A method, device and electronic device for detecting malicious traffic

By acquiring and processing protocol metadata and ACK values ​​of unidirectional encrypted traffic, calculating feature values ​​and training prediction models, the accuracy problem of encrypted traffic detection in the prior art when bidirectional flow is incomplete or only one-way flow exists, and efficient malicious traffic detection of unidirectional encrypted traffic is achieved.

CN115632801BActive Publication Date: 2025-06-24VIEWINTECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110752827.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-02
Publication Date
2025-06-24
Estimated Expiration
2041-07-02

AI Technical Summary

Technical Problem

When existing encrypted flow detection schemes deal with incomplete bidirectional flow or only one-way flow, they have incomplete features or errors, affecting the accuracy of model detection.

Method used

By obtaining the protocol metadata and ACK values ​​of the one-way encrypted traffic, sorting them in chronological order, the ACK value difference is calculated to determine the eigenvalues, and based on these eigenvalues, the prediction model is trained to determine whether the target one-way encrypted traffic is malicious traffic.

Benefits of technology

Overcoming the limitation that traditional solutions can only predict bidirectional encrypted traffic, it can accurately determine whether the one-way encrypted traffic is malicious traffic when the bidirectional flow is incomplete or only one-way flow exists, improving the prediction accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632801B_ABST
    Figure CN115632801B_ABST
Patent Text Reader

Abstract

The present invention provides a method, apparatus and electronic device for detecting malicious traffic. The method includes: obtaining a plurality of sample one-way encrypted traffic, which is divided into normal encrypted traffic and malicious encrypted traffic and includes protocol metadata and a plurality of protocol packets; determining the ACK values in the protocol packets and sorting the ACK values in chronological order; determining the differences of the ACK values and determining the characteristic values of the sample one-way encrypted traffic according to the plurality of differences; training a prediction model based on the protocol metadata and characteristic values of the sample one-way encrypted traffic, and predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model. Through the method for detecting malicious traffic provided by the embodiments of the present invention, the difference of the ACK values can be used to determine the size of the data transmitted by the missing peer one-way encrypted traffic, and based on the protocol metadata of the current end, it can also be determined whether the one-way encrypted traffic of the current end is malicious traffic based on the information of the peer end, improving the prediction accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted traffic analysis, and in particular, to a method, device, electronic device, and computer-readable storage medium for constructing a feature set for detecting malicious traffic. Background Art

[0002] With the popularization of encrypted services and the improvement of network security awareness, there are more and more cases of using encrypted services for communication in the Internet. At present, the use of machine learning technology to detect encrypted traffic has gradually become a hot topic. However, there are currently a large number of problems in the Internet, such as incomplete two-way flows of encrypted traffic due to lost data packets, uplink and downlink separation, etc., or encrypted traffic with only one-way flow. Existing machine learning solutions lack responses to such special situations. Most existing encrypted traffic detections use artificial intelligence algorithms to build models for detection. When building a model, multiple features of the client and the server need to be collected for training. When the two-way flow is incomplete or only one-way flow exists, it will cause incomplete or incorrect features, thereby affecting the accuracy of model detection. Summary of the Invention

[0003] To solve the existing technical problems, embodiments of the present invention provide a method, device, electronic device, and computer-readable storage medium for detecting malicious traffic.

[0004] In a first aspect, an embodiment of the present invention provides a method for detecting malicious traffic, including: obtaining a plurality of sample one-way encrypted traffic, the sample one-way encrypted traffic being divided into normal encrypted traffic and malicious encrypted traffic, and the sample one-way encrypted traffic including protocol metadata and a plurality of protocol packets; determining the ACK values in the protocol packets of the sample one-way encrypted traffic, sorting the ACK values in chronological order to obtain an ACK sequence; determining the differences between two adjacent ACK values in the ACK sequence, and determining the feature values of the sample one-way encrypted traffic according to the plurality of differences; training a prediction model based on the protocol metadata and the feature values of the sample one-way encrypted traffic, and predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

[0005] Optionally, determining the ACK values in the protocol packets of the sample one-way encrypted traffic, sorting the ACK values in chronological order to obtain an ACK sequence, includes: setting the ACK value of the first protocol packet of the sample one-way encrypted traffic as the first element A1 of the ACK sequence; determining the ACK values of the plurality of other protocol packets of the sample one-way encrypted traffic, sorting the ACK values of the plurality of other protocol packets in chronological order and sequentially setting them as the corresponding elements A2, A3... A n , to obtain the ACK sequence {A1, A2,..., An}.

[0006] Optionally, a prediction model is trained based on the protocol metadata and the eigenvalue of the sample unidirectional encrypted traffic, and based on the prediction model, it is predicted whether the target unidirectional encrypted traffic is malicious encrypted traffic, including: determining the device identifier of the sample unidirectional encrypted traffic, where the device identifier is consistent with the greeting message in the sample unidirectional encrypted traffic; the device identifier includes a client or a server, and the greeting message includes a client greeting message or a server greeting message; training a prediction model of the device identifier based on the protocol metadata and the eigenvalue of the sample unidirectional encrypted traffic; when the greeting message in the target unidirectional encrypted traffic is consistent with the device identifier, predicting whether the target unidirectional encrypted traffic is malicious encrypted traffic based on the prediction model of the device identifier.

[0007] Optionally, the method further includes: setting a corresponding prediction model for each of the device identifiers; where, predicting whether the target unidirectional encrypted traffic is malicious encrypted traffic based on the prediction model includes: selecting a prediction model whose device identifier is consistent with the greeting message in the target unidirectional encrypted traffic, and predicting whether the target unidirectional encrypted traffic is malicious encrypted traffic based on the selected prediction model.

[0008] Optionally, the eigenvalue includes one or more of the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, and Markov transition probability of the difference.

[0009] Optionally, predicting whether the target unidirectional encrypted traffic is malicious encrypted traffic based on the prediction model includes: inputting the protocol metadata and eigenvalue of the target unidirectional encrypted traffic into the prediction model, and determining whether the target unidirectional encrypted traffic is malicious encrypted traffic according to the output result of the prediction model.

[0010] In a second aspect, an embodiment of the present invention provides a device for detecting malicious traffic, including: an acquisition module, a statistics module, an operation module, and a processing module.

[0011] The acquisition module is used to acquire a plurality of sample unidirectional encrypted traffic, the sample unidirectional encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, and the sample unidirectional encrypted traffic includes protocol metadata and a plurality of protocol packets.

[0012] The statistics module is used to determine the ACK value in the protocol packet of the sample unidirectional encrypted traffic, sort the ACK values in chronological order to obtain an ACK sequence.

[0013] The operation module is used to determine the difference between two adjacent ACK values in the ACK sequence, and determine the characteristic value of the sample one-way encrypted traffic according to multiple such differences.

[0014] The processing module is used to train a prediction model based on the protocol metadata and the characteristic value of the sample one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

[0015] Optionally, the statistics module includes: a setting unit and a sorting unit.

[0016] The setting unit is used to set the ACK value of the first protocol packet of the sample one-way encrypted traffic as the first element A1 of the ACK sequence.

[0017] The sorting unit is used to determine the ACK values of multiple other protocol packets of the sample one-way encrypted traffic, sort the ACK values of the multiple other protocol packets in chronological order and sequentially set them as the corresponding elements A2, A3... A of the ACK sequence n , to obtain the ACK sequence {A1, A2,..., A n}.

[0018] In a third aspect, an embodiment of the present invention provides an electronic device, including: a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor; the transceiver, the memory, and the processor are connected through the bus, and when the computer program is executed by the processor, it implements the steps in the method for detecting malicious traffic as described above.

[0019] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, including: a computer program stored on the readable storage medium; when the computer program is executed by a processor, it implements the steps in the method for detecting malicious traffic as described above.

[0020] A method, device and electronic device for detecting malicious traffic provided by an embodiment of the present invention not only obtain protocol metadata of unidirectional encrypted traffic for model training, but also obtain the ACK value of the protocol packet of the unidirectional encrypted traffic, sort the ACK values in the order of sending time to obtain a sequence of ACK values, calculate the difference between two adjacent ACK values in the sequence, use the difference of the ACK values to represent the size of the data sent by the missing or incomplete peer received, and perform various operations on the difference to determine multiple characteristic values of the unidirectional encrypted traffic. This method is aimed at some special scenarios in the current network where only unidirectional encrypted traffic can be seen, such as satellite links with uplink and downlink separation or situations where bidirectional encrypted traffic is incomplete due to packet loss. Only by obtaining the protocol metadata and characteristic values of the unidirectional encrypted traffic, it can be determined whether the unidirectional encrypted traffic is malicious encrypted traffic based on a prediction model, overcoming the defect in the traditional solution that can only predict bidirectional encrypted traffic and cannot predict unidirectional encrypted traffic. By calculating the difference of the ACK values, the size of the data transmitted by the missing unidirectional encrypted traffic of the peer can be determined, and based on the information of the peer on the basis of the protocol metadata at the current end, it can be judged whether the unidirectional encrypted traffic at the current end is malicious traffic; this method combines multiple characteristics of the current end and the peer, and can improve the accuracy of predicting whether the unidirectional encrypted traffic at the current end is malicious encrypted traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the background art, the following will describe the drawings required to be used in the embodiments of the present invention or the background art.

[0022] Figure 1 The flowchart of a method for detecting malicious traffic provided by an embodiment of the present invention is shown;

[0023] Figure 2 The flowchart of the specific method for determining the ACK value to obtain the ACK sequence in the method for detecting malicious traffic provided by an embodiment of the present invention is shown;

[0024] Figure 3 The flowchart of the specific method for training to obtain a prediction model in the method for detecting malicious traffic provided by an embodiment of the present invention is shown;

[0025] Figure 4 A detailed flowchart of a method for detecting malicious traffic provided by an embodiment of the present invention is shown;

[0026] Figure 5 The structural schematic diagram of a device for detecting malicious traffic provided by an embodiment of the present invention is shown;

[0027] Figure 6The structural schematic diagram of an electronic device provided by an embodiment of the present invention is shown. Detailed implementation manners

[0028] The embodiments of the present invention will be described below with reference to the accompanying drawings in the embodiments of the present invention.

[0029] Figure 1 The flowchart of a method for detecting malicious traffic provided by an embodiment of the present invention is shown. As Figure 1 shown, the method includes the following steps 101-104.

[0030] Step 101: Obtain a plurality of sample one-way encrypted traffic. The sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, and the sample one-way encrypted traffic includes protocol metadata and a plurality of protocol packets.

[0031] Among them, the one-way encrypted traffic represents the traffic sent by any end in a TLS (Transport Layer Security) session. One end can be regarded as the client and the other end as the server, and the two ends in the TLS session can be represented by the client or the server respectively; obtain a plurality of one-way encrypted traffic transmitted in the TLS session during normal Internet access, and use the one-way encrypted traffic during normal Internet access as the normal encrypted traffic; obtain a plurality of one-way encrypted traffic transmitted in the TLS session generated by malicious software, and use the one-way encrypted traffic generated by the malicious software as the malicious encrypted traffic; regard the obtained plurality of normal encrypted traffic and the plurality of malicious encrypted traffic as sample one-way encrypted traffic, and extract the protocol metadata and protocol packets of the sample one-way encrypted traffic. The protocol packet can be, for example, a TCP (Transmission Control Protocol) data packet. For example, the protocol metadata can specifically be the ssl / tls protocol version, the length of the client handshake part, the number of client-supported cipher suites, the list of client-supported cipher suites, the length of the client extension item, the number of client extension items, the list of client extension items, whether the client Session ID is empty, the length of the server handshake part, the length of the server extension item, the number of server extension items, the list of server extension items, whether the server Session ID is empty, and so on. Among them, the method of extracting protocol metadata and protocol packets belongs to a mature means in the art, and the present embodiment does not limit the above-mentioned obtaining means. In addition to obtaining the protocol metadata of the sample one-way encrypted traffic, the present embodiment also obtains the protocol packets of the sample one-way encrypted traffic, that is, TCP data packets. By collecting a variety of data that can represent the attributes of the one-way encrypted traffic, more bases are provided for subsequent judgment and classification of the one-way encrypted traffic.

[0032] Step 102: Determine the ACK values in the protocol packets of the sample one-way encrypted traffic, and sort the ACK values in chronological order to obtain an ACK sequence.

[0033] Among them, when sending a protocol packet, the protocol packet can contain various data such as a sequence number, the transmitted information, an ACK (Acknowledgement) value, etc. The ACK value represents the size of the cumulative data amount received from the peer. In this embodiment, the ACK values in multiple protocol packets of the sample one-way encrypted traffic are extracted, and the multiple extracted ACK values are sorted in the chronological order of transmission to obtain an ACK sequence.

[0034] Optionally, as shown in Figure 2 Step 102 can be specifically implemented according to the following steps 1021-1022.

[0035] Step 1021: Set the ACK value of the first protocol packet of the sample one-way encrypted traffic as the first element A1 of the ACK sequence.

[0036] Among them, a TLS session is a session jointly established by the first end and the second end. The ACK value of the first protocol packet of the sample one-way encrypted traffic can be determined by the way of establishing a connection through TCP three-way handshake, and this ACK value is used as the first element A1 of the ACK sequence; for example, the ACK in the TCP data packet sent by the first end when successfully establishing a connection request can be set as the first element A1 of the ACK sequence of this first end.

[0037] Step 1022: Determine the ACK values of multiple other protocol packets of the sample one-way encrypted traffic, sort the ACK values of the multiple other protocol packets in chronological order and sequentially set them as the corresponding elements A2, A3... An of the ACK sequence n , to obtain an ACK sequence {A1, A2,..., An} n}.

[0038] After obtaining the first element A1 of the above ACK sequence, sort the ACK values of multiple protocol packets in the sample one-way encrypted traffic in the chronological order of sending protocol packets. For example, in the sample one-way encrypted traffic of the first end, sort the ACK values included in each TCP data packet sent by the first end to the second end in the chronological order of sending, and correspondingly set the remaining elements A2, A3... An in the ACK sequence n , to obtain an ACK sequence {A1, A2,..., An} n , where n is the total number of ACK values in the sample one-way encrypted traffic.

[0039] Step 103: Determine the difference between two adjacent ACK values in the ACK sequence, and determine the eigenvalue of the sample one-way encrypted traffic according to multiple such differences.

[0040] In the embodiment of the present invention, each element starting from the second element in the ACK sequence is successively subtracted from the previous element to obtain the difference between two adjacent elements in the ACK sequence, that is, the difference A between two adjacent ACK values in the ACK sequence. i -A i-1 ; For example, for the sample one-way encrypted traffic at the first end, the difference in the ACK value represents the size of the data sent by the second end received at the first end. Therefore, in the case where the one-way encrypted traffic does not contain peer information, in this embodiment, the size of the data sent by the peer each time can also be known through the difference in the ACK value. Moreover, by performing various operations on the difference in the ACK value, various eigenvalues of the difference in the ACK value can be obtained, and the various eigenvalues of the difference in the ACK value can represent the characteristics of the peer of the sample one-way encrypted traffic. For example, after a session is established between the first end and the second end, the second end is the peer of the first end, and the eigenvalue of the sample one-way encrypted traffic at the first end can represent the characteristics of the second end.

[0041] Optionally, the eigenvalue includes one or more of the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, Markov transition probability, etc. of the difference. For example, by statistically calculating the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, Markov transition probability, etc. of the difference in the ACK value, various eigenvalues of the difference in the ACK value are obtained, and the eigenvalue of the sample one-way encrypted traffic is determined.

[0042] In the embodiment of the present invention, by calculating the difference in the ACK value, the size of the data transmitted by the missing peer's one-way encrypted traffic can be determined. And by performing various operations on the difference in the ACK value, such as the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, Markov transition probability, etc., more eigenvalues of the sample one-way encrypted traffic can be determined, and it is also more convenient to extract the characteristics of the peer from the difference.

[0043] Step 104: Train a prediction model based on the protocol metadata and the eigenvalue of the sample one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

[0044] Among them, through the processes described in the above steps 101-103, the protocol metadata and eigenvalue of the sample one-way encrypted traffic can be obtained. And the sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, that is, the label of the sample one-way encrypted traffic is normal encrypted traffic or malicious encrypted traffic. Therefore, by training the model according to the protocol metadata and eigenvalue of the collected sample one-way encrypted traffic, a prediction model can be obtained. The prediction model is a model that can predict whether the one-way encrypted traffic is malicious encrypted traffic. When it is necessary to predict whether a certain one-way encrypted traffic is malicious encrypted traffic, the one-way encrypted traffic is used as the target one-way encrypted traffic, and the protocol metadata and eigenvalue of the collected target one-way encrypted traffic are input into the prediction model. According to the output result of the prediction model, it can be determined whether the target one-way encrypted traffic is malicious encrypted traffic. Among them, the target one-way encrypted traffic can be any one-way encrypted traffic to be predicted in the network communication process; the prediction model is a model that can be used for classification, which can be an RNN (Recurrent Neural Network), etc. This embodiment does not make any limitations in this regard.

[0045] A method for detecting malicious traffic provided by an embodiment of the present invention not only obtains the protocol metadata of the one-way encrypted traffic for model training, but also obtains the ACK value of the protocol packet of the one-way encrypted traffic, sorts the ACK values in the order of sending time to obtain a sequence of ACK values, calculates the difference between two adjacent ACK values in the sequence, uses the difference of the ACK values to represent the size of the data sent by the missing or incomplete peer received, and performs various operations on the difference to determine multiple eigenvalues of the one-way encrypted traffic. This method is aimed at some special scenarios in the current network where only one-way encrypted traffic can be seen. For example, in the case of satellite links with uplink and downlink separation or incomplete two-way encrypted traffic due to packet loss, only the protocol metadata and eigenvalues of the one-way encrypted traffic need to be obtained, and based on the prediction model, it can be determined whether the one-way encrypted traffic is malicious encrypted traffic, overcoming the defect that the traditional solution can only predict two-way encrypted traffic and cannot predict one-way encrypted traffic. By calculating the difference of the ACK values, the size of the data transmitted by the missing peer's one-way encrypted traffic can be determined, and based on the information of the peer on the basis of the protocol metadata of the current end, it can be judged whether the one-way encrypted traffic of the current end is malicious traffic; this method combines various features of the current end and the peer, and can improve the accuracy of predicting whether the one-way encrypted traffic of the current end is malicious encrypted traffic.

[0046] Optionally, as shown in Figure 3 the above step 104 "training a prediction model according to the protocol metadata and the eigenvalue of the sample one-way encrypted traffic" further includes the following steps 301-303.

[0047] Step 301: Determine the device identifier of the sample one-way encrypted traffic, where the device identifier is consistent with the greeting message in the sample one-way encrypted traffic; the device identifier includes a client or a server, and the greeting message includes a client greeting message or a server greeting message.

[0048] Among them, when a session is established between a first end and a second end, one end can be regarded as a client and the other end as a server, and the client or the server is used to represent the two ends in the TLS session respectively; in addition to protocol packets, the sample one-way encrypted traffic also includes greeting messages, such as ClientHello (client greeting message) or ServerHello (server greeting message). For the specific meaning represented by this greeting message, the sample one-way encrypted traffic containing this greeting message is matched with the corresponding device identifier; among them, as described above, the greeting message can be a client greeting message or a server greeting message. Correspondingly, the device identifier is a client or a server. For example, when the greeting message in the sample one-way encrypted traffic is ClientHello (client greeting message), the sample one-way encrypted traffic represents the sample one-way encrypted traffic of the client; similarly, when the greeting message in the sample one-way encrypted traffic is ServerHello (server greeting message), the sample one-way encrypted traffic represents the sample one-way encrypted traffic of the server. Among them, some protocol metadata can be extracted from the greeting message. For example, the length of the client handshake part can be extracted from ClientHello.

[0049] Step 302: Train a prediction model for the device identifier based on the protocol metadata and the feature values of the sample one-way encrypted traffic.

[0050] Among them, when training the prediction model, it is trained based on the sample one-way encrypted traffic with the same device identifier to generate a prediction model for this device identifier. For example, when it is necessary to train a prediction model for the client, it is necessary to train based on the sample one-way encrypted traffic of the client, and at this time, the sample one-way encrypted traffic of the server is not required.

[0051] Step 303: When the greeting message in the target one-way encrypted traffic is consistent with the device identifier, predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model of the device identifier.

[0052] When it is necessary to predict whether a certain one-way encrypted traffic is malicious encrypted traffic, the one-way encrypted traffic is used as the target one-way encrypted traffic, and the greeting message of the target one-way encrypted traffic is identified. When the greeting message of the target one-way encrypted traffic is consistent with the device identifier, the protocol metadata and feature values of the target one-way encrypted traffic are collected and input into the prediction model of the device identifier. According to the output result of the prediction model, it can be determined whether the target one-way encrypted traffic is malicious encrypted traffic. For example, if the device identifier of the prediction model is the client, when the greeting message of the target one-way encrypted traffic to be predicted is ClientHello (client greeting message), that is, the target one-way encrypted traffic is the target one-way encrypted traffic of the client, and the target one-way encrypted traffic is consistent with the device identifier; the protocol metadata and feature values of the target one-way encrypted traffic are collected and input into the prediction model of the client, and according to the output result of the prediction model of the client, it can be determined whether the target one-way encrypted traffic is malicious encrypted traffic.

[0053] In this embodiment, by identifying the greeting message in the sample one-way encrypted traffic, the device identifier consistent with the greeting message is set for the sample one-way encrypted traffic. Based on the device identifier, the sample one-way encrypted traffic can be specifically divided. For the sample one-way encrypted traffic with the same device identifier, data is collected and the prediction model of the device identifier is constructed. During training, the sample one-way encrypted traffic can be preliminarily classified in advance, and then only the prediction model of the sample one-way encrypted traffic with one device identifier is constructed, so that the target one-way encrypted traffic with a specific device identifier can be predicted targeted, and the prediction accuracy can be improved.

[0054] Optionally, the method may further include: setting a corresponding prediction model for each of the device identifiers. Among them, the prediction models of each device identifier can be determined respectively based on the above steps 301-302. After setting multiple prediction models, then execute the above step 104 "predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model". At this time, the above step 104 "predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model" may include:

[0055] Select the prediction model whose device identifier is consistent with the greeting message in the target one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the selected prediction model.

[0056] Among them, based on the processes described in the above steps 301-302, a prediction model corresponding to each device identifier is further set, and the prediction models of these different device identifiers are saved respectively; when it is necessary to predict whether the target one-way encrypted traffic is malicious encrypted traffic, the prediction model of the device identifier consistent with the greeting message in the target one-way encrypted traffic can be directly selected for prediction, so as to more specifically predict and classify the target one-way encrypted traffic.

[0057] In this embodiment, independent prediction models are trained respectively, and different prediction models correspond to different device identifiers; by selecting the prediction model of the device identifier matching the greeting message included in the target one-way encrypted traffic for prediction, in the case of incomplete two-way traffic or only one-way traffic existing, the protocol metadata and characteristic values of the collected target one-way encrypted traffic are directly input into the prediction model matching it for prediction, so as to adapt to the prediction requirements of one-way encrypted traffic at different ends, effectively reduce the error rate of the prediction result, and improve the prediction accuracy.

[0058] Optionally, predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model includes: inputting the protocol metadata and characteristic values of the target one-way encrypted traffic into the prediction model, and determining whether the target one-way encrypted traffic is malicious encrypted traffic according to the output result of the prediction model.

[0059] In the embodiment of the present invention, by adopting the above technical solution, when there is a situation of incomplete two-way traffic or only one-way traffic in network communication, only by extracting the protocol metadata and characteristic values of the target one-way encrypted traffic as input, it can be determined whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model. Such a method can effectively and more accurately predict the result, avoiding the drawbacks in the traditional technology that it is easy to cause incomplete or incorrect feature extraction due to traffic loss, and then resulting in a relatively low accuracy of the prediction of the machine learning model. The range of types of predictable encrypted traffic is expanded from complete and standardized two-way encrypted traffic to one-way encrypted traffic that can also be predicted, improving the limitations in the field of encrypted traffic prediction.

[0060] Next, the method flow for detecting malicious traffic is introduced in detail through an embodiment. See Figure 4 As shown, the method includes the following steps 401-407.

[0061] Step 401: Obtain the protocol metadata and protocol packets of multiple sample one-way encrypted traffic, determine the greeting message in the protocol packets of the sample one-way encrypted traffic, and determine the device identifier of the sample one-way encrypted traffic.

[0062] Among them, based on the process described in step 101 above, protocol metadata and protocol packets of multiple sample one-way encrypted traffic can be obtained; the sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic; the greeting message includes a client greeting message or a server greeting message; the device identifier is a client or a server.

[0063] Step 402: Obtain the ACK values in the protocol packets of the sample one-way encrypted traffic, sort the ACK values in chronological order to obtain an ACK sequence.

[0064] Step 403: Determine the difference between two adjacent ACK values in the ACK sequence, and determine the characteristic value of the sample one-way encrypted traffic based on multiple differences.

[0065] Among them, the characteristic values of the sample one-way encrypted traffic include the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, Markov transition probability, etc. of the difference of the ACK values. The specific process of obtaining and processing the difference of the ACK values can refer to the relevant content of steps 102-103 above, which will not be elaborated here.

[0066] Step 404: For the device identifiers corresponding to the greeting messages in the protocol packets of the sample one-way encrypted traffic respectively, construct a prediction model for different device identifiers that can predict whether the sample one-way encrypted traffic is malicious encrypted traffic.

[0067] Among them, when the greeting message in the protocol packet of the sample one-way encrypted traffic is a client greeting message, the model is trained based on the protocol metadata and characteristic values of the sample one-way encrypted traffic to obtain a client prediction model; when the greeting message in the protocol packet of the sample one-way encrypted traffic is a server greeting message, the model is trained in the same way to obtain a server prediction model; the specific process can refer to the method described in steps 301-302 above, which will not be elaborated here.

[0068] Step 405: Obtain the protocol metadata and protocol packets of the target one-way encrypted traffic.

[0069] Step 406: Identify the greeting message in the protocol packet of the target one-way encrypted traffic, select the prediction model of the device identifier that is consistent with the greeting message, input the obtained protocol metadata and protocol packets of the target one-way encrypted traffic into the prediction model, and predict whether the target one-way encrypted traffic is malicious encrypted traffic according to the output result of the prediction model. For example, when the greeting message in the protocol packet of the target one-way encrypted traffic is ClientHello (client greeting message), then the greeting message corresponds to the prediction model of the client, and at this time, the prediction is based on the prediction model of the client.

[0070] Step 407: End the prediction.

[0071] An embodiment of the present invention provides a device for detecting malicious traffic. Refer to Figure 5 As shown, the device includes: an acquisition module 51, a statistics module 52, an operation module 53, and a processing module 54.

[0072] The acquisition module 51: is used to acquire multiple sample one-way encrypted traffic. The sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, and the sample one-way encrypted traffic includes protocol metadata and multiple protocol packets.

[0073] The statistics module 52: is used to determine the ACK values in the protocol packets of the sample one-way encrypted traffic, sort the ACK values in chronological order, and obtain an ACK sequence.

[0074] The operation module 53: is used to determine the difference between two adjacent ACK values in the ACK sequence, and determine the characteristic value of the sample one-way encrypted traffic according to multiple such differences.

[0075] The processing module 54: is used to train a prediction model based on the protocol metadata and the characteristic value of the sample one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

[0076] Optionally, the statistics module 52 includes: a setting unit and a sorting unit.

[0077] The setting unit is used to set the ACK value of the first protocol packet of the sample one-way encrypted traffic as the first element A1 of the ACK sequence.

[0078] The sorting unit is used to determine the ACK values of multiple other protocol packets of the sample one-way encrypted traffic, sort the ACK values of the multiple other protocol packets in chronological order and sequentially set them as the corresponding elements A2, A3... A n , to obtain an ACK sequence {A1, A2,..., A n}}.

[0079] Optionally, the processing module 54 includes: a first processing unit, a second processing unit, and a third processing unit.

[0080] The first processing unit is used to determine the device identifier of the sample one-way encrypted traffic, and the device identifier is consistent with the greeting message in the sample one-way encrypted traffic; the device identifier includes a client or a server, and the greeting message includes a client greeting message or a server greeting message.

[0081] The second processing unit is used to train a prediction model of the device identifier according to the protocol metadata and the characteristic value of the sample one-way encrypted traffic.

[0082] The third processing unit is configured to predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model of the device identifier when the greeting message in the target one-way encrypted traffic is consistent with the device identifier.

[0083] Optionally, the processing module 54 is further configured to: set a corresponding prediction model for each of the device identifiers. Wherein, the processing module 54 "predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model" includes: selecting a prediction model in which the device identifier is consistent with the greeting message in the target one-way encrypted traffic, and predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the selected prediction model.

[0084] Optionally, the eigenvalue determined by the operation module 53 includes one or more of the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, and Markov transition probability of the difference.

[0085] Optionally, the processing module 54 "predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model" includes: inputting the protocol metadata and eigenvalue of the target one-way encrypted traffic into the prediction model, and determining whether the target one-way encrypted traffic is malicious encrypted traffic according to the output result of the prediction model.

[0086] A device for detecting malicious traffic provided by an embodiment of the present invention not only obtains the protocol metadata of the one-way encrypted traffic for model training, but also obtains the ACK value of the protocol packet of the one-way encrypted traffic, sorts the ACK values in the order of sending time, obtains a sequence of ACK values, calculates the difference between two adjacent ACK values in the sequence, uses the difference of the ACK values to represent the size of the data sent by the missing or incomplete peer received, and performs various operations on the difference to determine multiple eigenvalues of the one-way encrypted traffic. This method is aimed at some special scenarios in the current network where only one-way encrypted traffic can be seen, for example, satellite links with uplink and downlink separation or situations where two-way encrypted traffic is incomplete due to packet loss. Only by obtaining the protocol metadata and eigenvalues of the one-way encrypted traffic, it can be determined whether the one-way encrypted traffic is malicious encrypted traffic based on the prediction model, overcoming the defect in the traditional solution that can only predict two-way encrypted traffic and cannot predict one-way encrypted traffic. By calculating the difference of the ACK values, the size of the data transmitted by the missing one-way encrypted traffic of the peer can be determined, and based on the information of the peer on the basis of the protocol metadata of the current end, it can be judged whether the one-way encrypted traffic of the current end is malicious traffic; this method combines various features of the current end and the peer, and can improve the accuracy of predicting whether the one-way encrypted traffic of the current end is malicious encrypted traffic.

[0087] In addition, an embodiment of the present invention further provides an electronic device, which includes a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. The transceiver, the memory, and the processor are respectively connected through the bus. When the computer program is executed by the processor, it implements each process of the above method embodiment for detecting malicious traffic and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0088] Specifically, referring to Figure 6 As shown, an embodiment of the present invention further provides an electronic device, which includes a bus 1110, a processor 1120, a transceiver 1130, a bus interface 1140, a memory 1150, and a user interface 1160.

[0089] In an embodiment of the present invention, the electronic device further includes: a computer program stored on the memory 1150 and executable on the processor 1120. When the computer program is executed by the processor 1120, it implements each process of the above method embodiment for detecting malicious traffic.

[0090] The transceiver 1130 is used to receive and send data under the control of the processor 1120.

[0091] In an embodiment of the present invention, the bus architecture (represented by the bus 1110), the bus 1110 may include any number of interconnected buses and bridges. The bus 1110 connects various circuits including one or more processors represented by the processor 1120 and the memory represented by the memory 1150 together.

[0092] The bus 1110 represents one or more of any of several types of bus structures, including a memory bus and a memory controller, a peripheral bus, an Accelerate Graphical Port (AGP), a processor, or a local bus using any bus structure in various bus architectures. By way of example and not limitation, such architectures include: Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Enhanced ISA (EISA) bus, Video Electronics Standards Association (VESA), Peripheral Component Interconnect (PCI) bus.

[0093] The processor 1120 may be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments may be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above-mentioned processor includes: general-purpose processor, central processing unit (CPU), network processor (NP), digital signal processor (DSP), application specific integrated circuit (ASIC), field programmable gate array (FPGA), complex programmable logic device (CPLD), programmable logic array (PLA), microcontroller unit (MCU), or other programmable logic devices, discrete gates, transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. For example, the processor may be a single-core processor or a multi-core processor, and the processor may be integrated on a single chip or located on multiple different chips.

[0094] The processor 1120 may be a microprocessor or any conventional processor. The method steps disclosed in combination with the embodiments of the present invention may be directly executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a readable storage medium well-known in the art such as random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), registers, etc. The readable storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0095] The bus 1110 may also connect together various other circuits such as, for example, peripheral devices, voltage regulators, or power management circuits. The bus interface 1140 provides an interface between the bus 1110 and the transceiver 1130, which are all well-known in the art. Therefore, the embodiments of the present invention will not further describe them.

[0096] The transceiver 1130 can be a single component or multiple components, such as multiple receivers and transmitters, providing units for communicating with various other devices over a transmission medium. For example, the transceiver 1130 receives external data from other devices, and the transceiver 1130 is used to send the data processed by the processor 1120 to other devices. Depending on the nature of the computer system, a user interface 1160 may also be provided, such as: a touch screen, a physical keyboard, a display, a mouse, speakers, a microphone, a trackball, a joystick, a stylus.

[0097] It should be understood that in the embodiments of the present invention, the memory 1150 may further include memories remotely located relative to the processor 1120, and these remotely located memories can be connected to the server through a network. One or more parts of the above networks can be an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless local area network (WLAN), a wide area network (WAN), a wireless wide area network (WWAN), a metropolitan area network (MAN), the Internet, a public switched telephone network (PSTN), a plain old telephone service network (POTS), a cellular telephone network, a wireless network, a Wi-Fi network, and a combination of two or more of the above networks. For example, the cellular telephone network and the wireless network can be a Global System for Mobile Communications (GSM) system, a Code Division Multiple Access (CDMA) system, a Worldwide Interoperability for Microwave Access (WiMAX) system, a General Packet Radio Service (GPRS) system, a Wideband Code Division Multiple Access (WCDMA) system, a Long Term Evolution (LTE) system, an LTE Frequency Division Duplex (FDD) system, an LTE Time Division Duplex (TDD) system, an Advanced Long Term Evolution (LTE-A) system, a Universal Mobile Telecommunications System (UMTS) system, an Enhance Mobile Broadband (eMBB) system, a massive Machine Type of Communication (mMTC) system, an UltraReliable Low Latency Communications (uRLLC) system, etc.

[0098] It should be understood that the memory 1150 in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory includes: Read-Only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically Erasable PROM (EEPROM), or Flash Memory.

[0099] The volatile memory includes: Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as: Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). The memory 1150 of the electronic device described in the embodiments of the present invention includes, but is not limited to, the above and any other suitable types of memory.

[0100] In the embodiments of the present invention, the memory 1150 stores the following elements of the operating system 1151 and the application program 1152: executable modules, data structures, or subsets thereof, or extended sets thereof.

[0101] Specifically, the operating system 1151 includes various system programs, such as: framework layer, core library layer, driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application program 1152 includes various application programs, such as: Media Player, Browser, for implementing various application services. The program for implementing the method of the embodiments of the present invention may be included in the application program 1152. The application program 1152 includes: applets, objects, components, logics, data structures, and other computer system executable instructions for performing specific tasks or implementing specific abstract data types.

[0102] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each process of the above method embodiment for detecting malicious traffic and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0103] A computer-readable storage medium includes: permanent and non-permanent, removable and non-removable media, which are tangible devices that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium includes: electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, and any suitable combination of the above. A computer-readable storage medium includes: phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tape storage, magnetic tape disk storage or other magnetic storage devices, memory sticks, mechanical encoding devices (such as punched cards or raised structures in grooves on which instructions are recorded) or any other non-transmission medium that can be used to store information accessible by a computing device. As defined in the embodiments of the present invention, a computer-readable storage medium does not include transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagated through waveguides or other transmission media (such as light pulses passing through fiber optic cables), or electrical signals transmitted through wires.

[0104] In several embodiments provided in the present application, it should be understood that the disclosed devices, electronic devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can also be in the form of electrical, mechanical, or other connections.

[0105] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units. They can be located in one position or distributed to multiple network units. Some or all of the units can be selected according to actual needs to solve the problems to be solved by the solution of the embodiments of the present invention.

[0106] In addition, in each embodiment of the present invention, each functional unit may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0107] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (including: a personal computer, a server, a data center or other network devices) to execute all or part of the steps of the methods described in each embodiment of the present invention. And the above-mentioned storage medium includes various media that can store program codes as listed above.

[0108] In the description of the embodiments of the present invention, those skilled in the art should know that the embodiments of the present invention can be implemented as a method, a device, an electronic device, and a computer-readable storage medium. Therefore, the embodiments of the present invention can be specifically implemented in the following forms: completely hardware, completely software (including firmware, resident software, microcode, etc.), and a combination of hardware and software. In addition, in some embodiments, the embodiments of the present invention can also be implemented in the form of a computer program product in one or more computer-readable storage media, and the computer-readable storage medium contains computer program codes.

[0109] The above-mentioned computer-readable storage media may adopt any combination of one or more computer-readable storage media. Computer-readable storage media include: electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media include: portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs), flash memories, optical fibers, compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any combination of the above. In the embodiments of the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or component.

[0110] The computer program code included in the above computer-readable storage medium can be transmitted by any suitable medium, including: wireless, wire, optical cable, radio frequency (RF), or any suitable combination of the above.

[0111] The computer program code for performing the operations of the embodiments of the present invention can be written in assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, status setting data, integrated circuit configuration data, or in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as C language or similar programming languages. The computer program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, and entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including: local area network (LAN) or wide area network (WAN), and can also be connected to an external computer.

[0112] The embodiments of the present invention describe the provided methods, apparatuses, and electronic devices through flowcharts and / or block diagrams.

[0113] It should be understood that each block of the flowchart and / or block diagram, and the combinations of blocks in the flowchart and / or block diagram, can be implemented by computer-readable program instructions. These computer-readable program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine. These computer-readable program instructions, when executed by a computer or other programmable data processing device, produce an apparatus for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0114] These computer-readable program instructions can also be stored in a computer-readable storage medium that enables a computer or other programmable data processing device to work in a specific manner. In this way, the instructions stored in the computer-readable storage medium produce an instruction device product that includes the instructions for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0115] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to generate a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus can provide a process for realizing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0116] As described above, the specific implementation manners of the embodiments of the present invention are only described, but the protection scope of the embodiments of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the embodiments of the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the embodiments of the present invention. Therefore, the protection scope of the embodiments of the present invention shall be subject to the protection scope of the claims.

Claims

1. A method for detecting malicious traffic, characterized in that, Including: Obtain multiple sample one-way encrypted traffic, the sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, and the sample one-way encrypted traffic includes protocol metadata and multiple protocol packets; Determine the ACK values in the protocol packets of the sample one-way encrypted traffic, sort the ACK values in chronological order to obtain an ACK sequence; Determine the differences between two adjacent ACK values in the ACK sequence, and determine the characteristic values of the sample one-way encrypted traffic according to the multiple differences; Train a prediction model based on the protocol metadata and the characteristic values of the sample one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

2. The method according to claim 1, characterized in that, The determining the ACK values in the protocol packets of the sample one-way encrypted traffic, sorting the ACK values in chronological order to obtain an ACK sequence, includes: Set the ACK value of the first protocol packet of the sample one-way encrypted traffic as the first element A1 of the ACK sequence; Determine the ACK values of multiple other protocol packets of the unidirectional encrypted traffic of the sample, sort the ACK values of the multiple other protocol packets in chronological order and sequentially set them as the corresponding elements A2, A3... A of the ACK sequence n , to obtain the ACK sequence {A1, A2,..., A n}}.

3. The method according to claim 2, wherein The training a prediction model based on the protocol metadata and the characteristic values of the sample one-way encrypted traffic, and predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model, includes: Determine the device identifier of the sample one-way encrypted traffic, the device identifier is consistent with the greeting message in the sample one-way encrypted traffic; the device identifier includes a client or a server, and the greeting message includes a client greeting message or a server greeting message; Train a prediction model of the device identifier according to the protocol metadata and the characteristic values of the sample one-way encrypted traffic; When the greeting message in the target one-way encrypted traffic is consistent with the device identifier, predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model of the device identifier.

4. The method according to claim 3, characterized in that Also including: Set a corresponding prediction model for each device identifier; Wherein, the predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model includes: Select the prediction model whose device identifier is consistent with the greeting message in the target one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the selected prediction model.

5. The method according to claim 4, wherein The characteristic values include one or more of the maximum value, minimum value, average value, variance, coefficient of variation, number of elements, Markov transition probability of the differences.

6. The method according to any one of claims 1-5, characterized in that, The predicting whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model includes: Input the protocol metadata and characteristic values of the target one-way encrypted traffic into the prediction model, and determine whether the target one-way encrypted traffic is malicious encrypted traffic according to the output result of the prediction model.

7. A device for detecting malicious traffic, characterized in that, Including: An acquisition module, a statistics module, an operation module and a processing module; The acquisition module is used to obtain multiple sample one-way encrypted traffic, the sample one-way encrypted traffic is divided into normal encrypted traffic and malicious encrypted traffic, and the sample one-way encrypted traffic includes protocol metadata and multiple protocol packets; The statistical module is used to determine the ACK value in the protocol packet of the sample one-way encrypted traffic, sort the ACK values in chronological order to obtain an ACK sequence; The operation module is used to determine the difference between two adjacent ACK values in the ACK sequence, and determine the characteristic value of the sample one-way encrypted traffic according to multiple such differences; The processing module is used to train a prediction model based on the protocol metadata and the characteristic value of the sample one-way encrypted traffic, and predict whether the target one-way encrypted traffic is malicious encrypted traffic based on the prediction model.

8. The device according to claim 7, wherein The statistical module includes: a setting unit and a sorting unit; The setting unit is used to set the ACK value of the protocol packet as the first element A1 of the ACK sequence; The sorting unit is used to determine the ACK values of multiple protocol packets, sort the multiple ACK values in chronological order, and sequentially set them as the corresponding elements A2, A3,..., A of the ACK sequence n , to obtain the ACK sequence {A1, A2,..., A n}}.

9. An electronic device, comprising a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the transceiver, the memory, and the processor are connected via the bus, characterized in that, When the computer program is executed by the processor, it implements the steps in the method for detecting malicious traffic according to any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps in the method for detecting malicious traffic according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Flow detection method and equipment in unidirectional flow detection mode

    CN101795277A

  • A method and device for defending against DDoS attacks

    CN102291378A