Network flow restoring and monitoring method
By dynamically embedding steganographic tags in the network and transport layer headers of encrypted traffic, the problem of dynamic embedding and extraction of monitoring metadata in encrypted traffic is solved, enabling accurate reassembly of encrypted session streams and cross-protocol threat detection, thus improving the detection effect of advanced persistent threats.
Patent Information
- Application Number
- CN202511318783.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-09-16
AI Technical Summary
Existing encrypted traffic monitoring technologies make it difficult to attach traceable monitoring metadata to encrypted traffic while maintaining the integrity of encrypted communications. This makes it difficult to reassemble encrypted session flows and has insufficient cross-protocol behavior tracking capabilities, impacting the detection of advanced persistent threats (APTs).
Steganographic tags are dynamically embedded in non-critical fields reserved in the headers of network and transport layers to generate encrypted traffic data packets carrying steganographic metadata. Data fragmentation, classification, aggregation and reorganization are achieved through flow association identifiers and protocol type encoding. Application layer payload content is extracted by stripping the transport layer header, and the set of behavioral element triples is mapped to a cross-protocol threat knowledge graph for adjacency matching.
It enables the appending of monitoring metadata to encrypted traffic without compromising the integrity of encrypted communication, supports accurate reassembly of encrypted session streams and application layer protocol parsing, provides a data foundation for cross-protocol threat detection, and improves the detection capability of advanced persistent threats.
Smart Images

Figure CN120825342A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network monitoring, and in particular to a network traffic restoration and monitoring method. Background Art
[0002] With the widespread adoption of network encryption, protocols like TLS / SSL have become the mainstream means of ensuring data transmission security. Encrypted traffic monitoring technology has also evolved accordingly, from early deep packet inspection (DPI) to more recent machine learning-assisted analysis, aiming to achieve traffic visualization and threat awareness without decryption. Current research focuses on single-dimensional analysis, such as traffic classification and anomaly detection. However, cross-protocol correlation analysis is gradually becoming a key research direction in this field.
[0003] However, existing encrypted traffic monitoring technologies have shortcomings. They struggle to attach traceable monitoring metadata to encrypted traffic while maintaining the integrity of encrypted communications. Traditional methods are unable to dynamically embed and extract flow association identifiers within network and transport layer headers, making it difficult to reassemble encrypted session flows and inadequate cross-protocol behavior tracking capabilities, thus hindering the detection of advanced persistent threats (APTs). Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network traffic restoration and monitoring method to solve the problems of dynamic embedding and extraction of monitoring metadata in encrypted traffic, as well as cross-protocol behavior correlation analysis.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: The present invention provides a network traffic restoration and monitoring method, which includes capturing original encrypted traffic data packets, dynamically embedding steganographic markers in non-critical fields reserved in network layer and transport layer message headers to generate encrypted traffic data packets carrying steganographic metadata; Receive encrypted traffic data packets carrying steganographic metadata, extract the steganographic mark, and classify and aggregate the data fragments according to the flow association identifier to reconstruct the complete session flow; Strip the transport layer header of the complete session stream according to the protocol type code, extract the application layer payload content, and output classified structured data entities; Mapping classified structured data entities into a unified behavioral element triple set; The behavioral element triples are injected into the constructed cross-protocol threat knowledge graph for adjacency matching. When the overlap between the unknown protocol behavior path and the graph threat link exceeds the preset security threshold, a high-risk threat matching result is output. Based on the high-risk threat matching results, real-time blocking is triggered and auditable alarm records are generated, the cross-protocol threat knowledge graph is updated, and the encrypted traffic restoration and intelligent monitoring closed loop are completed.
[0007] As a preferred solution of the network traffic restoration and monitoring method of the present invention, the steganographic mark includes a flow association identifier and a protocol type code.
[0008] As a preferred solution of the network traffic restoration and monitoring method of the present invention, the specific steps of generating an encrypted traffic data packet carrying steganographic metadata are as follows: Capture the original encrypted traffic data packets, parse the original encrypted traffic data packets, extract the network layer and transport layer header field values, synchronously obtain the current original encrypted traffic data packet arrival timestamp and transport layer sequence number, and collect the current network status parameters in real time; Generate steganographic metadata based on the network layer and transport layer header field values, combined with the stream association identifier and protocol type encoding; Calculate the steganalytic embedding utility value according to the current network state parameters, and decide the embedding strategy under the current network state according to the steganalytic embedding utility value; According to the embedding strategy and steganalytic metadata, a dynamic steganalytic encoding sequence is generated by combining the arrival timestamp of the current original encrypted traffic data packet and the transport layer sequence number; According to the embedding strategy, multiple reserved non-critical fields in the network layer and transport layer message headers are selected, and the dynamic steganographic encoding sequence is embedded bit by bit into the selected fields to generate encrypted traffic data packets carrying steganographic metadata.
[0009] As a preferred solution of the network traffic restoration and monitoring method of the present invention, the original encrypted traffic data packet includes data fragments transmitted by network layer fragments.
[0010] As a preferred solution of the network traffic restoration and monitoring method of the present invention, wherein: the reorganization into a complete session flow, the specific steps are as follows: The receiving end captures the encrypted traffic data packets carrying the steganographic metadata and accurately extracts the dynamic steganographic coding sequence from the specified field in the encrypted traffic data packet header; Perform inverse transformation and verification on the dynamic steganographic coding sequence to obtain the stream association identifier and protocol type code; Classify all data packet fragments into corresponding flow session buckets according to flow association identifiers, sort and reassemble them to generate a reassembled complete session flow; The reassembled complete session flow is verified, and the complete session flow is output after the verification passes.
[0011] As a preferred solution of the network traffic restoration and monitoring method of the present invention, wherein: the output classification structured data entity, the specific steps are as follows: Dynamically select the corresponding application layer protocol parser based on the protocol type code, strip the transport layer header of the complete session stream, obtain the encrypted protocol payload data, decrypt it, and generate the application layer payload content; Perform semantic analysis on the application layer payload content to identify and extract the protocol commands, header fields, and payload content semantics; The protocol commands, header fields and payload content semantics are converted into a key-value pair structure in a unified format to generate classified structured data entities.
[0012] As a preferred solution of the network traffic restoration and monitoring method of the present invention, wherein: the mapping is a unified behavior element triple set, the specific steps are as follows: Extract semantic elements from classified structured data entities and use information entropy to calculate the importance weight of each element in the semantic elements; Using the semantic elements and the importance weights of each element in the semantic elements, a plurality of preliminary behavioral element triplets are generated, and a confidence score of each preliminary element-behavior triplet is calculated; Screening multiple preliminary behavior factor triplets according to the confidence score of each preliminary behavior factor triplet, retaining preliminary behavior factor triplets with confidence scores exceeding a preset confidence threshold, and generating a behavior factor triplet set; The behavior element triple set is converted into a unified RDF format to generate a unified behavior element triple set.
[0013] As a preferred solution of the network traffic restoration and monitoring method described in the present invention, the constructed cross-protocol threat knowledge graph is generated through training of historical threat behavior data and contains a triple relationship chain of known attack patterns.
[0014] As a preferred solution of the network traffic restoration and monitoring method of the present invention, the output of high-risk threat matching results is carried out in the following specific steps: Taking each behavior triple in the unified behavior element triple set as query input, executing parallel query in the cross-protocol threat knowledge graph and activating relevant graph nodes; Perform a bidirectional traversal from all activated related graph nodes to extract all threat paths whose length does not exceed the preset length threshold; The behavior element triplets are used to construct the unknown protocol behavior path in chronological order, and the overlap between the unknown protocol behavior path and each threat path is calculated; When the overlap exceeds the preset safety threshold, it is determined to be a high-risk threat match and a high-risk threat match result including the overlap and evidence chain is generated.
[0015] As a preferred solution of the network traffic restoration and monitoring method of the present invention, the following specific steps are performed to complete the encrypted traffic restoration and intelligent monitoring closed loop: Dynamically assess the real-time threat response level based on the evidence chain and overlap in high-risk threat matching results; According to the threat response level, select and execute the corresponding level of network blocking strategy, perform digital signature, and generate auditable alarm records; Feedback auditable alarm records to the cross-protocol threat knowledge graph, update the edge weights in the cross-protocol threat knowledge graph, and complete the encrypted traffic restoration and intelligent monitoring closed loop.
[0016] The beneficial effects of this invention are: by dynamically embedding steganographic tags in network and transport layer message headers, encrypted traffic carries steganographic metadata during transmission, achieving covert marking of encrypted traffic. While ensuring that the original encrypted communication is not interfered with, this method provides accurate flow classification for traffic restoration, supports accurate reconstruction of encrypted session flows and application layer protocol parsing, and lays a data foundation for cross-protocol threat detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 Flowchart of the network traffic restoration and monitoring method.
[0019] Figure 2 Flowchart for generating encrypted traffic packets carrying steganographic metadata.
[0020] Figure 3 Flowchart generated for high-threat threat matching results.
[0021] Figure 4 This is a flow chart of the intelligent monitoring closed loop. DETAILED DESCRIPTION
[0022] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0023] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0024] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.
[0025] Reference Figures 1 to 4 , is an embodiment of the present invention, which provides a network traffic restoration and monitoring method, comprising the following steps: S1. Capture the original encrypted traffic data packets and dynamically embed the steganographic tags in the non-critical fields reserved in the network layer and transport layer message headers to generate encrypted traffic data packets carrying steganographic metadata.
[0026] S1.1: The steganographic tag contains the stream association identifier and the protocol type encoding.
[0027] Specifically, the flow association identifier is a string generated by using the SHA-256 hash algorithm on the five-tuple information of the original encrypted traffic data packet; The protocol type encoding is to map the application layer protocol name into binary code through a predefined protocol code table; It should be noted that the five-tuple information includes the source IP address, destination IP address, source port number, destination port number and transport layer protocol type; A predefined protocol code table is a pre-created and stored mapping table that establishes a correspondence between common application layer protocol names (such as HTTP, HTTPS, FTP, SSH, DNS, etc.) and unique fixed-length binary codes.
[0028] S1.2: Capture and parse the original encrypted traffic data packets, extract the network layer and transport layer header field values, synchronously obtain the arrival timestamp and transport layer sequence number of the current original encrypted traffic data packet, and collect the current network status parameters in real time; Specifically, the original encrypted traffic data packet is captured from the physical network card, the original encrypted traffic data packet is parsed, and the IP identification field value and the survival time field value of the network layer header, as well as the sequence number field value and the urgent pointer field value of the transport layer header are extracted; The arrival timestamp of the original encrypted traffic data packet is collected through a high-precision hardware clock, the sequence number field value is extracted from the transport layer header, and the current network average delay, network throughput fluctuation and network background traffic anomaly index are collected in real time as current network status parameters.
[0029] S1.3: Generate steganographic metadata based on the network layer and transport layer header field values, combined with the stream association identifier and protocol type encoding; Specifically, according to the network layer header field value and the transport layer header field value, the stream association identifier and the protocol type code are bit-wise spliced to form an initial sequence. The CRC-16-CCITT standard is used to calculate the check code of the initial sequence, and the check code is appended to the end of the initial sequence to generate steganographic metadata.
[0030] S1.4: Calculate the steganalytic embedding utility value based on the current network state parameters, and decide the embedding strategy under the current network state based on the steganalytic embedding utility value; Specifically, when the steganalysis embedding utility value exceeds a preset high-density threshold, a high-density embedding strategy is adopted, which selects all available reserved non-critical fields in the network layer and transport layer message headers for embedding; When the steganalysis embedding utility value does not exceed the preset high-density threshold and exceeds the preset medium-density threshold, the medium-density embedding strategy is adopted, which selects 50% of the available field capacity for embedding; When the steganographic embedding utility value does not exceed the preset medium-density threshold, a low-density embedding strategy is adopted, which selects 20% of the available field capacity for embedding.
[0031] It should be noted that the preset high-density threshold is a critical value set based on the optimal network performance test results, and the example value is 0.8; the preset medium-density threshold is a demarcation value set based on the stability experiment under light network load, and the example value is 0.5; When the medium-density embedding strategy selects 50% capacity, it can still ensure that about half of the available fields are used to transmit metadata, while avoiding excessive occupation of fields that affect message parsing; when the low-density embedding strategy selects 20% capacity, it only occupies a minimum amount of field space, ensuring that the transmission burden will not be significantly increased even in network congestion or high-latency environments.
[0032] The steganalysis embedding utility value is calculated based on the current network state parameters. The expression is: ; Where, represents the steganalytic embedding utility value, represents the delay impact weight coefficient, represents the exponential decay term, Indicates the current measured value of the average network delay. Indicates the network baseline delay value, represents the throughput fluctuation weight coefficient, Indicates the actual value of the current network throughput fluctuation. Indicates the maximum fluctuation of network throughput. represents the normalized ratio of throughput fluctuation, represents the abnormal index weight coefficient, Indicates the actual measured value of the current network background traffic anomaly index. Indicates the minimum value of the network background traffic anomaly index in historical statistics. Indicates the maximum value of the network background traffic anomaly index in historical statistics.
[0033] It should be noted that 、 and is dimensionless, and The dimension is milliseconds and is processed by the Sigmoid function is dimensionless, The ratio eliminates the dimension and becomes dimensionless. The ratio eliminates the dimension and becomes dimensionless, and the final output is It is dimensionless and maintains dimensional unity; The latency impact weight coefficient is derived from the priority setting for network transmission stability requirements, with an example value of 0.5. The throughput fluctuation weight coefficient is allocated based on the degree of impact of changes in network throughput on steganographic operations and can be obtained through machine learning parameter tuning. An example value is 0.3. The anomaly index weight coefficient is set based on the risk assessment results of embedding operations based on network abnormalities, with an example value of 0.2.
[0034] S1.5: Generate a dynamic steganocoding sequence based on the embedding strategy and stegano metadata, combining the arrival timestamp of the current original encrypted traffic data packet and the transport layer sequence number; Specifically, according to the embedding capacity determined by the embedding strategy, a data segment of corresponding length is intercepted from the steganalytic metadata; Obtain the binary value of the arrival timestamp of the current original encrypted traffic data packet, obtain the binary value of the transport layer sequence number, perform a bitwise exclusive OR operation on the binary value of the arrival timestamp and the binary value of the transport layer sequence number to generate a dynamic perturbation factor; A data segment of corresponding length intercepted from the steganalytic metadata is subjected to a bitwise XOR operation with the dynamic perturbation factor to generate a dynamic steganalytic coding sequence.
[0035] S1.6: Select multiple reserved non-critical fields in the network layer and transport layer message headers based on the embedding strategy, and embed the dynamic steganographic encoding sequence bit by bit into the selected fields to generate an encrypted traffic data packet carrying the steganographic metadata.
[0036] Specifically, based on the field capacity requirements determined by the embedding strategy, select the lower bits of the IP identification field and the available padding space in the IP option field from the network layer message header, and select the last bit of the TCP sequence number, the TCP reserved bit field, and the lower bits of the TCP urgent pointer from the transport layer message header; According to the preset field priority order, the bits of the dynamic steganographic encoding sequence are sequentially filled into the reserved bits of the selected reserved non-critical fields. After the embedding operation is completed, the network layer header checksum and the transport layer header checksum are calculated to generate an encrypted traffic data packet carrying the steganographic metadata.
[0037] It should be noted that the preset field priority order is set based on experimental analysis of the stability of each field in the network protocol specification and the impact of modification on communication.
[0038] Compared to conventional deep packet inspection (DPI), this approach dynamically embeds steganographic markers in network and transport layer message headers, allowing for the addition of monitoring metadata to encrypted traffic without compromising the integrity of encrypted communications. Conventional DPI requires decrypting traffic or relies on plaintext protocol features, which poses privacy risks and cannot handle fully encrypted traffic. Embedding steganographic markers in reserved fields in message headers eliminates the need for decryption and enables accurate reconstruction of encrypted sessions through stream association identifiers. This addresses the bottlenecks of stream association and protocol identification in encrypted traffic, providing underlying data support for cross-protocol threat detection.
[0039] S2. Receive encrypted traffic data packets carrying steganographic metadata, extract steganographic tags, and classify and aggregate data fragments according to stream association identifiers to reorganize them into complete session streams.
[0040] S2.1: The original encrypted traffic data packet contains data fragments transmitted by network layer fragments.
[0041] It should be noted that in the network layer fragmentation transmission scenario, a single original encrypted traffic data packet is split into multiple IP fragments, and each IP fragment header independently carries a dynamic steganographic encoding sequence.
[0042] S2.2: The receiving end captures the encrypted traffic data packets carrying the steganographic metadata and accurately extracts the dynamic steganographic coding sequence from the specified field in the encrypted traffic data packet header; Specifically, according to the preset field priority order, the specified low bit of the IP identification field in the network layer message header, the filling space of the IP option field, the specified last bit of the TCP sequence number in the transport layer message header, the TCP reserved bit and the specified low bit of the TCP urgent pointer are read in sequence, and the read bits are spliced in the embedding order to restore the complete dynamic steganographic encoding sequence.
[0043] S2.3: Perform inverse transformation and verification on the dynamic stego-encoded sequence to obtain the stream association identifier and protocol type code; Specifically, the last binary segment of the arrival timestamp of the current data packet is obtained and the last binary segment of the transport layer sequence number is subjected to a bitwise exclusive OR operation to generate a dynamic perturbation factor; Perform a cyclic bitwise XOR operation on the dynamic stego-encoded sequence and the dynamic perturbation factor to restore the full-length stego-metadata. Separate the checksum and valid data from the restored stego metadata, and calculate the checksum of the valid data using the same CRC checksum standard used during generation. If the calculated result is completely consistent with the separated checksum, the checksum is considered passed. The valid data that passes the verification is separated from the first binary data as the stream association identifier, and the remaining part is used as the protocol type code.
[0044] S2.4: Classify all data packet fragments into corresponding flow session buckets based on the flow association identifier, sort and reassemble them to generate a reassembled complete session flow; Specifically, the stream association identifier extracted from the dynamic steganocoding sequence is used as the classification primary key to create a corresponding stream session bucket data structure in memory; The data packet fragments with the same flow association identifier are stored in the same flow session bucket. The network layer fragment data in the flow session bucket are sorted in ascending order according to the IP fragment offset field value; For transport layer fragmented data, sort in ascending order according to the TCP sequence number field value; The sorted data shard payload contents are spliced in sequence to generate a reorganized complete session stream.
[0045] S2.5: Verify the reassembled complete session flow, and output the complete session flow after verification.
[0046] Specifically, the transport layer header checksum of the reassembled complete session stream is calculated to verify the consistency between the transport layer header checksum and the payload data; Check whether the application layer protocol header identifier conforms to the protocol specification corresponding to the protocol type encoding extracted from the steganographic metadata; When the transport layer checksum verification passes and the number of consecutive failures of the application layer protocol header identifier verification is lower than the preset threshold, the complete session flow verification is determined to be passed; and the verified complete session flow is output.
[0047] It should be noted that the preset number threshold is set based on the statistical results of network transmission reliability experimental data, and the example value is three consecutive verification failures.
[0048] S3. Strip the transport layer header of the complete session stream according to the protocol type encoding, extract the application layer payload content, and output the classified structured data entity.
[0049] S3.1: Dynamically select the corresponding application layer protocol parser based on the protocol type code, strip the transport layer header of the complete session stream, obtain the encrypted protocol payload data, decrypt it, and generate the application layer payload content; Specifically, the protocol type code is mapped to a specific application layer protocol name by querying a predefined protocol code table; Load the corresponding standard protocol parser according to the specific application layer protocol name, use the protocol parser to strip the transport layer header of the complete session stream, and extract the encrypted protocol payload data; The encrypted payload data is decrypted using a standard decryption algorithm. The TLS protocol uses the handshake protocol defined in RFC 8446 to negotiate key decryption, and the HTTPS protocol uses the certificate key for decryption. The decrypted data is used to generate the application layer payload content.
[0050] It should be noted that the predefined protocol code table refers to a mapping relationship table created and stored in advance, which establishes a correspondence between common application layer protocol names (such as HTTP, HTTPS, FTP, SSH, DNS, etc.) and unique fixed-length binary codes.
[0051] S3.2: Perform semantic analysis on the application layer payload content to identify and extract the protocol commands, header fields, and payload content semantics; Specifically, the parsing rules are defined according to the protocol specification corresponding to the protocol type code, and regular expression matching is used to identify protocol commands, including HTTP request methods, DNS query types, TLS handshake types, etc. Identify header fields, including HTTP header fields, DNS resource records, and TLS extension fields, through delimiter parsing and key-value pair extraction algorithms; Use length identifiers or boundary detection algorithms to extract payload content semantics.
[0052] S3.3: Convert the semantics of protocol commands, header fields, and payload content into a unified format key-value pair structure to generate classified structured data entities.
[0053] Specifically, the key name is defined using the three-level naming convention of "protocol type. element level. element name", where the protocol type is obtained by querying the predefined protocol code table and converting the protocol type code into the protocol name; The element level is divided into three fixed levels: command, header, and payload. The element names use the original field names defined by the corresponding protocol standards. Map the protocol commands obtained from semantic analysis into command-level key-value pairs, map the header fields into header-level key-value pairs, and map the payload content into payload-level key-value pairs. All values are converted to UTF-8 encoded string format to generate classified structured data entities.
[0054] S4. Map the classified structured data entities into a unified behavioral element triple set.
[0055] S4.1: Extract semantic elements from categorized structured data entities and use information entropy to calculate the importance weight of each element in the semantic elements; Specifically, all semantic elements are extracted from the key-value pairs of the classified structured data entities, including subject elements, predicate elements, and object elements.
[0056] The information entropy is used to calculate the importance weight of each element in the semantic element, and the expression is: ; Where, Indicates the The importance weight of each factor, Represents the feature index, Indicates the The information entropy of each element, Indicates the total number of types of semantic elements, represents the normalization factor.
[0057] It should be noted that and All are dimensionless, and the final output is It is dimensionless and maintains dimensional consistency.
[0058] S4.2: Generate multiple preliminary behavioral element triplets using the semantic elements and the importance weights of each element in the semantic elements, and calculate the confidence score of each preliminary element-behavior triplet; Specifically, the semantic elements are combined into preliminary behavioral element triplets according to the grammatical structure of "subject-predicate-object".
[0059] Calculate the confidence score of each preliminary feature behavior triplet, the expression is: ; Where, represents the confidence score of a single preliminary feature behavior triple, Indicates the total number of elements, Indicates traversing and summing all elements. Indicates the The integrity index of each element, represents the exponential decay term, represents the attenuation coefficient, Indicates the hierarchical depth of the preliminary feature behavior triple in the semantic parse tree.
[0060] It should be noted that 、 、 、 All are dimensionless, and the final output is It is dimensionless and maintains dimensional consistency.
[0061] S4.3: Screening multiple preliminary behavior factor triplets based on the confidence score of each preliminary behavior factor triplet, retaining preliminary behavior factor triplets with confidence scores exceeding a preset confidence threshold, and generating a set of behavior factor triplets; Specifically, screening is performed based on the comparison result of the confidence score of each preliminary behavior factor triple with the preset confidence threshold. When the confidence score of the preliminary behavior factor triple exceeds the preset confidence threshold, it is retained in the candidate set; When the confidence score of the preliminary behavior factor triple does not exceed the preset confidence threshold, it is removed from the candidate set; All retained preliminary behavior element triples are combined into a final behavior element triple set.
[0062] It should be noted that the preset confidence threshold is set based on the statistical results of the balance point between accuracy and recall in historical behavior data analysis, and the example value is 0.6.
[0063] S4.4: Convert the behavior element triple set into a unified RDF format to generate a unified behavior element triple set.
[0064] Specifically, the standard RDF triple structure is used for format conversion, and the subject element in each behavior element triple is mapped to a subject element, the predicate element is mapped to a predicate element, and the object element is mapped to an object element; Add timestamp attribute and stream association identifier attribute as extended annotations to each RDF triple; All converted triples are organized into a complete RDF document structure using RDF / XML serialization syntax to generate a unified behavioral element triple set.
[0065] S5. Inject the behavioral element triple set into the constructed cross-protocol threat knowledge graph for adjacency matching. When the overlap between the unknown protocol behavior path and the graph threat link exceeds the preset security threshold, output the high-risk threat matching result.
[0066] S5.1: The constructed cross-protocol threat knowledge graph is generated by training historical threat behavior data and contains triple relationship chains of known attack patterns.
[0067] Specifically, a knowledge graph is constructed based on historical threat intelligence data, in which nodes represent network entities (IP addresses, domain names, user accounts, etc.) and edges represent threat behavior relationships (vulnerability exploitation, data leakage, privilege escalation, etc.); a graph embedding algorithm is used to map nodes to low-dimensional vector representations; the threat path consists of a continuous chain of triple relationships, and each path is labeled with the threat type and confidence weight.
[0068] S5.2: Take each behavior triple in the unified behavior element triple set as a query input, perform a parallel query in the cross-protocol threat knowledge graph, and activate relevant graph nodes; Specifically, each triple in the RDF format unified behavior element triple set is split into a subject element, a predicate element, and an object element; Using subject and object elements as node query conditions and predicate elements as edge query conditions, we perform parallel node matching queries in the cross-protocol threat knowledge graph. The cosine similarity algorithm is used to calculate the similarity of the feature vectors of the query node and the graph node. When the similarity value exceeds the preset node matching threshold, the graph node is marked as active.
[0069] It should be noted that the preset node matching threshold is set based on the statistical results of the balance point between accuracy and recall in the historical threat data verification set, and the example value is 0.85.
[0070] S5.3: Perform a bidirectional traversal from all activated relevant graph nodes to extract all threat paths whose length does not exceed a preset length threshold; Specifically, each activated graph node is used as a starting point, and forward and reverse breadth-first traversals are performed simultaneously; Forward traversal searches for subsequent nodes along the outgoing edge direction, and reverse traversal searches for predecessor nodes along the incoming edge direction; During the traversal process, the node sequence and edge relationship passed through are recorded to form a candidate path. When the path length reaches the preset length threshold, the traversal of the branch is stopped; All complete paths whose length does not exceed the preset length threshold are collected as threat paths.
[0071] It should be noted that the preset length threshold is set based on the statistical results of the effective attack chain length distribution in historical threat path analysis, and the example value is 5.
[0072] S5.4: Construct the unknown protocol behavior path from the behavior element triples in chronological order, and calculate the overlap between the unknown protocol behavior path and each threat path; Specifically, extract the timestamp attribute of each behavior element triple from the unified behavior element triple set, and sort all behavior element triples in ascending order according to the timestamp attribute value; The node elements in the sorted behavior element triples are connected in sequence to form a node sequence, and edge relationships are added to adjacent nodes in the node sequence. The edge relationships are derived from the predicate elements of the corresponding behavior element triples, generating an unknown protocol behavior path with a temporal relationship.
[0073] Calculate the overlap between the unknown protocol behavior path and each threat path. The expression is: ; Where, Indicates the overlap between the unknown protocol behavior path and each threat path, A set of nodes representing unknown protocol behavior paths, represents the set of nodes for each threat path, Indicates the size of the intersection of the unknown protocol behavior path and each threat path, Represents the size of the union of the unknown protocol behavior path and each threat path, Indicates the length of the time window for unknown protocol behavior paths, Indicates the time window length of each threat path, It means taking the smaller value between the unknown protocol behavior path and the time window length of each threat path. Indicates taking the larger value between the unknown protocol behavior path and the time window length of each threat path.
[0074] It should be noted that and is dimensionless, and The dimension is seconds, and the dimension is eliminated by ratio, and the final output is It is dimensionless and maintains dimensional consistency.
[0075] S5.5: When the overlap exceeds the preset safety threshold, it is determined to be a high-risk threat match and a high-risk threat match result including the overlap and evidence chain is generated.
[0076] Specifically, the calculated overlap is compared with a preset safety threshold, and when the overlap exceeds the preset safety threshold, the threat path is marked as a matching path; The complete node sequence and edge relationship of the matching path are extracted as the evidence chain, and a high-risk threat matching result including the overlap degree, evidence chain and matching credibility is generated.
[0077] It should be noted that the preset security threshold is set based on the statistical analysis results of the balance point between false alarm rate and detection rate in historical threat verification data, and the example value is 0.6.
[0078] Compared to conventional rule-based or single-dimensional threat detection, this approach, by injecting behavioral element triplets into a cross-protocol threat knowledge graph for adjacency matching, accurately identifies cross-protocol, multi-step, and covert attack chains. Traditional methods rely on single-point feature matching or static rule bases, failing to effectively correlate discrete threat behaviors across different protocols. By leveraging the semantic association capabilities of the knowledge graph and calculating the overlap between behavioral paths and known threat links, this approach can identify cross-protocol attack combinations such as "SSH commands transmitted through HTTP tunnels" or "data exfiltration hidden through DNS tunnels," improving both the accuracy and depth of threat discovery for advanced persistent threats (APTs).
[0079] S6. Trigger real-time blocking and generate auditable alarm records based on high-risk threat matching results, update the cross-protocol threat knowledge graph, and complete the encrypted traffic restoration and intelligent monitoring closed loop.
[0080] S6.1: Dynamically assess the real-time threat response level based on the evidence chain and overlap in the high-risk threat matching results; Specifically, the strength level of the evidence chain is evaluated based on the number of nodes and the completeness of the edge relationships contained in the evidence chain; Determine the severity level of the threat based on the predefined range of the overlap; According to the combined mapping relationship between the evidence chain strength level and the threat severity level, the final real-time threat response level is determined from the predefined response level comparison table.
[0081] It should be noted that the predefined interval range is a division standard set based on the distribution statistical characteristics of the overlap in historical threat data. For example, a value of 0.6 to 0.8 is defined as a medium threat interval, and a value above 0.8 is defined as a high threat interval. The predefined response level comparison table is a mapping rule set based on the statistical results of the actual disposal effects of different combinations of evidence chain strength and threat severity in historical disposal records. Specifically, it refers to a correspondence table that maps the combination relationship of evidence chain strength level (high / medium / low) and threat severity level (high / medium / low) to a specific response level (high / medium / low).
[0082] S6.2: Based on the threat response level, select and implement the corresponding network blocking strategy, digitally sign it, and generate auditable alarm records; Specifically, the corresponding network blocking strategy is selected from the predefined response strategy mapping table based on the real-time threat response level; high-level responses use real-time connection blocking strategies, medium-level responses use session termination strategies, and low-level responses use traffic rate limiting strategies; The selected blocking policy instructions are issued to the target network device through the standard network management protocol, and the alarm records are signed using the RSA digital signature algorithm to generate auditable alarm records.
[0083] It should be noted that the predefined response strategy mapping table is an operation guideline set based on the correlation analysis results between different threat levels and actual disposal effects in historical network disposal records.
[0084] S6.3: Feedback auditable alarm records to the cross-protocol threat knowledge graph, update the edge weights in the cross-protocol threat knowledge graph, and complete the encrypted traffic restoration and intelligent monitoring closed loop.
[0085] Specifically, verified threat path information is extracted from auditable alarm records, including the node sequence and edge relationship in the path. Based on the threat response level and the credibility of the high-risk threat matching results, the weight value of the corresponding edge in the cross-protocol threat knowledge graph is adjusted; A weight update mechanism based on time decay is adopted to ensure that newly verified threat evidence receives a higher weight adjustment range. After the weight update is completed, a monitoring closed loop is formed, which enables the cross-protocol threat knowledge graph to have the ability to continuously evolve and provide an updated threat intelligence foundation for traffic monitoring.
[0086] In summary, this invention achieves covert marking of encrypted traffic by dynamically embedding steganographic tags in network and transport layer message headers, allowing encrypted traffic to carry steganographic metadata during transmission. This ensures that the original encrypted communication remains undisturbed, provides precise flow classification for traffic restoration, supports accurate reconstruction of encrypted session flows and application-layer protocol parsing, and lays a data foundation for cross-protocol threat detection.
[0087] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A network traffic restoration and monitoring method, characterized by: include, Capture the original encrypted traffic data packets, and dynamically embed the steganographic mark in the non-critical fields reserved in the network layer and transport layer message headers to generate encrypted traffic data packets carrying steganographic metadata; Receive encrypted traffic data packets carrying steganographic metadata, extract the steganographic mark, and classify and aggregate the data fragments according to the flow association identifier to reconstruct the complete session flow; Strip the transport layer header of the complete session stream according to the protocol type code, extract the application layer payload content, and output classified structured data entities; Mapping classified structured data entities into a unified behavioral element triple set; The behavioral element triples are injected into the constructed cross-protocol threat knowledge graph for adjacency matching. When the overlap between the unknown protocol behavior path and the graph threat link exceeds the preset security threshold, a high-risk threat matching result is output. Based on the high-risk threat matching results, real-time blocking is triggered and auditable alarm records are generated, the cross-protocol threat knowledge graph is updated, and the encrypted traffic restoration and intelligent monitoring closed loop are completed.
2. The network traffic restoration and monitoring method according to claim 1, wherein: The steganographic mark includes a stream association identifier and a protocol type code.
3. The network traffic restoration and monitoring method according to claim 2, wherein: The specific steps of generating an encrypted traffic data packet carrying steganographic metadata are as follows: Capture the original encrypted traffic data packets, parse the original encrypted traffic data packets, extract the network layer and transport layer header field values, synchronously obtain the current original encrypted traffic data packet arrival timestamp and transport layer sequence number, and collect the current network status parameters in real time; Generate steganographic metadata based on the network layer and transport layer header field values, combined with the stream association identifier and protocol type encoding; Calculate the steganalytic embedding utility value according to the current network state parameters, and decide the embedding strategy under the current network state according to the steganalytic embedding utility value; According to the embedding strategy and steganalytic metadata, a dynamic steganalytic encoding sequence is generated by combining the arrival timestamp of the current original encrypted traffic data packet and the transport layer sequence number; According to the embedding strategy, multiple reserved non-critical fields in the network layer and transport layer message headers are selected, and the dynamic steganographic encoding sequence is embedded bit by bit into the selected fields to generate encrypted traffic data packets carrying steganographic metadata.
4. The network traffic restoration and monitoring method according to claim 3, wherein: The original encrypted traffic data packet includes data fragments transmitted in network layer fragments.
5. The network traffic restoration and monitoring method according to claim 1, wherein: The steps of reorganizing into a complete conversation flow are as follows: The receiving end captures the encrypted traffic data packets carrying the steganographic metadata and accurately extracts the dynamic steganographic coding sequence from the specified field in the encrypted traffic data packet header; Perform inverse transformation and verification on the dynamic steganographic coding sequence to obtain the stream association identifier and protocol type code; Classify all data packet fragments into corresponding flow session buckets according to flow association identifiers, sort and reassemble them to generate a reassembled complete session flow; The reassembled complete session flow is verified, and the complete session flow is output after the verification passes.
6. The network traffic restoration and monitoring method according to claim 5, wherein: The output classification structured data entity is specifically performed in the following steps: Dynamically select the corresponding application layer protocol parser based on the protocol type code, strip the transport layer header of the complete session stream, obtain the encrypted protocol payload data, decrypt it, and generate the application layer payload content; Perform semantic analysis on the application layer payload content to identify and extract the protocol commands, header fields, and payload content semantics; The protocol commands, header fields and payload content semantics are converted into a key-value pair structure in a unified format to generate classified structured data entities.
7. The network traffic restoration and monitoring method according to claim 6, wherein: The mapping is a unified set of behavioral element triples, and the specific steps are as follows: Extract semantic elements from classified structured data entities and use information entropy to calculate the importance weight of each element in the semantic elements; Using the semantic elements and the importance weights of each element in the semantic elements, a plurality of preliminary behavioral element triplets are generated, and a confidence score of each preliminary element-behavior triplet is calculated; Screening multiple preliminary behavior factor triplets according to the confidence score of each preliminary behavior factor triplet, retaining preliminary behavior factor triplets with confidence scores exceeding a preset confidence threshold, and generating a behavior factor triplet set; The behavior element triple set is converted into a unified RDF format to generate a unified behavior element triple set.
8. The network traffic restoration and monitoring method according to claim 1, wherein: The constructed cross-protocol threat knowledge graph is generated through training of historical threat behavior data and contains triple relationship chains of known attack patterns.
9. The network traffic restoration and monitoring method according to claim 8, wherein: The specific steps of outputting high-risk threat matching results are as follows: Taking each behavior triple in the unified behavior element triple set as query input, executing parallel query in the cross-protocol threat knowledge graph and activating relevant graph nodes; Perform a bidirectional traversal from all activated related graph nodes to extract all threat paths whose length does not exceed the preset length threshold; The behavior element triplets are used to construct the unknown protocol behavior path in chronological order, and the overlap between the unknown protocol behavior path and each threat path is calculated; When the overlap exceeds the preset safety threshold, it is determined to be a high-risk threat match and a high-risk threat match result including the overlap and evidence chain is generated.
10. The network traffic restoration and monitoring method according to claim 9, wherein: The specific steps to complete the encrypted traffic restoration and intelligent monitoring closed loop are as follows: Dynamically assess the real-time threat response level based on the evidence chain and overlap in high-risk threat matching results; According to the threat response level, select and execute the corresponding level of network blocking strategy, perform digital signature, and generate auditable alarm records; Feedback auditable alarm records to the cross-protocol threat knowledge graph, update the edge weights in the cross-protocol threat knowledge graph, and complete the encrypted traffic restoration and intelligent monitoring closed loop.
Citation Information
Patent Citations
Block chain covert communication method based on generative steganography network and image double steganography
CN116527278A
Non-embedding image steganography method and device based on double dynamic mapping
CN116668012A
Network security detection method and system based on deep learning
CN119011196A
File transmission protection method, system and equipment based on multiple encryption algorithms
CN119675967A
Network security dynamic early warning method and system based on knowledge graph
CN119788344A
Cited By
Secure shell protocol traffic evidence obtaining and decryption method and system based on key injection
CN121125367A
Method and system for forensic decryption of secure shell protocol traffic based on key injection
CN121125367B