Self-adaptive VPN (Virtual Private Network) traffic classification system and method

Through the adaptive VPN traffic classification system, the pre-trained model is optimized using the fine-tuned data set, the problem of insufficient generalization capabilities in VPN traffic classification is solved, and higher classification accuracy and adaptability are achieved.

CN120256964APending Publication Date: 2025-07-04DALIAN NEUSOFT UNIV OF INFORMATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510394061.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing VPN traffic classification method uses public data set training, resulting in insufficient generalization ability and adaptability of the model, imbalanced data sets, and inaccurate classification results.

Method used

Adaptive VPN traffic classification system, including traffic classification subsystem and adaptive adjustment subsystem, is adopted to collect the original encrypted traffic of the public network, establish a pre-trained model, and optimize it with fine-tuned data sets to build VPN and non-VPN traffic data sets to improve the adaptability and generalization capabilities of the model.

Benefits of technology

It effectively solves the problems of data set imbalance and inaccurate classification, improves the generalization ability and adaptability of the model in different network environments, and improves the classification accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120256964A_ABST
    Figure CN120256964A_ABST
Patent Text Reader

Abstract

The invention discloses a self-adaptive VPN (Virtual Private Network) traffic classification system and method. The system comprises a traffic classification subsystem and a self-adaptive adjustment subsystem, the traffic classification subsystem is used for collecting original encrypted traffic in a public network and establishing a pre-trained encrypted traffic classification model; the adaptive adjustment subsystem is used for establishing a fine adjustment data set according to the original encrypted traffic, and optimizing the pre-trained encrypted traffic classification model by using the fine adjustment data set to obtain an optimized encrypted traffic classification model; classifying the encrypted traffic in the public network based on the optimized encrypted traffic classification model; according to the method, the problems of unbalanced public data sets, poor engineering application capability and inaccurate classification are effectively solved, and the generalization capability and adaptability of the model in different network environments are improved by continuously optimizing the model through the adaptive adjustment subsystem.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted traffic classification, and in particular to an adaptive VPN traffic classification system and method. Background Art

[0002] With the acceleration of the digitalization process, the encrypted traffic on the Internet has shown an explosive growth trend. Through encryption algorithms, not only a solid confidentiality and integrity barrier is built for data transmission, but also the level of user privacy protection is significantly improved, systematically optimizing the security ecosystem of the cyberspace. As a typical application of encrypted communication technology, the virtual private network (VPN) technology has been deeply integrated into the modern Internet service system with its innovative ability to build remote tunnels. By building a secure "digital bridge", this technology creates a private transmission channel for users in the public network and is widely used in legal scenarios such as cross-border commerce, remote work, and academic access.

[0003] It is worth noting that the VPN traffic is growing at an unexpected speed, and its double-edged sword effect is becoming increasingly prominent. While ensuring legitimate services, some lawbreakers use VPN technology to build regulatory blind spots and carry out illegal activities such as cybercrime and information theft, seriously disrupting the network order. Therefore, it is necessary to classify VPN traffic and monitor network traffic according to the recognition results to identify security threats or abnormal behaviors.

[0004] In the existing VPN traffic classification methods, since the existing public data sets are used to train the model, due to the fact that the public data sets may not cover all the variabilities in the real scenarios, the generalization ability and adaptability of the trained model are insufficient. Moreover, the public data sets are usually generated based on specific scenarios or laboratory environments, and their data distributions may be significantly different from the encrypted traffic in the actual network environment, resulting in data set imbalance and inaccurate classification results of the trained classification model. Summary of the Invention

[0005] The present invention provides an adaptive VPN traffic classification system and method to overcome the technical problems of insufficient generalization ability and adaptability in the existing VPN traffic classification methods and inaccurate classification results caused by data set imbalance.

[0006] To achieve the above object, the technical solution of the present invention is as follows:

[0007] An adaptive VPN traffic classification system includes: a traffic classification subsystem and an adaptive adjustment subsystem;

[0008] The traffic classification subsystem is used to collect the original encrypted traffic in the public network and establish a pre-trained encrypted traffic classification model;

[0009] The adaptive adjustment subsystem is used to establish a fine-tuning data set according to the original encrypted traffic, and use the fine-tuning data set to optimize the pre-trained encrypted traffic classification model to obtain an optimized encrypted traffic classification model;

[0010] Classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model;

[0011] The fine-tuning data set includes a VPN traffic data set and a non-VPN traffic data set.

[0012] Furthermore, the traffic classification subsystem includes:

[0013] A traffic collection module, which is used to collect the original encrypted traffic in the public network;

[0014] A traffic storage module, which is used to store and manage the original encrypted traffic collected by the traffic collection module;

[0015] An encrypted traffic classification model pre-training module, which is used to establish an initial encrypted traffic classification model and train the initial encrypted traffic classification model with a public traffic data set to obtain a pre-trained encrypted traffic classification model.

[0016] Furthermore, the adaptive adjustment subsystem includes:

[0017] A VPN server, which is used to decrypt the original encrypted traffic in the public network to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic; it is also used to encrypt the original plaintext traffic sent to the intranet to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic;

[0018] A deep packet inspection module, which is used to perform deep packet inspection on the original plaintext traffic and the decrypted plaintext traffic to obtain a plaintext traffic classification result;

[0019] A knowledge integration module, which is used to correlate the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a ciphertext traffic classification result;

[0020] A fine-tuning data set construction module, which is used to construct a fine-tuning data set based on the data stored in the knowledge integration module and the traffic storage module;

[0021] An encrypted traffic classification model optimization module, which is used to adaptively train the pre-trained encrypted traffic classification model based on the fine-tuning data set to obtain an optimized encrypted traffic classification model.

[0022] Furthermore, the knowledge integration module correlates the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationships between the original encrypted traffic and the decrypted plaintext traffic, and between the original plaintext traffic and the encrypted ciphertext traffic, including:

[0023] Establish a relationship mapping table based on the HASH structure of Redis and the mapping relationships between the original encrypted traffic and the decrypted plaintext traffic, and between the original plaintext traffic and the encrypted ciphertext traffic;

[0024] The key value in the relationship mapping table is the plaintext ID, and the attribute information includes the ciphertext ID, ciphertext five-tuple, plaintext five-tuple, plaintext traffic classification result, and timestamp;

[0025] Obtain the ciphertext traffic classification result based on the relationship mapping table and the plaintext traffic classification result.

[0026] Furthermore, the fine-tuning dataset construction module constructs a fine-tuning dataset based on the data stored in the knowledge integration module and the traffic storage module. The construction of the fine-tuning dataset includes:

[0027] Query the relationship mapping table based on the plaintext IDs of the original plaintext traffic and the decrypted plaintext traffic to obtain the plaintext five-tuple, ciphertext ID, ciphertext five-tuple, plaintext traffic classification result, and ciphertext traffic classification result;

[0028] Assign classification labels to the original plaintext traffic and the decrypted plaintext traffic according to the plaintext five-tuple and the plaintext traffic classification result to form the non-VPN traffic dataset;

[0029] Obtain the original encrypted traffic from the traffic storage module according to the ciphertext ID, and assign classification labels to the original encrypted traffic according to the ciphertext five-tuple and the ciphertext traffic classification result to form the VPN traffic dataset.

[0030] Furthermore, the initial encrypted traffic classification model is obtained based on the CNN model and the LSTM model architecture.

[0031] An adaptive VPN traffic classification method is implemented based on an adaptive VPN traffic classification system. The specific steps include:

[0032] S1: Obtain a public traffic dataset, establish an initial encrypted traffic classification model, and pre-train the initial encrypted traffic classification model based on the public traffic dataset to obtain a pre-trained encrypted traffic classification model;

[0033] S2: Collect the original encrypted traffic in the public network and the original plaintext traffic sent by the internal network;

[0034] S3: Decrypt the original encrypted traffic based on the VPN server to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and encrypt the original plaintext traffic sent by the internal network to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic;

[0035] S4: Use deep packet inspection technology to perform deep packet inspection on the original plaintext traffic and the decrypted plaintext traffic to obtain the plaintext traffic classification result;

[0036] S5: Correlate the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a relationship mapping table;

[0037] S6: Establish a fine-tuning data set based on the correlation mapping table;

[0038] S7: Perform adaptive training on the pre-trained encrypted traffic classification model based on the fine-tuning data set to obtain an optimized encrypted traffic classification model, and classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model.

[0039] Beneficial effects: The present invention proposes an adaptive VPN traffic classification system, including a traffic classification subsystem and an adaptive adjustment subsystem. The traffic classification subsystem can collect encrypted traffic in the public network and establish a pre-trained encrypted traffic classification model; the adaptive adjustment subsystem can establish a fine-tuning data set based on the traffic data collected by the traffic classification subsystem. The fine-tuning data set includes a VPN traffic data set and a non-VPN traffic data set, and uses the fine-tuning data set to optimize the pre-trained encrypted traffic classification model to obtain an optimized encrypted traffic classification model. It effectively solves the problems of unbalanced public data sets, poor engineering application capabilities, and inaccurate classification. At the same time, the model is continuously optimized through the adaptive adjustment subsystem to improve the generalization ability and adaptability of the model in different network environments. Description of the Drawings

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0041] Figure 1 This is a flowchart of an adaptive VPN traffic classification method in the present invention. Specific implementation manner

[0042] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] This embodiment provides an adaptive VPN traffic classification system, as Figure 1 shown, including: a traffic classification subsystem and an adaptive adjustment subsystem;

[0044] The traffic classification subsystem is used to collect the original encrypted traffic in the public network and establish a pre-trained encrypted traffic classification model;

[0045] The adaptive adjustment subsystem is used to establish a fine-tuning data set according to the original encrypted traffic and optimize the pre-trained encrypted traffic classification model with the fine-tuning data set to obtain an optimized encrypted traffic classification model;

[0046] Classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model;

[0047] The fine-tuning data set includes a VPN traffic data set and a non-VPN traffic data set.

[0048] In a specific embodiment, the traffic classification subsystem includes:

[0049] A traffic collection module, which is used to collect the original encrypted traffic in the public network by using dedicated hardware or software tools and send the collected original encrypted traffic to the traffic storage module for storage;

[0050] A traffic storage module, which is used to store and manage the original encrypted traffic collected by the traffic collection module;

[0051] Specifically, the traffic storage module uses a general system for full-volume storage and applies big data technology. An index for the encrypted traffic is established through the traffic storage module. In addition to the conventional five-tuples, the index also adds the ID of the original encrypted traffic for the subsequent fine-tuning data set to obtain the corresponding encrypted traffic information through the ciphertext ID.

[0052] The encrypted traffic classification model pre-training module is used to establish an initial encrypted traffic classification model and train the initial encrypted traffic classification model with a public traffic dataset (ISCX VPN-nonVPN) to obtain a pre-trained encrypted traffic classification model.

[0053] In a specific embodiment, the initial encrypted traffic classification model is obtained based on the CNN model and the LSTM model architecture.

[0054] Specifically, for the encrypted traffic classification model based on the CNN (Convolutional Neural Network) model and the LSTM (Long Short-Term Memory Network) model, the CNN model captures the spatial features of the input traffic (such as the traffic load byte distribution) and transmits them to the LSTM model. The LSTM model extracts the time series features of the input features (such as packet length, temporal dependence), and inputs the output of the LSTM model into a fully connected layer. Finally, the classification probability is output through Softmax to realize the identification of encrypted traffic types. By combining the respective advantages of the CNN model and the LSTM model, the classification performance is significantly improved.

[0055] In a specific embodiment, the adaptive adjustment subsystem includes:

[0056] A VPN server, which is used to decrypt the original encrypted traffic in the public network to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic; it is also used to encrypt the original plaintext traffic sent from the intranet to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic;

[0057] Specifically, obtaining the mapping relationship through the VPN server is a function inherent in the VPN server and is a conventional technology, so it will not be elaborated here.

[0058] Specifically, in this embodiment, the processing cores of the VPN server are divided into a management core, a service processing core, and a communication core. The management core is responsible for VPN negotiation traffic, the service processing core is responsible for the encryption and decryption of service traffic, and the communication core is used to complete the mapping relationship data transmission of the plaintext traffic and the ciphertext traffic. The management core and the service processing core are allocated according to the concurrency and actual load, and one communication core is reserved. The three types of cores cooperate with each other and are independent of each other. This design idea of separating the control plane and the data plane can significantly improve the processing efficiency of the VPN server, especially in the case of high load, ensuring that when the load of a certain type of service is large, it does not affect the normal function applications of the other two types of cores, which is of great significance for improving the user experience and network service quality.

[0059] Specifically, in this embodiment, a communication interface is added to the decryption processing and encryption processing logic of the VPN server. The ciphertext ID (ciphertext payload_hash), ciphertext five-tuple, plaintext ID (plaintext payload_hash), and plaintext five-tuple are passed as parameters to the communication interface, and the communication interface is responsible for sending the mapping relationship between the two to the knowledge integration module in the communication core.

[0060] Specifically, this system is deployed at the boundary, which is usually connected to the internal network and the external network. The original plaintext traffic sent by the internal network is the traffic that needs to be encrypted by the VPN server when sent from the internal network to the external network.

[0061] A deep packet inspection module, which is used to perform deep packet inspection on the original plaintext traffic and the decrypted plaintext traffic to obtain a plaintext traffic classification result and transmit it to the knowledge integration module;

[0062] Specifically, the deep packet inspection (DPI) technology is a technology that can deeply analyze and control network traffic. It has a very high detection granularity and can reach the application layer, so it can identify and control various application protocols such as HTTP, FTP, DNS, etc. The DPI technology has a wide range of applications in the fields of network security, network optimization, business operation, etc. In this embodiment, using the deep packet inspection technology to obtain the plaintext traffic classification result is a conventional technology in the art and will not be elaborated here.

[0063] A knowledge integration module, which is used to associate the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a ciphertext traffic classification result;

[0064] A fine-tuning dataset construction module, which is used to construct a fine-tuning dataset based on the data stored in the knowledge integration module and the traffic storage module,

[0065] An encrypted traffic classification model optimization module, which is used to adaptively train the pre-trained encrypted traffic classification model based on the fine-tuning dataset to obtain an optimized encrypted traffic classification model.

[0066] Specifically, pre-training the initial encrypted traffic classification model with a public traffic dataset can help the model learn the general features and patterns of encrypted traffic and enable the pre-trained model to possess rich general knowledge. However, since the public traffic dataset used for pre-training is usually generated based on specific scenarios or laboratory environments, its data distribution may be significantly different from that of encrypted traffic in the actual network environment. For example, encrypted traffic generated in the laboratory (such as traffic captured by honeypot technology) may not fully reflect the complexity and diversity in the real network. If the model relies solely on the public dataset for training, it may overfit the specific features and noises of these data and fail to generalize to the data in the real scenario. Although the public traffic dataset may contain a large amount of labeled data, these data may be insufficient in terms of class distribution, feature coverage, etc. For example, some classes may have too many samples while other classes have too few samples, resulting in insufficient learning of the model for minority classes. In addition, the public traffic dataset is usually static and cannot provide dynamic feedback in the real scenario. When the model is trained on these data, it may not be able to adapt to the changes and uncertainties in actual applications. Therefore, in this embodiment, the pre-trained encrypted traffic classification model is fine-tuned and optimized. And since the classification model has been pre-trained, only a small amount of specific task data is required in the fine-tuning stage to achieve good results, and the computational cost is relatively low because only some parameters need to be adjusted or a small number of training steps are required. Moreover, by combining the general knowledge of the pre-trained model with the specific task data in the fine-tuning stage, the generalization ability of the model to new data can be improved.

[0067] In a specific embodiment, the knowledge integration module associates the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationships between the original encrypted traffic and the decrypted plaintext traffic, and between the original plaintext traffic and the encrypted ciphertext traffic, including:

[0068] Establish a relationship mapping table based on the HASH structure of Redis and the mapping relationships between the original encrypted traffic and the decrypted plaintext traffic, and between the original plaintext traffic and the encrypted ciphertext traffic;

[0069] The key value in the relationship mapping table is the plaintext ID, and the attribute information includes the ciphertext ID, ciphertext five-tuple, plaintext five-tuple, plaintext traffic classification result, and timestamp;

[0070] Specifically, the ciphertext five-tuple and the plaintext five-tuple refer to five key parameters in network communication, including source IP, destination IP, source port, destination port, and protocol type.

[0071] Obtain the ciphertext traffic classification result based on the relationship mapping table and the plaintext traffic classification result.

[0072] Specifically, since the cleartext traffic classification result is known, according to the mapping relationship between cleartext and ciphertext stored in the knowledge integration module, it can guide the acquisition of the ciphertext classification result corresponding to the cleartext. For example, if the cleartext traffic of the WeChat APP is known and the mapping relationship between the cleartext traffic of the WeChat APP and the ciphertext traffic of the WeChat APP is also known, then the corresponding ciphertext traffic can be obtained as the WeChat APP traffic.

[0073] Specifically, in this embodiment, the knowledge integration module is also used to manage the association mapping table, including:

[0074] Adding relationship mapping table entries: The knowledge integration module receives the mapping relationship sent by the VPN server and inserts it with the cleartext ID as the key value.

[0075] Deleting relationship mapping table entries includes two deletion methods: The first method is to directly delete after the operation of querying the relationship mapping table entries. If an abnormal situation occurs and the first method fails to delete, in order to avoid the residual mapping entries, the second method is used for deletion, that is, the system automatically deletes after the key value expires. Specifically, the key value is set with a default expiration time (2 hours), which can be dynamically adjusted according to the processing performance of the machine.

[0076] In a specific embodiment, the fine-tuning dataset construction module constructs a fine-tuning dataset based on the data stored in the knowledge integration module and the traffic storage module. The construction of the fine-tuning dataset includes:

[0077] Query the relationship mapping table based on the cleartext ID of the original cleartext traffic and the decrypted cleartext traffic to obtain the cleartext five-tuple, ciphertext ID, ciphertext five-tuple, cleartext traffic classification result, and ciphertext traffic classification result;

[0078] Assign classification labels to the original cleartext traffic and the decrypted cleartext traffic according to the cleartext five-tuple and the cleartext traffic classification result to form the non-VPN traffic dataset;

[0079] Obtain the original encrypted traffic from the traffic storage module according to the ciphertext ID, and assign classification labels to the original encrypted traffic according to the ciphertext five-tuple and the ciphertext traffic classification result to form the VPN traffic dataset.

[0080] Specifically, in this embodiment, by designing the VPN traffic dataset and the non-VPN traffic dataset, the balance of the dataset is guaranteed to a certain extent, and at the same time, the accuracy of the labels of the binary classification dataset is guaranteed, which is very crucial for improving the performance of the traffic classification model and reducing the false alarm rate. At the same time, it also provides higher-quality data resources for the field of network security.

[0081] An adaptive VPN traffic classification method, which is implemented based on an adaptive VPN traffic classification system. The specific steps include:

[0082] S1: Obtain a public traffic dataset, establish an initial encrypted traffic classification model, and pre-train the initial encrypted traffic classification model based on the public traffic dataset to obtain a pre-trained encrypted traffic classification model;

[0083] S2: Collect the original encrypted traffic in the public network and the original plaintext traffic sent from the internal network;

[0084] S3: Decrypt the original encrypted traffic based on the VPN server to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and encrypt the original plaintext traffic sent from the internal network to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic;

[0085] S4: Use deep packet inspection technology to perform deep packet detection on the original plaintext traffic and the decrypted plaintext traffic to obtain the plaintext traffic classification result;

[0086] S5: Associate the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a relationship mapping table;

[0087] S6: Establish a fine-tuning dataset based on the association mapping table;

[0088] S7: Perform adaptive training on the pre-trained encrypted traffic classification model based on the fine-tuning dataset to obtain an optimized encrypted traffic classification model, and classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model.

[0089] Specifically, in this embodiment, since the pre-trained model is calculated according to the public traffic dataset and needs to be fine-tuned to adapt to the actual application scenario when deployed in the real traffic scenario, the pre-trained encrypted traffic classification model is adjusted based on the fine-tuning dataset, and the adjusted encrypted traffic classification model is updated to the model database. The optimal encrypted traffic classification model is selected from the model database for classifying encrypted traffic, including application classification or malicious traffic classification, and network traffic monitoring is performed through the classification results to identify security threats or abnormal behaviors.

[0090] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. An adaptive VPN traffic classification system, characterized in that, Including: A traffic classification subsystem and an adaptive adjustment subsystem; The traffic classification subsystem is used to collect the original encrypted traffic in the public network and establish a pre-trained encrypted traffic classification model; The adaptive adjustment subsystem is used to establish a fine-tuning data set based on the original encrypted traffic, and use the fine-tuning data set to optimize the pre-trained encrypted traffic classification model to obtain an optimized encrypted traffic classification model; Classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model; The fine-tuning data set includes a VPN traffic data set and a non-VPN traffic data set.

2. The adaptive VPN traffic classification system according to claim 1, wherein The traffic classification subsystem includes: A traffic collection module for collecting the original encrypted traffic in the public network; A traffic storage module for storing and managing the original encrypted traffic collected by the traffic collection module; An encrypted traffic classification model pre-training module for establishing an initial encrypted traffic classification model and training the initial encrypted traffic classification model with a public traffic data set to obtain a pre-trained encrypted traffic classification model.

3. The adaptive VPN traffic classification system according to claim 2, wherein The adaptive adjustment subsystem includes: A VPN server for decrypting the original encrypted traffic in the public network to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic; and for encrypting the original plaintext traffic sent by the intranet to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic; A deep packet inspection module for performing deep packet inspection on the original plaintext traffic and the decrypted plaintext traffic to obtain a plaintext traffic classification result; A knowledge integration module for correlating the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a ciphertext traffic classification result; A fine-tuning data set construction module for constructing a fine-tuning data set based on the data stored in the knowledge integration module and the traffic storage module; An encrypted traffic classification model optimization module for adaptively training the pre-trained encrypted traffic classification model based on the fine-tuning data set to obtain an optimized encrypted traffic classification model.

4. The adaptive VPN traffic classification system according to claim 3, wherein The knowledge integration module correlates the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic, including: Establishing a relationship mapping table based on the HASH structure of Redis and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic; The key value in the relationship mapping table is the plaintext ID, and the attribute information includes the ciphertext ID, the ciphertext five-tuple, the plaintext five-tuple, the plaintext traffic classification result, and the timestamp; Obtain the ciphertext traffic classification result based on the relationship mapping table and the plaintext traffic classification result.

5. The adaptive VPN traffic classification system according to claim 4, wherein The fine-tuning dataset construction module constructs a fine-tuning dataset based on the data stored in the knowledge integration module and the traffic storage module. The construction of the fine-tuning dataset includes: Query the relationship mapping table based on the plaintext ID of the original plaintext traffic and the decrypted plaintext traffic to obtain the plaintext quintuple, ciphertext ID, ciphertext quintuple, plaintext traffic classification result, and ciphertext traffic classification result; Assign classification labels to the original plaintext traffic and the decrypted plaintext traffic according to the plaintext quintuple and the plaintext traffic classification result to form the non-VPN traffic dataset; Obtain the original encrypted traffic from the traffic storage module according to the ciphertext ID, and assign classification labels to the original encrypted traffic according to the ciphertext quintuple and the ciphertext traffic classification result to form the VPN traffic dataset.

6. The adaptive VPN traffic classification system according to claim 5, wherein The initial encrypted traffic classification model is obtained based on the CNN model and the LSTM model architecture.

7. An adaptive VPN traffic classification method, implemented based on the system described in claim 3, characterized in that The specific steps include: S1: Obtain a public traffic dataset, establish an initial encrypted traffic classification model, and pre-train the initial encrypted traffic classification model based on the public traffic dataset to obtain a pre-trained encrypted traffic classification model; S2: Collect the original encrypted traffic in the public network and the original plaintext traffic sent from the internal network; S3: Decrypt the original encrypted traffic based on the VPN server to obtain the decrypted plaintext traffic and the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and encrypt the original plaintext traffic sent from the internal network to obtain the encrypted ciphertext traffic and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic; S4: Use the deep packet detection technology to perform deep packet detection on the original plaintext traffic and the decrypted plaintext traffic to obtain the plaintext traffic classification result; S5: Associate the original plaintext traffic, the decrypted plaintext traffic, the plaintext traffic classification result, the original encrypted traffic, the encrypted ciphertext traffic, the mapping relationship between the original encrypted traffic and the decrypted plaintext traffic, and the mapping relationship between the original plaintext traffic and the encrypted ciphertext traffic to obtain a relationship mapping table; S6: Establish a fine-tuning dataset based on the association mapping table; S7: Perform adaptive training on the pre-trained encrypted traffic classification model based on the fine-tuning dataset to obtain an optimized encrypted traffic classification model, and classify the encrypted traffic in the public network based on the optimized encrypted traffic classification model.