An encryption traffic identification analysis method based on dominant features

By analyzing the characteristics, time, and packet length feature matrix of network traffic data, the advantageous features of encrypted traffic can be identified, solving the problem of difficulty in identifying encrypted traffic, achieving efficient and accurate encrypted traffic management, and improving network security.

CN121193477BActive Publication Date: 2026-05-29BEIJING QITIAN ANXIN TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING QITIAN ANXIN TECH CO LTD
Filing Date
2025-09-17
Publication Date
2026-05-29

Smart Images

  • Figure CN121193477B_ABST
    Figure CN121193477B_ABST
Patent Text Reader

Abstract

The application provides a kind of advantage feature-based traffic identification analysis method, belongs to data analysis technical field, comprising: determining first feature based on the obtained network traffic data, determining first traffic based on first feature;Determine time feature matrix by analyzing the timestamp of all data packets in first traffic, at the same time, determine packet length feature matrix by analyzing the length of all data packets in first traffic;Determine correlation matrix based on time feature matrix, packet length feature matrix, determine the advantage feature of network traffic data based on correlation matrix.Can efficiently and accurately classify network traffic data, improve the first traffic analysis speed, quickly respond to network anomalies and attacks, dynamically adjust the advantage feature according to network traffic data, improve the effectiveness and practicality of traffic identification analysis, realize the fine management of encrypted traffic, and ensure the safe operation of network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data analysis technology, and in particular to a method for identifying and analyzing encrypted traffic based on advantageous features. Background Technology

[0002] Traffic identification and analysis plays a crucial role in modern network management and security, with wide applications in enterprise network management, cloud computing and data centers, the Internet of Things, and smart cities. The rapid development of the internet has led to increasingly diverse and complex traffic patterns, and the rising proportion of encrypted traffic poses challenges to network security, including difficulties in identifying encrypted traffic, slow identification speeds, poor accuracy, and low real-time performance.

[0003] Therefore, the present invention provides a method for identifying and analyzing encrypted traffic based on advantageous features. Summary of the Invention

[0004] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features. It determines a first feature and a first flow by parsing network traffic data, analyzes the first flow to determine a time feature matrix and a packet length feature matrix, and determines a correlation matrix. This method identifies the advantageous features of network traffic data, which can improve the effectiveness and practicality of traffic identification and analysis, achieve refined management of encrypted traffic, and ensure the safe operation of the network.

[0005] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features, comprising:

[0006] S101: Determine a first feature based on the acquired network traffic data, and determine a first traffic based on the first feature;

[0007] S102: Analyze the timestamps of all data packets in the first traffic to determine the time feature matrix; at the same time, analyze the lengths of all data packets in the first traffic to determine the packet length feature matrix.

[0008] S103: Determine the correlation matrix based on the time feature matrix and packet length feature matrix, and determine the advantageous features of network traffic data based on the correlation matrix.

[0009] According to the present invention, an encrypted traffic identification and analysis method based on advantageous features is provided, which determines a first feature based on acquired network traffic data, and determines a first traffic based on the first feature, including:

[0010] The network traffic data is parsed using a protocol parser, and the header information and payload data of each data packet at the protocol layer are extracted to determine the first feature. The network traffic data includes at least one or more data packets, and the first feature includes the source IP address, destination IP address, source port, destination port, and protocol type.

[0011] The network traffic data is classified based on the first feature. All data packets under each category are sorted according to their corresponding sequence number and timestamp to determine the first sub-traffic. The first traffic is determined based on all the first sub-traffic.

[0012] According to the present invention, an encrypted traffic identification and analysis method based on advantageous features is provided, which analyzes the timestamps of all data packets in a first traffic flow to determine a time feature matrix, including:

[0013] Extract the timestamps of all data packets in the first traffic flow, and determine the earliest and latest timestamps;

[0014] The sliding window is determined based on the number of data packets in the first traffic, the earliest timestamp, and the latest timestamp.

[0015] Calculate the number of data packets in each sliding window for the first sub-flow, select the sliding window with the most data packets as the peak period of the corresponding first sub-flow, and select the sliding window with the fewest data packets as the trough period of the corresponding first sub-flow.

[0016] The temporal feature matrix of the first sub-flow is determined based on the peak and trough periods of each first sub-flow and the timestamps of all data packets in the first sub-flow.

[0017] A method for identifying and analyzing encrypted traffic based on advantageous features, provided by the present invention, includes:

[0018] Determine the time feature matrix of the first flow ;

[0019] ;

[0020] ;

[0021] Where N1 represents the number of the first sub-flows in the first flow. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 1, respectively. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 2, respectively, and so on. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow N1, respectively. Let S = 1, 2, ..., N1, where SN2 represents the time interval characteristics of the first sub-flow S, SN3 and SN4 represent the number of data packets in the peak and off-peak periods of the first sub-flow S, respectively. Let these represent the timestamps of the (i+1)th and ith packets in the first sub-traffic S, respectively. Let and represent the timestamps of the (j+1)th and jth data packets respectively in the peak characteristics of the first sub-traffic S. Let and represent the timestamps of the (k+1)th and (k)th data packets respectively in the trough characteristic of the first sub-traffic S. The weights representing the peak characteristics of the first sub-flow S are... The weights representing the trough characteristics of the first sub-flow S. Let S represent the weighted number of data packets in the peak and trough characteristics of the first sub-traffic S, respectively. .

[0022] According to the present invention, an encrypted traffic identification and analysis method based on advantageous features is provided, which analyzes the length of all data packets in a first traffic flow to determine a packet length feature matrix, including:

[0023] Extract the length of all data packets in the first traffic flow and determine the packet length range of the first traffic flow;

[0024] Based on the number of data packets in the first flow, the packet length range of the first flow is divided into Nh packet length intervals;

[0025] The minimum packet length and maximum packet length of the first sub-flow are determined based on the packet length of each packet in the first sub-flow.

[0026] The packet length feature matrix of the first sub-flow is determined based on the minimum packet length, maximum packet length, and h packet length intervals of each first sub-flow.

[0027] A method for identifying and analyzing encrypted traffic based on advantageous features, provided by the present invention, includes:

[0028] Determine the packet length feature matrix of the first flow ;

[0029] ;

[0030] ;

[0031] ;

[0032] in, These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 1, respectively. These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 2, respectively, and so on. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow N1, respectively. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow S, respectively. This represents the length of the i-th data packet in the first sub-flow S. Let represent the lower limit and upper limit of the packet length of the p-th packet length interval in the first traffic, respectively, and let SN2 represent the number of data packets in the first sub-traffic S. This represents the characteristic of the number of interval data packets in the p-th packet length interval of the first sub-flow S. , , Indicates that the length of the i-th data packet in the first sub-flow S is in [ , The value is 1 when the packet length interval is within the specified range. The value is 0 when the length of the i-th data packet in the first sub-flow S is less than the lower limit of the length of the p-th data packet. The value is 0 when the length of the i-th data packet in the first sub-flow S is greater than or equal to the upper limit of the p-th packet length interval.

[0033] According to the present invention, an encrypted traffic identification and analysis method based on advantageous features determines a correlation matrix based on a time feature matrix and a packet length feature matrix, including:

[0034] The time feature matrix and packet length feature matrix are normalized, and the second feature matrix is ​​determined based on the normalized time feature matrix and packet length feature matrix.

[0035] Calculate the correlation value between every two features under the same first sub-flow based on the second feature matrix;

[0036] The correlation matrix is ​​determined based on the correlation values ​​between every two features under the same first sub-flow.

[0037] According to the present invention, an encrypted traffic identification and analysis method based on dominant features determines the dominant features of network traffic data based on a correlation matrix, including:

[0038] Sub-dominant features based on the first sub-flow are extracted based on the correlation matrix. When the correlation values ​​of two features of the first sub-flow based on the correlation matrix are in the range of (0, 1), the two features are determined to be sub-dominant features of the first sub-flow, and the extracted sub-dominant features are counted.

[0039] The count values ​​of the sub-dominant features of the first sub-flow are sorted from largest to smallest, and the dominant feature vector of the first sub-flow is determined based on the sorted order.

[0040] The dominant features of network traffic data are determined based on the dominant feature vectors of all first sub-traffic.

[0041] Compared with the prior art, the beneficial effects of this application are as follows:

[0042] By analyzing network traffic data to determine the primary features and primary traffic, analyzing the primary traffic to determine the time feature matrix and packet length feature matrix, and determining the correlation matrix, the advantageous features of network traffic data can be identified. This allows for efficient and accurate classification of network traffic data, improving the speed of primary traffic analysis, enabling rapid response to network anomalies and attacks, and dynamically adjusting advantageous features based on network traffic data to enhance the effectiveness and practicality of traffic identification and analysis. This achieves refined management of encrypted traffic and ensures the safe operation of the network. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0044] Figure 1 This is a flowchart illustrating an encrypted traffic identification and analysis method based on advantageous features provided in an embodiment of the present invention. Detailed Implementation

[0045] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0046] Example 1:

[0047] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features, such as... Figure 1 As shown, it includes:

[0048] S101: Determine a first feature based on the acquired network traffic data, and determine a first traffic based on the first feature;

[0049] S102: Analyze the timestamps of all data packets in the first traffic to determine the time feature matrix; at the same time, analyze the lengths of all data packets in the first traffic to determine the packet length feature matrix.

[0050] S103: Determine the correlation matrix based on the time feature matrix and packet length feature matrix, and determine the advantageous features of network traffic data based on the correlation matrix.

[0051] In this embodiment, network traffic data represents the collection of data packets transmitted through a computer network.

[0052] In this embodiment, network traffic data can be obtained through network interfaces, intermediate devices, and terminal devices. For example, it can be directly captured on network devices such as routers and switches through network interface cards such as Network Interface Cards (NICs); captured on network intermediate devices such as firewalls and intrusion detection systems; or captured on local devices using software tools such as Wireshark.

[0053] In this embodiment, each row of the time feature matrix represents a first sub-flow, and each column represents a feature of the first flow based on time.

[0054] In this embodiment, each row of the packet length feature matrix represents a first sub-flow, and each column represents a feature of the first flow based on the packet length.

[0055] The beneficial effects of the above technical solution are as follows: by parsing network traffic data to determine the first feature and the first traffic, analyzing the first traffic to determine the time feature matrix and packet length feature matrix, and determining the correlation matrix, the advantageous features of network traffic data can be identified. This allows for efficient and accurate classification of network traffic data, improves the speed of first traffic analysis, enables rapid response to network anomalies and attacks, and dynamically adjusts the advantageous features based on network traffic data, thereby improving the effectiveness and practicality of traffic identification and analysis, achieving refined management of encrypted traffic, and ensuring the safe operation of the network.

[0056] Example 2:

[0057] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features. The method determines a first feature based on acquired network traffic data, and then determines a first traffic flow based on the first feature. The method includes:

[0058] The network traffic data is parsed using a protocol parser, and the header information and payload data of each data packet at the protocol layer are extracted to determine the first feature. The network traffic data includes at least one or more data packets, and the first feature includes the source IP address, destination IP address, source port, destination port, and protocol type.

[0059] The network traffic data is classified based on the first feature. All data packets under each category are sorted according to their corresponding sequence number and timestamp to determine the first sub-traffic. The first traffic is determined based on all the first sub-traffic.

[0060] In this embodiment, parsing network traffic data means parsing binary network traffic data into a human-readable and analyzable text data structure.

[0061] In this embodiment, the protocol layer includes the link layer, network layer, transport layer, application layer, etc.

[0062] Parse the link layer to extract the MAC address and frame type; parse the network layer to extract the source IP address, destination IP address, TTL, and protocol type; parse the transport layer to extract the source port, destination port, sequence number, acknowledgment number, and flags; parse the application layer protocol to extract the specific application protocol.

[0063] In this embodiment, a data packet represents the basic unit of network communication.

[0064] In this embodiment, the sequence number represents a unique identifier for the data packet during transmission.

[0065] In this embodiment, the timestamp represents the time recorded when the data packet arrives.

[0066] In this embodiment, each category corresponds to a first sub-traffic, and the first sub-traffic contains data packets with identical first characteristics.

[0067] In this embodiment, a first sub-traffic is equivalent to a complete session, which includes all data packets from the three-way handshake to the four-way handshake.

[0068] The beneficial effects of the above technical solution are as follows: by determining the first feature based on the acquired network traffic data, and by determining the first traffic based on the first feature, the network traffic data can be effectively classified, the recognition effect can be improved, and the speed of network traffic data processing and analysis can be increased.

[0069] Example 3:

[0070] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features. The method analyzes the timestamps of all data packets in a first traffic stream to determine a time feature matrix, including:

[0071] Extract the timestamps of all data packets in the first traffic flow, and determine the earliest and latest timestamps;

[0072] The sliding window is determined based on the number of data packets in the first traffic, the earliest timestamp, and the latest timestamp.

[0073] Calculate the number of data packets in each sliding window for the first sub-flow, select the sliding window with the most data packets as the peak period of the corresponding first sub-flow, and select the sliding window with the fewest data packets as the trough period of the corresponding first sub-flow.

[0074] The temporal feature matrix of the first sub-flow is determined based on the peak and trough periods of each first sub-flow and the timestamps of all data packets in the first sub-flow.

[0075] In this embodiment, the timestamp represents the time when the corresponding data packet arrived.

[0076] In this embodiment, the earliest timestamp represents the timestamp of the earliest arriving data packet among all data in the first flow.

[0077] In this embodiment, the latest timestamp represents the timestamp of the latest data packet that arrives among all data in the first traffic.

[0078] In this embodiment, the sliding window refers to using a fixed-length window to slide along the timeline between the earliest and latest timestamps, moving a fixed step each time.

[0079] In this embodiment, each first sub-flow corresponds to a peak period and a trough period.

[0080] The beneficial effects of the above technical solution are as follows: by determining the earliest and latest timestamps and the sliding window to identify the peak and trough periods of the first sub-traffic, and by determining the time feature matrix, the dynamic changes of the first traffic can be captured, and abnormal traffic patterns can be identified in a timely and effective manner, thereby improving the accuracy of traffic identification.

[0081] Example 4:

[0082] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features, comprising:

[0083] Determine the time feature matrix of the first flow ;

[0084] ;

[0085] ;

[0086] Where N1 represents the number of the first sub-flows in the first flow. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 1, respectively. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 2, respectively, and so on. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow N1, respectively. Let S = 1, 2, ..., N1, where SN2 represents the time interval characteristics of the first sub-flow S, SN3 and SN4 represent the number of data packets in the peak and off-peak periods of the first sub-flow S, respectively. Let these represent the timestamps of the (i+1)th and ith packets in the first sub-traffic S, respectively. Let and represent the timestamps of the (j+1)th and jth data packets respectively in the peak characteristics of the first sub-traffic S. Let and represent the timestamps of the (k+1)th and (k)th data packets respectively in the trough characteristic of the first sub-traffic S. The weights representing the peak characteristics of the first sub-flow S are... The weights representing the trough characteristics of the first sub-flow S. Let S represent the weighted number of data packets in the peak and trough characteristics of the first sub-traffic S, respectively. .

[0087] In this embodiment, the time feature matrix It is an N1×3 matrix.

[0088] In this embodiment, the time feature matrix It includes the time-based peak characteristics, trough characteristics, and time interval characteristics of N1 first sub-flows.

[0089] In this embodiment, the peak period feature represents the peak period corresponding to the first sub-flow.

[0090] In this embodiment, the trough period feature represents the trough period corresponding to the first sub-flow.

[0091] In this embodiment, This represents the time interval consisting of the timestamp of the (i+1)th data packet and the timestamp of the ith data packet in the first sub-flow S.

[0092] In this embodiment, This represents the time interval consisting of the timestamp of the (j+1)th data packet and the timestamp of the jth data packet during the peak period of the first sub-traffic S.

[0093] In this embodiment, This represents the time interval consisting of the timestamp of the (k+1)th data packet and the timestamp of the kth data packet during the peak period of the first sub-traffic S.

[0094] The beneficial effects of the above technical solution are as follows: the time feature matrix of the first traffic is calculated based on the peak and trough periods of each first sub-traffic and the timestamps of all data packets in the first sub-traffic, which can intuitively display the time characteristics of the first traffic, improve the effect of dense traffic identification and analysis, and enhance the accuracy, efficiency and real-time performance of network traffic analysis.

[0095] Example 5:

[0096] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features. The method analyzes the length of all data packets in a first traffic stream to determine a packet length feature matrix, including:

[0097] Extract the length of all data packets in the first traffic flow and determine the packet length range of the first traffic flow;

[0098] Based on the number of data packets in the first flow, the packet length range of the first flow is divided into Nh packet length intervals;

[0099] The minimum packet length and maximum packet length of the first sub-flow are determined based on the packet length of each packet in the first sub-flow.

[0100] The packet length feature matrix of the first sub-flow is determined based on the minimum packet length, maximum packet length, and h packet length intervals of each first sub-flow.

[0101] In this embodiment, the length of the data packet represents the size of the data packet, which can be expressed in bytes.

[0102] In this embodiment, the packet length range represents the interval consisting of the minimum and maximum packet lengths in the first flow.

[0103] In this embodiment, the more data packets there are in the first traffic, the more packet length intervals are divided, and the smaller the interval range is.

[0104] In this embodiment, the minimum packet length refers to the packet with the smallest length among all data packets in the first sub-flow.

[0105] In this embodiment, the maximum packet length refers to the packet length with the largest length among all data packets in the first sub-flow.

[0106] The beneficial effects of the above technical solution are as follows: by determining the packet length range, packet length interval, minimum packet length, and maximum packet length of the first flow, and by determining the packet length feature matrix of the first flow, the packet length characteristics of the first flow can be analyzed, thereby achieving differentiated identification of dense flows and improving the accuracy of dense flow identification.

[0107] Example 6:

[0108] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features, comprising:

[0109] Determine the packet length feature matrix of the first flow ;

[0110] ;

[0111] ;

[0112] ;

[0113] in, These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 1, respectively. These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 2, respectively, and so on. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow N1, respectively. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow S, respectively. This represents the length of the i-th data packet in the first sub-flow S. Let represent the lower limit and upper limit of the packet length of the p-th packet length interval in the first traffic, respectively, and let SN2 represent the number of data packets in the first sub-traffic S. This represents the characteristic of the number of interval data packets in the p-th packet length interval of the first sub-flow S. , , Indicates that the length of the i-th data packet in the first sub-flow S is in [ , The value is 1 when the packet length interval is within the specified range. The value is 0 when the length of the i-th data packet in the first sub-flow S is less than the lower limit of the length of the p-th data packet. The value is 0 when the length of the i-th data packet in the first sub-flow S is greater than or equal to the upper limit of the p-th packet length interval.

[0114] In this embodiment, the packet length feature matrix It is an N1×(Nh+3) matrix.

[0115] In this embodiment, the time feature matrix It includes N1 first sub-traffic features based on packet length, including maximum packet length feature, minimum packet length feature, average packet length feature, and Nh interval packet quantity features.

[0116] In this embodiment, the maximum packet length feature represents the maximum packet length corresponding to the first sub-flow.

[0117] In this embodiment, the minimum packet length feature represents the minimum packet length corresponding to the first sub-flow.

[0118] In this embodiment, the average packet length feature represents the average packet length of all data packets in the corresponding first sub-traffic.

[0119] In this embodiment, the interval data packet quantity feature represents the number of data packets in different packet length intervals within the corresponding first sub-traffic.

[0120] In this embodiment, each first sub-traffic includes a maximum packet length feature, a minimum packet length feature, an average packet length feature, and Nh interval packet quantity features.

[0121] The beneficial effects of the above technical solution are as follows: the packet length feature matrix of the first traffic is calculated based on the minimum packet length, maximum packet length, and h packet length intervals of each first sub-traffic flow, which can intuitively display the packet length characteristics of the first traffic flow, further improve the effect of dense traffic identification and analysis, and further enhance the accuracy, efficiency, and real-time performance of network traffic analysis.

[0122] Example 7:

[0123] This invention provides a method for identifying and analyzing encrypted traffic based on advantageous features, which determines a correlation matrix based on a time feature matrix and a packet length feature matrix, including:

[0124] The time feature matrix and packet length feature matrix are normalized, and the second feature matrix is ​​determined based on the normalized time feature matrix and packet length feature matrix.

[0125] Calculate the correlation value between every two features under the same first sub-flow based on the second feature matrix;

[0126] The correlation matrix is ​​determined based on the correlation values ​​between every two features under the same first sub-flow.

[0127] In this embodiment, normalization means unifying the time-based features in the time feature matrix and the packet length-based features in the packet length feature matrix to the same scale.

[0128] In this embodiment, the second feature matrix is ​​an N1×(Nh+6) matrix.

[0129] In this embodiment, the second feature matrix includes N1 time-based peak period features, trough period features, and time interval features after normalization of the first sub-traffic, as well as maximum packet length features, minimum packet length features, and average packet length features based on packet length, and Nh interval data packet quantity features.

[0130] In this embodiment, the correlation value represents a measure of the degree of correlation between any two features under the same first sub-flow, ranging from -1 to 1.

[0131] In this embodiment, the correlation matrix visualizes all correlation values, representing a measure of the degree of correlation between every two features under the same first sub-flow.

[0132] The beneficial effects of the above technical solution are as follows: by determining the correlation matrix based on the time feature matrix and the packet length feature matrix, the time-based and packet length-based features of the first traffic can be standardized, improving the robustness and accuracy of traffic identification and realizing refined management of encrypted traffic.

[0133] Example 8:

[0134] This invention provides a method for identifying and analyzing encrypted traffic based on dominant features. The method determines the dominant features of network traffic data based on a correlation matrix, including:

[0135] Sub-dominant features based on the first sub-flow are extracted based on the correlation matrix. When the correlation values ​​of two features of the first sub-flow based on the correlation matrix are in the range of (0, 1), the two features are determined to be sub-dominant features of the first sub-flow, and the extracted sub-dominant features are counted.

[0136] The count values ​​of the sub-dominant features of the first sub-flow are sorted from largest to smallest, and the dominant feature vector of the first sub-flow is determined based on the sorted order.

[0137] The dominant features of network traffic data are determined based on the dominant feature vectors of all first sub-traffic.

[0138] In this embodiment, the sub-advantage features include multiple pairs of features with correlation values ​​in the range of (0, 1). For each occurrence of a time-based feature or a packet-length-based feature, the feature count is incremented by 1.

[0139] In this embodiment, the count value represents the number of times each feature is identified as a sub-dominant feature. The higher the count value, the more important the corresponding feature is in the analysis of the first sub-flow.

[0140] In this embodiment, the dominant feature vector represents the most representative set of features in the corresponding first sub-flow analysis.

[0141] In this embodiment, each first sub-flow corresponds to a sub-advantage feature and an advantage feature vector.

[0142] In this embodiment, the dominant features represent the set of features that are most representative in network traffic data analysis.

[0143] The beneficial effects of the above technical solution are as follows: By determining the sub-advantage features and advantage feature vectors of each first sub-traffic, the advantageous features of network traffic data can be identified. This allows for efficient and accurate classification of network traffic data, improved first-traffic analysis speed, rapid response to network anomalies and attacks, dynamic adjustment of advantage features based on network traffic data, enhanced effectiveness and practicality of traffic identification and analysis, refined management of encrypted traffic, and protection of network security.

[0144] The method embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0145] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0146] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for identifying and analyzing encrypted traffic based on advantageous features, characterized in that, include: S101: Based on the protocol parser, parse the network traffic data, extract the header information and payload data of each data packet protocol layer to determine the first feature, wherein the network traffic data includes at least one or more data packets, and the first feature includes the source IP address, destination IP address, source port, destination port and protocol type; classify the network traffic data based on the first feature, sort all data packets under each category based on the corresponding sequence number and timestamp to determine the first sub-traffic, and determine the first traffic based on all the first sub-traffic; S102: Extract the timestamps of all data packets in the first traffic and determine the earliest and latest timestamps; determine a sliding window based on the number of data packets, the earliest timestamp, and the latest timestamp in the first traffic; calculate the number of data packets in each sliding window for the first sub-traffic, select the sliding window with the most data packets as the peak period of the corresponding first sub-traffic, and select the sliding window with the fewest data packets as the trough period of the corresponding first sub-traffic; determine the time feature matrix of the first traffic based on the peak period, trough period, and timestamps of all data packets in each first sub-traffic. S103: Determine the correlation matrix based on the time feature matrix and packet length feature matrix, and determine the advantageous features of network traffic data based on the correlation matrix; Among them, the advantageous characteristics of network traffic data determined based on the correlation matrix include: Sub-dominant features based on the first sub-flow are extracted based on the correlation matrix. When the correlation values ​​of two features of the first sub-flow based on the correlation matrix are in the range of (0, 1), the two features are determined to be sub-dominant features of the first sub-flow, and the extracted sub-dominant features are counted. The count values ​​of the sub-dominant features of the first sub-flow are sorted from largest to smallest, and the dominant feature vector of the first sub-flow is determined based on the sorted order. The dominant features of network traffic data are determined based on the dominant feature vectors of all first sub-traffic.

2. The encrypted traffic identification and analysis method based on advantageous features according to claim 1, characterized in that, Determine the time feature matrix of the first flow ; ; ; Where N1 represents the number of the first sub-flows in the first flow. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 1, respectively. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow 2, respectively, and so on. These represent the peak period characteristics, trough period characteristics, and time interval characteristics of the first sub-flow N1, respectively. Let S = 1, 2, ..., N1, where SN2 represents the time interval characteristics of the first sub-flow S, SN3 and SN4 represent the number of data packets in the peak and off-peak periods of the first sub-flow S, respectively. Let these represent the timestamps of the (i+1)th and ith packets in the first sub-traffic S, respectively. Let and represent the timestamps of the (j+1)th and jth data packets respectively in the peak characteristics of the first sub-traffic S. Let and represent the timestamps of the (k+1)th and (k)th data packets respectively in the trough characteristic of the first sub-traffic S. The weights representing the peak characteristics of the first sub-flow S are... The weights representing the trough characteristics of the first sub-flow S. Let S represent the weighted number of data packets in the peak and trough characteristics of the first sub-traffic S, respectively. .

3. The encrypted traffic identification and analysis method based on advantageous features according to claim 1, characterized in that, Analyze the lengths of all data packets in the first traffic stream to determine the packet length feature matrix, including: Extract the length of all data packets in the first traffic flow and determine the packet length range of the first traffic flow; Based on the number of data packets in the first flow, the packet length range of the first flow is divided into Nh packet length intervals; The minimum packet length and maximum packet length of the first sub-flow are determined based on the packet length of each packet in the first sub-flow. The packet length feature matrix of the first sub-flow is determined based on the minimum packet length, maximum packet length, and Nh packet length intervals of each first sub-flow.

4. The encrypted traffic identification and analysis method based on advantageous features according to claim 3, characterized in that, Determine the packet length feature matrix of the first flow ; ; ; ; in, These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 1, respectively. These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow 2, respectively, and so on. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow N1, respectively. , These represent the maximum packet length feature, minimum packet length feature, and average packet length feature of the first sub-flow S, respectively. This represents the length of the i-th data packet in the first sub-flow S. Let represent the lower limit and upper limit of the packet length of the p-th packet length interval in the first traffic, respectively, and let SN2 represent the number of data packets in the first sub-traffic S. This represents the characteristic of the number of interval data packets in the p-th packet length interval of the first sub-flow S. , , Indicates that the length of the i-th data packet in the first sub-flow S is in [ , The value is 1 when the packet length interval is within the specified range. The value is 0 when the length of the i-th data packet in the first sub-flow S is less than the lower limit of the length of the p-th data packet. The value is 0 when the length of the i-th data packet in the first sub-flow S is greater than or equal to the upper limit of the length interval of the p-th data packet.

5. The encrypted traffic identification and analysis method based on advantageous features according to claim 4, characterized in that, The correlation matrix is ​​determined based on the time feature matrix and the packet length feature matrix, including: The time feature matrix and packet length feature matrix are normalized, and the second feature matrix is ​​determined based on the normalized time feature matrix and packet length feature matrix. Calculate the correlation value between every two features under the same first sub-flow based on the second feature matrix; The correlation matrix is ​​determined based on the correlation values ​​between every two features under the same first sub-flow.