Retrieval Method, Device, Storage Medium and Equipment for Suspicious Traffic

By generating metadata tables corresponding to the protocol type and filtering with the message header field, we can quickly and accurately retrieve suspicious traffic in massive data traffic, solving the problems of inefficient and inability to perform accurate search in the existing technology.

CN115664758BActive Publication Date: 2025-05-30CHINA CONSTRUCTION BANK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211278956.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-19
Publication Date
2025-05-30
Estimated Expiration
2042-10-19

AI Technical Summary

Technical Problem

Among massive data traffic, how to quickly and accurately retrieve suspicious traffic is inefficient and cannot accurately search in certain protocol messages or fields.

Method used

By saving the collected traffic packets into a preset database, a metadata table corresponding to each protocol type is generated, and the message header fields in the metadata table are filtered to obtain attack characteristics that match the search information entered by the user, thereby identifying and displaying suspicious traffic.

Benefits of technology

Accurate screening and display of suspicious traffic is realized, retrieval efficiency is improved, and the time cost of parsing all traffic data one by one is avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664758B_ABST
    Figure CN115664758B_ABST
Patent Text Reader

Abstract

The present application discloses a method, apparatus, storage medium, and device for retrieving suspicious traffic. The method is as follows: Save the data packets of each traffic data collected into a preset database; Based on each data packet in the preset database, obtain a metadata table corresponding to each protocol type; When it is determined that the retrieval information input by the user contains a feature field, obtain the metadata whose field value is the same as the feature field from the metadata table that meets the third preset condition as an attack feature; Identify the data packet containing the attack feature as suspicious traffic and display the suspicious traffic to the user through a preset interface. This method utilizes each metadata shown in the metadata table to achieve accurate screening of data packets, without the need to spend time cost parsing all traffic data one by one, effectively improving the retrieval efficiency of suspicious traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technologies, and in particular, to a method, device, storage medium, and equipment for retrieving suspicious traffic. Background Art

[0002] A network analysis system obtains data packets of required network traffic through mirroring, and stores, decodes, detects, analyzes, and diagnoses the data packets, which can help network security personnel locate suspicious traffic and avoid network intrusion risks. However, for large enterprises with complex network structures, how to quickly and accurately retrieve suspicious traffic from a large amount of data traffic is a very crucial retrieval method.

[0003] Currently, the commonly used suspicious traffic retrieval methods mainly use single IP, IP communication pairs, IP plus ports, and message content feature values, etc. These retrieval methods require knowing the accurate time point, IP address, or specific attack characteristics. In addition, when using feature values for retrieval, since it is not possible to retrieve in a certain protocol message or certain fields, it results in retrieving not only the message header but also all the content in the message body. If there is a large amount of page information or file picture information in the server's returned message, this will greatly increase the retrieval time.

[0004] Therefore, how to improve the retrieval efficiency of suspicious traffic has become an urgent problem to be solved in this field. Summary of the Invention

[0005] The present application provides a method, device, storage medium, and equipment for retrieving suspicious traffic, aiming to improve the retrieval efficiency of suspicious traffic.

[0006] To achieve the above object, the present application provides the following technical solutions:

[0007] A method for retrieving suspicious traffic includes:

[0008] Saving the data packets of each traffic data collected into a preset database;

[0009] Based on each of the data packets in the preset database, obtaining a metadata table corresponding to each protocol type; the metadata table includes a metadata set of each of the data packets; the metadata set includes multiple metadata and the field values of each metadata; the metadata represents the message header fields of the data packet;

[0010] When it is determined that the retrieval information input by the user includes a feature field, obtaining, from the metadata table that meets the third preset condition, the metadata whose field value is the same as the feature field as an attack feature; the third preset condition is that the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information;

[0011] Identify the data packet containing the attack feature as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0012] Optionally, obtaining a metadata table corresponding to each protocol type based on each of the data packets in the preset database includes:

[0013] Classify each of the data packets in the preset database to obtain data packet groups corresponding to each protocol type; among them, multiple data packets with the same protocol type will be divided into the same data packet group;

[0014] For each of the data packet groups, extract the header fields of each data packet in the data packet group to obtain a set of header fields for each data packet in the data packet group; the set of header fields includes multiple header fields and the field values of each of the header fields;

[0015] Generate a metadata table corresponding to each protocol type based on the set of header fields of each data packet in each of the data packet groups.

[0016] Optionally, the identifying the data packet containing the attack feature as suspicious traffic includes:

[0017] Pre-configure a region label and a time label for each of the data packets in the preset database; the region label indicates the front-end link from which the traffic data originates; the collection time indicates the collection time of the traffic data;

[0018] When it is determined that the retrieved information includes a time point, obtain the data packets that meet the first preset condition from the preset database as candidate data packets; the first preset condition is that the time difference between the collection time of the data packet and the time point indicated by the retrieved information is less than a preset time threshold;

[0019] When it is determined that the retrieved information includes a front-end link, screen out the candidate data packets that meet the second preset condition from the one or more candidate data packets obtained as valid data packets; the second preset condition is that the front-end link of the candidate data packet is the same as the front-end link indicated by the retrieved information;

[0020] Identify the valid data packet containing the attack feature as suspicious traffic.

[0021] Optionally, before identifying the valid data packet containing the attack feature as suspicious traffic, it further includes:

[0022] In the case where it is determined that the retrieved information does not contain the time point, traverse each data packet in the preset database in the order from the latest to the earliest collection time until a data packet containing the suspicious IP indicated by the retrieved information is obtained as the candidate data packet.

[0023] Optionally, before identifying the valid data packet containing the attack feature as suspicious traffic, it further includes:

[0024] In the case where it is determined that the retrieved information does not contain the front-end link, all the obtained candidate data packets are identified as the valid data packets.

[0025] Optionally, after filtering out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets in the case where it is determined that the retrieved information contains the front-end link, it further includes:

[0026] In the case where it is determined that the retrieved information contains any one or more elements in the five-tuple, obtain the valid data packets containing the elements indicated by the retrieved information from each of the valid data packets as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0027] Optionally, after filtering out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets in the case where it is determined that the retrieved information contains the front-end link, it further includes:

[0028] In the case where it is determined that the retrieved information does not contain the feature field, perform a feature value retrieval on each of the valid data packets to obtain the feature value of each valid data packet, and identify the valid data packets whose feature values contain a preset sensitive field as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0029] A retrieval device for suspicious traffic includes:

[0030] A traffic collection unit, configured to save the data packets of each traffic data collected into a preset database;

[0031] A metadata acquisition unit, configured to obtain a metadata table corresponding to each protocol type based on each of the data packets in the preset database; the metadata table includes a metadata set of each of the data packets; the metadata set includes multiple metadata and the field values of each metadata; the metadata represents the packet header fields of the data packet.

[0032] A metadata query unit, configured to, when determining that the retrieval information input by the user includes a feature field, obtain, from the metadata table that meets the third preset condition, metadata with a field value the same as the feature field as an attack feature; the third preset condition is that the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information.

[0033] A traffic screening unit, configured to identify data packets containing the attack feature as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0034] A computer-readable storage medium, including a stored program, where the program, when run by a processor, executes the method for retrieving suspicious traffic described above.

[0035] A device for retrieving suspicious traffic, including: a processor, a memory, and a bus; the processor is connected to the memory through the bus;

[0036] The memory is used to store a program, and the processor is used to run the program, where the program, when run by the processor, executes the method for retrieving suspicious traffic described above.

[0037] The technical solution provided by this application saves the data packets of each traffic data collected into a preset database. Based on each data packet in the preset database, a metadata table corresponding to each protocol type is obtained. When determining that the retrieval information input by the user includes a feature field, metadata with a field value the same as the feature field is obtained from the metadata table that meets the third preset condition as an attack feature. The data packets containing the attack feature are identified as suspicious traffic and the suspicious traffic is displayed to the user through a preset interface. This application uses each metadata shown in the metadata table to achieve accurate screening of data packets, without spending time cost to parse all traffic data one by one, effectively improving the retrieval efficiency of suspicious traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0039] Figure 1 It is a flowchart of a method for retrieving suspicious traffic provided by an embodiment of the present application;

[0040] Figure 2Schematic flowchart of another method for retrieving suspicious traffic provided by an embodiment of the present application;

[0041] Figure 3 Schematic architecture diagram of a device for retrieving suspicious traffic provided by an embodiment of the present application. Detailed implementation manners

[0042] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0043] As Figure 1 shown, it is a schematic flowchart of a method for retrieving suspicious traffic provided by an embodiment of the present application, including the following steps.

[0044] S101: Use a preset traffic collection tool to mirror each traffic data from different front-end links to obtain data packets of each traffic data.

[0045] Among them, the preset traffic collection tool includes, but is not limited to, the Data Plane Development Kit (DPDK).

[0046] S102: Save each data packet into a preset database, and configure a region label and a time label for each data packet.

[0047] Among them, the region label indicates the front-end link from which the traffic data comes. The time label is used to indicate the collection time of the traffic data.

[0048] S103: Classify each data packet in the preset database to obtain data packet groups corresponding to each protocol type.

[0049] Among them, multiple data packets with the same protocol type will be classified into the same data packet group.

[0050] It should be noted that each protocol type includes, but is not limited to, the HTTP protocol, the ICMP protocol, the DNS protocol, the POP3 protocol, etc.

[0051] S104: For each data packet group, extract the header fields of each data packet in the data packet group to obtain a set of header fields of each data packet in the data packet group.

[0052] Among them, the set of header fields includes multiple header fields and the field values of each header field.

[0053] Specifically, taking the data packets in the data packet groups corresponding to the HTTP protocol as an example, the respective header fields of the data packets include but are not limited to: URI, request method, Host, status code, XFF, Location, Referer, Useragent, cookie, etc.

[0054] S105: Generate a metadata table corresponding to each protocol type based on the set of header fields of each data packet in each data packet group.

[0055] Among them, the metadata table includes a set of metadata for each data packet in the data packet group. The set of metadata includes multiple metadata and the field values of each metadata, and the metadata represents the header fields.

[0056] Specifically, taking the data packet group corresponding to the http protocol as an example, the metadata shown in the metadata table can be referred to Table 1.

[0057] Table 1

[0058]

[0059]

[0060] It should be noted that the content shown in the above Table 1 is only for illustrative purposes.

[0061] S106: Parse the traffic query command input by the user to obtain retrieval information.

[0062] Among them, when suspicious traffic appears in the business system, the business system will give an alarm prompt. The user inputs a traffic query command based on the alarm prompt to capture the suspicious traffic.

[0063] S107: When it is determined that the retrieval information contains a time point, obtain the data packets that meet the first preset condition from the preset database as candidate data packets.

[0064] Among them, the first preset condition is: the time difference between the collection time of the data packet and the time point shown in the retrieval information is less than the preset time threshold.

[0065] Optionally, when it is determined that the retrieval information does not contain a time point, then traverse each data packet in the preset database in the order from the latest to the earliest collection time until a data packet containing the suspicious IP shown in the retrieval information is obtained as the candidate data packet.

[0066] Specifically, assuming that the retrieved information does not contain a time point, the time of the day when the traffic query command is sent is used as the query starting point. For example, if there is a suspicious IP at 5 o'clock today, then first query the time period from 0:00 to 5:00 today to see if there is relevant traffic (i.e., data packets). If not, query from 0:00 yesterday to 0:00 today, and then from 0:00 the day before yesterday to 0:00 yesterday, pushing forward day by day until the farthest storage time point of the data packets. For example, if the original traffic storage time in some regions is only three or four days, then it can only be pushed forward three or four days for query to see if there is relevant traffic. If not, it indicates that the traffic data has been rolled back.

[0067] It should be noted that the above specific implementation process is only for illustrative purposes.

[0068] S108: When it is determined that the retrieved information includes the front-end link, from the one or more candidate data packets obtained, filter out the candidate data packets that meet the second preset condition as valid data packets.

[0069] Among them, the second preset condition is that the front-end link of the candidate data packet is the same as the front-end link shown in the retrieved information.

[0070] Optionally, when it is determined that the retrieved information does not include the front-end link, all the candidate data packets obtained are marked as valid data packets.

[0071] S109: When it is determined that the retrieved information includes a feature field, obtain the metadata with a field value the same as the feature field from the metadata table that meets the third preset condition as the attack feature.

[0072] Among them, the third preset condition is that the protocol type corresponding to the data packet group to which the metadata table belongs is the same as the protocol type shown in the retrieved information.

[0073] It should be noted that the feature field included in the retrieved information, such as the common directory traversal attack, the attack feature / etc / passwd can be seen in the message header url. Based on this feature, suspicious traffic (i.e., the data packets containing the attack feature mentioned below) can be captured using the metadata of the http protocol.

[0074] Optionally, when it is determined that the retrieved information includes any one or more elements in the five-tuple, obtain the valid data packets containing the elements shown in the retrieved information from each valid data packet as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0075] It should be noted that the five-tuple includes the source IP, destination IP, source port, destination port, and transport layer protocol.

[0076] Optionally, when it is determined that the retrieved information does not contain the feature field, retrieve the feature value for each valid data packet to obtain the feature value of each valid data packet, and identify the valid data packet whose feature value contains the preset sensitive field as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0077] S110: Identify the valid data packet containing the attack feature as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0078] Based on the process shown in S101 - S110 above, this embodiment can customize the selection of some fields in the headers of individual protocol data packets to generate a metadata table, and establish a corresponding retrieval relationship with the traffic data. When performing retrieval, certain fields in the request header can be specified to perform precise screening using logical relationships of AND, OR, and NOT. Compared with performing a full - scale search in the request header and request body, this embodiment can not only improve the retrieval efficiency but also achieve precise positioning.

[0079] In summary, this embodiment uses each metadata shown in the metadata table to achieve accurate screening of data packets, without consuming time costs to parse all traffic data one by one, effectively improving the retrieval efficiency of suspicious traffic.

[0080] It should be noted that S101 mentioned in the above embodiment is an optional implementation manner of the retrieval method of suspicious traffic shown in the embodiments of the present application. In addition, S106 mentioned in the above embodiment is also an optional implementation manner of the retrieval method of suspicious traffic shown in the embodiments of the present application. Therefore, the process mentioned in the above embodiment can be summarized as Figure 2 the method shown.

[0081] As Figure 2 shown, it is a schematic flowchart of another retrieval method of suspicious traffic provided by the embodiments of the present application, including the following steps.

[0082] S201: Save the data packets of each traffic data collected into a preset database.

[0083] S202: Obtain a metadata table corresponding to each protocol type based on each data packet in the preset database.

[0084] Among them, the metadata table includes a metadata set of each data packet; the metadata set includes multiple metadata and the field values of each metadata; the metadata represents the message header field of the data packet.

[0085] S203: When it is determined that the retrieved information input by the user contains the feature field, obtain the metadata whose field value is the same as the feature field from the metadata table that meets the third preset condition as the attack feature.

[0086] Among them, the third preset condition is that the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information.

[0087] S204: Identify the data packet containing the attack feature as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0088] In summary, this embodiment utilizes each metadata shown in the metadata table to achieve accurate screening of data packets, without the need to spend time cost parsing all traffic data one by one, effectively improving the retrieval efficiency of suspicious traffic.

[0089] Corresponding to the method for retrieving suspicious traffic provided in the embodiment of the present application above, the embodiment of the present application also provides a device for retrieving suspicious traffic.

[0090] As Figure 3 shown, it is a schematic structural diagram of a device for retrieving suspicious traffic provided in the embodiment of the present application, including the following units.

[0091] A traffic collection unit 100, configured to save the data packets of each traffic data collected into a preset database.

[0092] A metadata acquisition unit 200, configured to obtain a metadata table corresponding to each protocol type based on each data packet in the preset database; the metadata table includes a metadata set of each data packet; the metadata set includes multiple metadata and the field values of each metadata; the metadata represents the message header fields of the data packet.

[0093] Optionally, the metadata acquisition unit 200 is specifically configured to: classify each data packet in the preset database to obtain data packet groups corresponding to each protocol type; among them, multiple data packets with the same protocol type will be divided into the same data packet group; for each data packet group, extract the message header fields of each data packet in the data packet group to obtain a message header field set of each data packet in the data packet group; the message header field set includes multiple message header fields and the field values of each message header field; based on the message header field sets of each data packet in each data packet group, generate a metadata table corresponding to each protocol type.

[0094] A metadata query unit 300, configured to, when determining that the retrieval information input by the user includes a feature field, obtain, from the metadata table that meets the third preset condition, the metadata whose field value is the same as the feature field as the attack feature; the third preset condition is that the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information.

[0095] The traffic screening unit 400 is used to identify the data packets containing attack features as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0096] Optionally, the traffic screening unit 400 is specifically configured to: pre-configure an area label and a time label for each data packet in a preset database; the area label indicates the front-end link from which the traffic data originates; the collection time indicates the collection time of the traffic data; when it is determined that the retrieval information input by the user contains a time point, obtain the data packets that meet the first preset condition from the preset database as candidate data packets; the first preset condition is that the time difference between the collection time of the data packet and the time point indicated by the retrieval information is less than a preset time threshold; when it is determined that the retrieval information contains a front-end link, screen out the candidate data packets that meet the second preset condition from the obtained one or more candidate data packets as valid data packets; the second preset condition is that the front-end link of the candidate data packet is the same as the front-end link indicated by the retrieval information; identify the valid data packets containing attack features as suspicious traffic.

[0097] The traffic screening unit 400 is further configured to: when it is determined that the retrieval information does not contain a time point, traverse each data packet in the preset database in descending order of collection time until a data packet containing the suspicious IP indicated by the retrieval information is obtained as a candidate data packet.

[0098] The traffic screening unit 400 is further configured to: when it is determined that the retrieval information does not contain a front-end link, identify all the obtained candidate data packets as valid data packets.

[0099] The traffic screening unit 400 is further configured to: when it is determined that the retrieval information contains any one or more elements in the five-tuple, obtain the valid data packets containing the elements indicated by the retrieval information from each valid data packet as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0100] The traffic screening unit 400 is further configured to: when it is determined that the retrieval information does not contain a feature field, perform a feature value retrieval on each valid data packet to obtain the feature value of each valid data packet, and identify the valid data packets whose feature values contain a preset sensitive field as suspicious traffic and display the suspicious traffic to the user through a preset interface.

[0101] In summary, this embodiment utilizes each metadata shown in the metadata table to achieve accurate screening of data packets, without consuming time costs to parse all traffic data one by one, effectively improving the retrieval efficiency of suspicious traffic.

[0102] The present application also provides a computer-readable storage medium, which includes a stored program. Wherein, the program executes the retrieval method for suspicious traffic provided by the present application as described above.

[0103] The present application also provides a retrieval device for suspicious traffic, including: a processor, a memory, and a bus. The processor is connected to the memory through the bus. The memory is used to store a program, and the processor is used to run the program. Wherein, when the program runs, it executes the retrieval method for suspicious traffic provided by the present application as described above, including the following steps:

[0104] Save the data packets of each traffic data collected into a preset database;

[0105] Based on each of the data packets in the preset database, obtain a metadata table corresponding to each protocol type; the metadata table includes a set of metadata corresponding to each of the data packets; the set of metadata includes a plurality of metadata and the field values of each of the metadata; the metadata represents the message header fields of the data packet;

[0106] When it is determined that the retrieval information input by the user includes a feature field, obtain, from the metadata table that meets the third preset condition, the metadata whose field value is the same as the feature field as the attack feature; the third preset condition is: the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information;

[0107] Identify the data packets containing the attack feature as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0108] Specifically, on the basis of the above embodiment, the obtaining, based on each of the data packets in the preset database, a metadata table corresponding to each protocol type includes:

[0109] Classify each of the data packets in the preset database to obtain data packet groups corresponding to each protocol type; wherein, multiple data packets with the same protocol type will be classified into the same data packet group;

[0110] For each of the data packet groups, extract the message header fields of each data packet in the data packet group to obtain a set of message header fields of each data packet in the data packet group; the set of message header fields includes a plurality of message header fields and the field values of each of the message header fields;

[0111] Generate a metadata table corresponding to each protocol type based on the set of message header fields of each data packet in each of the data packet groups.

[0112] Specifically, based on the above embodiments, identifying the data packet containing the attack feature as suspicious traffic includes:

[0113] Pre-configure area tags and time tags for each of the data packets in the preset database; the area tag indicates the front-end link from which the traffic data originates; the collection time indicates the collection time of the traffic data;

[0114] When it is determined that the retrieval information input by the user includes a time point, obtain the data packets that meet the first preset condition from the preset database as candidate data packets; the first preset condition is that the time difference between the collection time of the data packet and the time point indicated by the retrieval information is less than a preset time threshold;

[0115] When it is determined that the retrieval information includes a front-end link, screen out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets; the second preset condition is that the front-end link of the candidate data packet is the same as the front-end link indicated by the retrieval information;

[0116] Identify the valid data packet containing the attack feature as suspicious traffic.

[0117] Specifically, based on the above embodiments, before identifying the valid data packet containing the attack feature as suspicious traffic, it further includes:

[0118] When it is determined that the retrieval information does not include the time point, traverse each data packet in the preset database in the order from the latest to the earliest collection time until a data packet containing the suspicious IP indicated by the retrieval information is obtained as the candidate data packet.

[0119] Specifically, based on the above embodiments, before identifying the valid data packet containing the attack feature as suspicious traffic, it further includes:

[0120] When it is determined that the retrieval information does not include the front-end link, identify all the obtained candidate data packets as the valid data packets.

[0121] Specifically, based on the above embodiments, after screening out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets when it is determined that the retrieval information includes a front-end link, it further includes:

[0122] In the case where it is determined that the retrieved information contains any one or more elements of the five-tuple, obtain, from each of the valid data packets, the valid data packets containing the elements indicated by the retrieved information as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0123] Specifically, on the basis of the above embodiment, after screening out, from the one or more candidate data packets obtained, the candidate data packets that meet the second preset condition as valid data packets when it is determined that the retrieved information contains the front-end link, the method further includes:

[0124] In the case where it is determined that the retrieved information does not contain the feature field, perform a feature value retrieval on each of the valid data packets to obtain the feature value of each valid data packet, and identify the valid data packets whose feature values contain a preset sensitive field as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

[0125] If the functions described in the method embodiments of this application are implemented in the form of software function units and sold or used as independent products, they can be stored in a storage medium readable by a computing device. Based on such an understanding, the part of this application that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a computing device (which may be a personal computer, a server, a mobile computing device, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory, a random access memory, a magnetic disk, or an optical disc that can store program codes.

[0126] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.

[0127] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for retrieving suspicious traffic, characterized in that, it includes: Saving the data packets of each traffic data collected into a preset database; Based on each of the data packets in the preset database, obtaining a metadata table corresponding to each protocol type; the metadata table includes a metadata set of each of the data packets; the metadata set includes multiple metadata and the field values of each of the metadata; The metadata represents the header fields of the data packet; When it is determined that the retrieval information input by the user contains a characteristic field, obtaining, from the metadata table that meets the third preset condition, the metadata whose field value is the same as the characteristic field as an attack characteristic; The third preset condition is: the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieval information; Identifying the data packet containing the attack characteristic as suspicious traffic, and displaying the suspicious traffic to the user through a preset interface; The identifying the data packet containing the attack characteristic as suspicious traffic includes: pre-configuring an area label and a time label for each of the data packets in the preset database; the area label indicates the front-end link from which the traffic data comes; the time label indicates the collection time of the traffic data; when it is determined that the retrieval information contains a time point, obtaining, from the preset database, the data packets that meet the first preset condition as candidate data packets; the first preset condition is: the time difference between the collection time of the data packet and the time point indicated by the retrieval information is less than a preset time threshold; when it is determined that the retrieval information contains a front-end link, screening out, from the one or more candidate data packets obtained, the candidate data packets that meet the second preset condition as valid data packets; the second preset condition is: the front-end link of the candidate data packet is the same as the front-end link indicated by the retrieval information; identifying the valid data packet containing the attack characteristic as suspicious traffic.

2. The method according to claim 1, characterized in that, The obtaining a metadata table corresponding to each protocol type based on each of the data packets in the preset database includes: Classifying each of the data packets in the preset database to obtain data packet groups corresponding to each protocol type; wherein, multiple data packets with the same protocol type will be classified into the same data packet group; For each of the data packet groups, extracting the header fields of each data packet in the data packet group to obtain a header field set of each data packet in the data packet group; the header field set includes multiple header fields and the field values of each header field; Generating a metadata table corresponding to each protocol type based on the header field sets of each data packet in each of the data packet groups.

3. The method according to claim 1, characterized in that, Before identifying the valid data packet containing the attack characteristic as suspicious traffic, it further includes: In the case where it is determined that the retrieved information does not contain the time point, traverse each data packet in the preset database in the order from the latest collection time to the earliest until a data packet containing the suspicious IP indicated by the retrieved information is obtained as the candidate data packet.

4. The method according to claim 1, wherein, before identifying the valid data packet containing the attack feature as suspicious traffic, further includes: In the case where it is determined that the retrieved information does not contain the front-end link, all the obtained candidate data packets are identified as the valid data packets.

5. The method according to claim 1, wherein, after filtering out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets in the case where it is determined that the retrieved information contains the front-end link, further includes: In the case where it is determined that the retrieved information contains any one or more elements in the five-tuple, obtain the valid data packets containing the elements indicated by the retrieved information from each of the valid data packets as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

6. The method according to claim 1, wherein, after filtering out the candidate data packets that meet the second preset condition from the one or more obtained candidate data packets as valid data packets in the case where it is determined that the retrieved information contains the front-end link, further includes: In the case where it is determined that the retrieved information does not contain the feature field, perform a feature value retrieval on each valid data packet to obtain the feature value of each valid data packet, and identify the valid data packets whose feature values contain the preset sensitive field as suspicious traffic, and display the suspicious traffic to the user through a preset interface.

7. A retrieval device for suspicious traffic, wherein, includes: A traffic collection unit for saving the data packets of each traffic data collected into a preset database; A metadata acquisition unit for obtaining a metadata table corresponding to each protocol type based on each data packet in the preset database; the metadata table includes a metadata set of each data packet; the metadata set includes multiple metadata and the field values of each metadata; The metadata represents the packet header fields of the data packet; A metadata query unit for obtaining, as an attack feature, the metadata whose field value is the same as the feature field from the metadata table that meets the third preset condition in the case where it is determined that the retrieved information input by the user contains the feature field; The third preset condition is: the protocol type corresponding to the metadata table is the same as the protocol type indicated by the retrieved information; A traffic screening unit for identifying the data packets containing the attack feature as suspicious traffic and displaying the suspicious traffic to the user through a preset interface; The traffic screening unit is specifically configured to: pre-configure an area tag and a time tag for each of the data packets in the preset database; the area tag indicates the front-end link from which the traffic data originates; the time tag indicates the acquisition time of the traffic data; When it is determined that the retrieved information includes a time point, obtain the data packets that meet the first preset condition from the preset database as candidate data packets; the first preset condition is that the time difference between the acquisition time of the data packet and the time point indicated by the retrieved information is less than a preset time threshold; when it is determined that the retrieved information includes a front-end link, screen out the candidate data packets that meet the second preset condition from the one or more candidate data packets obtained as valid data packets; the second preset condition is that the front-end link of the candidate data packet is the same as the front-end link indicated by the retrieved information; identify the valid data packets containing the attack feature as suspicious traffic.

8. A computer-readable storage medium, characterized in that the computer-readable storage medium includes a stored program, wherein the program, when run by a processor, executes the suspicious traffic retrieval method according to any one of claims 1-6.

9. A suspicious traffic retrieval device, characterized in that it includes: a processor, a memory, and a bus; the processor is connected to the memory through the bus; the memory is used to store a program, and the processor is used to run the program, wherein the program, when run by the processor, executes the suspicious traffic retrieval method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Data detection method, device and equipment and readable storage medium

    CN112468520A

  • Device fingerprint selection method and device, electronic device and medium

    CN114338600A

  • Information prediction method and device, computer equipment and storage medium

    CN114385954A