Method and device for identifying service type based on DPI (Deep Packet Inspection)
By deploying domain names and multi-level directories on DPI cloud servers, using vector conversion and similarity matching, quickly identifying the service type of packets, solving the problem of inefficient identification in the existing technology, and achieving efficient processing and rapid execution of service types.
Patent Information
- Application Number
- CN202510725189.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, deep message detection DPI cloud servers are inefficient in identifying service types, and each time they identify the message type, they must be compared with all information in the feature library.
By deploying the domain name and multi-level directories of the DPI cloud server, pre-store the correspondence between packets and service types, use vector transformation and similarity matching to quickly identify the target service type, and obtain the service type through the DPI module identification attribute field when it is not matched.
It realizes efficient identification of service types for packets, reduces identification time, improves processing efficiency, and supports rapid execution of different service types.
Smart Images

Figure CN120263745A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of business identification, and in particular, to a method and device for identifying business types based on DPI. Background Art
[0002] At present, with the continuous development of cloud servers, deep packet inspection (DPI) cloud servers still use some business rules to identify business types. For example, they often identify the key information, purpose and other features of the message, and then compare them with the information stored in the feature library to directly identify the business type of the message.
[0003] The above method has great limitations. Each time the message type is identified, it must be compared with all the information in the feature library, which is inefficient.
[0004] Therefore, how to efficiently identify the service type of a message is a technical problem that needs to be solved. Summary of the invention
[0005] The purpose of the embodiments of the present application is to provide a method for identifying service types based on DPI. The technical solution of the embodiments of the present application can achieve the effect of efficiently identifying the service type of a message.
[0006] In a first aspect, an embodiment of the present application provides a method for identifying business types based on DPI, which is applied to a deep packet inspection DPI cloud server, including: a domain name and a multi-level directory for deploying the DPI cloud server, wherein the domain name or the multi-level directory includes a correspondence between the message and the business type, and the multi-level directory includes at least one of a three-level directory and a four-level directory; from the domain name or the multi-level directory, matching the target business type corresponding to the target message, wherein the target business type includes a voice business type or a video business type; when the target business type is not matched from the domain name or the multi-level directory, identifying the business type of the target message, and storing the business type of the target message in the DPI cloud server, wherein the business type of the target message is obtained by identifying the attribute field of the target message through the DPI module stored in the DPI cloud server.
[0007] In the above-mentioned embodiments of the present application, directories and domain names at all levels of the DPI cloud server are deployed in advance, and the correspondence between messages and business types is stored through the directories and domain names. When a new message is obtained, the new message is directly matched with the business type stored in the server directory and domain name to quickly obtain the business type, thereby achieving the effect of efficiently identifying the business type of the message.
[0008] In some embodiments, deploying the domain name and multi-level directories of the DPI cloud server includes: obtaining historical packets and the corresponding service types of the historical packets; constructing the domain name, three-level directory, and four-level directory of the DPI cloud server; storing the historical packets and the corresponding service types thereof under the domain name, three-level directory, or four-level directory.
[0009] In the above embodiments of the present application, by pre-deploying the domain name and multi-level directories in the DPI cloud server, the relationship between different packets and the corresponding service types can be pre-stored. When obtaining new packets, the corresponding service types can be quickly matched through the domain name and multi-level directories of the DPI cloud server.
[0010] In some embodiments, matching the target service type corresponding to the target packet from the domain name or multi-level directories includes: converting the target packet and the packets stored in the DPI cloud server into vectors; performing similarity matching between the vector corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server respectively to obtain multiple similarity values; selecting the matching packet corresponding to the vector with the maximum similarity among the multiple similarity values; using the service type corresponding to the matching packet as the target service type.
[0011] In the above embodiments of the present application, through the methods of vector conversion and similarity matching, the packets can be quickly matched with each other, and then the service type corresponding to the matched packet can be obtained as the service type of the target packet.
[0012] In some embodiments, identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server includes: identifying the attribute fields of the target packet through the DPI module stored in the DPI cloud server to obtain the service type of the target packet, where the attribute fields are preset fields for identifying packet types; storing the service type of the target packet under the domain name or multi-level directories.
[0013] In the above embodiments of the present application, the attributes of the packets stored in the DPI cloud server can be matched with the added attribute fields of the target packet to quickly obtain the service type of the target packet.
[0014] In some embodiments, when the target service type is not matched from the domain name or multi-level directories, after identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server, it further includes: identifying the target service type or the service type of the target packet; when the target service type or the service type of the target packet is a voice service, performing voice forwarding; when the target service type or the service type of the target packet is a video service, queuing and forwarding the video. In the above embodiments of the present application, different services perform different service operations, which can enable the services to be executed normally and reasonably.
[0015] In a second aspect, an embodiment of the present application provides an apparatus for identifying service types based on DPI, including: A deployment module, configured to deploy the domain name and multi-level directories of the DPI cloud server, where the domain name or multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of a three-level directory and a four-level directory; A matching module, configured to match the target service type corresponding to the target packet from the domain name or multi-level directories, where the target service type includes a voice service type or a video service type; An identification and storage module, configured to identify the service type of the target packet and store the service type of the target packet in the DPI cloud server when the target service type is not matched from the domain name or multi-level directories, where the service type of the target packet is obtained by the DPI module stored in the DPI cloud server to identify the attribute fields of the target packet.
[0016] Optionally, the deployment module is specifically configured to: Obtain historical packets and the service types corresponding to the historical packets; Construct the domain name, three-level directory, and four-level directory of the DPI cloud server; Store the historical packets and the service types corresponding to the historical packets under the domain name, three-level directory, or four-level directory.
[0017] Optionally, the matching module is specifically configured to: Convert the target packet and the packets stored in the DPI cloud server into vectors; Perform similarity matching on the vector corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server respectively to obtain multiple similarity values; Select the matching packet corresponding to the vector with the maximum similarity among the multiple similarity values; Use the service type corresponding to the matching packet as the target service type.
[0018] Optionally, the identification and storage module is specifically configured to: Identify the attribute fields of the target packet through the DPI module stored in the DPI cloud server to obtain the service type of the target packet, where the attribute fields are preset fields for identifying packet types; Store the service type of the target packet under the domain name or multi-level directories.
[0019] Optionally, the apparatus further includes: A service execution module, configured to, when the identification and storage module fails to match the target service type from a domain name or a multi-level directory, identify the service type of a target message, store the service type of the target message in a DPI cloud server, and then identify the target service type or the service type of the target message; When the target service type or the service type of the target message is a voice service, perform voice forwarding; When the target service type or the service type of the target message is a video service, queue and forward the video.
[0020] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory, where the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect above are run.
[0021] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the method provided in the first aspect above are run.
[0022] Other features and advantages of the present application will be described in the subsequent description, and some of them will become obvious from the description, or be understood by implementing the embodiments of the present application. Description of the Drawings
[0023] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a flowchart of a method for identifying a service type based on DPI provided by an embodiment of the present application; Figure 2 It is a flowchart of an implementation method for identifying a service type based on DPI provided by an embodiment of the present application; Figure 3 It is a schematic block diagram of a device for identifying a service type based on DPI provided by an embodiment of the present application; Figure 4 It is a structural schematic block diagram of a device for identifying a service type based on DPI provided by an embodiment of the present application. Detailed Embodiments
[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and shown in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.
[0026] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0027] First, some terms involved in the embodiments of the present application will be described to facilitate the understanding of those skilled in the art.
[0028] The DPI cloud server refers to a server deployed in the cloud using DPI technology (Deep Packet Inspection). The DPI technology is mainly used for in-depth analysis and detection of network traffic, identifying and processing application-layer data packets, so as to achieve refined management of network traffic.
[0029] URL (Uniform Resource Locator) is the unique address used to identify and locate resources on the Internet.
[0030] The present application is applied to the scenario of service identification. The specific scenario is that when processing a new packet service, it will first match with the packets stored in the pre-deployed DPI cloud server. When the match is successful, the corresponding service type is directly obtained. When the match is unsuccessful, the service type of the new packet is stored in the DPI cloud server for use in the next match.
[0031] Currently, with the continuous development of cloud servers, the DPI cloud server for deep packet inspection still identifies service types through some service rules. For example, after often identifying based on the key information, purpose, and other characteristics of the packet and comparing it with the information stored in the feature library, the service type of the packet is directly identified. The above method has great limitations. Every time the packet type is identified, it has to be compared with all the information in the feature library, and the efficiency is relatively low.
[0032] To this end, the present application deploys the domain name and multi-level directory of the DPI cloud server, wherein the domain name or multi-level directory includes the correspondence between the message and the service type, and the multi-level directory includes at least one of the three-level directory and the four-level directory; from the domain name or multi-level directory, the target service type corresponding to the target message is matched, wherein the target service type includes the voice service type or the video service type; when the target service type is not matched from the domain name or multi-level directory, the service type of the target message is identified, and the service type of the target message is stored in the DPI cloud server. Deploy the directories and domain names of the DPI cloud server at all levels in advance, store the correspondence between the message and the service type through the directory and domain name, and when a new message is obtained, directly match the new message with the service type stored in the server directory and domain name, quickly obtain the service type, and achieve the effect of efficiently identifying the service type of the message.
[0033] In an embodiment of the present application, the execution entity may be a DPI-based business type identification device in a DPI-based business type identification system. In actual applications, the DPI-based business type identification device may be electronic devices such as terminal devices and servers, and no limitation is made here.
[0034] Combine the following Figure 1 The method for identifying service types based on DPI in an embodiment of the present application is described in detail.
[0035] Please see Figure 1 , Figure 1 A flowchart of a method for identifying service types based on DPI provided in an embodiment of the present application is applied to a deep packet inspection DPI cloud server, such as Figure 1 The method for identifying the service type based on DPI includes: Step 110: Deploy the domain name and multi-level directory of the DPI cloud server.
[0036] The domain name or multi-level directory includes the correspondence between the message and the service type, and the multi-level directory includes at least one of a three-level directory and a four-level directory. The directory may also include a first-level directory and a second-level directory. The domain name may also include a top-level domain name (TLD), a second-level domain name (SLD), and a subdomain name, which may store message information and service types respectively.
[0037] In some embodiments of the present application, the domain name and multi-level directory of the DPI cloud server are deployed, including: obtaining historical messages and business types corresponding to the historical messages; constructing the domain name, third-level directory and fourth-level directory of the DPI cloud server; storing the historical messages and business types corresponding to the historical messages under the domain name, third-level directory or fourth-level directory URL.
[0038] In the above process of this application, by deploying domain names and multi-level directories in the DPI cloud server in advance, the mapping relationships between different packets and corresponding service types can be pre-stored. When obtaining new packets, the corresponding service type can be quickly matched through the domain name and multi-level directories of the DPI cloud server.
[0039] Among them, historical packets can be various cloud services, such as voice, telephone, video forwarding, etc. Storing historical packets and the service types corresponding to the historical packets under the domain name, three-level directory or four-level directory includes storing not only the packets and the service types corresponding to the packets, but also the attribute fields, labels and key information in the packets, etc. The key information can be words, fields or texts, etc.
[0040] Step 120: Match the target service type corresponding to the target packet from the domain name or multi-level directory.
[0041] Among them, the target service type includes a voice service type or a video service type, and can also include a confidence query service or a telephone transfer service, etc.
[0042] In some embodiments of this application, matching the target service type corresponding to the target packet from the domain name or multi-level directory includes: converting the target packet and the packets stored in the DPI cloud server into vectors; respectively performing similarity matching between the vector corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server to obtain multiple similarity values; selecting the matching packet corresponding to the vector with the maximum similarity among the multiple similarity values; using the service type corresponding to the matching packet as the target service type.
[0043] In the above process of this application, through the methods of vector conversion and similarity matching, the matching of packets and packets can be quickly performed, and then the service type corresponding to the matched packet is used as the service type of the target packet.
[0044] Among them, performing similarity matching between the vector corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server can use the method of cosine similarity calculation, and the maximum similarity value is obtained through cross-entropy loss.
[0045] Optionally, after matching the target service type corresponding to the target packet from the domain name or multi-level directory, Figure 1 The method shown also includes: sending the target service type to the corresponding execution device, and executing the target service through the execution device. Among them, the execution device can be any server and terminal device. The execution device only obtains the execution result of a service type and executes the corresponding task according to the service type. The process of identifying the service type can be executed by the DPI cloud server, reducing the identification time.
[0046] Step 130: When the target service type is not matched from the domain name or multi-level directory, identify the service type of the target message and store the service type of the target message in the DPI cloud server.
[0047] Among them, the service type of the target message is obtained by the DPI module stored in the DPI cloud server to identify the attribute fields of the target message.
[0048] In some embodiments of the present application, identifying the service type of the target message and storing the service type of the target message in the DPI cloud server includes: identifying the attribute fields of the target message by the DPI module stored in the DPI cloud server to obtain the service type of the target message, where the attribute fields are preset fields for identifying the message type; storing the service type of the target message under the domain name or multi-level directory.
[0049] In the above process of the present application, the attributes of the message stored in the DPI cloud server can be matched with the added attribute fields of the target message to quickly obtain the service type of the target message.
[0050] Among them, identifying the service type of the target message can directly input the service type in the DPI cloud server when the target message is uploaded, or can identify the key information of the target message and match it with the service type to obtain the service type. Storing the service type of the target message under the domain name or multi-level directory can store the message information, attribute fields, key information, etc. of the target message together with the corresponding service type under the domain name or each level directory of the DPI cloud server.
[0051] In some embodiments of the present application, after identifying the service type of the target message and storing the service type of the target message in the DPI cloud server when the target service type is not matched from the domain name or multi-level directory, Figure 1 The method shown also includes: identifying the target service type or the service type of the target message; when the target service type or the service type of the target message is a voice service, perform voice forwarding; when the target service type or the service type of the target message is a video service, queue the video for forwarding. In the above process of the present application, different services perform different service operations, which can enable the services to be executed normally and reasonably.
[0052] Among them, the voice service requires timeliness and cannot have delays, so it can be given priority in execution. Video forwarding can be queued for forwarding and executed at the end of other services.
[0053] In the above Figure 1In the process shown, the present application deploys the domain name and multi-level directories of the DPI cloud server, where the domain name or multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of three-level directories and four-level directories; match the target service type corresponding to the target packet from the domain name or multi-level directories, where the target service type includes a voice service type or a video service type; when the target service type is not matched from the domain name or multi-level directories, identify the service type of the target packet and store the service type of the target packet in the DPI cloud server. By deploying the various levels of directories and domain names of the DPI cloud server in advance, storing the correspondence between packets and service types through the directories and domain names, when a new packet is obtained, directly match the new packet with the service types stored in the server directories and domain names, quickly obtain the service type, and achieve the effect of efficiently identifying the service type of the packet.
[0054] Next, Figure 2 a detailed description will be given to the implementation method of identifying service types based on DPI in the embodiments of the present application.
[0055] Please refer to Figure 2 , Figure 2 which is a flowchart of an implementation method of identifying service types based on DPI provided by the embodiments of the present application. As Figure 2 shown, the implementation method of identifying service types based on DPI includes: Step 210: Server deployment.
[0056] Specifically: Deploy the domain name and multi-level directories of the DPI cloud server.
[0057] Step 220: Whether the target service type corresponding to the target packet is matched.
[0058] Specifically: If the target service type is matched from the domain name or multi-level directories, go to step 240; if not, go to step 210.
[0059] Step 230: Identify the service and store the service type.
[0060] Specifically: When the target service type is not matched from the domain name or multi-level directories, identify the service type of the target packet and store the service type of the target packet in the DPI cloud server.
[0061] Step 240: Execute the service.
[0062] Specifically: Send the target service type to the corresponding execution device, and the execution device executes the target service.
[0063] In addition, Figure 2 the specific methods and steps shown can be referred to Figure 1 the method shown, and details will not be elaborated here.
[0064] As described above Figure 1 - Figure 2 a method for identifying service types based on DPI is described. Next, a device for identifying service types based on DPI will be described in conjunction with Figure 3 - Figure 4 the following.
[0065] Please refer to Figure 3 , which is a schematic block diagram of a device 300 for identifying service types based on DPI provided in an embodiment of the present application. The device 300 may be a module, a program segment, or code on an electronic device. The device 300 corresponds to the above Figure 1 method embodiment and can execute Figure 1 each step involved in the method embodiment. The specific functions of the device 300 can be seen in the following description. To avoid repetition, the detailed description is appropriately omitted here.
[0066] Optionally, the device 300 includes: A deployment module 310, configured to deploy the domain name and multi-level directories of the DPI cloud server, where the domain name or multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of a three-level directory and a four-level directory; A matching module 320, configured to match the target service type corresponding to the target packet from the domain name or multi-level directories, where the target service type includes a voice service type or a video service type; An identification and storage module 330, configured to identify the service type of the target packet and store the service type of the target packet in the DPI cloud server when the target service type is not matched from the domain name or multi-level directories, where the service type of the target packet is obtained by the DPI module stored in the DPI cloud server to identify the attribute fields of the target packet.
[0067] Optionally, the deployment module is specifically configured to: Obtain historical packets and the service types corresponding to the historical packets; construct the domain name, three-level directory, and four-level directory of the DPI cloud server; store the historical packets and the service types corresponding to the historical packets under the domain name, three-level directory, or four-level directory.
[0068] Optionally, the matching module is specifically configured to: Convert the target packet and the packets stored in the DPI cloud server into vectors; perform similarity matching on the vectors corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server respectively to obtain multiple similarity values; select the matching packet corresponding to the vector with the maximum similarity among the multiple similarity values; use the service type corresponding to the matching packet as the target service type.
[0069] Optionally, the identification and storage module is specifically configured to: The DPI module stored in the DPI cloud server identifies the attribute fields of the target packet to obtain the service type of the target packet, where the attribute fields are preset fields for identifying the packet type; the service type of the target packet is stored under a domain name or a multi-level directory.
[0070] Optionally, the device further includes: A service execution module, configured to, when the identification and storage module fails to match the target service type from the domain name or the multi-level directory, identify the service type of the target packet, and after storing the service type of the target packet in the DPI cloud server, identify the target service type or the service type of the target packet; when the target service type or the service type of the target packet is a voice service, perform voice forwarding; when the target service type or the service type of the target packet is a video service, queue and forward the video.
[0071] Please refer to Figure 4 FIG. is a schematic structural diagram of a device for identifying a service type based on DPI provided in an embodiment of the present application. The device may include a memory 410 and a processor 420. Optionally, the device may further include: a communication interface 430 and a communication bus 440. The device corresponds to the above Figure 1 method embodiment and is capable of executing Figure 1 each step involved in the method embodiment. The specific functions of the device can be seen in the following description.
[0072] Specifically, the memory 410 is used to store computer-readable instructions.
[0073] The processor 420 is configured to process the readable instructions stored in the memory and is capable of executing Figure 1 each step in the method.
[0074] The communication interface 430 is used to communicate signaling or data with other node devices. For example: used for communication with a server or a terminal, or for communication with other device nodes. The embodiments of the present application are not limited to this.
[0075] The communication bus 440 is used to implement direct connection communication between the above components.
[0076] Among them, the communication interface 430 of the device in the embodiment of the present application is used to communicate signaling or data with other node devices. The memory 410 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 410 may further be at least one storage device located far from the aforementioned processor. The memory 410 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 420, the electronic device executes the above Figure 1The method process shown. The processor 420 can be used on the device 300 and is used to execute the functions in this application. Exemplarily, the above-mentioned processor 420 can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The embodiments of this application are not limited thereto.
[0077] The embodiments of this application also provide a readable storage medium. When the computer program is executed by a processor, it executes the method process executed by the electronic device in the method embodiment shown as Figure 1 shown.
[0078] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the above-described device can refer to the corresponding process in the foregoing method, and will not be elaborated herein.
[0079] In summary, the embodiments of this application provide a method and a device for identifying a service type based on DPI. The method includes deploying the domain name and multi-level directories of the DPI cloud server, where the domain name or multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of a three-level directory and a four-level directory; matching the target service type corresponding to the target packet from the domain name or multi-level directories, where the target service type includes a voice service type or a video service type; when the target service type is not matched from the domain name or multi-level directories, identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server, where the service type of the target packet is obtained by the DPI module stored in the DPI cloud server identifying the attribute fields of the target packet. Through this method, the effect of efficiently identifying the service type of the packet can be achieved.
[0080] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0081] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0082] If the described functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.
[0083] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0084] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered within the protection scope of the present application.
[0085] It should be noted that in this text, relative terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
Claims
1. A method for identifying service types based on DPI, characterized in that, Applied to a deep packet inspection (DPI) cloud server, including: Deploying the domain name and multi-level directories of the DPI cloud server, where the domain name or the multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of three-level directories and four-level directories; Matching the target service type corresponding to the target packet from the domain name or the multi-level directories, where the target service type includes a voice service type or a video service type; When the target service type is not matched from the domain name or the multi-level directories, identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server, where the service type of the target packet is obtained by the DPI module stored in the DPI cloud server to identify the attribute fields of the target packet; Storing the service type of the target packet under the domain name or the multi-level directories.
2. The method according to claim 1, characterized in that The deploying the domain name and multi-level directories of the DPI cloud server includes: Obtaining historical packets and the service types corresponding to the historical packets; Constructing the domain name, three-level directories and four-level directories of the DPI cloud server; Storing the historical packets and the service types corresponding to the historical packets under the domain name, the three-level directories or the four-level directories.
3. The method according to claim 1 or 2, characterized in that, The matching the target service type corresponding to the target packet from the domain name or the multi-level directories includes: Converting the target packet and the packets stored in the DPI cloud server into vectors; Performing similarity matching on the vector corresponding to the target packet and the vectors corresponding to the packets stored in the DPI cloud server respectively to obtain a plurality of similarity values; Selecting the matching packet corresponding to the vector with the maximum similarity among the plurality of similarity values; Taking the service type corresponding to the matching packet as the target service type.
4. The method according to claim 1 or 2, characterized in that, Identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server includes: Identifying the attribute fields of the target packet through the DPI module stored in the DPI cloud server to obtain the service type of the target packet, where the attribute fields are preset fields for identifying packet types; Storing the service type of the target packet under the domain name or the multi-level directories.
5. The method according to claim 1 or 2, characterized in that, After the step of, when the target service type is not matched from the domain name or the multi-level directories, identifying the service type of the target packet and storing the service type of the target packet in the DPI cloud server, the method further includes: Identifying the target service type or the service type of the target packet; When the target service type or the service type of the target packet is a voice service, performing voice forwarding; When the target service type or the service type of the target packet is a video service, queuing and forwarding the video.
6. An apparatus for identifying service types based on DPI, characterized in that, Including: A deployment module, configured to deploy the domain name and multi-level directories of the DPI cloud server, where the domain name or the multi-level directories include the correspondence between packets and service types, and the multi-level directories include at least one of three-level directories and four-level directories; A matching module, configured to match a target service type corresponding to a target message from the domain name or the multi-level directory, where the target service type includes a voice service type or a video service type; An identification and storage module, configured to identify the service type of the target message and store the service type of the target message in the DPI cloud server when the target service type is not matched from the domain name or the multi-level directory, where the service type of the target message is obtained by the DPI module stored in the DPI cloud server to identify the attribute fields of the target message.
7. The device according to claim 6, wherein The deployment module is specifically configured to: Obtain historical messages and the service types corresponding to the historical messages; Construct the domain name, the three-level directory, and the four-level directory of the DPI cloud server; Store the historical messages and the service types corresponding to the historical messages under the domain name, the three-level directory, or the four-level directory.
8. The device according to claim 6 or 7, characterized in that, The matching module is specifically configured to: Convert the target message and the messages stored in the DPI cloud server into vectors; Perform similarity matching between the vector corresponding to the target message and the vectors corresponding to the messages stored in the DPI cloud server respectively to obtain a plurality of similarity values; Select the matching message corresponding to the vector with the maximum similarity among the plurality of similarity values; Use the service type corresponding to the matching message as the target service type.
9. The device according to claim 6 or 7, characterized in that The identification and storage module is specifically configured to: Identify the attribute fields of the target message through the DPI module stored in the DPI cloud server to obtain the service type of the target message, where the attribute fields are preset fields for identifying the message type; Store the service type of the target message under the domain name or the multi-level directory.
10. The device according to claim 6 or 7, characterized in that, The apparatus further includes: A service execution module, configured to, after the identification and storage module identifies the service type of the target message and stores the service type of the target message in the DPI cloud server when the target service type is not matched from the domain name or the multi-level directory, identify the target service type or the service type of the target message; When the target service type or the service type of the target message is a voice service, perform voice forwarding; When the target service type or the service type of the target message is a video service, queue and forward the video.
Citation Information
Patent Citations
Message service type identifying method and message service type identifying device based on data processing installation (DPI)
CN103023670A
Deep packet inspection method, device and system for cloud terminal Wi-fi system
CN104618231A
Method for judging malicious traffic attack types based on vectorization
CN111191767A
Traffic service identification method, device and equipment and computer storage medium
CN112565106A
Traffic identification method, apparatus and device, and computer storage medium
CN115842788A