Covert communication method, device, storage medium and network equipment
By using dynamic routing protocols in restricted networks, using data fragments as routing addresses and adding target identifiers, the problem of tunnel protocol exposing identity information is solved, and the effect of hidden communication is achieved.
Patent Information
- Application Number
- CN202211523384.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-30
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-11-30
AI Technical Summary
Under restricted networks, the existing tunnel protocol communication methods are prone to expose the identity information of both parties to the communication and may trigger traffic monitoring abnormal alarms.
The dynamic routing protocol is adopted to use the target data fragment as the routing address to generate dynamic routing protocol packets carrying the target identifier, and transmit them between routers to conceal the identity information of both parties in the communication.
It realizes hidden communication under restricted networks, avoids the exposure of identity information of sending and receiving devices, and reduces traffic monitoring abnormal alarms.
Smart Images

Figure CN116015718B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communications, and more specifically, to a covert communication method, apparatus, storage medium, and network equipment. Background Art
[0002] Firewalls and intrusion detection devices are set up in the network environment to intercept and identify malicious traffic, thereby protecting personal computers and corporate servers on the Internet. In some business scenarios, communication needs to be carried out under restricted networks.
[0003] Currently, tunneling protocols are commonly used to achieve communication within restricted networks. This involves encapsulating custom protocols and sending and parsing them as part of conventional protocols (such as HTTP and DNS). This approach allows for bypassing firewalls and intrusion detection devices that restrict and monitor communication protocols. However, this approach is limited by the TCP / IP protocol specification, and its data packets contain both the source and destination, potentially exposing the identities of both communicating parties. Summary of the Invention
[0004] To overcome at least one of the shortcomings of the prior art, the present application provides a covert communication method, apparatus, storage medium, and network device for implementing covert communication in a network environment. Specifically, the method includes:
[0005] In a first aspect, the present application provides a covert communication method, applied to a sending device, the method comprising:
[0006] Using the target data fragment as a routing address of a dynamic routing protocol, generating a dynamic routing protocol message carrying a target identifier, wherein the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message;
[0007] Sending the dynamic routing protocol message carrying the target identifier.
[0008] In a second aspect, the present application provides a covert communication method, applied to a receiving device, the method comprising:
[0009] Receive dynamic routing protocol messages;
[0010] If the dynamic routing protocol message includes a target identifier, obtaining a routing address in the dynamic routing protocol;
[0011] The routing address is used as the target data segment.
[0012] In a third aspect, the present application provides a covert communication device, applied to a sending device, the device comprising:
[0013] A data acquisition module is used to acquire target data segments to be sent;
[0014] a message construction module, configured to use the target data fragment as a routing address of a dynamic routing protocol to generate a dynamic routing protocol message carrying a target identifier, wherein the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message;
[0015] The data sending module is used to send the dynamic routing protocol message carrying the target identifier.
[0016] In a fourth aspect, the present application provides a covert communication device, applied to a receiving device, the device comprising:
[0017] A message receiving module, used for receiving dynamic routing protocol messages;
[0018] a data extraction module, configured to obtain a routing address in the dynamic routing protocol if the dynamic routing protocol message includes a target identifier;
[0019] The data extraction module is further configured to use the routing address as a target data segment.
[0020] In a fifth aspect, the present application provides a storage medium storing a computer program. When the computer program is executed by a processor, it implements a covert communication method applied to a sending device or a covert communication method applied to a receiving device.
[0021] In a sixth aspect, the present application provides a network device, which includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, it implements a covert communication method applied to a sending device or a covert communication method applied to a receiving device.
[0022] Compared with the prior art, this application has the following beneficial effects:
[0023] In the covert communication method, apparatus, storage medium, and network device provided by this application, a sending device obtains a target data segment to be sent; uses the target data segment as the routing address of a dynamic routing protocol to generate a dynamic routing protocol message carrying a target identifier; and sends a dynamic routing protocol message carrying the target identifier, wherein the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message. In this way, the target data segment is carried by a dynamic routing protocol, so that the target data segment is transmitted between routers in the form of a routing table, and the routing table does not record the information of the sending device, so that the sending device can send the target data segment to the receiving device without exposing the identity information of the sending device and the receiving device. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0025] Figure 1 Schematic diagram of the tunneling protocol principle provided in the embodiment of the present application;
[0026] Figure 2 A schematic diagram of a system provided in an embodiment of the present application;
[0027] Figure 3 Schematic diagram of the dynamic routing protocol provided in this application embodiment;
[0028] Figure 4 One of the flow charts of the covert communication method provided in the embodiment of the present application;
[0029] Figure 5 The RIP protocol message format provided in the embodiment of this application;
[0030] Figure 6 This is an example diagram of the principle of the covert communication method provided in the embodiment of the present application;
[0031] Figure 7 The second flowchart of the covert communication method provided in the embodiment of the present application;
[0032] Figure 8 This is one of the structural diagrams of the covert communication device provided in an embodiment of the present application;
[0033] Figure 9 This is a second structural diagram of the covert communication device provided in an embodiment of the present application;
[0034] Figure 10 A schematic diagram of the structure of the network device provided in an embodiment of the present application.
[0035] Icons: 101A-data acquisition module; 102A-message construction module; 103A-data sending module; 101B-message receiving module; 102B-data extraction module; 201-memory; 202-processor; 203-communication unit; 204-system bus. DETAILED DESCRIPTION
[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0037] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0038] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0039] In the description of this application, it should be noted that the terms "first", "second", "third", etc. are used only to distinguish descriptions and should not be understood as indicating or implying relative importance. In addition, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.
[0040] Based on the above statement, this embodiment study found that tunnel protocols are usually used to achieve communication in a restricted network, thereby breaking through the restrictions and monitoring of communication protocols by firewalls or intrusion monitoring devices. However, this method is limited by the TCP / IP protocol specifications, and its data packets contain source and destination, which may expose the identity information of both parties in the communication. Among them, common tunnel protocols include the SOCKS protocol for proxy, the TLS (Transport Layer Security) protocol for encryption, and the PPTP (Point-to-Point Tunneling Protocol) for virtual machine private networks (VPN).
[0041] For example, Figure 1As shown in the figure, assuming that HTTP is permitted in a restricted network environment provided by a firewall, if the FTP data stream "0x01, 0x02, 0x03, 0x04" is sent directly to the receiving device without HTTP encapsulation, it will be blocked by the firewall. 0x01, 0x02, 0x03, and 0x04 represent the hexadecimal representation of each byte in the data stream. Therefore, the FTP data stream "0x01, 0x02, 0x03, 0x04" must be treated as HTTP data and encapsulated into an HTTP message in order to pass through the firewall that only permits HTTP.
[0042] However, research has found that the tunnel protocols allowed to pass through in different restricted scenarios vary to a certain extent, and tunnel protocol communications must be adapted to function. Moreover, compared to normal protocol load conditions, tunnel protocols need to package and encapsulate custom protocols and send and parse them as part of the data of conventional protocols (HTTP, DNS, etc.), resulting in the generation of additional communication data, which may trigger abnormal alerts in traffic monitoring.
[0043] In addition, due to the limitations of the TCP / IP protocol specifications, its data packets contain the source and destination addresses, which may expose the identity information of the communicating parties and cannot truly achieve covert communication.
[0044] It should be noted that the defects existing in the solutions in the above-mentioned prior art are the results obtained by the inventors after practice and careful research. Therefore, the discovery process of the above-mentioned problems and the solutions proposed in the embodiments of this application below for the above-mentioned problems should be the contributions made by the inventors to this application in the process of invention and creation, and should not be understood as technical contents known to technical personnel in this field.
[0045] In view of this, the study further found that the Internet is composed of a large number of network devices, which are responsible for data transmission between computers, and routers play a backbone role in this. Routers direct data transmission in the network by configuring routing tables. The dynamic routing protocol running in the routers is used to build routing tables between different routers and ultimately form the best communication link.
[0046] In an autonomous system (AS), different routers exchange routing information using dynamic routing protocols. If a sending device accesses the AS as a router and sends data as routing information, the routing information is eventually transmitted to all routers within the AS via the dynamic routing protocol. A receiving device, still accessing the AS as a router, reads the routing information and receives the data packets. Thus, covert communication is achieved within an AS using dynamic routing protocols.
[0047] Based on the above principles, this embodiment provides a covert communication method for hiding the identity information of both parties in the communication process. Figure 2 As shown, the application scenario involved in this embodiment includes a sending device and a receiving device, and the sending device and the receiving device establish a communication connection in a network environment through a dynamic routing protocol. Compared with conventional communication methods, this embodiment uses a dynamic routing protocol to carry data, thereby concealing the identity information of the communicating parties.
[0048] To facilitate understanding, before detailing the method provided in this embodiment, we will first introduce the dynamic routing protocol involved in this embodiment. A dynamic routing protocol is a concept corresponding to a static routing protocol. In the field of computer networks, "routing" refers to the path information that guides the transmission of IP packets.
[0049] Dynamic routing protocols are one of the methods used by network devices such as routers to learn routing information in the network. These protocols enable routers to dynamically update their stored routing tables as changes occur in the network topology (such as the failure of certain paths or the emergence of new routes). This allows routers in the network to automatically maintain consistent routing information in a short period of time without the intervention of network administrators, allowing the entire network to reach a state of routing convergence, thereby maintaining rapid network convergence and high availability. Common dynamic routing protocols include RIP (Routing Information Protocol), OSPF (Open Shortest Path First), IS-IS (Intermediate System-to-Intermediate System), IGRP (Interior Gateway Routing Protocol), EIGRP (Enhanced Interior Gateway Routing Protocol), BGP (Border Gateway Protocol), etc.
[0050] For example, Figure 3 As shown in the figure, there are four routers (router A, router B, router C, router B), among which the network address of router A is "1.1.1.0 / 24", the network address of router B is "2.2.2.0 / 24"; the network address of router C is "3.3.3.0 / 24", and the network address of router D is "4.4.4.0 / 24".
[0051] In addition, each router maintains a routing table that records the routing information between the four routers. For example, the routing table in router A is:
[0052] address port 2.2.2.0 / 24 1 3.3.3.0 / 24 2 4.4.4.0 / 24 1
[0053] Based on the above introduction, the following Figure 4 Each step of the secret communication method provided in this embodiment is described in detail. However, it should be understood that the operations in the flowchart can be implemented in any order, and steps that have no logical contextual relationship can be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart, or remove one or more operations from the flowchart, guided by the content of this application. Figure 4 As shown, the method includes:
[0054] S101A, obtaining a target data segment to be sent.
[0055] In an optional implementation manner, step S101A includes the following specific implementation manners:
[0056] S101A-1, obtain data to be sent.
[0057] S101A-2, dividing the data to be sent into at least one data segment according to the length of the routing address.
[0058] S101A-3, select a target data segment from at least one data segment.
[0059] It should be understood that the length of the routing address is 4 bytes. Therefore, in a specific implementation, the sending device may divide the data to be sent into at least one data segment according to the length of 4 bytes.
[0060] For example, assuming that the data to be sent is 32 bytes, the 32 bytes are divided into 8 data segments of 4 bytes in length. Then, these 8 data segments are sequentially used as target data segments, encapsulated into dynamic routing protocol messages carrying target identifiers, and sent, thereby sending the 32 bytes of data to be sent to the receiving device.
[0061] S102A: Use the target data fragment as a routing address of the dynamic routing protocol to generate a dynamic routing protocol message carrying a target identifier.
[0062] The target identifier is used to distinguish the dynamic routing protocol message from the regular dynamic routing protocol message.
[0063] In this embodiment, according to the message format of the dynamic routing protocol, the target data is used as the routing address in the dynamic routing protocol, and the target identifier is used as the network mask of the dynamic routing protocol, thereby constructing a dynamic routing protocol message carrying the target identifier.
[0064] For example, assuming that the dynamic routing protocol is the RIP protocol, Figure 5 The following fields are included in the RIP message format:
[0065] Command field, which identifies the type of RIP message. A value of 1 indicates a Request message, and a value of 2 indicates a Response message.
[0066] Version field. In the RIP-2 protocol, the value of this field is 2.
[0067] Address Family Identifier: A value of 2 indicates the IP protocol. If the message is a Request message and is used to request the entire routing table from a directly connected routing device, the value of this field is set to 0. At the same time, this Request message contains only one routing entry, the destination network address of which is 0.0.0.0, and the metric value is 16.
[0068] Route tag: Used to set tag information for routes. Routes can be flexibly controlled based on tags in routing policies. For example, when an external route is imported into RIP, forming a RIP route, RIP can set a route tag for the route. When the route is propagated throughout the RIP routing domain, the route tag is not lost.
[0069] Routing address: The destination network address of the route.
[0070] Network mask: The destination network mask used to store routing entries. RIP-2 further supports variable length subnet masks (VLSM), route aggregation, and CIDR (Classless Inter-Domain Routing).
[0071] Next hop: RIP-2 defines this field to prevent routing devices from displaying suboptimal paths on multi-access networks and to select the optimal next hop address on broadcast networks.
[0072] Assuming that the target data segment is "0x8,0x8,0x8,0x8" and the target identifier is "32", the data segment is used as Figure 5 The RIP protocol routing address shown uses the destination identifier as the RIP protocol network mask; other fields in the RIP protocol are assigned and populated according to the standard RIP protocol. It should be understood that in routers, the network mask is typically set to "24," and setting it to "32" is extremely rare. Therefore, in this embodiment, "32" is used as the destination identifier to distinguish it from standard RIP protocol messages. Of course, under the same inventive concept, when implementing this solution, technicians may also select other fields in the protocol to record the destination identifier, and this embodiment does not specifically limit this.
[0073] Based on the above introduction to dynamic routing protocol messages carrying target identifiers, continue to refer to Figure 4 , the method further comprises:
[0074] S103A: Send a dynamic routing protocol message carrying a target identifier.
[0075] Research has found that dynamic routing protocols are updated at regular intervals, which results in a certain degree of communication delay when communicating based on dynamic routing protocols. Sending multiple dynamic routing protocol messages carrying target identifiers at once can easily cause the messages received by the receiving device to become out of order. In view of this, in this embodiment, if the time since the last dynamic routing protocol message was sent is greater than the duration threshold, the sending device sends a dynamic routing protocol message carrying the target identifier. For example, the RIP protocol broadcasts routing information every 30 seconds by default, so the duration threshold can be set to any value greater than 30 seconds.
[0076] In order to enable those skilled in the art to use the content of this application, a specific example is provided for illustration. Figure 6 As shown in the figure, the target data segment sent is "0x8, 0x8, 0x8, 0x8", and the sending device supports basic dynamic routing protocols (for example, handshake protocol, sending routing information protocol, receiving routing information protocol); the target data segment "0x8, 0x8, 0x8, 0x8" and the target identifier "32" are encapsulated into a dynamic routing protocol message carrying the target identifier.
[0077] After the four routers on the network exchange information using a dynamic routing protocol, each router will have a routing information of "8.8.8.8 / 32." The receiving device must also support basic dynamic routing protocols (e.g., handshake protocol, send routing information protocol, receive routing information protocol) to obtain the routing information of the adjacent router D and receive the target data fragment "0x8,0x8,0x8,0x8."
[0078] In this way, a dynamic routing protocol is used to carry the target data fragment, so that the target data fragment is transmitted between routers in the form of a routing table, and the routing table does not record the information of the sending device, so that the sending device can send the target data fragment to the receiving device without exposing the identity information of the sending device and the receiving device.
[0079] Based on the same inventive concept, this embodiment also provides a covert communication method, which is applied to a receiving device. Figure 7 As shown, the method includes:
[0080] S101B receives a dynamic routing protocol message.
[0081] S102B: If the dynamic routing protocol message includes a target identifier, obtain a routing address in the dynamic routing protocol.
[0082] S103B, using the routing address as the target data segment.
[0083] For example, see Figure 6 The receiving device obtains routing information from neighboring router D through a dynamic routing protocol. A routing message with a target identifier of "32" in the mask indicates that the routing address in the message is actually the target data fragment sent by the sending device. This allows the receiving device to distinguish the target data fragment from the numerous dynamic routing protocol messages.
[0084] This embodiment also provides a covert communication device, which includes at least one software function module that can be stored in the memory 201 or fixed in the operating system (OS) of the network device in the form of software. The processor 202 in the network device is used to execute the executable module stored in the memory 201. For example, the software function module and computer program included in the covert communication device. Please refer to Figure 8 When a covert communication device is applied to a transmitting device, the covert communication device may include:
[0085] The data acquisition module 101A is used to acquire target data segments to be sent.
[0086] In this embodiment, the data acquisition module 101A is used to implement Figure 4 For the detailed description of step S101A in China, please refer to the detailed description of step S101A for the detailed description of the data acquisition module 101A.
[0087] The message construction module 102A is configured to use the target data segment as a routing address of the dynamic routing protocol to generate a dynamic routing protocol message carrying a target identifier, wherein the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message.
[0088] In this example, the message construction module 102A is used to implement Figure 4 For a detailed introduction of the message construction module 102A, please refer to the detailed introduction of step S102A.
[0089] The data sending module 103A is configured to send a dynamic routing protocol message carrying a target identifier.
[0090] In this embodiment, the data sending module 103A is used to implement Figure 4 For a detailed description of the data sending module 103A, please refer to the detailed description of step S103A.
[0091] In addition, it is worth noting that, under the same inventive concept, the above data acquisition module 101A, message construction module 102A, and data transmission module 103A can also be used to implement other steps or sub-steps in the covert communication method applied to the transmitting device. This embodiment will not elaborate on this.
[0092] Please refer to Figure 9 When the covert communication method is applied to a receiving device, the covert communication device may include the following functional components:
[0093] The message receiving module 101B is used to receive dynamic routing protocol messages.
[0094] In this embodiment, the message receiving module 101B is used to implement Figure 7 For a detailed description of the message receiving module 101B, please refer to the detailed description of step S101B.
[0095] The data extraction module 102B is configured to obtain a routing address in the dynamic routing protocol if the dynamic routing protocol message includes a target identifier.
[0096] The data extraction module 102B is further configured to use the routing address as a target data segment.
[0097] In this embodiment, the data extraction module 102B is used to implement Figure 7For a detailed introduction of the data extraction module 102B, please refer to the detailed introduction of steps S102B and S103B.
[0098] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0099] It should also be understood that if the above embodiments are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application.
[0100] Therefore, this embodiment further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the covert communication method provided in this embodiment is implemented. The computer-readable storage medium can be a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, among other media capable of storing program code.
[0101] Please refer to Figure 10 This embodiment provides a network device, which may include a processor 202 and a memory 201. The memory 201 stores a computer program, and the processor reads and executes the computer program corresponding to the above embodiment in the memory 201. When the network device is a sending device, the covert communication method applied to the sending device provided in this embodiment is implemented; when the network device is a receiving device, the covert communication method applied to the receiving device provided in this embodiment is implemented.
[0102] Continue to see Figure 10 The network device further includes a communication unit 203. The memory 201, the processor 202 and the communication unit 203 are electrically connected to each other directly or indirectly via a system bus 204 to achieve data transmission or interaction.
[0103] The memory 201 may be an information recording device based on any electronic, magnetic, optical or other physical principles, for recording execution instructions, data, etc. In some embodiments, the memory 201 may be, but is not limited to, a volatile memory, a non-volatile memory, a storage drive, etc.
[0104] In some embodiments, the volatile memory may be a random access memory (RAM); in some embodiments, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, etc.; in some embodiments, the storage drive may be a magnetic disk drive, a solid-state drive, any type of storage disk (such as a CD, DVD, etc.), or a similar storage medium, or a combination thereof.
[0105] The communication unit 203 is used to send and receive data through a network. In some embodiments, the network may include a wired network, a wireless network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a wide area network (WAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, or a near field communication (NFC) network, or any combination thereof. In some embodiments, the network may include one or more network access points. For example, the network may include a wired or wireless network access point, such as a base station and / or a network switching node, through which one or more components of the service request processing system can connect to the network to exchange data and / or information.
[0106] The processor 202 may be an integrated circuit chip having signal processing capabilities, and the processor may include one or more processing cores (e.g., a single-core processor or a multi-core processor). By way of example only, the processor may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), an application-specific instruction set processor (ASIP), a graphics processing unit (GPU), a physical processing unit (PPU), a digital signal processor (DSP), a field programmable gate array (FPGA), a programmable logic device (PLD), a controller, a microcontroller unit, a reduced instruction set computer (RISC), or a microprocessor, or any combination thereof.
[0107] It should be understood that the devices and methods disclosed in the above embodiments may also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram may represent a module, a program segment, or a portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box may also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes may actually be executed substantially in parallel, or they may sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, may be implemented using a dedicated hardware-based system that performs a specified function or action, or may be implemented using a combination of dedicated hardware and computer instructions.
[0108] The above descriptions are merely examples of various embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be readily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A covert communication method, characterized in that: Applied to a sending device, the method includes: Get the target data fragment to be sent; Using the target data fragment as a routing address of a dynamic routing protocol, and generating a dynamic routing protocol message carrying a target identifier, including: generating the dynamic routing protocol message by using the target data fragment as the routing address of the dynamic routing protocol and the target identifier as the network mask of the dynamic routing protocol, wherein the routing table of the dynamic routing protocol does not record information of the sending device, and the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message; Sending the dynamic routing protocol message carrying the target identifier.
2. The covert communication method according to claim 1, characterized in that: The step of obtaining the target data segment to be sent includes: Get the data to be sent; Splitting the data to be sent into at least one data segment according to the length of the routing address; The target data segment is selected from the at least one data segment.
3. The covert communication method according to claim 2, wherein: The length of the routing address is 4 bytes, and the data to be sent is divided into at least one data segment according to the length of the routing address, including: The data to be sent is divided into the at least one data segment according to the length of 4 bytes.
4. The covert communication method according to claim 1, wherein: The sending of the dynamic routing protocol message carrying the target identifier includes: If the time since the last dynamic routing protocol message was sent is greater than the duration threshold, the dynamic routing protocol message carrying the target identifier is sent.
5. A covert communication method, characterized in that: Applied to a receiving device, the method includes: Receive dynamic routing protocol messages; If the dynamic routing protocol message includes a target identifier, obtaining a routing address in the dynamic routing protocol; The routing address is used as the target data segment.
6. A covert communication device, characterized in that: Applied to a sending device, the apparatus includes: A data acquisition module is used to acquire target data segments to be sent; The message construction module is used to use the target data fragment as the routing address of the dynamic routing protocol to generate a dynamic routing protocol message carrying a target identifier, specifically for: generating the dynamic routing protocol message by using the target data fragment as the routing address of the dynamic routing protocol and the target identifier as the network mask of the dynamic routing protocol, wherein the routing table of the dynamic routing protocol does not record information of the sending device, and the target identifier is used to distinguish the dynamic routing protocol message from a conventional dynamic routing protocol message; The data sending module is used to send the dynamic routing protocol message carrying the target identifier.
7. A covert communication device, characterized in that: Applied to a receiving device, the apparatus comprises: A message receiving module, used for receiving dynamic routing protocol messages; a data extraction module, configured to obtain a routing address in the dynamic routing protocol if the dynamic routing protocol message includes a target identifier; The data extraction module is further configured to use the routing address as a target data segment.
8. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by the processor, the covert communication method according to any one of claims 1 to 4 or the covert communication method according to claim 5 is implemented.
9. A network device, characterized in that: The network device includes a processor and a memory, wherein the memory stores a computer program. When the computer program is executed by the processor, the covert communication method according to any one of claims 1 to 4 or the covert communication method according to claim 5 is implemented.
Citation Information
Patent Citations
Data secrete sharing system and method based on core network
CN103458046A