System and method for realizing long reasoning of network protocol analysis model

By designing a long inference implementation system for network protocol analysis models, using large language models and protocol inference rationality formulas for network protocol analysis, the shortcomings of complex network protocol inference are solved, and efficient long-link inference optimization and rationality improvement of protocol analysis are achieved.

CN120151256AActive Publication Date: 2025-06-13SHANGHAI NETIS TECH CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510629599.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-06-13
Estimated Expiration
2045-05-16

AI Technical Summary

Technical Problem

The prior art has shortcomings in dealing with complex network protocol inference, especially to carry out efficient long-link inference optimization while ensuring the rationality and accuracy of the inference.

Method used

A long inference implementation system for network protocol analysis model is designed, including a Pcap packet information extraction device, a long inference synthesis collection device, and a long inference scoring and optimization device. By extracting Pcap packet information, using a large language model to synthesize long inference data, and scoring and optimizing through protocol inference rationality formulas and GRPO algorithms, a trained network protocol long inference model is generated.

Benefits of technology

The long inference function of network protocol analysis is realized, which reduces the labor cost of pcap packet analysis, improves the speed and accuracy of analysis, and improves the rationality of protocol fields and hierarchical inference of large models in network protocol long inference.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151256A_ABST
    Figure CN120151256A_ABST
Patent Text Reader

Abstract

The invention provides a system and a method for realizing long reasoning of a network protocol analysis model, and the system comprises a Pcap packet information extraction device which is used for extracting related information from an input Pcap packet and outputting the related information; the Pcap packet length reasoning, synthesizing and collecting device is used for processing the relevant information output by the Pcap packet information extracting device and outputting a data set; the data set comprises extraction information of a pcap packet and a set of two-tuple data of long reasoning synthesis data; and the Pcap packet length reasoning scoring and optimizing device is used for inputting the data set and outputting a trained network protocol long reasoning model. According to the invention, a protocol reasoning rationality formula is designed for business knowledge of network protocol analysis to reinforce scoring of learning, so that protocol analysis is more reasonable; and based on a high-quality protocol analysis language model, the manpower cost of pcap packet analysis is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network monitoring and management, and specifically, to a system and method for implementing long inference of a network protocol analysis model. Background Art

[0002] Pcap packet analysis is an important way for network fault location, but pcap analysis requires professional network protocol knowledge and experience, and is generally carried out by senior network engineers. By analyzing Pcap packets, network engineers can obtain detailed network traffic information, such as traffic statistics, TCP / UDP session details, HTTP / DNS / TLS protocol content parsing, and potential abnormal behaviors. However, this kind of analysis usually requires the operator to have profound network protocol knowledge and rich practical experience, which limits its application scope and efficiency.

[0003] In recent years, with the development of artificial intelligence technology, especially the application of large language models (LLMs), new possibilities have been provided for automated network protocol analysis. By inputting the information of Pcap packets into a well-trained large language model, intelligent diagnosis of network problems can be realized, thereby reducing the dependence on professional human resources and improving the speed and accuracy of analysis. However, existing solutions still have deficiencies in dealing with complex network protocol reasoning, especially in optimizing long-link reasoning efficiently while ensuring the rationality and accuracy of reasoning.

[0004] The present invention aims to design a "protocol inference rationality formula" for the business knowledge of network protocol analysis, which is used for scoring in reinforcement learning to make protocol analysis more reasonable; based on a high-quality protocol analysis language model, the labor cost of pcap packet analysis is greatly reduced.

[0005] In the Chinese patent document with the publication number CN119182838A, a method and system for identifying users of network devices based on network protocol analysis are disclosed. The method includes: collecting network protocol data generated when a user interacts with a network device; performing protocol parsing on the network protocol data to obtain protocol features; performing user category annotation on the network protocol data according to the protocol features; performing differential encoding and splicing on the protocol features to form a network protocol feature vector; constructing a network device user identification model based on a deep neural network, and predicting the user category according to the network protocol feature vector; comparing the user category prediction result with the user category annotation result to perform iterative training on the network device user identification model; collecting real-time network protocol data generated when a user interacts with a network device and converting it into a real-time network protocol feature vector; and identifying the unknown user category through the trained network device user identification model. However, in this document, a traditional neural network is used for network feature identification, and the analysis process does not involve the large language model used in the present application.

[0006] In the Chinese patent document with the publication number CN116915679A, a protocol analysis system for a computer network is disclosed, including a port access system, a port analysis system, a network connection system, a network analysis system, a protocol retrieval system, a protocol analysis system, a hierarchical requirement system, a standard data warehouse, and an exception handling system. However, this patent document has nothing to do with the large language model technology used in the present invention, and there are essential technical differences between the two. Summary of the Invention

[0007] Aiming at the defects in the prior art, the purpose of the present invention is to provide a method and system for realizing long inference of a network protocol analysis model.

[0008] According to a system for realizing long inference of a network protocol analysis model provided by the present invention, it includes: A Pcap packet information extraction device for extracting relevant information from the input Pcap packet and outputting it; the relevant information includes traffic statistics information, TCP / UDP session information, parsing of protocol content such as HTTP / DNS / TLS, and abnormal behavior information; A Pcap packet long inference synthesis collection device for processing the relevant information output by the Pcap packet information extraction device and outputting a data set; the data set includes a set of binary data of the extraction information of the Pcap packet and the long inference synthesis data; A Pcap packet long inference scoring and optimization device, inputting the data set and outputting a trained network protocol long inference model.

[0009] Preferably, the Pcap packet information extraction device includes: A traffic statistics information extraction module for extracting the statistical information of the flows in the pcap packets; A TCP / UDP session extraction module for extracting TCP / UDP session information in the pcap packets; An HTTP / DNS / TLS payload information extraction module for extracting the payload information of HTTP / DNS / TLS in the pcap packets; A network abnormal behavior information extraction module for extracting the network abnormal information in the pcap packets.

[0010] Preferably, the output information of the traffic statistics information extraction module includes the total traffic size, the number of data packets, per-IP statistics, protocol distribution, port distribution, and traffic time series; The output information of the TCP / UDP session extraction module includes the TCP three-way handshake success rate, packet loss rate, retransmission rate, whether there is a Reset exception, UDP session request-response success rate, TLS handshake success rate, and whether there is an abnormal Alert detection; The output information of the HTTP / DNS / TLS payload information extraction module includes the HTTP target, User-Agent, Host, error ratio, DNS resolved domain name, TLS encryption algorithm, and whether there is a certificate exception; The output information of the network abnormal behavior information extraction module includes whether there is a scan, whether there is a DDOS, and TLS certificate forgery.

[0011] Preferably, it further includes: An information aggregation module for recording all the extracted information in text and forming a binary tuple with the original pcap packet; The binary tuple includes {pcap packet, extract_info}, where extract_info is the extracted information corresponding to the pcap packet.

[0012] Preferably, the Pcap packet length inference synthesis collection device includes: A Pcap packet length inference prompt word preparation module that inputs the binary tuple to form a prompt word data set; A long inference data synthesis module that calls a large language model and inputs the corresponding prompt words into the large language model one by one to obtain a long inference synthesis data set output by the model; Each element in the long inference synthesis data set is a binary tuple.

[0013] Preferably, the input of the Pcap packet length inference prompt preparation module is the prompt words formed by the extract_info in the output binary tuple of the information aggregation module to form a prompt word data set, and each record in the data is a binary tuple {pcap, pcap_reference_prompt}, where pcap_reference_prompt is the prompt word corresponding to pcap; The large language models called by the long inference data synthesis module include deepseek and Qwen, denoted as LLM pcap_analysis , and the pcap_reference_prompt part in the prompt word data set is input into the large language model one by one to obtain the long inference output by the model, forming a long inference synthesis data set; each element in the data set is a binary tuple {pcap, pcap_reference_result}.

[0014] Preferably, the Pcap packet length inference scoring and optimization device includes: An unreasonable protocol field extraction module for long inference, which inputs the binary tuple in the long inference synthesis data set and outputs the unreasonable protocol field ratio; An unreasonable protocol layer extraction module for long inference, which inputs the binary tuple in the long inference synthesis data set and outputs the unreasonable protocol layer ratio; A long inference scoring and training module, which inputs the binary tuple, the unreasonable protocol field ratio, and the unreasonable protocol layer ratio in the long inference synthesis data set and outputs a scoring score between 0 and 1.

[0015] Preferably, the input of the unreasonable protocol field extraction module for long inference is the binary tuple {pcap, pcap_reference_result}, and the output is the unreasonable protocol field ratio; the reasonable protocol fields included in pcap are denoted as the variable valid_vars, and the characters in the form of protocal.field in pcap_reference_result are extracted through regular expressions. The protocol fields that do not exist in valid_vars are unreasonable fields, and the rest are reasonable fields; calculate the unreasonable field ratio, denoted as invalid_field_ratio.

[0016] Preferably, the input of the unreasonable protocol layer extraction module for long inference is the binary tuple {pcap, pcap_reference_result}, and the extraction process is completed by comparing the network protocol layer rule list; The long inference scoring and training module includes checking whether the content of pcap_reference_result conforms to the XML format defined by the Pcap packet length inference prompt word preparation module, denoted as is_valid_format. If it conforms, it is 1; if not, it is 0. The long inference score is calculated according to the following formula:

[0017] where ; is a decimal between 0 and 1, represents whether it is a valid format, 1 means valid, 0 means invalid; invalid_field_ratio represents the ratio of unreasonable fields, and its value ranges from 0 to 1. The larger the value, the higher the proportion of unreasonable fields; represents the ratio of invalid protocol nesting formats, and its value ranges from 0 to 1. The larger the value, the higher the ratio of invalid protocol nesting formats; Use the GRPO algorithm to train the LLM pcap_analysis During the optimization process, the reward value of the GPRO algorithm uses the Reward of the long inference scoring and training module.

[0018] According to an implementation method of long inference of a network protocol analysis model provided by the present invention, it includes: Step S1: Extract traffic statistics information, TCP / UDP session information, HTTP / DNS / TLS protocol content parsing, and abnormal behavior information from the input Pcap packet through the Pcap packet information extraction device; Step S2: Use the Pcap packet length inference synthesis collection device to process the above information to generate a binary tuple {pcap, pcap_reference_result} containing long inference synthesis data; Step S3: Score and optimize the long inference synthesis data through the Pcap packet length inference scoring and optimization device, and finally output the trained network protocol long inference model.

[0019] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention proposes an implementation method of long inference for network protocol analysis. The LLM (Large Language Model) trained based on this method can replace network engineers to complete pcap analysis tools; the present invention designs a "protocol inference rationality formula" for the scoring of reinforcement learning for the business knowledge of network protocol analysis, making protocol analysis more reasonable; based on a high-quality protocol analysis language model, the labor cost of pcap packet analysis is greatly reduced.

[0020] 2. The present invention first uses tools to extract information from Pcap packets (including traffic statistics information, TCP / UDP session information, parsing of HTTP / DNS / TLS, and abnormal behavior information), and then inputs the information into a basic large model (such as deepseek, Qwen, etc.) for the synthesis of inference data. The synthesized data is scored using the "protocol inference rationality formula", and finally the GRPO method is used to optimize the long inference function, realizing the long inference function of network protocol analysis.

[0021] 3. By improving the reward function of the GRPO algorithm, the present invention takes into account "unreasonable protocol fields", improves the rationality of the protocol field description in the long inference of network protocols by the large model, and improves the quality of the long inference of network protocol analysis.

[0022] 4. By improving the reward function of the GRPO algorithm, the present invention takes into account "unreasonable protocol levels", improves the rationality of the protocol level inference in the long inference of network protocols by the large model, and improves the quality of the long inference of network protocol analysis.

[0023] Other beneficial effects of the present invention will be elaborated in the specific implementation manner through the introduction of specific technical features and technical solutions. Those skilled in the art should be able to understand the beneficial technical effects brought by the said technical features and technical solutions through these introductions. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objectives, and advantages of the present invention will become more apparent: Figure 1 It is the operation flowchart of the Pcap packet information extraction device in the present invention.

[0025] Figure 2 It is the operation flowchart of the Pcap packet long inference synthesis collection device in the present invention.

[0026] Figure 3 It is the operation flowchart of the Pcap packet long inference scoring and optimization device in the present invention.

[0027] Figure 4 It is the method flowchart of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0028] The present invention will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but do not limit the present invention in any form. It should be noted that those of ordinary skill in the art can make several changes and improvements without departing from the concept of the present invention. These all belong to the protection scope of the present invention.

[0029] Reference Figure 4 As shown, a method for implementing long inference of a network protocol analysis model includes: Step 1: Refer to Figure 1 As shown, use a Pcap packet information extraction device, which inputs Pcap packets and outputs traffic statistics information, TCP / UDP session information, parsing of protocol content such as HTTP / DNS / TLS, and abnormal behavior information. The output information will be input into a large model in Step 2 for the synthesis of long inference data; Step 1.1: Traffic statistics information extraction module. This module extracts the statistical information of the flows in the pcap packets. The output information of the module includes: Traffic statistics: Record the total traffic size, the number of data packets, and statistics for each IP; Protocol distribution: (For example) TCP 70%, UDP 20%, ICMP 5%; Port distribution: (For example) HTTP (80) 40%, DNS (53) 20%, others 40%; Traffic time series: Average RTT (round-trip time), packet loss rate, number of TCP connections; Step 1.2: TCP / UDP session extraction module. This module extracts the TCP / UDP session information in the pcap packets. The output information of the module includes: - Success rate of TCP three-way handshake; - Packet loss rate and retransmission rate of TCP connections; - Whether there is a Reset exception in TCP; - Request-response success rate of UDP sessions; - Success rate of TLS handshake; - Whether there is an abnormal Alert in TLS.

[0030] Step 1.3: HTTP / DNS / TLS payload information extraction module. This module extracts the HTTP / DNS / TLS payload information in the pcap packets. The output information of the module includes: HTTP: GET / POST targets, User-Agent, Host, 403 / 404 / 500 error ratio; DNS: Resolved domain names, whether there is NXDOMAIN; TLS: Encryption algorithms used (such as TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256), whether there are certificate exceptions; Step 1.4: Network abnormal behavior information extraction module. This module extracts the network abnormal information in the pcap packets. The output information of the module includes: Whether there is a scan: the number of SYN packets; Whether there is a DDOS: whether there is a SYN Flood, whether there is an ICMP Flood; TLS certificate forgery: detect whether there are certificates issued by uncommon CAs (e.g., using the Suricata tool); Step 1.5: Information aggregation module. Record the extracted information text from Steps 1.1 - 1.4 and the original pcap packet to form a binary tuple <pcap packet, extract_info>, where extract_info is the extracted information corresponding to the pcap packet.

[0031] Step 2: Refer to Figure 2 As shown, use the Pcap packet length inference synthesis collection device. The input of this device is the extracted information of the Pcap packet, which is the output information of the "Pcap packet information extraction device"; the output of this device is a set of binary tuple data <extracted information of the pcap packet, length inference synthesis data>. The output data of this device will be used in Step 3 to optimize the long inference function of the model; Step 2.1: Pcap packet length inference prompt preparation module. The input of this module is the prompt words formed by extract_info in the binary tuple output in Step 1.5, which constitutes the "prompt word data set". Each record in the data is a binary tuple <pcap, pcap_reference_prompt>, where pcap_reference_prompt is the prompt word corresponding to pcap. The prompt word template is as follows (the {extract_info} in the template is replaced with the actual extracted information of the pcap packet): # Please diagnose network problems based on the "various extracted information" in the following pcap packet. The extracted information is: {extract_info} # Output requirements: ## The output format is xml, including multiple thinking nodes and an answer node, and the format is: <analysis> <think> <id> 1< / id> <protocal>HTTP< / protocal> …< / think> <think> <id> 2< / id> <protocal>TCP carries 1< / protocal> …< / think> … <think> <id> n< / id> <protocal>UDP over k< / protocal> …< / think> <answer> …< / answer> < / analysis> Note: Each think has a unique increasing id number; each think involves a protocol; if the protocol of a think is deduced based on the protocol analysis of an existing think, then use protocal over / carries id to represent it, and the id corresponds to the existing think. 1, 2, k, n in the above example are the ids of the thinks.

[0032] ## Protocol field description specification: It must be described as protocal.field, for example: tcp.ack, tcp.flags, udp.dst_port ## Protocol layer description specification: In the protocal node, if the protocol in the current think is derived from the protocol of an existing think, the carries / over is used to represent the reasonable protocol relationship Step 2.2: Long inference data synthesis module. This module calls a large language model (such as deepseek, Qwen, etc.), denoted as LLMpcap_analysis, and inputs the pcap_reference_prompt part in the dataset output in Step 2.1 into the large language model one by one to obtain the long inferences output by the model, constituting the "long inference synthesis data set". Each element in the data set is a binary tuple <pcap, pcap_reference_result>.

[0033] Step 3: Refer to Figure 3 As shown, use the Pcap packet long inference scoring and optimization device. The input of this device is a data set of <extracted information of the Pcap packet, long inference synthesis data>, that is, the output information of Step 2; the output of this device is the trained network protocol long inference model

[0034] Step 3.1: "Unreasonable protocol field" extraction module for long inference. The input of this module is the binary tuple data <pcap, pcap_reference_result> in the data generated in Step 2.2, and the output is the ratio of "unreasonable protocol fields". The reasonable protocol fields included in the pcap are denoted as the variable valid_vars. Extract the characters in the form of protocal.field in the pcap_reference_result through regular expressions. The protocol fields that do not exist in the valid_vars are unreasonable fields, and the rest are reasonable fields. Calculate the ratio of unreasonable fields, denoted as invalid_field_ratio

[0035] The method for obtaining protocol fields can be achieved through the following command: tshark -r demo.pcap -T json Collect all the protocol fields in the execution result of the above command and denote them as the variable valid_vars. The possible contents in the valid_vars are, for example: tcp.ack, tcp.ack_raw, tcp.hdr_len, tcp.flags … tcp.flags_tree Step 3.2: "Unreasonable Protocol Hierarchy" Extraction Module for Long Inferences. The input of this module is the binary tuple data <pcap, pcap_reference_result> in the data generated in Step 2.2, and the output is the ratio of "unreasonable protocol hierarchy". The extraction process is completed by comparing with the "Network Protocol Hierarchy Rules" list. Examples of "Network Protocol Hierarchy Rules" are as follows: ARP over Ethernet, ARP over PPP, ARP over Wi-Fi, DHCP over UDP, DNSover TCP, DNS over UDP, FTP over TCP, HTTPS over TLS, HTTP over TCP, ICMPover IP, IP over Ethernet, IP over PPP, IP over Wi-Fi, IPv6 over Ethernet,IPv6 over PPP, IPv6 over Wi-Fi, QUIC over UDP, RTP over UDP, SMTP over TCP,SSH over TCP, TCP over IP, TCP over IPv6, TLS over TCP, UDP over IP, UDP overIPv6 … Ethernet carries ARP, Ethernet carries IP, Ethernet carries IPv6, PPPcarries ARP, PPP carries IP, PPP carries IPv6, Wi-Fi carries ARP, Wi-Ficarries IP, Wi-Fi carries IPv6, IP carries ICMP, IP carries TCP, IP carriesUDP, IPv6 carries TCP, IPv6 carries UDP, TCP carries DNS, TCP carries FTP,TCP carries HTTP, TCP carries SMTP, TCP carries SSH, TCP carries TLS, TLScarries HTTPS, UDP carries DHCP, UDP carries DNS, UDP carries QUIC, UDPcarries RTP … Based on the content of each protocal node of think in the xml output in step 2.1, if it contains a node id, replace it with the corresponding protocol. For example, if the protocal of a certain think is "IP carries 6", and among them, the protocol of the think with id 6 is TCP or "TCP carries HTTP", then the replaced result is "IP carries TCP". For the protocol level description "IP carries TCP", if the same rule cannot be found in the "Network Protocol Level Rules" list, it is an unreasonable rule. Calculate the ratio of unreasonable rules and denote it as invalid_nested_protocol_ratio. Step 3.3: Long Inference Scoring and Training Module. The input of this module is the output of step 2.2, step 3.1, and step 3.2, and the output of this module is a score between 0 and 1. Check whether the content of pcap_reference_result conforms to the XML format defined in step 2.1, denoted as is_valid_format. If it conforms, it is 1; if not, it is 0. Calculate the long inference score according to the following formula:

[0036]

[0037] is a decimal between 0 and 1, The larger it is, the greater the influencing factor of the factor of the item where it is located.

[0038] Indicates whether it is a valid format. 1 means valid, and 0 means invalid.

[0039] invalid_field_ratio represents the ratio of unreasonable fields, and its value ranges from 0 to 1. The larger it is, the higher the proportion of unreasonable fields.

[0040] Represents the ratio of invalid protocol nesting formats, and its value ranges from 0 to 1. The larger it is, the higher the ratio of invalid protocol nesting formats.

[0041] Use the GRPO algorithm to train LL Mpcap_analysis During the optimization process, the reward value of the GPRO algorithm uses the Reward in step 3.3. The GRPO algorithm is a large model optimization algorithm proposed in "DeepSeekMath: Pushing the Limits of Mathematical Reasoning in Open Language Models".

[0042] The GRPO algorithm optimizes the model's parameters based on the reward. The effect after the application of this algorithm is that the model is more inclined to produce outputs with high rewards and less likely to produce outputs with low rewards.

[0043] An implementation system for long inference of a network protocol analysis model, comprising: A Pcap packet information extraction device, a Pcap packet length inference synthesis collection device, and a Pcap packet length inference scoring and optimization device.

[0044] The Pcap packet information extraction device inputs Pcap packets and outputs traffic statistics information, TCP / UDP session information, parsing of protocol content such as HTTP / DNS / TLS, and abnormal behavior information. The output information will be input into a large model in the Pcap packet length inference synthesis collection device for the synthesis of long inference data; The input of the Pcap packet length inference synthesis collection device is the extraction information of Pcap packets, that is, the output information of the "Pcap packet information extraction device"; the output of this device is a set of binary tuple data of <extraction information of Pcap packets, long inference synthesis data>. The output data of this device will be used in the Pcap packet length inference scoring and optimization device for optimizing the long inference function of the model; The Pcap packet length inference scoring and optimization device. The input of this device is a data set of <extraction information of Pcap packets, long inference synthesis data>, that is, the output information of the Pcap packet length inference synthesis collection device; the output of this device is a trained network protocol long inference model.

[0045] Those skilled in the art know that in addition to implementing the system and its various devices, modules, and units provided by the present invention in the form of pure computer-readable program code, the method steps can be logically programmed to enable the system and its various devices, modules, and units provided by the present invention to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers, etc. to achieve the same functions. Therefore, the system and its various devices, modules, and units provided by the present invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be regarded as the structures within the hardware component; the devices, modules, and units for implementing various functions can also be regarded as either software modules for implementing the method or structures within the hardware component.

[0046] The specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the above specific implementation manners, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Without conflict, the embodiments of the present application and the features in the embodiments can be arbitrarily combined with each other.

Claims

1. A long-term reasoning implementation system for a network protocol analysis model, characterized in that: include: Pcap packet information extraction device, used to extract relevant information from the input Pcap packet and output it; The relevant information includes traffic statistics information, TCP / UDP session information, HTTP / DNS / TLS protocol content analysis and abnormal behavior information; A Pcap packet length reasoning synthesis collection device, used to process the relevant information output by the Pcap packet information extraction device and output a data set; The data set includes a set of binary data of the extracted information of the pcap package and the long reasoning synthetic data; The Pcap packet length reasoning scoring and optimization device inputs the data set and outputs a trained network protocol long reasoning model.

2. The long reasoning implementation system of the network protocol analysis model according to claim 1 is characterized in that: The Pcap packet information extraction device comprises: Traffic statistics extraction module, used to extract the statistics of the flow of pcap packets; TCP / UDP session extraction module, used to extract TCP / UDP session information in pcap packets; HTTP / DNS / TLS payload information extraction module, used to extract HTTP / DNS / TLS payload information in pcap packets; The network abnormal behavior information extraction module is used to extract network abnormality information in the pcap package.

3. The long reasoning implementation system of the network protocol analysis model according to claim 2 is characterized in that: The output information of the traffic statistics extraction module includes the total traffic size, the number of packets, each IP statistics, protocol distribution, port distribution and traffic timing; The output information of the TCP / UDP session extraction module includes TCP three-way handshake success rate, packet loss rate, retransmission rate, whether there is a reset anomaly, UDP session request-response success rate, TLS handshake success rate and whether there is an abnormal Alert detection; The output information of the HTTP / DNS / TLS load information extraction module includes HTTP target, User-Agent, Host, error ratio, DNS resolution domain name, TLS encryption algorithm and whether there is a certificate anomaly; The output information of the network abnormal behavior information extraction module includes whether there is scanning, whether there is DDOS, and TLS certificate forgery.

4. The long reasoning implementation system of the network protocol analysis model according to claim 2 is characterized in that: Also includes: The information summary module records all the extracted information in text and forms a tuple with the original pcap package; The tuple includes {pcap package, extract_info}, wherein extract_info is the extraction information corresponding to the pcap package.

5. The long reasoning implementation system of the network protocol analysis model according to claim 4 is characterized in that: The Pcap packet length reasoning synthesis collection device comprises: A Pcap packet length reasoning prompt word preparation module, which inputs the two-tuple to form a prompt word data set; The long inference data synthesis module calls a large language model, inputs the corresponding prompt words into the large language model one by one, and obtains the long inference synthesis data set output by the model; Each element in the long reasoning synthetic data set is a two-tuple.

6. The long reasoning implementation system of the network protocol analysis model according to claim 5 is characterized in that: The input of the Pcap packet length reasoning prompt word preparation module is the prompt word constituted by extract_info in the output binary tuple of the information summary module to form a prompt word data set, and each record in the data is a binary tuple {pcap, pcap_reference_prompt}, where pcap_reference_prompt is the prompt word corresponding to pcap; The large language models called by the long reasoning data synthesis module include deepseek and Qwen, denoted as LLM pcap_analysis , input the pcap_reference_prompt part in the prompt word dataset into the large language model one by one, obtain the long reasoning output by the model, and form a long reasoning synthetic data set; each element in the data set is a two-tuple {pcap, pcap_reference_result}.

7. The long reasoning implementation system of the network protocol analysis model according to claim 6 is characterized in that: The Pcap packet length reasoning scoring and optimization device comprises: The unreasonable protocol field extraction module for long reasoning takes as input the binary data in the long reasoning synthetic data set and outputs the proportion of unreasonable protocol fields; The unreasonable protocol level extraction module for long reasoning takes as input the binary data in the long reasoning synthetic data set and outputs the unreasonable protocol level ratio; The long reasoning scoring and training module inputs the bigrams, unreasonable protocol field ratio, and unreasonable protocol level ratio in the long reasoning synthetic data set, and outputs a scoring score between 0 and 1.

8. The long reasoning implementation system of the network protocol analysis model according to claim 7 is characterized in that: The input of the unreasonable protocol field extraction module of the long reasoning is the tuple {pcap, pcap_reference_result}, and the output is the ratio of unreasonable protocol fields; the reasonable protocol fields contained in pcap are recorded as variable valid_vars, and the characters in the form of protocol.field in pcap_reference_result are extracted through regular expressions. The protocol fields that do not exist in valid_vars are unreasonable fields, and the rest are reasonable fields; the ratio of unreasonable fields is calculated and recorded as invalid_field_ratio.

9. The long reasoning implementation system of the network protocol analysis model according to claim 8, characterized in that: The input of the unreasonable protocol level extraction module of the long reasoning is a tuple {pcap, pcap_reference_result}, and the extraction process is completed by comparing the network protocol level rule list; The long reasoning scoring and training module includes checking whether the content of pcap_reference_result conforms to the XML format defined by the Pcap packet long reasoning prompt word preparation module, which is recorded as is_valid_format. If it conforms, it is 1, and if it does not conform, it is 0. The long reasoning score is calculated according to the following formula: in, ; is a decimal between 0 and 1. Indicates whether it is a valid format, 1 indicates valid, 0 indicates invalid; invalid_field_ratio indicates the ratio of unreasonable fields, ranging from 0 to 1, the larger the value, the higher the ratio of unreasonable fields; Indicates the proportion of invalid protocol nested formats, with a value ranging from 0 to 1. A larger value indicates a higher proportion of invalid protocol nested formats. Using GRPO algorithm to analyze LLM pcap_analysis During training and optimization, the reward value of the GPRO algorithm uses the long reasoning score and the reward of the training module.

10. A method for implementing long reasoning of a network protocol analysis model, using the implementation system for long reasoning of a network protocol analysis model according to any one of claims 1 to 9, characterized in that: include: Step S1: extracting traffic statistics information, TCP / UDP session information, HTTP / DNS / TLS protocol content analysis and abnormal behavior information from the input Pcap packet through the Pcap packet information extraction device; Step S2: Use the Pcap packet length reasoning synthesis collection device to process the above information and generate a tuple {pcap, pcap_reference_result} containing long reasoning synthesis data; Step S3: The long reasoning synthetic data is scored and optimized by the Pcap packet long reasoning scoring and optimization device, and finally a trained network protocol long reasoning model is output.

Citation Information

Patent Citations

  • Protocol analysis system of computer network

    CN116915679A

  • Network device user identification method and system based on network protocol analysis

    CN119182838A

  • DNS (Domain Name System) tunnel Trojan detection method based on communication behavior analysis

    CN107733851A

  • Network traffic anomaly detection method and device

    CN117749535A

  • Data protocol analysis method and device based on hierarchical sequence structure reasoning

    CN118631916A