Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

156 results about "Traffic identification" patented technology

Tor network exit flow identification system and method fusing multi-scale LSTM (Long Short Term Memory) and Transform network

The invention discloses a Tor network exit traffic identification system and method fusing a multi-scale LSTM and a Transform network, and belongs to the technical field of anonymous network traffic analysis and network security. The system comprises five core components, namely a multi-scale feature extraction module, a feature fusion module, a global dependency modeling module, a dynamic weighted aggregation module and a classification module. The multi-scale feature extraction module adopts parallel bidirectional LSTM branches with different time resolutions to capture a microcosmic burst mode and a macroscopic session behavior at the same time; the feature fusion module unifies the scale features to the same time sequence length and splices the scale features; the global dependence modeling module utilizes a multi-head self-attention mechanism to learn long-distance time sequence dependence; the dynamic weighted aggregation module highlights a key time slice through adaptive weight pooling; and the classification module outputs website category labels. According to the system, the recognition accuracy on a GTT23 data set is remarkably improved compared with that of an existing method, and good recognition capability and robustness are shown for various flow defense mechanisms.
Owner:JIANGSU UNIV

Network abnormal traffic identification method and system applied to big data

The invention provides a network abnormal traffic identification method and system applied to big data, and the method comprises the steps: receiving an original traffic data stream flowing in a network transmission link, and extracting the associated attribute information carried by the original traffic data stream; performing link association analysis processing on the original traffic data flow to obtain a traffic association map and traffic transmission link characteristics; and inputting the traffic association map and the traffic transmission link features into a preset anomaly identification network, and generating traffic anomaly association features through hierarchical interaction processing. And triggering a classification decision-making mechanism based on the traffic anomaly association features, and outputting an anomaly identification result of the network traffic. And finally, generating flow control guide information according to an abnormal identification result, and sending the flow control guide information to a flow control node to execute a control operation. According to the method, flow data are analyzed from multiple dimensions, association between features is fully mined, accurate identification and effective management and control are realized, the capability of the network to deal with abnormal flow is effectively improved, and stable operation of the network and data security are guaranteed.
Owner:CHENGDU XINXIU CULTURE MEDIA CO LTD

Method, device and equipment for identifying and controlling PCDN flow, and storage medium

The invention relates to a PCDN traffic identification control method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the steps of obtaining traffic access records of a plurality of candidate broadband users, performing PCDN feature recognition and reasoning on the traffic access records of the plurality of candidate users to obtain PCDN traffic information, the PCDN traffic information comprising PCDN broadband user accounts and PCDN traffic identifiers, sending the PCDN traffic information to a management and control device, and sending the PCDN traffic information to the management and control device. The PCDN flow information is used for the management and control equipment to position the PCDN flow so as to manage and control the PCDN flow. The PCDN traffic can be accurately identified, the PCDN traffic is effectively controlled, and other normal service traffic of a user is not affected.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Abnormal network flow identification method and device and medium

The invention relates to an abnormal network traffic identification method and device and a medium, and belongs to the technical field of network security. The method comprises the following steps: collecting a real-time network data packet; processing the real-time network data packet to obtain semantic features and time sequence feature indexes; an improved BERT model is adopted to encode the semantic features to obtain a high-dimensional semantic vector, and the BERT model is improved and comprises the steps that corresponding Tokenizer and Embedding layers are designed for the semantic features; modeling and coding the time sequence characteristic indexes by using a Prophet model to obtain time sequence characteristic vectors; generating a multi-modal feature vector; detecting the multi-modal feature vector by using the model to obtain an identification result; wherein the reinforcement learning network model adopts a DDQN algorithm, the model comprises a state, an action and a reward, and parameters of the network model are updated according to the final reward executed by the action. According to the scheme, the abnormal network traffic can be accurately identified, and new and unknown attack modes can be continuously adapted.
Owner:CHONGQING TELECOMM PLAN & DESIGN INST

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

Intranet encryption malicious traffic identification method and system based on attention mechanism

The invention belongs to the technical field of intranet security, and discloses an intranet encryption malicious traffic identification method and system based on an attention mechanism, and the method comprises the steps: carrying out the encryption processing of original CAN bus data through employing an XTEA lightweight algorithm, and simulating a real intranet encryption environment; the encrypted data are converted into two-dimensional image features and sequential sequence features at the same time, efficient spatial feature extraction is performed by using an optimized CNN structure, and the sequential features are captured by combining a GRU network, a self-attention mechanism and a Transform encoder; and training is carried out through feature fusion, so that accurate recognition of different types of attacks is realized. According to the method, on the premise of not depending on hardware, high-precision identification is realized under the condition that malicious traffic encrypted by the in-vehicle network does not need to be decrypted, the requirements of the in-vehicle network on real-time performance and resource consumption are met, and meanwhile, high-precision identification capability is still kept in the face of various attacks.
Owner:XIAN UNIV OF POSTS & TELECOMM

Encrypted traffic identification method based on big data

The invention relates to the technical field of information security, in particular to an encrypted traffic identification method based on big data, which comprises the following steps of: acquiring a network data packet, extracting flow statistical characteristics and a TLS handshake protocol field, generating an original characteristic vector after numeralization processing; determining a traffic data type based on the type identification model, further calculating a network data feature coefficient, and determining an encrypted traffic identification model based on a comparison result with a historical coefficient; inputting the original feature vector into the model to obtain an initial recognition result and a flow confidence coefficient, classifying the recognition result based on the flow confidence coefficient, and executing corresponding regulation and control operation based on the recognition result; and re-collecting the regulated data packet, extracting the network state data to calculate a regulation efficiency index, and determining whether to regulate the historical network data feature coefficient based on the regulation efficiency index and the identification efficiency index. Through a closed-loop feedback optimization mechanism, adaptive adjustment of encrypted traffic identification is realized, and the identification accuracy and the regulation and control efficiency are improved.
Owner:BEIJING YOUYUAN TECH CO LTD

P2P traffic identification method, device, equipment, medium and program product

The invention provides a P2P traffic identification method, apparatus and device, a medium and a program product. The method comprises the steps of determining a P2P traffic identification result sample corresponding to a traffic feature sample; performing feedback scoring according to the flow characteristic sample and the P2P flow identification result sample to obtain a target score value of the P2P flow identification result sample; adjusting and optimizing the P2P flow identification model based on the target score value to obtain an adjusted and optimized P2P flow identification model; and based on the flow characteristic data of the network node, performing prediction through the adjusted and optimized P2P flow identification model to obtain a P2P flow identification result of the flow characteristic data. According to the P2P flow identification method provided by the invention, through offline analysis training and online prediction of network node flow data, complex and diversified flow type conditions in a network can be better dealt with, the method has very strong generalization processing capability for identification of network node P2P flow, and the accuracy of P2P flow identification is integrally improved.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Iot gateway data processing method and related apparatus

The application provides an Internet of Things gateway data processing method and related device, a traffic identification framework is acquired and a device set to be processed is determined; each decision unit in the traffic identification framework is walked through from a starting identification unit of the traffic identification framework, a traffic detection network corresponding to the walked decision unit is acquired, and a device set corresponding to the walked decision unit in the device set to be processed is determined; based on the traffic detection network corresponding to the walked decision unit and a traffic identification feature vector in the traffic detection network corresponding to the walked decision unit, the device set corresponding to the walked decision unit is identified, a device set corresponding to each sub-decision unit connected to the walked decision unit is determined, and each terminal identification unit in the traffic identification framework is obtained until each terminal identification unit in the traffic identification framework corresponds to a device set respectively. The application can improve the accuracy of device identification.
Owner:BEIHANG UNIV

Fine-grained traffic classification method based on improved residual convolutional network in SDN environment

The application relates to a fine-grained traffic classification method based on an improved residual convolutional network in an SDN environment and belongs to the software technical field. In order to provide finer-grained application-aware traffic classification, let network operators better analyze network composition and manage and schedule network resources, fine-grained classification of the specific application programs is very important. Traditional methods tend to classify traffic based on protocols, which is coarse-grained classification. Inspired by the research in computer vision, the method of the residual convolutional network is applied to the identification and classification of network traffic. The method solves the network degradation problem that occurs in the process of fine-grained network traffic identification by traditional deep learning methods with the increase of network depth, can effectively learn deeper network features, and further realizes fine-grained network traffic classification.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Centralized acceleration method and device, equipment, program product and storage medium

The invention relates to the technical field of acceleration, and provides a centralized acceleration method and device, equipment, a program product and a storage medium. The method comprises the following steps: receiving user traffic to be accelerated sent by a service router; based on the access control strategy, screening out target user traffic from the to-be-accelerated user traffic; forwarding the target user traffic to an acceleration network for acceleration; the access control strategy is generated by the acceleration management platform based on the network characteristics of the target user in the traceability system. According to the centralized acceleration method, device and equipment, the program product and the storage medium provided by the invention, traffic identification and distinguishing and centralized acceleration based on user granularity can be realized on the premise of not carrying out any transformation on the broadband access server of the existing network, the waste of the IP address of the public network is reduced, and in addition, the user experience is improved. The acceleration management platform can be directly and independently transplanted and deployed, various value-added services for identifying user traffic can be customized based on service requirements, and the implementation difficulty is greatly reduced.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Malicious traffic identification and active interception system for industrial internet

The invention relates to the technical field of network security of industrial internet, and discloses an industrial internet-oriented malicious traffic identification and active interception system, which comprises a traffic acquisition module used for acquiring data traffic associated with the industrial internet; the feature determination module is used for determining drift features at least associated with the data traffic and determining potential features corresponding to the drift features; the learning identification module is used for identifying the potential features based on an attack rule through a lightweight adversarial learning model, and determining the risk level of the data traffic; and the active interception module is used for executing active interception operation corresponding to the risk level on the data traffic. According to the scheme, the detection and interception requirements of diversified data traffic of the industrial internet can be met.
Owner:HEBEI VOCATIONAL COLLEGE OF FOREIGN LANGUAGES

A method and system for encrypted traffic identification based on spatio-temporal features and semantic alignment

This invention discloses a method and system for identifying encrypted traffic based on spatiotemporal features and semantic alignment. The method first extracts the spatial and temporal feature sequences of the network flow, and uses a byte-pair encoding algorithm to convert the spatial packet length into discrete symbols. Then, the discrete symbols and temporal features are mapped to a high-dimensional space and fused together. A global spatiotemporal feature vector is extracted through a network using a concatenated one-dimensional convolution and multi-head self-attention mechanism. Next, the text semantic bullseye matrix of fine-grained behaviors of various known applications is obtained offline from a large language model. Finally, the similarity between the spatiotemporal features and the text bullseye is calculated, and a multi-instance learning max-pooling mechanism is introduced for dynamic routing. Based on this, a contrastive learning loss function optimization model is constructed or cross-modal inference is performed. This invention completely overcomes the conceptual drift problem caused by changes in encrypted features, achieving extremely high generalization accuracy and feature interpretability across generations.
Owner:WUHAN UNIV

Attack traffic identification method and device, computer equipment, medium and program product

The invention relates to an attack traffic identification method and device, computer equipment, a medium and a program product. The method comprises the following steps: when a new network connection of a virtual switch is detected, determining a connection rate of the new network connection; when the connection rate of the new network connection reaches a preset attack traffic threshold, determining the connection state of each network connection of the virtual switch; each network connection comprises the new network connection; and when the connection state is a semi-connection state, determining that the attack traffic aiming at the virtual switch exists. By adopting the method, whether attack traffic exists or not can be accurately identified.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Machine learning based abnormal traffic identification management and control method and system

PendingCN122660974AInternet trafficEngineering
The application discloses an abnormal traffic identification management and control method and system based on machine learning, multi-dimensional network traffic data in multiple scenes is collected, the collected data is sequentially preprocessed to obtain initial traffic data; based on a graph neural network, IP nodes in a network topology are regarded as vertices, and traffic interaction is regarded as an edge, spatial features of the initial traffic data on spatial distribution are extracted; based on an encoder, suddenness and periodicity deviation of the initial traffic data on a time dimension is captured to obtain time sequence features of traffic; an abnormal traffic identification result is output, risk level determination is performed according to the result, and a hierarchical management and control strategy is executed. Real-time identification, accurate determination and rapid disposal of abnormal traffic are realized, and network security protection capability is comprehensively improved.
Owner:SHENZHEN YUNTU COMM CO LTD

Distillation enhanced clustering acceleration method for encrypted traffic classification

The invention discloses a distillation enhanced clustering acceleration method for encrypted traffic classification, and relates to the technical field of computer network encrypted traffic classification, and the method comprises a clustering perception knowledge distillation stage and a hybrid reasoning acceleration stage, the clustering perception knowledge distillation stage is responsible for optimizing the feature space of a model, and firstly, the clustering perception knowledge distillation stage is responsible for optimizing the feature space of the model; a novel cluster-friendly encoder loss is introduced in the fine tuning process, so that the model is forced to learn feature representation which is beneficial to classification and high-purity clustering; and then, taking the fine-tuned PTM as a teacher model, distilling knowledge of the PTM into a lightweight five-layer feed-forward neural network so as to obtain a student model capable of rapidly extracting semantic features, and the hybrid reasoning acceleration stage is responsible for realizing efficient classification and new product discovery. According to the method, on the basis that the original structure of a pre-training model is not changed at all, an efficient and accurate classification system with a novel flow recognition capability is realized through knowledge distillation of clustering perception and a hybrid reasoning acceleration mechanism.
Owner:NANJING INFORMATION HIGH-SPEED RAILWAY RES INST OF SCI AND TECH

Malicious traffic detection system based on point cloud analysis false positive cleaning method and device

The application discloses a false positive cleaning method and device for a malicious traffic detection system based on point cloud analysis, and the method comprises the following steps: obtaining a point cloud based on a traffic feature vector associated with an alarm signal generated by the malicious traffic detection system; covering the point cloud by using a first plurality of voxels, and determining a second plurality of voxels based on the point cloud covering result; performing an aggregation operation on the second plurality of voxels to construct a voxel group; and respectively identifying alarm signals corresponding to a high-density voxel group and a low-density voxel group obtained based on voxel group clustering to obtain a true positive alarm identification result and a false positive alarm identification result. Through the point cloud analysis method based on voxels, the application automatically divides the alarms generated by the malicious traffic identification system into true positive alarms and false positive alarms. The manual cost of manually distinguishing the true positive alarms from the false positive alarms is significantly reduced, and the application has good real-time performance, accuracy and robustness.
Owner:TSINGHUA UNIVERSITY

Passenger information system and procedures for transmitting passenger information

ActiveDE102020110677B4Data processing applicationsPassenger information systemDisplay device
Passenger information system (10) for transmitting passenger information to one or more passengers with at least one stationary display device (11) designed for the visual display of vehicle and timetable-related transport information (14) of at least one means of transport for the carriage of passengers, wherein at least one mobile display device (20) assigned to a passenger (200) is provided, which is equipped: - to identify the means of transport displayed on the stationary display device (11), for which the vehicle and timetable-related transport information (14) is shown, and to determine the relevant vehicle and / or timetable-related data depending on the identified means of transport by means of a transport identification unit, - to determine passenger-related booking data of a travel booking relating to a planned journey of the passenger (200) assigned to this mobile display device (20) by means of a booking data determination unit, wherein the passenger-related booking data includes at least the means of transport required for the planned journey, and - to determine transport-related and / or passenger-related travel information in addition to the vehicle- and timetable-related transport information (14) displayed on the stationary display device (11) based on the vehicle- and timetable-related data of the identified means of transport and the passenger-related booking data and to display this information on a display unit of the mobile display device (20) for the passenger (200), - characterized in that the mobile display device (20) has an AR visualization device which is configured to record the environment of the mobile display device (20) by means of a camera and to display it on the display unit of the mobile display device (20), whereby the transport-related and / or passenger-related information is superimposed on the displayed environment.
Owner:DEUTSCHES ZENTRUM FÜR LUFT UND RAUMFAHRT E V

Abnormal network traffic identification method, device, equipment and medium

The invention discloses an abnormal network traffic identification method, device and equipment and a medium, and the method comprises the steps: obtaining historical routing snapshot data in a set first time period and historical network traffic data sent by a first AS to each second AS from a boundary router of a first AS; based on the historical routing snapshot data and the historical network traffic data, determining expected network traffic data sent to each second AS by the first AS in the second duration; for any second AS, determining a target error value based on expected network traffic data and actual network traffic data sent to any second AS by the first AS in a second duration; and comparing the target error value with a set target threshold value, and judging whether the first AS and any second AS have abnormal network traffic within the second duration. According to the method, the accuracy of predicting the expected network traffic data can be improved, and the accuracy of identifying the abnormal network traffic can be improved.
Owner:CHINA TELECOM CORP LTD

Multi-feature anonymous network traffic identification method and device based on convolution-attention hybrid architecture

The invention discloses a multi-feature anonymous network traffic identification method and device based on a convolution-attention hybrid architecture, and relates to the technical field of network information security. The method comprises the following steps: acquiring original data of anonymous network traffic to be identified, preprocessing the original data, dividing a continuous data packet into a plurality of burst streams, and generating a structured traffic sequence; extracting a plurality of key features from the traffic sequence, and inputting the key features into a preprocessing convolution block for grouping convolution, feature fusion and dimension reduction to obtain structured multichannel traffic features; inputting the multi-channel traffic characteristics into a trained traffic identification model to obtain a category identification result of the anonymous network traffic; wherein the traffic recognition model is obtained by performing iterative training on the convolution-attention mixed architecture by adopting a pseudo-label mechanism. According to the method, the multi-dimensional features of the traffic can be comprehensively utilized, so that the accuracy of traffic identification is improved, and the generalization ability and scene adaptability of the model are remarkably enhanced.
Owner:NANJING UNIV OF POSTS & TELECOMM

Test script generation method and device, storage medium and terminal

The invention discloses a test script generation method and device, a storage medium and a terminal. Inputting the attack traffic into a pre-trained traffic identification model to obtain at least one attack method of the attack traffic and network messages corresponding to the attack methods; correcting each attack method and the network message corresponding to each attack method through a pre-trained large language model; and controlling the large language model to generate test scripts corresponding to the attack methods according to the modified attack methods and the network messages corresponding to the attack methods. According to the method, the attack method and the network message are extracted through the pre-trained traffic recognition model and then are corrected by the large language model, the advantages of the pre-trained traffic recognition model and the large language model are combined, the high efficiency of the pre-trained traffic recognition model in traffic recognition is utilized, and the capability of the large model in generalization reasoning is also exerted; the illusion problem of a large language model is reduced, and the coverage range and the accuracy degree of the test script are improved in a security evaluation scene.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD

Traffic identification method and device, computer device, readable storage medium and program product

The application relates to a traffic identification method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: obtaining target traffic to be identified; identifying the target traffic through a hotspot engine to obtain a first identification result; wherein the hotspot engine is constructed based on a hotspot rule set, and the hotspot rule set contains hotspot rules in an application identification engine that meet preset traffic hit conditions; if the first identification result is that a target hotspot rule in the hotspot rule set is hit, an application identification result corresponding to the target hotspot rule is output; and if the first identification result is that the hotspot rule set is not hit, the target traffic is identified through the application identification engine, and a second identification result is output. The method can effectively improve the efficiency of application identification.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Abnormal traffic identification method and apparatus, and electronic device

The invention discloses an abnormal traffic identification method and apparatus, and an electronic device. The method comprises the following steps: acquiring a historical bit stream captured by a network interface; determining a time feature vector corresponding to the traffic feature, determining a semantic vector corresponding to the digital digest, and constructing a spatial feature matrix according to the traffic feature; splicing the time feature vector, the semantic vector and the spatial feature matrix to obtain a fusion feature tensor, and determining a probability density function that historical network traffic corresponding to the fusion feature tensor belongs to normal traffic by using an online learning model; and obtaining a target fusion feature tensor in the current time window, updating the online learning model based on the target fusion feature tensor, and determining whether the network traffic corresponding to the target fusion feature tensor is abnormal traffic by using the updated online learning model. According to the method and the device, the technical problem that the recognition precision of the abnormal traffic is relatively low due to the fact that the complex characteristics of the network traffic cannot be comprehensively and deeply captured in related technologies is solved.
Owner:CHINA TELECOM CORP LTD

Network security data transmission control method based on abnormal traffic identification

The invention relates to the technical field of computer network security and data transmission control, in particular to a network security data transmission control method based on abnormal flow recognition, which comprises the following steps: acquiring original data flow in a network transmission channel, and generating a flow statistical feature vector; constructing a micro-disturbance injector model, and generating a modulation feedback flow with active time sequence characteristics; constructing a response behavior track of the source end to the active time sequence characteristics according to the dynamic response data, and forming behavior difference characteristic representation; constructing a protocol stack behavior discriminator model, and calculating a fitting deviation degree between a source end behavior and a standard protocol stack; generating a transmission control instruction set based on the fitting deviation degree; executing physical layer intervention on a transmission channel of the original data stream according to the transmission control instruction set, and updating a stream statistical feature vector according to a channel state after intervention to complete closed-loop control of data transmission; according to the method, the lag of the traditional passive monitoring scheme on timeliness and the excessive dependence on static characteristics are eliminated.
Owner:CHONGQING QICAIHONG DIGITAL TECH CO LTD

An abnormal traffic identification method and device, electronic equipment and storage medium

PendingCN122160172AScreening is efficient and accuratequick lockSecuring communicationInformation repositoryIp address
The application provides a kind of abnormal flow discernment method, device, electronic equipment and computer readable storage medium, it is related to network information security technical field.Discernment method includes: identifying abnormal flow and its corresponding IP address, wherein, abnormal flow refers to one or more kinds of abnormal network flow;According to IP address and preset device information library, the port bandwidth data of abnormal device is monitored, wherein, abnormal device refers to one or more devices to which abnormal flow belongs;According to port bandwidth data, normal flow and target abnormal flow in abnormal flow are discerned.It at least solves the core pain points of low accuracy, poor timeliness, difficult to troubleshoot and fragmented collaboration in related technologies, leading to high network security risk, high operation and maintenance cost and large business loss.Adapted to abnormal flow detection and diagnosis scene.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

A method, apparatus, electronic device, medium, and program product for identifying network traffic.

This invention belongs to the field of data processing technology, specifically disclosing a network traffic identification method, device, electronic equipment, medium, and program product. The method is implemented through hardware and software collaboration. The hardware module first identifies fixed feature strings in link packets and writes them into a flow table, then filters packets with payloads according to a preset strategy and mirrors them to the software module. The software module parses the packets to extract the application layer payload, performs multi-feature string matching based on a dynamically updatable feature library, and generates dynamic service features. The results are then encapsulated into backwash frames in UDP and GRE formats. After receiving the backwash frames, the hardware module compares the software features with its own feature priorities, prioritizing the updating of high-priority software features to the flow table, thus completing the service backwash. This invention improves the refinement and accuracy of traffic identification, adapts to dynamic changes in services, reduces hardware resource consumption, and ensures real-time network processing.
Owner:HAOHAN DATA

Encrypted network traffic behavior feature extraction method, device and system

The invention provides an encrypted network traffic behavior feature extraction method, device and system, and relates to the technical field of networks, the method comprises the following steps: preprocessing multi-source heterogeneous context information to obtain preprocessed context features; extracting an original data packet of the encrypted traffic to obtain metadata features of the encrypted traffic; dynamically selecting the context feature based on the preprocessed context feature, the metadata feature of the encrypted traffic and the performance feedback from the downstream application; adaptively adjusting the weights of the context features and the metadata features to obtain selected and weighted features; and fusing the selected and weighted features to obtain an enhanced behavior feature vector. According to the method, the problems of low encrypted traffic identification accuracy and poor adaptability in a complex network environment can be solved.
Owner:HARBIN INST OF TECH AT WEIHAI +1