Website identification method, system and device for anonymous communication network and storage medium
By building an anonymous website identification network model, using LSTM and CNN to extract features and using SVD matrix decomposition and cosine similarity judgment, the problem of illegal website identification in anonymous communication network is solved, the recognition accuracy and efficiency are improved, and resource consumption is reduced.
Patent Information
- Application Number
- CN202510481528.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-18
AI Technical Summary
The prior art is difficult to efficiently identify illegal websites in anonymous communication networks, and it takes a lot of resources and time to build large-scale training data sets and train complex machine learning models.
By building an anonymous website identification network model, including feature extraction module, feature fusion module and identification classification module, the features are extracted using LSTM and CNN network models, SVD matrix decomposition and cosine similarity judgment are used, and the ELU activation function and new loss function optimization model is used.
Accurate identification of anonymous website traffic data is achieved, training costs are reduced, identification accuracy is improved, and law enforcement personnel are assisted in monitoring network security and tracking illegal behaviors.
Smart Images

Figure CN120342686A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a method, system, device and storage medium for identifying websites in an anonymous communication network. Background Art
[0002] With the continuous improvement of network privacy awareness, more and more people use anonymous communication networks (such as the Tor network) to protect their user identities and browsing behaviors from being tracked. Anonymous communication networks hide the identities of senders, receivers and communication relationships, thus effectively hiding the communication content of users and preventing third-party eavesdropping and tampering. However, although anonymous communication systems largely protect users' privacy, they also provide opportunities for lawbreakers to commit crimes. They use the privacy convenience provided by anonymous communication networks to access various anonymous websites and conduct illegal activities, and such illegal activities are often difficult to track.
[0003] In the prior art, law enforcement officers such as public security network security departments and government regulatory agencies mainly identify and classify the information of illegal websites visited by lawbreakers through website fingerprint attack technology, and use IP tracking technology to track down lawbreakers and take measures; website fingerprint attack refers to the process of obtaining the traffic data generated when lawbreakers visit websites and classifying it using methods such as machine learning. Since website fingerprint attack requires in-depth learning of traffic patterns, this usually requires law enforcement officers to obtain a large amount of labeled monitored website data as training data, so that the model can better capture and learn the characteristics of website traffic. However, constructing a large-scale dataset is not only technically challenging, but also requires law enforcement officers to consume a lot of time and national resources. In addition, training complex machine learning or deep learning models also requires high-performance computing resources, which further increases the cost. Summary of the Invention
[0004] The purpose of the present invention is to overcome the above-mentioned deficiencies in the prior art, and provide a method for identifying websites in an anonymous communication network. Through a trained anonymous website identification network model, this method can accurately identify whether the anonymous website traffic data information to be identified contains monitored website information, so as to assist law enforcement officers such as public security network security departments and government regulatory agencies to better supervise network security and track illegal activities, and improve the security of the network.
[0005] At the same time, the second purpose of the present invention is to provide a system for identifying websites in an anonymous communication network.
[0006] At the same time, the third purpose of the present invention is to provide a computer device.
[0007] At the same time, the fourth purpose of the present invention is to provide a storage medium.
[0008] The object of the present invention is achieved by the following technical solutions:
[0009] A method for identifying websites in an anonymous communication network, comprising the following steps:
[0010] S1. Obtain the traffic data information of multiple monitored websites, preprocess the traffic data information of the multiple different monitored websites, and construct a monitored website traffic set; the traffic data information includes website traffic sequence direction information and time information;
[0011] S2. Construct an anonymous website identification network model, which includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence;
[0012] S3. Divide a training set from the monitored website traffic set to train the anonymous website identification network model, and obtain a trained anonymous website identification network model;
[0013] S4. Input the collected traffic data information of the anonymous website to be identified into the trained anonymous website identification network model, and identify whether the traffic data information of the anonymous website contains the monitored website.
[0014] Preferably, the training process of the anonymous website identification network model in step S3 is as follows:
[0015] S31. Divide a training set from the monitored website traffic set, preprocess the website traffic data in the training set, and input the preprocessed website traffic data into the feature extraction module;
[0016] S32. The feature extraction module extracts preliminary feature vectors according to the input website traffic data, and inputs the preliminary feature vectors into the feature fusion module;
[0017] S33. The feature fusion module first converts the preliminary feature vectors into a feature matrix, and then performs singular value decomposition on the feature matrix by using the SVD matrix decomposition method to obtain the optimal feature vectors corresponding to the input website traffic data;
[0018] S34. Input the optimal feature vectors into the identification and classification module, and the identification and classification module calculates the distances between the input optimal feature vectors and the representative feature vectors of the preset monitored websites respectively. When the distance is less than the preset threshold, it is considered that the website corresponding to the input optimal feature vector belongs to the monitored website and is reported. Otherwise, it is considered that the website corresponding to the input optimal feature vector is a non-monitored website;
[0019] S35. Repeat steps S31 - S34 to train the anonymous website recognition network model until the model meets the termination condition. Take the anonymous website recognition network model obtained at this time as the trained anonymous website recognition network model and save the parameters.
[0020] Preferably, in step S2, the feature extraction module uses an LSTM network model, the feature fusion module uses a CNN network model with the last fully connected layer removed, and the recognition and classification module is a cosine similarity layer; the LSTM network model, the CNN network model with the last fully connected layer removed, and the cosine similarity layer are connected in sequence.
[0021] Preferably, the loss function during the training of the anonymous website recognition network is set as follows:
[0022] loss true = 1 - CosineSimilarity true_s
[0023]
[0024] loss 总 = loss false + loss true
[0025] Among them, loss 总 is the total loss function, loss true is the loss between the predicted value and the true sample, loss false is the loss between the predicted value and other non - true samples, CosineSimilarity strue_s is the cosine similarity between the weight vector of this sample to the true website s, and N C is the total number of monitored websites.
[0026] Preferably, the anonymous website recognition network uses the ELU activation function as the activation function;
[0027] The ELU activation function is specifically expressed as follows:
[0028]
[0029] Among them, α is set to 1, and x is the input data.
[0030] Preferably, the representation of the optimal feature vector in step S33 is as follows:
[0031] F w = CNN(LSTM(x))
[0032] Among them, F wIt is the initial feature vector obtained by extracting the input data x through LSTM and CNN.
[0033] Preferably, the method for obtaining the optimal feature vector of the preset monitoring website in step S34 is as follows:
[0034] First, if there is only one monitoring website, first obtain the multi-segment traffic data information of the monitoring website, preprocess the multi-segment traffic data information, and make the preprocessed multi-segment traffic data information into a monitoring website training data set. Assuming that the monitoring website training data set has n training data, use the feature extraction module to process the n training data in sequence to obtain n initial feature vectors corresponding to the monitoring website, and then aggregate the n initial feature vectors into a matrix. Use the SVD matrix decomposition method to perform singular value decomposition on the aggregated feature matrix, and extract the first left singular vector as the representative feature vector of the monitoring website;
[0035] The representative feature vector of the monitoring website is expressed as follows:
[0036] M s =U∑V T
[0037] F s =U[:,1]
[0038] Where U and V are orthogonal matrices, ∑ is a diagonal matrix with singular values along the diagonal, M s is the feature matrix of the monitoring website s, and F s is the representative feature vector of the monitoring website s;
[0039] If there are multiple monitoring websites, repeat the above method to process each monitoring website in sequence to obtain the representative feature vectors corresponding to multiple monitoring websites.
[0040] A website recognition system for an anonymous communication network, used to implement the website recognition method for an anonymous communication network, includes:
[0041] A sample acquisition module, used to acquire the traffic data information of multiple monitoring websites, preprocess and label the traffic data information of the multiple monitoring websites, establish a monitoring website traffic set, and divide it into a training set and a test set; the traffic data information includes website traffic sequence direction information and time information;
[0042] A model construction module, used to construct an anonymous website recognition network model, and the anonymous website recognition network model includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence;
[0043] A model training module, which is used to train the anonymous website recognition network model with the training set obtained by the sample acquisition module, so as to obtain a trained anonymous website recognition network model;
[0044] A module for receiving information on traffic data of websites to be recognized, which is used to receive in real time the information on traffic data of anonymous websites to be recognized transmitted by law enforcement agencies and preprocess the information on traffic data of anonymous websites to be recognized;
[0045] An anonymous website recognition module, which is used to input the information on traffic data of anonymous websites to be recognized into the trained anonymous website recognition network model, identify whether the information on traffic data of anonymous websites to be recognized contains the monitored website, and output corresponding results;
[0046] An early warning module, which is used to send a corresponding early warning signal to the law enforcement agencies according to the results output by the anonymous website recognition module.
[0047] A computer device includes a processor and a memory for storing programs executable by the processor. When the processor executes the programs stored in the memory, the website recognition method for an anonymous communication network described above is implemented.
[0048] A storage medium stores a program, and when the program is executed by a processor, the website recognition method for an anonymous communication network described above is implemented.
[0049] The present invention has the following advantages and beneficial effects compared with the prior art:
[0050] (1) The website recognition method for an anonymous communication network of the present invention identifies the information on traffic data of anonymous websites to be recognized through a trained anonymous website recognition network model, and can accurately identify whether the information on traffic data of anonymous websites to be recognized contains the monitored website information, so as to assist law enforcement officers such as public security network security departments and government regulatory agencies to better supervise network security and track illegal acts, and improve the security of the network environment.
[0051] (2) The anonymous website recognition network model of the present invention only uses monitored websites as training data, enabling the model to also distinguish monitored websites and non-monitored websites with relatively high confidence, effectively solving the problem of poor classification performance of traditional methods when facing non-monitored websites. Secondly, in order to improve the feature extraction ability of the model, the feature extraction module of the anonymous website recognition network model uses an LSTM network model to extract features from data traffic, thus facilitating the capture of temporal dependence relationships in traffic data. In addition, the anonymous website recognition network model introduces ELU as the activation function to accelerate model convergence and improve the non-linear feature extraction effect. Then, the model also introduces a new loss function to measure the loss value of the model prediction value, better calculating the loss between the predicted value and the true label as well as the non-true label, thereby effectively improving the accuracy of model recognition.
[0052] (3) The anonymous website recognition network model of the present invention only uses monitored websites as training data during the training process, and determines its category by extracting the feature distance between the optimal feature vectors of the monitored websites and the optimal feature vectors of the websites to be recognized, reducing unnecessary training costs during the model training process. Brief Description of the Drawings
[0053] Figure 1 It is a schematic flowchart of the website recognition method for an anonymous communication network provided in Embodiment 1 of the present invention;
[0054] Figure 2 It is a schematic flowchart of the training process of the anonymous website recognition network model provided in Embodiment 1 of the present invention;
[0055] Figure 3 It is a schematic structural diagram of the website recognition system for an anonymous communication network provided in Embodiment 2 of the present invention;
[0056] Figure 4 It is a schematic structural diagram of a computer device provided in Embodiment 3 of the present invention.
[0057] Figure 5 It is a schematic structural diagram of a storage medium provided in Embodiment 4 of the present invention. Detailed Embodiments
[0058] The present invention will be further described below with reference to the drawings and embodiments.
[0059] In order to make the objectives, features, and advantages of the present invention more obvious and understandable, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0060] The following further illustrates the technical solutions of the present invention with reference to the accompanying drawings and through specific embodiments.
[0061] Embodiment 1
[0062] A method for identifying websites in an anonymous communication network includes the following steps:
[0063] S1. Obtain traffic data information of multiple monitored websites, preprocess the traffic data information of the multiple different monitored websites, and construct a monitored website traffic set; the traffic data information includes website traffic sequence direction information and time information;
[0064] S2. Construct an anonymous website identification network model, which includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence;
[0065] Specifically, in step S2, the feature extraction module uses an LSTM network model, the feature fusion module uses a CNN network model with the last fully connected layer removed, and the identification and classification module is a cosine similarity layer; the LSTM network model, the CNN network model with the last fully connected layer removed, and the cosine similarity layer are connected in sequence.
[0066] Specifically, the anonymous website identification network uses an ELU activation function as the activation function;
[0067] The ELU activation function is specifically expressed as follows:
[0068]
[0069] Among them, α is set to 1, and x is the input data.
[0070] S3. Divide a training set from the monitored website traffic set to train the anonymous website identification network model, and obtain a trained anonymous website identification network model;
[0071] Specifically, the training process of the anonymous website identification network model in step S3 is as follows:
[0072] S31. Divide the training set from the concentrated monitoring website traffic, preprocess the website traffic data in the training set, and input the preprocessed website traffic data into the feature extraction module;
[0073] S32. The feature extraction module extracts the preliminary feature vectors according to the input website traffic data, and inputs the preliminary feature vectors into the feature fusion module;
[0074] S33. The feature fusion module first converts the preliminary feature vectors into a feature matrix, and then performs singular value decomposition on the feature matrix using the SVD matrix decomposition method to obtain the optimal feature vectors corresponding to the input website traffic data;
[0075] Specifically, the representation of the optimal feature vectors in step S33 is as follows:
[0076] F w = CNN(LSTM(x))
[0077] where F w is the preliminary feature vector extracted from the input data x through LSTM and CNN.
[0078] S34. Input the optimal feature vectors into the recognition and classification module. The recognition and classification module calculates the distances between the input optimal feature vectors and the representative feature vectors of the preset monitored websites respectively. When the distance is less than the preset threshold, it is considered that the website corresponding to the input optimal feature vector belongs to the monitored website and report it. Otherwise, it is considered that the website corresponding to the input optimal feature vector is a non-monitored website;
[0079] Specifically, the acquisition method of the optimal feature vectors of the preset monitored websites in step S34 is as follows:
[0080] First, if there is only one monitored website, first obtain the multi-segment traffic data information of the monitored website, preprocess the multi-segment traffic data information, and make the preprocessed multi-segment traffic data information into a monitored website training data set. Assume that the monitored website training data set has n training data. Use the feature extraction module to process the n training data in sequence to obtain n preliminary feature vectors corresponding to the monitored website. Then aggregate the n preliminary feature vectors into a matrix, perform singular value decomposition on the aggregated feature matrix using the SVD matrix decomposition method, and extract the first left singular vector as the representative feature vector of the monitored website;
[0081] The representation of the representative feature vector of the monitored website is as follows:
[0082] M s = U∑V T
[0083] F s = U[:, 1]
[0084] where U and V are orthogonal matrices, ∑ is a diagonal matrix with singular values along the diagonal, M s is the feature matrix for monitoring website s, and F s is the representative feature vector for monitoring website s;
[0085] If there are multiple such monitoring websites, repeat the above method to process each monitoring website in sequence to obtain representative feature vectors corresponding to multiple monitoring websites.
[0086] S35. Repeat steps S31 - S34 to train the anonymous website recognition network model until the model meets the termination condition. Take the anonymous website recognition network model obtained at this time as the trained anonymous website recognition network model and save the parameters.
[0087] Specifically, the derivation process of the loss function during the training of the anonymous website recognition network is as follows:
[0088] Since the anonymous website recognition network model must calculate the loss between the feature vector of the training sample and each category during the training process to optimize the model, the traditional cross - entropy loss is not suitable for this task. The traditional cross - entropy loss only calculates the loss between the predicted category and the true category of the sample, ignoring the loss between the predicted category and other categories. To solve this problem, we introduce a new loss function.
[0089] After calculating the cosine similarity between the feature vectors extracted by the feature extraction module and the feature fusion module and the orthogonal vector of the last layer of the model, we calculate the loss value of the prediction result. The closer the cosine similarity is to 1, the higher the similarity. Therefore, we calculate the difference between the cosine similarity and 1 as the loss value loss true for the true label, as follows.
[0090] loss true = 1 - CosineSimilarity true_s
[0091] where loss true is the loss between the predicted value and the true sample, and CosineSimilarity s is the cosine similarity between this sample and the weight vector of website s.
[0092] Then, we calculate the cosine similarity between the predicted value and other labels. Our goal is to minimize the cosine similarity, so we directly use the average value as the loss value y false, as shown below. Finally, we add the above two losses to obtain the final loss value.
[0093]
[0094] loss 总 = loss false + loss true
[0095] where loss 总 is the total loss function, loss false is the loss between the predicted value and other non-real samples, CosineSimilarity strue_s is the cosine similarity between the weight vector of this sample to the real website s, and N C is the total number of monitored websites.
[0096] S4. Input the collected anonymized website traffic data information to be recognized into the trained anonymized website recognition network model to recognize whether the anonymized website traffic data information contains the monitored websites.
[0097] Embodiment 2
[0098] As Figure 3 shown, a website recognition system for an anonymous communication network, used to implement the website recognition method for an anonymous communication network described in Embodiment 1. The system includes:
[0099] A sample acquisition module, used to acquire traffic data information of multiple monitored websites, preprocess and label the traffic data information of the multiple monitored websites, establish a monitored website traffic set, and divide it into a training set and a test set; the traffic data information includes website traffic sequence direction information and time information;
[0100] A model construction module, used to construct an anonymized website recognition network model, and the anonymized website recognition network model includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence;
[0101] A model training module, used to train the anonymized website recognition network model with the training set obtained by the sample acquisition module to obtain a trained anonymized website recognition network model;
[0102] A to-be-recognized website traffic data information receiving module, used to receive in real time the anonymized website traffic data information transmitted by a law enforcement agency, and preprocess the anonymized website traffic data information to be recognized;
[0103] An anonymous website recognition module, which is configured to input the traffic data information of the anonymous website to be recognized into the trained anonymous website recognition network model, recognize whether the traffic data information of the anonymous website to be recognized contains the monitored website, and output corresponding results;
[0104] An early warning module, which is configured to send a corresponding early warning signal to the law enforcement agency according to the result output by the anonymous website recognition module.
[0105] Embodiment 3
[0106] As Figure 4 shown, this embodiment provides a computer device, which includes a processor 102, a memory, an input device 103, a display 104, and a network interface 105 connected through a system bus 101. Among them, the processor 102 is used to provide computing and control capabilities. The memory includes a non-volatile storage medium 106 and an internal memory 107. The non-volatile storage medium 106 stores an operating system, a computer program, and a database. The internal memory 107 provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium 106. When the computer program is executed by the processor 102, the website recognition method for the anonymous communication network described in Embodiment 1 is implemented.
[0107] Embodiment 4
[0108] As Figure 5 shown, this embodiment provides a storage medium storing a program, and when the program is executed by a processor, the website recognition method for the anonymous communication network described in Embodiment 1 is implemented.
[0109] It should be noted that the computer-readable storage medium in this embodiment may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0110] In this embodiment, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In this embodiment, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0111] The above computer-readable storage medium can be written in one or more programming languages or combinations thereof for executing the computer program of this embodiment. The above programming languages include object-oriented programming languages - such as Java, Python, C++, and also include conventional procedural programming languages - such as C language or similar programming languages. The program can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or, can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0112] In summary, the present invention uses a trained anonymous website recognition network model to recognize the traffic data information of the anonymous website to be recognized, and can accurately identify whether the traffic data information of the anonymous website to be recognized contains monitoring website information, so as to assist law enforcement officers such as public security network security departments and government regulatory agencies to better supervise network security and track illegal acts, improving the security of the network environment. In addition, the anonymous website recognition network model of the present invention only uses monitoring websites as training data, enabling the model to also distinguish monitoring websites and non-monitoring websites with a high confidence, effectively solving the problem of poor classification performance of traditional methods when facing non-monitoring websites. Then, in order to improve the feature extraction ability of the model, the feature extraction module of the anonymous website recognition network model uses an LSTM network model to extract features from the data traffic, which is conducive to capturing the temporal dependence relationship in the traffic data. In addition, the anonymous website recognition network model introduces ELU as the activation function to accelerate the convergence of the model and improve the non-linear feature extraction effect. Then, the model also introduces a new loss function to measure the loss value of the model prediction value, better calculating the loss between the prediction value and the true label as well as the non-true label, thus effectively improving the accuracy of model recognition.
[0113] The above specific implementation manners are the preferred embodiments of the present invention and cannot limit the present invention. Any other changes or other equivalent replacement methods that do not deviate from the technical solution of the present invention are included in the protection scope of the present invention.
Claims
1. A method for identifying websites in an anonymous communication network, characterized in that, Including the following steps: S1. Obtain the traffic data information of multiple monitoring websites, preprocess the traffic data information of the multiple different monitoring websites, and construct a monitoring website traffic set; the traffic data information includes website traffic sequence direction information and time information; S2. Construct an anonymous website recognition network model, which includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence; S3. Divide a training set from the monitoring website traffic set to train the anonymous website recognition network model, and obtain a trained anonymous website recognition network model; S4. Input the collected anonymous website traffic data information to be recognized into the trained anonymous website recognition network model to identify whether the anonymous website traffic data information contains the monitoring website.
2. The website identification method for an anonymous communication network according to claim 1, wherein, The training process of the anonymous website recognition network model in step S3 is as follows: S31. Divide a training set from the monitoring website traffic set, preprocess the website traffic data in the training set, and input the preprocessed website traffic data into the feature extraction module; S32. The feature extraction module extracts preliminary feature vectors according to the input website traffic data and inputs the preliminary feature vectors into the feature fusion module; S33. The feature fusion module first converts the preliminary feature vectors into a feature matrix, and then performs singular value decomposition on the feature matrix using the SVD matrix decomposition method to obtain the optimal feature vectors corresponding to the input website traffic data; S34. Input the optimal feature vectors into the identification and classification module, and the identification and classification module calculates the distances between the input optimal feature vectors and the representative feature vectors of the preset monitoring websites respectively. When the distance is less than the preset threshold, it is considered that the website corresponding to the input optimal feature vector belongs to the monitoring website and is reported. Otherwise, it is considered that the website corresponding to the input optimal feature vector is a non-monitoring website; S35. Repeat steps S31 - S34 to train the anonymous website recognition network model until the model meets the termination condition. Take the anonymous website recognition network model obtained at this time as the trained anonymous website recognition network model and save the parameters.
3. The website identification method for an anonymous communication network according to claim 1, wherein In step S2, the feature extraction module uses an LSTM network model, the feature fusion module uses a CNN network model with the last fully connected layer removed, and the identification and classification module is a cosine similarity layer; the LSTM network model, the CNN network model with the last fully connected layer removed, and the cosine similarity layer are connected in sequence.
4. The website identification method for an anonymous communication network according to claim 1, characterized in that, The loss function during the training of the anonymous website recognition network is set as follows: loss true = 1 - CosineSimilarity true_s loss 总 = loss false + loss true Among them, loss 总 is the total loss function, loss true is the loss between the predicted value and the true sample, loss false is the loss between the predicted value and other non-true samples, CosineSimilarity true_s is the cosine similarity between the weight vector of this sample to the true website s, N C is the total number of monitored websites.
5. The website identification method for an anonymous communication network according to claim 1, characterized in that, The anonymous website recognition network uses the ELU activation function as the activation function; The ELU activation function is specifically expressed as follows: where α is set to 1 and x is the input data.
6. The website identification method for an anonymous communication network according to claim 2, characterized in that The representation of the optimal feature vectors in step S33 is as follows: F w = CNN(LSTM(x)) Among them, F w is the preliminary feature vector extracted from the input data x through LSTM and CNN.
7. The website identification method for an anonymous communication network according to claim 2, characterized in that, The obtaining method of the preset representative feature vectors of the monitoring websites in step S34 is as follows: First, if there is only one monitored website, first obtain multiple segments of traffic data information of the monitored website, preprocess the multiple segments of traffic data information, and make the preprocessed multiple segments of traffic data information into a monitored website training dataset. Assuming that the monitored website training dataset has n training data, use the feature extraction module to process the n training data in sequence to obtain n preliminary feature vectors corresponding to the monitored website. Then, aggregate the n preliminary feature vectors into a matrix, perform singular value decomposition on the aggregated feature matrix using the SVD matrix decomposition method, and extract the first left singular vector as the representative feature vector of the monitored website; The representative feature vector of the monitored website is expressed as follows: M s = U∑V T F s = U[:,1] where U and V are orthogonal matrices, ∑ is a diagonal matrix with singular values along the diagonal, M s is the feature matrix for monitoring website s, F s is the representative feature vector for monitoring website s; If there are multiple monitored websites, repeat the above method to process each monitored website in sequence to obtain representative feature vectors corresponding to multiple monitored websites.
8. A website recognition system for an anonymous communication network, which is used to implement the website recognition method for an anonymous communication network according to any one of claims 1-7, characterized in that, Including: A sample acquisition module, configured to acquire traffic data information of multiple monitored websites, preprocess and mark the traffic data information of the multiple monitored websites, establish a monitored website traffic set, and divide it into a training set and a test set; the traffic data information includes website traffic sequence direction information and time information; A model construction module, configured to construct an anonymous website recognition network model, where the anonymous website recognition network model includes a feature extraction module, a feature fusion module, and an identification and classification module connected in sequence; A model training module, configured to train the anonymous website recognition network model using the training set obtained by the sample acquisition module to obtain a trained anonymous website recognition network model; A module for receiving traffic data information of the website to be recognized, configured to receive in real time the traffic data information of the anonymous website to be recognized transmitted by a law enforcement agency, and preprocess the traffic data information of the anonymous website to be recognized; An anonymous website recognition module, configured to input the traffic data information of the anonymous website to be recognized into the trained anonymous website recognition network model, identify whether the traffic data information of the anonymous website to be recognized contains the monitored website, and output a corresponding result; An early warning module, configured to send a corresponding early warning signal to the law enforcement agency according to the result output by the anonymous website recognition module.
9. A computer device, comprising a processor and a memory for storing processor-executable programs, characterized in that When the processor executes the program stored in the memory, it implements the website recognition method for an anonymous communication network according to any one of claims 1-7.
10. A storage medium stores a program, characterized in that, When the program is executed by the processor, it implements the website recognition method for an anonymous communication network according to any one of claims 1-7.