Dynamic Network Traffic Identification via Adaptive Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network traffic identification methods struggle to accurately classify unknown traffic data in dynamic network environments, where new applications and malicious traffic emerge frequently, leading to a decline in identification efficiency and potential security threats.
Innovation Solution
A method and device that acquire and preprocess network traffic data using a self-adaptive confidence principle and adaptive clustering, followed by similarity coefficient estimation to classify unknown traffic data, and update the known network traffic classification model with identified malicious and normal traffic data, enabling continuous learning and improved identification accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing network traffic classification models are used to identify traffic data, then identification accuracy is high for known traffic types, but identification efficiency declines when new unknown traffic types emerge
Solution Approach 1:
The patent implements a dynamic updating mechanism where the network traffic classification model is continuously trained with newly identified unknown traffic data. The system transitions from a static model to a dynamic one that adapts to new traffic types by incorporating identified unknown traffic into the training set, thereby maintaining high identification accuracy while improving adaptability to emerging traffic patterns.
Solution Approach 2:
The system establishes a feedback loop where identified unknown traffic data is fed back into the model training process. The classification model outputs predictions, unknown traffic is identified through confidence threshold evaluation, and this identified traffic is subsequently used to retrain and update the model, creating a continuous improvement cycle that enhances both accuracy and adaptability.
2Ease of manufacture
If traditional traffic identification methods are applied, then implementation is simple, but they cannot effectively identify unknown malicious traffic in dynamic network environments
Solution Approach 1:
The patent introduces an intermediary unknown traffic identification module that bridges traditional classification methods and deep learning-based unknown traffic detection. This module uses confidence threshold evaluation to identify unknown traffic, which is then used to update the classification model, combining the simplicity of traditional methods with the effectiveness of adaptive learning.
Solution Approach 2:
The system performs preliminary evaluation of traffic data using the classification model before full deep learning analysis. By first using the simpler classification model to identify potential unknown traffic through confidence thresholds, the system prepares data for more sophisticated analysis only when necessary, maintaining simplicity while improving effectiveness.
3Measurement precision
If the classification model is continuously updated with new traffic data, then identification accuracy improves, but system complexity increases
Solution Approach 1:
The system implements self-service through automated model updating. The identified unknown traffic data automatically triggers model retraining without manual intervention. The system autonomously collects, processes, and incorporates new traffic data into the model training pipeline, reducing operational complexity while maintaining continuous improvement of identification accuracy.
Solution Approach 2:
The patent manages complexity by controlling parameter changes in the model updating process. Instead of continuously retraining with all available data, the system selectively updates the model using identified unknown traffic data that meets specific confidence threshold criteria, optimizing the balance between accuracy improvement and computational complexity.
Data Source
AI summary
The disclosure relates to a method and device for identifying unknown traffic data based on a dynamic network environment. The method includes following steps. The known traffic in the network data is classified by using the known network traffic classification model, then the preliminary determination is performed according to a classification prediction result, network data preliminarily determined as the unknown traffic data is classified by using the adaptive clustering method, and then respective classes are identified by using a similarity coefficient estimation method so as to identify the classes of the malicious traffic and the normal traffic, that is, to further identify and learn the unknown traffic data, and transform it into known traffic data, and then the known network traffic classification model is trained and updated again with the new known traffic data.


