Encrypted traffic classification method and device, electronic equipment and storage medium
By subdividing the business types in the encrypted traffic classification method into multiple subclasses, and using deep metric learning strategies to extract differential and common features for multi-center decoupling, a multi-center encrypted traffic classifier is built, which solves the problem of poor classification accuracy of traffic samples for unknown applications, and achieves stronger generalization capabilities and recognition effects.
Patent Information
- Application Number
- CN202411822026.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-05-09
AI Technical Summary
The existing encrypted traffic classification methods have poor accuracy in classifying traffic samples for unknown applications, making it difficult to effectively identify emerging application traffic.
By dividing each business type into multiple subclasses based on the inherent traffic characteristics differences between different applications under the same business type under the preset; then, based on the deep metric learning strategy, the differentiated and common features between multiple subclasses corresponding to each business type are extracted, and multi-center decoupling is performed to build a multi-center encrypted traffic classifier. The classifier can classify traffic samples of target unknown applications and identify their encrypted traffic types by comparing the distances of traffic samples to the centers of each subclass feature.
It improves the classification accuracy of unknown application traffic samples, enhances the ability to identify emerging application traffic, and solves the problem of decreasing generalization in the existing technology.
Smart Images

Figure CN119961774A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of encrypted traffic classification, and in particular to an encrypted traffic classification method, device, electronic device and storage medium. Background Art
[0002] As the Internet continues to develop, various types of applications, such as social media, videos, and online games, emerge in an endless stream. Encrypted traffic classification technology can determine the type of business it belongs to based on the characteristics of different types of traffic. This technology plays an important role in network management and network supervision.
[0003] First, encrypted traffic classification technology can help network administrators better understand and grasp the composition and trend of network traffic, thereby optimizing network resource allocation, improving network performance and stability; second, encrypted traffic classification technology can also help network regulators effectively monitor and manage network usage behavior, identify and block malicious traffic, and protect network security and user privacy. In short, the development and application of encrypted traffic classification technology will bring more efficient and accurate means to network management and network supervision, and promote the healthy development of the Internet.
[0004] Encrypted traffic classification requires consideration of the following two practical issues:
[0005] 1. The flow completion time of delay-sensitive applications (such as online search, social media, etc.) directly affects the user experience and even the cost-benefit of Internet operators. Therefore, in order to meet the performance requirements of this application, encrypted traffic classification must ensure that the classification speed is as fast as possible.
[0006] 2. The actual network environment is dynamic and unpredictable, and new applications are constantly emerging. It is impossible to grasp the traffic characteristics of all applications running in the network in advance. Therefore, encrypted traffic classification needs to have the ability to generalize unknown applications in order to effectively classify the traffic of newly emerging applications.
[0007] In recent years, some related technologies have attempted to use machine learning technology to classify encrypted traffic. Methods based on data flow statistical characteristics or time series characteristics have good performance. However, these methods must collect multiple data packets or even the entire stream to obtain sufficient information to ensure classification accuracy, resulting in large classification delays. In order to achieve fast classification, existing technologies can also classify traffic based on the original data content of a single data packet (data packet header or payload). This method can reduce the classification delay from milliseconds to microseconds, and the recognition accuracy is also considerable.
[0008] However, although the existing encrypted traffic classification methods based on data streams can provide high classification accuracy, they need to collect information from multiple data packets or the entire flow, resulting in a low classification speed. In addition, although the methods based on single data packets can achieve fast classification to a certain extent, when facing traffic from unknown applications, there may be problems such as decreased generalization, which need to be solved urgently. Summary of the invention
[0009] The present application provides an encrypted traffic classification method, device, electronic device and storage medium to solve the problem that the existing encrypted traffic classification method has poor classification accuracy for traffic samples of unknown applications.
[0010] The first aspect of the present application provides an encrypted traffic classification method, comprising the following steps: first, based on the inherent traffic feature differences between different applications under the same business type, each business type is divided into multiple subclasses; then, based on a preset deep metric learning strategy, the differential features between the multiple subclasses corresponding to each business type are extracted, and the common features between the multiple subclasses are retained, so as to perform multi-center decoupling of the feature space of each business type according to the differential features and the common features, so as to construct a multi-center encrypted traffic classifier; the traffic samples of the target unknown application are classified by the multi-center encrypted traffic classifier to obtain a classification result, and the distance from the traffic sample to each subclass feature center corresponding to the target unknown application is compared, so as to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance.
[0011] Optionally, in one embodiment of the present application, each business type is divided into multiple subclasses based on the inherent traffic characteristic differences between different applications under the same preset business type, including: performing a subclass analysis operation on each business type to obtain a subclass analysis result; and classifying the traffic samples of each business type according to the subclass analysis result to generate multiple subclasses corresponding to each business type.
[0012] Optionally, in one embodiment of the present application, the preset deep metric learning strategy is used to extract the differential features between the multiple subclasses corresponding to each business type, and retain the common features between the multiple subclasses, so as to perform multi-center decoupling on the feature space of each business type according to the differential features and the common features, so as to construct a multi-center encrypted traffic classifier, including: extracting the message byte size, arrival time, and uplink and downlink transmission direction features of each subclass in the multiple subclasses corresponding to each business type; based on the preset data feature optimization loss function and the message byte size, arrival time, and uplink and downlink transmission direction features of each subclass, obtaining the differential features and the common features of different subclasses under each business type; performing multi-center decoupling on the feature space of each business type according to the differential features and the common features, obtaining the multi-center features of the feature space of each business type, and using the multi-center features to construct the multi-center encrypted traffic classifier.
[0013] Optionally, in one embodiment of the present application, the traffic sample of the target unknown application is classified by the multi-center encrypted traffic classifier to obtain a classification result, and the distance from the traffic sample to each subclass feature center corresponding to the target unknown application is compared to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance, including: obtaining the message byte size, arrival time, and uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application; based on the message byte size, arrival time, uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application and the multi-center encrypted traffic classifier, comparing the distance from the traffic sample of the target unknown application to each subclass feature center corresponding to the target unknown application to determine the encrypted traffic type of the traffic sample of the unknown application according to the distance.
[0014] Optionally, in one embodiment of the present application, the mathematical expression of the data feature optimization loss function is:
[0015]
[0016] Among them, D ij represents the distance between data sample i and data sample j; y ij Indicates whether the data sample i and the data sample j are of the same business type / subclass data, y ij =0 means that sample i and data sample j belong to different business types, y ij =1 means that sample i and data sample j belong to different subcategories under the same business type, y ij=2 means that sample i and data sample j belong to the same subclass under the same business type; a is the distance constraint between samples of the same subclass, b is the distance constraint between samples of different subclasses under the same business type, and m is the distance constraint between samples of different classes.
[0017] The second aspect of the present application provides an encrypted traffic classification device, including: a classification module, which is used to divide each business type into multiple subclasses based on the inherent traffic feature differences between different applications under the same business type; a decoupling module, which is used to extract the difference features between the multiple subclasses corresponding to each business type based on a preset deep metric learning strategy, and retain the common features between the multiple subclasses, so as to perform multi-center decoupling of the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; an identification module, which is used to classify the traffic samples of the target unknown application through the multi-center encrypted traffic classifier to obtain a classification result, and compare the distance from the traffic sample to each subclass feature center corresponding to the target unknown application, so as to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance.
[0018] Optionally, in one embodiment of the present application, the classification module includes: a subclass analysis unit, used to perform a subclass analysis operation on each business type to obtain a subclass analysis result; and a classification unit, used to classify the traffic samples of each business type according to the subclass analysis result to generate multiple subclasses corresponding to each business type.
[0019] Optionally, in one embodiment of the present application, the decoupling module includes: an extraction unit, used to extract the message byte size, arrival time, and uplink and downlink transmission direction characteristics of each subclass corresponding to each service type; a first acquisition unit, used to optimize the loss function based on a preset data feature and the message byte size, the arrival time, and the uplink and downlink transmission direction characteristics of each subclass, to obtain the differential characteristics and the common characteristics of different subclasses under each service type; a construction unit, used to perform multi-center decoupling on the feature space of each service type according to the differential characteristics and the common characteristics, to obtain the multi-center characteristics of the feature space of each service type, and to construct the multi-center encrypted traffic classifier using the multi-center characteristics.
[0020] Optionally, in one embodiment of the present application, the identification module includes: a second acquisition unit, used to obtain the message byte size, arrival time, and uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application; a determination unit, used to compare the distance from the traffic sample of the target unknown application to each subclass feature center corresponding to the target unknown application based on the message byte size, arrival time, uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application and the multi-center encrypted traffic classifier, so as to determine the encrypted traffic type of the traffic sample of the unknown application according to the distance.
[0021] Optionally, in one embodiment of the present application, the mathematical expression of the data feature optimization loss function is:
[0022]
[0023] Among them, D ij represents the distance between data sample i and data sample j; y ij Indicates whether the data sample i and the data sample j are of the same business type / subclass data, y ij =0 means that sample i and data sample j belong to different business types, y ij =1 means that sample i and data sample j belong to different subcategories under the same business type, y ij =2 means that sample i and data sample j belong to the same subclass under the same business type; a is the distance constraint between samples of the same subclass, b is the distance constraint between samples of different subclasses under the same business type, and m is the distance constraint between samples of different classes.
[0024] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the encrypted traffic classification method as described in the above embodiment.
[0025] The fourth aspect of the present application provides a computer-readable storage medium, which stores a computer program that implements the above encrypted traffic classification method when executed by a processor.
[0026] Therefore, the embodiments of the present application have the following beneficial effects:
[0027] The embodiments of the present application can divide each business type into multiple subclasses based on the inherent traffic feature differences between different applications under the same business type; then based on the preset deep metric learning strategy, extract the difference features between the multiple subclasses corresponding to each business type, and retain the common features between the multiple subclasses, so as to perform multi-center decoupling of the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; classify the traffic samples of the target unknown application through the multi-center encrypted traffic classifier to obtain the classification results, and compare the distances from the traffic samples to the feature centers of each subclass corresponding to the target unknown application, so as to identify the encrypted traffic type corresponding to the traffic samples of the unknown application based on the classification results and the distances. Thus, the problems such as the poor classification accuracy of traffic samples of unknown applications by the existing encrypted traffic classification methods are solved.
[0028] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0030] Figure 1 A flowchart of an encrypted traffic classification method provided according to an embodiment of the present application;
[0031] Figure 2 A schematic diagram of a training process of a multi-center encrypted traffic classifier provided for one embodiment of the present application;
[0032] Figure 3 This is an example diagram of an encrypted traffic classification device according to an embodiment of the present application;
[0033] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0034] Among them, 10-encrypted traffic classification device; 100-classification module, 200-decoupling module, 300-identification module; 401-memory, 402-processor, 403-communication interface. DETAILED DESCRIPTION
[0035] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0036] The following describes the encrypted traffic classification method, device, electronic device and storage medium of the embodiment of the present application with reference to the accompanying drawings. In response to the problems mentioned in the above background technology, the present application provides an encrypted traffic classification method, in which each business type is first divided into multiple subclasses based on the inherent traffic feature differences between different applications under the same business type; then, based on the preset deep metric learning strategy, the difference features between the multiple subclasses corresponding to each business type are extracted, and the common features between the multiple subclasses are retained, so as to perform multi-center decoupling of the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; the traffic samples of the target unknown application are classified by the multi-center encrypted traffic classifier to obtain the classification results, and the distances from the traffic samples to the feature centers of each subclass corresponding to the target unknown application are compared, so as to identify the encrypted traffic type corresponding to the traffic samples of the unknown application based on the classification results and the distances. Thus, the problem of poor classification accuracy of traffic samples of unknown applications by the existing encrypted traffic classification methods is solved.
[0037] Specifically, Figure 1 A flowchart of an encrypted traffic classification method provided in an embodiment of the present application.
[0038] like Figure 1 As shown, the encrypted traffic classification method includes the following steps:
[0039] In step S101, each service type is divided into multiple subclasses based on the inherent traffic characteristic differences between different applications under the same service type.
[0040] The embodiments of the present application can first observe the traffic characteristics of different applications of each business type and divide each business type into multiple subclasses according to different traffic patterns. This step is the basis for subsequent multi-center feature decoupling.
[0041] Optionally, in one embodiment of the present application, each business type is divided into multiple subclasses based on the inherent traffic characteristic differences between different applications under the same preset business type, including: performing a subclass analysis operation on each business type to obtain a subclass analysis result; and classifying the traffic samples of each business type according to the subclass analysis result to generate multiple subclasses corresponding to each business type.
[0042] In one embodiment of the present application, in order to more finely analyze and manage the traffic characteristics under the same business type, each business type can be further subdivided into multiple subcategories based on the inherent traffic characteristic differences between different applications under the same business type.
[0043] It can be understood that the above-mentioned subdivision operation can more accurately reflect the traffic characteristics in different application scenarios. For example, for video services, they can be subdivided into short video, long video and live broadcast: the traffic characteristics of short video are usually characterized by high request frequency, small data volume and strong burstiness; the traffic characteristics of long video are mainly continuous and stable data flow, with large bandwidth occupancy; while the live broadcast emphasizes real-time and low latency, and the data transmission is continuous and highly stable. By performing subclass analysis operations on each business type and identifying its inherent traffic characteristics, accurate subclass analysis results can be obtained. Subsequently, based on these subclass analysis results, the traffic samples of each business type are classified to obtain a set of traffic samples corresponding to multiple subclasses.
[0044] The embodiment of the present application pre-classifies the traffic samples of each business type by analyzing the subcategories that may be included in each business type.
[0045] In step S102, based on the preset deep metric learning strategy, the differential features between multiple subclasses corresponding to each business type are extracted, and the common features between the multiple subclasses are retained, so as to perform multi-center decoupling of the feature space of each business type according to the differential features and the common features, so as to construct a multi-center encrypted traffic classifier.
[0046] Optionally, in one embodiment of the present application, based on a preset deep metric learning strategy, differential features between multiple subclasses corresponding to each business type are extracted, and common features between multiple subclasses are retained, so as to perform multi-center decoupling of the feature space of each business type according to the differential features and common features, so as to construct a multi-center encrypted traffic classifier, including: extracting the message byte size, arrival time, and uplink and downlink transmission direction features of each subclass in the multiple subclasses corresponding to each business type; optimizing the loss function based on a preset data feature and the message byte size, arrival time, and uplink and downlink transmission direction features of each subclass, to obtain the differential features and common features of different subclasses under each business type; performing multi-center decoupling of the feature space of each business type according to the differential features and common features, to obtain the multi-center features of the feature space of each business type, and using the multi-center features to construct a multi-center encrypted traffic classifier.
[0047] It should be noted that the embodiment of the present application can extract differential features from multiple subclasses of each business type by introducing a preset deep metric learning strategy, while retaining the common features between multiple subclasses, thereby effectively realizing the multi-center decoupling of the feature space, and then constructing an efficient multi-center encrypted traffic classifier. Specifically, the core steps of this embodiment include the following:
[0048] First, we extract key traffic features such as the message byte size, arrival time, and uplink and downlink transmission directions of different subclasses in each service type. These features can reflect the time series characteristics, directional characteristics, and traffic intensity of traffic behavior, thus providing a basis for subsequent feature analysis.
[0049] Secondly, based on the preset deep metric learning strategy, a loss function for data feature optimization is introduced. By taking the subclass’s message byte size, arrival time, and uplink and downlink transmission direction as input, the feature distribution of each subclass is calculated to accurately capture the differential features of different subclasses and extract the common features between subclasses. This optimization process balances the extraction of differential features and common features, avoiding excessive aliasing of features between subclasses and enhancing the ability to characterize the internal traffic features of each service type.
[0050] Afterwards, the feature space of each business type is decoupled by multiple centers using the above-mentioned differential features and common features. The multi-center decoupling aims to construct multiple center points based on the unique differential features of each subclass, while using common features to maintain the correlation between subclasses. Thus, the feature space of each subclass is separated around its own center point, while the feature space of the overall business type remains consistent and complete.
[0051] Finally, based on the decoupled multi-center feature space, a multi-center encrypted traffic classifier is constructed. This classifier can accurately classify encrypted traffic according to the multi-center structure of the feature space of the business type.
[0052] Optionally, in one embodiment of the present application, the mathematical expression of the data feature optimization loss function is:
[0053]
[0054] Among them, D ij represents the distance between data sample i and data sample j; y ij Indicates whether data sample i and data sample j are of the same business type / subcategory, y ij =0 means that sample i and data sample j belong to different business types, y ij =1 means that sample i and data sample j belong to different subcategories under the same business type, y ij =2 means that sample i and data sample j belong to the same subclass under the same business type; a is the distance constraint between samples of the same subclass, b is the distance constraint between samples of different subclasses under the same business type, and m is the distance constraint between samples of different classes.
[0055] As an achievable method, the embodiments of the present application may use the above formula as the loss function of deep metric learning to train the feature extractor.
[0056] Therefore, the embodiments of the present application improve the training effect of the multi-center encrypted traffic classifier by setting a suitable loss function.
[0057] In step S103, the traffic sample of the target unknown application is classified by a multi-center encrypted traffic classifier to obtain a classification result, and the distance between the traffic sample and each subclass feature center corresponding to the target unknown application is compared to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance.
[0058] Optionally, in one embodiment of the present application, traffic samples of the target unknown application are classified by a multi-center encrypted traffic classifier to obtain classification results, and the distances from the traffic samples to the feature centers of each subclass corresponding to the target unknown application are compared to identify the encrypted traffic type corresponding to the traffic samples of the unknown application based on the classification results and the distances, including: obtaining the message byte size, arrival time, and uplink and downlink transmission direction characteristics of the traffic samples of the target unknown application; based on the message byte size, arrival time, uplink and downlink transmission direction characteristics of the traffic samples of the target unknown application and the multi-center encrypted traffic classifier, comparing the distances from the traffic samples of the target unknown application to the feature centers of each subclass corresponding to the target unknown application to determine the encrypted traffic type of the traffic samples of the unknown application according to the distance.
[0059] It should be noted that the embodiments of the present application can first obtain the message byte size, arrival time, and uplink and downlink transmission direction characteristics of the unknown application traffic sample; secondly, based on the multi-center encrypted traffic classifier, the encrypted traffic type of the unknown application traffic sample is determined by comparing the distance from the unknown application traffic sample to the feature center of each subclass.
[0060] Therefore, the embodiments of the present application achieve accurate identification of unknown application traffic samples through deep metric learning and optimized loss function, which effectively ensures the generalization of the method.
[0061] like Figure 2 As shown in the figure, the classification process of the multi-center encrypted traffic classifier is as follows:
[0062] 1. Pre-classification: By observing the traffic characteristics of different applications of each business type, each business type is divided into multiple subcategories according to different traffic patterns, such as Figure 2 As shown, in the embodiment of the present application, the number of subclasses is 2, and the specific value can be observed and set by those skilled in the art according to the actual situation, and is not specifically limited here;
[0063] 2. Multi-center feature extraction: Through deep metric learning combined with data features to optimize the loss function, the following three optimization goals are achieved:
[0064] 1) Different business types are distinguished, and the negative sample distance is limited to be greater than or equal to m;
[0065] 2) Differentiate between subcategories under the same business type, and limit the distance between subcategories to be greater than or equal to b;
[0066] 3) The samples within the subclass of the same business type are as close as possible, and the distance between samples within the subclass is limited to be less than or equal to a.
[0067] It can be understood that the embodiment of the present application can achieve the decoupling of the multi-center features of the feature space of each business type through deep metric learning combined with the classifier trained by the above-mentioned loss function; then calculate the average value of the sample features contained in each subclass under each business type, that is, the feature center of each subclass, and finally obtain the multi-center features of each business type.
[0068] Therefore, the embodiment of the present application classifies unknown application traffic samples based on a multi-center encrypted traffic classifier, which can achieve a relatively accurate classification effect (the classification accuracy is increased by 10%) and demonstrate a stronger generalization ability.
[0069] According to the encrypted traffic classification method proposed in the embodiment of the present application, firstly, based on the inherent traffic feature differences between different applications under the same business type, each business type is divided into multiple subclasses; then, based on the preset deep metric learning strategy, the difference features between the multiple subclasses corresponding to each business type are extracted, and the common features between the multiple subclasses are retained, so as to perform multi-center decoupling of the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; the traffic samples of the target unknown application are classified by the multi-center encrypted traffic classifier to obtain the classification results, and the distances from the traffic samples to the feature centers of each subclass corresponding to the target unknown application are compared, so as to identify the encrypted traffic type corresponding to the traffic samples of the unknown application based on the classification results and the distances. Thus, the existing encrypted traffic classification method solves the problem of poor accuracy in unknown application traffic classification due to the offset of the traffic features of the unknown application compared with the traffic features of the known application.
[0070] Secondly, the encrypted traffic classification device proposed according to the embodiment of the present application is described with reference to the accompanying drawings.
[0071] Figure 3 It is a block diagram of an encrypted traffic classification device according to an embodiment of the present application.
[0072] like Figure 3 As shown, the encrypted traffic classification device 10 includes: a classification module 100, a decoupling module 200 and an identification module 300.
[0073] The classification module 100 is used to classify each service type into multiple subclasses based on the inherent traffic characteristic differences between different applications under the same service type.
[0074] The decoupling module 200 is used to extract the differential features between multiple subclasses corresponding to each business type based on a preset deep metric learning strategy, and retain the common features between multiple subclasses, so as to perform multi-center decoupling on the feature space of each business type according to the differential features and common features, so as to construct a multi-center encrypted traffic classifier.
[0075] The identification module 300 is used to classify the traffic samples of the target unknown application through a multi-center encrypted traffic classifier, obtain the classification results, and compare the distances between the traffic samples and each subclass feature center corresponding to the target unknown application, so as to identify the encrypted traffic type corresponding to the traffic samples of the unknown application based on the classification results and the distances.
[0076] Optionally, in one embodiment of the present application, the classification module 100 includes: a subclass analysis unit and a classification unit.
[0077] The subclass analysis unit is used to perform a subclass analysis operation on each business type to obtain a subclass analysis result.
[0078] The classification unit is used to classify the traffic samples of each business type according to the subclass analysis results to generate multiple subclasses corresponding to each business type.
[0079] Optionally, in one embodiment of the present application, the decoupling module 200 includes: an extraction unit, a first acquisition unit and a construction unit.
[0080] The extraction unit is used to extract the message byte size, arrival time, and uplink and downlink transmission direction characteristics of each subclass in the multiple subclasses corresponding to each service type.
[0081] The first acquisition unit is used to optimize the loss function and the message byte size, arrival time, and uplink and downlink transmission direction characteristics of each subclass based on preset data characteristics, and obtain the difference characteristics and common characteristics of different subclasses under each service type.
[0082] The construction unit is used to perform multi-center decoupling on the feature space of each business type according to the difference characteristics and common characteristics, obtain the multi-center characteristics of the feature space of each business type, and construct a multi-center encrypted traffic classifier using the multi-center characteristics.
[0083] Optionally, in one embodiment of the present application, the identification module 300 includes: a second acquisition unit and a determination unit.
[0084] Among them, the second acquisition unit is used to obtain the message byte size, arrival time, and uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application.
[0085] A determination unit is used to compare the distance between the traffic sample of the target unknown application and each subclass feature center corresponding to the target unknown application based on the message byte size, arrival time, uplink and downlink transmission direction characteristics and a multi-center encrypted traffic classifier of the traffic sample of the target unknown application, so as to determine the encrypted traffic type of the traffic sample of the unknown application according to the distance.
[0086] Optionally, in one embodiment of the present application, the mathematical expression of the data feature optimization loss function is:
[0087]
[0088] Among them, D ij represents the distance between data sample i and data sample j; y ij Indicates whether data sample i and data sample j are of the same business type / subcategory, y ij =0 means that sample i and data sample j belong to different business types, y ij =1 means that sample i and data sample j belong to different subcategories under the same business type, y ij =2 means that sample i and data sample j belong to the same subclass under the same business type; a is the distance constraint between samples of the same subclass, b is the distance constraint between samples of different subclasses under the same business type, and m is the distance constraint between samples of different classes.
[0089] It should be noted that the aforementioned explanation of the embodiment of the encrypted traffic classification method is also applicable to the encrypted traffic classification device of this embodiment, and will not be repeated here.
[0090] According to the encrypted traffic classification device proposed in the embodiment of the present application, it includes a classification module, which is used to divide each business type into multiple subclasses based on the inherent traffic feature differences between different applications under the same business type; a decoupling module, which is used to extract the difference features between the multiple subclasses corresponding to each business type based on a preset deep metric learning strategy, and retain the common features between the multiple subclasses, so as to perform multi-center decoupling of the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; an identification module, which is used to classify the traffic samples of the target unknown application through the multi-center encrypted traffic classifier to obtain the classification result, and compare the distance from the traffic sample to the feature center of each subclass corresponding to the target unknown application, so as to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance, thereby realizing the real-time classification of the traffic sample through deep metric learning and clustering algorithm while ensuring the generalization of the traffic samples of the unknown application.
[0091] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:
[0092] Memory 401 , processor 402 , and a computer program stored in the memory 401 and executable on the processor 402 .
[0093] When the processor 402 executes the program, the encrypted traffic classification method provided in the above embodiment is implemented.
[0094] Furthermore, the electronic device further comprises:
[0095] The communication interface 403 is used for communication between the memory 401 and the processor 402 .
[0096] The memory 401 is used to store computer programs that can be executed on the processor 402 .
[0097] The memory 401 may include a high-speed RAM memory, and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
[0098] If the memory 401, the processor 402 and the communication interface 403 are implemented independently, the communication interface 403, the memory 401 and the processor 402 can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0099] Optionally, in a specific implementation, if the memory 401, the processor 402 and the communication interface 403 are integrated on a chip, the memory 401, the processor 402 and the communication interface 403 can communicate with each other through an internal interface.
[0100] The processor 402 may be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.
[0101] An embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the above-mentioned encrypted traffic classification method is implemented.
[0102] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0103] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0104] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or N executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.
[0105] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or N wirings (electronic devices), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically by optically scanning the paper or other medium and then editing, interpreting or processing in other suitable ways as necessary and then storing it in a computer memory.
[0106] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. If implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0107] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.
[0108] In addition, each functional unit in each embodiment of the present application may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0109] The storage medium mentioned above may be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. A method for classifying encrypted traffic, characterized in that: The following steps are involved: Based on the inherent traffic characteristics of different applications under the same business type, each business type is divided into multiple sub-categories; Based on a preset deep metric learning strategy, extract the difference features between the multiple subclasses corresponding to each business type, and retain the common features between the multiple subclasses, so as to perform multi-center decoupling on the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; The traffic sample of the target unknown application is classified by the multi-center encrypted traffic classifier to obtain a classification result, and the distance between the traffic sample and each subclass feature center corresponding to the target unknown application is compared to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance.
2. The encrypted traffic classification method according to claim 1, characterized in that: Based on the inherent traffic characteristic differences between different applications under the same business type, each business type is divided into multiple subcategories, including: Performing a subclass analysis operation on each of the business types to obtain a subclass analysis result; The traffic samples of each business type are classified according to the subclass analysis results to generate multiple subclasses corresponding to each business type.
3. The encrypted traffic classification method according to claim 2, characterized in that: The method based on the preset deep metric learning strategy extracts the difference features between the multiple subclasses corresponding to each business type, and retains the common features between the multiple subclasses, so as to perform multi-center decoupling on the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier, including: Extracting message byte size, arrival time, and uplink and downlink transmission direction characteristics of each subclass in the multiple subclasses corresponding to each service type; Based on the preset data feature optimization loss function and the message byte size, the arrival time, and the uplink and downlink transmission direction characteristics of each subclass, the difference characteristics and the common characteristics of different subclasses under each service type are obtained; The feature space of each business type is multi-center decoupled according to the differential features and the common features to obtain the multi-center features of the feature space of each business type, and the multi-center encrypted traffic classifier is constructed using the multi-center features.
4. The encrypted traffic classification method according to claim 3, characterized in that: The method of classifying the traffic sample of the target unknown application by the multi-center encrypted traffic classifier to obtain a classification result, and comparing the distance between the traffic sample and each subclass feature center corresponding to the target unknown application to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance, includes: Obtaining message byte size, arrival time, and uplink and downlink transmission direction characteristics of the traffic sample of the target unknown application; Based on the message byte size, the arrival time, the uplink and downlink transmission direction characteristics and the multi-center encrypted traffic classifier of the traffic sample of the target unknown application, compare the distance between the traffic sample of the target unknown application and the feature center of each subclass corresponding to the target unknown application to determine the encrypted traffic type of the traffic sample of the unknown application according to the distance.
5. The encrypted traffic classification method according to claim 3, characterized in that: The mathematical expression of the data feature optimization loss function is: Among them, D ij represents the distance between data sample i and data sample j; y ij Indicates whether the data sample i and the data sample j are of the same business type / subclass data, y ij =0 means that sample i and data sample j belong to different business types, y ij =1 means that sample i and data sample j belong to different subcategories under the same business type, y ij =2 means that sample i and data sample j belong to the same subclass under the same business type; a is the distance constraint between samples of the same subclass, b is the distance constraint between samples of different subclasses under the same business type, and m is the distance constraint between samples of different classes.
6. An encrypted traffic classification device, characterized in that: include: A classification module, used to classify each service type into multiple subclasses based on the inherent traffic characteristic differences between different applications under the same service type; A decoupling module, for extracting the difference features between the multiple subclasses corresponding to each business type based on a preset deep metric learning strategy, and retaining the common features between the multiple subclasses, so as to perform multi-center decoupling on the feature space of each business type according to the difference features and the common features, so as to construct a multi-center encrypted traffic classifier; An identification module is used to classify the traffic samples of the target unknown application through the multi-center encrypted traffic classifier to obtain a classification result, and compare the distance between the traffic sample and each subclass feature center corresponding to the target unknown application, so as to identify the encrypted traffic type corresponding to the traffic sample of the unknown application based on the classification result and the distance.
7. The encrypted traffic classification device according to claim 6, characterized in that: The classification module comprises: A subclass analysis unit, used to perform a subclass analysis operation on each of the business types to obtain a subclass analysis result; A classification unit is used to classify the traffic samples of each business type according to the subclass analysis result to generate multiple subclasses corresponding to each business type.
8. The encrypted traffic classification device according to claim 7, characterized in that: The decoupling module comprises: An extraction unit, used to extract the message byte size, arrival time, and uplink and downlink transmission direction characteristics of each subclass in the multiple subclasses corresponding to each service type; A first acquisition unit, configured to acquire the difference characteristics and the common characteristics of different subclasses under each service type based on a preset data feature optimization loss function and the message byte size, the arrival time, and the uplink and downlink transmission direction characteristics of each subclass; A construction unit is used to perform multi-center decoupling on the feature space of each business type according to the differential features and the common features, obtain the multi-center features of the feature space of each business type, and use the multi-center features to construct the multi-center encrypted traffic classifier.
9. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the encrypted traffic classification method as described in any one of claims 1 to 5.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the encrypted traffic classification method as described in any one of claims 1-5.