Encrypted traffic detection method and system based on NiN hybrid dense residual network
Through the encrypted traffic detection method based on NiN hybrid dense residual network, the problems of unstable accuracy and high missed rate of the encrypted traffic detection model in the prior art are solved, and efficient identification and classification of encrypted traffic data packets are realized.
Patent Information
- Application Number
- CN202510260611.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The existing encrypted traffic detection methods have shortcomings in feature selection and model robustness, resulting in unstable model accuracy and high missed reporting rates, making it difficult to adapt to malicious encrypted traffic recognition in different data sets.
The encrypted traffic detection method based on NiN hybrid dense residual network is adopted, and the deep-level features of encrypted traffic data packets are extracted through step-by-step learning of the multi-module network, and the robustness and adaptability of the model are improved.
It realizes efficient identification and detection of encrypted traffic data packets, reduces the missed rate and improves work efficiency, and can analyze and classify encrypted traffic more stably and accurately.
Smart Images

Figure CN120217078A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an encrypted traffic detection method and system based on a NiN hybrid dense residual network, and belongs to the technical field of traffic detection and recognition. Background Art
[0002] With the increasing attention to the communication security of users and enterprises on the Internet, in order to protect the security of user and enterprise communication information, encrypting the traffic generated during the communication process has become the mainstream security measure. Among many encryption protocols, the most widely used is HTTPS (Hypertext Transfer Protocol Secure), which uses SSL (Secure Sockets Layer) and TLS (Transport Layer Security) on the basis of the Hypertext Transfer Protocol (HTTP) to ensure secure transmission. After the ordinary Internet traffic is encrypted, although it protects the privacy and integrity of information to a certain extent, it also provides shelter for malicious behaviors on the network, enabling them to perform destructive behaviors more covertly. These encrypted malicious traffic behaviors based on the SSL / TLS protocol may steal user information, implant malicious advertisements, and communicate between botnets, causing great harm and incalculable losses to ordinary users, enterprises, national critical facilities, etc. Therefore, in such a background, the encrypted traffic detection method based on various modern computer technologies has always been one of the main research directions.
[0003] Traditional malicious traffic detection mainly focuses on the screening and analysis of plaintext information, and generally uses DPI-based detection technology to deeply detect data packets. However, for encrypted traffic, the DPI-based detection method basically fails and cannot directly extract plaintext information; currently, more are encrypted traffic recognition methods based on machine learning and deep learning. Among them, the encrypted traffic recognition based on machine learning mainly solves two problems: features and algorithms. For features, most studies extract protocol-independent or protocol-related features from data packets or sessions, sometimes combined with manually selected features; for algorithms, traditional machine learning recognition methods can be divided into malicious encrypted traffic recognition algorithms based on supervised learning and unsupervised learning. Although the malicious encrypted traffic recognition method based on traditional machine learning algorithms has achieved many results, this method is restricted by the selection of features, and now more research focuses on deep learning algorithms with powerful representation ability and feature mining ability. The deficiencies of existing malicious encrypted traffic recognition methods are summarized as follows:
[0004] (1) Due to the limitations of manually selected features, many hidden features in encrypted traffic cannot be well mined, resulting in unstable model accuracy and a relatively high false negative rate.
[0005] (2) For networks with a large amount of unknown and new malicious encrypted traffic, the robustness and adaptability of existing models are poor and cannot well adapt to different data sets. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to provide an encrypted traffic detection method based on a NiN hybrid dense residual network, which is created based on an innovative classification network to improve the detection and recognition efficiency of encrypted traffic data packets.
[0007] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs an encrypted traffic detection method based on a NiN hybrid dense residual network, and performs the following steps A to B to obtain an encrypted traffic data packet recognition model; then performs step i, and applies the encrypted traffic data packet recognition model to identify and detect the encrypted traffic data packet to be analyzed.
[0008] Step A. Construct a preset number of sample encrypted traffic data packets corresponding to each preset traffic classification, and extract the preset target traffic feature values corresponding to each sample encrypted traffic data packet. Combine the target traffic feature values corresponding to a single sample encrypted traffic data packet with the traffic classification category corresponding to the sample encrypted traffic data packet to construct a sample, and then obtain a sample data set, and then enter step B.
[0009] Step B. Construct a NiN hybrid dense residual network, and based on the sample data set, use the target traffic feature values corresponding to the sample encrypted traffic data packets in the sample as inputs and the traffic classification categories corresponding to the sample encrypted traffic data packets as outputs to train the NiN hybrid dense residual network to obtain an encrypted traffic data packet recognition model.
[0010] Step i. Extract the target traffic feature values corresponding to the encrypted traffic data packet to be analyzed, input them into the encrypted traffic data packet recognition model for processing, and obtain the traffic classification category corresponding to the encrypted traffic data packet to be analyzed, so as to realize the identification and detection of the encrypted traffic data packet to be analyzed.
[0011] As a preferred technical solution of the present invention: in the step B, the NiN hybrid dense residual network includes a feature input module, a first NiN module, a first residual series structure, a first max pooling layer, a second NiN module, a dense series structure, a transition module, a second max pooling layer, a third NiN module, a second residual module, a global average pooling layer, a fully connected layer, and a classification output module, which are sequentially connected in series from the input end to the output end; the input end of the feature input module constitutes the input end of the NiN hybrid dense residual network, and the output end of the classification output module constitutes the output end of the NiN hybrid dense residual network. The first residual series structure includes at least one first residual module sequentially connected in series from the input end to the output end. The input end of the first first residual module in sequence constitutes the input end of the first residual series structure, and the output end of the last first residual module in sequence constitutes the output end of the first residual series structure. The dense series structure includes at least two dense modules sequentially connected in series from the input end to the output end. The input end of the first dense module in sequence constitutes the input end of the dense series structure, and the output end of the last dense module in sequence constitutes the output end of the dense series structure.
[0012] As a preferred technical solution of the present invention: the structures of the first NiN module, the second NiN module, and the third NiN module are the same as each other. Each NiN module respectively includes a 1×1 convolutional layer, a ReLU activation function layer, a 1×1 convolutional layer, and a ReLU activation function layer, which are sequentially connected in series from the input end to the output end. Among them, the input end of the first 1×1 convolutional layer in sequence constitutes the input end of the NiN module, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the NiN module.
[0013] As a preferred technical solution of the present invention: the structure of the second residual module and the structures of the first residual modules are the same as each other. Each residual module respectively includes a 3×3 convolutional layer, a batch normalization layer, a ReLU activation function layer, a 3×3 convolutional layer, a batch normalization layer, a fusion layer, and a ReLU activation function layer, which are sequentially connected in series from the input end to the output end. Among them, the input end of the first 3×3 convolutional layer in sequence constitutes the input end of the residual module, the input end of the fusion layer is connected to the input end of the residual module at the same time, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the residual module.
[0014] As a preferred technical solution of the present invention: the structures of each dense module are the same as each other. Each dense module respectively includes four convolution normalization activation modules connected in series in the direction from the input end to the output end. The input end of the first convolution normalization activation module in sequence constitutes the input end of the dense module, and the output end of the fourth convolution normalization activation module in sequence constitutes the output end of the dense module. The structures of each convolution normalization activation module are the same as each other. Each convolution normalization activation module respectively includes a 3×3 convolution layer, a batch normalization layer, a ReLU activation function layer, and a splicing layer connected in series in the direction from the input end to the output end. Among them, the input end of the 3×3 convolution layer constitutes the input end of the convolution normalization activation module, and the output end of the splicing layer constitutes the output end of the convolution normalization activation module. The input ends of the splicing layers in each convolution normalization activation module are respectively further connected to the input end of the dense module and the output ends of the previous convolution normalization activation modules in sequence.
[0015] As a preferred technical solution of the present invention: the transition module includes a 1×1 convolution layer, a batch normalization layer, a ReLU activation function layer, and an average pooling layer connected in series in the direction from the input end to the output end. Among them, the input end of the 1×1 convolution layer constitutes the input end of the transition module, and the output end of the average pooling layer constitutes the output end of the transition module.
[0016] As a preferred technical solution of the present invention: the preset target traffic characteristic values include traffic data packet duration, number of forward / backward data packets, statistical characteristics of data packet length, number of bytes and data packets of traffic per second, statistical quantity of traffic arrival time interval, and TCP flag bits.
[0017] As a preferred technical solution of the present invention: the sample encrypted traffic data packets and the encrypted traffic data packets to be analyzed are respectively obtained from the original traffic data packets according to the following steps a to c;
[0018] Step a. Traffic data segmentation: According to the traffic five-tuple information of the source IP, destination IP, source port, destination port, and protocol type corresponding to the traffic, each encrypted traffic in the original traffic data packets is divided to obtain each primary encrypted traffic.
[0019] Step b. Traffic data duplicate removal and filtering: Each primary encrypted traffic is screened to obtain each primary encrypted traffic corresponding to the preset target types of encryption protocols, and each intermediate encrypted traffic is formed.
[0020] Step c. Traffic data recombination: According to the traffic five-tuple information and time stamps, each intermediate encrypted traffic belonging to the same traffic session is recombined to form encrypted traffic data packets.
[0021] Corresponding to the above, the technical problem to be solved by the present invention is to provide a system for encrypted traffic detection method based on NiN hybrid dense residual network, create and design each module based on innovative classification network, and efficiently complete model training and recognition detection.
[0022] In order to solve the above technical problems, the present invention adopts the following technical solutions: the present invention designs a system of an encrypted traffic detection method based on a NiN hybrid dense residual network, including an encrypted traffic feature extraction module, a model training module, and a model prediction and classification module. The encrypted traffic feature extraction module is used to read, parse, and extract features from sample encrypted traffic data packets and encrypted traffic data packets to be analyzed, respectively, to obtain preset target traffic feature values corresponding to the encrypted traffic data packets, and preset target traffic feature values corresponding to the encrypted traffic data packets to be analyzed;
[0023] The model training module is based on the sample data set, with the target traffic feature values corresponding to the sample encrypted traffic data packets in the sample as input and the traffic classification categories corresponding to the sample encrypted traffic data packets as output. Combined with the cross entropy loss function, the NiN hybrid dense residual network is trained to obtain the encrypted traffic data packet recognition model;
[0024] The model prediction and classification module is used to apply the encrypted traffic data packet recognition model to process the preset target traffic characteristic values corresponding to the encrypted traffic data packets to be analyzed, obtain the traffic classification category corresponding to the encrypted traffic data packets to be analyzed, and realize the identification and detection of the encrypted traffic data packets to be analyzed.
[0025] The encrypted traffic detection method and system based on the NiN hybrid dense residual network of the present invention adopts the above technical solution and has the following technical effects compared with the prior art:
[0026] (1) The encrypted traffic detection method based on the NiN hybrid dense residual network designed by the present invention is an innovative design of the NiN hybrid dense residual network integrating the NiN module, the residual module and the dense module. Based on the sample data set, the target traffic feature values corresponding to the encrypted traffic data packets are used as the analysis objects. The NiN hybrid dense residual network is trained to obtain an encrypted traffic data packet recognition model, and then the encrypted traffic data packets to be analyzed are recognized and detected. The present invention also designs a corresponding system, designs corresponding modules from feature extraction, network training, and prediction and classification, and efficiently realizes the recognition and detection of encrypted traffic data packets. The NiN hybrid dense residual network designed by the present invention adopts the step-by-step learning of multi-module networks, has higher model robustness and lower model underreporting rate, can mine deeper features in encrypted traffic data, realize efficient and stable data analysis and classification, and improve the work efficiency of encrypted traffic recognition and detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a schematic structural diagram of the NiN hybrid dense residual network in the design of the present invention;
[0028] Figure 2 It is a schematic system diagram of the encrypted traffic detection method based on the NiN hybrid dense residual network in the design of the present invention;
[0029] Figure 3 It is a preprocessing flow chart of the original traffic data packet in the design of the present invention;
[0030] Figure 4 It is a data processing flow chart before network training in the application implementation of the design of the present invention;
[0031] Figure 5 It is a classification flow chart of the encrypted traffic data packet to be analyzed in the application implementation of the design of the present invention. Specific implementation manner
[0032] The following further elaborates on the specific implementation manner of the present invention in conjunction with the accompanying drawings of the specification.
[0033] In the actual application of the encrypted traffic detection method based on the NiN hybrid dense residual network designed by the present invention, the following steps A to B are executed to obtain an encrypted traffic data packet recognition model.
[0034] Step A. Construct various sample encrypted traffic data packets corresponding to a preset number for each preset traffic classification, and extract the preset target traffic feature values corresponding to each sample encrypted traffic data packet. Using the target traffic feature values corresponding to a single sample encrypted traffic data packet and combining the traffic classification category corresponding to this sample encrypted traffic data packet, construct samples, and then obtain a sample data set, and then enter step B.
[0035] In practical applications, since the data is encrypted traffic and there is basically no obvious plaintext information in the encrypted traffic, the present invention designs to adopt partial statistical features of the traffic. These statistical features have nothing to do with the core information of the data and are just a kind of feature statistical work in terms of time or space. That is, various target traffic feature values are preset here, such as flow packet duration (Flow Duration), number of forward / backward packets (Total Fwd / Backward Packets), statistical features of packet length (Max, Min, Mean, Std of Packet Length), number of bytes and packets per second of traffic (Flow Bytes / s, Flow Packets / s), statistical quantity of flow arrival time interval (Flow IAT Mean, Std, Max, Min), TCP flag bits (such as FIN, SYN, ACK, etc.). Through these features, the model can capture different feature patterns of the encrypted traffic, thereby providing richer information for the subsequent classification model.
[0036] Step B. Construct a NiN hybrid dense residual network, and based on the sample data set, use the respective target traffic feature values corresponding to the sample encrypted traffic packets in the sample as the input and the traffic classification category corresponding to the sample encrypted traffic packets as the output to train the NiN hybrid dense residual network to obtain an encrypted traffic packet recognition model.
[0037] In practical applications, as Figure 1 shown, constructing a NiN hybrid dense residual network includes a feature input module, a first NiN module, a first residual series structure, a first max pooling layer, a second NiN module, a dense series structure, a transition module, a second max pooling layer, a third NiN module, a second residual module, a global average pooling layer, a fully connected layer, and a classification output module connected in series in sequence from the input end to the output end; the input end of the feature input module constitutes the input end of the NiN hybrid dense residual network, and the output end of the classification output module constitutes the output end of the NiN hybrid dense residual network. The first residual series structure includes at least one first residual module connected in series in sequence from the input end to the output end. The input end of the first first residual module in sequence constitutes the input end of the first residual series structure, and the output end of the last first residual module in sequence constitutes the output end of the first residual series structure. The dense series structure includes at least two dense modules connected in series in sequence from the input end to the output end. The input end of the first dense module in sequence constitutes the input end of the dense series structure, and the output end of the last dense module in sequence constitutes the output end of the dense series structure.
[0038] Among them, the structures of the first NiN module, the second NiN module, and the third NiN module are the same as each other. Each NiN module respectively includes a 1×1 convolutional layer, a ReLU activation function layer, a 1×1 convolutional layer, and a ReLU activation function layer that are sequentially connected in series from the input end to the output end. Among them, the input end of the first 1×1 convolutional layer in sequence constitutes the input end of the NiN module, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the NiN module.
[0039] The structures of the second residual module and the structures of each first residual module are the same as each other. Each residual module respectively includes a 3×3 convolutional layer, a batch normalization layer, a ReLU activation function layer, a 3×3 convolutional layer, a batch normalization layer, a fusion layer, and a ReLU activation function layer that are sequentially connected in series from the input end to the output end. Among them, the input end of the first 3×3 convolutional layer in sequence constitutes the input end of the residual module, the input end of the fusion layer is simultaneously connected to the input end of the residual module, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the residual module.
[0040] The structures of each dense module are the same as each other. Each dense module respectively includes four convolutional normalization activation modules that are sequentially connected in series from the input end to the output end. The input end of the first convolutional normalization activation module in sequence constitutes the input end of the dense module, and the output end of the fourth convolutional normalization activation module in sequence constitutes the output end of the dense module. The structures of each convolutional normalization activation module are the same as each other. Each convolutional normalization activation module respectively includes a 3×3 convolutional layer, a batch normalization layer, a ReLU activation function layer, and a concatenation layer that are sequentially connected in series from the input end to the output end. Among them, the input end of the 3×3 convolutional layer constitutes the input end of the convolutional normalization activation module, and the output end of the concatenation layer constitutes the output end of the convolutional normalization activation module. The input ends of the concatenation layers in each convolutional normalization activation module are respectively further connected to the input end of the dense module and the output ends of the previous convolutional normalization activation modules in sequence.
[0041] The transition module includes a 1×1 convolutional layer, a batch normalization layer, a ReLU activation function layer, and an average pooling layer that are sequentially connected in series from the input end to the output end. Among them, the input end of the 1×1 convolutional layer constitutes the input end of the transition module, and the output end of the average pooling layer constitutes the output end of the transition module.
[0042] In the sequential analysis and processing of the target traffic feature values corresponding to the encrypted traffic data packets by the above-mentioned NiN hybrid dense-residual network, the feature input module, as the input of the NiN hybrid dense-residual network, receives the target traffic feature values corresponding to the encrypted traffic data packets. In the design of the present invention, it is assumed that the dimension of the input feature quantity is x. The input data is batch-fed into the feature input module, and the shape of the data for each batch is [batch_size, x]. Traffic features usually include multiple numerical attributes, which are used to describe each encrypted traffic data packet. The main task of the feature input module is to format these features into a format that can be processed by subsequent layers. In applications, it can be represented by a formula. Assuming that the dimension of the input feature quantity is x, the input data is expressed as X ∈ R^{N×x}, where N is the number of samples and x is the dimension of the feature quantity.
[0043] The first NiN module uses 1×1 convolution operations to map the dimension of the input data from x features to 128 channels. This process is completed by two layers of 1×1 convolutions. After convolution, the ReLU activation function is applied. The role of the NiN module is to improve the expressive ability of features through local linear combinations, and at the same time introduce non-linearity to generate more complex and high-dimensional feature maps, providing rich information for subsequent layers. In applications, it can be represented by a formula as the input is X_in ∈ R^{N×x} and the output is X_out ∈ R^{N×128}, that is, mapping the input features from 70 to 128.
[0044] In the application of the first NiN module, the convolution operation: X out = ReLU(W * X in + b), where W ∈ R^{128×x} is the convolution kernel, b is the bias term, and * represents the convolution operation. In applications, the designed NiN module includes two layers of 1×1 convolutional layers, and the weight matrices of the first layer and the second layer are a1 ∈ R^{128×x} and a2 ∈ R^{128×128} respectively.
[0045] The first residual concatenation structure specifically uses two consecutive first residual modules, and both adopt two layers of convolution operations with a convolution kernel size of 3×3, and there are batch normalization layers and ReLU activation function layers after each layer. In the first residual module, it is designed that the input is directly added to the output (skip connection) to prevent the problem of gradient disappearance and keep information flowing in the deep network. Through the introduction of the first residual concatenation structure, even when the number of layers increases, the network can still be effectively trained. The batch normalization layer can help accelerate the training process and improve stability.
[0046] In the application of the first residual concatenation structure, the residual operation is expressed as: Y1 = ReLU(W1 * X + b1), Y2 = W2 * Y1 + b2; the residual connection is expressed as: Y out= X + Y2; where W1 and W2 are convolutional kernels, X is the input feature, Y1 is the feature after the first convolution, Y2 is the feature after the second convolution, b1 and b2 are bias terms, the number of input channels is 128, and the number of output channels remains unchanged at 128.
[0047] The first max pooling layer reduces the dimension of the feature map by extracting the maximum value in the local area. The size of the pooling window is set to 2, so that the feature channels remain unchanged while reducing the spatial dimension of the features. The pooling operation can reduce the computational amount while retaining the most important feature information and enhancing the robustness of the model.
[0048] In the application of the first max pooling layer, the pooling operation is expressed as: X out = max(X in (i:i+2)), where i is the pooling window index, X in is the input feature, and the number of input and output channels is 128. The pooling operation only changes the feature dimension.
[0049] The second NiN module uses a 1×1 convolution again to increase the number of channels from 128 to 256, which means that the feature dimension continues to be increased, providing more feature expression space. By increasing the number of channels, the model can capture more different levels of features and prepare a more complex feature map for the subsequent dense blocks. In the application of the second NiN module, the convolution operation is expressed as: X out = ReLU(W * X in + b), where W ∈ R^{256×128}.
[0050] The dense concatenation structure uses three consecutive dense modules with the same structure to ensure that deeper features in the data can be learned. Each dense module consists of multiple layers of convolutions. The input of each layer is the result of concatenating the outputs of all previous layers. The dense module introduces a deep connection mechanism, so that the input of each layer contains not only the output of the previous layer, but also the outputs of all previous layers. The dense connection enhances the flow of information, effectively solves the problem of gradient disappearance, and at the same time improves the feature reuse rate. Here, each dense module has 4 layers, and each layer outputs 64 features. Finally, the number of channels of the feature map output by the dense concatenation structure is T out = T in + 4×64 + 4×64 + 4×64 = 1024, that is, after passing through the dense concatenation structure, the number of feature channels is expanded to 1024, where T in is the number of input channels. In the application, the dense operation is expressed as: Y l = ReLU(W l * Concatenate(X0,X1,...,X l-1 ) + b l )), where W lis the convolutional kernel of the l-th layer, X l is the output of the l-th layer, b l is the corresponding bias term.
[0051] The transition module reduces the number of channels and the size of the feature map through 1×1 convolution and average pooling. The transition block reduces the number of channels from 1024 to 512 and reduces the spatial dimension through average pooling. The role of the transition block is to control the computational complexity of the model while maintaining the efficient flow of feature information. In the application, the transition operation is expressed as: X out = AvgPooling(ReLU(W*X in +b)), where W ∈ R^{512×1024}.
[0052] The second max pooling layer is the same as the first max pooling layer, using a pooling window size of 2. Pooling further reduces the spatial dimension of the features, helps reduce the computational cost, and enhances the feature abstraction ability. The pooling operation is expressed as: X out = max(X in (i:i+2)), where i is the pooling window index, X in is the input feature, and the number of input and output channels is 512. The pooling operation only changes the feature dimension.
[0053] The third NiN module increases the number of channels from 512 to 1024 through 1×1 convolution. This design further improves the feature expression ability of the network, allowing the model to extract more rich high-dimensional features. Increasing the number of channels is to capture more complex patterns and relationships in the deeper layers of the model. In the application, the convolution operation is expressed as: X out = ReLU(W*X in +b), where W ∈ R^{1024×512}.
[0054] The second residual module contains two convolutional layers, each followed by a batch normalization layer and a ReLU activation function layer. The input is directly passed to the output through a skip connection. The second residual module is used to further capture deep features while maintaining the gradient flow through the residual connection. In the application, the operation of the second residual module is expressed as: Y out = X + W2*ReLU(W1*X + b1) + b2, where W1 and W2 are convolutional kernels, X is the input feature, and Y out is the output feature.
[0055] The global average pooling layer takes the average value of each feature channel, and finally generates a feature vector of size [batch_size, 1024]. Through the global average pooling operation, the model can significantly reduce the number of parameters, avoid overfitting, and provide a compact feature representation for the classification task. In the application, the global average pooling operation is expressed as: Among them, T is the characteristic length, j is the channel index, the number of input channels is 1024, and the number of output channels remains 1024.
[0056] The fully connected layer maps the features to Y categories (the number of target classifications) through a linear transformation. After the fully connected layer, the softmax activation function is used to output the probability of each category. The fully connected layer is used for the final classification decision, mapping the features to the probability distribution of the output labels. In the application, the fully connected operation is expressed as: Z = Softmax(W fc *X + b fc ), where W fc ∈R^{1024×15} is the weight matrix, and b fc is the bias term.
[0057] The classification output module uses the softmax activation function to convert the output of the model into the probability of each category, and finally makes a prediction based on the category with the highest probability. This module provides the final classification result of the input data, outputting the prediction of each traffic sample belonging to a certain category. In the application, the output prediction is expressed as: where Z is the output of the fully connected layer, is the predicted label.
[0058] During the training process of the NiN hybrid dense-residual network in the above step B, as Figure 4 shown, it mainly includes the following key steps: data cleaning, data standardization and normalization, data labeling, data segmentation, and model training. After these steps, the training of the NiN hybrid dense-residual network can be completed, and an encrypted traffic packet recognition model can be obtained.
[0059] During the data cleaning process, there are mainly three steps, namely dealing with default values, removing duplicate data, and outlier processing. Some traffic may cause data loss due to reasons such as interruption during the packet capture process. At this time, missing feature values need to be processed, such as filling or deletion. Some data packets may be recorded repeatedly, and duplicate data packets or traffic need to be cleared during the preprocessing process, and outliers need to be detected and processed. It is also necessary to ensure the rationality of the feature data.
[0060] In the steps of data standardization and normalization, the mean of each feature is made 0 and the standard deviation is 1 to eliminate the influence of the dimension between different features, making it easier for the model to learn; during the normalization process, the feature values are mapped to the range of [-1, 1] to make different features have the same scale and improve the performance of the algorithm.
[0061] In the data labeling step, that is, initially select the encrypted traffic data packets of each sample corresponding to the preset traffic classifications, that is, the classification labeling here, and mark the nature of its traffic.
[0062] In the data splitting step, the dataset is divided into a training set and a test set at a ratio of 8:2. The former is for the training of the model, and the latter is for the verification and testing of the model.
[0063] During the process of model training, by presetting the training parameters, the NiN hybrid dense residual network is trained, so that the model converges after a certain number of training rounds, and the trained model is saved.
[0064] In the model prediction and model verification steps, the previously divided test dataset is used to test and verify the effectiveness of the model, and the accuracy rate, false alarm rate, miss rate, etc. of the model are recorded, and a test report is generated.
[0065] According to the above steps A to B, an encrypted traffic packet identification model is obtained. In further actual implementation, the following step i is executed. The encrypted traffic packet identification model is applied to identify and detect the encrypted traffic packet to be analyzed.
[0066] Step i. Extract the respective target traffic feature values corresponding to the encrypted traffic packet to be analyzed, input them into the encrypted traffic packet identification model for processing, and obtain the traffic classification category corresponding to the encrypted traffic packet to be analyzed, so as to realize the identification and detection of the encrypted traffic packet to be analyzed.
[0067] In the specific execution of step i, as Figure 5 shown, it mainly includes the following key steps: reading the encrypted traffic packet to be analyzed, loading the model, and predicting and classifying the model. After these steps, the prediction and classification of the encrypted traffic packet to be analyzed can be completed.
[0068] First, read the encrypted traffic packet to be analyzed, and apply the encrypted traffic feature extraction module to further perform traffic reading, traffic parsing, and traffic feature extraction on the encrypted traffic packet to be analyzed, so as to obtain the respective preset target traffic feature values corresponding to the encrypted traffic packet to be analyzed, which are used as the input of the encrypted traffic packet identification model.
[0069] Then, use the encrypted traffic packet identification model to receive the input of the respective preset target traffic feature values corresponding to the encrypted traffic packet to be analyzed, predict and output the class prediction probability of each encrypted traffic packet to be analyzed through the encrypted traffic packet identification model, select the prediction class with the highest probability for the classification of the encrypted traffic packet to be analyzed, save the record in the classification document, and finally complete the output of the classification report. Thus, the encrypted traffic classification work is completed.
[0070] In actual application, in order to implement the application of the above-designed encrypted traffic detection method, a corresponding system is further designed, as Figure 2As shown in the figure, it includes an encrypted traffic feature extraction module, a model training module, and a model prediction and classification module. Among them, the encrypted traffic feature extraction module is responsible for extracting various preset target traffic feature values from encrypted traffic data packets for subsequent model training and prediction. In the application, the encrypted traffic feature extraction module is used to perform traffic reading, traffic parsing, and traffic feature extraction on the sample encrypted traffic data packets and the encrypted traffic data packets to be analyzed respectively, so as to obtain various preset target traffic feature values corresponding to the encrypted traffic data packets and various preset target traffic feature values corresponding to the encrypted traffic data packets to be analyzed, that is, the flow duration of the data packet (Flow Duration), the number of forward / backward data packets (Total Fwd / Backward Packets), the statistical features of the data packet length (Max, Min, Mean, Std of Packet Length), the number of bytes and data packets per second of the traffic (Flow Bytes / s, Flow Packets / s), the statistical quantity of the traffic arrival time interval (Flow IAT Mean, Std, Max, Min), and TCP flag bits (such as FIN, SYN, ACK, etc.).
[0071] In the actual application of the encrypted traffic feature extraction module, the process of feature extraction can be described by the formula: X i =[f1(x i ), f2(x i ),..., f n (x i )], where X i represents the i-th encrypted traffic data packet, and f1(x i ), f2(x i ),..., f n (x i ) respectively represent the features extracted from the encrypted traffic data packet, and the feature dimension n depends on the specific extraction rules.
[0072] Based on the sample data set, the model training module uses the various target traffic feature values corresponding to the sample encrypted traffic data packets in the sample as the input and the traffic classification category corresponding to the sample encrypted traffic data packets as the output, and combines the cross-entropy loss function to train the NiN hybrid dense residual network to obtain an encrypted traffic data packet recognition model.
[0073] In practical applications, the design model training module performs operations including data normalization and standardization, dataset splitting, setting training parameters, and model training. Among them, the purpose of data standardization is to make the mean of each feature equal to 0 and the standard deviation equal to 1, which can eliminate the influence of the dimension of different features and make it easier for the model to learn. The purpose of normalization is to map the feature values to a specified range. Here, the feature range of [-1, 1] is used, which can make different features have the same scale and help improve the performance of the algorithm.
[0074] Set the dataset splitting ratio according to the general training and learning ratio, i.e., training set: test set = 8:2. The training parameters can be set according to specific requirements, including the number of training epochs, learning rate, etc. The training process uses the cross-entropy loss function and an optimization algorithm for gradient descent and weight update: where L is the loss function, y is the true label, is the predicted value, and C is the total number of classification categories.
[0075] The model prediction and classification module uses the trained encrypted traffic packet identification model to identify and classify the preset target traffic feature values corresponding to new encrypted traffic packets to be analyzed, mainly including reading the encrypted traffic packets to be analyzed and classifying and outputting the encrypted traffic packets to be analyzed. The classification output module in the encrypted traffic packet identification model is responsible for traffic classification according to the model prediction results, and dividing the encrypted traffic packets to be analyzed into different categories (such as normal traffic, attack traffic, etc.). Among them, the processing flow: by comparing the probability values, determine the category corresponding to the maximum probability: Output: the final encrypted traffic classification result, such as the attack type (DoS, DDoS, etc.) or normal traffic. At the same time, this module can also record the classification results and generate classification reports for convenient subsequent network security analysis work.
[0076] Applying the designed encrypted traffic detection method of the present invention to practice, the sample encrypted traffic packets and the encrypted traffic packets to be analyzed involved are obtained from the original traffic packets respectively according to the following steps a to c, as Figure 3 shown.
[0077] Step a. Traffic data splitting. According to the traffic five-tuple information of the source IP, destination IP, source port, destination port, and protocol type corresponding to the traffic, each encrypted traffic in the original traffic packets is divided to obtain each primary encrypted traffic. In specific implementation, the traffic can also be divided according to the time window, and the encrypted traffic within a certain time range is regarded as a flow. In this way, the long-time original traffic packets can be split into smaller independent flows for subsequent processing.
[0078] Step b. Deduplication and filtering of traffic data, screening of each primary encrypted traffic, obtaining each primary encrypted traffic corresponding to each preset target type encryption protocol, forming each intermediate encrypted traffic; in specific applications, firstly, it is necessary to remove some irrelevant traffic, such as filtering out broadcast traffic, multicast traffic, and other network packets irrelevant to encrypted traffic analysis (such as IPv6, ARP packets, etc.), and then extracting the traffic of a specific protocol, that is, each primary encrypted traffic that meets the target type encryption protocol. For the encrypted traffic analysis designed for the present invention, usually only the traffic of a specific encryption protocol (such as TLS, SSH, IPSec, etc.) is retained, and non-encrypted traffic data is filtered out.
[0079] Step c. Traffic data reorganization: According to the traffic quintuple information and timestamp, the intermediate encrypted traffic belonging to the same traffic session is reorganized to form a complete traffic session and an encrypted traffic data packet. In specific applications, for TCP traffic, ensure that each encrypted traffic data packet is reorganized in sequence; at the same time, it can further distinguish between forward encrypted traffic data packets (client-to-server) and backward encrypted traffic data packets (server-to-client), and can also process bidirectional traffic separately as needed.
[0080] After determining each encrypted traffic data packet in the above manner, the encrypted traffic feature extraction module can be applied to further perform traffic reading, traffic parsing, and traffic feature extraction on the sample encrypted traffic data packets and the encrypted traffic data packets to be analyzed, and obtain the preset target traffic feature values corresponding to the encrypted traffic data packets.
[0081] The encrypted traffic detection method designed by the present invention innovatively designs a NiN hybrid dense residual network that integrates NiN modules, residual modules, and dense modules. Based on a sample data set, the target traffic feature values corresponding to the encrypted traffic data packets are used as analysis objects. The NiN hybrid dense residual network is trained to obtain an encrypted traffic data packet recognition model, and then the encrypted traffic data packets to be analyzed are identified and detected. The present invention also designs a corresponding system, designs corresponding modules from feature extraction, network training, and prediction and classification, and efficiently realizes the identification and detection of encrypted traffic data packets. The NiN hybrid dense residual network designed by the present invention adopts step-by-step learning of multi-module networks, has higher model robustness and lower model underreporting rate, can mine deeper features in encrypted traffic data, realize efficient and stable data analysis and classification, and improve the work efficiency of encrypted traffic identification and detection.
[0082] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments, and various changes can be made within the knowledge scope of ordinary technicians in this field without departing from the purpose of the present invention.
Claims
1. The encrypted traffic detection method based on NiN hybrid dense residual network is characterized by: Execute the following steps A to B to obtain an encrypted traffic data packet identification model; then execute step i to apply the encrypted traffic data packet identification model to identify and detect the encrypted traffic data packet to be analyzed; Step A. Construct a preset number of sample encrypted traffic data packets corresponding to preset traffic classifications, and extract the preset target traffic feature values corresponding to each sample encrypted traffic data packet, respectively, and construct a sample with the target traffic feature values corresponding to a single sample encrypted traffic data packet and the traffic classification category corresponding to the sample encrypted traffic data packet, thereby obtaining a sample data set, and then proceeding to step B; Step B. Construct a NiN hybrid dense residual network, and based on the sample data set, take the target traffic feature values corresponding to the sample encrypted traffic data packets in the sample as input and the traffic classification category corresponding to the sample encrypted traffic data packets as output, train the NiN hybrid dense residual network, and obtain an encrypted traffic data packet recognition model; Step i. Extract the target traffic feature values corresponding to the encrypted traffic data packets to be analyzed, input them into the encrypted traffic data packet recognition model for processing, obtain the traffic classification category corresponding to the encrypted traffic data packets to be analyzed, and realize the recognition and detection of the encrypted traffic data packets to be analyzed.
2. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 1 is characterized in that: In the step B, the NiN hybrid dense residual network includes a feature input module, a first NiN module, a first residual series structure, a first maximum pooling layer, a second NiN module, a dense series structure, a transition module, a second maximum pooling layer, a third NiN module, a second residual module, a global average pooling layer, a fully connected layer, and a classification output module, which are sequentially connected in series from the input end to the output end; the input end of the feature input module constitutes the input end of the NiN hybrid dense residual network, the output end of the classification output module constitutes the output end of the NiN hybrid dense residual network, the first residual series structure includes at least one first residual module sequentially connected in series from the input end to the output end, the input end of the first first residual module in sequence constitutes the input end of the first residual series structure, and the output end of the last first residual module in sequence constitutes the output end of the first residual series structure, and the dense series structure includes at least two dense modules sequentially connected in series from the input end to the output end, the input end of the first dense module in sequence constitutes the input end of the dense series structure, and the output end of the last dense module in sequence constitutes the output end of the dense series structure.
3. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 2 is characterized in that: The structures of the first NiN module, the second NiN module and the third NiN module are the same. Each NiN module includes a 1×1 convolution layer, a ReLU activation function layer, a 1×1 convolution layer and a ReLU activation function layer connected in series from the input end to the output end, wherein the input end of the first 1×1 convolution layer in sequence constitutes the input end of the NiN module, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the NiN module.
4. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 2 is characterized in that: The structure of the second residual module and the structures of each first residual module are the same as each other. Each residual module includes a 3×3 convolution layer, a batch normalization layer, a ReLU activation function layer, a 3×3 convolution layer, a batch normalization layer, a fusion layer, and a ReLU activation function layer connected in series from the input end to the output end, wherein the input end of the first 3×3 convolution layer in sequence constitutes the input end of the residual module, the input end of the fusion layer is also connected to the input end of the residual module, and the output end of the last ReLU activation function layer in sequence constitutes the output end of the residual module.
5. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 2 is characterized in that: The structures of each dense module are the same as each other. Each dense module includes four convolutional normalization activation modules connected in series from the input end to the output end. The input end of the first convolutional normalization activation module in sequence constitutes the input end of the dense module, and the output end of the fourth convolutional normalization activation module in sequence constitutes the output end of the dense module. The structures of each convolutional normalization activation module are the same as each other. Each convolutional normalization activation module includes a 3×3 convolutional layer, a batch normalization layer, a ReLU activation function layer, and a splicing layer connected in series from the input end to the output end. Among them, the input end of the 3×3 convolutional layer constitutes the input end of the convolutional normalization activation module, and the output end of the splicing layer constitutes the output end of the convolutional normalization activation module. The input end of the splicing layer in each convolutional normalization activation module is also connected to the input end of the dense module and the output end of each preceding convolutional normalization activation module.
6. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 2 is characterized in that: The transition module includes a 1×1 convolution layer, a batch normalization layer, a ReLU activation function layer, and an average pooling layer which are connected in series from the input end to the output end. The input end of the 1×1 convolution layer constitutes the input end of the transition module, and the output end of the average pooling layer constitutes the output end of the transition module.
7. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 1 is characterized in that: The preset target traffic characteristic values include traffic packet duration, forward / backward data packet number, data packet length statistical characteristics, traffic bytes and data packets per second, traffic arrival time interval statistics, and TCP flag.
8. The encrypted traffic detection method based on NiN hybrid dense residual network according to claim 1 is characterized in that: The sample encrypted traffic data packet and the encrypted traffic data packet to be analyzed are obtained from the original traffic data packet according to the following steps a to c; Step a. Traffic data segmentation: according to the traffic five-tuple information corresponding to the source IP, destination IP, source port, destination port, and protocol type of the traffic, each encrypted traffic in the original traffic data packet is divided to obtain each primary encrypted traffic; Step b. Filter and de-duplicate the traffic data, screen each primary encrypted traffic, obtain each primary encrypted traffic corresponding to each preset target type encryption protocol, and constitute each intermediate encrypted traffic; Step c. Traffic data reorganization: according to the traffic five-tuple information and timestamp, various intermediate encrypted traffics belonging to the same traffic session are reorganized to form an encrypted traffic data packet.
9. A system for implementing the encrypted traffic detection method based on NiN hybrid dense residual network as described in any one of claims 1 to 8, characterized in that: It includes an encrypted traffic feature extraction module, a model training module, and a model prediction and classification module. The encrypted traffic feature extraction module is used to read, parse, and extract features from sample encrypted traffic data packets and encrypted traffic data packets to be analyzed, respectively, to obtain preset target traffic feature values corresponding to the encrypted traffic data packets, and preset target traffic feature values corresponding to the encrypted traffic data packets to be analyzed; The model training module is based on the sample data set, with the target traffic feature values corresponding to the sample encrypted traffic data packets in the sample as input and the traffic classification categories corresponding to the sample encrypted traffic data packets as output. Combined with the cross entropy loss function, the NiN hybrid dense residual network is trained to obtain the encrypted traffic data packet recognition model; The model prediction and classification module is used to apply the encrypted traffic data packet recognition model to process the preset target traffic characteristic values corresponding to the encrypted traffic data packets to be analyzed, obtain the traffic classification category corresponding to the encrypted traffic data packets to be analyzed, and realize the identification and detection of the encrypted traffic data packets to be analyzed.
Citation Information
Patent Citations
Storage file and network data flow encryption communication detection method and system
CN111507386A
Traffic image safety belt classification method based on deep learning
CN112836584A
Intrusion detection method and system based on multi-scale spatial-temporal feature residual fusion
CN117375896A
Method and apparatus for identifying network encrypted traffic
WO2022041394A1