Service type identification method, electronic device, and storage medium
By using the QUIC accelerated recognition system and leveraging UDP stream management and the QUIC accelerated learning module, historical context is dynamically established, bypassing the decryption process of the QUIC service recognition module. This solves the problem of DPI system performance degradation caused by QUIC service traffic and achieves efficient service type recognition.
Patent Information
- Application Number
- PCT/CN2025/082825
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-25
- Filing Date
- 2025-03-17
- Publication Date
- 2026-01-02
AI Technical Summary
The increase in QUIC traffic has led to a decrease in the performance of the deep packet inspection system, causing the QUIC traffic identification and classification function to consume a large amount of CPU resources, which in turn affects the performance of the DPI device.
The QUIC accelerated recognition system utilizes the UDP stream management module, the QUIC accelerated recognition module, and the QUIC accelerated learning module to dynamically establish historical context, bypassing the decryption process of the QUIC business recognition module and directly searching for business types from the historical context, thereby reducing resource consumption and improving recognition efficiency.
It shortens the business type identification process, reduces resource consumption, improves the performance and throughput of QUIC business identification, and resolves the impact of QUIC business traffic on the performance of the DPI system.
Smart Images

Figure CN2025082825_02012026_PF_FP_ABST
Abstract
Description
Method for identifying service type, electronic device and storage medium
[0001] Cross-reference to related applications
[0002] The present application claims priority to the Chinese patent application No. 202410830504.X, filed on June 25, 2024, and entitled "Method for Identifying Service Type, Electronic Device and Storage Medium", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application belongs to the field of communication, and specifically relates to a method for identifying service type, an electronic device and a storage medium. BACKGROUND
[0004] Deep Packet Inspection (DPI) technology is a network traffic analysis technology, which usually identifies and classifies service traffic according to domain name information. For UDP-Based Multiplexed and Secure Transport (QUIC) protocol, the DPI system will first decrypt the QUIC initial packet and sort and recombine to obtain a CRYPTO frame, and then try to match the SNI field domain name information of the TLS 1.3 ClientHello message in the CRYPTO frame.
[0005] Since the decryption process of the QUIC initial packet requires a lot of Central Processing Unit (CPU) processing time, as the QUIC service traffic increases, the QUIC service identification and classification function has a greater negative impact on the performance of the DPI device, which can cause a significant decrease in the performance of the DPI system. SUMMARY
[0006] The present application provides a method for identifying service type, an electronic device and a storage medium.
[0007] In a first aspect, the present application provides a method for identifying service type, which comprises: obtaining a target identifier of a to-be-identified packet; in the case that the target identifier matches a historical identifier in a historical context, finding a historical service type corresponding to the historical identifier in the historical context, the historical service type being obtained by identifying a historical packet; and outputting the historical service type as the service type of the to-be-identified packet.
[0008] In a second aspect, an embodiment of the present application provides a service type identification device, which comprises: an acquisition module, configured to acquire a target identifier of a to-be-identified message; an identification module, configured to, in a case where the target identifier matches a historical identifier in a historical context, find a historical service type corresponding to the historical identifier in the historical context, the historical service type being obtained by identifying a historical message; and an output module, configured to output the historical service type as a service type of the to-be-identified message.
[0009] In a third aspect, an embodiment of the present application provides an electronic device, which comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, and the program or instruction is executed by the processor to implement the steps of the method in the first aspect.
[0010] In a fourth aspect, an embodiment of the present application provides a readable storage medium, which stores a program or instruction, and the program or instruction is executed by a processor to implement the steps of the method in the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0011] FIG. 1 is a schematic diagram of a framework of a QUIC acceleration identification system according to an embodiment of the present application;
[0012] FIG. 2 is a schematic diagram of a flow context according to an embodiment of the present application;
[0013] FIG. 3 is a schematic diagram of a service type identification method according to an embodiment of the present application;
[0014] FIG. 4 is a schematic diagram of a first uplink initial message according to an embodiment of the present application;
[0015] FIG. 5 is a schematic diagram of a historical context according to an embodiment of the present application;
[0016] FIG. 6 is a schematic diagram of a message decryption process according to an embodiment of the present application;
[0017] FIG. 7 is a schematic diagram of a learning context according to an embodiment of the present application;
[0018] FIG. 8 is a schematic diagram of a learning context array according to an embodiment of the present application;
[0019] FIG. 9 is a schematic diagram of a process of calculating a user number statistic according to an embodiment of the present application;
[0020] FIG. 10 is a schematic diagram of a learning success logic according to an embodiment of the present application;
[0021] FIG. 11 is a schematic diagram of a learning state management according to an embodiment of the present application;
[0022] FIG. 12 is another learning state management schematic diagram provided by an embodiment of the present application;
[0023] FIG. 13 is another learning state management schematic diagram provided by an embodiment of the present application;
[0024] FIG. 14 is another learning state management schematic diagram provided by an embodiment of the present application;
[0025] FIG. 15 is a flowchart of another service type identification method provided by an embodiment of the present application;
[0026] FIG. 16 is a structural schematic diagram of a service type identification apparatus provided by an embodiment of the present application;
[0027] FIG. 17 is a structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0029] The terms "first", "second", and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally a category, not limited to the number of objects, for example, the first object can be one or more. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / ", generally indicates that the front and rear associated objects are in an "or" relationship.
[0030] The embodiments of the present application provide a QUIC acceleration identification system, and the identification of the service type can be realized through the QUIC acceleration identification system. Specifically, as shown in FIG. 1, the QUIC acceleration identification system includes a user datagram protocol (UDP) flow management module, a QUIC service identification module, a QUIC acceleration learning module, and a QUIC acceleration identification module. The UDP flow management module is responsible for judging whether a UDP flow or a service flow is a QUIC protocol, and sending the first uplink initial message of the QUIC flow, i.e., the to-be-identified message of the QUIC flow, to the QUIC acceleration identification module. The UDP flow table managed by the module is a kind of dynamic data collection.
[0031] The QUIC acceleration identification module can receive learning success or failure information sent by the QUIC acceleration learning module, and dynamically establish a historical context, which can also be referred to as an acceleration context. The QUIC acceleration identification module can receive a to-be-identified packet of a QUIC flow sent by the UDP flow management module, and identify the service type of the to-be-identified packet according to the historical context, so as to bypass the decryption and other complex processes of the QUIC service identification module, thereby accelerating the identification process. The acceleration table managed by the module is a dynamic data set, and the acceleration table includes the historical context described above.
[0032] The QUIC acceleration learning module can receive service type identification result information reported by the QUIC service identification module, dynamically learn through an online statistical learning algorithm, and send learning success / failure information to the QUIC acceleration identification module. The learning table managed by the module is a dynamic data set.
[0033] The QUIC service identification module can receive a first uplink initial packet (to-be-identified packet) of a QUIC flow sent by the QUIC acceleration identification module, decrypt the packet, reorder and recombine the packet, decode the packet, match a feature of the packet, identify the service type of the packet, and report the service type identification result to the QUIC acceleration learning module. The feature table managed by the module is a static data set.
[0034] The UDP flow management module can implement a dynamic UDP flow table with a five-tuple as a key. The five-tuple can be a user IP address, a user UDP port, a server IP address, a server UDP port, and an IP protocol type. The IP protocol type is 17, indicating UDP, because QUIC is based on UDP. The module classifies packets with the same five-tuple into the same flow context in the UDP flow table, and a key uniquely identifies a flow context. The data content of the flow context includes the state and identification result information of the flow, for example, as shown in FIG. 2: whether the flow definitely does not contain an uplink initial packet, whether the flow has appeared a first uplink initial packet, whether the flow has been identified, the identification result of the flow, a flow creation timestamp, a latest packet timestamp of the flow, an uplink packet number statistic of the flow, a downlink packet number statistic of the flow, an uplink byte number statistic of the flow, a downlink byte number statistic of the flow, and the like.
[0035] The service type identification method, the electronic device, and the storage medium provided in the embodiments of the present application will be described in detail in combination with the accompanying drawings and specific embodiments and application scenarios.
[0036] Figure 3 shows a method for identifying a service type according to an embodiment of the present application, which can be executed by an electronic device comprising the above-mentioned QUIC acceleration identification system. In other words, the method can be executed by software or hardware installed in the electronic device, and the method comprises the following steps:
[0037] Step 302: obtaining a target identifier of a packet to be identified.
[0038] Specifically, the UDP stream management module receives a UDP packet, extracts a five-tuple from the packet, and looks up the UDP stream table using the five-tuple as a key. There are two cases as follows:
[0039] Case 1: If the flow context can be found, the flow context is obtained for subsequent processing.
[0040] The UDP stream management module adds 0 or 1 to the number of uplink packets of the flow according to the direction of the packet, adds 0 or 1 to the number of downlink packets of the flow according to the direction of the packet, adds 0 or the length to the number of uplink bytes of the flow according to the direction and length of the packet, and adds 0 or the length to the number of downlink bytes of the flow according to the direction and length of the packet. The module sets the latest packet timestamp of the flow to the current time.
[0041] Case 2: If the flow context cannot be found, a new flow context is created in the UDP stream table, the five-tuple is used as the key of the flow context, and the following information is recorded in the data of the flow context: whether the flow definitely cannot contain uplink initial packets is set to no, whether the first uplink initial packet of the flow has appeared is set to no, whether the flow has been identified is set to no, the identification result of the flow is set to empty, the creation timestamp of the flow is set to the current time, the latest packet timestamp of the flow is set to the current time, the number of uplink packets of the flow is set to 0, the number of downlink packets of the flow is set to 0, the number of uplink bytes of the flow is set to 0, and the number of downlink bytes of the flow is set to 0. Then, the module obtains the newly created flow context for subsequent processing.
[0042] In addition, the UDP stream management module can receive the five-tuple of the first uplink initial packet of a certain flow and its identification result information from the QUIC service identification module, find the corresponding flow context in the UDP stream table using the five-tuple as a key, and record the identification result in the flow context as the service type identification result of the flow.
[0043] The UDP stream management module can obtain a to-be-identified packet in a UDP stream. In the embodiment of the present application, the to-be-identified packet is the first uplink initial packet of the received UDP stream. The specific conditions for the UDP stream management module to determine whether a packet is the first uplink initial packet of a QUIC stream are as follows: the direction of the packet is uplink (i.e., from the user terminal side to the network server side), the type of the packet is the QUIC initial type (decoded according to RFC 9000 QUIC v1 or RFC 9369 QUIC v2), the QUIC header of the packet is the QUIC long header (divided into long and short headers according to RFC 9000 QUIC v1), the UDP payload length of the packet is at least 1200 bytes (as specified in the RFC 9000 QUIC v1 protocol), the QUIC version number of the packet is a legal value (for example, the QUIC v1 version number in RFC 9000 is "0x00000001", and the QUIC v2 version number in RFC 9369 is "0x6b3343cf"), and there can be only 0 or more uplink long header QUIC packets of the 0-RTT type before the packet in the stream. That is, there can be no downlink packet, no other type of QUIC packet, and no non-QUIC packet before the target packet in the stream.
[0044] As an example, for example, as shown in FIG. 4, it is determined whether a QUIC stream has a first uplink initial packet, wherein the No. 1 packet of the first QUIC stream is the first uplink initial packet of the first QUIC stream. The No. 2 packet of the second QUIC stream is the first uplink initial packet of the second QUIC stream because there is only an uplink 0-RTT type long header packet before it. The No. 1 packet of the third QUIC stream is a short header packet, so it is considered that the third QUIC stream does not have a first uplink initial packet, i.e., does not have a to-be-identified packet.
[0045] Specifically, the UDP stream management module can obtain the to-be-identified packet (the first uplink initial packet) of the UDP stream and send the to-be-identified packet to the QUIC acceleration identification module for processing. Since the to-be-identified packet carries a target identifier, the target identifier can be the triple of the to-be-identified packet: server IP address, server UDP port, and IP protocol type, wherein the IP protocol type is 17 indicating UDP. Therefore, after receiving the to-be-identified packet through the QUIC acceleration identification module, the target identifier can be obtained from the to-be-identified packet, i.e., the server IP address, the server UDP port, and the IP protocol type can be extracted from the to-be-identified packet as the target identifier.
[0046] Step 304: In the case where the target identifier matches the historical identifier in the historical context, the historical service type corresponding to the historical identifier in the historical context is found.
[0047] In the embodiment of the present application, the historical service type is obtained by identifying historical messages, that is, the historical service type is a service type identification result of the historical messages, and the historical messages are messages whose service types are identified in advance by the QUIC service identification module. Specifically, a dynamic acceleration table with historical identifiers of the historical messages as keys is implemented in the QUIC acceleration identification module. The historical identifier can be a triple of the historical messages: server IP address, server UDP port, and IP protocol type. Among them, the IP protocol type is 17, indicating UDP.
[0048] The QUIC service identification module can attribute messages with the same historical identifier (triple) to the same historical context in the acceleration table, and a historical identifier uniquely identifies a historical context. The data content of the historical context includes the identification result of the service type and other information, such as the acceleration table shown in FIG. 5. The acceleration table can include: the historical identifier of the historical service, whether the historical context has been identified, the service type identification result of the historical context, the context creation timestamp, the latest access timestamp of the context, etc.
[0049] Specifically, after receiving the to-be-identified message by the QUIC service identification module, the target identifier of the to-be-identified message is used as a key to search for a historical identifier matching the target identifier in the acceleration table. If a historical identifier matching the target identifier can be found, the historical service type corresponding to the historical identifier is searched from the historical context corresponding to the historical identifier. If no historical identifier matching the target identifier can be found, the to-be-identified message is sent to the QUIC service identification module for service type identification.
[0050] Step 306: output the historical service type as the service type of the to-be-identified message.
[0051] Specifically, in the case that the target identifier matches the historical identifier in the historical context, the historical service type corresponding to the historical identifier in the historical context is searched, and the historical service type is taken as the service type identification result of the to-be-identified message, that is, the identification result of the UDP flow to which the to-be-identified message belongs. The target identifier of the to-be-identified message and the found historical service type are sent to the UDP flow management module for output. As an example, assuming that in the case that the target identifier of the to-be-identified message matches the historical identifier in the historical context, the historical service type corresponding to the historical identifier in the historical context is searched, and the historical service type is “shopping website”, then “shopping website” is the service type of the to-be-identified message, and “shopping website” is output as the service type of the to-be-identified message.
[0052] The method for identifying a service type provided by the embodiments of the present application can obtain a target identifier of a to-be-identified message; in the case that the target identifier matches a historical identifier in a historical context, a historical service type corresponding to the historical identifier in the historical context is found, the historical service type being obtained by identifying a historical message; and the historical service type is output as the service type of the to-be-identified message. The historical service type corresponding to the historical identifier in the historical context is found, and then the historical service type is output as the service type of the to-be-identified message, thereby shortening the process of service type identification, reducing resource consumption, improving the performance and efficiency of service type identification, and improving the QUIC service identification throughput.
[0053] In an implementation manner, before the target identifier of the to-be-identified message is obtained, the method further includes: in the case that the historical service type is obtained by identifying the historical message, obtaining a learning context matched with the historical identifier; calculating a user number statistic and a traffic number corresponding to the historical service type in the learning context; and in the case that the user number statistic and the traffic number corresponding to the historical service type calculated satisfy a preset learning success condition, generating or updating the historical context according to the historical identifier and the historical service type in the learning context.
[0054] Specifically, the service type of the historical message can be identified by a QUIC service identification module. The QUIC service identification module can implement a static feature table, in which a plurality of regular expression rules are usually preset, for matching the SNI domain name part of the QUIC flow, and the matched QUIC flow can be identified as the service type specified by the rules. The QUIC service identification module receives the historical message of the QUIC UDP flow forwarded from the QUIC acceleration identification module. The QUIC service identification module compares the QUIC version number in the header of the historical message with the information of various QUIC version numbers and whether the QUIC content is encrypted, to determine whether the QUIC content in the historical message is encrypted. For example, the QUIC v1 version number in RFC 9000 is “0x00000001”, the QUIC v2 version number in RFC 9369 is “0x6b3343cf”, and if the QUIC version number of the historical message matches the two version numbers, it is considered that the QUIC content in the historical message is encrypted. According to whether the QUIC content in the historical message is encrypted, the following two cases are divided:
[0055] Case one: if the historical message QUIC content is not encrypted, the QUIC service identification module decodes according to the TLS 1.3 ClientHello message format and obtains the SNI domain name content, performs identification classification on the domain name to obtain a service type identification result, takes the service type result as the historical service type of the historical message, and sends the five-tuple of the message and the historical service type to the UDP flow management module.
[0056] Case two: as shown in FIG. 6, if the historical message QUIC content is encrypted, the QUIC service identification module obtains a preset corresponding SALT value according to the QUIC version number, and based on the HKDF algorithm and the AES_128_ECB algorithm, according to the QUIC header encryption rule and the QUIC header encoding rule, takes “tls13 client in”, “tls13 quic iv” (or “tls13 quicv2 iv”), “tls13 quic hp” (or “tls13 quicv2 hp”), “tls13 quic key” (or “tls13 quicv2 key”), the SALT value, and the target connection ID as parameters to calculate six data of symmetric key, encrypted content starting offset, encrypted length, initial vector, associated data, and authentication tag as decryption parameters. The QUIC service identification module uses the AEAD_AES_128_GCM algorithm to decrypt the QUIC content. These key generation materials and algorithms, decryption parameters, and decryption algorithms are processed and implemented according to the RFC protocol (such as: RFC 9000 QUIC v1, RFC 9369 QUIC v2), and therefore are not described in detail here. The QUIC service identification module obtains a complete CRYPTO frame by sorting and recombining multiple CRYPTO frames, PING frames, and PADDING frames that may be arranged in disorder according to the QUIC frame type, the QUIC frame starting offset, and the QUIC frame length after successfully decrypting the above QUIC content. From the CRYPTO frame decrypted and recombined from the QUIC content, the TLS 1.3 ClientHello message is obtained and decoded to obtain the SNI domain name content. The SNI domain name content is matched according to the rule to obtain a service type identification result, which is taken as the historical service type of the historical message and output. The QUIC service identification module sends the five-tuple of the message and the historical service type to the UDP flow management module. The QUIC service identification module sends the five-tuple of the message and the historical service type to the QUIC acceleration learning module. In this way, the historical service type corresponding to the historical message can be obtained through the QUIC service identification module.
[0057] In the QUIC acceleration learning module, a dynamic learning table is implemented with a history identifier (a three-tuple) as the key. The three-tuple can be the server IP address, the server UDP port, and the IP protocol type. The IP protocol type is 17, which represents UDP.
[0058] The QUIC acceleration learning module classifies packets with the same identifier into the same learning context in the learning table. A history identifier uniquely identifies a learning context. The data content of the learning context includes the learning state and the service type identification result, etc. As shown in FIG. 7, the learning state (learning, learning success, or learning failure), the identification result array, the total flow number, the successful identification result, the spot check identification result, the spot check number, and the learning failure start time are included. Each element of the identification result array includes the identification result, the user number statistics of the identification result, and the flow number of the identification result.
[0059] The QUIC acceleration learning module receives the history service type of the history packet and the five-tuple of the history packet sent by the QUIC service identification module, and searches the learning table with the three-tuple of the server IP address, the server UDP port, and the IP protocol type (UDP) in the five-tuple as the key. If a learning context matching the history identifier is found, the learning context is obtained for subsequent processing. The QUIC acceleration learning module adds 1 to the total flow number in the learning context. This is because the system module flow can ensure that at most only one packet (the first uplink initial packet of the QUIC flow) of a flow can be sent to the module.
[0060] In the QUIC acceleration learning module, the identification result array is established in the learning context matching the history identifier, as shown in FIG. 8. Each element of the array includes the service type identification result, the user number statistics of the service type identification result, and the flow number of the service type identification result. The array form is used because a small amount of similar data is processed faster in the array form, but a linked list form can also be used.
[0061] The QUIC acceleration learning module searches the identification result array in the learning context to find whether the history service type corresponding to the history identifier already exists. The following two cases are included.
[0062] Case 1: If the history service type corresponding to the history identifier does not exist in the array, the history service type corresponding to the history identifier obtained by the current identification is placed in the idle position in the array, the user number statistics corresponding to the array element is set to 0, and the flow number is set to 0. The array element is obtained for subsequent processing.
[0063] Case 2: If the history service type corresponding to the history identifier already exists in the array, the array element is obtained for subsequent processing.
[0064] The user number statistics and the traffic number corresponding to the array element of the historical service type recognition result are calculated and updated by the QUIC acceleration learning module. In a case where the calculated user number statistics and the traffic number corresponding to the historical service type meet a preset learning success condition, the historical context in the QUIC acceleration recognition module is generated or updated according to the historical identifier and the historical service type in the learning context. In this way, by pre-recognizing the historical message, the historical service type of the historical message is obtained, and the learning context and the historical context are obtained according to the historical service type of the historical message. When the historical identifier of the historical message is matched with the to-be-recognized message, the historical context of the to-be-recognized message is directly searched, and the service type recognition result of the to-be-recognized message is obtained, thereby avoiding decryption of the to-be-recognized message, reducing resource consumption, improving the performance and efficiency of service type recognition, and improving the QUIC service recognition throughput of the DPI system.
[0065] In an implementation manner, the calculating the user number statistics and the traffic number corresponding to the historical service type in the learning context comprises: obtaining a user Internet Protocol (IP) address corresponding to the historical service type; calculating the user number statistics according to the user IP address; and increasing the traffic number by a preset number.
[0066] Specifically, the user number statistics corresponding to the array element of the historical service type can be calculated and updated in the following manner:
[0067] The user IP address is obtained from the five-tuple corresponding to the historical service type, the user number statistics is calculated through the user IP address, the module increases the flow number corresponding to the array element of the historical service type by a preset number, and the preset number can be 1.
[0068] In an implementation manner, the calculating the user number statistics according to the user IP address comprises: calculating a hash value of the user IP address; obtaining a first remainder result by taking each hash value modulo a first preset number; setting a first preset number of binary bits, and setting a bit corresponding to the first remainder result on the binary bits to 1; and calculating the user number statistics according to the bit set to 1 on the binary bits.
[0069] Specifically, the user IP address is obtained from the quintuple, a proper hash algorithm (such as a lightweight hash algorithm such as DJB algorithm, a heavy hash algorithm such as MD5 algorithm, etc.) is selected to calculate the hash value of the user IP address, the hash value is taken modulo a preset M value, for example, M = 32, then the first remainder X is a number between 0 and 31, for example, X = 3. As shown in FIG. 8, in the array element, M binary bits are used as a statistical bit map, the Xth bit is set to 1, although there may be different user IP addresses mapping to the same Xth bit, the more the number of users is, the more the number of binary bits with value 1 in the statistical bit map is, which indicates that the more the number of different users of the array element is, so that the number of binary bits with value 1 in the statistical bit map forms a statistical quantity which is not accurate but has statistical significance, which can represent how many different user numbers (different user IP address numbers) are. As shown in FIG. 9, assuming M = 32, the number of binary bits with value 1 in the three statistical bit maps is 6, 15, and 21 respectively, which respectively represent a small, large, and very large number of users. In this way, the user number statistical quantity can be calculated, and the memory space of the learning context occupied by the calculation method is extremely small, and will not increase with the increase of the number of users, which occupies small and controllable memory resources.
[0070] In an implementation manner, the calculating the user number statistical quantity and the flow number corresponding to the historical service type in the learning context comprises: obtaining a user internet protocol address corresponding to the historical service type; updating the user number statistical quantity by recording the number of the user internet protocol addresses through a linked list or a hash table; and increasing the flow number by a preset number.
[0071] Specifically, the user IP address can be obtained from the quintuple, and a plurality of different user IP addresses are recorded in the array element through a linked list or a hash table. The flow number of the array element corresponding to the historical service type is increased by a preset number, which can be 1. In this way, the accurate user number can be obtained.
[0072] In an implementation manner, the learning success condition comprises: the updated user number statistical quantity corresponding to the historical service type is greater than a first threshold value; the updated flow number corresponding to the historical service type is greater than a second threshold value; and a ratio of the updated flow number corresponding to the historical service type to a total flow number of the learning context is greater than a third threshold value.
[0073] The learning success condition checking method of the embodiment of the present application is that when the learning context is in a learning state, after the QUIC accelerated learning module receives the historical service type of the historical packet sent by the QUIC service identification module, the total flow number and the statistical data of the identification result array in the learning context corresponding to the historical service type can be updated. If a certain identification result of the learning context meets the following three learning success conditions, the learning state of the learning context is migrated to a learning success state by the QUIC accelerated learning module, and the successful identification result is set as the historical service type.
[0074] Learning success condition 1: the updated user number statistical quantity corresponding to the historical service type is greater than a preset first threshold value (for example, the minimum bit is 20 bits below the threshold value).
[0075] Learning success condition 2: the updated flow number corresponding to the historical service type is greater than a preset second threshold value (for example, the second preset is 1000 flows).
[0076] Learning success condition 3: the ratio of the updated flow number corresponding to the historical service type to the total flow number of the learning context is greater than a third threshold value (for example, the third threshold value is 90%).
[0077] As an example, as shown in FIG. 10, if the No. 2 identification result in the identification result array of the learning context meets the three learning success conditions, it is considered that the learning context learns successfully, the learned identification result is Youtube, and the successful identification result of the learning context is recorded as Youtube. In this way, through the success condition, a stable and unchanged identification result accessed by a large number of users can be found, and the stability of the service type identification result is ensured.
[0078] In an implementation manner, the generating or updating the historical context according to the historical identifier and the historical service type in the learning context comprises: generating the historical context according to the historical identifier and the historical service type in the learning context in a case that the historical context is not found according to the historical identifier; or updating the historical context according to the historical identifier and the historical service type in the learning context in a case that the historical context is found according to the historical identifier.
[0079] Specifically, the QUIC accelerated identification module receives the historical identifier and the historical service type of the historical packet sent by the QUIC accelerated learning module, and searches the acceleration table with the historical identifier as the key. According to the search result and the learning result information, the following four cases are divided:
[0080] Case one, if the historical context cannot be found according to the historical identifier, and the learning result in the learning context is learning failure, the information is ignored.
[0081] Case two, if the historical context is not found according to the historical identifier, and the learning result in the learning context is learning success, a new historical context is generated in the acceleration table, the historical identifier (ternary) is the key of the historical context, and the historical context has been identified, the historical service type, the creation timestamp is the current moment, and the latest access timestamp is the current moment are recorded in the data of the historical context.
[0082] Case three, if the historical context is found according to the historical identifier, and the learning result in the learning context is learning failure, the acceleration context is deleted from the acceleration table.
[0083] Case four, if the historical context is found according to the historical identifier, and the learning result in the learning context is learning success, according to the historical identifier and the historical service type in the learning context: the historical context has been identified, the historical service type, and the latest access timestamp is the current moment.
[0084] In this way, through the generated or updated historical context, when identifying the to-be-identified message, the matching historical service type can be found according to the target identifier of the to-be-identified message, so that the historical service type is output as the service type of the to-be-identified message, avoiding decryption and identification of the to-be-identified message, reducing resource consumption, improving the performance and efficiency of service type identification, and improving the QUIC service identification throughput.
[0085] In an implementation manner, the outputting the historical service type as the service type of the to-be-identified message includes: checking whether the actual service type corresponding to the target identifier is same as the historical service type; and in a case where the actual service type corresponding to the target identifier is same as the historical service type, outputting the historical service type as the service type of the to-be-identified message.
[0086] Specifically, in a case where the target identifier matches the historical identifier of the historical service, it is necessary to check whether the actual service corresponding to the target identifier is same as the historical service type of the historical service. In a case where the actual service type corresponding to the target identifier is same as the historical service type, the historical service type is output as the service type of the to-be-identified message. The checking manner can be set according to requirements, for example, the message of the service type can be counted, and every N messages are extracted for checking. This checking is a light-weight checking mechanism, when the QUIC service server IP + actual service changes, the checking can find the change, avoiding the difference between the output to-be-identified service type and the actual service type.
[0087] In an implementation, after the checking whether the actual service type corresponding to the target identifier is same as the historical service type, further comprising: in the case that the actual service type corresponding to the target identifier is different from the historical service type, performing decryption identification on the to-be-identified packet.
[0088] Specifically, in the case that the actual service corresponding to the target identifier is different from the historical service type of the historical service, it is indicated that the actual service type of the to-be-identified service has changed, and then the to-be-identified service needs to be sent to the QUIC service identification module for identification.
[0089] In an implementation, the checking whether the actual service type corresponding to the target identifier is same as the historical service type comprises: generating an arbitrary random number; taking the arbitrary random number and a second preset number as a remainder to obtain a second remainder result; in the case that the second remainder result does not hit a preset examination probability, determining that the actual service type corresponding to the target identifier is same as the historical service type; in the case that the second remainder result hits the preset examination probability, determining that the actual service type corresponding to the target identifier is different from the historical service type.
[0090] Specifically, after the historical service type matching the target identifier is found in the historical context, the examination probability can be calculated, and the examination probability can be calculated through a random number. An arbitrary random number R1 is generated, R1 is taken as a remainder of a second preset number, for example, a second remainder result R2 is obtained after R1 is taken as a remainder of the second preset number 100, and the value range of R2 is 0-99, that is, 0, 1, 2, …, 98, 99, a total of 100 possible values. Assuming that the preset examination probability of the module is 10%, it is considered that the examination probability hits when R2 is 0-9, and it is considered that the actual service type corresponding to the target identifier is different from the historical service type. If the examination probability is not hit, it is determined that the actual service type corresponding to the target identifier is same as the historical service type, and the historical service type learned from the historical context is obtained. The five-tuple of the packet and the historical service type are sent to the UDP flow management module for output. Thus, the historical service type is taken as the service type of the to-be-identified packet for output, the service identification process is shortened, the resource consumption is reduced, the performance and efficiency of the service type identification are improved, and the QUIC service identification throughput of the DPI system is improved.
[0091] In an embodiment, each existing historical context in the acceleration table can be scanned by the QUIC acceleration identification module, a time difference from a latest access timestamp to a current time is calculated, and the historical context is deleted if the time difference exceeds a preset longest aging recycling duration. The longest aging recycling duration can be set according to actual needs, and is not specifically limited here.
[0092] In an implementation manner, before the learning context is generated or updated according to the historical identifier and the historical service type in the learning context, the method further includes: in a case where the number of users and the traffic corresponding to the updated historical service type meet a preset learning success condition, setting the learning context as a learning success state.
[0093] Specifically, the embodiment of the application provides a learning state management mechanism for the learning context in the QUIC acceleration learning module, as shown in FIG. 11.
[0094] Current state: learning. Trigger condition: the number of users and the traffic corresponding to the updated historical service type meet a preset learning success condition. State migration: change to a learning success state. Action: send the historical identifier and the historical service type to the QUIC acceleration identification module.
[0095] In this way, in a case where the number of users and the traffic corresponding to the updated historical service type meet a preset learning success condition, the learning context is set as a learning success state.
[0096] In an implementation manner, before the learning context is generated or updated according to the historical identifier and the historical service type in the learning context, the method further includes: in a case where the number of users and the traffic corresponding to the updated historical service type meet a preset learning success condition, setting the learning context as a learning success state.
[0097] Specifically, the embodiment of the application provides a learning state management mechanism for the learning context in the QUIC acceleration learning module, as shown in FIG. 11.
[0098] Current state: none. Trigger condition: in a case where the learning context is failed to be found according to the historical identifier, generate the learning context according to the historical identifier and the historical service type. State migration: change to a learning state. Action: none.
[0099] Current state: learning. Trigger condition: not meeting the learning success condition. State migration: keep the learning state unchanged. Action: none.
[0100] Current state: learning. Trigger condition: timeout without receiving the historical identifier and the historical service type from the QUIC service identification module. State migration: delete the learning context from the learning table. Action: send learning failure information to the QUIC acceleration identification module.
[0101] Current state: learning success. Trigger condition: meeting the learning success condition. State migration: keep the learning success state unchanged. Action: none.
[0102] Current state: learning success. Trigger condition: learning failure condition is met. State transition: change to learning failure state. Action: send learning failure information to QUIC acceleration identification module.
[0103] Current state: learning success. Trigger condition: timeout without receiving historical identification and historical service type from QUIC service identification module. State transition: delete the learning context from the learning table. Action: send learning failure result to QUIC acceleration identification module.
[0104] As an example, as shown in FIG. 12, taking a learning context as an example, when the learning context is in the learning state all the time, and then historical service type of the learning context is not received from the QUIC service identification module for a long time (for example, more than 12 hours of preset time length from T2 time to T3 time), the module deletes the learning context from the learning table, and the module sends learning failure information of the learning context to the QUIC acceleration identification module at T3 time.
[0105] As another example, as shown in FIG. 13, taking a learning context as an example, when the learning context reaches the learning success condition at T2 time, and changes from the learning state to the learning success state at T2 time, the module sends historical service type of the learning context to the QUIC acceleration identification module at T2 time. At T3 time, the module receives the historical service type of the learning context from the QUIC service identification module for the last time, and then does not receive identification result information of the learning context from the QUIC service identification module for a long time (for example, more than 12 hours of preset time length from T3 time to T4 time), the module deletes the learning context from the learning table at T4 time, and the module sends learning failure information of the learning context to the QUIC acceleration identification module at T4 time.
[0106] As another example, as shown in FIG. 14, taking a learning context as an example, when the learning context reaches the learning success condition at T2 time, and changes from the learning state to the learning success state at T2 time, the module sends learning success result information of the learning context to the QUIC acceleration identification module at T2 time. At T3 time, the learning context reaches the learning failure condition through spot check, and changes from the learning success state to the learning failure state at T3 time, the module sends learning failure information of the learning context to the QUIC acceleration identification module at T3 time. The learning context is deleted from the learning table by the module at T4 time, which starts from T3 time and lasts more than a preset learning failure duration (for example, 12 hours). Learning cannot be relearned in the learning failure state, and can be relearned after timeout.
[0107] In an implementation, after the learning context of the historical identifier matching is acquired in the case that the historical service type is acquired, the method further includes: in the case that the historical service type is different from the preset sampling result recorded in the learning context, updating the sampling result of the learning context to the historical service type and setting the sampling number to 1; in the case that the historical service type is the same as the preset sampling result recorded in the learning context, adding 1 to the sampling number; and in the case that the sampling number is greater than a fourth threshold value and the preset sampling result is different from the historical service type, setting the learning context to a learning failure state.
[0108] Specifically, after the learning context of the historical identifier matching is acquired, when the learning context is in a learning success state, the historical service type of the specified five-tuple is received by the QUIC acceleration identification module from the QUIC service identification module. It is checked whether the historical service type is the same as the preset sampling result (the last sampling identification result) recorded in the learning context, which is divided into the following two cases:
[0109] Case 1: If the current identification result is different from the preset sampling result (the last sampling identification result), the sampling identification result in the learning context is updated to the received historical service type, and the sampling number is set to 1, that is, the sampling number is re-counted.
[0110] Case 2: If the received historical service type is the same as the last sampling identification result, the sampling number is added by 1.
[0111] Specifically, the learning failure condition is that if the sampling number of the learning context is greater than a fourth threshold value (such as 15) and the preset sampling result is different from the historical service type, it is considered that the learning fails, and the learning state of the learning context is migrated to a learning failure state.
[0112] Next, the service type identification method provided by the embodiment of the application is further described by means of the service type identification diagram shown in FIG. 15, which includes the following steps:
[0113] Stage A: identification process:
[0114] Step A1: Extract the five-tuple from a UDP stream, and find the flow context in the UDP stream table by taking the five-tuple as a key. If not found, a new flow context is created. If found, the flow context is acquired.
[0115] Step A2: If the flow context already exists the identification result of the UDP stream, the identification result is directly output.
[0116] Step A3: If the identification result of the UDP stream does not exist in the flow context, check whether the first uplink initial packet of the QUIC stream has been found in the flow.
[0117] Step A4: If the first uplink initial packet of the QUIC stream has been found in the flow, output the result as unidentifiable.
[0118] Step A5: If the first uplink initial packet of the QUIC stream has not been found in the flow, check the packet count of the packet in the flow.
[0119] Step A6: Based on the QUIC protocol (RFC 9000 QUIC v1 and RFC 9369 QUIC V2), determine whether the packet is the first uplink initial packet of the QUIC stream. The specific determination conditions are: the direction of the packet is uplink, and the UDP payload length of the packet is greater than or equal to 1200 bytes, and the QUIC header of the packet is a long header, and the QUIC packet type of the packet is an initial type, and the QUIC version number of the packet is a legal value specified by the QUIC protocol, and the previous packet of the flow of the packet can only be 0 or at most N-1 uplink QUIC packets of the 0-RTT type. The determination conditions of the uplink QUIC packet of the 0-RTT type are: the direction of the packet is uplink, and the QUIC header of the packet is a long header, and the QUIC packet type of the packet is a 0-RTT type, and the QUIC version number of the packet is a legal value specified by the QUIC protocol.
[0120] Step A8: If the to-be-identified packet is the first initial packet of the QUIC stream (to-be-identified packet), obtain the target identifier from the packet, i.e., the triple (server IP address, server UDP port, IP protocol type UDP), and use the triple as a key to search for the historical context in the acceleration table.
[0121] Step A9: If the historical context cannot be found, decrypt the packet as the first uplink initial packet of the QUIC, sort and recombine the multiple CRYPTO frames after decryption into a TLS 1.3 ClientHello message, extract the SNI domain name from the ClientHello message, identify the SNI domain name to obtain an identification result, and transfer the packet and the identification result to phase B for learning.
[0122] Step A10: If the historical context can be found, calculate the spot check probability.
[0123] Step A11: If the sampling probability is less than or equal to the preset value, the QUIC first uplink initial message is decrypted, the multiple CRYPTO frames after decryption are sorted and reorganized into a TLS 1.3 ClientHello message, the SNI domain name is extracted from the ClientHello message, the SNI domain name is identified to obtain an identification result, and the message and the identification result are transferred to stage C for sampling.
[0124] Step A12: If the sampling probability is greater than the preset value, the historical service type obtained by successful learning recorded in the acceleration context is directly output as the service type of the current to-be-identified message. The five-tuple is obtained from the message, and the UDP flow table is searched with the five-tuple as the key to obtain the corresponding flow context. The identification result is recorded in the flow context.
[0125] Stage B: Learning process:
[0126] Step B1: The historical identifier, i.e., the three-tuple (server IP address, server UDP port, IP protocol type UDP) of the historical first uplink initial message (historical message) of the historical QUIC flow, is obtained, and the learning context is searched in the learning table with the three-tuple as the key. If not found, a learning context is newly created, and the learning state is set to learning. If found, and the learning state is learning, the learning context is obtained.
[0127] Step B2: According to the information of the historical message, the content of the learning context is updated. First, the total flow number of the learning context is increased by 1. Second, the historical service type of the historical message is recorded in the learning context. Third, the flow number of the historical service type of the learning context is increased by 1. Fourth, the user IP address of the historical message is hashed and updated to calculate the user number statistical quantity of the identification result of the learning context.
[0128] Step B3: The system checks the learning context, whether it meets the learning success condition. If the learning success condition is met, the learning state of the learning context is set to learning success, and the identification result of the historical message is recorded as the successful identification result of the learning context. The learning success condition is that the user number statistical quantity of a certain identification result of the learning context is greater than a preset value, and the flow number thereof is greater than a preset value, and the proportion of the flow number to the total flow number of the learning context is greater than a preset value.
[0129] Step B4: For the learning context of learning success, the same three-tuple (server IP address, server UDP port, IP protocol type UDP) as the key of the learning context is used as the historical identifier, a historical context is newly created in the acceleration table, and the learning successful historical service type is recorded in the historical context.
[0130] Stage C: Spot-checking process:
[0131] Step C1: Record the result of the spot-checking in the learning context. If the result of the spot-checking is unchanged for a plurality of times (greater than a preset number) and is different from the result of the successful learning, set the learning state of the learning context to learning failure.
[0132] Step C2: The system takes the triple of the learning context as a key to search the acceleration table and delete the corresponding historical context.
[0133] Stage D: Aging process:
[0134] Step D1: Scan each flow context in the UDP flow table. For a flow context, if the time from the time when the last packet accessing the flow context arrived to the current time exceeds a preset time length, delete the flow context.
[0135] Step D2: Scan each learning context in the learning table. For a learning context with a learning state of learning or learning success, if the time from the time when the last packet accessing the learning context arrived to the current time exceeds a preset time length, delete the learning context.
[0136] Step D3: Scan each learning context in the learning table. For a learning context with a learning state of learning failure, if the time from the time when the learning context failed to the current time exceeds a preset time length, delete the learning context.
[0137] Step D4: Scan each historical context in the acceleration table. For a historical context, if the time from the time when the last packet accessing the historical context arrived to the current time exceeds a preset time length, delete the historical context.
[0138] It should be noted that the execution subject of the business type identification method provided in the embodiments of the present application can be a business type identification device or a control module in the business type identification device for executing the business type identification method. In the embodiments of the present application, the business type identification device is taken as an example to illustrate the business type identification device provided in the embodiments of the present application.
[0139] FIG. 16 is a structural schematic diagram of a business type identification device according to an embodiment of the present application. As shown in FIG. 16, the business type identification device 1600 includes an acquisition module 1610, an identification module 1620, and an output module 1630.
[0140] The acquisition module 1610 is configured to acquire a target identifier of a to-be-identified message; the identification module 1620 is configured to, in a case where the target identifier matches a historical identifier in a historical context, find a historical service type corresponding to the historical identifier in the historical context, the historical service type being obtained by identifying a historical message; and the output module 1630 is configured to output the historical service type as a service type of the to-be-identified message.
[0141] In an implementation manner, the identification module 1620 is configured to, in a case where the historical service type is obtained by identifying the historical message, acquire a learning context to which the historical identifier matches; calculate a user number statistic and a flow number in the learning context corresponding to the historical service type; and in a case where it is determined that the user number statistic and the flow number corresponding to the historical service type calculated satisfy a preset learning success condition, generate or update the historical context according to the historical identifier and the historical service type in the learning context.
[0142] In an implementation manner, the identification module 1620 is configured to acquire a user Internet protocol address corresponding to the historical service type; calculate the user number statistic according to the user Internet protocol address; and increase the flow number by a preset number.
[0143] In an implementation manner, the identification module 1620 is configured to calculate hash values of the user Internet protocol addresses; obtain first remainder results by taking each of the hash values modulo a first preset number; set the first preset number of binary bits, and set bits corresponding to the first remainder results in the binary bits to be 1; and calculate the user number statistic according to bits that are 1 in the binary bits.
[0144] In an implementation manner, the identification module 1620 is configured to acquire a user Internet protocol address corresponding to the historical service type; update the user number statistic by recording a number of the user Internet protocol addresses through a linked list or a hash table; and increase the flow number by a preset number.
[0145] In an implementation manner, the learning success condition includes that a user number statistic corresponding to the historical service type after being updated is greater than a first threshold value; a flow number corresponding to the historical service type after being updated is greater than a second threshold value; and a ratio of the flow number corresponding to the historical service type after being updated to a total flow number of the learning context is greater than a third threshold value.
[0146] In an implementation manner, the identification module 1620 is configured to generate the historical context according to the historical identifier and the historical service type in the learning context in a case where the historical context is not found according to the historical identifier; or update the historical context according to the historical identifier and the historical service type in the learning context in a case where the historical context is found according to the historical identifier.
[0147] In an implementation manner, the identification module 1620 is configured to check whether the actual service type corresponding to the target identifier is same as the historical service type; and output the historical service type as the service type of the to-be-identified packet in a case where the actual service type corresponding to the target identifier is same as the historical service type.
[0148] In an implementation manner, the identification module 1620 is further configured to perform decryption identification on the to-be-identified packet in a case where the actual service type corresponding to the target identifier is different from the historical service type.
[0149] In an implementation manner, the identification module 1620 is configured to generate an arbitrary random number, take the arbitrary random number and a second preset number as a remainder to obtain a second remainder result, determine that the actual service type corresponding to the target identifier is same as the historical service type in a case where the second remainder result does not hit a preset examination probability, and determine that the actual service type corresponding to the target identifier is different from the historical service type in a case where the second remainder result hits the preset examination probability.
[0150] In an implementation manner, the identification module 1620 is configured to set the learning context as a learning success state in a case where the statistical quantity of users and the quantity of flows corresponding to the updated historical service type satisfy a preset learning success condition.
[0151] In an implementation manner, the identification module 1620 is configured to generate the learning context according to the historical identifier and the historical service type in a case where the learning context fails to be found according to the historical identifier, and set the learning context as a learning state.
[0152] In an implementation manner, the identification module 1620 is configured to update an examination result of the learning context to the historical service type and set an examination frequency to 1 in a case where the historical service type is different from a preset examination result recorded in the learning context, add 1 to the examination frequency in a case where the historical service type is same as the preset examination result recorded in the learning context, and set the learning context as a learning failure state in a case where the examination frequency is greater than a fourth threshold value and the preset examination result is different from the historical service type.
[0153] The service type identification apparatus in the embodiments of the present application can be an apparatus, or a component, an integrated circuit, or a chip in a terminal. The apparatus can be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and the non-mobile electronic device can be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc., and the embodiments of the present application are not limited specifically. The service type identification apparatus in the embodiments of the present application can be an apparatus with an operating system. The operating system can be an Android operating system, an ios operating system, or other possible operating systems, and the embodiments of the present application are not limited specifically.
[0154] The service type identification apparatus provided in the embodiments of the present application can implement each process implemented by the method embodiments of FIG. 1 to FIG. 15, and thus details are not repeated here.
[0155] As shown in FIG. 17, the embodiments of the present application further provide an electronic device 1700, which includes a processor 1701 and a memory 1702, and the memory 1702 stores programs or instructions executable on the processor 1701, and the programs or instructions are executed by the processor 1701 to implement the following: obtaining a target identifier of a to-be-identified message; in a case where the target identifier matches a historical identifier in a historical context, searching for a historical service type corresponding to the historical identifier in the historical context, the historical service type being obtained by identifying a historical message; and outputting the historical service type as a service type of the to-be-identified message.
[0156] In an implementation manner, before the target identifier of the to-be-identified message is obtained, in a case where the historical service type is obtained by identifying the historical message, a learning context matching the historical identifier is obtained; a user number statistic and a traffic number corresponding to the historical service type in the learning context are calculated; in a case where it is determined that the user number statistic and the traffic number corresponding to the historical service type calculated satisfy a preset learning success condition, the historical context is generated or updated according to the historical identifier and the historical service type in the learning context.
[0157] In an implementation manner, the user Internet protocol address corresponding to the historical service type is acquired; the user number statistical quantity is calculated according to the user Internet protocol address; and the flow number is increased by a preset number.
[0158] In an implementation manner, the hash value of the user Internet protocol address is calculated; each hash value is taken remainder by a first preset number to obtain a first remainder result; a first preset number of binary bits are set, and the bit corresponding to the first remainder result on the binary bit is set to 1; and the user number statistical quantity is calculated according to the bit set to 1 on the binary bit.
[0159] In an implementation manner, the user Internet protocol address corresponding to the historical service type is acquired; the number of the user Internet protocol addresses is recorded by a linked list or a hash table to update the user number statistical quantity; and the flow number is increased by a preset number.
[0160] In an implementation manner, the learning success condition comprises that the updated user number statistical quantity corresponding to the historical service type is greater than a first threshold value; the updated flow number corresponding to the historical service type is greater than a second threshold value; and the ratio of the updated flow number corresponding to the historical service type to the total flow number of the learning context is greater than a third threshold value.
[0161] In an implementation manner, in a case where the historical context is not found according to the historical identifier, the historical context is generated according to the historical identifier and the historical service type in the learning context; or in a case where the historical context is found according to the historical identifier, the historical context is updated according to the historical identifier and the historical service type in the learning context.
[0162] In an implementation manner, it is checked whether the actual service type corresponding to the target identifier is same as the historical service type; and in a case where the actual service type corresponding to the target identifier is same as the historical service type, the historical service type is output as the service type of the to-be-identified packet.
[0163] In an implementation manner, after the checking whether the actual service type corresponding to the target identifier is same as the historical service type, in a case where the actual service type corresponding to the target identifier is different from the historical service type, the to-be-identified packet is decrypted and identified.
[0164] In an implementation manner, an arbitrary random number is generated; the arbitrary random number is taken modulo a second preset number to obtain a second modulo result; in a case where the second modulo result does not hit a preset sampling probability, it is determined that an actual service type corresponding to the target identifier is same as the historical service type; in a case where the second modulo result hits the preset sampling probability, it is determined that the actual service type corresponding to the target identifier is different from the historical service type.
[0165] In an implementation manner, before the historical context is generated or updated according to the historical identifier and the historical service type in the learning context, in a case where a user number statistic and a traffic number corresponding to the updated historical service type satisfy a preset learning success condition, the learning context is set to a learning success state.
[0166] In an implementation manner, before the learning context matched with the historical identifier is acquired, in a case where the learning context is failed to be found according to the historical identifier and the historical service type, the learning context is generated according to the historical identifier and the historical service type; and the learning context is set to a learning state.
[0167] In an implementation manner, after the learning context matched with the historical identifier is acquired in a case where the historical service type is acquired, in a case where the historical service type is different from a preset sampling result recorded in the learning context, the sampling result of the learning context is updated to the historical service type and a sampling number is set to 1; in a case where the historical service type is same as the preset sampling result recorded in the learning context, the sampling number is increased by 1; in a case where the sampling number is greater than a fourth threshold value and the preset sampling result is different from the historical service type, the learning context is set to a learning failure state.
[0168] The specific execution steps can refer to the steps of the method for identifying a service type, and the same technical effects can be achieved. To avoid repetition, details are not described herein.
[0169] It should be noted that the electronic device in the embodiments of the present application includes a server, a terminal or other devices other than the terminal.
[0170] The above electronic device structure does not constitute a limitation on the electronic device, which can include more or fewer components than those shown, or combine some components, or have different arrangements of components, for example, the input unit can include a Graphics Processing Unit (GPU) and a microphone, and the display unit can be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit includes at least one of a touch panel and other input devices. The touch panel is also referred to as a touch screen. The other input devices can include, but are not limited to, a physical keyboard, function keys (such as volume control buttons, switch buttons, etc.), a trackball, a mouse, a joystick, and the like, which will not be described here.
[0171] The memory can be used to store software programs and various data. The memory can mainly include a first storage area storing programs or instructions and a second storage area storing data, wherein the first storage area can store an operating system, application programs or instructions required by at least one function (such as a sound playing function, an image playing function, etc.), and the like. In addition, the memory can include a volatile memory or a non-volatile memory, or the memory can include both volatile and non-volatile memories. The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synch link DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM).
[0172] The processor can include one or more processing units; optionally, the processor integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor can also not be integrated into the processor.
[0173] The embodiments of the present application also provide a readable storage medium, which stores a program or instructions, and the program or instructions are executed by a processor to implement various processes of the above-mentioned business type identification method embodiments and achieve the same technical effects. To avoid repetition, details are not described herein.
[0174] The processor is the processor in the electronic device described in the above-mentioned embodiments. The readable storage medium includes a computer readable storage medium, such as a ROM, a RAM, a magnetic disk, or an optical disk.
[0175] It should be noted that in this document, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusions, so that processes, methods, articles, or devices that include a series of elements not only include those elements, but also include other elements not explicitly listed, or include elements inherent to such processes, methods, articles, or devices. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article, or device that includes the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to the order of performing the functions shown or discussed, and can also include performing the functions in a substantially simultaneous manner or in reverse order, for example, the described method can be performed in an order different from that described, and various steps can also be added, omitted, or combined. In addition, the features described with reference to certain examples can be combined in other examples.
[0176] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, an optical disk), and includes a plurality of instructions for making a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in various embodiments of the present application.
[0177] The embodiments of the present application are described above with reference to the accompanying drawings, but the present application is not limited to the specific embodiments described above, and the specific embodiments described above are merely illustrative, but not restrictive, and a person of ordinary skill in the art can make many forms under the inspiration of the present application without departing from the purpose of the present application and the scope protected by the claims.
Claims
1. A method for identifying business types, wherein, include: Obtain the target identifier of the message to be identified; If the target identifier matches a historical identifier in the historical context, the historical service type corresponding to the historical identifier in the historical context is searched, and the historical service type is obtained by identifying historical packets; The historical service type is output as the service type of the message to be identified.
2. The identification method according to claim 1, wherein, Before obtaining the target identifier of the message to be identified, the method further includes: In the case of identifying the historical service type by analyzing the historical messages, the learning context of the historical identifier matching is obtained; Calculate the user count and traffic volume corresponding to the historical business type in the learning context; If the calculated user count and traffic volume corresponding to the historical service type meet the preset learning success conditions, the historical context is generated or updated based on the historical identifier and historical service type in the learning context.
3. The identification method according to claim 2, wherein, The calculation of the user count statistics and traffic volume corresponding to the historical business type in the learning context includes: Obtain the user's Internet Protocol address corresponding to the historical service type; Calculate the user count based on the user's Internet Protocol address; Increase the number of traffic flows by a preset amount.
4. The identification method according to claim 3, wherein, The step of calculating the user count based on the user's Internet Protocol address includes: Calculate the hash value of the user's Internet Protocol address; The first remainder result is obtained by taking the remainder of each hash value with the first preset number. Set the first preset number of binary bits, and set the bit on the binary bits corresponding to the first remainder result to 1; The user count is calculated based on the bits that are 1 in the binary representation.
5. The identification method according to claim 2, wherein, The calculation of the user count statistics and traffic volume corresponding to the historical business type in the learning context includes: Obtain the user's Internet Protocol address corresponding to the historical service type; The number of user Internet Protocol addresses is recorded using a linked list or hash table to update the user count statistics; Increase the number of traffic flows by a preset amount.
6. The identification method according to claim 2, wherein, The conditions for successful learning include: The updated user count for the aforementioned historical service type is greater than the first threshold. The updated traffic volume corresponding to the historical service type is greater than the second threshold; The ratio of the updated number of traffic corresponding to the historical service type to the total number of traffic in the learning context is greater than the third threshold.
7. The identification method according to claim 2, wherein, The step of generating or updating the historical context based on the historical identifier and historical business type in the learning context includes: If the historical context is not found based on the historical identifier, the historical context is generated based on the historical identifier and historical business type in the learning context; or If the historical context is found based on the historical identifier, the historical context is updated based on the historical identifier and historical business type in the learning context.
8. The identification method according to claim 1, wherein, The step of outputting the historical service type as the service type of the message to be identified includes: Check whether the actual business type corresponding to the target identifier is the same as the historical business type; If the actual service type corresponding to the target identifier is the same as the historical service type, the historical service type will be output as the service type of the message to be identified.
9. The identification method according to claim 8, wherein, After checking whether the actual business type corresponding to the target identifier is the same as the historical business type, the method further includes: If the actual service type corresponding to the target identifier is different from the historical service type, the message to be identified is decrypted and identified.
10. The identification method according to claim 9, wherein, The step of checking whether the actual business type corresponding to the target identifier is the same as the historical business type includes: Generate arbitrary random numbers; The second remainder result is obtained by taking the remainder between the arbitrary random number and the second preset number; If the second remainder result does not match the preset sampling probability, it is determined that the actual business type corresponding to the target identifier is the same as the historical business type; If the second remainder result matches the preset sampling probability, it is determined that the actual business type corresponding to the target identifier is different from the historical business type.
11. The identification method according to claim 2, wherein, Before generating or updating the historical context based on the historical identifier and historical business type in the learning context, the method further includes: If the updated user count and traffic volume corresponding to the historical service type meet the preset learning success conditions, the learning context is set to a learning success state.
12. The identification method according to claim 2, wherein, Before obtaining the learning context of the historical identifier matching, the method further includes: If the search for the learning context based on the historical identifier fails, the learning context is generated based on the historical identifier and the historical service type. Set the learning context to a learning state.
13. The identification method according to claim 2, wherein, After obtaining the learning context matching the historical identifier in the case of obtaining the historical business type, the method further includes: If the historical business type is different from the preset sampling result recorded in the learning context, update the sampling result of the learning context to the historical business type and set the sampling count to 1. If the historical business type is the same as the preset sampling result of the learning context record, the sampling count is incremented by 1; If the number of random checks exceeds the fourth threshold and the preset random check result is different from the historical business type, the learning context will be set to a learning failure state.
14. An electronic device, wherein, It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the service type identification method as described in any one of claims 1-13.
15. A readable storage medium, wherein, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the service type identification method as described in any one of claims 1-13.
Citation Information
Patent Citations
Message service type identifying method and message service type identifying device based on data processing installation (DPI)
CN103023670A
DPI identification method and device, computer equipment and storage medium
CN112039731A
Method and device for identifying subclass service traffic, electronic equipment and storage medium
CN118158167A
Deep Packet Inspection application classification systems and methods
US20210099429A1