Encrypted traffic classification method, device and equipment based on re-integral feature, and medium

Through the encrypted traffic classification method based on reintegration features, the model complexity problem caused by excessive feature dimensions in the prior art is solved, and lower usage cost and higher classification accuracy are achieved.

CN119939302AActive Publication Date: 2025-05-06RUIXIN INTELLIGENT DATA (GUANGZHOU) NETWORK TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411867547.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-05-06
Estimated Expiration
2044-12-18

AI Technical Summary

Technical Problem

In the existing encrypted traffic classification methods, excessive feature dimensions lead to increased model complexity, difficulty in training and deployment, and impact usage costs.

Method used

A method of encrypted traffic classification based on reintegration features is proposed. By obtaining encrypted traffic data, generating the original traffic path, performing path transformation, determining the reintegration feature data, and filtering the target feature data through the Tree SHAP algorithm, and inputting the traffic classification model for prediction.

Benefits of technology

It reduces the complexity of the model, optimizes the number of feature data, reduces the cost of using the encrypted traffic classification model, and improves the accuracy of classification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939302A_ABST
    Figure CN119939302A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an encrypted traffic classification method and device based on a re-integral feature, equipment and a medium, and belongs to the technical field of network communication. The method comprises the steps that encrypted traffic data of a target session is acquired, an original traffic path is generated according to the encrypted traffic data and a quintuple of the encrypted traffic data, and the original traffic path is a sequence formed by the data packet length of the target session in each time period; performing path conversion processing on the one-dimensional original flow path to obtain a five-dimensional target flow path; determining re-integral feature data according to the target traffic path, and screening and determining target feature data according to the re-integral feature data; and inputting the target feature data into a traffic classification model, and determining the category of the encrypted traffic data according to an output result of the traffic classification model. The invention aims to reduce the complexity of a model for classifying encrypted traffic so as to reduce the use cost of the model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network communication technology, and in particular to a method, device, equipment and medium for classifying encrypted traffic based on multi-integral features. Background Art

[0002] On the Internet, as users' awareness of privacy protection increases, the proportion of network traffic encryption is getting higher and higher. Although the encryption of network traffic increases the security and privacy of communications, it may also facilitate malicious behavior on the network. Therefore, encrypted traffic classification is a basic and important tool for network traffic analysis, providing important support for network management, security and service quality.

[0003] At present, the classification method for encrypted traffic is generally carried out through machine learning. However, this classification method requires using too high a feature dimension when extracting features from traffic data, which will cause the feature data used for training or prediction to be too large, making the model too complex, training more difficult, and deployment requirements higher, affecting the cost of using the model.

[0004] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the invention

[0005] The main purpose of the embodiments of the present application is to propose an encrypted traffic classification method, device, equipment and medium based on multi-integral features, aiming to reduce the complexity of the model for classifying encrypted traffic, thereby reducing the cost of using the model.

[0006] To achieve the above purpose, an embodiment of the present application proposes an encrypted traffic classification method based on a multi-integral feature, the method comprising: Acquire encrypted traffic data of a target session, and generate an original traffic path according to the encrypted traffic data and a five-tuple of the encrypted traffic data, wherein the original traffic path is a sequence formed by the lengths of data packets of the target session in each time period; Performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path; Determine the multi-integral characteristic data according to the target flow path, and screen and determine the target characteristic data according to the multi-integral characteristic data; The target feature data is input into a traffic classification model, and the category of the encrypted traffic data is determined according to an output result of the traffic classification model.

[0007] In some embodiments, the step of screening and determining target feature data according to the multi-integrated feature data comprises: Based on the Tree SHAP algorithm of BorutaShap, the Shapley value corresponding to each characteristic item in the multi-integrated characteristic data is calculated; According to the Shapley value of each of the feature items, a preset number of target feature items are screened out from the multi-integrated feature data, and the target feature data are formed according to the target feature items, wherein the Shapley value of the target feature item is the largest among the Shapley values ​​of all the feature items.

[0008] In some embodiments, the step of determining the multi-integrated characteristic data according to the target flow path includes: Obtaining a preset number of layers of the layered dynamic window, and determining a window size and a step size of the layered dynamic window at each layer according to the preset number of layers and the sequence length of the target traffic path; Based on the target traffic path, extracting a subpath of each dimension of the target traffic path according to the preset number of layers, the window size and the step size; The multi-integrated characteristic data is determined according to the sub-path.

[0009] In some embodiments, the step of determining the multi-integral characteristic data according to the sub-path comprises: For the sub-paths extracted from the same layered dynamic window, calculating corresponding sub-multiple integral feature data; The multi-integrated feature data is generated based on all the sub-multi-integrated feature data.

[0010] In some embodiments, the step of performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path includes: Performing path decomposition and transformation processing on the original traffic path to obtain a first upload path and a first download path; Performing accumulation and transformation processing on the first upload path and the first download path respectively to obtain a first accumulation and upload path and a first accumulation and download path; Performing base point transformation processing on the first upload path, the first download path, the first accumulation and upload path, and the first accumulation and download path, respectively, to obtain corresponding second upload path, second download path, second accumulation and upload path, and second accumulation and download path; Determining a time coordinate path according to the sequence length of the original traffic path; The five-dimensional target traffic path is formed according to the second upload path, the second download path, the second accumulation and upload path, the second accumulation and download path and the time coordinate path.

[0011] In some embodiments, the step of generating an original traffic path according to the encrypted traffic data and the five-tuple of the encrypted traffic data includes: Determine the data packet length of the encrypted traffic data in each of the time periods; Determine the data type of the data corresponding to the length of each data packet according to the quintuple, the data type including upload data or download data; The original traffic path is generated according to the data packet length and the data type in each of the time periods.

[0012] In some embodiments, the method further comprises: Acquire sample data of a sample set, and determine a sample session corresponding to the sample data according to a quintuple of the sample data; For the sample data of the same sample session, generating the original traffic path according to the sample data and the quintuple of the sample data; Performing path transformation processing on the original traffic path to obtain the target traffic path; Determine the multi-integral characteristic data according to the target flow path, and screen and determine the target characteristic data according to the multi-integral characteristic data; Determine the target feature data corresponding to different sample sessions as a training data set, and divide the training data set into a training set, a validation set, and a test set according to a preset ratio; A preset model is trained according to the training set, the validation set and the test set to obtain the traffic classification model.

[0013] To achieve the above purpose, another aspect of the embodiment of the present application provides an encrypted traffic classification device based on a multi-integral feature, the device comprising: A traffic processing module, used for obtaining encrypted traffic data of a target session, and generating an original traffic path according to the encrypted traffic data and a five-tuple of the encrypted traffic data, wherein the original traffic path is a sequence formed by the lengths of data packets of the target session in each time period; A path transformation module, used for performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path; A feature extraction module, used to determine the multi-integrated feature data according to the target flow path, and to screen and determine the target feature data according to the multi-integrated feature data; The prediction module is used to input the target feature data into the traffic classification model and determine the category of the encrypted traffic data according to the output result of the traffic classification model.

[0014] To achieve the above-mentioned purpose, another aspect of an embodiment of the present application provides an electronic device, the electronic device comprising a memory and a processor, the memory storing a computer program, and the processor implementing the above-mentioned method when executing the computer program.

[0015] To achieve the above objective, another aspect of an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.

[0016] The embodiments of the present application include at least the following beneficial effects: The present application provides an encrypted traffic classification method, device, equipment and medium based on the multi-integral feature, the scheme obtains the encrypted traffic data of the target session, generates the original traffic path according to the encrypted traffic data and its corresponding five-tuple, analyzes the target session by the length of the data packet in each time period in the original traffic path, and then performs path transformation processing on the original traffic path, expands its dimension to extract more effective features, improves accuracy, obtains a five-dimensional target traffic path, calculates the multi-integral feature data of the target traffic path, and further screens and determines the target feature data in order to avoid the feature data being too large, so as to perform predictive analysis based on the target feature data using the traffic classification model to determine the category of the encrypted traffic data. Compared with the current feature data being too large, the present application further screens the multi-integral feature data after extracting it to optimize the number of feature data, reduce the complexity of the model for classifying encrypted traffic, and thus reduce the cost of using the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a flow chart of an encrypted traffic classification method based on a multi-integral feature provided in an embodiment of the present application; Figure 2 yes Figure 1 Partial flow chart of step 103; Figure 3 is a schematic diagram of a hierarchical dynamic window extraction subpath in an embodiment of the present application; Figure 4 is another flow chart of an encrypted traffic classification method based on a multi-integral feature provided in an embodiment of the present application; Figure 5 It is a structural schematic diagram of an encrypted traffic classification device based on a multi-integral feature provided in an embodiment of the present application; Figure 6 It is a schematic diagram of the hardware structure of the electronic device provided in the embodiment of the present application. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present application. They are only examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the attached claims.

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.

[0020] In related technologies, as users' awareness of privacy protection increases, the proportion of network traffic encryption is increasing. Encrypting network traffic can improve the security and privacy of communications. Therefore, various network traffic encryption methods and tools continue to emerge, such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN) and Tor network. However, although the encryption of network traffic increases the security and privacy of communications, it also brings challenges to network management and facilitates malicious users to disguise attacks and escalate crimes. Therefore, encrypted traffic classification is a basic and important tool for network traffic analysis, providing important support for network management, security and quality of service (QoS).

[0021] For encrypted traffic data, traditional analysis methods based on plaintext payloads of data packets have become almost ineffective, and the simplest port-based methods often fail due to the use of dynamic port negotiation mechanisms. Therefore, they are generally classified through machine learning. However, machine learning-based methods rely on manually designed features. Currently, when extracting features from traffic data, it is generally necessary to use too high a feature dimension, which will cause the feature data used for training or prediction to be too large, making the model too complex, training more difficult, and deployment requirements higher, affecting the cost of using the model.

[0022] In view of this, an embodiment of the present application provides an encrypted traffic classification method, device and medium based on the multi-integral feature. Figure 1 is an optional flow chart of an encrypted traffic classification method based on a multi-integral feature provided in an embodiment of the present application. Figure 1 The method may include but is not limited to steps S101 to S104.

[0023] Step S101, obtaining encrypted traffic data of a target session, generating an original traffic path according to the encrypted traffic data and a five-tuple of the encrypted traffic data, wherein the original traffic path is a sequence formed by the lengths of data packets of the target session in each time period.

[0024] It should be noted that a unidirectional network flow can be uniquely identified by its quintuple, which includes the source IP address, destination IP address, source port, destination port and transport layer protocol. All data packets in the network flow correspond to the same quintuple. In a bidirectional network flow, it can be understood that all data packets correspond to the same quintuple or the same transposed quintuple (source IP address and destination IP address are transposed, source port and destination port are transposed).

[0025] Optionally, the traffic between the client and the server is observed through a third-party Internet service provider, and the traffic is collected through traffic collection tools such as Libpcap, TCPdump, Wireshark, and Netflow, so as to obtain encrypted traffic data. Based on this, combined with the five-tuple analysis of the data packets in the traffic, the traffic belonging to the same session can be distinguished to determine the target session. In the embodiment of the present application, only the classification of the encrypted traffic data of a single target session is analyzed and explained, and the category of the encrypted traffic data finally obtained is also the classification for the target session. It can be understood that the method of the embodiment of the present application can also be applied to the scenario of multiple target sessions, and the category of each target session can be analyzed separately.

[0026] On the other hand, in the target session, the client and the server continuously send data packets to each other to achieve communication, and at different stages of communication interaction, the density of data packets also varies to a certain extent. Therefore, the embodiment of the present application slices on a time scale and determines the corresponding data packet length in each time period, and determines the data item of the original traffic path by the data packet length, so as to generate the original traffic path representing the target session, and only uses the data packet length of the target session as the analysis information, which also avoids sensitive processing of the encrypted data content. The original traffic path is a sequence, and each data item in the sequence is the length of the data packet in the corresponding time period, and is sorted in order according to its corresponding time period.

[0027] Step S102, performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path.

[0028] Since the re-integration feature based on the one-dimensional original flow path cannot provide satisfactory effectiveness, it is necessary to perform a path transformation operation on the original flow path to highlight its hidden information, thereby improving the effectiveness of the subsequent re-integration feature data. By performing a path transformation process on the original flow path, a five-dimensional target flow path is obtained, and the target flow path includes five paths generated based on the original flow path. In this embodiment, the original flow path is not included in the five paths of the target flow path.

[0029] Step S103, determining the multi-integral characteristic data according to the target flow path, and screening and determining the target characteristic data according to the multi-integral characteristic data.

[0030] Furthermore, the five-dimensional path X can be expressed as , where the five items are the five paths, and the subscript t is used to indicate its time coordinate, that is, which time interval each path is The data within , in this embodiment, the five paths all correspond to the same t.

[0031] Calculate the multi-integral characteristic data of the target flow path. The k-fold iterative integral can be calculated according to formula (1), specifically: (1) Among them, i is the superscript that distinguishes different paths, and k is the truncation order.

[0032] For example, let a two-dimensional path , (a=0, b=4), , , calculate its double path integral (k=2), and then calculate the following formula (2): (2) The k-fold iterative integral of the five-dimensional path can also be calculated with reference to the above example. When calculating the k-order truncation of the d-dimensional path, its signature dimension can be calculated with reference to formula (3), specifically: (3) As in the above two-dimensional path example, its path multi-integral characteristic dimension is , which is equivalent to the number of characteristic items of its multi-integrated characteristic data.

[0033] After calculating the multi-integrated feature data of the target traffic path, in order to reduce the complexity of the model, the multi-integrated feature data is screened, and the target feature data with greater contribution is selected as the data actually used for prediction or training.

[0034] Step S104: input the target feature data into the traffic classification model, and determine the category of the encrypted traffic data according to the output result of the traffic classification model.

[0035] The target feature data is input into the traffic classification model to obtain the output result of the traffic classification model, which includes a score value predicting that the encrypted traffic data belongs to different categories. Based on the score value, it can be determined which category the encrypted traffic data should belong to.

[0036] Optionally, the traffic classification model can predict categories such as secure socket layer (SSL), transport layer security (TLS), virtual private network (VPN) and Tor network, etc., which are not limited in this embodiment. In addition, the traffic classification model can be one of machine learning models such as random forest, decision tree, Gaussian naive Bayes and K nearest neighbor, which are also not limited in this embodiment.

[0037] Steps S101 to S104 shown in the embodiment of the present application are to obtain the encrypted traffic data of the target session, generate the original traffic path according to the encrypted traffic data and its corresponding five-tuple, analyze the target session by the length of the data packet in each time period in the original traffic path, and then perform path transformation processing on the original traffic path, expand its dimension to extract more effective features, improve accuracy, obtain the five-dimensional target traffic path, calculate the multi-integral feature data of the target traffic path, and further screen and determine the target feature data in order to avoid the feature data being too large, so as to perform predictive analysis based on the target feature data using the traffic classification model to determine the category of the encrypted traffic data. Compared with the current feature data being too large, the present application further screens the multi-integral feature data after extracting it to optimize the number of feature data, reduce the complexity of the model for classifying encrypted traffic, and thus reduce the cost of using the model.

[0038] In step S101 of some embodiments, the step of generating the original traffic path according to the encrypted traffic data and the five-tuple of the encrypted traffic data includes: Determine the packet length of encrypted traffic data in various time periods.

[0039] The data type of the data corresponding to the length of each data packet is determined according to the quintuple, and the data type includes upload data or download data.

[0040] Generate the original traffic path based on the packet length and data type in each time period.

[0041] Specifically, each data item in the original traffic path, that is, each data packet length corresponds to the same time period length. Therefore, the sequence length of the original traffic path is determined according to the overall time interval length of the encrypted traffic data. In this embodiment, the time period length corresponding to each data packet length is not limited. Based on this, the packet length of the encrypted traffic data in each time period is determined, thereby determining the order and value of each data item in the original traffic path, and determining the sequence length of the original traffic path.

[0042] Since the target session may also be a bidirectional network flow, in order to further improve the representativeness of the original traffic path for the encrypted traffic data, in this embodiment, the data type is represented by positive and negative, where positive represents download data and negative represents upload data. Based on this, the data type corresponding to each data packet length is determined according to the five-tuple, and the positive and negative values ​​of the data items corresponding to each data packet length are determined according to its data type. In this way, the original traffic path is generated. For example, an original traffic path is , where the superscript o represents the original traffic path, .

[0043] By constructing the original traffic path of encrypted traffic data according to the packet length and data type, sensitive processing of the encrypted data content is avoided, the security of analyzing the encrypted traffic data is improved, and at the same time, the representativeness of the original traffic path for the encrypted traffic data is ensured, thereby improving the accuracy of subsequent classification and prediction of the encrypted traffic data based on the original traffic path.

[0044] In step S102 of some embodiments, the step of performing path transformation processing on the one-dimensional original traffic path to obtain the five-dimensional target traffic path includes: Perform path decomposition and transformation processing on the original traffic path to obtain a first upload path and a first download path.

[0045] Accumulation and transformation processing are performed on the first upload path and the first download path respectively to obtain a first accumulation and upload path and a first accumulation and download path.

[0046] Base point transformation processing is performed on the first upload path, the first download path, the first accumulation and upload path, and the first accumulation and download path, respectively, to obtain the corresponding second upload path, the second download path, the second accumulation and upload path, and the second accumulation and download path.

[0047] The time coordinate path is determined according to the sequence length of the original traffic path.

[0048] A five-dimensional target traffic path is formed according to the second upload path, the second download path, the second accumulation and upload path, the second accumulation and download path and the time coordinate path.

[0049] Specifically, the path transformation processing includes path decomposition transformation, accumulation and transformation, base point transformation and additional incremental dimension transformation.

[0050] Among them, the path decomposition transformation is to decompose the original traffic path into two paths, the first upload path and the first download path, according to the upload data or download data, generate the first download path according to the data items belonging to the download data in the original traffic path, and generate the first upload path according to the data items belonging to the upload data in the original traffic path. It should be noted that the data items in the opposite direction are replaced with zero, not directly discarded, so the sequence length of the first upload path and the first download path is the same as the original traffic path, and the position of the non-zero data items is the same as its position in the original traffic path. Converting a path into a set of sub-paths with the same dimension can improve the efficiency of its path re-integration.

[0051] Cumulative sum transformation is to perform cumulative processing on the data items in the path. For example, the second item in the sequence is updated to the cumulative sum of the first item and the original second item, and the third item is updated to the cumulative sum of the updated second item and the original third item. Based on this, the first upload path and the first download path are respectively processed by cumulative sum to obtain the corresponding first cumulative upload path and first cumulative download path. Since the same website or service often has a fixed payload to be transmitted, this will result in very similar cumulative sum features being output. Therefore, cumulative sum transformation is added to improve the validity of the re-integrated feature data.

[0052] The base point transformation adds a constant 0 to the beginning of the first upload path, the first download path, the first accumulation and upload path, and the first accumulation and download path, which is equivalent to shifting the data items in each path backwards, which will also cause the sequence length of each path to increase by 1. The original sequence length is defined as n, then the value of t is [1,n] before the base point transformation, and the value of t is [0,n] after the base point transformation. The base point transformation can make the multiple integral feature sensitive to the translation of the path and eliminate the translation invariance.

[0053] The additional increasing dimensional transformation is to determine the time coordinate path according to the sequence length of the original traffic path. The time coordinate path is determined based on the value range of t, so it is also equivalent to determining it according to the sequence length. However, it should be noted that because the above steps have been processed by the base point transformation, the value of t at this time is [0,n], for example, the time coordinate path is (0,1,2,3,…,n).

[0054] After the above four path transformation processes, the second upload path, the second download path, the second accumulation and upload path, the second accumulation and download path and the time coordinate path are obtained, and the five paths form the target traffic path.

[0055] By performing path transformation processing on the original traffic path, the original traffic path is converted into a target traffic path that is more capable of mining the encrypted traffic data features and has five dimensions, thereby improving the effectiveness of subsequent re-integrated feature data and the accuracy of predicted classification results.

[0056] In step S103 of some embodiments, reference Figure 2 , the step of determining the multi-integral characteristic data according to the target flow path includes: Step S201, obtaining a preset number of layers of the layered dynamic window, and determining the window size and step size of the layered dynamic window at each layer according to the preset number of layers and the sequence length of the target traffic path.

[0057] Step S202: based on the target traffic path, extract the sub-path of each dimension of the target traffic path according to the preset number of layers, window size and step size.

[0058] Step S203, determining the multi-integral characteristic data according to the sub-path.

[0059] In order to further improve the effectiveness of extracting the features of the target traffic path, the target traffic path is sliced ​​through a hierarchical dynamic window to extract multiple sub-paths.

[0060] Specifically, the preset number of layers of the hierarchical dynamic window is q. Since the window size and step size are the same at the same level, only the window size is used as an example for explanation. The window size is related to the level, and the window sizes of dynamic windows at different levels are different. Specifically, , where p is the actual level used for counting during extraction, p is less than or equal to q, and m is the sequence length of any path in the target traffic path. Based on this formula, it can be understood that as the level increases, the window size and step size gradually decrease relative to the sequence length, and more sub-paths will be extracted, which is equivalent to a finer extraction scale.

[0061] For any path in the target traffic path, it is sliced ​​according to the hierarchical dynamic window determined by the preset number of layers, window size and step size, and multiple sub-paths are extracted. The five paths in the target traffic path are all processed by the hierarchical dynamic window, and the corresponding multiple sub-paths are extracted respectively. Regarding the extraction process, the level is first set to 1. At this time, the window size and step size when the level is 1 are calculated according to the above window size formula. According to the formula, the window size when the level is 1 is equal to the sequence length. Therefore, the first sub-path extracted is the same as the original path. At this time, the level 2 is calculated. According to the above formula, the window size and step size when the level is 2 are calculated to be half of the sequence length. Therefore, two sub-paths are extracted. The two sub-paths are equivalent to slicing the original path from the middle position, and then and so on until the preset number of levels are also extracted. Reference Figure 3 , Figure 3This is a schematic diagram of extracting sub-paths from a path using a hierarchical dynamic window. In the figure, slices are indicated by dotted boxes. From top to bottom, they are the original path, the slice at level 1, the slice at level 2, and the slice at level 3. Each slice forms a sub-path.

[0062] For example, let q be 2, a sequence is [0,1,2,3,4,5,6,7,8,9], that is, m is 10, when level 1, the window size is =10, so the first subpath is [0,1,2,3,4,5,6,7,8,9]. Since the window has reached the end of the sequence, we start calculating level 2. At this time, the window size is =5, so the second subpath is [0,1,2,3,4], and the step size is also 5, so the third subpath is [5,6,7,8,9]. In this way, the level reaches the preset number of levels, and the window has reached the end of the sequence, and the subpath extraction is completed.

[0063] The step of calculating the multi-integral feature data is performed based on the extracted sub-paths, and the sub-paths of the target traffic path are further extracted through the hierarchical dynamic window, highlighting the effectiveness of the input information in calculating the multi-integral feature data, thereby improving the effectiveness of subsequent multi-integral feature data and the accuracy of predicted classification results.

[0064] In some embodiments, step S203 includes: For the sub-paths extracted from the same hierarchical dynamic window, the corresponding sub-multiple integral feature data are calculated.

[0065] Generate multi-integral characteristic data based on all sub-multi-integral characteristic data.

[0066] When calculating the multi-integral feature data based on the subpath, the subpaths extracted from the same hierarchical dynamic window are calculated as a group, and the corresponding sub-multi-integral feature data are calculated for each group. The same hierarchical dynamic window includes the same level and the same window position. For example, there are two sequences, which are [0, 1, 2, 3, 4, 5, 6, 7, 8, 9] and [10, 11, 12, 13, 14, 15, 16, 17, 18, 19], and the corresponding multiple subpaths are extracted through the hierarchical dynamic window, respectively. Among them, [0, 1, 2, 3, 4] and [10, 11, 12, 13, 14] belong to a group of subpaths extracted from the hierarchical dynamic window with the same level and the same window position. It can be understood that the other group includes [5, 6, 7, 8, 9] and [15, 16, 17, 18, 19].

[0067] The calculation formula of the multi-integral can refer to the above formula (1), and the calculated multiple sub-multi-integral characteristic data are combined to generate the required multi-integral characteristic data.

[0068] In addition, it should be noted that, referring to the above formula (1) and the corresponding examples, it can be understood that the first item of the calculated sub-multiple integral characteristic data is 1, and this data item is not helpful for the data analysis in the subsequent steps. Therefore, for each sub-multiple integral characteristic data, the first data item can be removed and then combined to generate the multi-integral characteristic data.

[0069] By calculating the sub-multiple integral feature data based on the sub-paths and then combining them into multiple integral feature data, the multiple integral calculation process can also make full use of the information of different scales extracted from the path by the hierarchical dynamic window, improve the effectiveness of the multiple integral feature data, and thus improve the accuracy of the predicted classification results.

[0070] In step S103 of some embodiments, the step of screening and determining target feature data according to the multi-integrated feature data includes: Based on the Tree SHAP algorithm of BorutaShap, the Shapley value corresponding to each characteristic item in the multi-integrated characteristic data is calculated.

[0071] According to the Shapley value of each feature item, a preset number of target feature items are screened out from the multi-integral feature data, and target feature data are formed according to the target feature items, wherein the Shapley value of the target feature item is the largest among the Shapley values ​​of all feature items.

[0072] The data items in the multiple integral feature data are defined as feature items. The number of feature items can be determined by the signature dimension of formula (3). By comparing the example of calculating the double path integral for a two-dimensional path in the above embodiment, it can be understood that the increase in dimension and the setting of a finer-scale hierarchical dynamic window will cause the number of feature items in the multiple integral feature data to increase exponentially, thus causing the feature data used for training or prediction to be too large, making the model too complicated.

[0073] To address this problem, this embodiment uses the Tree SHAP algorithm of BorutaShap to screen feature items. The BorutaSHAP algorithm combines the two feature selection methods, Boruta and SHAP value (Shapley value). The Boruta algorithm is a feature selection algorithm based on random forests. It determines the influence of each feature on the model by building a random forest model and comparing the importance of original features and randomly generated shadow features. The SHAP (SHapley AdditiveexPlanations) value is an explanatory machine learning technology. The Tree SHAP algorithm is a module of SHAP analysis. The Shapley value is used to measure the contribution of each feature to the model output and provides a global and local understanding of the model prediction explanation.

[0074] Specifically, for each feature item in the multi-integrated feature data, its corresponding Shapley value is calculated, and a preset number of target feature items with the largest Shapley values ​​are screened out, for example, 10 items. The target feature items are all features that contribute most to the model output. Based on this, target feature data is formed according to the target feature items.

[0075] The BorutaSHAP algorithm combines these two methods. It uses the Boruta algorithm for preliminary feature selection and combines it with the Shapley value to more accurately evaluate the importance of features. This combination can help identify the most important features in the data set and optimize the performance of the machine learning model. On the other hand, the number of feature items in the screened target feature data depends on the preset number set, so it is also possible to control and adjust the number of feature items and screen out the appropriate number of feature items, thereby reducing the complexity of the model for classifying encrypted traffic and reducing the cost of using the model.

[0076] In some embodiments, reference Figure 4 The method may also include but is not limited to steps S301 to S306.

[0077] Step S301 : acquiring sample data of a sample set, and determining a sample session corresponding to the sample data according to a quintuple of the sample data.

[0078] Step S302: for sample data of the same sample session, an original traffic path is generated according to the sample data and the five-tuple of the sample data.

[0079] Step S303: perform path transformation processing on the original traffic path to obtain the target traffic path.

[0080] Step S304, determining the multi-integral characteristic data according to the target flow path, and screening and determining the target characteristic data according to the multi-integral characteristic data.

[0081] Step S305 , determining the target feature data corresponding to different sample sessions as a training data set, and dividing the training data set into a training set, a validation set, and a test set according to a preset ratio.

[0082] Step S306, training a preset model according to the training set, the validation set and the test set to obtain a traffic classification model.

[0083] Before implementing the above-mentioned embodiment method, it is necessary to first obtain the traffic classification model, so this embodiment is proposed to be used for training to obtain the traffic classification model. Specifically, sample data of a sample set is obtained, and the sample set is a data set of network traffic. The traffic data is defined as the sample data. An original traffic path is generated according to the sample data and the five-tuple of the sample data. Four path transformation processes are performed on the original traffic path to obtain a target traffic path with the same specifications as above. A plurality of sub-paths are also extracted through a layered sliding window. The multi-integral feature data is determined based on the sub-path calculation, and the target feature data is determined by screening. The above steps can refer to the above embodiments, perform the same processing, and have the same effect on the multi-integral feature data generated based on the sample data. No further description is given here. Different from the above analysis only for the target session, the sample set includes a large number of sessions. Correspondingly, a large number of target feature data corresponding to different sessions are also obtained based on the sample set. The sample set is determined as a training data set, and is divided into a training set, a validation set, and a test set according to a preset ratio. The preset ratio can be set to 70%, 20%, and 10%, respectively. In other embodiments, it can also be set to other ratios. Then, the preset model is trained according to the training set, the validation set, and the test set. After the training is completed, the traffic classification model can be obtained.

[0084] Among them, since the training of general models relies on a large amount of artificially designed training data, the screening of multi-integral feature data in the training step of the model in this embodiment can better play a role in reducing the complexity and usage cost of the model, thereby obtaining a traffic classification model with a model complexity within the expectations of the staff, and maintaining a low usage cost in the subsequent prediction and classification process, thereby reducing the overall usage cost of the model.

[0085] The following is a detailed description and explanation of the solution of the embodiment of the present invention in conjunction with a specific application example: In an embodiment of the present application, an encrypted traffic classification method based on a multi-integral feature is provided. The method first obtains sample data of a sample set, determines the sample session corresponding to each sample data according to the five-tuple of the sample data, determines the length of the data packet of the sample data in each time period of the corresponding sample session for the sample data belonging to the same sample session, determines the data type of each data packet length according to its five-tuple as upload data or download data, and generates an original traffic path according to the length of the data packet in each time period and its data type. The original traffic path is subjected to path decomposition transformation processing to obtain a first upload path and a first download path, and then the first upload path and the first download path are respectively subjected to accumulation and transformation processing to obtain a first accumulation and upload path and a first accumulation and download path, and then the first upload path, the first download path, the first accumulation and upload path, and the first accumulation and download path are respectively subjected to base point transformation processing to obtain the corresponding second upload path, the second download path, the second accumulation and upload path, and the second accumulation and download path, and the time coordinate path is determined according to the sequence length of the original traffic path, and a five-dimensional target traffic path is formed according to the second upload path, the second download path, the second accumulation and upload path, the second accumulation and download path, and the time coordinate path.

[0086] Based on the target traffic path, the preset number of layers of the hierarchical dynamic window is obtained, and the window size and step size of the hierarchical dynamic window at each level are determined according to the preset number of layers and the sequence length of the target traffic path. The sub-paths of each dimension of the target traffic path are extracted according to the preset number of layers, window size and step size. For the sub-paths extracted from the same hierarchical dynamic window, the corresponding sub-multiple integral feature data are calculated, and the multi-integral feature data are generated by splicing all the sub-multiple integral feature data. Based on the Tree SHAP algorithm of BorutaShap, the Shapley value corresponding to each feature item in the multi-integral feature data is calculated, and the target feature items with the largest preset number of Shapley values ​​are screened out from the multi-integral feature data to form the target feature data. The target feature data corresponding to each sample session is formed into a training data set, and the training data set is divided into a training set, a validation set and a test set according to a preset ratio. The preset model is trained using the training set, the validation set and the test set to obtain a traffic classification model.

[0087] Based on the traffic classification model, the encrypted traffic data of the target session is collected, and the encrypted traffic data is processed in the same way as above. The original traffic path is generated according to the encrypted traffic data and its five-tuple, and the same path transformation processing is performed on the original traffic path to obtain the target traffic path. The sub-path is extracted based on the target traffic path, and the multi-integral feature data is calculated. The target feature data is determined based on the multi-integral feature data. The target feature data is input into the traffic classification model, and the category of the encrypted traffic data can be determined according to the output result of the traffic classification model.

[0088] The encrypted traffic classification method based on the multi-integral feature provided in the embodiment of the present application relates to the field of network communication technology. The encrypted traffic classification method based on the multi-integral feature provided in the embodiment of the present application can be applied to a terminal, can also be applied to a server, and can also be software running in a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, and a car terminal, etc., but is not limited to this; the server side can be configured as an independent physical server, or it can be configured as a server cluster or a distributed system composed of multiple physical servers, and can also be configured to provide cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms and other basic cloud computing services. The server can also be a node server in a blockchain network; the software can be an application that implements the encrypted traffic classification method based on the multi-integral feature, etc., but is not limited to the above forms.

[0089] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0090] See also Figure 5 The embodiment of the present application further provides an encrypted traffic classification device based on the multiple integral feature, which can implement the above-mentioned encrypted traffic classification method based on the multiple integral feature, and the device includes: The traffic processing module is used to obtain the encrypted traffic data of the target session, and generate the original traffic path according to the encrypted traffic data and the five-tuple of the encrypted traffic data. The original traffic path is a sequence formed by the length of the data packets of the target session in each time period.

[0091] The path transformation module is used to perform path transformation processing on the one-dimensional original traffic path to obtain the five-dimensional target traffic path.

[0092] The feature extraction module is used to determine the multi-integral feature data according to the target flow path, and to screen and determine the target feature data according to the multi-integral feature data.

[0093] The prediction module is used to input the target feature data into the traffic classification model and determine the category of the encrypted traffic data according to the output result of the traffic classification model.

[0094] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0095] See also Figure 6 , Figure 6 The hardware structure of an electronic device of another embodiment is illustrated, and the electronic device includes: The processor 901 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application; The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other applications. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 902, and the processor 901 calls and executes the encrypted traffic classification method based on the multi-integral feature of the embodiment of the present application; Input / output interface 903, used to implement information input and output; Communication interface 904, used to realize communication interaction between the device and other devices, which can be realized through wired mode (such as USB, network cable, etc.) or wireless mode (such as mobile network, WIFI, Bluetooth, etc.); A bus 905 that transmits information between various components of the device (e.g., the processor 901, the memory 902, the input / output interface 903, and the communication interface 904); The processor 901 , the memory 902 , the input / output interface 903 and the communication interface 904 are connected to each other in communication within the device via a bus 905 .

[0096] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned encrypted traffic classification method based on the multiple integral feature.

[0097] It can be understood that the contents of the above method embodiments are all applicable to the present storage medium embodiments, the functions specifically implemented by the present storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0098] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0099] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0100] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0101] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0102] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0103] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0104] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0105] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the above units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0106] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0107] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0108] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store programs.

[0109] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.

Claims

1. A method for classifying encrypted traffic based on multi-integral features, characterized in that: The method comprises: Acquire encrypted traffic data of a target session, and generate an original traffic path according to the encrypted traffic data and a five-tuple of the encrypted traffic data, wherein the original traffic path is a sequence formed by the lengths of data packets of the target session in each time period; Performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path; Determine the multi-integral characteristic data according to the target flow path, and screen and determine the target characteristic data according to the multi-integral characteristic data; The target feature data is input into a traffic classification model, and the category of the encrypted traffic data is determined according to an output result of the traffic classification model.

2. The method according to claim 1, characterized in that The step of screening and determining target characteristic data according to the multi-integrated characteristic data comprises: Based on the Tree SHAP algorithm of BorutaShap, the Shapley value corresponding to each characteristic item in the multi-integrated characteristic data is calculated; According to the Shapley value of each of the feature items, a preset number of target feature items are screened out from the multi-integrated feature data, and the target feature data are formed according to the target feature items, wherein the Shapley value of the target feature item is the largest among the Shapley values ​​of all the feature items.

3. The method according to claim 1, characterized in that The step of determining the multi-integrated characteristic data according to the target flow path comprises: Obtaining a preset number of layers of the layered dynamic window, and determining a window size and a step size of the layered dynamic window at each layer according to the preset number of layers and the sequence length of the target traffic path; Based on the target traffic path, extracting a subpath of each dimension of the target traffic path according to the preset number of layers, the window size and the step size; The multi-integrated characteristic data is determined according to the sub-path.

4. The method according to claim 3, characterized in that The step of determining the multi-integral characteristic data according to the sub-path comprises: For the sub-paths extracted from the same layered dynamic window, calculating corresponding sub-multiple integral feature data; The multi-integrated feature data is generated based on all the sub-multi-integrated feature data.

5. The method according to claim 1, characterized in that The step of performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path includes: Performing path decomposition and transformation processing on the original traffic path to obtain a first upload path and a first download path; Performing accumulation and transformation processing on the first upload path and the first download path respectively to obtain a first accumulation and upload path and a first accumulation and download path; Performing base point transformation processing on the first upload path, the first download path, the first accumulation and upload path, and the first accumulation and download path, respectively, to obtain corresponding second upload path, second download path, second accumulation and upload path, and second accumulation and download path; Determining a time coordinate path according to the sequence length of the original traffic path; The five-dimensional target traffic path is formed according to the second upload path, the second download path, the second accumulation and upload path, the second accumulation and download path and the time coordinate path.

6. The method according to claim 1, characterized in that The step of generating an original traffic path according to the encrypted traffic data and the five-tuple of the encrypted traffic data comprises: Determine the data packet length of the encrypted traffic data in each of the time periods; Determine the data type of the data corresponding to the length of each data packet according to the quintuple, the data type including upload data or download data; The original traffic path is generated according to the data packet length and the data type in each of the time periods.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Acquire sample data of a sample set, and determine a sample session corresponding to the sample data according to a quintuple of the sample data; For the sample data of the same sample session, generating the original traffic path according to the sample data and the quintuple of the sample data; Performing path transformation processing on the original traffic path to obtain the target traffic path; Determine the multi-integral characteristic data according to the target flow path, and screen and determine the target characteristic data according to the multi-integral characteristic data; Determine the target feature data corresponding to different sample sessions as a training data set, and divide the training data set into a training set, a validation set, and a test set according to a preset ratio; A preset model is trained according to the training set, the validation set and the test set to obtain the traffic classification model.

8. An encrypted traffic classification device based on multiple integral features, characterized in that: The device comprises: A traffic processing module, used for obtaining encrypted traffic data of a target session, and generating an original traffic path according to the encrypted traffic data and a five-tuple of the encrypted traffic data, wherein the original traffic path is a sequence formed by the lengths of data packets of the target session in each time period; A path transformation module, used for performing path transformation processing on the one-dimensional original traffic path to obtain a five-dimensional target traffic path; A feature extraction module, used to determine the multi-integrated feature data according to the target flow path, and to screen and determine the target feature data according to the multi-integrated feature data; The prediction module is used to input the target feature data into the traffic classification model and determine the category of the encrypted traffic data according to the output result of the traffic classification model.

9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Encrypted traffic classification method and device based on path signature

    CN118449702A

  • Real-time network application visibility classifier of encrypted traffic based on feature engineering

    US20210168083A1