Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Traffic classification" patented technology

Traffic classification is an automated process which categorises computer network traffic according to various parameters (for example, based on port number or protocol) into a number of traffic classes. Each resulting traffic class can be treated differently in order to differentiate the service implied for the data generator or consumer.

Device testing method, testing device and storage medium

This application relates to the field of electronic equipment technology, and discloses a device testing method, testing equipment, and storage medium. The method includes: loading and initializing a traffic classification module, a traffic isolation module, and an algorithm module at the kernel network protocol stack of the operating system of the device under test; using the traffic classification module to divert the test data of different test items to different queues based on the information of the test data of each test item in multiple test items; using the algorithm module to perform network impairment processing on the test data flowing through the traffic isolation module, so that the traffic isolation module outputs the impaired data; based on the impaired data, determining whether the network state of the device under test has been configured to a weak network state; if the network state of the device under test has been configured to a weak network state, evaluating the working state of the device under test, and determining the test result of the device under test based on the working state of the device under test. This application can test whether the device under test meets the requirements under a weak network state.
Owner:SHENZHEN JIUNIU YIMAO INTELLIGENT IOT TECH CO LTD

A channel access method and system for UAV local power line inspection tasks

PendingCN122340636AComputer networkChannel access method
This application discloses a channel access method and system for UAV local line inspection tasks, relating to the field of wireless communication. The method includes: classifying the data to be transmitted by communication nodes according to service requirements when the UAV is performing a local line inspection task; continuously sensing the occupancy status of the wireless channel; arbitrating the continuous idle state of the wireless channel based on the service classification result and the sensed channel state indication function, and determining whether the wireless channel meets the access conditions based on a continuous idle determination threshold; if it meets the conditions, generating a random backoff time corresponding to the current service priority according to the upper limit of the backoff window, and performing backoff counting; after the backoff counting is completed, if the pre-transmission review result of the wireless channel state indicates that the wireless channel is in an idle state, transmitting the data to be transmitted corresponding to the current service priority to the wireless channel. This application can improve the access timeliness and link continuity of high-priority C2 services.
Owner:CIVIL AVIATION UNIV OF CHINA

Modality-specific traffic classification in model-as-a-service platform

PCT designated stageWO2026135801A1Resource allocationHardware architectureEngineering
A model-as-a-service (MaaS) platform includes an intelligence layer that tracks modality-specific token utilization for a select customer assigned to use a first instance of a multimodal model. The first instance is instantiated within a supporting hardware architecture that allocates dedicated groups of processing resources to support different modality-specific processing pipelines. The intelligence layer uses the tracked utilization data to generate a predicted token ensemble ratio for the select customer and compares the predicted token ensemble to a compute ensemble ratio determined for each of two or more of other instances of the multimodal model. The intelligence layer re-assigns the select customer to a second instance of the multimodal model in response to determining that the predicted token ensemble ratio is more similar to the compute ensemble ratio of the second instance of the multimodal model than to the compute ensemble ratio of the first instance of the multimodal model.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Programmable data plane high-intensity traffic response method and system based on feature distribution

PendingCN122372332AWire speedInternet traffic
This invention discloses a programmable data plane high-intensity traffic response method and system based on feature distribution, belonging to the field of network traffic classification technology. The programmable data plane high-intensity traffic response method based on feature distribution includes: extracting features from each flow in the data plane and determining whether the features are matched by the current rule; if matched, processing according to the corresponding rule; if not matched, processing as an outlier and recording it; periodically sampling processed flows, triggering rule updates when outliers reach a preset threshold; the control plane uses a density-based clustering algorithm to cluster sampled points to obtain the current traffic feature distribution shape, extracting the boundaries of each cluster to form a high-dimensional rectangle as a new rule, and formulating corresponding processing measures based on spatial features and meta-features, and issuing them to the data plane. This invention achieves line-rate processing and dynamic adaptation on resource-constrained programmable hardware, effectively addressing feature drift under high-intensity traffic while ensuring interpretability.
Owner:UNIV OF JINAN

Encrypted traffic classification method and system based on state space modeling and cross-dimensional scanning

This invention belongs to the field of traffic data processing and relates to a method and system for classifying encrypted traffic based on state-space modeling and cross-dimensional scanning. The original encrypted traffic data is preprocessed to generate image domain samples. Gated detail enhancement is performed on the image domain samples, and these samples are mapped to gated signals and content enhancement signals. Enhanced coupling features are obtained through spatial-channel selective cross-scanning. These enhanced coupling features are then further enhanced locally and extracted step-by-step to finally obtain deep features. Encrypted traffic classification is completed based on these deep features. This invention addresses the characteristics of small grayscale image size and sparse payload in encrypted traffic by accurately capturing multi-dimensional feature associations through cross-scanning and feature extraction, significantly improving the classification accuracy and stability for long-tail categories.
Owner:SHANDONG UNIV OF SCI & TECH

Modality-specific traffic classification in model-as-a-service platform

A model-as-a-service (MaaS) platform includes an intelligence layer that tracks modality-specific token utilization for a select customer assigned to use a first instance of a multimodal model. The first instance is instantiated within a supporting hardware architecture that allocates dedicated groups of processing resources to support different modality-specific processing pipelines. The intelligence layer uses the tracked utilization data to generate a predicted token ensemble ratio for the select customer and compares the predicted token ensemble to a compute ensemble ratio determined for each of two or more of other instances of the multimodal model. The intelligence layer re-assigns the select customer to a second instance of the multimodal model in response to determining that the predicted token ensemble ratio is more similar to the compute ensemble ratio of the second instance of the multimodal model than to the compute ensemble ratio of the first instance of the multimodal model.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network traffic classification method, system, device and storage medium with multi-feature fusion

The application provides a multi-feature fusion network traffic classification method, system, device and storage medium, the method comprising: obtaining target traffic, the target traffic comprising multiple different types of traffic; inputting the target traffic into a network traffic classification model to obtain the traffic type in the target traffic; wherein the network traffic classification model comprises a multi-core convolutional neural network, a bidirectional long short-term memory network and a Transformer model, the multi-core convolutional neural network is used for extracting local features of the target traffic, the bidirectional long short-term memory network is used for extracting time sequence dynamic features according to the local features, and the Transformer model is used for obtaining attention features according to the time sequence dynamic features. The network traffic classification method in the embodiment of the application can effectively distinguish similar types of traffic, is effective in encrypted and obfuscated traffic classification, and has application potential in enhancing a network security system.
Owner:应急管理部大数据中心

Efficient network traffic classification using deterministic finite automata

In one embodiment, a method includes accessing a rule set for a group of networking assets; creating, based on the rule set, a primary automaton including a set of keys, each key including (1) a string identifying a network asset from the group of network assets (2) a separator character following the string and (3) a key branch number identifying a state. The method further includes creating, based on the rule set, one or more secondary automata by creating a secondary automaton for each type of result classification in the rule set; and for each secondary automaton, populating that secondary automaton with a set of values, each including (1) a value branch number identifying a state of that secondary automaton, each value branch number corresponding to a specific key branch number in the primary automaton, and (2) a string identifying a domain identified in the rule set.
Owner:SAMSUNG ELECTRONICS CO LTD

Traffic trajectory generation method for covert communication

PendingCN122332789AData packInternet traffic
This application provides a traffic trajectory generation method for covert communication, relating to the field of adversarial defense technology in network traffic classification. The method includes: extracting packet feature sequences based on sending behavior from a user-given traffic trajectory; extracting traffic statistical features based on packet windows from the packet feature sequences; training a GAN-based traffic feature generation model based on the packet feature sequences and traffic statistical features; constructing a probabilistic statistical model based on the user-given traffic trajectory; and generating a traffic trajectory for covert communication by sequentially using the trained GAN-based traffic feature generation model and the constructed probabilistic statistical model according to the user-input labels. This application designs a feature sequence based on sending behavior and constructs corresponding traffic statistical features based on it. It resolves the contradiction between GAN-generated fixed-length features and the requirement for variable-length network traffic feature sequences, constructing a traffic representation with well-distributed data that is conducive to the generation model.
Owner:HARBIN INST OF TECH AT WEIHAI +1

Traffic forwarding method and related device

PendingCN122268815ATransmissionKnowledge based modelsTraffic characteristicResource utilization
The present disclosure provides a traffic forwarding method and related equipment, and relates to the technical field of traffic management. The method comprises: obtaining real-time traffic data to be forwarded; classifying the real-time traffic data to determine a traffic classification result of the real-time traffic data, wherein the traffic classification result comprises first-type traffic data or second-type traffic data; determining a traffic processing mode based on the traffic classification result and generating a resource scheduling instruction; and issuing the resource scheduling instruction to a data plane, so that the data plane performs traffic forwarding on the real-time traffic data based on the resource scheduling instruction. The present disclosure can perform dynamic hierarchical scheduling based on traffic characteristics, thereby improving resource utilization.
Owner:JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD

A dynamic network-oriented encrypted traffic robust representation method

PendingCN122372150AData packNetwork conditions
This invention discloses a robust representation method for encrypted traffic in dynamic networks, comprising an offline representation knowledge base construction stage and an online representation application stage. In the offline representation knowledge base construction stage, target encrypted protocol traffic is collected under controlled network conditions to construct an observation sequence; the mapping relationship between physical data packets and encrypted bearer units is determined; based on the mapping relationship, the physical byte stream is reconstructed into an encrypted bearer unit sequence, and its length is corrected; the corresponding rules are written into the offline representation knowledge base. In the online representation application stage, the encrypted traffic is reconstructed into an encrypted bearer unit sequence according to the corresponding rules in the knowledge base, and its length is corrected to obtain a structured robust representation, which is then used for downstream encrypted traffic classification tasks. Compared with existing methods that directly use physical data packets as the analysis object, this invention can resist the drift of physical data packets caused by network disturbances in dynamic networks, providing robust representations for downstream tasks.
Owner:SOUTHEAST UNIV

Network traffic classification method, electronic device and computer readable storage medium

This application provides a network traffic classification method, an electronic device, and a computer-readable storage medium. The method includes: segmenting raw network traffic data into multiple samples according to bidirectional flow; extracting byte information, length, and direction information of each sample to generate a multimodal traffic representation sequence; performing unsupervised pre-training on a neural network model composed of Transformer layers and Mamba layers based on the multimodal traffic representation sequence and a masked language model to obtain pre-trained parameter weights; updating the neural network model; and performing few-sample supervised fine-tuning on the neural network model with added multimodal attention fusion mechanism to output the network traffic classification result. This application can solve the problems of insufficient classification ability of existing network traffic classification methods under multi-scenario and small-sample conditions, difficulty in taking into account global and local modeling with a single architecture, insufficient utilization of multimodal traffic structure information, and high model complexity.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

UPF Function Acceleration Method Based on Programmable Hardware

ActiveCN120640318BData packPathPing
This invention discloses a method for accelerating UPF functionality based on programmable hardware, belonging to the field of 5G mobile communication networks. It offloads the traditional CPU-based UPF functionality to the Data Processing Unit (DPU), fully leveraging the architectural advantages of DPU's hardware-software co-processing to significantly reduce packet processing latency and improve system throughput. By parsing and reconstructing dependent matching rules, it generates independent, dependency-free rules, reducing redundancy and conflicts in the hardware rule table. Simultaneously, a traffic classification mechanism is used to divide network traffic into large and small flows, mapping them to hardware and software paths respectively, maximizing the performance advantages of hardware-software co-processing. This invention can significantly optimize packet processing capabilities under high-load scenarios, effectively reduce latency bottlenecks, and improve overall system throughput and resource utilization.
Owner:NANKAI UNIV

Policy remapping upon network events

The techniques described herein relate to a method including: generating a first network policy and a second network policy at a forwarding device within a network, wherein the first network policy is applied to a first traffic classification and the second network policy is applied to a second traffic classification; obtaining first traffic from an endpoint device; classifying the first traffic with the first traffic classification; applying, at the forwarding device, the first network policy to the first traffic; obtaining, at the forwarding device, an indication of a network event within the network; obtaining second traffic from the endpoint device; classifying the second traffic with the second traffic classification in response to obtaining the indication of the network event; and applying, at the forwarding device, the second network policy to the second traffic.
Owner:CISCO TECHNOLOGY INC

HTTP / 3-oriented encrypted traffic ambient noise suppression method

PendingCN122293266APacket arrivalData pack
This invention proposes a noise suppression method for encrypted traffic environments under HTTP / 3, addressing the problem of incomplete traffic features caused by packet loss. The specific steps are as follows: 1) Construct a labeled traffic packet loss dataset based on a publicly available dataset, extracting the packet arrival time series and packet length series for each flow; 2) Train a deep generative model using a self-supervised learning paradigm, with an LSTM network as the core, learning the sequence repair mapping relationship by minimizing the error between the missing sequence and the original complete sequence; 3) In the application phase, monitor and complete real-time traffic: input the collected flow features into the generative model, calculate the difference between the input and output to determine packet loss, and use the output features of the generative model to complete the data when packet loss is detected; otherwise, retain the original features. This method targets encrypted traffic under the HTTP / 3 protocol environment, achieving noise suppression through time-series and length-series recovery modeling, thus improving the reliability of encrypted traffic classification and analysis.
Owner:SOUTHEAST UNIV

A network traffic classification method and system

The application relates to the technical field of flow data processing, and discloses a network flow classification method and system, the method comprising the following steps: acquiring network flow data, and extracting corresponding flows of the network flow data; dividing the flows into a plurality of sessions; aggregating sessions with the same communication direction into a grouping block; converting the grouping block into a two-dimensional gray grouping image; sequentially performing mode conversion and image recognition on the two-dimensional gray grouping image to obtain an image recognition text sequence; and using a classifier to classify the image recognition text sequence to obtain the application type of the network flow. The application can accurately detect and identify unknown network flow, and improves the classification effect and efficiency of the network flow.
Owner:GUANGDONG POLYTECHNIC NORMAL UNIV

A semi-supervised learning-based unknown encrypted traffic fine-grained identification method and system and storage medium

The application relates to an unknown encrypted traffic fine-grained identification method and system based on semi-supervised learning and a storage medium, and the method comprises the following steps: step 1, time-frequency feature extraction and fusion: a time-frequency encoder is designed to extract encrypted traffic features from time and frequency domains in parallel, and cross-time-domain attention and cross-frequency-domain attention mechanisms are used for fusion to obtain final features; step 2, fine-grained known traffic classification: comparative pre-training is performed on the final features of step 1, a classifier is trained under a semi-supervised learning framework, and fine-grained classification of known traffic is realized; step 3, fine-grained unknown traffic identification: nearest neighbor distance is used to realize unknown traffic detection, and deep clustering is performed on the detected unknown traffic to realize fine-grained classification of unknown traffic. The application has the beneficial effects that: 1. The application can reduce the calculation overhead limitation and reduce noise labeling; 2. The application can automatically discover the potential category structure in unknown traffic and does not depend on high-performance computing resources.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A dynamic load balancing method suitable for a weak network environment

PendingCN122247915ATransmissionPathPingDynamic load balancing
This invention discloses a dynamic load balancing method suitable for weak network environments, belonging to the field of network load balancing technology. The method includes the following steps: Step 1: Perform multi-dimensional link status collection in the network, monitor the key performance indicators of the physical and transport layers of each candidate path in real time, and calculate a comprehensive metric for each path; Step 2: Dynamically filter out a set of reliable paths for load balancing; Step 3: Dynamically calculate and adjust the traffic allocation weights of each path, including dynamic weight calculation based on inverse performance ratio, adaptive adjustment of sensitivity index, and weight fine-tuning based on real-time congestion; Step 4: Perform stability control and oscillation suppression; Step 5: Identify different upper-layer applications, and implement traffic classification and differentiated policy execution for different upper-layer application requirements.
Owner:ZHEJIANG UNIV +1

A method and device for all-network target-free intelligent traffic classification DDOS monitoring

The application discloses a method and device for full-network target-free intelligent traffic classification DDOS monitoring, wherein the method comprises the following steps: collecting Netflow traffic sent by a routing device in a full network in real time; after cleaning and normalizing the collected Netflow traffic, extracting feature information thereof, calculating the statistics of the features, and then constructing a baseline model by using an adaptive learning technique according to historical data and traffic patterns; using a K-means clustering algorithm to preliminarily classify the Netflow traffic and identify normal traffic and potential abnormal traffic; using a random forest classifier to further classify the preliminary classification results in detail and accurately identify DDoS attacks in abnormal traffic; combining the classification results with the baseline model to identify DDoS attack traffic, triggering an alarm and executing a defense measure at the same time; and updating the baseline model after the alarm is disposed. The method and device can timely discover abnormal traffic and respond, improving the accuracy and effectiveness of DDoS attack detection.
Owner:CHINA UNITECHS

Traffic classification methods based on session context-sensitive BERT, electronic devices, and media.

This invention discloses a traffic classification method, electronic device, and medium based on session context-sensitive BERT, comprising: acquiring network traffic data; performing session segmentation on the network traffic data to obtain several traffic sessions; tokenizing each traffic session to obtain a session byte sequence; extracting the packet length sequence of all data packets between multiple traffic sessions within a time window and performing multi-granularity temporal aggregation to obtain an inter-session packet length sequence; constructing a session context-sensitive BERT model; the processing includes: encoding the session byte sequence and the inter-session packet length sequence to obtain a first embedding vector and a second embedding vector; using the concatenated first embedding vector and second embedding vector as training samples to construct a joint loss function, thereby pre-training the model; fine-tuning the pre-trained model for downstream traffic classification tasks; and using the fine-tuned model to perform downstream traffic classification tasks.
Owner:ZHEJIANG UNIV

System and Method for Detecting Fraudulent Network Traffic

A method for detecting fraudulent traffic in a computer network including: receiving a packet from a traffic flow; determining data associated with the traffic flow; determining a score associated with each piece of determined data; aggregating an overall score for the traffic flow; and determining whether the traffic flow is trusted based on the overall score. A system for detecting fraudulent traffic in a computer network including: a data processing engine configured to receive a packet from a traffic flow; a data collection module configured to determine data associated with the traffic flow; a data correlation module configured to determining a score associated with each piece of determined data and aggregating an overall score for the traffic flow; and a traffic classification module configured to determine whether the traffic flow is trusted based on the overall score.
Owner:SANDVINE CORP

Meta verse optimization and prioritization system and method therefor

ActiveUS12672022B2Data packData mining
In some embodiments, a metaverse optimization and prioritization enabled cloud-based controller includes a metaverse traffic classification unit; and a metaverse optimization and prioritization unit, wherein based upon the identification and classification of data packets as metaverse data packets, the metaverse optimization and prioritization unit optimizes and prioritizes a metaverse client device and metaverse traffic associated with a metaverse optimization and prioritization enabled network. In some embodiments, the metaverse optimization and prioritization unit optimizes the metaverse client device based upon a quality of experience associated with the metaverse client device. In some embodiments, the metaverse optimization and prioritization unit prioritizes the metaverse traffic based on quality of service management features ascertained utilizing the metaverse optimization and prioritization enabled cloud-based controller.
Owner:META PLATFORMS INC

Method and system for fine-grained traffic generation and labeling for gui agent-based mobile application automation

PendingCN122457505AData packData set
The application discloses a kind of mobile application automation fine-grained traffic generation and marking method and system based on GUI Agent, belongs to mobile communication technical field.The method includes: generating function set according to the description text of target mobile application program, and generating corresponding task for each function;Based on NanoAgent intelligent agent, the task is executed, and the network data packet generated by equipment is captured, and the UI operation sequence with time stamp is extracted from the log module of NanoAgent intelligent agent;Network data packet is cut into several traffic bursts, and the traffic burst is marked based on the UI operation sequence.The application can construct large-scale, low-cost, high-fidelity fine-grained mobile application traffic dataset, significantly improve the accuracy of downstream traffic classification and security analysis task.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Encrypted traffic classification method and system based on state space modeling and cross-dimensional scanning

The present application belongs to the field of flow data processing, and relates to an encrypted traffic classification method and system based on state space modeling and cross-dimensional scanning. The original encrypted traffic data is preprocessed to generate image domain samples. The image domain samples are subjected to gated detail enhancement and mapped into gated signals and content enhancement signals, and the enhanced coupling features are obtained through spatial-channel selective cross scanning. The enhanced coupling features are then subjected to local feature enhancement and further extracted step by step to finally obtain deep features. The encrypted traffic classification is completed based on the deep features. The present application is aimed at the characteristics of small size and sparse load of encrypted traffic grayscale images, and through cross scanning and feature extraction, multi-dimensional feature correlation is accurately captured, and the classification discrimination accuracy and stability under long-tail categories are significantly improved.
Owner:SHANDONG UNIV OF SCI & TECH

Iot terminal low power consumption adaptive communication method and device

The application discloses a kind of low-power consumption self-adapting internet of things terminal communication method and device, the method includes: state acquisition pretreatment, environmental signal adaptation, service hierarchical scheduling, hibernate wake-up control and strategy iteration optimization.Optimal power is calculated, service scheduling, hibernate control and strategy optimization are all realized dynamic adjustment using corresponding formula.The device is set to five function modules corresponding to the method, and cooperates to form a closed loop.The application is adapted to smart home, industrial plant equipment monitoring and other scenes, can dynamically adapt to environmental and service changes, significantly reduce power consumption, improve communication stability, simple structure, strong practicality.
Owner:BEIJING HECHANG COMM TECH CO LTD

An encrypted traffic classification method based on a large language model

The present disclosure provides an encrypted traffic classification method based on a large language model. The method is composed of three modules: an encrypted traffic data preprocessing and two-dimensional table representation construction module, a two-dimensional table representation alignment module, and an end-to-end classification framework module. The two-dimensional table representation of encrypted traffic is constructed by the encrypted traffic data preprocessing and two-dimensional table representation construction module, and the structured metadata and unstructured payload information are uniformly mapped to the semantic space of the large language model. The self-supervised alignment method of the two-dimensional table representation alignment module strengthens the understanding ability of the model for traffic representation. Finally, the end-to-end classification framework module is used to realize the end-to-end process from the original encrypted traffic to the classification result. This solves the problems of insufficient labeled data and diversified classification tasks in the existing encrypted traffic classification task.
Owner:BEIHANG UNIV

Distributed intrusion detection method and system based on flexible secure and trusted federated learning

PendingCN122293441Aimprove securityImprove robustnessDistributed intrusion detectionInternet traffic
This invention discloses a distributed intrusion detection method and system based on flexible, secure, and trusted federated learning, belonging to the field of network data security and sharing. The method includes: dividing nodes into training nodes and aggregation nodes; training nodes collecting network traffic, training a local network traffic classification model, and sending it to an edge network device; the edge network device detecting the uploaded local model and updating the list of trusted and malicious nodes; aggregation nodes aggregating qualified local models and returning the generated global model to the edge device; the edge device receiving the global model, verifying it, and broadcasting it; all training nodes receiving and using the latest global model to obtain the final intrusion detection model, and using the final intrusion detection model to detect intrusions. This invention effectively improves the system's security and robustness while ensuring data privacy and the trustworthiness of sharing.
Owner:NANJING UNIV OF POSTS & TELECOMM

A network traffic classification method and system based on double position encoding and hybrid mask mechanism

The application belongs to the field of network traffic classification, and discloses a network traffic classification method and system based on double position encoding and a hybrid mask mechanism, which comprises the following steps: input network traffic is divided according to time segments, and structured traffic representation is generated based on source address, destination address, source port, destination port and transmission protocol; double position encoded flow data is input into a coding model based on a Transformer, and a hybrid mask mechanism is introduced in the attention calculation process to balance the dependence relationship between bytes in the packet and between packets; the classification result output by the coding model is obtained, and a preset confidence threshold is used for judgment; if the confidence of the classification result is within the preset confidence interval, flow caching and reconstruction processing are performed, otherwise, the classification result is directly output. The application can effectively improve the accuracy and robustness of encrypted traffic classification and attack detection, and is suitable for Internet of Things traffic, mobile traffic and complex network environments across platforms.
Owner:GUANGZHOU UNIVERSITY