A Training and Recognition Method for Encrypted Traffic Attack Behaviors

The dual-layer high-order convergent LM-Trans model with Swin Transformer and high-order LM algorithms addresses slow convergence and low accuracy in encrypted traffic detection, enhancing recognition speed and precision for malicious traffic.

CN119254544BActive Publication Date: 2025-07-15SHANGHAI FEIQI NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411783528.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-07-15
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

The existing deep learning methods have initial parameters sensitivity, slow algorithm convergence speed, numerous preset parameters and lack effective selection methods in encrypted traffic recognition, resulting in slow training speed, low recognition accuracy, and poor generalization ability when facing large-scale and complex encrypted traffic data.

Method used

The double-layer high-order convergence LM-Trans model is adopted, combined with the Swin Transformer architecture and the high-order convergence LM-MLP, and the grayscale map and statistical feature map are formed by pre-processing the encrypted traffic data. The high-order convergence LM algorithm is used to speed up the model convergence speed, and the recognition accuracy is improved through the weighted fusion feature map.

Benefits of technology

It improves the accuracy of encrypted malicious traffic recognition and the overall training speed of the model, and can quickly and accurately identify attacks in large-scale and complex encrypted traffic data to ensure network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119254544B_ABST
    Figure CN119254544B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for training and identifying encrypted traffic attack behaviors, comprising the following steps: obtaining traffic data; respectively inputting the traffic data into an identification model to obtain a first feature map and a second feature map; inputting the first feature map and the second feature map into a classifier of the identification model to obtain the attack type of the traffic data; wherein, the identification model is a deep learning model trained based on samples; the identification model is constituted by a double-layer high-order convergent LM-Trans model, and the double-layer high-order convergent LM-Trans model comprises two parallel LM-Trans models based on high-order convergence; the identification model is trained by a high-order convergent LM algorithm to obtain a quickly convergent identification model. According to the present invention, while ensuring the integrity of encrypted traffic information, the defect of the current encrypted traffic identification model in terms of convergence speed can be made up, and the hit rate of identifying malicious encrypted traffic attack behaviors can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and particularly relates to a method for training and identifying encrypted traffic attack behaviors. Background Art

[0002] With the rapid development of network communication technology, network security threats have been increasing year by year. More and more network communications adopt encryption technology during transmission to protect data security and privacy. Encrypted communication is widely used in fields such as websites, applications, emails, instant messaging, and VOIP. However, while encrypted traffic prevents network security issues such as data theft, it has also become a common attack method used by hackers. Malicious traffic uses encryption technology to hide malicious attack behaviors, making traditional detection methods such as deep packet inspection and port-based traffic classification no longer reliable.

[0003] With the development of artificial intelligence technology, machine learning algorithms such as random forest and SVM can distinguish malicious encrypted traffic from normal encrypted traffic by feature extraction. However, most of these methods are based on manually designed flow features, losing a large amount of packet details, making fine-grained operations impossible, thus affecting the recognition accuracy. To solve the feature engineering problem, the end-to-end deep learning encrypted traffic detection method has become a research hotspot, but at the same time, it has also posed new challenges to the robustness of the encrypted traffic defense model.

[0004] Although existing deep learning methods can learn network traffic features and achieve malicious encrypted traffic detection, they have problems such as being sensitive to initial parameters, slow algorithm convergence speed, numerous preset parameters and lack of effective selection methods, and being prone to falling into local minima, resulting in problems such as slow training speed, low recognition accuracy, and poor generalization ability when the model faces large-scale and complex-feature high-concealment abnormal traffic data.

[0005] Technical Term: Pcap: The full English name is packet capture, and the full Chinese name is "packet capture". It is an application programming interface for capturing network traffic, and the captured packet file format is the Pcap format;

[0006] Swin Transformer: This model is an improved version of Transformer. Its full English name is Hierarchical Vision Transformer using Shifted Windows, and the full Chinese name is "Hierarchical Vision Transformer Based on Shifted Windows". It is a general vision task model that can solve general image processing problems such as image feature extraction, image recognition, and image segmentation.

[0007] LM: The full English name is Levenberg - Marquardt, and the full Chinese name is the Levenberg - Marquardt method. It is a method for least - squares estimation of regression parameters in nonlinear regression. Summary of the Invention

[0008] Aiming at the deficiencies in the prior art, the purpose of the present invention is to provide a method for training and identifying encrypted traffic attack behaviors, which can ensure the integrity of encrypted traffic information while making up for the defect of the current encrypted traffic recognition model in terms of convergence speed and improving the recognition hit rate of malicious encrypted traffic attack behaviors. To achieve the above - mentioned purpose and other advantages of the present invention, a method for training and identifying encrypted traffic attack behaviors is provided, including the following steps:

[0009] Obtain traffic data;

[0010] Input the traffic data into the recognition model respectively to obtain a first feature map and a second feature map, and fuse the first feature map and the second feature map;

[0011] Input the first feature map and the second feature map into the recognition model to obtain the attack type of the traffic data;

[0012] Among them, the recognition model is a deep - learning model trained based on samples;

[0013] The recognition model is composed of a double - layer high - order convergent LM - Trans model, and the double - layer high - order convergent LM - Trans model includes two parallel LM - Trans models based on high - order convergence; the recognition model is trained by a high - order convergent LM algorithm to obtain a quickly convergent recognition model.

[0014] Preferably, the high - order convergent LM algorithm refers to an algorithm that calculates the step size based on the L - M algorithm and performs training according to the step size.

[0015] Preferably, the model based on the Swin Transformer architecture includes: two consecutive LM - Trans Blocks and Patch merging based on the window attention mechanism;

[0016] And the LM - Trans Block includes layer normalization, window - based attention, residual connection module, layer normalization, high - order convergent LM - MLP, and residual module;

[0017] Preferably, the step of inputting the traffic data into the recognition model respectively includes:

[0018] Perform pre - processing on the traffic data to obtain a first image and a second image in different forms of expression;

[0019] Input the first image and the second image into the recognition model.

[0020] Preferably, the step of performing preprocessing on the traffic data to obtain the first image and the second image in different forms of representation includes:

[0021] Identify the characteristic information of the traffic data, where the characteristic information includes at least one of the data packet size, time stamp, and five-tuple information, and the five-tuple information includes at least one of the source IP address, destination IP address, source port, destination port, and transport layer protocol;

[0022] Split the traffic data into sessions according to the characteristic information to obtain a plurality of split sessions;

[0023] Filter and clean the DNS protocol sessions, TCP handshake failure sessions, and empty sessions in the split sessions to obtain the cleaned session data;

[0024] Convert the cleaned session data into the first image and the second image in different forms of representation respectively.

[0025] Preferably, the forms of representation of the first image and the second image include grayscale images and / or traffic statistical graphs;

[0026] The grayscale image includes an image formed by converting the byte sequence data of the traffic data into a two-dimensional array;

[0027] The traffic statistical graph includes an image formed by a three-dimensional array, where the three-dimensional array takes the arrival time of the data packets in the traffic data as the first dimension, the size of the data packets as the second dimension, and the number of data packets with a specified size arriving within a specified period as the third dimension.

[0028] Preferably, the step of inputting the first feature map and the second feature map into the classifier of the recognition model includes:

[0029] Fuse the first feature map and the second feature map to obtain a fused feature map;

[0030] Input the fused feature map into the classifier.

[0031] Preferably, the specific training of the model is as follows:

[0032] Obtain data samples;

[0033] Extract the original traffic data packet set of the encrypted traffic samples from the data samples;

[0034] Perform data preprocessing on the set of original traffic data packets to obtain a third image and a fourth image;

[0035] Input the preprocessed third image and fourth image into the recognition model to be trained, obtain a third feature map and a fourth feature map, and obtain a fused sample feature map after fusing the third feature map and the fourth feature map;

[0036] Input the fused sample feature map into the classifier to be trained, and adjust the parameters of the model to be trained according to the output of the classifier to be trained until the preset training stop condition is met, and obtain the recognition model.

[0037] Preferably, the step of inputting the first feature map and the second feature map into the classifier of the recognition model includes:

[0038] Fuse the first feature map and the second feature map to obtain a fused feature map;

[0039] Input the fused feature map into the classifier.

[0040] An encrypted traffic attack behavior recognition training device includes:

[0041] A data acquisition module for acquiring traffic data;

[0042] A preprocessing module for extracting a set of original traffic data packets of the traffic data from the traffic data;

[0043] A training module for performing data preprocessing on the set of original traffic data packets to obtain a first feature map and a second feature map;

[0044] An identification module for inputting traffic data into the recognition model to obtain the attack type of the traffic data.

[0045] Compared with the prior art, the beneficial effects of the present invention are: by preprocessing encrypted traffic to respectively form a statistical feature map and a grayscale map, by respectively training two encrypted traffic attack behavior recognition models based on high-order convergence LM-Trans, two encrypted traffic feature maps are obtained. The model obtains the spatio-temporal features of the traffic through Swim Transformer, accelerates the model convergence speed through the high-order LM-MLP algorithm, and obtains multi-dimensional features by weighted fusion of the two feature maps, and then obtains the encrypted traffic attack behavior through the classifier, so as to improve the accuracy of encrypted malicious traffic recognition and improve the overall training speed of the model. Description of the Drawings

[0046] Figure 1 It is a flowchart of the encrypted traffic attack behavior training and recognition method according to the present invention;

[0047] Figure 2 It is a flowchart of step S103 of the method for training and identifying encrypted traffic attack behaviors according to the present invention;

[0048] Figure 3 It is a flowchart of steps S104 and S105 of the method for training and identifying encrypted traffic attack behaviors according to the present invention;

[0049] Figure 4 It is a flowchart of step S106 of the method for training and identifying encrypted traffic attack behaviors according to the present invention;

[0050] Figure 5 It is a schematic structural diagram of the identification process of encrypted traffic attack behaviors in the SDN architecture of the method for training and identifying encrypted traffic attack behaviors according to the present invention;

[0051] Figure 6 It is a schematic flowchart of the method for training and identifying encrypted traffic attack behaviors according to the present invention;

[0052] Figure 7 It is a schematic structural diagram of the training device of the encrypted traffic attack behavior recognition model according to the present invention. Detailed implementation manners

[0053] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0054] Refer to Figure 1 , a method for training and identifying encrypted traffic attack behaviors, including the following steps:

[0055] S101. Obtain traffic data samples.

[0056] The traffic data samples can be collected by the terminal device from the traffic data transmission process in the network, or obtained from a preset traffic data database. The present application does not limit the collection method of the traffic data samples, and any existing traffic data sample collection method can be used.

[0057] S102. Extract the original traffic data packet set of the encrypted traffic data samples from the traffic data samples.

[0058] This step uses an encrypted traffic recognition method to identify the traffic data sample, divides the sample into a plaintext traffic data set and an encrypted traffic data set, and forms the original traffic data packet set of the encrypted traffic data sample. The encrypted traffic recognition method may include content parameter recognition, SSL application traffic recognition, TLS recognition, or other methods. The encrypted traffic data label can be obtained through manual marking or by an identification program.

[0059] Alternatively, this step forms the original traffic data packet set of the encrypted traffic data sample by obtaining the encrypted traffic data with set labels in a preset traffic database. The encrypted traffic data label is obtained from the encrypted traffic type markings included in the encrypted traffic data sample.

[0060] The original traffic data packet set of the encrypted traffic data sample includes malicious encrypted traffic and / or non-malicious encrypted traffic. Among them, the types of malicious encrypted traffic may include adware, worm viruses, Htbot malware, Dridex banking trojans, TrickBot banking trojans, Virut file-infecting trojan viruses, Miuref malicious JavaScript files, WannaCry EternalBlue ransomware, Zeus trojan malware, Zbot trojan viruses, etc. Non-malicious encrypted traffic may include online chatting, emails, files, streaming media, Voice over Internet Protocol (VoIP), VPN encrypted chatting, VPN encrypted emails, VPN encrypted streaming media, and VPN encrypted VoIP.

[0061] S103. Perform data preprocessing on the original traffic data packet set. The preprocessing includes converting the original traffic data packets into two different image representation forms.

[0062] Among them, the original traffic data packet set is divided into a training set and a test set according to a ratio of 7:3, and the training set and the test set are preprocessed separately. The image is a grayscale image of the original traffic data packet, a statistical feature map of the original traffic data packet, or a one-hot encoded feature map of the data packet. Any two different image representation forms can be selected as the input of the encrypted traffic attack behavior recognition model.

[0063] S104. Input the two preprocessed encrypted traffic image data into a double-layer high-order convergent LM-Trans model for training. The double-layer high-order convergent LM-Trans model is specifically composed of two Swim Transformer models optimized by high-order convergent LM multi-layer perceptrons.

[0064] Among them, the two types of encrypted traffic image data after preprocessing the training set are input into the LM-Trans model with double-layer high-order convergence for training after being chunked and encoded, obtaining two encrypted traffic feature maps. The encoding methods include absolute position encoding, relative position encoding, and rotational position encoding.

[0065] The LM-Trans model with high-order convergence includes two consecutive LM-Trans Blocks with high-order convergence based on the window attention mechanism and Patch merging. The LM-Trans Block with high-order convergence includes layer normalization, window-based attention, residual connection, layer normalization, LM-MLP with high-order convergence, and residual. The LM-MLP with high-order convergence adjusts the corresponding parameters of the MLP by using the Chebyshev method and the Chebyshev optimization method to obtain the optimized MLP. Connecting the Patch merging to the two consecutive LM-Trans Blocks with high-order convergence based on the window attention mechanism, the LM-Trans model with high-order convergence is obtained.

[0066] S105: Fuse the two types of encrypted traffic attack behavior recognition feature maps obtained after training with the LM-Trans model with double-layer high-order convergence to form a fused feature map;

[0067] Among them, the two obtained encrypted traffic attack behavior recognition feature maps are feature maps of the same size. The feature map fusion methods are element-wise addition, weighted addition, and element-wise multiplication, or splicing the feature maps in the depth dimension to form a multi-dimensional fused feature map.

[0068] S106: Input the fused feature map into the classifier for training to obtain the final recognition model.

[0069] Among them, when inputting the fused feature map into the classifier for training, the test set preprocessed by step S103 is used to test the trained LM-Trans model with double-layer high-order convergence and the classifier to verify the encrypted traffic attack behavior recognition effect of the LM-Trans model with double-layer high-order convergence and the classifier. When the test result passes, the LM-Trans model with double-layer high-order convergence and the classifier are used as the trained encrypted traffic attack behavior recognition model.

[0070] The training method of the encrypted traffic attack behavior recognition model provided by this application converts traffic data packets into an image form through preprocessing the obtained encrypted traffic data samples, and trains through a double-layer high-order convergent LM-Trans model and a classifier to obtain an encrypted traffic attack behavior recognition model. By converting traffic data packets into an image form and using the double-layer high-order convergent LM-Trans model, this method enhances the feature extraction ability of traffic data packets, improves the accuracy of encrypted malicious traffic recognition, and increases the overall training speed of the model.

[0071] Next, taking the conversion of the original traffic data packets into grayscale images and statistical feature maps as an example, a detailed introduction will be given on how to perform data preprocessing on the original traffic data packet set in the foregoing step S103.

[0072] As Figure 2 shown, the foregoing step S103 specifically includes the following steps:

[0073] S201. Analyze the encrypted traffic data packet set, obtain the feature information of the encrypted traffic data packets, and perform session splitting according to the feature information to obtain multiple sessions.

[0074] Among them, the feature information of the encrypted traffic data packets includes the packet size, timestamp, and five-tuple information, and the five-tuple information includes the source IP address, destination IP address, source port, destination port, and transport layer protocol.

[0075] Split the pcap files in the original traffic data packet set by packets. Each type of traffic corresponds to a pcap file. Parse each packet through a network protocol parsing library in Java to identify the feature information of the original traffic data packet set. Arrange multiple packets with the same five-tuple information in the order of timestamp to form a data stream; then form sessions with the data streams having the same source IP and destination IP, thereby realizing the session splitting of the encrypted traffic data packets and obtaining multiple split sessions.

[0076] S202. Clean the split sessions to remove redundant sessions.

[0077] Among them, the main objects to be cleaned include DNS sessions for hostname resolution and sessions with TCP handshake failures. DNS sessions have less effective information for encrypted traffic recognition and are not used as analysis objects. Sessions with TCP handshake failures only contain handshake packets and no payloads, which are not conducive to traffic recognition and are also not used as analysis objects. At the same time, it is also necessary to filter out empty files generated by empty sessions without payloads and files generated by the same session.

[0078] S203. Crop the cleaned session data to obtain two different sizes of session data.

[0079] Among them, for the cropping method of the grayscale image, since the first 784 bytes of the session data contain the differential features of malicious encrypted traffic and normal encrypted traffic, the length of the cleaned session is uniformly trimmed to 784 bytes, and the insufficient length is padded with zeros at the end.

[0080] For the cropping method of the traffic feature statistical graph, four statistical feature information of the cleaned session data are extracted, which are the length information, arrival time information, direction information, and quantity information of each packet in each session. The four statistical feature information is saved to a CSV file, and the session is divided into small blocks of 180s, where the forward flow and the reverse flow each have 90s of time.

[0081] S204. The session data cropped according to the cropping method of the grayscale image is directly used to draw a grayscale image through numerical mapping.

[0082] Among them, the bytes of network traffic transmission are between 0 and 255. By converting the byte sequence data into two dimensions, 0 corresponds to black, 255 corresponds to white, and (0, 255) is gray of different degrees, generating a grayscale image in png format, visualizing the packet byte information, and directly feeling the differences between different traffic flows.

[0083] S205. The session data cropped according to the cropping method of the statistical feature graph is used to draw a histogram and compressed into a single channel to form a statistical feature graph.

[0084] The four statistical feature information is drawn into a three-dimensional histogram. Among them, the x-axis of the histogram represents the arrival time of the data packet, and when x > 0, it represents a forward data packet, and when x < 0, it represents a reverse data packet. The forward and reverse directions of the data packet are determined by the order of the IP addresses. The y-axis represents the size of the data packet. Since most of the data packet sizes do not exceed 1500 bytes, the value range of the y-axis is [0, 1500]. The z-axis represents the number of data packets with a specific size arriving within a certain period of time.

[0085] Furthermore, a specific value is used to replace the bar graph of the z-axis, that is, the three-dimensional histogram is compressed and converted into a single-channel image. Any position in the compressed image represents that within the time period reached data packets of size Based on the positive or negative value, the direction of the data packet can be determined. Since the input image size of the encrypted traffic attack recognition model is 224×224, it is necessary to further convert the above single-channel image into the corresponding size, and normalize the packet size and time to 0 - 224. For the x-axis, the 180s of the session is mapped to 224; for the y-axis, 1500 packets are mapped to 224, finally forming a single-channel traffic statistical feature map.

[0086] The method provided by the embodiment of the present application, through the preprocessing method of confidential traffic data packets, splits, cleans, and crops the original traffic data packets according to sessions, and converts them into grayscale images and statistical feature maps according to the packet feature information and statistical feature information of the traffic. Compared with other preprocessing methods of encrypted traffic data packets, using grayscale images and statistical feature maps can extract the time features and spatial features of encrypted traffic data packets in multiple dimensions.

[0087] In addition, during the process of identifying encrypted traffic attack behaviors, due to the large amount of calculation and slow convergence speed during the iterative training of the Swin Transformer model, and at the same time generating a large number of parameters, when facing the identification of large-scale complex encrypted traffic attack behaviors, it is unable to give the SDN controller a quick feedback of the identification results, resulting in the SDN controller being unable to timely and accurately detect the occurrence of network attack events according to encrypted traffic attack behaviors, and it is difficult to guarantee the network security requirements of users.

[0088] Before inputting the two types of preprocessed encrypted traffic image data into the double-layer high-order convergent LM-Trans model and classifier for training to obtain the trained encrypted traffic attack behavior recognition model, it may also include the method of the double-layer high-order convergent LM-Trans model. Figure 3 It is a schematic flowchart of a training method for an encrypted traffic attack behavior recognition model provided by an embodiment of the present application. As Figure 3 shown, the foregoing steps S104 and S105 specifically include the following steps:

[0089] S301. According to the high-order LM algorithm, improve the MLP layer in the Swin Transformer model.

[0090] Among them, the LM algorithm is a very effective optimization design method. This algorithm uses approximate second-order derivative information, combines the advantages of the Gauss-Newton algorithm and the gradient descent method, has both the local characteristics of the Newton method, that is, it can generate an ideal search direction near the optimal value, and the global characteristics of the gradient method, that is, it descends faster in the initial iteration stage, and has certain superiority in terms of convergence.

[0091] In some other examples with high timeliness requirements, the LM algorithm often incurs a large computational cost, its convergence speed is not ideal, and the required storage space is huge. Especially when the number of model parameters is very large, the machine learning algorithm based on LM is almost ineffective.

[0092] In the embodiments of the present application, by using the Chebyshev method and its optimization method and adjusting the corresponding parameters, a high-order convergent LM algorithm is formed. In each iteration process of the high-order convergent LM algorithm, first, a linear equation system is solved to obtain the first part of the step size :

[0093] ;

[0094] In the above formula, the parameter is selected as , is the function value at the current iteration point , and the non-negative parameter is autonomously adjusted in each iteration process. Then, the following formula is used to obtain the second part of the step size :

[0095] ;

[0096] Among them, the intermediate step , is a parameter between 0 and 1. Thus, in each iteration process, the actual step size obtained by the high-order convergent LM algorithm is . Under more general assumptions, the point sequence obtained by the high-order convergent LM algorithm satisfies the convergence conclusion, then:

[0097] ;

[0098] The above formula proves the superiority of the high-order convergent LM algorithm in terms of convergence and convergence speed, and is highly applicable to optimizing the performance of the MLP network in Swin Transformer, significantly improving the convergence speed of the Swin Transformer model.

[0099] S302. Superimpose two parallel high-order convergent LM-Trans models to construct a double-layer high-order convergent LM-Trans model.

[0100] Among them, the double-layer high-order convergent LM-Trans model is composed of two high-order convergent LM-Trans models. By training the two high-order convergent LM-Trans models separately, two feature maps with different dimensions are obtained. Through the weighted fusion algorithm, they are superimposed element by element according to the weight ratio to form a fused feature map. The weighted fusion algorithm can optimize the roles of the two different feature maps in the recognition process by controlling the weights. The weighted fusion algorithm is as follows:

[0101] ;

[0102] Among them, is the weight factor, and its value range is (0, 1), which is used to adjust the influence degree of each part of the feature on the final result. is the fused feature map, is the grayscale map feature, is the statistical feature map feature.

[0103] The method provided by the embodiments of the present application improves the convergence speed of the LM-Trans model based on high-order convergence through the high-order LM algorithm. By constructing a double-layer high-order convergent LM-Trans model, the grayscale map features and statistical feature map features of encrypted traffic data packets are extracted respectively. Thus, when the double-layer high-order convergent LM-Trans model is used for the recognition of large-scale complex encrypted traffic attack behaviors, it can give a fast and accurate recognition result feedback to the SDN controller, enabling the SDN controller to timely detect the occurrence of network attack events according to the encrypted traffic attack behaviors and ensuring the network security requirements of users.

[0104] After sending the encrypted traffic to the pre-trained double-layer high-order convergent LM-Trans model for processing, the recognition result of the encrypted traffic attack behavior can be determined.

[0105] As Figure 4 shown, step S106 specifically includes the following steps:

[0106] S401. Obtain the fused feature map and expand it into a one-dimensional vector through a fully connected layer.

[0107] Among them, the expansion method is: input the fused feature map into the pooling layer to improve the feature invariance of the model, perform feature dimensionality reduction to prevent overfitting, and then input the pooled feature map into the fully connected layer to convert the two-dimensional feature map into a one-dimensional vector.

[0108] S402. Input the one-dimensional vector into the classifier to obtain the specific attack type of the encrypted traffic.

[0109] Among them, the classification result of the classifier is a binary classification result obtained by using the probability value returned by the Sigmoid function; or a multi-classification result obtained by using the probability value returned by the Softmax function. Among them, taking the Softmax function as an example, the Softmax activation function can obtain the probability of identifying each type of encrypted traffic, and the maximum value is taken as the result identified by the LM-Trans model with double-layer high-order convergence. The Softmax function is:

[0110] ;

[0111] Among them, represents the probability that an input session is recognized as the i-th type of traffic, is the score corresponding to the traffic category.

[0112] Next, the usage method of the trained encrypted traffic attack behavior recognition model obtained by the above Figures 1 to 4 described training method of the encrypted traffic attack behavior recognition model will be introduced.

[0113] Among them, the encrypted traffic attack behavior recognition model is applied to the SDN control plane. Figure 5 This is a schematic structural diagram of the encrypted traffic attack behavior recognition process of an SDN architecture provided by an embodiment of the present application. As Figure 5 shown, this SDN architecture includes: an application plane, an SDN control plane, and a data plane. The application plane is connected to the SDN control plane through the northbound interface of the SDN control plane, and the data plane is connected to the SDN control plane through the southbound interface of the SDN control plane. In the SDN control plane, there is an SDN controller, and the encrypted traffic attack behavior recognition model, and the SDN controller is connected to the encrypted traffic attack behavior recognition model.

[0114] As Figure 6 shown, the method of the present application is applied in the SDN controller. This method is used in the SDN controller for the first time, which can improve the security detection ability of the SDN controller. The specific steps are as follows:

[0115] S601. Obtain network traffic;

[0116] Among them, the network traffic data is obtained by the SDN controller from the data plane according to the southbound interface of the SDN control plane. For example, it is obtained from the data forwarding module in the data plane through the southbound interface according to the OpenFlow protocol. The data forwarding module can be a switch, for example; the switch can collect a large amount of real encrypted traffic data containing multiple traffic types in a complex network.

[0117] S602. Input the network service data into the encrypted traffic attack behavior recognition model to obtain the attack type of the encrypted traffic data;

[0118] Among them, the encrypted traffic attack behavior recognition model is the trained encrypted traffic attack behavior recognition model obtained by the method provided in any of the foregoing Figures 1 to 5 Input the encrypted traffic data into the encrypted traffic attack behavior recognition model, and identify the encrypted traffic attack behavior type through the encrypted traffic attack behavior model, so as to obtain the specific encrypted traffic attack behavior;

[0119] S603. Manage network security according to the encrypted attack behavior.

[0120] The SDN controller analyzes the encrypted traffic according to the encrypted traffic attack behavior recognition result, makes a reasonable defense decision, and completes the interaction with the application plane through the northbound interface.

[0121] The method provided in the embodiment of the present application, by obtaining network traffic data, inputs the network traffic data into the encrypted traffic attack behavior recognition model trained in the method embodiment of the foregoing Figures 1 to 5 to obtain the specific type of the encrypted traffic attack behavior, and manages network security according to the attack behavior, thereby improving the accuracy and speed of the SDN controller for network security defense.

[0122] As Figure 7 shown, an encrypted traffic attack behavior recognition training device includes an acquisition module 11, a processing module 12, a training module 13, and an identification module 14.

[0123] The acquisition module 11 is used to acquire traffic data samples, and the traffic data samples include malicious encrypted traffic, non-malicious encrypted traffic, malicious plaintext traffic, and non-malicious plaintext traffic types.

[0124] The processing module 12 is used to extract the original traffic data packet set of the encrypted traffic data sample from the traffic data sample, and the original traffic data packet set of the encrypted traffic data sample includes malicious encrypted traffic and non-malicious encrypted traffic; perform data preprocessing on the original traffic data packet set, and the preprocessing includes converting the original traffic data packet into two different image representation forms.

[0125] The training device of the encrypted traffic attack behavior recognition model provided in the embodiment of the present application can execute the training method of the encrypted traffic attack behavior recognition model in the above method embodiment, and its implementation principle and technical effect are similar, and will not be described in detail here.

[0126] The number of devices and the processing scale described herein are used to simplify the description of the present invention. Applications, modifications, and variations of the present invention will be apparent to those skilled in the art.

[0127] Although the embodiments of the present invention have been disclosed above, they are not limited to the applications listed in the specification and the embodiments. It can be fully applied to various fields suitable for the present invention. For those familiar with the art, additional modifications can be easily achieved. Therefore, without departing from the general concept defined by the claims and the equivalent scope, the present invention is not limited to specific details and the examples shown and described herein.

Claims

1. A method for training and identifying encrypted traffic attack behaviors, characterized in that, Including the following steps: Obtain traffic data; Input the traffic data into the recognition model respectively to obtain two feature maps with different dimensions, namely the first feature map and the second feature map, and perform element-by-element superposition on the first feature map and the second feature map through a weighted fusion algorithm according to the weight ratio to form a fused feature map; Obtain the fused feature map, expand it into a one-dimensional vector through a fully connected layer, and input the one-dimensional vector into a classifier to obtain the attack type of the traffic data; Among them, the recognition model is a deep learning model trained based on samples; The recognition model is composed of a double-layer high-order convergent LM-Trans model, and the double-layer high-order convergent LM-Trans model includes two parallel LM-Trans models based on high-order convergence; the recognition model is trained through a high-order convergent LM algorithm to obtain a quickly convergent recognition model; The double-layer high-order convergent LM-Trans model is two SwimTransformer models optimized by high-order convergent LM multi-layer perceptrons.

2. The method for training and identifying encrypted traffic attack behaviors according to claim 1, wherein, The high-order convergent LM algorithm refers to an algorithm that calculates the step size based on the L-M algorithm and performs training according to the step size.

3. The method for training and identifying encrypted traffic attack behaviors according to claim 2, wherein The model based on the Swin Transformer architecture includes: two consecutive LM-TransBlocks and Patch merging based on the window attention mechanism; And the LM-Trans Block includes layer normalization, window-based attention, a residual connection module, layer normalization, a high-order convergent LM-MLP, and a residual module.

4. A method for training and identifying encrypted traffic attack behaviors according to any one of claims 1 to 3, characterized in that, The step of inputting the traffic data into the recognition model respectively includes: Perform preprocessing on the traffic data to obtain a first image and a second image in different forms; Input the first image and the second image into the recognition model.

5. The method for training and identifying encrypted traffic attack behaviors according to claim 4, characterized in that, The step of performing preprocessing on the traffic data to obtain a first image and a second image in different forms includes: Identify the feature information of the traffic data, and the feature information includes at least one of the packet size, timestamp, and five-tuple information, and the five-tuple information includes at least one of the source IP address, destination IP address, source port, destination port, and transport layer protocol; Split the traffic data into multiple split sessions according to the feature information; Filter and clean the DNS protocol sessions, TCP handshake failure sessions, and empty sessions in the split sessions to obtain the cleaned session data; Convert the cleaned session data into a first image and a second image in different forms respectively.

6. The method for training and identifying encrypted traffic attack behaviors according to claim 5, wherein, The forms of the first image and the second image include grayscale images and / or traffic statistical graphs; The grayscale image includes an image formed by converting the byte sequence data of the traffic data into a two-dimensional array; The traffic statistical chart includes an image composed of a three-dimensional array, where the three-dimensional array has the arrival time of data packets in the traffic data as the first dimension, the size of the data packets as the second dimension, and the number of the data packets with a specified size arriving within a specified period as the third dimension.

7. The encryption traffic attack behavior training and recognition method according to claim 1, characterized in that, The specific training of the recognition model is as follows: Obtain data samples; Extract the original traffic data packet set of encrypted traffic samples from the data samples; Perform data preprocessing on the original traffic data packet set to obtain a third image and a fourth image; Input the preprocessed third image and fourth image into the recognition model to be trained to obtain a third feature map and a fourth feature map, and obtain a fused sample feature map after fusing the third feature map and the fourth feature map; Input the fused sample feature map into the classifier to be trained, and adjust the parameters of the model to be trained according to the output of the classifier to be trained until the preset training stop condition is met, and obtain the recognition model.

8. An encrypted traffic attack behavior recognition device, characterized in that, It includes: A data acquisition module for acquiring traffic data; A feature module for inputting the traffic data into the recognition model respectively to obtain two feature maps with different dimensions, namely a first feature map and a second feature map, and performing element-by-element superposition on the first feature map and the second feature map through a weighted fusion algorithm according to the weight ratio to form a fused feature map; A classification module for obtaining the fused feature map, expanding it into a one-dimensional vector through a fully connected layer, and inputting the one-dimensional vector into a classifier to obtain the attack type of the traffic data; Among them, the recognition model is a deep learning model trained based on samples; the recognition model is composed of a double-layer high-order convergent LM-Trans model, and the double-layer high-order convergent LM-Trans model includes two parallel LM-Trans models based on high-order convergence; the recognition model is trained through a high-order convergent LM algorithm to obtain a quickly convergent recognition model; the double-layer high-order convergent LM-Trans model is two Swim Transformer models optimized by high-order convergent LM multi-layer perceptrons.

9. An encrypted traffic attack behavior recognition device, characterized in that It includes a program storage unit and a program running unit, and when the program in the program storage unit is loaded by the program running unit, it executes the encrypted traffic attack behavior training and recognition method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Encrypted traffic classification method and device based on SwinT-CNN model

    CN116363436A

  • Network traffic identification method and device, electronic equipment and storage medium

    CN116980356A

  • Multi-modal anomaly detection method and system for big data network traffic

    CN118626982A