Encrypted malicious traffic classification method and device based on byte frequency domain information

Through the encrypted malicious traffic classification method based on byte frequency domain information, the traffic classification model of one-dimensional CNN and important byte frequency domain information screening is solved in the existing technology, and the efficient identification and fine classification of encrypted malicious traffic are realized.

CN120017348AActive Publication Date: 2025-05-16NAT UNIV OF DEFENSE TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510147046.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-16
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

The prior art has problems such as leakage of private information, high computing cost and low recognition accuracy when identifying encrypted malicious traffic, which is difficult to meet the needs of network protection.

Method used

The encrypted malicious traffic classification method based on byte frequency domain information is adopted, and the traffic classification model filtered by one-dimensional CNN and important byte frequency domain information is used to realize the real-time identification and classification of encrypted malicious traffic in the original traffic data.

Benefits of technology

It improves the processing efficiency and classification accuracy of encrypted malicious traffic identification, and realizes the refined classification of encrypted malicious traffic and the fast real-time identification of unknown malicious traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017348A_ABST
    Figure CN120017348A_ABST
Patent Text Reader

Abstract

The invention discloses an encrypted malicious traffic classification method and device based on byte frequency domain information. The method comprises the following steps: acquiring first data; preprocessing the first data to obtain second data; performing extraction processing on the second data to obtain a second data feature information set; and processing the second data feature information set by using a traffic data classification model to obtain traffic data classification information. According to the method, real-time identification and classification of the encrypted malicious traffic in the original traffic data are realized based on important byte frequency domain information screening by utilizing the traffic data classification model, and the identification processing efficiency and classification accuracy of the encrypted malicious traffic are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security, and in particular to a method and device for identifying and classifying encrypted malicious traffic of a small sample. Background Art

[0002] Methods based on communication content review, such as Deep Packet Inspection (DPI) technology, cannot directly parse the information in the encrypted payload, so it is difficult to identify malicious content and behavior. Data packets can be decrypted by pre-importing user encryption certificates, but this method consumes a lot of computing resources and time costs, which is an unbearable burden for high-throughput network nodes. In addition, the decryption process will also lead to the leakage of private information, which goes against the original intention of adopting encryption protocols.

[0003] Although signature-based identification methods can try to use plaintext information in each layer of the protocol to generate encrypted malicious traffic signatures, this method is much more difficult and requires network analysis experts to invest more time and energy to design targeted features to adapt to the ever-changing attack patterns. In addition, attackers often use obfuscation and camouflage techniques to adjust the characteristics of encrypted malicious traffic to bypass signature-based identification mechanisms.

[0004] Anomaly-based identification methods rely on modeling of normal traffic. Commonly used models include machine learning models and deep learning models. Encrypted malicious traffic identification methods based on machine learning are highly dependent on feature engineering and lack a systematic feature design method. Deep learning-based identification methods can automatically extract features from raw traffic data and show strong versatility. However, existing research lacks targeted design for encrypted traffic, which affects the accuracy of encrypted malicious traffic identification. In addition, deep learning models usually have high requirements for computing resources and are difficult to meet real-time requirements in high-bandwidth and high-throughput network environments.

[0005] Therefore, traditional methods have shortcomings in identifying encrypted malicious traffic, such as privacy information leakage, high computational cost, and low recognition accuracy, which makes it difficult to meet network protection needs. This method focuses on maintaining a high recognition accuracy of encrypted malicious traffic while achieving refined classification of encrypted malicious traffic and rapid real-time recognition of unknown malicious traffic through encrypted malicious traffic recognition technology based on deep feature learning. By designing a lightweight deep learning model, it promotes intelligent identification of encrypted malicious traffic and proposes a solution to the increasingly complex network threats and network security maintenance. Summary of the invention

[0006] The technical problem to be solved by the present invention is to provide a method and device for classifying encrypted malicious traffic based on byte frequency domain information, which utilizes a traffic data classification model to realize real-time identification and classification of encrypted malicious traffic in original traffic data based on screening of important byte frequency domain information, thereby improving the efficiency of encrypted malicious traffic identification and processing and the accuracy of classification.

[0007] In order to solve the above technical problems, the first aspect of the embodiment of the present invention discloses a method for classifying encrypted malicious traffic based on byte frequency domain information, the method comprising:

[0008] S1, obtaining first data;

[0009] S2, preprocessing the first data to obtain second data;

[0010] S3, extracting and processing the second data to obtain a second data feature information set;

[0011] S4: Process the second data feature information set using a traffic data classification model to obtain traffic data classification information.

[0012] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the preprocessing of the first data to obtain the important byte data includes:

[0013] S21, encoding the first data to obtain a data packet byte data set;

[0014] The data packet byte data set includes a plurality of data packet byte data;

[0015] S22, processing the data packet byte data set based on the error assessment model to obtain a first byte parameter information set;

[0016] The first byte parameter information set includes a plurality of first byte parameter information;

[0017] S23, performing difference processing on the first byte parameter information set to obtain a second byte parameter information set;

[0018] The second byte parameter information set includes a plurality of second byte parameter information;

[0019] S24, sorting the byte data of the data packet according to the size order of the second byte parameter information to obtain a data packet byte sorting data set;

[0020] The data packet byte sorting data set includes a plurality of data packet byte sorting data;

[0021] S25, based on the second byte parameter information, filter and process all the byte sorting data of the data packet to obtain second data.

[0022] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the expression of the error evaluation model is:

[0023]

[0024] Where i represents the index of the byte data of the data packet; i Represents the classification prediction error rate of the byte data of the i-th data packet; FP i Indicates the number of samples misclassified as normal; FN i Indicates the number of samples misclassified as malicious; TP i Indicates the number of samples correctly classified as normal; TN i Represents the number of samples correctly classified as malicious;

[0025] The difference processing expression is:

[0026] ER i '=ER i -ER;

[0027] Among them, ER i ' represents the importance parameter of the byte data of the i-th data packet; ER represents the classification prediction error rate benchmark value.

[0028] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the extracting and processing the second data to obtain the second data feature information set includes:

[0029] S31, performing concatenation processing on the second data to obtain an important byte sequence set;

[0030] The important byte sequence set includes several important byte sequences;

[0031] S32, transforming any of the important byte sequences to obtain second data feature information;

[0032] The transformation processing expression is:

[0033]

[0034] Where Q[K] represents the characteristic information of the kth important byte data; x n represents the second data; N represents the size of the second data; j is an imaginary unit; k represents the index of the important byte data;

[0035] S33, all the second data feature information are combined in order to obtain a second data feature information set;

[0036] The second data feature information set includes a plurality of second data feature information.

[0037] As an optional implementation, in the first aspect of the embodiment of the present invention, the traffic data classification model includes: a packet-level benchmark characterization module, an inter-packet feature extraction module and a data classification module;

[0038] The packet-level benchmark characterization module is used to process the second data feature information set to obtain a first feature information set;

[0039] The inter-packet feature extraction module is used to perform convolution processing on the first feature information set to obtain a second feature information set;

[0040] The data classification module is used to perform splicing and identification processing on the second feature information set to obtain flow data classification information;

[0041] The packet-level benchmark characterization module, the inter-packet feature extraction module and the data classification module are sequentially data-connected.

[0042] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the using of the traffic data classification model to process the second data feature information set to obtain the traffic data classification information includes:

[0043] S41, using the packet-level benchmark characterization module, processing the second data feature information set to obtain a first feature information set;

[0044] S42, using the inter-packet feature extraction module to process the first feature information set to obtain a second feature information set;

[0045] S43: Utilize the data classification module to process the second feature information set to obtain flow data classification information.

[0046] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the using of the packet-level benchmark characterization module to process the second data feature information set to obtain the first feature information set includes:

[0047] S4101, performing a first convolution process on the second data feature information set to obtain frequency domain feature information within a first packet;

[0048] Performing a second convolution process on the second data feature information set to obtain frequency domain feature information within a second packet;

[0049] S4102, performing a first function processing on the frequency domain feature information in the first packet to obtain frequency domain feature information in a third packet;

[0050] Performing a first function processing on the frequency domain feature information in the second packet to obtain frequency domain feature information in a fourth packet;

[0051] S4103, performing a second function processing on the frequency domain feature information in the third packet to obtain frequency domain feature information in a fifth packet;

[0052] Performing a second function processing on the frequency domain feature information in the fourth packet to obtain frequency domain feature information in a sixth packet;

[0053] S4104, performing a first pooling process on the frequency domain feature information in the fifth packet to obtain frequency domain feature information in a seventh packet;

[0054] Performing a second pooling process on the frequency domain feature information in the sixth packet to obtain frequency domain feature information in an eighth packet;

[0055] S4105, performing a third convolution process on the frequency domain feature information in the seventh packet to obtain frequency domain feature information in a ninth packet;

[0056] Performing a fourth convolution process on the frequency domain feature information in the eighth packet to obtain frequency domain feature information in a tenth packet;

[0057] S4106, performing a third function processing on the frequency domain feature information in the ninth packet to obtain frequency domain feature information in the eleventh packet;

[0058] Performing a third function processing on the frequency domain feature information in the tenth packet to obtain frequency domain feature information in the twelfth packet;

[0059] S4107, performing a fourth function processing on the frequency domain feature information in the eleven packets to obtain frequency domain feature information in the thirteenth packet;

[0060] Performing a fourth function processing on the frequency domain feature information in the twelfth packet to obtain frequency domain feature information in the fourteenth packet;

[0061] S4108, performing a third pooling process on the frequency domain feature information in the thirteenth packet to obtain frequency domain feature information in the fifteenth packet;

[0062] Performing a fourth pooling process on the frequency domain feature information in the fourteenth packet to obtain frequency domain feature information in the sixteenth packet;

[0063] S4109, concatenating and flattening the frequency domain feature information in the fifteenth packet and the frequency domain feature information in the sixteenth packet to obtain frequency domain feature information in the seventeenth packet;

[0064] S4110, performing a first linear processing on the frequency domain feature information in the seventeenth packet to obtain frequency domain feature information in the eighteenth packet;

[0065] S4111, generalize the frequency domain feature information in the eighteenth packet to obtain frequency domain feature information in the nineteenth packet;

[0066] S4112, performing a second linear processing on the frequency domain feature information in the nineteenth packet to obtain frequency domain feature information in the twentieth packet;

[0067] S4113, performing a fifth function processing on the frequency domain feature information in the 20th packet to obtain a first feature information set.

[0068] A second aspect of an embodiment of the present invention discloses an encrypted malicious traffic classification device based on byte frequency domain information, the device comprising:

[0069] A data acquisition module, a first processing module, a second processing module and a third processing module;

[0070] The data acquisition module is used to acquire first data;

[0071] The first processing module is used to pre-process the first data to obtain second data;

[0072] The second processing module is used to extract and process the second data to obtain a second data feature information set;

[0073] The third processing module is used to process the second data feature information set using a flow data classification model to obtain flow data classification information.

[0074] A third aspect of an embodiment of the present invention discloses another encrypted malicious traffic classification device based on byte frequency domain information, the device comprising:

[0075] A memory storing executable program code;

[0076] a processor coupled to the memory;

[0077] The processor calls the executable program code stored in the memory to execute part or all of the steps in the encrypted malicious traffic classification method based on byte frequency domain information disclosed in the first aspect of the embodiment of the present invention.

[0078] The fourth aspect of the present invention discloses a computer-readable storage medium, which stores computer instructions. When the computer instructions are called, some or all of the steps in the encrypted malicious traffic classification method based on byte frequency domain information disclosed in the first aspect of the embodiment of the present invention are executed.

[0079] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0080] The present invention utilizes a traffic classification model based on one-dimensional CNN and important byte frequency domain information screening, and realizes real-time identification and classification of encrypted malicious traffic in original traffic data based on important byte frequency domain information screening, thereby improving the encrypted malicious traffic identification processing efficiency and classification accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0082] Figure 1 is a schematic diagram of a scenario of a network security monitoring system provided by an embodiment of the present invention;

[0083] Figure 2 It is a flowchart of a method for classifying encrypted malicious traffic based on byte frequency domain information disclosed in an embodiment of the present invention;

[0084] Figure 3 It is a structural schematic diagram of an encrypted malicious traffic classification device based on byte frequency domain information disclosed in an embodiment of the present invention;

[0085] Figure 4 It is a structural schematic diagram of another encrypted malicious traffic classification device based on byte frequency domain information disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0086] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0087] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, device, product or equipment that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or equipment.

[0088] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0089] In this application, the word "exemplary" is used to mean "used as an example, illustration, or description." Any embodiment described in this application as "exemplary" is not necessarily to be construed as being preferred or advantageous over other embodiments. The following description is given to enable any technician in the field to implement and use the present application. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present application can be implemented without using these specific details. In other instances, well-known structures and processes will not be elaborated in detail to avoid obscuring the description of the present application with unnecessary details. Therefore, the present application is not intended to be limited to the embodiments shown, but is consistent with the widest scope consistent with the principles and features disclosed in the present application.

[0090] It should be noted that since the method of the embodiment of the present application is executed in a computer device, the processing objects of each computer device exist in the form of data or information. For example, time is actually time information. It can be understood that if size, quantity, position, etc. are mentioned in subsequent embodiments, they are all corresponding data for processing by the computer device. The details will not be repeated here.

[0091] It should be noted that the artificial intelligence related technologies that may be involved in this application are briefly described. Artificial Intelligence (AI) is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results. In other words, artificial intelligence is a comprehensive technology in computer science that attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a similar way to human intelligence. Artificial intelligence is to study the design principles and implementation methods of various intelligent machines so that machines have the functions of perception, reasoning and decision-making.

[0092] Artificial intelligence technology is a comprehensive discipline that covers a wide range of fields, including both hardware-level and software-level technologies. The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, mechatronics and other technologies. Artificial intelligence software technology mainly includes computer vision technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0093] Computer Vision (CV) is a science that studies how to make machines "see". To put it more specifically, it refers to machine vision such as using cameras and computers to replace human eyes to identify and measure targets, and further processing graphics so that the computer processing becomes an image that is more suitable for human observation or transmission to instruments for detection. As a scientific discipline, computer vision studies related theories and technologies, and attempts to establish an artificial intelligence system that can obtain information from images or multi-dimensional data. Computer vision technology usually includes image processing, image recognition, image semantic understanding, image retrieval, OCR, video processing, video semantic understanding, video content / behavior recognition, three-dimensional object reconstruction, 3D technology, virtual reality, augmented reality, simultaneous positioning and map construction, and other technologies, as well as common biometric recognition technologies such as face recognition and fingerprint recognition.

[0094] Unimodal information is data of only one type, such as text, image, audio, video, electromagnetic signal, etc. Multimodal information is data that includes at least two types of unimodal information. Furthermore, multimodal information is suitable for complex tasks that require the integration of multiple information sources, such as sentiment analysis, robot interaction, autonomous driving, etc. By integrating information from multiple modalities, higher performance and accuracy can usually be achieved on the task.

[0095] A large model refers to an artificial neural network model with a very large number of parameters. In the field of artificial intelligence, a large model generally refers to a model with hundreds of millions to trillions of parameters. Models usually need to be trained on large-scale data sets and require a large amount of computing resources to be optimized and adjusted. Large models are often used to solve complex tasks such as natural language processing, computer vision, and speech recognition. Generative AI is an AI that can create new content and ideas, including conversations, stories, images, videos, and music. In an embodiment of the present application, the large model can be a BERT, XLNet, Zhipu model, Claude, Moonshot AI model, ChatGLM model, Qianyi Tongwen model, MiniMax model, Spark model, Llama model, 360GPT model, Qwen model, Baichuan model, Skylark model, vivoLM model, and Wenxin Yiyan scale language model, which is not limited in the embodiments of the present application.

[0096] The embodiments of the present application provide a method, system, apparatus, computer device, and computer-readable storage medium for classifying encrypted malicious traffic based on byte frequency domain information, which are described in detail below.

[0097] See also Figure 1 , Figure 1 The schematic diagram of the scenario of the network security monitoring system provided by the embodiment of the present application is as follows. The system may include a computer device 100, in which an encrypted malicious traffic classification device based on byte frequency domain information is integrated, such as Figure 1 Computer equipment in.

[0098] In the embodiment of the present application, the computer device 100 may be an independent server, or a server network or server cluster composed of servers. For example, the computer device 100 described in the embodiment of the present application includes but is not limited to a computer, a network host, a single network server, a plurality of network server sets or a cloud server composed of a plurality of servers. The cloud server is composed of a large number of computers or network servers based on cloud computing.

[0099] It is understandable that the computer device 100 used in the embodiments of the present application may be a device including both receiving and transmitting hardware, that is, a device having receiving and transmitting hardware capable of performing two-way communication on a two-way communication link. Such a device may include: a cellular or other communication device having a single-line display or a multi-line display or a cellular or other communication device without a multi-line display. The specific computer device 100 may be a desktop terminal or a mobile terminal, and the computer device 100 may also be one of a mobile phone, a tablet computer, a laptop computer, etc.

[0100] Those skilled in the art will understand that Figure 1 The application environment shown in the figure is only one application scenario of the present application solution and does not constitute a limitation on the application scenario of the present application solution. Other application environments may also include Figure 1 More or less computer equipment as shown in Figure 1 Only one computer device is shown in the figure. It can be understood that the system can also include one or more other services, which are not limited here.

[0101] In addition, if Figure 1 As shown, the network security monitoring system may further include a memory 200 for storing recognition result data and sample data, such as simulation result data, and the like.

[0102] It should be noted that Figure 1 The scenario diagram of the network security monitoring system shown is merely an example. The network security monitoring system and scenario described in the embodiment of the present application are intended to more clearly illustrate the technical solution of the embodiment of the present application, and do not constitute a limitation on the technical solution provided in the embodiment of the present application. A person of ordinary skill in the art can appreciate that with the evolution of the network security monitoring management system and the emergence of new business scenarios, the technical solution provided in the embodiment of the present application is equally applicable to similar technical problems.

[0103] The present invention discloses a method and device for classifying encrypted malicious traffic based on byte frequency domain information, which utilizes a traffic classification model based on one-dimensional CNN and screening of important byte frequency domain information, and implements real-time identification and classification of encrypted malicious traffic in raw traffic data based on screening of important byte frequency domain information, thereby improving the efficiency of encrypted malicious traffic identification and processing and classification accuracy. The following are detailed descriptions.

[0104] Embodiment 1

[0105] See also Figure 2 , Figure 2 1 is a flow chart of a method for classifying encrypted malicious traffic based on byte frequency domain information disclosed in an embodiment of the present invention. Figure 2 The encrypted malicious traffic classification method based on byte frequency domain information is applied to a network security monitoring system, such as a local server or a cloud server of a network security monitoring system, and is not limited in the embodiments of the present invention. Figure 1 As shown, the encrypted malicious traffic classification method based on byte frequency domain information may include the following operations:

[0106] S1, obtaining first data;

[0107] It should be noted that the first data, i.e., the original traffic data, refers to the CIC-IDS2017 dataset or the CSE-CIC-IDS2018 dataset, which is widely used in the evaluation of encrypted malicious traffic identification methods;

[0108] It should be noted that the CIC-IDS2017 dataset constructs an abstract network behavior model of 25 users, covering a variety of common network protocols such as HTTP, HTTPS, FTP, SSH and email; covering 7 typical attacks including brute force, denial of service (DoS), distributed denial of service (DDoS), botnet, web attacks, port scan and infiltration: The CIC-IDS2017 dataset includes original pcap data and extracted feature csv data, and the pcap data volume is 48.8GB;

[0109] It should be noted that the CSE-CIC-IDS2018 dataset is used to simulate real network traffic. It consists of two parts, B-Profile and M-Profile, and provides pcap data files and feature csv data files. The pcap data is as high as 444.5GB, and the collection time span is 10 days, which is the working time period of weekdays; B-Profile is responsible for describing the abstract behavior of user interaction and generating normal traffic; M-Profile is used to describe and execute attack scenarios and generate traffic with attack behaviors; the attack types involved in CSE-CIC-IDS2018 are the same as those in CIC-IDS2017; the pcap data in the CSE-CIC-IDS2018 data is divided into 10 folders, corresponding to the collection time of 10 days, in which the traffic data of each host constitutes a separate pcap file; the specific time and attack path of the attack execution provided by the official website, based on this information, combined with the characteristics of each type of attack, we extract malicious traffic and save them as pcap files respectively;

[0110] S2, preprocessing the first data to obtain second data;

[0111] It should be noted that the second data is the important byte data;

[0112] S3, extracting and processing the second data to obtain a second data feature information set;

[0113] S4: Process the second data feature information set using a traffic data classification model to obtain traffic data classification information.

[0114] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the traffic classification model is used to realize real-time identification and classification of encrypted malicious traffic in the original traffic data, thereby improving the efficiency of encrypted malicious traffic identification and processing and the classification accuracy.

[0115] In an optional embodiment, in the above step S2, the preprocessing of the first data to obtain important byte data includes:

[0116] S21, encoding the first data to obtain a data packet byte data set;

[0117] The data packet byte data set includes a plurality of data packet byte data;

[0118] It should be noted that the encoding process means obtaining a target byte data set from the first data in units of bytes, and then performing ASC encoding on the target byte data set to obtain a target data packet byte data set;

[0119] It should be noted that the byte data including the MAC address and the IP address in the target data packet byte data set is removed to obtain the data packet byte data set;

[0120] S22, processing the data packet byte data set based on the error assessment model to obtain a first byte parameter information set;

[0121] The first byte parameter information set includes a plurality of first byte parameter information;

[0122] S23, performing difference processing on the first byte parameter information set to obtain a second byte parameter information set;

[0123] The second byte parameter information set includes a plurality of second byte parameter information;

[0124] S24, sorting the byte data of the data packet according to the size order of the second byte parameter information to obtain a data packet byte sorting data set;

[0125] The data packet byte sorting data set includes a plurality of data packet byte sorting data;

[0126] It should be noted that the second byte parameter information size indicates the size of the second byte parameter value;

[0127] S25, based on the second byte parameter information, filter all the byte sorting data of the data packet to obtain second data;

[0128] It should be noted that the screening process means filtering out bytes whose second byte parameter is less than or equal to 0;

[0129] It should be noted that the second data is the important byte data.

[0130] In another optional embodiment, in the above step S22, the expression of the error evaluation model is:

[0131]

[0132] Where i represents the index of the byte data of the data packet; i Represents the classification prediction error rate of the byte data of the i-th data packet; FP i Indicates the number of samples misclassified as normal; FN i Indicates the number of samples misclassified as malicious; TP i Indicates the number of samples correctly classified as normal; TN i Represents the number of samples correctly classified as malicious;

[0133] In another optional embodiment, in the above step S23, the difference processing expression is:

[0134] ER i '=ER i -ER;

[0135] Among them, ER i ' represents the importance parameter of the byte data of the i-th data packet; ER represents the classification prediction error rate benchmark value;

[0136] It should be noted that, in this embodiment, the classification prediction error rate benchmark value is set to: 0.1 according to experience;

[0137] It should be noted that the second data, namely, the important byte data, indicates data ranked in the top 5 according to the importance parameter.

[0138] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented to pre-process the original traffic data to provide data support for subsequent data processing, thereby realizing real-time identification and classification of encrypted malicious traffic in the original traffic data, and improving the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0139] In another optional embodiment, in the above step S3, the extracting and processing the second data to obtain the second data feature information set includes:

[0140] S31, performing concatenation processing on the second data to obtain an important byte sequence set;

[0141] The important byte sequence set includes several important byte sequences;

[0142] It should be noted that the splicing process means splicing the second data in a front-to-back order;

[0143] S32, transforming any of the important byte sequences to obtain second data feature information;

[0144] The transformation processing expression is:

[0145]

[0146] Where Q[k] represents the characteristic information of the kth important byte data; x n represents the second data; N represents the size of the second data; j is an imaginary unit; k represents the index of the important byte data;

[0147] It should be noted that the imaginary unit is an intermediate calculation variable;

[0148] S33, all the second data feature information are combined in order to obtain a second data feature information set;

[0149] The second data feature information set includes a plurality of second data feature information;

[0150] It should be noted that the sequential combination means combining in chronological order;

[0151] It should be noted that the second data feature information set is an important byte feature information set.

[0152] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented to extract the important byte data set to obtain an important byte feature information set, thereby providing data support for subsequent data processing, thereby realizing real-time identification and classification of encrypted malicious traffic in the original traffic data, and improving the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0153] In another optional embodiment, in the above step S4, the traffic data classification model includes: a packet-level benchmark characterization module, an inter-packet feature extraction module and a data classification module;

[0154] The packet-level benchmark characterization module is used to process the second data feature information set to obtain a first feature information set;

[0155] The inter-packet feature extraction module is used to process the first feature information set to obtain a second feature information set;

[0156] The data classification module is used to process the second feature information set to obtain flow data classification information;

[0157] The packet-level benchmark characterization module, the inter-packet feature extraction module and the data classification module are sequentially data-connected.

[0158] It can be seen that by implementing the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention, the traffic classification model realizes real-time identification and classification of encrypted malicious traffic in the original traffic data, thereby improving the efficiency of encrypted malicious traffic identification and processing and the classification accuracy.

[0159] In another optional embodiment, the above-mentioned use of the traffic data classification model to process the second data feature information set to obtain traffic data classification information includes:

[0160] S41, using the packet-level benchmark characterization module, processing the second data feature information set to obtain a first feature information set;

[0161] S42, using the inter-packet feature extraction module to process the first feature information set to obtain a second feature information set;

[0162] S43: Utilize the data classification module to process the second feature information set to obtain flow data classification information.

[0163] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the traffic classification model is used to realize real-time identification and classification of encrypted malicious traffic of the important byte feature information set, thereby improving the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0164] In another optional embodiment, in the above step S41, the using the packet-level benchmark characterization module to process the second data feature information set to obtain the first feature information set includes:

[0165] S4101, performing a first convolution process on the second data feature information set to obtain frequency domain feature information within a first packet;

[0166] It should be noted that the first convolution process uses one-dimensional convolution, the input channel is set to 2, the output channel is set to 32; the convolution kernel size is set to 3, and the step size is 1;

[0167] The convolution kernel is a small matrix used to perform convolution operations on the input traffic features. The step size is the amplitude of the convolution kernel movement during the operation process.

[0168] Performing a second convolution process on the second data feature information set to obtain frequency domain feature information within a second packet;

[0169] It should be noted that the second convolution process uses one-dimensional convolution, the input channel is set to 2, the output channel is set to 32; the convolution kernel size is set to 5, and the step size is 1;

[0170] S4102, performing a first function processing on the frequency domain feature information in the first packet to obtain frequency domain feature information in a third packet;

[0171] Performing a first function processing on the frequency domain feature information in the second packet to obtain frequency domain feature information in a fourth packet;

[0172] It should be noted that the first function adopts the BatchNorm function;

[0173] S4103, performing a second function processing on the frequency domain feature information in the third packet to obtain frequency domain feature information in a fifth packet;

[0174] Performing a second function processing on the frequency domain feature information in the fourth packet to obtain frequency domain feature information in a sixth packet;

[0175] It should be noted that the second function is a ReLU activation function;

[0176] The ReLU activation function expression is:

[0177] f(x)=max(0,W T x+B);

[0178] Wherein, W represents the slope; B represents the intercept; x represents the frequency domain feature information in the fourth packet;

[0179] S4104, performing pooling processing on the frequency domain feature information in the fifth packet to obtain frequency domain feature information in a seventh packet;

[0180] It should be noted that the pooling process uses the Maxpool pooling component;

[0181] It should be noted that the Maxpool pooling component divides the frequency domain feature information in the fifth packet input into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0182] Performing pooling processing on the frequency domain feature information in the sixth packet to obtain frequency domain feature information in an eighth packet;

[0183] It should be noted that the pooling process uses the Maxpool pooling component;

[0184] It should be noted that the pooling process uses a Maxpool pooling component; it should be noted that the Maxpool pooling component divides the input frequency domain feature information in the sixth packet into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0185] S4105, performing a third convolution process on the frequency domain feature information in the seventh packet to obtain frequency domain feature information in a ninth packet;

[0186] It should be noted that the third convolution process adopts one-dimensional convolution, the input channel is set to 2, the output channel is set to 64; the convolution kernel size is set to 3, and the step size is 1;

[0187] Performing a fourth convolution process on the frequency domain feature information in the eighth packet to obtain frequency domain feature information in a tenth packet;

[0188] It should be noted that the fourth convolution process adopts one-dimensional convolution, the input channel is set to 2, the output channel is set to 64; the convolution kernel size is set to 5, and the step size is 1;

[0189] S4106, performing a third function processing on the frequency domain feature information in the ninth packet to obtain frequency domain feature information in the eleventh packet;

[0190] Performing a third function processing on the frequency domain feature information in the tenth packet to obtain frequency domain feature information in the twelfth packet;

[0191] It should be noted that the third function adopts the BatchNorm function;

[0192] S4107, performing a fourth function processing on the frequency domain feature information in the eleven packets to obtain frequency domain feature information in the thirteenth packet;

[0193] Performing a fourth function processing on the frequency domain feature information in the twelfth packet to obtain frequency domain feature information in the fourteenth packet;

[0194] It should be noted that the fourth function is the same as the second function, which is a ReLU activation function;

[0195] S4108, performing pooling processing on the frequency domain feature information in the thirteenth packet to obtain frequency domain feature information in the fifteenth packet;

[0196] It should be noted that the pooling process uses a Maxpool pooling component; it should be noted that the Maxpool pooling component divides the input frequency domain feature information of the thirteenth packet into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0197] Performing pooling processing on the frequency domain feature information in the fourteenth packet to obtain frequency domain feature information in the sixteenth packet;

[0198] It should be noted that the pooling process uses the Maxpool pooling component;

[0199] It should be noted that the pooling process uses a Maxpool pooling component; it should be noted that the Maxpool pooling component divides the input frequency domain feature information in the fourteenth packet into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0200] S4109, concatenating and flattening the frequency domain feature information in the fifteenth packet and the frequency domain feature information in the sixteenth packet to obtain frequency domain feature information in the seventeenth packet;

[0201] It should be noted that the splicing means splicing according to the order of output data;

[0202] It should be noted that the flattening means flattening the data into one dimension;

[0203] S4110, performing a first linear processing on the frequency domain feature information in the seventeenth packet to obtain frequency domain feature information in the eighteenth packet;

[0204] It should be noted that the first linear processing expression is:

[0205] y=w*x+B

[0206] Wherein, y represents the linear processing output value; w represents the weight value; B represents the bias; x represents the frequency domain feature information in the seventeenth packet;

[0207] It should be noted that the value range of w and B is 0 to 1;

[0208] S4111, generalize the frequency domain feature information in the eighteenth packet to obtain frequency domain feature information in the nineteenth packet;

[0209] It should be noted that the generalized processing expression is:

[0210] y=x⊙Bernoulli(p)

[0211] Wherein, y represents the frequency domain feature information in the nineteenth packet; ⊙ represents element-by-element multiplication, Bernoulli() represents Bernoulli distribution; p represents the probability of discarding an element; x represents the frequency domain feature information in the eighteenth packet;

[0212] In this embodiment, p = 0.6;

[0213] S4112, performing a second linear processing on the frequency domain feature information in the nineteenth packet to obtain frequency domain feature information in the twentieth packet;

[0214] It should be noted that the second linear processing is consistent with the first linear processing;

[0215] S4113, performing a fifth function processing on the frequency domain feature information in the 20th packet to obtain a first feature information set;

[0216] It should be noted that the fifth function is a Softmax activation function;

[0217] It should be noted that the Softmax activation function converts an unnormalized vector (usually the output of the model) into a probability distribution so that each value in the output is between 0 and 1, and the sum of all outputs is 1;

[0218] The Softmax activation function expression is:

[0219]

[0220] Among them, x i is the i-th element in the input vector; K represents the total number of categories; e represents the base of the natural logarithm;

[0221] It should be noted that the Softmax activation function converts the output value x of each category i Convert to a positive value while keeping the relative proportions between categories unchanged, and ensure that the output values ​​of all categories add up to 1 through normalization, indicating the probability of each category;

[0222] It should be noted that the first feature information set is an n×256 vector sequence, where n is the number of data packets.

[0223] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the packet-level benchmark characterization module of the traffic classification model is used to perform convolution and mapping processing on the important byte feature information set to obtain the first feature information set, which lays the foundation for the subsequent real-time identification and classification of the encrypted malicious traffic of the second data feature information set, and improves the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0224] In another optional embodiment, in the above step S42, the using the inter-packet feature extraction module to process the first feature information set to obtain the second feature information set includes:

[0225] S421, performing a fifth convolution process on the first feature information set to obtain first inter-packet feature information;

[0226] It should be noted that the fifth convolution process adopts one-dimensional convolution, the input channel is set to 2, the output channel is set to 32; the convolution kernel size is set to 3, and the step size is 1;

[0227] Performing a sixth convolution process on the second data feature information set to obtain second inter-packet feature information;

[0228] It should be noted that the sixth convolution process adopts one-dimensional convolution, the input channel is set to 2, the output channel is set to 32; the convolution kernel size is set to 5, and the step size is 1;

[0229] S422, performing a sixth function processing on the second package room characteristic information to obtain third package room characteristic information;

[0230] Performing a sixth function processing on the second private room characteristic information to obtain fourth private room characteristic information;

[0231] It should be noted that the sixth function adopts the BatchNorm function;

[0232] S423, performing a seventh function processing on the fourth room characteristic information to obtain fifth room characteristic information;

[0233] Performing a seventh function processing on the fourth private room characteristic information to obtain sixth private room characteristic information;

[0234] It should be noted that the seventh function is the same as the second function, which is a ReLU activation function;

[0235] S424, performing pooling processing on the fifth room characteristic information to obtain seventh room characteristic information;

[0236] It should be noted that the pooling process uses the Maxpool pooling component;

[0237] It should be noted that the Maxpool pooling component divides the input fifth package feature information into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0238] Performing pooling processing on the sixth private room characteristic information to obtain eighth private room characteristic information;

[0239] It should be noted that the pooling process uses the Maxpool pooling component;

[0240] It should be noted that the Maxpool pooling component divides the input sixth package feature information into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0241] S425, concatenating the seventh private room characteristic information and the eighth private room characteristic information to obtain a second characteristic information set;

[0242] It should be noted that the splicing means splicing according to the order of output data;

[0243] It should be noted that the second feature information set is the inter-packet timing feature;

[0244] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the first feature information set is processed using the inter-packet feature extraction module of the traffic classification model to obtain the second feature information set, which lays the foundation for the subsequent real-time identification and classification of encrypted malicious traffic of the second data feature information set, and improves the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0245] In another optional embodiment, in the above step S43, the using the data classification module to process the second feature information set to obtain the flow data classification information includes:

[0246] S431, performing pooling processing on the second feature information set to obtain first global feature information;

[0247] It should be noted that the seventh pooling process uses the Maxpool pooling component;

[0248] It should be noted that the Maxpool pooling component divides the input second feature information set into multiple regions, and samples the maximum value in each region, thereby achieving feature dimensionality reduction and extracting important features;

[0249] S432, performing a seventh convolution process on the first global feature information to obtain second global feature information and weight vector information;

[0250] It should be noted that the weight vector information is used to represent the weight vector with the same number of input feature channels;

[0251] S433, fusing the second feature information set, the second global feature information, and the weight vector information to obtain third global feature information;

[0252] It should be noted that the fusion processing means bit-by-bit multiplication of the second feature information set, the second global feature information and the weight vector information;

[0253] S434, normalizing the third global feature information to obtain the traffic data classification information;

[0254] It should be noted that the normalization process uses a softmax function;

[0255] It should be noted that the softmax function expression is:

[0256] The Softmax activation function expression is:

[0257]

[0258] Among them, m i is the i-th element in the third global feature information; K represents the total number of categories; e represents the base of the natural logarithm;

[0259] It should be noted that the softmax function converts an unnormalized vector (usually the output of the model) into a probability distribution so that each value in the output is between 0 and 1, and the sum of all outputs is 1;

[0260] It should be noted that after normalization, the weight value of each channel is between 0 and 1;

[0261] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the data classification module of the traffic classification model is used to process the second feature information set to obtain traffic data classification information, thereby improving the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0262] In another optional embodiment, the loss function expression of the traffic classification model is:

[0263]

[0264] Z=[z1,z2,…,z C ]T

[0265] Wherein, Z represents the prediction results of all categories; y represents the yth sample data of the first data; β represents the hyperparameter; C represents the total number of categories of the first data; n y represents the number of samples of the first data; y Represents the prediction result of the yth sample data; z j Represents the prediction result of the jth category;

[0266] It should be noted that the value range of β is [0, 1);

[0267] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention is implemented, and the data classification module of the traffic classification model is used to process the second feature information set on the basis of obtaining the second feature information set to obtain traffic data classification information, thereby improving the encrypted malicious traffic identification and processing efficiency and classification accuracy.

[0268] It should be noted that this embodiment uses a packet-level classification model based on one-dimensional CNN and a classification model based on random forest as benchmark models, respectively, and tests the importance of bytes on CIC-IDS2017 and CSE-CIC-IDS2018 data sets. The maximum number of bytes extracted from each data packet is set to 200; for common TCP / IP protocol clusters, the Ethernet protocol header usually occupies 14 bytes, the TCP protocol header occupies 20 bytes, and the IPv4 protocol header occupies 20 bytes, so the total number of protocol header bytes is generally within 54 bytes, and after removing the MAC address and IP address, 34 bytes remain; after byte importance calculation, we obtained the important bytes of 2 data sets. Among these bytes, the more important ones include: packet length, IP flag and fragment offset, lifetime, transport layer protocol, checksum, source port, destination port, TCP header length, TCP flag (including SYN, ACK, RST, FIN, PSH, URG and other flags), window size, TCP checksum. For the UDP protocol, there are fewer attack lists involved; for other important bytes except the above important bytes, we analyzed the traffic categories that these bytes have a greater impact on, and found that they are mainly DoSHulk, DoS GoldenEye and DoS Slowloris attacks. Using Wireshark traffic analysis software to analyze the original pcap, we found that the fields corresponding to these bytes are optional fields in the TCP protocol header, which are used to store TCP timestamps. Since these two data sets are attack traffic simulated by attack tools in a controllable network environment, relying on timestamps to achieve better classification results may introduce artificial traces.

[0269] It should be noted that the same number of important bytes are selected for data packets of different flows, the important bytes of the same data packet are concatenated into an important byte row vector, and then the important byte row vectors of all flows are constructed into a matrix, in which each row of the matrix represents the important byte of a data packet of a flow; Fourier transform is performed on each row of the important byte matrix to obtain the corresponding frequency domain feature information.

[0270] It should be noted that the performance of the recognition and classification model was tested and analyzed without filtering important bytes. The first two hundred bytes of each data packet excluding the MAC address and IP address were extracted.

[0271] It should be noted that the flow-level malicious traffic classification results obtained in the CIC-IDS2017 dataset include precision, recall and F1 score, and the total accuracy, macro average and weighted average are calculated. For the 13 attacks included in the dataset, the proposed method can achieve good detection results. The precision and recall of most attacks are close to 1. Only the recall of the Infiltration attack is slightly lower, reaching 92.31%. We analyzed the pcap file corresponding to Infiltration and found that some flows do not belong to the traffic of successful attacks. They only contain SYN packets for TCP connection establishment and RST reset packets. These flows are also given Infiltration labels, which affects the accuracy of model classification. Most datasets collect traffic by using attack tools to simulate the attack process, but problems in the configuration process can easily lead to some attacks not being executed correctly, so that the collected attack traffic is mixed with traffic that does not conform to the attack behavior.

[0272] In the normalized confusion matrix of CIC-IDS2017 flow-level and IP-pair-level malicious traffic classification, each category of attack can be correctly classified with a high probability, and the probability values ​​are distributed on the diagonal with high values. In the Infiltration attack with poor recognition effect, some samples were classified into the benign traffic category. At the IP pair granularity, the attack was correctly classified. Infiltration contains a small number of flows, only 65, but the flow with successful attack contains a large number of data packets, so it will be divided into more samples at the IP pair granularity. The flow with failed attack contains few data packets and has little impact at the IP pair granularity. The detection accuracy of each category remains at a high level (more than 99%), which also shows that detecting malicious traffic at the IP pair level has certain advantages and can make up for the shortcomings of flow-level detection.

[0273] The flow-level malicious traffic classification results obtained in the CSE-CIC-IDS2018 dataset show that the F1 scores of most attacks are above 99%, and the F1 scores of 9 types of attacks reach 100%, indicating that the proposed method has a good classification ability for the CSE-CIC-IDS2018 dataset. At the IP pair granularity, the proposed method can achieve better detection results, and the classification accuracy of Brute Force-Web attacks is improved from 98% to 100%.

[0274] It can be seen that the encrypted malicious traffic classification method based on byte frequency domain information described in the embodiment of the present invention utilizes a traffic classification model based on one-dimensional CNN and important byte frequency domain information screening, and realizes real-time identification and classification of encrypted malicious traffic in original traffic data based on important byte frequency domain information screening. Experiments have shown that the encrypted malicious traffic classification method based on byte frequency domain information can improve the processing efficiency by 3-4 times, and the classification accuracy of encrypted malicious traffic can reach 99.9%, thereby improving the identification and processing efficiency and classification accuracy of encrypted malicious traffic.

[0275] Embodiment 2

[0276] See also Figure 3 , Figure 3 1 is a schematic diagram of a structure of an encrypted malicious traffic classification device based on byte frequency domain information disclosed in an embodiment of the present invention. Figure 3 The described device can be used in a network security monitoring system, such as a local server or a cloud server in a network security monitoring system, and the embodiments of the present invention do not limit this. Figure 3 As shown, the device may include:

[0277] Data acquisition module 101, first processing module 102, second processing module 103 and third processing module 104;

[0278] The data acquisition module 101 is used to acquire first data;

[0279] The first processing module 102 is used to pre-process the first data to obtain second data;

[0280] The second processing module 103 is used to extract and process the second data to obtain a second data feature information set;

[0281] The third processing module 104 is used to process the second data feature information set using a flow data classification model to obtain flow data classification information.

[0282] Embodiment 3

[0283] See also Figure 4 , Figure 4 This is a schematic diagram of the structure of a method and device for classifying encrypted malicious traffic based on byte frequency domain information disclosed in an embodiment of the present invention. Figure 4 The described device can be applied to a network security monitoring system, such as a local server or a cloud server in a network security monitoring system, and the embodiments of the present invention are not limited thereto. Figure 4 As shown, the device may include:

[0284] A memory 202 storing executable program code;

[0285] A processor 201 coupled to a memory 202;

[0286] The processor 201 calls the executable program code stored in the memory 202 to execute the steps in the encrypted malicious traffic classification method based on byte frequency domain information described in the first embodiment.

[0287] Embodiment 4

[0288] An embodiment of the present invention discloses a computer-readable storage medium that stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the encrypted malicious traffic classification method based on byte frequency domain information described in the first embodiment.

[0289] Embodiment 5

[0290] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps in the encrypted malicious traffic classification method based on byte frequency domain information described in Example 1.

[0291] The device embodiments described above are only illustrative, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, i.e., they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Those of ordinary skill in the art may understand and implement it without creative work.

[0292] Through the specific description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution can be essentially or partly contributed to the prior art in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable rewritable read-only memory (EEPROM), a compact disc (CD-ROM) or other optical disc storage, a magnetic disk storage, a magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0293] Finally, it should be noted that the encrypted malicious traffic classification method, system and device based on byte frequency domain information disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, which are only used to illustrate the technical scheme of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, it should be understood by those skilled in the art that the technical schemes described in the aforementioned embodiments can still be modified, or some of the technical features therein can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical schemes from the spirit and scope of the technical schemes of the embodiments of the present invention.

Claims

1. A method for classifying encrypted malicious traffic, characterized in that: The method comprises: S1, obtaining first data; S2, preprocessing the first data to obtain second data; S3, extracting and processing the second data to obtain a second data feature information set; S4: Process the second data feature information set using a traffic data classification model to obtain traffic data classification information.

2. The encrypted malicious traffic classification method according to claim 1, characterized in that: The preprocessing of the first data to obtain important byte data includes: S21, encoding the first data to obtain a data packet byte data set; The data packet byte data set includes a plurality of data packet byte data; S22, processing the data packet byte data set based on the error assessment model to obtain a first byte parameter information set; The first byte parameter information set includes a plurality of first byte parameter information; S23, performing difference processing on the first byte parameter information set to obtain a second byte parameter information set; The second byte parameter information set includes a plurality of second byte parameter information; S24, sorting the byte data of the data packet according to the size order of the second byte parameter information to obtain a data packet byte sorting data set; The data packet byte sorting data set includes a plurality of data packet byte sorting data; S25, based on the second byte parameter information, filter and process all the byte sorting data of the data packet to obtain second data.

3. The encrypted malicious traffic classification method according to claim 2, characterized in that: The expression of the error evaluation model is: Where i represents the index of the data packet byte data; ERi represents the classification prediction error rate of the byte data of the i-th data packet; FP i Indicates the number of samples misclassified as normal; FN i Indicates the number of samples misclassified as malicious; TP i Indicates the number of samples correctly classified as normal; TN i Represents the number of samples correctly classified as malicious; The difference processing expression is: IS i’ =IS i -IS; Among them, ER i’ It represents the importance parameter of the byte data of the i-th data packet; ER represents the classification prediction error rate benchmark value.

4. The encrypted malicious traffic classification method according to claim 1, characterized in that: The extracting and processing the second data to obtain a second data feature information set includes: S31, performing concatenation processing on the second data to obtain an important byte sequence set; The important byte sequence set includes several important byte sequences; S32, transforming any of the important byte sequences to obtain second data feature information; The transformation processing expression is: Where Q[k] represents the characteristic information of the kth important byte data; x n represents the second data; N represents the size of the second data; j is an imaginary unit; k represents the index of the important byte data; S33, all the second data feature information are combined in order to obtain a second data feature information set; The second data feature information set includes a plurality of second data feature information.

5. The encrypted malicious traffic classification method according to claim 1, characterized in that: The traffic data classification model includes: a packet-level benchmark characterization module, an inter-packet feature extraction module and a data classification module; The packet-level benchmark characterization module is used to process the second data feature information set to obtain a first feature information set; The inter-packet feature extraction module is used to perform convolution processing on the first feature information set to obtain a second feature information set; The data classification module is used to perform splicing and identification processing on the second feature information set to obtain flow data classification information; The packet-level benchmark characterization module, the inter-packet feature extraction module and the data classification module are sequentially data-connected.

6. The encrypted malicious traffic classification method according to claim 5, characterized in that: The flow data classification model is used to process the second data feature information set to obtain flow data classification information, including: S41, using the packet-level benchmark characterization module, performing convolution and mapping processing on the second data feature information set to obtain a first feature information set; S42, using the inter-packet feature extraction module to process the first feature information set to obtain a second feature information set; S43: Utilize the data classification module to process the second feature information set to obtain flow data classification information.

7. The encrypted malicious traffic classification method according to claim 6, characterized in that: The packet-level benchmark characterization module using the traffic data classification model performs convolution and mapping processing on the second data feature information set to obtain a first feature information set, including: S4101, performing a first convolution process on the second data feature information set to obtain frequency domain feature information within a first packet; Performing a second convolution process on the second data feature information set to obtain frequency domain feature information within a second packet; S4102, performing a first function processing on the frequency domain feature information in the first packet to obtain frequency domain feature information in a third packet; Performing a first function processing on the frequency domain feature information in the second packet to obtain frequency domain feature information in a fourth packet; S4103, performing a second function processing on the frequency domain feature information in the third packet to obtain frequency domain feature information in a fifth packet; Performing a second function processing on the frequency domain feature information in the fourth packet to obtain frequency domain feature information in a sixth packet; S4104, performing a first pooling process on the frequency domain feature information in the fifth packet to obtain frequency domain feature information in a seventh packet; Performing a second pooling process on the frequency domain feature information in the sixth packet to obtain frequency domain feature information in an eighth packet; S4105, performing a third convolution process on the frequency domain feature information in the seventh packet to obtain frequency domain feature information in a ninth packet; Performing a fourth convolution process on the frequency domain feature information in the eighth packet to obtain frequency domain feature information in a tenth packet; S4106, performing a third function processing on the frequency domain feature information in the ninth packet to obtain frequency domain feature information in the eleventh packet; Performing a third function processing on the frequency domain feature information in the tenth packet to obtain frequency domain feature information in the twelfth packet; S4107, performing a fourth function processing on the frequency domain feature information in the eleven packets to obtain frequency domain feature information in the thirteenth packet; Performing a fourth function processing on the frequency domain feature information in the twelfth packet to obtain frequency domain feature information in the fourteenth packet; S4108, performing a third pooling process on the frequency domain feature information in the thirteenth packet to obtain frequency domain feature information in the fifteenth packet; Performing a fourth pooling process on the frequency domain feature information in the fourteenth packet to obtain frequency domain feature information in the sixteenth packet; S4109, concatenating and flattening the frequency domain feature information in the fifteenth packet and the frequency domain feature information in the sixteenth packet to obtain frequency domain feature information in the seventeenth packet; S4110, performing a first linear processing on the frequency domain feature information in the seventeenth packet to obtain frequency domain feature information in the eighteenth packet; S4111, generalize the frequency domain feature information in the eighteenth packet to obtain frequency domain feature information in the nineteenth packet; S4112, performing a second linear processing on the frequency domain feature information in the nineteenth packet to obtain frequency domain feature information in the twentieth packet; S4113, performing a fifth function processing on the frequency domain feature information in the 20th packet to obtain a first feature information set.

8. An encrypted malicious traffic classification device, characterized in that: The system comprises: A data acquisition module, a first processing module, a second processing module and a third processing module; The data acquisition module is used to acquire first data; The first processing module is used to pre-process the first data to obtain second data; The second processing module is used to extract and process the second data to obtain a second data feature information set; The third processing module is used to process the second data feature information set using a flow data classification model to obtain flow data classification information.

9. An encrypted malicious traffic classification device, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the encrypted malicious traffic classification method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, which, when called, are used to execute the encrypted malicious traffic classification method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Traffic intrusion detection method and device, equipment, storage medium and program product

    CN115695002A

  • Malicious traffic detection method and system, electronic equipment and storage medium

    CN118764269A

  • Internet Traffic Classification Via Time-Frequency Analysis

    US20180316693A1