Business action identification method

By extracting and matching the characteristic symbol sequence of App traffic, the problem that DPI method cannot recognize App business actions is solved, and the accurate identification of App business actions and user intention behavior is achieved is achieved, and the accuracy of network equipment's evaluation of user experience is improved.

CN120416104APending Publication Date: 2025-08-01ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410133913.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-30
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing DPI method cannot accurately identify the business actions of mobile application apps, especially the complex traffic composition of the app's first screen opening action, which leads to network devices being unable to accurately analyze user behavior intentions.

Method used

By obtaining the traffic data flow of the business actions to be identified, the flow characteristics are extracted, and a feature symbol sequence is generated based on the preset mapping relationship, the feature symbols are matched to determine the business actions, and the feature symbols in the feature symbol sequence are used to match the feature symbols of the target business actions to identify and belong to complex App cloud service traffic.

Benefits of technology

It realizes accurate identification of App business actions, can more accurately evaluate users' online experience, and provides a reasonable basis for network optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416104A_ABST
    Figure CN120416104A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a service action identification method, which comprises the following steps: acquiring a data stream in the traffic of a to-be-identified service action, and extracting a stream feature of the to-be-identified service action from the data stream; generating a feature symbol sequence of the to-be-identified service action according to the flow feature of the to-be-identified service action and a preset mapping relationship; wherein the preset mapping relationship is a mapping relationship between the flow feature of the target service action and the feature symbol of the target service action; and under the condition that the feature symbols in the feature symbol sequence are matched with the feature symbols of the target service action, determining that the to-be-identified service action is the target service action. According to the method and the device, the problem that a DPI method in the related technology cannot accurately identify the service action in the APP is solved, the service action in the APP can be accurately identified to represent the intention behavior of the user, the network equipment can more accurately evaluate the internet surfing experience of the user, and a reasonable basis can be provided for a network optimization function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communications, and in particular, to a method for identifying service actions. Background Art

[0002] In recent years, with the continuous development of the mobile Internet, the traffic composition of mobile applications (Apps) has become increasingly complex, making it increasingly difficult for network devices to accurately identify the user service actions of Apps by detecting the network traffic of Apps in order to analyze the user behavior intention.

[0003] For example, generally, the speed of opening the first screen of an App will bring different usage experiences and feelings to users. Network devices hope to detect the action of opening the first screen of the App through the DPI (Deep Packet Inspection) function, so as to analyze the corresponding traffic metrics, measure the user's Internet experience, and trigger further network optimization processing strategies. However, the traffic composition of the action of opening the first screen of the App is usually very complex, and the existing DPI methods cannot accurately identify this service action. Summary of the Invention

[0004] The embodiments of the present application provide a method for identifying service actions to at least solve the problem that the DPI method in the related art cannot accurately identify service actions in an APP.

[0005] According to an embodiment of the present application, a method for identifying service actions is provided, including:

[0006] Obtain the data stream in the traffic of the service action to be identified, and extract the flow characteristics of the service action to be identified from the stream;

[0007] Generate a feature symbol sequence of the service action to be identified according to the flow characteristics of the service action to be identified and a preset mapping relationship; wherein, the preset mapping relationship is the mapping relationship between the flow characteristics of the target service action and the feature symbols of the target service action;

[0008] When the feature symbols in the feature symbol sequence match the feature symbols of the target service action, determine that the service action to be identified is the target service action.

[0009] According to another embodiment of the present application, a computer-readable storage medium is further provided. A computer program is stored in the computer-readable storage medium, wherein the computer program is configured to execute the steps in any one of the above method embodiments when running.

[0010] According to another embodiment of the present application, an electronic device is further provided, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0011] In the present application, data streams in the traffic of the service action to be recognized are obtained, and flow features of the service action to be recognized are extracted from the data streams; a mapping relationship and feature symbols of the target service action are obtained; the mapping relationship is a mapping relationship between flow features and feature symbols; according to the flow features of the service action to be recognized and the mapping relationship, a sequence of feature symbols of the service action to be recognized is generated; when the feature symbols in the sequence of feature symbols match the feature symbols of the target service action, it is determined that the service action to be recognized is the target service action, solving the problem that the DPI method in the related art cannot accurately recognize service actions in an APP, being able to accurately recognize service actions in an APP to characterize the user's intention behavior. Thus, the evaluation of the user's Internet experience by the network device is more accurate, and a reasonable basis can be provided for the network optimization function. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is a hardware structure block diagram of a mobile terminal for a method for recognizing a service action according to an embodiment of the present application;

[0013] Figure 2 is an architecture diagram of a network traffic user intention detection system according to an embodiment of the present application;

[0014] Figure 3 is a flowchart of a method for recognizing a service action according to an embodiment of the present application;

[0015] Figure 4 is a five-tuple flow representation intention according to an embodiment of the present application;

[0016] Figure 5 is a schematic diagram of a single-character feature symbol of a feature symbol mapping form according to an embodiment of the present application;

[0017] Figure 6 is a schematic diagram of a double-character feature symbol of a feature symbol mapping table according to an embodiment of the present application;

[0018] Figure 7 is a schematic diagram of a traffic detection process according to an embodiment of the present application;

[0019] Figure 8 is a schematic diagram of feature matching in the traffic detection stage according to an embodiment of the present application;

[0020] Figure 9 is a user representation intention according to an embodiment of the present application;

[0021] Figure 10Schematic diagram of reporting recognition result messages according to embodiments of the present application;

[0022] Figure 11 Schematic diagram of the feature training process according to embodiments of the present application;

[0023] Figure 12 Schematic diagram of adjacent compression of feature symbol sequences according to embodiments of the present application;

[0024] Figure 13 Schematic diagram of obtaining the longest common feature symbol subsequence according to embodiments of the present application;

[0025] Figure 14 Schematic diagram of the multi-sequence LCS algorithm according to embodiments of the present application;

[0026] Figure 15 Schematic diagram of obtaining start class, end class, and existence class feature symbols according to embodiments of the present application;

[0027] Figure 16 Schematic diagram of obtaining attribution class feature symbols according to embodiments of the present application. Detailed implementation manners

[0028] Embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments.

[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.

[0030] Embodiments of the present invention are described by taking the opening action of the first screen of an APP as an example. When a user opens the App on the device, the App not only connects to various servers of its manufacturer, but also calls a variety of public API cloud services (such as: risk control service, domain name query service, mobile advertising service, log service, etc.) to connect to the corresponding API servers; its traffic composition is very complex, often generating hundreds of TCP connections to dozens of different domain name HTTP / HTTPS servers. However, the usual DPI detection method will independently identify the APP connection traffic and the connection traffic of each API cloud service, which results in the inability to accurately identify the opening action of the first screen of the App and also unable to attribute the traffic of each API cloud service to the opening action of the first screen of the App.

[0031] Based on the above existing technical problems, an embodiment of the present application proposes a method for identifying service actions. The technical concept lies in converting the data stream in the service action traffic to be identified into corresponding feature symbols, and matching the feature symbols of the service to be identified with the feature symbols of the target service actions in the feature file. In the case of a match, it is determined that the service action to be identified is the target service action. This can not only accurately detect whether the service action to be identified, which represents the user's intended behavior, is the target service action, but also accurately classify complex traffic such as access to common App cloud services in the target service action into the corresponding service actions. Thus, the evaluation of the user's Internet experience by the network device is more accurate, and a reasonable basis can be provided for network optimization functions.

[0032] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Taking the operation on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of a mobile terminal for a method of identifying service actions according to an embodiment of the present application. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1 processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above mobile terminal. For example, the mobile terminal may further include more or fewer components than Figure 1 shown, or have a different configuration from

[0033] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the method for identifying service actions in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided with respect to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise internal network, a local area network, a mobile communication network, and their combinations.

[0034] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of a mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0035] Figure 2 is an architecture diagram of a network traffic user intention detection system according to an embodiment of the present application. The embodiment of the present application can run on Figure 2 the system architecture shown, such as Figure 2 shown, the system architecture includes: a feature training module, a traffic detection module, where:

[0036] The feature training module can be used to sample the target service action traffic, extract the flow features of the data stream in the target service action traffic, assign a unique feature symbol to each flow feature, and establish a feature symbol mapping table; sample the target service action traffic multiple times, and generate multiple feature symbol sequences corresponding to the target service action traffic based on the feature symbol mapping table, and extract the common feature symbols from the multiple feature symbol sequences, and respectively use them as the recognition class feature symbols and attribution class feature symbols of the target service action.

[0037] Among them, the recognition class feature symbols and attribution class feature symbols are used to complete the recognition of service actions, improve the recognition accuracy, and realize the attribution of relevant traffic such as API cloud services to the corresponding service actions.

[0038] The traffic detection module can be used to extract the flow features of the data stream in the traffic of the service action to be recognized, generate a feature symbol sequence of the service action to be recognized based on the feature symbol mapping table, and match the feature symbols in the feature symbol sequence of the service action to be recognized with the recognition class feature symbols and attribution class feature symbols of the target service action respectively. On the one hand, it recognizes the occurrence of the target service action, and on the other hand, it attributes the relevant traffic of the service action to be recognized to the target service action, so as to realize the accurate recognition of service actions and traffic.

[0039] It should be noted that the above-mentioned network traffic user intention detection system can be used as an independent DPI device, or can be used as a built-in DPI function component of a wireless network device, and can be applied to the detection of complex network traffic user intention behavior service actions. The above-mentioned network traffic user intention detection system can detect the user service action traffic in a serial or online manner, or can detect the user service action traffic in a parallel or bypass manner.

[0040] In this embodiment, a method for identifying a service action running on the above-mentioned mobile terminal or network architecture is provided. Figure 3 It is a flowchart of a method for identifying a service action according to an embodiment of the present application, as Figure 3 shown. The process includes the following steps:

[0041] Step S301: Obtain the data stream in the traffic of the service action to be identified, and extract the flow characteristics of the service action to be identified from the data stream.

[0042] In the embodiment of the present application, in the service action traffic detection stage, the network traffic of the APP can be detected to accurately identify the user service action of the App and analyze the user behavior intention.

[0043] As an example, the traffic of the service action to be identified generated by the user using the APP can be obtained, and the corresponding flow characteristics can be extracted from the data stream in the traffic of the service action to be identified.

[0044] In an exemplary embodiment, step S301 may specifically include:

[0045] Establish a corresponding five-tuple flow table for the flow in the traffic of the service action to be identified; the data stream includes at least one request message; based on the five-tuple flow table, extract the flow characteristics of the service action to be identified, and the flow characteristics are the server domain names carried in the first request message of the data stream.

[0046] As an example, the traffic of the service action of each user may include multiple data streams, and the types of data streams may be one or more. For example, the types of data streams may include Hypertext Transfer Protocol (HTTP) streams, Hypertext Transfer Protocol Secure (HTTPS) streams, Quick UDP Internet Connections (QUIC) streams, etc., where UDP is the User Datagram Protocol.

[0047] As an example, after obtaining the traffic of the service action to be identified of the user, a five-tuple flow table can be established for the data stream in the traffic of the service action to be identified.

[0048] As an example, each data stream may include one or more request messages, each request message may carry a server domain name, and the flow characteristics may be the server domain names carried in the first request message of the data stream.

[0049] As an example, based on the five-tuple flow table, according to the chronological order of the data streams in the service action traffic to be recognized, the server domain name carried in the first request message of each data stream can be extracted, and the server domain name carried in the first request message of the extracted data stream is the flow feature.

[0050] For example, based on the established five-tuple flow table, the host name "Host" of the first HTTP request message can be extracted for each HTTP flow, and the server name indication (Server Name Indication, SNI) of the first client hello message can be extracted for each HTTPS / QUIC flow. "Host / SNI" is the flow feature.

[0051] The following further illustrates the establishment process of the five-tuple flow table and the extraction process of flow features in the embodiments of the present application through several examples:

[0052] Example 1

[0053] Establishment process of the five-tuple flow table:

[0054] Figure 4 It is based on the five-tuple flow table schematic diagram of the embodiments of the present application. As Figure 4 shown, in order to implement data stream-based processing, a flow table in the form of a key-value in-memory data table can be established, and a flow context is allocated for each data stream.

[0055] Among them, the "key" in the flow table can be the five-tuple that uniquely identifies a data stream, that is, "user IP address + user port number + network IP address + network port number + TCP / UDP protocol number". Packets matching a certain five-tuple can be attributed to the corresponding flow context.

[0056] Among them, the "value" in the flow table is a data structure that stores the processing status information of the data stream. The processing status information of the data stream can include: flow type (for example, HTTP flow, HTTPS flow, QUIC flow, etc.), whether the Host / SNI has been extracted, the feature symbol mapped by the Host / SNI, update timestamp, cumulative number of packets, cumulative number of bytes, etc.

[0057] Example 2

[0058] Extraction process of the flow feature of the HTTP flow:

[0059] When extracting the Host feature of the first request of the HTTP flow, the data stream in the service action traffic can be first identified to determine whether it is an HTTP flow. In the case of an HTTP flow, the request message of the HTTP flow can be further identified. The specific process can be as follows:

[0060] 1) Identify the data stream in the service action traffic;

[0061] For example, if the first uplink packet containing TCP payload in a Transmission Control Protocol (TCP) stream in the service action traffic contains payload content that conforms to the regular expression "^(GET|POST).+?\sHTTP / 1\.

[01] \r\n", then this stream can be identified as an HTTP stream.

[0062] 2) Identify the request message in the HTTP stream;

[0063] For example, if the TCP payload of an uplink packet in an HTTP stream conforms to the regular expression "^(GET|POST).+?\sHTTP / 1\.

[01] \r\n", then it can be determined that this packet is a request message.

[0064] 3) Obtain the first request message of the HTTP stream;

[0065] For example, it is possible to determine whether the Host in the first request of this HTTP stream has been extracted according to the value of "whether Host / SNI has been extracted" in the flow context of the five-tuple flow table; if it has been extracted, then the extraction of this HTTP stream will no longer be performed; if it has not been extracted, then the extraction of this HTTP stream can be performed again.

[0066] 4) Extract the Host value from the first request message of an HTTP stream;

[0067] For example, it is possible to decode the HTTP header (i.e., the message header) of this HTTP request message and find the content that conforms to the regular expression "Host:\s?(.+)\r\n" in the decoded message header, capture the content that matches the "(.+)" part of the regular expression, and use this captured content as the Host value.

[0068] Example 3

[0069] The process of extracting the flow characteristics of an HTTPS stream:

[0070] When extracting the SNI characteristics of the first ClientHello message of an HTTPS stream, it is possible to first identify the stream in the service action traffic to determine whether it is an HTTPS stream. In the case of an HTTPS stream, it is possible to further identify the request message of the HTTPS stream. The specific process can be as follows:

[0071] 1) Identify the stream in the service action traffic;

[0072] For example, if the first uplink packet containing TCP payload in a TCP flow in the service action traffic meets the basic decoding conditions of the ClientHello message conforming to the TLS 1.0 / TLS 1.1 / TLS 1.2 / TLS 1.3 protocol, then this flow can be identified as an HTTPS flow.

[0073] 2) Identify the ClientHello message in the HTTPS flow;

[0074] For example, the first uplink packet containing TCP payload of an identified HTTPS flow can be used as the ClientHello message.

[0075] 3) Obtain the first ClientHello message of the HTTPS flow;

[0076] For example, according to the value of "whether the Host / SNI has been extracted" in the flow context of the five-tuple flow table, it can be judged whether the SNI in the first ClientHello request of this HTTPS flow has been extracted; if it has been extracted, this HTTPS flow will no longer be extracted; if it has not been extracted, this HTTPS flow can be extracted again.

[0077] 4) Obtain the SNI value from the first ClientHello message of an HTTPS flow;

[0078] For example, according to the TLS 1.0 / TLS 1.1 / TLS 1.2 / TLS 1.3 protocol, the first ClientHello message of an HTTPS flow can be decoded, and the content of the Server Name Indication extension field of the TLS server name indication is obtained as the SNI value.

[0079] Example 4

[0080] Extraction process of the flow characteristics of the QUIC flow:

[0081] When extracting the SNI characteristics of the first ClientHello message of the QUIC flow, the flow in the service action traffic can be identified first to judge whether it is a QUIC flow. In the case of a QUIC flow, the request message of the QUIC flow can be further identified. The specific process can be as follows:

[0082] 1) Identify the flow in the service action traffic;

[0083] For example, if the first uplink packet containing a UDP payload in a UDP flow within the service action traffic meets the basic decoding conditions for an Initial type message or a Zero Round Trip Time (0-RTT) type message that conforms to the QUIC protocol, then this flow can be identified as a QUIC flow. For a flow identified as QUIC, the flow type in the flow context can be updated to QUIC in the five-tuple table.

[0084] 2) Identify the ClientHello message in the QUIC flow;

[0085] For example, the first uplink packet of an Initial type containing an encrypted Crypto frame in a UDP payload in a QUIC flow can be used as the ClientHello message.

[0086] 3) Obtain the first ClientHello message of the QUIC flow;

[0087] For example, according to the value of "whether the Host / SNI has been extracted" in the flow context of the five-tuple flow table, it can be determined whether the SNI in the first ClientHello request of this QUIC flow has been extracted; if it has been extracted, then the extraction of this QUIC flow will no longer be performed; if it has not been extracted, then the extraction of this QUIC flow can be performed again.

[0088] 4) Obtain the SNI value from the first ClientHello message of a QUIC flow;

[0089] For example, the QUIC header can be decoded according to the QUIC protocol, the Initial type QUIC packet can be decrypted according to the QUIC protocol, the Crypto frame can be reassembled according to the QUIC protocol, and then decoded according to the TLS1.3 protocol to obtain the content of the TLS Sever NameIndication extension field as the SNI value.

[0090] Step S303: Generate a feature symbol sequence of the service action to be recognized according to the flow characteristics of the service action to be recognized and the mapping relationship; wherein, the preset mapping relationship is the mapping relationship between the flow characteristics of the target service action and the feature symbols of the target service action.

[0091] As an example, a feature file of the service action traffic set in advance can be obtained. The feature file can include the mapping relationship between the flow characteristics and the feature symbols, and the feature information of one or more target service actions. The feature information of each target service action can include the target service action name or number, the feature symbols of the target service action, and so on.

[0092] As an example, corresponding feature symbols can be pre-assigned to each flow feature. The feature symbols can include printable characters or non-printable characters; the number of feature symbols can be a single character or a combination of multiple characters. The embodiments of the present invention do not limit the form or type of the feature symbols.

[0093] For example, Figure 5 is a schematic diagram of the character feature symbols of the feature symbol mapping form according to the embodiments of the present application. As Figure 5 shown, Figure 5 it shows the feature symbol mapping of more than 30 different Host / SNI flow features generated during the opening of the first screen of XXApp. Each Host / SNI flow feature can correspond to a unique single-character feature symbol.

[0094] Figure 6 is a schematic diagram of the double-character feature symbols of the feature symbol mapping table according to the embodiments of the present application. As Figure 6 shown, a combination of double characters of printable characters "A-Za-z0-9" can be selected as the feature symbol set. For example, it includes "AA, AB, AC,..., X0, X1,...", with a total of 62 * 62 = 3844 different Host / SNI original features that can be expressed. Using the double-character combination as the feature symbol set can support a higher number of recognized business actions than single-character feature symbols. Figure 6 shows the feature symbol mapping of more than 30 different lightweight Host / SNIs generated during the opening of the first screen of XXApp, using double-character feature symbols.

[0095] A combination of triple characters of "A-Za-z0-9" can also be used as the feature symbol set. For example, it includes "AAA, AAB, AAC,...", with a total of 62 * 62 * 62 = 238328 different Host / SNI features that can be expressed.

[0096] In an exemplary embodiment, the feature symbols of the target business action include recognition-type feature symbols; the recognition-type feature symbols include at least one of the following feature symbols: start-type feature symbol set, longest common feature symbol subsequence, existence-type feature symbol set, end-type feature symbol set.

[0097] As an example, the start-type feature symbol set can be used to represent the start of the target business action; the longest common feature symbol subsequence can be used for the accurate recognition of the target business action; the existence-type feature symbol set can be used to enhance the accuracy of recognizing the target business action; the end-type feature symbol set can be used to represent the completion of the target business action.

[0098] As an example, a feature symbol sequence of the business action to be recognized can be generated according to the flow characteristics of the business action to be recognized and the mapping relationship between the flow characteristics and the feature symbols.

[0099] In an exemplary embodiment, step S303 may specifically include:

[0100] Step S3031, generating a head feature symbol sequence of the flow characteristics according to the time sequence of the appearance of the flow characteristics of the business action to be recognized and the mapping relationship;

[0101] Step S3032, traversing the feature symbols of the target business action and matching the head feature symbol sequence with the feature symbols of the target business action;

[0102] Step S3033, when the recognition type feature symbols include the start type feature symbol set and at least one start type feature symbol in the start type feature symbol set matches the feature symbol of the head feature symbol sequence, generating a feature symbol sequence of the business action to be recognized.

[0103] As an example, based on the five-tuple flow table of the traffic of the business action to be recognized, the earliest appearing flow characteristic can be determined, and a head feature symbol sequence of the business action to be recognized can be generated according to the earliest appearing flow characteristic and the mapping relationship between the flow characteristic and the feature symbol.

[0104] As an example, the feature symbols of the target business action in the feature file can be traversed, the feature symbols in the head feature symbol sequence of the business action to be recognized are matched with the feature symbols of the target business action, and when the recognition type feature symbols include the start type feature symbol set and at least one start type feature symbol in the start type feature symbol set matches the feature symbol in the head feature symbol sequence, the feature symbol sequence after the head feature symbol sequence of the business action to be recognized is continuously generated.

[0105] In an exemplary embodiment, step S3033 may include:

[0106] Marking the state of the business action to be recognized as the start state of the target business action; generating a feature symbol sequence of the business action to be recognized in the start state.

[0107] In an exemplary embodiment, it further includes:

[0108] Obtaining the maximum continuous duration of the target business action;

[0109] When the duration of generating the feature symbol sequence of the business action to be recognized reaches the maximum continuous duration of the target business action, stop generating the feature symbol sequence of the business action to be recognized.

[0110] As an example, when a feature symbol in the head feature symbol sequence matches at least one start class feature symbol in the start class feature symbol set, the status of the business action to be recognized can be marked as the start status of the target business action.

[0111] As an example, the feature file may further include the maximum duration of the target business action. The maximum duration of the target business action can be obtained, and generation can be stopped when the duration of generating the feature symbol sequence of the business action to be recognized reaches the maximum duration of the target business action.

[0112] As an example, when the status of the business action to be recognized is the start status of the target business action, the feature symbol sequence after the head feature symbol sequence of the business action to be recognized can be continuously generated, and generation can be stopped when the generated duration reaches the maximum duration of the target business action.

[0113] Step S304: When the feature symbol in the feature symbol sequence matches the feature symbol of the target business action, determine that the business action to be recognized is the target business action.

[0114] As an example, the feature symbols in the feature symbol sequence of the business action to be recognized can be matched with the feature symbols of the target business action. When the feature symbols in the feature symbol sequence of the business action to be recognized match the feature symbols of the target business action, determine that the business action to be recognized is the target business action.

[0115] As an example, the target business action can be a user business action of an App. For example, the action of opening the first screen of the App, etc.

[0116] In an exemplary embodiment, step S304 may include:

[0117] Step S3041: Determine whether the feature symbol in the feature symbol sequence matches the longest common feature symbol subsequence;

[0118] Step S3042: When the feature symbol in the feature symbol sequence matches the longest common feature symbol subsequence, determine that the business action to be recognized is the target business action, and determine that the recognition accuracy is the first accuracy.

[0119] As an example, if the longest common feature symbol subsequence of the target business action exists in the feature symbol sequence of the business action to be recognized, it can be determined that the business action recognition is successful. The business action to be recognized that the user is currently performing is the target business action, and it can be confirmed that the recognition accuracy at this time is average.

[0120] As an example, if the characteristic symbol sequence of the business action to be recognized does not match the longest common characteristic symbol subsequence of the target business action within the maximum continuous duration of the target business action, it can be determined that the recognition of the business action fails.

[0121] In an exemplary embodiment, after step S3042, it may further include:

[0122] Determine whether the characteristic symbols in the characteristic symbol sequence include all the existence type characteristic symbols in the existence type characteristic symbol set; when the characteristic symbols in the characteristic symbol sequence include all the existence type characteristic symbols in the existence type characteristic symbol set, determine that the recognition accuracy of the business action to be recognized as the target business action is the second accuracy, where the second accuracy is higher than the first accuracy.

[0123] As an example, after recognizing that the characteristic symbol sequence of the business action to be recognized contains the longest common characteristic symbol subsequence of the target business action, it can continue to recognize whether the characteristic symbol sequence of the business action to be recognized contains all the existence type characteristic symbols of the target business action. If it contains all the existence type characteristic symbols of the target business action, it can be considered that the recognition accuracy of recognizing the business action to be recognized as the target business action is the second accuracy, and the second accuracy is higher than the first accuracy.

[0124] By matching the existence type characteristic symbols, the recognition accuracy of recognizing the business action to be recognized as the target business action can be improved.

[0125] It should be noted that the first accuracy and the second accuracy in the embodiments of the present application are evaluations of the recognition results, which can be represented by specific numerical values. For example, the first accuracy is 60%, and the second accuracy is 90%; it can also be represented by recognition levels. For example, the first accuracy is general, and the second accuracy is high; the first accuracy is medium, and the second accuracy is excellent, etc.; it can also be represented by thresholds. For example, the first accuracy is less than or equal to the preset accuracy threshold, and the second accuracy is greater than the preset accuracy threshold, etc. The embodiments of the present application do not limit the evaluation methods of the recognition results.

[0126] In an exemplary embodiment, the characteristic symbols of the target business action further include attribution type characteristic symbols; after step S304, it may further include:

[0127] Step S305, match the characteristic symbols in the characteristic sequence with the attribution type characteristic symbols;

[0128] Step S306, when the characteristic symbols match the attribution type characteristic symbols, determine that the data stream corresponding to the characteristic symbols is the data stream in the target business action traffic.

[0129] As an example, the attribution characteristic symbol set can be used to accurately attribute flows in traffic to target service actions.

[0130] As an example, when the characteristic symbol in the characteristic sequence of the business action to be identified matches the attribution characteristic symbol, it can be determined that the data flow corresponding to the characteristic symbol belongs to the data flow in the target business action traffic, thereby achieving accurate identification of the traffic.

[0131] The following uses several examples to further illustrate the traffic detection process and feature symbol matching process in the service action recognition process during the service action traffic detection phase:

[0132] Example 5

[0133] Traffic detection process:

[0134] Figure 7 Schematic diagram of the flow detection process according to the embodiment of the present application. Figure 7 As shown, the flow detection process may specifically include the following steps:

[0135] Step 1: Load the signature file.

[0136] The feature files obtained during the training phase can be loaded into the system memory.

[0137] Step 2: Obtain stream-level Host / SNI features.

[0138] The system performs user-based detection and can establish a five-tuple flow table for each user's Internet traffic. It can extract the Host of the first HTTP request message for each HTTP flow and the SNI of the first ClientHello message for each HTTPS / QUIC flow.

[0139] Step 3: Get the characteristic symbol.

[0140] The system maps Host / SNI to a characteristic symbol based on the characteristic symbol mapping table.

[0141] Step 4: Get the characteristic symbol sequence.

[0142] The characteristic information of each business action in the characteristic file can be traversed. If the characteristic symbol of the business action to be identified exists in the starting class characteristic symbol set of a business action in the characteristic file, the business action of the user is marked as the starting state, and the subsequent characteristic symbols of the user can be recorded in sequence until the business action is identified or the maximum duration of the business action is reached, thereby obtaining the characteristic symbol sequence of the user's business action.

[0143] Step 5: Match the longest common feature symbol subsequence: If the longest common feature symbol subsequence of the business action to be recognized is detected and exists in the corresponding feature symbol sequence of this user, it is considered that the recognition of this business action is successful, that is, this user is currently performing this target business action, and the recognition accuracy is considered to be average. If the longest common feature symbol subsequence of this business action is not matched within the maximum duration of this business action, it is considered that the recognition of this business action fails, and the subsequent steps are not continued.

[0144] Step 6: Match the existence type features: If the recognition is successful and all the symbols in the existence type feature symbol set of this business action are included in the corresponding feature symbol sequence of this user, the recognition accuracy is considered to be high.

[0145] Step 7: Match the termination type features: If the system detects that the recognition is successful and the feature symbols in the corresponding feature symbol sequence of this user exist in the termination type feature symbol set of this business action, it is considered that the recognition of this business action is completed. If the system does not match the termination type feature symbol of this business action within the maximum duration of this business action, it is considered that the recognition of this business action fails, and the subsequent steps are not continued.

[0146] Step 8: Match the attribution type features and report the recognition result: If the system detects that the recognition is completed, the traffic of the attribution type feature symbols can be classified into this business action, and the flow records of the relevant traffic are marked with the name or number of this business action. The recognition result information can be summarized and reported to the external system through message passing.

[0147] In this example, the data stream in the traffic of the business action to be recognized is converted into the corresponding feature symbols, and the feature symbols of the business action to be recognized are matched with the feature symbols of the target business action in the feature file. In the case of a match, it is determined that the business action to be recognized is the target business action. It can not only accurately detect whether the business action to be recognized, which represents the user's intended behavior, is the target business action, but also accurately classify complex traffic such as access to the common App cloud service in the target business action into the corresponding business action. Thus, the evaluation of the user's Internet experience by the network device is more accurate, and a reasonable basis can be provided for the network optimization function.

[0148] Example 6

[0149] The matching process of the feature symbols:

[0150] Figure 8 It is the schematic diagram of feature matching in the traffic detection stage according to the embodiment of the present application. Refer to Figure 8, assume that the feature information of the target service action is as follows: the starting class feature symbol set is {A, B}; the longest common feature symbol subsequence is B D E JO P T Q J W 0; the existing class feature symbol set is {G, F, X, Y}; the ending class feature symbol set is {H, 0}; the belonging class feature symbol set is {A, B, D, E, F, G, H, I, J, K, M, N, O, P, Q, R, T, V, X, Y, Z, 0}, and the user's current feature symbol sequence is: A A B A B C C C D C E E F G H I J K O P Q R S T U S Q V Q J W X Y Z DH 0. After the feature matching process of 4 steps, namely matching the starting class feature symbols, matching the longest common feature symbol subsequence, matching the existing class feature symbols, and matching the ending class feature symbols, it can be confirmed that the user is currently performing the target service action.

[0151] After identifying that the user is performing the target service action, it is possible to further check whether each symbol in the user's current feature symbol sequence exists in the belonging feature symbol set. As Figure 8 shown by the bolded feature symbols in the user's current feature symbol sequence, they exist in the belonging class feature symbol set. The data stream corresponding to the belonging class feature symbols in the user's current feature symbol sequence can be attributed to the data stream in the target service action traffic.

[0152] In this example, the feature symbols of the service to be identified are matched with the feature symbols of the target service action in the feature file. By determining steps such as matching the starting class feature symbols, matching the longest common feature symbol subsequence, and matching the ending class feature symbols of the feature symbols of the service to be identified, it can be recognized that the user is currently performing the target service action; by matching the existing class feature symbols, the accuracy of recognizing that the user is currently performing the target service action can be improved; by matching the belonging feature symbols of the target service action, it is possible to attribute the data stream corresponding to the belonging class feature symbols in the user's current feature symbol sequence to the data stream in the target service action traffic. Thus, the evaluation of the user's Internet experience by the network device is more accurate, and a reasonable basis can be provided for the network optimization function.

[0153] As an example, before identifying the service traffic to be identified, in order to implement the detection based on the user's service action, a user table in the form of a key-value in-memory data table can be established in advance, and a user context is assigned to each user to record the detection status information of this service action.

[0154] For example, Figure 9 is the schematic diagram of the user table according to the embodiment of the present application, as Figure 9As shown, the "key" in the user table can be the "user IP address" that uniquely identifies a user or the "combination of user IP address and VLAN identifier". Packets matching a certain unique identifier can be attributed to the corresponding user context. The "value" is a data structure in the form of an array or a one-dimensional linked list, which stores the detection status information of one or more possible service actions of a user. Each array or linked list element may include, but is not limited to, dynamic information such as service action number, service action status, service action start timestamp, and service action recognition accuracy.

[0155] After successfully identifying that a certain user has completed a certain service action, the detection status information of this service action is generated in the user table of this user, that is, based on the "value" in the user table of this user.

[0156] As an example, after successfully identifying that a certain user has completed a certain service action, based on the "key" and "value" in the user table, a service action recognition message can be generated and sent to an external system. The external system can perform an association analysis on the user's intended behavior and the processing performance of the network device according to the service action recognition message, find the impact of the network device performance indicators on the user's intended behavior, and then can improve the user experience by adjusting the performance indicators of the network device.

[0157] For example, Figure 10 is a schematic diagram of reporting the recognition result message according to an embodiment of the present application. As Figure 10 shown, after successfully identifying that a certain user has completed a certain service action, the relevant recognition and statistical information (for example, who, at what time, what happened) of this service action of this user can be sent to an external system in the form of a message. The message may include:

[0158] 1) Information of the "user IP address" or "combination of user IP address and VLAN identifier" of the user.

[0159] 2) Start time and end time information of this service action of the user.

[0160] 3) Name or number information of this service action of the user.

[0161] 4) Traffic statistics information such as the number of flows, bytes, and packets of this service action of the user.

[0162] The external system can perform an association analysis on the user's intended behavior and the processing performance of the network device according to the above information in the message, find the impact of the network device performance indicators on the user's intended behavior, and then can improve the user network experience by adjusting the performance indicators of the network device.

[0163] In an embodiment of the present invention, before the service action traffic detection phase, a service feature training phase may further be included, and the common rules of the complex network traffic of the target service action may be determined in advance during the service feature training phase to generate feature information. The specific process may be as follows:

[0164] In an exemplary embodiment, before step S301, the following may further be included:

[0165] Sample the traffic of the target service action, and extract flow features from the data stream in the traffic of the target service action; assign a unique feature symbol to each flow feature of the target service action, and establish a mapping relationship between the flow features of the target service action and the feature symbols of the target service action.

[0166] In an exemplary embodiment, the types of data streams in the traffic of the target service action include at least one of the following: HTTP stream, HTTPS stream, QUIC stream.

[0167] In an embodiment of the present invention, the server domain name carried in the first request message of each data stream may be used as the corresponding flow feature, and the mapping relationship between the flow feature and the feature symbol may be established during the service feature training phase.

[0168] As an example, the traffic of the target service action may be sampled in advance, a five-tuple flow table of the target service action may be established, and based on the five-tuple flow table of the target service action, the flow features of each data stream in the traffic of the target service action may be extracted respectively, and a unique feature symbol may be assigned to the flow feature of each data stream of the target service action, and the mapping relationship between the flow feature and the feature symbol may be established.

[0169] As an example, flow-level HTTP Host or flow-level HTTPS SNI or flow-level QUIC SNI may be used as the "lightweight flow feature".

[0170] For example, based on the established five-tuple flow table, the host name Host of the first HTTP request message may be extracted for each HTTP stream, and the server name indication (Server Name Indication, SNI) of the first client hello message may be extracted for each HTTPS / QUIC stream, and Host / SNI may be used as the feature of the data stream.

[0171] In an exemplary embodiment, before obtaining the data stream in the traffic of the service action to be recognized, the following is further included:

[0172] Step A11: Sample the traffic of the target service action multiple times, extract flow features from the data stream of the target service action traffic for each sampling, and generate multiple sets of flow feature samples corresponding to the traffic of the target service action.

[0173] Step A12: Generate multiple feature symbol sample sequences corresponding to the target service action according to the mapping relationship and the multiple sets of flow feature samples.

[0174] In an exemplary embodiment, after step A12, it further includes:

[0175] Step A13: Extract the multiple feature symbol sample sequences corresponding to the target service action to obtain the recognition class feature symbols and the attribution class feature symbols.

[0176] For example, sample the target service action traffic N times, and respectively extract the flow features of the data stream in the target service action traffic for each sampling. For each sampling, according to the order of appearance of each Host / SNI feature and the mapping relationship between the flow feature and the feature symbol, generate the corresponding feature symbol sequence sample. N samplings can generate N sets of feature symbol sequence samples, and the common feature symbols can be extracted from the N sets of feature symbol sequence samples as the recognition class feature symbols and the attribution class feature symbols of the target service action respectively.

[0177] For example, the common feature symbols can be obtained from the N sets of feature symbol sequence samples and used as the longest common feature symbol subsequence, the start class feature symbol set, the end class feature symbol set, the existence class feature symbol set, the attribution class feature symbol set, etc. of the target service action respectively.

[0178] As an example, all the common and identically ordered feature symbols in the multiple feature symbol sample sequences can be extracted in order as the longest common feature symbol subsequence; the feature symbols that exist in all the multiple feature symbol sample sequences and are within the first preset character range at the start position of each sample sequence are used as the start class feature symbol set; the feature symbols that exist in all the multiple feature symbol sample sequences and are within the second preset character range at the end position of each sample sequence are used as the end class feature symbol set; the feature symbols that exist in all the multiple feature symbol sample sequences and are neither start class feature symbols nor end class feature symbols nor feature symbols in the longest common feature symbol subsequence are used as the existence class feature symbol set; the feature symbols that exist in more than a preset percentage of the total number of feature symbol sample sequences are used as the attribution class feature symbols.

[0179] In an exemplary embodiment, step A12 may include:

[0180] Generate multiple initial feature symbol sample sequences corresponding to the target service action according to the mapping relationship between the flow features and the feature symbols and the multiple groups of flow feature samples; compress adjacent and continuously repeated feature symbols in the initial feature symbol sequences into one feature symbol to generate multiple feature symbol sample sequences corresponding to the target service action.

[0181] As an example, the lightweight Host / SNI original feature sequence generated by the target service action can be mapped to an initial feature symbol sequence based on the mapping relationship between the flow features and the feature symbols. The adjacent and continuously repeated feature symbols in the initial feature symbol sequence can be compressed into one feature symbol by using the proximity compression method to generate a feature symbol sequence. For example, compress "CC" into one "C" and compress "EEEE" into one "E".

[0182] The following uses several examples to illustrate the feature training process in the service feature training stage, the proximity compression process of the feature symbol sequence, and the acquisition processes of the longest common feature symbol subsequence, the start class feature symbol set, the end class feature symbol set, the existence class feature symbol set, and the attribution class feature symbol set respectively.

[0183] Example 7

[0184] Feature training process in the service feature training stage:

[0185] Figure 11 It is a schematic diagram of the feature training process according to the embodiment of the present application. As Figure 11 shown, the feature training can specifically include the following steps:

[0186] Step 1: Obtain the flow lightweight Host / SNI features.

[0187] The system samples the target service action traffic to establish a five-tuple flow table, extracts the Host of the first HTTP request message for each HTTP flow, and the SNI of each HTTPS / QUIC ClientHello message. The Host / SNI can be used as the lightweight original feature of the flow.

[0188] Step 2: Establish a feature symbol mapping table.

[0189] A feature symbol mapping table for the lightweight original features Host / SNI can be established, and a unique feature symbol is assigned to each Host / SNI.

[0190] Step 3: Obtain N groups of feature symbol sequences.

[0191] The target business action traffic can be sampled N times. For each sampling, according to the order in which each Host / SNI original feature appears, a corresponding feature symbol sequence is generated, and N feature symbol sequences can be obtained from N samplings.

[0192] Obtain the maximum duration of N samplings to avoid mis-matching that may be caused by the infinite duration accumulation of features during the traffic detection phase.

[0193] Step 4: Obtain the recognition type features and attribution type features.

[0194] The following features can be obtained from the N feature symbol sequences of N samplings:

[0195] 1) Obtain the starting type feature symbol set, which is used to represent the start of the target business action.

[0196] 2) Obtain the longest common feature symbol subsequence, which is used for accurate recognition of the target business action.

[0197] 3) Obtain the existence type feature symbol set, which is used to enhance the accuracy of recognizing the target business action. (Optional)

[0198] 4) Obtain the attribution type feature symbol set, which is used to accurately attribute the relevant traffic to the target business action.

[0199] 5) Obtain the termination type feature symbol set, which is used to represent the completion of the target business action.

[0200] Step 5: Generate a feature file.

[0201] The feature information of the target business action can be generated into structured data and saved in the feature file. A feature file can contain a feature symbol mapping table and the feature information of one or more business actions. The feature information of each target business action can include the following:

[0202] 1) The name or number of the target business action;

[0203] 2) The maximum duration of the target business action;

[0204] 3) The starting type feature symbol set;

[0205] 4) The longest common feature symbol subsequence;

[0206] 5) The existence type feature symbol set;

[0207] 6) The attribution type feature symbol set;

[0208] 7) The termination type feature symbol set.

[0209] Example 8

[0210] Feature symbol sequence proximity compression process:

[0211] Figure 12 It is a schematic diagram of the proximity compression of the feature symbol sequence according to the embodiment of the present application. For example, Figure 12 taking the action of opening the first screen of the App as the target service action as an example, Figure 12 it is the process of the system sampling and testing the target service action 10 times to obtain the corresponding 10 feature symbol sequences. The following takes Figure 12 a sampling test of the target service action "TestNo 1" in

[0212] 1) The lightweight raw feature sequence obtained by the system in a sampling test "TestNo 1" of the target business action is "SNI:edith.xiaohongshu.com; SNI:www.xiaohongshu.com; SNI:edith.xiaohongshu.com; SNI:www.xiaohongshu.com; SNI:dns.alidns.com; SNI:as.xiaohongshu.com; SNI:dns.alidns.com; SNI:dns.alidns.com; SNI:doh.pub; SNI:doh.pub; SNI:doh.pub; SNI:doh.pub; SNI:crash.xiaohongshu.com; HOST:fp-it.fengkongcloud.com; SNI:lng.xiaohongshu.com; SNI:sns-avatar-qc.xhscdn.com; SNI:t2.xiaohongshu.com; SNI:ci.xiaohongshu.com; SNI:ca.iadsdk.apple.com; SNI:pages.xiaohongshu.com; SNI:pages.xiaohongshu.com; HOST:sns-img-hw.xhscdn.com; HOST:sns-img-hw.xhscdn.com; HOST:sns-img-hw.xhscdn.com; HOST:cdn-api-verify.mob.com; HOST:f.gm.mob.com; HOST:f.gm.mob.com; HOST:www.xiaohongshu.com; SNI:fe-video-qc.xhscdn.com; SNI:web-resource-app.xiaohongshu.com; SNI:rn-resource-app.xiaohongshu.com; SNI:rn-resource-app.xiaohongshu.com; SNI:bag.itunes.apple.com; SNI:web-resource-app.xiaohongshu.com; SNI:pages.xiaohongshu.com; HOST:www.xiaohongshu.com; HOST:license.vod2.myqcloud.com; HOST:www.xiaohongshu.com; HOST:www.xiaohongshu.com; SNI: t2.xiaohongshu.com; SNI: t2.xiaohongshu.com; SNI: t2.xiaohongshu.com; HOST: sns-img-hw.xhscdn.com; HOST: sns-img-hw.xhscdn.com; HOST: sns-img-hw.xhscdn.com; SNI: apm-fe.xiaohongshu.com; HOST: sns-video-hw.xhscdn.com; SNI: spider-tracker.xiaohongshu.com; HOST: l.gm.mob.com; SNI: as.xiaohongshu.com; SNI: lng.xiaohongshu.com; SNI: log-verify.mob.com;”.

[0213] 2) According to the mapping relationship between the flow characteristics and the characteristic symbols in the single-character characteristic symbol mapping table, the preliminary characteristic symbol sequence obtained from "TestNo1" is "ABABCDCCEEEEFGHIJKLMMNNNOPPQRSTTUSMQVQQJJJNNNWXYZDH0".

[0214] 3) By performing adjacent characteristic symbol compression on the preliminary characteristic symbol sequence "ABABCDCCEEEEFGHIJKLMMNNNOPPQRSTTUSMQVQQJJJNNNWXYZDH0", the compressed characteristic symbol sequence can be obtained as "ABABCDCEFGHIJKLMNOPQRSTUSMQVQJNWXYZDH0".

[0215] Example 9

[0216] The process of obtaining the longest common characteristic symbol subsequence:

[0217] Based on the multi-sequence LCS (Longest Common Subsequence) algorithm, a common characteristic symbol subsequence can be obtained from multiple characteristic symbol sample sequences of the target service action. The longest common characteristic symbol sequence among the multiple characteristic symbol sample sequences can be used as the longest common characteristic symbol subsequence.

[0218] Figure 5 is a schematic diagram for obtaining the longest common characteristic symbol subsequence according to the embodiment of the present application. Taking Figure 13 the 13 characteristic symbol sequences generated as an example for illustration. As Figure 12As shown, based on the multi-sequence LCS algorithm, the common feature symbol subsequence of these feature symbol sequences can be obtained from the 10 feature symbol sequences obtained from multiple trainings of the target business action, and the longest common feature symbol sequence among the 10 feature symbol sample sequences can be used as the longest common feature symbol subsequence.

[0219] Each symbol in the longest common characteristic symbol subsequence may be continuous or discontinuous, but the order in which they appear in each characteristic symbol sequence is the same or remains unchanged.

[0220] Figure 13 The common characteristic symbols in the characteristic sequences from No. 1 to No. 10 are displayed in bold, such as Figure 13 As shown in the figure, the longest common characteristic symbol subsequence of 11 single characters "BDEJOPTQJW0" can be obtained based on the multi-sequence LCS algorithm. From the figure, it can be seen that the longest common characteristic symbol subsequence of "BDEJOPTQJW0" is not continuous, but the order of appearance remains unchanged.

[0221] in, Figure 13 Although all 10 characteristic symbol sequences are A, A sometimes comes before B and sometimes comes after B. The order of A and B is chaotic, and A and B cannot be taken at the same time. Therefore, only one of A and B can be selected. Figure 13 The selection of B is only an example. A can also be selected, but B needs to be discarded. Those skilled in the art can make a selection according to actual conditions, and the embodiment of the present invention does not limit this.

[0222] Example 10

[0223] The process of obtaining the longest common subsequence based on the multi-sequence LCS algorithm:

[0224] The present application may use a multi-sequence LCS algorithm to obtain the longest common subsequence from multiple sequences.

[0225] A specific method is to randomly select two sequences and obtain the longest common subsequence between the two sequences as a temporary longest common subsequence. Then, the temporary longest common subsequence is combined with a third randomly selected sequence to obtain a new temporary longest common subsequence. This process continues until all sequences have been processed. The final temporary longest common subsequence is then used as the longest common subsequence of the multiple sequences.

[0226] The longest common subsequence of two sequences is the longest common subsequence among all non-empty subsequences in the two sequences. The symbols in the subsequence can be continuous or discontinuous, but the order of the symbols in the subsequence remains consistent with the original sequence. For example, the non-empty common subsequences of "ABCD" and "NAXDE" are "A", "D", and "AD", where "AD" is the longest common subsequence.

[0227] For example, Figure 13 is a schematic diagram of the multi-sequence LCS algorithm according to an embodiment of the present application. As Figure 14 shown, it includes three feature symbol sequences "ABCDEFGH", "6A1CDFFXY", and "BDAAZ217F".

[0228] First, the temporary longest common subsequence of the first two sequences "ABCDEFGH" and "6A1CDFFXY" can be obtained as "ACDF". Then, a new temporary longest common subsequence "AF" can be obtained from the temporary longest common subsequence "ACDF" and the third sequence "BDAAZ217F". The final temporary "AF" is used as the longest common subsequence of these three sequences.

[0229] The LCS algorithm is a conventional algorithm for finding the longest common subsequence of two sequences, which can be implemented by a full traversal method or based on a dynamic programming method. The specific algorithm is not elaborated in this application.

[0230] Example 11

[0231] The process of obtaining the starting class feature symbol set, the ending class feature symbol set, and the existing class feature symbol set:

[0232] In an embodiment of the present invention, feature symbols that exist in multiple feature symbol sample sequences and are within the first preset character range at the start position of each sample sequence can be used as the starting class feature symbol set; feature symbols that exist in multiple feature symbol sample sequences and are within the second preset character range at the end position of each sample sequence can be used as the ending class feature symbol set; feature symbols that exist in multiple feature symbol sample sequences, are neither starting class feature symbols nor ending class feature symbols, and are not feature symbols in the longest common feature symbol subsequence can be used as the existing class feature symbol set.

[0233] Figure 14 is a schematic diagram of obtaining starting class, ending class, and existing class feature symbols according to an embodiment of the present application. As Figure 15 shown

[0234] 1) Feature symbols that exist in all sequences and are near the start position of each sequence can be used as the starting class feature symbols. As Figure 15 shown, the starting class feature symbols of this service action are "A" or "B". Among them, for the vicinity of the start position of each sequence, it refers to the first X characters of each sequence. For example, X = 5.

[0235] 2) The feature symbols that exist in all sequences and are near the end positions of each sequence can be used as termination-type feature symbols. As shown in the example, the termination-type feature symbols for this service operation are "H" or "0". Among them, for near the end positions of each sequence, it means the last Y characters of each sequence, for example, Y = 5.

[0236] 3) Z feature symbols can be selected from the feature symbols that exist in all sequences as existence-type feature symbols, ensuring that these feature symbols: are not start-type feature symbols, are not termination-type feature symbols, and are not feature symbols in the longest common feature symbol subsequence. For example Figure 15 "F", "G", "X", "Y" in

[0237] 4) The recognition accuracy can be divided into multiple levels, and the existence-type feature symbols can be used to increase the recognition accuracy. For example, the recognition accuracy can be divided into 2 levels: generally accurate, highly accurate.

[0238] 5) The difference between the existence-type feature symbols and the feature symbols in the longest common feature symbol subsequence is that the order of the existence-type feature symbols in each sequence is inconsistent, while the order of each symbol in the longest common feature symbol subsequence remains unchanged in the corresponding feature symbol sequence.

[0239] Example 12

[0240] Process for obtaining the set of attribution-type feature symbols:

[0241] In the embodiments of the present application, the feature symbols that exist in more than a preset percentage of the total number of feature symbol sample sequences are used as attribution-type feature symbols. For example, the feature symbols that exist in more than 70% of the total number of sequences can be used as attribution-type feature symbols, that is, if a certain feature symbol exists in more than 7 of 10 sequences, then this feature symbol is considered an attribution-type feature symbol.

[0242] Figure 15 is a schematic diagram for obtaining the attribution-type feature symbols according to the embodiments of the present application, Figure 16 in which the feature symbols that exist in all sequences are used as attribution-type feature symbols and are shown in bold. Among them, the non-bold feature symbols indicate that the feature symbols do not appear in Figure 13 Figure 16 all the feature symbol sequences in, for example, "C" does not appear in the feature symbol sequence No6, "L" does not appear in the feature symbol sequences No2, No3, No4, No5, No6, No7, No8, No9, No10, etc.

[0243] In the embodiments of the present application, not all feature symbols in all sequences are considered as attribution-type feature symbols, which can avoid misidentifying occasional interfering traffic.

[0244] In an embodiment of the present application, by obtaining a flow in the traffic of a service action to be recognized and extracting the flow feature of the service action to be recognized from the flow; obtaining a mapping relationship and a feature symbol of a target service action; the mapping relationship being a mapping relationship between the flow feature and the feature symbol; generating a feature symbol sequence corresponding to the service action to be recognized according to the flow feature of the service action to be recognized and the mapping relationship; and determining that the service action to be recognized is the target service action when the feature symbol in the feature symbol sequence matches the feature symbol of the target service action, the problem that the DPI method in the related art cannot accurately recognize the service action in the APP is solved, and the service action in the APP can be accurately recognized to represent the user's intent behavior. Thus, the evaluation of the user's Internet experience by the network device is more accurate, and a reasonable basis can be provided for the network optimization function.

[0245] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

[0246] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to execute the steps in any one of the above method embodiments when running.

[0247] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (ROM for short), random access memory (RAM for short), mobile hard disk, magnetic disk, or optical disc and other media that can store computer programs.

[0248] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0249] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device, where the transmission device is connected to the above processor, and the input / output device is connected to the above processor.

[0250] For the specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary embodiments, and details thereof will not be repeated here.

[0251] Obviously, those skilled in the art should understand that the various modules or steps of the present application described above can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a sequence different from that here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. In this way, the present application is not limited to any specific combination of hardware and software.

[0252] The above are only exemplary embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included within the protection scope of the present application.

Claims

1. A method for identifying a service action, characterized in that, Including: Obtain the data stream in the traffic of the business action to be recognized, and extract the flow characteristics of the business action to be recognized from the data stream; Generate a feature symbol sequence of the business action to be recognized according to the flow characteristics of the business action to be recognized and a preset mapping relationship; wherein, the preset mapping relationship is the mapping relationship between the flow characteristics of the target business action and the feature symbols of the target business action; When the feature symbols in the feature symbol sequence match the feature symbols of the target business action, determine that the business action to be recognized is the target business action.

2. The method according to claim 1, characterized in that, The obtaining the data stream in the traffic of the business action to be recognized and extracting the flow characteristics of the business action to be recognized from the data stream includes: Establish a corresponding five-tuple flow table for the data stream in the traffic of the business action to be recognized; the data stream includes at least one request message; Based on the five-tuple flow table, extract the flow characteristics of the business action to be recognized, and the flow characteristics are the server domain names carried in the first request message of the data stream.

3. The method according to claim 1, wherein The feature symbols of the target business action include recognition type feature symbols; the recognition type feature symbols include at least one of the following: start type feature symbol set, longest common feature symbol subsequence, existence type feature symbol set, termination type feature symbol set.

4. The method according to claim 3, characterized in that The generating the feature symbol sequence of the business action to be recognized according to the flow characteristics of the business action to be recognized and a preset mapping relationship includes: Generate a header feature symbol sequence corresponding to the flow characteristics according to the time sequence of the appearance of the flow characteristics of the business action to be recognized and the mapping relationship; Traverse the feature symbols of the target business action, and match the header feature symbol sequence with the feature symbols of the target business action; When the recognition type feature symbols include the start type feature symbol set and the feature symbols in the header feature symbol sequence match at least one start type feature symbol in the start type feature symbol set, generate the feature symbol sequence of the business action to be recognized.

5. The method according to claim 4, characterized in that The generating the feature symbol sequence of the business action to be recognized when the recognition type feature symbols include the start type feature symbol set and the feature symbols in the header feature symbol sequence match at least one start type feature symbol in the start type feature symbol set includes: Mark the state of the business action to be recognized as the start state of the target business action; Generate the feature symbol sequence of the business action to be recognized in the start state.

6. The method according to claim 5, wherein It also includes: Obtain the maximum continuous duration of the target business action; When the duration of generating the feature symbol sequence of the business action to be recognized reaches the maximum continuous duration of the target business action, stop generating the feature symbol sequence of the business action to be recognized.

7. The method according to claim 3, characterized in that, When the feature symbols in the feature symbol sequence match the feature symbols of the target business action, determining that the business action to be recognized is the target business action includes: Judge whether the feature symbols in the feature symbol sequence match the longest common feature symbol subsequence; When the feature symbols in the feature symbol sequence match the longest common feature symbol subsequence, determine that the business action to be recognized is the target business action, and determine that the recognition accuracy is the first accuracy.

8. The method according to claim 7, wherein After determining that the business action to be recognized is the target business action, it further includes: Determine whether the feature symbols in the feature symbol sequence include all the existence-type feature symbols in the existence-type feature symbol set; When the feature symbols in the feature symbol sequence include all the existence-type feature symbols in the existence-type feature symbol set, determine that the recognition accuracy of the business action to be recognized as the target business action is the second accuracy, where the second accuracy is higher than the first accuracy.

9. The method according to claim 7, wherein The feature symbols of the target business action further include attribution-type feature symbols; after determining that the business action to be recognized is the target business action, it further includes: Match the feature symbols in the feature sequence with the attribution-type feature symbols; When the feature symbols match the attribution-type feature symbols, determine that the data stream corresponding to the feature symbols is the data stream in the target business action traffic.

10. The method according to claim 1, characterized in that Before obtaining the data stream in the traffic of the business action to be recognized, it further includes: Sample the traffic of the target business action, and extract flow features from the data stream in the traffic of the target business action; Assign a unique feature symbol to each flow feature of the target business action, and establish a mapping relationship between the flow features of the target business action and the feature symbols of the target business action.

11. The method according to claim 9, wherein Before obtaining the data stream in the traffic of the business action to be recognized, it further includes: Sample the traffic of the target business action multiple times, extract flow features from the data stream of the traffic of the target business action for each sampling, and generate multiple groups of flow feature samples corresponding to the traffic of the target business action; Generate multiple feature symbol sample sequences corresponding to the target business action according to the mapping relationship and the multiple groups of flow feature samples.

12. The method according to claim 11, wherein After generating multiple feature symbol sample sequences corresponding to the target business action, it further includes: Extract from the multiple feature symbol sample sequences corresponding to the target business action to obtain the recognition-type feature symbols and the attribution-type feature symbols.

13. The method according to claim 11, wherein The generating multiple feature symbol sample sequences corresponding to the target business action according to the mapping relationship between the flow features and the feature symbols and the multiple groups of flow feature samples includes: Generate multiple preliminary feature symbol sample sequences corresponding to the target business action according to the mapping relationship between the flow features and the feature symbols and the multiple groups of flow feature samples; Compress adjacent and continuously repeated feature symbols in the preliminary feature symbol sequence into one feature symbol to generate multiple feature symbol sample sequences corresponding to the target business action.

14. The method according to any one of claims 1-11, characterized in that, The types of data streams in the traffic of the target business action include at least one of the following streams: HTTP stream, HTTPS stream, QUIC stream.

15. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program, when executed by a processor, implements the steps of the method described in any one of claims 1 to 13.

16. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the method described in any one of claims 1 to 13 are implemented.