Behavior recognition method, device, equipment and storage medium based on blockchain

By combining communication protocols and communication end addresses to identify blockchain behaviors, the problem of difficulty in identifying private infrastructure behaviors and insufficient recognition accuracy in the prior art is solved, and a wider and more accurate behavior recognition is achieved.

CN114119221BActive Publication Date: 2025-05-13EVERSEC BEIJING TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111402562.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-19
Publication Date
2025-05-13
Estimated Expiration
2041-11-19

AI Technical Summary

Technical Problem

The prior art is difficult to identify blockchain transaction element acquisition behavior based on private infrastructure, and behavior identification is prone to missed detection and missed detection.

Method used

By obtaining the target protocol traffic data based on the blockchain behavior protocol type of the target blockchain behavior, determining it as the target communication type data, and obtaining the communication end address data, and when the communication end address data contains the target infrastructure address data, the communication behavior is determined as the target blockchain behavior.

Benefits of technology

The scope of behavior recognition has been expanded, the accuracy of behavior recognition has been improved, and missed detection and false detection due to relying solely on IP addresses or domain names.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114119221B_ABST
    Figure CN114119221B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention discloses a behavior recognition method, device, equipment and storage medium based on blockchain. The method includes: obtaining target protocol flow data according to the blockchain behavior protocol type of the target blockchain behavior; obtaining the communication end address data of the target protocol flow data when the target protocol flow data is determined to be the target communication type data; and determining the communication behavior corresponding to the target protocol flow data as the target blockchain behavior when the communication end address data includes the target infrastructure address data. The embodiment of the present invention can expand the scope of behavior recognition and improve the accuracy of behavior recognition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of blockchain technology, and in particular to a behavior recognition method, device, equipment and storage medium based on blockchain. Background Art

[0002] The transaction elements used to implement transactions and forwarding in the blockchain require blockchain nodes to consume computing power to generate them. The greater the computing power, the greater the probability of harvesting transaction elements. At this stage, it is difficult for a single node to obtain transaction elements by its own computing power alone. Instead, it is necessary to build a computing power pool to gather the computing power of a large number of nodes, harvest transaction elements and distribute them among nodes according to work. A single node that provides computing power needs to establish communication and message transmission with the infrastructure that aggregates computing power in order to participate in the construction of the computing power pool and the acquisition of transaction elements.

[0003] In the prior art, the identification of the acquisition behavior of transaction elements of the blockchain is mainly achieved by verifying the IP address (Internet Protocol Address) or domain name of the infrastructure of the collective computing power, that is, the IP address or domain name of the communication message is verified to determine whether the communication end is a known IP address or domain name of the infrastructure, thereby identifying whether the communication behavior corresponds to the acquisition behavior of transaction elements.

[0004] However, the behavior recognition method provided by the above-mentioned prior art can only identify the transaction element acquisition behavior based on the mainstream infrastructure. Since the known IP address or domain name is difficult to cover the private infrastructure information, the transaction element acquisition behavior based on the private infrastructure cannot be recognized. At the same time, there is also a certain degree of risk of false detection when relying solely on IP addresses or domain names for behavior recognition. Summary of the invention

[0005] Embodiments of the present invention provide a blockchain-based behavior recognition method, device, equipment, and storage medium to expand the scope of behavior recognition and improve the accuracy of behavior recognition.

[0006] In a first aspect, an embodiment of the present invention provides a behavior recognition method based on blockchain, comprising:

[0007] According to the blockchain behavior protocol type of the target blockchain behavior, target protocol traffic data is obtained;

[0008] In the case where it is determined that the target protocol flow data is target communication type data, obtaining communication end address data of the target protocol flow data;

[0009] When it is determined that the communication terminal address data includes the target infrastructure address data, the communication behavior corresponding to the target protocol traffic data is determined as the target blockchain behavior.

[0010] In a second aspect, an embodiment of the present invention further provides a behavior recognition device based on blockchain, comprising:

[0011] A traffic acquisition module, used to acquire target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior;

[0012] An address acquisition module, used to acquire communication end address data of the target protocol flow data when it is determined that the target protocol flow data is target communication type data;

[0013] A behavior determination module is used to determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data.

[0014] In a third aspect, an embodiment of the present invention further provides a computer device, the computer device comprising:

[0015] one or more processors;

[0016] A storage device for storing one or more programs;

[0017] When the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain-based behavior recognition method provided by any embodiment of the present invention.

[0018] In a fourth aspect, an embodiment of the present invention further provides a computer storage medium on which a computer program is stored, which, when executed by a processor, implements the blockchain-based behavior recognition method provided by any embodiment of the present invention.

[0019] The embodiments of the present invention obtain target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior, obtain the communication terminal address data of the target protocol traffic data when it is determined that the target protocol traffic data is the target communication type data, and determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data, thereby realizing behavior identification by combining the communication protocol with the communication terminal address, solving the technical problem that the prior art only performs behavior identification based on the communication terminal address and is prone to missed detection and false detection, expanding the scope of behavior identification, and improving the accuracy of behavior identification. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1A flowchart of a behavior recognition method based on blockchain provided in Example 1 of the present invention.

[0021] Figure 2 A flowchart of a behavior recognition method based on blockchain provided in Example 2 of the present invention.

[0022] Figure 3 A flowchart of a behavior recognition method based on blockchain provided in Embodiment 2 of the present invention.

[0023] Figure 4 A schematic diagram of the structure of a behavior recognition device based on blockchain provided in Example 3 of the present invention.

[0024] Figure 5 A schematic diagram of the structure of a computer device provided in Embodiment 4 of the present invention. DETAILED DESCRIPTION

[0025] The present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention.

[0026] It should also be noted that, for ease of description, only the part relevant to the present invention but not all content is shown in the accompanying drawings. It should be mentioned before discussing exemplary embodiments in more detail that some exemplary embodiments are described as processing or methods depicted as flow charts. Although the flow chart describes each operation (or step) as sequential processing, many operations therein can be implemented in parallel, concurrently or simultaneously. In addition, the order of each operation can be rearranged. When its operation is completed, the processing can be terminated, but it can also have additional steps not included in the accompanying drawings. The processing can correspond to methods, functions, procedures, subroutines, subprograms, etc.

[0027] Embodiment 1

[0028] Figure 1 is a flowchart of a behavior recognition method based on blockchain provided by the first embodiment of the present invention. This embodiment is applicable to the case of identifying the behavior of blockchain. The method can be executed by the behavior recognition device based on blockchain provided by the embodiment of the present invention. The device can be implemented by software and / or hardware and can generally be integrated in a computer device. Figure 1 As shown, the method includes the following operations:

[0029] S110. Obtain target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior.

[0030] The target blockchain behavior may be a behavior that needs to be identified. The blockchain behavior protocol type may be the type of communication protocol used by the blockchain node to communicate with the target infrastructure in the target blockchain behavior. The target infrastructure may be an infrastructure for aggregating multi-node computing power to perform the target blockchain behavior. The target protocol traffic data may be traffic data generated by communication using the blockchain behavior protocol type.

[0031] Accordingly, the blockchain node can communicate with the target infrastructure to access the target infrastructure and work together with other connected nodes through the target infrastructure to perform the target blockchain behavior. According to the target blockchain behavior that needs to be identified, the type of blockchain behavior protocol used by each node to communicate with the target infrastructure can be determined, and the type of communication protocol used by the communication behavior can be reflected in the traffic data generated by the communication behavior. Therefore, the target protocol traffic data can be obtained from the traffic data generated by any communication behavior, and it can be determined that the target protocol traffic data is suspected to be the traffic data generated by the target blockchain behavior. As for the traffic data generated by communicating using other communication protocols, it can be determined that it is not the traffic data generated by the target blockchain behavior, and there is no need to perform further behavior identification based on this part of the traffic data.

[0032] S120. When it is determined that the target protocol flow data is target communication type data, obtain communication end address data of the target protocol flow data.

[0033] The target communication type data may be data generated by any type of communication that needs to be conducted between the blockchain node and the target infrastructure in the target blockchain behavior. The communication end address data may be data describing the communication end address in the communication that generates the target protocol traffic data.

[0034] Accordingly, since the target protocol traffic data is suspected to be the traffic data generated by the target blockchain behavior, the target protocol traffic data can be further judged whether it is the target communication type data. According to the communication required in the target blockchain behavior to be identified, the type of the part of the communication and the specific format of the generated traffic data can be determined, so as to determine the specific method of judging whether the target protocol traffic data is the target communication type data, which is not limited in this embodiment. In the case of determining that the target protocol traffic data is the target communication type data, it can be explained that the target protocol traffic data is generated by the corresponding type of communication, and then it is further determined that the target protocol traffic data is suspected to be the traffic data generated by the target blockchain behavior. If the target protocol traffic data is not the target communication type data, the possibility that it is the traffic data generated by the target blockchain behavior can be excluded, and there is no need to perform further behavior identification based on this part of the traffic data. Therefore, in the case of determining that the target protocol traffic data is the target communication type data, the communication end address data of the target protocol traffic data can be obtained to further identify the communication behavior corresponding to the target protocol traffic data based on the communication end address data.

[0035] S130. When it is determined that the communication terminal address data includes the target infrastructure address data, the communication behavior corresponding to the target protocol traffic data is determined as the target blockchain behavior.

[0036] The target infrastructure address data may be data describing the address of a known target infrastructure.

[0037] Correspondingly, when it is determined that the communication end address data includes the target infrastructure address data, it can be stated that any communication end in the communication that generates the target protocol traffic data is the target infrastructure, and it can be determined that the communication is the communication between the blockchain node and the target infrastructure for the purpose of performing the target blockchain behavior. Therefore, the communication behavior corresponding to the target protocol traffic data can be determined as the target blockchain behavior.

[0038] The embodiment of the present invention provides a behavior identification method based on blockchain, by obtaining target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior, and when it is determined that the target protocol traffic data is the target communication type data, obtaining the communication terminal address data of the target protocol traffic data, and when it is determined that the communication terminal address data includes the target infrastructure address data, determining the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior, realizing behavior identification by combining the communication protocol with the communication terminal address, solving the technical problem that the prior art only performs behavior identification based on the communication terminal address and is prone to missed detection and false detection, expanding the scope of behavior identification, and improving the accuracy of behavior identification.

[0039] Embodiment 2

[0040] Figure 2 A flowchart of a behavior identification method based on blockchain is provided for the second embodiment of the present invention. The embodiment of the present invention is specific based on the above embodiment. In the embodiment of the present invention, a specific optional implementation method of performing behavior identification is provided after obtaining the communication terminal address data of the target protocol traffic data and determining that the communication terminal address data does not include the target infrastructure address data.

[0041] like Figure 2 As shown, the method of the embodiment of the present invention specifically includes:

[0042] S210. Obtain target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior.

[0043] In an optional embodiment of the present invention, the method of obtaining target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior may include: determining a target data packet format according to the blockchain behavior protocol type; extracting a data packet to be detected from a data stream to be detected; and determining the data packet to be detected that satisfies the target data packet format as the target protocol traffic data.

[0044] The target data packet format may be a format of a data packet extracted from a data stream generated by a communication protocol using a blockchain behavior protocol type. The data stream to be detected may be a data stream generated by any unknown communication behavior. The data packet to be detected may be a data packet to be detected extracted from the data stream to be detected.

[0045] Accordingly, the traffic data generated by communicating using any type of communication protocol has a specific data packet format, so the communication protocol used by the communication behavior that generates the traffic data can be determined based on the data packet format. Therefore, the target data packet format can be determined based on the blockchain behavior protocol type, and data packets can be extracted from the data stream to be detected to obtain at least one data packet to be detected, thereby determining whether each data packet to be detected meets the target data packet format. If any data packet to be detected meets the target data packet format, it can be said that this part of the traffic data is the target protocol traffic data.

[0046] For example, currently in the transaction element acquisition behavior, the communication protocol commonly used between the blockchain node and the target infrastructure of the collective computing power is the Stratum protocol, and the corresponding target data packet format is the JSON (JavaScript Object Notation) format. Then, the data packet can be extracted from the data stream to be detected to determine whether the data packet is in the JSON format. If so, it can be preliminarily determined that the data packet is data generated by the suspected transaction element acquisition behavior, and subsequent behavior identification can be performed based on it; otherwise, it can be determined that the data packet is not data generated by the transaction element acquisition behavior, and subsequent processing of the data packet is terminated.

[0047] S220, determining whether the target protocol flow data is target communication type data, if so, executing S230 to S260, otherwise, executing S270.

[0048] In an optional embodiment of the present invention, the determination that the target protocol flow data is target communication type data may include: converting the target protocol flow data into target format data; reading a request type field in the target format data; and determining that the target protocol flow data includes target message flow data based on the field value of the request type field, determining the target protocol flow data as the target communication type data.

[0049] The target format data may be data obtained by converting the target protocol flow data into a specific format, and the data content of the target protocol flow data may be stored in a field format. The request type field may be a field in the target format data that stores the type of the communication request message corresponding to the target protocol flow data. The target message flow data may be flow data corresponding to the communication request message that needs to be transmitted between the blockchain node and the target infrastructure in the target blockchain behavior.

[0050] Accordingly, since the target protocol traffic data are all generated by the communication using the communication protocol of the blockchain behavior protocol type, they can all be converted into target format data. The target format data includes a request type field, and the type of communication request message transmitted in the communication behavior that generates the target protocol traffic data can be determined according to the field value of the request type field, so that it can be determined whether the target protocol traffic data includes the target message traffic data according to whether the field value of the request type field includes a specific request type. If it is determined that the target protocol traffic data includes the target message traffic data according to the field value of the request type field, it can be explained that a specific type of communication request message is transmitted in the communication behavior that generates the target protocol traffic data, and the communication behavior is a specific type of communication behavior that needs to be performed in the target blockchain behavior, then the target protocol traffic data can be determined to be the target communication type data.

[0051] In an optional embodiment of the present invention, determining that the target protocol traffic data includes target message traffic data based on the field value of the request type field may include: obtaining target message parameters of the target blockchain behavior; and determining that the target protocol traffic data includes the target message traffic data when it is determined that the field value of the request type field includes at least one of the target message parameters.

[0052] The target message parameter may be the field value content corresponding to the traffic data corresponding to the communication request message that needs to be transmitted between the blockchain node and the target infrastructure in the target blockchain behavior after being converted into the target format data in the request type field. The target message parameters include subscription message parameters, authorization message parameters, difficulty sending message parameters, task sending message parameters, and submission message parameters.

[0053] Specifically, the subscription message parameter may be the target message parameter corresponding to the communication request message transmitted in the behavior of establishing a communication connection between the blockchain node and the target infrastructure in the target blockchain behavior. The authorization message parameter may be the target message parameter corresponding to the communication request message transmitted in the behavior of the blockchain node authorizing the target infrastructure in the target blockchain behavior. The difficulty sending message parameter may be the target message parameter corresponding to the communication request message transmitted in the behavior of the target infrastructure sending the task difficulty to the blockchain node in the target blockchain behavior. The task sending message parameter may be the target message parameter corresponding to the communication request message transmitted in the behavior of the target infrastructure sending the task to the blockchain node in the target blockchain behavior. The submission message parameter may be the target message parameter corresponding to the communication request message transmitted in the behavior of the blockchain node feeding back the harvested transaction elements to the target infrastructure in the target blockchain behavior.

[0054] Accordingly, according to the communication request message that needs to be transmitted in the target blockchain behavior that needs to be identified, the above-mentioned target message parameters can be determined, so that the request type field can be parameter-checked according to the target message parameters. If the request type field includes at least one of the target message parameters, it can be explained that a specific type of communication request message is transmitted in the communication behavior that generates the target protocol flow data, and the specific type of communication request message is the communication request message that needs to be transmitted in the target blockchain behavior, then it can be determined that the target protocol flow data includes the target message flow data.

[0055] For example, in the above example of obtaining the current transaction element behavior, determining that the blockchain behavior protocol type is the Stratum protocol and the target data packet format is the JSON format, the selected JSON format data packet can be format-converted and the Method (request type) field can be read from it to perform parameter verification on the Method field. Specifically, according to the current transaction element acquisition behavior, the parameters corresponding to the subscription request, authorization request, difficulty issuance request, task issuance request and submission request can be determined. Among them, the subscription request is used to establish a TCP (Transmission Control Protocol) connection with the target infrastructure after the blockchain node is started, and then send a subscription message to the target infrastructure. The message content can be, for example, {"id":1,"method":"mining.subscribe","params":[]}. After receiving the subscription message, the target infrastructure can respond to the subscription message and send a corresponding message, such as {"id":1,"result":[[["mining.set_difficulty","01000000"],["mining.notify","01000000"]],"01000000",8],"error":null}. After receiving the response message from the target infrastructure, the node can send an authorization message to the target infrastructure, including at least two parameters: node name and password, such as {"id":2,"method":"mining.authorize","params":["zsc.1","x"]}. After successful authorization, the target infrastructure can issue difficulty to the node, and then issue tasks. The content of the difficulty message can be, for example, {"id":null,"method":"mining.set_difficulty","params":

[8192] }, and the content of the task message can be, for example, {"id":null,"method":"mining.notify","params":["required information for obtaining relevant transaction elements"]}. After the node obtains the calculation results that meet the task, it can submit the results obtained through calculation to the target infrastructure. The content of the message for submitting the results can be, for example, {"id":3,"method":"mining.submit","params":["zsc.1","0","b909000000000000","5cc1713f","5a0199e2"]}.Therefore, if the JSON format data packet after format conversion contains the Method field, and the field value of the Method field is covered by the parameters mining.subscribe, mining.authorize, mining.set_difficulty, mining.notify, and mining.submit corresponding to the above message, it can be further determined that the data packet is data generated by suspected transaction element acquisition behavior.

[0056] S230, determining whether the communication terminal address data includes the target infrastructure address data, if so, executing S240, otherwise, executing S250 to S260.

[0057] S240. Determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior.

[0058] S250. Update the suspicious data volume of each communication terminal address data according to the target protocol flow data.

[0059] Among them, the suspicious data volume can be the total data volume of traffic data generated by all communication behaviors suspected to be in the target blockchain behavior corresponding to the communication end described by the communication end address data.

[0060] Accordingly, if the communication terminal address data does not include the target infrastructure address data, it can be said that the communication terminal described by the communication terminal address data does not include the known target infrastructure, and the suspicious data volume of the communication terminal address data can be further judged whether it is the target infrastructure. Therefore, when the target protocol flow data is determined to be the target communication type data, it can be preliminarily determined that it is suspected to be the flow data generated by the communication behavior in the target blockchain behavior. For the communication terminal described by the communication terminal address data obtained in the target protocol flow data, its suspicious data volume needs to be updated.

[0061] In an optional embodiment of the present invention, updating the suspicious data volume of each communication terminal address data according to the target protocol flow data may include: determining the target protocol flow data as the suspicious flow data of each communication terminal address data; respectively obtaining the current total data volume of the suspicious flow data of each communication terminal address data, and respectively determining each current total data volume as the updated suspicious data volume of each communication terminal address data.

[0062] The suspicious traffic data may be traffic data suspected to be generated by communication behavior in the target blockchain behavior. The current total data volume may be the total data volume of all suspicious traffic data at the current moment.

[0063] Correspondingly, when the target protocol traffic data is determined to be the target communication type data, the target protocol traffic data can be used as the suspicious traffic data of each corresponding communication terminal address data. Then, for any communication terminal address data, the traffic data generated by all communication behaviors suspected to be in the target blockchain behavior performed by the communication terminal described by the communication terminal address data can be recorded. Furthermore, after the target protocol traffic data is determined to be the suspicious traffic data of each corresponding communication terminal address data, the current total data volume of all suspicious traffic data of any communication terminal address data can be obtained as the suspicious data volume of the communication terminal address data to update its suspicious data volume. Optionally, obtaining the current total data volume of the suspicious traffic data of any communication terminal address data can be to obtain all its suspicious traffic data at the current moment and calculate the current total data volume, or to obtain the data volume of the currently increased suspicious traffic data, and determine the sum of this data volume and the suspicious data volume at the previous moment as the current total data volume, which is not limited here.

[0064] S260. Determine the communication behavior corresponding to the target protocol flow data according to the updated suspicious data volume.

[0065] Accordingly, the suspicious data volume of any communication terminal address data can reflect the total amount of communication behaviors suspected to be target blockchain behaviors performed by the communication terminal described by the communication terminal address data, that is, it can reflect the degree of suspicion of the target blockchain behaviors of the communication terminal. Therefore, when it is determined that the target protocol flow data is the target communication type data, and the corresponding communication terminal address data does not include the target infrastructure address data, the suspicious data volume of each communication terminal address data can be updated according to the target protocol flow data, and the suspicious data volume of each communication terminal address data after the update can be obtained. Then, the degree of suspicion of the target blockchain behaviors of each communication terminal address data can be obtained in real time, thereby determining whether the communication terminal described by each communication terminal address data has performed the target blockchain behavior, and at the same time, the communication behavior corresponding to the target protocol flow data can be determined.

[0066] In an optional embodiment of the present invention, determining the communication behavior corresponding to the target protocol traffic data based on the updated suspicious data volume may include: when it is determined that the suspicious data volume of any communication terminal address data reaches a data volume threshold, determining the communication terminal address data as the target infrastructure address data, and determining the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior.

[0067] Among them, the data volume threshold can be the upper limit of the data volume of the target protocol traffic data determined as the target communication type data generated by the communication behavior of any communication terminal other than the target infrastructure, and can be predetermined based on empirical values.

[0068] Correspondingly, if the target infrastructure is used to perform the target blockchain behavior, the traffic data generated by it includes a large amount of target protocol traffic data that can be determined as target communication type data, while the communication behavior of any communication terminal other than the target infrastructure generates less traffic data of this type, which usually does not reach the data volume threshold. Therefore, in the case where the suspicious data volume of any communication terminal address data reaches the data volume threshold, it can be determined that the communication terminal described by the communication terminal address data is the target infrastructure, that is, the communication terminal address data is the target infrastructure address data. Furthermore, in the case where the communication terminal address data of the target protocol traffic data includes the target infrastructure address data, the communication behavior corresponding to the target protocol traffic data can be determined as the target blockchain behavior.

[0069] S270: End the behavior identification based on the target protocol traffic data.

[0070] For example, Figure 3 is a flowchart of a behavior recognition method based on blockchain provided by Embodiment 2 of the present invention. In a specific example, Figure 3 As shown, through a traffic collection tool, such as Wireshark software, the target protocol traffic data generated by the blockchain node in the behavior of obtaining transaction elements is collected, and the traffic data is identified through format verification, and the identified traffic data is further verified based on the IP address or domain name, and finally the transaction element acquisition behavior of the blockchain node reflected by the collected traffic data is identified. Among them, the identification rules for the target protocol traffic data can be determined based on subscription messages, authorization messages, difficulty messages, task messages, and submission messages.

[0071] The embodiment of the present invention provides a behavior identification method based on blockchain, which obtains target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior, obtains the communication terminal address data of the target protocol traffic data when it is determined that the target protocol traffic data is the target communication type data, and determines the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data, thereby realizing behavior identification by combining the communication protocol with the communication terminal address, solving the technical problem that the prior art only performs behavior identification based on the communication terminal address and is prone to missed detection and false detection, expanding the scope of behavior identification, and improving the accuracy of behavior identification; further, by real-time updating of the suspicious data volume of the communication terminal that does not belong to the known target infrastructure, the target infrastructure is identified according to the suspicious data volume, and the target blockchain behavior is further identified, thereby expanding the identification scenario of the target blockchain behavior and improving the practicality of the behavior identification method.

[0072] Embodiment 3

[0073] Figure 4 A schematic diagram of a behavior recognition device based on blockchain provided in Embodiment 3 of the present invention is shown in FIG. Figure 4 As shown, the device includes: a traffic acquisition module 310, an address acquisition module 320 and a first behavior determination module 330.

[0074] Among them, the traffic acquisition module 310 is used to obtain target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior.

[0075] The address acquisition module 320 is used to acquire the communication end address data of the target protocol flow data when it is determined that the target protocol flow data is target communication type data.

[0076] The first behavior determination module 330 is used to determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data.

[0077] In an optional implementation of the embodiment of the present invention, the device also includes: a suspicious data volume updating module, which is used to update the suspicious data volume of each communication end address data according to the target protocol traffic data when it is determined that the communication end address data does not include the target infrastructure address data; a second behavior determination module, which is used to determine the communication behavior corresponding to the target protocol traffic data based on the updated suspicious data volume.

[0078] In an optional implementation of an embodiment of the present invention, the suspicious data volume update module can be specifically used to: determine the target protocol traffic data as the suspicious traffic data of each communication terminal address data; respectively obtain the current total data volume of the suspicious traffic data of each communication terminal address data, and respectively determine each current total data volume as the updated suspicious data volume of each communication terminal address data.

[0079] In an optional implementation of an embodiment of the present invention, the second behavior determination module can be specifically used to: when it is determined that the suspicious data volume of any communication terminal address data reaches a data volume threshold, determine the communication terminal address data as the target infrastructure address data, and determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior.

[0080] In an optional implementation of an embodiment of the present invention, the traffic acquisition module 310 can be specifically used to: determine the target data packet format according to the blockchain behavior protocol type; extract the data packet to be detected from the data stream to be detected; and determine the data packet to be detected that meets the target data packet format as the target protocol traffic data.

[0081] In an optional implementation of an embodiment of the present invention, the address acquisition module 320 may include: a format conversion submodule, used to convert the target protocol traffic data into target format data; a field reading submodule, used to read the request type field in the target format data; a type determination submodule, used to determine the target protocol traffic data as the target communication type data when it is determined that the target protocol traffic data includes target message traffic data based on the field value of the request type field.

[0082] In an optional implementation of an embodiment of the present invention, the type determination submodule can be specifically used to: obtain target message parameters of the target blockchain behavior; wherein the target message parameters include subscription message parameters, authorization message parameters, difficulty delivery message parameters, task delivery message parameters and submission message parameters; when it is determined that the field value of the request type field includes at least one of the target message parameters, determine that the target protocol traffic data includes the target message traffic data.

[0083] The above-mentioned device can execute the blockchain-based behavior recognition method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.

[0084] An embodiment of the present invention provides a behavior identification device based on blockchain, which obtains target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior, obtains the communication terminal address data of the target protocol traffic data when it is determined that the target protocol traffic data is the target communication type data, and determines the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data, thereby realizing behavior identification by combining the communication protocol with the communication terminal address, solving the technical problem that the prior art only performs behavior identification based on the communication terminal address and is prone to missed detection and false detection, expands the scope of behavior identification, and improves the accuracy of behavior identification.

[0085] Embodiment 4

[0086] Figure 5 A schematic diagram of the structure of a computer device provided in Embodiment 4 of the present invention. Figure 5 A block diagram of an exemplary computer device 12 suitable for use in implementing embodiments of the present invention is shown. Figure 5 The computer device 12 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0087] like Figure 5As shown, the computer device 12 is in the form of a general-purpose computing device. The components of the computer device 12 may include, but are not limited to: one or more processors 16, a memory 28, and a bus 18 that connects various system components (including the memory 28 and the processor 16).

[0088] Bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor or a local bus using any of a variety of bus architectures. By way of example, these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.

[0089] The computer device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the computer device 12, including volatile and non-volatile media, removable and non-removable media.

[0090] The memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The computer device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 34 may be used to read and write non-removable, non-volatile magnetic media ( Figure 5 not shown, usually called a "hard drive"). Although Figure 5 Not shown in the figure, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, a DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 via one or more data medium interfaces. The memory 28 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the various embodiments of the present invention.

[0091] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in the memory 28, such program modules 42 including, but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods of the embodiments described herein.

[0092] The computer device 12 may also communicate with one or more external devices 14 (e.g., keyboards, pointing devices, displays 24, etc.), one or more devices that enable a user to interact with the computer device 12, and / or any device that enables the computer device 12 to communicate with one or more other computing devices (e.g., network cards, modems, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the computer device 12 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with the other modules of the computer device 12 via the bus 18. It should be understood that although Figure 5 Not shown, other hardware and / or software modules may be used in conjunction with computer device 12, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0093] The processor 16 executes various functional applications and data processing by running the program stored in the memory 28, thereby implementing the blockchain-based behavior identification method provided by the embodiment of the present invention: obtaining the target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior; when it is determined that the target protocol traffic data is the target communication type data, obtaining the communication end address data of the target protocol traffic data; when it is determined that the communication end address data includes the target infrastructure address data, determining the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior.

[0094] Embodiment 5

[0095] Embodiment 5 of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the blockchain-based behavior identification method provided by the embodiment of the present invention is implemented: according to the blockchain behavior protocol type of the target blockchain behavior, the target protocol traffic data is obtained; when it is determined that the target protocol traffic data is the target communication type data, the communication end address data of the target protocol traffic data is obtained; when it is determined that the communication end address data includes the target infrastructure address data, the communication behavior corresponding to the target protocol traffic data is determined as the target blockchain behavior.

[0096] Any combination of one or more computer-readable media can be used. Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable storage media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, computer-readable storage media can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it.

[0097] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0098] The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0099] Computer program code for performing the operation of the present invention may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or computer device. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0100] Note that the above are only preferred embodiments of the present invention and the technical principles used. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of the present invention, and the scope of the present invention is determined by the scope of the appended claims.

Claims

1. A behavior recognition method based on blockchain, characterized in that: include: According to the blockchain behavior protocol type of the target blockchain behavior, target protocol traffic data is obtained; In the case where it is determined that the target protocol flow data is target communication type data, obtaining communication end address data of the target protocol flow data, wherein the target communication type data is data generated by any type of communication between a blockchain node and a target infrastructure in a target blockchain behavior; When it is determined that the communication terminal address data includes the target infrastructure address data, the communication behavior corresponding to the target protocol traffic data is determined as the target blockchain behavior.

2. The method according to claim 1, characterized in that After acquiring the communication terminal address data of the target protocol flow data, the method further includes: In the case where it is determined that the communication terminal address data does not include the target infrastructure address data, updating the suspicious data volume of each communication terminal address data according to the target protocol flow data; The communication behavior corresponding to the target protocol flow data is determined according to the updated suspicious data volume.

3. The method according to claim 2, characterized in that The updating of the suspicious data volume of each communication terminal address data according to the target protocol flow data includes: Determining the target protocol flow data as suspicious flow data of each of the communication terminal address data; The current total data volume of the suspicious traffic data of each of the communication terminal address data is respectively obtained, and each of the current total data volumes is respectively determined as the updated suspicious data volume of each of the communication terminal address data.

4. The method according to claim 2, characterized in that: The determining, according to the updated suspicious data volume, the communication behavior corresponding to the target protocol flow data includes: When it is determined that the suspicious data volume of any communication terminal address data reaches the data volume threshold, the communication terminal address data is determined as the target infrastructure address data, and the communication behavior corresponding to the target protocol traffic data is determined as the target blockchain behavior.

5. The method according to claim 1, characterized in that The step of obtaining target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior includes: Determine the target data packet format according to the blockchain behavior protocol type; Extracting a data packet to be detected from a data stream to be detected; The data packet to be detected that meets the target data packet format is determined as the target protocol flow data.

6. The method according to claim 1, characterized in that The determining that the target protocol flow data is target communication type data includes: Converting the target protocol flow data into target format data; Reading a request type field in the target format data; When it is determined, based on the field value of the request type field, that the target protocol flow data includes target message flow data, the target protocol flow data is determined as the target communication type data.

7. The method according to claim 6, characterized in that The determining, according to the field value of the request type field, that the target protocol flow data includes target message flow data comprises: Obtain target message parameters of the target blockchain behavior; wherein the target message parameters include subscription message parameters, authorization message parameters, difficulty sending message parameters, task sending message parameters and submission message parameters; In case it is determined that the field value of the request type field includes at least one of the target message parameters, it is determined that the target protocol flow data includes the target message flow data.

8. A behavior recognition device based on blockchain, characterized in that: include: A traffic acquisition module, used to acquire target protocol traffic data according to the blockchain behavior protocol type of the target blockchain behavior; An address acquisition module, configured to acquire communication end address data of the target protocol traffic data when it is determined that the target protocol traffic data is target communication type data, wherein the target communication type data is data generated by any type of communication between a blockchain node and a target infrastructure in a target blockchain behavior; The first behavior determination module is used to determine the communication behavior corresponding to the target protocol traffic data as the target blockchain behavior when it is determined that the communication terminal address data includes the target infrastructure address data.

9. A computer device, characterized in that: The computer device comprises: one or more processors; A storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the blockchain-based behavior recognition method as described in any one of claims 1-7.

10. A computer storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the blockchain-based behavior recognition method as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • P2P protocol identification method based on protocol content identification and behavior identification

    CN103220329A

  • Method and device for identifying abnormal encrypted traffic

    CN107360159A