A PCDN traffic identification method, device, equipment and medium

By periodically acquiring multicast traffic data and using a trained model to identify PCDN traffic, the problem of insufficient accuracy in IPv6 and multicast environments in existing technologies is solved, achieving more efficient PCDN traffic identification.

CN119788535BActive Publication Date: 2026-01-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411998848.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2026-01-06
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

Existing PCDN traffic detection methods lack accuracy and real-time performance in IPv6 and multicast environments, making it difficult to effectively identify PCDN traffic.

Method used

By periodically acquiring multicast traffic data, using a trained PCDN traffic identification model to extract traffic feature information, and inputting it into the output layer to determine the traffic probability, the model is combined with a set probability threshold to determine whether PCDN traffic exists.

Benefits of technology

It improves the accuracy and efficiency of PCDN traffic identification, enabling more accurate identification of PCDN traffic within multicast traffic data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788535B_ABST
    Figure CN119788535B_ABST
Patent Text Reader

Abstract

The application discloses a PCDN traffic identification method, device, equipment and medium. The method comprises the following steps: periodically acquiring multicast traffic data in a set time period; inputting the multicast traffic data into a trained PCDN traffic identification model for processing to obtain a PCDN traffic probability output by the PCDN traffic identification model; comparing the PCDN traffic probability with a set probability threshold to obtain a comparison result; and determining whether the multicast traffic data contains PCDN traffic in the set time period based on the comparison result. The method can improve the accuracy of PCDN traffic identification and improve the efficiency of PCDN traffic identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular to a PCDN traffic identification method, apparatus, device, and medium. Background Technology

[0002] PCDN (Peer-to-Peer Content Delivery Network) is a content delivery network based on P2P (Peer-to-Peer) technology. It transmits content by direct sharing between users, rather than through a central server. In PCDN, users can share their bandwidth and storage resources, thereby reducing the burden on the central server and improving the efficiency and reliability of content distribution. This technology is commonly used in scenarios such as video streaming, file downloads, and online games.

[0003] Currently, PCDN traffic detection methods are mainly based on traditional traffic characteristics or NetFlow analysis. Although they can monitor PCDN traffic relatively comprehensively, these methods lack accuracy and real-time performance in IPv6 (Internet Protocol Version 6) and multicast environments. Summary of the Invention

[0004] This application provides a PCDN traffic identification method, apparatus, device, and medium to improve the accuracy and efficiency of PCDN traffic identification.

[0005] In a first aspect, embodiments of this application provide a PCDN traffic identification method, including:

[0006] Periodically acquire multicast traffic data within a set time period;

[0007] The multicast traffic data is input into a trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0008] The PCDN traffic probability is compared with a set probability threshold to obtain a comparison result. Based on the comparison result, it is determined whether the multicast traffic data contains PCDN traffic within the set time period.

[0009] In this embodiment, multicast traffic data within a set time period is periodically acquired. This multicast traffic data is then input into a trained PCDN traffic identification model for processing, yielding the PCDN traffic probability output by the model. This probability characterizes the likelihood of PCDN traffic existing within the set time period. Furthermore, this application compares the PCDN traffic probability with a set probability threshold to obtain a comparison result. Based on this result, the presence of PCDN traffic within the set time period can be determined more accurately, thereby improving the accuracy and efficiency of PCDN traffic identification.

[0010] In one possible design, the step of inputting the multicast traffic data into a trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model includes:

[0011] The multicast traffic data is input into the feature extraction layer of the PCDN traffic identification model, and the traffic feature information of the PCDN traffic is extracted through the feature extraction layer.

[0012] The traffic characteristic information is input into the output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic characteristic information.

[0013] In this embodiment, the traffic feature information of multicast traffic data is extracted by the feature extraction layer of the PCDN traffic identification model, and the PCDN traffic probability of the traffic feature information is determined by the output layer of the multicast traffic data model, so as to improve the accuracy of the determined PCDN traffic probability.

[0014] In one possible design, determining whether PCDN traffic exists in the multicast traffic data within the set time period based on the comparison result includes:

[0015] If the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, then it is determined that the multicast traffic data contains PCDN traffic within the set time period.

[0016] If the comparison result indicates that the probability of PCDN traffic is less than the set probability threshold, then it is determined that there is no PCDN traffic in the multicast traffic data within the set time period.

[0017] In this embodiment of the application, the existence of PCDN traffic data within a set time period is determined based on the relationship between the PCDN traffic probability and a set probability threshold, so as to improve the accuracy of PCDN traffic identification.

[0018] In one possible design, the PCDN traffic identification model is trained using the following method:

[0019] Obtain a training dataset, wherein the training dataset includes multiple historical multicast traffic data, each historical multicast traffic data includes historical multicast Domain Name System (mDNS) data and a label, the label being used to characterize whether the historical multicast traffic data contains PCDN traffic;

[0020] Each historical multicast traffic data in the training dataset is input into a preset PCDN traffic identification model, and the preset PCDN traffic identification model is used for processing to train the preset PCDN traffic identification model with the goal of outputting the labels of the historical multicast traffic data.

[0021] The PCDN traffic identification model is obtained until the preset PCDN traffic identification model converges.

[0022] In this embodiment of the application, a preset PCDN traffic identification model is trained using a training dataset that includes multiple historical multicast traffic data to obtain the PCDN traffic identification model, thereby improving the accuracy of PCDN traffic identification.

[0023] In one possible design, the periodic acquisition of multicast traffic data within a set time period includes:

[0024] Periodically retrieve mDNS data within a set time period;

[0025] Based on the mDNS data, multicast traffic data is determined.

[0026] In this embodiment of the application, mDNS data within a set time period is periodically acquired, and multicast traffic data is determined based on the mDNS data, thereby more accurately characterizing the traffic features in the multicast traffic data.

[0027] In one possible design, determining the multicast traffic data based on the mDNS data includes some or all of the following:

[0028] Based on the destination address and destination port of the mDNS data, the multicast address information in the multicast traffic data is determined;

[0029] Based on the existence of specific service records in the mDNS data, the service record information in the multicast traffic data is determined;

[0030] Based on the service name in the mDNS data, determine the service information in the multicast traffic data;

[0031] Based on the number of mDNS services in the mDNS data and the set time period, determine the mDNS service response frequency in the multicast traffic data;

[0032] Based on the number of forwardings of each data packet in the mDNS data, the information on the change in the number of forwardings in the multicast traffic data is determined;

[0033] Based on the size of the packets in each data packet in the mDNS data, the packet information in the multicast traffic data is determined.

[0034] In this embodiment of the application, multicast traffic data is determined based on mDNS data. The multicast traffic data includes part and all of the multicast address information, service record information, service information, mDNS service response frequency, forwarding number change information, and message information, thereby more accurately characterizing the traffic features in the multicast traffic data.

[0035] In one possible design, after periodically acquiring mDNS data within a set time period, the method further includes:

[0036] Periodically acquire Internet Protocol version 6 (IPv6) multicast data within a set time period;

[0037] Based on the mDNS data, multicast traffic data is determined, including:

[0038] Based on the mDNS data and IPv6 multicast data, multicast traffic data is determined.

[0039] In this embodiment of the application, after periodically acquiring mDNS data within a set time period, IPv6 multicast data within the set time period is acquired periodically, and multicast traffic data is determined based on mDNS data and IPv6 multicast data, thereby ensuring the accuracy and integrity of multicast traffic data and more accurately characterizing the traffic features in multicast traffic data.

[0040] Secondly, embodiments of this application provide a PCDN traffic identification device, comprising:

[0041] The acquisition module is used to periodically acquire multicast traffic data within a set time period;

[0042] The processing module is used to input the multicast traffic data into the trained PCDN traffic identification model for processing, and obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0043] The determination module is used to compare the PCDN traffic probability with a set probability threshold, obtain a comparison result, and determine whether the multicast traffic data contains PCDN traffic within the set time period based on the comparison result.

[0044] In one possible design, the processing module is used for:

[0045] The multicast traffic data is input into the feature extraction layer of the PCDN traffic identification model, and the traffic feature information of the PCDN traffic is extracted through the feature extraction layer.

[0046] The traffic characteristic information is input into the output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic characteristic information.

[0047] In one possible design, the determining module is used for:

[0048] If the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, then it is determined that the multicast traffic data contains PCDN traffic within the set time period.

[0049] If the comparison result indicates that the probability of PCDN traffic is less than the set probability threshold, then it is determined that there is no PCDN traffic in the multicast traffic data within the set time period.

[0050] In one possible design, the processing module is used to train the PCDN traffic identification model using the following method:

[0051] Obtain a training dataset, wherein the training dataset includes multiple historical multicast traffic data, each historical multicast traffic data includes historical multicast Domain Name System (mDNS) data and a label, the label being used to characterize whether the historical multicast traffic data contains PCDN traffic;

[0052] Each historical multicast traffic data in the training dataset is input into a preset PCDN traffic identification model, and the preset PCDN traffic identification model is used for processing to train the preset PCDN traffic identification model with the goal of outputting the labels of the historical multicast traffic data.

[0053] The PCDN traffic identification model is obtained until the preset PCDN traffic identification model converges.

[0054] In one possible design, the acquisition module is used for:

[0055] Periodically retrieve mDNS data within a set time period;

[0056] Based on the mDNS data, multicast traffic data is determined.

[0057] In one possible design, the acquisition module is used to determine multicast traffic data based on the mDNS data, including some or all of the following:

[0058] Based on the destination address and destination port of the mDNS data, the multicast address information in the multicast traffic data is determined;

[0059] Based on the existence of specific service records in the mDNS data, the service record information in the multicast traffic data is determined;

[0060] Based on the service name in the mDNS data, determine the service information in the multicast traffic data;

[0061] Based on the number of mDNS services in the mDNS data and the set time period, determine the mDNS service response frequency in the multicast traffic data;

[0062] Based on the number of forwardings of each data packet in the mDNS data, the information on the change in the number of forwardings in the multicast traffic data is determined;

[0063] Based on the size of the packets in each data packet in the mDNS data, the packet information in the multicast traffic data is determined.

[0064] In one possible design, after periodically acquiring mDNS data within a set time period, the acquisition module is further configured to:

[0065] Periodically acquire Internet Protocol version 6 (IPv6) multicast data within a set time period;

[0066] The acquisition module is used to determine multicast traffic data based on the mDNS data, including:

[0067] Based on the mDNS data and IPv6 multicast data, multicast traffic data is determined.

[0068] Thirdly, this application provides an electronic device, comprising:

[0069] Memory, used to store program instructions;

[0070] A processor is configured to invoke program instructions stored in the memory and execute the steps of the method described in any one of the first aspects according to the obtained program instructions.

[0071] Fourthly, this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions that, when executed by a computer, cause the computer to perform the method described in any one of the first aspects.

[0072] Fifthly, this application provides a computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform the method described in any one of the first aspects.

[0073] The technical effects of aspects two through five and any one of their designs can be found in the technical effects of the corresponding designs in aspect one, and will not be repeated here. Attached Figure Description

[0074] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;

[0075] Figure 2 A flowchart illustrating a PCDN traffic identification method provided in this application embodiment;

[0076] Figure 3 A detailed flowchart of a PCDN traffic identification method provided in this application embodiment;

[0077] Figure 4 A flowchart illustrating a method for obtaining PCDN traffic probability output by a PCDN traffic identification model, provided in an embodiment of this application;

[0078] Figure 5 A flowchart illustrating a PCDN traffic identification model training method provided in this application embodiment;

[0079] Figure 6 A schematic diagram of the structure of a PCDN flow identification device provided in an embodiment of this application;

[0080] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0081] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0082] The terms "first" and "second" in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices. The term "multiple" in this application can mean at least two, for example, two, three, or more, and the embodiments of this application do not impose limitations.

[0083] The data collection, dissemination, and use in this application all comply with relevant national laws and regulations.

[0084] Before introducing the PCDN traffic identification method provided in the embodiments of this application, the technical background of the embodiments of this application will be described in detail below for ease of understanding.

[0085] PCDN is a peer-to-peer (P2P) content delivery network. It transmits content through direct sharing between users, rather than through a central server. In PCDN, users can share their bandwidth and storage resources, thus reducing the burden on the central server and improving the efficiency and reliability of content distribution. This technology is commonly used in scenarios such as video streaming, file downloading, and online gaming.

[0086] Currently, PCDN traffic detection methods are mainly based on traditional traffic characteristics or NetFlow analysis. Although they can monitor PCDN traffic relatively comprehensively, these methods lack accuracy and real-time performance in IPv6 and multicast environments.

[0087] To address the aforementioned issues, this application proposes a PCDN traffic identification method, apparatus, device, and medium to improve the accuracy and efficiency of PCDN traffic identification.

[0088] First refer to Figure 1This is a schematic diagram illustrating an application scenario of this application, including a collector 11 and a server 12. The collector 11 and server 12 communicate via a network, which can be a local area network (LAN), a wide area network (WAN), etc. The collector 11 is deployed on any edge node within the LAN, which may include multiple edge nodes. The server 12 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, and big data and artificial intelligence platforms. The collector 11 periodically collects multicast traffic data within a set time period and sends the multicast traffic data to the server 12. The server 12 determines whether PCDN traffic exists within the set time period based on the multicast traffic data.

[0089] In this embodiment of the application, as an optional implementation, the server 12 periodically acquires multicast traffic data collected by the collector 11 within a set time period; inputs the multicast traffic data into a trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model; compares the PCDN traffic probability with a set probability threshold to obtain a comparison result; and based on the comparison result, determines whether the multicast traffic data contains PCDN traffic within the set time period.

[0090] The following is for reference. Figure 2 The flowchart shown illustrates a PCDN traffic identification method, which clarifies the technical solution provided in the embodiments of this application.

[0091] Step 201: Periodically acquire multicast traffic data within a set time period.

[0092] The time period can be set according to the actual situation; for example, the time period can be 1 second.

[0093] Step 202: Input the multicast traffic data into the trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0094] The PCDN traffic identification model is a probabilistic model that can be pre-trained using machine learning methods (such as supervised learning). The base model used to train the PCDN traffic identification model, i.e., the pre-defined PCDN traffic identification model, can be various models with predictive capabilities, such as convolutional neural network models, neural network models, logistic regression, random forests, support vector machines (SVM), etc.

[0095] Step 203: Compare the PCDN traffic probability with the set probability threshold to obtain the comparison result. Based on the comparison result, determine whether PCDN traffic exists in the multicast traffic data within the set time period.

[0096] The probability threshold can be set according to actual conditions; for example, the probability threshold can be set to 0.8. PCDN traffic probability represents the probability that multicast traffic data contains PCDN traffic within a set time period.

[0097] Optionally, based on the comparison results, determine whether PCDN traffic exists in the multicast traffic data within a set time period, including:

[0098] If the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, then it is determined that the multicast traffic data contains PCDN traffic within the set time period.

[0099] If the comparison result indicates that the probability of PCDN traffic is less than the set probability threshold, then it is determined that there is no PCDN traffic in the multicast traffic data within the set time period.

[0100] In this embodiment, multicast traffic data within a set time period is periodically acquired. This multicast traffic data is then input into a trained PCDN traffic identification model for processing, yielding the PCDN traffic probability output by the model. This probability characterizes the likelihood of PCDN traffic existing within the set time period. Furthermore, this application compares the PCDN traffic probability with a set probability threshold to obtain a comparison result. Based on this result, the presence of PCDN traffic within the set time period can be determined more accurately, thereby improving the accuracy and efficiency of PCDN traffic identification.

[0101] The following will provide a detailed explanation of the specific steps involved in the PCDN traffic identification method described above, such as... Figure 3 As shown:

[0102] Step 301: Periodically acquire multicast traffic data within a set time period.

[0103] The multicast traffic data within a specified time period can be the mDNS data within that time period.

[0104] Optionally, multicast traffic data within a set time period can be acquired periodically, including:

[0105] Periodically acquire mDNS (Multicast Domain Name System) data within a set time period; determine multicast traffic data based on mDNS data.

[0106] mDNS is a DNS (Domain Name System) based protocol that allows devices to discover each other and services within a local area network (LAN) through multicast DNS messages. It does not require a traditional DNS server and performs service discovery and name resolution directly within the LAN.

[0107] mDNS data refers to network traffic data based on UDP (User Datagram Protocol) port 5353. This network traffic data includes domain name resolution requests and response information. mDNS is used for name resolution of devices within a local area network, and therefore includes the device's service name, IP (Internet Protocol) address, service type, etc.

[0108] In this embodiment, mDNS data is collected at the cell exit, and the edge node in the MEC (Multi-access Edge Computing) is the optimal location for mDNS data collection because it can efficiently collect mDNS data across cells and has real-time analysis capabilities. By collecting and processing mDNS data on the MEC, PCDN activity can be identified in a timely manner, and the results can be quickly fed back to the core network for response.

[0109] MEC is an edge computing technology that deploys servers near base stations in mobile communication systems to migrate computing tasks that originally needed to be completed in the core network or cloud to the network edge, thereby reducing signal transmission latency and improving data processing efficiency.

[0110] In this embodiment of the application, the multicast traffic data includes part or all of the multicast address information, service record information, service information, mDNS service response frequency, forwarding count change information, and message information.

[0111] If the multicast traffic data includes multicast address information, the multicast address information is determined using the following method:

[0112] Based on the destination address and destination port of mDNS data, determine the multicast address information in the multicast traffic data.

[0113] Specifically, the destination address and destination port of the mDNS data are analyzed to determine whether a multicast address and multicast port exist. If they exist, the first tag is used as the multicast address information; if they do not exist, the second tag is used as the multicast address information.

[0114] The multicast address is ff02::fb, the multicast port is udp5353, and the first and second flags can be set according to the actual situation. For example, the first flag can be 1 and the second flag can be 0.

[0115] If the multicast traffic data includes service record information, the service record information is determined using the following method:

[0116] Based on the existence of specific types of records in mDNS data, service record information in multicast traffic data is determined.

[0117] Among these, specific record types can be Service (SRV) records or other types of records. An SRV record is a record type in DNS used to specify the address of a server providing a specific service. An SRV record contains information such as the service name, protocol, priority, weight, port, and target hostname. SRV records (Service Location Records) and A / AAAA records (Address Records) in mDNS are commonly used by PCDN to register and distribute service information. These records contain characteristics such as service names, port numbers, or IP addresses, reflecting the activity characteristics of PCDN nodes. By analyzing these specific records, especially their usage frequency and content patterns, the detection system can more accurately identify PCDN traffic.

[0118] Specifically, if a specific type of record exists in the mDNS data, the third tag will be used as the service record information; if the specific type of record does not exist in the mDNS data, the fourth tag will be used as the service record information.

[0119] The third and fourth markers can be set according to the actual situation. For example, the third marker can be 1 and the fourth marker can be 0.

[0120] If the multicast traffic data includes service information, the service information is determined using the following method:

[0121] Based on the service name in mDNS data, determine the service information in multicast traffic data.

[0122] Specifically, based on the service name in the mDNS data, it is determined whether there is a service name belonging to a regular service or a service name belonging to a PCDN service in the mDNS data; if there is, the fifth tag is used as the multicast address information; if there is no such tag, the sixth tag is used as the multicast address information.

[0123] The service name for regular services can be http._tcp.local, and the service name for PCDN services can be hostname.local. The fifth and sixth flags can be set according to the actual situation; for example, the fifth flag can be 1 and the sixth flag can be 0.

[0124] If the multicast traffic data includes the mDNS service response frequency, then the mDNS service response frequency is determined using the following method:

[0125] Based on the number of mDNS services in the mDNS data and the set time period, determine the mDNS service response frequency in the multicast traffic data.

[0126] Specifically, the ratio of the number of mDNS service calls to the set time period is used as the mDNS service response frequency.

[0127] The mDNS service count refers to the number of times an mDNS node responds to query requests within the local area network, used to measure the activity level of the device in domain name resolution. For PCDN, frequent responses may be related to the distribution characteristics of node services.

[0128] In addition to the mDNS service response frequency mentioned above, multicast traffic data may also include query records (PCDN may favor specific types), response latency, service name patterns (PCDN service names are usually different from ordinary services), and other information.

[0129] If the multicast traffic data includes information on changes in the number of forwardings, then the information on changes in the number of forwardings is determined using the following method:

[0130] Based on the number of forwardings of each data packet in the mDNS data, the information on the change in the number of forwardings in the multicast traffic data is determined.

[0131] The Time To Live (TTL) of each data packet refers to the maximum number of hops a data packet can be forwarded in a computer network. It is an 8-bit (binary digit) data in an IP segment. TTL, also known as the time limit, primarily limits the lifespan of data packets in the network to prevent them from looping indefinitely. For example, if a data packet requires two routers to travel from source to destination, its TTL is 3. Information on changes in the TTL includes the average TTL and partial and full values ​​of the TTL frequency.

[0132] Time-to-Live (TTL) is widely used in network diagnostic tools (such as traceroute) to step-by-step determine the path and network nodes traversed by data packets. By observing changes in TTL, the number of hops a data packet has traversed can be inferred, thereby analyzing the network path.

[0133] Specifically, the average number of forwardings is determined based on the number of forwardings of each data packet in the mDNS data and the total number of data packets in the mDNS data. That is, the average number of forwardings is the ratio of the sum of the number of forwardings of each data packet in the mDNS data to the total number of data packets in the mDNS data.

[0134] For example, mDNS data includes m data packets, and the number of forwardings for data packet j is bj, where j ranges from [1, m]. The average number of forwardings... Where m is an integer greater than 0.

[0135] Specifically, based on the forwarding count of each data packet in the mDNS data, a first number of data packets with abnormal forwarding counts is determined; based on this first number and the total number of data packets in the mDNS data, the forwarding frequency is determined. That is, the ratio of the first number to the total number of data packets in the mDNS data is used as the forwarding frequency.

[0136] If the multicast traffic data includes packet information, the packet information is determined using the following method:

[0137] Based on the size of the packets in each data packet in the mDNS data, the packet information in the multicast traffic data is determined.

[0138] The message information includes the average message size and part and all of the changes in message size.

[0139] Specifically, the average packet size is determined based on the size of each packet in the mDNS data and the total number of packets in the mDNS data. That is, the average packet size is the ratio of the sum of the sizes of each packet in the mDNS data to the total number of packets in the mDNS data.

[0140] For example, mDNS data includes n packets, where packet i has a size of ai, and the value of i ranges from [1, n]. The average packet size... Where n is an integer greater than 0.

[0141] Specifically, based on the size of the packets in each data packet in the mDNS data, the maximum and minimum packet sizes in the mDNS data are determined. Based on the maximum and minimum packet sizes and a set time period, the change in packet size is determined.

[0142] In this embodiment of the application, the change in message size R can be determined using the following formula. size :

[0143]

[0144] Among them, S max It is the maximum packet size in mDNS data, S min It is the minimum packet size in mDNS data, and T is the set time period.

[0145] Since some mDNS data may be present in IPv6 multicast data, after periodically acquiring mDNS data within a set time period, the process also includes periodically acquiring IPv6 multicast data within a set time period. Based on the mDNS data and IPv6 multicast data, multicast traffic data is determined to ensure the integrity and accuracy of the multicast traffic data.

[0146] IPv6 multicast data refers to data packets whose destination address is a multicast address. For example, the IPv6 multicast address of mDNS is ff02::fb. The main function of IPv6 multicast data is to broadcast data to a specified group of devices on the network, rather than unicast or broadcast, thus optimizing network efficiency.

[0147] Step 302: Input the multicast traffic data into the trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0148] The PCDN traffic probability output by the PCDN traffic identification model represents the likelihood that a given observed traffic will be classified as PCDN traffic. This observed traffic primarily includes mDNS data, which is a crucial basis for PCDN detection. By analyzing the request and response content of mDNS (such as service name, query frequency, and other characteristics), the model can capture PCDN-related behavioral patterns and calculate the probability of traffic belonging to the PCDN network based on these patterns.

[0149] In this embodiment of the application, the PCDN traffic identification model can determine the PCDN traffic probability P(PCDN|X) of multicast traffic data X using the following formula:

[0150]

[0151] Where β0 is the bias term, β1, β2, β3, β4, β5 and β6 are the weights of the PCDN traffic identification model, X1 is the multicast address information, X2 is the service record information, X3 is the service information, X4 is the mDNS service response frequency, X5 is the forwarding count change information, and X6 is the packet information.

[0152] Bias terms are additional parameters for each neuron (or the output channel corresponding to the convolution kernel) in the PCDN traffic recognition model. They are used to shift or offset the input, thereby adjusting the output range of the neuron. The bias term can be understood as adding a constant term to the convolution operation; it is typically added after the weighted sum of the convolution operations and before applying the activation function. By updating the weights and bias terms during training, the PCDN traffic recognition model can gradually reduce the value of the loss function, thereby improving the model's accuracy and generalization ability.

[0153] Figure 4 A flowchart illustrating a method for obtaining PCDN traffic probability output by a PCDN traffic identification model, as provided in this application embodiment, is shown below. Figure 4 As shown, step 302 above includes at least the following steps 401-402:

[0154] Step 401: Input the multicast traffic data into the feature extraction layer of the PCDN traffic identification model, and extract the traffic feature information of the PCDN traffic through the feature extraction layer.

[0155] The PCDN traffic identification model includes an input layer, a feature extraction layer, and an output layer. The feature extraction layer can also be called a hidden layer, which can include one or more layers.

[0156] Step 402: Input the traffic characteristic information into the output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic characteristic information.

[0157] Specifically, the output layer is used to map the traffic feature information output by the hidden layer to the interval [0, 1] using an activation function, thereby obtaining the PCDN traffic probability.

[0158] in, Figure 5 A flowchart of a PCDN traffic identification model training method provided in this application embodiment is shown below. Figure 5 As shown, the PCDN traffic identification model is trained through the following steps 501-503:

[0159] Step 501: Obtain the training dataset.

[0160] The training dataset includes multiple historical multicast traffic records. Each record contains historical multicast Domain Name System (mDNS) data and a label. The label indicates whether PCDN traffic exists in the historical multicast traffic data. Specifically, if PCDN traffic exists, the label is assigned the seventh value; otherwise, it is assigned the eighth value. The seventh and eighth values ​​can be set according to specific requirements; for example, the seventh value can be 1 and the eighth value can be 0.

[0161] Step 502: Input each historical multicast traffic data in the training dataset into the preset PCDN traffic identification model, process it using the preset PCDN traffic identification model, and train the preset PCDN traffic identification model with the output labels of the historical multicast traffic data as the target.

[0162] Step 503: Continue until the preset PCDN traffic identification model converges to obtain the PCDN traffic identification model.

[0163] During training, historical multicast traffic data from the training dataset can be input one by one into a pre-defined PCDN traffic identification model to obtain the detection results (i.e., the PCDN traffic probabilities corresponding to the historical multicast traffic data) output by the pre-defined PCDN traffic identification model. Then, a loss function can be used to determine the loss value between the detection results and the labels corresponding to the input historical multicast traffic data. The loss function is a non-negative real-valued function that can be used to characterize the difference between the detection results and the labels (true results) corresponding to the input historical multicast traffic data. Generally, the smaller the loss value, the better the robustness of the pre-defined PCDN traffic identification model. The loss function can be set according to actual needs. Afterwards, the weights of the pre-defined PCDN traffic identification model can be updated using this loss value. Thus, each time historical multicast traffic data is input, the weights of the pre-defined PCDN traffic identification model can be updated based on the loss value corresponding to that historical multicast traffic data until training is complete. The pre-defined PCDN traffic identification model at the end of training can then be used as the PCDN traffic identification model.

[0164] In this embodiment, a validation set is used to evaluate the PCDN traffic identification model, focusing on key metrics such as accuracy and recall. For scenarios with poor performance, the PCDN traffic identification model is re-optimized or additional feature correction methods are introduced to improve its generalization ability. The validation set includes multiple historical multicast traffic data entries, each containing historical multicast Domain Name System (mDNS) data and tags.

[0165] In this embodiment, the applicability of the PCDN traffic identification model is tested under simulated different network environments, including scenarios with high multicast load and frequent mDNS queries. Simultaneously, the response speed and detection efficiency of the PCDN traffic identification model in a real network are tested to ensure its reliability after deployment.

[0166] In this embodiment, the trained PCDN traffic identification model is deployed to the actual detection environment to replace or run in parallel with the old model to avoid detection blind spots, and a version management system is configured to ensure the traceability and rollback capability of the PCDN traffic identification model.

[0167] Step 303: Determine whether the PCDN traffic probability is greater than or equal to the set probability threshold. If yes, proceed to step 304; otherwise, proceed to step 305.

[0168] Step 304: Determine if PCDN traffic exists within the set time period.

[0169] Taking a probability threshold of 0.8 as an example, if the probability of multicast traffic data being PCDN traffic within a set time period is 0.9, and the probability of PCDN traffic is greater than 0.8, then it is determined that multicast traffic data is being PCDN traffic within the set time period.

[0170] In this embodiment of the application, if it is determined that PCDN traffic exists within a set time period for multicast traffic data, a detection report is generated so that the user can take corresponding actions based on the content of the detection report, such as limiting traffic or isolating nodes, thereby providing data support for network management and security policy adjustments.

[0171] The detection report includes information such as abnormal nodes, traffic information, and identification efficiency.

[0172] Step 305: Determine that there is no PCDN traffic in the multicast traffic data within the set time period.

[0173] Taking a probability threshold of 0.8 as an example, if the probability of PCDN traffic for multicast traffic data within a set time period is 0.3, and the probability of PCDN traffic is determined to be less than 0.8, then it is determined that there is no PCDN traffic for multicast traffic data within the set time period.

[0174] Based on the same technical concept, this application provides an exemplary PCDN traffic identification device, such as... Figure 6 As shown, the device includes:

[0175] The acquisition module 601 is used to periodically acquire multicast traffic data within a set time period;

[0176] Processing module 602 is used to input the multicast traffic data into a trained PCDN traffic identification model for processing, and obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0177] The determination module 603 is used to compare the PCDN traffic probability with a set probability threshold, obtain a comparison result, and determine whether the multicast traffic data contains PCDN traffic within the set time period based on the comparison result.

[0178] Optionally, the processing module 602 is used for:

[0179] The multicast traffic data is input into the feature extraction layer of the PCDN traffic identification model, and the traffic feature information of the PCDN traffic is extracted through the feature extraction layer.

[0180] The traffic characteristic information is input into the output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic characteristic information.

[0181] Optionally, the determining module 603 is used to:

[0182] If the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, then it is determined that the multicast traffic data contains PCDN traffic within the set time period.

[0183] If the comparison result indicates that the probability of PCDN traffic is less than the set probability threshold, then it is determined that there is no PCDN traffic in the multicast traffic data within the set time period.

[0184] Optionally, the processing module 602 is used to train the PCDN traffic identification model using the following method:

[0185] Obtain a training dataset, wherein the training dataset includes multiple historical multicast traffic data, each historical multicast traffic data includes historical multicast Domain Name System (mDNS) data and a label, the label being used to characterize whether the historical multicast traffic data contains PCDN traffic;

[0186] Each historical multicast traffic data in the training dataset is input into a preset PCDN traffic identification model, and the preset PCDN traffic identification model is used for processing to train the preset PCDN traffic identification model with the goal of outputting the labels of the historical multicast traffic data.

[0187] The PCDN traffic identification model is obtained until the preset PCDN traffic identification model converges.

[0188] Optionally, the acquisition module 601 is used for:

[0189] Periodically retrieve mDNS data within a set time period;

[0190] Based on the mDNS data, multicast traffic data is determined.

[0191] Optionally, the acquisition module 601 is used to determine multicast traffic data based on the mDNS data, including some or all of the following:

[0192] Based on the destination address and destination port of the mDNS data, the multicast address information in the multicast traffic data is determined;

[0193] Based on the existence of specific service record (SRV) in the mDNS data, the service record information in the multicast traffic data is determined.

[0194] Based on the service name in the mDNS data, determine the service information in the multicast traffic data;

[0195] Based on the number of mDNS services in the mDNS data and the set time period, determine the mDNS service response frequency in the multicast traffic data;

[0196] Based on the number of forwardings of each data packet in the mDNS data, the information on the change in the number of forwardings in the multicast traffic data is determined;

[0197] Based on the size of the packets in each data packet in the mDNS data, the packet information in the multicast traffic data is determined.

[0198] Optionally, after periodically acquiring mDNS data within a set time period, the acquisition module 601 is further configured to:

[0199] Periodically acquire Internet Protocol version 6 (IPv6) multicast data within a set time period;

[0200] The acquisition module is used to determine multicast traffic data based on the mDNS data, including:

[0201] Based on the mDNS data and IPv6 multicast data, multicast traffic data is determined.

[0202] Based on the same inventive concept, this application provides an electronic device that can realize the function of the PCDN traffic identification device described above. Please refer to... Figure 7 The device includes a processor 701 and a memory 702, wherein the memory 702 is used to store program instructions;

[0203] The processor 701 calls the program instructions stored in the memory and executes the program instructions to achieve the following steps:

[0204] Periodically acquire multicast traffic data within a set time period;

[0205] The multicast traffic data is input into a trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model.

[0206] The PCDN traffic probability is compared with a set probability threshold to obtain a comparison result. Based on the comparison result, it is determined whether the multicast traffic data contains PCDN traffic within the set time period.

[0207] Optionally, the step of inputting the multicast traffic data into a trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model includes:

[0208] The multicast traffic data is input into the feature extraction layer of the PCDN traffic identification model, and the traffic feature information of the PCDN traffic is extracted through the feature extraction layer.

[0209] The traffic characteristic information is input into the output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic characteristic information.

[0210] Optionally, determining whether PCDN traffic exists in the multicast traffic data within the set time period based on the comparison result includes:

[0211] If the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, then it is determined that the multicast traffic data contains PCDN traffic within the set time period.

[0212] If the comparison result indicates that the probability of PCDN traffic is less than the set probability threshold, then it is determined that there is no PCDN traffic in the multicast traffic data within the set time period.

[0213] Optionally, the PCDN traffic identification model is trained using the following method:

[0214] Obtain a training dataset, wherein the training dataset includes multiple historical multicast traffic data, each historical multicast traffic data includes historical multicast Domain Name System (mDNS) data and a label, the label being used to characterize whether the historical multicast traffic data contains PCDN traffic;

[0215] Each historical multicast traffic data in the training dataset is input into a preset PCDN traffic identification model, and the preset PCDN traffic identification model is used for processing to train the preset PCDN traffic identification model with the goal of outputting the labels of the historical multicast traffic data.

[0216] The PCDN traffic identification model is obtained until the preset PCDN traffic identification model converges.

[0217] Optionally, the periodic acquisition of multicast traffic data within a set time period includes:

[0218] Periodically retrieve mDNS data within a set time period;

[0219] Based on the mDNS data, multicast traffic data is determined.

[0220] Optionally, determining the multicast traffic data based on the mDNS data includes some or all of the following:

[0221] Based on the destination address and destination port of the mDNS data, the multicast address information in the multicast traffic data is determined;

[0222] Based on the existence of specific service records in the mDNS data, the service record information in the multicast traffic data is determined;

[0223] Based on the service name in the mDNS data, determine the service information in the multicast traffic data;

[0224] Based on the number of mDNS services in the mDNS data and the set time period, determine the mDNS service response frequency in the multicast traffic data;

[0225] Based on the number of forwardings of each data packet in the mDNS data, the information on the change in the number of forwardings in the multicast traffic data is determined;

[0226] Based on the size of the packets in each data packet in the mDNS data, the packet information in the multicast traffic data is determined.

[0227] Optionally, after periodically acquiring mDNS data within a set time period, the method further includes:

[0228] Periodically acquire Internet Protocol version 6 (IPv6) multicast data within a set time period;

[0229] Based on the mDNS data, multicast traffic data is determined, including:

[0230] Based on the mDNS data and IPv6 multicast data, multicast traffic data is determined.

[0231] Based on the same inventive concept, embodiments of this application provide a computer-readable storage medium. The computer program product includes computer program code, which, when executed on a computer, causes the computer to perform any of the PCDN traffic identification methods discussed above. Since the principle by which the above-described computer-readable storage medium solves the problem is similar to that of the PCDN traffic identification method, the implementation of the above-described computer-readable storage medium can be found in the implementation of the method; repeated details will not be elaborated further.

[0232] Based on the same inventive concept, this application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute any of the PCDN traffic identification methods discussed above. Since the principle by which the above computer program product solves the problem is similar to that of the PCDN traffic identification method, the implementation of the above computer program product can refer to the implementation of the method, and repeated details will not be described again.

[0233] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0234] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0235] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0236] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of user-operated steps to be executed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0237] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A point-to-point content delivery network (PCDN) traffic identification method, characterized in that, The method comprises the following steps: periodically acquiring multicast domain name system (mDNS) data in a set time period, determining multicast traffic data based on the mDNS data; inputting the multicast traffic data into a trained PCDN traffic identification model for processing to obtain a PCDN traffic probability output by the PCDN traffic identification model, wherein the PCDN traffic identification model is obtained by the following method: acquiring a training data set, wherein the training data set comprises a plurality of historical multicast traffic data, each piece of historical multicast traffic data comprises historical mDNS data and a label, and the label is used to represent whether the historical multicast traffic data contains PCDN traffic; inputting each piece of historical multicast traffic data in the training data set into a preset PCDN traffic identification model, processing the preset PCDN traffic identification model, and training the preset PCDN traffic identification model with the label of the historical multicast traffic data as the target until the preset PCDN traffic identification model converges to obtain the PCDN traffic identification model; comparing the PCDN traffic probability with a set probability threshold to obtain a comparison result, and determining whether the multicast traffic data contains PCDN traffic in the set time period based on the comparison result; wherein, after periodically acquiring the mDNS data in the set time period, the method further comprises: periodically acquiring Internet Protocol version 6 (IPv6) multicast data in a set time period; determining multicast traffic data based on the mDNS data, comprising: determining multicast traffic data based on the mDNS data and the IPv6 multicast data.

2. The method of claim 1, wherein, The method of inputting the multicast traffic data into the trained PCDN traffic identification model for processing to obtain the PCDN traffic probability output by the PCDN traffic identification model comprises: inputting the multicast traffic data into a feature extraction layer of the PCDN traffic identification model, and extracting traffic feature information of the PCDN traffic through the feature extraction layer; inputting the traffic feature information into an output layer of the PCDN traffic identification model to determine the PCDN traffic probability of the traffic feature information.

3. The method of claim 1, wherein, The method of determining whether the multicast traffic data contains PCDN traffic in the set time period based on the comparison result comprises: if the comparison result indicates that the PCDN traffic probability is greater than or equal to the set probability threshold, it is determined that the multicast traffic data contains PCDN traffic in the set time period; if the comparison result indicates that the PCDN traffic probability is less than the set probability threshold, it is determined that the multicast traffic data does not contain PCDN traffic in the set time period.

4. The method of claim 1, wherein, The method of determining multicast traffic data based on the mDNS data comprises some or all of the following: determining multicast address information in the multicast traffic data based on the destination address and the destination port of the mDNS data; determining service record information in the multicast traffic data based on the existence of a specific service record of the mDNS data; determine service information in the multicast traffic data based on a service name of the mDNS data; determine an mDNS service response frequency in the multicast traffic data based on an mDNS service number in the mDNS data and the set time period; determine a forwarding number change information in the multicast traffic data based on a forwarding number of each data packet in the mDNS data; determine message information in the multicast traffic data based on a message size in each data packet in the mDNS data. 5.A PCDN traffic identification device, characterized in that, The method comprises: an acquisition module configured to periodically acquire multicast domain name system (mDNS) data in a set time period, and determine multicast traffic data based on the mDNS data; a processing module configured to input the multicast traffic data into a trained PCDN traffic recognition model for processing to obtain a PCDN traffic probability output by the PCDN traffic recognition model, wherein the PCDN traffic recognition model is obtained by training in the following manner: obtaining a training data set, wherein the training data set comprises a plurality of historical multicast traffic data, each piece of historical multicast traffic data comprising historical mDNS data and a label, and the label is used to represent whether the historical multicast traffic data contains PCDN traffic; inputting each piece of historical multicast traffic data in the training data set into a preset PCDN traffic recognition model, processing using the preset PCDN traffic recognition model, and training the preset PCDN traffic recognition model with the label of the historical multicast traffic data as a target until the preset PCDN traffic recognition model converges, thereby obtaining the PCDN traffic recognition model; a determination module configured to compare the PCDN traffic probability with a set probability threshold to obtain a comparison result, and determine whether the multicast traffic data contains PCDN traffic in the set time period based on the comparison result; wherein, after periodically acquiring the mDNS data in the set time period, the acquisition module is further configured to: periodically acquire Internet Protocol version 6 (IPv6) multicast data in the set time period; the acquisition module is configured to determine the multicast traffic data based on the mDNS data, comprising: determining the multicast traffic data based on the mDNS data and the IPv6 multicast data.

6. An electronic device, comprising: The method comprises: a memory configured to store program instructions; a processor configured to invoke the program instructions stored in the memory, and execute the steps included in the method according to the obtained program instructions.

7. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program comprises program instructions, which, when executed by a computer, cause the computer to execute the method according to any one of claims 1-4.

8. A computer program product, characterised in that, The computer program product comprises computer program code, which, when executed on a computer, causes the computer to execute the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Method for identifying virtual machine in local area network

    CN112068926A

  • PCDN service processing method and device, electronic equipment and readable storage medium

    CN119135624A