Encrypted network traffic classification method based on structured state space dual model
By adopting a structured state space dual (SSD) model and masked autoencoder structure in the encrypted network traffic classification, the problem of inefficient computing and memory in the prior art is solved, and a more efficient encrypted traffic classification is achieved.
Patent Information
- Application Number
- CN202510147887.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-11
AI Technical Summary
The prior art has problems of inefficiency in computing and memory in encrypted network traffic classification, especially when dealing with ultra-long sequences.
The encrypted network traffic classification method based on the structured state space dual (SSD) model is adopted to generate a stride sequence through data preprocessing, and a pre-trained encrypted network traffic classification model is used for classification, and self-supervised pre-training and fine-tuning optimization is performed in combination with the masked autoencoder structure.
While maintaining low GPU memory usage, it improves inference speed and achieves more efficient and effective encrypted traffic classification.
Smart Images

Figure CN120067803A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network information security, and particularly relates to an encrypted network traffic classification method based on a structured state space dual model. Background Art
[0002] Network traffic classification refers to the technology of identifying, classifying, and analyzing the traffic transmitted in the Internet or local area network, and is used to distinguish different types of network applications, protocols, devices, etc. With the increase in the scale and complexity of the network, the importance of network traffic classification in network management, performance optimization, traffic monitoring, security analysis, etc. has become increasingly prominent. An overview of the general framework for encrypted traffic classification, in which four components have been developed, namely traffic collection, traffic representation, traffic classification method, and performance evaluation.
[0003] Original traffic representation, that is, using frameworks or models such as deep learning algorithms to automatically extract features. Generally, traffic is encoded as a sequence, graph, or image for classification. For example, traffic can be abstracted as a graph. The structure of the graph can be regarded as a set of interconnected nodes, and each node is regarded as a data packet. This is similar to the definition of a graph in data structures and can be enhanced through direction, weight, etc.
[0004] Traffic classification method based on pre-training. Recently, pre-training has become a popular model training paradigm in natural language processing (NLP) and computer vision (CV). Driven by this trend, several pre-trained traffic models based on Transformer have been developed to learn general traffic representations from a large amount of unlabeled data, and then fine-tune specific downstream tasks using limited labeled traffic data. Through self-supervised learning, the pre-training method greatly reduces the need for labeled training data. In addition, the unbiased data representation learned from a large amount of unlabeled data can further improve the performance of downstream tasks. The pre-training method first uses unlabeled data to obtain a pre-trained model, and then loads the model parameters to complete the downstream tasks. The pre-trained model can be fine-tuned on a small amount of task-specific labeled data and achieve state-of-the-art performance in the encrypted traffic classification task. In addition, since the input traffic bytes lack clear high-level semantic units, some studies have used CV tasks to extract the latent representation of traffic bytes and achieved good performance on real-world traffic datasets.
[0005] Structured State Space Duality (SSD) is an advanced technology for sequence modeling and long-distance dependence problems. Based on the theoretical basis of the State Space Model (SSM) and combined with the mathematical structure of duality, it achieves efficient computation and excellent performance of the model. Traditional sequence modeling methods (such as RNN, LSTM, GRU) perform poorly when dealing with long sequences because they are difficult to effectively capture long-distance dependencies and have a high computational complexity. Although Transformer overcomes this problem, the computational complexity of its attention mechanism is O(n²), which is not efficient when dealing with extremely long sequences. The SSD technology realizes sequence modeling with linear time complexity by introducing the mathematical properties of the State Space Model (SSM) and duality, thus being able to efficiently process extremely long sequences. Summary of the Invention
[0006] The object of the present invention is to overcome the deficiencies in the prior art and provide an encrypted network traffic classification method based on a structured state space duality model, which improves the inference speed while maintaining low GPU memory usage, and is conducive to more efficient and effective implementation of encrypted traffic classification.
[0007] To solve the above technical problems, the present invention is implemented by adopting the following technical solutions:
[0008] The present invention provides an encrypted network traffic classification method based on a structured state space duality model, including:
[0009] Perform data preprocessing on the encrypted network traffic to be classified to obtain a stride sequence;
[0010] Input the stride sequence into a pre-trained encrypted network traffic classification model for traffic classification to obtain a classification result;
[0011] The data preprocessing includes:
[0012] Obtain pcap data packets in the encrypted network traffic;
[0013] Extract the hierarchical flow information in the pcap traffic packet and generate a stride sequence according to the hierarchical flow information;
[0014] The training of the encrypted network traffic classification model includes:
[0015] Obtain an encrypted network traffic dataset, including labeled data and unlabeled data;
[0016] Build an initial encrypted network traffic classification model through a masked autoencoder structure, including a model encoder and a model decoder;
[0017] Perform self-supervised pre-training on the initial encrypted network traffic classification model according to the unlabeled data, and learn the general representation of traffic data through the reconstruction masking step;
[0018] Replace the model decoder with a multi-layer perceptron head, fine-tune and optimize the model through the labeled data, improve the general representation of the traffic data, and obtain a trained encrypted network traffic classification model.
[0019] Optionally, extracting the hierarchical flow information from the pcap traffic packet and generating a stride sequence according to the hierarchical flow information includes:
[0020] Group the pcap traffic packets according to the five-tuple (source IP, destination IP, source port, destination port, protocol type) of the pcap traffic packet to form different flows;
[0021] Process the pcap traffic packets in each flow, and extract the fixed-size header and payload bytes;
[0022] Arrange the header and payload bytes in sequence to form a unified byte array;
[0023] Divide the byte array into non-overlapping stride sequences, and each stride contains a fixed number of bytes.
[0024] Optionally, the processing of the pcap traffic packets in each flow includes:
[0025] When analyzing the traffic data of a specific application or service, exclude all pcap traffic packets carried by non-ip protocols, while retaining the payload and total length fields, removing the Ethernet header, and masking the IP address.
[0026] Optionally, performing self-supervised pre-training on the initial encrypted network traffic classification model and learning the general representation of traffic data through the reconstruction masking step includes:
[0027] Perform data preprocessing on the unlabeled data to obtain a stride sequence;
[0028] Perform embedding processing on the stride sequence, including word embedding and position embedding, to obtain an embedded stride sequence;
[0029] According to the embedded stride sequence, randomly select a certain proportion of strides for masking processing to obtain a masked stride sequence;
[0030] Input the embedded stride sequence and the masked stride sequence into the model encoder for feature extraction to obtain an encoded representation that can represent the entire stride sequence;
[0031] Concatenate the encoded representation with the mask flag, restore it to the original sequence order, and add the position embedding specific to the model decoder to obtain the input to the model decoder;
[0032] Input the input to the model decoder into the model decoder, and use the feature representation generated by the model encoder to reconstruct the strides masked in the input;
[0033] Optimize the pre-training by minimizing the reconstruction loss of the masked strides.
[0034] Optionally, the embedding process for the stride sequence includes:
[0035] For each stride in the stride sequence Perform a linear projection to obtain a vector of size and add the position embedding to obtain the embedded stride sequence which is specifically implemented through the following embedding formula:
[0036] (1)
[0037] Where, represents the embedded stride sequence, represents the -th stride in the stride sequence, represents the learnable projection matrix, represents the continuous byte length of the non-overlapping data stream stride sequence, i.e., the number of rows of the projection matrix, represents the hidden state dimension of the encoder, i.e., the number of columns of the projection matrix, is a class token, represents the position embedding matrix, represents the total number of individual data stream stride sequences, i.e., the number of rows of the position embedding matrix.
[0038] Optionally, randomly selecting a certain proportion of strides for masking includes:
[0039] According to the embedded stride sequence, randomly sample a part of the strides, and at the same time remove the remaining strides for masking to obtain the masked stride sequence, which is specifically implemented through the following masking formula:
[0040] (2)
[0041] Where, represents the masked stride sequence, represents the embedded stride sequence, represents the length of the embedded stride sequence, represents the randomly permuted embedded stride sequence , Indicates the length of the visible marker, Indicates the predefined mask ratio.
[0042] Optionally, the calculation formula of the reconstruction loss is as follows:
[0043] (3)
[0044] Wherein, Indicates the mean square error loss of self-supervised reconstruction, Indicates the mean square error function, Indicates the true masked marker, Indicates the predicted marker.
[0045] Optionally, the model encoder is implemented by the SSD model framework and includes the following steps:
[0046] After normalizing the input sequence, project it into and respectively through two parallel linear projection layers;
[0047] Apply causal one-dimensional convolution to while generating parameter , and send parameter and the convolved to the state space model SSM to calculate the output ;
[0048] Pass to gate-control the output to obtain the output result, and normalize the output result;
[0049] Perform a residual connection on the normalized output result and the original input to obtain the final output.
[0050] Optionally, the state space model SSM establishes a mapping from the input sequence to the output sequence through the intermediate latent state , and the specific formula is as follows:
[0051] (4)
[0052] Wherein, Indicates the intermediate parameter.
[0053] Optionally, the fine-tuning and optimization of the model using the marker data includes:
[0054] Fine-tune in a supervised manner, and the calculation formula is as follows:
[0055] (5)
[0056] Among them, represents the encoding function, represents the normal form function, represents the multi-layer perceptron, represents the length of the post-embedded stride sequence, represents the prediction distribution;
[0057] The classification process is optimized by minimizing the cross-entropy loss between the prediction distribution and the true label, and the calculation formula is as follows:
[0058] (6)
[0059] Among them, represents the cross-entropy loss between the prediction distribution and the true label, represents the cross-entropy loss function, represents minimizing the prediction distribution, represents the true label.
[0060] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: It solves the optimization problem of the existing methods for encrypted network traffic classification based on the structured state space dual model in the current research in the field of deep learning; based on the structured state space dual model, it solves the problem of low computational and memory efficiency faced due to the quadratic complexity of the self-attention mechanism, improves the inference speed while maintaining low GPU memory usage, and is conducive to more efficient and effective implementation of encrypted traffic classification. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 is a flowchart of the encrypted network traffic classification method based on the structured state space dual model provided by an embodiment of the present invention;
[0062] Figure 2 is a flowchart of the training of the encrypted network traffic classification model provided by an embodiment of the present invention;
[0063] Figure 3 is a flowchart of extracting hierarchical flow information from pcap traffic packets and generating a stride sequence provided by an embodiment of the present invention;
[0064] Figure 4 is a flowchart of self-supervised pre-training and reconstruction mask steps provided by an embodiment of the present invention;
[0065] Figure 5 is a flowchart of the SSD model framework provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0066] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of the present application and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Without conflict, the technical features in the embodiments of the present application and the embodiments can be combined with each other.
[0067] It should be noted that the term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0068] Embodiment 1:
[0069] An embodiment of the present invention discloses an encrypted network traffic classification method based on a structured state space dual model. Referring to Figure 1 as shown, the specific steps are as follows:
[0070] S1. Preprocess the encrypted network traffic to be classified to obtain a stride sequence;
[0071] S2. Input the stride sequence into a pre-trained encrypted network traffic classification model for traffic classification to obtain a classification result.
[0072] Specifically,
[0073] In step S1, the data preprocessing includes:
[0074] S1.1. Obtain the pcap data packets in the encrypted network traffic;
[0075] S1.2. Extract the hierarchical flow information from the pcap traffic packets and generate a stride sequence according to the hierarchical flow information.
[0076] Referring to Figure 3 as shown, in step S1.2, extracting the hierarchical flow information from the pcap traffic packets and generating a stride sequence according to the hierarchical flow information includes:
[0077] Group the pcap traffic packets according to the five-tuple (source IP, destination IP, source port, destination port, protocol type) of the pcap traffic packets to form different flows;
[0078] Process the pcap traffic packets in each flow, and extract the fixed-size headers and payload bytes;
[0079] Arrange the headers and payload bytes in sequence to form a unified byte array;
[0080] Split the byte array into a sequence of non-overlapping strides, each stride containing a fixed number of bytes.
[0081] Among them, processing the data packet includes excluding all data packets carried by non-IP protocols when analyzing traffic data of a specific application or service, while retaining key information such as the payload and total length fields, and removing the Ethernet header and masking the IP address.
[0082] Reference Figure 2 As shown in the figure, in step S2, the training of the encrypted network traffic classification model includes:
[0083] S2.1, Obtain an encrypted network traffic data set, including labeled data and unlabeled data;
[0084] S2.2, Build an initial encrypted network traffic classification model through a masked autoencoder structure, including a model encoder and a model decoder;
[0085] S2.3, According to the unlabeled data, perform self-supervised pre-training on the initial encrypted network traffic classification model, and learn the general representation of traffic data through the reconstruction mask step;
[0086] S2.4, Replace the model decoder with a multi-layer perceptron head, fine-tune and optimize the model through the labeled data, improve the general representation of the traffic data, and obtain a trained encrypted network traffic classification model.
[0087] In this embodiment, the encrypted network traffic data set is mainly obtained by collecting and using an open-source data set. For example, the itc-net-blend-60 collects network traffic from more than 50 Android applications in 5 network scenarios.
[0088] Reference Figure 4 As shown in the figure, in step S2.3, performing self-supervised pre-training on the initial encrypted network traffic classification model and learning the general representation of traffic data through the reconstruction mask step includes:
[0089] S2.3.1, Perform data preprocessing on the unlabeled data to obtain a stride sequence;
[0090] S2.3.2, Perform embedding processing on the stride sequence, including word embedding and position embedding, to obtain an embedded stride sequence;
[0091] S2.3.3, According to the embedded stride sequence, randomly select a certain proportion of strides for masking processing to obtain a masked stride sequence;
[0092] S2.3.4. Input the embedded stride sequence and the masked stride sequence into the model encoder for feature extraction to obtain an encoded representation that can represent the entire stride sequence.
[0093] S2.3.5. Concatenate the encoded representation with the mask flag, restore it to the original sequence order, and add the position embedding specific to the model decoder to obtain the input to the model decoder.
[0094] S2.3.6. Input the input to the model decoder into the model decoder and use the feature representation generated by the model encoder to reconstruct the strides masked in the input.
[0095] S2.3.7. Optimize the pre-training by minimizing the reconstruction loss of the masked strides.
[0096] In step S2.3.2, the embedding process of the stride sequence includes:
[0097] For each stride in the stride sequence perform a linear projection to obtain a vector of size and add the position embedding to obtain the embedded stride sequence which is specifically implemented through the following embedding formula:
[0098] (1)
[0099] where represents the embedded stride sequence, represents the th stride in the stride sequence, represents the learnable projection matrix, represents the continuous byte length of the non-overlapping data stream stride sequence, i.e., the number of rows of the projection matrix, represents the hidden state dimension of the encoder, i.e., the number of columns of the projection matrix, is a class token representing the entire stride sequence, appended at the end of the sequence, represents the position embedding matrix, represents the total number of individual data stream stride sequences, i.e., the number of rows of the position embedding matrix.
[0100] In step S2.3.3, randomly selecting a certain proportion of strides for masking includes:
[0101] According to the embedded stride sequence, randomly sample a part of the strides, and at the same time remove the remaining strides for masking to obtain the masked stride sequence, which is specifically implemented through the following masking formula:
[0102] (2)
[0103] Among them, represents the masked stride sequence, represents the embedded stride sequence, represents the length of the embedded stride sequence, represents the randomly permuted embedded stride sequence , represents the length of the visible tokens, represents the predefined masking ratio.
[0104] In step S2.3.7, the calculation formula of the reconstruction loss is as follows:
[0105] (3)
[0106] Among them, represents the mean squared error loss of self-supervised reconstruction, represents the mean squared error function, represents the true masked tokens, represents the predicted tokens.
[0107] Refer to Figure 5 As shown, in step S2.2, the model encoder is implemented by the SSD model framework, including the following steps:
[0108] After normalizing the input sequence, project it into and respectively through two parallel linear projection layers;
[0109] Apply causal one-dimensional convolution to , and simultaneously generate the parameter . Send the parameter and the convolution result of into the state space model (SSM: State Space Model) to calculate the output ;
[0110] Perform gated control on the output through to obtain the output result, and normalize the output result;
[0111] Perform a residual connection on the normalized output result and the original input to obtain the final output.
[0112] Among them, the state space model (SSM) represents a class of modern sequence models in deep learning, which has extensive connections with recurrent neural networks (RNN) and convolutional neural networks (CNN).
[0113] Inspired by continuous systems, SSMs are typically constructed as linear ordinary differential equations (ODEs), through intermediate latent states to establish a mapping from the input sequence to the output sequence The specific formula is as follows:
[0114] (4)
[0115] where represents the intermediate parameter.
[0116] The Structured State Space Duality (SSD) model adds "duality" to the original SSM model, that is, the equation , in the case of the scalar identity structure A, and the equation are actually exactly the same model, which requires the diagonal parameter A to further become a scalar multiplied by the identity matrix structure.
[0117] In step S2.4, the decoder is replaced with a multi-layer perceptron head, and the model is fine-tuned with limited labeled data to improve the flow representation. In the fine-tuning stage, all encoder parameters, including the embedding module and the mamba-2 module, are loaded from pre-training, the decoder is replaced with an MLP head, and the fine-tuning is performed in a supervised manner. The formula is as follows:
[0118] (5)
[0119] where represents the encoding function, represents the normalization function, represents the multi-layer perceptron, represents the length of the post-embedded stride sequence, represents the prediction distribution;
[0120] The classification process is optimized by minimizing the cross-entropy loss between the prediction distribution and the true label. The calculation formula is as follows:
[0121] (6)
[0122] where represents the cross-entropy loss between the prediction distribution and the true label, represents the cross-entropy loss function, represents the minimized prediction distribution, represents the true label.
[0123] After the model training is completed, perform the downstream encrypted network traffic classification task based on the improved traffic representation using the structured state space dual model. Finally, different encrypted traffic should be correctly classified.
[0124] In summary, the encrypted network traffic classification method based on the structured state space dual model provided by the present invention obtains pcap data packets in the encrypted network traffic, extracts the hierarchical flow information in the original pcap traffic packets, and generates a stride sequence therefrom; inputs the stride sequence into the model, uses the masked autoencoder structure to perform self-supervised pre-training on a large amount of unlabeled data, and learns the general representation of the traffic data through reconstructing the masked steps; replaces the decoder with a multi-layer perceptron head, fine-tunes the model with a limited amount of labeled data to improve the traffic representation; performs encrypted network traffic classification based on the improved traffic representation using the structured state space dual model; while keeping the GPU memory usage low, improves the inference speed, which is beneficial to more efficient and effective implementation of encrypted traffic classification.
[0125] Embodiment 2:
[0126] Based on the same inventive concept as Embodiment 1, the embodiment of the present invention discloses an encrypted network traffic classification system based on the structured state space dual model, including:
[0127] A preprocessing module: used for: performing data preprocessing on the encrypted network traffic to be classified to obtain a stride sequence;
[0128] An encrypted network traffic classification module based on the structured state space dual model, used for: inputting the stride sequence into a pre-trained encrypted network traffic classification model for traffic classification to obtain a classification result.
[0129] Specifically,
[0130] The data preprocessing includes:
[0131] Obtaining pcap data packets in the encrypted network traffic;
[0132] Extracting the hierarchical flow information in the pcap traffic packets and generating a stride sequence according to the hierarchical flow information.
[0133] The training of the encrypted network traffic classification model includes:
[0134] Obtaining an encrypted network traffic data set, including labeled data and unlabeled data;
[0135] Building an initial encrypted network traffic classification model through a masked autoencoder structure, including a model encoder and a model decoder;
[0136] Based on the unlabeled data, perform self-supervised pre-training on the initial encrypted network traffic classification model, and learn the general representation of traffic data through the reconstruction mask step;
[0137] Replace the model decoder with a multi-layer perceptron head, fine-tune and optimize the model through the labeled data, improve the general representation of the traffic data, and obtain a trained encrypted network traffic classification model.
[0138] For the specific functional implementation of each of the above modules, refer to the relevant content in the method of Embodiment 1, which will not be elaborated.
[0139] Embodiment 3:
[0140] This embodiment provides a computer-readable storage medium, on which a computer program / instructions are stored. When the computer program / instructions are executed by a processor, the steps of the encrypted network traffic classification method based on the structured state space dual model described in any one of Embodiment 1 are implemented.
[0141] Embodiment 4:
[0142] This embodiment provides a computer device / system, including:
[0143] A memory for storing computer programs / instructions;
[0144] A processor for executing the computer programs / instructions to implement the steps of the encrypted network traffic classification method based on the structured state space dual model described in any one of the first aspect.
[0145] Embodiment 5:
[0146] This embodiment provides a computer program product, including computer programs / instructions, characterized in that when the computer programs / instructions are executed by a processor, the steps of the encrypted network traffic classification method based on the structured state space dual model described in any one of Embodiment 1 are implemented.
[0147] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0148] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0149] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0151] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the present invention and the claims. All of these fall within the protection scope of the present invention.
Claims
1. A method for classifying encrypted network traffic based on a structured state space dual model, characterized in that: include: Perform data preprocessing on the encrypted network traffic to be classified to obtain a stride sequence; Inputting the stride sequence into a pre-trained encrypted network traffic classification model to perform traffic classification and obtain a classification result; The data preprocessing includes: Get pcap packets in encrypted network traffic; Extracting layered flow information from the pcap traffic packet, and generating a stride sequence according to the layered flow information; The training of the encrypted network traffic classification model includes: Obtain encrypted network traffic datasets, including labeled and unlabeled data; Build an initial encrypted network traffic classification model through a masked autoencoder structure, including a model encoder and a model decoder; Based on the unlabeled data, the initial encrypted network traffic classification model is self-supervised pre-trained, and a universal representation of the traffic data is learned by reconstructing a mask step; The model decoder is replaced with a multi-layer perceptron head, the model is fine-tuned and optimized through the labeled data, the general representation of the traffic data is improved, and a trained encrypted network traffic classification model is obtained.
2. The encrypted network traffic classification method based on the structured state space dual model according to claim 1 is characterized in that: Extracting the layered flow information in the pcap flow packet and generating a stride sequence according to the layered flow information includes: The pcap traffic packets are grouped according to the five-tuple (source IP, destination IP, source port, destination port, protocol type) of the pcap traffic packets to form different flows; Process the pcap traffic packets in each stream and extract the fixed-size header and payload bytes; Arranging the header and payload bytes in order to form a unified byte array; Split the byte array into a non-overlapping sequence of strides, each containing a fixed number of bytes.
3. The encrypted network traffic classification method based on the structured state space dual model according to claim 2 is characterized in that: The pcap flow packets in each stream are processed as follows: When analyzing traffic data of a specific application or service, all pcap traffic packets carried by non-IP protocols are excluded, while retaining the payload and total length fields, removing the Ethernet header, and masking the IP address.
4. The encrypted network traffic classification method based on the structured state space dual model according to claim 1 is characterized in that: The initial encrypted network traffic classification model is self-supervised pre-trained and a general representation of traffic data is learned by reconstructing the mask step, including: Performing data preprocessing on the unlabeled data to obtain a stride sequence; Performing embedding processing on the stride sequence, including word embedding and position embedding, to obtain an embedded stride sequence; According to the embedded stride sequence, a certain proportion of strides are randomly selected for masking to obtain a masked stride sequence; Inputting the embedded stride sequence and the masked stride sequence into a model encoder to perform feature extraction to obtain an encoding representation that can represent the entire stride sequence; The encoding representation is concatenated with the mask flag, restored to the original sequence order, and embedded with the position specific to the model decoder to obtain the model decoder input; Inputting the model decoder input into the model decoder, using the feature representation generated by the model encoder to reconstruct the stride that was masked in the input; Pre-training is optimized by minimizing the reconstruction loss with respect to the masked stride.
5. The encrypted network traffic classification method based on the structured state space dual model according to claim 4 is characterized in that: The embedding process of the stride sequence includes: For each stride in the stride sequence Perform linear projection and get the size vector and add position embedding , get the embedded stride sequence , which is implemented by the following embedding formula: (1) in, represents the sequence of strides after embedding, Indicates the stride sequence stride, represents the learnable projection matrix, The length of the continuous byte sequence representing the non-overlapping data stream stride, i.e. the number of rows in the projection matrix, represents the hidden state dimension of the encoder, that is, the number of columns of the projection matrix, For a class label, represents the position embedding matrix, Represents the total number of sequences of strides for a single data stream, i.e., the number of rows in the position embedding matrix.
6. The encrypted network traffic classification method based on the structured state space dual model according to claim 4 is characterized in that: Randomly select a certain proportion of strides for masking including: According to the embedded stride sequence, a part of the strides is randomly sampled, and the remaining strides are removed, and masking is performed to obtain a masked stride sequence, which is specifically implemented by the following masking formula: (2) in, represents the stride sequence after masking, represents the sequence of strides after embedding, represents the length of the stride sequence after embedding, Represents the stride sequence after random permutation embedding , Indicates the length of the visible mark, Indicates a predefined mask ratio.
7. The encrypted network traffic classification method based on the structured state space dual model according to claim 4 is characterized in that: The calculation formula of the reconstruction loss is as follows: (3) in, represents the mean squared error loss of self-supervised reconstruction, represents the mean square error function, represents the true mask mark, A marker indicating a prediction.
8. The encrypted network traffic classification method based on the structured state space dual model according to claim 1 is characterized in that: The model encoder is implemented by the SSD model framework, including the following steps: After the input sequence is normalized, it is projected into and ; right Apply a causal 1D convolution, generating parameters simultaneously , the parameters And after convolution Input into the state space model SSM to calculate the output ; pass Output Perform gate control to obtain output results, and normalize the output results; The normalized output result is residually connected with the original input to obtain the final output.
9. The encrypted network traffic classification method based on the structured state space dual model according to claim 8 is characterized in that: The state space model SSM consists of intermediate latent states Build from input sequence To the output sequence The mapping is as follows: (4) in, Indicates an intermediate parameter.
10. The encrypted network traffic classification method based on structured state space dual model according to claim 1 is characterized in that: The fine-tuning and optimizing the model by using the labeled data includes: Fine-tuning is performed in a supervised manner, and the calculation formula is as follows: (5) in, represents the encoding function, represents the normal form function, represents a multi-layer perceptron, represents the length of the stride sequence after embedding, represents the predicted distribution; The classification process is optimized by minimizing the cross entropy loss between the predicted distribution and the true label, which is calculated as follows: (6) in, represents the cross entropy loss between the predicted distribution and the true label, represents the cross entropy loss function, represents the minimization of the prediction distribution, represents the true label.
Citation Information
Patent Citations
AES (Advanced Encryption Standard)-based encryption method and device
CN108964872A
Network traffic classification method based on adaptive model of distributed fuzzy support vector machine
CN110008983A
Tor encrypted traffic application behavior classification method and device based on residual network
CN115242496A
Encrypted network traffic classification method based on large language model
CN118523948A
Data encryption method and device, data decryption method and device, equipment and computer storage medium
CN118802229A
Cited By
Pathological image classification method based on state space duality
CN119048825A
A pathological image classification method based on state-space duality
CN119048825B
Encrypted traffic classification model training method, electronic equipment, storage medium and program product
CN120567564A
Network traffic classification method and related device
CN121486340A
Pre-training encrypted traffic classification method based on self-distillation dynamic reasoning acceleration
CN121644468A