Method, device, processor and computer readable storage medium for realizing encrypted application traffic identification processing based on multi-graph representation enhancement
Patent Information
- Application Number
- CN202311805721.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-26
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-12-26
AI Technical Summary
但是由于灰度图的构建存在被攻击的风险,即在原始流量添加一个很小的扰动(数据包),会对流量灰度图造成极大影响,从而达到欺骗模型,使得分类预测错误
[0042]采用了本发明的基于多图表征增强实现加密应用流量识别处理的方法、装置、处理器及其计算机可读存储介质,针对现有基于深度学习的加密流量分类算法特征构建存在易被攻击,且忽略会话间语义关联等问题。首先,基于数据包负载长度、方向、包序列、簇信息等交互特征,构建数据包级的加密会话拓扑图,以充分挖掘加密应用流量中会话流信息。进一步,突破单条会话流的表征限制,基于加密会话间访问网络服务相同和数据包序列相似,构建基于流序列关联关系的加密应用会话流图。最后,引入层次图卷积网络,对基于单条会话构建的数据包图和基于多条会话构建的会话流图进行表征学习,从而解决单一会话流表征不足等问题,实现加密流量高精度识别和分类。该方法创新性地构建了数据包图和会话流图,充分挖掘会话流及会话流间的信息,具有一定的创新性。
Smart Images

Figure CN117633657B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of graph neural network processing technology in deep learning, and particularly to the field of encrypted application traffic classification. Specifically, it refers to a method, apparatus, processor, and computer-readable storage medium for encrypted application traffic identification and processing based on multi-graph representation enhancement. Background Technology
[0002] Classifying encrypted application traffic is a crucial issue in cybersecurity oversight. Encrypted communication not only effectively protects data transmission security but also blocks most intrusive attacks and interceptions. However, this also presents challenges for cybersecurity oversight. Therefore, classifying and identifying encrypted application traffic has become a key technology for strengthening cybersecurity oversight.
[0003] In terms of encrypted application traffic classification, existing algorithms can be classified according to their working principles and classification methods, mainly as follows: (1) Rule-based algorithms: Based on expert experience or prior knowledge, rule sets are constructed to judge the format and structure of transmitted messages and classify the traffic. These algorithms do not require model training, so they are fast, but the accuracy and applicable scenarios of classification are limited, and they rely on human experience. (2) Algorithms based on traditional machine learning: Features are extracted from encrypted traffic using statistical or machine learning methods, and then the extracted features are matched and classified. This algorithm requires the establishment of appropriate feature representations for the dataset to improve classification accuracy, but there are still some limitations, such as the extracted features being related to specific encryption algorithms. (3) Deep learning-based algorithms: Based on deep learning models such as convolutional neural networks (CNN) and recurrent neural networks (RNN), they can learn abstract and high-dimensional feature representations from the original data, and then classify encrypted traffic. This algorithm requires a large number of data samples and computing resources, but the classification effect is better than other methods.
[0004] The above three methods have all achieved good results in the field of encrypted application traffic classification, especially the deep learning-based algorithms, which have achieved more obvious results. However, the existing deep learning-based encrypted application traffic classification algorithms have the following problems: (1) They focus more on the sequence features of a single session stream. That is, by converting the encrypted traffic sequence into a grayscale image, a model such as CNN is used to learn the features of the grayscale image and complete the final classification. However, the construction of the grayscale image is at risk of being attacked. That is, adding a small perturbation (data packet) to the original traffic will have a great impact on the traffic grayscale image, thereby deceiving the model and causing the classification prediction to be wrong. (2) They ignore the semantic relationship between session streams. The existing algorithm model focuses more on the data features of a single session stream and ignores the rich semantic relationship between multiple encrypted sessions. That is, it does not perform correlation analysis on multiple encrypted sessions with related relationships, thus limiting the existing session stream features to the single session stream itself. Summary of the Invention
[0005] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, apparatus, processor and computer-readable storage medium for encrypted application traffic identification and processing based on multi-graph representation enhancement, which is characterized by high precision, ease of operation and wide applicability.
[0006] To achieve the above objectives, the present invention provides a method, apparatus, processor, and computer-readable storage medium for encrypted application traffic identification and processing based on multi-graph representation enhancement, as well as the following:
[0007] The method for identifying and processing encrypted application traffic based on multi-graph representation enhancement is characterized by the following steps:
[0008] (1) Extract all session stream data of a single encrypted application traffic from the encrypted application traffic dataset;
[0009] (2) Construct a data packet graph;
[0010] (3) Introduce graph convolutional networks into the data packet graph to continuously update the state information of data packet nodes;
[0011] (4) Represents the original encrypted traffic grayscale image, and selects an appropriate length of bytes for characterization;
[0012] (5) Represents the original encrypted traffic grayscale image convolutional network;
[0013] (6) Construct a session flow graph;
[0014] (7) represents graph convolution in the session flow graph, and graph convolutional networks are also introduced into the session flow graph;
[0015] (8) Calculate encrypted application traffic classification;
[0016] (9) Perform traffic classification and prediction for encrypted applications.
[0017] Preferably, step (2) specifically includes the following steps:
[0018] (2.1) Divide the raw traffic according to the session granularity and extract the basic information in the session flow used to construct the packet graph;
[0019] (2.2) Define each data packet in a single session stream as a node in the packet graph;
[0020] (2.3) If the transmission direction of the first data packet is defined as positive, then subsequent data packets with the same direction are positive, otherwise they are negative;
[0021] (2.4) The transmission of continuous data packets in the same direction is called a cluster. Based on the timing and access interaction information of data packets in the session flow, the edges of the data packet graph are divided into cluster edges and cluster edges. Full connection is used between different clusters.
[0022] Preferably, step (5) specifically includes the following steps:
[0023] (5.1) Convert the handshake information byte stream into a grayscale image, and use the embedding operation to map the original bytes to a fixed-length feature;
[0024] (5.2) Use one-dimensional convolution operation to process the grayscale image, obtain the contextual information of each byte, and obtain richer semantic representation information.
[0025] Preferably, step (6) specifically includes the following steps:
[0026] (6.1) Process encrypted traffic at the session granularity, divide encrypted sessions according to the same five-tuple, and delete unencrypted session streams and incomplete session streams;
[0027] (6.2) Use the complete session flow in the encrypted traffic as a node in the session flow graph;
[0028] (6.3) Define the edges in the session flow graph based on the access to network services and the similarity of packet sequences.
[0029] Preferably, updating the data packet node status information in step (3) specifically involves:
[0030] Update the data packet node status information according to the following formula:
[0031]
[0032] in, Let D be the adjacency matrix of the data packet graph. The degree matrix, the initial feature matrix is set to V i,m This is an embedded representation of data packets based on their payload.
[0033] Preferably, the calculation of encrypted application traffic classification in step (8) specifically includes:
[0034] Calculate encrypted application traffic categories using the following formula:
[0035]
[0036] in, This represents the probability that encrypted session stream i belongs to category c, where C represents the number of categories of encrypted traffic.
[0037] The apparatus for implementing encrypted application traffic identification processing based on multi-graph representation enhancement is characterized in that the apparatus comprises:
[0038] A processor is configured to execute computer-executable instructions;
[0039] The memory stores one or more computer-executable instructions, which, when executed by the processor, implement the steps of the method described above for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0040] The processor used to implement encrypted application traffic identification processing based on multi-graph representation enhancement is characterized in that the processor is configured to execute computer-executable instructions, which, when executed by the processor, implement the various steps of the above-described method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0041] The computer-readable storage medium is characterized in that it stores a computer program that can be executed by a processor to implement the various steps of the above-described method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0042] This invention employs a method, apparatus, processor, and computer-readable storage medium for encrypted application traffic identification and processing based on multi-graph representation enhancement. It addresses the vulnerabilities of existing deep learning-based encrypted traffic classification algorithms in feature construction and their neglect of semantic relationships between sessions. First, based on interactive features such as packet payload length, direction, packet sequence, and cluster information, a packet-level encrypted session topology graph is constructed to fully extract session flow information from encrypted application traffic. Furthermore, it overcomes the representation limitations of single session flows by constructing an encrypted application session flow graph based on the similarity of network services accessed and packet sequences between encrypted sessions, thus establishing a flow sequence-based relationship. Finally, a hierarchical graph convolutional network is introduced to perform representation learning on the packet graph constructed based on a single session and the session flow graph constructed based on multiple sessions, thereby solving the problem of insufficient representation of a single session flow and achieving high-precision identification and classification of encrypted traffic. This method innovatively constructs packet graphs and session flow graphs, fully extracting information from session flows and between them, demonstrating significant innovation. Attached Figure Description
[0043] Figure 1 This is a schematic diagram of the basic structure of the method for implementing encrypted application traffic identification and processing based on multi-graph representation enhancement according to the present invention.
[0044] Figure 2 This is a flowchart illustrating an embodiment of the method for identifying and processing encrypted application traffic based on multi-graph representation enhancement according to the present invention. Detailed Implementation
[0045] To more clearly describe the technical content of the present invention, the following description is provided in conjunction with specific embodiments.
[0046] The method for identifying and processing encrypted application traffic based on multi-graph representation enhancement of the present invention includes the following steps:
[0047] (1) Extract all session stream data of a single encrypted application traffic from the encrypted application traffic dataset;
[0048] (2) Construct a data packet graph;
[0049] (3) Introduce graph convolutional networks into the data packet graph to continuously update the state information of data packet nodes;
[0050] (4) Represents the original encrypted traffic grayscale image, and selects an appropriate length of bytes for characterization;
[0051] (5) Represents the original encrypted traffic grayscale image convolutional network;
[0052] (6) Construct a session flow graph;
[0053] (7) represents graph convolution in the session flow graph, and graph convolutional networks are also introduced into the session flow graph;
[0054] (8) Calculate encrypted application traffic classification;
[0055] (9) Perform traffic classification and prediction for encrypted applications.
[0056] In a preferred embodiment of the present invention, step (2) specifically includes the following steps:
[0057] (2.1) Divide the raw traffic according to the session granularity and extract the basic information in the session flow used to construct the packet graph;
[0058] (2.2) Define each data packet in a single session stream as a node in the packet graph;
[0059] (2.3) If the transmission direction of the first data packet is defined as positive, then subsequent data packets with the same direction are positive, otherwise they are negative;
[0060] (2.4) The transmission of continuous data packets in the same direction is called a cluster. Based on the timing and access interaction information of data packets in the session flow, the edges of the data packet graph are divided into cluster edges and cluster edges. Full connection is used between different clusters.
[0061] In a preferred embodiment of the present invention, step (5) specifically includes the following steps:
[0062] (5.1) Convert the handshake information byte stream into a grayscale image, and use the embedding operation to map the original bytes to a fixed-length feature;
[0063] (5.2) Use one-dimensional convolution operation to process the grayscale image, obtain the contextual information of each byte, and obtain richer semantic representation information.
[0064] In a preferred embodiment of the present invention, step (6) specifically includes the following steps:
[0065] (6.1) Process encrypted traffic at the session granularity, divide encrypted sessions according to the same five-tuple, and delete unencrypted session streams and incomplete session streams;
[0066] (6.2) Use the complete session flow in the encrypted traffic as a node in the session flow graph;
[0067] (6.3) Define the edges in the session flow graph based on the access to network services and the similarity of packet sequences.
[0068] In a preferred embodiment of the present invention, updating the data packet node status information in step (3) specifically involves:
[0069] Update the data packet node status information according to the following formula:
[0070]
[0071] in, Let D be the adjacency matrix of the data packet graph. The degree matrix, the initial feature matrix is set to V i,m This is an embedded representation of data packets based on their payload.
[0072] In a preferred embodiment of the present invention, the calculation of encrypted application traffic classification in step (8) specifically includes:
[0073] Calculate encrypted application traffic categories using the following formula:
[0074]
[0075] in, This represents the probability that encrypted session stream i belongs to category c, where C represents the number of categories of encrypted traffic.
[0076] The apparatus of the present invention for implementing encrypted application traffic identification processing based on multi-graph representation enhancement is characterized in that the apparatus comprises:
[0077] A processor is configured to execute computer-executable instructions;
[0078] The memory stores one or more computer-executable instructions, which, when executed by the processor, implement the steps of the method described above for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0079] The processor of the present invention for implementing encrypted application traffic identification processing based on multi-graph representation enhancement is characterized in that the processor is configured to execute computer-executable instructions, which, when executed by the processor, implement the various steps of the above-described method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0080] The main feature of the computer-readable storage medium of the present invention is that it stores a computer program thereon, which can be executed by a processor to implement the various steps of the above-described method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement.
[0081] In specific embodiments of the present invention, for the identification and classification of encrypted application traffic, the multi-dimensional representation of encrypted traffic is taken as the starting point. (1) A data packet graph construction method based on multi-type interaction information is proposed to solve the problem that the traditional single session grayscale graph representation is easily attacked; (2) A session flow graph construction method based on flow sequence association relationship is proposed to break through the limitation of single session flow representation and enrich the semantic representation of each encrypted session through the association relationship between multiple encrypted sessions; (3) Graph convolutional neural network technology is introduced. By fusing multi-level graph neural networks, the representation learning of data packet graphs constructed based on single sessions and session flow graphs constructed based on multiple sessions is carried out to achieve high-precision identification and classification of encrypted application traffic.
[0082] This invention adopts the following technical solution. A method for identifying encrypted application traffic based on enhanced multi-graph representation is proposed. First, for packet graph construction, a method based on multi-type interaction information is proposed to improve the representation capability of single session flows based on packet patterns. For session flow graph construction, a method based on flow sequence association is proposed to solve the problem of missing session association information in encrypted traffic representation, thereby improving the representation capability of session flows based on encrypted session context. Then, a hierarchical graph convolutional network structure is proposed to construct a fast identification and classification model for encrypted application traffic based on packet level and session flow level. The specific steps included in the method are as follows:
[0083] Step 1: Packet graph construction based on multi-type interaction information. This invention focuses on packets in a single session flow, comprehensively considering the differences in packet interaction characteristics (such as packet payload, packet flow direction, packet sequence, etc.) to construct a packet interaction topology graph, mainly including: (1) Encrypted traffic preprocessing. The original traffic is divided according to session granularity, and basic information such as packet quintuples, packet payload, and packet flow direction in the session flow are extracted to construct the packet graph; (2) Packet graph node construction. This invention defines each packet in a single session flow as a node in the packet graph, and uses packet payload and packet flow direction as the initial values of the nodes; (3) Packet graph edge construction. Continuous packet transmission in the same direction is called a cluster. According to the temporal interaction and access interaction information of packets in the session flow, the packet graph edges are divided into intra-cluster edges and extra-cluster edges. This invention adopts a fully connected approach for different intra- and extra-cluster edges to obtain richer node relationship information.
[0084] Step 2: Constructing a session flow graph based on flow sequence association. This invention constructs a session flow graph (Record Graph) based on flow sequence association to obtain richer semantic information between multiple encrypted sessions, mainly including: (1) Encrypted traffic preprocessing. Encrypted traffic is processed at the session granularity to retain encrypted and complete session flows; (2) Constructing session flow graph nodes. This invention uses complete session flows in encrypted traffic as nodes of the session flow graph, and uses packet graph representation and original encrypted traffic grayscale representation as the initial values of the nodes; (3) Constructing session flow graph edges. If the destination IP address and destination port number of two session flows are the same, the two session flows establish a connection (access network service association). When the similarity between two session flows is greater than a threshold, the two session flows are more likely to carry the same type of application, and the two session flows establish a connection (packet sequence similarity).
[0085] Step 3: Encrypted Application Traffic Classification Based on Hierarchical Graph Convolutional Networks. This invention uses Graph Convolutional Networks (GCNs) as the foundational network for graph representation extraction. First, a GCN is introduced into the packet graph to continuously update the state information of packet nodes and aggregate different state information of neighboring nodes, thereby enriching the representation of a single session flow. Second, to capture representations at different granularities, such as packet level and session flow level, the packet feature representation of the session flow and the original encrypted traffic grayscale representation are used as the initial representations of the session flow graph nodes, and further introduced into the GCN to obtain richer and more robust feature representations. Then, after the multi-layer GCN representation layer, a linear function is used to linearly transform the output data, and a Softmax layer is used to predict the distribution characteristics of different encrypted traffic application categories. The application category to which the encrypted traffic belongs is calculated through probability distribution.
[0086] See the appendix for embodiments of the present invention. Figure 2 The encrypted application traffic identification method of the present invention includes the following steps:
[0087] 1. Data Preparation. Extract all session stream data for a single encrypted application traffic instance from the encrypted application traffic dataset.
[0088] 2. Packet Graph Construction. 1) Divide the raw traffic according to session granularity and extract the basic information from the session flow used to construct the packet graph, including the packet 5-tuple (transmission protocol, source port number, source IP address, destination port number, destination IP address), packet payload, and packet flow direction. 2) Define each packet in a single session flow as a node in the packet graph, V i,j(i = 1, 2, ..., n; j = 1, 2, ..., m) represents the j-th data packet in the i-th session stream, where n represents the number of session streams in a certain segment of encrypted traffic, and m represents the number of data packets in a single session stream; 3) The direction of data packet flow is represented by the data packet payload length symbol, that is, the transmission direction of the first data packet is defined as positive, such as (V 11 10) If the subsequent data packet is in the same direction as the data packet, it is positive; otherwise, it is negative. 4) The transmission of consecutive data packets in the same direction is called a cluster. Based on the timing and access interaction information of the data packets in the session flow, the edges of the data packet graph are divided into intra-cluster edges and extra-cluster edges. Full connectivity is used between different clusters.
[0089] 3. Data packet graph convolutional network representation. In the data packet graph, a graph convolutional network is introduced to continuously update the state information of the data packet nodes according to formula (1).
[0090]
[0091] in, It is the adjacency matrix of the data packet graph, and D is... The degree matrix, It is the output of the previous convolution, and the initial feature matrix is set to... V i,m This is an embedded representation of data packets based on their payload.
[0092] 4. Original encrypted traffic grayscale representation. A suitable length of bytes (the first B bytes) is selected to represent the construction, ensuring that the first B bytes contain ClientHello, ServerHello, and Certificate messages, etc. The handshake information in session i is represented as follows:
[0093] RawBytes(i) = (b i,1 ,b i,2 ,…,b i,b ,…b i,B )……(2)
[0094] Among them, b i,b This represents the b-th byte of the handshake information in the i-th session stream, where b i,b ∈[0,255].
[0095] 5. Original Encrypted Traffic Grayscale Image Representation via Convolutional Network. The handshake information byte stream is converted into a grayscale image, and embedding operations are used to map the original bytes to fixed-length feature responses. Then, one-dimensional convolutional operations are used to process the grayscale image to obtain the contextual information of each byte, thereby obtaining richer semantic representation information. The grayscale image representation of the i-th session stream is then:
[0096] RawHi =Conv1D(embedding(RBytes(i)))……(3)
[0097] 6. Session Flow Graph Construction. 1) The basic unit for constructing a session flow graph is the session flow. Therefore, encrypted traffic will be processed at the session granularity, including splitting and filtering. The original encrypted traffic is split into independent session flow units, i.e., encrypted sessions are divided according to the same 5-tuple, where the source IP and port can be interchanged with the destination IP and port. Unencrypted and incomplete session flows are deleted to reduce unnecessary subsequent computational overhead. 2) Complete session flows within the encrypted traffic are used as nodes in the session flow graph. R i (i = 1, 2, ..., n) represents the i-th session node, and n represents the total number of sessions in a certain segment of encrypted traffic. 3) The definition of edges in the session flow graph is based on the association relationship of session flow sequences, and is intended to include two parts: access to network services and packet sequence similarity. Among them: access to network services association refers to whether two session flows share the same destination IP address and destination port number. The specific formula is as follows, where 1 indicates that a connection is established between two session flows.
[0098]
[0099] Packet sequence similarity association refers to establishing a connection between two session streams when their similarity exceeds a threshold. The higher the similarity, the greater the likelihood that the two session streams belong to the same type of application. The similarity between two session streams is calculated using Euclidean distance, as follows.
[0100]
[0101]
[0102] 7. Graph Convolutional Representation of Session Flow Graph. Graph convolutional networks are also introduced into the session flow graph. However, unlike other methods, the initial representation of session flow nodes in the session flow graph includes both packet feature representation and the original encrypted traffic grayscale representation. This allows for the capture of representational information at different granularities, such as packet level and session flow level, at the session flow nodes, resulting in richer expressive power and greater robustness. The specific formula is as follows:
[0103]
[0104] in,
[0105] 8. Encrypted application traffic classification calculation. Softmax is used to predict the category probability distribution of encrypted application traffic, as shown in equation (8) below.
[0106]
[0107] in, This represents the probability that encrypted session stream i belongs to category c, where C represents the number of categories of encrypted traffic.
[0108] 9. Encrypted Application Traffic Classification Prediction. The classification probabilities of the selected encrypted application traffic are calculated as follows: {Twitter: 0.93; Telegram: 0.02; Facebook: 0.04; YouTube: 0.01}. Therefore, the final classification result of the model is: Twitter.
[0109] For the specific implementation scheme of this embodiment, please refer to the relevant descriptions in the above embodiments, which will not be repeated here.
[0110] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.
[0111] It should be noted that in the description of this invention, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this invention, unless otherwise stated, "a plurality of" means at least two.
[0112] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.
[0113] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution device. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0114] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The corresponding program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0115] Furthermore, the functional units in the various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.
[0116] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.
[0117] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0118] This invention employs a method, apparatus, processor, and computer-readable storage medium for encrypted application traffic identification and processing based on multi-graph representation enhancement. It addresses the vulnerabilities of existing deep learning-based encrypted traffic classification algorithms in feature construction and their neglect of semantic relationships between sessions. First, based on interactive features such as packet payload length, direction, packet sequence, and cluster information, a packet-level encrypted session topology graph is constructed to fully extract session flow information from encrypted application traffic. Furthermore, it overcomes the representation limitations of single session flows by constructing an encrypted application session flow graph based on the similarity of network services accessed and packet sequences between encrypted sessions, thus establishing a flow sequence-based relationship. Finally, a hierarchical graph convolutional network is introduced to perform representation learning on the packet graph constructed based on a single session and the session flow graph constructed based on multiple sessions, thereby solving the problem of insufficient representation of a single session flow and achieving high-precision identification and classification of encrypted traffic. This method innovatively constructs packet graphs and session flow graphs, fully extracting information from session flows and between them, demonstrating significant innovation.
[0119] In this specification, the invention has been described with reference to specific embodiments thereof. However, it will be apparent that various modifications and variations can be made without departing from the spirit and scope of the invention. Therefore, the specification and drawings should be considered illustrative rather than restrictive.
Claims
1. A method for identifying and processing encrypted application traffic based on multi-graph representation enhancement, characterized in that, The method includes the following steps: (1) Extract all session stream data of a single encrypted application traffic from the encrypted application traffic dataset; (2) Construct a data packet graph; (3) Introduce a graph convolutional network into the data packet graph to continuously update the state information of the data packet nodes; (4) Represents the original encrypted traffic grayscale image, and selects an appropriate length of bytes for characterization; (5) Represents the original encrypted traffic grayscale image convolutional network; (6) Construct a session flow graph; (7) Represents graph convolution in the session flow graph, and graph convolutional networks are also introduced in the session flow graph; (8) Calculate the classification of encrypted application traffic; (9) Perform traffic classification and prediction for encrypted applications; Step (2) specifically includes the following steps: (2.1) Divide the raw traffic according to the session granularity and extract the basic information in the session flow used to construct the packet graph; (2.2) Define each data packet in a single session stream as a node in the packet graph; (2.3) If the transmission direction of the first data packet is defined as positive, then subsequent data packets with the same direction are positive, otherwise they are negative; (2.4) The transmission of consecutive data packets in the same direction is called a cluster. Based on the timing and access interaction information of data packets in the session flow, the edges of the data packet graph are divided into intra-cluster edges and extra-cluster edges. Full connection is used between different clusters. Step (6) specifically includes the following steps: (6.1) Process encrypted traffic at the session granularity, divide encrypted sessions according to the same five-tuple, and delete unencrypted session streams and incomplete session streams; (6.2) Use the complete session flow in the encrypted traffic as a node in the session flow graph; (6.3) Define the edges in the session flow graph based on the access to network services and the similarity of packet sequences.
2. The method for identifying and processing encrypted application traffic based on multi-graph representation enhancement according to claim 1, characterized in that, Step (5) specifically includes the following steps: (5.1) Convert the handshake information byte stream into a grayscale image, and use the embedding operation to map the original bytes to a fixed-length feature; (5.2) Use one-dimensional convolution operation to process the grayscale image, obtain the context association information of each byte, and obtain richer semantic representation information.
3. The method for identifying and processing encrypted application traffic based on multi-graph representation enhancement according to claim 1, characterized in that, The step (3) mentioned above, which updates the data packet node status information, specifically involves: Update the data packet node status information according to the following formula: ; in, This is the adjacency matrix of the data packet graph. yes The degree matrix, the initial feature matrix is set to , This is an embedded representation of data packets based on their payload.
4. The method for identifying and processing encrypted application traffic based on multi-graph representation enhancement according to claim 1, characterized in that, The calculation of encrypted application traffic classification in step (8) is specifically as follows: Calculate encrypted application traffic categories using the following formula: in, This represents the probability that encrypted session stream i belongs to category c, where C represents the number of categories of encrypted traffic.
5. An apparatus for implementing encrypted application traffic identification processing based on multi-graph representation enhancement, characterized in that, The device includes: A processor is configured to execute computer-executable instructions; The memory stores one or more computer-executable instructions, which, when executed by the processor, implement the steps of the method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement as described in any one of claims 1 to 4.
6. A processor for implementing encrypted application traffic identification processing based on multi-graph representation enhancement, characterized in that, The processor is configured to execute computer-executable instructions, which, when executed by the processor, implement the steps of the method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement as described in any one of claims 1 to 4.
7. A computer-readable storage medium, characterized in that, It stores a computer program that can be executed by a processor to implement the steps of the method for implementing encrypted application traffic identification processing based on multi-graph representation enhancement as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Malicious encrypted traffic detection method, terminal equipment and storage medium
CN114866310A
Malicious encrypted traffic detection method based on graph convolutional network
CN115174169A