Mobile application encrypted traffic behavior identification method based on dynamic interlaced graph attention mechanism

Through the combination of dynamic interleaving graph attention mechanism and time convolution network, the problem of low accuracy in the behavior recognition of encrypted traffic in mobile applications is solved, effective extraction and analysis of spatiotemporal features is achieved, and the accuracy and robustness of behavior recognition are improved.

CN120263484APending Publication Date: 2025-07-04NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510430609.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The prior art has low accuracy and high error recognition rate in the recognition of encrypted traffic behavior of mobile applications, and it is difficult to effectively utilize the spatial and temporal correlation between streams, resulting in poor recognition effect in real scenarios.

Method used

Using a method based on the dynamic interleaved graph attention mechanism, the encrypted traffic relationship of mobile applications is characterized by the graph attention spatiotemporal feature correlation graph, combining the time convolution network and the convolution neural network, the spatiotemporal characteristics of the traffic are extracted and analyzed to achieve behavioral recognition.

Benefits of technology

It improves the accuracy and robustness of mobile applications' encrypted traffic behavior recognition, can better capture the spatial and temporal correlation between traffic, and enhances the accuracy and generalization ability of behavior recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263484A_ABST
    Figure CN120263484A_ABST
Patent Text Reader

Abstract

The invention discloses a mobile application encrypted traffic behavior recognition method based on a dynamic interlaced graph attention mechanism, which comprises the following steps: collecting original data of mobile application encrypted traffic, and obtaining a graph attention spatial-temporal characteristic data packet of the mobile application encrypted traffic data; obtaining a graph attention spatial-temporal feature correlation graph at each moment, and obtaining graph attention spatial features; extracting a plurality of states from the graph attention spatio-temporal characteristic correlation graph of each node at different moments, forming a state sequence, coding the state sequence through a time convolution network, obtaining state time characteristics, and inputting the state time characteristics into a spatio-temporal attention module based on a dynamic interlaced graph attention mechanism to obtain graph attention spatio-temporal characteristics; and splicing and inputting the graph attention spatial-temporal features and the graph attention spatial features into a convolutional neural network, and outputting behavior analysis features to obtain a behavior classification result of the mobile application encrypted traffic. According to the invention, the accuracy of mobile application encrypted traffic behavior identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of traffic recognition, and particularly to a method for identifying encrypted traffic behavior of mobile applications based on a dynamic interleaved graph attention mechanism. Background Art

[0002] In recent years, with the rapid increase in the number of users of network mobile applications and the emphasis on the protection of user privacy and data security, the scale of mobile application encrypted traffic has grown rapidly. The popularity of mobile application encrypted traffic ensures the security and concealment of network communication between mobile applications, but at the same time brings many new problems. For example, there are some network attacks that use mobile application encrypted traffic to hide malicious behaviors, which makes the identification of mobile application encrypted traffic behavior an important means to ensure modern network security. However, since the data generated by mobile application encrypted network traffic is more complex than other network traffic, many traditional methods are difficult to learn effective features, resulting in a low accuracy rate of subsequent behavior recognition. On the other hand, due to the existence of homogeneous traffic generated by different mobile applications, the traditional methods may learn the same features of homogeneous traffic of different mobile applications, bringing great difficulties to subsequent behavior recognition.

[0003] To address the above problems, it is necessary to process the complex and numerous encrypted traffic of mobile applications through certain means for subsequent behavior recognition. Currently, many studies only stop at the classification of encrypted traffic without delving into behavior recognition. The authors of Li, Jianfeng, et al. "FOAP: Fine-Grained Open-World android app fingerprinting" [C]. 31st USENIX Security Symposium. Security 2022 used deep learning algorithms to capture the similarity of data packets and, on this basis, constructed anchor data packets with multi-time scale sequence features to reduce the interference of noise in the encrypted traffic of mobile applications, thereby improving the classification effect of encrypted traffic data. However, this method ignores the correlation between flows, resulting in unsatisfactory performance in some scenarios where network traffic is inseparable. At the same time, its method is only limited to specific bandwidth networks and network topology environments, with poor generalization and difficulty in being applied to real-world scenarios. The authors of P. Lin, K. Ye, Y. Hu, Y. Lin, C.-Z. Xu, "A novel multimodal deep learning framework for encrypted traffic classification", IEEE / ACM Trans. Netw. 31 (2022) 1369–1384 used a multimodal end-to-end learning strategy to extract traffic features from two perspectives: the content of data packets and the length of data packets, modeled the temporal dependence relationship between data packets using a convolutional neural network, and used its multi-head self-attention mechanism to focus on the data content from multiple dimensions, enhancing the model's ability to understand complex traffic patterns. However, since this method processes the encrypted traffic of mobile applications in an end-to-end manner, it will be affected by factors such as useless packets and noise in practical applications. At the same time, although this method will utilize temporal dependence information, in the case where there is a large time span between two packets and there are connections in attributes, it is easy to ignore the relationship factors between packets, resulting in a decline in the recognition effect. Summary of the Invention

[0004] Devoted to the research on the behavioral characteristics of encrypted traffic in mobile applications and solving the problems of low accuracy and high false recognition rate in the identification of encrypted traffic behavior in mobile applications, this application provides a method for identifying encrypted traffic behavior in mobile applications based on a dynamic interleaved graph attention mechanism. On the basis of considering the correlation between encrypted traffic, this method establishes a representation of encrypted traffic in mobile applications in the form of a graph attention spatio-temporal feature correlation graph, making the relationship between encrypted traffic in mobile applications more intuitive and clear through the form of the graph attention spatio-temporal feature correlation graph, establishing a dynamic interleaved graph attention mechanism to extract the behavioral characteristics of encrypted traffic in mobile applications, and classifying the behavioral characteristics through a neural network and a softmax function to achieve the identification of encrypted traffic behavior in mobile applications.

[0005] This application discloses a method for identifying encrypted traffic behavior in mobile applications based on a dynamic interleaved graph attention mechanism, which includes:

[0006] Step 1: Collect the original data of encrypted traffic in mobile applications, and perform preprocessing on the original data of encrypted traffic in mobile applications by dividing the traffic data to obtain encrypted traffic files of mobile applications;

[0007] Step 2: Perform cleaning preprocessing on the traffic data of the encrypted traffic files of mobile applications to obtain graph attention spatio-temporal feature data packets of the encrypted traffic data of mobile applications;

[0008] Step 3: Read the graph attention spatio-temporal feature data packets, and adopt a graph structure modeling method to obtain the graph attention spatio-temporal feature correlation graph at each moment, and obtain the graph attention spatial features;

[0009] Step 4: Extract multiple states from the graph attention spatio-temporal feature correlation graphs of each node at different moments, form a state sequence and encode the state sequence through a temporal convolutional network to obtain a tensor sequence. According to the tensor sequence, obtain the state time features and input them into the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatio-temporal features;

[0010] Step 5: Concatenate and input the graph attention spatio-temporal features and the graph attention spatial features into a convolutional neural network, output the behavioral analysis features, and finally obtain the behavioral classification result of the encrypted traffic in mobile applications through the softmax function.

[0011] Further, the said Step 1 includes:

[0012] Collect the original data of encrypted traffic in mobile applications and save it as an original data file of encrypted traffic in mobile applications; read the original data file of encrypted traffic in mobile applications and parse it one by one; through parsing, divide the file into the same encrypted traffic file of mobile applications according to the same bidirectional flow, fixed number of data packets, fixed file size, and the same time period.

[0013] Further, step 2 includes:

[0014] Perform preliminary cleaning on the traffic data of the encrypted traffic file of the mobile application, delete the Ethernet header information and tail information in the data link layer of the file, and replace the data link layer address with 0-bit data; delete the retransmission packets, duplicate acknowledgment packets, RESET packets and other noisy network traffic in the file, retain the data packet headers and payload information in the network layer and transport layer, and save the traffic file after the cleaning preprocessing as the cleaned preprocessing traffic file.

[0015] Read the cleaned preprocessing file, sort the traffic in the entire data packet file according to the chronological order of the data packets in the file, and obtain the graph attention spatio-temporal feature data packets of the encrypted traffic data of the mobile application.

[0016] Further, step 3 includes:

[0017] Step 31: Read the graph attention spatio-temporal feature data packets, adopt the modeling method of the graph structure, abstract the encrypted traffic as graph nodes, connect the graph nodes through different types of relationships, and embed the transmission traffic status information on each graph node to obtain the graph attention spatio-temporal feature related graph at each moment.

[0018] Step 32: Input the state of the graph attention spatio-temporal feature related graph of the i-th node at the T-th time interval on the transmission flow into a multi-layer perceptron for characterization to obtain a state feature vector, and input it into the spatial attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatial feature.

[0019] Further, step 31 includes:

[0020] Step 311: Read the graph attention spatio-temporal feature data packets respectively, adopt the graph structure-based modeling method, abstract the traffic sequence as nodes in the graph, and embed the load information in each node as the state information of the node; connect the nodes in different ways; establish a type of attribute connection for the traffic with a request-response relationship between encrypted traffic; establish a type-two full connection for the attribute connection between two encrypted traffic, and finally obtain multiple graph attention spatio-temporal feature related subgraphs.

[0021] Step 312: Set a time threshold, connect different nodes in the graph attention spatial feature related graph according to the time threshold to obtain multiple graph attention spatio-temporal feature related graphs, and each graph attention spatio-temporal feature related graph is characterized by an adjacency matrix and a state feature matrix; among them, the adjacency matrix represents the connectivity relationship of each node in the graph attention spatio-temporal feature related graph, and the state feature matrix represents the state information embedded in each node of the graph attention spatio-temporal feature related graph, that is, the length, direction and data features of the load information embedded in each node.

[0022] Furthermore, step 32 includes:

[0023] Step 321: Input the state of the i-th graph attention spatio-temporal feature correlation graph at time T into a multi-layer fully connected network for characterization to obtain a state feature vector;

[0024] Step 322: According to the state feature vector, use the spatial attention module based on the dynamic interleaved graph attention mechanism to calculate the scaled dot product and attention scores, and finally calculate the graph attention spatial feature.

[0025] Furthermore, step 321 includes:

[0026] Extract the graph attention spatio-temporal feature correlation sub-graph of the i-th node at the T-th time interval from the graph attention spatio-temporal feature correlation graph, and combine the feature matrix and the adjacency matrix into a state;

[0027] Input the state into a K-layer fully connected network for characterization to obtain the state feature vector corresponding to the i-th node; the state feature vector is determined according to the activation function, the output of the (K - 1)-th layer fully connected network, and the weight matrix and bias vector of the K-th layer fully connected network.

[0028] Furthermore, step 322 includes:

[0029] According to the state feature vector, the number of hidden neurons in the graph attention layer of the spatial attention module, and the value parameter of the graph attention layer of the spatial attention module, obtain the first scaled dot product;

[0030] According to the first scaled dot product and the set of all adjacent nodes of each data stream in the graph attention spatio-temporal feature correlation graph, obtain the first attention score;

[0031] According to the first attention score, the number of attention functions of different linear mappings, and the keyword parameter of the graph attention layer of the spatial attention module, obtain the first graph attention spatio-temporal feature;

[0032] According to the first graph attention spatio-temporal feature, the keyword parameter of the spatial attention module based on dynamic interleaving, and the number of hidden neurons of the spatial attention module based on dynamic interleaving, obtain the second scaled dot product;

[0033] According to the second scaled dot product and the set of all adjacent nodes of each node in the graph attention spatio-temporal feature correlation graph, obtain the second attention score;

[0034] According to the second attention score, the number of attention functions of different linear mappings, and the value parameter of the graph attention layer of the spatial attention module, obtain the graph attention spatial feature.

[0035] Furthermore, step 4 includes:

[0036] Step 41: Extract multiple states from the graph attention spatio-temporal feature correlation graph of the i-th node from the 1st moment to the T-th moment and splice them to form a state sequence;

[0037] Step 42: Perform dilated causal convolution on the state sequence, perform interval sampling on the input when calculating the convolution to obtain the sampled state sequence; normalize the weights in the dilated causal convolution module according to the state sequence, and output the mapped state sequence after the sampled state sequence passes through the activation function; randomly select a part of the neurons from the hidden layer of the deep network for masking, update the other unmasked neurons through gradient descent, and then restore the masked neurons, whose weight values remain the same as before being masked;

[0038] Step 43: Repeat the operation of step 42 on the mapped state sequence to obtain the final state sequence, add it to the state sequence, and obtain the tensor sequence output by the first layer of the temporal convolutional network;

[0039] Step 44: Repeat the operations of step 42 to step 43 on the tensor sequence to perform dilated causal convolution, perform interval sampling on the input when calculating the convolution, and obtain the tensor sequence output by the second layer of the temporal convolutional network, that is, the overall output value of the temporal convolutional network;

[0040] Step 45: Perform global max pooling and global average pooling on the tensor sequence output by the second layer of the temporal convolutional network, splice the features output by the global max pooling and global average pooling, and use a fully connected layer to represent the spliced features to obtain the state temporal features;

[0041] Step 46: Input the state temporal features, calculate the scaled dot product and attention scores using the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism, and finally calculate the graph attention spatio-temporal features.

[0042] Furthermore, step 46 includes:

[0043] Obtain the third scaled dot product according to the state temporal features, the keyword parameters of the spatio-temporal attention module, and the number of hidden neurons in the graph attention layer of the spatio-temporal attention module;

[0044] Obtain the third attention score according to the third scaled dot product and the set of all adjacent nodes of each node in the graph attention spatio-temporal feature correlation graph;

[0045] Obtain the second graph attention spatio-temporal feature according to the third attention score, the number of attention functions of different linear mappings, and the value parameters of the graph attention layer of the spatio-temporal attention module;

[0046] Based on the spatio-temporal features of the third figure, the number of implicit neurons in the spatio-temporal attention module based on dynamic interleaving, and the graph attention layer value parameters of the spatio-temporal attention module based on dynamic interleaving, the fourth scaled dot product is obtained;

[0047] Based on the fourth scaled dot product and the set of all adjacent nodes of each data stream in the graph related to the spatio-temporal features of graph attention, the fourth attention score is obtained;

[0048] Based on the fourth attention score, the number of attention functions of different linear mappings, and the keyword parameters of the graph attention layer of the spatio-temporal attention module, the spatio-temporal features of graph attention are obtained.

[0049] Further, step 5 includes:

[0050] The spatio-temporal features of graph attention and the spatial features of graph attention are concatenated and input into the convolutional layer in the convolutional neural network. The result output by the convolutional layer is successively processed by batch normalization and activation function, and then input into the convolutional layer for processing again. The processed result is subjected to residual connection with the concatenated result of the spatio-temporal features of graph attention and the spatial features of graph attention. The result of the residual connection is input into the fully connected layer, and the behavior classification probability of the encrypted traffic of the mobile application is generated through the softmax function. By maximizing the behavior classification probability, the behavior classification result of the encrypted traffic of the mobile application is obtained.

[0051] Due to the adoption of the above technical solutions, the present application has the following advantages:

[0052] 1. None of the existing methods for identifying the behaviors of encrypted traffic of mobile applications make full use of the spatio-temporal correlation between flows, and the performance of identifying the behaviors of encrypted traffic of mobile applications in real scenarios is not good. A method for identifying the behaviors of mobile application traffic based on a dynamic interleaved graph attention mechanism proposed by the present invention can not only extract the hidden information in the traffic, but also capture the spatio-temporal correlation between flows, and make the relationship between the encrypted traffic of mobile applications more intuitive and clear through the form of a spatio-temporal feature correlation graph. By analyzing the relationship between the time information and the spatial information of the encrypted traffic of mobile applications, the accuracy of identifying the behaviors of the encrypted traffic of mobile applications is improved. The present invention introduces a dynamic interleaved graph attention mechanism to analyze spatio-temporal information. The dynamic interleaved graph attention mechanism can better capture spatio-temporal dependencies in long-term sequence tasks and embed them into features, enabling the behavior recognition neural network to utilize this dependency. This way can make the robustness of the encrypted traffic behavior recognition of mobile applications stronger, and at the same time the behavior recognition accuracy will also be higher.

[0053] 2. The method proposed by the present invention can accurately express the temporal and spatial relationships between encrypted traffic of mobile applications, enabling the full utilization of spatio-temporal correlations. At the same time, through the dynamic interleaved graph attention mechanism, it can capture subtle temporal and spatial feature information more effectively than existing technical methods, thereby effectively distinguishing the potential actions of encrypted traffic of mobile applications. Based on this, it can more accurately identify the user behavior of mobile applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0055] Figure 1 It is a schematic flowchart of a method for identifying the behavior of encrypted traffic of mobile applications based on a dynamic interleaved graph attention mechanism according to an embodiment of the present application;

[0056] Figure 2 It is a schematic flowchart of the preprocessing process of encrypted traffic data of mobile applications according to an embodiment of the present application;

[0057] Figure 3 It is a schematic flowchart of a method for establishing a graph attention spatio-temporal feature correlation graph according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0058] The present application will be further described in conjunction with the drawings and embodiments. The described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art shall fall within the scope of protection of the embodiments of the present application.

[0059] Traditional methods using machine learning models cannot automatically extract and select features and rely on the experience of domain experts, resulting in great uncertainty when applying machine learning to encrypted traffic classification. At the same time, traditional methods using deep learning models require a large amount of labeled data for training, and the data needs to be evenly distributed and representative. Moreover, deep learning models may be affected by overfitting, resulting in a decrease in the accuracy of the trained model in real-world applications. At the same time, traditional methods also make it difficult for the model to learn the connections between encrypted traffic of mobile applications, resulting in low accuracy of behavior recognition.

[0060] To solve the above technical problems, an embodiment of a method for identifying the behavior of encrypted traffic of mobile applications based on a graph attention mechanism is proposed in the present application. Referring to Figure 1 , the method proposed in the embodiment of the present application includes the following steps:

[0061] S1: Collect the original data of encrypted traffic of mobile applications, and perform preprocessing on the original data of encrypted traffic of mobile applications by traffic data division to obtain the encrypted traffic PCAP file of mobile applications, as Figure 2 shown.

[0062] S2: Clean and preprocess the traffic data of the encrypted traffic PCAP file of mobile applications after the division preprocessing is completed to obtain the cleaned and preprocessed PCAP file.

[0063] S3: Sort the traffic in the cleaned and preprocessed PCAP file according to the chronological order of data packets to obtain the graph attention spatio-temporal feature data packets of encrypted traffic of mobile applications.

[0064] S4: Read the graph attention spatio-temporal feature data packets, adopt the modeling method of graph structure, abstract the encrypted traffic as graph nodes, connect the graph nodes through different types of relationships, and embed the transmission traffic status information on each graph node to obtain the graph attention spatio-temporal feature related graph at each moment, as Figure 3 shown.

[0065] S5: Input the state s i,T of the graph attention spatio-temporal feature related graph of the i-th node at the T-th time interval on the transmission flow into a multi-layer perceptron for characterization to obtain the state feature vector h i ;

[0066] S6: Extract the states s i,1 , s i,2 , ……, s i,T-1 , s i,T from the graph attention spatio-temporal feature related graphs of the i-th node from the 1st moment to the T-th moment to form the state sequence H i = [s i,1 , s i,2 , ……, s i,T-1 , s i,T , and encode H i through a temporal convolutional network to obtain a tensor sequence

[0067] S7: Perform pooling and concatenation on the tensor sequence to obtain the state time feature x i ;

[0068] S8: Input the state time feature x i into the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatio-temporal feature z i ;

[0069] S9: Input the state feature vector h iInput it into the spatial attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatial feature z'. i ;

[0070] S10: Concatenate the graph attention spatio-temporal feature z i and the graph attention spatial feature z' i and input them into a convolutional neural network, output the behavior analysis feature through the convolutional neural network, and finally obtain the behavior classification result of the encrypted traffic of the mobile application through the softmax function.

[0071] S1: Collect the original data of the encrypted traffic of the mobile application, and perform preprocessing on the traffic data division of the original data of the encrypted traffic of the mobile application to obtain the PCAP file of the encrypted traffic of the mobile application, as Figure 2 shown. S1 includes the following steps:

[0072] S1.1: Collect the original data of the encrypted traffic of the mobile application and save it as the PCAP file of the original data of the encrypted traffic of the mobile application.

[0073] S1.2: Read the PCAP file of the original data of the encrypted traffic of the mobile application and parse it one by one.

[0074] S1.3: Through parsing, divide the data packets of the PCAP file into the same PCAP file of the encrypted traffic of the mobile application according to the same two-way flow.

[0075] S1.4: Through parsing, divide the PCAP file into the same PCAP file of the encrypted traffic of the mobile application according to the number of 200 data packets.

[0076] S1.5: Through parsing, divide the PCAP file into the same PCAP file of the encrypted traffic of the mobile application according to the data packet file size of 20MB.

[0077] S1.6: Through parsing, divide the PCAP file into the same PCAP file of the encrypted traffic of the mobile application within the same time period.

[0078] S2: Perform cleaning preprocessing on the traffic data of the PCAP file of the encrypted traffic of the mobile application after the division preprocessing is completed to obtain the cleaned preprocessing PCAP file. S2 includes the following steps:

[0079] S2.1: Perform preliminary cleaning on the traffic data of the PCAP file of the encrypted traffic of the mobile application after the division preprocessing is completed, delete the Ethernet header information and tail information of the data link layer in the PCAP file, and replace the MAC address of the data link layer with 0bit data; delete the retransmission packets, duplicate acknowledgment packets, RESET packets and other noise network traffic in the PCAP file, and retain the data packet headers and payload information of the network layer and transport layer.

[0080] S2.2: Save the data after completing the cleaning preprocessing as a cleaning preprocessing PCAP file.

[0081] S3: Sort the traffic in the cleaning preprocessing PCAP file according to the chronological order of the data packets to obtain the graph attention spatio-temporal feature data packets of the mobile application encrypted traffic. S3 includes the following steps:

[0082] S3.1: Read the cleaning preprocessing PCAP file after completing the cleaning preprocessing, and sort the traffic in the entire data packet file according to the chronological order of the data packets in the PCAP file to obtain the graph attention spatio-temporal feature data packets of the mobile application encrypted traffic.

[0083] S3.2: Save the graph attention spatio-temporal feature data packets of the mobile application encrypted traffic.

[0084] S4: Read the graph attention spatio-temporal feature data packets, adopt the modeling method of the graph structure, abstract the encrypted traffic as graph nodes, connect the graph nodes through different types of relationships, and embed the transmission traffic status information on each graph node to obtain the graph attention spatio-temporal feature related graph at each moment, as Figure 3 shown. S4 includes the following steps:

[0085] S4.1: Read the graph attention spatio-temporal feature data packets, adopt the graph structure-based modeling method, abstract each traffic in the traffic sequence as a node in the graph, and embed the length, direction, and data characteristics of the load information in each node as the status information of the node.

[0086] S4.2: Connect the nodes abstracted in S4.1 through different types. First, establish a type of attribute connection for the traffic with a request-response relationship between the traffic; then establish a type of full connection for the attribute connection between two encrypted traffics; finally, establish a graph attention spatio-temporal feature related subgraph.

[0087] S4.3: For all the graph attention spatio-temporal feature data packets in S4.2, m graph attention spatio-temporal feature related subgraphs are established. Set the time threshold Tthresh. If the time interval between two encrypted traffics is lower than the threshold Tthresh, it is considered that there is a correlation between the nodes corresponding to the two traffics, and a time connection is established between the correlated nodes. Finally, the m graph attention spatio-temporal feature related subgraphs are divided into N graph attention spatio-temporal feature related graphs. Represent the graph attention spatio-temporal feature related graph of each encrypted traffic as G = <R, X>, where the adjacency matrix R represents the connectivity relationship of each node in the graph attention spatio-temporal feature related graph, and the feature matrix X represents the status information embedded in each node, that is, the length, direction, and data characteristics of the load information embedded in each node.

[0088] S5: Input the state s of the graph attention spatio-temporal feature correlation graph of the i-th node in the T-th time interval on the traffic transmission flow i,T into a multi-layer perceptron for characterization to obtain the state feature vector h i . S5 includes the following steps:

[0089] S5.1: Extract the graph attention spatio-temporal feature correlation subgraph of the i-th node in the T-th time interval from the graph attention spatio-temporal feature correlation graph established in S4.3, and combine the feature matrix x' and the adjacency matrix R' into the state s i,T .

[0090] S5.2: Input the state s i,T into a ten-layer fully connected network for characterization, and obtain the state feature vector h corresponding to the i-th node according to the following formulas i :

[0091] f1 = σ(s i,t W i,1 + b i,1 )

[0092] f2 = σ(f1W i,2 + b i,2 )

[0093] f3 = σ(f2W i,3 + b i,3 )

[0094] f4 = avg(f1 + f2 + f3)

[0095] f5 = σ(f4W i,5 + b i,5 )

[0096] f6 = σ(f5W i,6 + b i,6 )

[0097] f7 = σ(f6W i,7 + b i,7 )

[0098] f8 = maxpool(avg(f5 + f6 + f7))

[0099] f9 = σ(f8W i,9 + b i,9 )

[0100] h i = σ(f9W i,10 + b i,10 )

[0101] Among them, W i,1, W i,2 , W i,3 , W i,4 are the weight matrices of the first, second, third, and fourth layers of the fully connected network, respectively, and b i,1 , b i,2 , b i,3 , b i,4 are the bias vectors of the first, second, third, and fourth layers of the fully connected network, respectively. W i,5 , W i,6 , W i,7 are the weight matrices of the fifth, sixth, and seventh layers of the fully connected network, respectively, and b i,5 , b i,6 , b i,7 are the bias vectors of the fifth, sixth, and seventh layers of the fully connected network, respectively. W i,8 , W i,9 , W i,10 are the weight matrices of the eighth, ninth, and tenth layers of the fully connected network, respectively, and b i,8 , b i,9 , b i,10 are the bias vectors of the eighth, ninth, and tenth layers of the fully connected network, respectively. σ represents the ReLU activation function, avg represents taking the average value, maxpool represents taking the max pooling process, and f1, f2, f3, f4, f5, f6, f7, f8, f9 are all the extracted intermediate step feature vectors.

[0102] S6: The state s i,1 , s i,2 , ……, s i,T-1 , s i,T extracted from the graph attention spatio-temporal feature correlation graph from the i-th node, the 1st moment to the T-th moment is composed into a state sequence H i = [s i,1 , s i,2 , ……, s i,T-1 , s i,T , and H i is encoded through a temporal convolutional network to obtain a tensor sequence S6 includes the following steps:

[0103] S6.1: Repeat S5.1 to extract the state s i,1 , s i,2 , ……, s i,+-1 , s i,T from the graph attention spatio-temporal feature correlation graph from the i-th node, the 1st moment to the T-th moment and concatenate them to obtain a state sequence H i = [s i,1 , s i,2 , ……, s i,T-1 , s i,T .

[0104] S6.2: Perform dilated causal convolution on the state sequence H i During the convolution calculation, perform interval sampling on the input to obtain H′ i ;

[0105] Normalize the weights W in the dilated causal convolution module. The calculation formula is as follows:

[0106]

[0107] where g is the scalar factor in the dilated causal convolution module.

[0108] S6.3: Pass H′ i through the ReLU activation function to obtain

[0109] S6.4: Randomly select a part of the neurons from the hidden layer of the deep network for masking, update the other unmasked neurons through gradient descent, and then restore the masked neurons. Their weight values remain the same as before masking;

[0110] S6.5: For Repeat one round of operations from S6.2 to S6.4 to obtain Pass the state sequence H i through a 1×1 convolution block and add it to to obtain the tensor sequence output by the first layer of the temporal convolutional network

[0111] S6.6: For the tensor sequence output by the first layer of the temporal convolutional network Repeat one round of operations from S6.2 to S6.5 to obtain the tensor sequence output by the second layer of the temporal convolutional network That is, the overall output value of the temporal convolutional network;

[0112] S7: Perform pooling and concatenation on the tensor sequence to obtain the state-time feature x i . S7 includes the following steps:

[0113] S7.1: Perform global max pooling and global average pooling on the tensor sequence to obtain the features and respectively. The calculation formulas are as follows:

[0114]

[0115] where MP represents global max pooling and AP represents global average pooling;

[0116] S7.2: Concatenate the global max pooling feature Concatenate with the global average pooling feature The calculation formula is as follows:

[0117]

[0118] where x cat is the concatenated feature, and || represents concatenating the vectors at both ends of it;

[0119] S7.3: Use a fully connected network to represent the concatenated feature x cat to obtain the state-time feature x i , and the calculation formula is as follows:

[0120] fc1 = σ(x cat W1 + b1)

[0121] fc2 = σ(fc1W2 + b2)

[0122] fc3 = σ(fc2W3 + b3)

[0123] where W1, W2, and W3 are the weight matrices of the first, second, and third layers of the fully connected network respectively, b1, b2, and b3 are the bias vectors of the first, second, and third layers of the fully connected network respectively, and σ represents the ReLU activation function.

[0124] S8: Input the state-time feature x i into the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatio-temporal feature z i . S8 includes the following steps:

[0125] S8.1: According to the state-time feature x i , calculate the scaled dot product through the following formula

[0126]

[0127] where K i,u is the keyword parameter of the spatio-temporal attention module, and d h represents the number of hidden neurons in the graph attention layer of the spatio-temporal attention module;

[0128] S8.2: Obtain the attention score α i through the following formula:

[0129]

[0130] where N i represents the set of all adjacent nodes of the i-th node in the graph related to the graph attention spatio-temporal feature;

[0131] S8.3: Obtain the graph attention spatio-temporal feature y through the following formula i :

[0132]

[0133] where M is the number of attention functions of different linear mappings, and V i,u is the graph attention layer value parameter of the spatio-temporal attention module.

[0134] S8.4: Calculate the scaled dot product φ through the following formula according to the graph attention spatio-temporal feature y i : i :

[0135]

[0136] where d h represents the number of hidden neurons in the spatio-temporal attention module based on dynamic interleaving, and V' i,u is the graph attention layer value parameter of the spatio-temporal attention module based on dynamic interleaving;

[0137] S8.5: Obtain the attention score β through the following formula i :

[0138]

[0139] where N i represents the set of all adjacent nodes of the i-th data stream in the graph related to the graph attention spatio-temporal feature;

[0140] S8.6: Obtain the graph attention spatio-temporal feature z through the following formula i :

[0141]

[0142] where M is the number of attention functions of different linear mappings, and K' i,u is the keyword parameter of the graph attention layer of the spatio-temporal attention module.

[0143] S9: Input the state feature vector h i into the spatial attention module based on the dynamic interleaving graph attention mechanism to obtain the graph attention spatial feature z' i . S9 includes the following steps:

[0144] S9.1: Calculate the scaled dot product θ through the following formula according to the state feature vector h i : i :

[0145]

[0146] where dh represents the number of hidden neurons in the graph attention layer of the spatial attention module, V″ i,u is the value parameter of the graph attention layer of the spatial attention module;

[0147] S9.2: Obtain the attention score γ through the following formula i :

[0148]

[0149] where N i represents the set of all adjacent nodes of the i-th data stream in the graph attention spatio-temporal feature correlation graph;

[0150] S9.3: Obtain the graph attention spatial feature g through the following formula i :

[0151]

[0152] where M is the number of attention functions of different linear mappings, K″ i,u is the keyword parameter of the graph attention layer of the spatial attention module.

[0153] S9.4: According to the graph attention spatial feature g i , calculate the scaled dot product ε through the following formula i ;

[0154]

[0155] where K″′ i,u is the keyword parameter of the spatial attention module based on dynamic interleaving, d h represents the number of hidden neurons of the spatial attention module based on dynamic interleaving;

[0156] S9.5: Obtain the attention score μ through the following formula i :

[0157]

[0158] where N i represents the set of all adjacent nodes of the i-th node in the graph attention spatio-temporal feature correlation graph;

[0159] S9.6: Obtain the graph attention spatial feature z′ through the following formula i :

[0160]

[0161] where M is the number of attention functions of different linear mappings, V″′ i,uIt is the value parameter of the graph attention layer in the spatial attention module.

[0162] S10: Concatenate the graph attention spatio-temporal feature z i and the graph attention spatial feature z' i and input them into the convolutional neural network, and output the behavior analysis feature through the convolutional neural network. Finally, obtain the behavior classification result of the encrypted traffic of the mobile application through the softmax function. S10 includes the following steps:

[0163] S10.1: Concatenate the graph attention spatio-temporal feature z i obtained according to the state time feature x i and the graph attention spatio-temporal feature z' i obtained according to the state feature vector h i , that is:

[0164]

[0165] where, represents the concatenation result, and || represents concatenating the vectors at both ends of it;

[0166] S10.2: Input the concatenated feature vector into the convolutional layer for processing.

[0167]

[0168] where, W0 is the convolutional kernel weight matrix, b0 is the convolutional kernel bias term, and Conv is the convolutional process.

[0169] S10.3: Process Z0 sequentially through batch normalization and activation function.

[0170] Z1 = tanh(batch_normalize(Z0))

[0171] where, tanh is the activation function and batch_normalize is the batch normalization process.

[0172] S10.4: Input Z1 into the convolutional layer again for processing.

[0173] Z2 = Conv(Z1; W1, b1)

[0174] where, W1 is the convolutional kernel weight matrix, b1 is the convolutional kernel bias term, and Conv is the convolutional process. S10.5: Perform a residual connection on Z2, and the calculation formula is as follows.

[0175]

[0176] Among them, Z3 is a behavior analysis feature, W2 is a convolution kernel weight matrix, b2 is a convolution kernel bias term, and Conv is a convolution process.

[0177] S10.6: Input Z3 into a fully connected layer, and generate the behavior classification probability p of the encrypted traffic of the mobile application through the softmax function:

[0178] p = softmax(FCL(W c Z3 + b c ))

[0179] Among them, FCL represents the fully connected layer process, and softmax represents the multi-class normalization function.

[0180] S10.7: Obtain the behavior classification result of the encrypted traffic of the mobile application through the maximum probability solving function.

[0181] action = argmax(p)

[0182] That is, the final behavior recognition result action of the encrypted traffic node i of the mobile application can be obtained.

[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present application, and any modification or equivalent replacement that does not depart from the spirit and scope of the present application should be covered by the protection scope of the claims of the present application.

Claims

1. A method for identifying encrypted traffic behavior of mobile applications based on a dynamic interleaved graph attention mechanism, characterized in that, Including: Step 1: Collect the original data of encrypted traffic of mobile applications, and perform preprocessing on the traffic data division of the original data of encrypted traffic of mobile applications to obtain encrypted traffic files of mobile applications; Step 2: Perform cleaning preprocessing on the traffic data of the encrypted traffic files of mobile applications to obtain graph attention spatio-temporal feature data packets of the encrypted traffic data of mobile applications; Step 3: Read the graph attention spatio-temporal feature data packets, adopt the modeling method of graph structure, obtain the graph attention spatio-temporal feature related graphs at each moment, and obtain the graph attention spatial features; Step 4: Extract multiple states from the graph attention spatio-temporal feature related graphs of each node at different moments, form a state sequence and encode the state sequence through a temporal convolutional network to obtain a tensor sequence. According to the tensor sequence, obtain the state temporal features and input them into the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatio-temporal features; Step 5: Concatenate and input the graph attention spatio-temporal features and the graph attention spatial features into a convolutional neural network, output the behavior analysis features, and finally obtain the behavior classification result of the encrypted traffic of mobile applications through the softmax function.

2. The method according to claim 1, wherein The said Step 1 includes: Collect the original data of encrypted traffic of mobile applications and save it as an original data file of encrypted traffic of mobile applications; read the original data file of encrypted traffic of mobile applications and parse it one by one; through parsing, divide the file into the same encrypted traffic file of mobile applications according to the same bidirectional flow, fixed number of data packets, fixed file size and the same time period.

3. The method according to claim 1, characterized in that The said Step 2 includes: Perform preliminary cleaning on the traffic data of the encrypted traffic files of mobile applications, delete the Ethernet header information and tail information in the data link layer of the file, and replace the data link layer address with 0bit data; delete the retransmission packets, duplicate acknowledgment packets, RESET packets and other noise network traffic in the file, and retain the data packet headers and payload information in the network layer and transport layer. Save the data after cleaning preprocessing as a cleaned preprocessing traffic file; Read the cleaned preprocessing file, sort the traffic in the entire data packet file according to the time sequence of the data packets in the file, and obtain the graph attention spatio-temporal feature data packets of the encrypted traffic data of mobile applications.

4. The method according to claim 1, wherein The said Step 3 includes: Step 31: Read the graph attention spatio-temporal feature data packets, adopt the modeling method of graph structure, abstract the encrypted traffic as graph nodes, connect the graph nodes through different types of relationships, and embed the transmission traffic state information on each graph node to obtain the graph attention spatio-temporal feature related graphs at each moment; Step 32: Input the state of the graph attention spatio-temporal feature related graph of the i-th node at the T-th time interval on the transmission flow into a multi-layer perceptron for characterization to obtain a state feature vector, and input it into the spatial attention module based on the dynamic interleaved graph attention mechanism to obtain the graph attention spatial features.

5. The method according to claim 4, wherein The said Step 31 includes: Step 311: Read the graph attention spatio-temporal feature data packets respectively. Adopt a graph-structure-based modeling method to abstract the traffic sequence into nodes in the graph, and embed the load information in each node as the state information of the node. Connect the nodes in different ways. Establish a type of attribute connection for the traffic with a request-response relationship between encrypted traffic. Establish a type-two full connection for the encrypted traffic with an attribute connection between two encrypted traffic, and finally obtain multiple subgraphs related to graph attention spatio-temporal features. Step 312: Set a time threshold, and connect different nodes in the graph attention spatial feature-related graph according to the time threshold to obtain multiple graph attention spatio-temporal feature-related graphs. Each graph attention spatio-temporal feature-related graph is characterized by an adjacency matrix and a state feature matrix. Among them, the adjacency matrix represents the connectivity relationship of each node in the graph attention spatio-temporal feature-related graph, and the state feature matrix represents the state information embedded in each node of the graph attention spatio-temporal feature-related graph, that is, the length, direction, and data features of the load information embedded in each node.

6. The method according to claim 4, characterized in that, The said step 32 includes: Step 321: Input the state of the i-th graph attention spatio-temporal feature-related graph at time T into a multi-layer fully connected network for characterization to obtain a state feature vector. Step 322: According to the state feature vector, use the spatial attention module based on the dynamic interleaved graph attention mechanism to calculate the scaled dot product and attention scores, and finally calculate the graph attention spatial features.

7. The method according to claim 6, wherein The said step 321 includes: Extract the subgraph related to the graph attention spatio-temporal features of the i-th node at the T-th time interval from the graph attention spatio-temporal feature-related graph, and combine the feature matrix and the adjacency matrix into a state. Input the state into a K-layer fully connected network for characterization to obtain the state feature vector corresponding to the i-th node. The state feature vector is determined according to the activation function, the output of the (K - 1)-th layer fully connected network, and the weight matrix and bias vector of the K-th layer fully connected network.

8. The method according to claim 6, characterized in that, The said step 322 includes: Obtain the first scaled dot product according to the state feature vector, the number of hidden neurons in the graph attention layer of the spatial attention module, and the value parameters of the graph attention layer of the spatial attention module. Obtain the first attention score according to the first scaled dot product and the set of all adjacent nodes of each data stream in the graph attention spatio-temporal feature-related graph. Obtain the first graph attention spatio-temporal feature according to the first attention score, the number of attention functions of different linear mappings, and the keyword parameters of the graph attention layer of the spatial attention module. Obtain the second scaled dot product according to the first graph attention spatio-temporal feature, the keyword parameters of the spatial attention module based on dynamic interleaving, and the number of hidden neurons of the spatial attention module based on dynamic interleaving. Obtain the second attention score according to the second scaled dot product and the set of all adjacent nodes of each node in the graph attention spatio-temporal feature-related graph. Obtain the graph attention spatial feature according to the second attention score, the number of attention functions of different linear mappings, and the value parameters of the graph attention layer of the spatial attention module.

9. The method according to claim 1, wherein The said step 4 includes: Step 41: Extract multiple states from the graph attention spatio-temporal feature correlation graph of the i-th node from the 1st moment to the T-th moment and concatenate them to form a state sequence; Step 42: Perform dilated causal convolution on the state sequence. When calculating the convolution, perform interval sampling on the input to obtain the state sequence after sampling; According to the state sequence, normalize the weights in the dilated causal convolution module. The state sequence after sampling passes through the activation function and then outputs the mapped state sequence; Randomly select a part of the neurons from the hidden layer of the deep network for masking, update the other unmasked neurons through gradient descent, and then restore the masked neurons, whose weight values remain the same as before being masked; Step 43: Repeat the operation of Step 42 on the mapped state sequence to obtain the final state sequence. After adding it to the state sequence, obtain the tensor sequence output by the first layer of the temporal convolutional network; Step 44: Repeat the operations from Step 42 to Step 43 on the tensor sequence to perform dilated causal convolution. When calculating the convolution, perform interval sampling on the input to obtain the tensor sequence output by the second layer of the temporal convolutional network, that is, the overall output value of the temporal convolutional network; Step 45: Perform global max pooling and global average pooling on the tensor sequence output by the second layer of the temporal convolutional network. Concatenate the features output by the global max pooling and global average pooling, and use a fully connected layer to characterize the concatenated features to obtain the state temporal features; Step 46: Input the state temporal features, calculate the scaled dot product and attention scores using the spatio-temporal attention module based on the dynamic interleaved graph attention mechanism, and finally calculate the graph attention spatio-temporal features.

10. The method according to claim 9, characterized in that The said Step 46 includes: Obtain the third scaled dot product according to the state temporal features, the keyword parameters of the spatio-temporal attention module, and the number of hidden neurons in the graph attention layer of the spatio-temporal attention module; Obtain the third attention score according to the third scaled dot product and the set of all adjacent nodes of each node in the graph attention spatio-temporal feature correlation graph; Obtain the second graph attention spatio-temporal feature according to the third attention score, the number of attention functions of different linear mappings, and the value parameters of the graph attention layer of the spatio-temporal attention module; Obtain the fourth scaled dot product according to the third graph attention spatio-temporal feature, the number of hidden neurons in the spatio-temporal attention module based on dynamic interleaving, and the value parameters of the graph attention layer of the spatio-temporal attention module based on dynamic interleaving; Obtain the fourth attention score according to the fourth scaled dot product and the set of all adjacent nodes of each data stream in the graph attention spatio-temporal feature correlation graph; Obtain the graph attention spatio-temporal feature according to the fourth attention score, the number of attention functions of different linear mappings, and the keyword parameters of the graph attention layer of the spatio-temporal attention module.

11. The method according to claim 1, characterized in that, The said Step 5 includes: The concatenated graph attention spatio-temporal features and graph attention spatial features are input into the convolutional layer in the convolutional neural network. The results output by the convolutional layer are successively processed by batch normalization and activation functions, and then input into the convolutional layer again for processing. The processed results are subjected to residual connection with the concatenated results of the graph attention spatio-temporal features and graph attention spatial features. The results of the residual connection are input into the fully connected layer, and the behavior classification probability of the encrypted traffic of the mobile application is generated through the softmax function. By maximizing the behavior classification probability, the behavior classification result of the encrypted traffic of the mobile application is obtained.