Encrypted traffic classification method and system based on pulse convolutional neural network
By using pulse convolutional neural networks in encrypted traffic classification, extracting and fusing the characteristics of packet headers and payloads, the problem of excessive computing resources and energy consumption in the prior art is solved, and encrypted traffic classification with high accuracy and low energy consumption is achieved.
Patent Information
- Application Number
- CN202510149931.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-30
AI Technical Summary
The existing encrypted traffic classification technology has high requirements for computing resources and energy consumption during training and inference, and cannot be deployed in actual conditions. The lightweight method leads to a decrease in classification accuracy.
The encrypted traffic classification method based on pulse convolutional neural network is adopted to build a pulse neural network through convolutional encoder, pulse convolutional encoder, cross-gated gating unit and classifier to extract and fusion the data packet header and payload feature to reduce the model parameter quantity and energy consumption.
While improving the accuracy of encrypted traffic classification, the model parameter volume and energy consumption are significantly reduced, making this method more suitable for actual deployment.
Smart Images

Figure CN120067804A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of traffic classification, and in particular to an encrypted traffic classification method and system based on a spiking convolutional neural network. Background Art
[0002] Existing encrypted traffic classification technologies are mainly implemented through pre-trained model methods. Although such methods improve the accuracy rate, they have certain requirements for computing resources and overheads during both the training and inference processes and cannot be deployed in actual situations. Some lightweight methods are implemented by simplifying the model input and model structure, but this will lead to a decrease in the accuracy rate of classifying encrypted traffic. Summary of the Invention
[0003] In order to at least partially solve the problem of excessive model parameters and energy consumption when classifying traffic according to a model, the present invention provides an encrypted traffic classification method and system based on a spiking convolutional neural network. The present invention uses a convolutional encoder, a spiking convolutional encoder, a cross-gating unit, and a classifier to construct a spiking neural network, which encodes and fuses features of network data packets, thereby improving the classification effect while reducing the model parameters and energy consumption.
[0004] To achieve the above object, the technical solution of the present invention is as follows:
[0005] The first aspect of the present invention proposes an encrypted traffic classification method based on a spiking convolutional neural network, including:
[0006] Step 1: Process the target encrypted traffic data packet to obtain the header and payload of the target encrypted traffic data packet, facilitating the extraction of features of the encrypted traffic.
[0007] Step 2: Input the header and payload of the target encrypted traffic data packet into a convolutional encoder and a spiking convolutional encoder respectively to obtain a header vector and a payload vector, facilitating the obtaining of an effective feature representation.
[0008] Step 3: Input the header vector and the payload vector into a cross-gating unit for feature fusion to obtain a fused feature, facilitating filtering and extraction of effective features.
[0009] Step 4: Input the fused feature into a classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
[0010] Further, the convolutional encoder is represented by the following formula:
[0011] encoder h (h) = MaxPool(Batchnorm(Conv1d(h)))
[0012] Among them, h is the header vector of the message after embedding, d 2 ×d 1 is the dimension of h, encoder h (h) is the header vector, MaxPool is the max pooling layer, Batchnorm is batch normalization, and Conv1d is one-dimensional convolution.
[0013] Furthermore, the pulsed convolutional encoder includes a word embedding unit, a first processing unit, and a second processing unit connected in sequence. Both the first processing unit and the second processing unit include a first convolutional layer, a second convolutional layer, a batch normalization subunit, a pulsed neuron, a first pooling layer, and a second pooling layer;
[0014] The word embedding unit is used to convert the payload into a vector representation to obtain the embedded payload vector, facilitating subsequent extraction of the features of the payload;
[0015] Both the first processing unit and the second processing unit are used to extract the effective features of the embedded payload vector;
[0016] The first convolutional layer is used to perform convolutional processing on the embedded payload vector;
[0017] The second convolutional layer is used to perform convolutional processing on the output of the first convolutional layer;
[0018] The batch normalization subunit is used to perform batch normalization processing on the output of the second convolutional layer;
[0019] The pulsed neuron is used to filter out the invalid noise in the output of the batch normalization subunit and stimulate more pulsed outputs;
[0020] The first pooling layer is used to perform pooling processing on the output of the pulsed neuron;
[0021] The second pooling layer is used to perform pooling processing on the output of the first pooling layer.
[0022] Furthermore, the pulsed convolutional encoder is represented by the following formula:
[0023] encoder p (p) = MaxPool(LIF(Batchnorm(Conv1d(D))))
[0024] D = MaxPool(LIF(Batchnorm(Conv1d(p))))
[0025] Among them, D is the output of the first processing unit, p is the embedded payload vector, d2 ×d 1 is the dimension of the payload vector after embedding, encoder p (p) is the payload vector, LIF is the spiking neuron, MaxPool is the max pooling layer, Batchnorm is the batch normalization, Conv1d is the convolutional layer;
[0026] The spiking convolutional encoder is used to extract key features and reduce network parameters.
[0027] Furthermore, the spiking neuron is represented by the following formula:
[0028] V[t] = H[t] + β(X[t] - (H[t - 1] - V reset ))
[0029] S[t] = Θ(V[t] - V threshold )
[0030] H[t] = V[t] · (1 - S[t])
[0031] where V is the neuron membrane potential, β is the decay factor, X is the input of the spiking neuron, Θ is the step function, H is the reset process of the membrane potential after spiking activation, V reset is the neuron reset membrane potential, S is the firing process of the neuron, V threshold is the threshold potential;
[0032] When the spiking neuron transmits information between different layers, it can gradually accumulate and filter the input signal. The processing of the payload by the entire network will be smoother and more stable, accumulating the effective information of the encrypted traffic, filtering out the invalid noise, and stimulating more pulse outputs, while reducing the computational requirements and ensuring the classification ability.
[0033] Furthermore, the cross-gating unit is represented by the following formula:
[0034]
[0035] z = CONCAT(attn h ⊙p en , attn p ⊙h en )
[0036] where h en and p en are the header vector and the payload vector respectively, L × d are the byte length and the embedding dimension respectively, attn h and attn p are the attention calculations of the header feature and the payload feature respectively, ⊙ represents the element-wise product, z is the fused feature, and Softmax is the activation function. is the second linear layer of the header vector. is the first linear layer of the header vector, and AvgPool is the average pooling layer. is the first linear layer of the payload vector. is the second linear layer of the payload vector. and are the different biases of the convolutional neural network of the header encoder respectively. and are the different biases of the convolutional neural network of the payload encoder respectively. CONCAT is the concatenation function.
[0037] Furthermore, the classifier is represented by the following formula:
[0038]
[0039] where d num is the number of classes, f is the classification result. and are the first linear layer of the fused feature and the second linear layer of the fused feature respectively. Flatten is the flattening process. and are the different biases of the fully connected network in the classifier respectively.
[0040] In the second aspect of the present invention, an encrypted traffic classification system based on a spiking convolutional neural network is proposed, including:
[0041] A processing module for processing the target encrypted traffic data packet to obtain the header and payload of the target encrypted traffic data packet, facilitating the extraction of the features of the encrypted traffic.
[0042] An extraction module for respectively inputting the header and payload of the target encrypted traffic data packet into the convolutional encoder and the spiking convolutional encoder to obtain the header vector and the payload vector, facilitating the obtaining of an effective feature representation.
[0043] A fusion module for inputting the header vector and the payload vector into the cross-gating unit for feature fusion to obtain the fused feature, facilitating filtering and extracting effective features.
[0044] A classification module for inputting the fused feature into the classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
[0045] A third aspect of the present invention provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements an encrypted traffic classification method based on a spiking convolutional neural network as described in the first aspect above.
[0046] A fourth aspect of the present invention provides a computer-readable storage medium. The storage medium includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute an encrypted traffic classification method based on a spiking convolutional neural network as described in the first aspect above.
[0047] Advantages of the present invention:
[0048] The present invention constructs a spiking neural network using a convolutional encoder, a spiking convolutional encoder, a cross-gating unit, and a classifier. Specifically, by using a processing module, the header and payload of a target encrypted traffic data packet are obtained. The convolutional encoder and the spiking convolutional encoder respectively encode the header and payload of the target encrypted traffic data packet, and a cross-gating unit based on spiking neurons is used for feature fusion, which improves the classification ability while reducing the number of parameters and energy consumption. Description of the drawings
[0049] Figure 1 It is one of the flowcharts of an encrypted traffic classification method based on a spiking convolutional neural network provided by an embodiment of the present invention.
[0050] Figure 2 It is another flowchart of an encrypted traffic classification method based on a spiking convolutional neural network provided by an embodiment of the present invention.
[0051] Figure 3 It is a schematic diagram of the working process of a spiking convolutional encoder provided by an embodiment of the present invention.
[0052] Figure 4 It is a schematic diagram of the comparison of the model calculation cost results provided by an embodiment of the present invention.
[0053] Figure 5 It is an architecture diagram of an encrypted traffic classification system based on a spiking convolutional neural network provided by an embodiment of the present invention. Detailed implementation manners
[0054] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0055] Embodiment 1
[0056] As Figure 1 shown, a method for classifying encrypted traffic based on a pulsed convolutional neural network includes:
[0057] S101: Process the target encrypted traffic data packet to obtain the header and payload of the target encrypted traffic data packet.
[0058] Specifically, the present invention selects four publicly available data sets, namely ISCX VPN-nonVPN and ISCX Tor-nonTor, for training and testing. The present invention considers that network traffic is a one-dimensional byte stream, and the structures of bytes, data packets, sessions, and the entire traffic are very similar to the structures of words, phrases, sentences, and entire articles in the field of natural language processing. Therefore, the text form is used as the input representation of traffic packet data.
[0059] Since encrypted network traffic generates different network flows according to different applications, protocols, and services, it will increase the difficulty of learning features. Moreover, there are a large number of service data packets in the network that are meaningless for classification, such as ARP, TCP handshakes, etc. These data packets are not encrypted and are difficult to distinguish in the data of each category, which will bring a large amount of noise to the classification process. Therefore, the present invention uses the original bytes of the traffic as the representation, divides the data by a five-tuple (destination IP, source IP, destination port, source port, protocol number), and data packets with the same five-tuple are regarded as a network flow, and classification is only performed in units of network flows. When extracting bytes, since the protocol part of the traffic, that is, the header, is not encrypted and has a relatively fixed format according to different network protocols, and the payload part of the traffic is encrypted and has irregular characteristics, when processing the data, the header and the payload are separated and input into the model for processing.
[0060] First, use the SplitCap tool to divide the network traffic and filter out some network traffic without valid information or errors. It should be noted that since the ISCX Tor dataset has relatively few data divided by five-tuples, the present invention re-divides the data every 60 seconds. Secondly, delete user-sensitive information such as MAC and IP in the header, and also delete some service data packets without valid information. Each network flow only retains the first 200 bytes. When the number of bytes is insufficient, in order to distinguish from the normal single-byte numerical range of 0-255, the present invention supplements 256 as a mask until the byte number requirement is met.
[0061] S102: Input the header and payload of the target encrypted traffic data packet into the convolutional encoder and the spiking convolutional encoder respectively to obtain the header vector and the payload vector.
[0062] S103: Input the header vector and the payload vector into the cross-gating unit for feature fusion to obtain the fused feature.
[0063] S104: Input the fused feature into the classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
[0064] The present invention constructs a spiking convolutional neural network based on a convolutional encoder, a spiking convolutional encoder, a cross-gating unit based on spiking neurons, and a classifier. The spiking convolutional neural network first extracts the header and payload of the traffic data packet and inputs them into the convolutional encoder and the spiking convolutional encoder respectively to extract the effective feature representation. Subsequently, feature fusion is performed through the spiking cross-gating module, and finally the classifier is used to obtain the classification result. The present invention improves the classification effect while reducing the model parameter quantity and energy consumption.
[0065] Embodiment 2
[0066] Based on the above embodiment, as Figure 2 shown, the embodiment of the present invention provides the structure of the spiking convolutional neural network, which specifically includes:
[0067] The overall structure of the encrypted traffic classification method based on the spiking convolutional neural network mainly consists of four parts: a convolutional encoder, a spiking convolutional encoder, a cross-gating unit based on spiking neurons, and a classifier.
[0068] The network packet header protocol part contains important information such as network protocol, packet size, time, etc., and has a fixed format, with a large amount of information redundancy. The convolutional encoder plays a filtering role and can extract key features. At the same time, the one-dimensional convolutional neural network can also reduce network parameters. Therefore, the convolutional encoder is used to encode the header vector.
[0069] The convolutional encoder is represented by the following formula:
[0070] encoder h h = MaxPool(Batchnorm(Conv1d(h)))
[0071] where h is the vector of the embedded message header d 2 ×d 1 is the dimension of h, encoder h h is the header vector, MaxPool is the max pooling layer, Batchnorm is batch normalization, and Conv1d is one-dimensional convolution
[0072] The payload part is encrypted and randomized data with a lot of associated information between upper and lower bytes. And spiking neurons are suitable for processing sequences that change over time, and can generate more spike signals for the payload data with large changes. Therefore, the present invention uses a spiking convolutional encoder to downsample and encode the payload data
[0073] The spiking convolutional encoder consists of spiking neurons and a one-dimensional convolutional neural network, and its working process is as Figure 3 shown. The payload first extracts features through a one-dimensional convolutional neural network, and then the payload features are input into the spiking neurons to charge them. When the potential reaches the threshold, the spiking neurons input spike signals, and in this way, the temporal change information of the payload data is extracted
[0074] The spiking convolutional encoder includes a word embedding unit, a first processing unit, and a second processing unit connected in sequence. The first processing unit and the second processing unit both include a first convolutional layer, a second convolutional layer, a batch normalization subunit, spiking neurons, a first pooling layer, and a second pooling layer
[0075] The word embedding unit is used to convert the payload into a vector representation to obtain the embedded payload vector. The first processing unit and the second processing unit are both used to extract the effective features of the embedded payload vector. The first convolutional layer is used to perform convolutional processing on the embedded payload vector. The second convolutional layer is used to perform convolutional processing on the output of the first convolutional layer. The batch normalization subunit is used to perform batch normalization processing on the output of the second convolutional layer. The spiking neurons are used to filter out the invalid noise in the output of the batch normalization subunit and generate more spike outputs. The first pooling layer is used to perform pooling processing on the output of the spiking neurons. The second pooling layer is used to perform pooling processing on the output of the first pooling layer
[0076] The spiking convolutional encoder is represented by the following formula
[0077] encoder p(p) = MaxPool(LIF(Batchnorm(Conv1d(D))))
[0078] D = MaxPool(LIF(Batchnorm(Conv1d(p))))
[0079] Where D is the output of the first processing unit, and p is the embedded payload vector. d 2 ×d 1 is the dimension of the embedded payload vector, encoder p (p) is the payload vector, LIF is the spiking neuron, MaxPool is the max pooling layer, Batchnorm is the batch normalization, and Conv1d is the convolutional layer.
[0080] The spiking neuron model is a mathematical model used to simulate the working principle of biological neurons. The present invention considers the Leaky Integrate-and-Fire (LIF) neuron commonly used in computational neuroscience as the default spiking neuron. LIF simulates the processes of neuron charging, discharging, and restoring potential, and the process is expressed by the following formula:
[0081] V[t] = H[t] + β(X[t] - (H[t - 1] - V reset ))
[0082] S[t] = Θ(V[t] - V threshold )
[0083] H[t] = V[t]·(1 - S[t])
[0084] Where V is the neuron membrane potential, β is the decay factor, X is the input of the spiking neuron, Θ is the step function, H is the reset process of the membrane potential after pulse activation, V reset is the neuron reset membrane potential, S is the discharging process of the neuron, V thershold is the threshold potential.
[0085] The neurons of the LIF model only fire pulses when the potential accumulates to the threshold. The neurons are mostly silent most of the time. This trigger-based operation mode greatly reduces unnecessary operations and signal transmissions, and reduces the overall power consumption. Different from the continuous calculation of traditional neural networks, the SNN does not perform any activities when there is no pulse firing, reducing a large amount of computational requirements.
[0086] To enable the spiking neuron to have a higher firing rate, the observation time T is usually set to observe the input multiple times. The increased spikes will result in a higher probability of determining a specific category. Since the non-differentiable characteristic of the step function makes it impossible to train the spiking neural network, a substitute gradient function is used to replace the step function, enabling the spiking neuron to be trained normally. In the present invention, the observation time is taken as T = 2, the substitute gradient function is selected as the Tanh function, and the influence is analyzed through comparative experiments with different observation times and different substitute functions, and V is set threshold = 1, V reset = 0 and β = 0.5.
[0087] For encrypted traffic data, when the spiking neural network processes traffic data, since the LIF neuron accumulates potential over time and decays, its output spikes can represent the time order and intensity of network traffic. Through the time interval or frequency of emitting spikes, the LIF model can encode and transmit the timing information of the input data. And when the LIF model transmits information between different layers, it can gradually accumulate and filter the input signal, and the processing of the payload by the entire network will be smoother and more stable, accumulating the effective information of the encrypted traffic, filtering out invalid noise, and stimulating more spike outputs, while reducing the computational requirements and ensuring the classification ability.
[0088] Some fields in the data packet header correspond one-to-one with the characteristics of the payload, such as the payload protocol and the payload length. To effectively utilize this correlation information between the packet and the payload, the present invention designs a cross-gating module based on spiking neurons to further reduce the network power consumption while fusing features. The operation mechanism of the unit is similar to mutual attention, and the attention extraction is completed through average pooling, two linear layers, adding a spiking neuron in the middle of the linear layer, and finally adding a SoftMax operation. The pooling layer to the linear layer mainly functions as filtering, filtering out unimportant information in the packet and the protocol, retaining the important information, and converting the information into attention weights through the SoftMax operation, which are respectively applied to two feature vectors.
[0089] The cross-gating unit is represented by the following formula:
[0090]
[0091] z = CONCAT(attn h ⊙p en , attn p ⊙h en )
[0092] where h en and p en are the header vector and the payload vector respectively, L and d are the byte length and the embedding dimension respectively, and attn h and attn p are the attention calculations for the header feature and the payload feature respectively. ⊙ represents element-wise multiplication, z is the fused feature, Softmax is the activation function. is the second linear layer of the header vector. is the first linear layer of the header vector, and AvgPool is the average pooling layer. is the first linear layer of the payload vector. is the second linear layer of the payload vector. and are the different biases of the convolutional neural network of the header encoder respectively. and are the different biases of the convolutional neural network of the payload encoder respectively. CONCAT is the concatenation function.
[0093] The classifier consists of two linear layers. First, the feature vector is flattened into one dimension, and then the classification result is output by the linear layer. The specific process is shown in the following formula:
[0094]
[0095] Among them, d num is the number of classes, f is the classification result. and are the first linear layer and the second linear layer of the fused feature respectively. Flatten is the flattening process. and are the different biases of the fully connected network in the classifier respectively.
[0096] Preferably, in the spiking neural network, the loss function of the classification task choosing the Minimum Square Error (MSE) function is often better than the Cross Entropy (CE) function. Therefore, the present invention uses MSE as the training loss, as shown in the following formula:
[0097]
[0098] Among them, y represents the true label, and MSE is the mean square error.
[0099] Preferably, in the training phase, the maximum number of training rounds is set to 40, the initial learning rate is set to 1e-3, and the Adam optimizer with a learning rate scheduler is used. The scheduler gradually decays the learning rate from 1e-2 to 1e-7. The batch size is 16, the observation time T is taken as 2, the substitution gradient function is the arctangent function, and the reset method is soft reset. All models are implemented using PyTorch, and each experiment is independently run 10 times on a single Nvidia Tesla V100 GPU to obtain the average value.
[0100] Example 3
[0101] Based on the above embodiments, an evaluation method of the present invention is provided as follows:
[0102] The present invention conducts comparative experiments with the prior art on the public datasets ISCX VPN-nonVPN and ISCX Tor-nonTor, and is evaluated according to accuracy (AC), precision (PR), recall (RC), and F1 value (F1). The results are shown in Table 1. According to Table 1, the following results can be obtained: (1) The four indicators of the method of the present invention on the ISCX VPN and ISCX nonTor datasets are all better than the comparative methods, and the accuracy is improved by 1.23% and 1.24% respectively compared with the best models in the past. On the ISCX nonVPN dataset, except that the precision of the present invention is slightly lower than that of the CLE-TFE model by 0.08%, the other three indicators are slightly better than the baseline by 0.30%, 0.30%, and 0.34%. This is due to the framework of separately processing the packet header and payload of the present invention, and the strong processing ability of spiking neurons for time-varying sequences. On the ISCX Tor dataset, the present invention is close to the CLE-TFE model in the four indicators, and the four indicators are respectively lower than the CLE-TFE model by 0.76%, 0.73%, 0.76%, and 0.76%. This is because the network packet-level task of CLE-TFE promotes the learning representation of the network flow-level task and achieves significant capabilities in the flow-level task. (2) The good performance of the ET-BERT model benefits from its large parameter scale and pre-training on a large number of datasets. The CLE-TFE model also adopts the form of separately inputting the header and payload. At the same time, due to the strong representation ability of its graph neural network and graph contrast learning, it also achieves high accuracy. However, the number of parameters and the computational complexity of these two models are much larger than those of the present invention. The present invention achieves good results due to the strong time series processing ability of the spiking convolutional network.
[0103] Table 1 Results on the public datasets ISCX VPN-nonVPN and ISCX Tor-nonTor
[0104]
[0105]
[0106] Figure 4 Shows the comparison of the model calculation cost results. The present invention uses floating-point operations (Flops), power consumption (Energy consumption), the number of model parameters (Parameters), and the average running time per round to evaluate the running cost of the model. It is tested on the ISCX VPN dataset, with the same batchsize = 16, and the results are compared with ET-BERT and CLE-TFE. Figure 4 Shows the comparison results.
[0107] According to Figure 4 the results, the following conclusions can be drawn: ET-BERT is a pre-trained model that requires the most computing cost. The algorithm model of the present invention has achieved the minimum computing cost. The floating-point operations and the number of model parameters are 4.97% and 2.09% of the CLE-TFE model respectively, which are far less than those of the ET-BERT and CLE-TFE models and are more suitable for edge deployment in practice. The power consumption of SCNNTraffic is only 0.3248 mJ, which is far less than the two compared models, because the spiking neurons have the characteristic of energy saving.
[0108] Example 4
[0109] Based on the above embodiments, as Figure 5 shown, a system for classifying encrypted traffic based on a spiking convolutional neural network includes:
[0110] A processing module for processing the target encrypted traffic data packet to obtain the header and payload of the target encrypted traffic data packet.
[0111] An extraction module for respectively inputting the header and payload of the target encrypted traffic data packet into a convolutional encoder and a spiking convolutional encoder to obtain a header vector and a payload vector.
[0112] A fusion module for inputting the header vector and the payload vector into a cross-gating unit for feature fusion to obtain a fusion feature.
[0113] A classification module for inputting the fusion feature into a classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
[0114] It should be noted that the system for classifying encrypted traffic based on a spiking convolutional neural network provided by the embodiments of the present invention is to implement the above method for classifying encrypted traffic based on a spiking convolutional neural network. Its functions can be specifically referred to the above method embodiments and will not be elaborated here.
[0115] Example 5
[0116] Based on the above embodiments, an embodiment of the present invention further provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a method for classifying encrypted traffic based on a pulsed convolutional neural network in the above embodiments.
[0117] The present invention also provides a computer-readable storage medium. The storage medium includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute a method for classifying encrypted traffic based on a pulsed convolutional neural network in the above embodiments.
[0118] In summary, the present invention constructs a pulsed neural network using a convolutional encoder, a pulsed convolutional encoder cross-gating unit, and a classifier. Specifically, by using a processing module, the header and payload of the target encrypted traffic packet are obtained. The convolutional encoder and the pulsed convolutional encoder respectively encode the header and payload of the target encrypted traffic packet, and a cross-gating unit based on pulsed neurons is used for feature fusion, which improves the classification ability while reducing the number of parameters and energy consumption.
[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for classifying encrypted traffic based on pulse convolutional neural network, characterized in that: include: Step 1: Process the target encrypted traffic data packet to obtain the header and payload of the target encrypted traffic data packet; Step 2: Input the header and payload of the target encrypted traffic data packet into the convolution encoder and the pulse convolution encoder respectively to obtain a header vector and a payload vector; Step 3: Input the header vector and the payload vector into the cross-gating unit for feature fusion to obtain fused features; Step 4: Input the fused features into the classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
2. According to claim 1, a method for classifying encrypted traffic based on pulse convolutional neural network is characterized in that: The convolutional encoder is expressed as follows: encoder h (h)=MaxPool(Batchnorm(Conv1d(h))) Among them, h is the embedded message header vector, d2×d1 is the dimension of h, encoder h (h) is the header vector, MaxPool is the maximum pooling layer, Batchnorm is batch normalization, and Conv1d is the one-dimensional convolution.
3. According to claim 1, the encrypted traffic classification method based on pulse convolutional neural network is characterized in that: The pulse convolution encoder includes a word embedding unit, a first processing unit and a second processing unit connected in sequence, and the first processing unit and the second processing unit both include a first convolutional layer, a second convolutional layer, a batch normalization subunit, a pulse neuron, a first pooling layer and a second pooling layer; The word embedding unit is used to convert the payload into a vector representation to obtain an embedded payload vector; The first processing unit and the second processing unit are both used to extract effective features of the embedded payload vector; The first convolutional layer is used to perform convolution processing on the embedded payload vector; The second convolutional layer is used to perform convolution processing on the output of the first convolutional layer; The batch normalization subunit is used to perform batch normalization processing on the output of the second convolutional layer; The pulse neuron is used to filter invalid noise in the output of the batch normalization subunit and stimulate more pulse output; The first pooling layer is used to perform pooling processing on the output of the spiking neuron; The second pooling layer is used to perform pooling processing on the output of the first pooling layer.
4. The encrypted traffic classification method based on pulse convolutional neural network according to claim 3 is characterized in that: The pulse convolution encoder is expressed by the following formula: encoder p (p)=MaxPool(LIF(Batchnorm(Conv1d(D)))) D=MaxPool(LIF(Batchnorm(Conv1d(p)))) Where D is the output of the first processing unit, p is the embedded payload vector, d2×d1 is the dimension of the payload vector after embedding, encoder p (p) is the payload vector, LIF is the spike neuron, MaxPool is the maximum pooling layer, Batchnorm is the batch normalization, and Conv1d is the convolutional layer.
5. According to claim 3, the encrypted traffic classification method based on pulse convolutional neural network is characterized in that: The spiking neuron is expressed by the following formula: V[t]=H[t]+β(X[t]-(H[t-1]-V reset )) S[t]=Θ(V[t]-V threshold ) H[t]=V[t]·(1-S[t]) Where V is the neuron membrane potential, β is the attenuation factor, X is the input of the spiking neuron, Θ is the step function, H is the reset process of the membrane potential after the pulse activation, V reset is the neuron resetting membrane potential, S is the neuron discharge process, V threshold is the threshold potential.
6. According to claim 4, a method for classifying encrypted traffic based on pulse convolutional neural network is characterized in that: The cross-gating unit is expressed by the following formula: z=CONCAT(attn h ⊙p en ,attn p ⊙h en ) Among them, h en and p en are the header vector and the payload vector respectively, L×d are the length in bytes and the embedding dimension, attn h and attn p are the attention calculations for header features and payload features, respectively. ⊙ represents the element product, z is the fusion feature, Softmax is the activation function, is the second linear layer of the header vector, is the first linear layer of the header vector, AvgPool is the average pooling layer, is the payload vector of the first linear layer, is the payload vector of the second linear layer, and are different biases of the header encoder convolutional neural network, and They are different biases of the load encoder convolutional neural network, and CONCAT is the connection function.
7. The encrypted traffic classification method based on pulse convolutional neural network according to claim 6 is characterized in that: The classifier is expressed as follows: Among them, d num is the number of categories, f is the classification result, and They are the first linear layer of fused features and the second linear layer of fused features, and Flatten is the flattening process. and They are the different biases of the fully connected network in the classifier.
8. An encrypted traffic classification system based on pulse convolutional neural network, characterized in that: include: A processing module, used for processing a target encrypted traffic data packet to obtain a header and a payload of the target encrypted traffic data packet; An extraction module, used for inputting the header and the payload of the target encrypted traffic data packet into the convolution encoder and the pulse convolution encoder respectively, to obtain a header vector and a payload vector; A fusion module, used for inputting the header vector and the payload vector into the cross-gating unit for feature fusion to obtain a fusion feature; The classification module is used to input the fusion features into the classifier to obtain the classification result of the target encrypted traffic in the target encrypted traffic data packet.
9. An electronic device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements an encrypted traffic classification method based on a pulse convolutional neural network as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute an encrypted traffic classification method based on a pulse convolutional neural network as described in any one of claims 1 to 7.