Traffic identification method, traffic identification model training method and related equipment
By extracting feature vectors from the target traffic data and comparing the fingerprint features of IoT devices, the problem of IoT device recognition method dependence on the environment is solved, and efficient and accurate identification is achieved, which is suitable for the DNS system network environment.
Patent Information
- Application Number
- CN202410033754.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-09
- Publication Date
- 2025-07-11
AI Technical Summary
Existing IoT device identification methods require a special applicable environment, and poor network instructions and device reliability.
By extracting the target feature vector from the target traffic data, comparing it with the fingerprint features of the Internet of Things device, it determines whether the target traffic data is related, and it is recognized in a way that does not require a connection to the target device.
Improves identification efficiency and accuracy, suitable for any DNS-based network environment, avoiding the impact on network quality and device reliability.
Smart Images

Figure CN120301609A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer and communication technologies, and in particular, to a traffic identification method, a training method for a traffic identification model, and related devices. Background Art
[0002] With the popularization of Internet of Things (IoT) devices and the rapid application of IoT technologies, IoT devices and technologies are widely used in scenarios such as smart home, smart healthcare, intelligent transportation, intelligent building, and smart city. The IoT has brought convenience to human life, but due to in-network communication, many network security problems have also arisen. Most IoT devices do not have sufficient security protection mechanisms, so centralized management is required.
[0003] Traditional IoT management systems generally use activation detection and active scanning methods to identify IoT devices. They need to establish a connection with the target device, require a special applicable environment, and are likely to affect network quality and device reliability. Summary of the Invention
[0004] Embodiments of the present application provide a traffic identification method, a training method for a traffic identification model, and related devices, which can at least to some extent overcome the problems that the existing IoT device identification methods require a special applicable environment, and have poor network instructions and device reliability.
[0005] Other features and advantages of the present application will become apparent through the following detailed description, or be learned in part through the practice of the present application.
[0006] According to one aspect of the embodiments of the present application, a traffic identification method is provided, including: extracting a target feature vector from target traffic data, where the target traffic data is traffic data collected by a target client from a target device; comparing the target feature vector with the fingerprint feature of an IoT device to obtain a similarity degree; and determining whether the target traffic data is related to the IoT device according to the similarity degree.
[0007] According to one aspect of the embodiments of the present application, a method for training a traffic recognition model is provided. The traffic recognition model is used to perform the traffic recognition method as described above. The method for training the traffic recognition model specifically includes: obtaining a set of predetermined traffic data training samples, where the set of predetermined traffic data training samples includes a plurality of predetermined traffic data training samples, and each predetermined traffic data training sample is marked as coming from an Internet of Things device; inputting the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from the Internet of Things device, and obtaining the fingerprint features of the Internet of Things device; obtaining a set of predetermined traffic data test samples, where the set of predetermined traffic data test samples includes a plurality of predetermined traffic data test samples, and each predetermined traffic data test sample is marked with a label indicating whether it comes from the Internet of Things device; inputting the predetermined traffic data test samples into the traffic recognition model one by one for testing, and obtaining a test result, where the test result includes whether the trained traffic recognition model passes the test.
[0008] According to one aspect of the embodiments of the present application, a traffic recognition device is provided. The traffic recognition device includes: a vector extraction module, configured to extract a target feature vector from target traffic data, where the target traffic data is traffic data collected by a target client from a target device; a feature comparison module, configured to compare the target feature vector with the fingerprint features of the Internet of Things device to obtain a similarity degree; and a similarity determination module, configured to determine whether the target traffic data is related to the Internet of Things device according to the similarity degree.
[0009] According to one aspect of the embodiments of the present application, a device for training a traffic recognition model is provided. The device for training the traffic recognition model includes: a training sample acquisition module, configured to obtain a set of predetermined traffic data training samples, where the set of predetermined traffic data training samples includes a plurality of predetermined traffic data training samples, and each predetermined traffic data training sample is marked as coming from an Internet of Things device; a training sample input module, configured to input the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from the Internet of Things device, and obtaining the fingerprint features of the Internet of Things device; a test sample acquisition module, configured to obtain a set of predetermined traffic data test samples, where the set of predetermined traffic data test samples includes a plurality of predetermined traffic data test samples, and each predetermined traffic data test sample is marked with a label indicating whether it comes from the Internet of Things device; and a test sample input module, configured to input the predetermined traffic data test samples into the traffic recognition model one by one for testing, and obtaining a test result, where the test result includes whether the trained traffic recognition model passes the test.
[0010] According to one aspect of the embodiments of the present application, there is provided a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processor, it implements the traffic identification method or the training method of the traffic identification model as described in the above embodiments.
[0011] According to one aspect of the embodiments of the present application, there is provided an electronic device, including: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the traffic identification method or the training method of the traffic identification model as described in the above embodiments.
[0012] In the technical solutions provided by some embodiments of the present application, after collecting traffic data through a target client, corresponding target feature vectors are extracted from the target traffic data and compared with the fingerprint features of existing Internet of Things devices to obtain a similarity degree. According to this similarity degree, it is determined whether the target data traffic is related to the Internet of Things device. Compared with traditional activation detection and active scanning methods, the embodiments of the present application do not need to establish a connection with the target device, only need the traffic data from the target device, and this traffic data from the target device can be collected through the target client, which can avoid affecting the network quality and device reliability, and is applicable to any network environment based on the DNS system, with high environmental adaptability. At the same time, the present application determines whether the target traffic data is related to the Internet of Things device by comparing the target feature vector with the fingerprint features of the Internet of Things device, with high accuracy, and at the same time, the computing power consumed is not much, and the recognition efficiency is high.
[0013] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. Brief Description of the Drawings
[0014] The accompanying drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application. Obviously, the accompanying drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts. In the drawings:
[0015] Figure 1 Shows a schematic diagram of an exemplary system architecture to which the technical solutions of the embodiments of the present application can be applied;
[0016] Figure 2 Shows a flowchart of a traffic identification method provided by an embodiment of the present application.
[0017] Figure 3 The flowchart shows a method for training a traffic recognition model provided by an embodiment of the present application.
[0018] Figure 4 It shows according to Figure 3 A specific implementation flowchart of step S200 in the method for training a traffic recognition model shown in the corresponding embodiment.
[0019] Figure 5 It shows according to Figure 4 A specific implementation flowchart of step S210 in the method for training a traffic recognition model shown in the corresponding embodiment.
[0020] Figure 6 It shows according to Figure 3 A specific implementation flowchart of step S400 in the method for training a traffic recognition model shown in the corresponding embodiment.
[0021] Figure 7 It shows according to Figure 6 A specific implementation flowchart of step S410 in the method for training a traffic recognition model shown in the corresponding embodiment.
[0022] Figure 8 It shows according to Figure 6 A specific implementation flowchart of step S430 in the method for training a traffic recognition model shown in the corresponding embodiment.
[0023] Figure 9 The structural schematic diagram of a traffic recognition device provided by an embodiment of the present application.
[0024] Figure 10 The structural schematic diagram of a traffic recognition device provided by an embodiment of the present application.
[0025] Figure 11 The structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0026] Now, example embodiments will be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this application will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art.
[0027] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application may be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.
[0028] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0029] The flowcharts shown in the drawings are only exemplary illustrations and do not necessarily include all contents and operations / steps, nor do they necessarily need to be executed in the described order. For example, some operations / steps may be decomposed, while some operations / steps may be combined or partially combined, so the actual execution order may change according to the actual situation.
[0030] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solutions of the embodiments of the present application can be applied is shown.
[0031] As Figure 1 shown, the system architecture may include terminal devices (such as Figure 1 one or more of the smart phone 101, tablet computer 102, and portable computer 103 shown in
[0032] should be understood that Figure 1 the number of terminal devices, networks, and servers in
[0033] A user can use a terminal device to interact with a server 105 via a network 104 to receive or send messages, etc. The server 105 can be a server that provides various services. For example, the user uses a terminal device 103 (which can also be terminal device 101 or 102) to upload target traffic data to the server 105. The server 105 can extract a target feature vector from the target traffic data, where the target traffic data is traffic data collected by a target client from a target device; compare the target feature vector with the fingerprint feature of an Internet of Things device to obtain a similarity degree; and determine whether the target traffic data is related to the Internet of Things device according to the similarity degree.
[0034] It should be noted that the traffic identification method provided by the embodiments of the present application is generally executed by the server 105. Correspondingly, the traffic identification device is generally arranged in the server 105. However, in other embodiments of the present application, the terminal device can also have a similar function to the server, so as to execute the traffic identification solution provided by the embodiments of the present application.
[0035] The implementation details of the technical solutions of the embodiments of the present application are elaborated in detail below:
[0036] Figure 2 The flowchart of a traffic identification method according to an embodiment of the present application is shown. The traffic identification method can be executed by a server, and the server can be Figure 1 the server shown in
[0037] Referring to Figure 2 shown, the traffic identification method at least includes:
[0038] Step S102: Extract a target feature vector from the target traffic data, where the target traffic data is traffic data collected by a target client from a target device.
[0039] Step S104: Compare the target feature vector with the fingerprint feature of the Internet of Things device to obtain a similarity degree.
[0040] Step S106: Determine whether the target traffic data is related to the Internet of Things device according to the similarity degree.
[0041] In the embodiments of the present application, after collecting traffic data through the target client, the corresponding target feature vector is extracted from the target traffic data and compared with the fingerprint features of existing Internet of Things devices to obtain the similarity degree. According to this similarity degree, it is determined whether the target data traffic is related to the Internet of Things device. Compared with traditional activation detection and active scanning methods, the embodiments of the present application do not need to establish a connection with the target device, and only need the traffic data from the target device. The traffic data from the target device can be collected through the target client, which can avoid affecting the network quality and device reliability, and is applicable to any network environment based on the DNS system, with high environmental adaptability. At the same time, the present application determines whether the target traffic data is related to the Internet of Things device by comparing the target feature vector with the fingerprint features of the Internet of Things device, with high accuracy, and at the same time, the computing power consumed is not much, and the recognition efficiency is high.
[0042] In step S102, the traffic data from the target device collected through the target client enables the server to obtain the traffic data from the target device during operation without connecting to the target device, which can avoid affecting the network quality and device reliability.
[0043] Specifically, the server collects the DNS traffic from the target device through the target client C(j) in the time window T(t), and extracts the feature vector F c (j) = [f1(j), f2(j), …, f m (j)]. Where f m (j) represents how many different domain names the client has queried within the time period T(t), and the position of the domain name in the m-th position of the feature vector.
[0044] After de-duplicating the feature vector F c (j) = [f1(j), f2(j), …, f m (j)], the target feature vector is obtained.
[0045] In step S104, the target feature vector is compared with the fingerprint features P(k) of all Internet of Things devices to obtain the similarity degree between them. The similarity degree can be represented by a similarity level or a similarity value, and its calculation method can be calculated using distance measurement methods such as cosine distance or Euclidean distance.
[0046] Specifically, in some embodiments, the specific implementation manner of step S102 can refer to the following embodiments. This embodiment is based on Figure 2Details of step S102 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S102 may include the following steps:
[0047] Based on the target feature vector, obtain the fingerprint feature of the target traffic data.
[0048] Compare the fingerprint feature of the target traffic data with the fingerprint feature of the IoT device to obtain the degree of similarity.
[0049] In this embodiment, based on the target feature vector, the fingerprint feature of the target traffic data can be obtained, and then the degree of similarity can be obtained through the comparison between the fingerprint feature of the target traffic data and the fingerprint feature of the IoT device.
[0050] In step S106, if the similarity between the target feature vector and the fingerprint feature is higher, it is more likely to be related to the IoT device.
[0051] Specifically, in some embodiments, the specific implementation of step S102 can refer to the following embodiments. This embodiment is based on Figure 2 Details of step S102 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S102 may include the following steps:
[0052] Based on the degree of similarity, determine whether the target traffic data is potentially matched with the IoT device.
[0053] If the target traffic data is potentially matched with the IoT device, then based on specific information, identify whether the target traffic data is related to the IoT device.
[0054] In this embodiment, if the similarity between the target feature vector and the fingerprint feature of one of the IoT devices is higher than a predefined threshold, it is considered that there is a potential match for the target traffic data at this time, that is, whether the target traffic data is potentially matched with the IoT device.
[0055] For all target feature vectors whose similarity exceeds the predefined threshold, further verification is required to determine whether the match is valid.
[0056] Specifically, special control messages or TCP connections with the target device can be used to perform additional identification and verification. If the match is confirmed to be credible during the verification process, the target device can be marked as part of the specific IoT device.
[0057] Figure 3The flowchart of the training method of the traffic recognition model according to an embodiment of the present application is shown. The training method of the traffic recognition model can be executed by a server, and the server can be the Figure 1 server shown in Figure 4 As shown, the traffic recognition model is used to execute the traffic recognition method as described above. The training method of the traffic recognition model specifically includes:
[0058] Step S100: Obtain a set of training samples of predetermined traffic data. The set of training samples of predetermined traffic data contains multiple training samples of predetermined traffic data, and each training sample of predetermined traffic data is labeled as coming from an IoT device.
[0059] Step S200: Input the training samples of the predetermined traffic data into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the training samples of the predetermined traffic data come from an IoT device, and obtain the fingerprint features of the IoT device.
[0060] Step S300: Obtain a set of test samples of predetermined traffic data. The set of test samples of predetermined traffic data contains multiple test samples of predetermined traffic data, and each test sample of predetermined traffic data is labeled as coming from an IoT device.
[0061] Step S400: Input the test samples of the predetermined traffic data into the traffic recognition model one by one for testing, and obtain a test result. The test result includes whether the trained traffic recognition model passes the test.
[0062] In the embodiment of the present application, the traffic recognition model is used to execute Figure 2 the traffic recognition method shown in Figure 2 That is, steps S102, S104, and S106 in
[0063] Specifically, the training method of the traffic recognition model includes a training stage and a testing stage, and corresponding training sample sets and test sample sets are used respectively.
[0064] First, perform the training stage. In the training stage, use the training sample set, that is, the set of training samples of predetermined traffic data. The set of training samples of predetermined traffic data contains multiple training samples of predetermined traffic data, and each training sample of predetermined traffic data is a white sample, that is, it is labeled as coming from an IoT device.
[0065] Input the above-mentioned training samples of the predetermined traffic data into the traffic recognition model one by one for multiple rounds of unsupervised learning training until the results output by the traffic recognition model for a predetermined proportion of the training samples of the predetermined traffic data are that the training samples of the predetermined traffic data come from an IoT device. At this time, the traffic recognition model has learned the features of the traffic data from the IoT device.
[0066] At this time, the testing phase is carried out. In the testing phase, a testing sample set is used, that is, a predetermined traffic data testing sample set. The predetermined traffic data testing sample set includes multiple predetermined traffic data testing samples, and each predetermined traffic data testing sample is a white sample, that is, it is marked as coming from an Internet of Things device.
[0067] The above-mentioned predetermined traffic data testing samples are input into the traffic recognition model one by one for testing. At this time, the traffic recognition model outputs a similarity degree, which is the similarity degree between the predetermined traffic data testing sample and the characteristics of the traffic data from the Internet of Things device it has learned.
[0068] Among them, if the similarity degree output by the traffic recognition model is not less than the detection threshold, it is determined that the trained traffic recognition model fails the test; if the similarity degree output by the traffic recognition model is less than the detection threshold, it is determined that the trained traffic recognition model passes the test. After the trained traffic recognition model passes the test, the trained traffic recognition model is obtained.
[0069] It should be noted that in the above embodiments, each predetermined traffic data training sample and each predetermined traffic data testing sample correspond to the traffic of the Internet of Things device within a time period T(t).
[0070] Specifically, in some embodiments, the specific implementation manner of step S200 can refer to Figure 4 . Figure 4 It is based on Figure 3 The details of step S200 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S200 may include the following steps:
[0071] Step S210: Input the predetermined traffic data training samples into the traffic recognition model one by one to obtain the fingerprint features corresponding to the predetermined traffic data training samples.
[0072] Step S220: Determine whether the predetermined traffic data training samples come from the Internet of Things device according to the fingerprint features corresponding to the predetermined traffic data training samples.
[0073] Step S230: Train the traffic recognition model according to the result determined by the traffic recognition model and the labels of the predetermined traffic data testing samples until the predetermined training end condition is reached to obtain the fingerprint features of the Internet of Things device.
[0074] In an embodiment of the present application, after a predetermined traffic data training sample is input into the traffic recognition model one by one, the traffic recognition model will obtain the fingerprint features corresponding to the predetermined traffic data training sample, and then determine whether the predetermined traffic data training sample comes from an IoT device according to the fingerprint features. The fingerprint features of traffic data from different devices are different. According to the confirmed result and the marked label, the traffic recognition model is trained until it reaches the predetermined training end condition and the training is ended. At this time, the traffic recognition model has learned the fingerprint features of the traffic data from the IoT device, that is, the fingerprint features of the IoT device are obtained.
[0075] In step S210, each predetermined traffic data training sample corresponds to the traffic of an IoT device within a time period T(t), and the traffic recognition model can extract the domain names queried within the corresponding time period T(t) in the predetermined traffic data training sample.
[0076] Specifically, in some embodiments, the specific implementation manner of step S210 can refer to Figure 5 . Figure 5 It is based on Figure 4 the detailed description of step S210 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S210 may include the following steps:
[0077] Step S212, determine the time window and the target domain name corresponding to the predetermined traffic data training sample according to the sample feature vector.
[0078] Step S214, determine the query probability and the inverse document frequency corresponding to the target domain name.
[0079] In this embodiment, each predetermined traffic data training sample corresponds to the traffic of an IoT device within a time period T(t), and the traffic recognition model will first extract the sample feature vector F(k)=[f1(k), f2(k),…, f m (k)] in the predetermined traffic data training sample, where f m (k) represents how many different domain names q(kj) the device has queried in total within the time period T(l), and the positions of these domain names are at the mth position in the feature vector. Then, the domain names queried by the predetermined traffic data training sample within the corresponding time period T(t) can be obtained from the sample feature vector F(k), and then the query probability and the inverse document frequency (IDF) corresponding to each domain name are determined.
[0080] In step S212, to identify the device by analyzing the DNS traffic data queries of the IoT device within a certain period of time, the traffic data needs to be segmented into several non-overlapping segments of traffic according to the time window first.
[0081] For example, if the time period T(l) is divided into non - overlapping time windows of length w, then the number of time windows N(w) is expressed as
[0082]
[0083] where represents the floor function. The meaning of this expression is to divide the given time period T(l) into time windows of length w and calculate the number of all possible time windows.
[0084] It should be noted that since a non - overlapping method is adopted here, the last segment may be less than a complete time window, and a rounding operation is required to ensure the correct result.
[0085] After obtaining the time windows, the sample feature vectors F(k)=[f1(k), f2(k),…, f m (k)] in the predetermined traffic data training samples can be extracted according to the time windows, and the corresponding domain names of the queries can be obtained.
[0086] Calculating f m (k) can use the following formula:
[0087]
[0088] where loc(q(kj)) represents the position of the query domain name loc(q(kj)) in the feature vector, and if the position is exactly m, the value in the square brackets is 1, otherwise it is 0. The finally obtained f m (k)) represents how many query domain names of this device are in the m - th position of the feature vector within the time period T(l).
[0089] In some embodiments, the domain names queried in the corresponding time period T(t) in the sample feature vector F(k) may be repeated, so a deduplication process is required. This deduplication process can be completed when extracting the feature vector or when extracting the domain names.
[0090] In step S214, after obtaining the domain names queried in different time windows, the number of times each domain name is queried can be statistically calculated, and then the query probability and inverse document frequency can be obtained.
[0091] Specifically, in some embodiments, the specific implementation manner of step S214 can refer to the following embodiments. This embodiment is a detailed description of step S214 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S214 may include the following steps: Figure 4
[0092] Determine the number of times each of the target domain names is queried.
[0093] Determine the query probability of each of the target domain names according to the number of times each of the target domain names is queried.
[0094] Determine the inverse document frequency of each of the target domain names according to the number of times each of the target domain names is queried.
[0095] In this embodiment, if the Internet of Things device queries m(k) different domain names q(kj) within the time period T(l) and obtains the feature vectors related to the queried domain names in each time window, then the query times Q(k) within this time period can be calculated by summing up the feature vectors in all time windows. Specifically, the formula for calculating Q(k) can be expressed as:
[0096]
[0097] After obtaining the query times Q(k) of each target domain name in each time window, the probability that it is queried at least once by the Internet of Things device in each time window can be determined, that is, its corresponding query probability. The calculation method of the query probability p(kj) can refer to the following formula:
[0098]
[0099] Among them, Q(kj) represents the number of times of querying the domain name q(kj) within the time period T(l). The meaning of this formula is that when the Internet of Things device makes Q(kj) queries, each query has a probability of 1 / w of hitting within a time window of length w. Therefore, the probability of not querying this domain name in all time windows is Furthermore, the probability that this domain name is queried at least once can be obtained, that is, the query probability p(kj).
[0100] The inverse document frequency of each domain name queried by the Internet of Things device is used to evaluate the "popularity" of each domain name in the global DNS query.
[0101] Specifically, the inverse document frequency of a queried domain name q(kj) can be calculated in the following way:
[0102]
[0103] Among them, N represents the total number of queries of the target domain name q(kj) that appear in all the same Internet of Things devices, and n j represents the total number of queries of the target domain name q(kj) that appear in all different Internet of Things devices. Here, It can also be interpreted as the ratio of the number of documents in which a target domain name is located (i.e., the number of all identical Internet of Things devices) to the total number of documents (i.e., the number of all different Internet of Things devices).
[0104] In step S220, for an Internet of Things device, the DNS traffic statistical fingerprint feature of the device can be constructed by using the statistical information of all query domain names q(kj) of the device.
[0105] The higher the query probability, the more likely a query domain name q(kj) is to be queried by an Internet of Things device, and the more likely it is to be related to the Internet of Things device.
[0106] The higher the inverse document frequency, the less frequently a query domain name q(kj) appears in the queries of all Internet of Things devices, and it may have higher attack characteristics.
[0107] Therefore, on the one hand, it is possible to determine whether a query domain name comes from an Internet of Things device according to the inverse document frequency; on the other hand, the inverse document frequency of each query domain name can also be used as one of the features to help identify abnormal query behaviors and perform threat analysis and detection.
[0108] In step S230, the predetermined training end condition may be that after more than a predetermined number or a predetermined proportion of the predetermined traffic data training samples in the predetermined traffic data training sample set are input into the traffic recognition model, the result of whether the predetermined traffic data training sample comes from an Internet of Things device can be obtained, or it may be that the loss function converges or is less than a predetermined loss threshold according to the result determined by the traffic recognition model and the label of the predetermined traffic data test sample.
[0109] Specifically, in some embodiments, the specific implementation manner of step S230 can refer to the following embodiments. This embodiment is based on Figure 4 The details of step S230 in the traffic recognition method shown in the corresponding embodiment are described. In the traffic recognition method, step S230 may include the following steps:
[0110] Train the traffic recognition model according to the result determined by the traffic recognition model and the label of the predetermined traffic data test sample until the predetermined training end condition is reached.
[0111] If in the predetermined traffic data training sample set, only no more than a predetermined number or a predetermined proportion of the predetermined traffic data training samples are input into the traffic recognition model and the result of whether the predetermined traffic data training sample comes from an Internet of Things device can be obtained, then update the parameters of the traffic recognition model;
[0112] If, among the predetermined traffic data training samples in the predetermined traffic data training sample set, when more than a predetermined number or a predetermined proportion of the predetermined traffic data training samples are input into the traffic recognition model, the result of whether the predetermined traffic data training samples come from Internet of Things devices can be obtained, then the training ends and waits to enter the testing phase.
[0113] Specifically, in some other embodiments, the specific implementation manner of step S230 can be referred to the following embodiments. This embodiment is based on Figure 4 the detailed description of step S230 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S230 may include the following steps:
[0114] Determine the recognition loss according to the result determined by the traffic recognition model and the label of the predetermined traffic data test sample;
[0115] Update the parameters of the traffic recognition model according to the recognition loss until a predetermined training end condition is reached, then end the training and wait to enter the testing phase.
[0116] In this embodiment, the predetermined training end condition may be that the recognition loss converges or is less than a predetermined loss threshold.
[0117] Specifically, in some embodiments, the specific implementation manner of step S400 can be referred to Figure 6 . Figure 6 is based on Figure 3 the detailed description of step S400 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S400 may include the following steps:
[0118] Step S410, input the predetermined traffic data test samples into the traffic recognition model one by one to obtain a detection threshold.
[0119] Step S420, input the predetermined traffic data test samples into the traffic recognition model again one by one to extract the fingerprint features of the predetermined traffic data test samples.
[0120] Step S430, compare the fingerprint features of the predetermined traffic data test samples with the fingerprint features of the Internet of Things devices to obtain a test result.
[0121] In an embodiment of the present application, it is necessary to input the predetermined traffic data test samples into the traffic recognition model one by one twice. After the first input of the predetermined traffic data test samples into the traffic recognition model one by one, according to the output result of the model, the detection threshold corresponding to the test stage is determined. After the second input of the predetermined traffic data test samples into the traffic recognition model one by one, the traffic recognition model will obtain the fingerprint features corresponding to the predetermined traffic data test samples, and then according to the fingerprint features, it is determined whether the predetermined traffic data training sample comes from an Internet of Things device. The fingerprint features of traffic data from different devices are different.
[0122] Specifically, in the test stage, the traffic recognition model will compare the fingerprint features of the predetermined traffic data test samples with the fingerprint features of the Internet of Things devices, and then determine whether it is traffic data from an Internet of Things device. After comparing with the label, the test result is obtained.
[0123] In step S410, after the first input of the predetermined traffic data test samples into the traffic recognition model one by one, according to the output result of the model, the detection threshold corresponding to the test stage is determined.
[0124] Specifically, in some embodiments, the specific implementation manner of step S410 can refer to Figure 7 。 Figure 7 is based on Figure 6 The details of step S410 in the traffic recognition method shown in the corresponding embodiment are described. In the traffic recognition method, step S410 may include the following steps:
[0125] Step S412, input the predetermined traffic data test samples into the traffic recognition model one by one, and obtain the results of whether each of the predetermined traffic data test samples comes from an Internet of Things device.
[0126] Step S414, determine the detection threshold according to the results of whether each of the predetermined traffic data test samples comes from an Internet of Things device and the labels of each of the predetermined traffic data test samples.
[0127] In this embodiment, after inputting the predetermined traffic data test samples into the traffic recognition model one by one, the results of whether the predetermined traffic data test samples come from an Internet of Things device can be obtained. At the same time, the predetermined traffic data test samples are labeled with whether they come from an Internet of Things device. According to the label and the result, the detection threshold with the highest accuracy can be confirmed.
[0128] Specifically, in some embodiments, the specific implementation manner of step S414 can refer to the following embodiment. This embodiment is based on Figure 6 The details of step S414 in the traffic recognition method shown in the corresponding embodiment are described. In the traffic recognition method, step S414 may include the following steps:
[0129] Determine the true positive rate and false positive rate in the set of predetermined traffic data test samples based on the results of whether each of the predetermined traffic data test samples comes from an Internet of Things device and the labels of each of the predetermined traffic data test samples;
[0130] Determine the detection threshold according to the true positive rate and false positive rate in the set of the predetermined traffic data test samples.
[0131] In this embodiment, according to the results of whether each of the predetermined traffic data test samples comes from an Internet of Things device and the labels of each of the predetermined traffic data test samples, the predetermined traffic data test samples in the set of predetermined traffic data test samples can be divided into the following four types: true positive samples where both the output result and the marked label come from an Internet of Things device; true negative samples where neither the output result nor the marked label comes from an Internet of Things device; false positive samples where the output result comes from an Internet of Things device but the marked label does not come from an Internet of Things device; false negative samples where the output result does not come from an Internet of Things device but the marked label comes from an Internet of Things device.
[0132] According to the proportions of true positive samples and false positive samples in the set of predetermined traffic data test samples respectively, the true positive rate and false positive rate can be determined.
[0133] In other embodiments, it is also possible to filter out the samples whose output results do not come from an Internet of Things device, leaving only the true positive samples and false positive samples, and then determine the proportions of the true positive samples and false positive samples in the sample set composed of the true positive samples and false positive samples together, and determine the true positive rate and false positive rate.
[0134] According to the true positive rate and false positive rate, the detection threshold can be determined to ensure that the true positive rate increases and the false positive rate decreases.
[0135] In step S420, after the predetermined traffic data test samples are input into the traffic recognition model one by one for the second time, the traffic recognition model will obtain the fingerprint features corresponding to the predetermined traffic data test samples for comparison with the fingerprint features of the Internet of Things device.
[0136] In step S430, by comparing the fingerprint features of the predetermined traffic data test samples with the fingerprint features of the Internet of Things device, the similarity degree between the traffic data test samples and the traffic data of the Internet of Things device can be obtained, to confirm whether the traffic data test samples come from an Internet of Things device, and further determine whether the test is qualified.
[0137] Specifically, in some embodiments, the specific implementation manner of step S430 can refer to Figure 8 . Figure 8 It is according to Figure 6 The detailed description of step S430 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S430 may include the following steps:
[0138] Step S432: Respectively, based on the fingerprint features of the predetermined traffic data test samples and the fingerprint features of the Internet of Things devices, determine the term frequency-inverse document frequency vector of the device from which the predetermined traffic data test samples are from and the term frequency-inverse document frequency vector of the Internet of Things devices.
[0139] Step S434: Compare the term frequency-inverse document frequency vector of the fingerprint features of the predetermined traffic data test samples and the term frequency-inverse document frequency vector of the Internet of Things devices to obtain the degree of similarity.
[0140] Step S436: Obtain the test result based on the degree of similarity.
[0141] In the embodiments of the present application, according to the fingerprint features, the corresponding term frequency-inverse document frequency vector can be obtained, and then the degree of similarity can be calculated based on the term frequency-inverse document frequency vector. The degree of similarity can be a similarity level or a similarity value, and the present application does not make a limitation here. According to the degree of similarity, the result of whether the predetermined traffic data test samples are from the Internet of Things devices can be obtained, and further, the accuracy rate of the traffic recognition model can be determined to obtain the test result.
[0142] In step S432, before making the comparison, the fingerprint features need to be vectorized. The fingerprint features include the time window, the query probability, and the inverse document frequency, and then they can be vectorized into a term frequency-inverse document frequency vector through the term frequency-inverse document frequency algorithm.
[0143] In step S434, the degree of similarity can be represented by a similarity level or a similarity value, and its calculation method can be calculated using distance measurement methods such as cosine distance or Euclidean distance.
[0144] The higher the degree of similarity, the higher the correlation between the predetermined traffic data test samples and the Internet of Things devices, and the more likely they are to come from the Internet of Things devices.
[0145] In step S436, according to the degree of similarity, the result of whether each predetermined traffic data test sample is from the Internet of Things devices can be obtained. According to the results and labels of the predetermined traffic data test samples in the predetermined traffic data test sample set, the accuracy rate of the model can be obtained, and further, the result of whether the model is qualified can be obtained.
[0146] Specifically, in some embodiments, the specific implementation manner of step S436 can refer to the following embodiments. This embodiment is based on Figure 8 The detailed description of step S436 in the traffic recognition method shown in the corresponding embodiment. In the traffic recognition method, step S436 may include the following steps:
[0147] If there are predetermined traffic data test samples from Internet of Things devices for more than a first predetermined ratio of tags, and the similarity degree output by the traffic recognition model is less than the detection threshold, and at the same time, for more than a second predetermined ratio of tags, there are predetermined traffic data test samples that are not from Internet of Things devices, and the similarity degree output by the traffic recognition model is greater than the detection threshold, then it is determined that the test result is that the trained traffic recognition model passes the test;
[0148] If there are predetermined traffic data test samples from Internet of Things devices for no more than a first predetermined ratio of tags, and the similarity degree output by the traffic recognition model is less than the detection threshold, and at the same time, for no more than a second predetermined ratio of tags, there are predetermined traffic data test samples that are not from Internet of Things devices, and the similarity degree output by the traffic recognition model is greater than the detection threshold, then it is determined that the test result is that the trained traffic recognition model fails the test.
[0149] The following describes the device embodiments of the present application, which can be used to execute the traffic recognition method and / or the training method of the traffic recognition model in the above embodiments of the present application. For the details not disclosed in the device embodiments of the present application, please refer to the embodiments of the traffic recognition method and / or the training method of the traffic recognition model above of the present application.
[0150] Figure 9 The block diagram of a traffic recognition device according to an embodiment of the present application is shown.
[0151] Refer to Figure 9 As shown, a traffic recognition device 900 according to an embodiment of the present application includes:
[0152] A vector extraction module 910, configured to extract a target feature vector from target traffic data, where the target traffic data is traffic data from a target device collected by a target client;
[0153] A feature comparison module 920, configured to compare the target feature vector with the fingerprint feature of the Internet of Things device to obtain a similarity degree;
[0154] A similarity determination module 930, configured to determine whether the target traffic data is related to the Internet of Things device according to the similarity degree.
[0155] The specific details of each module in the above traffic recognition device have been described in detail in the corresponding traffic recognition method, so they will not be repeated here.
[0156] Figure 10 The block diagram of a training device of a traffic recognition model according to an embodiment of the present application is shown.
[0157] Refer to Figure 10As shown, a training device 1000 for a traffic recognition model according to an embodiment of the present application includes:
[0158] A training sample acquisition module 1010, configured to acquire a set of predetermined traffic data training samples, the set of predetermined traffic data training samples including a plurality of predetermined traffic data training samples, and each predetermined traffic data training sample is labeled as coming from an Internet of Things device;
[0159] A training sample input module 1020, configured to input the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from an Internet of Things device, and obtain fingerprint features of the Internet of Things device;
[0160] A test sample acquisition module 1030, configured to acquire a set of predetermined traffic data test samples, the set of predetermined traffic data test samples including a plurality of predetermined traffic data test samples, and each predetermined traffic data test sample is labeled with a tag indicating whether it comes from an Internet of Things device;
[0161] A test sample input module 1040, configured to input the predetermined traffic data test samples into the traffic recognition model one by one for testing, and obtain a test result, the test result including whether the trained traffic recognition model passes the test.
[0162] The specific details of each module in the above training device for the traffic recognition model have been described in detail in the corresponding training method for the traffic recognition model, and thus will not be elaborated herein.
[0163] It should be noted that although several modules or units of a device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more of the above-mentioned modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by a plurality of modules or units.
[0164] In addition, although the steps of the method in the present application are described in a specific order in the drawings, this does not require or imply that these steps must be executed in that specific order, or that all the steps shown must be executed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.
[0165] Those skilled in the art can easily understand from the description of the above embodiments that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0166] Figure 11 The structural schematic diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application is shown.
[0167] It should be noted that Figure 11 The computer system of the electronic device shown is only an example and should not impose any limitation on the functions and the scope of use of the embodiments of the present application.
[0168] As Figure 11 shown, the computer system includes a central processing unit (CPU) 1801, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1802 or the program loaded from the storage section 1808 into the random access memory (RAM) 1803, such as executing the method described in the above embodiments. In the RAM 1803, various programs and data required for system operation are also stored. The CPU 1801, the ROM 1802, and the RAM 1803 are connected to each other through a bus 1804. The input / output (I / O) interface 1805 is also connected to the bus 1804.
[0169] The following components are connected to the I / O interface 1805: an input section 1806 including a keyboard, a mouse, etc.; an output section 1807 including such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 1808 including a hard disk, etc.; and a communication section 1809 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 1809 performs communication processing via a network such as the Internet. A drive 1810 is also connected to the I / O interface 1805 as required. A removable medium 1811, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is mounted on the drive 1810 as required so that a computer program read therefrom is installed into the storage section 1808 as required.
[0170] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 1809, and / or installed from the removable medium 1811. When the computer program is executed by a central processing unit (CPU) 1801, various functions defined in the system of the present application are executed.
[0171] It should be noted that the computer-readable medium shown in the embodiments of the present application may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0172] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0173] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not, in some cases, constitute a limitation on the unit itself.
[0174] As another aspect, this application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs, and when the above one or more programs are executed by an electronic device, the electronic device implements the methods described in the above embodiments.
[0175] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of this application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0176] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a touch terminal, or a network device, etc.) to execute the methods according to the embodiments of this application.
[0177] After considering the specification and practicing the embodiments disclosed herein, those skilled in the art will readily conceive of other embodiments of this application. This application is intended to cover any variations, uses, or adaptations of this application, which follow the general principles of this application and include known common knowledge or conventional technical means in the technical field not disclosed in this application.
[0178] It should be understood that this application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is only limited by the appended claims.
Claims
1. A traffic recognition method, characterized in that, The described traffic recognition method includes: Extracting a target feature vector from target traffic data, where the target traffic data is traffic data collected by a target client from a target device; Comparing the target feature vector with the fingerprint features of an Internet of Things device to obtain a similarity degree; Determining whether the target traffic data is related to the Internet of Things device according to the similarity degree.
2. The traffic recognition method according to claim 1, wherein The determining whether the target traffic data is related to the Internet of Things device according to the similarity degree specifically includes: Determining whether the target traffic data potentially matches the Internet of Things device according to the similarity degree; If the target traffic data potentially matches the Internet of Things device, then identifying whether the target traffic data is related to the Internet of Things device according to specific information.
3. The traffic identification method according to claim 1, wherein Comparing the target feature vector with the fingerprint features of an Internet of Things device to obtain a similarity degree specifically includes: Obtaining the fingerprint features of the target traffic data according to the target feature vector; Comparing the fingerprint features of the target traffic data with the fingerprint features of the Internet of Things device to obtain a similarity degree.
4. A training method for a traffic recognition model, characterized in that The traffic recognition model is used to execute the traffic recognition method described in any one of claims 1 to 3. The training method of the traffic recognition model specifically includes: Obtaining a set of predetermined traffic data training samples, where the set of predetermined traffic data training samples contains multiple predetermined traffic data training samples, and each predetermined traffic data training sample is labeled as coming from an Internet of Things device; Inputting the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from an Internet of Things device, and obtaining the fingerprint features of the Internet of Things device; Obtaining a set of predetermined traffic data test samples, where the set of predetermined traffic data test samples contains multiple predetermined traffic data test samples, and each predetermined traffic data test sample is labeled with a tag indicating whether it comes from an Internet of Things device; Inputting the predetermined traffic data test samples into the traffic recognition model one by one for testing to obtain a test result, where the test result includes whether the trained traffic recognition model passes the test.
5. The training method of the traffic recognition model according to claim 4, characterized in that, The inputting the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from an Internet of Things device specifically includes: Inputting the predetermined traffic data training samples into the traffic recognition model one by one to obtain the fingerprint features corresponding to the predetermined traffic data training samples; Determining whether the predetermined traffic data training samples come from an Internet of Things device according to the fingerprint features corresponding to the predetermined traffic data training samples; Training the traffic recognition model according to the result determined by the traffic recognition model and the label of the predetermined traffic data test sample until a predetermined training end condition is reached, and obtaining the fingerprint features of the Internet of Things device.
6. The training method of the traffic recognition model according to claim 5, characterized in that The fingerprint features include a time window, the query probability of a target domain name, and the inverse document frequency of the target domain name. The inputting the predetermined traffic data training samples into the traffic recognition model one by one to obtain the fingerprint features corresponding to the predetermined traffic data training samples specifically includes: Determine the time window corresponding to the predetermined traffic data training sample and all target domain names according to the sample feature vector; Determine the query probability and inverse document frequency corresponding to each of the target domain names.
7. A traffic recognition device, characterized in that, The traffic recognition device includes: A vector extraction module, configured to extract a target feature vector from target traffic data, where the target traffic data is traffic data collected by a target client from a target device; A feature comparison module, configured to compare the target feature vector with the fingerprint feature of an Internet of Things device to obtain a similarity degree; A similarity determination module, configured to determine whether the target traffic data is related to the Internet of Things device according to the similarity degree.
8. A training device for a traffic recognition model, characterized in that The training device of the traffic recognition model includes: A training sample acquisition module, configured to acquire a set of predetermined traffic data training samples, where the set of predetermined traffic data training samples includes a plurality of predetermined traffic data training samples, and each predetermined traffic data training sample is labeled as coming from an Internet of Things device; A training sample input module, configured to input the predetermined traffic data training samples into the traffic recognition model one by one for training, so that the traffic recognition model outputs that the predetermined traffic data training samples come from an Internet of Things device, and obtain the fingerprint feature of the Internet of Things device; A test sample acquisition module, configured to acquire a set of predetermined traffic data test samples, where the set of predetermined traffic data test samples includes a plurality of predetermined traffic data test samples, and each predetermined traffic data test sample is labeled with a label indicating whether it comes from an Internet of Things device; A test sample input module, configured to input the predetermined traffic data test samples into the traffic recognition model one by one for testing, and obtain a test result, where the test result includes whether the trained traffic recognition model passes the test.
9. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the traffic recognition method according to any one of claims 1 to 3 and / or the training method of the traffic recognition model according to any one of claims 4 to 6.
10. An electronic device, characterized in that, Including: One or more processors; A storage device, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors implement the traffic recognition method according to any one of claims 1 to 3 and / or the training method of the traffic recognition model according to any one of claims 4 to 6.