TCP (Transmission Control Protocol) data enhancement method and system for encrypted traffic classification

By simulating the TCP protocol behavior, multi-path transmission, sliding window and TCP congestion control mechanism are used to enhance packets in disorder, retransmission and length characteristics of encrypted network traffic, solving the problem of inconsistent characteristics of the existing technology in diversified and dynamic network environments, and significantly improving the robust performance of traffic and the classification ability of deep learning models.

CN120128546AActive Publication Date: 2025-06-10NANJING UNIV OF INFORMATION SCI & TECH

Patent Information

Application Number
CN202510604686.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-06-10
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

Existing encrypted network traffic classification technologies usually can only be trained for a single network environment and cannot adapt to diversified and dynamic network environments, resulting in inconsistent features extracted under different network conditions and the classification capability of deep learning models is reduced.

Method used

By simulating the behavior of the TCP protocol in a real network environment, a multi-path transmission mechanism, sliding window mechanism and TCP congestion control mechanism are used to enhance packet out of order, retransmission enhancement and packet length feature enhancement to generate more robust traffic features.

Benefits of technology

The robust performance of traffic is significantly improved in different network environments, and the adaptability and classification accuracy of deep learning models under dynamic network conditions are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128546A_ABST
    Figure CN120128546A_ABST
Patent Text Reader

Abstract

The invention provides a TCP (Transmission Control Protocol) data enhancement method and system oriented to encrypted traffic classification, and the system comprises a data preprocessing module which is used for preprocessing collected network data to form data enhancement feature input; the out-of-order feature enhancement module is used for setting a plurality of paths through a multi-path transmission mechanism, distributing the data packets to different paths by utilizing a hash function, increasing delay, sorting according to a transmission delay sequence and recombining the data packets; the retransmission data enhancement module is used for setting packet loss to trigger a retransmission mechanism in dynamic window adjustment, and inserting a retransmission data packet into an enhancement queue; and the data packet length characteristic enhancement module is used for processing the data packets according to the congestion window and the dynamic segmentation control algorithm by dynamically adjusting the size of the maximum message segment, and adjusting the length characteristics of the data packets in the sequence. According to the method, the accuracy of encrypted traffic feature description in different network environments is improved, and the detection capability of deep learning on encrypted traffic classification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of network communication and artificial intelligence, and particularly relates to a TCP data enhancement method and system for encrypted traffic classification. Background Art

[0002] With the rapid popularization of encrypted traffic and its extensive applications in fields such as HTTPS, VPN, and cloud services, encrypted data dominates network traffic. Traditional content - and rule - based traffic classification methods exhibit significant limitations when faced with encrypted traffic and dynamic network environments. Deep learning, especially self - supervised learning methods, have gradually become the mainstream technology for encrypted traffic classification because they do not require manual feature design and have the ability to automatically extract complex patterns. To cope with different network environment changes and consider the characteristics of network protocols, it is very important to enhance data and extract more robust features for the classification of encrypted traffic.

[0003] Existing technologies have attempted to use data enhancement for network traffic classification. For example, the invention "Malicious traffic hypothesis detection method and device based on attention mechanism and data enhancement (CN119172107A)" discloses a malicious traffic detection method that enhances training data through starGAN, then fine - tunes and trains the Transformer, extracts feature information in the traffic, and then performs a KS test on it to give the confidence level that the traffic is malicious. The invention "Network intrusion detection method based on data enhancement and self - supervised feature enhancement (CN114978613B)" discloses an intrusion traffic detection method that constructs a semi - self - supervised model composed of a CNN - BiLSTM neural network and an auto - encoder to extract high - dimensional traffic features and self - supervised features respectively, and uses the combined features after feature enhancement as the final features for input. The invention "Category - imbalance encrypted traffic data enhancement method and system based on WSAGAN (CN118643325A)" discloses a traffic classification method that uses a generative adversarial network model to generate augmented encrypted traffic sample data and forms an enhanced encrypted traffic sample data set with real encrypted traffic sample data. The invention "Network traffic generation data enhancement method based on diffusion model (CN118282948A)" discloses a classification model that converts original network traffic data into a two - dimensional RGB image form and inputs it into a diffusion model for training to expand the network flow image data set and effectively synthesize the original network traffic of a specified category. These methods do not consider the following two problems:

[0004] (1) Existing encrypted network traffic classification technologies are usually trained for a single network environment without considering diverse and dynamic network environments. This results in inconsistent features extracted by the model under network conditions different from the training environment (such as high latency and high packet loss rate), and the classification and malicious traffic detection capabilities of deep learning models will decline sharply.

[0005] (2) In the field of traffic data augmentation, the mainstream method is to use generative models for data augmentation, such as using generative adversarial models (GANs), diffusion models, etc. Although this model-based data augmentation can utilize mature algorithms, it only considers enhancing data diversity and does not consider improving the robustness of data features. Especially in a dynamic network environment, it will cause changes in traffic features, and diverse traffic data needs to be generated according to its specific features to approximate the actual network scenario. Summary of the Invention

[0006] Object of the Invention: The technical problem to be solved by the present invention is to provide a TCP (Transmission Control Protocol) data augmentation method and system for encrypted traffic classification to address the problem that in different network environments, traffic features change, the extracted features are not robust enough, and the classification accuracy of deep learning models decreases.

[0007] The method includes the following steps: Step 1, preprocess the collected traffic data: Record the length of each data packet in chronological order from each traffic flow, generate classification labels according to the traffic type, obtain the packet length sequence of each flow, and perform length unification processing on the packet length sequence; Step 2, according to the multi-path transmission mechanism, create more than two independent paths, set random delays, packet loss rates, and bandwidths for each path, and use a hash function to distribute data packets to different paths; Reorganize the data packets by sorting according to the transmission delay to achieve packet disorder augmentation; Step 3, use the sliding window mechanism to simulate random packet loss during the data packet transmission process, trigger the retransmission mechanism, and insert the retransmitted data packets into the augmentation queue to achieve generated data packet retransmission augmentation; Step 4, control the size of data packet transmission according to the congestion control mechanism of TCP, make corresponding adjustments to the congestion control stage according to the dynamic adjustment of the maximum segment size MSS and the state change of the round-trip time RTT of the data packet, perform dynamic segmentation control on the data packet, and adjust the data packet length size to achieve data packet length feature augmentation.

[0008] Step 1 includes: Step 1-1: Capture the original network data stream and extract key fields, including: IP packet length, timestamp, and the five-tuple: source IP, destination IP, source port, destination port, and protocol type. Step 1-2: Group the data into independent flows according to the five-tuple (src_ip, dst_ip, src_port, dst_port, protocol), and sort the packets within each flow in ascending order of timestamp; where src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type. Step 1-3: Uniformly process the packet length sequence of each flow. If the number of packets is less than N, pad with zeros; if the number of packets exceeds N, truncate. The general value range of N is from 50 to 200, depending on the application scenario and data characteristics. Step 1-4: Associate a label, such as ["Normal", "Malicious"], ["Web Traffic", "File Transfer", "Streaming"], ["YouTube", "Netflix", "Twitch"], with each packet length sequence. Step 1-5: Save the processed data in CSV file format. The first N columns of each row represent the packet length sequence, and the last column represents the label of the flow. Separate the packet length sequence and the label, extract the label column, encode the label, standardize the classification label to a numerical value, store the packet length sequence as features in a data class, and convert it to a NumPy array.

[0009] Step 2 includes: Step 2-1: Dynamic path initialization processing: Create more than two independent paths. Set the value range of the number of paths from 2 to 8 according to the actual application scenario. Set the following dynamic parameters for each path: queue length Q, used to record the size of the packets currently waiting to be transmitted; dynamic delay value D, used to simulate the delay fluctuations caused by various factors in the real network; packet loss rate q, used to count the number of recent packet losses; dynamic bandwidth B, used to periodically measure the actual transmission rate. Step 2-2: Set the dynamic bandwidth B. Update the bandwidth by triggering a check periodically. Check the difference between the current time and the time of the last bandwidth update. If the difference is greater than the preset bandwidth update interval, generally set the bandwidth update interval to 1 second, and trigger the update of the bandwidth. The formula is: (1), (2), Among them, the congestion level c is the ratio of the current queue length Q to the queue length threshold The queue length threshold is generally set in the range of 1KB to 10MB. The low-latency path range is from 1KB to 1MB, and the high-throughput path range is from 5MB to 10MB; is the path base bandwidth. Each path will set a different initial value according to the transmission capacity of the path, that is, the path base bandwidth ; is the congestion sensitivity coefficient, generally ranging from [0.1, 0.5]. The larger the value, the faster the bandwidth drops during congestion; is the bandwidth perturbation weight, generally ranging from [0.1, 0.3], which is used to control the amplitude of random noise and simulate the interference of network background traffic; is Gaussian noise, which is used to increase the authenticity of bandwidth fluctuations; Step 2-3, set the dynamic delay value: Calculate the average delay according to the current queue length Q and the dynamic bandwidth B , which reflects the real-time load situation of each path and is used for data allocation in the later multi-path algorithm. The delay standard deviation reflects the stability of the path, that is, simulates the fluctuation of the delay after the load increases. The formula is: (3), (4), Among them, is the base delay of the path. Each time a data packet enters, the queue length Q is updated, and and ; Step 2-4, set the dynamic packet loss rate : (5), Among them, is the base packet loss rate, that is, the inherent packet loss rate of the path, generally ranging from 0.01% to 5%; is generally 1MB. After exceeding this threshold the packet loss rate will increase; is the adjustment coefficient, which controls the amplitude of the packet loss rate increase with the load, and the value range is from 0.1 to 0.5; Step 2-5, allocate data packets to paths: Calculate the weight of each path, and calculate the selection probability of each path according to the weight of path i and the total weight of all paths : (6), (7), wherein, is the weight of the i-th path, is the current available bandwidth of the path, is the real-time average delay of the path, reflecting network jitter; Construct a hash probability mapping, use the packet length feature as the feature of the hash input, hash the generated string using the hash function SHA-256, obtain a hash value of a fixed length, modulo normalize it to [0,1), and use binary search to match the cumulative probability interval to determine the selected path; Step 2-6, when each packet arrives at the path, a delay value D needs to be added to simulate the delay fluctuation caused by various factors in the real network. The formula is: (8), (9), wherein, is the base delay of the path, generate random noise from the standard normal distribution to simulate the delay fluctuation caused by network load and other uncertain factors; is the transmission delay, that is, the time required for the packet to be sent onto the path, is the size of the current packet; is the waiting time caused by network congestion, is the transmission delay coefficient, which is inversely proportional to the bandwidth; Step 2-7, reorder out-of-order packets: Each packet needs to add a timestamp when it is sent. The receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the packet arrives at the receiving end, and sorts them according to the arrival order to form the final out-of-order sequence.

[0010] Step 3 includes the following steps: Step 3-1, initialize parameters: The initial stage is the slow start stage. Set the initial congestion window cwnd, slow start threshold (generally in the range of 10~50 MSS), maximum window and minimum window , and the maximum segment size MSS; MSS refers to the maximum number of bytes of application data that a single data segment can carry in the TCP protocol (excluding the TCP header and IP header), which is a length value; Step 3-2, dynamic window adjustment: It is divided into two stages. The first stage is the slow start stage, at this time , the window ; The second stage is the congestion avoidance stage, at this time , each time a data packet is added to the transmission queue M, the counter is incremented, and when the counter reaches the slow start threshold ssthresh, an adjustment is triggered, and the window is adjusted to ; Step 3-3, if random packet loss occurs, the window is shrunk, and based on retransmission, a data enhancement result is obtained. During the window shrinkage stage triggered by fast retransmission, the slow start threshold is updated , the window is updated , during the window shrinkage stage triggered by timeout retransmission, the window is reset , the slow start threshold is updated , is the window size before timeout; Step 3-4, set the reference packet loss rate , where the parameter b is the adjustment weight of the initial congestion window cwnd for the packet loss rate, which can be set during the slow start stage , set during the congestion avoidance stage , set during the window shrinkage stage triggered by fast retransmission , set during the window shrinkage stage triggered by timeout retransmission , when b belongs to multiple stages simultaneously, it is triggered according to the defined priority. When b = 0.3, fast retransmission is preferentially triggered; when b = 0.1, congestion avoidance is preferentially triggered; when b = 0.5, timeout retransmission is preferentially triggered; the random packet loss probability is set according to the dynamic formula (9) : (10), where is the inherent packet loss probability of the path in the non-congested state; Set a random number , if , then the data packet is normally sent to the final confirmation queue. If , then the data packet is marked as lost and added to the queue waiting for confirmation, waiting for retransmission; Step 3-5, when the number of duplicate ACKs for the detected packet loss reaches more than 3 times, fast retransmission is triggered; ACK refers to the signal sent by the receiver to the sender to confirm that the data packet has been successfully received; timeout retransmission is performed after detecting a delay exceeding the RTO period. RTO is the maximum time for the sender to wait for the receiver to return a confirmation (ACK) after sending a data packet. To simplify the steps, set a random number , the fast retransmission probability , if , then fast retransmission is triggered. If , then timeout retransmission is triggered; Step 3-6, if , trigger fast retransmission, enter the fast retransmission trigger window shrinking stage, add the data packet to the pending confirmation queue buf, and every time an ACK signal sent by the receiver to the sender is received, transfer the data packet to the final confirmation queue, and set the maximum number of repetitions , that is, when the confirmation retransmission signal is received for the third time and the data is repeated, the window is dynamically adjusted according to steps 3-2 and 3-3; Step 3-7, if , trigger timeout retransmission, enter the timeout retransmission trigger window shrinking stage. The general scenario is continuous packet loss. Adjust the random probability, set the continuous packet loss quantity S, add the data packet to the pending confirmation queue, set the timeout retransmission delay range for packet loss as T, simulate the timeout waiting, wait for T data packets for each lost packet and then trigger retransmission, insert it after T data packets, keep the original packet order, and dynamically adjust the window according to steps 3-2 and 3-3 after the data is repeated until all data is traversed to obtain the final data repetition enhancement list.

[0011] In step 4, for the data table that has undergone out-of-order enhancement and retransmission enhancement, perform the following steps: Step 4-1, initialization processing: generate a random delay sequence delays to simulate the delay in network transmission; the pending confirmation queue buf is used to simulate the data packet buffer; the final confirmation queue res is used to store the final enhancement processing result; initialize the relevant parameters of congestion control, including: set the initial congestion window cwnd value to 1MSS; initialize the slow start threshold ssthresh, with the initial value set to 44MSS; initialize the maximum segment size MSS to cover different network environments, set the candidate list of the maximum segment size MSS, including the maximum segment size MSS candidate values in different scenarios, taking 1460 in the standard Ethernet, taking the minimum security value of 536 in the traditional wide area network, taking 1448 in the VPN tunnel encapsulation scenario, taking 1232 when running the IPv6 protocol in the Ethernet point-to-point protocol environment, and set the initial maximum segment size MSS; set the initial bandwidth, process the delay and the basic propagation delay ; Step 4-2, dynamically adjust the maximum segment size MSS, set the probability P = 15% to trigger MSS reduction, filter all values smaller than the current MSS from the candidate list of the maximum segment size MSS, and take the maximum value in the filtering result; set the probability P = 8% to simulate path recovery detection, filter all values larger than the current MSS from the candidate list, and take the minimum value in the filtering result; Step 4-3, in a dynamic Maximum Transmission Unit (MTU) network environment, TCP triggers the active adjustment of the Maximum Segment Size (MSS) by perceiving the change in the path MTU in real time, which directly affects the calculation of the Round-Trip Time (RTT), and calculates the RTT value: (11); Step 4-4, Packet processing: Within each RTT, based on the dynamic MSS fragmentation strategy and congestion window limit, split the packet into compliant segments; Step 4-5, Adjustment result: Add the data of the processed packets within the current RTT to the final result; adjust the congestion window and slow start threshold according to the transmission status; Step 4-6, Fixed sequence length: Pad or truncate the result to adjust it to a fixed length, and finally output a packet length sequence with enhanced length features.

[0012] Step 4-4 includes: Step 4-4-1, Delay processing: Take a delay value from the pre-generated dynamic delay sequence delays, subtract the delay value from the RTT time window to obtain the remaining RTT. If the remaining RTT ≤ 0, it means the current window time has expired, stop sending data to the packet buffer buf, and directly send it to the final confirmation queue res; if the remaining RTT > 0, continue to send the packet to the packet buffer buf for packet size segmentation processing; Step 4-4-2, Packet processing: Store the data in the input queue. Each time, take a packet from the input queue and add it to the packet buffer buf for the next operation; Step 4-4-3, If the size of the packet is less than the MSS, do not send the packet immediately. First, cache the packet in the packet buffer buf. When the packets in the packet buffer buf accumulate to be equal to or exceed the MSS, send a complete segment to the final confirmation queue res, and subtract the MSS from the packet buffer buf. The remaining packets continue to be stored in the packet buffer buf for the next accumulation; if the packet size is already greater than or equal to the MSS, directly send it to the final confirmation queue res; Step 4-4-4: According to the limit of the congestion window, check whether the current transmission volume exceeds the congestion window. If the size of the data packet buffer buf is greater than or equal to the current congestion window, it means that the data packet has exceeded the current available window size. Stop sending data packets and wait for the network status to recover; Step 4-4-5: Process the remaining buffer. If there is still unsent data in the data packet buffer buf, that is, the part less than the MSS, and the current window time has not expired, directly add the unsent data to the final confirmation queue res; Step 4-4-6: After processing the data packets within each round-trip time RTT, regenerate a new round-trip time RTT, take the next delay value from the dynamic delay sequence delays, simulate the data packet transmission, and loop through steps 4-4-1 to 4-4-5 until all data packets are processed.

[0013] Step 4-5 includes: Step 4-5-1: Adjust the congestion window. If the round-trip time RTT is not exhausted, that is, the sender receives an acknowledgment ACK signal within the estimated round-trip time RTT, indicating successful transmission of the data packet, adjust cwnd. If cwnd is less than the slow start threshold ssthresh, enter the slow start phase and increase exponentially; otherwise, enter the congestion avoidance phase and increase linearly; Step 4-5-2: If the round-trip time RTT is exhausted, that is, the sender does not receive an acknowledgment ACK signal for a certain data packet within the estimated round-trip time RTT, indicating packet loss, reset the size to a maximum segment size MSS, set the slow start threshold ssthresh to half of the current cwnd, and re-enter the slow start phase.

[0014] The present invention also provides a TCP data enhancement system for encrypted traffic classification implemented based on the above method, including: A data preprocessing module for preprocessing the collected network data to form a feature input for data enhancement; A disordered feature enhancement module for setting multiple paths through a multipath transmission mechanism, using a hash function to allocate data packets to different paths, increasing the delay and sorting them in the order of transmission delay, and reorganizing the data packets; A retransmission data enhancement module for setting a packet loss-triggered retransmission mechanism in dynamic window adjustment and inserting the retransmitted data packets into the enhancement queue; A data packet length feature enhancement module for using dynamic adjustment of the maximum segment size MSS to process data packets according to the congestion window and dynamic segmentation control algorithm within each round-trip time RTT, and adjusting the length size feature of the data packets in the sequence.

[0015] The present invention provides a traffic classification device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of the method are implemented.

[0016] The present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the method are implemented.

[0017] Compared with the prior art, the present invention has the following beneficial effects: 1. In view of the existing encrypted network traffic classification technology, which usually only trains for a single network environment, the present invention innovatively considers a diversified and dynamic network environment. By simulating the protocol behavior of TCP in a real network environment, under different network conditions in the training environment, the features extracted by the model can overcome the inconsistent situation in different scenarios, greatly improving the ability of the deep learning model to adapt to dynamic network conditions.

[0018] 2. In view of the problem of the change of the packet length sequence of encrypted traffic in different network environments, the present invention designs three enhancement methods combining the characteristics of the TCP protocol, realizes the out-of-order enhancement of packets through a multi-path transmission mechanism, performs the retransmission enhancement of packets by using a sliding window mechanism, and enhances the packet length characteristics according to the congestion control mechanism of TCP and dynamically adjusts the MSS to generate a mode that can restore the traffic deformation in the real environment, significantly improving the robust performance of traffic in different network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is a flowchart of the steps of the method of the present invention.

[0020] Figure 2 It is a processing flow of data out-of-order enhancement.

[0021] Figure 3 It is a processing flow of data retransmission enhancement.

[0022] Figure 4 It is a processing flow of data length enhancement. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] The following further describes the present invention in detail with reference to the drawings and specific embodiments, and the above and other advantages of the present invention will become clearer.

[0024] Such as Figure 1As shown in the figure, an embodiment of the present invention provides a TCP data enhancement method for encrypted traffic classification. The method includes: preprocessing the captured encrypted network traffic data, extracting each flow packet payload and the corresponding label, and forming a packet length sequence; performing shuffling, retransmission, and length feature enhancement on the packet length sequence according to the data enhancement loader of the TCP mechanism. The specific steps include: Step 1, preprocess the collected traffic data: record the length of each packet in chronological order from each traffic flow, generate classification labels according to the traffic type, obtain the packet length sequence of each flow, and perform length normalization processing on it; Step 2, according to the multi-path transmission mechanism, create more than two independent paths, set random delays, packet loss rates, and bandwidths for each path, and use a hash function to distribute the packets to different paths; realize packet shuffling enhancement by sorting and reorganizing the packets according to the transmission delay; Step 3, use the sliding window mechanism to simulate random packet loss during the packet transmission process, trigger the retransmission mechanism, retransmit the packets and insert them into the enhancement queue to realize the generation of packet retransmission enhancement; Step 4, control the size of the packet transmission according to the congestion control mechanism of TCP, make corresponding adjustments to the congestion control stage according to the dynamic adjustment of the maximum segment size MSS and the state change of the packet round-trip time RTT, perform dynamic segmentation control on the packets, and adjust the packet length size to realize packet length feature enhancement.

[0025] In this embodiment, Step 1 includes: Step 1-1, capture the original network data stream, extract key fields, including: IP packet length, timestamp, and five-tuple (source IP, destination IP, source port, destination port, protocol type); Step 1-2, group by five-tuple (src_ip, dst_ip, src_port, dst_port, protocol) into independent flows, and sort the packets in each flow in ascending order of timestamp; where src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type; Step 1-3, perform normalization processing on the packet length sequence of each flow. If the number of packets is less than N = 100 in length, fill it with zeros. If the number of packets exceeds N = 100 in length, truncate it; Step 1-4, associate a label label with each packet length sequence; Steps 1 - 5, save the processed data in the CSV file format, where the first 99 columns of each row represent the packet length sequence, and the last column represents the label of the flow. Separate the packet length sequence and the label, extract the label column, encode the label, standardize the classification label to a numerical value, store the packet length sequence as a feature in a data class, and convert it into a NumPy array as the format for subsequent data augmentation processing; Convert the network traffic data into a data length sequence format suitable for data augmentation through the above Step 1.

[0026] In this embodiment, as Figure 2 shown, the packet length sequence scrambling augmentation needs to be operated through the following steps: In Step 2, input the pre - processed data set into the packet scrambling augmentation processor. The specific steps are as follows: Step 2 - 1, dynamic path initialization processing: Create 4 independent paths, and set the following dynamic parameters for each path: queue length Q, used to record the size of the packets currently waiting to be transmitted; dynamic delay value D, used to simulate the delay fluctuations caused by various factors in the real network; packet loss rate q, used to count the latest number of packet losses; dynamic bandwidth B, used to periodically measure the actual transmission rate; Step 2 - 2, set the dynamic bandwidth B. Update the bandwidth by triggering a check periodically. Check the difference between the current time and the time of the last bandwidth update. If this difference is greater than the preset bandwidth update interval, set the bandwidth update time interval to 1 second and trigger the update of the bandwidth according to the following formula: (1), (2), where the congestion level c is the ratio of the current queue length Q to the queue length threshold The queue length threshold is generally set in the range of 1KB - 10MB. Set the queue length threshold of path 1 to 10KB, path 2 to 1MB, path 3 to 5MB, and path 4 to 10MB. is the path base bandwidth. Set the of path 1 to 100Mbps, path 2 to 500Mbps, path 3 to 100Mbps, and path 4 to 1Gbps. is the congestion sensitivity coefficient, generally in the range of [0.1, 0.5]. The larger the value, the faster the bandwidth drops during congestion; Bandwidth perturbation weight, generally in the range of [0.1, 0.3], controls the amplitude of random noise and simulates the interference of network background traffic; is Gaussian noise, which increases the authenticity of bandwidth fluctuations; Step 2-3, set the dynamic delay value: calculate the average delay according to the current queue length Q and the dynamic bandwidth B , which reflects the real-time load situation of each path and is used for data allocation in the later multi-path algorithm. The standard deviation of delay reflects the stability of the path, that is, the fluctuation of the delay after simulating the increase of the load. According to the following formula: (3), (4), where, is the basic delay of the path. Set the value of path 1 to be 100 Mbps, path 2 to be 500 Mbps, path 3 to be 100 Mbps, and path 4 to be 1 Gbps. Update the queue length Q each time a data packet enters, and update the calculation and ; Step 2-4, set the dynamic packet loss rate : (5), where, is the basic packet loss rate, that is, the inherent packet loss rate of the path. Generally, the value range is 0.01% - 5%. Set the value of path 1 to be 0.1%, path 2 to be 0.2%, path 3 to be 1%, and path 4 to be 0.5%. is the queue length threshold. After exceeding this threshold, the packet loss rate will increase; is the adjustment coefficient, which controls the amplitude of the packet loss rate increasing with the load. The value range is 0.1 - 0.5; Step 2-5, allocate data packets to paths: calculate the weight of each path , and calculate the selection probability of each path according to the weight of path i and the total weight of all paths : (6), (7), In formula (6), is the path weight, is the current available bandwidth of the path, is the real-time average delay of the path, is the standard deviation of delay, which reflects network jitter.

[0027] Construct a hash probability mapping. Use the packet length feature as a feature of the hash input. Use the hash function SHA-256 to hash the generated string to obtain a hash value of a fixed length, and take the modulus to normalize it to [0, 1). Use binary search to match the cumulative probability interval to determine the selection path. Step 2-6, when each packet arrives at the path, a delay value D needs to be added to simulate the delay fluctuations caused by various factors in the real network. The formula is: (8), (9), where, is the base delay of the path. Generate random noise from the standard normal distribution to simulate the delay fluctuations caused by network load and other uncertain factors. is the standard deviation of the delay, representing the amplitude of the delay fluctuations; is the transmission delay, that is, the time required for the packet to be sent onto the path. is the waiting time caused by network congestion. is the transmission delay coefficient, which is inversely proportional to the bandwidth; Step 2-7, reorder out-of-order packets: Each packet needs to add a timestamp T when it is sent. The receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the packet arrives at the receiving end, and sorts them according to the arrival order to form the final out-of-order sequence.

[0028] In this embodiment, as Figure 3 shown, data duplication enhancement needs to be operated through the following steps: In step 3, the preprocessed data is input into the data retransmission enhancement processing module. The specific steps are as follows: Step 3-1, initialize the parameters. The initial stage is the slow start stage, and the window size , the slow start threshold , the maximum window , the minimum window , and the MSS is set to 1448; Step 3-2, dynamic window adjustment: It is divided into two stages. The first stage is the slow start stage, at this time , and the window is ; The second stage is the congestion avoidance stage, at this time , when adding a packet to the transmission queue M each time, the counter is incremented. When the counter reaches the slow start threshold ssthresh, an adjustment is triggered, and the window is adjusted to ; Step 3-3, if random packet loss occurs, reduce the window, obtain the data enhancement result based on retransmission. During the fast retransmission-triggered window reduction phase, update the slow start threshold , update the window , during the timeout retransmission-triggered window reduction phase, reset the window , update the slow start threshold , is the window size before timeout; Step 3-4, set the baseline packet loss rate , where parameter b is the adjustment weight of the congestion window cwnd for the packet loss rate. Set b = 0.2 during the slow start phase, b = 0.08 during the congestion avoidance phase, b = 0.4 during the fast retransmission-triggered window reduction phase, and b = 0.8 during the timeout retransmission-triggered window reduction phase. Set the random packet loss probability according to the dynamic formula (9) : (10), Set a random number , if , then normally send the data packet to the final confirmation queue. If , then mark the data packet as lost and add it to the queue to be confirmed, waiting for retransmission; Step 3-5, when the number of duplicate ACKs for the detected packet loss reaches more than 3 times, ACK refers to the signal sent by the receiver to the sender to confirm the successful reception of the data packet, triggering fast retransmission; perform timeout retransmission after detecting a delay exceeding the RTO period. RTO is the maximum time for the sender to wait for the receiver to return an acknowledgment (ACK) after sending a data packet. Simplify the steps, set a random number , fast retransmission probability , if , then trigger fast retransmission. If , then trigger timeout retransmission; Step 3-6, if , trigger fast retransmission, add the data packet to the queue to be confirmed buf. Each time an ACK is received, transfer the data packet to the final confirmation queue, and set the maximum number of repetitions , that is, when receiving the signal for retransmission confirmation for the third time and the data is repeated, dynamically adjust the window according to Steps 3-2 and 3-3; Step 3-7, if , trigger timeout retransmission. The general scenario is continuous packet loss. Adjust the random probability, set the number of consecutive packet losses , add the data packet to the queue to be confirmed, and set the timeout retransmission delay range for packet loss to be , simulate the timeout waiting, wait for each lost packet for After T data packets are triggered for retransmission and inserted after T data packets, while maintaining the original packet order, after data duplication, the window is dynamically adjusted according to steps 3-2 and 3-3 until all data is traversed to obtain the final data duplication enhancement list.

[0029] In this embodiment, as Figure 4 shown, the data length enhancement needs to be operated through the following steps: In step 4, the preprocessed data is input into the data length enhancement processing module, and the specific steps are as follows: Step 4-1, initialization processing: Generate a random delay sequence delays to simulate the delay in network transmission; the pending confirmation queue buf is used to simulate the data packet buffer; the final confirmation queue res is used to store the final enhancement processing result; initialize the relevant parameters of congestion control, and set the initial congestion window value to 1MSS; initialize the slow start threshold ssthresh, with an initial value set to 44MSS; initialize the maximum segment size MSS to cover different network environments, set a candidate list of the maximum segment size MSS, including the candidate values of the maximum segment size MSS in different scenarios, and the candidate values include 536, 1232, 1448, 1460, and set the initial maximum segment size MSS value to 1448; set the initial bandwidth, processing delay and the base propagation delay ; Step 4-2, dynamically adjust the maximum segment size MSS, set the probability P = 15% to trigger MSS reduction, filter all values smaller than the current MSS from the MSS candidate list, and take the maximum value of the filtering result; set the probability P = 8% to simulate path recovery detection, filter all values larger than the current maximum segment size MSS from the candidate list, and take the minimum value of the filtering result; Step 4-3, in a dynamic maximum transmission unit MTU network environment, TCP actively adjusts the maximum segment size MSS by real-time sensing the change of the path maximum transmission unit MTU. The round-trip time RTT will be determined by the data packet transmission time, ACK transmission time, and delay. The dynamic value of the maximum segment size MSS is 536, 1232, 1448, 1460, in bytes, the ACK size is a fixed value of 40 bytes, the initial bandwidth is 100Mbps, the processing delay base propagation delay , calculate the RTT value: (11), Step 4-4, data packet processing: Within each round-trip time RTT, based on the dynamic maximum segment size MSS fragmentation strategy and congestion window limit, split the data packet into compliant segments; Step 4-5, adjust the result, add the processed packet data within the current round-trip time RTT to the final result; adjust the congestion window and slow start threshold according to the transmission status; Step 4-6, fix the sequence length, pad or truncate the result to adjust it to a fixed length, and finally output the packet length sequence with enhanced length features.

[0030] Step 4-4 includes: Step 4-4-1, delay processing: Take a delay value from the pre-generated dynamic delay sequence delays, subtract the delay value from the round-trip time RTT time window to obtain the remaining round-trip time remaining_RTT. If the remaining round-trip time remaining_RTT ≤ 0, it means the current window time has expired, stop sending data to the packet buffer buf, and directly send it to the final confirmation queue res; if the remaining round-trip time remaining_RTT > 0, continue to send the packet to the packet buffer buf for packet size segmentation processing; Step 4-4-2, packet processing: Store the data in the input queue, and each time take a packet from the input queue and add it to the packet buffer buf for the next operation; Step 4-4-3, if the size of the packet is less than the maximum segment size MSS, do not send the packet immediately. First, cache the packet in the packet buffer buf. When the packets in the packet buffer buf accumulate to be equal to or exceed the maximum segment size MSS, send a complete segment to the final confirmation queue res, and subtract the maximum segment size MSS from the packet buffer buf. The remaining packets continue to be stored in the packet buffer buf for the next accumulation; if the packet size is already greater than or equal to the maximum segment size MSS, directly send it to the final confirmation queue res; Step 4-4-4, according to the limit of the congestion window, check whether the current transmission volume exceeds the congestion window. If the size of the packet buffer buf is greater than or equal to the current congestion window, it means the packet has exceeded the current available window size, stop sending the packet, and wait for the network status to recover; Step 4-4-5, process the remaining buffer. If there is still unsent data in the packet buffer buf, that is, the part less than MSS, and the current window time has not expired, directly add the unsent data to the final confirmation queue res; Step 4-4-6: After processing the data packets within each round-trip time (RTT), generate a new RTT. Retrieve the next delay value from the dynamic delay sequence "delays" and simulate data packet transmission. Loop through steps 4-4-1 to 4-4-5 until all data packets are processed.

[0031] Step 4-5 includes: Step 4-5-1: Adjust the congestion window. If the round-trip time (RTT) is not exhausted, i.e., the sender receives an acknowledgment (ACK) within the estimated RTT, indicating successful data packet transmission, adjust cwnd. If cwnd is less than ssthresh, enter the slow start phase and increase it exponentially; otherwise, enter the congestion avoidance phase and increase it linearly. Step 4-5-2: If the round-trip time (RTT) is exhausted, i.e., the sender does not receive an ACK for a certain data packet within the estimated RTT, indicating packet loss, reset the size to one maximum segment size (MSS), set ssthresh to half of the current cwnd, and re-enter the slow start phase.

[0032] The present invention provides a TCP data enhancement method and system for encrypted traffic classification. There are many methods and ways to specifically implement this technical solution. The above description is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Each component not clearly defined in this embodiment can be implemented using existing technologies.

Claims

1. A TCP data enhancement method for encrypted traffic classification, characterized in that: The method comprises the following steps: Step 1: pre-process the collected traffic data: record the length of each data packet in each flow in chronological order, generate classification labels according to the traffic type, obtain the packet length sequence of each flow, and unify the length of the packet length sequence; Step 2: According to the multi-path transmission mechanism, two or more independent paths are created, random delay, packet loss rate and bandwidth are set for each path, and the data packets are allocated to different paths using a hash function; the data packets are reorganized by sorting the transmission delay to achieve data packet out-of-order enhancement; Step 3: Using the sliding window mechanism, simulate the random packet loss during data packet transmission, trigger the retransmission mechanism, insert the retransmitted data packet into the enhancement queue, and realize the generation of data packet retransmission enhancement; Step 4: Control the size of data packet transmission according to the congestion control mechanism of TCP. According to the dynamic adjustment of the maximum segment size MSS and the state change of the data packet round-trip time RTT, make corresponding adjustments to the congestion control stage, dynamically segment the data packet, adjust the data packet length, and enhance the data packet length feature.

2. The method according to claim 1, characterized in that: Step 1 includes: Step 1-1, capture the original network data flow and extract key fields, including: IP packet length, timestamp, and five-tuple: source IP, destination IP, source port, destination port, protocol type; Step 1-2, group the packets into independent flows according to the five-tuple (src_ip, dst_ip, src_port, dst_port, protocol), and sort the packets in each flow in ascending order by timestamp; src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type; Step 1-3, unify the length sequence of the data packets of each flow, fill with zeros if the number of data packets is less than the length N, and truncate if the number of data packets exceeds the length N; Step 1-4, associate a label label with each data packet length sequence; Steps 1-5: Save the processed data in CSV file format, where the first N columns of each row represent the packet length sequence, and the last column represents the label of the flow. Separate the packet length sequence and label, extract the label column, encode the label, standardize the classification label to a numerical value, store the packet length sequence as a feature in the data class, and convert it into a NumPy array.

3. The method according to claim 2, characterized in that Step 2 includes: Step 2-1, dynamic path initialization processing: create two or more independent paths, set the range of path quantity, and set the following dynamic parameters for each path: queue length Q, used to record the size of the current data packet to be transmitted; dynamic delay value D, used to simulate the delay fluctuation caused by various factors in the real network; packet loss rate q, used to count the latest number of packet losses; dynamic bandwidth B, used to periodically measure the actual transmission rate; Step 2-2, set the dynamic bandwidth B, update the bandwidth once by periodically triggering the check, check the difference between the current time and the time of the last bandwidth update, if the difference is greater than the preset bandwidth update interval, trigger the bandwidth update, the formula is: (1), (2), Among them, the congestion level c is the current queue length Q and the queue length threshold The ratio of is the path base bandwidth; is the congestion sensitivity coefficient; is the bandwidth perturbation weight; is Gaussian noise; Step 2-3, set the dynamic delay value: calculate the average delay based on the current queue length Q and dynamic bandwidth B , the formula is: (3), (4), in is the delay standard deviation, is the basic delay of the path, and the queue length Q is updated each time a packet enters. and ; Step 2-4, set dynamic packet loss rate : (5), in, is the basic packet loss rate; is the adjustment coefficient; Step 2-5, assign data packets to paths: Calculate the weight of each path, and calculate the selection probability of each path based on the weight of path i and the total weight of all paths. : (6), (7), in, is the weight of the ith path, is the current available bandwidth of the path, is the real-time average delay of the path; Construct a hash probability map, use the packet length feature as the hash input feature, use the hash function SHA-256 to hash the generated string, get a fixed-length hash value modulo normalized to [0,1), use binary search to match the cumulative probability interval, and determine the selected path; In step 2-6, a delay value D needs to be added when each data packet arrives at the path to simulate the delay fluctuation caused by various factors in the real network. The formula is: (8), (9), in, is the base delay of the path, drawn from a standard normal distribution Generate random noise in is the transmission delay, is the current packet size; is the waiting time caused by network congestion, is the transmission delay coefficient; Step 2-7, reorganize out-of-order data packets: Each data packet needs to add a timestamp when it is sent. The receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the data packet arrives at the receiving end, and sorts them according to the order of arrival to form the final out-of-order sequence.

4. The method according to claim 3, characterized in that: Step 3 includes the following steps: Step 3-1, initialization parameters: The initial stage is the slow start stage, set the initial congestion window cwnd and slow start threshold , Maximum Window and minimum window , and the maximum segment size MSS; MSS refers to the maximum number of bytes of application data that can be carried in a single data segment in the TCP protocol; Step 3-2, dynamic window adjustment: It is divided into two stages. The first stage is the slow start stage. ,window ; The second stage is the congestion avoidance stage. Each time a packet is added to the transmission queue M, the counter is incremented. When the counter reaches the slow start threshold ssthresh, the adjustment is triggered and the window is adjusted to ; Step 3-3: If random packet loss occurs, the window is reduced, and data enhancement results are obtained based on retransmission. In the fast retransmission trigger window reduction phase, the slow start threshold is updated. , update window , timeout retransmission triggers the window reduction phase, reset the window , update the slow start threshold , is the window size before timeout; Step 3-4, set the baseline packet loss rate , parameter b is the adjustment weight of the initial congestion window cwnd on the packet loss rate, set in the slow start phase , set in the congestion avoidance phase , Fast retransmit trigger window reduction stage setting , timeout retransmission triggers window reduction stage setting , when b=0.3, fast retransmission is triggered first; when b=0.1, congestion avoidance is triggered first; When b=0.5, timeout retransmission is triggered first; Set the random packet loss probability according to formula (9) : (10), in is the inherent packet loss probability of the path in a non-congested state; Setting random numbers ,if , then send the data packet to the final confirmation queue normally. If , the data packet is marked as lost and added to the pending confirmation queue, waiting for retransmission; Step 3-5: When the number of repeated ACKs for packet loss reaches more than 3 times, a fast retransmission is triggered; ACK is a signal sent by the receiver to the sender to confirm that the data packet has been successfully received; after the delay exceeds the RTO period, a timeout retransmission is performed. RTO is the maximum time the sender waits for the receiver to return an acknowledgment after sending a data packet. Set a random number , fast retransmission probability ,if , then trigger fast retransmission, if , then trigger timeout retransmission; Step 3-6, if , trigger fast retransmission, enter the fast retransmission trigger window reduction phase, add the data packet to the confirmation queue buf, each time the receiver receives the signal ACK sent to the sender, transfer the data packet to the final confirmation queue, and set the maximum number of repetitions , that is, after receiving the confirmation retransmission received signal for the third time, the window is dynamically adjusted according to steps 3-2 and 3-3 after the data is repeated; Step 3-7, if , trigger timeout retransmission, enter the timeout retransmission trigger window reduction stage, set the number of consecutive packet losses S, add the data packet to the queue to be confirmed, set the packet loss timeout retransmission delay range to T, simulate timeout waiting, and trigger retransmission for each lost packet after waiting for T data packets. Insert it after T data packets and keep the original packet order. After the data is repeated, dynamically adjust the window according to steps 3-2 and 3-3 until all the data are traversed to obtain the final data duplication enhancement list.

5. The method according to claim 4, characterized in that In step 4, for the data table that has undergone out-of-order enhancement and retransmission enhancement, perform the following steps: Step 4-1, initialization processing: generate a random delay sequence delays to simulate the delay in network transmission; the pending confirmation queue buf is used to simulate the data packet buffer; the final confirmation queue res is used to store the final enhancement processing results; Initialize the relevant parameters of congestion control, including: setting the initial congestion window cwnd to 1MSS; initializing the slow start threshold ssthresh, with the initial value set to 44MSS; initializing the maximum segment size MSS to cover different network environments, setting the candidate list of the maximum segment size MSS, including the candidate values ​​of the maximum segment size MSS in different scenarios, and setting the initial maximum segment size MSS; setting the initial bandwidth and processing delay and the basic propagation delay ; Step 4-2, dynamically adjust the maximum segment size MSS, set the probability P=15% to trigger the MSS reduction, filter all values ​​smaller than the current MSS from the candidate list of the maximum segment size MSS, and take the maximum value from the screening results; set the probability P=8% to simulate the path recovery detection, filter all values ​​larger than the current MSS from the candidate list, and take the minimum value from the screening results; Step 4-3, in a dynamic maximum transmission unit (MTU) network environment, TCP triggers active adjustment of the maximum segment size (MSS) by real-time sensing of the path maximum transmission unit (MTU) change, which directly affects the round-trip time (RTT) calculation and calculates the RTT value: (11); Step 4-4, data packet processing: within each round trip time RTT, split the data packet into compliant segments based on the dynamic maximum segment size MSS fragmentation strategy and congestion window limit; Step 4-5, adjust the result, add the processed data packet data within the current round-trip time RTT to the final result; adjust the congestion window and slow start threshold according to the transmission status; Steps 4-6, fix the sequence length, pad or truncate the result, adjust it to a fixed length, and finally output the data packet length sequence with enhanced length features.

6. The method according to claim 5, characterized in that Step 4-4 includes: Step 4-4-1, delay processing: take a delay value from the pre-generated dynamic delay sequence delays, deduct the delay value from the RTT time window to get the remaining round-trip time remaining_RTT. If the remaining round-trip time remaining_RTT ≤ 0, it means that the current window time is exhausted, stop sending data to the data packet buffer buf, and send it directly to the final confirmation queue res; if the remaining round-trip time remaining_RTT > 0, continue to send data packets to the data packet buffer buf, and perform data packet size segmentation processing; Step 4-4-2, data packet processing: store the data in the input queue, take out a data packet from the input queue each time, add it to the data packet buffer buf, and proceed to the next step; Step 4-4-3, if the size of the data packet is less than the maximum segment size MSS, the data packet is not sent immediately, but is first cached in the data packet buffer buf. When the data packets in the data packet buffer buf accumulate to equal to or exceed the maximum segment size MSS, a complete segment is sent to the final confirmation queue res, and the maximum segment size MSS is subtracted from the data packet buffer buf. The remaining data packets continue to be stored in the data packet buffer buf for the next accumulation; if the data packet size is already greater than or equal to the maximum segment size MSS, it is directly sent to the final confirmation queue res; Step 4-4-4, according to the limit of the congestion window, check whether the current sending volume exceeds the congestion window. If the size of the data packet buffer buf is greater than or equal to the current congestion window, it means that the data packet has exceeded the current available window size, stop sending data packets, and wait for the network status to recover; Step 4-4-5, process the remaining buffer. If there is still unsent data in the data packet buffer buf and the current window time has not expired, the unsent data will be directly added to the final confirmation queue res; Step 4-4-6, after each data packet within the round-trip time RTT is processed, a new round-trip time RTT is regenerated, and the next delay value is taken from the dynamic delay sequence delays to simulate the data packet transmission, and steps 4-4-1 to 4-4-5 are repeated until all data packets are processed.

7. The method according to claim 6, characterized in that Steps 4-5 include: Step 4-5-1, adjust the congestion window. If the round-trip time RTT is not exhausted, that is, the sender receives the confirmation ACK signal within the estimated round-trip time RTT, indicating that the data packet is successfully transmitted, adjust cwnd. If cwnd is less than the slow start threshold ssthresh, enter the slow start phase; otherwise, enter the congestion avoidance phase; In step 4-5-2, if the round-trip time RTT is exhausted, that is, the sender does not receive the confirmation ACK signal of a data packet within the estimated round-trip time RTT, it means that packet loss has occurred. The reset size is a maximum segment size MSS, and the slow start threshold ssthresh is set to half of the current cwnd, and the slow start phase is re-entered.

8. A TCP data enhancement system for encrypted traffic classification implemented based on the method described in any one of claims 1 to 7, characterized in that: include: A data preprocessing module is used to preprocess the collected network data to form feature input for data enhancement; The out-of-order feature enhancement module is used to,set multiple paths through a multi-path transmission mechanism, assign data packets to different paths using a hash function, increase delays and sort them in the order of transmission delay, and reorganize data packets; The retransmission data enhancement module is used to set the packet loss to trigger the retransmission mechanism in the dynamic window adjustment, and insert the retransmission data packet into the enhancement queue; The data packet length feature enhancement module is used to dynamically adjust the maximum segment size MSS, process data packets according to the congestion window and dynamic segmentation control algorithm within each round-trip time RTT, and adjust the length size characteristics of the data packets in the sequence.

9. A traffic classification device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Network Intrusion Detection Methods Based on Data Augmentation and Self-Supervised Feature Enhancement

    CN114978613B

  • Network flow generation data enhancement method based on diffusion model

    CN118282948A

  • Method and system for enhancing class imbalance encrypted traffic data based on WSAGAN

    CN118643325A

  • Malicious traffic hypothesis detection method and device based on attention mechanism and data enhancement

    CN119172107A

  • Intelligent SPD (Surge Protective Device) based on internet of things

    CN103066703A

Cited By

  • Satellite communication high-speed data transmission method and system

    CN120415550A

  • Secure data transmission method and system for API (Application Program Interface) and medium

    CN120768703A

  • Traffic scheduling method and electronic equipment

    CN121098802A