A DPI-based network traffic identification method, device, and medium
By constructing a bidirectional session flow and performing multi-layer closure discrimination, the problems of insufficient traffic process representation and insufficient identification stability in network traffic identification are solved, achieving higher identification accuracy and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BYZORO NETWORK LTD
- Filing Date
- 2026-04-16
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies for network traffic identification suffer from insufficient representation of traffic processes and inadequate stability in complex traffic scenarios. In particular, they do not pay enough attention to boundary changes during the internal communication phase of bidirectional session flows, resulting in room for improvement in the stability and accuracy of identification results.
By collecting raw network packets to construct a bidirectional session stream, out-of-order recovery, retransmission deduplication, and fragment reassembly are performed. Changes in application layer fields, packet length ranges, and uplink/downlink dominant directions are extracted to generate a sequence of communication change events. Communication stages are divided by anchoring transition events, trimming local change events, and merging shortest stage constraints. Stage structure representation parameters are extracted to generate a set of stage stream fragments. Multi-level closure discrimination is then performed to determine the final service category.
It improves the continuity of traffic representation and the accuracy of event extraction, enhances the stability of stage boundary identification and the completeness of stage structure expression, and improves the accuracy and reliability of network traffic identification.
Smart Images

Figure CN122053416B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network management technology, and in particular to a network traffic identification method, device and medium based on DPI. Background Technology
[0002] In network management and service awareness scenarios, network traffic identification is a crucial foundation for supporting traffic scheduling, behavior analysis, service assurance, and security control. Conventional technologies typically parse and classify network packets using port numbers, protocol fields, packet statistical features, or deep packet inspection to identify the service type or application category to which the traffic belongs. As network service models continue to evolve, existing technologies are gradually incorporating techniques such as session reassembly, protocol feature extraction, encrypted handshake identification, and template matching to enhance identification capabilities in complex network environments. Therefore, DPI-based network traffic identification methods have become an important implementation path in the field of network traffic analysis.
[0003] However, analysis of the technical solution of this invention reveals that conventional methods still have room for further optimization in two aspects. First, conventional methods often rely on single-message characteristics or rectification statistics for identification, paying insufficient attention to boundary changes in the communication stages within a bidirectional session flow, thus resulting in inadequate representation of the traffic process. Second, when faced with traffic that lacks structure, experiences stage disturbances, or has similar service patterns, conventional methods typically lack an identification mechanism that differentiates each stage layer by layer, leading to room for improvement in the stability and accuracy of traffic identification results. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, this invention provides a DPI-based network traffic identification method to solve the problems of insufficient traffic process representation and insufficient identification stability in complex traffic scenarios in existing technologies.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, the present invention provides a network traffic identification method based on DPI, comprising: collecting raw network packets, constructing a bidirectional session flow according to a five-tuple and session timeout rules, performing out-of-order recovery, retransmission deduplication, and fragment reassembly on the bidirectional session flow, and using DPI parsing to extract application layer field changes, packet length range changes, uplink and downlink dominant direction changes, and adjacent packet time interval changes to generate a communication change event sequence; based on the communication change event sequence, dividing the bidirectional session flow into communication stages through transition event anchoring, local change event trimming, and shortest stage constraint merging, extracting stage structure characterization parameters for each communication stage, and generating a set of stage flow pattern fragments; and selecting target completion stages based on the structural closure state of each stage flow pattern fragment. The process involves extracting adjacency handshake metadata, first packet contour, stage persistence features, and byte distribution stability features from the target completion stage. Restricted completion is performed on missing structural items to generate a complete set of stage manifolds. The complete set of stage manifolds is then standardized and aligned according to the stage type sequence to construct stage-constrained manifold fingerprints. Candidate service manifold templates are clustered based on the number of stages, the first stage type, and the transport layer type. Intra-stage closure discrimination, inter-stage transition closure discrimination, and accompaniment relationship closure discrimination are then performed sequentially to determine the final service category and stage-constrained manifold fingerprint. Based on the stage-constrained manifold fingerprint, similar categories are merged according to service category and standard stage sequence skeleton. Stable structural kernels are extracted, template stability gating is applied, and stable service manifold templates and feedback call indexes are generated.
[0008] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the construction of the bidirectional session flow includes: receiving original network packets at the mirror acquisition location of the target network link, reading the arrival time, source address, destination address, source port, destination port, transport layer type, total packet length, and link direction identifier, and generating an original packet registration record; generating a mirror merging key based on the 5-tuple, arranging the original network packets with the same mirror merging key in ascending order of arrival time to form a candidate packet sequence, and segmenting them according to the bidirectional session timeout threshold to obtain the bidirectional session flow.
[0009] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the generation of the communication change event sequence includes: performing out-of-order recovery, retransmission deduplication, and fragmentation reassembly on the bidirectional session stream, and filtering the normalized bidirectional session stream according to the normalization integrity; performing DPI parsing on the normalized bidirectional session stream packet by packet, extracting the application layer field change amount, packet length range change amount, uplink and downlink dominant direction change amount, and adjacent packet time interval change amount, calculating the comprehensive change intensity and discretizing it to generate the communication change event sequence.
[0010] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the generation of the stage flow pattern fragment set includes: establishing an event location index table based on bidirectional session flows; filtering significant transition events; retaining significant transition events that have consecutive local change events and maintain positional connection with significant transition events as effective anchor points to form initial stage candidate segments; performing boundary trimming centered on effective anchor points; merging excessively short stages according to stage span thresholds to obtain the final communication stage set; extracting field category distribution, median message length, stage duration, uplink and downlink byte distribution, and direction dominant change rate for each final communication stage to form stage flow pattern fragments, and arranging them in chronological order to generate the stage flow pattern fragment set.
[0011] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the generation of a complete stage flow pattern set includes: based on the stage flow pattern fragment set, selecting target completion stages according to the stage structure closure state of each stage flow pattern fragment; recording stage flow pattern fragments in which all necessary structural items have been successfully extracted as directly retained stages; recording stage flow pattern fragments in which necessary structural items are missing and stage boundaries have been determined as target completion stages; extracting adjacency handshake information, first packet contour, stage persistence features, and byte distribution stability features from the target completion stages, and performing restricted completion on missing items in field category distribution, first packet contour, stage persistence features, and byte distribution stability features; recording the target completion stages as stable completion stages, restricted retention stages, or weak evidence retention stages through consistency verification; unifying the directly retained stages and the completed stages into complete stage flow pattern units, and arranging them in chronological order to generate a complete stage flow pattern set.
[0012] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the determination of the final service category and stage-constrained flow fingerprint includes: performing standardized alignment on the complete stage flow set according to the stage type sequence to obtain a standard stage sequence, connecting each stage in the standard stage sequence in chronological order, and constructing a stage-constrained flow fingerprint by combining the transition relationship between adjacent standard stages; performing candidate convergence on the service flow template library based on the number of stages, the type of the first stage, and the transport layer type to obtain a candidate service flow template set; and sequentially performing intra-stage closure discrimination, inter-stage transition closure discrimination, and accompaniment relationship closure discrimination on the candidate service flow template set to determine the final service category and the confirmed stage-constrained flow fingerprint.
[0013] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the intra-phase closure discrimination, inter-phase transition closure discrimination, and accompaniment relationship closure discrimination include: calculating the intra-phase closure deviation index by comparing the current phase constraint flow pattern fingerprint with the intra-phase parameters of each standard phase, and deleting candidate service flow pattern templates whose intra-phase closure deviation index is greater than a first deviation threshold; calculating the inter-phase transition closure deviation index by comparing the phase transition parameters between adjacent standard phases, and deleting candidate service flow pattern templates whose inter-phase transition closure deviation index is greater than a second deviation threshold; calculating the accompaniment relationship closure deviation index by comparing the accompaniment relationship parameters of the target session and the associated session, and determining the final service category and the confirmed phase constraint flow pattern fingerprint based on the accompaniment relationship closure deviation index and a third deviation threshold.
[0014] As a preferred embodiment of the DPI-based network traffic identification method of the present invention, the generation of stable service flow pattern templates and feedback call indexes includes: performing similar merging on the confirmed stage constraint flow pattern fingerprints according to service category and standard stage sequence skeleton to form merged clusters; extracting recurring and consistent structural items within the merged clusters to form stable structural kernels, and reorganizing the stable structural kernels into service flow pattern templates to be solidified; gating the service flow pattern templates to be solidified according to the template stability, and solidifying the service flow pattern templates to be solidified with template stability not lower than the stability threshold as stable service flow templates; generating feedback call indexes for stable service flow templates, calculating feedback priority, and writing the feedback priority and feedback call indexes into the stable service flow template library.
[0015] In a second aspect, the present invention provides a computer device including a memory and a processor, wherein the memory stores a computer program, and the computer program, when executed by the processor, implements any step of the DPI-based network traffic identification method as described in the first aspect of the present invention.
[0016] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any step of the DPI-based network traffic identification method described in the first aspect of the present invention.
[0017] The beneficial effects of this invention are as follows: by collecting original network packets and constructing bidirectional session flows and extracting communication change event sequences, the continuity of traffic representation and the accuracy of event extraction are improved; by anchoring transition events, trimming local change events, merging shortest stage constraints, and limiting the completion of missing structural items, the stability of stage boundary identification and the completeness of stage structure expression are improved; by constructing stage constraint flow pattern fingerprints and performing multi-layer closure discrimination and stable service flow pattern template feedback calls, the accuracy, reliability, and efficiency of subsequent calls in network traffic identification are improved. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart of a DPI-based network traffic identification method.
[0020] Figure 2 A flowchart generated for communication change events.
[0021] Figure 3 This is a flowchart for generating stage flow patterns.
[0022] Figure 4 This is a flowchart of the manifold recognition feedback. Detailed Implementation
[0023] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0024] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0025] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0026] Reference Figures 1-4 This is one embodiment of the present invention, which provides a network traffic identification method based on DPI, including the following steps:
[0027] S1. Collect raw network packets, construct bidirectional session streams according to 5-tuples and session timeout rules, perform out-of-order recovery, retransmission deduplication, and fragmentation reassembly on the bidirectional session streams, and use DPI parsing to extract application layer field changes, packet length range changes, uplink and downlink dominant direction changes, and adjacent packet time interval changes to generate a communication change event sequence.
[0028] Collect raw network packets and construct a bidirectional session flow based on the five-tuple and session timeout rules.
[0029] Furthermore, at the mirror acquisition location of the target network link, raw network packets are continuously received. For each raw network packet, the arrival time, source address, destination address, source port, destination port, transport layer type, total packet length, and link direction identifier are read sequentially to generate a raw packet registration record.
[0030] The link direction identifier is determined by a fixed definition method, that is, the message consistent with the exit direction of the collection point is recorded as the uplink message, and the message consistent with the entry direction of the collection point is recorded as the downlink message.
[0031] A 5-tuple is constructed using the source address, destination address, source port, destination port, and transport layer type, and a mirror merge key is further generated. The mirror merge key is represented as:
[0032] ;
[0033] in, For mirror merge key, For the source address, For the destination address, For the source port, For destination port, This is the transport layer type.
[0034] It should be noted that the mirror merge key is used to merge round-trip packets from the same connection into the same candidate session;
[0035] Based on the mirror merge key, original network packets with the same mirror merge key are sorted in ascending order of arrival time to form a candidate packet sequence.
[0036] For candidate message sequences under the same mirror merge key, bidirectional session segmentation is performed according to the session timeout rule. Specifically, the arrival time difference between two adjacent messages is calculated and compared with the bidirectional session timeout threshold. When the arrival time difference between two adjacent messages is greater than the bidirectional session timeout threshold, the message is cut off at that point and a new bidirectional session stream is generated. The expression for the bidirectional session timeout threshold is:
[0037] ;
[0038] in, This is the timeout threshold for two-way sessions. Based on timeout duration, It is the ratio of the median interval of the most recent consecutive messages under the same mirror merge key to the baseline message sending interval.
[0039] It should be noted that, The baseline message transmission interval is obtained by taking the median of the time difference between two adjacent valid messages under the same mirror merge key in the historical network session samples and rounding it up.
[0040] After the segmentation is completed, the set of messages that are continuous and contain round-trip messages in each time interval is determined as a bidirectional session flow.
[0041] Perform out-of-order recovery, retransmission deduplication, and fragment reassembly on the bidirectional session stream.
[0042] Furthermore, the packets are first restored to their logical order according to their sequence identifiers in each direction, ensuring that the payloads in the same direction are logically continuous. Duplicate packets with the same sequential coverage and identical payload content are detected, and only valid packets that first enter the bidirectional session stream are retained to complete retransmission deduplication. For fragmented packets, the complete upper-layer packets are restored according to the fragment offset order. To quantify the session quality after normalization, a normalization integrity is defined, expressed as:
[0043] ;
[0044] in, For the normalization completeness of bidirectional session streams, To determine the number of valid messages retained after out-of-order recovery, deduplication, and reassembly, The number of packets that are identified as duplicate retransmissions and are therefore discarded. The number of messages that cannot be restored to their complete structure during the fragmentation and reassembly process and are recorded as incomplete.
[0045] When the normalization integrity is lower than the normalization threshold, the bidirectional session flow is recorded as a low-quality session flow; when it is not lower than the normalization threshold, the current bidirectional session flow is recorded as a normalized bidirectional session flow.
[0046] It should be noted that the normalization threshold is obtained by sorting the normalization completeness of historically confirmed business category samples in ascending order and taking the normalization completeness value corresponding to the 20% position of the sort. The value range is [0.70, 0.95]. In the session stream below the 20% position, the interference of out-of-order, retransmission and fragmentation incompleteness on the extraction of stage events is significantly increased, while the session stream above the 20% position can maintain the basic structural continuity.
[0047] DPI parsing is performed packet by packet in the order of message arrival for the normalized bidirectional session flow.
[0048] Furthermore, for messages with identifiable application layer protocols, the application layer field type, field value length, and field occurrence position are extracted; for messages whose application layer protocols cannot be fully identified, at least the payload length, transmission direction, and arrival time are extracted. For two adjacent valid messages within the same normalized bidirectional session stream, the application layer field change, message length range change, uplink / downlink dominant direction change, and adjacent message time interval change are constructed respectively. To ultimately converge to a unified event triggering criterion, real communication state transitions are extracted. Only when multiple types of changes in fields, length, direction, and delay occur simultaneously should a high-confidence change event be considered. If only one dimension fluctuates, the overall change intensity will not abnormally increase, thus suppressing the interference of occasional jitter on event extraction. The overall change intensity between two adjacent valid messages is defined as follows:
[0049] ;
[0050] in, For the first The first valid message and the first The overall change intensity among valid messages For the change in the field, This represents the variation in message length range. This represents the change in the dominant upward and downward directions. This represents the change in the time interval between adjacent messages.
[0051] It should be noted that the overall change intensity refers to the degree of change obtained by jointly characterizing the changes in fields, message length range, uplink and downlink dominant directions, and time interval between adjacent valid messages. It is used to reflect the degree of deviation of the current message from the previous communication state. When only a single dimension fluctuates, the overall change intensity is not used to characterize the actual communication state transition. However, when multiple types of changes occur together, the overall change intensity increases accordingly.
[0052] It should be noted that, The preferred definition is the count of discrete differences between two adjacent valid messages in the application layer field category; The preferred definition is the ratio of the absolute value of the difference between the payload lengths of two adjacent valid messages to the larger payload length of the two messages; The preferred definition is the difference ratio between the current message pair's direction state and the previous message pair's direction state; The preferred definition is the absolute value of the difference between the arrival time interval of the current message pair and the median time interval of the preceding message pair in the bidirectional session flow, which is then normalized by the median time interval of the preceding message pair.
[0053] For each message pair, the event is discretized to generate a sequence of communication change events.
[0054] Furthermore, when the overall change intensity is less than the first event threshold, the message pair is recorded as a stationary continuation event; when the overall change intensity is not less than the first event threshold and less than the second event threshold, the message pair is recorded as a local change event; when the overall change intensity is not less than the second event threshold, the message pair is recorded as a significant transition event.
[0055] It should be noted that the first event threshold and the second event threshold were obtained by continuously calculating the comprehensive change intensity from small to large on historical confirmed business category samples. The comprehensive change intensity values corresponding to the first minimum cross-misjudgment number between stationary continuation events and local change events, and the comprehensive change intensity values corresponding to the first minimum cross-misjudgment number between local change events and significant transition events were selected as the first event threshold and the second event threshold, respectively. The value range of the first event threshold is [0.10, 0.30], and the value range of the second event threshold is [0.35, 0.60].
[0056] S2. Based on the sequence of communication change events, the bidirectional session flow is divided into communication stages by anchoring transition events, trimming local change events, and merging the shortest stage constraints. The stage structure representation parameters of each communication stage are extracted to generate a set of stage flow pattern fragments.
[0057] Using bidirectional session streams as units, all event records corresponding to the same bidirectional session stream are sorted in ascending order by message pair position to create an event position index table.
[0058] After establishing the event location index table, significant transition events are screened and valid anchor points are determined. Specifically, the event distribution in the neighborhood before and after each significant transition event is checked one by one. If local change events occur consecutively before and after a significant transition event, and the continuous segment of the local change events is connected to the significant transition event in position, then the significant transition event is retained as a valid anchor point. If the events before and after a significant transition event are mainly stable and continuous, and lack the support of continuous local change events, then it is not directly used as a stage anchor point. Instead, a set of valid anchor points arranged in chronological order is obtained, and the segment between adjacent valid anchor points is used as the initial stage candidate segment.
[0059] It should be noted that a local change event refers to a communication change event in which the overall change intensity indicates a local communication state disturbance between adjacent message pairs, but the disturbance has not yet reached a significant transition level.
[0060] After forming the initial candidate segments, boundary trimming is performed on each valid anchor point. Specifically, with the valid anchor point as the center, the starting point of the nearest continuous local change event segment adjacent to the valid anchor point is searched forward along the bidirectional session flow, and the starting point of the continuous local change event segment is determined as the candidate front edge of the stage boundary; the ending point of the nearest continuous local change event segment adjacent to the valid anchor point is searched backward along the bidirectional session flow, and the ending point of the continuous local change event segment is determined as the candidate trailing edge of the stage boundary; the insertion of stationary continuation events is checked between the candidate front edge and the candidate trailing edge. When local change events maintain continuous coverage and are not interrupted by long stationary continuation event segments, the starting point and ending point of the continuous local change event segment are used as the trimmed stage boundary; when local change events are significantly separated by long stationary continuation event segments, the trimmed stage boundary is shrunk to the continuous local change event segment on the side closest to the significant transition event.
[0061] After obtaining all the adjusted stage boundaries, the bidirectional session flow is divided into multiple initial communication stages according to the order of the stage boundaries in the bidirectional session flow. The number of valid messages in each initial communication stage is counted, and the ratio of the number of valid messages in the current initial communication stage to the larger number of valid messages in the adjacent preceding and following stages is calculated. When the ratio is less than the stage span threshold, the current initial communication stage is determined to be too short. If an initial communication stage is too short, it is not directly retained as an independent stage, but is compared with the adjacent preceding and following stages. The specific comparison includes the median difference in message length between the short stage and the preceding stage, the median difference in message length between the short stage and the following stage, the difference in directional dominance between the short stage and the preceding stage, and the difference in directional dominance between the short stage and the following stage. If the difference between the short stage and the preceding stage is smaller, the short stage is merged into the preceding stage; if the difference between the short stage and the following stage is smaller, the short stage is merged into the following stage, thus obtaining the final set of communication stages.
[0062] It should be noted that the stage span threshold is obtained by statistically analyzing the ratio of the number of valid messages in the real independent communication stage to the number of valid messages in the adjacent dominant stage in the historical confirmed business category sample, with a value range of [0.10, 0.35].
[0063] For each final communication stage, stage structure characterization parameters are extracted. These parameters include field category distribution, median message length, stage duration, uplink and downlink byte distribution, and dominant direction change rate. Specifically, all valid messages within each final communication stage are statistically analyzed, and the occurrence of different field categories is statistically analyzed based on the DPI parsing results to form a field category distribution. The median message length is obtained by taking the median value of all valid message lengths within the stage. The stage duration is obtained by the difference between the end timestamp and the start timestamp of the stage. The total number of uplink and downlink message bytes within the stage are accumulated to obtain the uplink and downlink byte distribution. The dominant direction change rate of the stage is extracted based on the relationship between the uplink byte ratio of the stage and the previous or next stage.
[0064] Each final communication stage forms a stage stream segment, which includes the stage start and end positions, field category distribution, median message length, stage duration, uplink and downlink byte distribution, dominant direction change rate, and stage structure closure state.
[0065] The phase structure closure state is determined by checking whether the field category distribution, median message length, phase duration, uplink and downlink byte distribution, and direction-dominant change rate have all been successfully extracted. If all of these are present in a phase, it is recorded as a structurally complete phase flow pattern segment. If at least one necessary parameter is missing in a phase, but the phase boundary is clear and the basic phase skeleton has been formed, it is recorded as a structurally incomplete phase flow pattern segment.
[0066] Arrange the phase flow pattern segments according to their temporal order in the corresponding bidirectional session stream to generate a set of phase flow pattern segments.
[0067] S3. Based on the structural closure state of each stage manifold segment, select the target completion stage, extract the adjacent handshake element information, first packet contour, stage persistence features and byte distribution stability features of the target completion stage, perform restricted completion on the missing structural items, and generate a complete stage manifold set.
[0068] The target completion stage is selected based on the structural closure state of the flow pattern segments at each stage.
[0069] Furthermore, the stage structure closure status of each stage manifold fragment is checked one by one. Stage manifold fragments in which all necessary structural items have been successfully extracted are recorded as directly retained stages; stage manifold fragments in which necessary structural items are missing, but the start and end positions of the stage have been determined and the basic manifold skeleton of the stage has been formed are recorded as target completion stages; necessary structural items include field category distribution, first packet outline, stage persistence features, and byte distribution stability features.
[0070] It should be noted that the first packet profile is formed by reading the first few valid packets starting from the target completion stage, extracting the packet length, uplink and downlink directions, and adjacent arrival time intervals of each valid packet in the order of arrival, and combining them in sequence; the stage duration feature is obtained by extracting the difference between the timestamp of the starting packet and the timestamp of the ending packet of the target completion stage, and combining it with the arrival time interval sequence of adjacent valid packets within the stage; and the uplink and downlink byte ratio changes in the continuous packet window are calculated by statistically analyzing the uplink and downlink byte counts of each valid packet within the target completion stage.
[0071] Extract adjacency handshake metadata, first packet outline, stage persistence features, and byte distribution stability features from the target completion stage.
[0072] Furthermore, after identifying the target completion stages, completion evidence is extracted for each stage. Specifically, taking the start and end positions of the target completion stage in its respective bidirectional session flow as the center, local context information from adjacent stages is extracted forward and backward without crossing the boundaries of the determined stages. The completion evidence is limited to four categories: the first category is adjacent handshake information, used to characterize whether there is a connection establishment, capability negotiation, or encryption negotiation process near the target completion stage; the second category is first packet profile information, used to characterize the length arrangement of several valid packets at the beginning of the target completion stage; the third category is stage persistence characteristics, used to characterize the duration and internal arrival rhythm of the target completion stage; and the fourth category is byte distribution stability characteristics, used to characterize whether the uplink and downlink byte distribution within the target completion stage remains relatively stable. When extracting completion evidence, only the target completion stage itself and the information from the adjacent preceding and following stages are allowed; it is not allowed to extend the search range to further stages beyond adjacent stages.
[0073] For the target completion phase, restricted completion is performed. Specifically, for the target completion phase with missing field category distribution, the adjacency handshake metadata from adjacent phases and the resolvable application layer field identifiers from several (e.g., 3) valid packets before the start of the target completion phase are read, and the consistent corresponding field categories are determined as the field category distribution. For the target completion phase with missing first packet profile, the payload length, uplink / downlink direction, and adjacent arrival time interval of several valid packets before the start are read, and combined in the arrival order to form the first packet profile. For the target completion phase with missing phase persistence features, the phase duration is determined by the difference between the start and end packet timestamps, and the arrival time interval sequence of adjacent valid packets within the phase is used as the phase persistence feature. For the target completion phase with missing byte distribution stability features, the uplink / downlink byte count of all valid packets within the phase is counted, a continuous packet window is constructed in the arrival order, and the byte distribution stability feature is determined based on the change in the uplink byte ratio between adjacent continuous packet windows.
[0074] Consistency checks are performed on the completion results. Specifically, the completed structural items are compared item by item with the original message length median, stage duration, uplink and downlink byte distribution, and direction dominance rate of change of the target completion stage to check whether the added structure is consistent with the original stage skeleton. The adjacency relationship of the completed target completion stage is checked with the adjacent previous and adjacent next stages to check whether there are any field categories, first packet outlines, or abnormal reversals of direction dominance that obviously conflict with the adjacent stages. If the completed structural items are consistent with the original skeleton of the target completion stage and do not have obvious conflicts with the adjacent previous and adjacent next stages, the target completion stage is recorded as a stable completion stage. If some structural items are consistent with the original skeleton after completion, but there are still some local uncertainties, the target completion stage is recorded as a restricted retention stage. If there are still obvious structural conflicts after completion, or the completion evidence is insufficient to support stable completion, the target completion stage is recorded as a weak evidence retention stage.
[0075] After completing the consistency verification of all target completion stages, the direct retention stage and the completed stages are unified into a complete stage manifold unit. Specifically, for the direct retention stage, all successfully extracted structural items are retained and the state is marked as native complete; for the stable completion stage, all completed structural items are retained and the state is marked as stable completion; for the restricted retention stage, only structural items that are consistent with the original skeleton of the target completion stage and supported by adjacent evidence are retained and the state is marked as restricted retention; for the weak evidence retention stage, only the original structural items that have been successfully extracted are retained, and the completion content is no longer expanded and the state is marked as weak evidence retention.
[0076] Arrange the complete phase flow units according to their temporal order in the corresponding bidirectional session stream to generate a complete phase flow set. Each phase in the complete phase flow set includes the phase start and end positions, median message length, phase duration, uplink and downlink byte distribution, direction-dominant change rate, field category distribution, first packet profile, and phase status label.
[0077] S4. Perform standardization alignment on the complete set of stage flow patterns according to the stage type sequence, construct stage-constrained flow pattern fingerprints, gather candidate service flow pattern templates based on the number of stages, the type of the first stage, and the transport layer type, and sequentially perform intra-stage closure discrimination, inter-stage transition closure discrimination, and accompaniment relationship closure discrimination to determine the final service category and stage-constrained flow pattern fingerprint.
[0078] When field category distribution is missing or field evidence is insufficient, the determination of the first packet profile stage is based on changes in payload length, transmission direction, arrival time interval between adjacent packets, and the first packet profile determination stage type.
[0079] Specifically, it is based on the payload length sequence, transmission direction sequence, adjacent message arrival time interval sequence, and first packet profile determination stage type.
[0080] The following stages are defined as follows: the stage at the beginning of the bidirectional session flow where the transmission directions of adjacent messages in the first packet outline alternate sequentially is the establishment stage; the stage after the establishment stage and before the exchange stage where the transmission directions of adjacent messages in the first packet outline alternate sequentially is the negotiation stage; the stage containing consecutive segments in the same direction, where the cumulative byte count in the corresponding direction of the consecutive segments in the same direction is greater than the cumulative byte count in the other direction, is the exchange stage; the stage after the exchange stage and before the termination stage, where no consecutive segments in the same direction appear within the stage, is the maintenance stage; and the stage at the end of the bidirectional session flow where the transmission directions of the messages at the end of the stage alternate sequentially is the termination stage.
[0081] For messages whose application layer protocols can be identified, for each stage in the complete set of stage streams, the median message length, stage duration, uplink byte percentage, field category distribution, and first packet profile are read sequentially, and stage type mapping is performed in a fixed order.
[0082] Specifically, when the field category distribution includes connection establishment fields and the first packet profile consists of consecutive short messages, the current stage is mapped to the establishment stage; when the field category distribution includes handshake fields or capability exchange fields, the current stage is mapped to the negotiation stage; when the field category distribution includes service payload fields and the uplink and downlink byte distribution within the stage maintains a continuous transmission relationship, the current stage is mapped to the exchange stage; when the field category distribution does not include connection establishment fields, handshake fields, or end acknowledgment fields, and the round-trip messages within the stage maintain a low-fluctuation continuity relationship, the current stage is mapped to the maintenance stage; when the field category distribution includes end acknowledgment fields, or a consecutive short message contraction sequence appears at the end of the stage, the current stage is mapped to the convergence stage; when the same stage simultaneously meets two or more mapping conditions, the unique stage type is determined according to the priority order of convergence stage, negotiation stage, establishment stage, exchange stage, and maintenance stage, and a standard stage sequence is obtained.
[0083] It should be noted that the connection establishment field is obtained by performing DPI parsing on the target message and reading the protocol field representing the connection initiation; the handshake field is obtained by performing DPI parsing on the target message and reading the protocol field representing the handshake confirmation process; the capability exchange field is obtained by performing DPI parsing on the target message and reading the protocol field representing the parameter negotiation or capability declaration process; the service payload field is obtained by performing DPI parsing on the target message and reading the protocol field representing the service content transmission process; and the termination confirmation field is obtained by performing DPI parsing on the target message and reading the protocol field representing the connection termination or session release process.
[0084] The stages in the standard stage sequence are connected in chronological order, and the transition relationships between adjacent stages are extracted to construct a stage-constrained flow fingerprint. Specifically, the stage-constrained flow fingerprint includes three parts: the first part is the standard stage type order; the second part is the structural characterization parameters within each standard stage, preferably including the median message length, stage duration, field category distribution, first packet profile, and uplink byte ratio; and the third part is the transition relationship between adjacent standard stages, preferably including the direction-dominant change rate and duration ratio.
[0085] It should be noted that the standard phase type order is obtained by recording the standard phase type mapped to each phase in the order of their time sequence in the bidirectional session flow.
[0086] The service flow pattern template library is narrowed down by using the number of stages, the type of the first stage, and the transport layer type. Specifically, the number of standard stages in the current stage constraint flow pattern fingerprint is counted and compared with the number of standard stages in each template in the service flow pattern template library. Service flow pattern templates whose difference in the number of standard stages exceeds the tolerance range are deleted. The first stage type of the current stage constraint flow pattern fingerprint is compared with the first stage type of each service flow pattern template. Service flow pattern templates with inconsistent first stage types are deleted. The transport layer type of the bidirectional session flow to which the current stage constraint flow pattern fingerprint belongs is compared with the transport layer type of each service flow pattern template. Service flow pattern templates with inconsistent transport layer types are deleted. The remaining service flow pattern templates constitute the candidate service flow pattern template set.
[0087] It should be noted that the business flow pattern template library is obtained by merging and organizing the stage constraint flow pattern fingerprints corresponding to the historically confirmed business category samples according to the business category, and extracting the stage chain patterns that appear repeatedly and have the same structure in each category; the tolerance range is obtained by statistically analyzing the standard stage number deviations corresponding to the same business flow pattern template in the historically confirmed business category samples, and taking the maximum allowable deviation value among the standard stage number deviations as the tolerance range.
[0088] After obtaining the set of candidate service flow pattern templates, the first-level intra-stage closure judgment is performed. Specifically, for each candidate service flow pattern template, the median message length, stage duration, and first packet profile of each standard stage in the current stage constraint flow pattern fingerprint are compared one by one with the reference values of the same index standard stage in the corresponding candidate service flow pattern template. If the differences within all standard stages fall within the corresponding tolerance range, the current candidate service flow pattern template is considered to meet the intra-stage closure condition. If the difference within a certain standard stage exceeds the corresponding tolerance range, the current candidate service flow pattern template is considered not to meet the intra-stage closure condition, and the current candidate service flow pattern template is deleted from the candidate set. The intra-stage closure deviation index is defined as follows:
[0089] ;
[0090] in, For the first The intra-stage closure deviation index of each candidate business flow pattern template relative to the current stage constraint flow pattern fingerprint; This represents the number of standard stages in the current stage constrained manifold fingerprint. For the current stage of constrained manifold fingerprinting, the first The median message length of each standard phase; For the first In the candidate business flow template, the first The median reference value for message length in each standard stage; To accommodate the corresponding message length tolerance; For the current stage of constrained manifold fingerprinting, the first The duration of each standard phase; For the first In the candidate business flow template, the first Reference value for the duration of each standard phase; This refers to the duration tolerance of the corresponding stage. For the current stage of constrained manifold fingerprinting, the first The first package profile representation of each standard stage; For the first In the candidate business flow template, the first Reference quantities for the first package outline of each standard stage; To correspond to the first package outline tolerance.
[0091] It should be noted that, , ,as well as Indicates a normal value. , as well as , represents the reference value. The ordinary value represents the actual measured parameters of the current stage constraint flow fingerprint in the corresponding standard stage. It is obtained by statistically analyzing the corresponding standard stage of the current bidirectional session flow to be identified. The corresponding reference value represents the template baseline parameter of the candidate service flow template in the corresponding standard stage. It is obtained by collecting the same parameters in the corresponding standard stage from the historically confirmed similar service samples, aligning them according to the unified stage index and removing outliers, and then extracting the unique representative value according to the parameter type. Among them, the median value is taken for continuous parameters and the mode value is taken for discrete parameters. , ,as well as It is obtained by collecting similar parameters from historically confirmed similar business samples at the corresponding standard stage, aligning them according to a unified stage index, removing outliers, and then calculating the maximum permissible deviation of the remaining parameters relative to the corresponding reference quantity.
[0092] Candidate business flow templates with a closure deviation index greater than the first deviation threshold during the deletion phase are removed, while the remaining candidate business flow templates are retained.
[0093] It should be noted that the first deviation threshold is obtained by continuously calculating the intra-stage closure deviation index from small to large on historically confirmed business category samples, and the intra-stage closure deviation index value corresponding to the first stable retention of the correct business flow template and the first stable removal of the non-corresponding business flow template is taken as the first deviation threshold, with a value range of [0.15, 0.40].
[0094] On the retained candidate flow pattern templates, a second-level inter-stage transition closure judgment is performed. Specifically, for each candidate flow pattern template that passes the first-level judgment, the dominant rate of change of direction and the proportion of duration between adjacent standard stages in the current stage constraint flow pattern fingerprint are compared one by one with the reference values of adjacent standard stages in the corresponding candidate flow pattern template. If the differences of all adjacent stage pairs fall within the corresponding tolerance range, the current candidate flow pattern template is deemed to meet the inter-stage transition closure condition. If the difference of any adjacent stage pair exceeds the tolerance range, the current candidate flow pattern template is deemed not to meet the inter-stage transition closure condition and is deleted. The inter-stage transition closure deviation index is defined as follows:
[0095] ;
[0096] in, For the first The inter-stage transition closure deviation index of each candidate business flow pattern template relative to the current stage constraint flow pattern fingerprint; Indexes for adjacent standard stages; For the current stage of constrained manifold fingerprinting, the first The dominant rate of change of direction for adjacent standard stages; For the first Reference value of the dominant change rate of the direction of the corresponding stage transfer in each candidate business flow template; Tolerance for the dominant rate of change in the corresponding direction; For the current stage of constrained manifold fingerprinting, the first The proportion of the duration of adjacent standard phases; For the first Reference value for the duration ratio of the corresponding stage transition in each candidate business flow template; This corresponds to the proportional tolerance for the duration.
[0097] Candidate business flow pattern templates with inter-stage transition closure deviation indices greater than the second deviation threshold are deleted, while candidate business flow pattern templates with inter-stage transition closure deviation indices not greater than the second deviation threshold are retained. If only one candidate business flow pattern template remains, the business category corresponding to that candidate business flow pattern template is directly determined, and the current stage constraint flow pattern fingerprint is output as the confirmed stage constraint flow pattern fingerprint. If two or more candidate business flow pattern templates remain, the third-level discrimination is initiated.
[0098] It should be noted that the second deviation threshold is obtained by continuously calculating the inter-stage transfer closure deviation index from small to large on historically confirmed business category samples. The value of the inter-stage transfer closure deviation index corresponding to the first stable retention of the correct business flow template and the first stable removal of the non-corresponding business flow template with mismatched stage transfer structure is taken as the second deviation threshold, with a value range of [0.10, 0.35].
[0099] In the third-level discrimination, the closure discrimination of the accompanying relationship is performed. Specifically, around the bidirectional session flow to which the constraint flow fingerprint of the current stage belongs, the associated sessions established by the same source terminal within the time window are extracted, and the sequential response relationship, concurrent accompanying relationship, and destination set coordination relationship between the associated sessions and the target session are statistically analyzed. If a candidate service flow template is closest to the target session in terms of accompanying relationship, and the difference falls within the corresponding tolerance range, then the service category corresponding to the candidate service flow template is determined as the final service category, and the accompanying relationship closure deviation index is defined, with the expression as follows:
[0100] ;
[0101] in, For the first The closure deviation index of the association relationship between each candidate business flow pattern template and the current stage constraint flow pattern fingerprint; This represents the number of characteristic terms associated with the relationship. For the current stage, constrain the flow fingerprint corresponding to the target session and associated session in the 1st stage. Observations on the adjoint relationship; For the first In the candidate business flow template, the first Reference values for accompanying relationships; This corresponds to the tolerance of the accompanying relationship.
[0102] It should be noted that the preferred accompanying relationship includes the sequential response interval, the degree of concurrent overlap, and the degree of destination set overlap. The sequential response interval is obtained by calculating the absolute value of the time difference between the start timestamp of the associated session and the start timestamp of the target session. The degree of concurrent overlap is obtained by statistically analyzing the overlap duration between the duration intervals of the associated session and the duration interval of the target session, and taking the ratio of the overlap duration to the total duration of the union of the two duration intervals as the degree of concurrent overlap. The degree of destination set overlap is obtained by extracting the destination address set of the associated session and the destination address set of the target session, statistically analyzing the number of intersection elements between the two, and taking the ratio of the number of intersection elements to the number of elements in the union of the two as the degree of destination set overlap.
[0103] If, after the third-level discrimination, there exists a unique optimal candidate business flow pattern template whose accompanying relation closure deviation index does not exceed the third deviation threshold, then the corresponding business category is determined as the final business category, and the current stage constraint flow pattern fingerprint is recorded as the confirmed stage constraint flow pattern fingerprint; if, after the third-level discrimination, there is still no unique candidate business flow pattern template, then the current stage constraint flow pattern fingerprint is recorded as a structural variant fingerprint and transferred to the subsequent observation set, instead of being directly solidified into a stable business flow pattern template.
[0104] It should be noted that the third deviation threshold is obtained by continuously calculating the deviation index of the closure of the accompanying relationship from small to large on the historical confirmed business category samples. The value of the deviation index of the closure of the accompanying relationship is taken as the first stable retention of the correct business flow template and the first stable removal of the non-corresponding business flow template with mismatched accompanying relationship. The value range is [0.08, 0.25].
[0105] S5. Based on the stage constraint flow fingerprint, perform similar merging according to business category and standard stage sequence skeleton, extract stable structure kernel, perform template stability gating, and generate stable business flow template and feedback call index.
[0106] First, the confirmed stage constraint flow fingerprints are classified into primary categories according to business categories, and stage constraint flow fingerprints with the same business category are placed into the same business category set. Within the same business category set, secondary merging is performed according to the standard stage sequence skeleton. Only when the business categories are the same and the standard stage type order is the same, the two stage constraint flow fingerprints are merged into the same merging cluster.
[0107] It should be noted that the standard stage sequence skeleton refers to the skeleton structure formed by the sequence of standard stage types.
[0108] After merging similar clusters, the stage constraint flow fingerprints within each merge cluster are checked item by item. The recurring and consistent structural items within the merge clusters are extracted to form a stable structural core. The structural items include the standard stage type order, the median reference value of the message length of each standard stage, the reference value of the stage duration of each standard stage, the reference value of the field category distribution of each standard stage, the reference value of the first packet profile of each standard stage, the reference value of the uplink byte ratio of each standard stage, the reference value of the direction dominant change rate between adjacent standard stages, and the reference value of the duration ratio. The recurring and consistent means that a structural item is repeatedly contained in multiple stage constraint flow fingerprints in the same merge cluster, and the structural items are kept within the same allowable structural item deviation range in terms of value or category.
[0109] It should be noted that the allowable deviation range of the same structural item is obtained by aggregating similar structural items of the same standard stage from historically confirmed similar business samples, aligning them according to the unified stage index, deleting one maximum value and one minimum value, and then subtracting the minimum value from the maximum value among the remaining structural items.
[0110] To determine whether a candidate service flow pattern template structure item has entered the stable structure kernel, the number of stage constraint flow pattern fingerprints that contain candidate service flow pattern template structure items in the same merge cluster and whose candidate service flow pattern template structure items are consistent with the standard stage type order, the median reference value of the message length of each standard stage, the reference value of the stage duration, the reference value of the field category distribution, the reference value of the first packet outline, the reference value of the uplink byte ratio, the reference value of the direction dominant change rate between adjacent standard stages, and the reference value of the duration ratio are counted. Then, the number of candidate service flow pattern fingerprints that do not contain candidate service flow pattern template structure items in the same merge cluster, or candidate services... The number of stage constraint flow fingerprints that are inconsistent with the flow pattern template structure item, standard stage type order, median message length reference value of each standard stage, stage duration reference value, field category distribution reference value, first packet outline reference value, uplink byte ratio reference value, direction dominant change rate reference value between adjacent standard stages, and duration ratio reference value; when the number of stage constraint flow fingerprints that are included and consistent is greater than the number of stage constraint flow fingerprints that are not included or inconsistent, the candidate service flow pattern template structure item is included in the stable structure core; otherwise, the candidate service flow pattern template structure item is deleted from the stable structure core.
[0111] The stable structure kernel is reorganized according to the field organization method of the candidate business flow templates in the business flow template library to generate the business flow template to be solidified.
[0112] The business flow pattern template to be solidified and the candidate business flow pattern template have the same structure. The difference is that the candidate business flow pattern template comes from the business flow pattern template library and is used for current business identification and comparison, while the business flow pattern template to be solidified comes from the same type of merged result of the confirmed stage constraint flow pattern fingerprint. The reorganization specifically includes writing the standard stage type in the stable structure kernel sequentially into the template skeleton position, writing each standard stage reference parameter in the stable structure kernel into the corresponding standard stage parameter position, and writing the adjacent standard stage transfer reference parameter in the stable structure kernel into the corresponding stage transfer parameter position.
[0113] To quantify whether the business flow template to be solidified has met the solidification conditions, template stability is defined, and its expression is:
[0114] ;
[0115] in, For the first Template stability of a business flow template to be solidified; For the first The number of standard stages that have been covered by a stable structural core in a business flow template to be solidified; For the first The number of standard stages in a business flow template that has not yet been covered by a stable structure core; For the first The number of cycles in which a business flow pattern template to be solidified is hit again in a continuous identification cycle; For the first The number of cycles in the observation window that are not hit again for each business flow pattern template to be solidified; For the first The number of structural items dominated by the weak evidence retention stage in each business flow template to be solidified; For the first The number of structural items dominated by the native complete stage or the stable completion stage in a business flow template to be solidified.
[0116] It should be noted that, and It is obtained by dividing the network traffic identification runtime into multiple adjacent time windows of fixed duration, and then counting the number of time windows in which the stage constraint manifold fingerprint that is consistent with the target template in terms of business category and standard stage sequence skeleton reappears.
[0117] Business flow templates with a stability not lower than the stability threshold are solidified into stable business flow templates, while business flow templates with a stability lower than the stability threshold are kept in the observation area without being solidified.
[0118] It should be noted that the stability threshold is obtained by aggregating the template stability of historical business flow templates to be solidified and taking the minimum value from the template stability corresponding to the historical business flow templates to be solidified that have been successfully solidified.
[0119] A feedback call index is generated for each stable service flow template. The feedback call index preferably adopts a three-key structure, including a service category index, a standard stage sequence skeleton index, and a transport layer type index. Specifically, the service category index is used to first limit the range of service categories to which candidate templates belong during subsequent identification; the standard stage sequence skeleton index is used to further and quickly locate stable service flow templates consistent with the current stage constraint flow fingerprint skeleton within the same service category; and the transport layer type index is used to exclude stable service flow templates with inconsistent transport layer types. To differentiate the priority of different stable service flow templates in feedback calls, a feedback priority is defined, expressed as:
[0120] ;
[0121] in, For the first Feedback priority for a stable business flow template; For the first The number of times a stable business flow template has been successfully matched and the business category has been confirmed in the most recent observation window; For the first The number of times a stable business flow template is invoked within the same observation window but the business category confirmation is not completed.
[0122] It should be noted that, By counting the most recent calls within the observation window After a stable business flow pattern template is established, the phase constraint flow pattern fingerprint and the first The system obtains the number of calls for a stable business flow template that has been successfully matched and outputs the corresponding business category. By counting the most recent calls within the observation window After a stable business flow pattern template is established, the phase constraint flow pattern fingerprint does not match the first... The number of calls for a stable business flow template that successfully closed the match or did not output the corresponding business category is obtained.
[0123] Feedback priority and three-key feedback call index are written together into the stable business flow template library, which serves as the basis for prioritizing the use of stable business flow templates in subsequent identification processes.
[0124] This embodiment also provides a computer device applicable to the DPI-based network traffic identification method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the DPI-based network traffic identification method proposed in the above embodiment.
[0125] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0126] This embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements the DPI-based network traffic identification method proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0127] In summary, this invention improves the continuity of traffic representation and the accuracy of event extraction by collecting raw network packets, constructing bidirectional session flows, and extracting communication change event sequences; it enhances the stability of stage boundary identification and the completeness of stage structure expression by anchoring transition events, trimming local change events, merging shortest stage constraints, and completing missing structural items; and it improves the accuracy, reliability, and efficiency of subsequent calls by constructing stage constraint flow pattern fingerprints, performing multi-layer closure discrimination, and using stable service flow pattern template feedback calls.
[0128] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A network traffic identification method based on DPI, characterized in that, include: Collect raw network packets, construct bidirectional session streams according to five-tuples and session timeout rules, perform out-of-order recovery, retransmission deduplication, and fragmentation reassembly on the bidirectional session streams, and use DPI parsing to extract application layer field changes, packet length range changes, uplink and downlink dominant direction changes, and adjacent packet time interval changes to generate a communication change event sequence. Based on the sequence of communication change events, the bidirectional session flow is divided into communication stages by anchoring transition events, trimming local change events, and merging the shortest stage constraints. The stage structure representation parameters of each communication stage are extracted to generate a set of stage flow pattern fragments. Based on the structural closure state of each stage manifold segment, the target completion stage is selected, and the adjacency handshake meta-information, first packet contour, stage persistence features, and byte distribution stability features of the target completion stage are extracted. Restricted completion is performed on the missing structural items to generate a complete set of stage manifolds. The complete set of stage flow patterns is standardized and aligned according to the stage type sequence to construct stage-constrained flow pattern fingerprints. Candidate service flow pattern templates are gathered based on the number of stages, the type of the first stage, and the transport layer type. Then, intra-stage closure discrimination, inter-stage transition closure discrimination, and accompaniment relationship closure discrimination are performed in sequence to determine the final service category and stage-constrained flow pattern fingerprint. Based on the stage-constrained flow pattern fingerprint, perform similar merging according to business category and standard stage sequence skeleton, extract stable structure kernels, perform template stability gating, and generate stable business flow pattern templates and feedback call indexes.
2. The network traffic identification method based on DPI as described in claim 1, characterized in that, The construction of the bidirectional session stream includes: At the mirror acquisition location of the target network link, receive the original network packets, read the arrival time, source address, destination address, source port, destination port, transport layer type, total packet length, and link direction identifier, and generate the original packet registration record; The mirror merge key is generated based on the 5-tuple. The original network packets with the same mirror merge key are sorted in ascending order of arrival time to form a candidate packet sequence. The packets are then segmented according to the bidirectional session timeout threshold to obtain the bidirectional session flow.
3. The network traffic identification method based on DPI as described in claim 2, characterized in that, The generated communication change event sequence includes: Perform out-of-order recovery, retransmission deduplication, and fragmentation reassembly on the bidirectional session stream, and filter the normalized bidirectional session stream based on normalization integrity; DPI parsing is performed packet by packet on the normalized bidirectional session stream to extract changes in application layer fields, changes in message length range, changes in the dominant uplink and downlink directions, and changes in the time interval between adjacent messages. The overall change intensity is calculated and discretized to generate a sequence of communication change events.
4. The DPI-based network traffic identification method as described in claim 1 or 3, characterized in that, The set of manifold fragments in the generation stage includes: An event location index table is established based on the bidirectional session flow. Significant transition events are filtered out, and significant transition events that have consecutive local change events and maintain positional connection with significant transition events are retained as effective anchor points to form candidate segments in the initial stage. Boundary trimming is performed with effective anchor points as the center, and excessively short stages are merged back according to the stage span threshold to obtain the final communication stage set; For each final communication stage, extract the field category distribution, median message length, stage duration, uplink and downlink byte distribution, and direction-dominant rate of change to form stage flow pattern fragments, and arrange them in chronological order to generate a set of stage flow pattern fragments.
5. The network traffic identification method based on DPI as described in claim 1, characterized in that, The complete set of generation stage flow patterns includes: Based on the set of stage manifold segments, the target completion stage is selected according to the stage structure closure state of each stage manifold segment. The stage manifold segment in which all necessary structural items have been successfully extracted is recorded as the directly retained stage. A stage flow pattern segment where necessary structural items are missing and the stage boundary is determined is denoted as the target completion stage; Extract adjacency handshake metadata, first packet profile, stage persistence features, and byte distribution stability features from the target completion stage, and perform restricted completion on missing items in field category distribution, first packet profile, stage persistence features, and byte distribution stability features; The target completion stage is recorded as a stable completion stage, a restricted retention stage, or a weak evidence retention stage through consistency verification. The directly retained stages and the completed stages are uniformly organized into complete stage manifold units, and arranged in chronological order to generate a complete set of stage manifolds.
6. The network traffic identification method based on DPI as described in claim 5, characterized in that, The determination of the final business category and stage constraint flow fingerprint includes: Perform normalization alignment on the complete set of stage manifolds according to the stage type sequence to obtain the standard stage sequence, and connect each stage in the standard stage sequence in chronological order. Combine the transition relationship between adjacent standard stages to construct the stage constraint manifold fingerprint. Based on the number of stages, the type of the first stage, and the type of the transport layer, candidate convergence is performed on the service flow pattern template library to obtain a set of candidate service flow pattern templates; For the candidate business flow pattern template set, perform intra-stage closure discrimination, inter-stage transition closure discrimination, and accompaniment relationship closure discrimination in sequence to determine the final business category and the confirmed stage constraint flow pattern fingerprint.
7. The network traffic identification method based on DPI as described in claim 6, characterized in that, The closure criteria within the execution phase, the closure criteria for inter-phase transitions, and the closure criteria for accompanying relationships include: By comparing the current stage constraint flow pattern fingerprint with the stage parameters of each standard stage, the stage closure deviation index is calculated, and candidate business flow pattern templates with stage closure deviation index greater than the first deviation threshold are deleted. By comparing the stage transition parameters between adjacent standard stages, the inter-stage transition closure deviation index is calculated, and candidate business flow templates with an inter-stage transition closure deviation index greater than the second deviation threshold are deleted. By comparing the accompaniment parameters of the target session and the associated session, the accompaniment closure deviation index is calculated. Based on the accompaniment closure deviation index and the third deviation threshold, the final business category and the confirmed stage constraint flow fingerprint are determined.
8. The DPI-based network traffic identification method as described in claim 7, characterized in that, The generation of stable business flow templates and feedback call indexes include: Merge the confirmed stage constraint flow fingerprints according to business category and standard stage sequence skeleton to form merge clusters; Extract recurring and consistent structural items from the merged clusters to form stable structural kernels, and reorganize the stable structural kernels into business flow templates to be solidified. Gating is performed on the business flow templates to be solidified based on the template stability, and the business flow templates to be solidified with a stability of not less than the stability threshold are solidified as stable business flow templates; Generate a feedback call index for the stable business flow template, calculate the feedback priority, and write the feedback priority and feedback call index into the stable business flow template library.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the DPI-based network traffic identification method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the DPI-based network traffic identification method according to any one of claims 1 to 8.