Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

219 results about "Traffic classification" patented technology

Traffic classification is an automated process which categorises computer network traffic according to various parameters (for example, based on port number or protocol) into a number of traffic classes. Each resulting traffic class can be treated differently in order to differentiate the service implied for the data generator or consumer.

Transform encrypted traffic classification method based on pre-training and structure optimization fine tuning

The invention discloses an encrypted traffic classification method based on Transform, and belongs to the technical field of network security and encrypted traffic analysis. In order to solve the problems that load content in a novel encryption protocol (such as TLS 1.3 and VPN) is encrypted, structural disturbance is complex, category distribution is unbalanced and the like, the invention provides a dual-phase Transform framework (DPFT) with pre-training and structure optimization fine tuning. According to the framework, two self-supervision tasks of masked burst prediction (MBP) and burst structure discrimination (BSDT) are introduced in a pre-training stage, and deep data packet representation is learned from unlabeled traffic, so that the deep data packet representation is learned from the unlabeled traffic; in the fine tuning stage, dynamic weighting of word embedding and position embedding, multi-head attention pooling and Focus Loss are adopted, so that the modeling capability of the model on an encrypted traffic complex structure is enhanced, and the recognition sensitivity on minority class samples is improved. Experimental results show that the method disclosed by the invention is obviously superior to the existing method on various encrypted traffic data sets (including TLS 1.3, VPN, malicious traffic and the like), and achieves leading performance on classification accuracy and macro average F1 index.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Encrypted traffic classification method fusing space, time sequence and frequency spectrum features

The invention relates to an encrypted traffic classification method fusing space, time sequence and frequency spectrum features, and belongs to the field of encrypted traffic classification and deep learning. The method comprises the following steps: analyzing a network original flow Pcap packet, segmenting the packet into different sessions according to a quintuple, and preprocessing each session: extracting first n data packets, and then extracting first m bytes and t time sequence data from each packet; utilizing byte data of the session to train a spatial feature module, and extracting spatial features of the session; training a time sequence feature module by using the time sequence data of the session, and extracting time sequence features of the session; the byte data of the session are converted into frequency spectrum information through fast Fourier transform, a frequency spectrum feature module is trained, and frequency spectrum features of the session are extracted; and fusing the extracted global spatial features, time sequence features and frequency spectrum features, and training by using multi-modal joint feature representation to realize fine classification of encrypted traffic. According to the invention, the precision and robustness of traffic classification can be improved.
Owner:FUZHOU UNIV

Cross-Tor version domain small sample website fingerprint identification method based on comparative learning

The invention designs a cross-Tor version domain small sample website fingerprint identification method based on comparative learning. The method comprises three parts of a pre-training strategy based on comparative learning, a fine tuning strategy based on double-branch confidence alignment and a flow classification strategy driven by a prototype. The method comprises the following steps: firstly, constructing a discriminative representation space through a trunk convolution feature extractor and a traffic attention module based on a pre-training strategy of comparative learning, and introducing supervised comparative learning to obtain feature representation with a cross-domain migration capability; secondly, a double-branch confidence alignment fine tuning strategy is adopted, the stability of a model structure is kept in combination with a partial freezing mechanism, and rapid adaptation to a target domain is achieved through joint optimization of cross entropy loss and weighted comparison loss; and finally, introducing a prototype-driven classification strategy, and on the basis of a semantic structure formed in a fine tuning stage, realizing accurate identification of Tor traffic in closed world and open world scenes by using a category prototype, so that the cross-domain generalization ability of small sample website fingerprint identification is remarkably improved.
Owner:SOUTHEAST UNIV

Encrypted network traffic classification method and system based on large model hierarchical fine tuning

The invention discloses an encrypted network flow classification method based on large model hierarchical fine tuning, comprising the following steps: obtaining an input tensor used for representing encrypted network flow data to be classified; inputting the input tensor into a local time sequence aggregator, so that the local time sequence aggregator extracts short-time high-frequency burst features in the input tensor through a deep convolution mechanism; inputting the short-time high-frequency burst features and the input tensor into a hierarchical fine-tuning large model to enable the hierarchical fine-tuning large model to extract encrypted traffic features in the input tensor based on a hierarchical parameter fine-tuning mechanism, and fusing the short-time high-frequency burst features and the encrypted traffic features to obtain advanced spatial-temporal features; and based on the short-time high-frequency burst feature and the advanced spatial-temporal feature, obtaining a classification result of the encrypted network traffic data to be classified. According to the method, the accuracy of classifying the encrypted network traffic data can be improved, and meanwhile, the training resource consumption is reduced.
Owner:XIDIAN UNIV

Adaptive network traffic classification

Devices and methods for adaptively classifying network traffic associated with a new application are provided. A network device, for example, an edge device, stores a Machine Learning (ML) model pre-trained based on historical network traffic associated with a set of applications. The network device receives network traffic associated with a new application, for example, a zero-day application, that is different from the set of applications. The ML model learns one or more patterns associated with the received network traffic. The ML model detects whether the learned pattern(s) is similar to previously learned patterns of at least one application. The ML model classifies the received network traffic as legitimate traffic or anomalous traffic based on the detection. The ML model is scalable, providing timely classifications for different types of network traffic, while handling protocol and application diversity, variability in traffic patterns, and emergence of zero-day application traffic.
Owner:CISCO TECHNOLOGY INC

Cloud edge-end collaborative multi-scene adaptive network intrusion detection method

The invention discloses a cloud side-end cooperative multi-scene adaptive network intrusion detection method, and solves the problems of poor scene adaptation, weak dynamic processing, privacy-precision imbalance and the like in the prior art. The method is realized through four steps: 1, multi-scene traffic collection and hierarchical preprocessing, terminal sensing layer optimization frame processing and traffic classification, edge layer screening of high-value traffic, and cloud fragmentation scheduling; 2, multi-scene adaptive feature fusion is carried out, scene exclusive features and general features are extracted, and 50-dimensional feature vectors are generated; 3, a cloud edge-end collaborative detection model and an edge lightweight model are preliminarily screened, a cloud federal fusion model is finely detected, and dynamic weight and differential privacy are combined; 4, dynamic attack response and model iteration are carried out, attacks are responded in a scene mode, and the stability of the model is guaranteed through anti-forgetting optimization. According to the method, multiple scenes are covered, the detection precision is larger than or equal to 98.5%, the edge delay is smaller than or equal to 40 ms, the privacy leakage risk is reduced by 90%, the renaturation is high, and the robustness is high.
Owner:季亚文

Sequence similarity segmentation-based WireGuard multi-behavior traffic classification method and system

The invention relates to the technical field of network information security, in particular to a sequence similarity segmentation-based WireGuard multi-behavior traffic classification method and system, and the method comprises the steps: traffic collection: capturing encrypted traffic transmitted by a user through a WireGuard protocol; flow segmentation: dividing the feature sequence into equal sub-sequence fragments to form a plurality of sub-sequence sets with different sub-sequence lengths; calculating the similarity between the interior of the quantum sequence and the adjacent sub-sequences based on the maximum mean value difference function; adopting a greedy strategy to select connection points between K most dissimilar adjacent subsequences as segmentation points; feature extraction: constructing a multi-dimensional flow path based on the segmented subsequences; extracting path signature features on the multi-dimensional flow path by adopting a sliding window method; and traffic classification: inputting the path signature features into an LSTM model for time sequence modeling, and realizing classification of user behaviors through a full connection layer. According to the method, automatic, lightweight and fine-grained accurate classification of multi-user behaviors in encrypted traffic is realized.
Owner:HAINAN UNIV

Network action classification and analysis using widely distributed and selectively attributed sensor nodes and cloud-based processing

A system for network traffic classification using distributed sensor nodes is provided, comprising a plurality of network traffic sensors each configured to monitor visible network traffic, analyze the monitored traffic to identify patterns, communicate with other network sensors to correlate their respective traffic data, produce a threat landscape based on the correlated traffic data, identify a potential cybersecurity threat based on the threat landscape, and export the analyzed traffic and threat landscape for use by external systems.
Owner:QOMPLX INC

Abnormal traffic classification method and system

The invention relates to the technical field of network security abnormal traffic detection, in particular to an abnormal traffic classification method and system, and the method comprises the steps: collecting and marking traffic data to construct a training set, and then extracting static features to train a random forest model to obtain a baseline classification model; when business changes, business features are dynamically created and registered to a central feature library, static and dynamic features are extracted from real-time traffic based on the feature library to form a fusion feature vector, and the fusion feature vector is input into a baseline model to realize accurate classification, so that the problem that the business changes are difficult to dynamically adapt due to dependence on the static features and a fixed model in the prior art is solved; and therefore, the classification accuracy is reduced and the adaptability is insufficient in a real network environment can be solved.
Owner:BEIJING FULE TECH CO LTD

Multi-modal encrypted traffic classification method and system based on collaborative attention mechanism

The invention discloses a multi-modal encrypted traffic classification method and system based on a collaborative attention mechanism, and relates to the technical field of network security and artificial intelligence, and the method comprises the steps: obtaining a traffic data set, carrying out the preprocessing of the traffic data set, obtaining a processed traffic data set, calculating the cosine similarity based on the processed traffic data set, and carrying out the calculation of the cosine similarity. Obtaining a cosine similarity matrix; the cosine similarity matrix is subjected to collaborative attention weighting, the attention comprises convolution attention and multi-head self-attention, convolution attention output and multi-head self-attention output are spliced and then extracted, extracted features are obtained, and the extracted features are extracted; the extracted features comprise data packet byte vector representation emphasizing key bytes and tag semantic features; and carrying out feature splicing on the extracted features to obtain an overall feature representation, inputting the overall feature representation into a full connection layer, generating a traffic classification probability by using a classifier, obtaining a classified traffic category, and realizing high-precision classification of encrypted traffic.
Owner:NANJING UNIV OF POSTS & TELECOMM

Malicious traffic classification method and system based on lightweight time sequence coding and expert routing

The invention belongs to the field of network traffic classification, and discloses a malicious traffic classification method and system based on lightweight time sequence coding and expert routing.The method comprises the steps that session aggregation and burst segmentation are conducted on original traffic, fixed-length byte sequences of headers and loads are intercepted respectively, and dual-channel embedded representation is formed; carrying out local time sequence modeling by adopting MinLSTM, and introducing a sparsely activated expert route into a Transform feed-forward layer so as to fuse global features; in the pre-training stage, parameter initialization is realized through mask byte modeling, and in the fine tuning stage, a classification head is optimized based on annotation data; and finally, splicing header and load features in a classification stage, and inputting the header and load features into a global attention encoder after prepolymerization compression to finish classification. According to the method, small sample and cross-scene robustness of malicious traffic detection can be improved, attention complexity and resource consumption are remarkably reduced, and the method is suitable for resource limited scenes.
Owner:GUANGZHOU UNIVERSITY

Satellite network encrypted traffic preprocessing method and system under multi-feature fusion

The invention discloses a satellite network encrypted traffic preprocessing method and system under multi-feature fusion, and the method comprises the steps: cooperatively processing original traffic data from two dimensions of a data packet level and a session level: at the data packet level, deleting an invalid TCP control segment and a TLS / DNS key exchange segment to eliminate redundancy, and removing a data link layer header to reduce interference; anonymization mask processing is carried out on an IP header to prevent overfitting, data normalization and standardization operations are executed to balance the feature scale, and meanwhile the data length is unified through truncation and zero filling strategies; in a session level, session splitting is carried out based on a quintuple sharing a source IP, a target IP, a port number and a protocol, statistical features such as the total number of data packets and session duration are extracted to capture time sequence association, and feature vectorization is realized by adopting Min-Max normalization. The double-layer fusion mechanism effectively combines data packet level microscopic fine-grained features with session level macroscopic context information to jointly improve the accuracy of encrypted traffic classification and the model generalization ability.
Owner:鹏鹄物宇(无锡)航天有限公司

Malicious encrypted traffic classification method and system based on session spatio-temporal feature map

The invention provides a malicious encrypted traffic classification method and system based on a session spatio-temporal feature map. The method comprises the following steps: sliding on a cleaned encrypted traffic session by using a sliding window with a predefined duration, and extracting statistical characteristics of the encrypted traffic session, including a packet size characteristic, a packet arrival time characteristic and a packet load alpha-Renyi entropy; taking the packet size feature and the packet arrival time feature of the encrypted traffic session as a Y axis and an X axis respectively, mapping the packet load alpha-Renyi entropy into a gray value, and forming a session spatial-temporal feature map; and inputting the session spatio-temporal feature map into a ResNet-50 model of a CBAM attention mechanism to perform malicious encrypted traffic classification. The scheme provided by the invention can adapt to different malicious encrypted traffic application scenes, so that more efficient and more accurate encrypted traffic classification is realized.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Network encryption traffic classification method based on convolution self-attention

The invention relates to a convolutional self-attention-based network encrypted traffic classification method, belongs to the technical field of network encrypted data analysis, and solves the problems that an existing traditional machine learning method depends on tedious manual feature engineering, is difficult to capture a deep time sequence mode and protocol semantics, and is low in classification efficiency. Therefore, the problems of low classification precision, poor generalization ability and incapability of effectively adapting to novel encryption application are solved. The method comprises the following steps: acquiring to-be-classified network encryption traffic; preprocessing the network encrypted traffic to be classified to obtain a token vector sequence of the network encrypted traffic; wherein the preprocessing comprises the following steps: constructing a token sequence based on each data packet in the network encrypted traffic to be classified and a time interval between the data packets, and mapping the token sequence into a token vector sequence; and inputting the token vector sequence into a trained encrypted traffic classification model to obtain the type of the network encrypted traffic.
Owner:36TH RES INST OF CETC

Network traffic classification method, system and device, and storage medium

The invention relates to the technical field of machine learning, and relates to a network traffic classification method, system and device, and a storage medium. The network traffic classification method comprises the following steps: acquiring original network data; converting the original network data into an initial network flow vector sequence; constructing a network structure of a Transform model used for deep learning of network traffic features; performing iterative training on a network of a Transform model by using the initial network traffic vector sequence, and optimizing parameters of an encoder of the Transform model to obtain a target encoder; inputting the initial network traffic vector sequence into a target encoder, and sequentially extracting features of network traffic vectors in the initial network traffic vector sequence by the target encoder to obtain target network traffic features; and determining a classification result of the original network data according to the target network flow characteristics. According to the method, information of original network data can be reserved, and the classification expression capability is remarkably enhanced.
Owner:CHONGQING UNIV

Lightweight encrypted traffic classification method and system based on time anchor diagram representation

The invention discloses a lightweight encrypted traffic classification method and system based on time anchor diagram representation, and belongs to the technical field of network data security. Original traffic packets are preprocessed, and only head and load data are reserved; constructing a head graph and a load graph, dividing the fixed-length byte sequence into a plurality of time intervals, introducing corresponding anchor nodes, connecting the byte nodes in the intervals with anchor points, and injecting absolute / relative position information into the head graph and the load graph to obtain the head graph and the load graph after the time anchor points are enhanced; and on the head graph and the load graph after the time anchor point enhancement, coding the constructed time anchor point byte graph by adopting small-scale GraphSAGE to obtain a packet level vector, completing encryption traffic category judgment through a very simple classification head, and realizing a flow level decision through multi-packet aggregation. According to the method, the accuracy and robustness of encrypted traffic classification can be effectively improved while light weight and deployability are kept.
Owner:NANJING FUTURE NETWORK CO LTD

QoS traffic stream setup with stream classification service (SCS) request / response

A non-Access Point Extremely High Throughput Station (non-AP EHT STA) initiates a Quality-of-Service (QoS) setup by sending a Stream Classification Service (SCS) Request frame to an associated access point (AP). The SCS request frame may be encoded to have a request type field set to “Add” and may contain an SCS Descriptor element having a traffic description field, a traffic classification field, and a Multi-Link Operation (MLO) field. The non-AP EHT STA may decode an SCS Response frame from the AP that indicate whether the QoS setup has been added. The non-AP EHT STA may then exchange a QoS traffic flow with the associated AP in accordance with the QoS setup when the QoS setup has been added. When the QoS traffic flow ends, the non-AP EHT STA may encode a second SCS Request frame for transmission to the AP with the request type field set to “Remove” to delete the QoS setup.
Owner:INTEL CORP

SDN industrial network routing method based on deep traffic classification and dynamic pheromone optimization

The invention relates to the technical field of industrial network communication, in particular to an SDN (Software Defined Network) industrial network routing method based on deep traffic classification and dynamic pheromone optimization. According to the method, an SMOTE algorithm is improved, a target sub-region is selected through an adaptive boundary to perform oversampling to balance sample data, the problem of flow imbalance of the SDN multi-access interconnection architecture is solved, meanwhile, a CNN-LSTM model fused with an attention mechanism is established, and depth feature extraction is performed on samples after the samples are balanced so as to meet dynamic features of the flow in a short sequence.
Owner:JIANGSU KEREAD INTELLIGENT CONTROL AUTOMATION TECH CO LTD

Network traffic classification method and device, equipment, storage medium and program product

The invention provides a network traffic classification method and device, equipment, a storage medium and a program product. In some embodiments of the invention, the method comprises the following steps: obtaining a to-be-classified traffic data packet; inputting the traffic data packets to be classified into the traffic classification model; in the traffic classification model, joint embedding is carried out on a data packet header and a candidate label to obtain a first byte label embedding representation; carrying out joint embedding on the data packet load and the candidate tag to obtain a second byte tag embedding representation; inputting the first byte label embedded representation and the second byte label embedded representation into a joint attention encoder to obtain a data packet representation vector; performing traffic classification on the to-be-classified traffic data packets according to the data packet representation vectors to obtain a traffic classification result; according to the method, the bytes of the data packets and the candidate labels are subjected to deep semantic association, and the data packet representation vectors are generated through the joint attention encoder, so that the accuracy of network flow classification is improved, and the classification efficiency is improved.
Owner:CHINA MOBILE COMM LTD RES INST +1

Factoring service hierarchical access method and device

According to the factoring service hierarchical access method and device provided by the invention, multi-source heterogeneous data of a target enterprise is collected through a standardized interface, dimensions such as financial indexes, system performance, public opinion dynamics and compliance texts are covered, and data quality and safety are ensured through a professional data preprocessing process. A risk grading model of a fusion framework is adopted: text semantic features are extracted by utilizing a BERT model subjected to field fine tuning, structured data are analyzed in combination with the numerical understanding capability of a GPT series model, multi-source feature alignment is realized through a cross-modal attention mechanism, a comprehensive feature vector is generated based on a multi-head attention network, and the risk grading model of the fusion framework is obtained. And finally, outputting a risk level by the lightweight full-connection network, and forming a corresponding access strategy based on the risk level. According to the method, actual measurement-free evaluation is realized, a traditional test period needing a plurality of weeks is compressed to a plurality of hours, the model adaptability is continuously optimized through an online learning mechanism, multi-dimensional risk evaluation is realized, and test resource consumption and time cost are greatly reduced.
Owner:CLOUDCHAIN GRP CO LTD

Adaptive network traffic classification

Devices and methods for adaptively classifying network traffic associated with a new application are provided. A network device, for example, an edge device, stores a Machine Learning (ML) model pre-trained based on historical network traffic associated with a set of applications. The network device receives network traffic associated with a new application, for example, a zero-day application, that is different from the set of applications. The ML model learns one or more patterns associated with the received network traffic. The ML model detects whether the learned pattern(s) is similar to previously learned patterns of at least one application. The ML model classifies the received network traffic as legitimate traffic or anomalous traffic based on the detection. The ML model is scalable, providing timely classifications for different types of network traffic, while handling protocol and application diversity, variability in traffic patterns, and emergence of zero-day application traffic.
Owner:CISCO TECHNOLOGY INC

Encrypted traffic classification method and system based on semi-supervised contrast learning, and storage medium

The invention relates to an encrypted traffic classification method and system based on semi-supervised contrast learning, and a storage medium, and the method comprises the steps: 1, carrying out the flow division of an original encrypted traffic, respectively aligning the header and load of a data packet in a network flow, and generating an enhanced header and an enhanced load according to an enhancement strategy; step 2, multi-granularity feature extraction: a double-branch feature extractor is adopted to process an enhanced head and an enhanced load respectively, a cross attention mechanism is utilized to obtain fused flow level representation, and depth features are extracted through Mama; and step 3, semi-supervised contrast learning: the contrast learning loss and the cross entropy loss of the label data and the FixMatch loss of the non-label data are integrated, and an encrypted traffic fine-grained classifier is trained. The method has the beneficial effects that the noise propagation is jointly inhibited by comparing the feature structured constraint of learning and a high-confidence threshold filtering mechanism in FixMatch, the training stability is improved, and the labeling cost is remarkably reduced.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A multi-level management, multi-functional IPv6 traffic monitoring platform

This invention relates to a multi-level managed IPv6 traffic multi-functional monitoring platform, comprising a data acquisition layer, a regional monitoring layer, a core analysis layer, a control and orchestration layer, and a feedback optimization layer. The data acquisition layer, located at the network edge, is responsible for collecting real-time traffic data and performing preliminary traffic classification and anomaly detection. The regional monitoring layer is distributed across various regions, aggregating edge data to construct a regional traffic feature database, while simultaneously handling local traffic anomalies and executing response strategies. The core analysis layer contains a centralized platform core computing unit that optimizes the global AI model through federated learning and introduces a dual-stream neural network to fuse global and personalized features, providing cross-regional collaborative monitoring and global optimization. The control and orchestration layer provides dynamic resource allocation and policy adjustment, coordinating the operation of global and regional nodes. The feedback optimization layer combines digital twins and reinforcement learning to continuously optimize traffic scheduling and protection strategies.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT JIANGXI BRANCH

Encrypted traffic classification method and system based on graph comparison clustering

The invention discloses an encrypted traffic classification method and system based on graph contrast clustering, and the method specifically comprises the steps: carrying out the grouping of captured PCAP format traffic data, extracting the size features, direction features and time interval features of a data package, and generating an original traffic interaction graph; multiple enhancement operations are applied to the original traffic interaction diagram, and a balanced traffic diagram data set is generated; respectively applying two enhancement operations to each traffic interaction diagram in the balanced traffic diagram data set to generate double-view data; inputting the dual-view data into a shared encoder and a projection head, and mapping the dual-view data to an embedding space through encoding to obtain corresponding multi-view image embedding; a positive and negative sample pair set is built based on multi-view graph embedding, and intra-class aggregation and inter-class separation of the positive and negative sample pair set are enhanced by using supervised contrast loss and central perception loss to train the model. According to the method, high-robustness and high-discrimination encrypted traffic identification and dynamic category expansion capabilities are realized.
Owner:HUNAN UNIV OF SCI & TECH

An encrypted traffic classification method based on multi-view heterogeneous graph model

The application provides an encrypted traffic classification method based on a multi-view heterogeneous graph model (MH-Net), which can effectively improve the accuracy and robustness of network traffic classification. In this method, a multi-view traffic graph is constructed, and different numbers of traffic bits are aggregated into multiple types of traffic units to enrich the diversity of information granularity. Further, three types of traffic unit correlations, including header-header, header-payload, and payload-payload, are introduced to form a heterogeneous traffic graph, and a heterogeneous graph neural network is used for feature extraction. In addition, through a multi-task contrastive learning strategy, the robustness of traffic unit representation is enhanced, and synchronous training is realized in traffic-level and packet-level classification tasks to optimize overall performance. Experimental results show that this method achieves excellent performance on multiple datasets, surpassing existing technologies and demonstrating its application potential in the field of network traffic classification.
Owner:TSINGHUA SHENZHEN INTERNATIONAL GRADUATE SCHOOL

Device testing method, testing device and storage medium

This application relates to the field of electronic equipment technology, and discloses a device testing method, testing equipment, and storage medium. The method includes: loading and initializing a traffic classification module, a traffic isolation module, and an algorithm module at the kernel network protocol stack of the operating system of the device under test; using the traffic classification module to divert the test data of different test items to different queues based on the information of the test data of each test item in multiple test items; using the algorithm module to perform network impairment processing on the test data flowing through the traffic isolation module, so that the traffic isolation module outputs the impaired data; based on the impaired data, determining whether the network state of the device under test has been configured to a weak network state; if the network state of the device under test has been configured to a weak network state, evaluating the working state of the device under test, and determining the test result of the device under test based on the working state of the device under test. This application can test whether the device under test meets the requirements under a weak network state.
Owner:SHENZHEN JIUNIU YIMAO INTELLIGENT IOT TECH CO LTD

DoH tunnel detection method based on feature fusion and large language model

The invention discloses a DoH tunnel detection method based on feature fusion and a large language model, and relates to the field of network space security, and the method comprises the steps: obtaining original network encrypted traffic data, and dividing the original network encrypted traffic data into a plurality of traffic sessions; extracting a byte sequence of the original data packet, and calculating a time sequence abnormal feature and a length abnormal feature to form an expert feature vector; formatting and splicing the byte sequence of the original data packet and the expert feature vector to generate a structured sequence; constructing a mask auto-encoder model and performing pre-training to obtain a pre-trained feature encoder; accessing a classification module to form an initial classification model; performing fine adjustment on the initial classification model by using the first data set and the second data set to obtain a DoH tunnel malicious traffic detection model; and generating a structured sequence input model by using the to-be-detected network traffic, and outputting a malicious DoH traffic classification result. Through combination of feature fusion and a pre-training model, high-precision and strong-generalization detection of DoH tunnel malicious behaviors in encrypted traffic is realized.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Network management methods, devices, electronic equipment and storage media

This invention discloses a network management method, device, electronic device, and storage medium, relating to the field of data processing technology. It includes training an initial classification model using a sample traffic feature dataset and corresponding classification targets. The model can fuse traffic features according to the classification targets and iterate model parameters using the model classification results and the actual classification results corresponding to the training data to obtain an actual classification model. This model then outputs the traffic classification result for any server network, enabling network resource allocation. This invention solves the technical problems in related technologies, such as the use of dynamic ports breaking the fixed mapping relationship between port numbers and applications, encryption techniques hiding payload content making it difficult to directly extract traffic features, affecting classification accuracy, and thus impacting network management effectiveness. It improves traffic classification accuracy in complex network environments, facilitating effective network management and ultimately enhancing the network user experience.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Network traffic classification method and device based on multi-modal feature fusion

The invention discloses a network flow classification method and device based on multi-modal feature fusion, and the method comprises the steps: obtaining network flow data, extracting an IP address as a node, and constructing a communication graph; time modal features and event modal features are extracted for each node, and standardization processing is carried out on the time modal features and the event modal features; the time modal features and the event modal features are aligned; fusing the two types of aligned features; performing multi-layer neighbor sampling and hierarchical aggregation on the communication graph by using a graph neural network model to obtain structure-enhanced node features containing multi-hop neighbor information, inputting the node features into a linear classifier, outputting a category probability, selecting a category with the maximum probability as a prediction result, and performing iterative training to obtain a classification model; and mapping the classification model to a data plane of the programmable switch to realize online reasoning of the data packet. According to the method, high-precision identification of various network traffic types is realized by fusing the spatial modal, time and event modal characteristics.
Owner:GUANGZHOU UNIVERSITY

Adapting restricted target wake time to provide traffic classification granularity

Aspects of the present disclosure are directed to modifying use of Restricted Target Wake Up Time Service to restrict broadcasting traffic parameters sets on a per traffic category basis between an access point and an end device in a wireless network. In one aspect, a method includes transmitting, by an access point, a message to an end device connected to the access point, the message identifying for the end device a traffic type restriction policy that the access point has on reporting Restricted Target Wake Time (R-TWT) parameters for a plurality of traffic types; and receiving, from the end device, a separate Broadcast TWT Parameters Set for each one of the plurality of traffic types in accordance with the traffic type restriction policy.
Owner:CISCO TECHNOLOGY INC