Network flow association method and system based on tetrad metric learning

Through a method based on quadruple metric learning, a data set containing perturbation traffic is constructed and a dual-channel feature embedding network and a multi-window voting mechanism is combined, which solves the problems of disturbance and low computing efficiency in the prior art, and realizes high-precision network flow association.

CN120498805APending Publication Date: 2025-08-15SOUTH CHINA UNIV OF TECH
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510693637.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing network flow association technology has contradictions between disturbance, computing efficiency and concealment. It has weak disturbance resistance, low computing efficiency, unsolid dynamic threshold selection, and relying on traffic feature modification to insufficient concealment.

Method used

Using a quadruple metric learning method, by constructing a quadruple dataset containing original samples, positive samples, negative samples and perturbation samples, using an adversarial generation network to inject perturbation traffic that complies with the statistical constraints of the protocol, combining the dual-channel feature embedding network and a multi-window voting mechanism, the threshold is dynamically adjusted to improve the anti-noise interference capability and correlation discrimination of the model.

Benefits of technology

It significantly improves the anti-perturbation ability of network flow association, reduces the missed response rate of long sessions, improves computing efficiency and concealment, and realizes high-precision network flow association.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498805A_ABST
    Figure CN120498805A_ABST
Patent Text Reader

Abstract

The invention discloses a network flow association method and system based on tetrad metric learning, and the method comprises the following steps: constructing a tetrad data set containing an adversarial disturbance sample through extracting the packet interval and packet size characteristics of network flow; a double-branch feature embedded network is combined with a channel attention and space attention module, so that the dynamic sensing ability of key features is enhanced; introducing a tetrad loss function to optimize a feature embedding space, and compulsorily confronting a rejection relationship between a disturbance sample and a negative sample; based on a dynamic mixed quantile method, a correlation threshold is adaptively selected, and the robustness is improved in combination with a multi-window voting mechanism. According to the method, the association discrimination of the network flow is realized by adopting a tetrad metric learning method, the anti-disturbance capability and the calculation efficiency are remarkably improved, the distribution characteristics of the original flow are not changed, and the method is suitable for a large-scale real-time anonymous network flow association scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security and anonymous communication analysis, and in particular to a network flow association method and system based on quadruple metric learning. Background Art

[0002] Existing flow correlation techniques for anonymous networks have significant limitations. Traditional statistical methods (such as analysis based on packet interval features) are sensitive to network jitter, with accuracy below 60% when latency fluctuations exceed 50ms. While deep learning models based on CNN / LSTM (such as fingerprinting) have improved accuracy to over 90%, the feature extraction network lacks selective attention to key spatiotemporal dimensions, leading to significant noise interference issues. Furthermore, the triplet loss function is insufficiently constrained in the adversarial embedding space, resulting in false positive rates exceeding 35% when subjected to blind adversarial attacks. Furthermore, mainstream anti-disturbance solutions have inherent flaws. Adversarial training methods based on PGD are computationally extremely complex (increasing inference latency by a factor of 10), while dynamic traffic shaping techniques can disrupt the original traffic distribution and introduce risks in detecting protocol anomalies. Existing attention mechanisms (such as the CBAM module) are not deeply integrated with metric learning frameworks, failing to synergistically optimize feature discriminability and anti-disturbance capabilities. Furthermore, fixed threshold solutions experience a surge in false positives in non-steady-state traffic, while dynamic quantile methods fail to address multi-scale spatiotemporal correlation, resulting in long-session underreporting rates exceeding 15%. Existing technologies face an irreconcilable contradiction between anti-disturbance, computational efficiency, and stealth (Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations MiladNasr, Alireza Bahramali, and Amir Houmansadr, University of Massachusetts Amherst). There is an urgent need for an innovative solution that can achieve a synergistic improvement in high accuracy, low overhead, and strong robustness. Summary of the Invention

[0003] In view of this, an embodiment of the present invention provides a network flow association method and system based on quadruple metric learning, which can solve the problems existing in existing network flow association technologies, such as weak anti-disturbance ability, low computational efficiency, non-robust dynamic threshold selection, and insufficient concealment due to reliance on traffic feature modification.

[0004] The present invention is achieved through at least one of the following technical solutions.

[0005] A network flow association method based on quadruple metric learning includes the following steps:

[0006] The traffic data is divided into multiple time windows, and the spatiotemporal traffic characteristics of the inlet and outlet traffic are extracted for each independent time window through the trained four-tuple metric learning model.

[0007] Each window independently calculates cosine similarity using spatiotemporal traffic characteristics and compares the cosine similarity with the dynamic mixing quantile threshold. If the cosine similarity is greater than or equal to the threshold, the network ingress and egress flows are considered associated. Otherwise, according to the multi-window voting mechanism, if the total number of votes is greater than the set voting threshold, the pair of network flows is ultimately determined to be associated.

[0008] Furthermore, the dual-channel feature embedding network adopts a symmetric dual-branch deep neural network architecture, including an inlet flow feature embedding network and an outlet flow feature embedding network, wherein the inlet flow feature embedding network is used to extract input flow features, and the outlet flow feature embedding network is used to extract output flow features. Each inlet flow feature embedding network and outlet flow feature embedding network includes multi-level convolutional layers, and an attention mechanism module is cascaded after the last convolution layer to extract disturbance-resistant spatiotemporal flow features.

[0009] Furthermore, the attention mechanism module includes a channel attention module and a spatial attention module;

[0010] The channel attention module generates a channel weight vector through two fully connected layers, normalizes it with the Sigmoid function, and then performs channel weighting with the original feature map to achieve global average pooling and compress the channel dimension of the feature map;

[0011] The spatial attention module generates a spatial weight matrix after dimensionality reduction through a 7×1 convolution kernel, calibrates the features of the time-sensitive area through the Sigmoid function, and realizes the feature splicing of maximum pooling and average pooling in the channel dimension.

[0012] Furthermore, the training of the quadruple metric learning model includes the following steps:

[0013] Construct a four-tuple dataset containing original samples, positive samples, negative samples, and perturbation samples, and divide the data into training sets and test sets;

[0014] The training set is used to train the four-tuple metric learning model. During the training process of the four-tuple metric learning model, a dynamic semi-hard sample mining mechanism is adopted. In each batch of training, the semi-hard samples in the positive samples of the batch are selected as the negative samples corresponding to the anchor samples. The semi-hard sample screening process is as follows:

[0015] Calculate the cosine similarity matrix of the feature vectors of the inlet flow sample and all the outlet flow samples in the batch, and filter out the negative samples that meet the following formula in this matrix:

[0016]

[0017] in Control sample difficulty, S(a,n) is the similarity between the anchor sample and the negative sample, S(a,p) is the similarity between the anchor and the positive sample, a, p, n represent the anchor sample, positive sample and negative sample respectively.

[0018] Furthermore, the loss function of the quadruple metric learning model is as follows:

[0019] L q =max(d ap -d an1 +α,0)+max(d an2 -d n1n2 +β,0)

[0020] Among them, d ap is the feature space distance between the anchor point and the positive sample, d an1 is the distance between the anchor point and the negative sample, d an2 is the distance between the positive sample and the perturbation sample, d n1n2 is the distance between the negative sample and the perturbation sample, α and β are both boundary thresholds, L q is the loss function of the model.

[0021] Furthermore, the cosine similarity is calculated as:

[0022]

[0023] Among them, corr(v,u) represents the cosine similarity between vectors v and u, n represents the dimension of this vector, v i and u i Represent the i-th vector in the input stream and output stream vector groups respectively.

[0024] Furthermore, the dynamic mixing quantile threshold θ final Calculated by the following formula:

[0025] θ final =0.5θ global +0.3θ dynamic +0.2θ local

[0026] where θ global =Q3+1.5IQR, Q3 is the 3 / 4 quantile of the similarity sequence, IQR is the difference between the 3 / 4 quantile and the 1 / 4 quantile; θ local is the 9 / 10 quantile of the sliding window of the last k values; θ dynamic The formula for calculating the exponentially weighted moving quantile is as follows:

[0027] θ dynamic =θ t =(1-β)·θt-1 +γ·quantile(W t ,0.95)

[0028] Among them, W t is a sliding window that selects the most recent k values, γ is the decay factor, and θ t is the exponentially weighted moving quantile of the current sliding window, quantile(.) is the function of taking the sequence quantile, and β is the weighting coefficient.

[0029] Furthermore, the multi-window voting mechanism uses a sliding window protocol to perform multi-scale time series segmentation on the original traffic data stream. The cosine similarity of each window is compared with the dynamic hybrid quantile threshold. If the window is associated, it is counted as one vote, otherwise it is counted as 0. If the total voting score is greater than or equal to the voting threshold, the data stream is finally judged to be associated.

[0030] A system for implementing the network flow association method based on quadruple metric learning includes:

[0031] The feature extraction module is used to extract and weight the spatiotemporal features of network flows, suppress noise interference through channel and spatial attention mechanisms, and generate highly discriminative traffic feature vectors;

[0032] The perturbation generation and injection module is used to generate adversarial perturbation samples that conform to the statistical characteristics of network jitter. These samples are injected into the network traffic training set by perturbing timing delay and packet size, improving the model's defense against blind adversarial attacks.

[0033] The metric learning optimization module is used to optimize the feature embedding space by using the four-tuple sample distance constraint, and to improve the model's intra-class aggregation and inter-class discrimination by combining the original and perturbed samples.

[0034] The threshold determination module is used to integrate the global baseline, dynamic quantile and local window threshold, and adaptively determine the network flow correlation through a multi-level threshold voting mechanism.

[0035] A computer device of the present invention includes: a memory, a processor, and a computer program stored in the memory. When the computer program is executed on the processor, the method described above is implemented.

[0036] Compared with the existing technology, the beneficial effects of the present invention are:

[0037] In response to the key issues existing in the existing anonymous network traffic correlation technology, such as sensitivity to adversarial disturbances, insufficient feature discrimination, and poor robustness of dynamic thresholds, the present invention has achieved a technological breakthrough through multi-dimensional innovation. The present invention first constructs a four-tuple data set containing original samples, positive samples, negative samples, and adversarial perturbation samples, and uses an adversarial generative network to inject perturbed traffic that meets the statistical constraints of the protocol, effectively simulating real network attack scenarios and providing comprehensive adversarial sample support for model training. Through the dual-channel feature embedding network, the channel attention and spatial attention collaborative mechanism are integrated in the dilated convolution module, so that the model dynamically focuses on the key spatiotemporal features of the traffic, significantly improving the filtering ability of noise interference.

[0038] The four-tuple loss function of this invention, based on the traditional triple constraint, enforces an exclusionary relationship between adversarial perturbation samples and negative samples, forming a more robust feature space topology. The dynamic hybrid quantile threshold selection strategy overcomes the failure of traditional fixed thresholds in non-steady-state traffic by integrating a global baseline, exponentially weighted quantiles, and local window statistics. Combined with a multi-window voting mechanism, it enables joint determination of relevance across time scales, significantly reducing the underreporting rate of long sessions. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0040] Figure 1 A flow chart of the network flow correlation method disclosed in an embodiment of the present invention;

[0041] Figure 2 A diagram of a network flow association model disclosed in an embodiment of the present invention;

[0042] Figure 3 This is a diagram of the feature embedding network architecture disclosed in an embodiment of the present invention;

[0043] Figure 4 Schematic diagram of the loss function disclosed in an embodiment of the present invention;

[0044] Figure 5 A schematic diagram of the structure of a network flow correlation system disclosed in an embodiment of the present invention;

[0045] Figure 6 This is a schematic diagram of the structure of the network flow association device disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0047] An embodiment of the present application provides a network flow association method based on quadruple metric learning. The method can be applied to various computer terminals or smart terminals, and its execution subject can be a processor or server of the computer terminal or smart terminal.

[0048] like Figure 1 The network flow association method based on quadruple metric learning shown in FIG. 1 includes the following steps:

[0049] Step S1: Synchronously capture bidirectional traffic data from the entry and exit nodes of the Tor network. This is used to intercept traffic segments from both network nodes and determine whether they are the same network flow. Perturbed traffic is generated using blind adversarial perturbation techniques, and a four-tuple dataset consisting of original samples, positive samples, negative samples, and perturbed samples is constructed.

[0050] Specifically, by re-parsing the raw DeepCorr data (preserving the inbound / outbound packet separation feature), we selected 12,503 unique destination flow pairs as the base set. Furthermore, we deployed a Tor client and a SOCKS proxy server on a physical machine, capturing a full 60-second traffic session at the Ethernet layer, and constructed a DCF dataset containing 60,084 raw flow pairs.

[0051] Among the 60,084 pairs of original flows, pairs with more than 15 packets per window were selected, resulting in a total of 35,433 pairs of network flows. Adversarial perturbations were added to the egress flows of each pair of flows in turn to obtain a set of pseudo-negative samples (perturbed samples).

[0052] The pseudo-negative sample set is obtained by generating blind adversarial perturbations and injecting positive samples. The adversarial perturbations include: perturbing the time and size of data packets, and inserting virtual network data packets.

[0053] Use the remapping function M T To control the amount of added timing delay, as follows:

[0054]

[0055] in, is the average value of the disturbance G(z), μ and σ are the maximum allowable average value and standard deviation of the delay, M is the sequence after the disturbance is added, x is the original input, that is, the timing delay sequence to which the disturbance needs to be added, and std(.) is the standard deviation function.

[0056] The added packet size is a blind adversarial perturbation G(z), which is a generator trained to simulate natural network jitter and make the perturbed data conform to the expected packet size distribution of the underlying network protocol.

[0057] The process for inserting virtual network packets involves constructing a generator G(z) and a discriminator D(x), taking as input the noise z (32-dimensional Gaussian noise), and outputting a joint feature vector of the packet size sequence (packet size) and the inter-interval time series (IPD). Insertion points are then randomly selected using a Poisson process. The generator network is a four-layer fully connected network with a Reluctant Luminance (ReLU) activation function. The final layer uses Tanh to constrain the output range. The discriminator network is a four-layer fully connected network, with the final layer outputting probability values.

[0058] The four-tuple dataset is constructed using the following rules to generate four-tuple sample units (a, p, n1, n2), where a is the anchor sample (input stream); p is the positive sample associated with a (output stream); n1 is a common negative sample (non-associated output stream); and n2 is a pseudo-negative sample generated by adding a blind adversarial perturbation to p. 80% of this data is used for the training set, and the remaining 20% is used for the test set, with no reuse between the two sets.

[0059] S2. Combining channel attention and spatial attention to construct a four-tuple metric learning model, which includes a dual-channel feature embedding network.

[0060] Specifically, the feature embedding network adopts a symmetrical dual-branch deep neural network architecture, including an inlet flow feature embedding network (denoted as A network) and an outlet flow feature embedding network (denoted as P / N network). Figure 3As shown in the figure, each network adopts a progressive structure of multi-stage double convolution layers. The input data first passes through the first double convolution layer (number of filters 32, 7×7 convolution kernel / step size 1, activation function ELU), followed by a maximum pooling layer (MaxPooling, 4×4 kernel / step size 2), Dropout (dropout rate 0.1) and CBAM (Convolutional Block Attention Module, channel compression ratio 16) in sequence; the second double convolution layer increases the number of filters to 64, uses a 5×5 convolution kernel and maintains the ELU activation function, and the subsequent processing flow is consistent with the first layer; the subsequent two groups of 128-filter double convolution layers use the RELU activation function instead, both are configured with 3×3 convolution kernels, and repeat the pooling, Dropout and CBAM operations; finally, after dimensionality reduction by the global pooling layer (Global Pooling, adaptive maximum pooling), the feature vector is generated by the fully connected layer (Fully Connected Layer) with an output dimension of 64.

[0061] Each dilated convolution module, i.e., the convolution layer plus the connection between the convolution layers, is composed of a dilated convolution layer, an ELU activation layer, a maximum pooling layer, and an attention unit connected in sequence. The dilated convolution kernel size is set to 3×1, and the dilation coefficient is dynamically adjusted to 2. (n-1) (n is the module level number);

[0062] The channel attention module generates a channel weight vector through two fully connected layers, normalizes it with the Sigmoid function, and then performs channel weighting with the original feature map to achieve global average pooling and compress the channel dimension of the feature map:

[0063] s c =σ(W2·δ(W1·GAP(X)))

[0064] The spatial attention module generates a spatial weight matrix after dimensionality reduction using a 7×1 convolution kernel. It calibrates the features of the time-sensitive area using the Sigmoid function and implements feature concatenation of maximum pooling and average pooling in the channel dimension.

[0065] S=σ(Conv 7×7 (Concat(AvgPool(X),MaxPool(X))))

[0066] Among them, W1 and W2 are fully connected weights, σ(.) is the Sigmoid function, GAP(.) is the global average pooling, S represents spatial attention, X is the input feature map, and the dimension is [C, H, W] (number of channels, height, width), Conv 7×7(.) is a 7*7 convolutional layer, Concat(.) represents the concatenation of two pooling results along the channel dimension, AvgPool(.) and MaxPool(.) represent the average pooling and maximum pooling of the spatial dimension of the feature map respectively.

[0067] The four-tuple metric learning model is as follows Figure 2 As shown in the figure, the inputs t0-tn and x0-xn are the inlet flow data and outlet flow data of the network flow, respectively. The data features are composed of the packet size and inter-packet delay of the network traffic in series, and are normalized before entering the dual-channel feature embedding network. Among them, Anchor (anchor sample), Positive (positive sample), Negative (negative sample), and False Neg (pseudo-negative sample) are the inlet flow, the outlet flow associated with the inlet flow, the outlet flow not associated with the inlet flow, and the associated outlet flow with disturbance added; after designing the four-tuple loss function, two feature embedding networks A and P / N are trained with these data, namely the four-tuple metric learning model.

[0068] Construct a loss function for the perturbation and train a four-tuple metric learning model based on the four-tuple data set in step S1. Specifically, the loss function is as follows: Figure 4 As shown, after each iteration of model training, the basis of triple loss in feature space (the distance d between the anchor sample and the positive sample) ap Compared to the distance d from the negative sample an1 Closer), so that the distance d between the pseudo negative sample (adding perturbation data) and the negative sample in the feature space is n1n2 further, and make the distance d between the anchor sample and the pseudo negative sample an2 More recently, the loss function is designed as follows:

[0069] L q =max(d ap -d an1 +α,0)+max(d an2 -d n1n2 +β,0)

[0070] Among them, d ap is the feature space distance between the anchor point and the positive sample, d an1 is the distance between the anchor point and the negative sample, d an2 is the distance between the positive sample and the perturbation sample, d n1n2 is the distance between the negative sample and the perturbation sample, α and β are both boundary thresholds, L q is the loss function of the model.

[0071] During the training of the quadruple metric learning model, a dynamic semi-hard sample mining mechanism is adopted. In each batch of training, semi-hard samples in the positive samples of the batch are selected as negative samples corresponding to the anchor samples. The semi-hard sample screening process is as follows:

[0072] Calculate the cosine similarity matrix of the feature vectors of the inlet flow sample and all the outlet flow samples in the batch, and filter out the negative samples that meet the following formula in this matrix:

[0073]

[0074] in To control sample difficulty, S(a,n) is the similarity between the anchor sample and the negative sample, and S(a,p) is the similarity between the anchor sample and the positive sample. a, n, and p represent the anchor sample, the positive sample, and the negative sample. Negative samples that meet the requirements are used as semi-difficult samples for training. If there are no matching negative samples in the batch, a random negative sample is selected as the training set.

[0075] S3. Segment the traffic data into multiple time windows and extract the corresponding spatiotemporal feature vector for each time window using the trained four-tuple metric learning model. Calculate the window-level cosine similarity using the extracted spatiotemporal feature vector. The window-level cosine similarity calculation is defined as:

[0076]

[0077] Among them, corr(v,u) represents the cosine similarity between vectors v and u, n represents the dimension of this vector, v i and u i Represents the i-th vector in the input and output stream vector groups, respectively. As an embodiment, the feature vector dimension output by the feature embedding network is 64-dimensional.

[0078] S5. Track the real-time similarity distribution through exponentially weighted moving quantiles to generate a dynamic mixed quantile threshold; the dynamic mixed quantile threshold θ final Calculated by the following formula:

[0079] θ final =0.5θ global +0.3θ dynamic +0.2θ local

[0080] where θ global =Q3+1.5IQR, Q3 is the 3 / 4 quantile of the similarity sequence, IQR is the difference between the 3 / 4 quantile and the 1 / 4 quantile; θ local The 9 / 10 quantile of the sliding window of the last k values (default k = 50). dynamicis the exponentially weighted moving quantile, which is calculated as follows:

[0081] θ dynamic =θ t =(1-β)·θ t-1 +γ·quantile(W t ,0.95)

[0082] Among them, W t is a sliding window that selects the most recent k values (default k = 50), γ is the attenuation factor, the default value is 0.2, and θ t is the exponentially weighted moving quantile of the current sliding window, quantile(.) is the function that takes the sequence quantile, and β is the weighting coefficient, which defaults to 0.2.

[0083] S6. Compare the window-level cosine similarity with the dynamic hybrid quantile threshold to make a preliminary association judgment. If it is greater than or equal to the threshold, the window is marked as associated. If it is less than the threshold, it is judged as unrelated and a multi-window voting mechanism is used for further judgment.

[0084] The multi-window voting mechanism uses a sliding window protocol to perform multi-scale time series segmentation on the original traffic data stream. A 50% overlap rate is used between each window for sliding coverage to form a dense sampling grid coupled in time and space. A voting threshold is set and the number of associated time windows of the flow pair is accumulated for the final judgment. If the total number of votes is greater than the set voting threshold, the pair of network flows is finally determined to be associated.

[0085] The cosine similarity of each window and the dynamic mixing quantile threshold θ final After comparison, if the windows are associated, one vote is assigned; otherwise, zero is assigned. If the total vote score, W_score, is greater than or equal to the set threshold, the data flows are considered associated. For example, if the number of time windows is 11 and the total number of votes is greater than 9, the pair of network flows is considered associated.

[0086] like Figure 2 As shown in the figure, the inflow and outflow are divided into five equal-length windows W1 to W5 according to the time series, such as 0-4, 2-6, 4-8, 6-10, and 8-12, which are four-second windows. These five equal-length windows are input into the feature embedding network A and P / N respectively to obtain the cosine similarity of each window, which is then compared with the dynamic hybrid quantile threshold θ final After comparison, five voting scores W1_score-W5_score are obtained. If the total score of the five voting scores is greater than or equal to 4, the data flow is finally determined to be associated.

[0087] like Figure 5As shown, an embodiment of the present application also provides a network flow association system, including a feature extraction module, a disturbance generation and injection module, a metric learning optimization module and a threshold determination module.

[0088] The feature extraction module is used to extract and weight the spatiotemporal features of network flows, suppress noise interference through channel and spatial attention mechanisms, and generate highly discriminative traffic feature vectors;

[0089] The perturbation generation and injection module is used to generate adversarial perturbation samples that conform to the statistical characteristics of network jitter. These samples are injected into the network traffic training set by perturbing timing delay and packet size, improving the model's defense against blind adversarial attacks.

[0090] The metric learning optimization module is used to optimize the feature embedding space by using the four-tuple sample distance constraint, and to improve the model's intra-class aggregation and inter-class discrimination by combining the original and perturbed samples.

[0091] The threshold determination module is used to integrate the global baseline, dynamic quantile and local window threshold, and adaptively determine the network flow correlation through a multi-level threshold voting mechanism.

[0092] like Figure 6 As shown, the embodiment of the present application further provides a computer device, including: a processing unit, a network flow interface and a storage unit. In the device shown in the figure, the number of processing units can be single or multiple, and only one processing unit is shown in the figure as an example. In the embodiment of the present invention, the processing unit, the network flow interface and the storage unit can be interconnected through a bus system or other means, such as Figure 6 As shown, interconnection is achieved through a bus system.

[0093] The processing unit can be a central processing unit (CPU), a network processing unit (NPU), or a hybrid configuration of a CPU and an NPU. The processing unit can also integrate hardware accelerators. These hardware accelerators can be application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or a combination thereof. The above-mentioned PLD can be a complex programmable logic device (CPLD), a field programmable gate array (FPGA), generic array logic (GAL), or any combination thereof. The storage unit can include volatile memory, such as random-access memory (RAM); the storage unit can also include non-volatile memory, such as flash memory, hard disk drive (HDD), or solid-state drive (SSD); the storage unit can also be a combination of the above-mentioned types of memory.

[0094] An embodiment of the present application further provides a computer-readable storage medium comprising instructions, which, when executed on a computer, enables the computer to execute the network flow association method mentioned in the above embodiment.

[0095] Those skilled in the art will understand that all or part of the steps and corresponding devices for implementing the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a disk or an optical disk, etc.

[0096] The above embodiments are preferred implementation modes of the present invention, but the implementation modes of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications that do not deviate from the spirit and principles of the present invention should be considered as equivalent replacement methods and are included in the scope of protection of the present invention.

Claims

1. A network flow association method based on quadruple metric learning, characterized in that: The following steps are involved: The traffic data is divided into multiple time windows, and the spatiotemporal traffic characteristics of the inlet and outlet traffic are extracted for each independent time window through the trained four-tuple metric learning model. Each window independently calculates cosine similarity using spatiotemporal traffic characteristics and compares the cosine similarity with the dynamic mixing quantile threshold. If the cosine similarity is greater than or equal to the threshold, the network ingress and egress flows are considered associated. Otherwise, according to the multi-window voting mechanism, if the total number of votes is greater than the set voting threshold, the pair of network flows is ultimately determined to be associated.

2. A network flow association method based on quadruple metric learning according to claim 1, characterized in that: The dual-channel feature embedding network adopts a symmetric dual-branch deep neural network architecture, including an inlet flow feature embedding network and an outlet flow feature embedding network. The inlet flow feature embedding network is used to extract input flow features, and the outlet flow feature embedding network is used to extract output flow features. Each inlet flow feature embedding network and outlet flow feature embedding network includes multi-level convolutional layers, and an attention mechanism module is cascaded after the last convolution layer to extract disturbance-resistant spatiotemporal flow features.

3. A network flow association method based on quadruple metric learning according to claim 2, characterized in that: The attention mechanism module includes a channel attention module and a spatial attention module; The channel attention module generates a channel weight vector through two fully connected layers, normalizes it with the Sigmoid function, and then performs channel weighting with the original feature map to achieve global average pooling and compress the channel dimension of the feature map; The spatial attention module generates a spatial weight matrix after dimensionality reduction through a 7×1 convolution kernel, calibrates the features of the time-sensitive area through the Sigmoid function, and realizes the feature splicing of maximum pooling and average pooling in the channel dimension.

4. A network flow association method based on quadruple metric learning according to claim 1, characterized in that: The training of the quadruple metric learning model consists of the following steps: Construct a four-tuple dataset containing original samples, positive samples, negative samples, and perturbation samples, and divide the data into training sets and test sets; The training set is used to train the four-tuple metric learning model. During the training process of the four-tuple metric learning model, a dynamic semi-hard sample mining mechanism is adopted. In each batch of training, the semi-hard samples in the positive samples of the batch are selected as the negative samples corresponding to the anchor samples. The semi-hard sample screening process is as follows: Calculate the cosine similarity matrix of the feature vectors of the inlet flow sample and all the outlet flow samples in the batch, and filter out the negative samples that meet the following formula in this matrix: in Control sample difficulty, S(a,n) is the similarity between the anchor sample and the negative sample, S(a,p) is the similarity between the anchor and the positive sample, a, p, n represent the anchor sample, positive sample and negative sample respectively.

5. The network flow association method based on quadruple metric learning according to claim 1 is characterized in that: The loss function of the quadruple metric learning model is as follows: L q =max(d ap -d an1 +α,0)+max(d an2 -d n1n2 +β,0) Among them, d ap is the feature space distance between the anchor point and the positive sample, d an1 is the distance between the anchor point and the negative sample, d an2 is the distance between the positive sample and the perturbation sample, d n1n2 is the distance between the negative sample and the perturbation sample, α and β are both boundary thresholds, L q is the loss function of the model.

6. A network flow association method based on quadruple metric learning according to claim 1, characterized in that: Cosine similarity is calculated as: Among them, corr(v,u) represents the cosine similarity between vectors v and u, n represents the dimension of this vector, v i and u i Represent the i-th vector in the input stream and output stream vector groups respectively.

7. The network flow association method based on quadruple metric learning according to claim 1 is characterized in that: The dynamic mixing quantile threshold θ final Calculated by the following formula: i final =0.5θ global +0.3θ dynamic +0.2θ local where θ global =Q3+1.5IQR, Q3 is the 3 / 4 quantile of the similarity sequence, IQR is the difference between the 3 / 4 quantile and the 1 / 4 quantile; θ local is the 9 / 10 quantile of the sliding window of the last k values; θ dynamic The formula for calculating the exponentially weighted moving quantile is as follows: i dynamic =θ t =(1-β)·θ t-1 +γ·quantile(W t ,0.95) Among them, W t is a sliding window that selects the most recent k values, γ is the decay factor, and θ t is the exponentially weighted moving quantile of the current sliding window, quantile(.) is the function of taking the sequence quantile, and β is the weighting coefficient.

8. The network flow association method based on quadruple metric learning according to claim 1 is characterized in that: The multi-window voting mechanism uses a sliding window protocol to perform multi-scale time series segmentation on the original traffic data stream. The cosine similarity of each window is compared with the dynamic hybrid quantile threshold. If the window is associated, it is counted as one vote, otherwise it is counted as 0. If the total voting score is greater than or equal to the voting threshold, the data stream is finally judged to be associated.

9. A system for implementing the network flow association method based on quadruple metric learning according to claim 1, characterized in that: include: The feature extraction module is used to extract and weight the spatiotemporal features of network flows, suppress noise interference through channel and spatial attention mechanisms, and generate highly discriminative traffic feature vectors; The perturbation generation and injection module is used to generate adversarial perturbation samples that conform to the statistical characteristics of network jitter. These samples are injected into the network traffic training set by perturbing timing delay and packet size, improving the model's defense against blind adversarial attacks. The metric learning optimization module is used to optimize the feature embedding space by using the four-tuple sample distance constraint, and to improve the model's intra-class aggregation and inter-class discrimination by combining the original and perturbed samples. The threshold determination module is used to integrate the global baseline, dynamic quantile and local window threshold, and adaptively determine the network flow correlation through a multi-level threshold voting mechanism.

10. A computer device, characterized in that: include: A memory, a processor, and a computer program stored in the memory, which implements the method according to any one of claims 1 to 8 when the computer program is executed on the processor.

Citation Information

Cited By

  • Anonymous network flow association method based on feature extraction and feature enhancement

    CN119906552A

  • Anonymous network traffic correlation method based on feature extraction and feature enhancement

    CN119906552B

  • Bimodal image fusion method and device based on tuple disturbance and storage medium

    CN120783175A

  • Twin modal image fusion method and device based on tuple disturbance and storage medium

    CN120783175B