Generating descriptive information about a network trace in a telecommunications network
The method distinguishes between single-activity and multi-activity network scenarios using packet fragment characteristics, improving network management by optimizing resource allocation and identifying involved activities and applications.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Utility models
- Current Assignee / Owner
- ORANGE SA
- Filing Date
- 2024-10-16
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for classifying digital activities in telecommunications networks are limited to single-activity situations and cannot differentiate between single-activity and multi-activity scenarios, which are increasingly common due to multiple devices accessing the same network access point.
A method for generating descriptive information about network traces that involves determining characteristics of packet fragments, applying a classification model to these characteristics to distinguish between single-activity and multi-activity situations, and using features such as packet sizes, arrival intervals, and global flow characteristics to enhance classification accuracy and reduce training time.
Enables differentiation between single-activity and multi-activity situations, allowing for optimized resource allocation and improved network management by identifying the activities and applications involved, thereby enhancing network efficiency and responsiveness.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Generation of descriptive information for a network trace in a telecommunications network. Technical field
[0001] The invention relates to the field of telecommunications.
[0002] The classification of digital activities on a telecommunications network allows for better knowledge and therefore better management of the network by the operator in charge of its management. State of the art
[0003] A user can access a wide area network, in particular of the IP type, via an access point which can be a home gateway, or a mobile phone of the "Mobile Hotspot" type acting as a network gateway.
[0004] The access point can be accessed via a wireless connection, such as Wi-Fi. A local Wi-Fi network can thus be created by the access point, allowing home devices to communicate with each other and also to access the IP wide area network, particularly to access services offered by remote service platforms.
[0005] The digital activities that can be carried out from a user terminal are increasingly numerous, and they relate to increasingly varied applications and can involve different types of actions on the part of the user. Digital activities include, but are not limited to, chat or instant messaging, telephone calls via VoIP (Voice Protocol Over IP), video streaming, and access to applications, including social networking applications such as Facebook™, Instagram™, YouTube™, Twitter™, etc.
[0006] It is useful for a network operator to classify the digital activities implemented by network users and generating data packet flows in the network via access points such as home gateways, in order to facilitate network management, to prioritize certain services, to offer new services or for security purposes.
[0007] To this end, classification methods are known in order to:
[0008] - classify a stream of data packets as belonging to an application among Several predefined applications such as YouTube, Instagram, Facebook, etc. For example, the publication "Real-time encrypted traffic classification via lightweight neural networks," by J. Cheng et al., in Globecom 2020 IEEE Global Communications Conference, pp. 1-6, describes a method enabling such classification. The publication "Mimetic: Mobile encrypted traffic classification using multimodal deep learning", G. Aceto et al., Computer networks, vol. 165, p. 106944, 2019 describes another method enabling such classification;
[0009] - classifying packet streams into actions performed within applications, by Examples include "posting a tweet on Twitter™" and "commenting on a post on Facebook™". The publication "Eavesdropping on fine-grained user activities within smartphone apps over encrypted network traffic" by B. Saltaformaggio et al., published in the USENIX Workshop on Offensive Technologies (WOOT 16), 2016, describes a method for such a classification of actions. The publication "Analyzing Android encrypted network traffic to identify user actions" by M. Conti et al., published in IEEE Transactions on Information Forensics and Security, vol. 11, no. 1, pp. 114-125, 2015, describes another method for such a classification of actions.
[0010] - classify the data type of data packets, for example between data VoIP voice, chat data, and video streaming data are all examples of such data types. The publication "Online classification of user activities using machine learning on network traffic," by V. Labayen et al., *Computer Networks*, vol. 181, p. 107557, 2020, describes a method for such data type classification. The publication "Identification of encrypted traffic through attention mechanism based long short-term memory," by H. Yao et al., *IEEE Transactions on Big Data*, 2019, describes another method for such data type classification.
[0011] However, these methods are dedicated to the identification of a single digital activity (single-activity situation), which implies that the received packet flows are necessarily data flows captured when a single digital activity is implemented.
[0012] However, it is not permissible to determine that a data stream comprises several digital activities carried out by the user (a situation known as multi-activity), either in parallel (at the same time) or alternately.
[0013] However, such situations are becoming increasingly common, particularly when a user has several terminals on a home network, with the terminals accessing the same access point, which may be a home gateway. Such terminals may include a TV set-top box (STB), a mobile device such as a smartphone or tablet, connected devices such as a smartwatch, etc.
[0014] Knowledge of the type of situation associated with a current trace, among a single-activity or multi-activity situation, would allow for a relevant adaptation of resource allocation in the network.
[0015] Thus, there is a need to differentiate between single-activity situations and multi-activity situations, in a network trace comprising packets exchanged in a telecommunications network.
[0016] The invention offers a solution that does not present the disadvantages of the prior art. Description of the invention
[0017] To this end, according to a functional aspect, the invention relates to a method for generating descriptive information of a network trace comprising packets exchanged on a telecommunications network, comprising the following steps: - determination of at least one characteristic of the network trace from packets of the network trace; - generation of descriptive information of the network trace as a function of at least one output of a classification model applied to said at least one determined characteristic, said descriptive information indicating at least whether the network trace corresponds to a single-activity situation or a multi-activity situation.
[0018] Thus, the invention makes it possible to differentiate network traces corresponding to single-activity situations from those corresponding to multi-activity situations. Taking this difference into account is useful for a network access point in the telecommunications network or for a telecommunications network planner, particularly for optimizing resource allocation.
[0019] According to embodiments, the method may further include fragmenting the network trace into at least one fragment of predetermined duration T, said at least one feature may be extracted from said fragment from the packets in said fragment, and the descriptive information of the network trace may be generated as a function of at least one output of the classification model applied to said at least one feature extracted from said fragment.
[0020] Such fragmentation makes it possible to process fragments of a given duration. It is thus made possible to analyze several fragments in the same network trace, in order in particular to detect periods of multi-activity and to isolate them.
[0021] The duration T can be predetermined based on a set of at least one constraint. In particular, the duration T can be predetermined from a given range of values, the lower limit of which is sufficiently large to provide the classification model with enough knowledge to classify the segment, and the upper limit of which is sufficiently small to allow for a low processing time for the classification model, thus enabling high responsiveness of the process. T can, for example, be within the range between 100 milliseconds and 2 hours. Preferably, T can be between 1 second and 1 minute, or even between 5 and 15 seconds. T can, for example, be equal to 10 seconds.
[0022] According to embodiments, said at least one feature may include: - a first type of feature comprising at least one feature based on the respective sizes of the network trace packets; - a second type of characteristic comprising at least one characteristic based on the respective arrival intervals of the network trace packets; - a third type of characteristic comprising at least one global characteristic of the network trace packets and / or one flow characteristic of the network trace packets.
[0023] The characteristics described above with reference to the three types of characteristics are particularly suitable for the classification of network trace fragments, not only to differentiate a single-activity situation from a multi-activity situation, but also to classify a fragment in a multi-activity or single-activity category, and / or to classify the fragment in an application category (single-activity situation) or in an application category (multi-activity situation).
[0024] In particular, such features make it possible to reduce the training time of the classification model when it is obtained by machine learning, that is, the time required for the classification model to converge. Furthermore, such features reduce the risk of overfitting, as well as the size of the classification model.
[0025] In addition or alternatively, the first type of feature may include at least one feature based on the respective packet sizes in a fragment of the network trace, and the extraction of at least one feature of the first type in the fragment may include: - a determination of a distribution of the respective sizes of the packets of the fragment; - a obtaining of one or more statistical indicators from the distribution, the statistical indicator(s) constituting at least one characteristic of the first type.
[0026] Such characteristics of the first type allow for high accuracy of the classification model as well as rapid convergence during machine learning.
[0027] In addition or alternatively, the second type of feature may include at least one feature based on the respective arrival intervals of packets in a fragment of the network trace, and the extraction of at least one feature of the second type in the fragment may include:
[0028] - a decomposition of the fragment into L sub-fragments, corresponding respectively to time windows of duration equal to T / L; - a determination for at least one sub-fragment, of at least one characteristic based on the respective arrival intervals of the packets of the sub-fragment, in order to constitute at least one characteristic of the second type.
[0029] Such characteristics of the second type allow for high accuracy of the classification model as well as rapid convergence during machine learning.
[0030] As a further complement or alternative, at least one characteristic of the third type may include one or more of the following characteristics: - a number of packets of a fragment of a network trace; - an overall size of the fragment corresponding to a sum of the respective sizes of the packets of the fragment; - a number of distinct IP addresses for the packets in the fragment; and - a number of distinct port numbers for the packets in the fragment.
[0031] Such characteristics of the third type allow for high accuracy of the classification model as well as rapid convergence during machine learning.
[0032] According to some embodiments, at least one output of the classification model may include one or more of the following outputs: - a first output which is a type of situation, the type of situation indicating whether the network trace corresponds to a multi-activity situation or a single-activity situation; - a second output which is a multi-activity category or a single-activity category corresponding to the network trace, the multi-activity category identifying a combination of activities and the single-activity category identifying a single activity; - a third output which is an application category or an application combination category corresponding to the network trace, the application category indicating a single application and the application combination category identifying a combination of applications.
[0033] Thus, the descriptive information of the network trace is of high precision, and can make it possible not only to differentiate multi-activity situations from single-activity situations, but also to identify the activity or activities concerned, as well as possibly the application or applications related to this activity or these activities.
[0034] According to embodiments, the method may further include a preliminary phase of training the classification model by supervised learning, from a set of training network traces, associated with respective labels.
[0035] Thus, the classification model can be obtained by machine learning: it thereby makes it possible to obtain one or more high-precision outputs. Preferably, the data in the training network trace set are numerous and varied.
[0036] In addition, a given training network trace can be associated with at least one of the following labels: - a first label which is a type of situation between a single-activity situation and a multi-activity situation; - a second label which is either a single-activity category, from a set of predefined single-activity categories, indicating a single activity from the given training network trace, or a multi-activity category, from a set of predefined multi-activity categories, indicating a plurality of activities from the given training network trace; and / or - a third label which is either an application category, from a set of predefined application categories, indicating a single application of the given training network trace, or an application combination category, from a set of predefined application combination categories, indicating a combination of applications of the given training network trace.
[0037] Thus, the classification model can be trained to produce one or more high-precision outputs, after supervised learning based on training network traces associated with one or more labels. According to another functional aspect, the invention relates to the use of descriptive information of a network trace by a network access point of a local access network, and / or by a server of the telecommunications network, for adapting a resource allocation based on said descriptive information, said descriptive information being generated by the defined process.
[0038] Thus, descriptive information is transmitted to an entity capable of modifying resource allocation. This enables better management of telecommunications network and / or local access network resources. The network trace can be received from the local access network access point, and the descriptive information of the network access trace can be transmitted to the access point to adapt the bandwidth allocation within the local access network. Therefore, descriptive information can be requested by transmitting the network trace by the entity responsible for managing bandwidth allocation within the local access network, namely the access point. This allows for dynamic adaptation of the bandwidth allocation within the local access network.
[0039] According to a material aspect, the invention also relates to a device comprising an interface capable of obtaining a network trace comprising packets exchanged on a telecommunications network, and a processor configured to: - determine at least one characteristic of the network trace from packets in the network trace; - generate descriptive information of the network trace based on at least one output of a classification model applied to said at least one determined characteristic, said descriptive information indicating at least whether the network trace corresponds to a single-activity situation or a multi-activity situation.
[0040] According to another material aspect, the invention also relates to a computer program suitable for implementation on a classification device, the program comprising code instructions which, when the program is executed by a processor, performs the steps of the defined process.
[0041] Such programs can use any programming language. They can be downloaded from a communication network and / or stored on a computer-readable medium.
[0042] Such instructions can be stored permanently in a non-transient memory medium of the content receiving device implementing the control method according to the invention.
[0043] This program may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0044] The invention also relates to a recording medium or information medium readable by a computer, and comprising instructions for a computer program as mentioned above.
[0045] The recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a mobile medium, a hard drive or an SSD.
[0046] On the other hand, the recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program it contains is executable remotely. The program according to the invention can, in particular, be uploaded to a network, for example, an Internet-type network.
[0047] Alternatively, the recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the aforementioned control method.
[0048] According to one embodiment, the present technique is implemented using software and / or hardware components. In this context, the term "device" or " "module" in this document can refer to a software component, a hardware component, or a set of hardware and software components. Brief description of the drawings
[0049] The invention will be better understood upon reading the following description, given by way of example and with reference to the accompanying drawings in which:
[0050] Fig. 1 illustrates a telecommunications system according to embodiments of the invention.
[0051] Fig. 2a is a diagram illustrating the steps of a training phase for generating descriptive information of a network trace according to embodiments of the invention.
[0052] Fig. 2b is a diagram illustrating the steps of a common phase of the process of generating descriptive information of the network trace, according to embodiments of the invention.
[0053] Figure 3 illustrates a classification device according to embodiments of the invention. Description of the implementation methods
[0054] Fig. 1 illustrates an example of an implementation environment for the invention according to embodiments.
[0055] An extended 100 telecommunications network, of the IP type, is capable of allowing the exchange of data packets between various network entities which are described below.
[0056] Several access points 130.1 to 130.n are represented, n being an integer greater than or equal to two in the example shown in [Fig.1]. No restriction is attached to the integer n, which can be equal to several hundred, or even several thousand, or even several tens or hundreds of thousands.
[0057] In the environment of [Fig. 1], access points 130.1 to 130.n can be home gateways associated with wireless local access networks, such as Wi-Fi networks, 131.1 to 131.n. Thus, user terminals 140.1, 140.2, and 140.n can access digital activity services in network 100, for example, services provided by platforms 121 and 122. Only one terminal is shown for each access point, but several user terminals can access the network through the same access point. There are no restrictions on the services provided by platforms 121 and 122, which can be platforms associated with mobile applications, streaming platforms, or any other service.
[0058] User terminals 140.1, 104.2 and 14O.n of local access networks 131.1 to 131.n can access other types of digital activity services, such as VoIP, chat, mailing, file transfer services, etc.
[0059] A first reference database 111.1 comprises a first set of reference network traces corresponding to single-activity situations, for a given user or for several given users, referred to as single-activity reference network traces. A single-activity reference network trace is a network trace comprising packets associated with a single digital activity, such as chat, a file download, video streaming, or any other digital activity, and labeled with at least one label containing information indicating that the network trace corresponds to a single-activity situation.
[0060] To this end, each reference single-activity network trace can be labeled with a first label which is a situation type indicating a single-activity type. The situation type can take two predefined values, a first situation type value indicating that the labeled reference network trace corresponds to a single-activity situation, and a second situation type value indicating that the labeled reference network trace corresponds to a multi-activity situation.
[0061] In addition or alternatively, each reference single-activity network trace in the first set can be labeled with a second label, which is a single-activity category from a set of predefined single-activity categories, indicating the single activity of the reference single-activity network trace. Further in addition or alternatively, each reference single-activity network trace in the first set can be labeled with a third label, which is an application category from a set of predefined application categories, the application category indicating the application involved in the single activity of the reference single-activity network trace.
[0062] No restriction is attached to the number of predefined single-activity categories, which is any number greater than or equal to 1.
[0063] Furthermore, no restrictions are attached to the single-activity categories, which can differentiate several single-activity situations, during which a user performs only one digital activity. The set of predefined categories can thus include the following categories, given by way of example: "video", "email", "chat", "internet browsing", "file transfer", etc.
[0064] No restriction is attached to the number of application categories, which includes at least one application category per single-activity category.
[0065] Furthermore, no restrictions are attached to the application categories, each of which can identify an application enabling a digital activity. The set of predefined application categories can thus include the following application categories, given by way of example:
[0066] - the "Audio Application" category and the "Audio Application 2" category all two associated with the audio streaming activity; - the "ApplicationVideo1" category and the "ApplicationVideo2" category, both associated with video streaming activity; - the "ApplicationMaill" category associated with the "mail" activity; - the "Social Network" category associated with the "chat" activity; -the "SearchEngine" category associated with the "Internet browsing" activity, etc.
[0067] A second reference database 111.2 includes a second set of reference network traces, which are multi-activity reference network traces, for a given user or for several given users.
[0068] A reference multi-activity network trace is a network trace comprising packets associated with at least two distinct digital activities, and associated with at least one label including information indicating that the reference network trace corresponds to a multi-activity situation.
[0069] Each reference multi-activity network trace of the second set can be labeled with a first label that is a situation type indicating a multi-activity type (the second situation type value introduced previously). In addition, or alternatively, each reference multi-activity network trace of the second set can be labeled with a second label that is a multi-activity category, from among a set of predefined multi-activity categories, indicating the numerical activities of the reference multi-activity network trace.As a further complement or alternative, each reference multi-activity network trace from the first set can be labeled with a third label which is an application combination category, from among a set of predefined application combination categories, the application combination category indicating the combination of applications involved in the multiple activities of the reference multi-activity network trace.
[0070] No restriction is attached to the number of predefined multi-activity categories, which is any number greater than or equal to 1.
[0071] Furthermore, no restrictions are attached to the multi-activity categories, which can identify situations of dual activity, during which a user performs two digital activities simultaneously or alternately, i.e., one after the other. The set of predefined categories can thus include the following categories, given by way of example: "video + email", "chat + email", "chat + video", "chat + internet browsing", "chat + file transfer", etc.
[0072] Furthermore, at least one of the predefined multi-activity categories may correspond to a situation in which a user performs three or more digital activities simultaneously or alternately. The set of predefined categories may thus also include at least one of the following categories, given by way of example: "video + email + chat", "video + internet browsing + email", etc.
[0073] No restriction is attached to the number of application combination categories, which includes at least one application combination category per multi-activity category.
[0074] Furthermore, no restrictions are attached to the application combination categories, which can identify a combination of applications involved in the implementation of several digital activities. The set of application combination categories can thus include the following application combination categories, given by way of example: - the "Audio Application and Mail Application" category associated with the "audio streaming + mail" activity; - the "Audio Application and Mail Application" category associated with the "audio streaming + mail" activity; - the category "Social Network and Search Engine" associated with the activity "chat + internet browsing"; etc.
[0075] No restrictions are attached to the manner in which the first and second databases 111.1 and 111.2 are constructed, in particular to the manner in which the first, second and / or third label of each reference network trace was obtained.
[0076] No restriction is attached to the number of single-activity reference network traces of the first set that are stored in the first database 111.1, nor to the number of multi-activity reference network traces of the second set that are stored in the second database 111.2. In order to enable machine learning of a classification model according to the invention, detailed below, the first set stored in the first reference database 111.1 and the second set stored in the second reference database 111.2 each comprise several hundred, or even several thousand, or even several tens or hundreds of thousands of reference network traces, for a given user or for several given users.
[0077] Alternatively, a single reference database comprises the first and second sets of reference network traces described above.
[0078] Thus, each reference network trace (from the first database 111.1 and the second database 111.2) is associated: - to only one initial label, indicating one type of situation among a multi-activity situation and a multi-activity situation; or - to only a second label, indicating a multi-activity category or a single-activity category. Note that a multi-activity category labeling a reference multi-activity network trace indirectly indicates that the situation type is a multi-activity situation. Similarly, a single-activity category labeling A single-activity reference network trace indicates that the situation type is a single-activity situation; or - to only a third label indicating an application category or a category of application combinations. Note that a category of application combinations labeling a reference multi-activity network trace indirectly indicates that the type of situation is a multi-activity situation, and further indirectly indicates the multi-activity category implemented by the category of application combinations.Similarly, an application category labeling a reference single-activity network trace indirectly indicates that the situation type is a single-activity situation, and further indirectly indicates the single-activity category implemented by the application category; or - to a first label indicating a situation type and a second label indicating a single-activity category or a multi-activity category; or - to a first label indicating a situation type, a second label indicating a single-activity category or a multi-activity category, and a third label indicating an application category or a category of combination of applications.
[0079] Thus, more generally, each reference network trace is associated with at least one label containing information indicating whether the reference network trace corresponds to a single-activity situation or a multi-activity situation.
[0080] Finally, no restrictions are attached to the format of network traces (whether they are reference traces from the reference databases 111.1 and 111.2, or whether they are current network traces, for example, when they are from database 112 described below). Network traces generally include one or more of the following information: duration of the network trace, size of each data packet exchanged, date of sending / receiving each exchanged packet, also called the timestamp value, number of packets in the network trace, a source identifier such as a source port number and a source IP address, and a destination identifier such as a destination port number and a destination IP address. Each packet can be identified by its timestamp value and its packet size.Thus, a network trace corresponds to all the packets exchanged on the network during the execution of a single digital activity (network trace of a single-activity situation) or several digital activities (network trace of a multi-activity situation), over a given time period, from or to a user's access point 130.1 to 130.n. The exchanged packets can be shown sequentially in the network trace. A dataset can include one or more network traces; for example, all the network traces for a given day concerning a single user. given. The user can notably be identified by a network identifier of their access point 130.1 to 130.n.
[0081] Preferably, the reference network traces of each of the first and second sets are varied, that is to say: - the first set of reference single-activity network traces includes a large number of single-activity network traces for each of the predefined single-activity categories, and preferably for each of the predefined application categories, and within each category (single-activity or application), the reference single-activity network traces differ from each other, by their durations, by the users concerned, by the time ranges concerned, etc.; - the second set includes a large number of reference multi-activity network traces for each of the predefined multi-activity categories, and preferably for each of the predefined application categories, and within each category (multi-activity or combination of applications), the reference multi-activity network traces differ from each other, by their durations, by the users concerned, by the time slots concerned, etc.
[0082] Furthermore, a database 112 may include current network traces for classification. Unlike the reference network traces of the first and second reference databases 111.1 and 111.2, the current network traces of database 112 are not associated with one or more identifying labels: - whether the network trace corresponds to a single-activity situation or a multi-activity situation; - the single-activity or multi-activity category of the network trace; - the category of application or applications of the network trace.
[0083] The current network traces of the database 112 can be processed by a classification device 110 according to the invention in order to assign them a category among the set of predefined multi-activity categories.
[0084] The classification device 110 is capable of receiving a current network trace as input and determining, for a current fragment of the current network trace, whether the current fragment corresponds to a multi-activity situation or a single-activity situation. In addition, according to certain embodiments, the classification device 110 can further determine - the single-activity category or the multi-activity category of the current fragment; and optionally - the application category or category of applications of the current fragment.
[0085] For this purpose, the classification device 110 can store a classification model of a network trace fragment, as will be better understood from reading the description of the figures 2a and 2b that follow.
[0086] Figure 2a is a diagram illustrating a learning phase of a process generating descriptive information of a network trace, according to embodiments of the invention.
[0087] At step 200, a training network trace set is obtained from the first reference network trace set and the second reference network trace set mentioned above. The training network trace set includes both single-activity reference network traces from the first set and multi-activity reference network traces from the second set.
[0088] In particular, the first set and the second set can be decomposed into: - a training set comprising training network traces, the training network traces comprising both single-activity reference network traces from the first set and multi-activity reference network traces from the second set, and - a test set, comprising test network traces distinct from the training network traces, the test network traces comprising both single-activity reference network traces from the first set and multi-activity reference network traces from the second set.
[0089] At a step 201, the classification device 110 obtains a first training network trace from among the training network traces. Since the first training network trace comes from the first set or the second set, it is associated with at least one label, from among the first, second and third labels described previously.
[0090] At a step 202, the classification device 110 fragments the first training network trace into at least one training fragment of a determined duration T.
[0091] The duration T is a hyperparameter, that is to say a parameter whose value is used to control the learning process described below.
[0092] For example, the duration T can be predetermined based on a set of at least one constraint. In particular, the duration T can be predetermined from a given range of values, the lower limit of which is sufficiently large to provide the classification model with enough knowledge to classify the segment, and the upper limit of which is sufficiently small to allow the classification model to process the segment in less than 10 seconds.
[0093] For example, the duration T is between NI and N2 seconds. T can, for example, be within the interval between 100 milliseconds and 2 hours. Preferably, T can be within the interval between 1 second and 1 minute. or even in the interval between 5 seconds and 15 seconds. T could, for example, be equal to 10 seconds.
[0094] Indeed, the upper limit N2 can be set according to the maximum duration of a single-activity or multi-activity situation. For example, if the category "video streaming" is considered a single-activity category or part of a multi-activity category, N2 can be less than or equal to a few hours, for example, 2 hours, which corresponds to the duration of watching a film. The lower limit NI, on the other hand, is defined in such a way as to allow the detection of a multi-activity situation. For example, below 10 milliseconds, only single-activity situations are identified, even within a multi-activity situation, which, for the sake of simplicity, includes 10 ms of video streaming, 10 ms of instant messaging, and then another 10 ms of video streaming. A longer period, for example, 100 ms, allows the identification of the multi-activity situation. Thus, NI is preferably greater than 100 ms. Thus, a training fragment comprises a series of data packets from a given trace over a period of duration T. The first network trace can be of duration between N*T and (N+1)*T and can thus be decomposed into N training segments, N being an integer greater than or equal to 1. The at least one label assigned to the first network trace can be assigned to each training fragment obtained from the first network trace.
[0095] N training fragments are thus obtained by the classification device 110 at step 202.
[0096] At a step 203, the classification device 110 determines at least one characteristic of a first training fragment from among the at least one training fragment obtained at step 202.
[0097] The at least one feature may include one or more features of the following feature types: - a first type of feature comprising at least one feature based on the respective sizes of the packets of the first training fragment; - a second type of feature comprising at least one feature based on the respective arrival intervals, or "inter-arrival times", of the packets in the first training fragment; - a third type of feature comprising at least one global feature of the first training fragment and / or one flow feature of the first training fragment.
[0098] According to embodiments of the invention, obtaining at least one characteristic of the first type comprises: - the determination of a distribution of the respective sizes of the packets of the first training fragment, the distribution being a histogram comprising B packet size intervals, each interval being of size S in number of bytes, in which the maximum size considered for a packet is P, in number of bytes. We thus have B=P / S. The B packet size intervals can thus each be represented by an index i varying between 0 and Bl. Thus, in the packet size interval of index i, the distribution corresponds to the frequency of packets whose size in number of bytes is between i*S and i+l*S; - obtaining one or more statistical indicators from the distribution (mean, variance, skewness coefficient, and / or sharpness coefficient), the statistical indicator(s) forming at least one characteristic of the first type.
[0099] According to embodiments of the invention, obtaining at least one feature of the second type comprises: - the decomposition of the first training fragment into L training sub-fragments, each training sub-fragment corresponding to a time window of duration equal to T / L; - the determination for at least one sub-fragment, of at least one feature based on the respective arrival intervals of the packets of the training sub-fragment, in order to form the feature(s) of the second type.
[0100] For example, at least one feature based on the respective arrival intervals of the packets in the training sub-fragment may include one or more statistical indicators from among: - the average of the arrival intervals of the packets in the training sub-fragment; - the variance of the arrival intervals of the packets in the training sub-fragment; - a coefficient of asymmetry, or "skewness" in English, of the arrival intervals of the packets of the training sub-fragment; - an acuity coefficient, or "kurtosis" in English, of the arrival intervals of the parquet floors of the training sub-fragment.
[0101] According to embodiments of the invention, at least one feature of the third type comprises one or more of the following features: - a number of packets of the first training fragment; - an overall size of the first training fragment, which can be obtained by summing the respective sizes of the packets of the first training fragment; - a number of distinct IP addresses for the packets in the first training fragment; and - a number of distinct port numbers for the packets in the first training fragment.
[0102] The features described above with reference to the three types of features are particularly well-suited for network trace fragment classification, not only for differentiating a single-activity situation from a multi-activity situation, but also for classifying a current fragment (described below) into a multi-activity or single-activity category, and / or for classifying the current fragment into an application category (single-activity situation) or a combination of applications category (multi-activity situation). In particular, such features make it possible to reduce the training time of the classification model, that is, the time required for the classification model to converge. Furthermore, such features reduce the risk of overfitting, as well as the size of the classification model.
[0103] Preferably, several different characteristics of the first training fragment are determined. According to one embodiment of the invention, all the aforementioned characteristics are determined for each training sample.
[0104] At a step 204, the classification device 110 trains a machine learning classification model submitting as input to the model the feature(s) determined for the first training fragment, the model being trained to predict one or more of the following outputs: - the type of situation (first output of the classification model) corresponding to the fragment submitted as input, among the multi-activity type and the single-activity type, if the training network traces are labeled with the first label, the second label and / or the third label; - the multi-activity category or the single-activity category (second output of the classification model) corresponding to the fragment submitted as input, if the training network traces are labeled at least with the second label or with the third label; - the application category or the application combination category (third output of the classification model) of the input fragment, if the training network traces are labeled at least with the third label.
[0105] To this end, during the training step, the classification device 110: - applies a current version of the classification model to at least one feature obtained in step 203 for the first training fragment; - obtains, as output from the current version of the classification model, at least one of the predicted outputs listed above for the first training fragment; - compares at least one predicted output with at least one label associated with the first training fragment; - updates one or more parameters of the classification model based on a result of the comparison between at least one predicted output and at least one label.
[0106] Such training is of the supervised type, the principle of which is known and is not described further in the present description.
[0107] Thus, at the end of training step 204, the classification model is updated and a new current version of the classification model is obtained.
[0108] Such training is repeated for a plurality of training fragments, up to a stopping criterion which may be: - a convergence criterion for the classification model, estimated from the test network traces obtained in step 200; - an exhaustion of the training network traces obtained in step 200 (steps 201 to 204 were applied to all the training network traces obtained in step 200).
[0109] Thus, at a step 205 following step 204, the classification device 110 can determine whether the first network trace includes at least one other training fragment determined in step 202 to which steps 203 and 204 have not been applied. If so, the classification device 110 selects a new training fragment (for example, a second training fragment after the first training fragment) and applies steps 203 and 204 to the new training fragment.
[0110] If this is not the case, i.e. if the classification device has applied steps 203 and 204 to all the training fragments of the first training network trace obtained in step 201, the process proceeds to a step 206.
[0111] At a step 206, the classification device 110 can determine whether there remains at least one training network trace obtained at step 200 to which steps 202 to 205 have not been applied, and / or whether the convergence criterion of the classification model is not met.
[0112] If this is the case, that is to say if there remains at least one training network trace obtained in step 200 to which steps 202 to 205 have not been applied, and / or if the convergence criterion of the classification model is not met, the process returns to step 201, and the classification device 110 obtains another training network trace (for example a second training network trace after the first training network trace), and applies steps 202 to 205 previously described to the other training network trace.
[0113] If this is not the case, that is, if steps 202 to 205 have been applied to all the training network traces obtained in step 200, or if the criterion of Convergence of the classification model is reached, the training phase of the classification model ends at step 207.
[0114] No restrictions are attached to the classification model that is trained in step 204. The classification model may, in particular, be chosen from one of the following models:
[0115] - a random forest type model, or "random forest" in English;
[0116] - an eXtreme Gradient Boosting, or XGBoost, model;
[0117] - a one-dimensional convolutional neural network, with mechanism attention;
[0118] - a bidirectional, short-term long memory cell, BiLSTM, for " Bidirectional Long Short-Term Memory, with attention mechanism;
[0119] - a Transformer type encoder.
[0120] As described previously, the classification model can determine one to three outputs (predictions), from among the first, second and third outputs described previously.
[0121] Regardless of the output, it at least allows us to determine whether the input fragment corresponds to a multi-activity or a single-activity situation. Indeed, the first output directly indicates whether the fragment corresponds to a multi-activity or a single-activity situation, while the second and third outputs each allow us to deduce the first output. For example, the second output is more specific than the first, so having the second output allows us to deduce the first output.
[0122] The steps in [Fig.2a] have been described as being implemented by the classification device 110. However, the model can be trained by any entity comprising computing capabilities and memory enabling the implementation of the aforementioned steps, and then the model is stored in the classification device 110. In order to train the model, such an entity is able to access the first training database 111.1 and the second training database 111.2, via the network 100 or via a direct link.
[0123] The identification phase described above with reference to [Fig. 2b] is implemented by the classification device 110, which can be implemented in any network element capable of accessing network 100. The classification device 110 can thus be implemented in a server, in a network access point 100, in a router, or even in a user terminal. Alternatively, the classification device 110 is implemented in a hybrid manner between one of the aforementioned network elements and a component of a cloud architecture.
[0124] Fig. 2b is a diagram illustrating the steps of a common phase of a process for generating descriptive information of a network trace, according to embodiments of the invention.
[0125] At step 210, the classification model previously trained in accordance with the learning phase of [Fig.2a] is stored by the classification device 110. Such storage may be in an internal memory of the classification device 110, or may be stored remotely, in a remote server of the cloud type for example, to which the classification device 110 has access.
[0126] The steps in [Fig.2a] can thus be considered as steps in a training phase prior to a current phase described with reference to [Fig.2b].
[0127] At a step 211, the classification device 110 obtains a current network trace comprising a set of packets exchanged over a time range for the performance of one or more digital activities. Each exchanged packet can be identified by a packet identifier, a packet size, a packet date, a source port and a destination port, a source IP address and a destination IP address.
[0128] The current network trace can be a network trace: - stored in database 112; - captured by a previously described 130.1-130.n access point. A 130.1-130.n network access point can, in particular, transmit the current network trace in real time once captured; - captured by a server or device of the telecommunications network 100. The server or device can in particular transmit the current network trace in real time once captured.
[0129] At a step 212, the classification device 110 can fragment the current network trace into at least one current fragment of the duration T described previously.
[0130] At a step 213, the classification device 110 determines at least one feature of the current fragment, the at least one feature being identical to the at least one feature extracted at step 203 during the training phase, that is to say that the at least one feature may include one or more features of the first type, one or more features of the second type and / or one or more features of the third type.
[0131] At a step 214, the feature, or features thus determined for the current fragment, is submitted or are submitted to the classification model stored at step 210 by the classification device 110, to obtain at least one prediction on one or more of the outputs of the classification model.
[0132] The current fragment is thus classified and the type of situation corresponding to the fragment is identified. Optionally, according to certain embodiments of the invention, the multi-activity or single-activity category of the current fragment, and / or the application category or combination of applications category of the current fragment.
[0133] Steps 212 to 214 can be repeated to apply the classification model to another current fragment of the current network trace obtained in step 211.
[0134] At a step 215, the classification device 110 can generate descriptive information about the current network trace based on the type of situation identified at least for the current fragment, and optionally based on the multi-activity or single-activity category of at least one current fragment, and / or the application or combination of applications category of at least one current fragment. The descriptive information can be: - the first output; - the second output; - the third output; - a combination of several outputs from the classification model. The descriptive information of the current network trace thus indicates at least whether the current network trace is single-activity or multi-activity (since the first output can be deduced from the second and third outputs). Additionally, the descriptive information can indicate which activity or activities correspond to the current network trace if it includes the second or third output (the second output being deducible from the third output), and / or which application or applications correspond to the current network trace if the descriptive information includes the third output.
[0135] The descriptive information of the current network trace can be transmitted to a network entity (server or terminal) in charge of allocating resources in the network, or in a part of the network, or can be transmitted to the access point 130.1-130.n which acquired the current network trace, for adaptation of the resources used in the corresponding local access network 131.1-131.n, at a step 216.
[0136] Steps 211 to 216 can be repeated upon receipt of a new current network trace.
[0137] A particular example of application of the method according to the invention is described below by way of illustration.
[0138] In this example, the current network trace is sent at a given frequency, by the access point 130.1 associated with the local access network 131.1, to the classification device 110. Thus, the access point 130.1 transmits a first current network trace, then a second current network trace captured after the first current network trace, then a third current network trace captured after the second current network trace.
[0139] The classification device applies a first iteration of steps 211 to 216 and transmits to step 216 the first descriptive information of the first current network trace.
[0140] The first descriptive information may indicate a single-activity situation associated with a video game activity (single-activity category). Upon receiving the first descriptive information, the first access point 130.1 may allocate the maximum available bandwidth to allow for an optimal user experience during the video game activity.
[0141] The classification device 110 then applies a second iteration of steps 211 to 216 and transmits to step 216 the second descriptive information of the second current network trace.
[0142] The second descriptive information may indicate a multi-activity situation associated with video conferencing and, in parallel, a video game session (multi-activity category "video conferencing + video game"). Upon receiving the second descriptive information, the first access point 130.1 may allocate a portion of bandwidth to each activity, each portion of bandwidth being determined in such a way as to optimize the overall user experience of video conferencing and video game.
[0143] The classification device 110 then applies a third iteration of steps 211 to 216 and transmits to step 216 the third descriptive information of the third current network trace.
[0144] The third descriptive information may indicate a single-activity situation associated with video conferencing communication (single-activity category), the user having closed their video game session before the third current network trace was captured by the first access point 130.1.
[0145] Upon receipt of the third descriptive information, the first access point 130.1 can allocate a maximum of bandwidth to video conferencing communication, in order to optimize the user experience associated with video conferencing communication.
[0146] Figure [Fig. 3] shows the structure of a device 110 according to embodiments of the invention.
[0147] The device 110 includes a processor 301 configured to communicate unidirectionally or bidirectionally, via one or more buses or via a direct wired connection, with a memory 302 such as a Random Access Memory (RAM), a Read Only Memory (ROM), or any other type of memory (Flash, EEPROM, etc.). Alternatively, the memory 302 comprises several memories of the aforementioned types.
[0148] The memory 302 includes at least one non-volatile memory in which the data used and / or resulting from the implementation of the steps of the current phase of the classification process according to the invention described with reference to [Fig.2b] are stored, temporarily or permanently.
[0149] In particular, memory 302 can store the classification model during step 210 described above. Memory 302 can also store methods for determining one or more features of current network trace fragments, as described above, for example in the form of software instructions.
[0150] The processor 301 is capable of executing instructions, stored in memory 302, for the implementation of steps 211 to 216 of the current phase of the classification process according to the invention, described with reference to [Fig. 2b]. Optionally and additionally, the processor 301 is capable of executing instructions, stored in memory 302, for the implementation of steps 200 to 207 of the training phase of the classification process according to the invention, described with reference to [Fig. 2a].
[0151] Device 110 includes a first interface 303 capable of receiving a current network trace during step 211 described above.
[0152] The device 110 further includes a second interface 304 capable of transmitting descriptive information during step 216 described previously.
Claims
Demands
1. A computer-readable information carrier, comprising instructions for a computer program capable of being implemented in a device, the program comprising code instructions which, when executed by a processor (301), performs the steps of a method for generating descriptive information for a network trace comprising packets exchanged on a telecommunications network (100), said method comprising the following steps: - determining (213) at least one characteristic from packets of the network trace; - generating (215) descriptive information for the network trace based on at least one output of a classification model applied (214) to said at least one determined characteristic, said descriptive information indicating at least whether the network trace corresponds to a single-activity situation or a multi-activity situation.
2. Information carrier according to claim 1, wherein said at least one feature comprises: - a first type of feature comprising at least one feature based on the respective sizes of the network trace packets; - a second type of feature comprising at least one feature based on the respective arrival intervals of the network trace packets; - a third type of feature comprising at least one global feature of the network trace packets and / or a flow feature of the network trace packets.
3. Information carrier according to claim 2, wherein the first type of feature comprises at least one feature based on the respective sizes of the packets in a fragment of said network trace, and wherein the extraction (213) of at least one feature of the first type in the fragment comprises: - a determination of a distribution of the respective sizes of the packets of the fragment; - obtaining one or more statistical indicators from the distribution, the statistical indicator(s) constituting at least one characteristic of the first type.
4. Information carrier according to any one of claims 2 or 3, wherein the second type of feature comprises at least one feature based on the respective arrival intervals of packets in a fragment of said network trace, and wherein the extraction (213) of at least one feature of the second type in the fragment comprises: - a decomposition of the fragment into L sub-fragments, corresponding respectively to time windows of duration equal to T / L; - a determination for at least one sub-fragment, of at least one feature based on the respective arrival intervals of packets of the sub-fragment, in order to constitute the at least one feature of the second type.
5. Information carrier according to any one of claims 2 to 5, wherein at least one feature of the third type comprises one or more of the following features: - a number of packets in a fragment of a network trace; - an overall size of the fragment corresponding to a sum of the respective sizes of the packets in the fragment; - a number of distinct IP addresses of the packets in the fragment; and - a number of distinct port numbers of the packets in the fragment.
6. Information carrier according to any one of the preceding claims, wherein at least one output of the classification model comprises one or more of the following outputs: - a first output which is a situation type, the situation type indicating whether the network trace corresponds to a multi-activity situation or a single-activity situation; - a second output which is a multi-activity category or a single-activity category corresponding to the network trace, the multi-activity category identifying a combination of activities and the single-activity category identifying a single activity; - a third output which is an application category or a combination of applications category corresponding to the network trace, the application category indicating a single application and the combination of applications category identifying a combination of applications.
7. Information carrier according to any one of the preceding claims, comprising a prior training phase (200-207) of the supervised learning classification model, from a set of training network traces, associated with respective labels.
8. Information carrier according to claim 7, wherein a given training network trace is associated with at least one label from: - a first label which is a type of situation between a single-activity situation and a multi-activity situation; - a second label which is either a single-activity category, from a set of predefined single-activity categories, indicating a single activity from the given training network trace, or a multi-activity category, from a set of predefined multi-activity categories, indicating a plurality of activities from the given training network trace; and / or - a third label which is either an application category, from a set of predefined application categories, indicating a single application of the given training network trace, or an application combination category, from a set of predefined application combination categories, indicating a combination of applications of the given training network trace.