Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

300 results about "Traffic analysis" patented technology

Traffic analysis is the process of intercepting and examining messages in order to deduce information from patterns in communication, which can be performed even when the messages are encrypted. In general, the greater the number of messages observed, or even intercepted and stored, the more can be inferred from the traffic. Traffic analysis can be performed in the context of military intelligence, counter-intelligence, or pattern-of-life analysis, and is a concern in computer security.

Multi-stage spatial-temporal clustering method and system based on fused mahalanobis distance

ActiveCN121051489AData setAlgorithm
The invention discloses a multi-stage spatial-temporal clustering method and system based on a fused mahalanobis distance. The method comprises the following steps: acquiring a spatio-temporal data set, and determining a spatio-temporal neighbor relation of samples in the data set; calculating a space communication distance and a time decay distance of the sample; fusing the space communication distance and the time decay distance by using a mahalanobis distance to obtain a relative distance of the sample; selecting a class cluster center from the data set according to the local density of the sample and the relative distance; adopting a multi-stage distribution strategy to distribute non-class-cluster center samples to corresponding class clusters; wherein the multi-stage allocation strategy comprises an inevitable allocation stage based on space-time shared neighbor and a similarity allocation stage based on a weighted similarity matrix. According to the method, the key problems that an existing space-time clustering algorithm is insufficient in space-time attribute coupling processing and sensitive to distribution errors are solved, and the clustering accuracy, robustness and practicability in the fields of intelligent traffic analysis, seismic sequence recognition and the like are remarkably improved.
Owner:NANCHANG INST OF TECH

Non-intrusive network flow real-time analysis method and system based on eBPF

The invention relates to the technical field of network flow analysis, in particular to a non-intrusive network flow real-time analysis method and system based on an eBPF, and the method comprises the steps: deploying an eBPF program in a kernel mode, and capturing a network data packet entering a kernel protocol stack in real time; identifying an application layer protocol type and analyzing a key field; the structured data is transmitted to the user mode through the annular buffer area; and the user state carries out TCP stream recombination and session-level aggregation statistics on the structured data. According to the invention, on the premise that application codes are not modified, real-time and structured protocol analysis can be carried out on various common application layer protocols in a kernel layer; end-to-end delay is accurately disassembled through a full-link delay disassembling mechanism, and a performance bottleneck link is positioned; the analysis result is output in the form of structured data, second-level performance statistics and abnormal behavior detection are supported, and the operation and maintenance analysis efficiency and the system observability are remarkably improved.
Owner:HENAN ZHONGYUAN CONSUMER FINANCE CO LTD

Transform encrypted traffic classification method based on pre-training and structure optimization fine tuning

The invention discloses an encrypted traffic classification method based on Transform, and belongs to the technical field of network security and encrypted traffic analysis. In order to solve the problems that load content in a novel encryption protocol (such as TLS 1.3 and VPN) is encrypted, structural disturbance is complex, category distribution is unbalanced and the like, the invention provides a dual-phase Transform framework (DPFT) with pre-training and structure optimization fine tuning. According to the framework, two self-supervision tasks of masked burst prediction (MBP) and burst structure discrimination (BSDT) are introduced in a pre-training stage, and deep data packet representation is learned from unlabeled traffic, so that the deep data packet representation is learned from the unlabeled traffic; in the fine tuning stage, dynamic weighting of word embedding and position embedding, multi-head attention pooling and Focus Loss are adopted, so that the modeling capability of the model on an encrypted traffic complex structure is enhanced, and the recognition sensitivity on minority class samples is improved. Experimental results show that the method disclosed by the invention is obviously superior to the existing method on various encrypted traffic data sets (including TLS 1.3, VPN, malicious traffic and the like), and achieves leading performance on classification accuracy and macro average F1 index.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Traffic flow prediction method and device, storage medium and electronic equipment

The invention discloses a traffic flow prediction method and device, a storage medium and electronic equipment. The method relates to the technical field of traffic flow analysis, and comprises the following steps: constructing a multi-source traffic data pool, and preprocessing historical traffic data in the multi-source traffic data pool to obtain a target multi-source traffic data pool; performing data enhancement processing on the historical traffic data in the target multi-source traffic data pool by adopting a pre-trained GANs model to obtain an enhanced sample set for training a target traffic flow prediction model; performing model training on an initial traffic flow prediction model by adopting a Dropout method based on the enhanced sample set to obtain a target traffic flow prediction model meeting a preset condition; and performing traffic flow prediction on multi-source traffic data acquired in real time by using the target traffic flow prediction model to obtain a traffic flow prediction result. According to the method, the accuracy of urban traffic flow prediction can be improved.
Owner:ANHUI POLYTECHNIC UNIV MECHANICAL & ELECTRICAL COLLEGE

Power monitoring system intrusion detection method and system based on flow analysis

The invention relates to the field of electric power monitoring, in particular to an electric power monitoring system intrusion detection method and system based on flow analysis. The method comprises the following steps: collecting network traffic, analyzing and recombining to obtain structured session data; time sequence behavior features and function code distribution features are extracted to construct a multi-dimensional feature set; inputting the feature set into a compliance rule base and a behavior baseline model in parallel, and respectively outputting a rule matching result and an abnormal deviation degree score; generating a comprehensive threat index by adopting a weighted decision fusion strategy; and when the index exceeds a dynamic threshold value, intrusion is determined and an alarm is given. According to the invention, the problem of insufficient precision and adaptability caused by single feature dimension and isolated detection mechanism is solved.
Owner:LINZHANG POWER SUPPLY BRANCH OF STATE GRID HEBEI ELECTRIC POWER CO LTD +2

Encrypted domain name resolution protocol simulation and representation system

The invention discloses an encrypted domain name resolution protocol simulation and characterization system, and relates to the technical field of network security and network traffic analysis. The invention aims to simulate an encrypted domain name resolution process in a real network environment, collect the flow of the process and extract features to construct a data set, and ensure the quality of the generated data set through data enhancement and a data set evaluation scheme. The system comprises a traffic simulation module, a traffic representation module, a data enhancement module and a data set evaluation module. The flow simulation and characterization module simulates and encrypts domain name resolution flow and extracts a structured feature vector containing 34 side channel features; and the data enhancement and data set evaluation module is used for enhancing a feature set based on a conditional table generative adversarial network CTGAN so as to construct a feature data set which is closer to traffic in a real network environment, and ensuring that the constructed data set has engineering availability and theoretical rationality through evaluation. The system can be used for constructing a current scarce encrypted domain name resolution protocol side channel feature data set, and provides data support for related security detection and research.
Owner:HARBIN INST OF TECH

Automatic creation of adaptive application aware routing policies on a software-defined wide area network (sd-wan)

This disclosure describes techniques for improving routing policy awareness in a network. The method includes detecting, by a controller, an application initiated for use at an edge node of a network. Then, generating, by an analytics engine coupled to the controller, analytical data of traffic flow at the edge node of the network wherein the traffic flow is in accordance with a routing policy for routing traffic associated with the application. Further, routing of the traffic through a path from one or more paths configured at the edge node that is in accordance with at least a Service Level Agreement (SLA) for traffic flow. Also, in response to an SLA violation during routing of the traffic, causing an action, by the controller, of routing traffic flow through another path that is in accordance with at least the SLA for traffic flow based on analytical data received of the traffic flow.
Owner:CISCO TECHNOLOGY INC

Multi-label website fingerprint identification method and system based on attribution analysis

The invention discloses a multi-label website fingerprint identification method and system based on attribution analysis, and the method comprises the steps: firstly carrying out the model attribution analysis of a training sample, and constructing an average discrimination template of each website category; high contribution areas of all categories are extracted according to the average discrimination template, and a structured mask template used for guiding identification is formed; in the identification stage, sliding window matching is carried out on input hybrid network traffic, the position of a potential pseudo sub-stream is judged according to the similarity between a mask template and a window sub-sequence, and single-label identification is carried out on the extracted pseudo sub-stream, so that effective analysis of multi-label traffic is realized. The method has the advantages of being high in structure perception, high in template generalization and good in mixed flow adaptability, the website recognition capacity in a complex network environment can be remarkably improved, and the method is suitable for scenes such as encrypted communication monitoring and anonymous channel flow analysis.
Owner:SICHUAN UNIV

Tor network exit flow identification system and method fusing multi-scale LSTM (Long Short Term Memory) and Transform network

The invention discloses a Tor network exit traffic identification system and method fusing a multi-scale LSTM and a Transform network, and belongs to the technical field of anonymous network traffic analysis and network security. The system comprises five core components, namely a multi-scale feature extraction module, a feature fusion module, a global dependency modeling module, a dynamic weighted aggregation module and a classification module. The multi-scale feature extraction module adopts parallel bidirectional LSTM branches with different time resolutions to capture a microcosmic burst mode and a macroscopic session behavior at the same time; the feature fusion module unifies the scale features to the same time sequence length and splices the scale features; the global dependence modeling module utilizes a multi-head self-attention mechanism to learn long-distance time sequence dependence; the dynamic weighted aggregation module highlights a key time slice through adaptive weight pooling; and the classification module outputs website category labels. According to the system, the recognition accuracy on a GTT23 data set is remarkably improved compared with that of an existing method, and good recognition capability and robustness are shown for various flow defense mechanisms.
Owner:JIANGSU UNIV

Large model-based data security risk automatic research and judgment processing system and method

The large-model-based data security risk automatic research and judgment processing system comprises a fusion research and judgment module which is used for carrying out comprehensive research and judgment on the risk level, attack intention and potential influence of a security event based on security data in combination with deep learning and a large-scale language model, and transmitting a research and judgment conclusion to an automatic processing module; the business process disassembling and analyzing module is used for automatically discovering and modeling based on the security data through process mining and flow analysis, perceiving a business process and a dependency graph associated with a security event in real time, evaluating potential influences of different disposal measures on business continuity, and transmitting business influence evaluation to the automatic disposal module; and the automatic disposal module is used for selecting and executing an optimal risk disposal strategy from the security strategy library by adopting a distributed architecture of an AI intelligent agent according to the research and judgment conclusion and the business influence evaluation. The accuracy of alarm study and judgment is improved, 'alarm fatigue 'is relieved, and the method has high elasticity, high fault tolerance and strong cooperative capability.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH

Multi-modal detection method and system for abnormal risk traffic of private network based on AI

The invention discloses an AI-based private network abnormal risk traffic multi-modal detection method and system, relates to the technical field of network security, and is used for solving the problem that compound attacks which are high in concealment and have service context association are difficult to effectively identify in a private network. The method comprises the following steps: firstly, injecting business semantics for flow analysis through multi-modal data acquisition and business intention marking; then, by adopting a mode of combining session boundary stability analysis and protocol compliance verification, detecting anomalies from two dimensions of microscopic protocol operation and macroscopic behavior trend respectively, and generating risk events of different levels; finally, an attack chain judgment mechanism is constructed through time sequence correlation analysis, a front-end detection strategy is dynamically optimized based on a judgment result, a closed-loop detection system from data collection to threat response is formed, and the detection accuracy of advanced threats in the private network environment and the self-adaptive capacity of the system are effectively improved.
Owner:GUANGZHOU TRUSTMO INFORMATION SYST CO LTD

Interface testing method and device, electronic equipment and storage medium

The embodiment of the invention provides an interface testing method and device, electronic equipment and a storage medium. The method comprises the following steps: executing static code analysis on a to-be-tested system to obtain a code interface list, and executing dynamic flow analysis on the to-be-tested system to obtain a flow interface list; determining an interface document of the to-be-tested system, and analyzing the interface document through a pre-trained large language model to obtain a document interface list; and respectively testing the document interface list through the code interface list and the flow interface list to obtain a test result. According to the scheme, the interface document is analyzed through the large language model, various formats can be compatible, the compatibility of the interface document is improved, and therefore the test accuracy is improved.
Owner:PEOPLE'S INSURANCE COMPANY OF CHINA

Server security protection method and system based on dynamic gateway strategy

The invention relates to the technical field of computer network security, and discloses a server security protection method and system based on a dynamic gateway policy. The method aims at solving the problems that a traditional security gateway is low in protection efficiency, high in false alarm rate and difficult to cope with complex dynamic network attacks due to static rule matching, single flow analysis dimension, strategy updating lagging and poor response collaboration. The method comprises the following steps: receiving an inbound request through a security gateway agent, extracting a multi-dimensional feature, and constructing a structured traffic feature vector; and establishing a dynamic behavior baseline model based on historical normal traffic. According to the scheme, self-adaptive adjustment and minute-level response of the security policy are realized, the false alarm rate is reduced, the detection accuracy of hidden attacks is improved, the continuity of core services under high load is guaranteed, a self-evolution closed loop of'detection-response-learning 'is formed, and the intelligence and reliability of overall protection are enhanced.
Owner:SHENZHEN IBD INTELLIGENT TECH CO LTD

Interface agent system and method based on Web visual configuration

The invention provides an interface proxy system and method based on Web visual configuration. The interface proxy system comprises a Web management platform, a proxy service engine and a data storage and synchronization module, the Web management platform is used for providing a visual Web interface for a user, so that the user performs function operation through the visual Web interface; wherein the function operation at least comprises configuration of a Mock rule, Mock interface preview, flow analysis, and use case recording and playback; the proxy service engine is used for carrying out request forwarding, Mock response and flow recording according to a Mock rule configured by the Web management platform; and the data storage and synchronization module is used for storing user information, project information, Mock rules, flow data and test cases through a MongoDB database. According to the invention, the interface Mock and traffic proxy requirements in a complex service scene can be covered, and the adaptability and expansibility of the system are improved.
Owner:TONGCHENG NETWORK TECH CO LTD

Overseas website access encrypted traffic detection method based on multi-scale information entropy modeling

PendingCN121814387ARealize intelligent identificationSecuring communicationData packWeb site
The invention relates to an overseas website access encrypted traffic detection method based on multi-scale information entropy modeling, and belongs to the technical field of communication. The method comprises the following steps: collecting and preprocessing network traffic, and extracting a data packet byte sequence, a length sequence and a time interval sequence; calculating a multi-scale information entropy matrix of the traffic sequence based on different time scales and packet window scales; inputting the information entropy matrix into a convolutional neural network and attention mechanism fusion method for feature extraction; a long-time dependency relationship is modeled through a self-attention mechanism by using a Transform model, so that the accuracy of flow analysis is further improved; model training optimization is carried out through a cross entropy loss function and an Adam optimization algorithm, and the generalization ability is improved by adopting regularization and data enhancement methods. According to the invention, intelligent identification of Chinese websites and non-Chinese websites is realized in an encrypted traffic environment.
Owner:BEIJING INST OF COMP TECH & APPL

Asset state detection platform, asset state detection method, equipment and storage medium

The invention discloses an asset state detection platform, an asset state detection method, equipment and a storage medium, and relates to the technical field of information processing, and the method comprises the steps: a flow analysis engine module is used for extracting the core identification information and communication feature data of a first asset in protocol flow, and determining a first asset state of the first asset; the SNMP active acquisition module is used for verifying an equipment basic state, a resource load state and a communication state corresponding to the second asset, and determining a second asset state of the second asset; the terminal agent acquisition module is used for receiving the state data packet monitored by the agent module in the third asset, analyzing the state data packet and determining a third asset state of the third asset; the silent asset detection module is used for selecting a target agent through an agent scheduling algorithm, sending a detection request to a fourth asset through the target agent, and determining a fourth asset state of the fourth asset; and the data integration and analysis module is used for realizing asset integration and state analysis and generating an asset state unified view.
Owner:BENXI IRON & STEEL (GROUP) INFORMATION AUTOMATION CO LTD

Malicious message quarantine systems for enhanced security via deep packet inspection

Systems and methods receive, by an internet provider, a network traffic analysis subscription request to screen incoming network traffic using a DPI protocol, the network traffic including data messages from external parties to a plurality of recipient devices, the DPI protocol being configured to detect malicious code by examining contents of data packets as well as a packet header of the data packets and predict that a source of the data packets is likely a fraudulent source, the network traffic analysis subscription request identifying a plurality of subscribed devices. Incoming network traffic directed to the subscribed devices is monitored using the DPI protocol at a network gateway. Based on the monitoring, it is determined that a message that includes data packet(s) is coming from a source predicted to be fraudulent and a screening action is performed to quarantine the message.
Owner:TRUIST BANK

Multi-source data fusion intelligent traffic analysis platform and method for smart city

The invention discloses a multi-source data fusion intelligent traffic analysis platform and method for a smart city, and relates to the technical field of traffic data analysis. Comprising the following steps: S1, collecting traffic analysis data in real time, and carrying out data preprocessing; s2, dividing the urban traffic network into different space units and different time periods, constructing a space-time joint feature data set, quantifying the sensitivity of each space unit and time period combination, and screening sensitive areas; s3, aiming at the space unit and time period combination of the sensitive area, quantifying the abnormal degree, and carrying out space-time clustering and positioning; and S4, generating a corresponding emergency response strategy, synchronously evaluating an abnormal risk propagation probability between space units, adjusting a space early warning range and emergency scheduling measures, and performing visual display and parameter optimization. The method solves the problem that the traditional traffic analysis technology generally focuses on a central hot spot area, so that traffic abnormity in an edge space and an abnormal time period is easy to ignore, and a small crowd high-risk point is difficult to find in time.
Owner:ZTE HAOTIAN (BEIJING) CONSTR TECH CO LTD

A malicious traffic detection method, system, device and storage medium

The application discloses a malicious traffic detection method, system and device and a storage medium, and belongs to the technical field of network traffic analysis and cyberspace security application, and the method comprises the following steps: obtaining traffic statistical information to be detected, and performing format preprocessing on the traffic statistical information to obtain a sample vector; inputting the sample vector into a pre-trained neural network partial framework search network model to obtain a prediction vector; the prediction vector comprises a plurality of prediction values, each prediction value comprises a classification label of itself, a classification label of a maximum prediction value is selected as a final classification label, if the final classification label is malicious, then traffic corresponding to the traffic statistical information is malicious traffic, otherwise, the traffic is non-malicious traffic; the category of the traffic can be determined without manual feature design; by using a relatively light model, the calculation amount is reduced, the model can be deployed on an edge computing node, the feature extraction capability and practicability are enhanced, and the problems of insufficient precision and insufficient universality are overcome.
Owner:NANJING UNIV OF POSTS & TELECOMM

IPv6 traffic analysis method and device, electronic equipment and storage medium

The invention discloses an IPv6 traffic analysis method and device, electronic equipment and a storage medium, and relates to the technical field of communication, and the method comprises the steps: obtaining IPv6 traffic monitoring data of a to-be-verified network; analyzing the IPv6 flow monitoring data, and determining an initial influence factor; the initial influence factor represents a factor influencing the IPv6 flow ratio; verifying the initial influence factor based on the simulation network to obtain a verification result, and obtaining a target influence factor based on the verification result; the verification result represents the influence proportion of the target influence factor on the IPv6 flow ratio. Therefore, the influence proportion of each complex factor on the IPv6 traffic proportion can be verified, and accurate analysis of the IPv6 traffic proportion is realized.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Malicious behavior bypass interception system based on flow analysis and detection

PendingCN121418179ABiological modelsAlarmsSQL injectionAttack
The invention belongs to the technical field of network security protection, and discloses a malicious behavior bypass interception system based on flow analysis and detection, a rule engine quickly matches known attacks based on a dynamic feature library, such as SQL injection, common port scanning, federated learning model combined multi-node cooperative training, and flow time, behavior and content features are combined to realize the flow analysis and detection of malicious behaviors. Unknown threats such as 0day vulnerability variants and low-frequency hidden attacks are accurately captured; in an enterprise mixed service traffic environment, missed judgment of traditional static detection on unknown attacks can be avoided, false alarms caused by data limitation of a single model can be reduced, energy consumption of operation and maintenance personnel for processing invalid alarms is reduced, core assets are prevented from being damaged by novel attacks, and comprehensiveness and reliability of network protection are remarkably improved; a bypass deployment mode is adopted, traffic is obtained through network TAP equipment or traffic mirror images, a service main forwarding link does not need to be intervened, and network delay and single-point failure risks introduced by traditional series deployment are avoided.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Inter-application calling risk monitoring method and system under bypass flow monitoring

The invention provides an inter-application calling risk monitoring method and system under bypass flow monitoring, and belongs to the technical field of network security, and the method comprises the steps: firstly constructing a dynamically updated application IP library and an application asset list through the combination of active scanning and passive flow analysis; then, performing dual matching on the source IP and the target IP of the bypass flow and an application IP library, and accurately screening out inter-application calling flow; then, carrying out deep analysis on the screened traffic, extracting key information, associating the key information with an application asset list, and constructing a fine-grained calling relation unit and a global calling relation graph; and finally, defining a normal behavior baseline and a risk rule based on the atlas, and giving an alarm for an abnormal calling behavior. The inter-application calling risk monitoring method and device achieve accurate and efficient monitoring of the inter-application calling risk, do not need business invasion and are low in implementation cost.
Owner:SHENZHEN SHIXI TECH CO LTD

Traffic influence autonomous evaluation system based on natural language processing and working method

The invention discloses a traffic influence autonomous evaluation system based on natural language processing and a working method, and belongs to the technical field of traffic management. In order to solve the problem of difficulty in urban traffic multi-scene analysis iteration, the system comprises a basic data layer, an NLU engine / intelligent processing layer and a user interaction layer, and the basic data layer, the NLU engine / intelligent processing layer and the user interaction layer are connected in sequence; the basic data layer comprises a road network facility database, a model parameter library, a traffic demand matrix and a traffic partition database; the NLU engine / intelligent processing layer comprises a natural language understanding NLU engine, a traffic analysis modeling evaluation module and a report generation module; and the user interaction layer comprises a Web / App graphical user interface, a voice / text input interface, a parameter confirmation and modification panel and an AR / Web visual report board, and realizes interaction between a user and the traffic influence autonomous evaluation system based on natural language processing. The method has the high efficiency of the whole process.
Owner:SHENZHEN URBAN TRANSPORT PLANNING CENT CO LTD +1

An intelligent large model driven heterogeneous traffic analysis method, device and system

The application relates to the technical field of heterogeneous traffic analysis, in particular to a heterogeneous traffic analysis method, device and system driven by an intelligent large model, which comprises the following steps: collecting side channel features of encrypted traffic, correcting a static position coding mode of a Transform model based on the length of each data packet in a single session, the traffic direction and the arrival time stamp relative to the session start time, dynamically coding the side channel features to obtain a first feature vector of each data packet; constructing a second feature vector, a third feature vector and a fourth feature vector; assigning a learnable bias vector to each feature vector to form a modal bias matrix as a learnable parameter in the training process of the Transform model and correcting the attention mechanism in the Transform model; obtaining a fusion feature vector of all feature vectors to perform attack detection on the input traffic. Therefore, the accuracy of traffic detection is improved.
Owner:HEBEI INST OF MACHINERY ELECTRICITY

Terminal certificate state abnormity monitoring method and device based on traffic analysis, electronic equipment and storage medium

The invention discloses a terminal certificate state abnormity monitoring method and device based on flow analysis, electronic equipment and a storage medium, and belongs to the field of network security monitoring, and the method comprises the steps: obtaining a certificate load message and current system time sent by a network access terminal in a key exchange process; analyzing the message to obtain a certificate public key, certificate deadline and a device unique identifier, and calling a historical fingerprint sequence from a local database according to the device unique identifier; performing hash processing on the certificate public key to generate a current public key fingerprint, comparing the current public key fingerprint with a historical fingerprint sequence, and calculating a difference value between certificate deadline and current system time to complete timeliness verification; and integrating the certificate state verification result and the certificate timeliness verification result, determining the current security state of the network access terminal, and generating a state monitoring report. According to the invention, the problem that the terminal certificate historical consistency abnormity cannot be identified in the prior art can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGDONG POWER GRID CO LTD

Network access control list adjusting method based on flow analysis and optimization

The invention provides a network access control list adjusting method based on flow analysis and optimization, which comprises the following steps of: firstly, acquiring total flow information, and then dynamically constructing a network digital twinborn model based on the total flow information; constructing a causal derivation model based on a simulation result of the network digital twin model; analyzing and processing the real-time traffic by using a causal derivation model, and generating a plurality of network access control list change rules and corresponding deployment strategies; and then simulating the network access control list change rules and the deployment strategy thereof in the network digital twin model, and determining a target network access control list from each network access control list change rule based on a simulation result. According to the invention, a self-learning, dynamic risk quantification and strategy automatic generation and verification ACL tuning system is constructed, and the ACL tuning system is not only an optimization rule, but fundamentally changes the generation and management normal form of the ACL.
Owner:BEIJING ITECHSHARE NETWORK INFORMATION TECH CO LTD

A method and system for anti-evasion of tor app traffic analysis

The application discloses an anti-characteristic-unstable Tor App traffic analysis method and system, first extracts basic characteristics and bidirectional statistics of traffic generated by a mobile phone App running on Tor as a candidate characteristic set, then selects a subset from the candidate characteristic set as the representation of the traffic, filters out the traffic of N specific application types by solving an application type combination optimization problem, selects N characteristic subsets from the candidate characteristic set, and iteratively selects a machine learning model and a characteristic set suitable for the specific application type by solving an optimal combination problem, so that the Tor App can be accurately identified. The application solves the problem of characteristic instability in Tor App traffic analysis caused by the instability of the mobile environment, the diversity of app work content and the increasing number of new apps running on Tor.
Owner:JIANGSU UNIV

File restoration method, device, equipment and computer readable storage medium

The embodiment of the present application relates to the technical field of computer communication, and discloses a file restoration method, device and equipment and a computer readable storage medium, wherein the method comprises the following steps: receiving an original code stream; separating the original code stream into a data plane traffic message and a control plane traffic message; distributing the control plane traffic message into an analysis group network card queue and distributing the data plane traffic message into a forwarding group network card queue; performing analysis processing on the control plane traffic message in the analysis group network card queue to obtain a control plane analysis message; forwarding the data plane traffic message in the forwarding group network card queue to a restoration server to perform file restoration processing, and obtaining a restored data plane message; and storing the control plane analysis message and the restored data plane message in association to obtain a restored file. Through the above method, the forwarding service and the analysis service are completely isolated, and the data forwarding throughput and the traffic analysis capability of the analysis server are improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method and system for positioning data stream with null domain name based on task ID

The invention relates to the technical field of network security management and flow analysis, and provides a method and a system for positioning a data flow with a null domain name based on a task ID, and the method comprises the steps: monitoring a synchronous message through a process A, and capturing network flow; the abnormal task ID is received through the process B, and a server IP list is determined according to the corresponding domain name of the abnormal task ID; filtering a Client Hello data stream of a target IP (Internet Protocol) from the captured message; judging whether each data stream carries a Server Name field or not; and counting the proportion of the data streams which do not carry the fields and have null domain names, and outputting an evidence message. The problems that traditional manual analysis is low in efficiency, poor in accuracy and high in personnel skill requirement are solved, and the network security management efficiency is remarkably improved.
Owner:SHANGHAI HENGWEI INTELLIGENT TECH CO LTD

A method for probabilistic quantitative identification of mixed states of urban functional areas by fusing multi-source heterogeneous data

PendingCN122310286AGeoinformaticsMulti source data
This invention discloses a method for probabilistic quantification of mixed states in urban functional areas by integrating multi-source heterogeneous data, belonging to the fields of geographic information science, smart cities, and artificial intelligence. The method includes: S1, constructing a traffic analysis area; S2, acquiring multi-source data; S3, preprocessing the multi-source data acquired in S2; S4, generating true probability distribution labels; S5, extracting socio-semantic features; S6, extracting dynamic activity features; S7, extracting physical scene features; S8, feature fusion and distribution prediction; S9, model training; and S10, determining the mixed state and outputting the results. This invention achieves refined quantification of the mixed states of urban functional areas, outputting a continuous probability distribution vector rather than a single category label, significantly improving the information density and application value of the recognition results.
Owner:NANJING UNIV