DoH encrypted domain name service traffic classification method and device

By performing dimensionality reduction processing and application of machine learning models on DoH encrypted domain name service traffic data, the problem of high computing resources consumption in the existing technology is solved, efficient traffic classification is achieved and security is improved.

CN119966910AActive Publication Date: 2025-05-09BEIJING UNIV OF POSTS & TELECOMM
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411831651.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-12
Publication Date
2025-05-09
Estimated Expiration
2044-12-12

AI Technical Summary

Technical Problem

The prior art consumes a lot of computing resources and takes a long time in the DoH encrypted domain name service traffic classification, making it difficult to effectively reduce computing resources consumption.

Method used

By reducing the dimensions of the target traffic feature data of DoH encrypted domain name service traffic data, using methods such as truncated singular value decomposition and information entropy calculation, traffic feature data after dimensionality reduction is generated, and input a preset machine learning model for classification.

Benefits of technology

It effectively reduces the computing resource consumption of DoH encrypted domain name service traffic classification process, improves detection efficiency, prevents data overfitting, and improves classification accuracy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966910A_ABST
    Figure CN119966910A_ABST
Patent Text Reader

Abstract

The invention provides a DoH encrypted domain name service traffic classification method and device, and the method comprises the steps: carrying out the dimension reduction processing of target traffic feature data corresponding to DoH encrypted domain name service traffic data, and obtaining the dimension-reduced traffic feature data corresponding to the target traffic feature data; and inputting the dimension-reduced traffic characteristic data into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model correspondingly outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data. According to the DoH encryption domain name service traffic classification method and device, the computing resource consumption in the DoH encryption domain name service traffic classification process can be effectively reduced, data overfitting can be prevented, the DoH encryption domain name service traffic classification efficiency can be effectively improved on the basis of ensuring the reliability and accuracy of the DoH encryption domain name service traffic classification result, and then the security of the DoH encryption domain name service can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of traffic classification, and in particular to a method and device for classifying DoH encrypted domain name service traffic. Background Art

[0002] DoH (DNS-over-HTTPS) refers to the use of the HTTPS protocol to perform DNS requests and implement DNS domain name resolution services. DoH encrypted domain name service traffic data refers to encrypted traffic data containing domain name information formed by encrypting the traffic generated by the DoH protocol through SSL or TLS. It is used to verify the identity of the domain name resolution service and protect the integrity of the data. The payload of the encrypted traffic data is in encrypted form and cannot be identified using conventional encrypted traffic detection methods such as deep packet inspection. Network attackers have repeatedly exploited the particularity of the DoH encrypted domain name service to carry out network damage or steal data by relying on security vulnerabilities.

[0003] Therefore, it is of great significance to distinguish the type of DoH encrypted domain name service traffic data from background traffic, whether it is non-DoH traffic, benign DoH traffic or malicious DoH traffic. Since DoH encrypted domain name service traffic data involves many feature dimensions, the conventional DoH encrypted domain name service traffic classification method will have a large computational burden and be time-consuming. Therefore, there is an urgent need to involve a method that can effectively reduce the computing resource consumption of the DoH encrypted domain name service traffic automatic classification process. Summary of the invention

[0004] In view of this, an embodiment of the present application provides a DoH encrypted domain name service traffic classification method and device to eliminate or improve one or more defects existing in the prior art.

[0005] One aspect of the present application provides a DoH encrypted domain name service traffic classification method, including:

[0006] Performing dimensionality reduction processing on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data to obtain dimensionality-reduced traffic feature data corresponding to the target traffic feature data;

[0007] The reduced-dimensionality traffic feature data is input into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

[0008] In some embodiments of the present application, the dimensionality reduction processing is performed on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data to obtain the dimensionality reduced traffic feature data corresponding to the target traffic feature data, including:

[0009] Based on the truncated singular value decomposition method, the target traffic feature data corresponding to the DoH encrypted domain name service traffic data is subjected to dimensionality reduction processing to obtain the reduced-dimensionality traffic feature data corresponding to the target traffic feature data.

[0010] In some embodiments of the present application, the dimensionality reduction processing is performed on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data based on the truncated singular value decomposition method to obtain the reduced-dimensional traffic feature data corresponding to the target traffic feature data, including:

[0011] The information entropy is calculated for the features of each dimension corresponding to the target traffic characteristic data, so as to obtain an information entropy matrix composed of the information entropy values ​​corresponding to the features of each dimension;

[0012] Sorting the information entropy values ​​in the information entropy matrix from large to small, and retaining the first preset number of the information entropy values ​​after sorting to obtain the corresponding optimized information entropy matrix, wherein the preset number is pre-determined based on the number and percentage threshold of the information entropy values ​​in the information entropy matrix;

[0013] And, performing singular value decomposition on the target flow characteristic data based on a truncated singular value decomposition method to obtain singular value decomposition result data of the target flow characteristic data;

[0014] The optimized information entropy matrix and the singular value decomposition result data are weighted and normalized to obtain a corresponding reduced-dimensionality flow characteristic matrix, so as to use the reduced-dimensionality flow characteristic matrix as the reduced-dimensionality flow characteristic data corresponding to the target flow characteristic data.

[0015] In some embodiments of the present application, the machine learning model includes: a classifier;

[0016] The classifier includes: XGBoost based on gradient boosting decision tree.

[0017] In some embodiments of the present application, the dimensionality reduction processing of the target traffic feature data corresponding to the DoH encrypted domain name service traffic data includes:

[0018] Perform feature extraction on the currently collected DoH encrypted domain name service traffic data to obtain traffic features corresponding to the DoH encrypted domain name service traffic data;

[0019] The traffic characteristics corresponding to the DoH encrypted domain name service traffic data are preprocessed to obtain target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data.

[0020] In some embodiments of the present application, the feature extraction of the currently collected DoH encrypted domain name service traffic data to obtain the traffic features corresponding to the DoH encrypted domain name service traffic data includes:

[0021] The Wireshark software is used to parse the currently collected DoH encrypted domain name service traffic data to extract the traffic characteristics corresponding to the DoH encrypted domain name service traffic data, wherein the traffic characteristics include: source IP, target IP, data length and transmission time.

[0022] In some embodiments of the present application, the preprocessing of the traffic characteristics corresponding to the DoH encrypted domain name service traffic data to obtain the target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data includes:

[0023] The traffic characteristics corresponding to the DoH encrypted domain name service traffic data are subjected to missing feature deletion and normalization processing to obtain the target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data.

[0024] Another aspect of the present application provides a DoH encrypted domain name service traffic classification device, including:

[0025] A feature dimension reduction module is used to perform dimension reduction processing on target traffic feature data corresponding to DoH encrypted domain name service traffic data to obtain reduced-dimensional traffic feature data corresponding to the target traffic feature data;

[0026] The traffic classification module is used to input the reduced-dimensional traffic feature data into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

[0027] The third aspect of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the DoH encrypted domain name service traffic classification method when executing the computer program.

[0028] The fourth aspect of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the DoH encrypted domain name service traffic classification method.

[0029] The fifth aspect of the present application provides a computer program product, including a computer program, which implements the DoH encrypted domain name service traffic classification method when executed by a processor.

[0030] The DoH encrypted domain name service traffic classification method provided in the present application performs dimensionality reduction processing on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data to obtain the reduced-dimensional traffic feature data corresponding to the target traffic feature data; the reduced-dimensional traffic feature data is input into a preset machine learning model for classifying the DoH encrypted domain name service traffic, so that the machine learning model outputs the traffic classification result data corresponding to the DoH encrypted domain name service traffic data, which can retain the part with more information in the traffic feature as the feature weight dimensionality reduction decomposition, reduce the influence of the eigenvalue of smaller information on parameter estimation, and effectively reduce the computing resource consumption of the DoH encrypted domain name service traffic classification process, while maintaining data integrity. The detection efficiency is greatly improved, on the one hand, saving the overall running calculation time of the model and improving efficiency, and on the other hand, preventing data overfitting and improving the accuracy of service classification, thereby effectively improving the efficiency of DoH encrypted domain name service traffic classification on the basis of ensuring the reliability and accuracy of the DoH encrypted domain name service traffic classification results, so as to improve the security of DoH encrypted domain name service.

[0031] Additional advantages, purposes, and features of the present application will be partially described in the following description, and will become partially apparent to those skilled in the art after studying the following, or may be learned from the practice of the present application. The purposes and other advantages of the present application can be achieved and obtained by the structures specifically pointed out in the specification and the drawings.

[0032] Those skilled in the art will understand that the purposes and advantages that can be achieved by the present application are not limited to the above specific description, and the above and other purposes that can be achieved by the present application will be more clearly understood based on the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings described herein are used to provide a further understanding of the present application, constitute a part of the present application, and do not constitute a limitation of the present application. The components in the drawings are not drawn to scale, but are only for the purpose of illustrating the principles of the present application. In order to facilitate the illustration and description of some parts of the present application, the corresponding parts in the drawings may be enlarged, that is, they may become larger relative to other components in the exemplary device actually manufactured according to the present application. In the drawings:

[0034] Figure 1 This is a first flow chart of a DoH encrypted domain name service traffic classification method in one embodiment of the present application.

[0035] Figure 2 This is a second flow chart of the DoH encrypted domain name service traffic classification method in one embodiment of the present application.

[0036] Figure 3This is a second flow chart of the DoH encrypted domain name service traffic classification method in one embodiment of the present application.

[0037] Figure 4 This is a structural diagram of a DoH encrypted domain name service traffic classification device in one embodiment of the present application. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the implementation modes and the accompanying drawings. Here, the illustrative implementation modes and descriptions of the present application are used to explain the present application, but are not intended to limit the present application.

[0039] It should also be noted here that in order to avoid obscuring the present application due to unnecessary details, only the structures and / or processing steps closely related to the scheme according to the present application are shown in the accompanying drawings, while other details that are not very relevant to the present application are omitted.

[0040] It should be emphasized that the term “include / comprises” when used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0041] It should also be noted that, unless otherwise specified, the term “connection” herein may refer not only to a direct connection but also to an indirect connection involving an intermediate.

[0042] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals represent the same or similar components, or the same or similar steps.

[0043] In order to solve the problems of high computational burden and long time consumption of conventional DoH encrypted domain name service traffic classification methods, the embodiments of the present application respectively provide a DoH encrypted domain name service traffic classification method, a DoH encrypted domain name service traffic classification device for executing the DoH encrypted domain name service traffic classification method, a physical device, a computer-readable storage medium and a computer program product, which can effectively reduce the computing resource consumption of the DoH encrypted domain name service traffic classification process and prevent data overfitting. On the basis of ensuring the reliability and accuracy of the DoH encrypted domain name service traffic classification results, it can effectively improve the efficiency of DoH encrypted domain name service traffic classification, thereby improving the security of DoH encrypted domain name service.

[0044] The details are described in detail through the following examples.

[0045] Based on this, the embodiment of the present application provides a DoH encrypted domain name service traffic classification method that can be implemented by a DoH encrypted domain name service traffic classification device, see Figure 1The DoH encrypted domain name service traffic classification method specifically includes the following contents:

[0046] Step 100: Perform dimensionality reduction processing on the target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data to obtain the reduced-dimensional traffic characteristic data corresponding to the target traffic characteristic data.

[0047] In one or more embodiments of the present application, DoH (DNS over HTTPS) runs DNS using a secure HTTPS protocol, the main purpose of which is to enhance user security and privacy. By using an encrypted HTTPS connection, third parties will no longer be able to influence or monitor the resolution process. Therefore, third parties will not be able to view the requested URL and change it. If DNS over HTTPS is used, the Transmission Control Protocol (TCP) in DoH will react faster when data is lost during transmission.

[0048] In one or more embodiments of the present application, DoH encrypted domain name service traffic data refers to encrypted traffic data containing domain name information formed by encrypting the traffic generated by the DoH protocol through SSL or TLS.

[0049] It is understandable that the target traffic characteristic data refers to data used to represent the traffic characteristics of DoH encrypted domain name service traffic data. The traffic characteristics include: source IP, target IP, data length and transmission time.

[0050] In one or more embodiments of the present application, the dimensionality reduction process may adopt at least one of dimensionality reduction methods such as PCA, LDA, and TSVD.

[0051] Among them, PCA (principal components analysis) is also known as principal component analysis technology, which aims to use the idea of ​​dimensionality reduction to transform multiple indicators into a few comprehensive indicators. The goal of PCA is to find r (r < n) new variables so that they reflect the main characteristics of things, compress the scale of the original data matrix, reduce the dimension of the feature vector, and select the least dimension to summarize the most important characteristics. Each new variable is a linear combination of the original variables, reflecting the comprehensive effect of the original variables and has certain practical meanings. These r new variables are called "principal components", which can reflect the influence of the original n variables to a large extent, and these new variables are unrelated and orthogonal. Through principal component analysis, the data space is compressed and the characteristics of multivariate data are intuitively represented in a low-dimensional space.

[0052] Among them, LDA is a linear discriminant analysis method and a supervised learning algorithm. LDA assumes that all types of sample data are Gaussian distributed, and the covariance matrix is ​​the same and full rank. Compared with PCA, LDA is a supervised dimensionality reduction algorithm, that is, the data is labeled (category label). TSVD refers to the truncated singular value decomposition method.

[0053] Step 200: Input the reduced-dimensional traffic feature data into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

[0054] In step 200, the machine learning model can be formed by pre-training a classifier using the reduced-dimensional traffic feature data corresponding to each historical DoH encrypted domain name service traffic data and the type label corresponding to each of the historical DoH encrypted domain name service traffic data, wherein the type label is used to indicate the type of the historical DoH encrypted domain name service traffic data, and the traffic classification result data is used to indicate the type of the DoH encrypted domain name service traffic data. It is understandable that the types include: non-DoH traffic, benign DoH traffic belonging to DoH traffic, and malicious DoH traffic belonging to DoH traffic.

[0055] From the above description, it can be seen that the DoH encrypted domain name service traffic classification method provided in the embodiment of the present application can retain the part with more information in the traffic characteristics as the feature weight dimensionality reduction decomposition, reduce the influence of the characteristic value of smaller information on parameter estimation, and can effectively reduce the computing resource consumption of the DoH encrypted domain name service traffic classification process. While maintaining data integrity, it greatly improves the detection efficiency. On the one hand, it saves the overall running calculation time of the model and improves efficiency. On the other hand, it prevents data overfitting and improves the accuracy of service classification. Therefore, on the basis of ensuring the reliability and accuracy of the DoH encrypted domain name service traffic classification results, it can effectively improve the efficiency of DoH encrypted domain name service traffic classification, so as to improve the security of DoH encrypted domain name service.

[0056] In order to further improve the effectiveness and reliability of dimensionality reduction processing of target traffic feature data corresponding to DoH encrypted domain name service traffic data, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, see Figure 2 , step 100 in the DoH encrypted domain name service traffic classification method specifically includes the following contents:

[0057] Step 110: Perform dimensionality reduction processing on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data based on the truncated singular value decomposition method to obtain the reduced-dimensional traffic feature data corresponding to the target traffic feature data.

[0058] Among them, Truncated singular value decomposition (TSVD) is a matrix factorization technique that decomposes the matrix M into three matrices U, ∑ and V. U is an m×m orthogonal matrix, called the left singular matrix; ∑ is an m×n diagonal matrix, and the elements on the diagonal are called singular values; V is an n×n orthogonal matrix, called the right singular matrix. TSVD is a variation of SVD, which only calculates the largest K singular values ​​specified by the user. TSVD is different from general SVD in that it can generate a decomposition matrix of a specified dimension. For example, there is a matrix that is still a matrix after SVD decomposition, while TSVD can generate a matrix of a specified dimension, so that dimensionality reduction can be achieved.

[0059] In order to optimize the truncated singular value decomposition process to further improve the effectiveness and reliability of dimensionality reduction processing of target traffic feature data corresponding to DoH encrypted domain name service traffic data, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, see Figure 3 , step 110 in the DoH encrypted domain name service traffic classification method specifically includes the following content:

[0060] Step 111: performing information entropy calculations on the features of each dimension corresponding to the target traffic feature data, respectively, to obtain an information entropy matrix composed of information entropy values ​​corresponding to the features of each dimension;

[0061] Step 112: Sort the information entropy values ​​in the information entropy matrix from large to small, and retain the first preset number of the information entropy values ​​after sorting to obtain the corresponding optimized information entropy matrix, wherein the preset number is pre-determined based on the number and percentage threshold of each information entropy value in the information entropy matrix.

[0062] It is understandable that the percentage threshold can be set according to actual application requirements. In one example, it can be set to 80%.

[0063] And, step 113: performing singular value decomposition on the target flow characteristic data based on a truncated singular value decomposition method to obtain singular value decomposition result data of the target flow characteristic data.

[0064] Step 114: weighting and normalizing the optimized information entropy matrix and the singular value decomposition result data to obtain a corresponding reduced-dimensionality flow characteristic matrix, and using the reduced-dimensionality flow characteristic matrix as the reduced-dimensionality flow characteristic data corresponding to the target flow characteristic data.

[0065] In order to further improve the accuracy and effectiveness of DoH encrypted domain name service traffic classification, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, the machine learning model can use a classifier, and in particular, the gradient boosting decision tree XGBoost can be selected as a classifier. Then, the reduced-dimensional traffic feature data is input into XGBoost, so that it outputs the traffic labeling result, and the classification of non-DoH traffic, benign DoH traffic and malicious DoH traffic is realized.

[0066] In order to further improve the application effectiveness and reliability of the target traffic feature data corresponding to the DoH encrypted domain name service traffic data, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, see Figure 2 , the DoH encrypted domain name service traffic classification method further specifically includes the following contents before step 100:

[0067] Step 010: extracting features of the currently collected DoH encrypted domain name service traffic data to obtain traffic features corresponding to the DoH encrypted domain name service traffic data;

[0068] Step 020: Preprocess the traffic characteristics corresponding to the DoH encrypted domain name service traffic data to obtain target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data.

[0069] In order to further improve the accuracy and reliability of feature extraction of DoH encrypted domain name service traffic data, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, see Figure 3 , step 010 in the DoH encrypted domain name service traffic classification method specifically includes the following contents:

[0070] Step 011: Use Wireshark software to parse the currently collected DoH encrypted domain name service traffic data to extract the traffic characteristics corresponding to the DoH encrypted domain name service traffic data, where the traffic characteristics include: source IP, target IP, data length and transmission time.

[0071] Specifically, Wireshark is a network packet analysis software. The function of network packet analysis software is to intercept network packets and display the most detailed network packet information as possible. Wireshark uses the network access system WinPCAP (windows packet capture) as an interface to directly exchange data packets with the network card.

[0072] Wireshark is not an Intrusion Detection System (IDS). Wireshark will not generate any alerts or any prompts for abnormal traffic behavior on the network. However, careful analysis of the packets intercepted by Wireshark can help users have a clearer understanding of network behavior. Wireshark will not modify the content of network packets, it only reflects the circulating packet information.

[0073] In addition, PCAPNG (PCAP Next Generation Dump File Format) refers to the next generation file format of the process characteristic analysis software package PCAP, with the suffix ".pcapng".

[0074] Based on this, in one example, before extracting traffic features, it is necessary to set up the environment to capture and parse traffic packets using the pyshark library (a Python library for network packet capture and analysis). First, you need to install Wireshark and ensure that the tshark (i.e., the command line version of Wireshark) command line tool is available. Then, set the path of tshark in the code and create a directory for saving downloaded files. The core function is analyze_pcap, which uses the pyshark library to parse a given PCAP file and extract packets of TCP, UDP, and ICMP protocols. It can capture information such as the source IP, destination IP, packet length, transmission time, source port, and destination port in the traffic packet as the traffic feature of the packet, and identify DNS queries and TLS handshake data.

[0075] In order to further improve the accuracy and reliability of preprocessing the traffic characteristics corresponding to the DoH encrypted domain name service traffic data, in a DoH encrypted domain name service traffic classification method provided in an embodiment of the present application, see Figure 3 , step 020 in the DoH encrypted domain name service traffic classification method specifically includes the following contents:

[0076] Step 021: Delete missing features and normalize the traffic features corresponding to the DoH encrypted domain name service traffic data to obtain target traffic feature data corresponding to the DoH encrypted domain name service traffic data.

[0077] Specifically, normalization can be performed using linear function normalization (Min-Max Scaling), zero mean normalization (Z-Score Normalization), and Max-Min normalization (also known as deviation normalization).

[0078] Specifically, linear function normalization (Min-Max Scaling) maps the data to the range of [0,1] by performing a linear transformation on the original data. This method is suitable for situations where the values ​​are relatively concentrated, but if the maximum and minimum values ​​are unstable, the normalization result will also be unstable12. Zero mean normalization (Z-Score Normalization) maps the original data to a distribution with a mean of 0 and a standard deviation of 1. Max-Min normalization maps the eigenvalues ​​to between [0,1].

[0079] To further illustrate the above embodiments, the present application also provides an application example of a DoH encrypted domain name service traffic classification method, which relates to the field of malicious classification and detection technology. In view of the problems of multiple feature dimensions and high computational burden in the general DoH encrypted domain name service traffic classification method, the present application improves the TSVD (Truncated Singular Value Decomposition) singular value decomposition dimensionality reduction method by analyzing the information entropy characteristics of the traffic, retaining the part with more information in the traffic characteristics as the feature weight dimensionality reduction decomposition, reducing the influence of the eigenvalues ​​of smaller information on parameter valuation, generating a matrix of specified dimensions, and finally obtaining the reduced dimensionality data features carrying feature importance information, which greatly improves the detection efficiency while maintaining data integrity. On the one hand, it saves the overall running calculation time of the model and improves efficiency, and on the other hand, it prevents data overfitting and improves service classification accuracy.

[0080] Based on this, the DoH encrypted domain name service traffic classification method provided by the application example of this application specifically includes the following contents:

[0081] S1: Obtain DoH encrypted domain name service traffic data and extract traffic characteristics.

[0082] Specifically, the original traffic data packet files are collected from the deployed device environment, and the pcapng files in the data packets are parsed using tools such as the command line version of Wireshark and the Linux command line to extract traffic features, where the traffic features include source IP, destination IP, data packet length, transmission time, etc. The traffic features are formally expressed as F = {f1, f2, ..., fT}, t = 1, 2, ..., T, where T is the total number of features and T is greater than 3.

[0083] S2: Preprocess the traffic characteristics, perform missing data processing and feature normalization processing, and obtain target traffic characteristic data.

[0084] Specifically, the data sets with missing features in each data set corresponding to the traffic feature are deleted to obtain a new data set corresponding to the traffic feature, and each set of features in the new data set is normalized.

[0085] S3: Perform TSVD truncated singular value decomposition operation on the preprocessed target traffic feature data, combine feature importance with TSVD calculation formula to achieve feature dimensionality reduction processing, and obtain traffic feature data after dimensionality reduction.

[0086] Specifically, the TSVD decomposition method is improved by combining the feature importance index to achieve the dimensionality reduction of traffic features, which includes:

[0087] First, the importance of the target traffic feature data Fz is calculated according to the size of the information entropy value, and the information entropy of each dimensional feature in the target traffic feature data Fz is calculated. The information entropy value of the i-th dimensional feature Fi is:

[0088]

[0089] n is the number of observations, and Fij is the j-th dimension value of the i-th dimension feature Fi.

[0090] Secondly, the target traffic feature data Fz is subjected to singular value decomposition. Given the traffic feature matrix Fz of m×n dimensions, the SVD formula of the matrix Z is defined as Z=CKV T , where C∈R m×m ,K∈R m×n , except for the elements on the main diagonal, all other parts are 0, and the elements on the main diagonal are singular values:

[0091] C T C=CC T =I m ,V T V=VV T =I n

[0092] Let Y = Z T Z, Y∈R n×n After eigendecomposition, we get n eigenvalues ​​and the corresponding eigenvector v, which satisfies the formula Yv i =λ i v i .

[0093] Let X = ZZ T , X∈R m×m , we get m eigenvalues ​​and the corresponding eigenvector u, satisfying (ZZ T ) i =λ i u i .

[0094] Finally, TSVD is improved by combining the feature importance index, retaining the feature dimensions ranked in the top 80% of the information entropy values ​​in the information entropy matrix to obtain the corresponding optimized information entropy matrix. The optimized information entropy matrix is ​​weighted and normalized with the singular value decomposition result to obtain the reduced-dimensional traffic feature matrix X carrying feature importance information:

[0095]

[0096] Where p = 80%, N is the total number of samples, the updated feature dataset is E1, and the dimension of E1 is u×v.

[0097] S4: Input the reduced-dimensional traffic feature matrix X corresponding to the DoH encrypted domain name service traffic data into the classifier, so that the classifier outputs the traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

[0098] Specifically, the marked traffic data features after dimensionality reduction optimization are input into the general machine learning classifier xgboost, and the traffic labeling results are output to achieve the classification of non-DoH traffic, DoH traffic, benign DoH traffic and malicious DoH traffic.

[0099] That is to say, the application example of this application provides doh flow detection based on machine learning, and adds feature dimensionality reduction in the middle of doh detection based on machine learning, and this application example is refined through a specific calculation method during the dimensionality reduction process. Compared with the existing dimensionality reduction method, it does not take into account the importance of the given features in advance and the large amount of calculation in the dimensionality reduction process, and it is very likely that the optimal representation features are left and the optimal identification features are lost. In this application example, the optimal discriminant features (features with large information entropy) can be predetermined in advance according to information entropy.

[0100] From the software level, the present application also provides a DoH encrypted domain name service traffic classification device for executing all or part of the DoH encrypted domain name service traffic classification method, see Figure 4 The DoH encrypted domain name service traffic classification device specifically includes the following contents:

[0101] The feature dimension reduction module 10 is used to perform dimension reduction processing on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data to obtain the reduced-dimensional traffic feature data corresponding to the target traffic feature data;

[0102] The traffic classification module 20 is used to input the reduced-dimensional traffic feature data into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

[0103] The embodiment of the DoH encrypted domain name service traffic classification device provided in the present application can be specifically used to execute the processing flow of the embodiment of the DoH encrypted domain name service traffic classification method in the above-mentioned embodiment. Its functions will not be repeated here, and reference can be made to the detailed description of the above-mentioned DoH encrypted domain name service traffic classification method embodiment.

[0104] The part of the DoH encrypted domain name service traffic classification device that performs DoH encrypted domain name service traffic classification can be completed in the server or in the client device. The specific selection can be based on the processing capability of the client device and the limitations of the user's usage scenario. This application is not limited to this. If all operations are completed in the client device, the client device may also include a processor for specific processing of DoH encrypted domain name service traffic classification.

[0105] The client device may have a communication module (i.e., a communication unit) that can communicate with a remote server to achieve data transmission with the server. The server may include a server on the task scheduling center side, and other implementation scenarios may also include a server on an intermediate platform, such as a server on a third-party server platform that has a communication link with the task scheduling center server. The server may include a single computer device, or a server cluster consisting of multiple servers, or a server structure of a distributed device.

[0106] The server and the client device may communicate with each other using any suitable network protocol, including network protocols that have not yet been developed on the date of filing this application. The network protocols may include, for example, TCP / IP, UDP / IP, HTTP, HTTPS, etc. Of course, the network protocols may also include, for example, RPC (Remote Procedure Call Protocol) and REST (Representational State Transfer) protocols used on top of the above protocols.

[0107] From the above description, it can be seen that the DoH encrypted domain name service traffic classification device provided in the embodiment of the present application can retain the part with more information in the traffic characteristics as the feature weight dimensionality reduction decomposition, reduce the influence of the characteristic value of smaller information on parameter estimation, and can effectively reduce the computing resource consumption of the DoH encrypted domain name service traffic classification process. While maintaining data integrity, it greatly improves the detection efficiency. On the one hand, it saves the overall running calculation time of the model and improves efficiency. On the other hand, it prevents data overfitting and improves the accuracy of service classification. Therefore, on the basis of ensuring the reliability and accuracy of the DoH encrypted domain name service traffic classification results, it can effectively improve the efficiency of DoH encrypted domain name service traffic classification, so as to improve the security of DoH encrypted domain name service.

[0108] The embodiment of the present application also provides an electronic device, which may include a processor, a memory, a receiver and a transmitter, wherein the processor is used to execute the DoH encrypted domain name service traffic classification method mentioned in the above embodiment, wherein the processor and the memory may be connected via a bus or other means, such as by bus connection. The receiver may be connected to the processor and the memory via wired or wireless means.

[0109] The processor may be a central processing unit (CPU). The processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the above chips.

[0110] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as the program instructions / modules corresponding to the DoH encrypted domain name service traffic classification method in the embodiment of the present application. The processor executes various functional applications and data processing of the processor by running the non-transitory software programs, instructions and modules stored in the memory, that is, implementing the DoH encrypted domain name service traffic classification method in the above method embodiment.

[0111] The memory may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created by the processor, etc. In addition, the memory may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0112] The one or more modules are stored in the memory, and when executed by the processor, perform the DoH encrypted domain name service traffic classification method in the embodiment.

[0113] In some embodiments of the present application, the user equipment may include a processor, a memory, and a transceiver unit, which may include a receiver and a transmitter. The processor, memory, receiver, and transmitter may be connected through a bus system. The memory is used to store computer instructions, and the processor is used to execute the computer instructions stored in the memory to control the transceiver unit to send and receive signals.

[0114] As an implementation method, the functions of the receiver and the transmitter in the present application can be considered to be implemented through a transceiver circuit or a dedicated chip for transceiver, and the processor can be considered to be implemented through a dedicated processing chip, a processing circuit or a general chip.

[0115] As another implementation method, it is possible to use a general-purpose computer to implement the server provided in the embodiment of the present application, that is, to store the program code for implementing the functions of the processor, receiver, and transmitter in a memory, and the general-purpose processor implements the functions of the processor, receiver, and transmitter by executing the code in the memory.

[0116] The embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the aforementioned DoH encrypted domain name service traffic classification method are implemented. The computer-readable storage medium can be a tangible storage medium, such as a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a floppy disk, a hard disk, a removable storage disk, a CD-ROM, or any other form of storage medium known in the technical field.

[0117] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the aforementioned DoH encrypted domain name service traffic classification method.

[0118] It should be understood by those skilled in the art that the exemplary components, systems and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software or a combination of the two. Whether it is specifically performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier.

[0119] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.

[0120] In the present application, features described and / or illustrated for one embodiment may be used in the same manner or in a similar manner in one or more other embodiments, and / or combined with features of other embodiments or replace features of other embodiments.

[0121] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the embodiments of the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A DoH encrypted domain name service traffic classification method, characterized in that: include: Performing dimensionality reduction processing on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data to obtain dimensionality-reduced traffic feature data corresponding to the target traffic feature data; The reduced-dimensionality traffic feature data is input into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

2. The DoH encrypted domain name service traffic classification method according to claim 1 is characterized in that: The dimensionality reduction processing is performed on the target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data to obtain the dimensionality reduced traffic characteristic data corresponding to the target traffic characteristic data, including: Based on the truncated singular value decomposition method, the target traffic feature data corresponding to the DoH encrypted domain name service traffic data is subjected to dimensionality reduction processing to obtain the reduced-dimensionality traffic feature data corresponding to the target traffic feature data.

3. The DoH encrypted domain name service traffic classification method according to claim 2 is characterized in that: The dimensionality reduction processing is performed on the target traffic feature data corresponding to the DoH encrypted domain name service traffic data based on the truncated singular value decomposition method to obtain the reduced-dimensional traffic feature data corresponding to the target traffic feature data, including: The information entropy is calculated for the features of each dimension corresponding to the target traffic characteristic data, so as to obtain an information entropy matrix composed of the information entropy values ​​corresponding to the features of each dimension; Sorting the information entropy values ​​in the information entropy matrix from large to small, and retaining the first preset number of the information entropy values ​​after sorting to obtain the corresponding optimized information entropy matrix, wherein the preset number is pre-determined based on the number and percentage threshold of the information entropy values ​​in the information entropy matrix; And, performing singular value decomposition on the target flow characteristic data based on a truncated singular value decomposition method to obtain singular value decomposition result data of the target flow characteristic data; The optimized information entropy matrix and the singular value decomposition result data are weighted and normalized to obtain a corresponding reduced-dimensionality flow characteristic matrix, so as to use the reduced-dimensionality flow characteristic matrix as the reduced-dimensionality flow characteristic data corresponding to the target flow characteristic data.

4. The DoH encrypted domain name service traffic classification method according to claim 1, characterized in that: The machine learning model includes: a classifier; The classifier includes: XGBoost based on gradient boosting decision tree.

5. The DoH encrypted domain name service traffic classification method according to claim 1, characterized in that: The dimensionality reduction processing of the target traffic feature data corresponding to the DoH encrypted domain name service traffic data includes: Perform feature extraction on the currently collected DoH encrypted domain name service traffic data to obtain traffic features corresponding to the DoH encrypted domain name service traffic data; The traffic characteristics corresponding to the DoH encrypted domain name service traffic data are preprocessed to obtain target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data.

6. The DoH encrypted domain name service traffic classification method according to claim 5, characterized in that: The feature extraction of the currently collected DoH encrypted domain name service traffic data to obtain traffic features corresponding to the DoH encrypted domain name service traffic data includes: The Wireshark software is used to parse the currently collected DoH encrypted domain name service traffic data to extract the traffic characteristics corresponding to the DoH encrypted domain name service traffic data, wherein the traffic characteristics include: source IP, target IP, data length and transmission time.

7. The DoH encrypted domain name service traffic classification method according to claim 5, characterized in that: The preprocessing of the traffic characteristics corresponding to the DoH encrypted domain name service traffic data to obtain target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data includes: The traffic characteristics corresponding to the DoH encrypted domain name service traffic data are subjected to missing feature deletion and normalization processing to obtain the target traffic characteristic data corresponding to the DoH encrypted domain name service traffic data.

8. A DoH encrypted domain name service traffic classification device, characterized in that: include: A feature dimension reduction module is used to perform dimension reduction processing on target traffic feature data corresponding to DoH encrypted domain name service traffic data to obtain reduced-dimensional traffic feature data corresponding to the target traffic feature data; The traffic classification module is used to input the reduced-dimensional traffic feature data into a preset machine learning model for classifying DoH encrypted domain name service traffic, so that the machine learning model outputs traffic classification result data corresponding to the DoH encrypted domain name service traffic data.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the DoH encrypted domain name service traffic classification method as described in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the DoH encrypted domain name service traffic classification method as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Ultra-high-dimensional data dimension reduction algorithm based on information entropy

    CN106407363A

  • Service type identification method based on fusion of PCA and XGBoost

    CN114048795A

  • Feature weighted fuzzy clustering method and system based on information entropy

    CN115828125A

  • Encrypted traffic classification method based on machine learning

    CN116405405A

  • Method for selecting clustering feature using entropyweight and singular value decomposition

    KR1020030017121A