Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

215 results about "Traffic identification" patented technology

Lightweight malicious network traffic detection method based on heterogeneous modal feature fusion

The invention discloses a lightweight malicious network traffic detection method based on heterogeneous modal feature fusion, and mainly solves the problems of low feature extraction efficiency and insufficient single modal feature representation of the existing method. Comprising the following steps: acquiring and optimizing a network flow data set, preprocessing the network flow data set, and extracting and generating spatial feature, time sequence feature and behavior pattern feature vectors; an improved self-attention mechanism network is constructed, a lightweight heterogeneous modal feature fusion model LMF is designed, multi-modal feature deep fusion is performed through dynamic weight distribution, a lightweight classification model is trained, and the model is utilized to detect network malicious traffic. Through the lightweight heterogeneous modal feature fusion model LMF and in combination with a dynamic weight distribution mechanism, spatial distribution, time sequence dependence and behavior semantic information of network traffic are deeply mined, data processing efficiency, malicious traffic detection accuracy and system robustness are improved, and the method is suitable for efficient malicious traffic identification and defense in the field of network security.
Owner:XIAN TECH UNIV

Method and system for identifying abnormal traffic of Internet of Things based on deep neural network

The invention relates to the technical field of Internet of Things anomaly identification, in particular to an Internet of Things anomaly traffic identification method and system based on a deep neural network. The method comprises the following steps: collecting communication data of each piece of IoT equipment in real time from an edge gateway of the Internet of Things; preprocessing the collected communication data, and constructing a multi-dimensional feature vector; based on a convolutional neural network and a bidirectional long-short-term memory network, performing time sequence feature extraction and anomaly discrimination on the multi-dimensional feature vector to output a traffic anomaly probability; and comparing the abnormal probability output by the depth time sequence modeling neural network with a dynamic threshold value, and if the abnormal probability exceeds a preset threshold value, determining that the traffic is abnormal. A gating mechanism is introduced into a bidirectional long-short-term memory layer, a gating coefficient is calculated at a time step level, the influence weight of time step information on final output is dynamically adjusted, feature expression of key time steps is strengthened, noise or irrelevant information is suppressed, and the sensitivity of a model to time sequence data is improved.
Owner:BEIJING XINJIE TECHNOLOGY CO LTD

Traffic checkpoint holographic recognition method and system based on multi-mode perception and medium

The invention discloses a traffic checkpoint holographic recognition method and system based on multi-mode perception and a medium, and relates to the technical field of traffic management, and the method comprises the steps: collecting an original perception data set in real time through a multi-mode sensor array disposed at a target traffic checkpoint; performing time-space synchronization processing on the original sensing data set to generate a multi-modal data frame sequence; performing fusion processing on the multi-modal data frame sequence by using a deep learning model to generate a holographic feature vector of the target vehicle; and based on the holographic feature vector, target identity recognition and behavior analysis of the target vehicle are carried out, a recognition result is output, and abnormal event early warning is carried out. The technical problems of low traffic recognition precision and insufficient real-time performance caused by the fact that an existing traffic monitoring system cannot efficiently fuse various sensor data for holographic recognition are solved, and the technical effect of improving traffic management efficiency and safety through multi-modal data space-time synchronization and deep feature fusion is achieved.
Owner:INTELLIGENT INTER CONNECTION TECH CO LTD

Flow characteristic adaptive QoS intelligent prediction adjustment method

The invention discloses a flow characteristic adaptive QoS intelligent prediction adjustment method, and relates to the field of network flow management, and the method comprises the steps: 1, collecting flow data in real time, and constructing a multi-dimensional characteristic vector based on protocol types, port numbers and user behavior dynamic classification; 2, high-frequency / low-frequency components are separated, and QoS parameter prediction is output through fusion of an LSTM short-term prediction module and a periodic trend analysis module; 3, solving a resource pre-allocation scheme by adopting reinforcement learning by taking minimization of packet delay as a target; and 4, executing traffic identification, speed limiting and priority queue scheduling by using NPU hardware unloading. According to the method, the precision is improved through a high-frequency / low-frequency combined prediction architecture, decision delay is compressed to a large extent through reinforcement learning and NPU cooperation, and meanwhile online model iteration is achieved through a prediction error triggering mechanism.
Owner:陕西港芯电子科技有限公司

Deep learning-based traffic jam intelligent identification method and system

The invention provides a traffic jam intelligent identification method and system based on deep learning. The method comprises the steps of obtaining a multi-source traffic recognition optimized data set by obtaining and optimizing a multi-source traffic recognition data set, then constructing traffic scene label feature data, recognizing dynamic traffic scene category feature data, evaluating a traffic jam initial evaluation index, analyzing a traffic jam recognition influence factor, and optimizing to obtain a traffic jam correction index. And finally, performing threshold value comparison with a preset dynamic traffic jam identification threshold value, judging whether traffic jam exists or not according to a threshold value comparison result, analyzing and identifying a jam cause, and generating an intelligent traffic jam identification report at the same time. According to the invention, multi-source heterogeneous data is collected, data fusion and feature extraction are completed through the deep learning model, congestion identification is realized by combining dynamic scene classification and adaptive threshold determination, and congestion cause tracing analysis is completed by using the deep learning classification model, so that traffic congestion intelligent identification based on deep learning is realized.
Owner:GUANGZHOU TURINGIT CO LTD

Tor network exit flow identification system and method fusing multi-scale LSTM (Long Short Term Memory) and Transform network

The invention discloses a Tor network exit traffic identification system and method fusing a multi-scale LSTM and a Transform network, and belongs to the technical field of anonymous network traffic analysis and network security. The system comprises five core components, namely a multi-scale feature extraction module, a feature fusion module, a global dependency modeling module, a dynamic weighted aggregation module and a classification module. The multi-scale feature extraction module adopts parallel bidirectional LSTM branches with different time resolutions to capture a microcosmic burst mode and a macroscopic session behavior at the same time; the feature fusion module unifies the scale features to the same time sequence length and splices the scale features; the global dependence modeling module utilizes a multi-head self-attention mechanism to learn long-distance time sequence dependence; the dynamic weighted aggregation module highlights a key time slice through adaptive weight pooling; and the classification module outputs website category labels. According to the system, the recognition accuracy on a GTT23 data set is remarkably improved compared with that of an existing method, and good recognition capability and robustness are shown for various flow defense mechanisms.
Owner:JIANGSU UNIV

Multi-source heterogeneous network security method and intelligent terminal

The invention discloses a multi-source heterogeneous network security method and an intelligent terminal, and relates to the technical field of data security, and the method comprises the steps: constructing a first traffic feature sub-graph according to first network traffic data, and constructing a second traffic feature sub-graph according to second network traffic data; performing node feature remapping on the second traffic feature sub-graph according to the first traffic feature sub-graph to obtain a cross feature sub-graph; performing node feature correction on the first flow feature sub-graph according to the cross feature sub-graph to form a fusion feature sub-graph; calculating a topological correlation entropy between nodes according to the fusion feature sub-graph, updating a node connection relationship based on the topological correlation entropy to obtain a dynamic fusion feature graph, and reversely updating node features in the cross feature sub-graph according to the dynamic fusion feature graph; according to the method, the traffic structure change can be dynamically perceived, the identification capability on potential attack behaviors is enhanced, and security risk detection and abnormal traffic identification are stably and efficiently carried out in a multi-source and dynamically changed complex network environment.
Owner:SHENZHEN ANSITONG TECH CO LTD

Network abnormal traffic identification method and system applied to big data

The invention provides a network abnormal traffic identification method and system applied to big data, and the method comprises the steps: receiving an original traffic data stream flowing in a network transmission link, and extracting the associated attribute information carried by the original traffic data stream; performing link association analysis processing on the original traffic data flow to obtain a traffic association map and traffic transmission link characteristics; and inputting the traffic association map and the traffic transmission link features into a preset anomaly identification network, and generating traffic anomaly association features through hierarchical interaction processing. And triggering a classification decision-making mechanism based on the traffic anomaly association features, and outputting an anomaly identification result of the network traffic. And finally, generating flow control guide information according to an abnormal identification result, and sending the flow control guide information to a flow control node to execute a control operation. According to the method, flow data are analyzed from multiple dimensions, association between features is fully mined, accurate identification and effective management and control are realized, the capability of the network to deal with abnormal flow is effectively improved, and stable operation of the network and data security are guaranteed.
Owner:CHENGDU XINXIU CULTURE MEDIA CO LTD

Cross-end traffic identification and user behavior attribution analysis method and system

The invention relates to a cross-end traffic identification and user behavior attribution analysis method and system. The method comprises the following steps: obtaining a user behavior data set according to application store advertisement click data and landing page downloading data; matching the user behavior data set through a preset equipment fingerprint database to obtain a global user identifier and real-time behavior data corresponding to the user behavior data set; classifying the users through a sliding window algorithm according to the global user identifier and the real-time behavior data to obtain new users and active users; attributing the newly-added users and the active users to obtain attribution results of the newly-added users and attribution results of the active users; and integrating the attribution result of the new user, the attribution result of the active user and the historical new attribution rule calculation result to generate the real-time inquirable channel efficiency, so that the method has the advantages of effectively avoiding the settlement misjudgment and realizing the channel efficiency optimization under the complex business scene of the specific financial field.
Owner:SHANGHAI XURONG NETWORK TECH CO LTD

Network security-oriented abnormal traffic identification processing method

The invention discloses a network security-oriented abnormal traffic identification processing method. The method comprises the following steps of: constructing a traffic baseline model of target network link access equipment in different scenes and time windows based on historical traffic data; collecting flow characteristic data and bandwidth characteristic data of the equipment in real time, comparing the data with the flow baseline model, and identifying abnormal equipment through the baseline deviation degree; the content type is identified by using URL classification and deep packet inspection technologies, and the destination and the anomaly degree of the abnormal traffic are determined in combination with the attribute and traffic consumption of the known type of content and the traffic consumption and bandwidth occupation duration of the unknown type of content; and generating a detection report and pushing the detection report to an administrator terminal. Through scene-divided and multi-dimensional dynamic baseline modeling and flow feature and bandwidth feature fusion collaborative analysis, abnormal equipment and flow are accurately identified, the misjudgment rate is reduced, the network security operation and maintenance efficiency is improved, and the method is suitable for abnormal flow monitoring of various network environments.
Owner:LIUZHOU CITY VOCATIONAL COLLEGE

Abnormal traffic monitoring method and system based on security gateway

The invention discloses an abnormal traffic monitoring method and system based on a security gateway, and the method comprises the steps: obtaining a TLS handshake feature in a traffic request in response to the traffic request of a target user, and carrying out the Hash calculation of the TLS handshake feature, and obtaining a JA3 Hash fingerprint; performing three-level cache matching on the JA3 hash fingerprints in sequence, and extracting fingerprint tags of the JA3 hash fingerprints which are not matched in three-level cache; performing feature extraction on the traffic data corresponding to the fingerprint tag to obtain traffic features; and inputting the traffic characteristics into a pre-trained abnormal traffic identification model based on Transform to obtain an abnormal traffic identification result. According to the method provided by the invention, the detection precision of the abnormal traffic is improved.
Owner:BEIJING HUITONG JINCAI INFORMATION TECH +1

Method, device and equipment for identifying and controlling PCDN flow, and storage medium

The invention relates to a PCDN traffic identification control method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the steps of obtaining traffic access records of a plurality of candidate broadband users, performing PCDN feature recognition and reasoning on the traffic access records of the plurality of candidate users to obtain PCDN traffic information, the PCDN traffic information comprising PCDN broadband user accounts and PCDN traffic identifiers, sending the PCDN traffic information to a management and control device, and sending the PCDN traffic information to the management and control device. The PCDN flow information is used for the management and control equipment to position the PCDN flow so as to manage and control the PCDN flow. The PCDN traffic can be accurately identified, the PCDN traffic is effectively controlled, and other normal service traffic of a user is not affected.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Method and system for identifying general overseas VPN (Virtual Private Network) proxy traffic based on TCP (Transmission Control Protocol)

The invention discloses a method and a system for identifying general overseas VPN (Virtual Private Network) proxy traffic based on a TCP (Transmission Control Protocol). The method comprises the following steps: S1, carrying out switch TCP traffic mirroring and session SYN related time delay calculation; s2, performing hash table interaction and time delay calculation under downlink message load distinguishing; s3, on the basis of judgment of the time delay # imgabs0 # and a threshold value D, counting and logic insertion are carried out on the HashVPS hash table; s4, periodically triggering HashVPS traversal and VPS proxy service affirmation in a timing manner; the system is suitable for the general overseas VPN proxy traffic identification method based on the TCP protocol. Aiming at various TCP transmission VPN protocols, the method breaks through conventional identification limitation, is not afraid of encryption, disguising and mining proxy traffic characteristic differences, constructs a complete identification closed loop, accurately screens out proxy traffic, and builds a network security defense line.
Owner:HAOHAN DATA

CAN intrusion detection method based on signal relation graph Transform

The invention is suitable for the field of vehicle information security, and provides a CAN intrusion detection method based on a signal relation graph Transform, which comprises the following steps: converting a frame sequence of a CAN network into a signal sequence, deeply mining key signal features in a message, systematically analyzing complex relevance between signals, and constructing a signal node feature representation system. In order to further improve the detection precision, the method uses a graph attention network and a Transform model, and optimizes the extraction and learning process of input signal features, thereby significantly reducing the false alarm rate in abnormal traffic recognition. By accurately capturing abnormal behaviors in the CAN network, the method can effectively cope with potential network attacks, meets the requirements of the advanced intelligent networked vehicle for functional security and network security, and provides important technical support for realizing a high-reliability and high-security vehicle-mounted communication system.
Owner:JILIN UNIVERSITY

Internet of things card abnormal flow identification and multistage response control system

The invention relates to the technical field of Internet of Things, in particular to an Internet of Things card abnormal traffic identification and multistage response control system, which comprises a quantum key distribution and generation module, a data acquisition and preprocessing module, an abnormal traffic identification module, a multistage response execution module and a quantum security management module. According to the method, the preprocessed traffic features are converted into low-dimensional core fingerprints, high-robustness detection of encrypted traffic anomalies is realized by combining a quantum heuristic CNN and gradient mask adversarial training hybrid intelligent model, and the detection accuracy is guaranteed by matching risk score quantification anomaly degree and baseline dynamic update. According to the method, the pain points that in traditional encrypted traffic detection, identification is difficult without decryption, and adversarial attack is likely to happen are effectively solved, and the security, robustness and reliability of Internet of Things card traffic management and control are remarkably improved.
Owner:SHANGHAI ZHUTONG INFORMATION TECH CO LTD

Real-time isolation method and device based on AI traffic anomaly recognition

The invention discloses a real-time isolation method and device based on AI traffic anomaly recognition, and relates to the technical field of network security and artificial intelligence, and the method comprises the steps: collecting network traffic data based on a preset traffic path, fusing communication protocol data, timestamp data, source address data and target address data, and obtaining a fusion result; the method comprises the steps of generating a traffic behavior model, analyzing the traffic behavior model, determining abnormal features in traffic behaviors and a distribution mode of the abnormal features, and switching a current traffic processing task to an isolation task when the distribution mode of the abnormal features meets a preset isolation condition. And generating an isolation area and an isolation signal according to the distribution mode of the abnormal characteristics, and executing an isolation task based on the isolation area and the isolation signal. By means of the mode, the technical problem that in the prior art, the processing efficiency of abnormal flow recognition and isolation is low is solved.
Owner:SHENZHEN NOVA TECH DEV CO LTD

Abnormal network flow identification method and device and medium

The invention relates to an abnormal network traffic identification method and device and a medium, and belongs to the technical field of network security. The method comprises the following steps: collecting a real-time network data packet; processing the real-time network data packet to obtain semantic features and time sequence feature indexes; an improved BERT model is adopted to encode the semantic features to obtain a high-dimensional semantic vector, and the BERT model is improved and comprises the steps that corresponding Tokenizer and Embedding layers are designed for the semantic features; modeling and coding the time sequence characteristic indexes by using a Prophet model to obtain time sequence characteristic vectors; generating a multi-modal feature vector; detecting the multi-modal feature vector by using the model to obtain an identification result; wherein the reinforcement learning network model adopts a DDQN algorithm, the model comprises a state, an action and a reward, and parameters of the network model are updated according to the final reward executed by the action. According to the scheme, the abnormal network traffic can be accurately identified, and new and unknown attack modes can be continuously adapted.
Owner:CHONGQING TELECOMM PLAN & DESIGN INST

Data center switch abnormal flow detection method, device, equipment and medium

The invention relates to the technical field of flow monitoring, in particular to a data center switch abnormal flow detection method and device, equipment and a medium, and the method comprises the following steps: collecting port flow, calculating a jump ratio, identifying an abnormal path, analyzing a multi-feature behavior, tracking the attribution of flow direction oscillation aggregation equipment, and outputting a detection result. According to the method, the port abrupt change phenomenon is identified through linkage of the jump ratio and the dynamic threshold value, the discrimination logic for the network jitter initial offset is established by combining the path continuous node response delay difference, and the path-level composite feature anomaly judgment is established by fusing the multi-dimensional index intersection behavior. Potential path oscillation is identified according to flow direction alternation in a period and traced to equipment granularity to realize chain affiliation aggregation, so that the granularity and accuracy of abnormal flow identification are enhanced, closed-loop abnormality diagnosis from transient abnormality to a path level to equipment affiliation is realized, the perception capability in a complex link disturbance and multi-point abnormality cooperation scene is improved, and the reliability of abnormal flow identification is improved. And the abnormal flow detection definition of the data center switch is improved.
Owner:HANGZHOU TONGYI TECHNOLOGY CO LTD

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

Intranet encryption malicious traffic identification method and system based on attention mechanism

The invention belongs to the technical field of intranet security, and discloses an intranet encryption malicious traffic identification method and system based on an attention mechanism, and the method comprises the steps: carrying out the encryption processing of original CAN bus data through employing an XTEA lightweight algorithm, and simulating a real intranet encryption environment; the encrypted data are converted into two-dimensional image features and sequential sequence features at the same time, efficient spatial feature extraction is performed by using an optimized CNN structure, and the sequential features are captured by combining a GRU network, a self-attention mechanism and a Transform encoder; and training is carried out through feature fusion, so that accurate recognition of different types of attacks is realized. According to the method, on the premise of not depending on hardware, high-precision identification is realized under the condition that malicious traffic encrypted by the in-vehicle network does not need to be decrypted, the requirements of the in-vehicle network on real-time performance and resource consumption are met, and meanwhile, high-precision identification capability is still kept in the face of various attacks.
Owner:XIAN UNIV OF POSTS & TELECOMM

A cryptocurrency assisted regulation method based on keyword traffic identification

The application relates to a cryptocurrency auxiliary supervision method based on keyword traffic identification, and belongs to the technical field of blockchain supervision. The application combines data information of a blockchain network and a communication function of a network node, first collects traffic data, extracts keyword features in the traffic data according to a communication protocol, matches specific fields with categories of cryptocurrencies, and obtains a preliminary judgment result of categories corresponding to the traffic. Then, simulated data packets are created according to a communication protocol of a target cryptocurrency in the preliminary judgment, a connection is established with a target node, the data packets are sent, returned data packets are received and parsed, and key information in the returned data packets is analyzed to verify the judgment result and determine the type of the target node. The node and information thereof are stored in a database in a labeled manner, and the node label is continuously monitored and regularly updated. The application realizes efficient identification of cryptocurrency traffic, and enhances the supervision efficiency of a supervision platform on cryptocurrencies.
Owner:BEIJING INST OF TECH

Encrypted traffic identification method based on big data

The invention relates to the technical field of information security, in particular to an encrypted traffic identification method based on big data, which comprises the following steps of: acquiring a network data packet, extracting flow statistical characteristics and a TLS handshake protocol field, generating an original characteristic vector after numeralization processing; determining a traffic data type based on the type identification model, further calculating a network data feature coefficient, and determining an encrypted traffic identification model based on a comparison result with a historical coefficient; inputting the original feature vector into the model to obtain an initial recognition result and a flow confidence coefficient, classifying the recognition result based on the flow confidence coefficient, and executing corresponding regulation and control operation based on the recognition result; and re-collecting the regulated data packet, extracting the network state data to calculate a regulation efficiency index, and determining whether to regulate the historical network data feature coefficient based on the regulation efficiency index and the identification efficiency index. Through a closed-loop feedback optimization mechanism, adaptive adjustment of encrypted traffic identification is realized, and the identification accuracy and the regulation and control efficiency are improved.
Owner:BEIJING YOUYUAN TECH CO LTD

P2P traffic identification method, device, equipment, medium and program product

The invention provides a P2P traffic identification method, apparatus and device, a medium and a program product. The method comprises the steps of determining a P2P traffic identification result sample corresponding to a traffic feature sample; performing feedback scoring according to the flow characteristic sample and the P2P flow identification result sample to obtain a target score value of the P2P flow identification result sample; adjusting and optimizing the P2P flow identification model based on the target score value to obtain an adjusted and optimized P2P flow identification model; and based on the flow characteristic data of the network node, performing prediction through the adjusted and optimized P2P flow identification model to obtain a P2P flow identification result of the flow characteristic data. According to the P2P flow identification method provided by the invention, through offline analysis training and online prediction of network node flow data, complex and diversified flow type conditions in a network can be better dealt with, the method has very strong generalization processing capability for identification of network node P2P flow, and the accuracy of P2P flow identification is integrally improved.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Industrial control system threat trapping method based on machine learning algorithm

This paper discloses a threat trapping method for industrial control systems based on machine learning algorithms. To address the complex types and high-dimensionality of abnormal traffic in power industrial control systems, a random forest algorithm is introduced to design a data detection module for a dynamic honeynet system, improving the accuracy of abnormal traffic identification. Furthermore, the deep reinforcement learning (DQN) algorithm is used to help the honeynet system dynamically adjust its strategy in response to different attack behaviors. Experimental results demonstrate that this method can effectively enhance the network security protection capabilities of industrial control systems.
Owner:NAVAL UNIV OF ENG PLA

Iot gateway data processing method and related apparatus

The application provides an Internet of Things gateway data processing method and related device, a traffic identification framework is acquired and a device set to be processed is determined; each decision unit in the traffic identification framework is walked through from a starting identification unit of the traffic identification framework, a traffic detection network corresponding to the walked decision unit is acquired, and a device set corresponding to the walked decision unit in the device set to be processed is determined; based on the traffic detection network corresponding to the walked decision unit and a traffic identification feature vector in the traffic detection network corresponding to the walked decision unit, the device set corresponding to the walked decision unit is identified, a device set corresponding to each sub-decision unit connected to the walked decision unit is determined, and each terminal identification unit in the traffic identification framework is obtained until each terminal identification unit in the traffic identification framework corresponds to a device set respectively. The application can improve the accuracy of device identification.
Owner:BEIHANG UNIV

Fine-grained traffic classification method based on improved residual convolutional network in SDN environment

The application relates to a fine-grained traffic classification method based on an improved residual convolutional network in an SDN environment and belongs to the software technical field. In order to provide finer-grained application-aware traffic classification, let network operators better analyze network composition and manage and schedule network resources, fine-grained classification of the specific application programs is very important. Traditional methods tend to classify traffic based on protocols, which is coarse-grained classification. Inspired by the research in computer vision, the method of the residual convolutional network is applied to the identification and classification of network traffic. The method solves the network degradation problem that occurs in the process of fine-grained network traffic identification by traditional deep learning methods with the increase of network depth, can effectively learn deeper network features, and further realizes fine-grained network traffic classification.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

APP identification method and device for TG framework, medium and product

The embodiment of the invention relates to the technical field of flow identification, and discloses an APP identification method and device for a TG framework, a medium and a product. TCP flow is collected; extracting a key and an initialization vector from a first loaded uplink packet of the TCP flow; according to the secret key and the initialization vector, an aes algorithm is adopted to decrypt the data of the first uplink packet with the load, and updakeyid is obtained; according to the secret key and the initialization vector, an aes algorithm is adopted to decrypt data of the first downlink packet with the load, and dnaeskeyid is obtained; and when the updakeyyid is the same as the dnaeskeyyid, judging that the TCP flow is an APP (Application) which adopts a TG (Triggered Generation) framework, and when the updaeskeyyid is the same as the dnaeskeyyid. The technical problem of TG framework application traffic identification can be at least solved.
Owner:WUHAN BOYIXUN INFORMATION TECH CO LTD

Centralized acceleration method and device, equipment, program product and storage medium

The invention relates to the technical field of acceleration, and provides a centralized acceleration method and device, equipment, a program product and a storage medium. The method comprises the following steps: receiving user traffic to be accelerated sent by a service router; based on the access control strategy, screening out target user traffic from the to-be-accelerated user traffic; forwarding the target user traffic to an acceleration network for acceleration; the access control strategy is generated by the acceleration management platform based on the network characteristics of the target user in the traceability system. According to the centralized acceleration method, device and equipment, the program product and the storage medium provided by the invention, traffic identification and distinguishing and centralized acceleration based on user granularity can be realized on the premise of not carrying out any transformation on the broadband access server of the existing network, the waste of the IP address of the public network is reduced, and in addition, the user experience is improved. The acceleration management platform can be directly and independently transplanted and deployed, various value-added services for identifying user traffic can be customized based on service requirements, and the implementation difficulty is greatly reduced.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Malicious traffic identification and active interception system for industrial internet

The invention relates to the technical field of network security of industrial internet, and discloses an industrial internet-oriented malicious traffic identification and active interception system, which comprises a traffic acquisition module used for acquiring data traffic associated with the industrial internet; the feature determination module is used for determining drift features at least associated with the data traffic and determining potential features corresponding to the drift features; the learning identification module is used for identifying the potential features based on an attack rule through a lightweight adversarial learning model, and determining the risk level of the data traffic; and the active interception module is used for executing active interception operation corresponding to the risk level on the data traffic. According to the scheme, the detection and interception requirements of diversified data traffic of the industrial internet can be met.
Owner:HEBEI VOCATIONAL COLLEGE OF FOREIGN LANGUAGES