Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

488 results about "Traffic analysis" patented technology

Traffic analysis is the process of intercepting and examining messages in order to deduce information from patterns in communication, which can be performed even when the messages are encrypted. In general, the greater the number of messages observed, or even intercepted and stored, the more can be inferred from the traffic. Traffic analysis can be performed in the context of military intelligence, counter-intelligence, or pattern-of-life analysis, and is a concern in computer security.

Enhanced encrypted traffic analysis via integrated entropy estimation and neural network-based feature hybridization

A method is provided for encrypted network traffic analysis. The method includes capturing network traffic data; calculating entropy of said data to classify traffic as encrypted or non-encrypted; applying statistical and sequential feature hybridization on encrypted traffic to extract comprehensive features; analyzing the features using a neural network model to identify encrypted traffic types and detect anomalies; and refining the analysis based on entropy and neural network insights through a feedback loop.
Owner:LEPTUDE INC

Flow analysis and threat detection method and device based on machine learning

The invention provides a flow analysis and threat detection method and device based on machine learning, and the method comprises the steps: collecting a real-time flow data package of a target network environment, carrying out the protocol analysis and session recombination, and generating a real-time flow feature data set containing multi-dimensional flow features; loading a pre-trained multi-level threat classification model, inputting the real-time traffic feature data set into a feature extraction layer of the model, carrying out normalized coding on traffic features of corresponding dimensions through feature coding channels, generating a real-time feature vector sequence, inputting the real-time feature vector sequence into a primary classifier of the model, and classifying the real-time traffic features according to the real-time feature vector sequence; and performing abnormal probability calculation and cluster division on the real-time feature vector sequence through a mixed detection unit, outputting a primary threat tag and an abnormal confidence coefficient corresponding to each real-time feature vector, inputting the primary threat tag and the abnormal confidence coefficient into an aggregation classifier, performing dynamic weighted aggregation, and generating a comprehensive threat score so as to judge whether a threat response strategy is triggered or not. According to the invention, the accuracy and timeliness of threat detection in a complex network environment can be improved.
Owner:FUZHOU PUBLIC SECURITY BUREAU +1

Network data intelligent tool system and method based on model context protocol MCP

The invention discloses a network data intelligent tool system and method based on a model context protocol MCP, and relates to the technical field of computer networks. The system comprises an AI analysis main body, an MCP Pcap tool engine, context management, a Pcap data source, various MCP Pcap tools, a Pcap tool gateway interface, a Pcap tool interface and a data packet interface. The invention provides an interaction mechanism of direct embedding and bypass data forwarding in tool calling. According to the method, direct embedded transmission of small-size data in tool calling is supported, separation of data transmission and instruction calling is achieved, the technical bottleneck that large-size Pcap data cannot be efficiently exchanged through a text channel is effectively overcome, efficient processing of the AI model on network packet capture data is achieved, and the data transmission efficiency is improved. And the efficiency and the automation degree of large-scale network traffic analysis are improved.
Owner:SHANGHAI NETIS TECH CO LTD

Multi-stage spatial-temporal clustering method and system based on fused mahalanobis distance

ActiveCN121051489AData setAlgorithm
The invention discloses a multi-stage spatial-temporal clustering method and system based on a fused mahalanobis distance. The method comprises the following steps: acquiring a spatio-temporal data set, and determining a spatio-temporal neighbor relation of samples in the data set; calculating a space communication distance and a time decay distance of the sample; fusing the space communication distance and the time decay distance by using a mahalanobis distance to obtain a relative distance of the sample; selecting a class cluster center from the data set according to the local density of the sample and the relative distance; adopting a multi-stage distribution strategy to distribute non-class-cluster center samples to corresponding class clusters; wherein the multi-stage allocation strategy comprises an inevitable allocation stage based on space-time shared neighbor and a similarity allocation stage based on a weighted similarity matrix. According to the method, the key problems that an existing space-time clustering algorithm is insufficient in space-time attribute coupling processing and sensitive to distribution errors are solved, and the clustering accuracy, robustness and practicability in the fields of intelligent traffic analysis, seismic sequence recognition and the like are remarkably improved.
Owner:NANCHANG INST OF TECH

Generative confrontation-driven intelligent security defense method and system

The invention provides a generative adversarial-driven intelligent security defense method and system, and solves the problem of dynamic network security defense through three-layer architecture innovation: 1, data fusion layer reconstruction: employing a multi-modal feature extraction engine driven by an MoE architecture, dynamically allocating computing power resources to a plurality of expert models, and improving the heterogeneous data distillation efficiency; an LLM for fine adjustment in the security field is introduced, a cross-modal semantic similarity matrix is constructed, and the accuracy of unstructured threat intelligence analysis is improved; a second dynamic attack and defense layer is constructed, a GPT-4 architecture attack generator is deployed, and generation of a multi-stage APT attack chain is simulated; a double-agent reinforcement learning framework is designed, and the confrontation training efficiency is improved; upgrading a three-cognitive decision-making layer, constructing a dynamic threat map based on a time sequence diagram neural network, and updating an adjacent matrix in real time; a plurality of agent clusters are deployed, the capabilities of encrypted traffic analysis and attack blocking are improved, and the problems of data layer defects, attack and defense confrontation limitation and decision-making layer bottleneck in the prior art are solved.
Owner:北京国瑞数智技术有限公司

Network traffic data security assessment method and system based on deep learning

InactiveCN120455172ASecuring communicationNeural learning methodsProbabilistic risk assessmentData set
The invention provides a network traffic data security assessment method and system based on deep learning. The method comprises the following steps: converting original network traffic data into a graph structure data set comprising a topological structure, node attributes and time sequence behaviors; in the process, the time-space fusion input tensor is formed through the association strength between adjacent matrix and Laplacian matrix coding network entities and the fusion of time sequence characteristics extracted by time window slices. Compared with traditional flow analysis which only pays attention to a single protocol or a rate threshold value, the method achieves global relevance expression of network behaviors through graph structure modeling. Through graph structure modeling, multi-dimensional feature fusion and probabilistic risk assessment, the method can adapt to dynamic change of network topology and continuous evolution of an attack mode, so that a final assessment result is more accurate.
Owner:URUMQI VOCATIONAL UNIV

Non-intrusive network flow real-time analysis method and system based on eBPF

The invention relates to the technical field of network flow analysis, in particular to a non-intrusive network flow real-time analysis method and system based on an eBPF, and the method comprises the steps: deploying an eBPF program in a kernel mode, and capturing a network data packet entering a kernel protocol stack in real time; identifying an application layer protocol type and analyzing a key field; the structured data is transmitted to the user mode through the annular buffer area; and the user state carries out TCP stream recombination and session-level aggregation statistics on the structured data. According to the invention, on the premise that application codes are not modified, real-time and structured protocol analysis can be carried out on various common application layer protocols in a kernel layer; end-to-end delay is accurately disassembled through a full-link delay disassembling mechanism, and a performance bottleneck link is positioned; the analysis result is output in the form of structured data, second-level performance statistics and abnormal behavior detection are supported, and the operation and maintenance analysis efficiency and the system observability are remarkably improved.
Owner:HENAN ZHONGYUAN CONSUMER FINANCE CO LTD

Network anomaly traffic monitoring and attack defense system based on artificial intelligence

The invention relates to the field of network security, and discloses a network abnormal traffic monitoring and attack defense system based on artificial intelligence, which comprises a data preprocessing module used for receiving original traffic data, executing cleaning, duplicate removal and normalization processing, and dividing a processing result into data fragments according to a preset time window; the network flow analysis module is used for receiving the data fragments, performing feature extraction and mode analysis and outputting an analysis result representing the flow abnormal degree, and the analysis result at least comprises a score value representing the overall abnormal degree and a feature vector representing the flow mode feature; the attack judgment module is used for comparing the score value with a preset abnormal threshold value so as to judge whether network abnormal traffic exists or not, if yes, the feature vector is further matched with a pre-constructed abnormal traffic type feature library, and a specific abnormal traffic type is determined according to a matching result; and the attack defense module is used for automatically triggering and executing a corresponding defense strategy.
Owner:枣庄职业学院

Pipe network water leakage point detection and distance positioning method based on flow analysis

The invention discloses a pipe network water leakage point detection and distance positioning method based on flow analysis. The method comprises the following steps: S1, constructing a flow balance model of a pipeline network; s2, monitoring the flow state of each node of the pipeline network in real time based on the flow balance model constructed in the step S1, and performing preliminary positioning on a leakage point when pipeline leakage is detected; s3, flow gradient analysis and reverse hydraulic fine positioning: in the suspected leakage area locked in the step S2, meter-scale precision positioning of a water leakage point is realized through a flow gradient analysis and reverse hydraulic iterative model; and S4, a plurality of sensor nodes are arranged on the water leakage pipeline determined in the step S3, detection data are collected, the position of a leakage point is determined according to a related positioning fusion algorithm, comprehensive decision making is carried out on the leakage point and the leakage point determined through flow gradient analysis and reverse hydraulic power in the step S3, and finally the accurate position of the pipeline leakage point is judged. The problems of low precision, weak interference resistance and the like of a traditional method can be solved, and accurate detection of leakage points is realized.
Owner:INNER MONGOLIA NORMAL UNIVERSITY

Method and system for dynamically expanding processing capacity of 4G baseband

The invention relates to the technical field of capacity evaluation and redistribution, in particular to a 4G baseband processing capacity dynamic expansion method and system, which comprises the following steps: acquiring a scheduling cycle connection request and rate, generating a load identifier in combination with a processing utilization rate trend, cross-positioning a high-density target block matching activation path, and carrying out dynamic expansion on the 4G baseband processing capacity. Extracting a frequency band request frequency and a flow analysis bearing level, processing interference intensity sorting frequency resources, screening frequency points, and splicing to generate a path configuration result. According to the invention, the connection request number and the data transmission rate in the 4G baseband scheduling period are collected to accurately identify the increased load section, the potential load rising pressure can be perceived in advance, the target block is crossly positioned according to the connection request position distribution and the data aggregation degree, and the processing resources are accurately bound to the high-demand path. The precision of spectrum resource scheduling is enhanced through priority ordering, and communication quality guarantee and continuous supply of processing resources in a high-concurrency access scene are supported.
Owner:SICHUAN QIANKUN COMMUNICATION TECHNOLOGY CO LTD +1

Internet of Things service quality management method and system based on adaptive flow optimization

The invention relates to an internet of things quality of service (QoS) management method and system, and aims to solve the problem that the internet of things quality of service is unstable through a self-adaptive flow optimization technology. The system comprises a device identification module, a flow analysis module, a flow prediction module, a resource allocation module, a congestion control module, a safety guarantee module, a user feedback module and the like, predicts a flow trend by using a machine learning algorithm, dynamically adjusts resource allocation, and improves network efficiency and user experience. The method is suitable for various scales of Internet of Things environments, and is of great significance for promoting the development of the Internet of Things technology.
Owner:NINGBO HEIFANG INFORMATION TECH CO LTD

Dynamic honeypot deployment and optimization method and system based on intelligent flow analysis

The invention provides a dynamic honeypot deployment and optimization method and system based on intelligent flow analysis, and belongs to the field of computer security and network security. The method comprises the following steps: collecting network traffic and preprocessing to obtain a feature vector; then, the trained random forest model is used for carrying out attack type identification on the network flow; clustering analysis is carried out on all the attack traffic, similar attack traffic forms clusters, priority ranking is carried out on the clusters, honeypots of corresponding positions and types are deployed according to matching rules in the sequence of the priorities of the clusters from high to low, and the attack traffic belonging to a certain cluster is introduced into the corresponding honeypot; a deep Q network is used in each honeypot for learning, and the optimal balance between the capture rate and the resource utilization rate is realized by modifying the configuration of the honeypot and observing the capture condition of attack traffic and the resource consumption of the honeypot. According to the method, intelligent deployment of the honeypot and dynamic configuration in the honeypot are realized, the attack capture rate of the honeypot is improved, and the resource utilization rate is maximized.
Owner:ZHEJIANG GUOLI SECURITY TECH CO LTD

Suspicious traffic analysis method and system

The invention provides a method and system for judging suspicious traffic in encrypted traffic, and the method comprises the steps: collecting to-be-detected encrypted traffic, and extracting the encrypted traffic features of the to-be-detected encrypted traffic; wherein the encrypted traffic feature comprises a first traffic feature and a second traffic feature, and the second traffic feature comprises domain name popularity; the second traffic feature is determined based on a malicious neighborhood value determined according to the relation graph; the relation graph comprises domain name nodes, entity nodes, edges connecting the entity nodes and edges connecting the entity nodes and the domain name nodes, and the edge attributes of the edges of the relation graph comprise communication related data and traffic types; determining the traffic type of the to-be-measured encrypted traffic based on the encrypted traffic feature of the to-be-measured encrypted traffic, the traffic type including normal traffic and suspicious traffic; and in response to the fact that the traffic type of the to-be-tested encrypted traffic is suspicious traffic, performing subsequent decryption analysis on the to-be-tested encrypted traffic through a decryption DPI module.
Owner:EXANDS INFORMATION TECH CO LTD

Unknown exploit detection using attack traffic analysis and real-time attack event streaming

Techniques for unknown exploit detection using attack traffic analysis and real-time attack event streaming are disclosed. In some embodiments, a system / process / computer program product for exploit detection using attack traffic analysis and real-time attack event streaming includes receiving a stream that includes a plurality of attack events from a security platform at a cloud security service; generating a cluster of attack events from the stream; and tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.
Owner:PALO ALTO NETWORKS INC

Transform encrypted traffic classification method based on pre-training and structure optimization fine tuning

The invention discloses an encrypted traffic classification method based on Transform, and belongs to the technical field of network security and encrypted traffic analysis. In order to solve the problems that load content in a novel encryption protocol (such as TLS 1.3 and VPN) is encrypted, structural disturbance is complex, category distribution is unbalanced and the like, the invention provides a dual-phase Transform framework (DPFT) with pre-training and structure optimization fine tuning. According to the framework, two self-supervision tasks of masked burst prediction (MBP) and burst structure discrimination (BSDT) are introduced in a pre-training stage, and deep data packet representation is learned from unlabeled traffic, so that the deep data packet representation is learned from the unlabeled traffic; in the fine tuning stage, dynamic weighting of word embedding and position embedding, multi-head attention pooling and Focus Loss are adopted, so that the modeling capability of the model on an encrypted traffic complex structure is enhanced, and the recognition sensitivity on minority class samples is improved. Experimental results show that the method disclosed by the invention is obviously superior to the existing method on various encrypted traffic data sets (including TLS 1.3, VPN, malicious traffic and the like), and achieves leading performance on classification accuracy and macro average F1 index.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Traffic flow prediction method and device, storage medium and electronic equipment

The invention discloses a traffic flow prediction method and device, a storage medium and electronic equipment. The method relates to the technical field of traffic flow analysis, and comprises the following steps: constructing a multi-source traffic data pool, and preprocessing historical traffic data in the multi-source traffic data pool to obtain a target multi-source traffic data pool; performing data enhancement processing on the historical traffic data in the target multi-source traffic data pool by adopting a pre-trained GANs model to obtain an enhanced sample set for training a target traffic flow prediction model; performing model training on an initial traffic flow prediction model by adopting a Dropout method based on the enhanced sample set to obtain a target traffic flow prediction model meeting a preset condition; and performing traffic flow prediction on multi-source traffic data acquired in real time by using the target traffic flow prediction model to obtain a traffic flow prediction result. According to the method, the accuracy of urban traffic flow prediction can be improved.
Owner:ANHUI POLYTECHNIC UNIV MECHANICAL & ELECTRICAL COLLEGE

Power monitoring system intrusion detection method and system based on flow analysis

The invention relates to the field of electric power monitoring, in particular to an electric power monitoring system intrusion detection method and system based on flow analysis. The method comprises the following steps: collecting network traffic, analyzing and recombining to obtain structured session data; time sequence behavior features and function code distribution features are extracted to construct a multi-dimensional feature set; inputting the feature set into a compliance rule base and a behavior baseline model in parallel, and respectively outputting a rule matching result and an abnormal deviation degree score; generating a comprehensive threat index by adopting a weighted decision fusion strategy; and when the index exceeds a dynamic threshold value, intrusion is determined and an alarm is given. According to the invention, the problem of insufficient precision and adaptability caused by single feature dimension and isolated detection mechanism is solved.
Owner:LINZHANG POWER SUPPLY BRANCH OF STATE GRID HEBEI ELECTRIC POWER CO LTD +2

Network traffic aggregation analysis method based on deep learning

The invention relates to the field of network traffic analysis, and particularly discloses a network traffic aggregation analysis method based on deep learning, which comprises the following steps: extracting a traffic data packet subset of a specified source I P address from an original data packet captured by a network interface, and carrying out time sequence modeling on the historical traffic data packet subset by utilizing a deep learning algorithm to obtain a network traffic aggregation analysis result; the method comprises the following steps: dynamically screening a plurality of historical network traffic behavior mode time sequence fragments most related to a current behavior mode based on a latest network traffic time sequence characteristic to form a candidate attribution group by using a source IP address as a source IP address to capture a reference behavior mode of the network traffic of the source IP address; and flow mode incremental aggregation learning is carried out on the newest network flow time sequence mode characteristics and the candidate group characteristics, and behavior migration of the newest flow mode is mined, so that dynamic updating and accurate description of the network flow behavior of the source IP address are realized. According to the method, the time sequence evolution rule of the network traffic behavior can be effectively captured, and the timeliness and accuracy of abnormal traffic detection and behavior pattern analysis are improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Password plaintext risk monitoring system and method based on traffic analysis and large model

The invention discloses a password plaintext risk monitoring system and method based on traffic analysis and a large model. The method comprises the following steps: collecting related basic information based on a traffic background environment to construct a knowledge base; analysis is carried out based on the pre-collected traffic, marking analysis is carried out on field information identified in the traffic, and a prompt word library is generated; the method comprises the following steps: collecting environment traffic, performing traffic analysis on the collected traffic, extracting interaction information in the traffic, performing cleaning and structural processing, and submitting the interaction information to a password plaintext risk identification agent; and the intelligent agent performs analysis through large model capability according to submitted content in combination with a knowledge base and cue words, judges a password plaintext state in the traffic information, and finally generates a risk report and returns the risk report. According to the method, the accuracy of password plaintext risk identification is improved through the intelligent analysis capability of the large model.
Owner:FUJIAN FUJITSU COMM SOFTWARE CO LTD

Water gate intelligent control data real-time processing method based on edge calculation

The invention discloses a sluice intelligent control data real-time processing method based on edge calculation, and relates to the technical field of sluice control data analysis, and the method comprises the following steps: obtaining the basic feature data of a sluice, obtaining the sluice opening degree flow relation, and collecting the related data of a water body in real time; in the water gate opening or closing process, the gate passing flow under different opening degrees is collected, data preprocessing is carried out, and basic opening degree flow data are obtained; theoretical opening flow analysis is carried out to obtain theoretical opening flow data; gate blockage analysis is carried out based on the basic opening flow data and the theoretical opening flow data, and the gate blockage condition is obtained; the method is used for solving the problems that when an existing water gate control data analysis technology is used for diagnosing and analyzing the water gate blocking condition through the lockage flow, blocking abnormity and opening abnormity cannot be accurately distinguished according to the deviation between the theoretical lockage flow and the actual lockage flow in the gate opening change process, and meanwhile the blocking condition cannot be judged.
Owner:YELLOW RIVER INST OF HYDRAULIC RES YELLOW RIVER CONSERVANCY COMMISSION

Intelligent control method and system of Internet protection gateway

The invention relates to the technical field of network security, and discloses an intelligent control method and system for an Internet protection gateway, and the method comprises the following steps: obtaining network flow, and extracting a multi-mode state feature; and performing causal reasoning in combination with the knowledge graph to generate causal features. After fusing the two features, inputting the two features to three agents, namely a flow analysis agent, a response strategy agent and a resource scheduling agent, for collaborative decision, and generating a security strategy and a resource scheme; according to the scheme, dynamic deployment is carried out on heterogeneous computing resources, flow processing is completed, and data are recorded; and finally, iteratively optimizing the agent model by utilizing the disposal data, and applying the optimized model to the next round of decision. According to the method, the multi-modal state features including the basic features, the application layer semantics and the time sequence information are extracted, the network security knowledge graph is further constructed for causal relationship reasoning, and isolated network events are placed in a wider logic relationship for analysis, so that the depth and accuracy of network threat identification are improved.
Owner:BAIGE ONLINE (XIAMEN) DIGITAL TECHNOLOGY CO LTD

Encrypted domain name resolution protocol simulation and representation system

The invention discloses an encrypted domain name resolution protocol simulation and characterization system, and relates to the technical field of network security and network traffic analysis. The invention aims to simulate an encrypted domain name resolution process in a real network environment, collect the flow of the process and extract features to construct a data set, and ensure the quality of the generated data set through data enhancement and a data set evaluation scheme. The system comprises a traffic simulation module, a traffic representation module, a data enhancement module and a data set evaluation module. The flow simulation and characterization module simulates and encrypts domain name resolution flow and extracts a structured feature vector containing 34 side channel features; and the data enhancement and data set evaluation module is used for enhancing a feature set based on a conditional table generative adversarial network CTGAN so as to construct a feature data set which is closer to traffic in a real network environment, and ensuring that the constructed data set has engineering availability and theoretical rationality through evaluation. The system can be used for constructing a current scarce encrypted domain name resolution protocol side channel feature data set, and provides data support for related security detection and research.
Owner:HARBIN INST OF TECH

Sensitive data anomaly cross-border detection method and system based on traffic analysis

The present application relates to a method and system for cross-border detection of abnormal sensitive data based on traffic analysis, wherein the method includes: obtaining multiple target flow sessions to be detected; analyzing each target flow session through a dynamic risk assessment model, and performing risk assessment based on a risk score based on reported information, a risk score based on historical behavior, and a comprehensive risk assessment rule matched according to the current business scenario to obtain a risk value; the dynamic risk assessment model is dynamically adjusted according to the data flow behavior; when it is detected that the risk value corresponding to the target flow session exceeds a preset risk threshold, a real-time warning is triggered. Through this application, the problem that the existing detection method is difficult to dynamically adapt to changes in data flow in complex scenarios of cross-border data flow, resulting in false positives and false negatives of sensitive data, is solved, and dynamic adaptation to changes in data flow in complex scenarios of cross-border data flow is achieved to avoid false positives and false negatives of sensitive data.
Owner:ZHEJIANG UNIV +1

Cryptographic algorithm and protocol test system

The invention discloses a cryptographic algorithm and protocol test system, the system is configured into two deployment modes: a transparent mode and a man-in-the-middle mode, the transparent mode can hide an IP or MAC address of a device, and certificate and algorithm information in a cryptographic protocol is identified and analyzed through a passive traffic analysis mode; the man-in-the-middle mode provides a dynamic packet changing function, realizes a dynamic interaction function with a server in an agent mode, can be used for application scenarios such as identity authentication, data encryption and decryption, protocol vulnerability analysis and performance test, can effectively improve the evaluation integrity and accuracy of a cryptographic algorithm and a cryptographic protocol, forms a complete and accurate test evaluation evidence chain, and improves the evaluation efficiency of the cryptographic algorithm and the cryptographic protocol. And the detection evaluation result is effectively supported. The system can be accessed to a production network to capture, identify and analyze network traffic, so that an international / national cryptographic algorithm and protocol security analysis function is realized, and verification and analysis on compliance, correctness, effectiveness and the like of password application in an important network and information system can be realized.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

Vehicle-road cooperation roadside signal processing device and method

The invention provides a vehicle-road cooperation roadside signal processing device. The vehicle-road cooperation roadside signal processing device comprises a high-definition camera, a laser radar, a millimeter-wave radar and a signal lamp collector which are arranged on the roadside. The RSU module is connected with the intelligent network connection vehicle and the edge computing node and is used for transmitting the vehicle position, the driving intention, the early warning information and the control instruction to the intelligent network connection vehicle and the edge computing node; the edge computing node comprises a data management module, a fusion sensing module, an application function module and a system management module, and the system management module performs monitoring, log level-to-level management, crash restart strategy and OTA updating functions on equipment states. The invention also provides a vehicle-road cooperation roadside signal processing method, which comprises the steps of designing parameter configuration, collecting data, generating traffic participant data based on a multi-sensor data fusion algorithm, and carrying out ROI partitioning and marking to generate an event detection analysis result and a traffic flow analysis result.
Owner:SHANGHAI LINGANG NEW AREA DIGITAL INFRASTRUCTURE INVESTMENT & DEVELOPMENT CO LTD

Encrypted traffic analysis method based on interaction spatio-temporal characteristics

The invention provides an encrypted traffic analysis method based on interaction spatio-temporal characteristics, relates to the field of network security, and aims at an original encrypted stream to construct a FITDect model consisting of an input layer, a GNN layer, an MLP layer and an output layer, and dynamically characterizes the traffic interaction diagram by mining the spatio-temporal interaction relationship of data packets in the original encrypted stream, constructing a dynamic traffic interaction diagram, and finally, analyzing the encrypted traffic. And analyzing a space-time coupling relationship through a GNN layer of the FITDect model by utilizing layered feature extraction, performing classification decision by utilizing an MLP layer of the FITDect model, sending a classification result to an output layer, and finally outputting an analysis result. According to the method, the problems that an existing deep flow detection technology depends on shallow statistical characteristics and a traditional deep packet detection technology fails are solved, fusion analysis of encrypted flow spatio-temporal characteristics is realized, the characterization capability of a model on encrypted flow hidden behaviors is remarkably enhanced, and a hidden behavior mode of the encrypted flow can be effectively captured.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Automatic creation of adaptive application aware routing policies on a software-defined wide area network (sd-wan)

This disclosure describes techniques for improving routing policy awareness in a network. The method includes detecting, by a controller, an application initiated for use at an edge node of a network. Then, generating, by an analytics engine coupled to the controller, analytical data of traffic flow at the edge node of the network wherein the traffic flow is in accordance with a routing policy for routing traffic associated with the application. Further, routing of the traffic through a path from one or more paths configured at the edge node that is in accordance with at least a Service Level Agreement (SLA) for traffic flow. Also, in response to an SLA violation during routing of the traffic, causing an action, by the controller, of routing traffic flow through another path that is in accordance with at least the SLA for traffic flow based on analytical data received of the traffic flow.
Owner:CISCO TECHNOLOGY INC

Multi-label website fingerprint identification method and system based on attribution analysis

The invention discloses a multi-label website fingerprint identification method and system based on attribution analysis, and the method comprises the steps: firstly carrying out the model attribution analysis of a training sample, and constructing an average discrimination template of each website category; high contribution areas of all categories are extracted according to the average discrimination template, and a structured mask template used for guiding identification is formed; in the identification stage, sliding window matching is carried out on input hybrid network traffic, the position of a potential pseudo sub-stream is judged according to the similarity between a mask template and a window sub-sequence, and single-label identification is carried out on the extracted pseudo sub-stream, so that effective analysis of multi-label traffic is realized. The method has the advantages of being high in structure perception, high in template generalization and good in mixed flow adaptability, the website recognition capacity in a complex network environment can be remarkably improved, and the method is suitable for scenes such as encrypted communication monitoring and anonymous channel flow analysis.
Owner:SICHUAN UNIV

Tor network exit flow identification system and method fusing multi-scale LSTM (Long Short Term Memory) and Transform network

The invention discloses a Tor network exit traffic identification system and method fusing a multi-scale LSTM and a Transform network, and belongs to the technical field of anonymous network traffic analysis and network security. The system comprises five core components, namely a multi-scale feature extraction module, a feature fusion module, a global dependency modeling module, a dynamic weighted aggregation module and a classification module. The multi-scale feature extraction module adopts parallel bidirectional LSTM branches with different time resolutions to capture a microcosmic burst mode and a macroscopic session behavior at the same time; the feature fusion module unifies the scale features to the same time sequence length and splices the scale features; the global dependence modeling module utilizes a multi-head self-attention mechanism to learn long-distance time sequence dependence; the dynamic weighted aggregation module highlights a key time slice through adaptive weight pooling; and the classification module outputs website category labels. According to the system, the recognition accuracy on a GTT23 data set is remarkably improved compared with that of an existing method, and good recognition capability and robustness are shown for various flow defense mechanisms.
Owner:JIANGSU UNIV

Large model-based data security risk automatic research and judgment processing system and method

The large-model-based data security risk automatic research and judgment processing system comprises a fusion research and judgment module which is used for carrying out comprehensive research and judgment on the risk level, attack intention and potential influence of a security event based on security data in combination with deep learning and a large-scale language model, and transmitting a research and judgment conclusion to an automatic processing module; the business process disassembling and analyzing module is used for automatically discovering and modeling based on the security data through process mining and flow analysis, perceiving a business process and a dependency graph associated with a security event in real time, evaluating potential influences of different disposal measures on business continuity, and transmitting business influence evaluation to the automatic disposal module; and the automatic disposal module is used for selecting and executing an optimal risk disposal strategy from the security strategy library by adopting a distributed architecture of an AI intelligent agent according to the research and judgment conclusion and the business influence evaluation. The accuracy of alarm study and judgment is improved, 'alarm fatigue 'is relieved, and the method has high elasticity, high fault tolerance and strong cooperative capability.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH