An Encryption Protocol Monitoring Method, Device and Electronic Device

By analyzing and processing the encrypted traffic in the network, extracting and determining protocol parameters and random parameters, the problem of irregular application of encryption protocols in the prior art is solved, and effective monitoring and security improvement of encrypted traffic is achieved.

CN115801917BActive Publication Date: 2025-06-13VIEWINTECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111050003.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-08
Publication Date
2025-06-13
Estimated Expiration
2041-09-08

AI Technical Summary

Technical Problem

The prior art is difficult to effectively monitor and identify whether the application of encryption protocols in encrypted traffic in the network complies with standard specifications, resulting in the vulnerability of encryption.

Method used

By obtaining the encrypted traffic to be detected, analyzing and processing the session data, extracting protocol parameters and random parameters, and comprehensively making judgments based on the compliance of protocol parameters and the randomness of random parameters, we determine whether the encrypted traffic complies with the standard specifications.

Benefits of technology

It quickly identifies whether the encryption protocol application in network traffic meets the standards, can be monitored online, and the judgment results are more accurate, which improves the standardization and security of the encryption protocol.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801917B_ABST
    Figure CN115801917B_ABST
Patent Text Reader

Abstract

The present invention provides a method, apparatus and electronic device for monitoring an encryption protocol. The method includes: obtaining encrypted traffic to be detected; parsing session data in the encrypted traffic to obtain protocol parameters and random parameters of the encrypted traffic; and determining that the encrypted traffic complies with the standard specification when the protocol parameters are compliant and the random parameters are random. Through the method, apparatus and electronic device for monitoring an encryption protocol provided by the embodiments of the present invention, it is possible to conveniently and quickly identify whether the application of the encryption protocol in network traffic meets the standards and is standardized, and online monitoring can be realized; and a comprehensive judgment is made by combining the protocol parameters and the random parameters, and the judgment result is more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted traffic, and in particular, to a method, device, electronic device and computer-readable storage medium for monitoring encrypted protocols. Background Art

[0002] Traffic in a network is a continuous packet of the same five-tuple between two network nodes, including an IP address, a port number, and a protocol type. Encrypted traffic in a network is traffic generated by an encryption algorithm and an encryption protocol. Currently, encrypted traffic in the network is growing rapidly, there are more and more encrypted services in the network, and the application of encryption protocols is becoming more and more common, including IPSEC, SSL / TLS, SSH, RDP, etc.

[0003] In the Internet, a large number of encryption protocols use open-source software. Due to insufficient understanding and comprehension of encryption protocols and encryption standards, there are often deviations from the standards in the actual application of encryption protocols, which results in the vulnerability of encryption. Summary of the Invention

[0004] To solve the existing technical problems, embodiments of the present invention provide a method, device, electronic device and computer-readable storage medium for monitoring encrypted protocols.

[0005] In a first aspect, an embodiment of the present invention provides a method for monitoring an encrypted protocol, including:

[0006] Obtaining encrypted traffic to be detected;

[0007] Parsing and processing session data in the encrypted traffic to obtain protocol parameters and random parameters of the encrypted traffic;

[0008] Determining that the encrypted traffic meets the standard specifications when the protocol parameters are compliant and the random parameters are random.

[0009] In a second aspect, an embodiment of the present invention further provides a device for monitoring an encrypted protocol, including:

[0010] An obtaining module, configured to obtain encrypted traffic to be detected;

[0011] An analyzing module, configured to parse and process session data in the encrypted traffic to obtain protocol parameters and random parameters of the encrypted traffic;

[0012] A processing module, configured to determine that the encrypted traffic meets the standard specifications when the protocol parameters are compliant and the random parameters are random.

[0013] In a third aspect, an embodiment of the present invention provides an electronic device, including a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. The transceiver, the memory, and the processor are connected through the bus. When the computer program is executed by the processor, the steps in the encryption protocol monitoring method described in any one of the above are implemented.

[0014] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the encryption protocol monitoring method described in any one of the above are implemented.

[0015] The encryption protocol monitoring method, device, electronic device, and computer-readable storage medium provided by the embodiments of the present invention parse and process the encrypted traffic in the network, extract the protocol parameters and random parameters therein, and determine whether the application of the encryption protocol in the encrypted traffic is standardized by judging whether the protocol parameters are compliant and whether the random parameters are random. This method can conveniently and quickly identify whether the application of the encryption protocol in the network traffic meets the standards and is standardized, and can achieve online monitoring; and a comprehensive judgment is made by combining the protocol parameters and random parameters, and the judgment result is more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the background art, the following will describe the drawings required to be used in the embodiments of the present invention or the background art.

[0017] Figure 1 Shows a flowchart of an encryption protocol monitoring method provided by an embodiment of the present invention;

[0018] Figure 2 Shows a schematic structural diagram of an encryption protocol monitoring device provided by an embodiment of the present invention;

[0019] Figure 3 Shows a schematic structural diagram of an electronic device for executing the encryption protocol monitoring method provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] The following describes the embodiments of the present invention with reference to the drawings in the embodiments of the present invention.

[0021] Figure 1 Shows a flowchart of an encryption protocol monitoring method provided by an embodiment of the present invention. As Figure 1 shown, the method includes:

[0022] Step 101: Obtain the encrypted traffic to be detected.

[0023] In an embodiment of the present invention, when it is necessary to determine whether the application of the encryption protocol in a certain encrypted traffic meets the standard, the encrypted traffic can be obtained. Among them, the encrypted traffic to be detected can be directly obtained from the already encrypted traffic, or the encrypted traffic can be extracted from the normal traffic. For example, the network traffic can be obtained by real-time monitoring of the network card, and then it is determined whether the network traffic is encrypted. If it is encrypted, it can be used as the encrypted traffic in step 101.

[0024] Step 102: Parse and process the session data in the encrypted traffic to obtain the protocol parameters and random parameters of the encrypted traffic.

[0025] In an embodiment of the present invention, the encrypted traffic is the traffic generated during the session, which includes session data, such as handshake data, etc. By parsing and processing the session data, the protocol parameters and random parameters that should be random in the session data can be extracted. Optionally, the protocol parameters include one or more of: encryption algorithm, encryption component, message format, payload format; the random parameters include random numbers and payloads, etc. For example, parsing the session data can obtain: the encryption algorithm or encryption component supported by the client, the encryption algorithm or encryption component selected by the server, the random numbers of the server and the client, the parameters for key exchange between the client and the server, the certificate of the server, etc. And generally, the message of the session data has a corresponding format, so the message format can also be used as a kind of protocol parameter.

[0026] Among them, the above step 102 "parse and process the session data in the encrypted traffic" may include: identifying the encryption protocol used by the encrypted traffic according to the port of the encrypted traffic, and parsing and processing the session data in the encrypted traffic based on the encryption protocol used by the encrypted traffic. In an embodiment of the present invention, the port identification method can be used to determine the encryption protocol used by the encrypted traffic, such as the SSL / TLS protocol, the ISAKMP protocol, the ESP protocol, etc., so that targeted parsing can be performed based on the protocol type.

[0027] Step 103: When the protocol parameters are compliant and the random parameters are random, it is determined that the encrypted traffic meets the standard specification.

[0028] In an embodiment of the present invention, the protocol parameters are parameters that meet a certain format or requirement. By judging whether the protocol parameters are compliant, it can be determined whether the application of the encryption protocol in the encrypted traffic is basically normal. For example, for the handshake packet of the SSL protocol, extract the key information of the handshake between the client and the server in the packet. If both can be correctly parsed and are within the standard requirements, it is considered that its message format is standard and compliant; in addition, for the content that can be parsed, according to the requirements of the standard protocol, whether the parsed content is within the value range. If it exceeds the corresponding value range, or the negotiation between the two parties is abnormal, it is considered that the application of the encryption protocol does not meet the specification.

[0029] Moreover, the encrypted traffic also includes some random parameters, such as random numbers, payloads, etc. In this embodiment, the randomness of these random parameters is further detected to determine whether the encrypted traffic conforms to the standard specification. If the random parameter does not have randomness, the random parameter may be artificially generated, and it can be considered that the protocol application in the encrypted traffic is not standardized, such as malicious encrypted traffic, etc.

[0030] The encrypted protocol monitoring method provided by the embodiment of the present invention extracts protocol parameters and random parameters therein by parsing and processing the encrypted traffic in the network, and determines whether the encrypted protocol application in the encrypted traffic is standardized by judging whether the protocol parameters are compliant and whether the random parameters have randomness. This method can conveniently and quickly identify whether the encrypted protocol application in the network traffic conforms to the standard and is standardized, and can achieve online monitoring; and a comprehensive judgment is made by combining protocol parameters and random parameters, and the judgment result is more accurate.

[0031] Based on the above embodiment, as described above, the random parameter may include a random number in the session data; the process of judging whether the random number has randomness in this embodiment includes:

[0032] Step A1: Divide the random number into L units, each unit contains n consecutive bits, and count and determine the frequency N corresponding to each type of unit i .

[0033] Step A2: Determine the offset ΔS of the random number. When the offset ΔS is less than the preset threshold, it is determined that the random number has randomness; the offset ΔS is:

[0034]

[0035] In the embodiment of the present invention, the random number is a string containing multiple bits. In this embodiment, n consecutive bits are used as a group to divide the random number, and L units are obtained; since each unit contains n consecutive bits (bit), each unit may take different values, and there are 2 n kinds of values, that is, the number of types of units is 2 n . For example, if each unit is one byte (8 bits), the value of the unit may be 0, 1, 2,..., 255, a total of 2 8 = 256 kinds.

[0036] For the frequency N i corresponding to the i-th type of unit, it can be regarded as the sum of L mutually independent random variables X 1 , X 2 ,..., X L , that is, N i = X1 +X 2 +…+X L According to the central limit theorem, the random variable follows the standard normal distribution N(0, 1), where μ is the mean of the random variable X i (i = 1, 2, …, L), and σ is the standard deviation of the random variable X i .

[0037] If the random numbers extracted from the encrypted traffic are random, the occurrence probability of each type of unit in the random numbers should be the same, and all are 1 / 2 n , so the mean μ of X i is 1 / 2 n ; Since X i follows the 0-1 distribution, its variance σ 2 = μ(1 - μ) = (2 n -1) / 2 2n . Therefore, the random variable follows the standard normal distribution N(0, 1). In this embodiment, the chi-square value of this standard normal distribution is used as the offset ΔS for judging randomness, that is, the offset is:

[0038]

[0039] Among them, based on the degrees of freedom 2 of the chi-square value n , the corresponding preset threshold can be set. For example, the preset threshold is 2 n . The probability that the offset ΔS is greater than the preset threshold is a small probability. Therefore, if the offset ΔS is less than the preset threshold, it can be considered that follows the standard normal distribution. Correspondingly, the frequency N of each type of unit in the random numbers i follows the 0-1 distribution, and the random numbers are random.

[0040] Since the random numbers are short, for example, the number of bytes of the random numbers is small, it is difficult to directly judge the randomness of the random numbers, and the accuracy is poor; in this embodiment, by using the characteristic that the frequencies of each type of unit in the random numbers can be regarded as independent and identically distributed random variables, the randomness of the random numbers is indirectly judged by judging the offset ΔS in the form of the chi-square value, and the judgment result is more accurate. Moreover, the unit division method can be determined in advance. For example, the unit contains 8 bits, so the preset threshold can be determined in advance, and the above method for calculating the offset is not complicated, which can save the resource overhead during real-time detection calculation and greatly improve the determination efficiency, so that this method can be applied to the real network environment of high-speed transmission.

[0041] In addition, optionally, the random parameter also includes the payload in the certificate. The process of judging whether the payload is random includes:

[0042] Step B1: Determine that the number of occurrences of k consecutive first bits in the payload is n k , and both ends of the k consecutive first bits are second bits; the first bit is one of the 0 bit and the 1 bit, and the second bit is the other of the 0 bit and the 1 bit.

[0043] Step B2: Determine the check value T corresponding to the k consecutive first bits k , and determine whether the payload has randomness according to the check value T k ; the check value T k is:

[0044]

[0045] where N is the total number of bits in the payload, p is the frequency of occurrence of the first bit, and q is the frequency of occurrence of the second bit.

[0046] In the embodiments of the present invention, the payload is similar to the above-mentioned random number and can also be regarded as a string of multiple bits. However, the random number is generally relatively short, while the payload is generally longer than the random number. In this embodiment, the randomness of the payload is judged by determining the frequency of occurrence of consecutive identical bits. Specifically, the bits are divided into 0 bits and 1 bits. In this embodiment, one of them is called the first bit and the other is called the second bit. For example, the 0 bit is used as the first bit and the 1 bit is used as the second bit. If k bits after a certain second bit in the payload are all first bits and the (k + 1)-th bit is a second bit, then it can be considered that k consecutive first bits have occurred. For example, k = 4, the first bit is 0, and the second bit is 1. If a part of the payload is 0100001101, then there are 4 consecutive 0 bits among them.

[0047] If the frequency of occurrence of the first bit is p and the frequency of occurrence of the second bit is q, then the probability of the occurrence of k consecutive first bits is q × p k × q = p k × q 2 . Similar to the above steps A1 - A2, the number of occurrences n of k consecutive first bits k can also be regarded as multiple (about N, where N represents the total number of bits in the payload) random variables of the 0 - 1 distribution, and the occurrence probability of this random variable is p k × q 2 . Since the total number of bits N of the payload is large, it can be considered that the number of random variables is also N. Therefore, it also conforms to the standard normal distribution.

[0048] In the embodiments of the present invention, the above value is used as the corresponding check value T k , and by judging this check value T kWhether it conforms to the standard normal distribution can be used to determine whether the load is random. For example, multiple different k values can be selected, the verification values corresponding to each k value can be calculated respectively, and the sum of the squares of multiple verification values can be compared with a preset verification standard value. If it is less than the verification standard value, it is considered that the load is random.

[0049] In the embodiment of the present invention, for a load with a large amount of data, by taking a small number of k values, the verification value T corresponding to each k can be determined. k , and then the randomness of the load can be quickly and accurately judged; and each k value can be determined in advance, and the verification standard value used for comparison can also be set in advance. Therefore, this method also has a high judgment efficiency and is suitable for application in the real network environment of high-speed transmission.

[0050] The above has described in detail the encryption protocol monitoring method provided by the embodiment of the present invention. This method can also be implemented by a corresponding device. Next, the encryption protocol monitoring device provided by the embodiment of the present invention will be described in detail.

[0051] Figure 2 shows a schematic structural diagram of an encryption protocol monitoring device provided by an embodiment of the present invention. As Figure 2 shown, the encryption protocol monitoring device includes:

[0052] An acquisition module 21, configured to acquire the encrypted traffic to be detected;

[0053] An analysis module 22, configured to analyze and process the session data in the encrypted traffic to obtain the protocol parameters and random parameters of the encrypted traffic;

[0054] A processing module 23, configured to determine that the encrypted traffic conforms to the standard specification when the protocol parameters are compliant and the random parameters are random.

[0055] Based on the above embodiment, the random parameter includes a random number in the session data;

[0056] The device further includes: a first judgment module, configured to:

[0057] Divide the random number into L units, each unit contains n consecutive bits, and statistically determine the frequency N corresponding to each unit i ;

[0058] Determine the offset ΔS of the random number, and determine that the random number is random when the offset ΔS is less than a preset threshold; the offset ΔS is:

[0059]

[0060] Based on the above embodiments, the random parameter includes the payload in the certificate;

[0061] The device further includes: a second determination module, configured to:

[0062] Determine that the occurrence times of k consecutive first bits in the payload is n k , and both ends of the k consecutive first bits are second bits; the first bit is one of a 0 bit and a 1 bit, and the second bit is the other of the 0 bit and the 1 bit;

[0063] Determine the check value T corresponding to the k consecutive first bits k , and based on the check value T k Judge whether the payload has randomness; the check value T k is:

[0064]

[0065] where N is the total number of bits in the payload, p is the frequency of the first bit appearance, and q is the frequency of the second bit appearance.

[0066] Based on the above embodiments, the protocol parameter includes one or more of: an encryption algorithm, an encryption component, a message format, and a payload format.

[0067] Based on the above embodiments, the parsing module 22 performs parsing processing on the session data in the encrypted traffic, including:

[0068] Identify the encryption protocol adopted by the encrypted traffic according to the port of the encrypted traffic, and perform parsing processing on the session data in the encrypted traffic based on the encryption protocol adopted by the encrypted traffic.

[0069] In addition, an embodiment of the present invention further provides an electronic device, including a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. The transceiver, the memory, and the processor are respectively connected through the bus. When the computer program is executed by the processor, it realizes each process of the above embodiment of the encrypted protocol monitoring method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0070] Specifically, as shown in Figure 3 , an embodiment of the present invention further provides an electronic device, which includes a bus 1110, a processor 1120, a transceiver 1130, a bus interface 1140, a memory 1150, and a user interface 1160.

[0071] In an embodiment of the present invention, the electronic device further includes: a computer program stored on the memory 1150 and executable on the processor 1120, and when the computer program is executed by the processor 1120, each process of the foregoing embodiment of the encryption protocol monitoring method is implemented.

[0072] The transceiver 1130 is configured to receive and transmit data under the control of the processor 1120.

[0073] In an embodiment of the present invention, a bus architecture (represented by the bus 1110), the bus 1110 may include any number of interconnected buses and bridges, and the bus 1110 connects various circuits including one or more processors represented by the processor 1120 and the memory represented by the memory 1150 together.

[0074] The bus 1110 represents one or more of any of several types of bus structures, including a memory bus and a memory controller, a peripheral bus, an Accelerated Graphics Port (AGP), a processor, or a local bus using any bus structure in various bus architectures. By way of example and not limitation, such architectures include: Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Extended ISA (EISA) bus, Video Electronics Standards Association (VESA), Peripheral Component Interconnect (PCI) bus.

[0075] The processor 1120 can be an integrated circuit chip with signal processing capabilities. In implementation, the steps of the above method embodiments can be completed by the integrated logic circuit in the hardware of the processor or instructions in the form of software. The above-mentioned processor includes: general-purpose processor, central processing unit (CPU), network processor (NP), digital signal processor (DSP), application specific integrated circuit (ASIC), field programmable gate array (FPGA), complex programmable logic device (CPLD), programmable logic array (PLA), microcontroller unit (MCU), or other programmable logic devices, discrete gates, transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. For example, the processor can be a single-core processor or a multi-core processor, and the processor can be integrated on a single chip or located on multiple different chips.

[0076] The processor 1120 can be a microprocessor or any conventional processor. The method steps disclosed in combination with the embodiments of the present invention can be directly executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module can be located in a readable storage medium well-known in the art such as random access memory (RAM), flash memory, read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), registers, etc. The readable storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0077] The bus 1110 can also connect together various other circuits such as, for example, peripheral devices, voltage regulators, or power management circuits. The bus interface 1140 provides an interface between the bus 1110 and the transceiver 1130, which are all well-known in the art. Therefore, the embodiments of the present invention will not be further described herein.

[0078] The transceiver 1130 can be a single component or multiple components, such as multiple receivers and transmitters, providing units for communicating with various other devices over a transmission medium. For example, the transceiver 1130 receives external data from other devices, and the transceiver 1130 is used to send the data processed by the processor 1120 to other devices. Depending on the nature of the computer system, a user interface 1160 may also be provided, such as a touch screen, a physical keyboard, a display, a mouse, speakers, a microphone, a trackball, a joystick, a stylus.

[0079] It should be understood that in the embodiments of the present invention, the memory 1150 may further include memories remotely located relative to the processor 1120, and these remotely located memories can be connected to the server through a network. One or more parts of the above networks can be an ad hoc network, an intranet, an extranet, a virtual private network (VPN), a local area network (LAN), a wireless local area network (WLAN), a wide area network (WAN), a wireless wide area network (WWAN), a metropolitan area network (MAN), the Internet, a public switched telephone network (PSTN), a plain old telephone service network (POTS), a cellular telephone network, a wireless network, a Wi-Fi network, and a combination of two or more of the above networks. For example, the cellular telephone network and the wireless network can be a Global System for Mobile Communications (GSM) system, a Code Division Multiple Access (CDMA) system, a Worldwide Interoperability for Microwave Access (WiMAX) system, a General Packet Radio Service (GPRS) system, a Wideband Code Division Multiple Access (WCDMA) system, a Long Term Evolution (LTE) system, an LTE Frequency Division Duplexing (FDD) system, an LTE Time Division Duplexing (TDD) system, an Advanced Long Term Evolution (LTE-A) system, a Universal Mobile Telecommunications System (UMTS) system, an Enhance Mobile Broadband (eMBB) system, a massive Machine Type of Communication (mMTC) system, an UltraReliable Low Latency Communications (uRLLC) system, etc.

[0080] It should be understood that the memory 1150 in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory includes: Read-Only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically Erasable PROM (EEPROM), or Flash Memory.

[0081] The volatile memory includes: Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as: Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). The memory 1150 of the electronic device described in the embodiments of the present invention includes but is not limited to the above and any other suitable types of memory.

[0082] In the embodiments of the present invention, the memory 1150 stores the following elements of the operating system 1151 and the application program 1152: executable modules, data structures, or subsets or extended sets thereof.

[0083] Specifically, the operating system 1151 includes various system programs, such as: framework layer, core library layer, driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application program 1152 includes various application programs, such as: Media Player, Browser, for implementing various application services. The program for implementing the method of the embodiments of the present invention may be included in the application program 1152. The application program 1152 includes: applets, objects, components, logics, data structures, and other computer system executable instructions for performing specific tasks or implementing specific abstract data types.

[0084] In addition, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each process of the above-mentioned embodiment of the encryption protocol monitoring method and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0085] A computer-readable storage medium includes permanent and non-permanent, removable and non-removable media, which are tangible devices that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium includes electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, and any suitable combination of the above. A computer-readable storage medium includes phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tape storage, magnetic tape disk storage or other magnetic storage devices, memory sticks, mechanical encoding devices (such as punched cards or raised structures in grooves on which instructions are recorded), or any other non-transmission medium that can be used to store information accessible by a computing device. As defined in the embodiments of the present invention, a computer-readable storage medium does not include transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (such as light pulses passing through an optical fiber cable), or electrical signals transmitted through wires.

[0086] In several embodiments provided by the present application, it should be understood that the disclosed devices, electronic devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can also be in electrical, mechanical, or other forms of connection.

[0087] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units. They can be located in one position or distributed to multiple network units. Some or all of the units can be selected according to actual needs to solve the problems to be solved by the solution of the embodiments of the present invention.

[0088] In addition, in each embodiment of the present invention, each functional unit may be integrated into a processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0089] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (including a personal computer, a server, a data center, or other network devices) to execute all or part of the steps of the method described in each embodiment of the present invention. The above-mentioned storage medium includes various media that can store program codes as listed above.

[0090] In the description of the embodiments of the present invention, those skilled in the art should know that the embodiments of the present invention can be implemented as a method, a device, an electronic device, and a computer-readable storage medium. Therefore, the embodiments of the present invention can be specifically implemented in the following forms: complete hardware, complete software (including firmware, resident software, microcode, etc.), and a combination of hardware and software. In addition, in some embodiments, the embodiments of the present invention can also be implemented in the form of a computer program product in one or more computer-readable storage media, and the computer-readable storage media contain computer program codes.

[0091] The above-mentioned computer-readable storage media may adopt any combination of one or more computer-readable storage media. Computer-readable storage media include: electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media include: portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs), flash memories, optical fibers, compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any combination of the above. In the embodiments of the present invention, the computer-readable storage media may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device, or component.

[0092] The computer program code included in the above computer-readable storage medium can be transmitted by any suitable medium, including: wireless, wire, optical fiber cable, radio frequency (RF), or any suitable combination of the above.

[0093] The computer program code for performing the operations of the embodiments of the present invention can be written in assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, integrated circuit configuration data, or in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as C language or similar programming languages. The computer program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, and entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including: local area network (LAN) or wide area network (WAN), and can also be connected to an external computer.

[0094] The methods, devices, and electronic devices provided by the embodiments of the present invention are described by flowcharts and / or block diagrams.

[0095] It should be understood that each block of the flowchart and / or block diagram, and the combinations of blocks in the flowchart and / or block diagram, can be implemented by computer-readable program instructions. These computer-readable program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine. These computer-readable program instructions, when executed by a computer or other programmable data processing device, produce a device that implements the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0096] These computer-readable program instructions can also be stored in a computer-readable storage medium that can cause a computer or other programmable data processing device to work in a specific manner. In this way, the instructions stored in the computer-readable storage medium produce an instruction device product that includes the instructions for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0097] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to generate a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus can provide a process for realizing the functions / operations specified in the blocks of the flowchart and / or block diagram.

[0098] As described above, the specific implementation manners of the embodiments of the present invention are only described, but the protection scope of the embodiments of the present invention is not limited thereto. Any person skilled in the technical field can easily think of changes or substitutions within the technical scope disclosed in the embodiments of the present invention, and all of them should be covered by the protection scope of the embodiments of the present invention. Therefore, the protection scope of the embodiments of the present invention shall be subject to the protection scope of the claims.

Claims

1. An encryption protocol monitoring method, characterized in that, it includes: Obtain the encrypted traffic to be detected; Parse and process the session data in the encrypted traffic to obtain the protocol parameters and random parameters of the encrypted traffic; When the protocol parameters are compliant and the random parameters are random, determine that the encrypted traffic meets the standard specifications; The random parameters include the random numbers in the session data; The method further includes: Divide the random numbers into L units, each unit containing n consecutive bits, and statistically determine the frequency N corresponding to each type of unit i ; Determine the offset ΔS of the random number, and determine that the random number is random when the offset ΔS is less than a preset threshold; the offset ΔS is:

2. The method according to claim 1, characterized in that, The random parameters include the payload in the certificate; The method further includes: Determine that the number of occurrences of k consecutive first bits in the load is n k , both ends of the k consecutive first bits are second bits; the first bit is one of the 0 bit and the 1 bit, and the second bit is the other of the 0 bit and the 1 bit; Determine the check value T corresponding to k consecutive first bits k , and based on the check value T k judge whether the payload has randomness; the check value T k is: where N is the total number of bits in the payload, p is the frequency of occurrence of the first bit, and q is the frequency of occurrence of the second bit.

3. The method according to claim 1, characterized in that, The protocol parameters include one or more of: encryption algorithm, encryption component, message format, payload format.

4. The method according to any one of claims 1-3, characterized in that, The parsing and processing of the session data in the encrypted traffic includes: Identify the encryption protocol adopted by the encrypted traffic according to the port of the encrypted traffic, and parse and process the session data in the encrypted traffic based on the encryption protocol adopted by the encrypted traffic.

5. An encryption protocol monitoring device, characterized in that, it includes: An acquisition module for acquiring the encrypted traffic to be detected; A parsing module for parsing and processing the session data in the encrypted traffic to obtain the protocol parameters and random parameters of the encrypted traffic; the random parameters include the random numbers in the session data; A processing module for determining that the encrypted traffic meets the standard specifications when the protocol parameters are compliant and the random parameters are random; Divide the random numbers into L units, where each unit contains n consecutive bits, and statistically determine the frequency N corresponding to each type of unit i ; Determine the offset ΔS of the random number, and determine that the random number is random when the offset ΔS is less than a preset threshold; the offset ΔS is:

6. The device according to claim 5, characterized in that, The protocol parameters include one or more of: encryption algorithm, encryption component, message format, payload format.

7. The device according to claim 5 or 6, characterized in that, The parsing module's parsing and processing of the session data in the encrypted traffic includes: Identify the encryption protocol adopted by the encrypted traffic according to the port of the encrypted traffic, and parse and process the session data in the encrypted traffic based on the encryption protocol adopted by the encrypted traffic.

8. An electronic device, including a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, the transceiver, the memory, and the processor are connected by the bus, characterized in that, When the computer program is executed by the processor, it implements the steps in the encryption protocol monitoring method according to any one of claims 1 to 4.

9. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, it implements the steps in the encryption protocol monitoring method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method of confirming safety of data and cipher system

    JP2003124924A