Application analysis method and system based on encrypted stream

By acquiring encrypted flows, determining multi-dimensional traffic characteristics and using machine learning models to process feature data, the problem of cumbersome encryption traffic recognition operations in the prior art is solved, and accurate analysis of application types and behavioral characteristics and identification of new applications are achieved.

CN120200982APending Publication Date: 2025-06-24EXANDS INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510503288.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art is cumbersome to use when identifying encrypted traffic, making it difficult to adapt to new applications and updated versions of applications.

Method used

By obtaining the encrypted flow to be analyzed, multi-dimensional traffic characteristics are determined, and the machine learning model is used to process these features and associated feature data in order to accurately analyze application types and application behavior characteristics.

Benefits of technology

It realizes convenient and accurate analysis of application types and application behavior characteristics, and improves the ability to identify new applications and updated application versions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200982A_ABST
    Figure CN120200982A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an application analysis method and system based on an encrypted stream, and the method is executed by a processor, and comprises the steps: obtaining a to-be-analyzed encrypted stream; based on the to-be-analyzed encrypted stream, determining a multi-dimensional traffic feature; the multi-dimensional traffic features refer to multi-dimensional features which can be used for analyzing the encrypted stream to be analyzed; and processing the multi-dimensional traffic features and the associated feature data based on an application analysis model, and determining an application type and an application behavior feature, the application analysis model being a machine learning model, and the associated feature data being data associated with the to-be-analyzed encrypted stream.
Need to check novelty before this filing date? Find Prior Art

Description

Division Case Explanation

[0001] This application is a divisional application filed in China based on the Chinese application with an application date of December 30, 2022, an application number of 202211724943.X, and an invention title of "An Application Analysis Method and System Based on Encrypted Streams". Technical Field

[0002] This specification relates to the field of encrypted stream analysis, and particularly to an application analysis method and system based on encrypted streams. Background Art

[0003] Currently, with the rapid development of Internet technology, network traffic classification has great potential value in aspects such as traffic optimization of operators. For example, identifying the application type and application behavior characteristics based on network traffic and feedbacking them to the operator will provide benefits such as the improvement direction of the application to the operator. With the increasing attention of major manufacturers to traffic encryption, methods for identifying encrypted streams play a crucial role. Nowadays, various application program versions are rapidly iterating, and various new application programs are constantly emerging. Identification methods for various encrypted streams need to be upgraded to cope with the current application market situation.

[0004] To solve the problem of efficiently identifying encrypted traffic, the prior art CN113162908B provides a method and system for detecting encrypted traffic based on deep learning, which converts traffic into an image processing method to extract its geometric features, and continuously cuts the original continuous traffic into discrete streams. The discrete streams are continuously cut into many small-sized data packets according to the session granularity to achieve effective classification of the service category and specific application category of encrypted traffic. Since this process relies on cutting traffic into small-sized data packets, the operation is relatively cumbersome.

[0005] Therefore, it is desired to provide an application analysis method and system based on encrypted streams for conveniently and accurately analyzing application types and application behavior characteristics. Summary of the Invention

[0006] One or more embodiments of this specification provide an application analysis method based on encrypted streams. The method is executed by a processor and includes: obtaining an encrypted stream to be analyzed; determining multi-dimensional traffic characteristics based on the encrypted stream to be analyzed, where the multi-dimensional traffic characteristics refer to characteristics in multiple dimensions that can be used to analyze the encrypted stream to be analyzed; processing the multi-dimensional traffic characteristics and associated feature data based on an application analysis model to determine the application type and application behavior characteristics, where the application analysis model is a machine learning model and the associated feature data is data associated with the encrypted stream to be analyzed.

[0007] One embodiment of this specification provides an application analysis system based on encrypted streams. The system includes: an acquisition module for acquiring encrypted streams to be analyzed; a first determination module for determining multi-dimensional traffic characteristics based on the encrypted streams to be analyzed. The multi-dimensional traffic characteristics refer to characteristics in multiple dimensions that can be used to analyze the encrypted streams to be analyzed; a second determination module for processing the multi-dimensional traffic characteristics and associated feature data based on an application analysis model to determine the application type and application behavior characteristics. The application analysis model is a machine learning model, and the associated feature data is data associated with the encrypted streams to be analyzed. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] This specification will be further described by way of exemplary embodiments, which will be described in detail through the accompanying drawings. These embodiments are not restrictive. In these embodiments, the same numbers represent the same structures, where:

[0009] Figure 1 is a schematic diagram of the application scenario of the application analysis system based on encrypted streams shown in some embodiments of this specification;

[0010] Figure 2 is a block diagram of the application analysis system based on encrypted streams shown in some embodiments of this specification;

[0011] Figure 3 is an exemplary flowchart of the application analysis method based on encrypted streams shown in some embodiments of this specification;

[0012] Figure 4 is an exemplary schematic diagram of determining the application type and application behavior characteristics shown in some embodiments of this specification;

[0013] Figure 5 is another exemplary schematic diagram of determining the application type and application behavior characteristics shown in some embodiments of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0014] To more clearly illustrate the technical solutions of the embodiments of this specification, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some examples or embodiments of this specification. For those of ordinary skill in the art, without creative efforts, this specification can also be applied to other similar scenarios based on these drawings. Unless obvious from the language context or otherwise stated, the same reference numerals in the figures represent the same structures or operations.

[0015] It should be understood that the "system", "device", "unit" and / or "module" used herein is a way to distinguish different components, elements, parts, portions or assemblies at different levels. However, if other words can achieve the same purpose, those words can be replaced by other expressions.

[0016] Unless the context clearly indicates an exception, words such as "a", "an", "one" and / or "the" are not specifically singular and may also include the plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the clearly identified steps and elements, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements.

[0017] Flowcharts are used in this specification to illustrate the operations performed by the system according to the embodiments of this specification. It should be understood that the previous or subsequent operations do not necessarily need to be executed precisely in sequence. On the contrary, the steps can be processed in reverse order or simultaneously. At the same time, other operations can also be added to these processes, or one or several steps can be removed from these processes.

[0018] To solve the problem that the method for identifying encrypted traffic in existing methods is relatively cumbersome and can better adapt to new applications and updated versions of applications, this specification provides an application analysis method and system based on encrypted flows, which can conveniently and accurately analyze the application type and application behavior characteristics by determining multi-dimensional traffic characteristics.

[0019] Figure 1 It is a schematic diagram of the application scenario of the application analysis system based on encrypted flows shown in some embodiments of this specification.

[0020] As Figure 1 shown, the application scenario 100 of the application analysis system based on encrypted flows may include an encrypted flow 110, a processor 120, an application type 130, and an application behavior characteristic 140.

[0021] The encrypted flow 110 can be analyzed and processed by the processor 120 to obtain the application type 130 and the application behavior characteristic 140, where the application behavior characteristic 140 may include a series of operations such as voice 140-1 and typing input 140-2 that can be performed in the application.

[0022] The encrypted flow 110 refers to the continuously generated data stream from the source end to the destination end. Among them, the source end may include mobile devices such as mobile phones and computers, and the destination end may include servers that receive the data stream. For the detailed content of the encrypted flow, refer to the relevant description later.

[0023] The processor 120 refers to a system with computing capabilities. In some embodiments, the processor 120 can be used to process the encrypted stream 110. For example, the processor 120 can be used to obtain the encrypted stream to be analyzed. Also for example, the processor 120 can further determine multi-dimensional traffic characteristics based on the encrypted stream to be analyzed, and determine the application type and application behavior characteristics based on the multi-dimensional traffic characteristics.

[0024] In some embodiments, the processor 120 can include one or more processing engines (e.g., a single-chip processing engine or a multi-chip processing engine). By way of example only, the processor 110 can include a central processing unit (CPU), an application-specific integrated circuit (ASIC), an application-specific instruction processor (ASIP), etc., or any combination thereof.

[0025] The application type 130 refers to the type of application at the source end. For example, the application type can include applications such as WeChat and Tencent Meeting.

[0026] The application behavior characteristics 140 can refer to the operation characteristics executed in the application. For example, the application behavior characteristics can include operations such as voice 140-1 and typing input 140-2 in the application.

[0027] Figure 2 It is a module diagram of an application analysis system based on an encrypted stream according to some embodiments of this specification.

[0028] In some embodiments, the application analysis system 200 based on an encrypted stream can include an acquisition module 210, a first determination module 220, and a second determination module 230.

[0029] In some embodiments, the acquisition module 210 can be used to obtain the encrypted stream to be analyzed. For the specific content of the encrypted stream to be analyzed, see Figure 3 and its related descriptions.

[0030] In some embodiments, the first determination module 220 can be used to determine multi-dimensional traffic characteristics based on the encrypted stream to be analyzed. The multi-dimensional traffic characteristics include at least one or more of a flow dimension feature, a data packet dimension feature, a host dimension feature, and a session dimension feature. For the specific content of the multi-dimensional traffic characteristics, see Figure 3 and its related descriptions.

[0031] In some embodiments, the second determination module 230 can be used to determine the application type and application behavior characteristics based on the multi-dimensional traffic characteristics.

[0032] In some embodiments, the second determination module 230 can be used to process the multi-dimensional traffic characteristics based on an application analysis model to determine the application type and application behavior characteristics. For the specific content of the application analysis model, see Figure 4 and its related descriptions.

[0033] In some embodiments, the second determination module 230 may be configured to determine first associated feature data based on the multi-dimensional traffic features, including: determining a first target feature vector based on the multi-dimensional traffic features; determining a first associated feature vector through a vector feature database based on the first target feature vector; determining first associated feature data based on the decrypted encrypted flow corresponding to the first associated feature vector; determining an application type based on the first associated feature data; wherein the first associated feature data is related to the decrypted encrypted flow. In some embodiments, the second determination module 230 may be configured to determine second associated feature data based on the multi-dimensional traffic features, including: determining a second target feature vector based on the multi-dimensional traffic features and the application type; determining a second associated feature vector through a vector feature database based on the second target feature vector; determining second associated feature data based on the decrypted encrypted flow corresponding to the second associated feature vector; determining application behavior features based on the second associated feature data; wherein the second associated feature data is related to the decrypted encrypted flows of the same application type within a preset time period. For the specific content of determining the application type and application behavior features, see Figure 5 and its related descriptions.

[0034] It should be noted that the above description of the application analysis system 200 based on encrypted flows and its modules is only for convenience of description and does not limit this specification to the scope of the examples given. It can be understood that for those skilled in the art, after understanding the principle of the system, they may, without departing from this principle, make any combination of the various modules, or form a subsystem and connect it to other modules. In some embodiments, Figure 2 the acquisition module 210, the first determination module 220, and the second determination module 230 disclosed in

[0035] Figure 3 may be different modules in a system, or a module may implement the functions of two or more of the above modules. For example, the various modules may share a storage module, or each module may have its own storage module. Such variations are within the protection scope of this specification.

[0035] Figure 3 is an exemplary flowchart of an application analysis method based on encrypted flows according to some embodiments of this specification. As Figure 3 shown, the process 300 includes the following steps. In some embodiments, the process 300 may be executed by the application analysis system 200 based on encrypted flows.

[0036] Step S310, obtaining the encrypted flow to be analyzed.

[0037] An encrypted stream refers to the data stream generated from the source end to the destination end. For example, after the source end connects to the relay end, the data generated by the source end's behavior on the network is sent to the destination end through the relay end to generate an encrypted stream. Among them, the source end can be a mobile device, such as a mobile phone, etc., the relay end can include a router, etc., and the destination end can include a server that receives the data generated by the behavior on the network. The data generated by the behavior on the network can include the data generated when using an application. For example, if a user uses Tencent Meeting on the network, the data generated by this behavior can include the data generated when using Tencent Meeting.

[0038] The encrypted stream to be analyzed refers to the encrypted stream intercepted within a certain period of time. For example, an encrypted stream with a duration of 5 seconds is intercepted.

[0039] In some embodiments, the processor can capture the encrypted stream to be analyzed from the source end, the relay end, or the destination end, etc. Among them, the capture can be performed by means such as packet capture or port mirroring. For example, the processor can capture the encrypted stream to be analyzed from a mobile phone, a wireless router, a switch, or a server, etc.

[0040] In some embodiments, the processor can preset the capture time length to obtain the encrypted stream to be analyzed. For example, if the processor presets the capture time length to 5 seconds, the data stream captured within 5 seconds can be used as the encrypted stream to be analyzed.

[0041] Step S320, based on the encrypted stream to be analyzed, determine multi-dimensional traffic characteristics, and the multi-dimensional traffic characteristics at least include one or more of the flow dimension characteristics, packet dimension characteristics, host dimension characteristics, and session dimension characteristics.

[0042] The multi-dimensional traffic characteristics refer to the characteristics of multiple dimensions that can be used to analyze the encrypted stream. In some embodiments, the multi-dimensional traffic characteristics at least include one or more of the flow dimension characteristics, packet dimension characteristics, host dimension characteristics, and session dimension characteristics.

[0043] The flow dimension characteristics refer to the characteristics related to the flow. In some embodiments, the flow dimension characteristics can include flow duration, flow arrival time interval, flow size, flow rate, etc. It should be noted that a flow is different from the encrypted stream to be analyzed, and the encrypted stream to be analyzed can include multiple flows.

[0044] The flow duration refers to the duration from the start time to the end time of the same flow. For example, if the start time of the a-th flow is 7:10:32 and the end time of the a-th flow is 7:10:38, then the flow duration of the a-th flow is 6 seconds.

[0045] The flow arrival time interval refers to the time interval between the start times of two different consecutive flows. For example, flow b and flow c are two consecutive flows initiated by the same application. The start time of flow b is 09:50:26, and the start time of flow c is 09:50:27. Then the flow arrival time interval between flow b and flow c is 1 second.

[0046] The flow size refers to the number of bytes of the flow. For example, if the number of data packets in flow d is 10, and the size of each data packet is 1500 bytes, then the size of flow d is 15000 bytes.

[0047] The flow rate refers to the flow size that a flow can transmit per unit time. In some embodiments, the flow rate can be calculated by dividing the flow size by the flow duration. For example, if the size of flow d is 15000 bytes and the flow duration of flow d is 1 second, then the flow rate is 15000 bytes / second.

[0048] The data packet dimension feature refers to the feature related to the data packet. A flow can include multiple data packets. In some embodiments, the data packet dimension feature can include the data packet size distribution, the distribution of the interval time between the arrivals of data packets, the data packet transmission efficiency, the service type distribution, the protocol type distribution, etc.

[0049] The data packet size distribution refers to the distribution vector that statistically analyzes the size distribution of multiple data packets in the encrypted flow to be analyzed. For example, the data packet size distribution can be represented by a vector (a, b,...), where a can represent the number of data packets with a size of 1 byte that appear in the encrypted flow to be analyzed, and b can represent the number of data packets with a size of 2 bytes that appear in the encrypted flow to be analyzed, etc.

[0050] In some embodiments, the processor can obtain the data packet size distribution by statistically counting the number of data packets of different sizes that appear in the encrypted flow to be analyzed. For example, if the number of data packets with a size of 1 byte that appear in the encrypted flow to be analyzed is 100, the number of data packets with a size of 2 bytes that appear in the encrypted flow to be analyzed is 49, and the number of data packets with a size of 3 bytes that appear in the encrypted flow to be analyzed is 158, then the data packet size distribution can be obtained as (100, 49, 158).

[0051] The distribution of the interval time between the arrivals of data packets refers to the distribution vector that statistically analyzes the distribution of the interval time between the arrivals of multiple data packets in the encrypted flow to be analyzed. For example, the distribution of the interval time between the arrivals of data packets can be represented by a vector (c, d,...), where c can represent the number of data packets with an interval time of 1 second between arrivals that appear in the encrypted flow to be analyzed, and d can represent the number of data packets with an interval time of 2 seconds between arrivals that appear in the encrypted flow to be analyzed, etc. The method of obtaining the distribution of the interval time between the arrivals of data packets is similar to the method of obtaining the data packet size distribution described above, and will not be elaborated here.

[0052] The data packet transmission efficiency refers to the number of data packets transmitted per unit time.

[0053] The service type refers to the service type of a packet, such as the TOS field of an IP packet. The service type distribution refers to a distribution vector that statistically represents the distribution of the service types of multiple data packets in the encrypted stream to be analyzed. For example, the service type distribution can be represented by a vector (e, f,...), where e can represent the number of times a data packet with a TOS field of 00010000 appears in the encrypted stream to be analyzed, and f can represent the number of times a data packet with a TOS field of 00001000 appears in the encrypted stream to be analyzed, etc. The method for obtaining the service type distribution is similar to the method for obtaining the data packet size distribution described above and will not be elaborated here.

[0054] The protocol type refers to the protocol type of a packet, such as the protocol type of an IP packet. The protocol type distribution refers to a distribution vector that statistically represents the distribution of the protocol types of multiple data packets in the encrypted stream to be analyzed. For example, the protocol type distribution can be represented by a vector (g, h,...), where g can represent the number of times a data packet of protocol type A appears in the encrypted stream to be analyzed, and h can represent the number of times a data packet of protocol type B appears in the encrypted stream to be analyzed, etc. The method for obtaining the protocol type distribution is similar to the method for obtaining the data packet size distribution described above and will not be elaborated here.

[0055] The host dimension features refer to features related to the host. In some embodiments, the host dimension features may include the average number of data packets per flow, the average number of port interactions per flow, the port packet distribution, etc.

[0056] The number of port interactions refers to the number of ports that have sent data packets. For example, in a flow, if host A has sent data packets to ports 135, 80, and 445 of host B, then the number of port interactions is 3.

[0057] The port packet distribution refers to the distribution of the source ports and destination ports of multiple data packets in the encrypted stream to be analyzed. The port packet distribution can be represented by a vector (i, j,...), where i represents the number of times each data packet's corresponding source port appears, and j represents the number of times each data packet's corresponding destination port appears, etc. For example, a certain port packet distribution of (22, 35) means that the data packet appears 22 times on a certain source port and 35 times on a certain destination port. The method for obtaining the port packet distribution is similar to the method for obtaining the data packet size distribution described above and will not be elaborated here.

[0058] Session dimension features refer to features related to sessions. In some embodiments, session dimension features may include session size distribution, session duration distribution, etc. In some embodiments, the encrypted flow to be analyzed may contain multiple sessions. For example, if the amount of data requested by the source for a certain data request is large, the server will divide the data request into multiple sessions for transmission.

[0059] Session size distribution refers to a distribution vector that statistically represents the distribution of session sizes in the encrypted flow to be analyzed. For example, the session size distribution can be represented by a vector (k, l,...), where k can represent the number of sessions with a size of 1 byte, l can represent the number of sessions with a size of 2 bytes, and so on. The method of obtaining the session size distribution is similar to the method of obtaining the packet size distribution described above and will not be elaborated here.

[0060] Session duration distribution refers to a distribution vector that statistically represents the distribution of session durations in the encrypted flow to be analyzed. For example, the session duration distribution can be represented by a vector (m, n,...), where m can represent the number of sessions with a duration of 1 second in the encrypted flow to be analyzed, n can represent the number of sessions with a duration of 2 seconds in the encrypted flow to be analyzed, and so on. The method of obtaining the session duration distribution is similar to the method of obtaining the packet size distribution described above and will not be elaborated here.

[0061] In some embodiments, the processor can analyze the encrypted flow to be analyzed to determine multi-dimensional traffic features. For example, analyzing and calculating the flow rate can obtain flow dimension features, and obtaining the session size distribution based on session size statistics can obtain session dimension features, etc.

[0062] In some embodiments, the processor can retrieve the decrypted encrypted flow, compare the similarity between the encrypted flow to be analyzed and the decrypted encrypted flow, select the decrypted encrypted flow with a similarity less than the threshold, and use the multi-dimensional traffic features corresponding to the decrypted encrypted flow as the multi-dimensional traffic features of the encrypted flow to be analyzed.

[0063] Step S330, based on the multi-dimensional traffic features, determine the application type and application behavior features.

[0064] In some embodiments, the processor can match multiple decrypted encrypted flows with a similarity higher than the similarity threshold in the historical decrypted encrypted flows based on the multi-dimensional traffic features, and determine the application type and application behavior features with the largest proportion in the above decrypted encrypted flows as the application type and application behavior features of the encrypted flow to be analyzed. Among them, the similarity threshold can be set in advance, such as 80%.

[0065] In some embodiments, the processor may analyze multi-dimensional traffic features based on an application analysis model to determine the application type and application behavior characteristics. For more descriptions on determining the application type and application behavior characteristics through the application analysis model, reference can be made to Figure 4 and its related descriptions.

[0066] In some embodiments, the processor may determine the application type based on the first associated feature data. In some embodiments, the processor may determine the application behavior characteristics based on the second associated feature data. For more descriptions on the first associated feature data and the second associated feature data, reference can be made to Figure 5 and its related descriptions.

[0067] In some embodiments of this specification, based on the multi-dimensional traffic features obtained from the encrypted flow to be analyzed, determining the application type and application behavior characteristics in the encrypted flow to be analyzed can accurately detect the application type and application behavior characteristics, facilitate subsequent application analysis and determination of the optimization direction of the application, and can also determine whether the application usage is abnormal, etc.

[0068] It should be noted that the above description of process 300 is only for illustration and explanation, and does not limit the scope of application of this specification. Those skilled in the art can make various corrections and changes to process 300 under the guidance of this specification. However, these corrections and changes are still within the scope of this specification.

[0069] Figure 4 is an exemplary diagram showing the determination of the application type and application behavior characteristics according to some embodiments of this specification.

[0070] In some embodiments, the processor may process the multi-dimensional traffic features 410 based on the application analysis model 420 to determine the application type 470 and the application behavior characteristics 490.

[0071] The application analysis model is a model for determining the application type and application behavior characteristics. In some embodiments, the application analysis model may be a machine learning model. For example, the application analysis model may be any one or a combination of various feasible models such as a Recurrent Neural Network (RNN) model, a Deep Neural Network (DNN) model, a Convolutional Neural Network (CNN) model, etc.

[0072] In some embodiments, the input to the application analysis model 420 may include multi-dimensional traffic features 410, where the multi-dimensional traffic features 410 may include flow dimension features 410-1, packet dimension features 410-2, host dimension features 410-3, and session dimension features 410-4. For more information on flow dimension features, packet dimension features, host dimension features, and session dimension features, see Figure 3 and its related descriptions.

[0073] In some embodiments, the output of the application analysis model 420 may include application types 470 and application behavior characteristics 490. For more information on application types and application behavior characteristics, see Figure 1 and its related descriptions.

[0074] In some embodiments, the processor may train an initial application analysis model based on training samples and their labels. The initial application analysis model may be an application analysis model without set parameters. The training samples may be sample multi-dimensional traffic features, and the labels may be their corresponding actual application types and actual application behavior characteristics. The training samples and labels may be obtained based on historical data retrieved from a storage device or database, and the labels may be obtained based on historical actual situations. An exemplary training process includes: inputting the sample multi-dimensional traffic features into the initial application analysis model for training to obtain the output application types and application behavior characteristics, constructing a loss function based on the output results of the initial application analysis model and the labels, and iteratively updating the initial application analysis model based on the loss function until a preset condition is met, at which point the training is completed and a trained application analysis model is obtained. Among them, the preset condition may be that the loss function is less than a threshold, convergence occurs, or the training cycle reaches a threshold.

[0075] In some embodiments, the application analysis model 420 may include an embedding layer 420-1, a type analysis layer 420-2, and a behavior analysis layer 420-3.

[0076] In some embodiments, the input to the embedding layer 420-1 may be the multi-dimensional traffic features 410, and the output may be an embedded feature vector 450. Among them, the embedded feature vector refers to a feature vector obtained by performing feature extraction on the multi-dimensional traffic features.

[0077] In some embodiments, the embedding layer 420-1 may be a single embedding layer or may have an embedding layer corresponding to each dimension feature. For example, the flow dimension feature 410-1, the packet dimension feature 410-2, the host dimension feature 410-3, and the session dimension feature 410-4 may each correspond to an embedding layer.

[0078] In some embodiments, the input to the type analysis layer 420-2 may include the embedded feature vector 450, and the output includes the application type 470.

[0079] In some embodiments, the input of the behavior analysis layer 420-3 may include the application type 470, and the output includes the application behavior feature 490. In some embodiments, the input of the behavior analysis layer 420-3 may further include the embedded feature vector 450.

[0080] In some embodiments, the application analysis model may also be obtained through joint training, and the joint training may be performed based on the foregoing training samples and labels. An exemplary training process includes: inputting the sample multi-dimensional traffic features into the initial embedding layer to obtain the embedded feature vector output by the initial embedding layer; inputting the embedded feature vector output by the initial embedding layer into the initial type analysis layer to obtain the application type output by the initial type analysis layer; inputting the embedded feature vector output by the initial embedding layer and the application type output by the initial type analysis layer into the initial behavior analysis layer to obtain the application behavior feature output by the initial behavior analysis layer. Constructing a loss function based on the label, the application type output by the initial type analysis layer, and the application behavior feature output by the initial behavior analysis layer, and iteratively updating the parameters of the initial embedding layer, the initial type analysis layer, and the initial behavior analysis layer based on the loss function until the preset condition is satisfied, the training is completed, and the trained application analysis model is obtained. Wherein, the preset condition may be that the loss function is less than a threshold, convergence, or the training cycle reaches a threshold.

[0081] In some embodiments, the input of the application analysis model 420 further includes the associated feature data 440.

[0082] The associated feature data refers to the data associated with the encrypted flow to be analyzed. In some embodiments, the associated feature data 440 includes the first associated feature data 440-1 and the second associated feature data 440-2. Wherein, the first associated feature data 440-1 and the second associated feature data 440-2 may be determined based on the vector feature database 430. For more descriptions of the first associated feature data and the second associated feature data, reference may be made to Figure 5 and its related descriptions.

[0083] In some embodiments, when the input of the application analysis model 420 includes the associated feature data 440, when training the application analysis model, the training samples may further include the sample associated feature data. The sample associated feature data may be stored in the vector feature database. For the remaining training parts, reference may be made to the relevant content above.

[0084] In some embodiments of this specification, by predicting the application type and the application behavior feature through the application analysis model, the prediction efficiency can be improved and the time cost can be saved. At the same time, by considering the influence of the associated feature data, the prediction accuracy of the model can be ensured.

[0085] In some embodiments, the input of the type analysis layer 420-2 further includes a reference application type distribution 460, and the input of the behavior analysis layer 420-3 further includes a reference application behavior distribution 480, where the reference application type distribution 460 can be determined based on the first associated feature data 440-1, and the reference application behavior distribution 480 can be determined based on the second associated feature data 440-2.

[0086] The reference application type distribution refers to a vector formed by statistically analyzing the distribution of application types. For example, the reference application type distribution can be represented by a vector (x, y, z), where x, y, and z can represent the occurrence times of application type X, application type Y, and application type Z, respectively.

[0087] In some embodiments, the reference application type distribution can be determined based on the first associated feature data. For example, the processor can count the occurrence times of multiple application types in the first associated feature data to obtain the reference application type distribution. By way of example only, the processor can count the occurrence times of WeChat, QQ, and DingTalk to obtain a reference application type distribution of (2, 1, 1), indicating that the occurrence times of WeChat, QQ, and DingTalk are 2 times, 1 time, and 1 time, respectively.

[0088] The reference application behavior distribution refers to a vector formed by statistically analyzing the distribution of application behavior characteristics. For example, the reference application behavior distribution can be represented by a vector (o, p, q), where o, p, and q can represent the occurrence times of application behavior characteristics O, P, and Q of the same application type, respectively.

[0089] In some embodiments, the reference application behavior distribution can be determined based on the second associated feature data. For example, the processor can count the occurrence times of multiple application behavior characteristics in the second associated feature data to obtain the reference application behavior distribution. By way of example only, the processor can count the occurrence times of the application behavior characteristics "sharing screen", "speaking", and "typing" to obtain a reference application behavior distribution of (2, 3, 2), indicating that the occurrence time of "sharing screen" is 2 times, the occurrence time of "speaking" is 3 times, and the occurrence time of "typing" is 2 times.

[0090] In some embodiments of this specification, the trained application analysis model has fixed parameters, but the application transmission data may change to some extent with the iterative update of the application, making the prediction result of the application analysis model inaccurate. Therefore, the reference application type distribution and the reference application behavior distribution obtained by inputting the associated feature data in the recent period (within a preset time period) can be used to avoid the adverse effects brought by the above data changes, so that the trained application analysis model can be used for a long time, and at the same time improve the prediction accuracy of the application analysis model.

[0091] In some embodiments, the processor may perform weighted processing based on each set of data in the second associated feature data to obtain a reference application behavior distribution, and the weight of each set of data is related to the dimension of the application behavior corresponding to the set of data and the distinguishability of the occurred behavior.

[0092] The dimension of application behavior refers to the dimension of behaviors that can occur in an application. For example, in Tencent Meeting, there can be three behaviors that can occur: "speaking", "typing", and "sharing screen", so the dimension of application behavior is 3.

[0093] The dimension of occurred application behavior refers to the dimension of behaviors that have actually occurred in an application. For example, assume that in the current Tencent Meeting, "no one is speaking", "someone is typing", and "someone is sharing screen", then the dimension of occurred application behavior is 2.

[0094] In some embodiments, the processor can determine the dimension of occurred application behavior according to the generated data stream. For example, if "someone is speaking" generates an additional data stream corresponding to "someone is speaking", capturing this data stream can determine the corresponding dimension of occurred application behavior.

[0095] The distinguishability of the occurred behavior refers to the degree of distinguishing the occurred application behavior. In some embodiments, the processor can judge the distinguishability of the occurred behavior based on the packet size or transmission duration of the encrypted stream to be analyzed. For example, the larger the packet size or the longer the transmission duration of the encrypted stream to be analyzed, the higher the judged distinguishability of the occurred behavior. The distinguishability of the occurred behavior of "sharing screen" may be relatively high because it generates an additional and relatively continuous image transmission stream; the distinguishability of the occurred behavior of "speaking" is the second highest because it generates an additional and relatively continuous voice data transmission stream; the distinguishability of the occurred behavior of "typing" is relatively low as it usually does not generate a relatively continuous data stream.

[0096] In some embodiments, the distinguishability of the occurred behavior can take a value between 0 and 1. The higher the value, the higher the distinguishability of the occurred behavior.

[0097] In some embodiments, the distinguishability of the occurred behavior can be the product of the distinguishabilities of individual occurred behaviors.

[0098] In some embodiments, the distinguishability of an individual occurred behavior can be preset through methods such as simulated packet capture testing. The distinguishability of an individual occurred behavior can take a value between 0 and 1. The higher the value, the higher the distinguishability of the individual occurred behavior. For example, the distinguishability of the individual occurred behavior of "sharing screen" can be preset to 1, the distinguishability of the individual occurred behavior of "speaking" can be preset to 0.7, and the distinguishability of the individual occurred behavior of "typing" can be preset to 0.4, etc.

[0099] As an example, if "no one is speaking", "someone is typing", and "someone is sharing the screen" in the application, the recognition of the actions that have occurred can be 0.4, which is the recognition of the single action of "sharing the screen" multiplied by 1 and the recognition of the single action of "typing" 0.4.

[0100] In some embodiments, the processor can perform weighted processing based on each group of data in the second associated feature data to obtain a reference application behavior distribution, and the weight of each group of data is related to the application behavior occurrence dimension corresponding to the group of data and the recognition of the behavior that has occurred. In some embodiments, the greater the application behavior occurrence dimension and the recognition of the behavior that has occurred, the greater the weight of the group of data. For example, each group of data in the second associated feature data contains application behavior feature E, application behavior feature F, and application behavior feature G, where data group 1 is (1, 1, 0), data group 2 is (0, 1, 0), and data group 3 is (0, 0, 1). Data group 1 indicates that application behavior feature E appears 1 time, application behavior feature F appears 1 time, and application behavior feature G appears 0 times. The meanings represented by the elements in data group 2 and data group 3 are similar. Since the application behavior occurrence dimensions of data group 1, data group 2 and data group 3 are 2, 1 and 1 respectively, and the recognition of the occurred behavior of data group 1 is the highest, and the recognition of the occurred behavior of data group 3 is the lowest, the weight of data group 1 can be 0.6, the weight of data group 2 can be 0.3, and the weight of data group 3 can be 0.1. Through weighted processing, the reference application behavior distribution can be obtained as (0.6, 0.9, 0.1).

[0101] In some embodiments of the present specification, the reference application behavior distribution is related to the dimension of application behavior occurrence and the recognition degree of the behavior that has occurred, so that the data with higher recognition degree of the behavior that has occurred provides greater reference value, making the reference application behavior distribution more accurate, thereby making the determined application behavior characteristics more accurate.

[0102] Figure 5 This is another exemplary schematic diagram of determining application types and application behavior characteristics according to some embodiments of this specification.

[0103] In some embodiments, the processor may determine first associated feature data 540 - 2 based on the multi-dimensional traffic feature 510 ; and determine an application type 550 based on the first associated feature data 540 - 2 ; wherein the first associated feature data is related to the encrypted stream that has been decrypted.

[0104] In some embodiments, determining the first associated feature data 540-2 based on the multi-dimensional traffic feature 510 includes: determining the first target feature vector 520 based on the multi-dimensional traffic feature 510; determining the first associated feature vector 540-1 through the vector feature database 530 based on the first target feature vector 520; and determining the first associated feature data 540-2 based on the decrypted encrypted stream corresponding to the first associated feature vector.

[0105] The first associated feature data refers to data related to the application type. In some embodiments, the first associated feature data may include multiple sets of historical (e.g., recent period) data, and each set of historical data corresponds to a historically decrypted encrypted stream. In some embodiments, each set of historical data includes the multi-dimensional traffic feature corresponding to the historically decrypted encrypted stream and the application type corresponding to the historically decrypted encrypted stream.

[0106] The first target feature vector refers to the feature vector corresponding to the multi-dimensional traffic feature.

[0107] In some embodiments, feature extraction may be performed on the multi-dimensional traffic feature of the encrypted stream to be analyzed to obtain the first target feature vector. In some embodiments, the embedded feature vector obtained by inputting the multi-dimensional traffic feature of the encrypted stream to be analyzed into the embedding layer may also be used as the first target feature vector.

[0108] The vector feature database refers to a database for storing, indexing, and querying vectors. Through the vector feature database, similarity queries and other vector management can be quickly performed on a large number of vectors.

[0109] In some embodiments, the vector feature database may include first reference feature vectors corresponding to the multi-dimensional traffic features of multiple historically decrypted encrypted streams. In some embodiments, the vector feature database may be constructed based on multiple historically decrypted encrypted streams and the first reference feature vectors corresponding to the multi-dimensional traffic features of the multiple historically decrypted encrypted streams.

[0110] The first associated feature vector is the target feature vector selected from multiple first reference feature vectors.

[0111] In some embodiments, the processor may determine, through the vector feature database, the first reference feature vector that meets the first preset condition as the first associated feature vector based on the first target feature vector. Among them, the first preset condition may refer to the preset condition for determining the first associated feature vector. In some embodiments, the first preset condition may include that the vector distance satisfies the distance threshold, the vector distance is the smallest, etc.

[0112] In some embodiments, the processor may determine first associated feature data based on the decrypted encrypted stream corresponding to the first associated feature vector. For example, the processor may determine the multi-dimensional traffic features and application types of the decrypted encrypted stream corresponding to the first associated feature vector as the first associated feature data.

[0113] In some embodiments, the processor may determine the application type with the largest proportion in the first associated feature data as the application type of the encrypted stream to be analyzed.

[0114] In some embodiments, the processor may determine second associated feature data 570-2 based on the multi-dimensional traffic features 510; and determine application behavior features 580 based on the second associated feature data 570-2; wherein, the second associated feature data is related to the decrypted encrypted streams with the same application type within a preset time period.

[0115] In some embodiments, determining the second associated feature data 570-2 based on the multi-dimensional traffic features 510 includes: determining a second target feature vector 560 based on the multi-dimensional traffic features 510 and the application type 550; determining a second associated feature vector 570-1 through the vector feature database 530 based on the second target feature vector 560; and determining the second associated feature data 570-2 based on the decrypted encrypted stream corresponding to the second associated feature vector 570-1.

[0116] The second associated feature data refers to data related to the multi-dimensional traffic features and application types. In some embodiments, the second associated feature data may include multiple sets of historical data, and the multiple sets of historical data are of the same application type, and each set of data corresponds to a historically decrypted encrypted stream. The historical data may be data for a recent period of time, such as one month, etc. In some embodiments, each set of data includes the multi-dimensional traffic features corresponding to the decrypted encrypted stream, and the application behavior features corresponding to the decrypted encrypted stream.

[0117] In some embodiments, the second associated feature data may be determined based on the multi-dimensional traffic features through matching in the vector feature database. For example, calculate the distance between the multi-dimensional traffic features and the multi-dimensional traffic features corresponding to the decrypted encrypted streams in the vector feature database, and use the historical data corresponding to the multi-dimensional traffic features in the vector feature database with the smallest distance as the second associated feature data corresponding to the multi-dimensional traffic features. For more information about the vector feature database, see the relevant description above.

[0118] The second target feature vector refers to the feature vector corresponding to the multi-dimensional traffic features and the application type.

[0119] In some embodiments, multi-dimensional traffic features and application types of the encrypted stream to be analyzed can be subjected to feature extraction to obtain a second target feature vector. In some embodiments, the embedded feature vector obtained by inputting the multi-dimensional traffic features and application types of the encrypted stream to be analyzed into an embedding layer can also be used as the second target feature vector.

[0120] In some embodiments, the vector feature database may include multi-dimensional traffic features of multiple historically decrypted encrypted streams and second reference feature vectors corresponding to application types. In some embodiments, a vector feature database can be constructed based on multiple historically decrypted encrypted streams, multi-dimensional traffic features of multiple historically decrypted encrypted streams, and second reference feature vectors corresponding to application types.

[0121] The second associated feature vector is a target feature vector selected from multiple second reference feature vectors.

[0122] In some embodiments, the processor can determine, based on the second target feature vector, a second reference feature vector that meets the second preset condition in the vector feature database as the second associated feature vector. Herein, the second preset condition may refer to a preset condition for determining the second associated feature vector. In some embodiments, the second preset condition may include that the similarity of the feature vectors meets a similarity threshold, etc.

[0123] In some embodiments, when determining the second associated feature vector based on the matching of the second target feature vector, the similarity threshold during the matching is related to the dimension of the occurrence of the application behavior and the recognizability of the occurred behavior.

[0124] In some embodiments, when the dimension of the occurrence of the application behavior is larger and the recognizability of the occurred behavior is smaller, the similarity threshold is smaller. For example, when determining whether vectors A, B, and C in the vector feature database are the second associated feature vectors, the dimension of the occurrence of the application behavior corresponding to vector A is a1, and the recognizability of the occurred behavior is a2. Based on a1 and a2, the similarity threshold x1 between the second target feature vector and vector A is determined. If the similarity between the second target feature vector and vector A is less than the similarity threshold x1 during the matching, then it can be determined that vector A is the second associated feature vector; the dimension of the occurrence of the application behavior corresponding to vector B is b1, and the recognizability of the occurred behavior is b2. Based on b1 and b2, the similarity threshold x2 between the second target feature vector and vector B is determined. If the similarity between the second target feature vector and vector B is less than the similarity threshold x2 during the matching, then it can be determined that vector B is the second associated feature vector; the dimension of the occurrence of the application behavior corresponding to vector C is c1, and the recognizability of the occurred behavior is c2. Based on c1 and c2, the similarity threshold x3 between the second target feature vector and vector C is determined. If the similarity between the second target feature vector and vector C is less than the similarity threshold x3 during the matching, then it can be determined that vector C is the second associated feature vector.

[0125] For more information on the dimensions of application behavior occurrence and the distinguishability of the occurred behavior, reference can be made to Figure 4 and its related descriptions.

[0126] In some embodiments of the present specification, by setting different application behavior occurrence dimensions to correspond to different similarity thresholds for the distinguishability of the occurred behavior, when matching based on the similarity threshold, the complexity brought by the application behavior occurrence dimension and the distinguishability of the occurred behavior can be considered, thereby making the determination of the application type and application behavior characteristics more accurate.

[0127] In some embodiments, the processor may determine the second associated feature data based on the decrypted encrypted stream corresponding to the second associated feature vector. For example, the processor may determine the multi-dimensional traffic characteristics and application behavior characteristics of the decrypted encrypted stream corresponding to the second associated feature vector as the second associated feature data.

[0128] In some embodiments, the second associated feature data is related to the encrypted streams of the same application type that have been decrypted within a preset time period. The processor may determine the second associated feature data based on the encrypted streams of the same application type as the decrypted encrypted stream corresponding to the second associated feature vector within the preset time period.

[0129] The preset time period refers to the time period during which encrypted streams of the same application type are obtained and decrypted. In some embodiments, the processor may set the preset time period, such as the most recent month, etc.

[0130] In some embodiments, the preset time period corresponding to different application types may be determined based on the application iteration rate corresponding to the application type. The application iteration rate may refer to the frequency of application version updates. In some embodiments, the faster the application iteration rate of the application type, the shorter the preset time period corresponding to the application type may be. For example, if the WeChat version is updated every half month, the preset time period corresponding to WeChat may be half a month; if the Baidu Cloud Disk version is updated once a month, the preset time period corresponding to Baidu Cloud Disk may be one month.

[0131] In some embodiments, the processor may determine the application behavior characteristic with the largest proportion in the second associated feature data as the application behavior characteristic of the encrypted stream to be analyzed.

[0132] In some embodiments of this specification, for applications of application type A with a high update frequency and rapid iteration, for application type A, the second associated feature data can be determined based on data within a relatively short preset time period (such as the most recent week). For applications of application type B with a low update frequency and slow iteration, for application type B, the second associated feature data can be determined based on data within a relatively long preset time period (such as the most recent month). This can reasonably determine the collection time of the second associated feature data and make the determined second associated feature data more accurate.

[0133] Some embodiments of this specification also provide an application analysis device based on an encrypted stream. The device includes at least one processor and at least one memory; the at least one memory is used to store computer instructions; the at least one processor is used to execute at least part of the computer instructions to implement the above-mentioned application analysis method based on an encrypted stream.

[0134] Some embodiments of this specification also provide a computer-readable storage medium that stores computer instructions, and when the computer instructions are executed by a processor, the above-mentioned application analysis method based on an encrypted stream is implemented.

[0135] The basic concepts have been described above. Obviously, for those skilled in the art, the above detailed disclosure is only an example and does not constitute a limitation to this specification. Although not explicitly stated here, those skilled in the art may make various modifications, improvements, and corrections to this specification. Such modifications, improvements, and corrections are proposed in this specification, so such modifications, improvements, and corrections still fall within the spirit and scope of the exemplary embodiments of this specification.

[0136] At the same time, this specification uses specific terms to describe the embodiments of this specification. Such as "one embodiment", "an embodiment", and / or "some embodiments" mean a certain feature, structure, or characteristic related to at least one embodiment of this specification. Therefore, it should be emphasized and noted that "an embodiment" or "one embodiment" or "an alternative embodiment" mentioned twice or more at different positions in this specification does not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of this specification can be appropriately combined.

[0137] In addition, unless clearly stated in the claims, the order of the processing elements and sequences, the use of numerical and alphabetical characters, or the use of other names described in this specification are not used to limit the order of the processes and methods in this specification. Although some currently useful embodiments of the invention are discussed through various examples in the above disclosure, it should be understood that such details are for illustrative purposes only. The appended claims are not limited to the disclosed embodiments. On the contrary, the claims are intended to cover all modifications and equivalent combinations that conform to the essence and scope of the embodiments of this specification. For example, although the system components described above can be implemented by hardware devices, they can also be implemented only through software solutions, such as installing the described system on existing servers or mobile devices.

[0138] Similarly, it should be noted that, in order to simplify the presentation of the disclosure in this specification and thus help the understanding of one or more embodiments of the invention, in the previous description of the embodiments of this specification, sometimes multiple features are merged into one embodiment, drawing, or description thereof. However, this method of disclosure does not mean that the features required by the subject matter of this specification are more than those mentioned in the claims. In fact, the features of the embodiments are fewer than all the features of the individual embodiments disclosed above.

[0139] In some embodiments, numbers are used to describe the components and the quantity of attributes. It should be understood that such numbers used to describe the embodiments are modified by the modifiers "about", "approximate" or "substantially" in some examples. Unless otherwise stated, "about", "approximate" or "substantially" indicate that the stated number allows a variation of ±20%. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, and such approximate values may change according to the characteristics required by individual embodiments. In some embodiments, the numerical parameters should consider the specified significant digits and adopt the method of retaining the general number of digits. Although the numerical ranges and parameters used to confirm the breadth of the scope in some embodiments of this specification are approximate values, in specific embodiments, the setting of such numerical values is as precise as possible within the feasible range.

[0140] For each patent, patent application, patent application publication, and other materials cited in this specification, such as articles, books, specifications, publications, documents, etc., their entire contents are hereby incorporated into this specification by reference. This excludes the application history documents that are inconsistent with or conflict with the content of this specification, and also excludes the documents that limit the broadest scope of the claims of this specification (currently or subsequently appended to this specification). It should be noted that if there are inconsistencies or conflicts between the descriptions, definitions, and / or uses of terms in the supplementary materials of this specification and the content described in this specification, the descriptions, definitions, and / or uses of terms in this specification shall prevail.

[0141] Finally, it should be understood that the embodiments described in this specification are only used to illustrate the principles of the embodiments of this specification. Other variations may also fall within the scope of this specification. Therefore, by way of example and not limitation, alternative configurations of the embodiments of this specification may be regarded as consistent with the teachings of this specification. Accordingly, the embodiments of this specification are not limited to the embodiments explicitly presented and described in this specification.

Claims

1. An application analysis method based on an encrypted stream, characterized in that, The method is executed by a processor, and the method includes: Obtaining an encrypted stream to be analyzed; Based on the encrypted stream to be analyzed, determining multi-dimensional traffic characteristics; the multi-dimensional traffic characteristics refer to characteristics in multiple dimensions that can be used to analyze the encrypted stream to be analyzed; Based on an application analysis model, processing the multi-dimensional traffic characteristics and associated feature data to determine an application type and application behavior characteristics, where the application analysis model is a machine learning model, and the associated feature data is data associated with the encrypted stream to be analyzed.

2. The application analysis method based on an encrypted stream according to claim 1, wherein The multi-dimensional traffic characteristics include at least one or more of a flow dimension characteristic, a data packet dimension characteristic, a host dimension characteristic, and a session dimension characteristic. The flow dimension characteristic includes a flow duration, a flow arrival time interval, a flow size, and a flow rate. The data packet dimension characteristic includes a data packet size distribution, an interval time distribution of data packet arrivals, a data packet transmission efficiency, a service type distribution, and a protocol type distribution.

3. The application analysis method based on an encrypted stream according to claim 1, wherein, The application analysis model includes an embedding layer, a type analysis layer, and a behavior analysis layer; The input of the embedding layer includes the multi-dimensional traffic characteristics, and the output of the embedding layer includes an embedded feature vector; The input of the type analysis layer includes the embedded feature vector, and the output of the type analysis layer includes the application type; The input of the behavior analysis layer includes the application type, and the output of the behavior analysis layer includes the application behavior characteristics.

4. The application analysis method based on an encrypted stream according to claim 3, wherein The associated feature data includes first associated feature data and second associated feature data, The input of the type analysis layer further includes a reference application type distribution, where the reference application type distribution is a vector formed by statistically analyzing the distribution of the application type, and the reference application type distribution is determined based on the first associated feature data; The input of the behavior analysis layer further includes a reference application behavior distribution, where the reference application behavior distribution is a vector formed by statistically analyzing the distribution of application behavior characteristics, and the reference application behavior distribution is determined based on the second associated feature data.

5. The application analysis method based on an encrypted stream according to claim 4, wherein Determining the reference application behavior distribution based on the second associated feature data includes: Performing weighted processing on each group of data in the second associated feature data to obtain the reference application behavior distribution, where the weight of each group of data is related to the dimension in which the corresponding application behavior occurs and the distinguishability of the occurred behavior.

6. The application analysis method based on an encrypted stream according to claim 1, wherein The determining the application type and application behavior characteristics based on the multi-dimensional traffic characteristics includes: Based on the multi-dimensional traffic characteristics, determining a first target feature vector; Based on the first target feature vector, determining a first associated feature vector through a vector feature database; Based on the decrypted encrypted stream corresponding to the first associated feature vector, determining first associated feature data; Based on the first associated feature data, determining the application type; where the first associated feature data is related to the decrypted encrypted stream; Based on the multi-dimensional traffic characteristics and the application type, determining a second target feature vector; Based on the second target feature vector, determining a second associated feature vector through the vector feature database; Based on the decrypted encrypted stream corresponding to the second associated feature vector, determining second associated feature data; Determine the application behavior characteristics based on the second associated feature data; wherein, the second associated feature data is related to encrypted flows of the same application type that have been decrypted within a preset time period.

7. An application analysis system based on an encrypted stream, characterized in that, The system includes: An acquisition module, configured to acquire an encrypted flow to be analyzed; A first determination module, configured to determine multi-dimensional traffic characteristics based on the encrypted flow to be analyzed; the multi-dimensional traffic characteristics refer to characteristics in multiple dimensions that can be used to analyze the encrypted flow to be analyzed; A second determination module, configured to process the multi-dimensional traffic characteristics and associated feature data based on an application analysis model to determine the application type and application behavior characteristics, the application analysis model being a machine learning model, and the associated feature data being data associated with the encrypted flow to be analyzed.

8. The application analysis system based on an encrypted stream according to claim 7, wherein The multi-dimensional traffic characteristics at least include one or more of a flow dimension characteristic, a data packet dimension characteristic, a host dimension characteristic, and a session dimension characteristic. The flow dimension characteristic includes flow duration, flow arrival time interval, flow size, and flow rate. The data packet dimension characteristic includes data packet size distribution, data packet arrival interval time distribution, data packet transmission efficiency, service type distribution, and protocol type distribution.

9. The application analysis system based on an encrypted stream according to claim 7, wherein The application analysis model includes an embedding layer, a type analysis layer, and a behavior analysis layer; The input of the embedding layer includes the multi-dimensional traffic characteristics, and the output of the embedding layer includes an embedded feature vector; The input of the type analysis layer includes the embedded feature vector, and the output of the type analysis layer includes the application type; The input of the behavior analysis layer includes the application type, and the output of the behavior analysis layer includes the application behavior characteristics.

10. The application analysis system based on an encrypted stream according to claim 8, wherein The associated feature data includes first associated feature data and second associated feature data, The input of the type analysis layer further includes a reference application type distribution, which is a vector formed by statistically analyzing the distribution of the application type and is determined based on the first associated feature data; The input of the behavior analysis layer further includes a reference application behavior distribution, which is a vector formed by statistically analyzing the distribution of application behavior characteristics and is determined based on the second associated feature data.

Citation Information

Patent Citations

  • A Deep Learning-Based Method and System for Encrypted Traffic Detection

    CN113162908B