A TCP Data Enhancement Method and System for Encrypted Traffic Classification

By simulating multi-path transmission, sliding window and TCP congestion control in real network environments, the encrypted traffic data is chaotic, retransmitted and length feature enhancement, which solves the problem of insufficient characteristics in encrypted traffic classification and improves the classification accuracy of the model in dynamic network environments.

CN120128546BActive Publication Date: 2025-07-08NANJING UNIV OF INFORMATION SCI & TECH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510604686.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-08
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

The existing encryption traffic classification technology is not robust enough in different network environments, resulting in a decrease in classification accuracy of deep learning models, and the existing data enhancement methods fail to effectively improve the robustness of data characteristics.

Method used

By simulating the real network environment, the multi-path transmission mechanism, sliding window mechanism and TCP congestion control mechanism are used to enhance the data packets in an out-of-order order, retransmission enhancement and length feature enhancement, and generate a pattern that can restore the traffic deformation of the real environment.

Benefits of technology

It significantly improves the robust performance of the encrypted traffic classification model in dynamic network environments, and enhances the adaptability and classification accuracy of features.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128546B_ABST
    Figure CN120128546B_ABST
Patent Text Reader

Abstract

The present invention provides a TCP data enhancement method and system for encrypted traffic classification. The system includes: a data preprocessing module for preprocessing the collected network data to form a feature input for data enhancement; a disordered feature enhancement module that sets multiple paths through a multipath transmission mechanism, uses a hash function to allocate data packets to different paths, increases the delay and sorts them in the order of transmission delay, and reorganizes the data packets; a retransmission data enhancement module that, in dynamic window adjustment, sets packet loss to trigger a retransmission mechanism and inserts the retransmitted data packets into an enhancement queue; a data packet length feature enhancement module that uses dynamic adjustment of the maximum segment size, processes data packets according to the congestion window and the dynamic segmentation control algorithm, and adjusts the length size feature of the data packets in the sequence. The present invention improves the accuracy of encrypted traffic feature description in different network environments and improves the detection ability of deep learning for encrypted traffic classification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical fields of network communication and artificial intelligence, and particularly relates to a TCP data enhancement method and system for encrypted traffic classification. Background Art

[0002] With the rapid popularization of encrypted traffic and its wide application in fields such as HTTPS, VPN, and cloud services, encrypted data dominates network traffic. Traditional content - and rule - based traffic classification methods show significant limitations when faced with encrypted traffic and dynamic network environments. Deep learning, especially self - supervised learning methods, have gradually become the mainstream technology for encrypted traffic classification because they do not require manual feature design and have the ability to automatically extract complex patterns. To cope with different network environment changes and consider the characteristics of network protocols, it is very important to enhance data and extract more robust features for the classification of encrypted traffic.

[0003] Existing technologies have attempted to use data enhancement for network traffic classification. For example, the invention "Method and device for malicious traffic hypothesis detection based on attention mechanism and data enhancement (CN119172107A)" discloses a malicious traffic detection method that enhances training data through starGAN, then fine - tunes and trains the Transformer, extracts feature information in the traffic, and then performs a KS test on it to give the confidence level that the traffic is malicious. The invention "Network intrusion detection method based on data enhancement and self - supervised feature enhancement (CN114978613B)" discloses an intrusion traffic detection method that constructs a semi - self - supervised model composed of a CNN - BiLSTM neural network and an auto - encoder to extract high - dimensional traffic features and self - supervised features respectively, and uses the combined features after feature enhancement as the final features for input. The invention "Category - imbalance encrypted traffic data enhancement method and system based on WSAGAN (CN118643325A)" discloses a traffic classification method that uses a generative adversarial network model to generate augmented encrypted traffic sample data and forms an enhanced encrypted traffic sample data set with real encrypted traffic sample data. The invention "Network traffic generation data enhancement method based on diffusion model (CN118282948A)" discloses a classification model that converts original network traffic data into a two - dimensional RGB image form and inputs it into a diffusion model for training to expand the network flow image data set and effectively synthesize the original network traffic of a specified category. These methods do not consider the following two problems:

[0004] (1) Existing encrypted network traffic classification technologies are usually trained for a single network environment without considering diverse and dynamic network environments. This results in inconsistent features extracted by the model under network conditions different from the training environment (such as high latency and high packet loss rate), and the classification and malicious traffic detection capabilities of deep learning models will decline sharply.

[0005] (2) In the field of traffic data augmentation, the mainstream method is to use generative models for data augmentation, such as using generative adversarial models (GANs), diffusion models, etc. Although this model-based data augmentation can utilize mature algorithms, it only considers enhancing data diversity and does not consider improving the robustness of data features. Especially in a dynamic network environment, it will cause changes in traffic features, and diverse traffic data needs to be generated according to its specific features to approximate the actual network scenario. Summary of the Invention

[0006] Object of the Invention: The technical problem to be solved by the present invention is to provide a TCP (Transmission Control Protocol) data augmentation method and system for encrypted traffic classification in view of the deficiencies of the prior art, so as to solve the problem that in different network environments, traffic features change, the extracted features are not robust enough, and the classification accuracy of deep learning models decreases.

[0007] The method includes the following steps:

[0008] Step 1, preprocess the collected traffic data: record the length of each data packet in chronological order from each traffic flow, generate classification labels according to the traffic type, obtain the packet length sequence of each flow, and perform length unification processing on the packet length sequence;

[0009] Step 2, according to the multi-path transmission mechanism, create more than two independent paths, set random delays, packet loss rates, and bandwidths for each path, and use a hash function to distribute data packets to different paths; realize packet disorder augmentation by sorting and reorganizing data packets according to transmission delays;

[0010] Step 3, use the sliding window mechanism to simulate random packet loss during the data packet transmission process, trigger the retransmission mechanism, and insert the retransmitted data packets into the augmentation queue to realize the generation of data packet retransmission augmentation;

[0011] Step 4, control the size of data packet transmission according to the congestion control mechanism of TCP, make corresponding adjustments to the congestion control stage according to the dynamic adjustment of the maximum segment size MSS and the state change of the round-trip time RTT of data packets, perform dynamic segmentation control on data packets, and adjust the length of data packets to realize the enhancement of data packet length features.

[0012] Step 1 includes:

[0013] Step 1-1, capture the original network data stream and extract key fields, including: IP packet length, timestamp, and the five-tuple: source IP, destination IP, source port, destination port, protocol type;

[0014] Step 1-2, group the data into independent flows according to the five-tuple (src_ip, dst_ip, src_port, dst_port, protocol), and sort the packets within each flow in ascending order of timestamp; where src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type;

[0015] Step 1-3, perform uniform processing on the packet length sequence of each flow. If the number of packets is less than N in length, pad with zeros; if the number of packets exceeds N in length, truncate. The general value range of N is from 50 to 200, depending on the application scenario and data characteristics;

[0016] Step 1-4, associate a label with each packet length sequence, such as ["Normal", "Malicious"], ["Web Traffic", "File Transfer", "Streaming"], ["YouTube", "Netflix", "Twitch"];

[0017] Step 1-5, save the processed data in CSV file format. The first N columns of each row represent the packet length sequence, and the last column represents the label of the flow. Separate the packet length sequence and the label, extract the label column, encode the labels, standardize the classification labels to numerical values, store the packet length sequence as features in a data class, and convert it to a NumPy array.

[0018] Step 2 includes:

[0019] Step 2-1, dynamic path initialization processing: create more than two independent paths, set the value range of the number of paths from 2 to 8 according to the actual application scenario, and set the following dynamic parameters for each path: queue length Q, used to record the size of the packets to be transmitted currently; dynamic delay value D, used to simulate the delay fluctuations caused by various factors in the real network; packet loss rate q, used to count the latest number of packet losses; dynamic bandwidth B, used to periodically measure the actual transmission rate;

[0020] Step 2-2: Set the dynamic bandwidth B. Update the bandwidth by triggering a check periodically. Check the difference between the current time and the time of the last bandwidth update. If the difference is greater than the preset bandwidth update interval (usually set the bandwidth update interval to 1 second), trigger the update of the bandwidth. The formula is:

[0021] (1),

[0022] (2),

[0023] where the congestion level c is the ratio of the current queue length Q to the queue length threshold The queue length threshold is generally set in the range of 1KB to 10MB. The low-latency path range is 1KB to 1MB, and the high-throughput path range is 5MB to 10MB; is the path base bandwidth. Each path will set a different initial value, i.e., the path base bandwidth, according to the transmission capacity of the path ; is the congestion sensitivity coefficient, generally in the range of [0.1, 0.5]. The larger the value, the faster the bandwidth drops during congestion; is the bandwidth perturbation weight, generally in the range of [0.1, 0.3], used to control the amplitude of random noise and simulate the interference of network background traffic; is Gaussian noise, used to increase the authenticity of bandwidth fluctuations;

[0024] Step 2-3: Set the dynamic delay value: Calculate the average delay based on the current queue length Q and the dynamic bandwidth B, which reflects the real-time load situation of each path and is used for data allocation in the later multi-path algorithm. The delay standard deviation reflects the stability of the path, i.e., simulates the fluctuation of the delay after the load increases. The formula is:

[0025] (3),

[0026] (4),

[0027] where is the base delay of the path. Update the queue length Q each time a data packet enters, and update and ;

[0028] Step 2-4: Set the dynamic packet loss rate :

[0029] (5),

[0030] where is the basic packet loss rate, that is, the inherent packet loss rate of the path, and its general value range is 0.01% - 5%; is generally 1MB. When it exceeds this threshold the packet loss rate will increase; is the adjustment coefficient, which controls the amplitude of the increase in the packet loss rate with the load, and its value range is 0.1 - 0.5;

[0031] Step 2 - 5, allocate data packets to paths: calculate the weight of each path, and calculate the selection probability of each path according to the weight of path i and the total weight of all paths :

[0032] (6),

[0033] (7),

[0034] where is the weight of the i - th path, is the current available bandwidth of the path, is the real - time average delay of the path, reflects network jitter;

[0035] Construct a hash probability mapping. Use the data packet length feature as the feature of the hash input, and use the hash function SHA - 256 to hash the generated string to obtain a hash value with a fixed length, modulo - normalize it to [0, 1), and use binary search to match the cumulative probability interval to determine the selected path;

[0036] Step 2 - 6, when each data packet arrives at the path, a delay value D needs to be added to simulate the delay fluctuations caused by various factors in the real network. The formula is:

[0037] (8),

[0038] (9),

[0039] where is the basic delay of the path, generate random noise from the standard normal distribution to simulate the delay fluctuations caused by network load and other uncertain factors; is the transmission delay, that is, the time required for the data packet to be sent onto the path, is the size of the current data packet; is the waiting time caused by network congestion, is the transmission delay coefficient, which is inversely proportional to the bandwidth;

[0040] Step 2-7, Reorganize out-of-order data packets: Each data packet needs to add a timestamp when it is sent. The receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the data packet arrives at the receiving end, and sorts them according to the arrival order to form the final out-of-order sequence.

[0041] Step 3 includes the following steps:

[0042] Step 3-1, Initialize parameters: The initial stage is the slow start stage. Set the initial congestion window cwnd, slow start threshold (generally in the range of 10 - 50 MSS), maximum window and minimum window , and the maximum segment size MSS; MSS refers to the maximum number of bytes of application data that a single data segment can carry in the TCP protocol (excluding the TCP header and IP header), which is a length value;

[0043] Step 3-2, Dynamic window adjustment: It is divided into two stages. The first stage is the slow start stage, at this time , the window ; The second stage is the congestion avoidance stage, at this time , each time a data packet is added to the transmission queue M, the counter is incremented. When the counter reaches the slow start threshold ssthresh, an adjustment is triggered, and the window is adjusted to ;

[0044] Step 3-3, If random packet loss occurs, shrink the window. Based on the retransmission to obtain the data enhancement result, in the fast retransmission trigger window shrinkage stage, update the slow start threshold , update the window , in the timeout retransmission trigger window shrinkage stage, reset the window , update the slow start threshold , is the window size before timeout;

[0045] Step 3-4, Set the baseline packet loss rate , the parameter b is the adjustment weight of the initial congestion window cwnd for the packet loss rate, which can be set in the slow start stage , set in the congestion avoidance stage , set in the fast retransmission trigger window shrinkage stage , set in the timeout retransmission trigger window shrinkage stage , when b belongs to multiple stages at the same time, trigger according to the defined priority. When b = 0.3, give priority to fast retransmission; when b = 0.1, give priority to congestion avoidance; when b = 0.5, give priority to timeout retransmission; Set the random packet loss probability according to the dynamic formula (9) :

[0046] (10),

[0047] where is the inherent packet loss probability of the path in the non - congested state;

[0048] Set a random number , if , then the data packet is normally sent to the final confirmation queue. If , then the data packet is marked as lost and added to the queue to be confirmed, waiting for re - transmission;

[0049] Step 3 - 5, when the number of duplicate ACKs detecting packet loss reaches more than 3 times, trigger fast re - transmission; ACK refers to the signal sent by the receiver to the sender to confirm that the data packet has been successfully received; when detecting that the delay exceeds the RTO period, perform timeout re - transmission. RTO is the maximum time for the sender to wait for the receiver to return an acknowledgment (ACK) after sending a data packet. Simplify the steps, set a random number , the fast re - transmission probability , if , then trigger fast re - transmission. If , then trigger timeout re - transmission;

[0050] Step 3 - 6, if , trigger fast re - transmission, enter the stage of shrinking the fast re - transmission trigger window, add the data packet to the queue to be confirmed buf, and each time an ACK signal sent by the receiver to the sender is received, transfer the data packet to the final confirmation queue. Set the maximum number of repetitions , that is, when receiving the confirmation re - transmission signal for the 3rd time and the data is repeated, dynamically adjust the window according to steps 3 - 2 and 3 - 3;

[0051] Step 3 - 7, if , trigger timeout re - transmission, enter the stage of shrinking the timeout re - transmission trigger window. The general scenario is continuous packet loss. Adjust the random probability, set the number of consecutive packet losses S, add the data packet to the queue to be confirmed, set the timeout re - transmission delay range for packet loss as T, simulate the timeout waiting, trigger re - transmission after waiting for T data packets for each lost packet, insert it after T data packets, keep the original packet order, and dynamically adjust the window according to steps 3 - 2 and 3 - 3 after the data is repeated until all data is traversed to obtain the final data repetition enhancement list.

[0052] In step 4, for the data table that has undergone out - of - order enhancement and re - transmission enhancement, perform the following steps:

[0053] Step 4-1, Initialization Processing: Generate a random delay sequence delays to simulate the delays in network transmission; the pending confirmation queue buf is used to simulate the packet buffer; the final confirmation queue res is used to store the final enhanced processing results; initialize the relevant parameters of congestion control, including: set the initial congestion window cwnd value to 1 MSS; initialize the slow start threshold ssthresh, with the initial value set to 44 MSS; initialize the maximum segment size MSS to cover different network environments, set the candidate list of the maximum segment size MSS, including the candidate values of the maximum segment size MSS in different scenarios, taking 1460 in standard Ethernet, the minimum security value in traditional wide area networks is 536, taking 1448 in the VPN tunnel encapsulation scenario, and taking 1232 when running the IPv6 protocol in the Ethernet Point-to-Point Protocol environment, and set the initial maximum segment size MSS; set the initial bandwidth, handle the delay and the base propagation delay ;

[0054] Step 4-2, Dynamically Adjust the Maximum Segment Size MSS. Set the probability P = 15% to trigger the reduction of MSS. Screen all values smaller than the current MSS from the candidate list of the maximum segment size MSS, and take the maximum value in the screening results; set the probability P = 8% to simulate path recovery detection. Screen all values larger than the current MSS from the candidate list, and take the minimum value in the screening results;

[0055] Step 4-3, In the dynamic maximum transmission unit MTU network environment, TCP actively adjusts the maximum segment size MSS by real-time sensing the change of the path maximum transmission unit MTU, which directly affects the calculation of the round-trip time RTT. Calculate the RTT value:

[0056] (11);

[0057] Step 4-4, Packet Processing: Within each round-trip time RTT, based on the dynamic maximum segment size MSS fragmentation strategy and congestion window limit, split the packet into compliant segments;

[0058] Step 4-5, Adjust the Results. Add the processed packet data within the current round-trip time RTT to the final result; adjust the congestion window and slow start threshold according to the transmission status;

[0059] Step 4-6, Fixed Sequence Length. Pad or truncate the result to adjust it to a fixed length, and finally output the packet length sequence with enhanced length features.

[0060] Step 4-4 includes:

[0061] Step 4-4-1, Delay Processing: Take a delay value from the pre-generated dynamic delay sequence delays, subtract the delay value from the RTT time window to obtain the remaining round-trip time remaining_RTT. If the remaining round-trip time remaining_RTT ≤ 0, it means the current window time has expired, stop sending data to the packet buffer buf and directly send it to the final confirmation queue res; if the remaining round-trip time remaining_RTT > 0, continue to send the packet to the packet buffer buf and perform packet size segmentation processing.

[0062] Step 4-4-2, Packet Processing: Store the data in the input queue. Each time, take a packet from the input queue and add it to the packet buffer buf for the next operation.

[0063] Step 4-4-3, If the size of the packet is less than the maximum segment size MSS, do not send the packet immediately. First, cache the packet in the packet buffer buf. When the packets in the packet buffer buf accumulate to be equal to or exceed the maximum segment size MSS, send a complete segment to the final confirmation queue res and subtract the maximum segment size MSS from the packet buffer buf. The remaining packets continue to be stored in the packet buffer buf for the next accumulation; if the packet size is already greater than or equal to the maximum segment size MSS, directly send it to the final confirmation queue res.

[0064] Step 4-4-4, According to the limit of the congestion window, check whether the current transmission volume exceeds the congestion window. If the size of the packet buffer buf is greater than or equal to the current congestion window, it means the packet has exceeded the current available window size, stop sending packets and wait for the network status to recover.

[0065] Step 4-4-5, Process the remaining buffer. If there is still unsent data in the packet buffer buf, that is, the part less than MSS, and the current window time has not expired, directly add the unsent data to the final confirmation queue res.

[0066] Step 4-4-6, After processing the packets within each round-trip time RTT, generate a new round-trip time RTT, take the next delay value from the dynamic delay sequence delays, simulate packet transmission, and loop through steps 4-4-1 to 4-4-5 until all packets are processed.

[0067] Step 4-5 includes:

[0068] Step 4-5-1: Adjust the congestion window. If the round-trip time (RTT) is not exhausted, that is, the sender receives an acknowledgment (ACK) signal within the estimated RTT, indicating successful transmission of the data packet, adjust the cwnd. If cwnd is less than the slow start threshold ssthresh, enter the slow start phase and increase it exponentially; otherwise, enter the congestion avoidance phase and increase it linearly.

[0069] Step 4-5-2: If the RTT is exhausted, that is, the sender does not receive an ACK signal for a certain data packet within the estimated RTT, indicating packet loss, reset the size to one maximum segment size (MSS), set the slow start threshold ssthresh to half of the current cwnd, and re-enter the slow start phase.

[0070] The present invention also provides a TCP data enhancement system for encrypted traffic classification implemented based on the above method, including:

[0071] A data preprocessing module for preprocessing the collected network data to form a feature input for data enhancement;

[0072] A disordered feature enhancement module for setting multiple paths through a multipath transmission mechanism, using a hash function to distribute data packets to different paths, increasing the delay and sorting them in the order of transmission delay, and reorganizing the data packets;

[0073] A retransmission data enhancement module for setting a packet loss-triggered retransmission mechanism in dynamic window adjustment and inserting the retransmitted data packets into the enhancement queue;

[0074] A data packet length feature enhancement module for dynamically adjusting the maximum segment size (MSS), processing data packets according to the congestion window and the dynamic segmentation control algorithm within each round-trip time (RTT), and adjusting the length size feature of the data packets in the sequence.

[0075] The present invention provides a traffic classification device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the steps of the above method are implemented.

[0076] The present invention provides a computer-readable storage medium with a computer program stored thereon. When the program is executed by the processor, the steps of the above method are implemented.

[0077] Compared with the prior art, the present invention has the following beneficial effects: 1. For the existing encrypted network traffic classification technology, which usually trains only for a single network environment, the present invention innovatively considers a diverse and dynamic network environment. By simulating the protocol behavior of TCP in a real network environment, under different network conditions in the training environment, the features extracted by the model can overcome the inconsistency in different scenarios, greatly improving the ability of the deep learning model to adapt to dynamic network conditions.

[0078] 2. For the problem of the change in the packet length sequence of encrypted traffic in different network environments, the present invention designs three enhancement methods combined with the TCP protocol characteristics. Through the multi-path transmission mechanism, packet disorder enhancement is achieved, the sliding window mechanism is used for packet retransmission enhancement, and the packet length feature enhancement is carried out according to the congestion control mechanism of TCP and dynamically adjusting the MSS, generating a pattern that can restore the traffic deformation in the real environment, significantly improving the robust performance of traffic in different network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0079] Figure 1 It is a flowchart of the steps of the method of the present invention.

[0080] Figure 2 It is a processing flow of packet disorder enhancement.

[0081] Figure 3 It is a processing flow of packet retransmission enhancement.

[0082] Figure 4 It is a processing flow of packet length enhancement. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0083] The following further specifically describes the present invention in conjunction with the drawings and specific embodiments, and the above and other advantages of the present invention will become clearer.

[0084] As Figure 1 shown, an embodiment of the present invention provides a TCP data enhancement method for encrypted traffic classification. The method includes: preprocessing the captured encrypted network traffic data, extracting the payload of each flow packet and the corresponding label, and forming a packet length sequence; performing disorder, retransmission, and length feature enhancement on the packet length sequence according to the data enhancement loader of the TCP mechanism. The specific steps include:

[0085] Step 1, preprocess the collected traffic data: record the length of each packet in chronological order from each traffic, generate a classification label according to the traffic type, obtain the packet length sequence of each flow, and perform length unification processing on it;

[0086] Step 2: According to the multipath transmission mechanism, by creating more than two independent paths, setting random delays, packet loss rates, and bandwidths for each path, and using a hash function to distribute data packets to different paths; by reordering and reorganizing data packets according to transmission delays, packet disorder enhancement is achieved.

[0087] Step 3: Utilize the sliding window mechanism to simulate random packet loss during the data packet transmission process, trigger the retransmission mechanism, and insert the retransmitted data packets into the enhancement queue to achieve the enhancement of data packet retransmission generation.

[0088] Step 4: Control the size of data packet transmission according to the congestion control mechanism of TCP. According to the dynamic adjustment of the maximum segment size (MSS) and the state change of the round-trip time (RTT) of data packets, make corresponding adjustments to the congestion control stage, perform dynamic segmentation control on data packets, and adjust the length size of data packets to achieve the enhancement of data packet length characteristics.

[0089] In this embodiment, Step 1 includes:

[0090] Step 1-1: Capture the original network data stream and extract key fields, including: IP data packet length, timestamp, and five-tuple (source IP, destination IP, source port, destination port, protocol type).

[0091] Step 1-2: Group into independent flows according to the five-tuple (src_ip, dst_ip, src_port, dst_port, protocol), and sort the data packets within each flow in ascending order of timestamp; where src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type.

[0092] Step 1-3: Perform uniform processing on the data packet length sequence of each flow. If the number of data packets is less than N = 100 in length, fill with zeros; if the number of data packets exceeds N = 100 in length, truncate.

[0093] Step 1-4: Associate a label "label" with each data packet length sequence.

[0094] Step 1-5: Save the processed data in the CSV file format. The first 99 columns of each row represent the data packet length sequence, and the last column represents the label of the flow. Separate the data packet length sequence and the label, extract the "label" label column, encode the label, standardize the classification label to a numerical value, store the data packet length sequence as a feature in the data class, and convert it to a NumPy array as the format for subsequent data augmentation processing.

[0095] Convert the network traffic data into a data length sequence format suitable for data augmentation through the above step 1.

[0096] In this embodiment, as Figure 2 shown, the packet length sequence scrambling augmentation needs to be operated through the following steps:

[0097] In step 2, input the preprocessed data set into the packet scrambling augmentation processor. The specific steps are as follows:

[0098] Step 2-1, dynamic path initialization processing: Create 4 independent paths, and set the following dynamic parameters for each path: queue length Q, which is used to record the size of the packets to be transmitted currently; dynamic delay value D, which is used to simulate the delay fluctuations caused by various factors in the real network; packet loss rate q, which is used to count the latest packet loss times; dynamic bandwidth B, which is used to periodically measure the actual transmission rate;

[0099] Step 2-2, set the dynamic bandwidth B. Update the bandwidth by triggering a periodic check once. Check the difference between the current time and the time of the last bandwidth update. If this difference is greater than the preset bandwidth update interval, set the bandwidth update time interval to 1 second and trigger the update of the bandwidth according to the following formula:

[0100] (1),

[0101] (2),

[0102] where the congestion level c is the ratio of the current queue length Q to the queue length threshold The queue length threshold is generally set in the range of 1 KB to 10 MB. Set the queue length threshold of path 1 to 10 KB, path 2 to 1 MB, path 3 to 5 MB, and path 4 to 10 MB. is the path base bandwidth. Set the of path 1 to 100 Mbps, path 2 to 500 Mbps, path 3 to 100 Mbps, and path 4 to 1 Gbps. is the congestion sensitivity coefficient, generally in the range of [0.1, 0.5]. The larger the value, the faster the bandwidth drops during congestion; Bandwidth perturbation weight, generally in the range of [0.1, 0.3], controls the amplitude of random noise and simulates the interference of network background traffic; is Gaussian noise, which increases the authenticity of bandwidth fluctuations;

[0103] Step 2-3, set the dynamic delay value: Calculate the average delay according to the current queue length Q and dynamic bandwidth B reflects the real-time load situation of each path, which is used for data allocation in the later multi-path algorithm, and the standard deviation of delay reflects the stability of the path, that is, the fluctuation of delay after simulating the increase of load, according to the following formula:

[0104] (3),

[0105] (4),

[0106] wherein, is the basic delay of the path. Set the value of path 1 to 100 Mbps, path 2 to 500 Mbps, path 3 to 100 Mbps, and path 4 to 1 Gbps. Update the queue length Q each time a data packet enters, and update the calculation of and ;

[0107] Step 2-4, set the dynamic packet loss rate :

[0108] (5),

[0109] wherein, is the basic packet loss rate, that is, the inherent packet loss rate of the path. Generally, the value range is 0.01% - 5%. Set the value of path 1 to 0.1%, path 2 to 0.2%, path 3 to 1%, and path 4 to 0.5%. is the queue length threshold. After exceeding this threshold, the packet loss rate will increase; is the adjustment coefficient, which controls the amplitude of the packet loss rate increase with the load, and the value range is 0.1 - 0.5;

[0110] Step 2-5, allocate data packets to paths: calculate the weight of each path , and calculate the selection probability of each path according to the weight of path i and the total weight of all paths :

[0111] (6),

[0112] (7),

[0113] In formula (6), is the path weight, is the current available bandwidth of the path, is the real-time average delay of the path, is the standard deviation of delay, which reflects network jitter.

[0114] Construct a hash probability mapping. Use the packet length feature as the feature of the hash input, and use the hash function SHA-256 to hash the generated string to obtain a hash value with a fixed length, which is modulo-normalized to [0, 1). Use binary search to match the cumulative probability interval to determine the selection path;

[0115] In step 2-6, when each packet arrives at the path, a delay value D needs to be added to simulate the delay fluctuations caused by various factors in the real network. The formula is:

[0116] (8),

[0117] (9),

[0118] Among them, is the base delay of the path, generating random noise from the standard normal distribution to simulate the delay fluctuations caused by network load and other uncertain factors, is the standard deviation of the delay, representing the amplitude of the delay fluctuation; is the transmission delay, that is, the time required for the packet to be sent onto the path, is the waiting time caused by network congestion, is the transmission delay coefficient, which is inversely proportional to the bandwidth;

[0119] In step 2-7, reorder the out-of-order packets: Each packet needs to add a timestamp T when it is sent. The receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the packet arrives at the receiving end, and sorts them according to the arrival order to form the final out-of-order sequence.

[0120] In this embodiment, as Figure 3 shown, data duplication enhancement needs to be operated through the following steps:

[0121] In step 3, input the preprocessed data into the data retransmission enhancement processing module. The specific steps are as follows:

[0122] In step 3-1, initialize the parameters. The initial stage is the slow start stage, and the window size , the slow start threshold , the maximum window , the minimum window , and the MSS is set to 1448;

[0123] In step 3-2, dynamically adjust the window: It is divided into two stages. The first stage is the slow start stage, at this time , the window is ; The second stage is the congestion avoidance stage, at this time , each time a data packet is added to the transmission queue M, the counter is incremented. When the counter reaches the slow start threshold ssthresh, an adjustment is triggered and the window is adjusted to ;

[0124] Step 3-3, if random packet loss occurs, the window is reduced, and the data enhancement result is obtained based on retransmission. During the window reduction stage triggered by fast retransmission, the slow start threshold is updated , the window is updated , during the window reduction stage triggered by timeout retransmission, the window is reset , the slow start threshold is updated , is the window size before timeout;

[0125] Step 3-4, set the reference packet loss rate , where the parameter b is the adjustment weight of the congestion window cwnd to the packet loss rate. Set b = 0.2 in the slow start stage, b = 0.08 in the congestion avoidance stage, b = 0.4 in the window reduction stage triggered by fast retransmission, and b = 0.8 in the window reduction stage triggered by timeout retransmission. Set the random packet loss probability according to the dynamic formula (9) :

[0126] (10),

[0127] Set a random number , if , the data packet is normally sent to the final confirmation queue. If , the data packet is marked as lost and added to the queue to be confirmed, waiting for retransmission;

[0128] Step 3-5, when the number of duplicate ACKs for detected packet loss reaches more than 3 times, ACK refers to the signal sent by the receiver to the sender to confirm successful receipt of the data packet, triggering fast retransmission; timeout retransmission is performed after detecting a delay exceeding the RTO period. RTO is the maximum time the sender waits for the receiver to return an acknowledgment (ACK) after sending a data packet. Simplify the steps and set a random number , fast retransmission probability , if , fast retransmission is triggered. If , timeout retransmission is triggered;

[0129] Step 3-6, if , fast retransmission is triggered, and the data packet is added to the queue to be confirmed buf. Each time an ACK is received, the data packet is passed into the final confirmation queue, and the maximum number of repetitions is set , that is, when the signal for retransmission is received for the third time and the data is repeated, the window is dynamically adjusted according to Steps 3-2 and 3-3;

[0130] Step 3 - 7, if , trigger timeout retransmission. The general scenario is continuous packet loss. Adjust the random probability and set the number of continuous packet losses , add the data packet to the queue waiting for confirmation, and set the timeout retransmission delay range for packet loss to be , simulate timeout waiting, wait for data packets for each lost packet before triggering retransmission, insert it after T data packets, keep the original packet order, and dynamically adjust the window according to Steps 3 - 2 and 3 - 3 after data duplication until all data is traversed to obtain the final data duplication enhancement list.

[0131] In this embodiment, as Figure 4 shown, data length enhancement needs to be operated through the following steps:

[0132] In Step 4, input the pre - processed data into the data length enhancement processing module. The specific steps are as follows:

[0133] Step 4 - 1, initialization processing: Generate a random delay sequence delays to simulate the delay in network transmission; the queue buf waiting for confirmation is used to simulate the data packet buffer; the final confirmation queue res is used to store the final enhancement processing result; initialize the relevant parameters of congestion control, set the initial congestion window value to 1MSS; initialize the slow start threshold ssthresh, with the initial value set to 44MSS; initialize the maximum segment size MSS to cover different network environments, set a candidate list of the maximum segment size MSS, including candidate values of the maximum segment size MSS in different scenarios, and the candidate values include 536, 1232, 1448, 1460, and set the initial maximum segment size MSS value to 1448; set the initial bandwidth, processing delay and the base propagation delay ;

[0134] Step 4 - 2, dynamically adjust the maximum segment size MSS. Set the probability P = 15% to trigger MSS reduction, screen all values smaller than the current MSS from the MSS candidate list, and take the maximum value of the screening results; set the probability P = 8% to simulate path recovery detection, screen all values larger than the current maximum segment size MSS from the candidate list, and take the minimum value of the screening results;

[0135] Step 4-3, in a dynamic Maximum Transmission Unit (MTU) network environment, TCP actively adjusts the Maximum Segment Size (MSS) by real-time sensing changes in the path MTU. The Round-Trip Time (RTT) is determined by the data packet transmission time, ACK transmission time, and latency. The dynamic value of the Maximum Segment Size (MSS) is 536, 1232, 1448, 1460 in bytes, the ACK size is a fixed value of 40 bytes, the initial bandwidth is 100 Mbps, and the processing latency Base propagation latency , calculate the RTT value:

[0136] (11),

[0137] Step 4-4, data packet processing: within each Round-Trip Time (RTT), based on the dynamic Maximum Segment Size (MSS) fragmentation strategy and congestion window limit, split the data packet into compliant segments;;

[0138] Step 4-5, adjust the result, add the data of the processed data packets within the current Round-Trip Time (RTT) to the final result; adjust the congestion window and slow start threshold according to the transmission status;

[0139] Step 4-6, fix the sequence length, pad or truncate the result to adjust it to a fixed length, and finally output a data packet length sequence with enhanced length features.

[0140] Step 4-4 includes:

[0141] Step 4-4-1, latency processing: take a latency value from the pre-generated dynamic latency sequence delays, subtract the latency value from the Round-Trip Time (RTT) time window to get the remaining Round-Trip Time remaining_RTT. If the remaining Round-Trip Time remaining_RTT ≤ 0, it means the current window time has expired, stop sending data to the data packet buffer buf and directly send it to the final confirmation queue res; if the remaining Round-Trip Time remaining_RTT > 0, continue to send data packets to the data packet buffer buf for data packet size segmentation processing;

[0142] Step 4-4-2, data packet processing: store the data in the input queue, each time take a data packet from the input queue, add it to the data packet buffer buf for the next operation;

[0143] Step 4-4-3, if the size of the data packet is less than the maximum segment size MSS, do not send the data packet immediately. Instead, buffer the data packet in the data packet buffer buf. When the data packets in the data packet buffer buf accumulate to be equal to or exceed the maximum segment size MSS, send a complete segment to the final acknowledgment queue res, and subtract the maximum segment size MSS from the data packet buffer buf. The remaining data packets continue to be stored in the data packet buffer buf for the next accumulation. If the data packet size is already greater than or equal to the maximum segment size MSS, send it directly to the final acknowledgment queue res;

[0144] Step 4-4-4, according to the limit of the congestion window, check whether the current transmission volume exceeds the congestion window. If the size of the data packet buffer buf is greater than or equal to the current congestion window, it means that the data packet has exceeded the current available window size, so stop sending data packets and wait for the network status to recover;

[0145] Step 4-4-5, process the remaining buffer. If there is still unsent data in the data packet buffer buf, that is, the part less than MSS, and the current window time has not expired, directly add the unsent data to the final acknowledgment queue res;

[0146] Step 4-4-6, after processing the data packets within each round-trip time RTT, generate a new round-trip time RTT. Take the next delay value from the dynamic delay sequence delays to simulate the data packet transmission, and loop through steps 4-4-1 to 4-4-5 until all data packets are processed.

[0147] Step 4-5 includes:

[0148] Step 4-5-1, adjust the congestion window. If the round-trip time RTT is not exhausted, that is, the sender receives an acknowledgment ACK within the estimated round-trip time RTT, indicating successful data packet transmission, adjust cwnd. If cwnd is less than ssthresh, enter the slow start phase and increase exponentially; otherwise, enter the congestion avoidance phase and increase linearly;

[0149] Step 4-5-2, if the round-trip time RTT is exhausted, that is, the sender does not receive an acknowledgment ACK for a certain data packet within the estimated round-trip time RTT, indicating packet loss, reset the size to a maximum segment size MSS, set ssthresh to half of the current cwnd, and re-enter the slow start phase.

[0150] The present invention provides a TCP data enhancement method and system for encrypted traffic classification. There are many methods and ways to specifically implement this technical solution. The above description is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention. Each component not clearly defined in this embodiment can be implemented by using existing technologies.

Claims

1. A TCP data enhancement method for encrypted traffic classification, characterized in that Including the following steps: Including the following steps: Step 1, preprocess the collected traffic data: Record the length of each data packet in each traffic in chronological order, generate classification labels according to the traffic type, obtain the packet length sequence of each flow, and perform length unification processing on the packet length sequence; Step 2, according to the multi-path transmission mechanism, create more than two independent paths, set random delays, packet loss rates, and bandwidths for each path, and use a hash function to allocate data packets to different paths; Reorganize the data packets by sorting according to the transmission delay to achieve packet disorder enhancement; Step 3, use the sliding window mechanism to simulate random packet loss during the data packet transmission process, trigger the retransmission mechanism, and insert the retransmitted data packets into the enhancement queue to achieve the generation of data packet retransmission enhancement; Step 4, control the size of data packet transmission according to the congestion control mechanism of TCP, and make corresponding adjustments to the congestion control phase according to the dynamic adjustment of the maximum segment size MSS and the state change of the round-trip time RTT of the data packet, perform dynamic segmentation control on the data packet, and adjust the length size of the data packet to achieve data packet length feature enhancement; Step 2 includes: Step 2-1, dynamic path initialization processing: Create more than two independent paths, set the value range of the number of paths, and set the following dynamic parameters for each path: queue length Q, which is used to record the size of the data packets to be transmitted currently; dynamic delay value D, which is used to simulate the delay fluctuations caused by various factors in the real network; packet loss rate q, which is used to count the latest number of packet losses; dynamic bandwidth B, which is used to periodically measure the actual transmission rate; Step 2-2, set the dynamic bandwidth B, trigger a check to update the bandwidth once every period, check the difference between the current time and the time of the last bandwidth update, if the difference is greater than the preset bandwidth update interval, trigger the update of the bandwidth, and the formula is: B = B b ×(1 - β×c) + w b ·ΔB (2), Among them, the congestion level c is the ratio of the current queue length Q to the queue length threshold Q t ; B b is the path base bandwidth; β is the congestion sensitivity coefficient; w b is the bandwidth perturbation weight; ΔB is Gaussian noise; Step 2-3, set the dynamic delay value: calculate the average delay μ according to the current queue length Q and the dynamic bandwidth B i , and the formula is: σ i = μ i × 0.1 (4), where σ i is the standard deviation of the delay, μ b is the base delay of the path, and the queue length Q is updated each time a data packet enters, and μ i and σ i are updated; Step 2-4, set the dynamic packet loss rate q i : where q b is the basic packet loss rate; α is the adjustment coefficient; Step 2-5, Allocate data packets to paths: Calculate the weight of each path, and calculate the selection probability p of each path based on the weight of path i and the total weight of all paths i : Among them, W i is the weight of the i-th path, B i is the current available bandwidth of the path, μ i is the real-time average delay of the path; Construct a hash probability mapping, use the data packet length feature as the feature of the hash input, use the hash function SHA-256 to perform hash processing on the generated string, obtain a fixed-length hash value and normalize it to [0,1), and use binary search to match the cumulative probability interval to determine the selected path; Step 2-6, when each data packet arrives at the path, a delay value D needs to be added to simulate the delay fluctuations caused by various factors in the real network, and the formula is: D = μ b + N(0, σ i ) + a·L i + a·Q (8), Among them, μ b is the base delay of the path, and random noise is generated from the standard normal distribution N(0, σ i ); a·L i is the transmission delay, L i is the current packet size; a·Q is the waiting time caused by network congestion, and a is the transmission delay coefficient; Step 2-7, reorganize the out-of-order data packets: Each data packet needs to add a timestamp when it is sent, and the receiving end calculates the sum of the timestamp and the dynamic delay value D as the time when the data packet arrives at the receiving end, and sorts them according to the order of arrival to form the final out-of-order sequence; Step 3 includes the following steps: Step 3-1, initialize parameters: The initial stage is the slow start stage, set the initial congestion window cwnd, slow start threshold ssthresh, maximum window W max and minimum window W min , and the maximum segment size MSS; MSS refers to the maximum number of bytes of application data that a single data segment can carry in the TCP protocol; Step 3-2, dynamic window adjustment: It is divided into two stages. The first stage is the slow start stage, where cwnd < ssthresh, and the window cwnd new = min(2 × cwnd, W max ); The second stage is the congestion avoidance stage, where cwnd ≥ ssthresh. Each time a data packet is added to the transmission queue M, the counter is incremented. When the counter reaches the slow start threshold ssthresh, an adjustment is triggered, and the window is adjusted to cwnd new = min(cwnd + 1, W max ); Step 3-3, if random packet loss occurs, reduce the window, obtain the data enhancement result based on retransmission, and update the slow start threshold during the window reduction stage triggered by fast retransmission Update the window cwnd new = ssthresh. During the window reduction stage triggered by timeout retransmission, reset the window cwnd = 1 MSS and update the slow start threshold W prev is the window size before timeout; Step 3-4, set the reference packet loss rate P b = 0.

3. The parameter b is the adjustment weight of the initial congestion window cwnd for the packet loss rate. In the slow start phase, set b ∈ [0.1, 0.3]. In the congestion avoidance phase, set b ∈ [0.05, 0.1]. In the fast retransmission trigger window reduction phase, set b ∈ [0.3, 0.5]. In the timeout retransmission trigger window reduction phase, set b ∈ [0.5, 1]. When b = 0.3, fast retransmission is preferentially triggered. When b = 0.1, congestion avoidance is preferentially triggered. When b = 0.5, timeout retransmission is preferentially triggered. Set the random packet loss probability p according to formula (9) c : where p b is the inherent packet loss probability of the path in the non-congested state; Set a random number \(L\in[0,1]\). If \(L > P\) c , then send the data packet to the final confirmation queue normally. If \(L\leq P\) c , then mark the data packet as lost and add it to the queue waiting for confirmation, waiting for retransmission; Step 3-5, when the number of duplicate ACKs for packet loss is detected to reach more than 3 times, fast retransmission is triggered; ACK refers to the signal sent by the receiver to the sender for confirming that the data packet has been successfully received; when the delay is detected to exceed the RTO period, timeout retransmission is performed. RTO is the maximum time for the sender to wait for the receiver to return an acknowledgment after sending the data packet. A random number r ∈ [0, 1] is set, and the fast retransmission probability is P fast , if r < P fast , then fast retransmission is triggered. If r ≥ P fast , then timeout retransmission is triggered; Step 3-6, if r < P fast , trigger fast retransmission, enter the fast retransmission trigger window shrinking stage, add the data packet to the pending confirmation queue buf, and each time an ACK signal sent by the receiver to the sender is received, transfer the data packet to the final confirmation queue, and set the maximum number of repetitions R max = 3, that is, when the confirmation retransmission signal is received for the third time and the data is repeated, the window is dynamically adjusted according to Steps 3-2 and 3-3; Step 3-7, if r≥P fast , trigger timeout retransmission, enter the timeout retransmission trigger window shrinking phase, set the continuous packet loss count S, add the data packet to the queue of packets to be acknowledged, set the timeout retransmission delay range for packet loss as T, simulate timeout waiting, trigger retransmission after waiting for T data packets for each lost packet, insert it after the T data packets, maintain the original packet order, and dynamically adjust the window according to Steps 3-2 and 3-3 after data duplication until all data is traversed to obtain the final data duplication enhancement list.

2. The method according to claim 1, wherein Step 1 includes: Step 1-1, capture the original network data stream, extract the key fields, including: IP data packet length, timestamp, and five-tuple: source IP, destination IP, source port, destination port, protocol type; Step 1-2: Group the data into independent flows according to the five-tuple (src_ip, dst_ip, src_port, dst_port, protocol), and sort the data packets within each flow in ascending order of timestamp. Here, src_ip represents the source IP, dst_ip represents the destination IP, src_port represents the source port, dst_port represents the destination port, and protocol represents the protocol type. Step 1-3: Uniformly process the data packet length sequences for each flow. If the number of data packets is less than N, pad with zeros. If the number of data packets exceeds N, truncate. Step 1-4: Associate a label with each data packet length sequence. Step 1-5: Save the processed data in CSV file format. The first N columns of each row represent the data packet length sequence, and the last column represents the label of the flow. Separate the data packet length sequence and the label, extract the label column, encode the label, standardize the classification label to a numerical value, store the data packet length sequence as features in a data class, and convert it to a NumPy array.

3. The method according to claim 2, wherein In Step 4, for the data table after shuffling augmentation and retransmission augmentation, perform the following steps: Step 4-1: Initialize the processing. Generate a random delay sequence delays to simulate the delay in network transmission. The pending confirmation queue buf is used to simulate the data packet buffer. The final confirmation queue res is used to store the final augmentation processing result. Initialize the relevant parameters of congestion control, including: set the value of the initial congestion window cwnd to 1 MSS; initialize the slow start threshold ssthresh, with an initial value of 44 MSS; initialize the maximum segment size MSS to cover different network environments, set a candidate list of the maximum segment size MSS, including the candidate values of the maximum segment size MSS in different scenarios, and set the initial maximum segment size MSS; set the initial bandwidth, processing delay D a and the base propagation delay D b ; Step 4-2: Dynamically adjust the maximum segment size MSS. Set the probability P = 15% to trigger the reduction of MSS. Filter all values smaller than the current MSS from the candidate list of the maximum segment size MSS, and take the maximum value of the filtered results. Set the probability P = 8% to simulate path recovery detection. Filter all values larger than the current MSS from the candidate list, and take the minimum value of the filtered results. Step 4-3: In a dynamic maximum transmission unit MTU network environment, TCP actively adjusts the maximum segment size MSS by real-time sensing the change of the path maximum transmission unit MTU, which directly affects the round-trip time RTT calculation. Calculate the RTT value: Step 4-4: Data packet processing. Within each round-trip time RTT, based on the dynamic maximum segment size MSS fragmentation strategy and congestion window limit, split the data packets into compliant segments. Step 4-5: Adjust the result. Add the processed data packets within the current round-trip time RTT to the final result. Adjust the congestion window and slow start threshold according to the transmission status. Step 4-6: Fix the sequence length. Pad or truncate the result to adjust it to a fixed length, and finally output the data packet length sequence with enhanced length features.

4. The method according to claim 3, wherein Step 4-4 includes: Step 4-4-1, Delay Processing: Take a delay value from the pre-generated dynamic delay sequence delays, subtract the delay value from the RTT time window to obtain the remaining round-trip time remaining_RTT. If the remaining round-trip time remaining_RTT ≤ 0, it means the current window time has expired, stop sending data to the packet buffer buf, and directly send it to the final confirmation queue res; if the remaining round-trip time remaining_RTT > 0, continue to send the data packet to the packet buffer buf for packet size segmentation processing. Step 4-4-2, Packet Processing: Store the data in the input queue. Each time, take a data packet from the input queue, add it to the packet buffer buf, and perform the next operation. Step 4-4-3, If the size of the data packet is less than the maximum segment size MSS, do not send the data packet immediately. First, cache the data packet in the packet buffer buf. When the data packets in the packet buffer buf accumulate to be equal to or exceed the maximum segment size MSS, send a complete segment to the final confirmation queue res, and subtract the maximum segment size MSS from the packet buffer buf. The remaining data packets continue to be stored in the packet buffer buf for the next accumulation; if the data packet size is already greater than or equal to the maximum segment size MSS, directly send it to the final confirmation queue res. Step 4-4-4, According to the limit of the congestion window, check whether the current transmission volume exceeds the congestion window. If the size of the packet buffer buf is greater than or equal to the current congestion window, it means the data packet has exceeded the current available window size, stop sending the data packet, and wait for the network status to recover. Step 4-4-5, Process the remaining buffer. If there is still untransmitted data in the packet buffer buf and the current window time has not expired, directly add the untransmitted data to the final confirmation queue res. Step 4-4-6, After processing the data packets within each round-trip time RTT, generate a new round-trip time RTT, take the next delay value from the dynamic delay sequence delays, simulate the data packet transmission, and loop through steps 4-4-1 to 4-4-5 until all data packets are processed.

5. The method according to claim 4, wherein Step 4-5 includes: Step 4-5-1, Adjust the congestion window. If the round-trip time RTT is not exhausted, that is, the sender receives the acknowledgment ACK signal within the estimated round-trip time RTT, indicating successful data packet transmission, adjust cwnd. If cwnd is less than the slow start threshold ssthresh, enter the slow start phase; otherwise, enter the congestion avoidance phase. Step 4-5-2, If the round-trip time RTT is exhausted, that is, the sender does not receive the acknowledgment ACK signal for a certain data packet within the estimated round-trip time RTT, indicating packet loss, reset the size to a maximum segment size MSS, set the slow start threshold ssthresh to half of the current cwnd, and re-enter the slow start phase.

6. A TCP data enhancement system for encrypted traffic classification implemented by the method according to any one of claims 1 to 5, characterized in that Includes: A data preprocessing module for preprocessing the collected network data to form a feature input with enhanced data; A disordered feature enhancement module for setting multiple paths through a multi-path transmission mechanism, distributing data packets to different paths using a hash function, increasing the delay and sorting them in the order of transmission delay, and reorganizing the data packets; A retransmitted data enhancement module for triggering a retransmission mechanism by setting packet loss during dynamic window adjustment and inserting the retransmitted data packets into an enhancement queue; A data packet length feature enhancement module for dynamically adjusting the maximum segment size (MSS), processing data packets according to the congestion window and the dynamic segmentation control algorithm within each round-trip time (RTT), and adjusting the length size feature of the data packets in the sequence.

7. A traffic classification device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network Intrusion Detection Methods Based on Data Augmentation and Self-Supervised Feature Enhancement

    CN114978613B

  • Network flow generation data enhancement method based on diffusion model

    CN118282948A

  • Method and system for enhancing class imbalance encrypted traffic data based on WSAGAN

    CN118643325A

  • Malicious traffic hypothesis detection method and device based on attention mechanism and data enhancement

    CN119172107A

  • Intelligent SPD (Surge Protective Device) based on internet of things

    CN103066703A