Anti-fingerprint identification defense method, system and device based on CAM, medium and product

By generating a traffic aggregation matrix and using the CAM importance score to determine the key areas, combined with the camouflage algorithm to process the network traffic, the limitations and resource consumption problems of the network fingerprint recognition defense method in the existing technology are solved, a more efficient defense effect and lower computational overhead are achieved, and the security of the anonymous communication system is enhanced.

CN120675760APending Publication Date: 2025-09-19XIAN UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510811622.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing network fingerprint recognition defense methods have limitations in reducing recognition accuracy, consume large computing resources, and are easily circumvented by new-generation recognition models, making it difficult to effectively enhance the security and practicality of anonymous communication systems.

Method used

By obtaining the original network traffic data, analyzing the traffic characteristics to generate the traffic aggregation matrix, calling the CAM importance score generation script to determine the key areas, and using a variety of traffic feature camouflage algorithms to camouflage the key areas, including random time perturbation, dynamic filling and merging and splitting of data packets, the camouflaged network traffic data is generated.

Benefits of technology

It improves the generalization ability, reduces the prediction accuracy of the website fingerprint recognition model, reduces the computing resource overhead of the camouflage algorithm, and enhances the security and practicality of the anonymous communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675760A_ABST
    Figure CN120675760A_ABST
Patent Text Reader

Abstract

The invention discloses a CAM-based anti-fingerprint identification defense method, system and device, a medium and a product, and relates to the technical field of network security, the method comprises the following steps: obtaining original network traffic and analyzing traffic characteristics of original network traffic data to obtain a traffic aggregation matrix; secondly, a CAM importance score generation script is called to generate importance scores, and according to the importance scores, the attention degree of the website fingerprint recognition model to each region during prediction is extracted from the traffic aggregation matrix; and finally, carrying out traffic camouflage on the key region of the traffic aggregation matrix based on the information key region feature file by adopting a plurality of traffic feature camouflage algorithms to obtain camouflaged network traffic data. The key features concerned by the website fingerprint identification model are disturbed and destroyed, the prediction accuracy of the website fingerprint identification model is effectively reduced, the computing resource overhead of a camouflage algorithm is reduced, and the security and practicability of an anonymous communication system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a CAM-based anti-fingerprint identification defense method, system, device, medium and product. Background Art

[0002] With the continuous advancement of internet technology, users are increasingly concerned about protecting their online privacy. More and more people are using encrypted channels such as HTTPS, VPNs, and, more recently, Tor, when browsing the web, sending messages, and transmitting data to ensure the privacy and security of their communications. These encryption technologies are widely used to protect user privacy and circumvent online censorship. However, research has shown that even when communications are encrypted, attackers can still perform website fingerprinting (WF) attacks by analyzing traffic statistics during encrypted communications (such as packet size, transmission direction, and time interval), thereby inferring the websites visited by users. Such attacks pose a serious threat to user privacy and have become a key security challenge for anonymous communication systems.

[0003] Currently, defenses against network fingerprinting attacks primarily rely on efficient feature extraction and classification models. A number of defense mechanisms have been proposed to combat these attacks, including timing perturbations, fixed padding, random insertion of noise packets, and traffic obfuscation. However, these methods have limitations in reducing recognition accuracy. Furthermore, some methods consume large amounts of computational resources and lack generalization capabilities, making them easily circumvented by newer recognition models.

[0004] Therefore, there is an urgent need to develop an anti-fingerprinting defense technology with excellent defense effect and flexible configurability to enhance the security and practicality of anonymous communication systems. Summary of the Invention

[0005] The purpose of this application is to provide a CAM-based anti-fingerprinting defense method, system, device, medium and product that can effectively reduce the prediction accuracy of the website fingerprint recognition model.

[0006] To achieve the above objectives, this application provides the following solutions:

[0007] In a first aspect, the present application provides a CAM-based anti-fingerprinting defense method, comprising the following steps:

[0008] The original network traffic data is obtained and the traffic characteristics of the original network traffic data are analyzed to obtain a traffic aggregation matrix; the traffic aggregation matrix is ​​used to characterize the transmission characteristics of all data packets in each time slot.

[0009] Call the CAM importance score generation script to generate the importance score, and generate the information key area feature file for the traffic aggregation matrix based on the importance score; the importance score is used to characterize the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature file is the key area extracted from the traffic aggregation matrix based on the importance score.

[0010] A variety of traffic feature camouflage algorithms are used to camouflage the key areas of the traffic aggregation matrix based on the information key area feature file to obtain the camouflaged network traffic data.

[0011] Optionally, the traffic characteristics of the original network traffic data include: the number of data packets, the direction of the data packets and the timestamp of the data packets; the traffic aggregation matrix is ​​a two-row and N-column matrix, N is the number of time slots, each data in the first row represents the number of data packets sent in a unit time slot, and each data in the second row represents the number of data packets received in a unit time slot.

[0012] Optionally, a CAM importance score generation script is called to generate importance scores, and traffic aggregation matrix is ​​aggregated according to the importance scores to generate information key area feature files, specifically including the following steps:

[0013] Call the CAM importance score generation script to generate importance scores, use the class activation feature map to calculate the key areas of the traffic aggregation matrix, and thus generate the CAM score map.

[0014] Based on the CAM score map and the pre-trained website fingerprint recognition model, an information key area feature file is generated for the traffic aggregation matrix; the pre-trained website fingerprint recognition model is a convolutional neural network trained in advance based on the traffic aggregation matrix of the original network traffic data. The pre-trained website fingerprint recognition model is used to identify the website fingerprint recognition results when the original network traffic data is not protected.

[0015] Optionally, the CAM-based anti-fingerprinting defense method further includes: using a data set partitioning script to partition the traffic aggregation matrix of the original network traffic data to obtain a training data set and a test data set; the test data set is used to test the predictive performance of the pre-trained website fingerprint recognition model; calling the model training script to train a convolutional neural network based on the training data set to obtain a pre-trained website fingerprint recognition model.

[0016] Optionally, the traffic feature camouflage algorithm includes: a combination of one or more of a random time perturbation algorithm, a data packet dynamic filling algorithm, and a data packet merging and splitting algorithm.

[0017] Optionally, the random time perturbation algorithm is to insert a 2% random time offset in a key area of ​​the traffic aggregation matrix, so that the time for sending data packets has a random 2% sending time difference.

[0018] The dynamic data packet filling algorithm is to take any key area of ​​the traffic aggregation matrix as the current key area; in another random key area of ​​the traffic aggregation matrix, select a value that conforms to the normal distribution as the filling value of the current key area.

[0019] The packet merging and splitting algorithm randomly merges and splits the sent data packets. When merging data packets, it ensures that the directions of the two merged data packets are the same. When splitting data packets, the sizes of the split data packets are divided according to the set ratio, and a small time interval is introduced between each split data packet.

[0020] In a second aspect, the present application provides a CAM-based anti-fingerprint recognition defense system, comprising:

[0021] The traffic collection and preprocessing module is used to obtain the original network traffic data and analyze the traffic characteristics of the original network traffic data to obtain the traffic aggregation matrix; the traffic aggregation matrix is ​​used to characterize the transmission characteristics of all data packets in each time slot.

[0022] The key feature area extraction module is used to call the CAM importance score generation script to generate importance scores, and generate information key area feature files for the traffic aggregation matrix based on the importance scores; the importance scores are used to characterize the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature files are key areas extracted from the traffic aggregation matrix based on the importance scores.

[0023] The dynamic traffic camouflage module is used to adopt multiple traffic feature camouflage algorithms and perform traffic camouflage on the key areas of the traffic aggregation matrix based on the information key area feature file to obtain the camouflaged network traffic data.

[0024] In a third aspect, the present application provides a computer device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the CAM-based anti-fingerprinting defense method described above.

[0025] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the CAM-based anti-fingerprint recognition defense method described above.

[0026] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the CAM-based anti-fingerprint recognition defense method described above.

[0027] According to the specific embodiments provided in this application, this application discloses the following technical effects:

[0028] The present application provides a CAM-based anti-fingerprinting defense method, system, device, medium and product. In this method, the traffic characteristics of the original network traffic data are first analyzed to obtain a traffic aggregation matrix; secondly, the CAM importance score generation script is called to generate importance scores, and the degree of attention of the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions is extracted based on the importance scores; finally, a variety of traffic feature camouflage algorithms are used to perform traffic camouflage on the key areas of the traffic aggregation matrix based on the information key area feature file to obtain the camouflaged network traffic data. The present application identifies the key areas of the traffic aggregation matrix through the CAM importance score generation script. When performing key area identification, the convolutional neural network obtained by pre-training is combined to accurately determine the key areas, improve the generalization ability, and is not easily bypassed by the new generation of recognition models. Subsequently, a variety of traffic feature camouflage algorithms are used to camouflage these key areas, so that the key features of the website fingerprint recognition model are disturbed and destroyed, effectively reducing the prediction accuracy of the website fingerprint recognition model. Moreover, since only a few key areas need to be dynamically camouflaged, the computing resource overhead of the camouflage algorithm is reduced, and the security and practicality of the anonymous communication system are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0030] Figure 1 A flowchart of a CAM-based anti-fingerprinting defense method provided in one embodiment of the present application.

[0031] Figure 2 A schematic diagram of a traffic aggregation matrix generated in a CAM-based anti-fingerprinting defense method provided in an embodiment of the present application.

[0032] Figure 3 This is a flowchart of step A2 in a CAM-based anti-fingerprint recognition defense method provided in one embodiment of the present application.

[0033] Figure 4A technical roadmap for a CAM-based anti-fingerprinting defense method provided in one embodiment of the present application.

[0034] Figure 5 A bar chart comparing the impact of a CAM-based anti-fingerprinting defense method provided in an embodiment of the present application and other defense solutions on the accuracy of website fingerprint attack recognition.

[0035] Figure 6 A bar chart comparing the impact of a CAM-based anti-fingerprinting defense method provided in an embodiment of the present application and other defense solutions on bandwidth and time.

[0036] Figure 7 A schematic diagram of the functional modules of a CAM-based anti-fingerprint recognition defense device provided in one embodiment of the present application.

[0037] Figure 8 A schematic diagram of the structure of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0038] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0039] Current network fingerprint attack technologies mainly rely on efficient feature extraction and classification models. Typical attack methods include: (1) traditional machine learning methods based on statistical features, such as k-nearest neighbor (k-NN), random forest (RandomForest), support vector machine (SVM), etc.; (2) automatic feature extraction technologies based on deep learning, such as convolutional neural network (CNN), recurrent neural network (RNN), long short-term memory network (LSTM), etc.; (3) modal traffic analysis models and end-to-end feature learning systems. These methods have achieved extremely high recognition accuracy on multiple public datasets (such as Tor Hidden Services Dataset). Even when network traffic is compressed or encrypted, the classification performance can still be maintained at above 80%, which seriously threatens the user's network anonymity and privacy.

[0040] To deal with the above attacks, the academic community has proposed some defense strategies, including: (1) time perturbation defense: by disrupting the time sequence of data packet sending, interfering with the attack model's modeling of traffic rhythm; (2) padding and pseudo-packet insertion: inserting random or regular invalid data packets into the communication to mask the real communication pattern; (3) blurring bandwidth and throughput characteristics: by adjusting the communication rate and rhythm, making the access traffic of different websites tend to be consistent; (4) confusion control strategy and adversarial samples: using generative adversarial networks (GANs) or adversarial perturbations to counter machine learning models.

[0041] Despite this, existing defense mechanisms primarily include techniques such as timing perturbations, fixed padding, random insertion of noise packets, and traffic obfuscation. However, these methods have limitations in reducing recognition accuracy. Some methods consume large amounts of computational resources, have insufficient generalization capabilities, and are easily circumvented by newer generation recognition models.

[0042] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0043] The embodiment of the present application provides a CAM-based anti-fingerprint identification defense method. In an exemplary embodiment, Figure 1 As shown, the following steps are included:

[0044] A1. Obtain the original network traffic data and analyze its traffic characteristics to obtain a traffic aggregation matrix. The traffic aggregation matrix is ​​used to characterize the transmission characteristics of all packets in each time slot. Specifically, the traffic characteristics of the original network traffic data include: the number of packets, the direction of the packets, and the timestamp of the packets. The traffic aggregation matrix is ​​a matrix with two rows and N columns, where N is the number of time slots, such as Figure 2 As shown, each data in the first row represents the number of data packets sent in a unit time slot, and each data in the second row represents the number of data packets received in a unit time slot.

[0045] Specifically, the raw network traffic data is input, its traffic characteristics are analyzed, and a traffic aggregation matrix is ​​output. The traffic aggregation matrix divides the entire trace into fixed-length time slots based on the number of packets transmitted within a small time interval. The number of sent and received packets in each time slot is then calculated and combined into a matrix. Assume that the length of each time slot is denoted by s, the maximum load time considered for a packet transmission request is T, and the number of time slots N can be calculated as T / s.

[0046] Before proceeding to step A2, the method further includes pre-training a website fingerprint recognition model based on the original network traffic data to determine the key areas that the model focuses on during prediction. The process includes the following steps:

[0047] The data set partitioning script is used to partition the traffic aggregation matrix of the original network traffic data to obtain a training data set and a test data set; the test data set is used to test the prediction performance of the pre-trained website fingerprint recognition model; the model training script is called to train a convolutional neural network based on the training data set to obtain a pre-trained website fingerprint recognition model.

[0048] In this example, before performing the above steps, install PyTorch and CUDA and configure the specific environment in PyCharm. After preprocessing the raw network traffic data to obtain a traffic aggregation matrix, use the configured package in PyCharm to run the dataset partitioning script extract-list.py to divide the dataset into training and test datasets. Finally, load the training dataset divided in the above steps into the training script train.py. During the training process, a convolutional neural network is used to extract features, and the final output is a softmax classification. After training, a pretrained website fingerprint recognition model is obtained.

[0049] A2. Call the CAM importance score generation script to generate importance scores, and generate information key area feature files for the traffic aggregation matrix based on the importance scores; the importance scores are used to characterize the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature files are key areas extracted from the traffic aggregation matrix based on the importance scores. In this embodiment, Figure 3 As shown, step A2 specifically includes the following steps:

[0050] A21. Call the CAM importance score generation script to generate importance scores. Use the class activation feature map to calculate the key areas of the traffic aggregation matrix, thereby generating a CAM score map. The CAM score map is used to mark the key parts of the traffic data.

[0051] A22. Generate an information key area feature file for the traffic aggregation matrix based on the CAM score map and the pre-trained website fingerprint recognition model. The pre-trained website fingerprint recognition model is a convolutional neural network pre-trained based on the traffic aggregation matrix of the original network traffic data. The pre-trained website fingerprint recognition model is used to identify the website fingerprint recognition results when the original network traffic data is unprotected.

[0052] A3. Using multiple traffic signature camouflage algorithms, based on the key area signature file, traffic is camouflaged in key areas of the traffic aggregation matrix to obtain camouflaged network traffic data. This ensures that the adjusted traffic signatures fall within a range that is difficult for attackers to exploit. In this embodiment, optional traffic signature camouflage algorithms include a combination of one or more of a random time perturbation algorithm, a dynamic packet filling algorithm, and a packet merging and splitting algorithm.

[0053] Specifically, the random time perturbation algorithm inserts a 2% random time offset in the key area of ​​the traffic aggregation matrix, so that the time of sending data packets has a random 2% sending time difference.

[0054] The dynamic data packet filling algorithm takes any key area of ​​the traffic aggregation matrix as the current key area, and selects a value that conforms to the normal distribution in another random key area of ​​the traffic aggregation matrix as the filling value of the current key area.

[0055] The packet merging and splitting algorithm randomly merges and splits the sent data packets. When merging data packets, it ensures that the directions of the two merged data packets are the same. When splitting data packets, the sizes of the split data packets are divided according to the set ratio, and a small time interval is introduced between each split data packet.

[0056] The overall technical route of the CAM-based anti-fingerprint recognition defense method provided in the above embodiment is as follows: Figure 4 To verify the effectiveness of the solution provided in the above embodiment, the defense generation script generate_defence.py is run to generate and save the defense-enhanced training and test datasets based on the disguised network traffic data. The defense-enhanced training dataset is loaded into the training script train.py and run, generating a defense-enhanced website fingerprint recognition model.

[0057] Then, load the unprotected test dataset and the pre-trained website fingerprint recognition model in the test script test.py, run this script, and get the accuracy of the website fingerprint attack on the unprotected dataset, as well as the consumed bandwidth and loading time; and load the protected test dataset and the trained website fingerprint recognition model in the test script test.py, run this script, and get the accuracy of the website fingerprint attack on the protected dataset, as well as the consumed bandwidth and loading time, respectively. Figure 5 and Figure 6 shown.

[0058] Depend on Figure 5 and Figure 6As can be seen, the traditional CAM method has an identification rate of 55.48% against website fingerprint attacks, while the enhanced CAM with dynamic traffic camouflage has an identification rate of 49.67%. Ultimately, the improved CAM defense method has a better defense effect against website fingerprint attacks than the traditional CAM defense method and other traditional defense methods. The method provided in this embodiment introduces a larger bandwidth due to the adaptive padding and time perturbation mechanisms, while slightly reducing loading time, demonstrating its feasibility in practical scenarios.

[0059] Based on the same inventive concept, the embodiment of the present application also provides a system for implementing the above-mentioned CAM-based anti-fingerprint identification defense method. The solution provided by the system is similar to the solution described in the above-mentioned method. In an exemplary embodiment, Figure 7 As shown, a CAM-based anti-fingerprint recognition defense system is provided, including the following functional modules:

[0060] The traffic collection and preprocessing module is used to obtain the original network traffic data and analyze the traffic characteristics of the original network traffic data to obtain the traffic aggregation matrix; the traffic aggregation matrix is ​​used to characterize the transmission characteristics of all data packets in each time slot.

[0061] The key feature area extraction module is used to call the CAM importance score generation script to generate importance scores, and generate information key area feature files for the traffic aggregation matrix based on the importance scores; the importance scores are used to characterize the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature files are key areas extracted from the traffic aggregation matrix based on the importance scores.

[0062] The dynamic traffic camouflage module is used to adopt multiple traffic feature camouflage algorithms and perform traffic camouflage on the key areas of the traffic aggregation matrix based on the information key area feature file to obtain the camouflaged network traffic data.

[0063] certainly, Figure 7 The architecture shown is only exemplary and can be omitted according to actual needs when implementing different functions. Figure 7 One or at least two components of the system shown.

[0064] In an exemplary embodiment, a computer device is provided. The computer device may be a server or a terminal. The internal structure diagram thereof may be as follows: Figure 8As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the CAM-based anti-fingerprint recognition defense method provided in the previous embodiment can be implemented.

[0065] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0066] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0067] In an exemplary embodiment, a computer-readable storage medium is provided, storing a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0068] In an exemplary embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0069] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0070] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM may be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0071] The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may include, but are not limited to, general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic units, data processing logic units based on quantum computing, and the like.

[0072] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0073] This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above examples is only intended to help understand the method and core concept of this application. At the same time, for those skilled in the art, based on the concept of this application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.

Claims

1. A CAM-based anti-fingerprinting defense method, characterized in that: include: Obtaining original network traffic data, and analyzing traffic characteristics of the original network traffic data to obtain a traffic aggregation matrix; The traffic aggregation matrix is ​​used to characterize the transmission characteristics of all data packets in each time slot; Calling the CAM importance score generation script to generate an importance score, and generating an information key area feature file for the traffic aggregation matrix based on the importance score; the importance score is used to represent the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature file is the key area extracted from the traffic aggregation matrix based on the importance score; A variety of traffic feature camouflage algorithms are used to perform traffic camouflage on the key areas of the traffic aggregation matrix based on the information key area feature file to obtain camouflaged network traffic data.

2. The CAM-based anti-fingerprinting defense method according to claim 1, characterized in that: The traffic characteristics of the original network traffic data include: the number of data packets, the direction of the data packets and the timestamp of the data packets; the traffic aggregation matrix is ​​a matrix with two rows and N columns, N is the number of time slots, each data in the first row represents the number of data packets sent in a unit time slot, and each data in the second row represents the number of data packets received in a unit time slot.

3. The CAM-based anti-fingerprinting defense method according to claim 1, characterized in that: Calling the CAM importance score generation script to generate an importance score, and generating an information key area feature file for the traffic aggregation matrix based on the importance score, specifically including: Calling the CAM importance score generation script to generate importance scores, using the class activation feature map to calculate the key areas of the traffic aggregation matrix, thereby generating a CAM score map; Based on the CAM score map and the pre-trained website fingerprint recognition model, an information key area feature file is generated for the traffic aggregation matrix; the pre-trained website fingerprint recognition model is a convolutional neural network trained in advance based on the traffic aggregation matrix of the original network traffic data, and the pre-trained website fingerprint recognition model is used to identify the website fingerprint recognition results when the original network traffic data is not protected.

4. The CAM-based anti-fingerprinting defense method according to claim 1, characterized in that: Also includes: Use a data set partitioning script to partition the traffic aggregation matrix of the original network traffic data to obtain a training data set and a test data set; The test data set is used to test the prediction performance of the pre-trained website fingerprint recognition model; A model training script is called to train a convolutional neural network based on the training data set to obtain a pre-trained website fingerprint recognition model.

5. The CAM-based anti-fingerprint identification defense method according to claim 1, characterized in that: The traffic feature camouflage algorithm includes: a combination of one or more of a random time perturbation algorithm, a data packet dynamic filling algorithm, and a data packet merging and splitting algorithm.

6. The CAM-based anti-fingerprinting defense method according to claim 5, characterized in that: The random time perturbation algorithm inserts a 2% random time offset in the key area of ​​the traffic aggregation matrix, so that the time of sending data packets has a random 2% sending time difference; The dynamic data packet filling algorithm is to target any key area of ​​the traffic aggregation matrix and use the key area as the current key area; In another random key region of the traffic aggregation matrix, selecting a value that conforms to a normal distribution as a filling value of the current key region; The packet merging and splitting algorithm randomly merges and splits the sent data packets. When merging data packets, it ensures that the directions of the two merged data packets are the same. When splitting data packets, the sizes of the split data packets are divided according to a set ratio, and a small time interval is introduced between each split data packet.

7. A CAM-based anti-fingerprint recognition defense system, characterized in that: include: The traffic collection and preprocessing module is used to obtain raw network traffic data and analyze the traffic characteristics of the raw network traffic data to obtain a traffic aggregation matrix; The traffic aggregation matrix is ​​used to characterize the transmission characteristics of all data packets in each time slot; A key feature area extraction module is used to call the CAM importance score generation script to generate an importance score, and generate an information key area feature file for the traffic aggregation matrix based on the importance score; the importance score is used to represent the degree of attention paid by the website fingerprint recognition model to each area in the traffic aggregation matrix when making predictions; the information key area feature file is the key area extracted from the traffic aggregation matrix based on the importance score; The dynamic traffic camouflage module is used to adopt multiple traffic feature camouflage algorithms and perform traffic camouflage on the key areas of the traffic aggregation matrix based on the information key area feature file to obtain camouflaged network traffic data.

8. A computer device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the CAM-based anti-fingerprint recognition defense method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the CAM-based anti-fingerprint identification defense method according to any one of claims 1 to 6 is implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the CAM-based anti-fingerprint identification defense method according to any one of claims 1 to 6 is implemented.