Network flow intelligent identification and control method and system
Through neural network model and IP five-unit classification technology, new applications and business types in network traffic are automatically identified, which solves the lag problem of manual update rule base in the existing technology, and realizes efficient and automated network traffic identification and control.
Patent Information
- Application Number
- CN202510202147.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-30
AI Technical Summary
Existing network traffic recognition technology cannot automatically identify newly released APPs or protocol update services. It requires manual packet extraction and features, the update cycle is long, and the scalability is poor when facing massive applications, which can easily lead to rule conflicts.
The intelligent processing model with neural network architecture is adopted to classify data packets through IP five-tuples, and the pre-architected intelligent processing model is trained to automatically learn traffic characteristics without manually defining rules.
It realizes automatic identification of business types after newly released applications or protocol updates, reduces operation and maintenance costs, improves identification accuracy and scalability, and reduces manual intervention and rule conflicts.
Smart Images

Figure CN120075150A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication technologies, and in particular, to a method and system for intelligent identification and control of network traffic. Background Art
[0002] The dynamic management and control scenario of Internet Service Provider (ISP) for user network traffic is particularly applicable to multi-form access environments such as fixed-line broadband, mobile terminals (4G / 5G / 6G), and satellite communication. For example, when a 4G / 5G mobile phone user accesses the Internet, the operator needs to monitor and identify the specific application program (APP) used by the user in real time, so as to execute targeted management and control strategies. If it is identified as a P2P service (such as Thunder download), its bandwidth occupancy can be dynamically restricted; if it is identified as a streaming media service of a specified video platform (such as movie playback), the free data traffic rule can be triggered.
[0003] To dynamically manage and control user network traffic, it is necessary to identify the network traffic data of users. The current mainstream network traffic identification technology is Deep Packet Inspection (DPI). Its technical principle is to manually capture the traffic data packets of target applications (such as WeChat, Thunder), analyze their fixed features (such as IP address, port number, protocol field), and construct a static rule library. Subsequently, by matching the protocol features of user traffic data with the rule library, the service type and application type are determined.
[0004] However, this existing technology cannot automatically identify newly released APPs or services with protocol updates (such as new short video applications using the QUIC protocol), and it is necessary to manually capture packets to extract features, with an update cycle of up to several weeks. Moreover, the feature library needs to be continuously maintained manually, with poor scalability in the face of a large number of applications, and rule conflicts are likely to occur in scenarios such as dynamic port allocation and CDN shared IP. For example, when a certain video APP frequently changes the CDN node IP, the rule library needs to be updated repeatedly to match the new IP address, resulting in low operation and maintenance efficiency. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for intelligent identification and control of network traffic that are automated, low-maintenance, and have high identification accuracy to solve the deficiencies of the above technical problems.
[0006] To achieve the above purpose, the present invention provides a method for intelligent identification and control of network traffic, which includes:
[0007] Obtaining data packets of the data stream generated by the terminal device accessing the Internet to obtain an initial data set;
[0008] Classifying the data packets in the initial data set according to the IP quintuple to obtain several target data sets belonging to different categories;
[0009] Train a pre-constructed intelligent processing model with a neural network architecture based on the target dataset;
[0010] Process each of the currently obtained target datasets respectively based on the pre-trained intelligent processing model to obtain the recognition result of the current target dataset; the recognition result includes a service type and an application type, the service type represents the function or service category of the data stream for the terminal device to access the Internet, and the application type represents the specific service instance that generates the data stream;
[0011] Control the corresponding data stream according to the recognition result.
[0012] Preferably, extract the first N data packets of each data stream, where N is a pre-configured positive integer.
[0013] Preferably, 5 ≤ N ≤ 10.
[0014] Preferably, preferentially extract the TCP three-way handshake and the data packets of the first application layer.
[0015] Preferably, also label the data packets in the target dataset used for training the intelligent processing model, and the labeling content includes a service type, an application type, a timestamp, and encryption certificate metadata.
[0016] Preferably, the encryption certificate metadata includes domain name information, certificate authority name, encryption protocol version, and key exchange algorithm type in the TLS / SSL certificate.
[0017] Preferably, call the corresponding control policy according to the recognition result to control the corresponding data stream, and the control policy includes one or more of the following:
[0018] Dynamic bandwidth limitation;
[0019] Flow metering and billing;
[0020] Security auditing and blocking.
[0021] The present invention also provides a network traffic intelligent recognition and control system, which includes a control unit, and the control unit controls the data stream of the terminal device based on the network traffic intelligent recognition and control method as described above.
[0022] The present invention also provides a network traffic intelligent recognition and control system, which includes:
[0023] One or more processors;
[0024] A memory;
[0025] And one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the programs include instructions for executing the network traffic intelligent identification and control method as described above.
[0026] The present invention also provides a computer-readable storage medium, which includes a computer program that can be executed by a processor to complete the network traffic intelligent identification and control method as described above.
[0027] Compared with the prior art, the network traffic intelligent identification and control method provided by the above technical solution of the present invention, firstly, uses an intelligent processing model with a neural network architecture for training and inference. The model can automatically learn traffic features without manual rule definition. Therefore, this method can automatically identify the service types after new applications are released or protocols are updated, solving the lag problem of traditional methods relying on manual update of the rule library. Moreover, through the model generalization ability, it supports intelligent inference of unknown applications and reduces manual intervention. In addition, it can also reduce repetitive work such as manual packet capture analysis and feature extraction, effectively reducing the operation and maintenance cost, adapting to the dynamic network environment, and avoiding misjudgment caused by rule conflicts in traditional methods.
[0028] Secondly, classifying data packets through the IP five-tuple can uniquely identify the data flow session, avoiding feature confusion between different services. This enables the model to accurately distinguish different services of the same user, significantly improving the classification accuracy. Quickly locate the target data flow, reduce redundant traffic processing, and improve the overall identification efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 It is a flowchart of the network traffic intelligent identification and control method in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following is described in detail in conjunction with the embodiments and the accompanying drawings.
[0031] This embodiment discloses a network traffic intelligent identification and control method for the dynamic management and control of user network traffic by an Internet service provider (ISP).
[0032] Such as Figure 1 , the method includes the following steps:
[0033] S1: Obtain data packets of the data flow generated by the terminal device accessing the Internet to obtain an initial data set.
[0034] S2: Classify the data packets in the initial data set according to the IP quintuple (including five parameters: source IP address, destination IP address, protocol number, source port number, and destination port number) to obtain several target data sets belonging to different categories respectively.
[0035] S3: Train a pre-constructed intelligent processing model with a neural network architecture based on the target data set.
[0036] S4: Process each of the currently obtained target data sets respectively based on the pre-trained intelligent processing model to obtain the recognition result of the current target data set. The recognition result includes a service type and an application type. The service type represents the function or service category of the data stream for the terminal device to access the Internet, and the application type represents the specific service instance that generates the data stream.
[0037] Specifically, the service type describes the function or usage category of the traffic, such as real-time audio and video, P2P transmission, streaming media, etc. The application type refers to a specific application program or service, such as the specific APP names like WeChat and Douyin.
[0038] S5: Control the corresponding data stream according to the recognition result.
[0039] On the other hand, to improve the data processing efficiency, in the above step S1, extract the first N data packets of each data stream, where N is a pre-configured positive integer.
[0040] Specifically, 5 ≤ N ≤ 10.
[0041] For further optimization, preferentially extract the TCP three-way handshake packets and the first data packet of the application layer.
[0042] In this embodiment, by restricting the number of data packets extracted from each data stream and preferentially capturing the TCP three-way handshake packets and the first data packet of the application layer, the amount of data to be processed can be significantly reduced, thereby filtering redundant traffic and reducing the computational load of subsequent model training and inference.
[0043] In a typical scenario, the amount of data processed by a single data stream is reduced by 80% - 90% (for example, only 5 packets are retained instead of the full amount of data), and the overall system throughput is increased by 2 - 3 times.
[0044] In addition, the TCP three-way handshake packets contain connection metadata such as protocol type and port number, and the first data packet of the application layer (such as the certificate information in the TLS handshake stage) carries the core features of the service. Preferentially extracting these packets can ensure that the model obtains valid information. This can avoid the interference of subsequent redundant data at the transport layer (such as continuous large packets of video streams) on model inference, and effectively reduce the classification misjudgment rate.
[0045] Generally speaking, through the dual optimization of data volume compression and key feature focusing, this improvement achieves a balance between efficiency and accuracy, providing better technical support for real-time traffic control scenarios.
[0046] On the other hand, with the popularization of encryption protocols such as HTTPS and QUIC, traditional methods can only classify data traffic relying on surface information (such as IP / port) because they cannot parse encrypted content, resulting in a significant increase in the misjudgment rate. Therefore, to solve this problem, the identification and control method in this embodiment also annotates the data packets in the target dataset used to train the intelligent processing model, and the annotation content includes service type, application type, timestamp, and encryption certificate metadata.
[0047] Specifically, the encryption certificate metadata includes domain name information, certificate issuing authority name, encryption protocol version, and key exchange algorithm type in the TLS / SSL certificate.
[0048] In this embodiment, by annotating the encryption certificate metadata, the model can directly learn the unencrypted protocol layer features of encrypted traffic, breaking through the limitations of traditional methods that rely on surface information such as IP / port. Even if the traffic content is encrypted (such as HTTPS, QUIC), the specific application type can still be accurately identified through the certificate metadata (such as the *.netflix.com domain name), solving the misjudgment problem caused by the inability to parse encrypted content in traditional technologies.
[0049] The annotation of metadata such as encryption protocol version (TLS1.3) and key exchange algorithm (such as ECDHE) further differentiates the handshake behaviors of different encrypted applications (such as video streams and ordinary web browsing), effectively improving the classification accuracy.
[0050] On the other hand, according to the recognition result, the corresponding control policy is called to control the corresponding data stream, and the control policy includes one or more of the following:
[0051] Dynamic bandwidth limitation;
[0052] Flow metering and charging;
[0053] Security auditing and blocking.
[0054] For example, implement dynamic bandwidth limitation for P2P services; trigger free flow metering and charging for specified video streaming services; conduct security auditing and blocking for the traffic of encrypted communication tools.
[0055] In summary, the present invention discloses a method for intelligent identification and control of network traffic. First, it classifies data packets by IP quintuples, can uniquely identify data flow sessions, and avoid feature confusion between different services. This enables the intelligent processing model to accurately distinguish different services of the same user (such as WeChat voice calls and video streaming media), and the classification accuracy is significantly improved; quickly locate the target data flow, reduce redundant traffic processing, and improve overall recognition efficiency.
[0056] Secondly, by using a pre-architected neural network model (such as Transformer or convolutional neural network) for training and reasoning, the model can automatically learn traffic characteristics (such as protocol behavior, timing patterns) without manually defining rules. This allows the model to automatically identify newly released applications (such as new short video apps) or business types after protocol updates, solving the lag problem of traditional methods that rely on manual updates of the rule base. Moreover, through the generalization ability of the model, it supports intelligent reasoning for unknown applications and reduces manual intervention.
[0057] Furthermore, based on the business type (functional category) and application type (specific instance) output by the model, network control policies (such as bandwidth limitation and billing adjustment) are directly triggered. This enables the control of traffic data to achieve a millisecond-level response speed, such as real-time limitation of P2P download bandwidth or marking video as free to stream, supports fine-grained control (such as speed limit only for a specific APP), and improves the flexibility of policy execution.
[0058] Furthermore, through the end-to-end training and deployment of the neural network model, there is no need to manually maintain a static rule base or frequently update the feature code. This reduces repetitive work such as manual packet capture analysis and feature extraction, and reduces operation and maintenance costs by more than 70%. It adapts to dynamic network environments (such as CDN shared IP and port randomization) and avoids misjudgments caused by rule conflicts in traditional methods.
[0059] In addition, the model can dynamically optimize recognition capabilities by continuously learning new traffic features in the target data set. It supports parallel recognition of massive applications (such as processing millions of user sessions at the same time), and its scalability is significantly better than that of traditional rule engines. It adapts to multi-mode access environments (fixed network, mobile network, satellite communication) and covers complex business scenarios.
[0060] In general, this method achieves an upgrade from "manual rule-driven" to "intelligent data-driven" by combining IP quintuple classification with neural network model reasoning. It is superior to traditional deep packet inspection (DPI) technology in terms of classification accuracy, automation level, real-time response, and cost control, providing operators with an efficient and scalable traffic control solution.
[0061] In another preferred embodiment of the present invention, there is also disclosed an intelligent network traffic recognition and control system, which includes a control unit. The control unit controls the data stream of the terminal device based on the network traffic intelligent recognition and control method in the above embodiment.
[0062] The present invention also discloses another recognition and control system, which includes one or more processors, a memory, and one or more programs. One or more of the programs are stored in the memory and are configured to be executed by the one or more processors. The programs include instructions for executing the recognition and control method as described above. The processor may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the functions required by the modules in the recognition and control system of the embodiments of the present application, or to execute the recognition and control method of the method embodiments of the present application.
[0063] The present invention also discloses a computer-readable storage medium, which includes a computer program. The computer program can be executed by a processor to complete the recognition and control method as described above. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a read-only memory (ROM), a random access memory (RAM), a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid-state disk (SSD), etc.
[0064] The embodiments of the present application also disclose a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above recognition and control method.
[0065] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A method for intelligent identification and control of network traffic, characterized in that: include: Acquire data packets of a data stream generated by a terminal device accessing the Internet to obtain an initial data set; Classifying the data packets in the initial data set according to the IP quintuple to obtain a plurality of target data sets belonging to different categories; Training a pre-architected intelligent processing model having a neural network architecture based on the target data set; Based on the pre-trained intelligent processing model, each of the currently obtained target data sets is processed respectively to obtain a recognition result of the current target data set; the recognition result includes a business type and an application type, the business type represents the function or service category of the data flow of the terminal device accessing the Internet, and the application type represents the specific service instance that generates the data flow; The corresponding data flow is controlled according to the identification result.
2. The network traffic intelligent identification and control method according to claim 1 is characterized in that: The first N data packets of each of the data streams are extracted, where N is a pre-configured positive integer.
3. The network traffic intelligent identification and control method according to claim 2 is characterized in that: 5≤N≤10。 4. The network traffic intelligent identification and control method according to claim 2 is characterized in that: Prioritize the extraction of TCP three-way handshake and the first application layer data packet.
5. The network traffic intelligent identification and control method according to claim 1 is characterized in that: The data packets in the target data set used to train the intelligent processing model are also labeled, and the labeled content includes business type, application type, timestamp and encryption certificate metadata.
6. The network traffic intelligent identification and control method according to claim 5, characterized in that: The encryption certificate metadata includes the domain name information, certificate authority name, encryption protocol version and key exchange algorithm type in the TLS / SSL certificate.
7. The network traffic intelligent identification and control method according to claim 1, characterized in that: The corresponding control strategy is called according to the recognition result to control the corresponding data flow, and the control strategy includes one or more of the following actions: Dynamic bandwidth limiting; Traffic billing; Security audit and blocking.
8. A network traffic intelligent identification and control system, characterized in that: It includes a control unit, which controls the data flow of the terminal device based on the network traffic intelligent identification and control method according to any one of claims 1 to 7.
9. A network traffic intelligent identification and control system, characterized in that: include: one or more processors; Memory; And one or more programs, wherein the one or more programs are stored in the memory and are configured to be executed by the one or more processors, and the programs include instructions for executing the network traffic intelligent identification and control method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: It includes a computer program, which can be executed by a processor to complete the network traffic intelligent identification and control method as described in any one of claims 1 to 7.