Encrypted transaction flow auxiliary identification method and system based on data packet representation learning

Through the method based on data packet representation learning, artificial intelligence detection model is used to identify digital tokens and digital RMB in encrypted transaction traffic, solving the problems of difficulty in identifying and illegal risks in the existing technology, and achieving efficient and accurate distinction and identification.

CN119939292APending Publication Date: 2025-05-06NANJING UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510003224.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

It is difficult for the existing technology to efficiently identify and distinguish between digital tokens and digital RMB in encrypted transaction traffic, and directly decrypting data packets will violate laws and regulations, and there is subjectivity and lag.

Method used

Using a method based on packet characterization learning, encrypted traffic is divided through two-way stream sessions, data packet parameters are extracted as detection features, input into an artificial intelligence detection model, and distinguished and identified using a combination of machine learning and deep learning.

Benefits of technology

It realizes efficient and accurate identification of crypto transaction traffic, reduces labor costs, improves the accuracy of the distinction between digital tokens and digital RMB, is highly adaptable and easy to expand.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939292A_ABST
    Figure CN119939292A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted transaction flow auxiliary identification method and system based on data packet characterization learning, and belongs to the technical field of encrypted flow detection and artificial intelligence, and the method comprises the steps: employing a bidirectional flow session as a basic division unit, dividing each encrypted flow file, and obtaining a plurality of sessions; randomly selecting part of data packets in each session according to a preset rule to represent global traffic, and extracting a plurality of parameters of each data packet as detection features; and inputting the detection features into an artificial intelligence detection model to obtain a distinguishing and identifying result of the digital tokens and the digital RMB. According to the method, the artificial intelligence model is adopted to assist in transaction distinguishing and recognition, high efficiency and accuracy are achieved, the multi-dimensional features of the data packets can be comprehensively considered, extension is easy, adaptability is high, the labor cost is greatly reduced, and the accuracy of distinguishing the two kinds of transactions is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of encrypted traffic detection and artificial intelligence technology, and more specifically to an encrypted transaction traffic auxiliary identification method and system based on data packet characterization learning. Background Art

[0002] At present, the digital RMB is a legal digital currency issued by the state and is protected and supported by domestic laws. Digital tokens are usually issued by private individuals or organizations and are not protected by the same laws. Digital tokens will interfere with the promotion and use of central bank legal currencies such as digital RMB. Various digital tokens are necessary for the use of consensus mechanisms, while legal currencies such as digital RMB do not have consensus mechanisms. Therefore, different types of transactions need to be monitored and managed. As a legal currency, the transactions of digital RMB meet the corresponding regulatory requirements; while digital tokens may involve certain illegal activities due to their characteristics such as decentralization and anonymity. Enterprises and individuals need to clearly understand the composition of funds in their accounts; digital RMB can be used directly for daily payments and transfers, while digital tokens may need to be converted into legal currency before they can be used. Distinguishing between these two types of transaction flows helps ensure that financial institutions and platforms comply with relevant laws and regulations and avoid illegal operations. It helps enterprises or individuals better manage their funds and avoid operational errors caused by confusion. For financial institutions, distinguishing the transaction flows of digital RMB and digital tokens helps to conduct data analysis and provide decision support. Therefore, it becomes crucial to distinguish between transactions of digital tokens and digital RMB.

[0003] However, for the transaction traffic of the above two transaction methods, due to the encryption of the data packets themselves, it is extremely inefficient to completely decrypt the traffic packets and then analyze the specific source of the transaction traffic based on the specific content of the cracking. In addition, since the decrypted data packets will obtain a large amount of personal privacy and transaction information, which is in violation of relevant laws and regulations, it is completely impractical to crack the data packets and then analyze the source of the traffic. For the direct analysis of encrypted traffic, the practice of using experts to formulate relevant formulas is highly subjective and lagging, and lacks universality, and performs poorly in this field. Summary of the invention

[0004] In view of this, the present invention provides an encrypted transaction traffic auxiliary identification method and system based on data packet representation learning, which adopts artificial intelligence technology to assist in transaction differentiation and identification, so as to effectively solve the above-mentioned problems mentioned in the background technology.

[0005] To achieve the above object, the technical solution adopted by the present invention is:

[0006] In a first aspect, the present invention provides an auxiliary identification method for encrypted transaction traffic based on data packet representation learning, the method comprising the following steps:

[0007] S1: Use the bidirectional flow session as the basic unit of division, divide each encrypted flow Pcap file into several sessions;

[0008] S2: Randomly select some data packets in each session to represent the global traffic according to the preset rules, and extract several parameters of each data packet as detection features;

[0009] S3: Input the detection features into the artificial intelligence detection model to obtain the model's recognition results for distinguishing between digital tokens and digital RMB.

[0010] In an optional embodiment, in step S2, the preset rule is: when the total number of traffic data packets to be detected is small, all data packets are directly used for subsequent analysis; if the traffic data to be detected is too much, data packets covering the entire time period should be selected to ensure that the statistical characteristics of the traffic packets are not lost, maintain the representativeness of the data and simplify the data processing process.

[0011] In an optional embodiment, in step S2, the several parameters should reflect the traffic pattern of the traffic to the greatest extent, such as traffic characteristics such as packet size, port usage, DNS requests, traffic density, TTP characteristics, traffic duration and frequency.

[0012] In an optional embodiment, in step S3, the artificial intelligence detection model includes several machine learning models (such as K-Means clustering) trained with a single feature parameter and a deep learning network.

[0013] In an optional embodiment, the machine learning model is established according to the following rules: calculate the Pearson correlation coefficient between each of the above-mentioned feature parameters and the target variable "Label" (representing whether the transaction source is a digital token or digital RMB), and assign weights to different parameters from high to low according to the Pearson correlation coefficient of each parameter.

[0014] The Pearson correlation coefficient formula is:

[0015]

[0016] Where r is the correlation coefficient, which is a statistic used to measure the linear correlation between variable X and target Y. In the present invention, x is the corresponding data packet parameter, y is the transaction classification label; n is the number of observation points; x i is the i-th observation value of variable X; y i is the i-th observed value of variable Y; x i is the mean value of variable X; y i is the mean value of variable Y, and the correlation coefficient is between -1 and 1.

[0017] Furthermore, since there are limited ways to obtain transaction flows of digital tokens and digital RMB with clear classifications, and financial security issues are involved, it can be predicted that the training data of machine learning models is extremely limited in quantity. In order to achieve the reliability and stability of the model trained on a limited data set, this method adopts the Bagging (Bootstrap Aggregating) ensemble learning method, and uses the Bootstrap method to extract samples from the original data set in a limited data set. Multiple small models are obtained through multiple trainings, and each model uses all the data in different combinations. The final model evaluation result is the common result of multiple small models. For example, 5 small models are trained from limited data, and the training data of each small model is different. After classification of five small models, if more than 3 small models obtain the same result, the result of the majority of small models is taken as the final result.

[0018] In an optional embodiment, the workflow of the deep learning network includes:

[0019] The features to be detected are input into the GRU network to obtain the GRU output. Specifically, the GRU algorithm is used to learn the features and mine the intrinsic temporal relationship between data packets. The problem of long-term dependence of the recurrent neural network is solved by constructing input gates, reset gates, update gates, and output gates. The data with temporal relationships are well processed and the relationship between the data is better mined. The specific formula is as follows:

[0020] z t =σ(W z ·[h t-1 ,x t ])

[0021] r t =σ(W r ·[h t-1 ,x t ])

[0022] Among them, x t Enter information for the current moment, h t-1 is the hidden state at the previous moment. The hidden state acts as the neural network memory, which contains information about the data that the node has seen before; t is the update gate, which is used to control the extent to which the state information of the previous moment is brought into the current state; r t is the reset gate, which determines how to combine the new input information with the previous memory, σ is the sigmoid function; W z and W r is the weight matrix.

[0023]

[0024] According to the above formula, we can deduce the hidden state h of the current node passed to the next node t ,h t Forgot to pass down h t-1 Some information in the memory is added to the current node input to get the final memory.

[0025] Furthermore, the GRU output is used as the query, key and value of the multi-head attention mechanism; different weight matrices are used to perform multiple linear transformations in parallel on the multi-head attention query, key and value to obtain the vector attention of different data packets; the vector attention of all data packets is merged to output the global feature; the global feature is processed by the fully connected layer to obtain the neural network classification result.

[0026] In an optional implementation, the final judgment result of the artificial intelligence detection model is jointly determined by the machine learning model and the deep learning network. The machine learning model result is the model result corresponding to each parameter multiplied by its corresponding weight and then added together; the neural network classification result is the result output after comprehensively considering multi-dimensional features. Only when the two results are consistent, the artificial intelligence detection model outputs the final judgment result.

[0027] In a second aspect, the present invention further provides an encrypted transaction flow auxiliary identification system based on data packet representation learning, which is applied to the above-mentioned encrypted transaction flow auxiliary identification method based on data packet representation learning to realize the distinction and identification of digital tokens and digital RMB, and the system includes:

[0028] A grouping module is used to divide each encrypted traffic file into several sessions by using a bidirectional flow session as a basic unit of division;

[0029] The parameter extraction module is used to randomly select some data packets in each session to represent the global traffic according to preset rules, and extract several parameters of each data packet as detection features;

[0030] The differentiation and identification module is used to input the detection features into the artificial intelligence detection model to obtain the differentiation and identification results of digital tokens and digital RMB.

[0031] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a processor and a memory, wherein the memory stores machine executable instructions that can be executed by the processor, and the processor executes the machine executable instructions to implement the above-mentioned method for auxiliary identification of encrypted transaction traffic based on data packet representation learning.

[0032] Compared with the prior art, the present invention has at least the following beneficial technical effects:

[0033] The present invention provides an encrypted transaction traffic auxiliary identification method and system based on data packet representation learning, which adopts an artificial intelligence detection model to assist in transaction differentiation and identification, has high efficiency and accuracy, can comprehensively consider the multi-dimensional characteristics of data packets, is easy to expand, has strong adaptability, greatly reduces labor costs, and improves the accuracy of distinguishing between digital tokens and digital RMB transactions.

[0034] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.

[0035] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0037] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.

[0038] Figure 1 A flow chart of an encrypted transaction traffic auxiliary identification method based on data packet representation learning provided in an embodiment of the present invention.

[0039] Figure 2 A schematic diagram of the GRU model structure provided for an embodiment of the present invention.

[0040] Figure 3 A schematic diagram of the structure of an encrypted transaction traffic auxiliary identification system based on data packet representation learning provided in an embodiment of the present invention.

[0041] Figure 4 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments.

[0043] In the description of the present invention, it should be noted that: in some processes described in the specification and drawings of this application, multiple operations appearing in a specific order are included, but it should be clearly understood that these operations may not be performed in the order in which they appear in this document or may be performed in parallel. In addition, various serial numbers are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0044] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0045] Embodiment 1:

[0046] See also Figure 1 As shown, an embodiment of the present invention provides an auxiliary identification method for encrypted transaction traffic based on data packet characterization learning, and the method mainly includes the following steps:

[0047] S1: Use the bidirectional flow session as the basic unit of division, divide each encrypted traffic file into several sessions;

[0048] S2: Randomly select some packets in each session to represent the global traffic according to the preset rules, and extract several parameters of each packet as detection features;

[0049] S3: Input the detection features into the artificial intelligence detection model to obtain the identification results of digital tokens and digital RMB.

[0050] Combine the following Figure 1 and Figure 2 As shown, the specific implementation of the method of the present invention and the working principle involved are described in detail:

[0051] like Figure 1 As shown, in the embodiment of the present invention, after the traffic to be detected is grouped according to preset rules, several groups of sessions are obtained, and multiple parameters that best reflect the difference in consensus mechanisms are extracted from the multiple groups of sessions, such as data packet size, port usage, DNS requests, traffic density, TTP characteristics, traffic duration and frequency, and other traffic characteristics. The significant differences between digital tokens and digital RMB under the above characteristics are as follows:

[0052] 1. Packet size:

[0053] Digital tokens: Larger data packets: Each transaction needs to contain enough information to verify its validity, such as signatures, public keys, transaction inputs and outputs, etc., so the data packets may be relatively large.

[0054] Digital RMB: Smaller data packets: Transaction information may be more concise because they rely on a centralized trust mechanism and may only need to include account information and transaction amounts, so the data packets may be smaller.

[0055] 2. Port usage:

[0056] Digital tokens: Specific ports: Use specific ports for communication, such as port 8333 of a certain currency. Even if the encrypted traffic cannot directly view the internal information, the specific traffic can be identified through the port.

[0057] Digital RMB: Non-standard ports: Different ports may be used, and these ports may be non-standard or dynamically changing because the communication of digital RMB may be more covert.

[0058] 3. DNS request:

[0059] Digital tokens: There may be DNS requests for nodes in the blockchain network, which may point to some well-known blockchain nodes or mining pools.

[0060] Digital RMB: DNS requests may point to the domain names of some financial institutions, or dedicated network services designed specifically for digital RMB.

[0061] 4. Traffic density:

[0062] Digital Tokens: Higher Traffic Density: Traffic density can be high, especially during busy times, as every transaction needs to propagate across the network.

[0063] Digital RMB: Lower traffic density: The traffic density may be lower because transactions are confirmed quickly and traffic is concentrated.

[0064] 5. TTP characteristics (Tactics, Techniques, and Procedures):

[0065] Digital Tokens: Specific Handshake Process: There may be specific protocol features related to the blockchain, such as specific handshake processes, data packet sequence numbers, etc.

[0066] Digital RMB: Traditional Financial Network Protocols: May use more traditional financial network protocol features that are related to existing banking or other financial services.

[0067] 6. Traffic duration and frequency:

[0068] Digital tokens: Since digital token transactions require confirmation from multiple nodes, they take a long time to confirm, so traffic may persist for a period of time and have a certain periodicity.

[0069] Digital RMB: Due to the fast transaction confirmation speed, traffic may appear as fast, short-lived pulse-like activity.

[0070] Furthermore, multiple parameters are used as inputs of the artificial intelligence detection model. In an embodiment of the present invention, the artificial intelligence detection model is divided into two main parts: a single-parameter machine learning model and a deep learning network. The single-parameter machine learning model contains multiple parameter modules, each of which analyzes the impact of a single parameter on the final classification result. The Bagging (Bootstrap Aggregating) ensemble learning method is adopted, and the Bootstrap method is used to extract samples from the original data set in a limited data set. Multiple small models are obtained by multiple trainings, and each model uses all the data in different combinations. The final model evaluation result is the common result of multiple small models. For example, 5 small models are obtained by training from limited data, and the training data of each small model is different. After classification of 5 small models, if there are more than 3 small models that obtain the same result, the result of the majority model small model is taken as the final result.

[0071] In actual situations, it is unscientific to consider the impact of single parameter changes on classification results to a certain extent. However, considering that there are limited ways to obtain transaction flows of digital tokens and digital RMB with clear classifications, and that they involve great financial security issues, it can be predicted that the amount of training data for machine learning models is extremely limited. The purpose of the above operations is to make full use of the value that the training data set can provide, to maximize the stability of the small sample training model, and to reduce the possibility of overfitting and underfitting.

[0072] In the embodiment of the present invention, the deep learning network receives multiple parameters at the same time and inputs them into the deep learning network as multi-dimensional features of transaction flow. In this example, the GRU model is used to analyze the multi-dimensional features. As a variant of the recurrent neural network (RNN), it has a simpler structure than LSTM. The model is trained faster and reduces the risk of overfitting. Compared with the performance of LSTM, the performance of GRU is comparable to or even better than LSTM. Similar to LSTM, GRU solves the problem of gradient vanishing or gradient exploding encountered by traditional RNN when processing long sequence data through a gating mechanism. The update gate and reset gate enable GRU to better capture long-term dependencies.

[0073] like Figure 2As shown in the figure, the features to be detected are input into the GRU network to obtain the GRU output. Specifically, the GRU algorithm is used to learn the features and mine the intrinsic temporal relationship between data packets. The problem of long-term dependence of the recurrent neural network is solved by constructing the input gate, reset gate, update gate and output gate, which can well handle the data with temporal relationship and better mine the relationship between the data. The specific formula is as follows:

[0074] z t =σ(W z ·[h t-1 ,x t ])

[0075] r t =σ(W r ·[h t-1 ,x t ])

[0076] Among them, x t Enter information for the current moment, h t-1 is the hidden state at the previous moment. The hidden state acts as the neural network memory, which contains information about the data that the node has seen before; t is the update gate, which is used to control the extent to which the state information of the previous moment is brought into the current state; r t is the reset gate, which determines how to combine the new input information with the previous memory, σ is the sigmoid function; W z and W r is the weight matrix.

[0077]

[0078] In the embodiment of the present invention, the hidden state h passed from the current node to the next node can be derived according to the above formula: t ,h t Forgot to pass down h t-1 Some information in the memory is added to the current node input to get the final memory.

[0079] Furthermore, the GRU output is used as the query, key and value of the multi-head attention mechanism; different weight matrices are used to perform multiple linear transformations in parallel on the multi-head attention query, key and value to obtain the vector attention of different data packets; the vector attention of all data packets is merged to output the global feature; the global feature is processed by the fully connected layer to obtain the neural network classification result.

[0080] Ultimately, the final judgment result of the artificial intelligence detection model is jointly determined by the machine learning model and the deep learning network. The machine learning model result is the model result corresponding to each parameter multiplied by its corresponding weight and then added together; the neural network classification result is the result output after comprehensively considering multi-dimensional features. Only when the two results are consistent, the artificial intelligence detection model outputs the final judgment result.

[0081] From the description of the above embodiments, those skilled in the art can know that: the present invention provides an auxiliary identification method for encrypted transaction traffic based on data packet characterization learning, which uses artificial intelligence methods to screen out suspicious encrypted traffic for multi-dimensional feature analysis, comprehensively considers the multi-dimensional characteristics of its traffic to analyze whether there is a consensus mechanism, and conducts high-level analysis based on traffic characteristics such as traffic patterns, data packet characteristics, network behavior and transaction characteristics. If the final traffic feature analysis results show that there may be a consensus mechanism, then there is a high possibility of digital token transactions, and supervision needs to be strengthened. If there is no possibility of a consensus mechanism, it is likely to be a legal digital currency, and the core data is backed up and archived for future supervision. The method of the present invention uses an artificial intelligence model to assist in transaction differentiation and identification, which has high efficiency and accuracy, can comprehensively consider the multi-dimensional characteristics of the data packet, is easy to expand, has strong adaptability, greatly reduces labor costs, and improves the accuracy of distinguishing between the two types of transactions.

[0082] Embodiment 2:

[0083] Reference Figure 3 As shown, the present invention also provides an encrypted transaction flow auxiliary identification system based on data packet characterization learning, which is applied to the encrypted transaction flow auxiliary identification method based on data packet characterization learning described in the above embodiment 1 to realize the distinction and identification of digital tokens and digital RMB. The system includes:

[0084] A grouping module is used to divide each encrypted traffic file into several sessions by using a bidirectional flow session as a basic unit of division;

[0085] The parameter extraction module is used to randomly select some data packets in each session to represent the global traffic according to preset rules, and extract several parameters of each data packet as detection features;

[0086] The differentiation and identification module is used to input the detection features into the artificial intelligence detection model to obtain the differentiation and identification results of digital tokens and digital RMB.

[0087] An embodiment of the present invention provides an auxiliary identification system for encrypted transaction traffic based on data packet representation learning. Its implementation principle and technical effects are the same as those of the aforementioned method embodiment. For the sake of brief description, parts not mentioned in this embodiment can be referred to the corresponding contents in the aforementioned method embodiment, which will not be repeated here.

[0088] Example 3

[0089] Reference Figure 4 As shown, an embodiment of the present invention further provides an electronic device, which may include a processor 10, a memory 11, a communication bus 12 and a communication interface 13, and may also include a computer program stored in the memory 11 and executable on the processor 10, and the processor executes the computer program to implement an encrypted transaction traffic auxiliary identification method based on data packet representation learning in the above-mentioned embodiment 1.

[0090] The processor 10 may be composed of an integrated circuit in some embodiments, for example, a single packaged integrated circuit, or a plurality of packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and combinations of various control chips. The processor 10 is the control core of the electronic device, and uses various interfaces and lines to connect various components of the entire electronic device, and executes various functions of the electronic device and processes data by running or executing programs or modules stored in the memory 11, and calling data stored in the memory 11.

[0091] It should be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems or computer program products, etc. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0092] It should be noted that the word "comprising" does not exclude the presence of components or steps not listed in the claims. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The invention can be implemented by means of hardware comprising several distinct components, and by means of a suitably programmed computer.

[0093] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0094] The above description of the disclosed embodiments enables one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for auxiliary identification of encrypted transaction traffic based on data packet representation learning, characterized in that: The method comprises the following steps: S1: Use the bidirectional flow session as the basic unit of division, divide each encrypted traffic file into several sessions; S2: Randomly select some packets in each session to represent the global traffic according to the preset rules, and extract several parameters of each packet as detection features; S3: Input the detection features into the artificial intelligence detection model to obtain the identification results of the digital tokens and digital RMB.

2. According to claim 1, a method for auxiliary identification of encrypted transaction traffic based on data packet representation learning is characterized in that: In step S2, the preset rule is: when the flow data to be detected is less than the preset value, all data packets are directly used for subsequent analysis; if the flow data to be detected is not less than the preset value, the data packets covering the entire time period are selected.

3. According to claim 1, a method for auxiliary identification of encrypted transaction traffic based on data packet representation learning is characterized in that: In step S2, the several parameters are traffic characteristics reflecting the traffic pattern, including: data packet size, port usage, DNS request, traffic density, TTP characteristics, traffic duration and frequency.

4. According to claim 1, a method for auxiliary identification of encrypted transaction traffic based on data packet representation learning is characterized in that: In step S3, the artificial intelligence detection model includes several machine learning models trained with a single feature parameter and a deep learning network.

5. According to claim 4, a method for auxiliary identification of encrypted transaction traffic based on data packet representation learning is characterized in that: The workflow of a machine learning model includes: Calculate the Pearson correlation coefficient between each feature parameter and the target variable, and assign weights to different parameters from high to low according to the Pearson correlation coefficient of each parameter; In a limited data set, the Bootstrap method is used to extract samples from the original data set, and multiple small models are obtained through multiple training. Each model uses all the data in different combinations, and the final model evaluation result is the common result of multiple small models.

6. According to claim 4, a method for auxiliary identification of encrypted transaction traffic based on data packet representation learning is characterized in that: The workflow of a deep learning network includes: Input the features to be detected into the GRU network and obtain the GRU output; Use the GRU output as the query, key, and value of the multi-head attention mechanism; Use different weight matrices to perform multiple linear transformations on the multi-head attention pairs, keys, and values ​​in parallel to obtain vector attention for different data packets; Merge the vector attention of all data packets and output the global features; After the global features are processed by the fully connected layer, the deep learning network classification result is obtained.

7. The encrypted transaction flow auxiliary identification method based on data packet representation learning according to claim 5 is characterized in that: The final recognition result of the artificial intelligence detection model is jointly determined by the machine learning model and the deep learning network; The result of the machine learning model is the model result corresponding to each parameter multiplied by its corresponding weight and added together; the classification result of the deep learning network is the result obtained by outputting it after integrating multi-dimensional features. Only when the two results are consistent, the artificial intelligence detection model outputs the final recognition result.

8. An encrypted transaction flow auxiliary identification system based on data packet representation learning, characterized in that: When applied, the method for auxiliary identification of encrypted transaction traffic based on data packet characterization learning according to any one of claims 1 to 7 is performed, and the system comprises: A grouping module is used to divide each encrypted traffic file into several sessions by using a bidirectional flow session as a basic unit of division; The parameter extraction module is used to randomly select some data packets in each session to represent the global traffic according to preset rules, and extract several parameters of each data packet as detection features; The differentiation and identification module is used to input the detection features into the artificial intelligence detection model to obtain the differentiation and identification results of digital tokens and digital RMB.

9. An electronic device, characterized in that: It includes a processor and a memory, the memory stores machine executable instructions that can be executed by the processor, and the processor executes the machine executable instructions to implement an encrypted transaction traffic auxiliary identification method based on data packet characterization learning as described in any one of claims 1-7.