message is obtained.

[0037] In some embodiments, the sampling terminal can initiate one or more query requests to the DNS server for the same service, thereby achieving multiple sampling and obtaining multiple first domain name system messages for the same service based on the multiple response messages returned by the DNS server.

[0038] In some embodiments, the sampling terminal can initiate one or more query requests to the DNS server for multiple services, thereby enabling multiple sampling of multiple services and obtaining multiple first domain name system messages for different services based on the multiple response messages returned by the DNS server.

[0039] It should be noted that there can be multiple DNS servers, and the sampling terminal can send query requests to multiple DNS servers. A DNS server can be a server provided by a service provider that stores resource record mappings of types such as domain names and IP addresses.

[0040] Step S2000: Obtain the first traffic information of the target service based on the first domain name system message. The first traffic information includes domain name information.

[0041] In some embodiments, the sampling terminal can initiate the same service to the DNS server multiple times, which will generate traffic information for several domain names. After multiple samplings, the first domain name system message of each sampling is obtained. The first traffic information of each service is obtained based on the first domain name system message. The first traffic information includes one or more domain name information of the service, and the domain name information includes the domain names of several traffic.

[0042] In some embodiments, the sampling terminal can initiate different services to the DNS server, generate traffic information of several domain names in different services, sample each service multiple times, and obtain the first traffic information of each service each time. The first traffic information includes the domain name information of each service, which includes the domain names of several traffic.

[0043] Step S3000: Based on the first traffic information, obtain the first mapping relationship between the target service and the domain name information and the first traffic statistical characteristics of the target service.

[0044] In some embodiments, the sampling terminal can initiate the same service or different services to the DNS server multiple times, and obtain the first mapping relationship between the target service and domain name information based on the first traffic information of the service, including the first mapping relationship between the service name of the target service and the domain name. This first mapping relationship can be a mapping relationship from service name to domain name. The first traffic statistical characteristics of the target service are obtained, including but not limited to at least one of the following: range of concurrent TCP connections, range of concurrent UDP connections, range of the ratio of average uplink rate to average downlink rate, range of the ratio of uplink traffic to downlink traffic, range of different network-side port numbers, and range of different domain names.

[0045] In some embodiments, the first mapping relationship may be a mapping relationship from a domain name to a business name.

[0046] In some embodiments, the first mapping relationship may be a mapping relationship from a business name to a domain name.

[0047] In some embodiments, the first mapping relationship may be a mapping relationship from domain name to business name, and then from business name to domain name.

[0048] In some embodiments, the first mapping relationship may be a mapping relationship from business name to domain name, and then from domain name to business name.

[0049] In some embodiments, such as Figure 2 As shown, Figure 2 This is a detailed flowchart of step S3000, which includes the following steps:

[0050] Step S3100: Obtain the domain name information corresponding to the business information and establish a first-level mapping relationship from business information to domain name information.

[0051] It should be noted that the first traffic information includes business information, which includes the business name (or business type). Network services can involve access to multiple different servers; therefore, the business information may contain different domain names corresponding to the same target business. For example, the same business name may correspond to different domain names, or different business names may correspond to the same domain name. First, the domain name information corresponding to the business information can be obtained from the first traffic information, establishing a first-level mapping relationship from business information to domain name information. This allows one or more corresponding domain names to be found from the business information. For example... Figure 3 As shown, business 1 corresponds to domain 1, domain 2, and domain 3, and business 2 corresponds to domain 1, domain 3, and domain 4. After establishing a first-level mapping relationship from business information to domain information, you can find the corresponding domain 1, domain 2, and domain 3 through business 1, and find the corresponding domain 1, domain 3, and domain 4 through business 2.

[0052] Step S3200: Obtain the business information corresponding to the domain name information and establish a two-level mapping relationship from domain name information to business information.

[0053] It should be noted that since the same business information can correspond to different domain names, and the same domain name can correspond to different business information, it is possible to obtain the business information corresponding to the domain name information and establish a two-level mapping relationship from domain name information to business information. For example, ... Figure 3 As shown, domain name 1 corresponds to business 1 and business 2, domain name 2 corresponds to business 1 and business x, domain name 3 corresponds to business 1, business 2 and business y, and domain name 4 corresponds to business 2. You can find the corresponding business 1 and business 2 through domain name 1, business 1 and business x through domain name 2, business 1, business 2 and business y through domain name 3, and business 2 through domain name 4.

[0054] Step S3300: Based on the secondary mapping relationship and the primary mapping relationship, generate a first mapping relationship that links business information and domain name information.

[0055] In some embodiments, the first mapping relationship is an association from domain name information to business information, and then from business information back to domain name information, for example, such as... Figure 4As shown, the first mapping relationship is an association from domain name to business name, and then from business name to domain name. According to the first mapping relationship, one or more businesses corresponding to a domain name can be found through the domain name, and then other domain names of one or more businesses can be found. For example, domain name 1 corresponds to business 1 and business 2. Business 1 corresponds to domain name 1, domain name 2 and domain name 3 respectively. Business 2 corresponds to domain name 1, domain name 3 and domain name 4 respectively. Business 1 and business 2 can be found through domain name 1, and then domain name 1, domain name 2, domain name 3 and domain name 4 corresponding to business 1 and business 2 can be found.

[0056] Step S4000: Obtain the second Domain Name System (DNS) message based on the domain name information, obtain the second traffic information based on the second DNS message, and obtain the relevant IP address of the domain name information based on the second traffic information;

[0057] In some embodiments, second Domain Name System (DNS) messages are actively and continuously collected based on domain name information. Second traffic information is obtained based on the second DNS messages. The relevant IP address corresponding to the domain name information can be obtained based on the second traffic information. Figure 5 , Figure 5 A detailed flowchart of step S4000 is provided, including steps S4100, 4200, and 4300:

[0058] Step S4100: Initiate a DNS query request to the DNS server based on the domain name information.

[0059] Step S4200: Receive the response message returned by the DNS server; wherein the response message includes a second Domain Name System message.

[0060] Step S4300: Obtain the second traffic information based on the second Domain Name System message, and obtain the relevant IP address corresponding to the domain name information based on the second traffic information.

[0061] It should be noted that the business identification system, acting as a DNS client, periodically and proactively initiates DNS query requests to designated DNS servers based on domain name information. The DNS server responds to the query request by sending a response message, including IP addresses, to the business identification system. The business identification system receives the response message from the DNS server and obtains the relevant IP addresses corresponding to the domain name information based on this response message. The business identification system can communicate with one or more DNS servers. Different DNS servers may return different results. Querying the same domain name from multiple different DNS servers can yield a more comprehensive set of IP addresses. For example, to query the IP address corresponding to domain name 1, DNS query requests can be initiated to different DNS servers. DNS server 1 returns IP address 1 and IP address 2, DNS server 2 returns IP address 3 and IP address 4, thus obtaining four IP addresses related to domain name 1.

[0062] In some embodiments, the domain name information may be the domain name information corresponding to a certain business information in the second traffic information, and the corresponding domain name information is obtained through the business information.

[0063] In some embodiments, the domain name information may be all domain name information obtained through the first mapping relationship. For example, obtain the domain name of a certain business, then find multiple business names corresponding to the domain name according to the first-level mapping relationship, and then find all domain names corresponding to the multiple business names according to the second-level mapping relationship. Then, initiate a query request to the DNS server based on all these domain names to obtain the relevant IP addresses corresponding to all these domain names and establish a cached IP address set.

[0064] It should be noted that the business identification system obtains the Time To Live (TTL) information corresponding to the domain name information based on the response message returned by DNS. Based on this TTL information, it determines whether there are any expired IP addresses among the relevant IP addresses. If there are expired IP addresses among the relevant IP addresses, the expired IP addresses are deleted, and the association between the expired IP addresses and the domain names is also deleted.

[0065] Step S5000: Based on the first mapping relationship, the relevant IP address and the first traffic statistical feature, perform time-series statistical feature matching to identify the current service.

[0066] In some embodiments, refer to Figure 6 , Figure 6 This is a detailed flowchart of step S5000, including steps S5100 and S5200:

[0067] Step S5100: Determine the relevant services for the current business based on the first mapping relationship and the relevant IP addresses.

[0068] Step S5200: Perform time-series statistical feature matching on relevant services based on the first traffic statistical features to identify the current service.

[0069] In some embodiments, the second traffic information may contain zero or one or more related services corresponding to the current service. If there are zero related services, it means that there are no related services corresponding to the current service in the second traffic information, indicating that the service identification has failed. If there are one or more related services corresponding to the current service in the second traffic information, the time-series statistical features of the related services are matched according to the first traffic statistical features, thereby identifying the current service.

[0070] In some embodiments, the association between a service name and domain name information can be found based on the first mapping relationship. Multiple related IP addresses corresponding to the domain name information can be found through the domain name information, forming a cached IP address set. When identifying the current service, the current IP address of the current service can be obtained and matched with the cached IP address set. If the current IP address matches the cached IP address set successfully, the relevant traffic information of the relevant service corresponding to the current IP address is obtained, thereby determining the relevant service corresponding to the current service. Then, the second traffic statistical feature in the relevant traffic information is matched with the first traffic statistical feature, thereby identifying the current service.

[0071] In some embodiments, refer to Figure 7 , Figure 7 The detailed flowchart of step S5100 includes steps S5110, S5120, and S5130:

[0072] Step S5110: Establish a cached IP address set based on the relevant IP addresses and the first mapping relationship;

[0073] In some embodiments, the business information corresponding to the domain name information in the second traffic information can be found through the first mapping relationship, and all IP addresses corresponding to the business information can be found based on the business information, thereby establishing a cached IP address set.

[0074] In some embodiments, a second mapping relationship between relevant IP addresses and domain name information can be established, and the relevant IP addresses can be expanded more comprehensively based on the first and second mapping relationships. (See reference...) Figure 8 , Figure 8 The detailed flowchart of step S5110 includes steps S5111, S5112, S5113, and S5114:

[0075] Step S5111: Establish a second mapping relationship between relevant IP addresses and domain name information, and establish a third mapping relationship between relevant IP addresses and business information based on the first and second mapping relationships.

[0076] Reference Figure 9 , Figure 9This is a diagram illustrating the fifth mapping relationship between relevant IP addresses. It should be noted that during the network traffic processing phase, the mapping relationship from IP address to domain name can be obtained through proactive DNS collection; this is the second mapping relationship between IP address and domain name. A second mapping relationship between relevant IP address and domain name information is then established. Since the first mapping relationship includes a second-level mapping relationship from domain name information to business information, a third mapping relationship between relevant IP address and business information can be established based on this second-level mapping relationship. The third mapping relationship can be from relevant IP address to domain name information, and then from domain name information to business information, for example, IP address 1 - domain name 1 - business 1, IP address 1 - domain name x - business x.

[0077] Step S5112: Establish a fourth mapping relationship between relevant IP addresses and domain name information based on the first and third mapping relationships.

[0078] It should be noted that since the first mapping relationship includes the association information between business information and domain name information, such as from domain name 1 to business 1, and then from business 1 to domain name 1 and domain name 2, all domain name information corresponding to business information can be found. Based on the first and third mapping relationships, a fourth mapping relationship between relevant IP addresses and domain name information is established, including from IP address to domain name information, then from domain name information to business information, and then from business information to domain name information. For example, IP address 1-domain name 1-business 1-domain name 1 (domain name 2, domain name 3), IP address 1-domain name 1-business 2-domain name 1 (domain name 3, domain name 4).

[0079] Step S5113: Establish a fifth mapping relationship between relevant IP addresses based on the second and fourth mapping relationships.

[0080] It should be noted that since the second mapping relationship includes the association between relevant IP addresses and domain name information, all domain name information corresponding to relevant IP addresses can be found based on the second mapping relationship. Therefore, a fifth mapping relationship between relevant IP addresses can be established based on the second mapping relationship, including from relevant IP address to domain name information, then from domain name information to business information, then from business information to domain name information, and then from domain name information to relevant IP address. For example, IP address 1-domain name 1-business 1-domain name 2-IP address x.

[0081] Step S5114: Based on the fifth mapping relationship, establish a set of cached IP addresses corresponding to each domain name information.

[0082] It should be noted that, based on the fifth mapping relationship, the corresponding domain name information can be found based on the relevant IP address of a certain target business, and then all relevant IP addresses corresponding to that domain name information can be found, and all relevant IP addresses can be used as a cache IP address set.

[0083] In one embodiment, the existence of expired IP addresses in the cached IP address set can be determined based on the time-to-live information. If expired IP addresses exist in the cached IP address set, the expired IP addresses are deleted from the cached IP address set, and the association between the expired IP addresses and the domain names is also deleted.

[0084] Step S5120: Obtain the current IP address of the current service and match the current IP address with the cached IP address set.

[0085] In one embodiment, during the process of identifying the current service, the current IP address of the current service is obtained, and the current IP address is matched with all relevant IP addresses in the cached IP address set.

[0086] In one embodiment, during the identification of the current service, the current IP address of the current service is obtained, and the current IP address is matched with a subset of relevant IP addresses in the cached IP address set. For example, the current IP address is first matched with 50% of the relevant IP addresses in the cached IP address set, and then it is determined whether to match it with the other 50% of the relevant IP addresses based on the matching results. The specific number of relevant IP addresses in the cached IP address set to be matched first can be determined according to the actual situation, and this embodiment does not impose a specific limitation.

[0087] In one embodiment, the system can obtain the four-tuple (i.e., source IP address, destination IP address, TCP source port, TCP destination port) of a Transmission Control Protocol (TCP) packet, establish a TCP flow context, and compare the first IP packet of the TCP flow context with each relevant IP address in the cached IP address set.

[0088] In one embodiment, the system establishes a UDP flow context based on the four-tuple (source IP address, destination IP address, UDP source port, and UDP destination port) of the User Datagram Protocol (UDP) packet, and compares the first IP packet of the UDP flow context with each relevant IP address in the cached IP address set.

[0089] Step S5130: If the current IP address matches the cached IP address set, obtain the relevant traffic information of the relevant service corresponding to the current IP address.

[0090] In one embodiment, if the current IP address successfully matches the cached IP address set, it indicates that one or more related services corresponding to the current IP address have been found, and the relevant traffic information of the related services can be obtained. Since the fifth mapping relationship includes the association between related IP address, domain name information, service information, domain name information, and related IP address, the service names of all related services can be found based on the current IP address, thereby obtaining the relevant traffic information of each related service.

[0091] In some embodiments, refer to Figure 10 , Figure 10 The detailed flowchart of step S5200 includes steps S5210, S5220, and S5230:

[0092] Step S5210: Divide the first traffic information in the target service into time windows to obtain multiple time windows; wherein, the time window includes multiple first traffic statistical features.

[0093] In some embodiments, during the sample sampling phase, a target service is sampled multiple times to obtain first traffic information after multiple samplings. The first traffic information of the target service with the longest service time during the multiple sampling processes can be obtained. This first traffic information is then divided into multiple time windows, and traffic statistics information for the first traffic information within each time window is obtained. These traffic statistics information includes first traffic statistical features, and each time window includes multiple first traffic statistical features. For example, refer to... Figure 11 and Figure 12 Business 1 is divided into m time windows, including T1, T2, T3, and Tm, where time window T1 = (t1 - t0), time window T2 = (t2 - t1), and time window T3 = (t3 - t2). Traffic statistics for business 1 within T1, T2, and T3 are obtained respectively. The T1 time window includes statistics on the first traffic statistical feature A, first traffic statistical feature B, and first traffic statistical feature C; the T2 time window includes statistics on first traffic statistical feature A, first traffic statistical feature C, first traffic statistical feature D, and first traffic statistical feature E; and the Tm time window includes statistics on first traffic statistical feature D and first traffic statistical feature X.

[0094] Step S5220: Calculate the value range of the first flow statistical feature in each time window.

[0095] In some embodiments, each first traffic statistical feature has a corresponding first statistical feature value. Since the same time window includes multiple identical first traffic statistical features, the same first traffic statistical feature has multiple first statistical feature values ​​within the same time window. Therefore, the value range of the same first traffic statistical feature can be obtained, thereby obtaining the value range of different first traffic statistical features in different time windows. For example, referring to... Figure 11 and Figure 12 There are m time windows. In time window T1, the value range of the first flow statistical feature A is [a1, a2], the value range of the first flow statistical feature B is [b1, b2], and the value range of the first flow statistical feature C is [c1, c2]. In time window T2, the value range of the first flow statistical feature A is [a3, a4], the value range of the first flow statistical feature C is [c1, c2], the value range of the first flow statistical feature D is [d1, d2], and the value range of the first flow statistical feature E is [e1, e2]. In time window Tm, the value range of the first flow statistical feature D is [d3, d4], and the valid value range of the first flow statistical feature X is [x1, x2].

[0096] Step S5230: Based on the relevant traffic information, obtain the second traffic statistical characteristics of the relevant services, calculate the second statistical characteristic value of the second traffic statistical characteristics, and match the second statistical characteristic value with the value range.

[0097] In some embodiments, refer to Figure 13 , Figure 13 This is a detailed flowchart of step S5230, including steps S5231, S5232, and S5233:

[0098] Step S5231: Divide the relevant traffic information into time windows according to each time window.

[0099] It should be noted that, referring to Figure 12 , Figure 12 Within the dashed box, the relevant IP addresses in the cached IP address set corresponding to service 1 include IP address 1, IP address X, and IP address Y. The relevant traffic information for the relevant services corresponding to these relevant IP addresses is obtained, and this relevant traffic information is divided into time windows. Different time windows include multiple different second traffic statistical features, and the same time window includes different second traffic statistical features. The specific time window division method for relevant traffic information is similar to that for the first traffic information time window division, and will not be elaborated upon in this embodiment.

[0100] Step S5232: Calculate the second statistical characteristic value of each second flow statistical characteristic in each time window.

[0101] Step S5233: If at least one of the second statistical feature values ​​is within the range, then the second statistical feature value is determined to match the range, and the current business identification is successful.

[0102] It should be noted that the second statistical feature value of the second flow statistical feature is calculated in each time window, and the second statistical feature value is matched with the value range of the corresponding time window. If the second flow statistical feature value is within the value range of the corresponding time window, then the second statistical feature value is determined to match the time window.

[0103] In some embodiments, if the second statistical feature values ​​of each second traffic statistical feature are all within the value range corresponding to each time window, it indicates that each time window of a certain service is completely matched, and the current service is identified as that service, that is, the current service is successfully identified. For example, refer to Figure 11 and Figure 12 The second traffic statistics feature A represents the number of concurrent TCP connections within the time window. a1 is 44 and a2 is 66. The value range of the second traffic statistics feature A in the T1 time window is [44, 66]. During the identification of the current service, the number of concurrent TCP connections of the IP address of the second traffic statistics feature A in the T1 time window falls within this range. For example, if the number of concurrent TCP connections is 55, it means that the second traffic statistics feature A of service 1 matches in the T1 time window.

[0104] In some embodiments, if the second statistical feature value of at least one second traffic statistical feature is within the value range corresponding to each time window, it means that each time window of a certain service is completely matched, and the current service is identified as that service, that is, the current service is successfully identified.

[0105] In some embodiments, if the value of the second statistical feature of at least one second traffic statistical feature is within the value range corresponding to at least one time window, it indicates that the time window of a certain service is matched, and the current service is identified as that service, that is, the current service is successfully identified.

[0106] In some embodiments, if each service in the relevant business cannot be matched with the value range, it means that there is no identifiable service in the relevant business, which means that the current service identification has failed.

[0107] In some embodiments, if the current service is successfully identified, the service that was not identified in the relevant services is abandoned.

[0108] In some embodiments, if the current service is successfully identified, the associated IP address corresponding to the current service is obtained according to the fifth mapping relationship, and the traffic information corresponding to the associated IP address is identified as the current service within a preset time period. For example, refer to Figure 11 and Figure 12 If the current service is identified as service 1, then the traffic information of IP addresses such as IP address 1, IP address X, and IP address Y associated with service 1 in the subsequent period will also be identified as service 1, indicating that the user is executing service 1.

[0109] One embodiment of this application also provides a service identification system, referring to... Figure 14 The business identification system includes:

[0110] The sampling module 100 is used to acquire the first domain name system message, obtain the first traffic information of the target service based on the first domain name system message, and obtain the relevant IP address of the target service based on the domain name information; wherein, the first traffic information includes the domain name information;

[0111] Training module 200 is used to obtain the first mapping relationship between the target service and the domain name information and the first traffic statistical characteristics of the target service based on the first traffic information;

[0112] The matching module 300 is used to obtain the second domain name system message based on the domain name information, obtain the second traffic information based on the second domain name system message, obtain the relevant IP address of the domain name information based on the second traffic information, and perform time-series statistical feature matching based on the first mapping relationship, the relevant IP address and the first traffic statistical features to identify the current business.

[0113] An embodiment of this application also provides a service identification device, which includes a memory and a processor. The memory stores a program, and when the program is read and executed by the processor, it implements the service identification method described in the above embodiment.

[0114] An embodiment of this application also provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the service identification method described above.

[0115] An embodiment of this application also provides a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the service identification method described above.

[0116] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0117] The non-transitory software program and instructions required to implement the service identification method of the above embodiments are stored in memory. When executed by the processor, the service identification method of the above embodiments is executed.

[0118] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0119] Furthermore, embodiments of this application also provide a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. The processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the above-described business identification method.

[0120] The above is a detailed description of the preferred embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

Claims

1. A business identification method, the method comprising: Get the first domain name system message; Based on the first domain name system message, the first traffic information of each target service is obtained; wherein, the first traffic information includes domain name information; Based on the first traffic information, a first mapping relationship between each target service and the domain name information and a first traffic statistical characteristic of each target service are obtained; Obtain a second Domain Name System (DNS) message based on the domain name information, obtain second traffic information based on the second DNS message, and obtain the relevant IP address of the domain name information based on the second traffic information; Based on the first mapping relationship, the relevant IP address, and the first traffic statistics feature, the current service is identified; The step of identifying the current service based on the first mapping relationship, the relevant IP address, and the first traffic statistics feature includes: Obtain the current IP address of the current service, and determine the relevant service corresponding to the current IP address based on the first mapping relationship, the relevant IP address, and the current IP address; Based on the first traffic statistics feature, the relevant traffic information of the relevant services corresponding to the current IP address is matched with time-series statistics features to identify the current service from the relevant services.

2. The service identification method as described in claim 1, characterized in that, The first traffic information includes service information. The step of obtaining a first mapping relationship between each target service and the domain name information based on the first traffic information includes: Obtain the domain name information corresponding to the business information, and establish a first-level mapping relationship from the business information to the domain name information; Obtain the business information corresponding to the domain name information, and establish a two-level mapping relationship from the domain name information to the business information; Based on the secondary mapping relationship and the primary mapping relationship, a first mapping relationship is generated that associates the business information with the domain name information.

3. The service identification method as described in claim 1, characterized in that, The step of determining the relevant service corresponding to the current IP address based on the first mapping relationship, the relevant IP address, and the current IP address includes: Establish a cached IP address set corresponding to each domain name information based on the relevant IP address and the first mapping relationship; Match the current IP address with the cached IP address set; If the current IP address matches the cached IP address set, then the relevant traffic information of the related service corresponding to the current IP address is obtained.

4. The service identification method as described in claim 3, characterized in that, The step of obtaining a second Domain Name System (DNS) message based on the domain name information, obtaining second traffic information based on the second DNS message, and obtaining the relevant IP address of the domain name information based on the second traffic information includes: Based on the domain name information, initiate a DNS query request to the DNS server; Receive a response message returned by the DNS server; wherein the response message includes the second Domain Name System message; Based on the second domain name system message, the second traffic information is obtained, and based on the second traffic information, the relevant IP address corresponding to the domain name information is obtained.

5. The service identification method as described in claim 4, characterized in that, The service identification method also includes: Based on the response message, the time-to-live information corresponding to the domain name information is obtained; Based on the time-to-live information, expired IP addresses are deleted from the cached IP address set.

6. The service identification method as described in claim 3, characterized in that, The step of establishing a cached IP address set based on the relevant IP address and the first mapping relationship includes: Establish a second mapping relationship between the relevant IP addresses and the domain name information, and establish a third mapping relationship between the relevant IP addresses and the business information based on the first mapping relationship and the second mapping relationship; A fourth mapping relationship between the relevant IP address and the domain name information is established based on the first mapping relationship and the third mapping relationship; A fifth mapping relationship is established between the relevant IP addresses based on the second mapping relationship and the fourth mapping relationship; Based on the fifth mapping relationship, establish the set of cached IP addresses corresponding to each domain name information.

7. The service identification method as described in claim 3, characterized in that, The step of performing time-series statistical feature matching on the relevant traffic information of the relevant service corresponding to the current IP address based on the first traffic statistical feature includes: The first traffic information in each of the target services is divided into time windows to obtain multiple time windows; wherein, each time window includes multiple first traffic statistical features; Calculate the value range of the first traffic statistics feature in each of the time windows; Based on the relevant traffic information, a second traffic statistical feature of the relevant service is obtained, and a second statistical feature value of the second traffic statistical feature is calculated. The second statistical feature value is then matched with the value range.

8. The service identification method as described in claim 7, characterized in that, The step of obtaining the second traffic statistical characteristics of the relevant service based on the relevant traffic information, calculating the second statistical characteristic value of the second traffic statistical characteristics, and matching the second statistical characteristic value with the value range includes: The relevant traffic information is divided into time windows according to each of the aforementioned time windows; Calculate the second statistical feature value of each of the second flow statistical features in each of the time windows; If at least one of the second statistical feature values ​​is within the range, then the second statistical feature value is determined to match the range, and the current service identification is successful.

9. The service identification method as described in claim 6, characterized in that, The service identification method also includes: If the current service is successfully identified, the associated IP address corresponding to the current service is obtained according to the fifth mapping relationship; Within a preset time period, all traffic information corresponding to the associated IP address is identified as the current service.

10. The service identification method according to any one of claims 3-9, characterized in that, The service identification method also includes: If the current service is successfully identified, then the identification of services that have not yet been identified among the relevant services will be abandoned.

11. The service identification method according to any one of claims 1-9, characterized in that, The first traffic statistics feature includes at least one of the following: range of concurrent TCP connections, range of concurrent UDP connections, range of the ratio of average uplink rate to average downlink rate, range of the ratio of uplink traffic to downlink traffic, range of different network-side port numbers, and range of different domain names.

12. A business identification system, characterized in that, The service identification system includes: The sampling module is used to acquire a first domain name system message, obtain first traffic information for each target service based on the first domain name system message, and obtain the relevant IP address of the target service based on the domain name information; wherein, the first traffic information includes domain name information; The training module is used to obtain a first mapping relationship between each target service and the domain name information and a first traffic statistical feature of each target service based on the first traffic information. The matching module is used to obtain a second domain name system message based on the domain name information, obtain second traffic information based on the second domain name system message, obtain the relevant IP address of the domain name information based on the second traffic information, and identify the current service based on the first mapping relationship, the relevant IP address and the first traffic statistical features. The matching module is further configured to obtain the current IP address of the current service, determine the relevant service corresponding to the current IP address based on the first mapping relationship, the relevant IP address and the current IP address; and perform time-series statistical feature matching on the relevant traffic information of the relevant service corresponding to the current IP address based on the first traffic statistical features, so as to identify the current service from the relevant services.

13. A service identification device, characterized in that, It includes a memory and a processor, wherein the memory stores a program that, when read and executed by the processor, implements the service identification method as described in any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores one or more programs, which can be executed by one or more processors to implement the service identification method as described in any one of claims 1 to 11.

15. A computer program product, comprising a computer program or computer instructions, characterized in that, The computer program or the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer program or the computer instructions from the computer-readable storage medium and executes the computer program or the computer instructions, causing the computer device to perform the service identification method as described in any one of claims 1 to 11.