Artificial intelligence-based encrypted communication traffic analysis method and system

By using an AI-based encrypted communication traffic analysis method, a security feature database is established, and deep learning networks and LSTM-Attention networks are used for multi-dimensional security assessment. This addresses the shortcomings of existing encrypted communication traffic analysis technologies and achieves efficient and accurate security assessment and abnormal traffic identification.

CN120342651BActive Publication Date: 2026-03-20RUNJIAN COMM +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510228851.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2026-03-20
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

Existing technologies are insufficient for effectively analyzing encrypted communication traffic, especially in terms of the comprehensiveness of feature extraction and the interpretability of analysis results. Furthermore, they lack comprehensive analysis of the multi-dimensional characteristics of encrypted traffic, making it difficult to accurately identify abnormal traffic.

Method used

An AI-based encrypted communication traffic analysis method is adopted. By establishing a security feature database, feature vectors are extracted using a deep learning network. Multi-dimensional security assessment is performed by combining feature matching score, matching feature element score, and traffic stability score. Deep feature analysis is then conducted using an LSTM-Attention network.

Benefits of technology

It achieves comprehensive feature extraction and accurate security assessment of encrypted communication traffic, improving the accuracy and reliability of the analysis. The dynamic weight adjustment mechanism makes the analysis results adaptive, reduces the false positive rate, and improves the classification accuracy of suspicious traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342651B_ABST
    Figure CN120342651B_ABST
Patent Text Reader

Abstract

The application discloses an encryption communication flow analysis method and system based on artificial intelligence, and the method stores feature elements of encryption communication flow packets judged as safe by establishing a security feature library; extracts a feature vector of to-be-analyzed flow based on a time sequence convolution neural network, calculates a feature matching score, a matching feature element score and a flow stability score; and comprehensively calculates a security evaluation score by combining the three scores to determine the security of the flow, so that automatic processing of the analysis method is realized; and the method provides a comprehensive and reliable encryption communication flow security analysis solution.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network communication security, and particularly relates to an encrypted communication flow analysis method and system based on artificial intelligence. BACKGROUND

[0002] With the rapid development of network technology, the proportion of encrypted communication flow in the network is increasing. While encrypted communication protects user privacy and data security, it also brings new challenges to network security monitoring.

[0003] Traditional flow analysis methods based on feature matching are difficult to meet the analysis needs of encrypted flow, and existing machine learning methods still have deficiencies in the comprehensiveness of feature extraction and the explainability of analysis results. In addition, existing methods lack comprehensive analysis of multi-dimensional features of encrypted flow, and are difficult to accurately identify abnormal flow with similar behavior characteristics, and lack in-depth analysis mechanism for suspicious flow at the boundary between security and abnormality.

[0004] Therefore, it is urgent to develop an encrypted communication flow analysis method that can comprehensively extract encrypted flow features, integrate multi-dimensional security evaluation indicators, and have deep analysis capability. SUMMARY

[0005] The purpose of the present application is to overcome the deficiencies of the prior art, and to provide an encrypted communication flow analysis method and system based on artificial intelligence, so as to achieve the purpose of comprehensively extracting encrypted flow features, accurately evaluating flow security, and in-depth analyzing suspicious flow.

[0006] The specific technical solutions are as follows:

[0007] In a first aspect, the present application provides an encrypted communication flow analysis method based on artificial intelligence, which is used to determine whether the encrypted communication flow is safe. The analysis method comprises the following steps:

[0008] Step S1, a security feature library is established, which stores a plurality of feature elements of encrypted communication flow packets that have been judged to be safe, and each feature element contains the basic features of the corresponding encrypted communication flow packet.

[0009] The basic features include: packet length distribution, packet arrival time interval, flow burstiness, protocol fingerprint, and encryption feature.

[0010] Step S2, the feature vector of the encrypted communication flow data to be analyzed is extracted based on a deep learning network, and based on the feature vector, the feature matching score, the matching feature element score and the flow stability score of the encrypted communication flow data to be analyzed are calculated.

[0011] Step S3: Calculate the security assessment score of the encrypted communication traffic data to be analyzed based on the feature matching score, matching feature element score, and traffic stability score, and obtain the qualitative result of the security assessment.

[0012] Furthermore, the security assessment score is denoted as S. The specific qualitative results of the security assessment are as follows: when S≥0.8, it is judged as safe traffic; when 0.5≤S<0.8, it is judged as suspicious traffic; and when S<0.5, it is judged as unsafe traffic.

[0013] Furthermore, the deep learning network adopts a temporal convolutional neural network structure. The input layer receives the sequence of encrypted communication traffic data packets to be analyzed. The convolutional layer contains three one-dimensional convolutional layers, using convolutional kernels of different sizes to extract temporal features: the first one-dimensional convolutional layer uses 64 convolutional kernels of size 3×1 to extract local temporal features. The second one-dimensional convolutional layer uses 128 convolutional kernels of size 3×1 to further extract composite features.

[0014] The third one-dimensional convolutional layer uses 256 convolutional kernels of size 3×1 to extract high-level features. Each convolutional layer is followed by a pooling layer, with a pooling kernel size of 2×1. The fully connected layer contains 512 neurons and uses the ReLU activation function. The output layer outputs a 256-dimensional feature vector, which serves as the basis for feature matching and computation.

[0015] Furthermore, the method for extracting basic features in step S2 is as follows:

[0016] Packet length distribution includes statistically analyzing the length distribution of N consecutive data packets, calculating the mean, variance, entropy, and interquartile range; packet arrival time interval is calculated based on the arrival time interval sequence of consecutive data packets, extracting the mean, variance, kurtosis, and skewness of the time interval; traffic burstiness is extracted based on wavelet analysis to extract traffic burst characteristics, calculating the energy density ratio and peak ratio; protocol fingerprint is extracted based on TLS handshake characteristics and cipher suite characteristics to extract protocol feature vectors; encryption characteristics reflect the randomness indicators of encrypted data, including approximate entropy and sequence complexity.

[0017] Furthermore, the feature matching score Se m The calculation formula is:

[0018] Among them, F i M represents the i-th component of the feature vector of the encrypted communication traffic to be analyzed; i v represents the i-th component of the feature vector in the security feature database; iThe weight coefficient of the i-th feature component is represented, reflecting the importance of the feature in the security determination; n represents the dimension of the feature vector, that is, the total number of feature components, and takes the value of 256.

[0019] Furthermore, the weighting coefficient v i The method for determining the contribution (PA) is as follows: Principal Component Analysis (PCA) is used to determine the contribution of each characteristic component. i The discriminative power of each feature component is calculated based on information gain. i ;Comprehensive contribution and distinguishing ability, v i =α·PA i +(1-α)·In i , where α is the balance coefficient, with a value of 0.6.

[0020] Furthermore, the matching feature element score Se s The calculation formula is: Where F represents the feature vector of the encrypted communication traffic to be analyzed; M j Let represent the j-th eigenvector among the k most similar eigenvectors to eigenvector F, where k represents the number of most similar eigenvectors, ranging from [3, 10]. The k most similar eigenvectors are selected from the feature space using the K-nearest neighbor algorithm; sim represents the similarity function, calculated using cosine similarity. ||F|| and ||M j || represent vectors F and M respectively. j The Euclidean norm.

[0021] Furthermore, the flow stability score Se t The calculation formula is: Se t =exp(-λ·σ), where σ represents the standard deviation of the characteristic sequence, and the calculation formula is: F t Let represent the eigenvector at time t; μ represents the mean of the eigenvector sequence, calculated using the following formula: T represents the number of sampling points within the observation time window; λ represents the adjustment coefficient, which is used to control the influence of the standard deviation on the stability score, and its value ranges from [0.5, 2.0].

[0022] The smaller the σ value, the more stable the flow characteristics. t The closer to 1; the larger the σ value, the greater the fluctuation in flow characteristics, Se t The closer it is to 0.

[0023] Furthermore, the formula for calculating the security assessment score S is as follows:

[0024] S=w1·Se m +w2·Ses +w3·Se t Wherein, w1+w2+w3=1, w1 represents the weight coefficient of the feature matching score, and the default value is 0.5; w2 represents the weight coefficient of the matching feature element score, and the default value is 0.3; w3 represents the weight coefficient of the flow stability score, and the default value is 0.2.

[0025] Further, the weight coefficient is dynamically adjusted according to the actual application scene, and the adjustment method is: analyzing the historical data, calculating the correlation of each sub-score and the final safety judgment result; based on the correlation analysis result, the gradient descent method is used to optimize the weight coefficient; the adjustment interval of the weight coefficient is once every 30 days, so as to adapt to the change of network environment.

[0026] Further, the encrypted communication flow analysis method based on artificial intelligence further comprises the following steps: further extracting the session layer features of the encrypted communication flow judged as suspicious flow 0.5≤S<0.8; constructing an LSTM-Attention network for deep feature analysis, the LSTM-Attention network comprising: an input layer for receiving the preprocessed time sequence feature sequence; an LSTM layer containing 128 LSTM units for extracting time sequence dependent features.

[0027] An attention layer for calculating the attention weight of each time step; a fully connected layer containing 128 neurons using a Tanh activation function; and an output layer for outputting a fine security score and an abnormal feature indication.

[0028] Based on the output result of the LSTM-Attention network, the suspicious flow is reclassified to improve the classification accuracy.

[0029] In a second aspect, the present application provides an encrypted communication flow analysis system based on artificial intelligence, which is used to execute the analysis method of the first aspect, and the system comprises the following modules connected in sequence: a storage module, a feature extraction module, a score calculation module and a result output module.

[0030] The storage module is used to store a security feature library, and the security feature library contains feature elements of a plurality of encrypted communication flow packets judged as safe.

[0031] The feature extraction module is used to extract the basic features of the encrypted communication flow to be analyzed, and the basic features include packet length distribution, packet arrival time interval, flow burstiness, protocol fingerprint and encryption feature.

[0032] The feature extraction module comprises a time sequence convolutional neural network unit and an LSTM-Attention network unit; the time sequence convolutional neural network unit is used for extracting a 256-dimensional feature vector of the encrypted communication traffic to be analyzed; and the LSTM-Attention network unit is used for deep feature analysis on the suspicious traffic.

[0033] The score calculation module is used for calculating a feature matching score Se m , a matching feature element score Se s , and a traffic stability score Se t ; and calculating a final security evaluation score S based on a weight coefficient.

[0034] The result output module is used for outputting a security evaluation qualitative result, storing an analysis history record, and generating an analysis report.

[0035] Further, a feature library management unit is arranged in the storage module, which is used for establishing a hierarchical index structure, accelerating the retrieval efficiency of feature elements, regularly cleaning up expired feature elements, maintaining the timeliness of the feature library, and performing quality evaluation on newly added feature elements to ensure the effectiveness of the features in the library.

[0036] Compared with the prior art, the present application has the following beneficial effects:

[0037] The present application extracts traffic features through a time sequence convolutional neural network, performs multi-dimensional security evaluation in combination with a feature matching score, a matching feature element score and a traffic stability score, improves the accuracy and reliability of the analysis, and adopts a dynamic weight adjustment mechanism to make the analysis result more adaptive and stable. BRIEF DESCRIPTION OF DRAWINGS

[0038] Figure 1 A flowchart of the encrypted communication traffic analysis method based on artificial intelligence according to the present application;

[0039] Figure 2 A composition schematic diagram of the encrypted communication traffic analysis system based on artificial intelligence according to the present application. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical scheme and advantages of the present application clearer, the technical scheme in the present application is described clearly and completely below, and obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.

[0041] Embodiment 1

[0042] As Figure 1As shown, it is an artificial intelligence-based encrypted communication traffic analysis method flowchart of the application, which comprises the following steps:

[0043] Step S1, establishing a security feature library, which stores a plurality of feature elements of encrypted communication traffic packets judged to be safe, each feature element containing the basic features of the corresponding encrypted communication traffic packet.

[0044] Encrypted communication traffic refers to network communication data stream processed by encryption algorithm, usually encrypted by SSL / TLS protocol, etc.; feature element is the basic unit to describe the features of encrypted communication traffic, containing multiple dimension feature values. The basic features include: packet length distribution, packet arrival time interval, traffic burstiness, protocol fingerprint, encryption feature.

[0045] The establishment process of the security feature library comprises the following steps: collecting a large number of known safe encrypted communication traffic samples; extracting the basic features of each sample, packet length distribution: statistical probability distribution characteristics of packet length; packet arrival time interval: analysis of statistical characteristics of time difference between data packets; traffic burstiness: evaluation of traffic fluctuation in time dimension; protocol fingerprint: extraction of encryption protocol feature parameters; encryption feature: analysis of randomness indicators of encrypted data; the extracted features are organized into feature elements and stored in the feature library; establish feature index to support fast retrieval.

[0046] The feature elements of encrypted communication traffic packets judged to be safe are mainly obtained from the following channels: official certified secure website communication data, enterprise intranet normal business traffic, and third-party application communication traffic after security authentication, etc. The sample collection process needs to ensure the reliability, diversity and representativeness of the data source, usually needs to collect not less than 1,000 safe encrypted communication session samples in different scenarios.

[0047] In step S1, the sampling window size N of continuous data packets is usually 100-1000, which is used to ensure the stability of statistical characteristics; in the statistical parameters of packet length distribution, the mean value reflects the central tendency of traffic packet size, the variance reflects the dispersion degree of traffic packet size, the entropy value reflects the uncertainty of packet length distribution, and the interquartile range reflects the dispersion degree of packet length distribution; in the time interval statistical parameters, the mean value reflects the average period of data packet arrival, the variance reflects the instability of arrival time, the kurtosis reflects the thickness of the tail of the distribution, and the skewness reflects the symmetry of the distribution; in the traffic burstiness parameters, the energy density ratio represents the ratio of wavelet coefficient energy at different scales, and the peak ratio represents the ratio of burst traffic to average traffic.

[0048] Step S2, extracting the feature vector of the encrypted communication traffic data to be analyzed based on the deep learning network, calculating the feature matching score, matching feature element score and traffic stability score of the encrypted communication traffic data to be analyzed based on the feature vector.

[0049] Step S3, calculating the security evaluation score of the encrypted communication traffic data to be analyzed based on the feature matching score, the matching feature element score and the flow stability score, and obtaining a security evaluation qualitative result.

[0050] The security evaluation score is represented as S, and the security evaluation qualitative result is specifically: when S≥0.8, it is determined as safe traffic, when 0.5≤S<0.8, it is determined as suspicious traffic, and when S<0.5, it is determined as unsafe traffic.

[0051] The deep learning network adopts a time sequence convolutional neural network structure, and an input layer receives a packet sequence of encrypted communication traffic data to be analyzed; the data dimension of the input layer is [batch size , sequence length , features], wherein batch size is the batch size, which is 32 by default; sequence length is the sequence length, which is 1000 by default; and features is the number of features, which is the combined dimension of basic features by default.

[0052] The parameter settings of each convolutional layer are as follows: the first layer uses 64 3×1 convolutional kernels, the step length is 1, and the padding mode is “same”; the second layer uses 128 3×1 convolutional kernels, the step length is 1, and the padding mode is “same”; the third layer uses 256 3×1 convolutional kernels, the step length is 1, and the padding mode is “same”; and all convolutional layers use the ReLU activation function f(x)=max(0,x). Each pooling layer uses the maximum pooling method, the pooling kernel size is 2×1, and the step length is 2, which is used for dimension reduction and extraction of significant features.

[0053] Specifically, the convolutional layer includes three one-dimensional convolutional layers, which use different sizes of convolutional kernels to extract time sequence features: the first one-dimensional convolutional layer uses 64 3×1 convolutional kernels to extract local time sequence features, the second one-dimensional convolutional layer uses 128 3×1 convolutional kernels to further extract composite features, the third one-dimensional convolutional layer uses 256 3×1 convolutional kernels to extract high-level features, Each convolutional layer is connected to a pooling layer, and the pooling kernel size of the pooling layer is 2×1; the fully connected layer includes 512 neurons, which uses the ReLU activation function; and the output layer outputs a 256-dimensional feature vector, which serves as the basis for feature matching and calculation.

[0054] The extraction method of the basic features in step S2 is specifically:

[0055] The packet length distribution includes the length distribution of a plurality of consecutive data packets, and the average value, variance, entropy value, and quartile range are calculated. The packet arrival time interval is based on the arrival time interval sequence of consecutive data packets, and the mean value, variance, kurtosis, and skewness of the time interval are extracted. The traffic burstiness is based on the traffic burst feature extracted by wavelet analysis, and the energy density ratio and peak ratio are calculated. The protocol fingerprint is based on the TLS handshake feature and the cipher suite feature, and the protocol feature vector is extracted.

[0056] The encryption feature reflects the randomness index of encrypted data, including approximate entropy and sequence complexity.

[0057] The feature matching score Se m is calculated by the following formula:

[0058] wherein, F i represents the i-th component of the feature vector of the encrypted communication traffic to be analyzed; M i represents the i-th component of the feature vector in the security feature library; v i represents the weight coefficient of the i-th feature component, reflecting the importance of the feature in the security decision; n represents the dimension of the feature vector, i.e. the total number of feature components, and takes the value of 256.

[0059] The determination method of the weight coefficient v i is as follows: the contribution degree PA i of each feature component is determined by principal component analysis PCA; the discrimination ability In i of each feature component is calculated based on information gain; and v i = α·PA i +(1-α)·In i , wherein α is a balance coefficient and takes the value of 0.6.

[0060] The calculation formula of the matching feature score Se s is as follows: wherein, F represents the feature vector of the encrypted communication traffic to be analyzed; M j represents the j-th feature vector in the k most similar feature vectors to the feature vector F, and k represents the number of the most similar feature vectors, taking the value range of [3, 10]; the k most similar feature vectors are selected in the feature space by K-nearest neighbor algorithm; the selection of k value is based on the size of the data set and the feature distribution characteristics, and a smaller k value (such as 3) is suitable for the scene with concentrated feature distribution, and a larger k value (such as 10) is suitable for the scene with dispersed feature distribution. The cosine similarity is used for similarity calculation, mainly considering the consistency of vector direction, and the normalization processing is used to avoid the influence of dimension.

[0061] sim represents the similarity function, and the cosine similarity is used for calculation:

[0062] ||F|| and ||M j represent the Euclidean norm of vectors F and M j respectively.

[0063] The formula for calculating the flow stability score Se t is:

[0064] Se t = exp(-λ·σ), where σ represents the standard deviation of the characteristic sequence, and the formula is:

[0065] F t represents the characteristic vector at time t; μ represents the mean of the characteristic vector sequence, and the formula is: T represents the number of sampling points in the observation time window; λ represents the adjustment coefficient, which is used to control the degree of influence of the standard deviation on the stability score, and the value range is [0.5, 2.0]; the sampling time window T is usually 300-600 seconds, and the characteristic vector sequence is standardized. In the selection of the adjustment coefficient λ, λ=0.5 is suitable for a lower requirement scenario, and λ=2.0 is suitable for a higher requirement scenario. This design makes the scoring mechanism have strong adaptability.

[0066] When the σ value is smaller, it indicates that the flow characteristics are more stable, and Se t is closer to 1; when the σ value is larger, it indicates that the flow characteristics fluctuate more, and Se t is closer to 0.

[0067] The formula for calculating the security evaluation score S is:

[0068] S = w1·Se m + w2·Se s + w3·Se t , where w1+w2+w3=1, w1 represents the weight coefficient of the characteristic matching score, and the default value is 0.5; w2 represents the weight coefficient of the matching characteristic element score, and the default value is 0.3; w3 represents the weight coefficient of the flow stability score, and the default value is 0.2.

[0069] A specific HTTPS encrypted communication flow sample is used as an example to illustrate the basic characteristics of the sample, including: packet length distribution characteristics (average value 800 bytes, variance 150 bytes, entropy value 4.2, quartile range 200 bytes); time interval characteristics (mean 0.05 seconds, variance 0.01 seconds, kurtosis 3.1, skewness 0.2); burstiness characteristics (energy density ratio 1.5, peak ratio 2.3).

[0070] The specific calculation steps are: first, a 256-dimensional feature vector F is extracted through a time series convolutional neural network; then, a feature matching score is calculated, assuming that the matching score Se of the most similar feature element in the security feature library is 0.85; then, k = 5 most similar feature elements are selected to calculate the matching feature element score Se = 0.78; the flow stability score Se is set to 1.0, and the flow stability score Se = 0.82 is calculated; finally, the final security evaluation score S = 0.5 x 0.85 + 0.3 x 0.78 + 0.2 x 0.82 = 0.823 is calculated; since S > 0.8, it is determined that the flow is safe. m s t This example embodies the multiple technical effects of the present application, and reduces the misjudgment rate through multi-dimensional feature analysis. In this example, the three scores are all high, indicating that the judgment result is reliable. The feature extraction and calculation process can be parallelized, and the analysis time of a single flow sample is controlled within 100 ms. Each sub-score can be traced back, facilitating analysis and judgment basis. The weight coefficient can be dynamically adjusted to adapt to different scene requirements.

[0071] The weight coefficient is dynamically adjusted according to the actual application scene. The adjustment method is: analyzing historical data to calculate the correlation between each sub-score and the final security judgment result; based on the correlation analysis result, using gradient descent method to optimize the weight coefficient; the adjustment interval of the weight coefficient is once every 30 days to adapt to the change of network environment.

[0072] The weight coefficient is dynamically adjusted according to the actual application scene. The adjustment method is: analyzing historical data to calculate the correlation between each sub-score and the final security judgment result; based on the correlation analysis result, using gradient descent method to optimize the weight coefficient; the adjustment interval of the weight coefficient is once every 30 days to adapt to the change of network environment.

[0073] The encrypted communication flow analysis method based on artificial intelligence further includes the following steps: further extracting the session layer features of the encrypted communication flow determined as suspicious flow 0.5 ≤ S < 0.8; constructing an LSTM-Attention network for deep feature analysis, the LSTM-Attention network including: an input layer for receiving preprocessed time series feature sequences; an LSTM layer containing 128 LSTM units for extracting time series dependent features.

[0074] An attention layer for calculating attention weights at each time step; a fully connected layer containing 128 neurons using a Tanh activation function; and an output layer for outputting a fine security score and an abnormal feature indication.

[0075] Based on the output results of the LSTM-Attention network, the suspicious flow is reclassified to improve the classification accuracy.

[0076] ​​For the deep analysis network of suspicious traffic (0.5≤S<0.8), the LSTM layer contains 128 LSTM units, the hidden state dimension is 256, and the dropout rate and the recurrent dropout rate are both 0.3; the attention layer adopts the additive attention mechanism, and the temperature parameter is 1.0; the dropout rate of the fully connected layer is 0.2; such deep network structure design can perform more fine feature extraction and analysis on suspicious traffic and improve the classification accuracy.

[0077] Specifically, the LSTM unit captures long-term dependencies through the gating mechanism, effectively extracts the long-term trend of the time sequence feature; the additive attention mechanism automatically identifies important time steps through learnable parameters, highlighting key features; the fully connected layer maps the attention-weighted features to a high-dimensional feature space, improving the feature expression ability; the dropout mechanism effectively prevents overfitting and improves the model generalization ability. In the deep analysis process, first, more fine-grained session layer features of suspicious traffic are extracted, including session duration, intra-session packet quantity distribution, session periodicity, etc.; then these features are input into the LSTM-Attention network for deep analysis; finally, based on the network output result, the suspicious traffic is reclassified to accurately identify disguised malicious traffic and improve the overall detection accuracy of the system. Experimental results show that this deep analysis mechanism can improve the classification accuracy of suspicious traffic from 85% to 93%, significantly reducing the misjudgment and omission.

[0078] Embodiment 2

[0079] As shown in Figure 2 , it is a composition schematic diagram of the encryption communication traffic analysis system based on artificial intelligence provided by the application, which is used to execute the analysis method of embodiment 1, and the system comprises, which are connected in sequence: a storage module, a feature extraction module, a score calculation module and a result output module.

[0080] The storage module is used to store a security feature library, and the security feature library contains feature elements of a plurality of encryption communication traffic packets judged as safe.

[0081] The feature extraction module is used to extract basic features of the encryption communication traffic to be analyzed, and the basic features include packet length distribution, packet arrival time interval, traffic burstiness, protocol fingerprint and encryption feature.

[0082] The feature extraction module comprises a time sequence convolutional neural network unit and an LSTM-Attention network unit; the time sequence convolutional neural network unit is used to extract a 256-dimensional feature vector of the encryption communication traffic to be analyzed; and the LSTM-Attention network unit is used to perform deep feature analysis on suspicious traffic.

[0083] The score calculation module is configured to calculate a feature matching score Se m a matching feature element score Se s and a flow stability score Se t ; calculate a final security evaluation score S based on a weight coefficient; the score calculation module realizes efficient calculation of the feature matching score, the matching feature element score, and the flow stability score. The module uses a vectorized calculation method, fully utilizes the SIMD instruction set of a modern processor, and improves the calculation efficiency. Dynamic adjustment of the weight coefficient is performed asynchronously in the background, without affecting the real-time analysis process. Multiple levels of cache are provided in the module to store intermediate calculation results, avoiding repeated calculation. For frequently accessed feature library data, a preloading strategy is used to reduce IO overhead.

[0084] The result output module is configured to output a security evaluation qualitative result, store analysis history records, and generate an analysis report; the result output module not only outputs the final security evaluation result, but also is responsible for generating a detailed analysis report; the analysis report contains scoring data, key feature indicators, and abnormal feature markers in each dimension, facilitating subsequent analysis by security analysts; the module also realizes storage and management of analysis history records, supports retrieval and statistical analysis according to multiple dimensions such as time, flow characteristics, and evaluation results. The analysis report is stored in a structured format, facilitating data mining and trend analysis.

[0085] The storage module is provided with a feature library management unit configured to establish a hierarchical index structure, accelerate the retrieval efficiency of feature elements, regularly clean up expired feature elements, and maintain the timeliness of the feature library; perform quality evaluation on newly added feature elements to ensure the effectiveness of the features in the library.

[0086] The feature library management unit in the storage module realizes automated maintenance of the feature library. The unit improves retrieval efficiency through a hierarchical index structure, and the index structure is implemented using a B+ tree to support efficient range queries. The life cycle management of feature elements is based on access frequency and timeliness, and low-frequency access and expired feature elements are regularly cleaned up. For newly added feature elements, the unit ensures their quality through multiple verifications, including feature integrity checking, numerical range verification, and timing feature consistency checking. To adapt to changes in the network environment, the feature library is updated once a week, and the update process does not affect the normal operation of the system.

[0087] Through the above modular design, the embodiment provides a complete encrypted communication flow analysis system solution. The system has the following advantages: 1) efficient parallel processing capability, supporting large-scale flow real-time analysis; 2) flexible feature library management mechanism, ensuring the timeliness and effectiveness of feature data; 3) perfect result output and history record management, facilitating in-depth analysis and trend research; 4) good scalability, allowing new analysis modules and functional units to be added as needed.

[0088] The test results show that the system can stably process thousands of traffic records per second, the average processing delay of a single record is controlled within 100 ms, and the accuracy is above 95%.

[0089] The above specific embodiments further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the protection scope of the present application.

Claims

1. An artificial intelligence-based encrypted communication traffic analysis method for determining whether the encrypted communication traffic is secure, characterized in that, The analytical method includes the following steps: Step S1: Establish a security feature database. The security feature database stores multiple feature elements of encrypted communication traffic packets that have been judged to be secure. Each feature element contains the basic features of the corresponding encrypted communication traffic packet. The basic characteristics include: packet length distribution, packet arrival time interval, traffic burstiness, protocol fingerprint, and encryption features; Step S2: Extract feature vectors from the encrypted communication traffic data to be analyzed based on the deep learning network; and calculate the feature matching score, matching feature element score, and traffic stability score of the encrypted communication traffic data to be analyzed based on the feature vectors. Step S3: Calculate the security assessment score of the encrypted communication traffic data to be analyzed based on the feature matching score, matching feature element score, and traffic stability score, and obtain the qualitative result of the security assessment. Feature matching score The calculation formula is: ,in, The first feature vector of the encrypted communication traffic to be analyzed represents the first feature vector. One component; Represents the first feature vector in the security feature database. One component; Indicates the first The weight coefficient of each feature component reflects the importance of the feature in the security determination; n represents the dimension of the feature vector, that is, the total number of feature components, and takes a value of 256. Weighting coefficient The method for determining the contribution of each characteristic component is as follows: Principal component analysis (PCA) is used to determine the contribution of each characteristic component. The discriminative power of each feature component is calculated based on information gain. Overall contribution and distinguishing ability, , where α is the balance coefficient, with a value of 0.6; The matching feature score The calculation formula is: ,in, This represents the feature vector of the encrypted communication traffic to be analyzed. Representation and eigenvectors Most similar The th eigenvector in the th eigenvector 1 eigenvector This represents the number of the most similar feature elements, with values ​​ranging from [3, 10]. Each feature element is selected from the feature space using the K-nearest neighbor algorithm; The similarity function is represented by cosine similarity. ; and Representing vectors respectively and The Euclidean norm; The flow stability score The calculation formula is: ,in, The standard deviation of a characteristic sequence is expressed by the following formula: , express The feature vector at time step; The mean of the eigenvector sequence is calculated using the following formula: , Indicates the number of sampling points within the observation time window; This represents the adjustment coefficient, used to control the degree of influence of the standard deviation on the stability score, with a value range of [0.5, 2.0]. when The smaller the value, the more stable the flow characteristics. The closer to 1; when The larger the value, the greater the fluctuation in flow characteristics. The closer to 0; The security assessment score is represented by S. ,in, , This represents the weighting coefficient for the feature matching score, with a default value of 0.

5. This represents the weighting coefficient for the matching feature score, with a default value of 0.

3. The weighting factor for the traffic stability score, with a default value of 0.2; The specific qualitative results of the security assessment are as follows: when S≥0.8, it is determined to be safe traffic; when 0.5≤S<0.8, it is determined to be suspicious traffic; and when S<0.5, it is determined to be unsafe traffic.

2. The method for analyzing encrypted communication traffic based on artificial intelligence according to claim 1, characterized in that, The deep learning network employs a temporal convolutional neural network structure. The input layer receives the sequence of encrypted communication traffic data packets to be analyzed. The convolutional layer consists of three one-dimensional convolutional layers, using convolutional kernels of different sizes to extract temporal features: the first one-dimensional convolutional layer uses 64 convolutional kernels of size 3×1 to extract local temporal features. The second one-dimensional convolutional layer uses 128 convolutional kernels of size 3×1 to further extract composite features. ; The third one-dimensional convolutional layer uses 256 convolutional kernels of size 3×1 to extract high-level features. Each convolutional layer is followed by a pooling layer, with a pooling kernel size of 2×1. The fully connected layer contains 512 neurons and uses the ReLU activation function. The output layer outputs a 256-dimensional feature vector, which serves as the basis for feature matching and computation.

3. The method for analyzing encrypted communication traffic based on artificial intelligence according to claim 1, characterized in that, The method for extracting basic features in step S2 is as follows: Packet length distribution includes statistically analyzing the length distribution of N consecutive data packets and calculating the mean, variance, entropy, and interquartile range; packet arrival time interval is based on calculating the arrival time interval sequence of consecutive data packets and extracting the mean, variance, kurtosis, and skewness of the time interval; traffic burstiness is based on wavelet analysis to extract traffic burst characteristics and calculate the energy density ratio and peak ratio; protocol fingerprint is based on TLS handshake characteristics and cipher suite characteristics to extract protocol feature vectors. Encryption features reflect the randomness of encrypted data, including approximate entropy and sequence complexity.

4. The method for analyzing encrypted communication traffic based on artificial intelligence according to claim 3, characterized in that, The security assessment score In the calculation formula, the weighting coefficients are dynamically adjusted according to the actual application scenario. The adjustment method is as follows: Historical data is analyzed to calculate the correlation between the scores of each sub-item and the final security assessment result; based on the correlation analysis results, the gradient descent method is used to optimize the weight coefficients; the weight coefficients are adjusted every 30 days to adapt to changes in the network environment.

5. The method for analyzing encrypted communication traffic based on artificial intelligence according to claim 1 or 4, characterized in that, It also includes the following steps: Traffic deemed suspicious The encrypted communication traffic is further extracted to extract its session layer features; an LSTM-Attention network is constructed for deep feature analysis. The LSTM-Attention network includes: an input layer, which receives the preprocessed temporal feature sequence; and an LSTM layer, which contains 128 LSTM units to extract temporal dependency features. The attention layer is used to calculate the attention weights at each time step; the fully connected layer contains 128 neurons and uses the Tanh activation function; the output layer is used to output a fine-grained security score and anomaly feature indication. Based on the output of the LSTM-Attention network, suspicious traffic is reclassified to improve classification accuracy.

6. An AI-based encrypted communication traffic analysis system, used to execute the analysis method according to any one of claims 1-5, characterized in that, The system includes, in sequence, a storage module, a feature extraction module, a scoring calculation module, and a result output module; The storage module is used to store a security feature library, which contains feature elements of multiple encrypted communication traffic packets that have been determined to be secure. The feature extraction module is used to extract the basic features of the encrypted communication traffic to be analyzed. The basic features include packet length distribution, packet arrival time interval, traffic burstiness, protocol fingerprint, and encryption features. The feature extraction module includes a temporal convolutional neural network unit and an LSTM-Attention network unit; the temporal convolutional neural network unit is used to extract a 256-dimensional feature vector of the encrypted communication traffic to be analyzed; the LSTM-Attention network unit is used to perform deep feature analysis on suspicious traffic. The scoring calculation module is used to calculate the feature matching score. Matching feature scores and traffic stability score The final security assessment score is calculated based on weighted coefficients. ; The result output module is used to output qualitative results of security assessment, store historical analysis records, and generate analysis reports.

7. The AI-based encrypted communication traffic analysis system according to claim 6, characterized in that, The storage module includes a feature library management unit, which is used to establish a hierarchical index structure, accelerate the retrieval efficiency of feature elements, regularly clean up expired feature elements to maintain the timeliness of the feature library, and conduct quality assessments on newly added feature elements to ensure the validity of the features added to the library.

Citation Information

Patent Citations

  • Encrypted malicious traffic identification method, equipment and device

    CN111447190A

  • Encrypted malicious traffic detection method and system based on multi-modal deep learning

    CN113542259A