Encrypted traffic classification model construction and classification method based on bidirectional convolution and LSTM
Through the encrypted traffic classification model of bidirectional convolution and LSTM, long-distance dependence is captured using expanded convolution and bidirectional branches, and global information modeling is combined with CBAM attention and linear attention modules, which solves the problems of insufficient modeling capabilities of the encrypted traffic classification model and global periodic mode ignorance in the existing technology, and improves classification performance.
Patent Information
- Application Number
- CN202510521426.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-08-19
AI Technical Summary
Existing deep learning-based encrypted traffic classification methods have poor modeling capabilities and are prone to ignore critical global cycle patterns.
The encrypted traffic classification model based on bidirectional convolution and LSTM is adopted, including a bidirectional timing convolution network, a bidirectional long-term short-term memory neural network, a linear attention module and a fully connected layer. The long-distance dependence is captured through expanded convolution and bidirectional branches, and the one-dimensional CBAM attention module is used to pay attention to key features, and the global information modeling is combined with bidirectional LSTM and linear attention module.
It improves the feature extraction accuracy of encrypted traffic classification and the understanding of complex timing dependencies, improves classification performance, and solves the problems of insufficient modeling capabilities of existing methods and ignore global periodic patterns.
Smart Images

Figure CN120508872A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of encrypted traffic identification and relates to an encrypted traffic classification method, specifically an encrypted traffic classification model construction and classification method based on bidirectional convolution and LSTM. Background Art
[0002] With the increasing severity of network security threats, the detection and classification of encrypted traffic has become a critical issue in network protection that needs to be addressed. Traditional encrypted traffic classification methods typically rely on plaintext information and features of the traffic. However, with the protection of modern encryption technologies, the content of network traffic is already encrypted, significantly reducing the effectiveness of traditional methods. To address this challenge, traffic classification methods based on deep learning have become a research hotspot. For example, recurrent neural networks (RNNs) and temporal convolutional networks (TCNs) have become a research hotspot. RNNs, however, suffer from the problems of vanishing and exploding gradients when processing long-term dependencies. Furthermore, RNNs excel at capturing dynamic changes between adjacent moments, but are relatively poor at modeling long-term dependencies. While TCNs can capture local temporal patterns, they have limited ability to model long-term dependencies and often overlook critical global periodic patterns. Summary of the Invention
[0003] In view of the shortcomings of the existing technology, the purpose of the present invention is to provide an encrypted traffic classification model construction and classification method based on bidirectional convolution and LSTM, so as to solve the technical problems that the existing traffic classification methods based on deep learning have relatively poor modeling capabilities and are prone to ignore key global periodic patterns.
[0004] In order to solve the above technical problems, the present invention adopts the following technical solutions:
[0005] A method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM, comprising the following steps:
[0006] Step 1: preprocessing the encrypted network traffic original data packet to obtain the preprocessed encrypted network traffic original data packet;
[0007] Step 2: Build an encrypted traffic classification model;
[0008] The encrypted traffic classification model includes a bidirectional temporal convolutional network, a bidirectional long short-term memory neural network, a linear attention module and a fully connected layer connected in sequence;
[0009] The bidirectional temporal convolutional network is used to extract time features from the preprocessed encrypted network traffic original data packet obtained in step 1 to obtain time features; and to weight the channel dimension and time dimension of the time features to obtain a weighted encrypted network traffic original data packet;
[0010] The bidirectional long short-term memory neural network is used to extract the time characteristics of the weighted encrypted network traffic original data packets;
[0011] The linear attention module is used to weight the temporal features to obtain a global feature vector;
[0012] The fully connected layer is used to convert the global feature vector into a classification result.
[0013] In step 3, the encrypted network traffic original data packet preprocessed in step 1 is used as input, the category of the encrypted network traffic original data packet is used as output, and the encrypted traffic classification model constructed in step 2 is trained using the cross entropy loss function to obtain a trained encrypted traffic classification model.
[0014] The present invention includes the following technical features:
[0015] The bidirectional temporal convolutional network includes three layers of bidirectional temporal convolutional units, each layer of bidirectional temporal convolutional units is connected to a one-dimensional CBAM attention module, and each layer of bidirectional temporal convolutional units includes a forward convolution branch and a reverse convolution branch with the same structure and arranged in parallel;
[0016] The forward convolution branch includes a 1×1 convolution layer and a TCN module arranged in parallel, and the TCN module includes a dilated causal convolution layer, a weight normalization layer, a ReLU activation layer, a Dropout layer, a dilated causal convolution layer, a weight normalization layer, a ReLU activation layer, and a Dropout layer arranged in sequence;
[0017] The reverse convolution branch includes a flip module and a 1×1 convolution layer and a TCN module arranged in parallel;
[0018] The one-dimensional CBAM attention module includes connected channel attention and temporal attention.
[0019] The bidirectional long short-term memory neural network includes two layers of stacked bidirectional LSTM network units, and each layer of bidirectional LSTM network units includes a forward LSTM and a reverse LSTM.
[0020] The fully connected layer includes a linear transformation layer and a softmax activation layer.
[0021] The step 1 specifically includes the following steps:
[0022] Step 1.1, remove the Ethernet header from the original data packet of the encrypted network traffic;
[0023] Step 1.2: Set the source IP address and destination IP address of the original encrypted network traffic data packet processed in step 1.1 to 0.0.0.0;
[0024] Step 1.3, trimming the TCP header field in the original data packet of the encrypted network traffic processed in step 1.2 to 20 bytes and padding the UDP header field to 20 bytes;
[0025] Step 1.4, deleting the DNS packet, ACK packet, SYN packet, and FIN packet from the original encrypted network traffic data packet processed in step 1.3;
[0026] In step 1.5, the encrypted network traffic original data packet processed in step 1.4 is trimmed or padded to 1500 bytes and normalized to obtain the pre-processed encrypted traffic data.
[0027] Furthermore, an encrypted traffic classification method based on bidirectional convolution and LSTM includes the following steps:
[0028] Step 1: obtaining an original data packet of encrypted network traffic to be classified and preprocessing it to obtain a preprocessed original data packet of encrypted network traffic to be classified;
[0029] Step 2: Input the preprocessed encrypted network traffic original data packet to be classified obtained in step 1 into the trained encrypted traffic classification model obtained in the encrypted traffic classification model construction method based on bidirectional convolution and LSTM, and output the classification result.
[0030] Compared with the prior art, the present invention has the following beneficial technical effects:
[0031] The bidirectional temporal convolutional network in the present invention can effectively capture long-distance dependencies by using dilated convolution and bidirectional branches, and automatically focus on the channels and time steps that are most critical to the classification task through the channel attention and temporal attention modules in the one-dimensional CBAM attention module, thereby improving the accuracy of feature extraction; the bidirectional long short-term memory neural network and the linear attention module are used to model global information, which enhances the understanding of the encrypted traffic classification model of complex temporal dependencies and improves the modeling ability of the overall characteristics and temporal dependencies of the encrypted traffic, thereby improving the classification performance and solving the technical problem that the existing deep learning-based traffic classification method has relatively poor modeling ability and easily ignores key global periodic patterns. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 A flow chart of the method for constructing an encrypted traffic classification model in the present invention;
[0033] Figure 2 This is a schematic diagram of the structure of the encrypted traffic classification model in the present invention;
[0034] Figure 3 for Figure 2Schematic diagram of the structure of the bidirectional temporal convolution unit in .
[0035] The specific contents of the present invention are further explained in detail below with reference to the embodiments. DETAILED DESCRIPTION
[0036] It should be noted that, unless otherwise specified, all components in the present invention are components known in the art.
[0037] Specific embodiments of the present invention are given below. It should be noted that the present invention is not limited to the following specific embodiments, and all equivalent modifications made on the basis of the technical solution of this application fall within the protection scope of the present invention.
[0038] The present invention provides a method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM, comprising the following steps:
[0039] Step 1: preprocessing the encrypted network traffic original data packet to obtain the preprocessed encrypted network traffic original data packet;
[0040] Step 2: Build an encrypted traffic classification model;
[0041] The encrypted traffic classification model includes a bidirectional temporal convolutional network, a bidirectional long short-term memory neural network, a linear attention module and a fully connected layer connected in sequence;
[0042] The bidirectional temporal convolutional network is used to extract time features from the preprocessed encrypted network traffic original data packet obtained in step 1 to obtain time features; and to weight the channel dimension and time dimension of the time features to obtain a weighted encrypted network traffic original data packet;
[0043] The bidirectional long short-term memory neural network is used to extract the time characteristics of the weighted encrypted network traffic original data packets;
[0044] The linear attention module is used to weight the temporal features to obtain a global feature vector;
[0045] The fully connected layer is used to convert the global feature vector into a classification result.
[0046] In step 3, the encrypted network traffic original data packet preprocessed in step 1 is used as input, the category of the encrypted network traffic original data packet is used as output, and the encrypted traffic classification model constructed in step 2 is trained using the cross entropy loss function to obtain a trained encrypted traffic classification model.
[0047] In this technical solution, pre-processed encrypted network traffic raw data packets are first processed through a bidirectional temporal convolutional network to extract temporal features. This is then enhanced using the CBAM attention mechanism. A bidirectional long-short-term memory neural network combined with a linear attention module is used to capture global temporal dependencies, significantly improving the accuracy and robustness of time series data classification. The extracted data is then subjected to fully connected layer classification, resulting in even more accurate classification results.
[0048] The bidirectional temporal convolutional network can effectively capture long-distance dependencies using dilated convolutions and bidirectional branches, and automatically focus on the channels and time steps that are most critical to the classification task through the channel attention and temporal attention modules in the one-dimensional CBAM attention module, thereby improving the accuracy of feature extraction; the bidirectional long short-term memory neural network and linear attention module are used to model global information, which enhances the encrypted traffic classification model's understanding of complex temporal dependencies and improves the ability to model the overall characteristics and temporal dependencies of encrypted traffic, thereby improving classification performance and solving the technical problem that the existing deep learning-based traffic classification methods have relatively poor modeling capabilities and easily ignore key global periodic patterns.
[0049] The model is trained using a cross-entropy loss function. The specific process includes: During each training cycle, the model's predicted output is compared with the true label, and the prediction error is calculated using the cross-entropy loss function. The calculated error is fed back to each layer of the network through a backpropagation algorithm, automatically adjusting the weights and bias parameters of the network nodes. After multiple rounds of iterative training, the model is continuously optimized and updated until the predicted result is as close as possible to the true label. After training is complete, the optimized model is used to make decision responses to test data, achieving accurate classification of encrypted traffic.
[0050] The bidirectional temporal convolutional network consists of three layers of bidirectional temporal convolutional units. Each layer of bidirectional temporal convolutional units is connected to a one-dimensional CBAM attention module. Each layer of bidirectional temporal convolutional units includes a forward convolution branch and a reverse convolution branch with the same structure and arranged in parallel.
[0051] The forward convolution branch includes a 1×1 convolutional layer and a TCN module arranged in parallel. The TCN module includes a dilated causal convolutional layer, a weight normalization layer, a ReLU activation layer, a Dropout layer, a dilated causal convolutional layer, a weight normalization layer, a ReLU activation layer, and a Dropout layer arranged in sequence.
[0052] The reverse convolution branch includes a flip module and a 1×1 convolution layer and a TCN module in parallel;
[0053] The one-dimensional CBAM attention module includes connected channel attention and temporal attention.
[0054] In the above technical solution, the preprocessed encrypted network traffic original data packet is sent as input data to the bidirectional temporal convolutional network for feature extraction. The bidirectional temporal convolutional network has a total of three layers of bidirectional temporal convolution units. Each layer of bidirectional temporal convolution units adopts a different dilation rate (dilation) to expand the receptive field and capture the long-distance temporal dependencies in the input data; in each layer of bidirectional temporal convolution units, the forward convolution branch directly performs void convolution, pruning, ReLU activation and Dropout random inactivation on the input data; at the same time, the reverse convolution branch first reverses the input data through the flip module, and then performs the same convolution processing as the forward convolution branch, and then reverses the output to restore the original timing. Finally, the outputs of the forward convolution branch and the reverse convolution branch are fused and merged with the original input through the residual connection, thereby achieving full fusion of positive and negative bidirectional information.
[0055] After the output of each layer of bidirectional convolutional unit, a one-dimensional CBAM attention module is added to recalibrate the output features. The one-dimensional CBAM attention module includes channel attention and temporal attention.
[0056] Channel attention is used to perform global average pooling and maximum pooling on the input features in the time dimension to obtain a statistical description of each channel. Channel weights are then generated through two layers of 1D convolution and ReLU activation. After Sigmoid activation, the input features are weighted channel by channel.
[0057] The temporal attention module is used to perform average pooling and maximum pooling on the channel dimension of each time step on the output after channel attention. After splicing, the weight of each time step is calculated using one-dimensional convolution, and the features are weighted time step by time step after Sigmoid activation.
[0058] Through the above operations, the encrypted traffic classification model can automatically identify and enhance the channel and time step information that is most critical to the classification task.
[0059] The bidirectional long short-term memory neural network includes two layers of stacked bidirectional LSTM network units, and each layer of bidirectional LSTM network units includes a forward LSTM and a backward LSTM.
[0060] In the above technical solution, the temporal features are transposed and sent to a bidirectional long short-term memory neural network (BiLSTM) to further extract the global temporal features of the data. First, the temporal features from the one-dimensional CBAM attention module are converted into the shape of [batch_size, seq_len, feature_dim] to adapt to the input requirements of BiLSTM. Then, a two-layer bidirectional LSTM network unit is used to process the transposed temporal features to capture the long-term dependency information in the sequence. Next, linear attention is introduced after the BiLSTM output. By performing tanh activation and inner product operations on the hidden state of each time step, attention weights are generated, and the hidden states of each time step are weighted summed to obtain a set of global feature vectors.
[0061] The fully connected layer includes a linear transformation layer and a softmax activation layer.
[0062] In the above technical solution, the global feature vector is input into the fully connected layer (Dense layer), and the softmax activation function outputs the probability distribution of each category as the final classification result. The core of this step is: the fully connected layer linearly maps the global feature vector to the output space of a predetermined number of categories; the softmax activation function converts the linear mapping result into a probability distribution, so that each output value represents the predicted probability of the corresponding category, thus obtaining the classification result;
[0063] Step 1 specifically includes the following steps:
[0064] Step 1.1, remove the Ethernet header from the original data packet of the encrypted network traffic;
[0065] Step 1.2: Set the source IP address and destination IP address of the original encrypted network traffic data packet processed in step 1.1 to 0.0.0.0;
[0066] Step 1.3, trimming the TCP header field in the original data packet of the encrypted network traffic processed in step 1.2 to 20 bytes and padding the UDP header field to 20 bytes;
[0067] Step 1.4, deleting the DNS packet, ACK packet, SYN packet, and FIN packet from the original encrypted network traffic data packet processed in step 1.3;
[0068] In step 1.5, the encrypted network traffic original data packet processed in step 1.4 is trimmed or padded to 1500 bytes and normalized to obtain the pre-processed encrypted traffic data.
[0069] In the above technical solution, the original data packets of encrypted network traffic contain a lot of redundant information, and the original data packets need to be preprocessed to be processed into a data format that can be input into the model. This information can easily lead to overfitting of the model.
[0070] The present invention also provides an encrypted traffic classification method based on bidirectional convolution and LSTM, which includes the following steps:
[0071] Step 1: obtaining an original data packet of encrypted network traffic to be classified and preprocessing it to obtain a preprocessed original data packet of encrypted network traffic to be classified;
[0072] Step 2: Input the pre-processed encrypted network traffic original data packet to be classified obtained in step 1 into the trained encrypted traffic classification model obtained in the encrypted traffic classification model construction method based on bidirectional convolution and LSTM, and output the classification result.
[0073] Comparative verification example:
[0074] This example presents an encrypted traffic classification method based on bidirectional convolution and LSTM. The ISCX-VPN-NonVPN-2016 dataset is used to verify the accuracy of the encrypted traffic classification model constructed using this method. This dataset is unbalanced, so it is balanced by selecting 50,000 samples from each class. For classes with fewer than 50,000 samples, all samples are selected.
[0075] The confusion matrix is used to evaluate the results of the classification model. This embodiment mainly performs 12 classification tasks. In the classification task, there are four different combinations between the predicted label and the correct label, which constitute the confusion matrix. These four different combinations are TP (True Positive), which indicates that the true value is positive and the model predicts positive; FN (False Negative), which indicates that the true value is positive and the model predicts negative; FP (False Positive), which indicates that the true value is negative and the model predicts positive; and TN (True Negative), which indicates that the true value is negative and the model predicts negative.
[0076] The confusion matrix can be used to calculate four indicators: Accuracy, Recall, Precision, and F1-score. The calculation formula is as follows:
[0077]
[0078] Table 1 shows the experimental results on the ISCX-VPN-NonVPN-2016 dataset. The model achieved the following scores across various metrics: Accuracy = 98.74%, Precision = 98.75%, Recall = 98.74%, and F1-score = 98.75%, making the encrypted traffic classification model the best performer. Table 2 shows the results of the ablation experiment, demonstrating the effectiveness of the encrypted traffic classification model structure.
[0079] Table 1 Experimental results on the ISCX-VPN-NonVPN-2016 dataset
[0080] Method Ac Pr Rc F1 Deeppacket 93.29 93.77 93.06 93.21 SAM 90.33 88.78 85.33 85.60 PERT 93.52 94.00 93.49 93.68 This model 98.74 98.75 98.74 98.75
[0081] Table 2 Ablation experiment results on ISCX-VPN-NonVPN-2016 dataset
[0082] Method Ac Pr Rc F1 BiTCN 96.64 96.68 96.64 96.61 No bidirectional branches 96.76 96.79 96.76 96.76 No CBAM module 98.02 98.03 98.02 98.03 This model 98.74 98.75 98.74 98.75
Claims
1. A method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM, characterized in that: The following steps are involved: Step 1: preprocessing the encrypted network traffic original data packet to obtain the preprocessed encrypted network traffic original data packet; Step 2: Build an encrypted traffic classification model; The encrypted traffic classification model includes a bidirectional temporal convolutional network, a bidirectional long short-term memory neural network, a linear attention module and a fully connected layer connected in sequence; The bidirectional temporal convolutional network is used to extract temporal features from the preprocessed encrypted network traffic original data packets obtained in step 1 to obtain temporal features; And weighting the channel dimension and time dimension of the time series feature to obtain the weighted encrypted network traffic original data packet; The bidirectional long short-term memory neural network is used to extract the time characteristics of the weighted encrypted network traffic original data packets; The linear attention module is used to weight the temporal features to obtain a global feature vector; The fully connected layer is used to convert the global feature vector into a classification result. In step 3, the encrypted network traffic original data packet preprocessed in step 1 is used as input, the category of the encrypted network traffic original data packet is used as output, and the encrypted traffic classification model constructed in step 2 is trained using the cross entropy loss function to obtain a trained encrypted traffic classification model.
2. The method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM as claimed in claim 1, characterized in that: The bidirectional temporal convolutional network includes three layers of bidirectional temporal convolutional units, each layer of bidirectional temporal convolutional units is connected to a one-dimensional CBAM attention module, and each layer of bidirectional temporal convolutional units includes a forward convolution branch and a reverse convolution branch with the same structure and arranged in parallel; The forward convolution branch includes a 1×1 convolution layer and a TCN module arranged in parallel, and the TCN module includes a dilated causal convolution layer, a weight normalization layer, a ReLU activation layer, a Dropout layer, a dilated causal convolution layer, a weight normalization layer, a ReLU activation layer, and a Dropout layer arranged in sequence; The reverse convolution branch includes a flip module and a 1×1 convolution layer and a TCN module arranged in parallel; The one-dimensional CBAM attention module includes connected channel attention and temporal attention.
3. The method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM as claimed in claim 1, characterized in that: The bidirectional long short-term memory neural network includes two layers of stacked bidirectional LSTM network units, and each layer of bidirectional LSTM network units includes a forward LSTM and a reverse LSTM.
4. The method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM as claimed in claim 1, characterized in that: The fully connected layer includes a linear transformation layer and a softmax activation layer.
5. The method for constructing an encrypted traffic classification model based on bidirectional convolution and LSTM as claimed in claim 1, characterized in that: The step 1 specifically includes the following steps: Step 1.1, remove the Ethernet header from the original data packet of the encrypted network traffic; Step 1.2: Set the source IP address and destination IP address of the original encrypted network traffic data packet processed in step 1.1 to 0.0.0.0; Step 1.3, trimming the TCP header field in the original data packet of the encrypted network traffic processed in step 1.2 to 20 bytes and padding the UDP header field to 20 bytes; Step 1.4, deleting the DNS packet, ACK packet, SYN packet, and FIN packet from the original encrypted network traffic data packet processed in step 1.3; In step 1.5, the encrypted network traffic original data packet processed in step 1.4 is trimmed or padded to 1500 bytes and normalized to obtain the pre-processed encrypted traffic data.
6. An encrypted traffic classification method based on bidirectional convolution and LSTM, characterized in that: The following steps are involved: Step 1: obtaining an original data packet of encrypted network traffic to be classified and preprocessing it to obtain a preprocessed original data packet of encrypted network traffic to be classified; Step 2: Input the preprocessed encrypted network traffic original data packet to be classified obtained in step 1 into the trained encrypted traffic classification model obtained in the encrypted traffic classification model construction method based on bidirectional convolution and LSTM described in any one of claims 1 to 5, and output the classification result.
Citation Information
Cited By
Server diagnosis log classification method and electronic equipment
CN120763715A