Network traffic classification method and related equipment
By extracting the characteristics of electromagnetic radiation signals and communication behavior sequences of network devices, and generating multi-dimensional classification feature vectors, the problem of difficulty in identifying encrypted traffic and new attack modes in the prior art is solved, and high accuracy and anti-forgery network traffic classification is achieved.
Patent Information
- Application Number
- CN202510480921.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-17
AI Technical Summary
Existing network traffic classification methods are difficult to effectively identify encrypted traffic and new attack modes, and rely on manual annotation of data training models, making it difficult to dynamically adapt to complex and changeable network environments.
By obtaining the electromagnetic radiation signal and historical communication behavior sequence of the target network device, the first frequency domain characteristics of the electromagnetic radiation signal and the second timing characteristics of the historical communication behavior sequence are extracted, the electromagnetic fingerprint identification and timing characteristics are generated, and a multi-dimensional classification feature vector is generated in combination with encoding to match and identify traffic types.
It improves the accuracy and anti-forgery ability of traffic classification, can effectively distinguish counterfeit devices, dynamically adapt to changes in the network environment, quickly identify new threats and associate abnormal behavior patterns.
Smart Images

Figure CN120030481A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network information security technology, and in particular to a network traffic classification method and related equipment. Background Art
[0002] Existing network traffic classification methods mostly rely on protocol parsing, IP quintuples or machine learning models to identify traffic features. However, such methods have significant limitations: on the one hand, attackers can bypass detection by forging protocol headers, tampering with data packet contents, etc., resulting in low reliability of classification results; on the other hand, traditional technologies are difficult to deal with encrypted traffic or new attack modes (such as adaptive malware), and rely on manually labeled data training models, which are difficult to dynamically adapt to complex and changing network environments. Therefore, a network traffic classification method is urgently needed to solve the above-mentioned technical problems. Summary of the invention
[0003] A series of simplified concepts are introduced in the Summary of the Invention section, which will be further described in detail in the Detailed Description of the Invention section. The Summary of the Invention section of this application does not mean to attempt to limit the key features and essential technical features of the claimed technical solution, nor does it mean to attempt to determine the scope of protection of the claimed technical solution.
[0004] In a first aspect, the present application provides a network traffic classification method, the method comprising: Obtain the electromagnetic radiation signals and historical communication behavior sequences of target network devices; Based on the electromagnetic radiation signal, extracting a first frequency domain feature in the electromagnetic radiation signal; Generate an electromagnetic fingerprint identification of the target network device based on the first frequency domain feature; Based on the historical communication behavior sequence, extract the second time series feature in the historical communication behavior sequence; The electromagnetic fingerprint identification is jointly encoded with the second time series feature to generate a multi-dimensional classification feature vector; Based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template, the traffic type of the target network device is generated.
[0005] In some embodiments, extracting a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal includes: Perform wavelet packet decomposition on electromagnetic radiation signals to extract the energy distribution ratio within a preset frequency band; The energy distribution ratio is nonlinearly reduced through a convolutional autoencoder to generate a first frequency domain feature containing the inherent noise characteristics of the hardware circuit.
[0006] In some implementations, generating an electromagnetic fingerprint identification of a target network device based on the first frequency domain feature includes: Performing cluster analysis on the first frequency domain feature to generate a cluster center vector uniquely corresponding to a hardware circuit of the target network device; The cluster center vector is mapped to a preset electromagnetic fingerprint identification library to generate an electromagnetic fingerprint identification in the form of a digital code, and the cluster center vector is associated with the digital code and stored; wherein the preset electromagnetic fingerprint identification library stores the mapping relationship between the digital code and the cluster center vector.
[0007] In some implementations, extracting a second time series feature in the historical communication behavior sequence based on the historical communication behavior sequence includes: Statistics are kept in the preset time window for the traffic burst interval, data packet length distribution and retransmission rate in the historical communication behavior sequence to generate a time series of statistical behavior characteristics; The periodic pattern of time series is extracted through long short-term memory network to obtain the second time series feature that characterizes the dynamic change of traffic.
[0008] In some implementations, the electromagnetic fingerprint identifier is jointly encoded with the second time series feature to generate a multi-dimensional classification feature vector, including: According to the electromagnetic fingerprint identification, the corresponding cluster center vector is obtained from a preset electromagnetic fingerprint identification library; Normalizing the cluster center vector to generate the first eigenvector; Performing standardization processing on the second time series feature to generate a second feature vector; The first feature vector and the second feature vector are concatenated according to a preset dimension, and feature fusion is performed through a fully connected layer to generate a multi-dimensional classification feature vector.
[0009] In some implementations, generating a traffic type of a target network device based on a matching degree between a multi-dimensional classification feature vector and a preset traffic category template includes: Calculating the cosine similarity between the multi-dimensional classification feature vector and each of the preset multiple traffic category templates; Selecting a template whose cosine similarity is higher than a first preset threshold from a plurality of traffic category templates as a candidate category; According to the stability coefficient of the electromagnetic fingerprint identification, the cosine similarity of each candidate category is weighted and modified to obtain the modified similarity of each candidate category; The candidate category with the highest value in the modified similarity is determined as the traffic type of the target network device.
[0010] In some embodiments, it further comprises: When the cosine similarities of all traffic category templates are lower than the first preset threshold, marking the multidimensional classification feature vector as an unknown type, and generating a new traffic class template based on the multidimensional classification feature vector; The new traffic class template is matched and associated with the historical abnormal behavior pattern in the abnormal behavior database.
[0011] In a second aspect, the present application proposes a network traffic classification device, the device comprising: A device data acquisition unit, used to acquire electromagnetic radiation signals and historical communication behavior sequences of target network devices; A frequency domain feature extraction unit, based on the electromagnetic radiation signal, extracts a first frequency domain feature in the electromagnetic radiation signal; A fingerprint identification generating unit, generating an electromagnetic fingerprint identification of a target network device based on the first frequency domain feature; A time series feature extraction unit, based on the historical communication behavior sequence, extracts a second time series feature in the historical communication behavior sequence; A feature vector fusion unit, used for jointly encoding the electromagnetic fingerprint identification and the second time series feature to generate a multi-dimensional classification feature vector; The traffic type confirmation unit generates the traffic type of the target network device based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template.
[0012] In a third aspect, an electronic device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor is configured to implement the steps of the network traffic classification method of any one of the first aspects when executing the computer program stored in the memory.
[0013] In a fourth aspect, the present application proposes a computer-readable storage medium having a computer program stored thereon, which implements the network traffic classification method of any one of the first aspects when the computer program is executed by a processor.
[0014] In summary, this application constructs a multidimensional classification model by integrating the electromagnetic fingerprint identification (hardware physical layer characteristics) of the target network device with the timing characteristics of the historical communication behavior sequence, thereby improving the accuracy and anti-counterfeiting ability of traffic classification. The electromagnetic fingerprint is generated based on the inherent characteristics of the hardware circuit, which is unique and cannot be tampered with, and can effectively distinguish counterfeit devices; the behavioral timing characteristics dynamically reflect changes in traffic patterns, making up for the shortcomings of static protocol analysis. The multidimensional feature vector generated by the joint encoding of the two can capture the device identity and behavioral intentions at the same time, solving the problem of single feature dimension in traditional methods. In addition, by dynamically matching traffic category templates and adaptively generating unknown type templates, rapid identification and abnormal association of new threats can be achieved, enhancing the security protection capabilities of the overall network. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present specification. Also, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings: Figure 1 A schematic diagram of a network traffic classification method flow provided in an embodiment of the present application; Figure 2 A schematic diagram of a network traffic classification structure provided in an embodiment of the present application; Figure 3 A structural diagram of a network traffic classification electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0016] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments.
[0017] See also Figure 1 , is a flow chart of a network traffic classification method provided in an embodiment of the present application, which may specifically include: S110, obtaining electromagnetic radiation signals and historical communication behavior sequences of target network devices; Exemplarily, by synchronously acquiring the electromagnetic radiation signals and historical communication behavior sequences of the target network device, a multi-dimensional data basis is provided for subsequent traffic classification. The electromagnetic radiation signal originates from the physical layer electromagnetic waves generated when the device hardware circuit (such as CPU, network card chip) is running. Its spectrum characteristics are closely related to the hardware structure and workload, and are unique to the device. The signal can be captured in real time by electromagnetic sensors (such as software-defined radio devices), providing a physical layer basis for distinguishing counterfeit devices or identifying hardware tampering.
[0018] The historical communication behavior sequence records the network interaction mode of the device within a preset time period, including statistical characteristics such as traffic burst intervals, packet length distribution, and retransmission rate. This type of data is obtained by capturing network traffic logs or real-time monitoring tools, reflecting the dynamic communication intentions and behavioral patterns of the device. The combination of the two constructs a dual verification framework of "hardware identity" and "behavior pattern", laying a data foundation for subsequent feature fusion and classification decisions.
[0019] S120, extracting a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal; Exemplarily, the first frequency domain feature is extracted from the electromagnetic radiation signal through frequency domain analysis technology, aiming to capture the inherent characteristics of the hardware circuit of the target network device. The frequency domain characteristics of the electromagnetic radiation signal reflect the difference in energy distribution of different frequency components when the device is running. For example, the high frequency band may correspond to electromagnetic leakage during high-speed operation of the chip, while the low frequency band may be related to power supply ripple. Such features are strongly related to the design parameters, manufacturing process and working status of the hardware circuit, have significant device uniqueness, and provide a physical layer basis for the subsequent generation of electromagnetic fingerprint identification.
[0020] To achieve feature extraction, this step uses frequency band division and nonlinear dimensionality reduction strategies. First, the energy distribution ratio within the preset frequency band is extracted through frequency band division technology to separate the core frequency domain components associated with the hardware circuit; then the nonlinear dimensionality reduction method is used to filter out environmental noise interference, retain the inherent noise characteristics of the hardware, and finally generate a low-dimensional and robust first frequency domain feature. This process converts the original electromagnetic signal into a key feature vector that can characterize the identity of the hardware, laying the foundation for subsequent multi-dimensional classification.
[0021] S130, generating an electromagnetic fingerprint identification of the target network device based on the first frequency domain feature; Exemplarily, the electromagnetic fingerprint of the target network device is generated through the first frequency domain feature, and its core lies in converting the physical layer characteristics of the hardware circuit into a unique and unalterable device identity. The electromagnetic fingerprint is based on the frequency domain characteristics of the electromagnetic radiation signal generated when the device is running, such as the energy distribution and noise pattern of a specific frequency band. These characteristics are determined by the physical structure of the hardware circuit (such as chip layout, circuit impedance) and manufacturing process differences. They have device-level uniqueness and can effectively distinguish different models or individual devices to avoid counterfeit attacks.
[0022] This step converts the first frequency domain feature into a standardized digital code sequence through feature mapping and identification processing. Specifically, the extracted features are matched or registered through the preset electromagnetic fingerprint identification library to generate a unique identification that is strongly bound to the target device hardware. This process ensures the stability and reusability of the electromagnetic fingerprint identification, and provides a reliable basis for the joint verification of device identity and behavior mode in subsequent traffic classification.
[0023] S140, extracting a second time series feature in the historical communication behavior sequence based on the historical communication behavior sequence; Exemplarily, by analyzing the historical communication behavior sequence of the target network device, the second time series feature characterizing its dynamic traffic pattern is extracted. The historical communication behavior sequence records the network interaction rules of the device within a preset time period, including statistical parameters such as traffic burst interval, data packet length distribution, and retransmission rate. These parameters reflect the communication intention and behavior preference of the device in different scenarios, providing a data basis for capturing its dynamic behavior pattern.
[0024] This step uses time series modeling technology to extract high-order time series rules from the original behavior sequence. Through time window division and pattern mining, the periodicity, burstiness or abnormal fluctuation characteristics of traffic behavior are identified. Such time series features can dynamically characterize the changes in the communication status of the device (such as the difference in behavior between normal operation and under attack), make up for the shortcomings of static protocol analysis, and provide key dimensions for subsequent multi-dimensional feature fusion to reflect behavioral intentions.
[0025] S150, jointly encoding the electromagnetic fingerprint identification and the second time series feature to generate a multi-dimensional classification feature vector; Exemplarily, the electromagnetic fingerprint identification is fused with the second time series feature through joint coding to generate a multi-dimensional classification feature vector. The electromagnetic fingerprint identification obtains the corresponding cluster center vector through the preset database mapping to characterize the hardware uniqueness of the device; the second time series feature reflects the dynamic communication behavior of the device. The combination of the two constructs a dual verification mechanism of "hardware identity authentication" and "behavioral intention recognition", breaking through the single-dimensional limitations of traditional traffic classification and providing multi-dimensional support for encrypted traffic identification and protocol camouflage attack defense.
[0026] Adopt feature standardization and cross-dimensional fusion strategies. The cluster center vector is normalized to eliminate the dimensional differences of hardware features, and the time series features are standardized to ensure the comparability of behavioral data; further, the correlation between hardware identity and behavioral patterns is explored through preset dimension splicing and full connection layer fusion to generate a highly discriminative fusion feature vector. This strategy strengthens the complementarity of features. Even if a single feature is tampered with, the joint feature can still ensure the reliability of classification, significantly improving the system's anti-counterfeiting ability and adaptability.
[0027] S160: Generate a traffic type of the target network device based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template.
[0028] Exemplarily, the traffic type of the target network device is determined by matching the multidimensional classification feature vector with the preset traffic category template. The multidimensional classification feature vector integrates the electromagnetic fingerprint identification and the second time series feature of the device, and the most matching candidate category is screened out by calculating its similarity with the preset template. This process combines the tamper-proof characteristics of the physical layer with the dynamic laws of the behavioral layer, effectively improving the accuracy and anti-counterfeiting capabilities of traffic classification, especially in encrypted traffic or protocol camouflage scenarios.
[0029] This step uses a dynamic matching mechanism to achieve the final determination of the traffic type. The preset traffic category template covers known traffic types (such as video streams, IoT data, and malicious attacks). Through multi-dimensional feature similarity comparison, high-confidence candidate categories are screened out; at the same time, a weighted correction of the stability coefficient is introduced to ensure the long-term reliability of the electromagnetic fingerprint. If the matching degree is insufficient, the unknown type processing mechanism is triggered, and a new template is dynamically generated and associated with the abnormal behavior to achieve adaptive classification and threat warning capabilities.
[0030] In summary, the embodiment of the present application constructs a classification model with multi-dimensional discrimination capabilities by integrating the electromagnetic fingerprint identification of the target network device and the timing characteristics of the historical communication behavior sequence, thereby improving the accuracy, anti-counterfeiting and dynamic adaptability of network traffic classification. First, the electromagnetic fingerprint identification is generated based on the inherent noise characteristics of the hardware circuit, and has device-level uniqueness and non-tamperability. It can effectively distinguish counterfeit devices or identify hardware tampering, and solves the problem that the traditional method that relies on protocol parsing or IP five-tuple is easily forged. Secondly, the timing features extracted by the long short-term memory network can dynamically capture the periodicity, burstiness and abnormal fluctuation patterns of traffic behavior, making up for the defect that static protocol analysis cannot adapt to dynamic network environments. The multi-dimensional classification feature vector formed by the joint encoding of the two contains both dimensions of hardware identity and behavioral intention, which enhances the discrimination of the feature space and can still maintain high classification accuracy in encrypted traffic, protocol camouflage or new attack scenarios. In addition, the classification strategy based on cosine similarity matching and weighted correction of stability coefficient, combined with the dynamic generation mechanism of unknown type templates, not only realizes the accurate identification of known traffic types, but also can quickly discover and associate abnormal behavior patterns, improving the system's adaptive ability and threat warning efficiency. Finally, this method does not need to rely on manually labeled data. It realizes automatic dimension reduction and identification mapping of features through autoencoders and clustering analysis, reduces the complexity of model training, and is suitable for real-time traffic classification and security protection in large-scale heterogeneous network environments.
[0031] In some examples, extracting a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal includes: Perform wavelet packet decomposition on electromagnetic radiation signals to extract the energy distribution ratio within a preset frequency band; The energy distribution ratio is nonlinearly reduced through a convolutional autoencoder to generate a first frequency domain feature containing the inherent noise characteristics of the hardware circuit.
[0032] Exemplarily, first, the electromagnetic radiation signal generated by the target network device during operation is subjected to wavelet packet decomposition. Compared with the traditional wavelet transform, the advantage of wavelet packet decomposition is that it can perform more refined multi-scale frequency band division on the signal. Wavelet packet decomposition recursively decomposes the signal into low-frequency and high-frequency components, and further subdivides them at each layer to form a complete binary tree structure. This multi-resolution feature enables wavelet packet decomposition to capture the detailed features of different frequency components in the signal, and is particularly suitable for the analysis of non-stationary signals (such as electromagnetic radiation signals). For example, when analyzing the electromagnetic radiation of a chip, the high-frequency component may reflect the rapid switching of the clock signal, while the low-frequency component may correspond to the periodic fluctuation of the power module. By selecting an appropriate number of decomposition layers, the signal can be divided into fine frequency bands, providing high-resolution frequency domain information for subsequent feature extraction.
[0033] The frequency band selection needs to be closely integrated with the hardware circuit characteristics of the target device. For example, the CPU main frequency of a certain model of network equipment is 2.4GHz, and its electromagnetic radiation signal may contain clock leakage energy in the 2.4GHz to 5GHz frequency band; while the operating frequency of the power management module is usually in the range of tens to hundreds of kHz, corresponding to the energy distribution of the low-frequency band. By pre-analyzing the hardware parameters of the target device, determine the frequency band range that needs attention. In actual operation, the frequency band division can be optimized in combination with experimental measurement data: electromagnetic signals are collected from multiple devices, and the energy concentration area is observed through a spectrum analyzer. Finally, 2.4-5GHz is selected as the core frequency band to ensure that the main radiation sources of the hardware circuit are covered.
[0034] The energy distribution ratio of each frequency band is obtained by integral calculation. Specifically, the energy of each sub-band signal after decomposition is integrated to calculate its percentage of the total signal energy. This calculation process can be achieved through digital signal processing algorithms. By quantifying the energy proportion of each frequency band, a feature vector that characterizes the hardware characteristics is formed. For example, a high energy proportion in the high-frequency band may reflect electromagnetic leakage during high-speed operation of the chip, while concentrated energy in the low-frequency band may correspond to periodic noise in the power supply circuit.
[0035] The frequency band energy distribution ratio extracted in this step provides the original input data for the subsequent nonlinear dimensionality reduction of the convolutional autoencoder. These data not only contain the inherent characteristics of the hardware circuit, but also contain implicit information about the working status of the device. The refined frequency band division through wavelet packet decomposition can effectively separate the environmental noise and the target signal, ensuring that the subsequent dimensionality reduction process focuses on key physical characteristics. For example, the energy proportion of the 3.0GHz frequency band of a certain device remains stable under different workloads, indicating that it can be used as a core feature of the hardware uniqueness identification, while frequency bands with large fluctuations may be filtered by the autoencoder, thereby improving the robustness of the feature.
[0036] The above-extracted frequency band energy distribution data (such as a 256-dimensional vector) contains mixed information of the inherent characteristics of the hardware circuit and environmental noise. In order to improve the feature discrimination, it is necessary to compress the data dimension and retain the core information through nonlinear dimensionality reduction technology. To this end, nonlinear dimensionality reduction is performed through Convolutional Autoencoder (CAE). This technology automatically captures the local correlation between frequency bands through end-to-end learning, suppresses environmental noise (such as Gaussian white noise, multipath interference) while compressing the data dimension, and generates a low-dimensional vector containing the inherent noise characteristics of the hardware circuit.
[0037] The convolutional autoencoder consists of an encoder and a decoder, and achieves data dimension reduction and reconstruction through hierarchical feature learning. The encoder contains convolutional layers and pooling layers. The convolutional layer uses a 3×1 convolution kernel to slide and scan the frequency band energy sequence to extract the correlation features between local frequency bands (such as the energy coupling pattern of adjacent 0.2GHz sub-bands); the pooling layer gradually compresses the feature dimension through a 2×1 window, and finally generates a 32-dimensional low-dimensional feature vector. The decoder reconstructs the original frequency band energy distribution through deconvolution and upsampling operations to ensure that the low-dimensional features retain key hardware characteristics. This structure can effectively capture hardware inherent noise patterns such as crystal oscillator phase jitter and power supply ripple frequency, while filtering out random interference.
[0038] The model training aims to minimize the mean square error (MSE) and optimizes the network parameters through back propagation. During the training process, the encoder learns to separate environmental noise from hardware features: for random noise, the encoder reduces its weight during compression; for stable hardware features, the encoder strengthens its feature expression. The decoder verifies the integrity of low-dimensional features through reconstruction to ensure that the energy distribution of key frequency bands (such as those related to the CPU main frequency) can be accurately restored.
[0039] The trained encoder converts the 256-dimensional frequency band energy distribution data into a 32-dimensional low-dimensional feature vector. For example, the input data contains the energy proportion of 10 preset frequency bands. After convolution and pooling operations, the output contains low-dimensional features of hardware characteristics such as power ripple frequency offset and clock signal phase noise, which is the first frequency domain feature.
[0040] In some examples, generating an electromagnetic fingerprint identification of a target network device based on the first frequency domain feature includes: Performing cluster analysis on the first frequency domain feature to generate a cluster center vector uniquely corresponding to a hardware circuit of the target network device; The cluster center vector is mapped to a preset electromagnetic fingerprint identification library to generate an electromagnetic fingerprint identification in the form of a digital code, and the cluster center vector is associated with the digital code and stored; wherein the preset electromagnetic fingerprint identification library stores the mapping relationship between the digital code and the cluster center vector.
[0041] Exemplarily, cluster analysis is performed on the first frequency domain features, aiming to identify the inherent patterns of the hardware circuits of the target network devices through unsupervised learning algorithms. Specifically, the K-means clustering algorithm is used to group multiple groups of first frequency domain features to generate cluster center vectors that uniquely correspond to the hardware circuits of the target devices. During the clustering process, the algorithm iteratively optimizes the centroid position so that similar features (such as multiple measurement data from the same device) are tightly clustered in the feature space, while heterogeneous features (such as measurement data from different devices) are significantly separated. For example, after clustering analysis of the feature data sets of 10 devices of the same model, the feature vectors of each device are distributed around an independent centroid, and the inter-class distance is greater than 3 times the intra-class distance, verifying the ability of the cluster center vector to characterize the uniqueness of the hardware.
[0042] After the cluster analysis is completed, the distance between the first frequency domain feature of the target device and the centroid of its cluster is used as the basis for discrimination to generate the cluster center vector. This vector is obtained by calculating the average or weighted average of similar features to ensure that it can represent the stable physical characteristics of the hardware circuit of the device. For example, the cluster center vector of a device contains parameters such as the mean frequency of the power ripple and the variance of the clock signal phase noise. In order to improve the compatibility of subsequent mapping, the cluster center vector is standardized to eliminate the dimensional difference so that it conforms to the input format of the preset electromagnetic fingerprint identification library.
[0043] The cluster center vector is mapped to the preset electromagnetic fingerprint identification library, an electromagnetic fingerprint identification in the form of a digital code is generated, and an associated storage relationship between the digital code and the cluster center vector is established. The preset electromagnetic fingerprint identification library stores the digital codes of all known devices and their corresponding cluster center vectors. During the mapping process, the Euclidean distance between the cluster center vector of the target device and the existing vectors in the library is calculated. If the minimum distance is lower than the preset threshold, the matching code is used as the electromagnetic fingerprint identification; if no match is found, a new unique digital code is generated for the device, and the code is associated with the vector and stored.
[0044] The electromagnetic fingerprint identification is presented in the form of a digital coding sequence, and the coding rules are in binary or hexadecimal format to ensure storability and transmission efficiency. For example, the code "0x3A7F" is mapped to the cluster center vector of a certain device, characterizing the joint characteristics of its power ripple frequency and clock noise. The digital code is protected by a hash function or encryption algorithm to prevent tampering or forgery. During the traffic classification process, the corresponding cluster center vector is retrieved from the library through the digital code, which is used for joint coding with the second timing feature to achieve dual verification of device identity and behavioral intention. For example, when the device corresponding to the code "0x3A7F" is detected to send abnormal traffic, the potential threat can be quickly determined based on the fusion result of its cluster center vector and behavioral characteristics.
[0045] In some examples, based on the historical communication behavior sequence, extracting the second time series feature in the historical communication behavior sequence includes: Statistics are kept in the preset time window for the traffic burst interval, data packet length distribution and retransmission rate in the historical communication behavior sequence to generate a time series of statistical behavior characteristics; The periodic pattern of time series is extracted through long short-term memory network to obtain the second time series feature that characterizes the dynamic change of traffic.
[0046] Exemplarily, the historical communication behavior sequence is statistically analyzed according to a preset time window to generate a time series of statistical behavior features. This step uses a sliding window mechanism to extract multi-dimensional features from traffic data. Specifically, a fixed time length (such as 5 minutes) is used as a window to slide on the historical communication behavior sequence, and the traffic burst interval, data packet length distribution and retransmission rate in each window are counted. The traffic burst interval reflects the drastic changes in network traffic in a short period of time, which is obtained by calculating the time difference between adjacent burst traffic events; the data packet length distribution describes the frequency of occurrence of data packets of different lengths in the network, which is determined by statistically analyzing the probability distribution of data packet length; the retransmission rate reflects the reliability of network communication, which is obtained by calculating the ratio of the number of retransmitted data packets to the total number of sent data packets. The statistical results in each window are arranged in chronological order to form a time series containing multiple feature dimensions, which records the behavioral characteristics of network traffic at different time points.
[0047] The time series generation process of statistical behavior features needs to consider the stability and representativeness of the data. To ensure the stability of the data, outliers are processed during the statistical process, for example, outliers are identified and removed using a method based on the interquartile range. Specifically, the traffic burst interval, packet length distribution, and retransmission rate are integrated into vector form and arranged in chronological order. The statistical vectors of continuous time windows constitute the time series of statistical behavior features, providing structured input for subsequent time series modeling.
[0048] The long short-term memory network (LSTM) is used to extract the periodic pattern of the generated time series to obtain the second time series feature that characterizes the dynamic changes of traffic. LSTM is a special recurrent neural network that can effectively process long-term dependencies in sequence data. Taking the time series of statistical behavior features as input, the LSTM network automatically learns the periodic change pattern of network traffic through internal memory units and gating mechanisms. Specifically, during the training process, the LSTM network adjusts the network parameters according to the input time series, so that the network can accurately predict future traffic behavior. By analyzing the trained LSTM network, extracting the final hidden state or sequence output of LSTM and mapping it through the fully connected layer, the second time series feature that characterizes the dynamic changes of traffic is generated. This feature is a low-dimensional vector (such as 64 dimensions) that contains abstract pattern information of device communication behavior. For example, the characteristics of video streaming devices may reflect "high burstiness and low retransmission rate", while malicious traffic presents a "irregular burst interval and high retransmission rate" pattern. After such features are jointly encoded with electromagnetic fingerprint identification, they can simultaneously characterize hardware identity and behavioral intentions, providing a multi-dimensional discrimination basis for traffic classification.
[0049] In some examples, the electromagnetic fingerprint identifier is jointly encoded with the second time series feature to generate a multi-dimensional classification feature vector, including: According to the electromagnetic fingerprint identification, the corresponding cluster center vector is obtained from a preset electromagnetic fingerprint identification library; Normalizing the cluster center vector to generate the first eigenvector; Performing standardization processing on the second time series feature to generate a second feature vector; The first feature vector and the second feature vector are concatenated according to a preset dimension, and feature fusion is performed through a fully connected layer to generate a multi-dimensional classification feature vector.
[0050] Exemplarily, according to the electromagnetic fingerprint identification, the corresponding cluster center vector is obtained from the preset electromagnetic fingerprint identification library. The electromagnetic fingerprint identification is in the form of digital coding. By querying the mapping relationship between the code and the cluster center vector stored in the identification library, the cluster center vector corresponding to the target device is extracted. For example, the code is mapped to the vector 0.85, 0.12, ..., 0.43, which represents the physical characteristics of the hardware circuit of the device. This step ensures the traceability and uniqueness of the hardware features through the coding retrieval mechanism, and provides a physical layer data foundation for subsequent feature fusion.
[0051] The cluster center vector is normalized to generate the first eigenvector. Normalization uses the minimum-maximum scaling method to linearly map the values of each dimension of the vector to the interval [0,1] to eliminate the dimensional differences of the hardware feature parameters. For example, after normalization, the noise is unified into a dimensionless value. This process ensures the scale consistency of different hardware features and avoids the deviation of fusion weights due to parameter dimensional differences.
[0052] The second time series feature is standardized to generate the second feature vector. The standardization uses the Z-score method to adjust the mean of the time series feature to 0 and the variance to 1. For example, the original mean of the traffic burst interval is 1.2 seconds and the standard deviation is 0.3 seconds. After standardization, the value distribution is centered on zero and the fluctuation range is controllable. This operation eliminates the distribution offset of the behavioral feature, improves the model training efficiency and generalization ability, and ensures the compatibility of the time series dynamic law and hardware characteristics.
[0053] The normalized first eigenvector and the standardized second eigenvector are concatenated according to the preset dimension to form an initial fusion vector, and nonlinear feature fusion is performed through the fully connected layer. The preset dimension is set according to the dimension of the hardware features and the behavioral features. For example, the first eigenvector is 32-dimensional, which is used to characterize the hardware characteristics; the second eigenvector is 64-dimensional, which is used to characterize the behavioral pattern, and a 96-dimensional fusion vector is generated after concatenation. The fully connected layer gradually compresses the dimension and extracts cross-modal correlation features through nonlinear transformation of the weight matrix and the activation function (such as ReLU), and finally generates a 32-dimensional multidimensional classification feature vector with high discriminability. This process strengthens the complementarity of hardware identity and behavioral intention. Even if a single feature is tampered with, the fused feature can still ensure the reliability of classification and provide high-precision input for traffic type determination.
[0054] In some examples, the traffic type of the target network device is generated based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template, including: Calculating the cosine similarity between the multi-dimensional classification feature vector and each of the preset multiple traffic category templates; Selecting a template whose cosine similarity is higher than a first preset threshold from a plurality of traffic category templates as a candidate category; According to the stability coefficient of the electromagnetic fingerprint identification, the cosine similarity of each candidate category is weighted and modified to obtain the modified similarity of each candidate category; The candidate category with the highest value in the modified similarity is determined as the traffic type of the target network device.
[0055] Exemplarily, to generate traffic types based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template, the cosine similarity between the feature vector and each template needs to be calculated first. The preset traffic category template is a pre-established database containing feature vectors of known traffic types (such as video streams, IoT data, malicious attacks). The calculation of cosine similarity is achieved by vector inner product and module length ratio. The formula for cosine similarity is:
[0056] in, is a multidimensional classification feature vector, is the feature vector of a traffic category template. By traversing all templates, a corresponding similarity list is generated. For example, the similarity of the video stream template is 0.92, the IoT data template is 0.75, and the malicious attack template is 0.35.
[0057] Templates with cosine similarity higher than the first preset threshold are selected from all traffic category templates as candidate categories. The setting of the preset threshold is determined based on experimental data and actual application requirements to balance classification accuracy and false alarm rate. If the similarity of a template exceeds the threshold, it is judged to have potential matching. For example, the video stream template 0.92 and the IoT data template 0.75 meet the threshold conditions, while the malicious attack template 0.35 is excluded. The screened candidate categories constitute a high-confidence candidate set, providing input for subsequent corrections. This step can quickly exclude traffic type templates that are significantly different from the traffic characteristics of the target device, narrow the scope of subsequent judgments, and improve classification efficiency. At the same time, it also ensures that the candidate category has a certain degree of similarity with the traffic characteristics of the target device, providing a preliminary guarantee for accurate classification.
[0058] According to the stability coefficient of the electromagnetic fingerprint identification, the cosine similarity of each candidate category is weighted and corrected to obtain the corrected similarity of each candidate category. The stability coefficient of the electromagnetic fingerprint identification is an indicator to measure the stability of the electromagnetic fingerprint in different time and environment. It reflects the reliability of the hardware characteristics of the device represented by the electromagnetic fingerprint. The higher the stability coefficient, the more stable the electromagnetic fingerprint is, and the greater its weight in traffic classification. When weighted correction is performed on the cosine similarity of the candidate category, the cosine similarity of each candidate category is multiplied by the stability coefficient of its corresponding electromagnetic fingerprint identification to obtain the corrected similarity. The stability coefficient ranges from 0 to 1. For example, if the stability coefficient of a device is 0.9, the original similarity of the video stream template is 0.92, and it is 0.828 after correction; if the original similarity of the IoT data template is 0.75, it is 0.675 after correction. This step reduces the risk of misjudgment caused by short-term fluctuations in the electromagnetic fingerprint by introducing hardware feature stability, and improves long-term classification reliability.
[0059] The candidate category with the highest corrected similarity is determined as the traffic type of the target network device. For example, if the corrected similarity of the video stream template is 0.828 and that of the IoT data template is 0.675, the traffic type is determined to be a video stream. If the corrected similarities of multiple candidate categories are the same, the category with a higher preset priority is preferred (e.g., the malicious attack category has a higher priority than normal traffic). The final classification result is output through the device interface or network protocol, triggering the corresponding security policy or routing optimization operation to achieve precise traffic management and threat interception.
[0060] In some examples, it also includes: When the cosine similarities of all traffic category templates are lower than the first preset threshold, marking the multidimensional classification feature vector as an unknown type, and generating a new traffic class template based on the multidimensional classification feature vector; The new traffic class template is matched and associated with the historical abnormal behavior pattern in the abnormal behavior database.
[0061] Exemplarily, when it is detected that the cosine similarity of all traffic category templates is lower than the first preset threshold, the multidimensional classification feature vector is marked as an unknown type. The first preset threshold is used to measure the similarity between the multidimensional classification feature vector and the known traffic category template. If it is lower than this threshold, it indicates that the traffic characteristics represented by the current multidimensional classification feature vector are greatly different from the known traffic categories and cannot be matched to any existing traffic category template. At this time, it is marked as an unknown type, which is a preliminary identification of abnormal traffic, providing an identification for subsequent further analysis and processing, so that the system can concentrate resources to conduct in-depth research on this type of special traffic to determine its potential threats or characteristics.
[0062] Based on the multidimensional classification feature vectors marked as unknown types, the system starts the dynamic generation process of new traffic category templates. First, the unsupervised clustering algorithm DBSCAN is used to group the unknown feature vectors in the temporary feature library to identify potential new traffic patterns. The center vector of each cluster is calculated as the feature representation of the new template and assigned a unique category identifier. Subsequently, the new template is added to the preset traffic category template library, and its generation time, associated devices, and initial matching rules are recorded. For example, a new template reflects the traffic behavior of an unknown encryption protocol, and its identifier is "Encrypted Traffic_New". This process breaks through the limitations of traditional classification methods that rely on fixed templates through an automated template expansion mechanism, and improves the system's adaptability to new traffic patterns.
[0063] The generated new traffic category template needs to be matched and associated with the historical abnormal patterns in the abnormal behavior database to assess its potential threat. During the matching process, the cosine similarity between the new template feature vector and all abnormal features in the abnormal database is calculated, and entries with a similarity higher than the second preset threshold are screened out. If the match is successful, the new template is associated with the threat level and feature description of the corresponding abnormal behavior. For example, if a new template has a similarity of 0.85 with the "DDoS attack pattern" in the database, it is marked as a "potential DDoS variant" and triggers a predefined security response strategy (such as traffic speed limit or session blocking). This step quickly maps unknown traffic to the historical attack knowledge base through a real-time association mechanism, shortens the threat response time, and enhances the system's defense capabilities against unknown attacks.
[0064] After the new template generation and anomaly association are completed, the adaptive learning process is started to continuously optimize the classification model. First, the new template and its associated anomaly features are input into the classification model, and the model parameters are updated through incremental learning to improve the recognition accuracy of new traffic patterns. Secondly, the effectiveness of the templates in the template library is regularly evaluated, and entries that have not been matched for a long time or have a high false alarm rate are removed to ensure the timeliness and accuracy of the template library. At the same time, verified new threat patterns are added to the anomaly database to improve the coverage of the attack feature library. For example, after the feature description and defense strategy of a new DDoS variant are included in the database, the system can automatically intercept subsequent similar attacks. This closed-loop optimization mechanism enables the system to dynamically adapt to changes in the network environment and the evolution of attack methods, and realize the continuous evolution of security protection capabilities.
[0065] See also Figure 2 , is a schematic diagram of the structure of a network traffic classification device provided in an embodiment of the present application, including: The device data acquisition unit 21 is used to acquire the electromagnetic radiation signal and historical communication behavior sequence of the target network device; The frequency domain feature extraction unit 22 extracts a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal; A fingerprint identification generating unit 23 generates an electromagnetic fingerprint identification of a target network device based on the first frequency domain feature; A time series feature extraction unit 24 extracts a second time series feature from the historical communication behavior sequence based on the historical communication behavior sequence; A feature vector fusion unit 25 is used to jointly encode the electromagnetic fingerprint identification and the second time series feature to generate a multi-dimensional classification feature vector; The traffic type confirmation unit 26 generates the traffic type of the target network device based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template.
[0066] See also Figure 3The embodiment of the present application also provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor. When the processor 320 executes the computer program 311, the steps of any method of network traffic classification are implemented.
[0067] Since the electronic device introduced in this embodiment is a device used to implement a network traffic classification device in the embodiment of the present application, based on the method introduced in the embodiment of the present application, the technical personnel in this field can understand the specific implementation mode of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of the present application is not introduced in detail here. As long as the equipment used by the technical personnel in this field to implement the method in the embodiment of the present application is within the scope of protection of this application.
[0068] During the specific implementation process, when the computer program 311 is executed by a processor, any implementation method in the embodiments corresponding to the first aspect can be implemented.
[0069] It should be noted that in the above embodiments, the description of each embodiment has its own emphasis, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0070] It should be understood by those skilled in the art that the embodiments of the present application may provide methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-readable storage media containing computer-readable program code.
[0071] The present application is described with reference to flowcharts and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0072] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0073] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0074] The present application also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device executes Figure 1 A process of a network traffic classification method in the corresponding embodiment.
[0075] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired or wireless means. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more available media integration. The available medium can be a magnetic medium, an optical medium or a semiconductor medium, etc.
[0076] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0077] In the several embodiments provided in the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0078] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0079] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated units may be implemented in the form of hardware and / or software functional units.
[0080] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device to execute all or part of the steps of the various embodiments of the present application.
[0081] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
[0082] Although the preferred embodiments of this specification have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of this specification.
[0083] Obviously, those skilled in the art can make various changes and modifications to this specification without departing from the spirit and scope of this specification. Thus, if these modifications and modifications of this specification fall within the scope of the claims of this specification and their equivalents, this specification is also intended to include these modifications and modifications.
Claims
1. A network traffic classification method, characterized in that: The method comprises: Obtain the electromagnetic radiation signals and historical communication behavior sequences of target network devices; Based on the electromagnetic radiation signal, extracting a first frequency domain feature in the electromagnetic radiation signal; Generating an electromagnetic fingerprint identification of the target network device based on the first frequency domain feature; Based on the historical communication behavior sequence, extracting a second time series feature in the historical communication behavior sequence; Jointly encoding the electromagnetic fingerprint identifier and the second time series feature to generate a multi-dimensional classification feature vector; Based on the matching degree between the multi-dimensional classification feature vector and a preset traffic category template, the traffic type of the target network device is generated.
2. The method according to claim 1, characterized in that: The extracting a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal comprises: Performing wavelet packet decomposition on the electromagnetic radiation signal to extract the energy distribution ratio within a preset frequency band; The energy distribution ratio is subjected to nonlinear dimensionality reduction by a convolutional autoencoder to generate a first frequency domain feature containing an inherent noise feature of a hardware circuit.
3. The method according to claim 1, characterized in that: The generating the electromagnetic fingerprint identification of the target network device based on the first frequency domain feature includes: Performing cluster analysis on the first frequency domain feature to generate a cluster center vector uniquely corresponding to the hardware circuit of the target network device; The cluster center vector is mapped to a preset electromagnetic fingerprint identification library to generate an electromagnetic fingerprint identification in the form of a digital code, and the cluster center vector is associated with the digital code and stored; wherein the preset electromagnetic fingerprint identification library stores the mapping relationship between the digital code and the cluster center vector.
4. The method according to claim 1, characterized in that: The extracting, based on the historical communication behavior sequence, a second time series feature in the historical communication behavior sequence includes: Counting the traffic burst interval, data packet length distribution and retransmission rate in the historical communication behavior sequence according to a preset time window to generate a time series of statistical behavior characteristics; The periodic pattern of the time series is extracted through a long short-term memory network to obtain a second time series feature that characterizes the dynamic change of the flow.
5. The method according to claim 3, characterized in that: The step of jointly encoding the electromagnetic fingerprint identifier and the second time series feature to generate a multi-dimensional classification feature vector includes: According to the electromagnetic fingerprint identification, obtaining a corresponding cluster center vector from the preset electromagnetic fingerprint identification library; Normalizing the cluster center vector to generate a first eigenvector; Performing standardization processing on the second time series feature to generate a second feature vector; The first feature vector and the second feature vector are concatenated according to a preset dimension, and feature fusion is performed through a fully connected layer to generate the multidimensional classification feature vector.
6. The method according to claim 1, characterized in that The generating the traffic type of the target network device based on the matching degree between the multi-dimensional classification feature vector and the preset traffic category template includes: Calculating the cosine similarity between the multidimensional classification feature vector and each of the preset multiple traffic category templates; Selecting a template whose cosine similarity is higher than a first preset threshold from the multiple traffic category templates as a candidate category; According to the stability coefficient of the electromagnetic fingerprint identification, the cosine similarity of each candidate category is weighted and corrected to obtain the corrected similarity of each candidate category; The candidate category with the highest value in the modified similarity is determined as the traffic type of the target network device.
7. The method according to claim 6, characterized in that Also includes: When the cosine similarities of all traffic category templates are lower than the first preset threshold, Marking the multidimensional classification feature vector as an unknown type, and generating a new traffic category template based on the multidimensional classification feature vector; The new traffic category template is matched and associated with the historical abnormal behavior pattern in the abnormal behavior database.
8. A network traffic classification device, characterized in that: The device comprises: A device data acquisition unit, used to acquire electromagnetic radiation signals and historical communication behavior sequences of target network devices; A frequency domain feature extraction unit, which extracts a first frequency domain feature from the electromagnetic radiation signal based on the electromagnetic radiation signal; A fingerprint identification generating unit, which generates an electromagnetic fingerprint identification of the target network device based on the first frequency domain feature; A time series feature extraction unit, based on the historical communication behavior sequence, extracts a second time series feature in the historical communication behavior sequence; A feature vector fusion unit, used for jointly encoding the electromagnetic fingerprint identification and the second time series feature to generate a multi-dimensional classification feature vector; The traffic type confirmation unit generates the traffic type of the target network device based on the matching degree between the multi-dimensional classification feature vector and a preset traffic category template.
9. An electronic device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor is used to implement the steps of the network traffic classification method as described in any one of claims 1 to 7 when executing the computer program stored in the memory.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the network traffic classification method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Concrete active crack electromagnetic radiation signal identification method based on GoogLeNet neural network
CN117421630A
Equipment identification and access method and device based on radio frequency information and network traffic
CN118714567A
GIS equipment breakdown signal analysis method and system based on hierarchical networking structure
CN118965107A
Systems and methods for attacker temporal behavior fingerprinting and grouping with spectrum interpretation and deep learning
US10645100B1
Cited By
Wireless communication test method and system based on portable frequency spectrograph, and medium
CN121194188A
Smart home scenarized audio linkage control system based on multi-mode perception
CN121523081A