Protocol message field semantic inference method based on session context
By considering the conversation context and natural language processing in the network protocol reverse analysis, and combining deep learning technology, the W-GRU-FCN classification module is built, which solves the problems of information loss and accuracy reduction in reverse analysis, and achieves higher accuracy of semantic inference of protocol packet fields.
Patent Information
- Application Number
- CN202510005112.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-02
AI Technical Summary
When the prior art reversely analyzes unknown network protocols, the correlation between session context information and message types is ignored, resulting in information loss and reduced accuracy.
The protocol packet field semantic inference method is adopted based on the session context, and the W-GRU-FCN classification module is built by acquiring and classifying network data packets, combining natural language processing and deep learning technology, and using the composite loss function and ADAM optimizer to train the model to infer the protocol field semantics.
It effectively solves the redundancy problem in message classification, improves the accuracy of field division, and enhances the accuracy of semantic inference of protocol packets.
Smart Images

Figure CN120075327A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to network space security technology, and more particularly to a method for inferring the semantics of protocol message fields based on session context. Background Art
[0002] With the rapid development of network and communication technologies, the network form has become increasingly complex, and a large number of network applications have emerged. The emergence and rapid development of the Internet of Things technology have led to a sharp increase in the number of Internet of Things terminal applications, followed by a large number of dedicated network communication protocols. Due to their special properties such as privacy and diversity, these protocols are widely used in fields such as military, network space security, and industrial control, but at the same time, they have also become effective tools for network security threats such as malware, dark web, and botnets.
[0003] With the rapid development of network protocol reverse analysis technology, automated network protocol analysis methods have gradually replaced the inefficient manual analysis methods. From the inference of protocol specifications to the understanding of protocol behaviors, automated methods have been widely used in many practical fields such as protocol behavior analysis, wireless protocol understanding and reconstruction, network honeypot protocol detection, state machine model analysis, protocol vulnerability mining, industrial control protocol modeling, and Internet of Things device security analysis. Most current methods for reverse analyzing unknown network protocols mainly rely on the multiple sequence alignment technology of messages in biology, but such methods are not fully applicable to the analysis of message sequences. The sequential analysis process from keyword extraction to message clustering ignores the mutual influence between different stages of reverse analysis, has no complete definition for the classification of message types, and does not fully consider the correlation between client and server messages, which will lead to the loss of some information in the protocol, resulting in a waste of resources and a decrease in accuracy. Therefore, it is of great practical value to fully consider the context information of the session, combine the characteristics of different types of messages for protocol reverse, and improve the accuracy of protocol message field semantic inference. Summary of the Invention
[0004] The present invention proposes a method for inferring the semantics of protocol message fields based on session context to analyze the field information of unknown protocols.
[0005] The technical solution for implementing the present invention is as follows:
[0006] A method for inferring the semantics of protocol message fields based on session context, comprising the following steps:
[0007] Step 1, obtain network data packets, perform preprocessing on the data by extraction and classification according to protocol types to obtain session messages of different protocols;
[0008] Step 2: Group the packets of the same protocol into packet sessions, divide each packet into fields every 4 bytes, replace the original packet content with numbers, obtain the overall packet time series and the sending packet time series in number format, and divide the training set and the validation set proportionally;
[0009] Step 3: According to the classified protocol types, retrieve the semantic descriptions of each field of different protocols from the network, use the Sentence-BERT model to classify the field semantics of the protocol, divide the fields with similar semantics into one category, and combine them with the overall packet time series and the sending packet time series in number format to obtain the overall time series T1 with classification labels and the sending time series T2;
[0010] Step 4: Combine the GRU and FCN networks, process the overall time series T1 with classification labels and the sending time series T2 through two parallel GRU-FCN networks respectively to obtain the output features X1 and X2 of the two networks, introduce a concatenate layer to merge the output features of the two networks into X3, and construct a W-GRU-FCN classification module accordingly;
[0011] Step 5: Use the composite loss function and the ADAM optimizer to train the W-GRU-FCN classification network for inferring the field semantics of the protocol;
[0012] Step 6: For the data of unknown protocols, preprocess it and input it into the W-GRU-FCN classification module to complete the semantic inference of the protocol packets, and use the network data of known protocols to simulate the network data of unknown protocols for testing.
[0013] Compared with the prior art, the significant advantages of the present invention are as follows: 1) Combining multi-sequence alignment segmentation and deep learning can effectively solve the redundancy problem existing in packet classification; 2) Using the method of natural language processing to set classification labels can improve the accuracy of field division; 3) Considering the different characteristics shown by the protocol in unidirectional and bidirectional sessions can enhance the accuracy of classification.
[0014] The following further describes the present invention in detail with reference to the accompanying drawings. Description of the Drawings
[0015] Figure 1 It is a flow schematic diagram of a method for inferring the semantic of protocol packet fields based on session context.
[0016] Figure 2 It is a flow chart of packet session grouping and field encoding.
[0017] Figure 3 It is a flow schematic diagram of packet sequence encoding processing.
[0018] Figure 4It is the structural diagram of the W-GRU-FCN classification module.
[0019] Figure 5 It is the schematic diagram of the model training process. Specific implementation manner
[0020] As Figure 1 shown, a method for semantic inference of protocol message fields based on session context is as follows:
[0021] Step 1: Obtain network data packets, perform preprocessing on the data for extraction and classification by protocol type to obtain session messages of different protocols.
[0022] Step 1-1: By using the wireshark tool, monitor a specific network interface to intercept network data packets;
[0023] Step 1-2: Extract and focus on network data of a specific protocol type, remove network data of irrelevant protocols, classify data of the same protocol into one category, and save the data as different pcap format files according to the protocol type.
[0024] Step 2: As Figure 2 shown, perform message session grouping on messages of the same protocol, divide each message into fields every 4 bytes, replace the original message content with numbers, obtain the overall message time series and the sending message time series in number format, and divide the training set and the validation set according to a ratio.
[0025] Step 2-1: Perform message session grouping on messages of the same protocol, use the SplitCap tool to divide the pcap file according to the five-tuple (source IP, destination IP, source port, destination port, and transport protocol) to obtain multiple session groups, and subdivide the data of each session into two types: sending and receiving according to the source IP and destination IP. The characteristics shown by the sending and receiving data are the same. Set the sending direction of the first data packet in each session as the sending direction, and all subsequent packets with the same direction as the first packet are in the sending direction. Extract unidirectional sending messages, and finally divide the data into a two-way overall session containing the original data and a sending session containing only unidirectional sending data;
[0026] Step 2-2: Replace the original message content with numbers. For each session group, divide each message into fields every 4 bytes. Set the upper limit of the number of two-way messages as 30 and the number of sending messages as 15. Number the values of the same fields in the message from 1 in ascending order. Values of the same size have the same number. For session groups with less than 30 or 15 sessions, supplement the generated field sequence with 0 to obtain the overall message time series and the sending message time series in number format;
[0027] Step 2-3: Divide the training set and the validation set in a ratio of 8:2, and use known protocols to simulate unknown protocol tests.
[0028] Step 3: According to the classified session protocol types, retrieve the semantic descriptions of each field of different protocols from the network, use the Sentence-BERT model to classify the field semantics of the protocol, classify the fields with similar semantics into one category, and combine them with the overall message time series and the sending message time series in the number format to obtain the overall time series T1 and the sending time series T2 with classification labels.
[0029] Step 3-1: According to the classified session protocol types, retrieve the semantic descriptions of each field of different protocols from the network, and use them as the input to the Sentence-BERT model dedicated to natural language processing. The model converts the semantic descriptions of each field into embedding vectors, and calculates the cosine similarity between every two embedding vectors of all fields;
[0030] Fine-tune the Sentence-BERT model through triplet loss optimization, construct multiple groups of triplet data, specifically including the semantic description of a field, the semantic description of another field similar to the semantic description of this field, and the semantic description of another field not similar to the semantic description of this field. The formula of the triplet loss function is:
[0031] L = max(0, m + ||f(a) - f(p)|| 2 - ||f(a) - f(n)|| 2 )
[0032] where a is the anchor sample, representing the semantic description of a field, p is the positive sample, belonging to the same category as the anchor, n is the negative sample, belonging to a different category from the anchor, f(x) is the feature representation function, m is the preset boundary, and use the constructed triplet data and the triplet loss function to train the Sentence-BERT model;
[0033] Subsequently, input the semantic descriptions of each field into the Sentence-BERT model for pairwise comparison. By passing the semantic description A and the semantic description B to the network, embedding vectors u and v are generated. Calculate the similarity of these embeddings using cosine similarity. The formula for cosine similarity is as follows:
[0034]
[0035] where ||u|| and ||v|| are the Euclidean norms of the vectors. Calculate the cosine similarity between every two embedding vectors of all fields, and combine all similarity values into the final similarity cosine matrix.
[0036] Step 3-2: After obtaining the similarity cosine matrix, first convert the similarity cosine matrix into a distance matrix. Apply the K-means clustering method to the distance matrix. The number of clusters k increases from 2 to one-third of the number of training samples. In each round of clustering, randomly select k fields and their corresponding distance vectors as the initial cluster centers. Assign each field to the cluster where the nearest cluster center is located, and recalculate the center point of each cluster until the cluster assignment no longer changes or reaches the maximum number of iterations. Record the sum of squared errors within the cluster (SSE) for each k value;
[0037] Step 3-3: Plot the SSE curve with the k value as the abscissa and the SSE value as the ordinate. Select the elbow position of the curve as the optimal number of clusters. Execute the K-means clustering algorithm on the distance matrix again to obtain the final cluster labels for each field. Add the corresponding field labels to the end of the overall message time series and the sent message time series in the row number format to obtain the overall time series T1 and the sent time series T2 with classification labels.
[0038] Step 4: Combine the GRU and FCN networks. Process the overall time series T1 and the sent time series T2 with classification labels through two parallel GRU-FCN networks respectively to obtain the output features X1 and X2 of the two networks. Introduce a concatenate layer to merge the output features of the two networks into X3. Send X3 into the Softmax layer to convert the output into a probability distribution to complete multi-class classification, and thus construct a W-GRU-FCN classification network model.
[0039] Step 4-1: GRU network design. The basic architecture of the GRU network includes an embedding layer, three layers of GRU units, a normalization layer, and a Dropout layer. The embedding layer converts the input overall time series T1 and sent time series T2 data with classification labels into high-dimensional embedding vectors. This conversion adjusts the dimension of the time series data and transforms it into a multi-variable form. The embedding vectors are fed into a sequence network composed of three layers of GRU units to form a sequence representation at a given time step and input into the normalization layer. The normalization layer calculates the mean and standard deviation of all hidden units and uses these parameters for normalization, specifically according to the following formula:
[0040]
[0041] where h t is the original output vector at time step t, μ t and σ t are the mean and standard deviation of h t respectively. After normalization, it is output to the Dropout layer, and the overall vector G1 and the sent vector G2 are output respectively;
[0042] Step 4-2: FCN network design. The FCN network consists of 3 basic convolutional blocks with sizes of 8 / 5 / 3 and a stride of 1. The basic convolutional block includes a one-dimensional convolutional layer, a batch normalization layer, and a ReLU activation function. The three convolutional layers are configured with 128, 256, and 128 convolutional kernels respectively. The batch normalization layer normalizes each feature (with a mean of 0 and a standard deviation of 1). Finally, there is a global average pooling layer, which outputs the overall time series T1 of the classification label and the transmission time series T2 in the form of vectors F1 and F2;
[0043] Step 4-3: GRU-FCN network design. The outputs G1 and G2 of the GRU and the outputs F1 and F2 of the FCN network are fused through a Concatenate layer. The GRU extracts different forms of sequence inputs to enhance the sequence features extracted by the FCN, and forms feature vectors X1 and X2 that integrate the learning results of the two networks for the sequence data for the overall and transmission data respectively;
[0044] Step 4-4: W-GRU-FCN neural network design. The W-GRU-FCN classification module is composed of 2 parallel GRU-FCN networks. The inputs are the overall time series T1 with classification labels and the transmission time series T2. After obtaining the output features X1 and X2 of the two GRU-FCN networks, a concatenate layer is introduced to merge the output features of the two networks into X3, and X3 is sent to the Softmax layer to convert the output into a probability distribution to complete multi-class classification;
[0045] Assume the vector generated by the Concatenate layer is z 1 ,z 2 ,...,z K , where K is the total number of categories. The Softmax function maps these values into a probability distribution, and the value of each element represents the probability of the corresponding category. For the j-th element, its probability p j is calculated as follows:
[0046]
[0047] where is the exponential function, which is used to ensure that the output probability is non-negative, and the denominator is the sum of all exponential values, which is used for normalization to ensure that the sum of all output probabilities is 1.
[0048] Step 5: Use the composite loss function and the ADAM optimizer to train the W-GRU-FCN classification network for the inference of protocol field semantics. The schematic diagram of the training process is shown in Figure 5 .
[0049] Step 5-1: Load the preprocessed overall time series T1 with classification labels and the sending time series T2. For each protocol's data, calculate the values of three loss functions, namely the online contrast loss L OnConLoss , the self-supervised contrast loss L InfoNCE , and the cross-entropy loss L CE , and calculate the loss gradients based on the loss function values;
[0050] The calculation of the online contrast loss function is shown in the formula:
[0051] L OnConLoss = (1 - y)max(0, ||f(x i ) - f(x j )|| - margin) + yD
[0052] where x i and x j are samples, mapped to a new space through the classification model f, y is a binary label indicating whether the two samples are a positive sample pair or a negative sample pair, margin is a hyperparameter, and the loss is the Euclidean distance ||f(x i ) - f(x j )|| between them;
[0053] The calculation of the self-supervised contrast loss is shown in the formula:
[0054]
[0055] where x is the anchor point, x + is the positive sample, x - is the negative sample, sim(x, x + ) is the cosine similarity between the anchor point and the positive sample, and τ is the temperature parameter used to control the degree of distribution focusing. The temperature parameter has an important impact on the learning process, and the parameter is set to 0.1 in the experiment;
[0056] The final loss gradient is shown in the formula:
[0057] L = α·L CE + β·L OnConLoss + γ·L InfoNCE
[0058] where α, β, and γ are loss function weight parameters;
[0059] Step 5-2: Use the Adam optimizer to update the network parameters according to the loss gradient. The weight parameters of the loss function are 0.5, 0.3, and 0.2 respectively. Use the warmup mechanism to gradually increase the learning rate at the beginning of training, starting from a small value and gradually increasing linearly to the predetermined learning rate. The initial margin of the online contrast loss is set to 0.5, the temperature value of the self-supervised contrast loss is set to 0.1, the initial learning rate is set to 0.001, the maximum learning rate is 0.01, the warmup steps are 1000 steps, the activation function is selected as ReLU, the number of epochs for early stopping is set to 10, and the minimum change amount is set to 0.001. Only when the improvement of the validation loss is greater than this value will it be determined as an improvement and the epoch counter will be reset. After each training epoch, evaluate the model using the validation set. If the performance on the validation set improves, update and save the best state of the model. If the performance on the validation set does not improve within the set patience epochs, stop training.
[0060] Step 6: For data with unknown protocols, after preprocessing, input it into the W-GRU-FCN classification module to complete the semantic inference of protocol messages, and use the network data of known protocols to simulate the network data of unknown protocols for testing.
[0061] Use the DCCP protocol to simulate unknown protocols for testing. Take the same processing as during training, perform session grouping, field division, and numbering on the message data to obtain the overall time series and transmission time series in numbered format. Load the optimal weights of the model. The network structure is the same as during training. The input is the overall time series and transmission time series in processed numbered format, and the output is the probability of each classification corresponding to the sequence fields. Finally, obtain the semantic classification prediction results of each field of the DCCP protocol.
[0062] The field type division of this method is an unsupervised text classification task, lacking predefined labels or categories. The purpose of the experimental result analysis is to evaluate the effectiveness of the algorithm in discovering the internal structure of the text, that is, to analyze the consistency of field types under the same category. And the field type division is completed through the elbow method and k-means clustering. Therefore, it is evaluated by comparing the classification accuracy of the model and the semantic classification of fields with the actual situation.
[0063] Use the DCCP protocol to simulate unknown protocols after field division. After data preprocessing, input it into the semantic inference model for classification testing. The real field structure of DCCP is shown in Table 1:
[0064] Table 1 Real Field Structure of DCCP Protocol
[0065]
[0066] Among them, the Data Offset field is used to indicate the offset from the start of the data to the start of the DCCP packet. The CCVal (Congestion Control Value) field transmits additional control information or status in the congestion control algorithm (such as CCID). The CsCov (Checksum Coverage) field is used to specify the range covered by the checksum. X is the extended sequence number. The Reserved field is for future use and padding alignment, and this field is not classified for the time being.
[0067] The classification results of DCCP protocol fields obtained by the field semantic reasoning model are shown in Table 2:
[0068] Table 2 Semantic Reasoning Results of DCCP Protocol Fields
[0069]
[0070] It can be seen from the semantic reasoning result table that the port field, sequence number field, and checksum are all successfully classified into the same category, and other identification or control fields are classified into one category. The values of the data offset and extended sequence number are related to the type of the packet and have the same variation pattern as the Type field. The classification of these three fields into the same category is an expected result. The value of the CsCov field is 0 in each packet, so it is classified into Category 2. Generally speaking, each field has been reasonably classified, which to a certain extent shows the effectiveness and feasibility of the semantic reasoning model.
Claims
1. A method for semantic inference of protocol message fields based on session context, characterized in that: The following steps are involved: Step 1: Obtain network data packets, classify them by protocol type, and obtain session messages of different protocols; Step 2: Group the messages of the same protocol into message sessions, divide each message into fields every 4 bytes, replace the original message content with numbers, and obtain the overall message time sequence and the sending message time sequence in the numbering format; Step 3: According to the classified protocol type, retrieve the semantic description of each field of different protocols, use the Sentence-BERT model to classify the field semantics of the protocol, classify the fields with similar semantics into one category, and combine them with the overall message time series and the sent message time series in the numbering format to obtain the overall time series T1 and the sent time series T2 with classification labels; Step 4: Build a W-GRU-FCN classification network model. Use two parallel GRU-FCN networks to process the overall time series T1 and the sending time series T2 with classification labels respectively, and obtain the output features X1 and X2 of the two GRU-FCN networks. Introduce a concatenate layer to output the combined feature X3 of the two networks. The combined feature X3 is sent to the Softmax layer to be converted into a probability distribution, and the semantics of the protocol field is inferred. Step 5: Use the composite loss function and ADAM optimizer to train the W-GRU-FCN classification network model; Step 6: For data of unknown protocols, input them into the W-GRU-FCN classification network model after preprocessing, complete the semantic inference of protocol messages, and use network data of known protocols to simulate network data of unknown protocols for testing.
2. The method for semantic inference of protocol message fields based on session context according to claim 1 is characterized in that: Step 1: Get network data packets, classify them by protocol type, and get session messages of different protocols. The specific method is as follows: Step 1-1, use the wireshark tool to monitor the network interface and intercept network data packets; Step 1-2, remove network data of irrelevant protocols; Steps 1-3, classify the data of the same protocol into one category, and save the network data into different pcap format files according to the protocol type.
3. The method for semantic inference of protocol message fields based on session context according to claim 1, characterized in that: Step 2: Group the messages of the same protocol into message sessions, divide each message into fields every 4 bytes, replace the original message content with numbers, and obtain the overall message time sequence and the sending message time sequence in the numbering format. The specific method is as follows: Step 2-1, group the packets of the same protocol into packet sessions, use the SplitCap tool to divide the pcap file according to the five-tuple (source IP, destination IP, source port, destination port and transport protocol), and obtain multiple session groups, and subdivide the data of each session into two types: sending and receiving according to the source IP and destination IP. The sending and receiving data show the same characteristics. The sending direction of the first data packet in each session is set as the sending direction, and the subsequent packets that are consistent with the first packet direction are all sending directions. Extract unidirectional sending packets, and finally divide the data into a two-way overall session containing original data and a sending session containing only unidirectional sending data; Step 2-2, replace the original message content with numbers, group each session, divide each message into fields every 4 bytes, set the upper limit of the number of two-way messages to 30, and the number of sent messages to 15. For the values of the same field in the message, they are numbered from small to large starting from 1, and values of the same size are numbered the same. The field sequence generated by the grouping of less than 30 or 15 sessions is supplemented with 0 to obtain the overall numbering format and the sent session data.
4. The method for inferring protocol message fields based on session context according to claim 1, characterized in that: Step 3: According to the classified protocol type, retrieve the semantic description of each field of different protocols, use the Sentence-BERT model to classify the field semantics of the protocol, classify the fields with similar semantics into one category, and combine them with the overall message time series and the sent message time series in the numbering format to obtain the overall time series T1 and the sent time series T2 with classification labels. The specific method is as follows: Step 3-1, obtain the semantic description of each field of the known protocol from the network as the input of the Sentence-BERT model dedicated to natural language processing, convert the semantic description of each field into an embedding vector, and calculate the cosine similarity of the embedding vectors of all fields; Step 3-2, convert the similarity cosine matrix into a distance matrix, apply the K-means clustering method to the distance matrix, and increase the number of clusters k from 2 to one-third of the number of training samples. In each round of clustering, randomly select k fields and their corresponding distance vectors as the initial cluster centers, assign each field to the cluster with the closest cluster center, recalculate the center point of each cluster until the cluster assignment does not change or the maximum number of iterations is reached, and record the intra-cluster sum of squared errors (SSE) for each k value; Step 3-3, draw the SSE curve with k value as the horizontal axis and SSE value as the vertical axis, select the elbow position of the curve as the optimal number of clusters, execute the K-means clustering algorithm on the distance matrix again, obtain the final cluster label of each field, add the label of the corresponding field to the end of the overall message time series and the sent message time series in each row number format, and obtain the overall time series T1 and the sent time series T2 with classification labels.
5. The method for semantic inference of protocol message fields based on session context according to claim 1, characterized in that: Step 4: Construct a W-GRU-FCN classification network model. Use two parallel GRU-FCN networks to process the overall time series T1 and the sending time series T2 with classification labels respectively, and obtain the output features X1 and X2 of the two GRU-FCN networks. Introduce a concatenate layer to output the merged feature X3 of the two GRU-FCN networks. The merged feature X3 is sent to the Softmax layer to be converted into a probability distribution to complete the inference of the protocol field semantics. The specific method is as follows: Step 4-1: GRU network design The basic architecture of the GRU network includes an embedding layer, a three-layer GRU unit, a normalization layer, and a Dropout layer. The embedding layer converts the input overall time series T1 and the transmission time series T2 data with classification labels into a high-dimensional embedding vector. This conversion adjusts the dimension of the time series data and converts it into a multivariate form. The embedding vector is sent to the sequence network composed of three layers of GRU units to form a sequence representation of a given time step and input to the normalization layer. The normalization layer calculates the mean and standard deviation of all hidden units and uses these parameters for normalization, specifically according to the following formula: where h t is the raw output vector at time step t, μ t and σ t They are h t The mean and standard deviation of are normalized and output to the Dropout layer, and the overall vector G1 and the sending vector G2 are output respectively; Step 4-2: FCN network design The FCN network consists of three basic convolutional blocks with sizes of 8 / 5 / 3 and stride of 1. The basic convolutional blocks include a one-dimensional convolutional layer, a batch normalization layer, and a ReLU activation function. The three convolutional layers are configured with 128, 256, and 128 convolution kernels respectively. The batch normalization layer standardizes each feature with a mean of 0 and a standard deviation of 1. Finally, it ends with a global average pooling layer, which outputs vectors F1 and F2 for the overall time series T1 and the sending time series T2 with classification labels respectively; Step 4-3: W-GRU-FCN classification network design The W-GRU-FCN classification network is composed of two parallel GRU-FCN networks. Each GRU-FCN network fuses the outputs G1 and G2 of the GRU and the outputs F1 and F2 of the FCN network through the Concatenate layer. The GRU extracts sequence inputs in different forms to enhance the sequence features extracted by the FCN. The feature vectors X1 and X2 that integrate the learning results of the two networks on the sequence data are formed for the overall and sent data respectively; then the concatenate layer is introduced to output the merged feature X3 of the two GRU-FCN networks, and the merged feature X3 is sent to the Softmax layer and converted into a probability distribution to complete multi-class classification.
6. The method for semantic inference of protocol message fields based on session context according to claim 1, characterized in that: Step 5: Use the composite loss function and ADAM optimizer to train the W-GRU-FCN classification network model. The specific method is: Step 5-1: Load the preprocessed overall time series T1 and the sending time series T2 with classification labels, and calculate the three loss function values for the data of each protocol, namely, the online contrast loss L OnConLoss , self-supervised contrast loss L InfoNCE , cross entropy loss L CE , calculate the loss gradient according to the loss function value, where: The calculation formula of the online contrast loss function is: L OnConLoss (1-y)max(0,||f(x) i )-f(x j )||-margin)+yD where x i and x j is a sample, mapped to a new space by the classification model f, y is a binary label, indicating whether the two samples are a positive sample pair or a negative sample pair, margin is a hyperparameter, and the loss is the Euclidean distance between them || f(x i )-f(x j )||; The formula for calculating the self-supervised contrast loss is: Where x is the anchor point, x + is a positive sample, x - is a negative sample, sim(x, x + ) is the cosine similarity between the anchor point and the positive sample, and τ is the temperature parameter used to control the degree of distribution focus. The temperature parameter has an important influence on the learning process, and the parameter is set to 0.1 in the experiment; The final loss gradient calculation formula is: L=α·L CE +β·L OnConLoss +γ·L InfoNCE Among them, α, β, and γ are the weight parameters of the loss function; Step 5-2: Use the Adam optimizer to update the network parameters according to the loss gradient, use the warmup mechanism to gradually increase the learning rate at the beginning of training, set the initial margin of the online contrast loss to 0.5, the temperature value of the self-supervised contrast loss to 0.1, the initial learning rate to 0.001, the maximum learning rate to 0.01, the warmup step number to 1000, the activation function to ReLU, the number of cycles for early stopping to 10, the minimum change to 0.001, and the validation set to evaluate the model after each training cycle.
7. The method for inferring protocol message fields based on session context according to claim 1, characterized in that: Step 6: For data of unknown protocols, input them into the W-GRU-FCN classification network model after preprocessing, complete the semantic inference of protocol messages, and use network data of known protocols to simulate network data of unknown protocols for testing. The specific method is as follows: The DCCP protocol is used to simulate an unknown protocol for testing. The same preprocessing as in training is adopted, and the optimal weights of the model are loaded. The network structure is the same as in training. The input is the preprocessed overall time series and sending time series with classification labels, and the returned field semantic classification results.
8. A method for semantic inference of protocol message fields based on session context, characterized in that: The method for semantic inference of protocol message fields based on session context described in any one of claims 1 to 7 is used to implement semantic inference of protocol message fields based on session context.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for semantic inference of protocol message fields based on session context according to any one of claims 1 to 7 is used to implement semantic inference of protocol message fields based on session context.
10. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method for semantic inference of protocol message fields based on session context based on any one of claims 1 to 7 is utilized to implement semantic inference of protocol message fields based on session context.
Citation Information
Patent Citations
Method for automatic reverse analysis of unknown protocol
CN112702235A
Industrial control protocol semantic analysis method based on industrial side channel information
CN114745417A
Unknown protocol reverse analysis method based on named entity recognition
CN115334179A
Security protocol semantic level format analysis method and system based on network traffic
CN116248565A
Unknown industrial control protocol reverse analysis method and device
CN117354207A
Cited By
Network protocol reverse analysis method based on deep learning and graph neural network
CN120321322A
Encrypted anonymous network traffic analysis and identification method based on traffic reconstruction
CN120935287A