Dynamic Network Traffic Identification via Adaptive Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network traffic identification methods struggle to accurately classify unknown traffic data in dynamic network environments, where new applications and malicious traffic emerge frequently, leading to a decline in identification efficiency and potential security threats.

Innovation Solution

A method and device that acquire and preprocess network traffic data using a self-adaptive confidence principle and adaptive clustering, followed by similarity coefficient estimation to classify unknown traffic data, and update the known network traffic classification model with identified malicious and normal traffic data, enabling continuous learning and improved identification accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing network traffic classification models are used to identify traffic data, then identification accuracy is high for known traffic types, but identification efficiency declines when new unknown traffic types emerge

Engineering Contradiction:
Improveidentification accuracyVSAvoidadaptability to new traffic types
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic updating mechanism where the network traffic classification model is continuously trained with newly identified unknown traffic data. The system transitions from a static model to a dynamic one that adapts to new traffic types by incorporating identified unknown traffic into the training set, thereby maintaining high identification accuracy while improving adaptability to emerging traffic patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where identified unknown traffic data is fed back into the model training process. The classification model outputs predictions, unknown traffic is identified through confidence threshold evaluation, and this identified traffic is subsequently used to retrain and update the model, creating a continuous improvement cycle that enhances both accuracy and adaptability.

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If traditional traffic identification methods are applied, then implementation is simple, but they cannot effectively identify unknown malicious traffic in dynamic network environments

Engineering Contradiction:
Improveimplementation simplicityVSAvoideffectiveness in identifying unknown malicious traffic
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary unknown traffic identification module that bridges traditional classification methods and deep learning-based unknown traffic detection. This module uses confidence threshold evaluation to identify unknown traffic, which is then used to update the classification model, combining the simplicity of traditional methods with the effectiveness of adaptive learning.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary evaluation of traffic data using the classification model before full deep learning analysis. By first using the simpler classification model to identify potential unknown traffic through confidence thresholds, the system prepares data for more sophisticated analysis only when necessary, maintaining simplicity while improving effectiveness.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the classification model is continuously updated with new traffic data, then identification accuracy improves, but system complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidmodel updating complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system implements self-service through automated model updating. The identified unknown traffic data automatically triggers model retraining without manual intervention. The system autonomously collects, processes, and incorporates new traffic data into the model training pipeline, reducing operational complexity while maintaining continuous improvement of identification accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent manages complexity by controlling parameter changes in the model updating process. Instead of continuously retraining with all available data, the system selectively updates the model using identified unknown traffic data that meets specific confidence threshold criteria, optimizing the balance between accuracy improvement and computational complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11658989B1Method and device for identifying unknown traffic data based dynamic network environment
Publication Date: 2023.05.23 NAT UNIV OF DEFENSE TECH
  • US11658989B1 patent drawing
  • US11658989B1 patent drawing
  • US11658989B1 patent drawing

AI summary

The disclosure relates to a method and device for identifying unknown traffic data based on a dynamic network environment. The method includes following steps. The known traffic in the network data is classified by using the known network traffic classification model, then the preliminary determination is performed according to a classification prediction result, network data preliminarily determined as the unknown traffic data is classified by using the adaptive clustering method, and then respective classes are identified by using a similarity coefficient estimation method so as to identify the classes of the malicious traffic and the normal traffic, that is, to further identify and learn the unknown traffic data, and transform it into known traffic data, and then the known network traffic classification model is trained and updated again with the new known traffic data.