Online monitoring method and system based on network traffic behavior identification

By constructing a nested pseudo-twin network structure to extract and analyze network traffic characteristics, the problem of inaccurate identification of adolescents' online behavior patterns in existing technologies has been solved, and accurate online behavior monitoring has been achieved.

CN120434287BActive Publication Date: 2025-11-04联通(陕西)产业互联网有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510934793.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-11-04
Estimated Expiration
2045-07-08

AI Technical Summary

Technical Problem

Existing technologies cannot accurately identify the online behavior patterns of teenagers, leading to inaccurate management, easy omissions or misjudgments.

Method used

A nested pseudo-twin network structure is constructed. By filtering and analyzing historical network traffic data, the characteristics of clean and mixed traffic are extracted, clean and mixed characteristic curves are generated, and comparative analysis is performed to identify the online behavior of teenagers.

Benefits of technology

It enables precise monitoring of teenagers' online behavior, improving the accuracy of identification and management effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434287B_ABST
    Figure CN120434287B_ABST
Patent Text Reader

Abstract

The application discloses an online monitoring method and system based on network traffic behavior recognition, and relates to the technical field of online monitoring, comprising: obtaining a historical network traffic database; obtaining a preset behavior mode of a target user, wherein the preset behavior mode corresponds to preset traffic characteristics; screening a plurality of historical data packet information with the preset traffic characteristics as a screening constraint to obtain pure traffic; activating an inner network in a nested pseudo-twin network structure to analyze a pure characteristic parameter set of the pure traffic, and obtaining a pure characteristic curve; obtaining mixed traffic, and analyzing the mixed traffic through an outer network in the nested pseudo-twin network structure to obtain a mixed characteristic curve; and performing online monitoring of the target user according to a comparison result obtained by comparing the mixed characteristic curve with the pure characteristic curve. The application solves the technical problem that the prior art cannot accurately identify specific online behavior modes of teenagers, and achieves the technical effect of accurately monitoring online behavior of teenagers.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of online monitoring, and particularly relates to an online monitoring method and system based on network traffic behavior recognition. BACKGROUND

[0002] In the management of online behaviors of teenagers, keyword filtering, access address list or traffic statistics-based methods are often used to judge online behaviors. These methods mainly rely on access content or frequency for preliminary identification, and lack comprehensive analysis of time sequence characteristics, protocol characteristics and device characteristics in network traffic, especially in the case of mixed learning and non-learning behaviors of teenagers, it is difficult to accurately identify the specific behavior patterns. Due to the lack of correlation analysis of individual historical behavior patterns and current behaviors, the behavior recognition is not accurate, and the problems of missed judgment or misjudgment often occur, which leads to ineffective management of online behaviors of teenagers. SUMMARY

[0003] The present application provides an online monitoring method and system based on network traffic behavior recognition, which is used to solve the technical problem that the specific online behavior patterns of teenagers cannot be accurately identified in the prior art.

[0004] In view of the above problems, the present application provides an online monitoring method and system based on network traffic behavior recognition.

[0005] In a first aspect of the present application, an online monitoring method based on network traffic behavior recognition is provided, which comprises:

[0006] obtaining a historical network traffic database, wherein the historical network traffic database comprises a plurality of historical data packet information; obtaining a preset behavior pattern of a target user, wherein the preset behavior pattern corresponds to a preset traffic characteristic; screening the plurality of historical data packet information with the preset traffic characteristic as a screening constraint to obtain pure traffic; activating an inner network in a nested pseudo-twin network structure to analyze a pure characteristic parameter set of the pure traffic, and obtaining a pure characteristic curve; obtaining mixed traffic, and analyzing the mixed traffic through an outer network in the nested pseudo-twin network structure to obtain a mixed characteristic curve; and performing online monitoring of the target user according to a comparison result obtained by comparing the mixed characteristic curve and the pure characteristic curve.

[0007] In a second aspect of the present application, an online monitoring system based on network traffic behavior recognition is provided, which comprises:

[0008] The historical data acquisition module is configured to acquire a historical network traffic database, wherein the historical network traffic database comprises a plurality of historical data packet information; the behavior pattern acquisition module is configured to acquire a preset behavior pattern of a target user, wherein the preset behavior pattern corresponds to a preset traffic feature; the screening module is configured to screen the plurality of historical data packet information with the preset traffic feature as a screening constraint to obtain pure traffic; the first analysis module is configured to activate an inner network in a nested pseudo twin network structure to analyze a pure feature parameter set of the pure traffic to obtain a pure feature curve; the second analysis module is configured to acquire mixed traffic and analyze the mixed traffic through an outer network in the nested pseudo twin network structure to obtain a mixed feature curve; and the online monitoring module is configured to perform online monitoring of the target user according to a comparison result obtained by comparing the mixed feature curve with the pure feature curve.

[0009] One or more technical solutions provided in the present application have at least the following technical effects or advantages:

[0010] The present application acquires a historical network traffic database, wherein the historical network traffic database comprises a plurality of historical data packet information; acquires a preset behavior pattern of a target user, wherein the preset behavior pattern corresponds to a preset traffic feature; screens the plurality of historical data packet information with the preset traffic feature as a screening constraint to obtain pure traffic; activates an inner network in a nested pseudo twin network structure to analyze a pure feature parameter set of the pure traffic to obtain a pure feature curve; acquires mixed traffic and analyzes the mixed traffic through an outer network in the nested pseudo twin network structure to obtain a mixed feature curve; and performs online monitoring of the target user according to a comparison result obtained by comparing the mixed feature curve with the pure feature curve. The present application solves the technical problem that a specific online behavior pattern of a teenager cannot be accurately identified in the prior art, and achieves the technical effect of accurately monitoring online behavior of a teenager by constructing a nested pseudo twin network structure to extract and compare pure and mixed traffic features. BRIEF DESCRIPTION OF DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.

[0012] Figure 1 The online monitoring method based on network traffic behavior identification provided by the embodiments of the present application is shown in the flowchart.

[0013] Figure 2A network monitoring system structure schematic diagram based on network traffic behavior recognition is provided in the embodiments of the present application.

[0014] Reference signs: historical data acquisition module 11, behavior pattern acquisition module 12, screening module 13, first analysis module 14, second analysis module 15, network monitoring module 16. DETAILED DESCRIPTION

[0015] The present application provides a network monitoring method and system based on network traffic behavior recognition, which can accurately identify specific online behavior patterns of teenagers in the prior art. By constructing a nested pseudo-twin network structure, pure and mixed traffic features are extracted and compared, achieving the technical effect of accurately monitoring the online behavior of teenagers.

[0016] The technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0017] It should be noted that any variation of the terms "comprise" and "have" is intended to cover non-exclusive inclusion, for example, a process, method, system, product or server comprising a series of steps or units does not have to be limited to those clearly listed steps or units, but can include other steps or modules that are not clearly listed or inherent to the process, method, product or device.

[0018] Embodiment one, as shown in the present application provides a network monitoring method based on network traffic behavior recognition, which comprises: Figure 1

[0019] Acquiring a historical network traffic database, wherein the historical network traffic database comprises a plurality of historical data packet information.

[0020] In the embodiments of the present application, a data capture device is deployed in a network communication link to continuously capture network transmission data generated by the target user during the online process, and these data are stored and arranged in the form of data packets to form a historical network traffic database. The historical network traffic database is indexed by time and saves a plurality of sequentially arranged historical data packet information.

[0021] ​Each historical data packet information includes multiple key field contents, specifically including source IP address and destination IP address, used to identify the network locations of the two parties of communication; source port and destination port, used to distinguish specific communication service types; protocol type, such as TCP, UDP or HTTP, used to indicate the transmission protocol adopted by the data packet; timestamp, used to record the sending or receiving time of the data packet; and data length, payload data and other auxiliary fields.

[0022] obtaining a preset behavior mode of the target user, wherein the preset behavior mode corresponds to a preset traffic feature.

[0023] In the embodiments of the present application, first, the preset behavior mode of the target user is obtained, that is, a pre-prepared behavior type template is called, which is used to define the behavior characteristics that the teenager should exhibit in a specific online situation, such as online learning, visiting an education platform or a specific social activity, etc. These preset behavior modes are formulated by technical experts in advance according to education management requirements or relevant behavior specifications, and have standardization and identifiability.

[0024] The preset traffic feature corresponding to the preset behavior mode refers to a set of network communication feature parameters matched one-to-one with the preset behavior mode, including source IP address, destination IP address, source port, destination port and protocol type, etc. These traffic features are used to identify the communication traffic consistent with the behavior mode in actual network data.

[0025] screening the plurality of historical data packet information with the preset traffic feature as a screening constraint to obtain pure traffic.

[0026] In the embodiments of the present application, the plurality of historical data packet information is screened with the preset traffic feature as a screening constraint. Specifically, a preset quintuple corresponding to the preset behavior mode is constructed as a screening template, and the key information in the historical data packet is extracted one by one to generate a corresponding quintuple. Through consistency comparison between the two, the traffic data meeting the conditions is screened out, and finally the pure traffic matching the target behavior mode is obtained.

[0027] Further, the method provided by the embodiments of the present application, screening the plurality of historical data packet information with the preset traffic feature as a screening constraint to obtain pure traffic, further includes:

[0028] forming a preset quintuple according to the preset traffic feature; extracting first information in the plurality of historical data packet information, and analyzing the first information to obtain a first quintuple; judging whether the first quintuple is consistent with the preset quintuple; if consistent, the first traffic corresponding to the first information is taken as the pure traffic.

[0029] Further, the method provided by the embodiments of the present application further includes:

[0030] The preset quintuple includes a preset source IP, a preset destination IP, a preset source port, a preset destination port, and a preset protocol type.

[0031] In the embodiment of the present application, first, a screening reference is constructed according to a preset traffic characteristic, forming a preset quintuple, which includes five fields of a preset source IP, a preset destination IP, a preset source port, a preset destination port, and a preset protocol type, for uniquely identifying the network communication characteristic corresponding to the target behavior.

[0032] Then, multiple historical data packet information in the historical network traffic database is processed in a traversal manner. Specifically, each piece of historical data packet information is read as first information, and a network protocol field analysis method is called to decode the message structure of the data packet, from which field values such as source IP address, destination IP address, source port number, destination port number, and protocol type are extracted, combined in a predetermined order, and a corresponding first quintuple is formed.

[0033] After the field extraction is completed, a quintuple comparison operation is performed to make a field-level consistency judgment between the generated first quintuple and the preset quintuple. Through field matching rules, the values of source IP, destination IP, source port, destination port, and protocol type are compared respectively to determine whether the contents of the two quintuples in all fields are completely consistent.

[0034] If the comparison result shows that the first quintuple is consistent with the preset quintuple, it indicates that the network communication behavior corresponding to the first information is consistent with the target behavior characteristic, and the network communication record corresponding to the data packet is regarded as pure traffic. The screening process compares all the historical data packets obtained in the traversal manner one by one, and only retains the traffic information that meets the requirement of complete field consistency, and excludes other traffic unrelated to the target behavior.

[0035] Further, the method provided by the application embodiment further includes the following steps before the inner network in the activated nested pseudo-twin network structure analyzes the pure characteristic parameter set of the pure traffic and obtains a pure characteristic curve:

[0036] acquiring a predetermined traffic characteristic dimension; collecting a first characteristic parameter set based on the predetermined traffic characteristic dimension, the first characteristic parameter set being obtained by collecting the first information in multiple dimensions; and taking the first characteristic parameter set as the pure characteristic parameter set; wherein the predetermined traffic characteristic dimension includes a time sequence dimension, a protocol dimension, and a device dimension, the time sequence dimension includes a sending frequency, a receiving frequency, and a time interval, the protocol dimension includes a protocol type, a key field content, and an occurrence frequency thereof, and the device dimension includes a hardware ID, a device type, and a network card MAC address.

[0037] In the embodiment of the present application, first, the pre-set predetermined traffic feature dimension is acquired, and the predetermined traffic feature dimension is used for classifying key attributes in network traffic, and specifically includes a time sequence dimension, a protocol dimension, and a device dimension. The time sequence dimension is used for describing transmission characteristics of data packets in the time domain, and includes sending frequency, receiving frequency, and time interval between adjacent data packets. The protocol dimension is used for reflecting protocol types and content characteristics of data communication, and includes protocol type, key field content, and occurrence frequency of the key field content in the communication process. The device dimension is used for identifying terminal device characteristics participating in communication, and includes hardware ID, device type, and network card MAC address.

[0038] Next, based on the predetermined traffic feature dimension, multi-dimensional feature collection is performed on each piece of first information. In the time sequence dimension, by analyzing the timestamp sequence of each data packet in the communication session in which the first information is located, the time interval between adjacent data packets is calculated, and the sending frequency and the receiving frequency in a unit time are counted. In the protocol dimension, a protocol analysis tool is called to identify the protocol type used, and the key field content is extracted from the data load, such as the request method of HTTP, the DNS query name, etc., and the occurrence frequency of the key field content in the data stream is counted. In the device dimension, the device identification information related to communication is extracted, including hardware ID (such as motherboard number, device identification code), device type (such as mobile terminal, desktop terminal), and network card MAC address, and standardized processing is performed thereon to ensure uniformity of field format.

[0039] Finally, the nine types of parameters collected, including sending frequency, receiving frequency, time interval, protocol type, key field content, occurrence frequency of key field content, hardware ID, device type, and network card MAC address, are uniformly constructed into a first feature parameter set.

[0040] The inner layer network in the activated nested pseudo-twin network structure analyzes the pure feature parameter set of the pure traffic, and obtains a pure feature curve.

[0041] In the embodiment of the present application, when the inner layer network in the activated nested pseudo-twin network structure analyzes the pure feature parameter set of the pure traffic, first, any index of any dimension in the predetermined traffic feature dimension is selected, such as sending frequency, protocol type, or device type. Then, the parameter value corresponding to the index is matched in the pure feature parameter set. For the matched parameter value, a predetermined coding strategy corresponding thereto is called to perform digital coding processing, and a standardized coding value is generated. The predetermined coding strategy includes multiple coding schemes set for various indexes in the predetermined traffic feature dimension, and can adapt to the value type and expression format of different behavior characteristics. By establishing a corresponding relationship between any index and its coding value, the inner layer network converts the pure feature parameter set into a structured feature expression sequence, and finally forms a continuous pure feature curve.

[0042] The nested pseudo-twin network structure is composed of an inner network and an outer network, the inner network is used for feature modeling of pure traffic with completed behavior classification and behavior label, and aims to generate a pure feature curve that can be used as a standard behavior reference.

[0043] Further, the method provided by the application embodiment further includes:

[0044] An arbitrary index of an arbitrary dimension in the predetermined traffic feature dimension is obtained, an arbitrary parameter corresponding to the arbitrary index is matched in the pure feature parameter set, a predetermined encoding strategy is called to digitally encode the arbitrary parameter to obtain an arbitrary encoding value, and the inner network forms the pure feature curve based on the corresponding relationship between the arbitrary index and the arbitrary encoding value.

[0045] Further, the method provided by the application embodiment further includes:

[0046] The predetermined encoding strategy includes multiple encoding schemes of multiple dimension indexes in the predetermined traffic feature dimension.

[0047] In the application embodiment, first, an arbitrary index of an arbitrary dimension in a predetermined traffic feature dimension is obtained. The predetermined traffic feature dimension includes a time sequence dimension, a protocol dimension, and a device dimension, each of which contains multiple refined indexes that can be used for modeling, such as sending frequency, receiving frequency, and time interval in the time sequence dimension, protocol type, key field content, and its occurrence frequency in the protocol dimension, and hardware ID, device type, and network card MAC address in the device dimension. Taking the protocol dimension as an example, the protocol type in the protocol dimension can be a specific protocol such as HTTP, TCP, and DNS, the key field content can be the Host field of HTTP or the Query field of DNS, and the occurrence frequency refers to the statistical number of the field in a certain time window or data stream.

[0048] After obtaining the arbitrary index, the specific parameter value corresponding to the index is located and extracted in the pure feature parameter set. The pure feature parameter set is a structured data set formed by feature extraction on pure traffic in the early stage, and each field in the set corresponds to a specific index. For example, if the selected index is “protocol type”, the corresponding field is found in the pure feature parameter set, such as “Protocol=HTTP” or “Protocol=TCP”, and the value is extracted.

[0049] After the parameter value is extracted, the parameter value is digitally encoded by calling a predetermined encoding strategy matched with the index. The predetermined encoding strategy is a standardized numerical conversion method preset for different indexes, including one-hot encoding, normalization encoding, label encoding, word embedding, etc. Taking "protocol type" as an example, since the index is a discrete classification variable, one-hot encoding can be used to convert it into a numerical vector, for example, "HTTP" corresponds to [1, 0, 0], "TCP" corresponds to [0, 1, 0], and "DNS" corresponds to [0, 0, 1]; for continuous indexes such as "sending frequency", the value is standardized to the interval [0, 1] by using the minimum-maximum normalization. The predetermined encoding strategy contains multiple encoding schemes, each corresponding to all optional indexes in the predetermined traffic feature dimension, ensuring that each type of parameter uses an adaptive encoding method.

[0050] After encoding is completed, a mapping relationship between any index and its corresponding any encoding value is established, and multiple encoding values are combined into a vector sequence in accordance with a preset order. The vector sequence is a pure feature curve, which is used to represent the multi-dimensional feature variation trend of the target user under the condition of meeting the behavior template.

[0051] The mixed traffic is obtained, and the mixed traffic is analyzed by using the outer network in the nested pseudo-twin network structure to obtain a mixed feature curve.

[0052] In the embodiments of the present application, in order to identify whether there is an inconsistent condition with the preset behavior mode in the current network behavior of the target user, the mixed traffic is first obtained. The mixed traffic refers to the part remaining after excluding the pure traffic that has matched the preset five-tuple from the plurality of historical packet information, specifically including the data communication records that do not meet the matching conditions of the source IP address, the destination IP address, the source port, the destination port and the protocol type. The mixed traffic usually contains online behavior data with complex sources and uncertain behaviors, which may involve social, entertainment, information retrieval and other non-target behavior characteristics.

[0053] After obtaining the mixed traffic, the outer network in the nested pseudo-twin network structure is called for analysis. The nested pseudo-twin network structure is composed of an inner network and an outer network, wherein the outer network is used to express the structure of the currently observed mixed traffic which has not been classified by behavior, and aims to generate a mixed feature curve which can be compared with a standard behavior curve. The analysis process is consistent with the processing method of pure traffic. First, the predetermined traffic feature dimensions are obtained, including time sequence dimension, protocol dimension and device dimension. The time sequence dimension includes sending frequency, receiving frequency and time interval, which is used to describe the dynamic characteristics of communication behavior in the time domain; the protocol dimension includes protocol type, key field content and its occurrence frequency, which is used to describe the structural properties of the communication protocol layer and the application layer; and the device dimension includes hardware ID, device type and network card MAC address, which is used to identify the physical identity of the terminal.

[0054] Next, based on the above predetermined traffic feature dimensions, multi-dimensional feature collection is performed on the mixed traffic. In the time sequence dimension, by analyzing the data packet timestamp sequence in the mixed traffic, the time interval of adjacent data packets is calculated, and the data packet sending frequency and receiving frequency per unit time are counted; in the protocol dimension, the communication protocol type is extracted by using the protocol field analysis method, and the key field content in the data load is analyzed, and its occurrence frequency in the communication process is recorded; in the device dimension, the device identification information associated with the mixed traffic is extracted, including hardware ID, device type and network card MAC address, etc., and standardized processing is performed to ensure consistency. Thus, a structured feature parameter set covering three dimensions and nine indicators is formed.

[0055] Subsequently, the predetermined encoding strategy consistent with the pure traffic processing is called to digitally encode the above parameters. For discrete indicators (such as protocol type, device type), one-hot encoding is used, for continuous indicators (such as sending frequency, time interval), normalization encoding is used, and for identification indicators (such as MAC address), label encoding or hash mapping is used to convert them into a unified numerical format. The encoded values are combined in a specific order to form a mixed feature vector sequence.

[0056] Finally, the outer network generates a mixed feature curve based on the mapping relationship between the above indicators and encoding values. The mixed feature curve is used as the feature expression of the current behavior of the target user, and is used for comparative analysis with the pure feature curve generated by the inner network to identify whether there is a behavior deviation or potential anomaly.

[0057] According to the comparison result obtained by comparing the mixed feature curve and the pure feature curve, the online monitoring of the target user is performed.

[0058] In the embodiments of the present application, firstly, the comparison results reflecting the overall difference degree of the two feature curves are obtained by comparing the mixed feature curve and the pure feature curve between all point pairs. Specifically, the mixed feature curve and the pure feature curve are respectively represented as a continuous vector sequence under the same feature dimension, based on all possible point pair combinations, the feature distance value between each pair of points is calculated by using a multi-dimensional feature distance measurement method, and a complete point pair distance mapping set is formed. On this basis, based on the principle of minimum alignment cost, a matching path is selected which makes the maximum distance value in the overall point pair distance sequence minimum, and a stable comparison result which can be used to reflect the global behavior difference of the curve is generated.

[0059] Next, based on the uniform sampling principle, representative point pairs with equal intervals are selected from the two feature curves to construct a point pair sample set. Then, based on the point pair sample set, the difference value between each sample point pair in the comparison result is extracted to obtain a structured sample comparison result. Next, the sample comparison result is analyzed and filled into the preset comparison grid to form a filling result for spatializing the behavior difference. The filling value corresponding to the predetermined grid position in the filling result is extracted as the target distance value between the mixed feature curve and the pure feature curve. If the target distance value is within the predetermined distance threshold range, an online warning signal is triggered. Finally, based on the online warning signal, it is judged that the current behavior of the target user has deviated from the established mode, and a warning of the existence of the preset behavior mode is issued, realizing dynamic identification and risk prompt of the online behavior of the target user.

[0060] Further, in the method provided by the embodiments of the present application, the online monitoring of the target user according to the comparison result obtained by comparing the mixed feature curve and the pure feature curve further comprises:

[0061] The point pair sample set is constructed based on the uniform sampling principle; the sample comparison result is obtained by traversing the comparison result based on the point pair sample set; the sample comparison result is analyzed and filled into the predetermined comparison grid to obtain the filling result; the filling value corresponding to the predetermined grid in the filling result is taken as the target distance value between the mixed feature curve and the pure feature curve; if the target distance value is within the predetermined distance threshold, an online warning signal is issued; and the target user is warned of the existence of the preset behavior mode based on the online warning signal.

[0062] In the embodiments of the present application, first, the point pair sample set is constructed based on the uniform sampling principle. The uniform sampling principle refers to extracting feature points on the mixed feature curve and the pure feature curve according to the same sampling interval, so as to ensure that the paired feature points are constructed at the same time scale or behavior sequence position. The sampling interval can be normalized divided according to the length of the feature curve to obtain equidistantly distributed sampling indexes, thereby constructing the point pair sample set.

[0063] After the construction, the sample set is traversed in the comparison result based on the point pair to obtain a sample comparison result. The comparison result is a distance mapping set between all point pairs obtained by comparing the two complete characteristic curves point by point in advance. The distance value between each pair of feature points of the mixed characteristic curve and the pure characteristic curve is calculated in a multi-dimensional Euclidean distance-based manner. In the traversal process, the corresponding distance value of each pair of sampling points in the sample set in the comparison result is extracted in sequence to form the sample comparison result.

[0064] Then, the sample comparison result is analyzed and the filling of the predetermined comparison grid is performed. In this step, the first result in the sample comparison result is first filled into the first row and first column regions of the predetermined comparison grid to form the initial filling result of the first region. Then, taking the filling value of the first region as a reference, the filling of the second region of the predetermined comparison grid other than the first row and the first column is continued to form the second filling result. Finally, the first filling result of the first region and the second filling result of the second region are combined to form the filling result.

[0065] After the filling is completed, the filling value corresponding to the predetermined grid in the filling result is taken as the target distance value between the mixed characteristic curve and the pure characteristic curve. The target distance value is compared with the predetermined distance threshold preset by the technical expert. If the target distance value is within the predetermined distance threshold, it is determined that the current behavior of the target user may deviate from the preset behavior mode, and an online warning signal is issued.

[0066] Finally, the online warning signal is used to warn the target user of the preset behavior mode, that is, the real-time recognition and abnormal prompt of the behavior state of the target user are completed by triggering the warning mechanism.

[0067] Further, in the method provided by the application embodiment, the sample comparison result is analyzed and the filling of the predetermined comparison grid is performed to obtain the filling result, which further includes:

[0068] The first result in the sample comparison result is taken; the first result is filled into the first region of the predetermined comparison grid to obtain a first filling result; the second region of the predetermined comparison grid is filled with reference to the first filling result to obtain a second filling result; the first filling result and the second filling result constitute the filling result; wherein the first region refers to the first row grid and the first column grid of the predetermined comparison grid, and the second region refers to the grid region of the predetermined comparison grid other than the first region.

[0069] In the embodiment of the present application, first, a first result is extracted from the sample comparison result, and the first result is a distance value of a pair of feature points located at the first position in the sample comparison result. Then, the first result is filled into a first region in a predetermined comparison grid, i.e., a first row and a first column in the grid structure, to obtain a first filling result by using a copy filling method.

[0070] Next, with reference to the first filling result, a second region in the predetermined comparison grid except the first row and the first column is filled to generate a second filling result. In this process, first, any grid cell to be filled in the second region is traversed, and based on its relative position in the grid, any reference grid set of the grid is constructed, i.e., the filled grids at the adjacent positions including the upper side, the left side, and the upper left corner of the grid. Then, the maximum value in the any reference grid set is selected as the maximum reference grid value. Then, the corresponding distance value of the any grid in the sample comparison result, i.e., the any filling value of the any grid, is summed with the maximum reference grid value, and the sum is written into the any grid cell to complete the update filling operation at the current position. The same operation is sequentially performed on all the grid cells in the second region, so that the second region is completely filled, and the complete second filling result is obtained.

[0071] Finally, the first filling result and the second filling result are combined to form the entire filling result. The first region refers to the first row and the first column of the predetermined comparison grid, which is used as a boundary condition; and the second region refers to all the internal grid regions in the comparison grid except the first region, which constitutes a main calculation region.

[0072] Further, in the method provided by the embodiment of the present application, with reference to the first filling result, the second region of the predetermined comparison grid is filled to obtain the second filling result, and the method further includes:

[0073] extracting any grid in the second region and constructing any reference grid set of the any grid; selecting the maximum reference grid value in the any reference grid set; summing the any filling value corresponding to the any grid and the maximum reference grid value to update and fill the any grid, and obtaining the second filling result.

[0074] In the embodiment of the present application, first, any grid in the second region is extracted to locate the grid to be filled. Then, any reference grid set of the any grid is constructed, and the reference grid set includes three adjacent grids of the left side, the upper side, and the upper left side of the any grid. The filling values of the three reference grids are sequentially read, and the maximum value is selected as the maximum reference grid value of the current any grid.

[0075] Then, the original distance value corresponding to the current arbitrary grid is extracted from the sample comparison result as an arbitrary filling value of the current arbitrary grid. The arbitrary filling value is summed with the maximum reference grid value to obtain an updated filling value of the current arbitrary grid. Finally, the updated filling value is written into the current arbitrary grid position, and the update filling of the grid is completed.

[0076] The above process is repeated to sequentially perform the same operation on all grids in the second region until the filling of the second region is completed, and a second filling result is formed.

[0077] In the embodiments of the present application, as described above, the embodiments of the present application have at least the following technical effects:

[0078] The present application obtains a historical network traffic database, wherein the historical network traffic database includes a plurality of historical data packet information; a preset behavior mode of a target user is obtained, wherein the preset behavior mode corresponds to a preset traffic feature; the plurality of historical data packet information is filtered with the preset traffic feature as a filtering constraint to obtain pure traffic; the pure feature parameter set of the pure traffic is analyzed by an inner network in a nested pseudo twin network structure to obtain a pure feature curve; mixed traffic is obtained, and the mixed traffic is analyzed by an outer network in the nested pseudo twin network structure to obtain a mixed feature curve; online monitoring of the target user is performed according to a comparison result obtained by comparing the mixed feature curve and the pure feature curve. The present application solves the technical problem that the specific online behavior mode of teenagers cannot be accurately identified in the prior art, and achieves the technical effect of accurately monitoring the online behavior of teenagers by constructing a nested pseudo twin network structure to extract and compare pure and mixed traffic features.

[0079] Embodiment two, based on the same inventive concept as the online monitoring method based on network traffic behavior recognition in the foregoing embodiments, as shown in Figure 2 The present application provides an online monitoring system based on network traffic behavior recognition, and the system and method embodiments in the embodiments of the present application are based on the same inventive concept. The system includes:

[0080] The historical data acquisition module 11 is configured to acquire a historical network traffic database, wherein the historical network traffic database comprises a plurality of historical packet information; the behavior pattern acquisition module 12 is configured to acquire a preset behavior pattern of a target user, wherein the preset behavior pattern corresponds to a preset traffic feature; the screening module 13 is configured to screen the plurality of historical packet information by taking the preset traffic feature as a screening constraint to obtain pure traffic; the first analysis module 14 is configured to activate an inner network in a nested pseudo twin network structure to analyze a pure feature parameter set of the pure traffic, and obtain a pure feature curve; the second analysis module 15 is configured to acquire mixed traffic, and analyze the mixed traffic by an outer network in the nested pseudo twin network structure to obtain a mixed feature curve; and the online monitoring module 16 is configured to perform online monitoring of the target user according to a comparison result obtained by comparing the mixed feature curve with the pure feature curve.

[0081] Further, the system is further configured to implement the following functions:

[0082] According to the preset traffic feature, a preset quintuple is formed; a first information in the plurality of historical packet information is extracted, and a first quintuple is obtained by analyzing the first information; it is judged whether the first quintuple is consistent with the preset quintuple; if yes, a first traffic corresponding to the first information is taken as the pure traffic.

[0083] Further, the system is further configured to implement the following functions:

[0084] The preset quintuple comprises a preset source IP, a preset destination IP, a preset source port, a preset destination port and a preset protocol type.

[0085] Further, the system is further configured to implement the following functions:

[0086] A predetermined traffic feature dimension is acquired; a first feature parameter set is obtained by performing multi-dimensional feature collection on the first information based on the predetermined traffic feature dimension; and the first feature parameter set is taken as the pure feature parameter set; wherein the predetermined traffic feature dimension comprises a time sequence dimension, a protocol dimension and a device dimension, the time sequence dimension comprises a sending frequency, a receiving frequency and a time interval, the protocol dimension comprises a protocol type, a key field content and an occurrence frequency thereof, and the device dimension comprises a hardware ID, a device type and a network card MAC address.

[0087] Further, the system is further configured to implement the following functions:

[0088] acquire any index of any dimension in the predetermined traffic feature dimension; match any parameter corresponding to the any index in the pure feature parameter set; call a predetermined encoding strategy to digitally encode the any parameter to obtain an any encoding value; the inner layer network forms the pure feature curve based on the corresponding relationship between the any index and the any encoding value.

[0089] Further, the system is also used to realize the following functions:

[0090] The predetermined encoding strategy includes a plurality of encoding schemes of a plurality of dimension indexes in the predetermined traffic feature dimension.

[0091] Further, the system is also used to realize the following functions:

[0092] Based on the uniform sampling principle, a point-to-sample set is established; based on the point-to-sample set, a sample comparison result is obtained by traversing in the comparison result; the sample comparison result is analyzed and a predetermined comparison grid is filled to obtain a filling result; a filling value corresponding to a predetermined grid in the filling result is taken as a target distance value of the mixed feature curve and the pure feature curve; if the target distance value is within a predetermined distance threshold, an online early warning signal is issued; based on the online early warning signal, the target user is warned of the preset behavior mode.

[0093] Further, the system is also used to realize the following functions:

[0094] Take a first result in the sample comparison result; fill the first result to a first area of the predetermined comparison grid to obtain a first filling result; based on the first filling result as a reference, a second area of the predetermined comparison grid is filled to obtain a second filling result; the first filling result and the second filling result constitute the filling result; wherein the first area refers to the first row and the first column of the predetermined comparison grid, and the second area refers to the grid area of the predetermined comparison grid except the first area.

[0095] Further, the system is also used to realize the following functions:

[0096] Extract any grid in the second area and establish any reference grid set of the any grid; filter to obtain a maximum reference grid value in the any reference grid set; take the sum of any filling value corresponding to the any grid and the maximum reference grid value to update the filling of the any grid to obtain the second filling result.

[0097] It should be noted that the above-mentioned embodiment sequence of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. And the above describes a specific embodiment of the present application. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.

[0098] The above only describes the preferred embodiments of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0099] The present application is only an exemplary description of the present application, and is considered to cover any and all modifications, changes, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various modifications and changes to the present application without departing from the scope of the present application. Thus, if these modifications and changes of the present application belong to the scope of the present application and its equivalents, the present application intends to include these modifications and changes.

Claims

1. A method for monitoring internet access based on network traffic behavior recognition, characterized in that, include: Obtain a historical network traffic database, wherein the historical network traffic database includes information on multiple historical data packets; Obtain the preset behavior pattern of the target user, wherein the preset behavior pattern corresponds to preset traffic characteristics; The multiple historical data packets are filtered using the preset traffic characteristics as filtering constraints to obtain clean traffic; The inner network in the nested pseudo-twin network structure is activated to analyze the pure characteristic parameter set of the pure flow, and the pure characteristic curve is obtained. The promiscuous traffic is acquired, and the promiscuous traffic is analyzed through the outer network in the nested pseudo-twin network structure to obtain the promiscuous characteristic curve; Based on the comparison results obtained by comparing the mixed feature curve and the pure feature curve, the internet access monitoring of the target user is performed; The process of filtering the multiple historical data packets using the preset traffic characteristics as a filtering constraint to obtain clean traffic includes: A preset quintuple is formed based on the preset flow characteristics; Extract the first information from the multiple historical data packets and analyze the first information to obtain the first quintuple; Determine whether the first quintuple is consistent with the preset quintuple; If they match, the first flow corresponding to the first information is taken as the pure flow. Before analyzing the pure characteristic parameter set of the pure flow to obtain the pure characteristic curve by activating the inner network in the nested pseudo-twin network structure, the process includes: Obtain the characteristic dimensions of the pre-defined traffic; Based on the predetermined traffic feature dimensions, multidimensional feature collection is performed on the first information to obtain a first feature parameter set; The first feature parameter set is used as the pure feature parameter set; The predetermined traffic feature dimensions include a time-series dimension, a protocol dimension, and a device dimension. The time-series dimension includes the sending frequency, the receiving frequency, and the time interval. The protocol dimension includes the protocol type, key field content, and their frequency of occurrence. The device dimension includes the hardware ID, device type, and network card MAC address.

2. The internet access monitoring method based on network traffic behavior recognition as described in claim 1, characterized in that, The preset quintuple includes a preset source IP, a preset destination IP, a preset source port, a preset destination port, and a preset protocol type.

3. The internet access monitoring method based on network traffic behavior recognition as described in claim 1, characterized in that, Activating the inner network in the nested pseudo-twin network structure to analyze the pure characteristic parameter set of the pure flow, yields a pure characteristic curve, including: Obtain any index from any dimension of the predetermined traffic feature dimensions; Match any parameter corresponding to any index in the pure feature parameter set; The predetermined encoding strategy is invoked to digitally encode the arbitrary parameter to obtain an arbitrary encoded value; The inner network forms the pure feature curve based on the correspondence between the arbitrary index and the arbitrary encoded value.

4. The internet access monitoring method based on network traffic behavior recognition as described in claim 3, characterized in that, The predetermined coding strategy includes multiple coding schemes for multiple dimension indicators in the predetermined traffic feature dimensions.

5. The Internet access monitoring method based on network traffic behavior recognition as described in claim 1, characterized in that, Based on the comparison results obtained by comparing the mixed feature curve and the pure feature curve, the internet access monitoring of the target user is performed, including: A point-to-point sample set is constructed based on the principle of uniform sampling. Based on the point-to-sample set, the comparison results are obtained by traversing the comparison results; The sample comparison results are analyzed and a predetermined comparison grid is filled to obtain the filling result; Take the filling value corresponding to the predetermined grid in the filling result as the target distance value between the mixed feature curve and the pure feature curve; If the target distance value is within a predetermined distance threshold, an internet access warning signal will be issued. The system issues a warning based on the internet access warning signal, indicating that the target user exhibits the preset behavioral pattern.

6. The Internet access monitoring method based on network traffic behavior recognition as described in claim 5, characterized in that, Analyze the sample comparison results and fill the predetermined comparison grid to obtain the filling result, including: Take the first result from the sample comparison results; The first result is filled into the first region of the predetermined contrast grid to obtain the first filling result; Using the first filling result as a reference, the second region of the predetermined comparison grid is filled to obtain the second filling result; The first filling result and the second filling result together constitute the filling result; Wherein, the first region refers to the first row and first column of the predetermined comparison grid, and the second region refers to the grid region in the predetermined comparison grid other than the first region.

7. The Internet access monitoring method based on network traffic behavior recognition as described in claim 6, characterized in that, Using the first filling result as a reference, the second region of the predetermined comparison grid is filled to obtain a second filling result, including: Extract any grid from the second region and construct an arbitrary reference grid set for the arbitrary grid; The maximum reference grid value in the arbitrary reference grid set is obtained by filtering. The arbitrary grid is updated and filled by taking the sum of any fill value corresponding to the arbitrary grid and the maximum reference grid value, thus obtaining the second fill result.

8. An internet access monitoring system based on network traffic behavior recognition, characterized in that, The system is used to execute the Internet access monitoring method based on network traffic behavior identification as described in any one of claims 1-7, and the system includes: The historical data acquisition module is used to acquire a historical network traffic database, wherein the historical network traffic database includes information on multiple historical data packets; The behavior pattern acquisition module is used to acquire the preset behavior pattern of the target user, wherein the preset behavior pattern corresponds to the preset traffic characteristics; The filtering module is used to filter the information of the multiple historical data packets based on the preset traffic characteristics as filtering constraints to obtain clean traffic; The first analysis module is used to activate the inner network in the nested pseudo-twin network structure to analyze the pure feature parameter set of the pure flow and obtain the pure feature curve. The second analysis module is used to acquire promiscuous traffic and analyze the promiscuous traffic through the outer network in the nested pseudo-twin network structure to obtain the promiscuous characteristic curve. The internet access monitoring module is used to monitor the internet access of the target user based on the comparison results obtained by comparing the mixed feature curve and the pure feature curve.

Citation Information

Patent Citations

  • Mobile terminal user behavior detection method based on nested deep twin neural network

    CN111159250A