DApp encrypted traffic classification method and device based on graph adaptive convolutional neural network
By constructing a graph adaptive convolutional neural network model, the problem of insufficient capture of traffic feature of DApp encryption is solved, and higher classification accuracy and recognition capabilities are achieved.
Patent Information
- Application Number
- CN202510616555.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-14
- Publication Date
- 2025-07-18
AI Technical Summary
The prior art is difficult to effectively capture the complex and variable characteristics of encrypted traffic of decentralized applications of DApp, and the model generalization capabilities are insufficient, resulting in limited classification accuracy and recognition capabilities of encrypted traffic.
A cryptographic traffic classification method based on graph adaptive convolution neural network is constructed. Through encrypted traffic preprocessing, traffic topology graph construction and graph adaptive convolution neural network model training, the graph convolution layer and adaptive weight mechanism are used to extract traffic features and encrypted traffic classification.
The accuracy of encrypted traffic classification has been improved to 99.4%, an increase of 5% over the existing methods.
Smart Images

Figure CN120342899A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the fields of blockchain and artificial intelligence, and particularly relates to a DApp encrypted traffic classification method and device based on a graph adaptive convolutional neural network. Background Art
[0002] With the popularization of the Internet and the rapid development of information technology, as a new application mode, decentralized application (DApp) is gradually changing the architecture of traditional centralized applications. By encrypting and anonymizing its traffic data, DApp effectively avoids the problem of privacy leakage, but this method also brings new challenges to network security and supervision. As the core component of DApp, encrypted traffic involves a large amount of network communication data and transaction information, and its security and privacy are crucial. Traditional methods for encrypted traffic classification rely on feature engineering and manually designed rules for identification. However, these methods are difficult to handle the complex and variable features of encrypted traffic in DApp, and have limited generalization ability for emerging DApps.
[0003] Currently, research using deep learning methods with the ability to automatically learn features has made progress, such as using traffic interaction graphs and graph neural network models for classification. However, existing methods often cannot fully capture the temporal and structural features of traffic data when dealing with DApp, and still have problems such as insufficient feature expression, insufficient model generalization ability, and difficulty in handling class imbalance. Therefore, further research and optimization of encrypted traffic classification methods are of great significance for improving the recognition ability of DApp. Summary of the Invention
[0004] In order to solve the problems in the background art, the purpose of the present invention is to provide a DApp encrypted traffic classification method based on a graph adaptive convolutional neural network, and the method includes the following steps:
[0005] Preprocessing of encrypted traffic: Cleaning the data information of the decentralized application DApp source traffic dataset Set captured by Ethereum to obtain the cleaned traffic data Data DApp , segmenting the traffic data Data according to the sequence rule P and performing feature selection on the segmented traffic data to obtain an ordered sequence P of traffic data packets P ; i
[0006] Construction of traffic topology graph: Using the obtained ordered traffic data of traffic data packets to construct a traffic topology graph Map Topology and generating a graph set Set Map and constructing a traffic topology graph Map TopologyCorresponding label M t ;
[0007] Construct a graph adaptive convolutional neural network model Model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism. The graph convolutional layer updates the feature representation of nodes from the neighborhood information of nodes in the traffic topology graph structure, captures the temporal and spatial features in network communication, and captures the dynamic associations between traffic flows; the adaptive weight mechanism dynamically adjusts the structure of the traffic topology graph according to the weights of nodes and edges, and optimizes the feature extraction process in the traffic topology graph; for the constructed graph adaptive convolutional neural network model Model ACNN Train to obtain the trained graph adaptive convolutional neural network model Model ACNN ;
[0008] Use the trained graph adaptive convolutional neural network model Model ACNN For encrypted traffic classification: Preprocess the encrypted traffic to be classified and generate a traffic topology graph, and input the generated traffic topology graph into the trained graph adaptive convolutional neural network model Model ACNN , use the fully connected layer to map the graph global aggregation feature h G To a new latent space H G , use the softmax function to obtain the predicted probability vector y ic , and obtain the classification result Results C ; Among them, the graph adaptive convolutional neural network model Model ACNN Is iterated three times by the graph convolutional layer and the adaptive weight mechanism. Nodes are aggregated after each layer, and a sum is taken at the last layer. The sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result.
[0009] Furthermore, in the graph convolutional layer of the graph adaptive convolutional neural network model Model ACNN , use the adjacency matrix A and the corresponding degree matrix D of the traffic topology graph for symmetric normalization to ensure the balanced contribution of each node during feature aggregation; update each node Node i Through sampling and feature aggregation of neighbor nodes; where the update process follows the following graph convolution formula:
[0010]
[0011] Among them, h (l) Represents the feature of the l-th layer, h (l+1) Represents the feature of the l+1-th layer, A is the symmetrically normalized adjacency matrix, D is the diagonal degree matrix of A, W (l) Is the weight matrix of the l-th layer, and σ is the activation function.
[0012] Further, for the graph adaptive convolutional neural network model Model ACNN 's adaptive weight mechanism, calculate the weight α between each node v and its neighbor node u according to the relationship between nodes Node i : Calculate the similarity between the node and its neighbor node using the inner product, and obtain the weight α of each node through softmax normalization vu Specifically: vu That is:
[0013]
[0014] where N(v) is the neighbor set of node v, and e vu′ is a learned weight parameter, representing the contribution of node u ′ to node v, and e vu =<h v ,h ′ u >, representing the inner product between node v and the transformed neighbor node u ′ ;
[0015] Use the obtained weight α vu to weighted-aggregate the features of neighbor node u, and update the feature representation h i of node Node ′ v The update formula is:
[0016]
[0017] where N(v) is the neighbor set of node v, h ′ v is the updated feature representation of node v, and h u is the feature representation of node u
[0018] Further, for the graph adaptive convolutional neural network model Model ACNN , use the max pooling method to perform global aggregation on graphs with different numbers of nodes, and obtain the global feature representation h Map of graph set Set G , and its formula is:
[0019]
[0020] where represents the node feature after K layers of message passing, V is the set of all nodes in the graph, v i is the node in the graph, and Max is the global aggregation function
[0021] The method for obtaining the predicted probability vector y ic is:
[0022] y ic = softmax(W f ·h G + b f );
[0023] where W f ∈ R C×d is a learnable mapping matrix, b f ∈ R C is a bias vector, C is the number of classification categories, d is the dimension of the graph features, and y ic is the probability that graph G i belongs to category c.
[0024] Furthermore, the method for constructing a traffic topology graph Map Topology and generating a graph set Set Map and constructing a traffic topology graph Map Topology corresponding to label M t is as follows:
[0025] 201) Mark the obtained ordered sequence P i of traffic data packets. Use the packet length l i to represent the vertex value, and the direction d i of the data packet to represent the sign of the value, obtaining the ordered traffic data Data S ;
[0026] 202) Use the ordered traffic data Data S to construct a traffic topology graph Map Topology . By adding edges between different levels, connect the vertices to construct an edge set E. Each vertex e ∈ E is divided into between levels and within levels. Connect the starting or ending vertices between consecutive levels with edges to form a level division;
[0027] 203) Add edges connecting each vertex between levels and within levels according to the temporal relationship of the data packets, obtaining the graph set Set Topology of the traffic topology graph Map Map ;
[0028] 204) Construct a traffic topology graph Map Topology corresponding to label M t ; where the label M t is derived from the category predefined for each graph in the dataset Data PA and is used to represent the classification target a N corresponding to each graph, expressed as
[0029] A DApp encrypted traffic classification device based on a graph adaptive convolutional neural network, comprising:
[0030] An encrypted traffic preprocessing module: used to clean the data information of the decentralized application DApp source traffic dataset Set captured by Ethereum to obtain the cleaned traffic data Data DApp and perform traffic data Data segmentation according to sequence rules, and perform feature selection on the segmented traffic data to obtain an ordered sequence P of traffic data packets P ; P ; i ;
[0031] A traffic topology graph construction module: used to construct a traffic topology graph Map using the obtained ordered traffic data of traffic data packets Yopology and generate a graph set Set Map and construct a traffic topology graph Map Topology corresponding label M t ;
[0032] A graph adaptive convolutional neural network model Model ACNN A construction training module: used to construct a graph adaptive convolutional neural network model Model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism. The graph convolutional layer updates the feature representation of nodes from the neighborhood information of nodes in the traffic topology graph structure, captures the temporal and spatial features in network communication, and captures the dynamic associations between traffic; the adaptive weight mechanism dynamically adjusts the structure of the traffic topology graph according to the weights of nodes and edges, and optimizes the feature extraction process in the traffic topology graph; train the constructed graph adaptive convolutional neural network model Model ACNN to obtain a trained graph adaptive convolutional neural network model Model ACNN ;
[0033] An encrypted traffic classification module: used to perform encrypted traffic classification using the trained graph adaptive convolutional neural network model Model ACNN : preprocess the encrypted traffic to be classified and generate a traffic topology graph, input the generated traffic topology graph into the trained graph adaptive convolutional neural network model Model ACNN , use the fully connected layer to map the graph global aggregation feature h G to a new latent space H G , use the softmax function to obtain the predicted probability vector y ic and obtain the classification result Results C ; among them, the graph adaptive convolutional neural network model Model ACNNThe graph convolutional layer and the adaptive weight mechanism are iterated three times. Nodes are aggregated after each layer and summed at the last layer, and the sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result.
[0034] Furthermore, the present invention adopts the following technical solutions:
[0035] A non-transitory computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, it implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network as described above.
[0036] Even further, the present invention adopts the following technical solutions:
[0037] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network as described above.
[0038] The beneficial technical effects of the present invention are:
[0039] The present invention proposes a DApp encrypted traffic recognition method based on a graph adaptive convolutional neural network, constructs a traffic topology graph using temporal traffic data, and designs a graph adaptive convolutional neural network model on this basis to extract key information. The proposed model learns local node representations through the graph convolutional layer and introduces adaptive weights to enhance node features; the present invention uses a real encrypted traffic dataset to verify the effectiveness of this method, and the classification accuracy reaches 99.4%, which is 5% higher than the existing method. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 It is a flowchart of the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network provided by the embodiment of the present invention. DETAILED DESCRIPTION
[0041] The following further clearly and completely describes the DApp encrypted traffic classification method and device based on the graph adaptive convolutional neural network provided by the present invention with reference to the drawings:
[0042] Embodiment 1
[0043] Figure 1 It is a flowchart of the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network provided by this embodiment; the present invention provides a DApp encrypted traffic classification method based on the graph adaptive convolutional neural network, and the method includes the following steps:
[0044] S1. Encrypted traffic preprocessing: Clean the data information in the traffic dataset Set from decentralized applications DApp captured on Ethereum to obtain the cleaned traffic data Data DApp and segment the traffic data Data according to the sequence rule P and perform feature selection on the segmented traffic data to obtain an ordered sequence P of traffic data packets P ; where the captured traffic dataset Set from decentralized applications DApp i is the top 15 different categories of decentralized applications DApp most used by users on Ethereum, including social communication applications, finance, online shopping, etc. Raw traffic data is collected from Ethereum and stored locally, and each row contains the five-tuple information tuple DApp obtained from the traffic data packet Packet data . data
[0045] When performing encrypted traffic preprocessing, the specific steps are as follows:
[0046] 101). Import the traffic dataset Set from decentralized applications DApp DApp , clean and filter redundant data, including filtering sessions with TCP handshake failures, sessions missing Client Hello packets or SNI fields, removing ACK packets and retransmission packets, filtering sessions with abnormal or too large packet lengths, etc. Independently segment each traffic session in the cleaned traffic data Data P by packets to obtain the segmented traffic data Data PA , and the traffic data Data PA contains multiple traffic sessions P i source , that is:
[0047] Data PA ={P1 source , P2 source ,…, P n source}
[0048] The data in P i source has the same five-tuple information tuple data , and the five-tuple information tuple data in the data packets is arranged in chronological order, specifically as follows:
[0049] tuple data ={source, target, protocal, size, message}
[0050] Among them, source represents the source address, target represents the destination address, protocal represents the traffic protocol, size represents the packet size, and message represents the traffic message;
[0051] 102), Each traffic session consists of multiple data packets; Each traffic session containing n data packets in the segmented dataset Data PA ={P1, P2,...} can usually be represented by a data packet sequence, that is where P i j represents the jth data packet of the ith traffic session; For the segmented traffic data Data PA feature selection is performed. According to the unique attributes and communication behavior characteristics of the decentralized application DApp traffic, the data packet length l i , the data packet direction d i and the arrival time t of the data packet i are selected as the main features to form an ordered sequence of traffic data packets, in the form of:
[0052]
[0053] S2. Traffic topology graph construction: Use the obtained ordered traffic data of traffic data packets to construct a traffic topology graph Map Topology , and generate a graph set Set Map , and construct a traffic topology graph Map Topology corresponding to the label M t ; Among them, the graph set {G1, G2,..., G N}∈G, G=(V, E), V is the set of vertices, and E is the set of edges.
[0054] Specifically, when constructing the traffic topology graph, the following steps are specifically included:
[0055] 201) Mark the obtained ordered sequence P of traffic data packets i , use the data packet length l i to represent the vertex value, and the direction d of the data packet i to represent the sign of the value (the direction d of the data packet i is determined by the combination of the source IP address source and the destination IP address target), and obtain the ordered traffic data Data S ; Among them, the ordered sequence Seq of traffic data packets o is used as the input to construct the vertex set V, and each vertex v∈V represents a data packet in each traffic session; The traffic sent by the decentralized application DApp client is marked as the negative direction, and the traffic returned by the server is marked as the positive direction;
[0056] 202) Use the ordered traffic data Data S Construct the traffic topology map Map Topplogy When constructing the edge set E by adding edges between different levels and connecting vertices, each vertex e ∈ E is divided into between levels and within levels. Connect the starting or ending vertices between consecutive levels with edges to form a level division. Among them, the state transitions within a segment of the same level (where the data packets or states are at the same protocol layer) are relatively stable and continuous. Therefore, place the data packets in the same direction segment at the same level and add edges to connect the starting and ending points of the levels between segments;
[0057] 203) Add edges connecting each vertex between levels and within levels according to the timing relationship of the data packets to obtain the traffic topology map Map Topology of the graph set Set Map Among them, add the edge attributes representing the timing characteristics of the data packets between different levels and within levels to help the model understand and process complex timing information, improving the accuracy of classification and the interpretability of the model;
[0058] 204) Construct the traffic topology map Map Topology corresponding to the label M t ; where the label M t comes from the category predefined for each graph in the data set Data PA and is used to represent the classification target a corresponding to each graph N , expressed as
[0059] S3. Construct the graph adaptive convolutional neural network model Model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism, aiming to capture local features and alleviate the impact of the sample imbalance problem. The graph convolutional layer updates the feature representation of the nodes from the neighborhood information of the nodes in the traffic topology map structure, captures the timing and spatial features in network communication, and captures the dynamic associations between traffic; the adaptive weight mechanism dynamically adjusts the structure of the traffic topology map according to the weights of the nodes and edges, optimizing the feature extraction process in the traffic topology map; train the constructed graph adaptive convolutional neural network model Model ACNN to obtain the trained graph adaptive convolutional neural network model Model aCNN ; The settings of the graph convolutional layer and the adaptive weight mechanism help the model better classify encrypted traffic in a complex network environment, and can also assign higher weights to minority class samples, so that the model pays more attention to them during training, improving the classification performance of minority class samples and effectively alleviating the impact of the sample imbalance problem;
[0060] S4. Use the trained graph adaptive convolutional neural network model Model ACNN to perform encrypted traffic classification: preprocess the encrypted traffic to be classified and generate a traffic topology graph, and input the generated traffic topology graph into the trained graph adaptive convolutional neural network model Model ACNN , use the fully connected layer to globally aggregate the graph feature h G and map it to a new latent space H G , use the softmax function to obtain the predicted probability vector y ic , and obtain the classification result Results C ; among them, the graph adaptive convolutional neural network model Model ACNN is iterated three times by the graph convolutional layer and the adaptive weight mechanism. Nodes are aggregated after each layer, and a sum is taken at the last layer. The sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result Results C .
[0061] It should be noted that in the graph convolutional layer of the graph adaptive convolutional neural network model Model ACNN , symmetric normalization is performed using the adjacency matrix A and the corresponding degree matrix D of the traffic topology graph to ensure the balanced contribution of each node during feature aggregation; each node Node is updated through sampling and feature aggregation of neighbor nodes i ; among them, the update process follows the following graph convolution formula:
[0062]
[0063] where h (l) represents the feature of the l-th layer, h (l+1) represents the feature of the (l + 1)-th layer, A is the symmetrically normalized adjacency matrix, D is the diagonal degree matrix of A, W (l) is the weight matrix of the l-th layer, and σ is the activation function
[0064] For the adaptive weight mechanism of the graph adaptive convolutional neural network model Model AcNN , calculate the weight α of each node v and its neighbor node u according to the relationship between nodes Node i : calculate the similarity between the node and its neighbor node using the inner product, and obtain the weight α of each node through softmax normalization vu , specifically: vi
[0065]
[0066] where N(v) is the neighbor set of node v, e vu′ is a learned weight parameter representing node u ′ 's contribution to node v, e vu = <h v , h ′ u >, representing the inner product between node v and the transformed neighboring node u ′ ;
[0067] Utilize the obtained weight α vu to weighted-aggregate the features of neighboring node u and update the feature representation h i of node Node ′ v . The update formula is:
[0068]
[0069] where N(v) is the neighbor set of node v, h ′ v is the updated feature representation of node v, and h u is the feature representation of node u.
[0070] The described graph adaptive convolutional neural network model Model ACNN , uses the max pooling method to globally aggregate graphs with different numbers of nodes to obtain the global feature representation h Map of graph set Set G . The formula is:
[0071]
[0072] where represents the node features after K layers of message passing, V is the set of all nodes in the graph, v i is a node in the graph, and Max is the global aggregation function;
[0073] The method for obtaining the predicted probability vector y ic is:
[0074] y ic = softmax(W f ·h G + b f );
[0075] W f ∈ R C×d is a learnable mapping matrix, b f ∈ R C is a bias vector, C is the number of classification categories, d is the dimension of the graph features, and y ic is the probability that graph G i belongs to category c.
[0076] For example, in this embodiment, in order to verify the accuracy of the method of the present invention, the method of this embodiment and other methods are used to evaluate the encrypted traffic classification:
[0077] The accuracy rate results are obtained through the 10-fold cross-validation method. Select the comparison method and use standard evaluation indicators such as accuracy rate and recall rate to compare and evaluate the performance of various methods. Solve the loss function L, and calculate the loss between the predicted label and the true label in the multi-classification problem. The formula is as follows:
[0078]
[0079] Among them, α represents the class balance factor, and γ represents the focusing factor. represents the true value of the class, C represents the class, and N represents the sample.
[0080] The data set to be classified is divided into 10 subsets of equal size. One subset is used as the test set, and the other 9 subsets are used for training; this is performed 10 times, and each subset is used as the test set once. Use the evaluation indicators of precision and recall to evaluate the classification results of the model in this paper and comparison methods such as MARK, APPS, FFP, and CBFM. Finally, calculate the average result of 10 experiments to obtain the final classification accuracy rate of 99.4%.
[0081]
[0082]
[0083] Among them, ACC represents the accuracy rate, and Recall represents the recall rate.
[0084] Embodiment 2
[0085] This embodiment provides a decentralized application encrypted traffic classification device based on a graph adaptive convolutional neural network, including:
[0086] An encrypted traffic preprocessing module: used to clean the data information of the traffic data set Set from the decentralized application DApp sources captured by Ethereum to obtain the cleaned traffic data Data DApp , and perform traffic data Data P segmentation according to the sequence rule, and perform feature selection on the segmented traffic data to obtain an ordered sequence P of traffic data packets P ; i ;
[0087] A traffic topology graph construction module: used to construct a traffic topology graph Map using the obtained ordered traffic data of traffic data packets Topology , and generate a graph set Set Map , and construct a traffic topology graph Map TopologyCorresponding label M t ;
[0088] Graph Adaptive Convolutional Neural Network Model Model ACNN Construct a training module for constructing the Graph Adaptive Convolutional Neural Network Model Model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism. The graph convolutional layer updates the feature representation of nodes from the neighborhood information of nodes in the traffic topology graph structure, captures the temporal and spatial features in network communication, and captures the dynamic associations between traffic; the adaptive weight mechanism dynamically adjusts the structure of the traffic topology graph according to the weights of nodes and edges, and optimizes the feature extraction process in the traffic topology graph; for the constructed Graph Adaptive Convolutional Neural Network Model Model ACNN Perform training to obtain the trained Graph Adaptive Convolutional Neural Network Model Model ACNN ;
[0089] An encrypted traffic classification module for using the trained Graph Adaptive Convolutional Neural Network Model Model ACNN To perform encrypted traffic classification: preprocess the encrypted traffic to be classified and generate a traffic topology graph, and input the generated traffic topology graph into the trained Graph Adaptive Convolutional Neural Network Model Model ACNN , use a fully connected layer to map the global aggregated feature h of the graph G To a new latent space H G , use the softmax function to obtain the predicted probability vector y ic , and obtain the classification result Results C ; Among them, the Graph Adaptive Convolutional Neural Network Model Model ACNN Is iterated three times by the graph convolutional layer and the adaptive weight mechanism. Nodes are aggregated after each layer and summed at the last layer, and the sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result.
[0090] Furthermore, the present invention adopts the following technical solutions:
[0091] A non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network as described above.
[0092] Even further, the present invention adopts the following technical solutions:
[0093] An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, it implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network as described above.
[0094] Through the description of the above embodiments, those skilled in the art can clearly understand that the facilities of the present invention can be implemented by means of software plus a necessary general hardware platform. The embodiments of the present invention can be implemented using existing processors, or by dedicated processors used for this purpose or other purposes in a suitable system, or by a hardwired system. The embodiments of the present invention also include non-transitory computer-readable storage media, which include machine-readable media for carrying or having machine-executable instructions or data structures stored thereon; such machine-readable media can be any available medium accessible by a general or special-purpose computer or other machine having a processor. For example, such machine-readable media can include RAM, ROM, EPROM, EEPROM, CD-ROM or other optical disk memories, magnetic disk memories or other magnetic storage devices, or any other medium that can be used to carry or store the required program code in the form of machine-executable instructions or data structures and can be accessed by a general or special-purpose computer or other machine with a processor. When information is transmitted or provided to a machine through a network or other communication connection (hardwired, wireless, or a combination of hardwired and wireless), the connection is also regarded as a machine-readable medium.
[0095] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the protection scope of the present invention.
Claims
1. A DApp encrypted traffic classification method based on a graph adaptive convolutional neural network, characterized in that The method includes the following steps: Preprocessing of encrypted traffic: Clean the data information of the traffic dataset Set from decentralized applications (DApps) captured by Ethereum to obtain the cleaned traffic data Data DApp , and perform feature selection on the split traffic data according to the sequence rules to obtain the ordered sequence P of traffic data packets P , split the traffic data Data P according to the sequence rules, and perform feature selection on the split traffic data to obtain the ordered sequence P of traffic data packets i ; Traffic topology graph construction: Construct a traffic topology graph Map using the ordered traffic data of the obtained traffic data packets Topology , and generate a graph set Set Map , and construct a traffic topology graph Map Topology Corresponding label M t ; Constructing a Graph Adaptive Convolutional Neural Network Model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism. The graph convolutional layer updates the feature representation of nodes from the neighborhood information of nodes in the traffic topology graph structure, captures the temporal and spatial features in network communication, and captures the dynamic associations between traffic flows; The adaptive weight mechanism dynamically adjusts the structure of the traffic topology graph according to the weights of nodes and edges, optimizing the feature extraction process in the traffic topology graph; Train the constructed graph adaptive convolutional neural network model Model ACNN to obtain the trained graph adaptive convolutional neural network model Model ACNN ; Using the trained graph adaptive convolutional neural network model Model ACNN for encrypted traffic classification: preprocess the encrypted traffic to be classified and generate a traffic topology graph, and input the generated traffic topology graph into the trained graph adaptive convolutional neural network model Model ACNN , use the fully connected layer to globally aggregate the graph feature h G and map it to a new latent space H G , use the softmax function to obtain the predicted probability vector y ic , and obtain the classification result Results C ; among them, the graph adaptive convolutional neural network model Model ACNN is iterated three times by the graph convolutional layer and the adaptive weight mechanism. Nodes are aggregated after each layer, and a sum is taken at the last layer. The sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result.
2. The DApp encrypted traffic classification method based on the graph adaptive convolutional neural network according to claim 1, wherein The described graph adaptive convolutional neural network model Model ACNN In the graph convolutional layer, symmetric normalization is performed using the adjacency matrix A of the traffic topology graph and the corresponding degree matrix D to ensure the balanced contribution of each node during feature aggregation; each node Node is updated through sampling and feature aggregation of neighbor nodes i ; where the update process follows the following graph convolution formula: where, h (l) represents the feature of the l-th layer, h (l+1) represents the feature of the (l + 1)-th layer, A is a symmetric normalized adjacency matrix, D is the diagonal degree matrix of A, W (l) is the weight matrix of the l-th layer, and σ is the activation function.
3. The DApp encrypted traffic classification method based on a graph adaptive convolutional neural network according to claim 1, wherein The described graph adaptive convolutional neural network model Model ACNN 's adaptive weight mechanism calculates the weight α of each node v and its neighbor node u according to the relationship between nodes Node i : Calculate the similarity between the node and its neighbor node using the inner product, and obtain the weight α of each node through softmax normalization vu Specifically: vu where N(v) is the set of neighbors of node v, and e vu′ is a learned weight parameter representing the contribution of node u ′ to node v, and e vu = <h v , h ′ u >, representing the inner product between node v and the transformed neighbor node u ′ ; Using the obtained weight α vu Weightedly aggregate the features of neighbor node u and update the feature representation h of node Node i as follows: ′ v , and the update formula is: where N(v) is the set of neighbors of node v, h ′ v is the updated feature representation of node v, and h u is the feature representation of node u.
4. The DApp encrypted traffic classification method based on the graph adaptive convolutional neural network according to claim 1, wherein The described graph adaptive convolutional neural network model Model ACNN , uses the max pooling method to globally aggregate graphs with different numbers of nodes to obtain a graph set Set Map of the global feature representation h G , and its formula is: Among them, represents the node features after K - layer message passing. V is the set of all nodes in the graph, and v i is a node in the graph, and Max is the global aggregation function; The method for obtaining the predicted probability vector y ic is as follows: y ic = softmax(W f ·h G + b f ); Among them, W f ∈R C×d is a learnable mapping matrix, b f ∈R C is a bias vector, C is the number of classification categories, d is the dimension of the graph feature, and y ic is the probability that the graph G i belongs to the category c.
5. The DApp encrypted traffic classification method based on the graph adaptive convolutional neural network according to claim 1, characterized in that Construct a traffic topology graph Map using the ordered traffic data of the obtained traffic data packets Topology and generate a graph set Set Map and construct a traffic topology graph Map Topology corresponding label M t The method is as follows: (201) Mark the ordered sequence P of the obtained traffic data packets i using the data packet length l i to represent the vertex value, and the direction d of the data packet i to represent the sign of the value, obtaining the ordered traffic data Data S ; 202) Utilize ordered traffic data Data S Construct a traffic topology map Map Topology , by adding edges between different levels, connect vertices to construct an edge set E. Each vertex e ∈ E is divided into between levels and within levels. Connect the starting or ending vertices between consecutive levels with edges to form a level division; (203) Add edges between connection levels and to each vertex within a level according to the timing relationship of data packets to obtain a traffic topology graph Map Yopology graph set Set Map ; Build the traffic topology map Map Topology Corresponding label M t ; where label M t comes from the category predefined for each graph in the dataset Data PA and is used to represent the classification target a corresponding to each graph N , expressed as 6. The DApp encrypted traffic classification device based on the graph adaptive convolutional neural network is characterized in that including: Encryption traffic preprocessing module: used to clean the data information of the traffic dataset Set from decentralized applications (DApps) captured by Ethereum DApp to obtain the cleaned traffic data Data P , segment the traffic data Data P according to the sequence rule, and perform feature selection on the segmented traffic data to obtain the ordered sequence P of traffic data packets i ; Traffic topology graph construction module: used to construct a traffic topology graph Map using the ordered traffic data of the obtained traffic data packets Topology , and generate a graph set Set Map , and construct a traffic topology graph Map Topology corresponding label M t ; Graph Adaptive Convolutional Neural Network Model ACNN Construct a training module for constructing a graph adaptive convolutional neural network model ACNN , the model includes a graph convolutional layer and an adaptive weight mechanism. The graph convolutional layer updates the feature representation of nodes from the neighborhood information of nodes in the traffic topology graph structure, captures the temporal and spatial features in network communication, and captures the dynamic associations between traffic flows; The adaptive weight mechanism dynamically adjusts the structure of the traffic topology graph according to the weights of nodes and edges, optimizing the feature extraction process in the traffic topology graph; Train the constructed graph adaptive convolutional neural network model Model ACNN to obtain the trained graph adaptive convolutional neural network model Model ACNN ; An encrypted traffic classification module for classifying encrypted traffic by using the trained graph adaptive convolutional neural network model Model ACNN for encrypted traffic classification: preprocess the encrypted traffic to be classified and generate a traffic topology graph, and input the generated traffic topology graph into the trained graph adaptive convolutional neural network model Model ACNN , use the fully connected layer to globally aggregate the graph feature h G and map it to a new latent space H G , use the softmax function to obtain the predicted probability vector y ic , and obtain the classification result Results C ; among them, the graph adaptive convolutional neural network model Model ACNN is iterated three times by the graph convolutional layer and the adaptive weight mechanism. Nodes are aggregated after each layer, and a sum is made at the last layer. The sum of the global representations is passed to the fully connected layer for classification prediction to obtain the final classification result.
7. A non-transitory computer-readable storage medium storing a computer program thereon, characterized in that, When executed by a processor, the computer program implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network according to any one of claims 1 to 5.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the DApp encrypted traffic classification method based on the graph adaptive convolutional neural network according to any one of claims 1 to 5.