Traffic Flow Identification Using Terminal-Side Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current traffic flow identification methods face challenges in accurately identifying the type of traffic flow due to limitations in deep packet inspection technology and low precision with deep/dynamic flow inspection methods.
Innovation Solution
A method and apparatus for traffic flow identification that involves collecting packet header statistics within a preset time window and using a traffic flow identification model to determine the type of traffic flow, considering terminal-side information and packet header statistics to improve identification precision.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection (DPI) technology is used to generate traffic flow identification model by analyzing application layer protocol payload content, then identification precision can be improved, but the system becomes vulnerable to encryption attacks and device complexity increases
Solution Approach 1:
The patent segments the traffic flow identification process into two independent modules: packet header inspection (data link layer/network layer/transport layer) and terminal-side information analysis (device attributes, application layer characteristics). This segmentation avoids the need for complex deep packet inspection of encrypted payload content while maintaining identification precision through multi-dimensional feature analysis.
2Device complexity
If deep/dynamic flow inspection (DFI) technology is used to generate traffic flow identification model based on packet header information, then device complexity is reduced, but identification precision deteriorates
Solution Approach 1:
The patent merges packet header inspection results with terminal-side information (device attributes, application layer characteristics, user behavior patterns) to create a comprehensive identification model. This combination compensates for the limitations of simple packet header analysis by incorporating multiple dimensions of traffic flow characteristics, thereby improving identification precision without requiring complex deep packet inspection.
3Measurement precision
If terminal-side information is fully considered in traffic flow identification, then identification rate is improved, but information processing complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-collecting and organizing terminal-side information (device attributes, application layer characteristics, user behavior patterns) into structured data before the actual identification process. This preprocessing step creates ready-to-use feature sets that can be quickly integrated with packet header information during traffic flow identification, reducing real-time processing complexity while maintaining high identification rates.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
This application provides a traffic flow identification method and apparatus, and a model generation method and apparatus. The traffic flow identification method includes: A first device obtains a to-be-identified traffic flow, collects statistics about packet header information in the to-be-identified traffic flow in a preset time window, to obtain to-be-identified packet header statistics information, and obtains to-be-identified terminal-side information based on the to-be-identified traffic flow. Further, the first device determines a type of the to-be-identified traffic flow based on the to-be-identified terminal-side information and the to-be-identified packet header statistics information by using a traffic flow identification model. Therefore, the first device can fully consider, by using the traffic flow identification model, attribute information of a device associated with the traffic flow, to improve an identification rate of the type of the traffic flow, and ensure an identification effect of the type of the traffic flow.