Secure shell protocol traffic detection method and device for complex bearing in tunnel

By performing feature extraction and frequency domain characterization of tunnel hybrid traffic, combined with recurrent neural network and multi-head attention mechanism, the problem of difficult SSH traffic in the hybrid traffic in the tunnel is solved, and more efficient detection and positioning capabilities are achieved.

CN120090887AActive Publication Date: 2025-06-03NANJING UNIV OF INFORMATION SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510580678.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-06-03
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and analyze secure shell protocol (SSH) traffic in mixed traffic in tunnels, especially when encryption and packaging characteristics make traditional traffic analysis methods poor.

Method used

A method is adopted to extract the length, arrival time interval and direction characteristics of the data packets by collecting the tunnel mixing traffic, and normalize and smooth the processing. Then, a burst sequence is constructed, the data packets are mapped into frequency domain signals based on frequency domain characterization, time sampling is performed, and statistical characteristics are calculated. Finally, using the encoder and decoder architecture based on recurrent neural networks, combined with the multi-head attention mechanism, we judge whether there is an SSH traffic in the mixed traffic and position its location.

Benefits of technology

It significantly improves the sensitivity and specificity of SSH traffic detection in a hybrid traffic environment, can more effectively deal with the identification challenges caused by the coexistence of complex behaviors in the tunnel, and accurately locate SSH traffic under the encryption protocol.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090887A_ABST
    Figure CN120090887A_ABST
Patent Text Reader

Abstract

The invention provides a secure shell protocol flow detection method and device for complex bearing in a tunnel, and the method comprises the steps: 1, collecting the mixed flow of the tunnel, and extracting the data packet length, arrival time interval and direction of a specified number of data packets in each flow; 2, constructing continuous data packets in the same direction into the same burst, and constructing a burst feature sequence; step 3, mapping each data packet in the burst into a frequency domain signal to obtain a mixed frequency domain signal of the burst traffic in the frequency domain representation; step 4, obtaining mixed frequency domain signal statistical characteristics; and 5, inputting the mixed frequency domain signal statistical characteristics into an encoder and decoder architecture based on a recurrent neural network to obtain a prediction label of a burst level and a prediction label of a flow level, judging whether the SSH flow exists in the mixed flow or not, and positioning the burst. According to the method, the SSH flow detection problem under the complex bearing of the tunnel is effectively solved, and the detection accuracy is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent network traffic analysis, and particularly to a method and device for detecting Secure Shell (SSH) protocol traffic with complex bearers in a tunnel. Background Art

[0002] With the continuous development of tunneling technology, it has become a widely used method for encapsulating protocol data packets in a network. Tunneling technology not only provides privacy protection and secure communication for data transmission but also plays an important role in aspects such as remote access and cross-regional network connection. By encapsulating the data of one protocol into another protocol, it can achieve protocol compatibility and bypass network restrictions. However, with the wide application of tunneling technology, it also brings some new challenges, especially in the monitoring and management of network traffic. Tunneling technologies such as Shadowsocks, Vmess, and Trojan combine encryption and encapsulation mechanisms, further enhancing the security of data transmission, but this also makes malicious activities and evasion of censorship more complex, posing great difficulties for network management.

[0003] Currently, research on encrypted tunnel traffic mainly focuses on the identification and classification of tunnel protocols, malicious traffic detection, and mixed traffic analysis. Tunnel traffic usually has encryption characteristics, which greatly reduces the effectiveness of traditional traffic identification methods based on ports and protocols. In addition, tunnel traffic often disguises itself as normal traffic (such as HTTPS or DNS), making traffic analysis and identification more difficult. Existing research mostly uses machine learning (ML) or deep learning (DL) methods, relying on the metadata of network traffic to identify and classify traffic in encrypted tunnels without decrypting the data. At the same time, with the diversification of web applications, the normalization patterns of traffic become more complex, increasing the difficulty of distinguishing malicious traffic from normal traffic.

[0004] Mixed traffic analysis assumes that multiple types of traffic are transmitted in a tunnel, and this complex scenario is more realistic. It includes the identification and classification of various network behaviors. Past research has conducted relevant analyses on mixed tunnel traffic, such as calculating the quantity and proportion of encrypted traffic in a tunnel. In this process, monitoring sensitive traffic is particularly crucial, especially when the tunnel involves multiple network behaviors. Remote management tools such as the SSH protocol are often exploited by attackers to hide malicious behaviors in mixed traffic. Once an attacker obtains remote control through SSH, they can initiate various attacks and steal data or implant malicious programs. In this regard, traffic detection methods based on a single behavior often struggle to effectively respond, and methods capable of identifying mixed tunnel traffic are needed.

[0005] Currently, research on mixed traffic within tunnels is still relatively limited. The tunnel encapsulation characteristics make it difficult to separate traffic between multiple network behaviors coexisting in the tunnel, which makes it more complicated to analyze data packets of sensitive behaviors. Traditional traffic analysis methods do not work well for encrypted and encapsulated tunnels because they mask key business identifiers and payload structures. As network behaviors become more complex, sensitive traffic and normal traffic are completely mixed together, increasing the difficulty of detection. Therefore, detailed analysis and identification technology for mixed traffic within tunnels remains an important issue that needs to be solved in the field of network security. Summary of the invention

[0006] Purpose of the invention: The technical problem to be solved by the present invention is to provide a method and device for detecting Secure Shell (SSH) traffic for complex bearers in a tunnel in view of the deficiencies in the prior art.

[0007] The method comprises the following steps: Step 1: Collect the mixed traffic in the tunnel, extract the three features of packet length, arrival time interval and direction of the specified number of packets in each flow, normalize the length of the packet, normalize the arrival time interval of the packet and smooth the feature distribution; Step 2: Constructing continuous data packets with the same direction into the same burst to obtain a burst sequence of tunnel mixed traffic. For the burst sequence, the burst is divided into a forward burst and a reverse burst according to different directions of the data. The data packets from the source address to the destination address are regarded as forward burst data packets, and the data packets from the destination address to the source address are regarded as reverse burst data packets. At the same time, a burst feature sequence is constructed according to the data packet length and arrival time interval of the forward and reverse burst data packets. Step 3: Based on the burst feature sequence obtained in step 2, a frequency-domain-based mixed traffic representation is introduced to map each data packet in the burst into a frequency-domain signal, and the frequency-domain signals of the data packets in the same burst are linearly added to obtain a mixed frequency-domain signal of the burst traffic in the frequency-domain representation. Each mixed frequency-domain signal represents a forward or reverse burst in the tunnel mixed traffic. Step 4: Perform time sampling on the mixed frequency domain signal obtained in step 3 to obtain the frequency domain discrete features of burst traffic. The four core statistical features of the discrete features are calculated. , get the mixed frequency domain signal statistical characteristics of each burst ,in represents the mean, represents the variance, represents peak value, and E represents energy; Step 5: Input the statistical features of the mixed frequency-domain signal obtained in Step 4 into an encoder-decoder architecture based on a recurrent neural network. The architecture uses a gated recurrent unit (GRU) as the basic unit of the encoder and decoder. Obtain the prediction label at the burst level based on the output of the decoder to locate the burst position where the SSH traffic is located. Further, splice the output features of each GRU in the decoder and input the spliced feature vector into a detection module based on a multi-head attention mechanism to obtain the prediction label at the flow level for determining whether there is SSH traffic in the mixed traffic.

[0008] In Step 1, the following formula is used to normalize and smooth the feature distribution of the packet time interval and the packet length : , , , where represents the normalized packet length, represents the maximum packet length, represents the normalized packet time interval, represents the packet time interval, represents the minimum time interval, represents the packet time interval after smooth distribution, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

[0009] In Step 2, the burst consists of a group of consecutive packets in the same direction. The packets come from requests or responses in the mixed flow, and the direction of the packet is determined by the destination address and the source address. Among them, the forward burst is represented as: , The reverse burst is represented as: , where represents the forward burst, represents the reverse burst, represents the -th forward burst packet from the source address to the destination address in the mixed traffic, represents the -th forward burst packet from the source address to the destination address in the mixed traffic, represents the Indicates the th reverse burst packet from the destination address to the source address in the mixed traffic, indicating the number of packets in the burst.

[0010] In step 3, the frequency-domain-based mixed traffic characterization includes the following steps: Step 3-1, map the packet length to the amplitude of the frequency-domain signal , and take the reciprocal of the packet time interval as the angular frequency of the mapped frequency-domain signal ; Step 3-2, if the burst is a forward burst , then map the packet to the frequency signal , if the burst is a reverse burst , then map the packet to the frequency signal , representing the time variable of the signal; Step 3-3, repeat steps 3-1 to 3-2 to map all packets in the burst to frequency signals , and superimpose the mapped frequency signals of all packets in the same burst to obtain the final mixed frequency-domain signal .

[0011] In step 4, the time sampling of the mixed frequency-domain signal obtained in step 3 means sampling within the maximum period range of the mixed frequency-domain signal at points, and after sampling, obtain the signal sequence , where is the number of sampling points, is the discrete signal value at the th sampling point; According to the sampled signal sequence, calculate the mean , variance , peak value , and energy of the signal as four core statistical features.

[0012] In step 5, the encoder-decoder architecture based on the recurrent neural network uses the gated recurrent unit GRU as the basic unit to capture the short-term temporal dependencies of the burst, and the encoder passes the cumulative information of the mixed flow to the decoder through the forward and backward hidden states; The state update process of the gated recurrent unit GRU is expressed as: , where, represents the updated hidden state at time step i, represents the hidden state of the previous time step, represents the current burst, and the function represents the gating strategy adopted by the gated recurrent unit (GRU).

[0013] In step 5, the prediction label at the burst level is obtained by processing the output of the decoder through the sigmoid activation function; The prediction label at the flow level is obtained through the following steps: First, the outputs of the decoder for all bursts are concatenated to obtain a feature vector (the decoder is constructed by GRU, and its input comes from the output of the encoder. The main role of the encoder is to extract the deep feature representation of the input sequence. The encoder reads each element of the input sequence step by step and can output a context information representing the entire input sequence. The role of the decoder is to gradually generate the output sequence based on the context representation generated by the encoder. At each time step, the decoder receives the output of the previous moment and the current hidden state and predicts the output value of the current step), then the feature vector is processed by a detection module based on the multi-head attention mechanism to obtain a flow feature vector, and finally the flow feature vector passes through the sigmoid activation function to obtain the flow-level prediction label.

[0014] In step 5, the encoder-decoder architecture based on the recurrent neural network can analyze tunnel traffic at the burst level and the flow level. Among them, the burst-level loss aims to improve the sensitivity of the model to detect SSH traffic at the burst level, while the flow-level loss improves the specificity of the model to detect SSH traffic at the flow level. The weighted binary cross-entropy loss at the burst level is: , where is the weighted binary cross-entropy loss at the burst level; is the prediction label at the burst level; is the ground truth label at the burst level; is the number of packets in the burst; is the ground truth label at the burst level of the i-th packet; is the prediction label at the burst level of the i-th packet; is the weight matrix of the burst loss, which increases the loss weight of the burst containing SSH traffic to solve the problem of data imbalance, and its value is set to the number of SSH packets in the burst; The binary cross-entropy loss at the flow level is: , where is the binary cross-entropy loss at the flow level; is the prediction label at the flow level; is the true label at the flow level; Adopt a multi-scale supervised training model to obtain the final combined loss based on the burst-level and flow-level losses : , where is the hyperparameter for balancing the flow loss and the burst loss. By adjusting , the model can be adjusted to make it pay more attention to the flow-level loss.

[0015] The present invention also provides a Secure Shell (SSH) protocol traffic detection device for complex bearers in tunnels implemented by the described method, including: a burst packet module for performing burst packetization on data packets; a feature extraction module for extracting the spatio-temporal features of data packets and performing preprocessing; a frequency-domain mapping module for mapping the spatio-temporal features of data packets into frequency-domain signals and characterizing burst traffic; a sampling module for sampling the frequency-domain features to obtain four statistical features of the mean, variance, peak, and energy of the signal; a detection module based on the encoder and decoder architecture of a recurrent neural network for determining whether there is SSH traffic in the tunnel hybrid traffic and locating the burst where it is located.

[0016] The present invention also provides a storage medium storing a computer program or instructions, which, when the computer program or instructions are run on a computer, execute the steps of the described method.

[0017] Compared with the prior art, the beneficial effects of the present invention are: (1) Aiming at the difficulty of behavior recognition caused by the coexistence of multiple network behaviors in hybrid tunnel traffic, the present invention proposes a novel SSH behavior detection method. This method integrates the feature information at the flow level and the burst level, and through the introduction of a multi-scale supervision strategy, realizes the joint optimization of the flow level and the burst level during the model training process, significantly improving the detection sensitivity and specificity in the hybrid traffic environment, so as to more effectively cope with the recognition challenges caused by the coexistence of complex behaviors in the tunnel.

[0018] (2) In order to effectively capture the temporal patterns and burst structures in hybrid tunnel traffic, the present invention transforms and extracts features from the perspective of the frequency domain for the original traffic, and constructs a burst-level traffic characterization method with a unified structure. This frequency-domain representation method can not only accurately reflect the periodic and burst behavior characteristics hidden in the traffic, but also has the ability to uniformly model bursts of different lengths. While reducing the feature dimension and the complexity of the traffic pattern, it retains important semantic information and physical interpretability, providing a more expressive feature basis for the refined recognition of SSH behaviors. Description of the Drawings

[0019] Figure 1It is the overall flowchart of an SSH traffic detection method for complex bearers in tunnels.

[0020] Figure 2 It is a schematic diagram of packet grouping in the tunnel.

[0021] Figure 3 It is a schematic diagram of the original and preprocessed spatio-temporal features of bursts.

[0022] Figure 4 It is the structural diagram of the tunnel SSH traffic detection model. Specific implementation mode

[0023] The following further specifically describes the present invention in conjunction with the accompanying drawings and specific implementation modes, and the above and / or other advantages of the present invention will become clearer.

[0024] Facing the complex network behaviors carried in the tunnel, detecting sensitive behaviors in the tunnel mixed traffic. The sensitive traffic and normal traffic are completely mixed together, increasing the difficulty of detection. Therefore, the embodiments of the present invention provide a secure shell protocol traffic detection method for complex bearers in tunnels. Referring to Figure 1 , it specifically includes the following steps: Step 1, the present invention first collects the tunnel mixed traffic, extracts three features of the packet length, arrival time interval, and direction of a specified number of packets in each flow, normalizes the packet length, and normalizes and smooths the feature distribution of the packet arrival time interval. The specific processing methods are as follows: by dividing each packet length by the maximum packet length to obtain the normalized packet length , normalizing the packet time interval through a conversion function to obtain the normalized packet time interval , and obtaining the smoothed packet time interval feature through smoothing the distribution of . The specific formulas for the normalization and feature distribution smoothing operations are as follows: , , , where represents the normalized packet length, represents the packet length, represents the maximum packet length, represents the normalized packet time interval, represents the packet time interval, represents the minimum time interval. Denote the packet time interval after smooth distribution, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

[0025] Step 2, referring to Figure 2 , divide the packet direction according to the source address and destination address of the packet. If the source address and destination address of the packet are from the client to the server, it is divided into the forward direction; if the source address and destination address of the packet are from the server to the client, it is divided into the reverse direction. Secondly, according to the continuity of the packets, the packets with the same direction and continuity in the tunnel flow are divided into the same burst.

[0026] Referring to Figure 3 , after all the packets are divided into bursts, obtain the burst feature sequence according to the packet length and arrival time interval of the packets in each burst.

[0027] Step 3, based on the frequency-domain hybrid traffic characterization method, map each packet in the burst to a frequency-domain signal according to the burst feature sequence, and linearly add the signals mapped by the packets in the same burst in the frequency-domain space to obtain the hybrid frequency-domain signal in the frequency-domain characterization of the burst traffic. The specific implementation steps are as follows: Step 3-1, map the preprocessed packet length to the amplitude A of the signal, and use the reciprocal of the preprocessed packet time interval as the angular frequency of the mapped signal ; Step 3-2, map the packet to a frequency-domain signal according to the packet direction. If the burst is a forward burst , then map the packet to , if the burst is a reverse burst , then map the packet to ; Step 3-3, repeat the above steps 3-1 and 3-2 to map all the packets in the burst to , and superimpose the mapped signals of all the packets in the same burst to obtain the hybrid frequency-domain signal .

[0028] Step 4, in order to analyze the burst signal, it is necessary to sample it first. The sampling process is carried out within the maximum period range of the signal. The selection of the number of sampling points N comprehensively considers the periodicity of the signal and the calculation requirements of the data. The purpose of sampling is to discretize the continuous frequency-domain signal into a finite number of sample points for subsequent calculation. Specifically, within the range of [0, 2 , perform N-point sampling on the burst hybrid frequency-domain signal , and the sampled signal sequence is , further calculate based on the sampled signal sequence the mean value of the signal , variance , peak value , energy These four statistical features, and further obtain the statistical features of the mixed frequency-domain signal of each burst .

[0029] Step 5, input the statistical features of the mixed frequency-domain signal into the encoder-decoder architecture based on the recurrent neural network. Obtain the prediction labels at the burst level according to the output of the decoder. Concatenate the output of the decoder and send it into the detection module based on the attention mechanism to obtain the prediction labels at the flow level. Calculate the binary cross-entropy loss based on the two-level prediction labels, and locate the burst where the SSH traffic is located and judge whether there is SSH traffic in the tunnel mixed traffic according to the binary cross-entropy loss; In this method, both the encoder and the decoder consist of four hidden layers, and the size of each hidden layer is set to 128. The encoder is responsible for receiving the frequency-domain statistical features of the burst traffic and converting them into a context vector (hidden state), which contains the key information about the input traffic. The decoder receives the hidden state of the encoder, and the decoder uses the forward and backward hidden states to transfer the cumulative information of the mixed flow to the output layer of the model.

[0030] Refer to Figure 4 , after the statistical features of the mixed frequency-domain signal are fed into the encoder-decoder, the output of the decoder for each burst is obtained. The output of the decoder is processed by the activation function to obtain the prediction labels at the burst level, which are used to locate the burst position where the SSH traffic is located; at the same time, the output of the decoder is concatenated to obtain the feature vector, and then the feature vector is processed by the attention module to obtain the flow feature vector. Finally, the flow feature vector passes through the activation function to obtain the prediction labels at the flow level, which are used to judge whether there is SSH traffic in the mixed traffic.

[0031] Analyze the tunnel traffic at the burst level and the flow level according to the prediction labels respectively. The burst-level loss aims to improve the sensitivity of the model to detect SSH traffic at the burst level, while the flow-level loss improves the specificity of the model to detect SSH traffic at the flow level. The specific formulas are as follows: The weighted binary cross-entropy loss at the burst level: , where is the weighted binary cross-entropy loss at the burst level; is the prediction label at the burst level; is the true label at the burst level; k is the number of data packets in the burst; It is the weight matrix for SSH burst loss, which increases the loss weight of the burst containing SSH traffic to address the problem of data imbalance, and its value is set to the number of SSH packets in the burst; Flow-level binary cross-entropy loss: , where is the flow-level binary cross-entropy loss; is the flow-level predicted label; is the flow-level true label.

[0032] Adopt a multi-scale supervised training model to obtain the final combined loss based on the burst-level and flow-level losses , and the specific calculation formula is as follows: , where is the hyperparameter that balances the flow loss and the burst loss. By adjusting , the model can be adjusted to make it pay more attention to the flow-level loss.

[0033] A specific embodiment of the method of the present invention in the context of a tunnel mixed traffic environment is as follows: Figure 2 The medium tunnel mixed flow contains packets. Packets and packet are continuous in time and both in the forward direction and are divided into a forward burst . Packet is divided into a negative burst because there are no packets with the same direction and continuous . Packet , , are divided into a forward burst , and so on until the nth packet. Finally, the mixed traffic is divided into a sequence of alternating forward and negative bursts. The traditional method fails to fully pay attention to the specific network behavior patterns contained in the traffic, while the burst division strategy of the present invention significantly enhances the ability to capture the behavioral characteristics of the encryption protocol by simulating the SSH protocol request-response interaction mode (such as the forward burst is the client request and the reverse burst is the server response).

[0034] Further extract the spatio-temporal features of the N bursts and perform the normalization and optimized distribution methods described in step 2 on the spatio-temporal features of the bursts, and obtain as Figure 3The normalized length and optimized interval shown. The prior art directly uses the original distribution of packet time intervals (vulnerable to network jitter), while the present invention optimizes the packet time interval distribution through non-linear transformation (such as the combination of tanh and sigmoid functions), highlighting the subtle features of packets, and improving the feature stability under the same network delay fluctuation, effectively suppressing the influence of noise.

[0035] Execute the frequency characterization method in step 3 according to the normalized length and smoothed packet time intervals. Burst 1 is characterized as , and burst 2 is characterized as , and burst 3 is characterized as . By mapping the spatio-temporal features of packets into frequency domain signals (forward bursts are modeled based on sine signals, and reverse bursts are modeled based on cosine signals), the present invention breaks through the limitations of traditional methods that rely on plaintext content or simple statistics. In the case where SSH traffic is encrypted or nested tunnels, network behavior interaction features can still be extracted through waveform superposition (such as the mixing of multi-frequency signals in burst 3). Then, in the range of [0, 2 , sample the burst frequency domain signal at 500 points to obtain the sampling sequence of each burst, and at the same time obtain the burst statistical features according to the formula described in step 4. Traditional deep learning models need to process high-dimensional raw data (such as packet sequences), while the present invention reduces the dimension through frequency domain sampling, reducing the computational complexity compared with traditional methods and significantly improving the inference speed in devices. Further, according to the steps described in step 5, send the burst statistical features into the encoder and decoder to obtain the decoder output of each burst, obtain burst-level and flow-level prediction labels through two processing methods, and still obtain the final combined loss according to the calculation formula in step 5. The prior art only supports flow-level detection and cannot locate the specific location of SSH traffic, while the GRU-attention architecture of the present invention can not only mark bursts but also comprehensively judge the flow-level risk, meeting the requirements of precise control and efficient detection at the same time.

[0036] The present invention provides a method and device for detecting Secure Shell protocol traffic facing complex bearers in tunnels. There are many methods and ways to specifically implement this technical solution. The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Each component not clearly defined in this embodiment can be implemented by the prior art.

Claims

1. A secure shell protocol traffic detection method for complex bearers in tunnels, characterized in that: The following steps are involved: Step 1: Collect the mixed traffic in the tunnel, extract the three features of packet length, arrival time interval and direction of the specified number of packets in each flow, normalize the length of the packet, normalize the arrival time interval of the packet and smooth the feature distribution; Step 2: Constructing continuous data packets with the same direction into the same burst to obtain a burst sequence of tunnel mixed traffic. For the burst sequence, the burst is divided into a forward burst and a reverse burst according to different directions of the data. The data packets from the source address to the destination address are regarded as forward burst data packets, and the data packets from the destination address to the source address are regarded as reverse burst data packets. At the same time, a burst feature sequence is constructed according to the data packet length and arrival time interval of the forward and reverse burst data packets. Step 3: Based on the burst feature sequence obtained in step 2, a frequency-domain-based mixed traffic representation is introduced to map each data packet in the burst into a frequency-domain signal, and the frequency-domain signals of the data packets in the same burst are linearly added to obtain a mixed frequency-domain signal of the burst traffic in the frequency-domain representation. Each mixed frequency-domain signal represents a forward or reverse burst in the tunnel mixed traffic. Step 4: Perform time sampling on the mixed frequency domain signal obtained in step 3 to obtain the frequency domain discrete features of burst traffic. The four core statistical features of the discrete features are calculated. , get the mixed frequency domain signal statistical characteristics of each burst ,in represents the mean, represents the variance, represents the peak value, Indicates energy; Step 5, inputting the mixed frequency domain signal statistical features obtained in step 4 into the encoder and decoder architecture based on the recurrent neural network, wherein the architecture uses the gated recurrent unit GRU as the basic unit of the encoder and decoder; obtaining a burst-level prediction label according to the output of the decoder, which is used to locate the burst position of the SSH traffic; further splicing the output features of each gated recurrent unit GRU in the decoder, and inputting the spliced ​​feature vector into the detection module based on the multi-head attention mechanism to obtain a flow-level prediction label, which is used to determine whether there is SSH traffic in the mixed traffic.

2. The method according to claim 1, characterized in that In step 1, the following formula is used to calculate the packet time interval and packet length Normalize and smooth feature distribution: , , , in Indicates the normalized packet length, Indicates the maximum packet length, represents the normalized packet time interval, Indicates the packet time interval, Indicates the minimum time interval, Indicates the time interval between packets after smooth distribution, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

3. The method according to claim 2, characterized in that In step 2, the burst consists of a group of continuous data packets in the same direction, the data packets come from requests or responses in the mixed flow, and the direction of the data packets is determined by the destination address and the source address, wherein the forward burst is represented as: , The reverse burst is expressed as: , in Indicates a positive burst, Indicates reverse burst, Indicates the mixed traffic from the source address to the destination address. Forward burst packets, Indicates the mixed traffic from the source address to the destination address. Forward burst packets, Indicates the mth reverse burst packet from the destination address to the source address in the mixed traffic. Indicates the mixed traffic from the destination address to the source address. Reverse burst packets, Indicates the number of packets in the burst.

4. The method according to claim 3, characterized in that In step 3, the frequency domain-based mixed traffic characterization includes the following steps: Step 3-1, set the packet length Mapped to the amplitude of the frequency domain signal , the inverse of the packet time interval As the angular frequency of the mapped frequency domain signal ; Step 3-2, if the burst is a forward burst , then the data packet is mapped into a frequency signal , if the burst is a reverse burst , then the data packet is mapped into a frequency signal , A time variable representing a signal; Step 3-3, repeat steps 3-1 to 3-2 to map all packets in the burst into frequency signals , the frequency signal of all packets in the same burst is mapped Superposition is performed to obtain the final mixed frequency domain signal .

5. The method according to claim 4, characterized in that In step 4, the time sampling of the mixed frequency domain signal obtained in step 3 refers to the time sampling of the mixed frequency domain signal. Within the maximum cycle range of conduct Point sampling, after sampling, the signal sequence is obtained ],in is the number of sampling points, For the Discrete signal value at sampling points; According to the sampled signal sequence, calculate the signal The mean ,variance , Peak ,energy Four core statistical features.

6. The method according to claim 5, characterized in that In step 5, the encoder and decoder architecture based on the recurrent neural network uses the gated recurrent unit GRU as the basic unit to capture the bursty short-term temporal dependencies, and the encoder passes the accumulated information of the mixed stream to the decoder through the forward and backward hidden states; The state update process of the gated recurrent unit GRU is expressed as: , in, represents the updated hidden state at time step i, represents the hidden state at the previous time step, Indicates the current burst, function Represents the gating strategy adopted by the gated recurrent unit GRU.

7. The method according to claim 6, characterized in that In step 5, the prediction label of the burst level is obtained by processing the decoder output through the sigmoid activation function; The flow-level prediction label is obtained by the following steps: first, all burst decoder outputs are spliced ​​to obtain a feature vector, then the feature vector is processed by a detection module based on a multi-head attention mechanism to obtain a flow feature vector, and finally the flow feature vector is passed through a sigmoid activation function to obtain a flow-level prediction label.

8. The method according to claim 7, characterized in that In step 5, the encoder and decoder architecture based on the recurrent neural network can analyze the tunnel traffic at the burst level and the flow level, and the weighted binary cross entropy loss at the burst level is: , in is the weighted binary cross entropy loss at the burst level; is the prediction label at the burst level; is the true label at the burst level; is the number of packets in the burst; is the true label of the burst level of the i-th packet; is the predicted label of the burst level of the i-th packet; is the weight matrix of burst loss; The binary cross entropy loss at the flow level is: , in is the binary cross entropy loss at the flow level; is the predicted label at the flow level; is the true label at the flow level; A multi-scale supervised training model is used to obtain the final combined loss based on the burst level and flow level losses. : , in is a hyperparameter that balances flow loss and burst loss.

9. A secure shell protocol flow detection device for complex bearers in a tunnel implemented by the method according to any one of claims 1 to 8, characterized in that: include: A burst grouping module is used to group data packets into bursts; a feature extraction module is used to extract the spatiotemporal features of data packets and perform preprocessing; The frequency domain mapping module is used to map the spatiotemporal characteristics of the data packet into frequency domain signals and characterize the burst traffic; the sampling module is used to sample the frequency domain characteristics to obtain the four statistical characteristics of the signal: mean, variance, peak value and energy; The detection module, based on the encoder and decoder architecture of recurrent neural networks, is used to determine whether there is SSH traffic in the tunnel mixed traffic and locate the burst.

10. A storage medium, characterized in that: A computer program or instruction is stored, and when the computer program or instruction is run on a computer, the steps of the method according to any one of claims 1 to 8 are executed.

Citation Information

Patent Citations

  • Calculation method of automatic processing tool based on abnormal link identification

    CN119324880A

  • Malicious activity detection by cross-trace analysis and deep learning

    US20200076842A1