Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

321 results about "Traffic classification" patented technology

Traffic classification is an automated process which categorises computer network traffic according to various parameters (for example, based on port number or protocol) into a number of traffic classes. Each resulting traffic class can be treated differently in order to differentiate the service implied for the data generator or consumer.

QUIC encrypted traffic classification method based on multi-model fusion

A QUIC encrypted traffic classification method based on multi-model fusion belongs to the field of communication, and comprises the following steps: a model training stage: dividing a data set, training each model in a high-precision model group and a high-recall-rate model group by using a training set, evaluating model performance by using a verification set, if a dynamic weight mechanism is started, calculating the weight of the model according to a model evaluation result, and if the dynamic weight mechanism is started, calculating the weight of the model; carrying out normalization processing on the weight, and searching an optimal decision threshold by using a plurality of candidate thresholds; in the model prediction stage, prediction data are input, each model generates a respective prediction probability, and if a dynamic weight mechanism is started, the prediction probability of each model is subjected to weighted averaging according to the weight obtained in the training stage so as to perform probability calibration; and combining the calibration probability of each model, judging the calibration probability through an optimal decision threshold, and generating a final classification prediction result. According to the method, the risks of overfitting and poor generalization ability of a single model are reduced, and QUIC encrypted traffic classification with high accuracy and stability is realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Transform encrypted traffic classification method based on pre-training and structure optimization fine tuning

The invention discloses an encrypted traffic classification method based on Transform, and belongs to the technical field of network security and encrypted traffic analysis. In order to solve the problems that load content in a novel encryption protocol (such as TLS 1.3 and VPN) is encrypted, structural disturbance is complex, category distribution is unbalanced and the like, the invention provides a dual-phase Transform framework (DPFT) with pre-training and structure optimization fine tuning. According to the framework, two self-supervision tasks of masked burst prediction (MBP) and burst structure discrimination (BSDT) are introduced in a pre-training stage, and deep data packet representation is learned from unlabeled traffic, so that the deep data packet representation is learned from the unlabeled traffic; in the fine tuning stage, dynamic weighting of word embedding and position embedding, multi-head attention pooling and Focus Loss are adopted, so that the modeling capability of the model on an encrypted traffic complex structure is enhanced, and the recognition sensitivity on minority class samples is improved. Experimental results show that the method disclosed by the invention is obviously superior to the existing method on various encrypted traffic data sets (including TLS 1.3, VPN, malicious traffic and the like), and achieves leading performance on classification accuracy and macro average F1 index.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Ship network layered intrusion detection method and system

The invention provides a ship network hierarchical intrusion detection method and system, and the method comprises the steps: obtaining multi-dimensional flow data from a plurality of hierarchies of a ship network, carrying out the preprocessing of the data, carrying out the feature extraction of the preprocessed flow data through a deep neural network model, obtaining the feature vector of the multi-dimensional flow data, and carrying out the detection of the multi-dimensional flow data. Then, establishing an anomaly detection model based on a random forest algorithm, inputting the feature vector into the anomaly detection model to obtain an anomaly score of the traffic data, and comparing the anomaly score with a preset score threshold to judge a confidence traffic and a question traffic; and finally, establishing an abnormal traffic classification model based on the bidirectional gating recurrent neural network and the convolutional neural network, inputting the doubt traffic into the abnormal traffic classification model to respectively obtain probabilities of the doubt traffic belonging to different known attack types, and respectively comparing the probabilities with a preset threshold. And then judging the attack type and whether the attack is a zero-day attack, and executing a corresponding defense strategy to complete hierarchical intrusion detection of the ship network.
Owner:SHANGHAI SHIP & SHIPPING RES INST CO LTD +1

Encrypted network traffic classification method based on pre-trained large language model

The invention relates to an encrypted network traffic classification method based on a pre-trained large language model, and belongs to the technical field of encrypted network traffic classification. The method mainly comprises three stages: a pre-training stage: converting original encrypted network traffic data into a double-byte hexadecimal format through preprocessing, generating and optimizing a basic vocabulary by using a byte pair coding algorithm, then constructing a large language model, and obtaining a pre-training model through distributed training; in the retraining stage, the data is subjected to head byte shuffling processing, and the pre-training model is quickly retrained to improve the generalization ability. In the fine tuning stage, to-be-classified data is preprocessed to generate hexadecimal double-byte data with labels, and classification task training is performed by using the retrained model to obtain an encrypted network traffic classification fine tuning model and classification accuracy. Through the combination of pre-training and retraining and the fine tuning of the pre-training model by means of data classification, the efficient processing and accurate classification of the complex encrypted network traffic are realized.
Owner:CHONGQING UNIV

Flow controllable forwarding method and system

The invention relates to the technical field of flow forwarding, in particular to a controllable flow forwarding method. The method comprises the following steps: S1, demand analysis, S2, traffic model construction, S3, equipment initial configuration, S4, traffic monitoring and evaluation, S5, traffic classification and priority setting, S6, bandwidth limitation and rate control, S7, load balancing, S8, resource reservation, S9, security encryption and verification of a data packet, S10, traffic caching and data loss prevention, and S11, dynamic adjustment of a forwarding strategy. According to the method, accurate control and management of network traffic are realized through traffic model construction, traffic monitoring and evaluation, traffic classification and priority setting, bandwidth limitation and rate control, load balancing and resource reservation, the security of data in a forwarding process is improved through security encryption and verification of a data packet, log recording and performance monitoring, and the data forwarding efficiency is improved. And data loss is avoided through flow caching, data loss prevention and dynamic adjustment of a forwarding strategy.
Owner:BEIJING ZHIYE TECH IND CO LTD

General traffic image generation method for solving unbalanced network traffic classification

The invention relates to the technical field of computers, in particular to a general traffic image generation method for solving unbalanced network traffic classification, which comprises the following steps of: arranging and combining original network traffic into a session stream according to a time sequence based on a session stream mode, and converting the session stream into an image by taking a data packet as a unit. Converting the effective load of each data packet into a grayscale image; the SCGAN is used for training; eliminating noise by adopting a convolution noise reduction auto-encoder, and performing high-definition reconstruction on the generated flow sample; and combining a minority of types of traffic image samples generated through high-definition reconstruction with the original real traffic samples. According to the method, when the data packets are converted into the traffic images, the time sequence dependency relationship of the network traffic is reserved, the structural features among the data packets in image representation are also reserved, a balanced new network traffic data set is constructed, the authenticity and diversity of the data set are kept, and the generalization ability and effect of the model are improved.
Owner:GUANGDONG UNIV OF SCI & TECH

Encrypted traffic classification method fusing space, time sequence and frequency spectrum features

The invention relates to an encrypted traffic classification method fusing space, time sequence and frequency spectrum features, and belongs to the field of encrypted traffic classification and deep learning. The method comprises the following steps: analyzing a network original flow Pcap packet, segmenting the packet into different sessions according to a quintuple, and preprocessing each session: extracting first n data packets, and then extracting first m bytes and t time sequence data from each packet; utilizing byte data of the session to train a spatial feature module, and extracting spatial features of the session; training a time sequence feature module by using the time sequence data of the session, and extracting time sequence features of the session; the byte data of the session are converted into frequency spectrum information through fast Fourier transform, a frequency spectrum feature module is trained, and frequency spectrum features of the session are extracted; and fusing the extracted global spatial features, time sequence features and frequency spectrum features, and training by using multi-modal joint feature representation to realize fine classification of encrypted traffic. According to the invention, the precision and robustness of traffic classification can be improved.
Owner:FUZHOU UNIV

Cross-Tor version domain small sample website fingerprint identification method based on comparative learning

The invention designs a cross-Tor version domain small sample website fingerprint identification method based on comparative learning. The method comprises three parts of a pre-training strategy based on comparative learning, a fine tuning strategy based on double-branch confidence alignment and a flow classification strategy driven by a prototype. The method comprises the following steps: firstly, constructing a discriminative representation space through a trunk convolution feature extractor and a traffic attention module based on a pre-training strategy of comparative learning, and introducing supervised comparative learning to obtain feature representation with a cross-domain migration capability; secondly, a double-branch confidence alignment fine tuning strategy is adopted, the stability of a model structure is kept in combination with a partial freezing mechanism, and rapid adaptation to a target domain is achieved through joint optimization of cross entropy loss and weighted comparison loss; and finally, introducing a prototype-driven classification strategy, and on the basis of a semantic structure formed in a fine tuning stage, realizing accurate identification of Tor traffic in closed world and open world scenes by using a category prototype, so that the cross-domain generalization ability of small sample website fingerprint identification is remarkably improved.
Owner:SOUTHEAST UNIV

Intelligent detection method and system for security vulnerabilities of terminal layer of power internet of things

The invention discloses an intelligent detection method and system for security vulnerabilities of a terminal layer of an electric power internet of things, and relates to the technical field of security protection of the electric power internet of things, and the method comprises the steps: collecting multi-dimensional information and network traffic characteristics of terminal equipment of the electric power internet of things, constructing an equipment fingerprint database, carrying out the comparison verification of the equipment, and obtaining a security vulnerability of the terminal layer of the electric power internet of things according to a verification result; the method comprises the following steps: classifying network traffic, identifying an abnormal traffic sequence, extracting behavior parameters of network traffic abnormity and network access abnormity, carrying out association analysis on the abnormal parameters, labeling equipment, and generating a security vulnerability detection report. The technical problem that potential security vulnerabilities are difficult to find and repair in time due to the fact that complex abnormal behaviors in a device layer and network traffic cannot be effectively recognized and handled in the prior art is solved, real-time and accurate security vulnerability detection is achieved by constructing a device fingerprint database and carrying out traffic classification and abnormal behavior analysis, and the security vulnerability detection efficiency is improved. Therefore, the technical effect of improving the security of the terminal layer of the power Internet of Things is achieved.
Owner:GUANGZHOU KETENG INFORMATION TECH

Lightweight Internet of Things traffic classification method based on improved MobileNetV2

The invention provides a lightweight Internet of Things traffic classification method based on improved MobileNetV2. A lightweight model based on MobileNetV2 is constructed and comprises an input layer, a network introducing an attention mechanism, a classification network and an output layer which are connected in sequence; the input layer performs flow splitting and anonymization processing on input network flow data and constructs a multi-dimensional feature representation matrix comprising a byte level, a data packet level and a data flow level; according to the introduction of the attention mechanism network, an attention mechanism module is added behind a plurality of bottleneck layers so as to combine current layer features with shallow high-resolution features; performing iterative training on the lightweight model by taking the training set as training data and adopting a combined strategy based on cosine annealing and hot restart to obtain a trained model; model parameters are optimized through quantitative compression and structure pruning, the test set serves as test data, the optimized model is evaluated, and a classification result is output. According to the invention, efficient and accurate traffic classification is realized, and the problem of resource limitation of the Internet of Things equipment is solved at the same time.
Owner:HENAN POLYTECHNIC INST +1

Encrypted network traffic classification method and system based on large model hierarchical fine tuning

The invention discloses an encrypted network flow classification method based on large model hierarchical fine tuning, comprising the following steps: obtaining an input tensor used for representing encrypted network flow data to be classified; inputting the input tensor into a local time sequence aggregator, so that the local time sequence aggregator extracts short-time high-frequency burst features in the input tensor through a deep convolution mechanism; inputting the short-time high-frequency burst features and the input tensor into a hierarchical fine-tuning large model to enable the hierarchical fine-tuning large model to extract encrypted traffic features in the input tensor based on a hierarchical parameter fine-tuning mechanism, and fusing the short-time high-frequency burst features and the encrypted traffic features to obtain advanced spatial-temporal features; and based on the short-time high-frequency burst feature and the advanced spatial-temporal feature, obtaining a classification result of the encrypted network traffic data to be classified. According to the method, the accuracy of classifying the encrypted network traffic data can be improved, and meanwhile, the training resource consumption is reduced.
Owner:XIDIAN UNIV

Adaptive network traffic classification

Devices and methods for adaptively classifying network traffic associated with a new application are provided. A network device, for example, an edge device, stores a Machine Learning (ML) model pre-trained based on historical network traffic associated with a set of applications. The network device receives network traffic associated with a new application, for example, a zero-day application, that is different from the set of applications. The ML model learns one or more patterns associated with the received network traffic. The ML model detects whether the learned pattern(s) is similar to previously learned patterns of at least one application. The ML model classifies the received network traffic as legitimate traffic or anomalous traffic based on the detection. The ML model is scalable, providing timely classifications for different types of network traffic, while handling protocol and application diversity, variability in traffic patterns, and emergence of zero-day application traffic.
Owner:CISCO TECHNOLOGY INC

Method, device and system for classifying network traffic data of data center

The invention relates to the technical field of network traffic classification, in particular to a network traffic data classification method, device and system for a data center, and the method specifically comprises the steps: constructing a feature data matrix based on all types of feature information of all traffic in a data set, obtaining principal components in the matrix through a principal component analysis algorithm, screening representative principal components based on the variance contribution rates of the principal components and the correlation between the variance contribution rates; calculating a dynamic flow interference degree index of the data set based on the Shannon entropy of the representative principal component and the density clustering characteristic; a dynamic threshold is set, a trigger condition of incremental learning is set in combination with a dynamic traffic interference degree index, and after the incremental learning is triggered, a bidirectional GRU network in an RNN model is dynamically adjusted through an elastic weight solidification method, so that traffic classification is carried out, historical knowledge is reserved, and meanwhile, the method adapts to a new traffic mode. The system is ensured to quickly respond to the traffic mode change, the performance degradation is avoided, and the accuracy of network traffic data classification is improved.
Owner:BEIJING XINKE SHANGZHI COMM TECH CO LTD

Cloud edge-end collaborative multi-scene adaptive network intrusion detection method

The invention discloses a cloud side-end cooperative multi-scene adaptive network intrusion detection method, and solves the problems of poor scene adaptation, weak dynamic processing, privacy-precision imbalance and the like in the prior art. The method is realized through four steps: 1, multi-scene traffic collection and hierarchical preprocessing, terminal sensing layer optimization frame processing and traffic classification, edge layer screening of high-value traffic, and cloud fragmentation scheduling; 2, multi-scene adaptive feature fusion is carried out, scene exclusive features and general features are extracted, and 50-dimensional feature vectors are generated; 3, a cloud edge-end collaborative detection model and an edge lightweight model are preliminarily screened, a cloud federal fusion model is finely detected, and dynamic weight and differential privacy are combined; 4, dynamic attack response and model iteration are carried out, attacks are responded in a scene mode, and the stability of the model is guaranteed through anti-forgetting optimization. According to the method, multiple scenes are covered, the detection precision is larger than or equal to 98.5%, the edge delay is smaller than or equal to 40 ms, the privacy leakage risk is reduced by 90%, the renaturation is high, and the robustness is high.
Owner:季亚文

Network traffic classification method, device and equipment based on multi-feature fusion

The invention provides a network traffic classification method, device and equipment based on multi-feature fusion, and belongs to the field of artificial intelligence. The method comprises the following steps: preprocessing traffic data to obtain a traffic grey-scale map; screening a minority class traffic sample set from the traffic grey-scale map; simulating a minority class traffic sample set through a WGAN model, and constructing and generating a sample; supplementing the generated sample into the flow grey-scale map to form a balanced sample set; inputting the balanced sample set into a ViT hybrid model to extract features, and obtaining sequence features; fusing the sequence features based on a cross attention mechanism to obtain a target traffic diagram; and classifying the target flow diagram by utilizing a multi-layer perceptron module of the perceptual layer to obtain a classification result. According to the method, the global features and the local features of the network traffic data can be effectively combined for classification, meanwhile, the model architecture is lightened, the accuracy of the model is improved, and the situation that the number of partial traffic type samples is small can be effectively handled.
Owner:GUANGZHOU DIESHENG TECHNOLOGY CO LTD

IPv6 traffic prediction system based on machine learning

The invention relates to the technical field of traffic prediction, and discloses an IPv6 traffic prediction system based on machine learning, and the system comprises a traffic collection module which is used for capturing the original traffic data of an IPv6 network interface and carrying out the protocol analysis and traffic classification preprocessing, and obtaining the preprocessed IPv6 traffic data; the multi-dimensional feature extraction module is used for performing multi-modal feature extraction on the preprocessed IPv6 flow data to generate a fusion feature vector; the real-time prediction module is used for inputting the fusion feature vector into a dynamic prediction model to obtain an IPv6 traffic prediction value of a future preset duration; and the dynamic scheduling module is used for pushing the IPv6 traffic prediction value of the future preset duration to a traffic scheduling controller so as to realize dynamic scheduling of network resources. According to the method, the network traffic prediction accuracy and real-time performance are improved, the adaptive capacity to IPv6 traffic mode change is enhanced, and reasonable distribution and efficient utilization of network resources are effectively promoted.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT JIANGXI BRANCH +1

Flow classification method based on parallel multi-channel fusion graph neural network

The invention relates to a traffic classification method based on a parallel multi-channel fusion graph neural network. The method comprises the following steps: S1, modeling an encrypted network traffic classification problem; s2, preprocessing the original data stream file to obtain a head part and a load part of each data packet; s3, modeling the preprocessed data packet byte sequence into a graph to obtain a flow graph of a head part and a load part; s4, inputting the flow diagrams of the head part and the load part into a parallel dual-channel graph neural network module to obtain a packet-level head vector representation and a packet-level load vector representation; s5, splicing the head vector representation and the load vector representation to obtain a complete data packet vector representation, and sending the three vector representations into a parallel three-channel network to obtain a flow level vector representation; and S6, performing feature fusion on the three vector representations, and obtaining a flow classification result through a final classification layer. Compared with the prior art, the method has the advantages of higher precision and the like.
Owner:SOUTHEAST UNIV

Encrypted traffic classification model training method, electronic equipment, storage medium and program product

The embodiment of the invention provides an encrypted traffic classification model training method, an electronic device, a storage medium and a program product, through a self-supervised learning framework, an unmarked patch is utilized to embed and express a training encoder-decoder structure, so that the model can autonomously learn universal spatio-temporal features from an encrypted traffic grey-scale map. The mask reconstruction task promotes the model to understand the internal structure rule of the traffic data, the understanding depth of the model for the input data is enhanced, the adaptability of the model to the distributed data is improved, and the generalization ability, adaptability and robustness of the model are also improved.
Owner:CAPITAL NORMAL UNIVERSITY

Sequence similarity segmentation-based WireGuard multi-behavior traffic classification method and system

The invention relates to the technical field of network information security, in particular to a sequence similarity segmentation-based WireGuard multi-behavior traffic classification method and system, and the method comprises the steps: traffic collection: capturing encrypted traffic transmitted by a user through a WireGuard protocol; flow segmentation: dividing the feature sequence into equal sub-sequence fragments to form a plurality of sub-sequence sets with different sub-sequence lengths; calculating the similarity between the interior of the quantum sequence and the adjacent sub-sequences based on the maximum mean value difference function; adopting a greedy strategy to select connection points between K most dissimilar adjacent subsequences as segmentation points; feature extraction: constructing a multi-dimensional flow path based on the segmented subsequences; extracting path signature features on the multi-dimensional flow path by adopting a sliding window method; and traffic classification: inputting the path signature features into an LSTM model for time sequence modeling, and realizing classification of user behaviors through a full connection layer. According to the method, automatic, lightweight and fine-grained accurate classification of multi-user behaviors in encrypted traffic is realized.
Owner:HAINAN UNIV

Network action classification and analysis using widely distributed and selectively attributed sensor nodes and cloud-based processing

A system for network traffic classification using distributed sensor nodes is provided, comprising a plurality of network traffic sensors each configured to monitor visible network traffic, analyze the monitored traffic to identify patterns, communicate with other network sensors to correlate their respective traffic data, produce a threat landscape based on the correlated traffic data, identify a potential cybersecurity threat based on the threat landscape, and export the analyzed traffic and threat landscape for use by external systems.
Owner:QOMPLX INC

Encrypted network traffic classification method, system and program based on semi-supervised learning

The invention relates to the technical field of network security, in particular to an encrypted network traffic classification method, system and program based on semi-supervised learning. The method comprises the following steps: acquiring network flow data; pre-training the BERT model through the network traffic data; performing data annotation on the network traffic data in a preset proportion to obtain first traffic data and second traffic data; performing conversion and data enhancement on the first traffic data and the second traffic data to obtain a first token sequence, a second token sequence and a third token sequence; inputting the first token sequence, the second token sequence and the third token sequence into a BERT model and a traffic classification model for fine tuning training; and classifying the encrypted network traffic by using the fine-tuned traffic classification model. According to the method and the device, semi-supervised learning training can be performed on the traffic classification model through a small amount of labeled data, and meanwhile, back propagation is performed through unsupervised loss and supervised loss, so that the classification accuracy of the traffic classification model on encrypted traffic is improved.
Owner:GUANGZHOU UNIVERSITY

Abnormal traffic classification method and system

The invention relates to the technical field of network security abnormal traffic detection, in particular to an abnormal traffic classification method and system, and the method comprises the steps: collecting and marking traffic data to construct a training set, and then extracting static features to train a random forest model to obtain a baseline classification model; when business changes, business features are dynamically created and registered to a central feature library, static and dynamic features are extracted from real-time traffic based on the feature library to form a fusion feature vector, and the fusion feature vector is input into a baseline model to realize accurate classification, so that the problem that the business changes are difficult to dynamically adapt due to dependence on the static features and a fixed model in the prior art is solved; and therefore, the classification accuracy is reduced and the adaptability is insufficient in a real network environment can be solved.
Owner:BEIJING FULE TECH CO LTD

Fusion encryption traffic classification method and system based on graph neural network

The invention relates to the technical field of network traffic analysis, in particular to a fused encrypted traffic classification method and system based on a graph neural network, and the method comprises the steps: standardizing to-be-classified encrypted traffic data, and then constructing a data set; constructing a flow interaction diagram according to the data packets and the communication relationship between the data packets, and extracting to obtain a statistical feature vector; respectively converting the encrypted traffic data into grayscale images, and extracting data feature vectors of the encrypted traffic from the grayscale images; and splicing the statistical feature vector and the data feature vector to obtain joint feature mapping, and classifying the joint feature mapping through a classifier. According to the method, the accuracy can be improved while the integrity of the original traffic data is ensured.
Owner:HUBEI UNIV

Multi-modal encrypted traffic classification method and system based on collaborative attention mechanism

The invention discloses a multi-modal encrypted traffic classification method and system based on a collaborative attention mechanism, and relates to the technical field of network security and artificial intelligence, and the method comprises the steps: obtaining a traffic data set, carrying out the preprocessing of the traffic data set, obtaining a processed traffic data set, calculating the cosine similarity based on the processed traffic data set, and carrying out the calculation of the cosine similarity. Obtaining a cosine similarity matrix; the cosine similarity matrix is subjected to collaborative attention weighting, the attention comprises convolution attention and multi-head self-attention, convolution attention output and multi-head self-attention output are spliced and then extracted, extracted features are obtained, and the extracted features are extracted; the extracted features comprise data packet byte vector representation emphasizing key bytes and tag semantic features; and carrying out feature splicing on the extracted features to obtain an overall feature representation, inputting the overall feature representation into a full connection layer, generating a traffic classification probability by using a classifier, obtaining a classified traffic category, and realizing high-precision classification of encrypted traffic.
Owner:NANJING UNIV OF POSTS & TELECOMM

Malicious traffic classification method and system based on lightweight time sequence coding and expert routing

The invention belongs to the field of network traffic classification, and discloses a malicious traffic classification method and system based on lightweight time sequence coding and expert routing.The method comprises the steps that session aggregation and burst segmentation are conducted on original traffic, fixed-length byte sequences of headers and loads are intercepted respectively, and dual-channel embedded representation is formed; carrying out local time sequence modeling by adopting MinLSTM, and introducing a sparsely activated expert route into a Transform feed-forward layer so as to fuse global features; in the pre-training stage, parameter initialization is realized through mask byte modeling, and in the fine tuning stage, a classification head is optimized based on annotation data; and finally, splicing header and load features in a classification stage, and inputting the header and load features into a global attention encoder after prepolymerization compression to finish classification. According to the method, small sample and cross-scene robustness of malicious traffic detection can be improved, attention complexity and resource consumption are remarkably reduced, and the method is suitable for resource limited scenes.
Owner:GUANGZHOU UNIVERSITY

Satellite network encrypted traffic preprocessing method and system under multi-feature fusion

The invention discloses a satellite network encrypted traffic preprocessing method and system under multi-feature fusion, and the method comprises the steps: cooperatively processing original traffic data from two dimensions of a data packet level and a session level: at the data packet level, deleting an invalid TCP control segment and a TLS / DNS key exchange segment to eliminate redundancy, and removing a data link layer header to reduce interference; anonymization mask processing is carried out on an IP header to prevent overfitting, data normalization and standardization operations are executed to balance the feature scale, and meanwhile the data length is unified through truncation and zero filling strategies; in a session level, session splitting is carried out based on a quintuple sharing a source IP, a target IP, a port number and a protocol, statistical features such as the total number of data packets and session duration are extracted to capture time sequence association, and feature vectorization is realized by adopting Min-Max normalization. The double-layer fusion mechanism effectively combines data packet level microscopic fine-grained features with session level macroscopic context information to jointly improve the accuracy of encrypted traffic classification and the model generalization ability.
Owner:鹏鹄物宇(无锡)航天有限公司

Flow classification method and system based on SmartNIC

The invention discloses a flow classification method based on SmartNIC, and the method comprises the steps: monitoring the network flow in real time, and obtaining a to-be-processed data package in the network flow; determining a hash value of a network flow corresponding to the to-be-processed data packet, determining a hash bucket where the to-be-processed data packet is located according to the hash value, and tracking the state of the network flow according to the hash bucket; accumulating the number of the data packets to be processed to a first preset number; performing standardization processing on the target number of to-be-processed data packets to obtain a target number of target data packets; and performing traffic classification on the target number of target data packets. After the Hash value and the Hash bucket are obtained, the state of the network flow can be effectively tracked, the calculation pressure of a CPU and a GPU of a server is reduced, the system delay, the throughput and the energy consumption are reduced, and the real-time performance and the stability of a flow classification system are ensured. In addition, the invention also provides a flow classification system based on the SmartNIC.
Owner:NORTHEASTERN UNIV CHINA

Network traffic classification method and device, storage medium and computer equipment

The invention relates to the technical field of internet, finance and medical health, and particularly discloses a network traffic classification method and device, a storage medium and computer equipment, and the method comprises the steps: obtaining a plurality of network traffic samples, and carrying out the data feature extraction of each network traffic sample, and obtaining the sample feature vector of the network traffic sample; training the initial traffic classification model by using the sample feature vector to obtain a target traffic classification model, a model loss value in the model training process being determined based on a sub-loss value of each network traffic sample, and the sub-loss value of each network traffic sample being determined based on a product of a category deviation and a category weight; and for each Pod in the target cluster, monitoring the traffic of the Pod through a cluster traffic monitoring tool, dynamically constructing a traffic feature vector of the Pod according to a monitoring result, and continuously determining the traffic category of the Pod through a target traffic classification model based on the dynamically constructed traffic feature vector.
Owner:PING AN PAY ELECTRONIC PAYMENT CO LTD

Malicious encrypted traffic classification method and system based on session spatio-temporal feature map

The invention provides a malicious encrypted traffic classification method and system based on a session spatio-temporal feature map. The method comprises the following steps: sliding on a cleaned encrypted traffic session by using a sliding window with a predefined duration, and extracting statistical characteristics of the encrypted traffic session, including a packet size characteristic, a packet arrival time characteristic and a packet load alpha-Renyi entropy; taking the packet size feature and the packet arrival time feature of the encrypted traffic session as a Y axis and an X axis respectively, mapping the packet load alpha-Renyi entropy into a gray value, and forming a session spatial-temporal feature map; and inputting the session spatio-temporal feature map into a ResNet-50 model of a CBAM attention mechanism to perform malicious encrypted traffic classification. The scheme provided by the invention can adapt to different malicious encrypted traffic application scenes, so that more efficient and more accurate encrypted traffic classification is realized.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Network encryption traffic classification method based on convolution self-attention

The invention relates to a convolutional self-attention-based network encrypted traffic classification method, belongs to the technical field of network encrypted data analysis, and solves the problems that an existing traditional machine learning method depends on tedious manual feature engineering, is difficult to capture a deep time sequence mode and protocol semantics, and is low in classification efficiency. Therefore, the problems of low classification precision, poor generalization ability and incapability of effectively adapting to novel encryption application are solved. The method comprises the following steps: acquiring to-be-classified network encryption traffic; preprocessing the network encrypted traffic to be classified to obtain a token vector sequence of the network encrypted traffic; wherein the preprocessing comprises the following steps: constructing a token sequence based on each data packet in the network encrypted traffic to be classified and a time interval between the data packets, and mapping the token sequence into a token vector sequence; and inputting the token vector sequence into a trained encrypted traffic classification model to obtain the type of the network encrypted traffic.
Owner:36TH RES INST OF CETC