Network traffic analysis method and system based on burst characteristics

Through the network traffic analysis method based on burst characteristics, combined with suspicion score and random forest algorithm, the problem of insufficient accuracy and efficiency of campus network traffic analysis in the existing technology is solved, and accurate identification and real-time monitoring of different types of traffic are realized, which improves network management and security.

CN120474826APending Publication Date: 2025-08-12UNIV OF JINAN
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510923242.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The existing campus network traffic analysis methods are inadequate in classification accuracy and efficiency when dealing with complex and variable network traffic, especially burst traffic, and it is difficult to identify encrypted traffic and obfuscated technologies, resulting in network management and security being affected.

Method used

A network traffic analysis method based on burst characteristics is adopted, combined with suspicion scoring mechanism and random forest algorithm, through real-time collection of network traffic data, five-tuple information and burst behavior characteristics are extracted, a lightweight and efficient pre-traffic filtering module is built, and a machine learning model is used for intelligent identification and classification.

Benefits of technology

It realizes accurate distinction between different types of traffic in the campus network, improves identification accuracy and response efficiency, reduces system load, supports real-time monitoring and abnormal detection, and improves network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474826A_ABST
    Figure CN120474826A_ABST
Patent Text Reader

Abstract

The invention provides a network traffic analysis method and system based on burst characteristics, and relates to the technical field of network space security, and the method comprises the steps: collecting original network traffic data; extracting quintuple information of the original network traffic data, calculating a suspicion degree based on a suspicion degree scoring mechanism, and obtaining screened data streams; extracting the emergency behavior characteristics of the screened data flow, and processing the to-be-tested emergency behavior characteristics by using a trained analysis model to obtain a network flow analysis result; wherein the analysis model is obtained by training a random forest algorithm. According to the method, advanced burst processing, suspicion degree calculation and machine learning prediction technologies are combined, and the traffic types in the campus network are accurately distinguished; the method supports real-time monitoring of an application scene, has an anomaly detection function, and is suitable for a complex and changeable park network environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cyberspace security technology, and in particular to a network traffic analysis method and system based on burst characteristics. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] With the rapid development of internet technology and the increasing demands of campus network users, traffic types within campus networks are becoming increasingly complex. In addition to traditional basic services such as web browsing and email, a growing number of applications, such as video streaming, online gaming, distance education, and large amounts of download and cloud service traffic, have become commonplace on campus networks. These diverse traffic types create enormous data processing demands, making efficient analysis and classification of this traffic, especially bursty traffic on high-speed networks, a core technical challenge for campus network management, optimization, and security.

[0004] Currently, campus network traffic analysis primarily relies on traditional methods such as deep packet inspection (DPI), traffic statistics analysis, and static rule matching. Traditional traffic analysis techniques often extract five-tuple information (source IP, destination IP, port, etc.) from packets and analyze traffic statistics to perform classification. However, with the emergence of new traffic types such as video streaming and online education, these static rules and analysis methods have shown limitations when dealing with the complex and volatile nature of campus network traffic. Existing methods often fall short of classification accuracy and efficiency when dealing with bursty traffic such as live video streaming, remote conferencing, and online gaming. Existing traffic analysis methods are particularly weak in handling encrypted traffic and obfuscation techniques, making some behaviors difficult to effectively monitor and prevent.

[0005] Furthermore, existing traffic analysis methods have significant shortcomings when dealing with traffic bursts in high-speed networks. On campus networks, network traffic often manifests as bursts, especially in applications such as live streaming, video conferencing, and online gaming. This type of traffic is highly time-sensitive and requires instantaneous bandwidth, making it difficult for existing technologies to efficiently identify and process this burst, leading to misjudgments or performance bottlenecks in traffic analysis, thus impacting the network's normal service and quality. Furthermore, traditional traffic monitoring systems, which rely heavily on periodic data collection and subsequent analysis, lack real-time capabilities and are unable to quickly respond to security threats such as network attacks and malware propagation, impacting the security and stability of campus networks. Summary of the Invention

[0006] This invention aims to provide a burst-based network traffic analysis method and system. By combining advanced burst processing, suspicion calculation, and machine learning prediction techniques, this method addresses the challenges of existing technologies and accurately distinguishes normal traffic types within campus networks, including live video traffic, on-demand video traffic, online gaming traffic, online voice traffic, download traffic, and music traffic. This system supports real-time monitoring of application scenarios (such as video, audio, gaming, and downloads) and includes anomaly detection capabilities, making it suitable for complex and changing campus network environments.

[0007] To achieve the above purpose, the invention adopts the following technical solutions: A first aspect of the present invention provides a method for analyzing network traffic based on burst characteristics, comprising the following steps: Collect raw network traffic data; Extracting the five-tuple information of the original network traffic data and obtaining the flow, calculating the suspicion based on the suspicion scoring mechanism, and obtaining the filtered data flow; Extracting the burst behavior characteristics of the filtered data stream, The trained analysis model is used to process the sudden behavior characteristics to be tested to obtain the network traffic analysis results; wherein, the analysis model is trained using the random forest algorithm.

[0008] Furthermore, the original network traffic data includes live traffic, on-demand traffic, download traffic, online game traffic, network voice traffic and VPN traffic within the campus network.

[0009] Furthermore, the five-tuple information of the original network traffic data is extracted and the flow is obtained. The suspicion is calculated based on the suspicion scoring mechanism to obtain the filtered data flow. Specifically: Using quintuple information to obtain flows, a suspicion scoring mechanism is constructed. This mechanism identifies and manages flow status by tracking the quintuple information of each packet in the network flow and assigns an initial suspicion to each flow. Upon receiving a packet, the suspicion of the flow is first exponentially decayed based on the difference between the current time and the last update time to reflect the time decay characteristics of its activity. Subsequently, the activity of the current data packet is determined based on its payload size. If it falls within the preset valid range, the suspicion increases, otherwise it decreases. When the suspicion is higher than the upper threshold, the flow is considered suspicious and its key data is recorded. When the suspicion is lower than the lower threshold, the flow is deleted and removed from tracking. Flows between the two thresholds are retained and observed. In addition, a minimum heap structure is used to maintain the suspicion status of all tracking flows. When the number of tracking flows reaches the upper limit, the flow with the lowest suspicion is automatically eliminated. The activity of the flow is determined by whether the size of the current data packet is within the "reasonable activity range". If the payload is within the set value range, it is considered a "valuable flow" and the suspicion increases. Otherwise, it is considered an inactive packet or an abnormal packet and the suspicion decreases. The suspicion level of each flow is graded. If the suspicion level exceeds the upper limit, it is judged as a suspicious flow, recorded and transferred to in-depth analysis; if the suspicion level is lower than the lower limit, it is judged as a worthless flow and directly cleared; the intermediate state is retained and awaits subsequent update judgment.

[0010] Furthermore, the extracting of the burst behavior features of the traffic training set is specifically as follows: Define the source IP and destination IP of the first packet as the source IP and destination IP of the entire flow. Upstream refers to the flow from the source IP to the destination IP, and downstream refers to the flow from the destination IP to the source IP. Build a burst queue based on the direction and arrival time of each packet. Constructing a burst queue specifically includes: for each data packet, defining its direction, relative arrival time and payload size; Secondly, for adjacent packets with continuous directions and time intervals less than the threshold, they are considered as the same burst and added to the current burst sequence. Otherwise, the burst is ended and its length is recorded. The length of the burst behavior sequence with a negative direction is recorded as a negative value to construct the burst behavior sequence. The burst behavior characteristics are calculated based on the burst queue and burst behavior sequence.

[0011] Furthermore, the burst behavior characteristics include: burst density, uplink and downlink burst ratio, average burst interval time, average uplink burst byte sum, average downlink burst byte sum, large packet number and small packet number.

[0012] Furthermore, the analysis model is constructed based on the burst behavior characteristics, a random forest algorithm is used to model and train multiple types of network flows, and the hyperparameters of the analysis model are automatically optimized through grid search.

[0013] A second aspect of the present invention provides a network traffic analysis system based on burst characteristics, which adopts the steps of the network traffic analysis method based on burst characteristics as described in the first aspect of the present invention, including: The data collection module is configured to: collect raw network traffic data from multiple client devices in real time; Suspicion Scoring Module: This module is configured to perform a preliminary screening of raw network traffic data and calculate a "suspicion value." If the suspicion value exceeds a set threshold, the flow is deemed worthy of further analysis and enters the subsequent feature extraction process. The feature extractor module is configured to: extract burst behavior features from the filtered traffic; The classification and identification module is configured to: perform fusion classification on the sudden behavior features input to be tested, and divide the traffic into multiple fine-grained business types.

[0014] A third aspect of the present invention provides a computer program product, which, when executed by a processor, implements the steps of the network traffic analysis method based on burst characteristics as described in the first aspect of the present invention.

[0015] A fourth aspect of the present invention provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps of a network traffic analysis method based on burst characteristics as described in the first aspect of the present invention.

[0016] The fifth aspect of the present invention provides an electronic device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, the steps of the network traffic analysis method based on burst characteristics as described in the first aspect of the present invention are implemented.

[0017] The technical solution of the present invention has the following beneficial effects: 1. This invention utilizes a traffic screening strategy based on a suspicion scoring mechanism and employs a hash map and minimum heap structure to construct a lightweight and efficient front-end traffic filtering module. By capturing network packets in real time, the system identifies the flow (Flow ID) to which each packet belongs and dynamically updates its suspicion score based on the flow's behavioral characteristics (such as packet size, arrival frequency, and time interval). Suspicion updates follow a dual-threshold rule: when a flow's packet size falls within a set active range, the suspicion increases; otherwise, it decreases. Furthermore, the system incorporates an exponential decay mechanism, which naturally reduces the suspicion of flows that have been inactive for a long time, effectively eliminating outdated flows.

[0018] 2. When a flow's suspicion exceeds the upper threshold, it is identified as suspicious. Key information (such as flow ID, source / destination IP, port, payload, and timestamp) is immediately recorded and passed to the feature extraction stage. If the suspicion falls below the lower threshold, the system automatically removes it. Flows falling between these thresholds are tracked and await the next judgment. This entire module, embedded as a coarse-grained filter at the data access stage, effectively preemptively eliminates a significant amount of irrelevant or low-value traffic, significantly reducing system load, reducing the amount of data required for subsequent processing, and improving overall processing efficiency and response speed.

[0019] 3. A traffic analysis method based on burst patterns, combined with a machine learning model, intelligently identifies network flows. After receiving traffic data, the system first reconstructs the time sequence of the packets in each flow and extracts key features. These features reflect the flow's behavioral patterns and can effectively distinguish different types of network applications, such as live streaming, video, downloads, games, voice, and VPNs. These features are then fed into a pre-trained random forest model for classification. The model's output of the flow type serves as the flow's identification label and is fed back to the client or subsequent processing modules. This mechanism, as the system's refined classification component, complements the pre-implemented suspicion screening mechanism. It also incorporates a domain name keyword matching mechanism, identifying characteristic words in the domain names associated with the flow and assisting in determining the traffic type through a bitrate analysis module. This further improves the accuracy of identifying complex network traffic and the system's response efficiency.

[0020] Advantages of additional aspects of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0022] Figure 1 This is a flow chart of a network traffic analysis method based on burst characteristics in the first embodiment of the present invention.

[0023] Figure 2 This is an architecture diagram of a network traffic analysis system based on burst characteristics in the second embodiment.

[0024] Figure 3 FIG. 4 is a flow chart of the burst identification strategy in the first embodiment.

[0025] Figure 4 This is a flow chart of the suspicion scoring mechanism in the first embodiment.

[0026] Figure 5 This is a flow chart of a network traffic analysis system based on burst characteristics in the second embodiment. DETAILED DESCRIPTION

[0027] It should be noted that the following detailed descriptions are exemplary and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.

[0028] It should be noted that the terms used herein are for describing particular embodiments only and are not intended to limit the exemplary embodiments according to the present invention.

[0029] In the absence of conflict, the embodiments of the present invention and the features thereof may be combined with each other.

[0030] Example 1 This embodiment provides a network traffic analysis method based on burst characteristics, such as Figure 1 As shown, the following steps are taken: Step 1: Collect raw network traffic data. Raw network traffic data includes live streaming traffic, on-demand traffic, download traffic, online game traffic, online voice traffic, and VPN traffic within the campus network.

[0031] When collecting raw network traffic data, we capture the network traffic of a specific process, filter out the TCP / UDP network packets used by that process, and save them as .pcap files for subsequent traffic analysis. We also capture UDP or TCP packets with port 53 (DNS requests and responses), extract domain names from DNS packets, and construct an IP⇄domain name mapping table to subsequently match the IP addresses in the five-tuple to the domain names they access.

[0032] This system is deployed on a host running the Windows operating system and leverages the NPcap network driver to implement low-level access control for the host network interface card (NIC). It supports the unified collection of local application processes and encrypted VPN traffic. The host NIC can be configured in local (loopback) mode or with a specific physical or virtual interface to fully capture all network traffic.

[0033] By leveraging the Scapy network sniffing library and the psutil process management library, we dynamically extract the local port used by a specific application process (such as DeltaForceClient-Win64-Shipping.exe) for its network connection. We then use scapy.sniff() to perform real-time packet capture on the target network interface (such as WLAN, Ethernet, or VPN virtual adapter). By setting a callback function, the system retains only TCP and UDP packets that match the target process port, accurately capturing the process's actual communication behavior.

[0034] Furthermore, to handle encrypted traffic transmitted through VPN tunnels, the system integrates support for VPN virtual network cards, automatically identifying client processes (such as openvpn.exe and wireguard.exe) for OpenVPN, WireGuard, or the Windows built-in VPN, and their associated virtual network interfaces (such as TAP, TUN, and Tunnel Adapter). Upon detecting VPN communication activity, the system switches to the corresponding virtual interface for packet capture, capturing encrypted traffic data at the VPN egress, ensuring complete collection during the local encapsulation phase.

[0035] The entire data collection process runs according to a set cycle, with each round lasting 60 seconds or capturing up to 5 million packets. The collected traffic data is saved as .pcap files with randomly generated UUID names and automatically archived in a designated directory. The system supports integration with the WinPcap Remote Capture service, which transmits traffic data to remote analysis terminals in real time, decoupling collection and analysis, effectively improving system processing efficiency and scalability.

[0036] Step 2: Extract the five-tuple information of the original network traffic data and obtain the flow, calculate the suspicion based on the suspicion scoring mechanism, and obtain the filtered data flow.

[0037] Extract the quintuple information, domain name information, and statistical feature information of the original network traffic data, including the load size and arrival time; obtain the flow based on the quintuple information; perform coarse-grained identification of the flow based on the duration and flow rate of the process and flow, and obtain normal flow and VPN flow training sets; specifically: according to Figure 4 As shown in the figure, we use quintuple information to acquire flows and construct a suspicion scoring mechanism. This mechanism identifies and manages flow status by tracking the quintuple information (source IP, source port, destination IP, destination port, and protocol type) of each packet in a network flow and assigns an initial suspicion to each flow. Upon receiving a packet, the suspicion of the flow is first exponentially decayed based on the difference between the current time and the last update time, reflecting the time-degradation characteristics of its activity.

[0038] (1) Among them, represents the suspicion degree at the current time t The suspicion level after the last update The result after "time decay". : Current time (seconds). τ: The time constant of the exponential decay, which controls the "memory duration".

[0039] The system then determines the activity of the current packet based on its payload size. If it falls within a preset valid range, the suspicion increases; otherwise, it decreases. When the suspicion exceeds the upper threshold, the system deems the flow suspicious and records its key data. When the suspicion falls below the lower threshold, the flow is deleted and removed from tracking. Flows between these thresholds are retained for continued observation.

[0040] Furthermore, the system uses a minimum heap structure to maintain the suspicion level of all traced flows. When the number of traces reaches the upper limit, the lowest-suspicion flows are automatically eliminated, enabling efficient resource management and traffic pre-screening. This mechanism enables lightweight, intelligent screening of large numbers of real-time network flows, providing high-value data streams for subsequent in-depth analysis.

[0041] (2) The activity of a flow is determined by whether the current packet size falls within a "reasonable activity range." If the payload falls within the set range (e.g., 20-5000 bytes), it indicates a "valuable flow" and its suspicion increases. Otherwise, it is considered an inactive packet or an abnormal packet (such as an ACK, a small packet, or an extremely large packet), and its suspicion decreases. The system classifies each flow's suspicion: If the suspicion exceeds an upper limit (e.g., ≥75), the flow is considered suspicious, recorded, and transferred to in-depth analysis. If the suspicion falls below a lower limit (e.g., ≤72), the flow is considered worthless and immediately cleared. Intermediate states are retained pending subsequent updates.

[0042] Step 3: Extract the burst behavior characteristics of the filtered data stream.

[0043] Specifically, the source IP and destination IP of the first packet are defined as the source IP and destination IP of the entire flow. Uplink represents the flow from the source IP to the destination IP, and downlink represents the flow from the destination IP to the source IP. The system constructs a burst queue (burstBuf) based on the direction (uplink / downlink) and arrival time of each packet. Based on the relationship between burst continuity and time interval, the following statistical behavior characteristics are extracted: First, construct a burst queue. For each data packet , defining its direction , relative arrival time , and load size : (3) in =+1, is the source IP; =-1, is the target IP; The time (in seconds) between the current packet and the first packet; The byte length of the current packet (including header and payload).

[0044] Secondly, if Figure 3 As shown in the figure, regarding the burst identification strategy: adjacent packets with continuous directions and a time interval less than a threshold (1ms) are considered to be the same burst. They are added to the current burst sequence (take++). Otherwise, the burst is ended and its length is recorded. The burst length of the negative direction is recorded as a negative value. The burst sequence is constructed: (4) Where burst is a burst behavior sequence, which consists of a series of signed burst lengths; is the direction of the jth burst in the burst sequence (+1 for uplink, -1 for downlink); is the number of consecutive packets in the jth burst; is the sign function that determines the direction of the burst.

[0045] Based on burstBuf and burst, the burst behavior characteristics are calculated and the following key features are extracted, as shown in Table 1: (1) Burst density (xdtf): This represents the ratio of the number of bursts to the total number of packets, and measures the degree of "clustering" of data packets in a flow. If there are frequent and continuous small time intervals (e.g., <1ms) between packets, multiple bursts will be formed, and xdtf will approach 1. If the traffic is sparse or randomly distributed, xdtf will approach 0. The formula is as follows: (5) (2) Uplink and downlink burst ratio (bbl): This feature measures the ratio of downlink bursts to uplink bursts and is used to determine the interactive direction characteristics of traffic. is the number of bursts in the downlink direction; is the number of bursts in the upstream direction, and the formula is as follows: (6) (3) Average burst interval (pjsjjg): The average time interval between bursts, reflecting the time distribution density of the burst, identifying the continuity and active rhythm of the flow, and the formula is as follows: (7) in, is the total time difference between adjacent bursts; |burst| is the number of bursts.

[0046] (4) Average uplink burst byte total (pjzxtfdx): The average number of bytes transmitted in each uplink burst, indicating the average data load of the uplink burst. It is used to determine whether the uplink burst is a lightweight control packet or a heavy load. The formula is as follows: (8) in, The total number of bytes in the upstream burst. The upstream burst number.

[0047] (5) Average total downlink burst bytes (pjfxtfdx): The average number of bytes transmitted in each downlink burst, indicating the average data load of the downlink burst, indicating the average amount of data transmitted in each downlink burst, and determining whether the burst sent by the server is a large-volume content. The formula is as follows: (9) in The total number of bytes in the upstream burst. The upstream burst number.

[0048] (6) Number of large packets: Counts the number of packets with a length greater than or equal to 100 bytes. This measures whether there is a large amount of substantial data transmission in the flow. The formula is as follows: (10) (7) Number of small packets: This refers to the number of data packets with a length of less than 100 bytes, reflecting the density of control or interactive data (such as ACK, signaling). The formula is as follows: (11) Table 1 is a comparison table of feature names and their corresponding meanings.

[0049] Table 1

[0050] Step 4: Build an analysis model and train it using the random forest algorithm.

[0051] This phase aims to build a machine learning model for multi-class flow identification using the burst behavior features extracted in the previous phase (e.g., xdtf, bbl, pjsjjg, pjzxtfdx, and pjfxtfdx). A random forest algorithm is used to model and train multi-class network flows, and grid search is used to automatically optimize model hyperparameters.

[0052] The specific process is as follows: Step 4.1: Read all extracted burst behavior features and their corresponding label types as a structured dataset.

[0053] Step 4.2: The dataset is divided into the following parts: training set: validation set: test set = 6:2:2. The input matrix is constructed using the following feature vectors: (12) Step 4.3: Optimize the hyperparameters of the random forest model using grid search (GridSearchCV). The search space includes the maximum depth of the tree (max_depth) and the number of trees in the forest (n_estimators). Combined with 3-fold cross validation, the best model structure is selected: (13) Step 4.4: Evaluate the final model on the test set, calculate the accuracy, precision, recall, and F1 score, and output the confusion matrix.

[0054] Step 4.5: After model training is complete, extract the contribution weight of each feature (Feature Importance), rank them, and visualize them. This is often used to explain the model's decision-making behavior. Finally, use joblib to serialize the trained model into a .pkl file for subsequent online deployment or offline inference. The model trained in this stage demonstrates good performance on the test set, validating the effectiveness of the burst feature-based network flow classification method. It boasts high accuracy, strong generalization, and fast response, providing a stable and reliable core classification module for subsequent flow recognition systems.

[0055] Step 5: Input the burst behavior characteristics to be tested into the trained analysis model and output the network traffic analysis results.

[0056] The trained random forest classification model is used for preliminary judgment, and the traffic volume is predicted hierarchically using "model judgment as the main method and rule correction as the auxiliary method", and the solid line achieves high-precision prediction.

[0057] After analyzing the model classification, accuracy correction is performed through the following two rounds of normalization post-processing mechanism: Using the suspicion scoring mechanism, if the model predicts 1 (not live), but the suspicion value of the stream is higher than the set threshold (≥125), the system infers that the stream has strong live broadcast characteristics and corrects it to 0 (live broadcast).

[0058] If the model output is 2, the domain name keyword matching mechanism is used to call check_keywords_in_string_and_update() to match the feature words of the associated domain name (ip_to_name) of the stream. If keywords such as "bili", "live", and "douyin" are detected, it is classified as 0 (live broadcast); if the keyword "download" is included, it is classified as 2 (download).

[0059] If the keyword isn't matched, the system uses a bitrate determination mechanism to further calculate the average downlink bitrate (in Mbps). If this value falls within the typical live broadcast range of [0.705515, 20.610207], it can be corrected to 0 (for live broadcast). Once the above determination process is complete, the domain name database is updated, and the system uses the final identified stream type as the stream label.

[0060] Example 2 This embodiment discloses a network traffic analysis system based on burst characteristics, such as Figure 2 and Figure 5 Shown, including: Data Collection Module: This module collects raw network traffic data from multiple client devices in real time. Using a traffic capture system deployed at the network egress, it collects passing TCP / UDP packets and saves them as .pcap files. This module supports filtering network data for specific processes or ports, ensuring accurate and targeted analysis.

[0061] The Suspicion Scoring module performs a preliminary screening of raw network traffic data after collection, calculating a "suspicion score" based on flow duration, downlink rate, and activity. If the suspicion score exceeds a set threshold (such as for specific behavior patterns used for live streaming, downloading, and VPN identification), the flow is deemed worthy of further analysis and enters the subsequent feature extraction process.

[0062] The feature extractor module extracts burst behavior features from filtered traffic. These include statistical metrics such as burst density, uplink / downlink burst ratio, burst interval, and average uplink / downlink burst size. During the extraction process, the flow is split into continuous bursts (bursts), and burst vector features are constructed based on dimensions such as direction, interval, and size, forming a structured data representation.

[0063] The classification and recognition module consists of multiple sub-recognition engines and performs integrated classification on the input feature data. It includes a random forest model, a domain name matching module, a suspicion module, and a rate module. Specifically: Random Forest Model: Classifies burst features based on a trained supervised learning model and preliminarily determines traffic types (such as live streaming, downloading, and social networking). Domain name matching module: parses DNS request response packets, obtains domain name information, and matches it with predefined keywords (such as live, video, download, etc.) to assist in identifying the classification of streams; Suspicion module: Combines the pre-set suspicion value with the model output to perform joint corrections, improving the robustness and fault tolerance of judgments; Rate module: Calculates the average downlink bit rate of the stream. If it is within the typical service range (e.g., 0.7–20 Mbps is a common rate for live streaming), it is used as a key feature to optimize and correct the initial judgment result.

[0064] Based on the comprehensive judgment results output by the multi-module classification model module, the traffic is divided into multiple fine-grained business types: real-time voice (voice icon), live video (LIVE icon), video on demand (TV icon), download transmission (download icon), online games (game icon), and VPN traffic (general icon).

[0065] Example 3 The purpose of this embodiment is to provide a computer program product. When executed by a processor, the computer program product implements the steps in the network traffic analysis method and system based on burst characteristics as described in the first embodiment of the present disclosure.

[0066] Example 4 The purpose of this embodiment is to provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the network traffic analysis method and system based on burst characteristics as described in the first embodiment of the present disclosure.

[0067] Example 5 The purpose of this embodiment is to provide an electronic device. The electronic device includes a memory, a processor, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the network traffic analysis method and system based on burst characteristics as described in the first embodiment of the present disclosure are implemented.

[0068] The electronic device can be a mobile terminal or a non-mobile terminal. The non-mobile terminal includes a desktop computer, and the mobile terminal includes a smart phone (such as an Android phone, an IOS phone, etc.), smart glasses, a smart watch, a smart bracelet, a tablet computer, a laptop computer, a personal digital assistant, and other mobile Internet devices that can communicate wirelessly.

[0069] It should be understood that in the present application, the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), off-the-shelf field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0070] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.

[0071] During implementation, each step of the above method can be performed by hardware integrated logic circuits in a processor or by software instructions. The steps of the method disclosed in this application can be directly implemented by a hardware processor or by a combination of hardware and software modules in the processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located in a memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, a detailed description is not given here. Those skilled in the art will appreciate that the units, i.e., algorithmic steps, described in each example in conjunction with the embodiments disclosed herein can be implemented using electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0072] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0073] The steps involved in the apparatuses of Examples 2, 3, 4, and 5 above correspond to those of Method Example 1. For detailed implementations, please refer to the relevant description of Example 1. The term "computer-readable storage medium" should be understood to mean a single medium or multiple media containing one or more instruction sets; it should also be understood to include any medium capable of storing, encoding, or carrying an instruction set for execution by a processor and causing the processor to perform any method of the present invention.

[0074] Those skilled in the art will appreciate that the modules or steps of the present invention described above can be implemented using a general-purpose computer device. Alternatively, they can be implemented using program code executable by a computing device, which can then be stored in a storage device and executed by the computing device. Alternatively, they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.

[0075] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.

Claims

1. A network traffic analysis method based on burst characteristics, characterized in that: The steps include: Collect raw network traffic data; Extracting the five-tuple information of the original network traffic data and obtaining the flow, calculating the suspicion based on the suspicion scoring mechanism, and obtaining the filtered data flow; Extracting the burst behavior characteristics of the filtered data stream, The trained analysis model is used to process the sudden behavior characteristics to be tested to obtain the network traffic analysis results; wherein, the analysis model is trained using the random forest algorithm.

2. A network traffic analysis method based on burst characteristics according to claim 1, characterized in that: The original network traffic data includes live broadcast traffic, on-demand traffic, download traffic, online game traffic, network voice traffic and VPN traffic within the campus network.

3. The network traffic analysis method based on burst characteristics according to claim 1, characterized in that: The five-tuple information of the original network traffic data is extracted, and suspicion is calculated to obtain the filtered data flow; specifically: Utilize quintuple information to obtain traffic and build a traffic identification and screening mechanism based on suspicion; This mechanism identifies and manages the state of a network flow by tracking the five-tuple information of each data packet and assigning an initial suspicion to each flow. After receiving a data packet, the suspicion of the flow is first exponentially decayed based on the difference between the current time and the last update time to reflect the time decay characteristics of its activity. Subsequently, the activity of the current data packet is determined based on its payload size. If it falls within the preset valid range, the suspicion increases, otherwise it decreases. When the suspicion is higher than the upper threshold, the flow is considered suspicious and its key data is recorded. When the suspicion is lower than the lower threshold, the flow is deleted and removed from tracking. Flows between the two thresholds are retained and observed. In addition, a minimum heap structure is used to maintain the suspicion status of all tracking flows. When the number of tracking flows reaches the upper limit, the flow with the lowest suspicion is automatically eliminated. The activity of a flow is determined by whether the size of the current data packet is within the "reasonable activity range." If the payload is within the set value range, it is considered a "valuable flow" and its suspicion increases. Otherwise, it is considered an inactive or abnormal packet and its suspicion decreases. The suspicion level of each flow is graded. If the suspicion level exceeds the upper limit, it is considered a suspicious flow, recorded, and transferred to in-depth analysis. If the suspicion is lower than the lower limit, it is judged as a worthless flow and is directly cleared; the intermediate state is retained and waits for subsequent update judgment.

4. A method for analyzing network traffic based on burst characteristics according to claim 1, characterized in that: The extracting of the burst behavior features of the traffic training set is specifically as follows: Define the source IP and destination IP of the first packet as the source IP and destination IP of the entire flow. Upstream refers to the flow from the source IP to the destination IP, and downstream refers to the flow from the destination IP to the source IP. Build a burst queue based on the direction and arrival time of each packet. Constructing a burst queue specifically includes: for each data packet, defining its direction, relative arrival time and payload size; Secondly, for adjacent packets with continuous directions and time intervals less than the threshold, they are considered as the same burst and added to the current burst sequence. Otherwise, the burst is ended and its length is recorded. The length of the burst behavior sequence with a negative direction is recorded as a negative value to construct the burst behavior sequence. The burst behavior characteristics are calculated based on the burst queue and burst behavior sequence.

5. The method for analyzing network traffic based on burst characteristics according to claim 1, wherein: The burst behavior characteristics include: burst density, uplink and downlink burst ratio, average burst interval time, average uplink burst byte sum, average downlink burst byte sum, large packet number and small packet number.

6. The method for analyzing network traffic based on burst characteristics according to claim 1, wherein: The analysis model is constructed based on the sudden behavior characteristics, a random forest algorithm is used to model and train multiple types of network flows, and the hyperparameters of the analysis model are automatically optimized through grid search.

7. A network traffic analysis system based on burst characteristics, based on the network traffic analysis method based on burst characteristics according to any one of claims 1 to 6, characterized in that: include: The data collection module is configured to: collect raw network traffic data from multiple client devices in real time; The suspicion scoring module is configured to perform a preliminary screening of raw network traffic data and calculate a "suspicion value." If the suspicion value exceeds a set threshold, the flow is deemed worthy of further analysis and enters the subsequent feature extraction process. The feature extractor module is configured to: extract burst behavior features from the filtered traffic; The classification and identification module is configured to: perform fusion classification on the sudden behavior features input to be tested, and divide the traffic into multiple fine-grained business types.

8. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the network traffic analysis method based on burst characteristics according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a program stored thereon, characterized in that: When the program is executed by a processor, the steps of the network traffic analysis method based on burst characteristics as described in any one of claims 1 to 6 are implemented.

10. An electronic device comprising a memory, a processor, and a program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the network traffic analysis method based on burst characteristics as described in any one of claims 1 to 6 are implemented.