Network communication method, device, equipment and storage medium
By performing encryption and decryption processing at the data stream layer and address layer of the Windows system driver framework, the problem of SSL/TLS man-in-the-middle attacks is resolved, ensuring the security of communication data and the correct response of the server.
Patent Information
- Application Number
- CN202310149819.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-13
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-02-13
AI Technical Summary
Existing technologies cannot effectively prevent SSL/TLS man-in-the-middle attacks in Windows systems, especially when man-in-the-middle tools replace server certificates, resulting in reduced communication security and the protection is not universal.
By monitoring the communication data to be encrypted at the data stream layer of the driver framework of the client operating system, using the preset storage container to determine whether to perform encryption processing, and decrypting the encrypted data at the address layer, the correctness of the communication data on the server side is ensured.
It implements protection for any type of application, prevents man-in-the-middle attacks, ensures the correctness of communication data on the server side, and avoids situations where the server cannot respond.
Smart Images

Figure CN116208404B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular to a network communication method, apparatus, device and storage medium. Background Art
[0002] Most applications on Windows use the SSL (Secure Sockets Layer) / TLS (Transport Layer Security) protocol for encrypted transmission. SSL / TLS is widely used in network communications to authenticate both communicating parties and negotiate session keys, thereby ensuring secure and reliable connections. The key to SSL / TLS security services is that the client receives the correct server certificate. However, this vulnerability can be exploited by man-in-the-middle tools, which can replace the server certificate and impersonate the legitimate identities of both communicating parties, thereby successfully carrying out SSL / TLS man-in-the-middle attacks.
[0003] Currently, the common solution for preventing man-in-the-middle attacks on Windows systems is to disable the system proxy or bind the server certificate public key to the application. However, existing technical solutions cannot prevent all types of man-in-the-middle tools, nor are they applicable to all types of applications, and are not universally applicable. Summary of the Invention
[0004] The present invention provides a network communication method, apparatus, device and storage medium to prevent attacks from any type of intermediary during system network communication and to protect any type of application program.
[0005] According to one aspect of the present invention, a network communication method is provided, the method comprising:
[0006] Monitor the data stream layer corresponding to the driver framework of the client's operating system to obtain the communication data to be encrypted;
[0007] Determining whether to encrypt the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and based on a preset storage container;
[0008] If so, encrypting the communication data to be encrypted to generate encrypted communication data;
[0009] When the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, the encrypted communication data is decrypted, and the decrypted communication data obtained after decryption is reassembled and then transmitted to the server.
[0010] According to another aspect of the present invention, there is provided a network communication device, characterized in that it includes:
[0011] The encrypted data acquisition module is used to monitor the data stream layer corresponding to the driver framework of the client's operating system to obtain the communication data to be encrypted;
[0012] an encryption processing judgment module, configured to determine whether to perform encryption processing on the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and based on a preset storage container;
[0013] an encrypted data generating module, configured to, if it is determined that the communication data to be encrypted is to be encrypted, encrypt the communication data to be encrypted to generate encrypted communication data;
[0014] The communication data decryption module is used to decrypt the encrypted communication data when the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, and transmit the decrypted communication data obtained after decryption to the server after performing a data packet reassembly operation.
[0015] According to another aspect of the present invention, an electronic device is provided, comprising:
[0016] at least one processor; and
[0017] a memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to execute the network communication method described in any embodiment of the present invention.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network communication method according to any embodiment of the present invention when executed.
[0020] The embodiment of the present invention obtains the communication data to be encrypted by monitoring the data stream layer corresponding to the driver framework of the operating system to which the client belongs; determines whether to encrypt the communication data to be encrypted based on the data analysis result of the communication data to be encrypted and based on the preset storage container; if so, encrypts the communication data to be encrypted to generate encrypted communication data; when the address layer corresponding to the driver framework monitors the transmission data packet of the encrypted communication data, decrypts the encrypted communication data, and performs a data packet reassembly operation on the decrypted communication data obtained after decryption and transmits it to the server. The above technical solution prevents attacks from any type of intermediary in the system network communication process by encrypting the communication data of the client application at the data stream layer during the network communication process, and ensures the correctness of the transmitted communication data on the server by decrypting the encrypted communication data at the address layer, avoids the situation where the communication data transmitted to the server is encrypted data and causes the server to be unable to respond, thereby realizing protection for any type of application.
[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0023] Figure 1 This is a flow chart of a network communication method provided according to the first embodiment of the present invention;
[0024] Figure 2 This is a flow chart of a network communication method provided according to a second embodiment of the present invention;
[0025] Figure 3 This is a flow chart of a network communication method provided according to Embodiment 3 of the present invention;
[0026] Figure 4 This is a schematic structural diagram of a network communication device provided according to a fourth embodiment of the present invention;
[0027] Figure 5 It is a structural diagram of an electronic device for implementing the network communication method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] Example 1
[0031] Figure 1 This is a flowchart of a network communication method provided in Example 1 of the present invention. This embodiment can be applied to prevent intermediary attacks during network communication. The method can be executed by a network communication device, which can be implemented in the form of hardware and / or software, and can be configured in an electronic device.
[0032] S110: Monitor the data stream layer corresponding to the driver framework of the operating system to which the client belongs to obtain communication data to be encrypted.
[0033] The client can be any device terminal, for example, a computer or other device. The operating system can be any operating system, for example, a Windows system or a Linux system. The driver framework is built into the operating system, and different operating systems have different corresponding driver frameworks. For example, the driver framework for the Windows system is the WFP (Windows Filtering Platform) driver framework.
[0034] The WFP driver framework is applied to all layers of the TCP (Transmission Control Protocol) / IP (Internet Protocol) protocol stack within the operating system kernel. Based on the TCP / IP communication protocol stack, the WFP driver framework is divided into four fixed filter layers, all of which are integrated into the four-layer protocol stack corresponding to TCP / IP. The four layers of the protocol stack corresponding to the WFP driver framework are the application layer, transport layer, address layer, and link layer. The data stream layer is located at the application layer and is responsible for receiving raw data packets from the application layer.
[0035] The communication data to be encrypted may be communication data sent by a client application to a server during network communication. The communication data to be encrypted may be communication data that needs to be encrypted or communication data that does not need to be encrypted.
[0036] It's important to note that during network communications, most applications on Windows use the SSL / TLS protocol for encrypted transmission. SSL / TLS is widely used to authenticate both communicating parties and negotiate session keys, thereby ensuring secure and reliable connections. Crucial to SSL / TLS security is that the client receives the correct server certificate. However, when a man-in-the-middle tool installs a root CA certificate on a Windows system, it can replace the server certificate in an SSL / TLS connection, impersonating the legitimate identities of both communicating parties and successfully executing an SSL / TLS man-in-the-middle attack.
[0037] It is understood that to prevent intermediary attacks, the client can protect the applications that require protection. That is, the communication data transmitted by the application in the network can be encrypted. In the event of an intermediary attack, the data obtained is encrypted data that the intermediary cannot decrypt. It should be noted that the client can contain multiple applications, and relevant technicians can select the applications to be protected based on actual needs.
[0038] For example, relevant technicians can configure a list of applications that need to be protected. For example, if the applications to be protected are Application A and Application B, the full paths of the application processes to be protected can be set as follows: C:\Program Files\Google\Chrome\Application\A.exe; C:\Program Files(x86)\Microsoft\Edge\Application\B.exe]. After configuring the full paths of the application processes to be protected, the communication data between the protected application and the server can be protected.
[0039] The communication data between the protected program and the server is transmitted downward from the application layer. Specifically, the data stream layer in the application layer obtains the original data of the communication data, that is, the data to be encrypted. The data stream layer is the FWPM_LAYER_STREAM_V4 layer in the WFP driver framework.
[0040] Exemplarily, the data stream layer corresponding to the driver framework of the client operating system may be monitored, and when original communication data is monitored, the monitored original communication data is obtained and determined as communication data to be encrypted.
[0041] S120: Determine whether to encrypt the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and a preset storage container.
[0042] The preset storage container may be a system or platform for storing or managing data, and may be pre-set by relevant technical personnel. For example, the preset storage container may be a Map (an object that maps keys to values). The preset storage container may store the storage path of the application to be protected.
[0043] For example, the results of data analysis of the encrypted communication data can be used to determine whether the encrypted communication data corresponds to the application to be protected. Specifically, the method can determine whether the storage path of the application associated with the encrypted communication data is within a preset storage container, thereby determining whether to encrypt the encrypted communication data. If so, the encrypted communication data is encrypted; if not, it is not encrypted.
[0044] S130: If yes, encrypt the communication data to be encrypted to generate encrypted communication data.
[0045] For example, if it is determined that the communication data needs to be encrypted, the WFP kernel-mode driver may encrypt the data to be encrypted monitored by the data flow to obtain encrypted communication data.
[0046] S140. When the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, the encrypted communication data is decrypted, and the decrypted communication data obtained after the decryption is reassembled into a data packet and then transmitted to the server.
[0047] The address layer, located in the internet layer of the WFP driver framework, is used to receive transmission data packets, also known as IP packets, from the upper transport layer. These packets can be the packets obtained by the application layer after the encrypted data is packaged for transmission to the lower layers. The address layer corresponding to the WFP driver framework is FWPM_LAYER_OUTBOUND_IPPACKET_V4.
[0048] For example, the address layer corresponding to the driver framework can be monitored, and when a transmission data packet is monitored, it is determined whether the transmission data packet is a data packet of encrypted communication data to be decrypted. If so, the transmission data packet is parsed to obtain encrypted communication data, and the encrypted communication data is decrypted to obtain decrypted communication data. The decrypted communication data is reassembled and transmitted to the server; if not, the transmission data packet is not processed.
[0049] It's important to note that encrypted communication data is decrypted at the address layer to ensure that the data received by the server is decrypted data. Man-in-the-middle tools are unable to attack the address layer during an attack, thus ensuring the secure transmission of communication data after decryption at the address layer.
[0050] The embodiment of the present invention obtains the communication data to be encrypted by monitoring the data stream layer corresponding to the driver framework of the operating system to which the client belongs; determines whether to encrypt the communication data to be encrypted based on the data analysis result of the communication data to be encrypted and based on the preset storage container; if so, encrypts the communication data to be encrypted to generate encrypted communication data; when the address layer corresponding to the driver framework monitors the transmission data packet of the encrypted communication data, decrypts the encrypted communication data, and performs a data packet reassembly operation on the decrypted communication data obtained after decryption and transmits it to the server. The above technical solution prevents attacks from any type of intermediary in the system network communication process by encrypting the communication data of the client application at the data stream layer during the network communication process, and ensures the correctness of the transmitted communication data on the server by decrypting the encrypted communication data at the address layer, avoids the situation where the communication data transmitted to the server is encrypted data and causes the server to be unable to respond, thereby realizing protection for any type of application.
[0051] Example 2
[0052] Figure 2 This is a flow chart of a network communication method provided in the second embodiment of the present invention. This embodiment is optimized and improved on the basis of the above technical solutions.
[0053] Furthermore, before the step of "monitoring the data stream layer corresponding to the driver framework of the operating system to which the client belongs to obtain the communication data to be encrypted", add the step of "monitoring the first session layer corresponding to the driver framework to obtain the socket connection creation request; parsing the Socket connection creation request to obtain the target process identifier and target five-tuple information corresponding to the Socket connection creation request; determining whether to update the preset storage container based on the target process identifier and the target five-tuple information; if so, storing the target five-tuple information in the preset storage container to update the preset storage container." to improve the method of updating the preset storage container.
[0054] Furthermore, the step "determining whether to encrypt the encrypted communication data based on the results of parsing the communication data to be encrypted and based on a preset storage container" is further refined to "parsing the encrypted communication data to obtain quintuple information corresponding to the communication data to be encrypted; and determining whether to encrypt the communication data to be encrypted based on the presence of the quintuple information corresponding to the communication data to be encrypted in the preset storage container." This improves the encryption method for encrypted communication data. It should be noted that for portions not described in detail in this embodiment of the present invention, reference may be made to the descriptions of other embodiments.
[0055] See also Figure 2 The network communication method shown includes:
[0056] S210: Monitor the first session layer corresponding to the driver framework to obtain a socket connection creation request.
[0057] The first session layer may be used to receive a socket connection creation request, wherein the first session layer is the FWPM_LAYER_ALE_AUTH_CONNECT_V4 layer of the WFP driver framework. The socket connection creation request may be a request from a client application to establish a connection with a server.
[0058] Exemplarily, the Socket connection creation event can be monitored by monitoring the first session layer corresponding to the WFP driver framework, and when the Socket connection creation event is monitored, the Socket connection creation request is obtained.
[0059] S220: Parse the socket connection creation request to obtain the target process identifier and target five-tuple information corresponding to the socket connection creation request.
[0060] For example, the socket connection creation request can be parsed to obtain the target process identifier and target five-tuple information of the application generating the socket connection creation request. The target process identifier can be the unique PID (Process Identification) of the application; the target five-tuple information can include the source port, source address, target port, target address, and communication transmission protocol.
[0061] S230: Determine whether to update the preset storage container according to the target process identifier and the target five-tuple information.
[0062] The preset storage container can be pre-set by relevant technical personnel. It should be noted that the client may have applications that require protection and applications that do not require protection. The preset storage container will subsequently be used to determine whether to encrypt communication data. Whether to update the preset storage container can be determined based on the target process identifier and target five-tuple information.
[0063] In an optional embodiment, determining whether to update a preset storage container is performed based on a target process identifier and target five-tuple information, including: obtaining the client's path information of the program to be protected; determining the target application process that generates a socket connection creation request based on the target process identifier; if the communication transmission protocol in the target five-tuple information meets the preset protocol judgment condition, determining the target program path corresponding to the target application process; judging whether the target application process meets the preset program protection condition based on the target program path and the program path information to be protected, and obtaining a program protection condition judgment result; and determining whether to update the preset storage container based on the program protection condition judgment result.
[0064] The path information of the program to be protected may be the path information corresponding to the application to be protected, predetermined by relevant technical personnel. For example, if the application to be protected is A, the path information corresponding to application A may be C:\Program Files\Google\Chrome\Application\A.exe.
[0065] For example, since the target process identifier is unique, the target application process that generates the socket connection creation request can be uniquely determined by identifying the target.
[0066] The protocol judgment condition may be pre-set by relevant technical personnel. For example, the protocol judgment condition may be that the communication transmission protocol is the TCP protocol.
[0067] Exemplarily, if the communication transmission protocol in the target five-tuple information is the TCP protocol, the target program path corresponding to the target application process is determined; if the communication transmission protocol in the target five-tuple information is not the TCP protocol, the socket connection creation request is not processed. If the target program path is in the program path row to be protected, the target application process is determined to be an application that requires protection, and the target application process is determined to meet the preset program protection conditions; if the target program path is not in the program path row to be protected, the target application process is determined to be an application that does not require protection, and the target application process is determined to not meet the preset program protection conditions. If the preset program protection conditions are met, it is determined to update the preset storage container; if the preset program protection conditions are not met, the preset storage container is not updated.
[0068] In an optional embodiment, the program path information to be protected includes at least one reference program path of the application to be protected; accordingly, based on the target program path and the program path information to be protected, it is judged whether the target application process meets the preset program protection condition, and a program protection condition judgment result is obtained, including: based on the matching situation of the target program path and each reference program path, a program protection condition judgment result is obtained; accordingly, based on the program protection condition judgment result, it is determined whether to update the preset storage container, including: if there is a reference program path that matches the target program path, then it is determined to update the preset storage container; if there is no reference program path that matches the target program path, then the preset storage container is not updated.
[0069] Each application to be protected corresponds to its own reference program path. For example, after determining the target program path, the target program path can be matched with each reference program path; if a reference program path that matches the target program path exists, then the preset storage container is updated; if no reference program path that matches the target program path exists, then the preset storage container is not updated.
[0070] S240: If yes, store the target quintuple information into a preset storage container to update the preset storage container.
[0071] Exemplarily, if it is determined to update the preset storage container, the target five-tuple information corresponding to the target application is stored in the preset storage container to implement the update of the preset storage container.
[0072] S250: Monitor the data stream layer corresponding to the driver framework of the operating system to which the client belongs to obtain the communication data to be encrypted.
[0073] S260: Parse the communication data to be encrypted to obtain quintuple information corresponding to the communication data to be encrypted.
[0074] S270: Determine whether to encrypt the communication data to be encrypted based on whether the five-tuple information corresponding to the communication data to be encrypted exists in the preset storage container.
[0075] Exemplarily, if the five-tuple information corresponding to the communication data to be encrypted exists in the preset storage container, it is determined that the communication data to be encrypted is encrypted; if the five-tuple information corresponding to the communication data to be encrypted does not exist in the preset storage container, the communication data to be encrypted is not encrypted.
[0076] S280: If yes, encrypt the communication data to be encrypted to generate encrypted communication data.
[0077] S290. When the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, the encrypted communication data is decrypted, and the decrypted communication data obtained after decryption is reassembled into a data packet and then transmitted to the server.
[0078] It should be noted that the transmission data packet obtained by the address layer corresponding to the driver framework may correspond to encrypted communication data or unencrypted communication data. However, the data types of unencrypted and encrypted communication data in the transmission data packet are identical and indistinguishable. Therefore, after the address layer obtains the transmission data packet, it is necessary to further determine whether to decrypt the transmission data packet.
[0079] In an optional embodiment, the address layer corresponding to the driving framework is monitored to obtain the transmission data packet; the transmission data packet is parsed to obtain the parsed communication data and the five-tuple information corresponding to the parsed communication data; if the five-tuple information corresponding to the parsed communication data exists in a preset storage container, the parsed communication data is decrypted to obtain the decrypted communication data, and the decrypted communication data is reassembled and then transmitted to the server.
[0080] Exemplarily, the address layer corresponding to the driver framework is monitored to obtain a transmission data packet. The transmission data packet is parsed to obtain parsed communication data and five-tuple information of the parsed communication data. A determination is made as to whether the five-tuple information of the parsed communication data is in a preset storage container. If so, the parsed communication data is decrypted to obtain decrypted communication data, and the decrypted communication data is reassembled and transmitted to the server. If not, no processing is performed and the parsed communication data is directly transmitted to the server.
[0081] It should be noted that, in order to ensure normal network communication between the client and the server, as well as the accuracy of encryption and decryption of communication data during the network communication process, the preset storage container can be further updated when the Socket connection is disconnected.
[0082] In an optional embodiment, the second session layer corresponding to the driving framework is monitored to obtain a Socket connection disconnection request; the Socket connection disconnection request is parsed to obtain five-tuple information corresponding to the Socket connection disconnection request; if the five-tuple information corresponding to the Socket connection disconnection request exists in a preset storage container, the five-tuple information corresponding to the Socket connection disconnection request is removed from the preset storage container to update the preset storage container.
[0083] Exemplarily, the second session layer corresponding to the driver framework is monitored, and when a socket connection is disconnected, a socket connection disconnection request is obtained. The socket connection disconnection request is parsed to obtain five-tuple information corresponding to the socket connection disconnection request; if the five-tuple information corresponding to the socket connection disconnection request exists in a preset storage container, the five-tuple information corresponding to the socket connection disconnection request is removed from the preset storage container to update the preset storage container; if the five-tuple information corresponding to the socket connection disconnection request exists in the preset storage container, no processing is performed on the preset storage container.
[0084] The technical solution of this embodiment parses the Socket connection creation request obtained by monitoring the first session layer to obtain the target process identifier and target five-tuple information corresponding to the Socket connection creation request, and determines whether to update the preset storage container based on the target process identifier and target five-tuple information; if so, the target five-tuple information is stored in the preset storage container to update the preset storage container. The above technical solution determines whether to update the preset storage container based on the target process identifier and target five-tuple information, thereby realizing the update judgment of the preset storage container, and improving the accuracy of the subsequent determination of whether to encrypt the communication data to be encrypted based on the preset storage container. It ensures the correctness of the transmitted communication data on the server, avoids the situation where the communication data transmitted to the server is encrypted data and causes the server to be unable to respond, and realizes protection for any type of application.
[0085] Example 3
[0086] Figure 3 This is a flow chart of a network communication method provided in Embodiment 3 of the present invention. This embodiment provides a preferred example based on the above embodiments.
[0087] S301: Monitor the first session layer corresponding to the driver framework to obtain a socket connection creation request.
[0088] S302: Parse the socket connection creation request to obtain the target process identifier and target five-tuple information corresponding to the socket connection creation request.
[0089] S303: Obtain the path information of the program to be protected of the client; the path information of the program to be protected includes a reference program path of at least one application to be protected.
[0090] S304: Determine the target application process that generates the Socket connection creation request according to the target process identifier.
[0091] S305: If the communication transmission protocol in the target quintuple information satisfies the preset protocol judgment condition, determine the target program path corresponding to the target application process.
[0092] S306 : Obtain a program protection condition judgment result based on the matching conditions between the target program path and each reference program path.
[0093] S307: If there is a reference program path that matches the target program path, store the target quintuple information in a preset storage container to update the preset storage container.
[0094] S308: If there is no reference program path matching the target program path, the preset storage container is not updated.
[0095] S309: Monitor the data stream layer corresponding to the driver framework of the operating system to which the client belongs to obtain the communication data to be encrypted.
[0096] S310: Parse the communication data to be encrypted to obtain quintuple information corresponding to the communication data to be encrypted.
[0097] S311 , determining whether to encrypt the communication data to be encrypted based on whether the five-tuple information corresponding to the communication data to be encrypted exists in a preset storage container.
[0098] S312: If yes, encrypt the communication data to be encrypted to generate encrypted communication data.
[0099] S313: Monitor the address layer corresponding to the driver framework to obtain the transmission data packet.
[0100] S314: Parse the transmission data packet to obtain parsed communication data and quintuple information corresponding to the parsed communication data.
[0101] S315: If the five-tuple information corresponding to the parsed communication data exists in the preset storage container, the parsed communication data is decrypted to obtain decrypted communication data, and the decrypted communication data is reassembled into data packets and then transmitted to the server.
[0102] Example 4
[0103] Figure 4 This is a schematic diagram of the structure of a network communication device provided by the fourth embodiment of the present invention. The network communication device provided by the embodiment of the present invention can be used to prevent intermediary attacks during network communication. The network communication device can be implemented in the form of hardware and / or software, such as Figure 4 As shown, the device specifically includes: an encrypted data acquisition module 401, an encryption processing judgment module 402, an encrypted data generation module 403 and a communication data decryption module 404.
[0104] The encrypted data acquisition module 401 is used to monitor the data stream layer corresponding to the driver framework of the operating system to which the client belongs to obtain the communication data to be encrypted;
[0105] An encryption processing determination module 402 is configured to determine whether to perform encryption processing on the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and based on a preset storage container;
[0106] The encrypted data generating module 403 is configured to encrypt the communication data to be encrypted to generate encrypted communication data if it is determined that the communication data to be encrypted is to be encrypted;
[0107] The communication data decryption module 404 is used to decrypt the encrypted communication data when the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, and transmit the decrypted communication data obtained after decryption to the server after performing a data packet reassembly operation.
[0108] The embodiment of the present invention obtains the communication data to be encrypted by monitoring the data stream layer corresponding to the driver framework of the operating system to which the client belongs; determines whether to encrypt the communication data to be encrypted based on the data analysis result of the communication data to be encrypted and based on the preset storage container; if so, encrypts the communication data to be encrypted to generate encrypted communication data; when the address layer corresponding to the driver framework monitors the transmission data packet of the encrypted communication data, decrypts the encrypted communication data, and performs a data packet reassembly operation on the decrypted communication data obtained after decryption and transmits it to the server. The above technical solution prevents attacks from any type of intermediary in the system network communication process by encrypting the communication data of the client application at the data stream layer during the network communication process, and ensures the correctness of the transmitted communication data on the server by decrypting the encrypted communication data at the address layer, avoids the situation where the communication data transmitted to the server is encrypted data and causes the server to be unable to respond, thereby realizing protection for any type of application.
[0109] Optionally, the device further includes:
[0110] A creation request acquisition module is used to monitor the first session layer corresponding to the driver framework and obtain a socket connection creation request;
[0111] A creation request parsing module is used to parse the socket connection creation request to obtain the target process identifier and target five-tuple information corresponding to the socket connection creation request;
[0112] An update judgment module, configured to determine whether to update the preset storage container based on the target process identifier and the target quintuple information;
[0113] The container updating module is configured to store the target quintuple information in the preset storage container if it is determined to update the preset storage container, so as to update the preset storage container.
[0114] Optionally, the update judgment module includes:
[0115] A path information acquisition unit, configured to acquire path information of the program to be protected on the client;
[0116] A target application determining unit, configured to determine a target application process that generates the Socket connection creation request according to the target process identifier;
[0117] a target program path determining unit, configured to determine a target program path corresponding to the target application process if the communication transmission protocol in the target quintuple information satisfies a preset protocol judgment condition;
[0118] a judgment result determination unit, configured to determine whether the target application process satisfies a preset program protection condition based on the target program path and the path information of the program to be protected, and obtain a program protection condition judgment result;
[0119] The container updating unit is used to determine whether to update the preset storage container according to the judgment result of the program protection condition.
[0120] Optionally, the program path information to be protected includes at least one reference program path of the application to be protected;
[0121] Accordingly, the judgment result determination unit includes:
[0122] A judgment result determination subunit, configured to obtain a program protection condition judgment result based on a matching condition between the target program path and each reference program path;
[0123] Accordingly, the container updating unit includes:
[0124] a first container updating subunit, configured to determine to update the preset storage container if there is a reference program path matching the target program path;
[0125] The second container updating subunit is configured to not update the preset storage container if there is no reference program path matching the target program path.
[0126] Optionally, the encryption processing determination module 402 includes:
[0127] a quintuple information obtaining unit, configured to parse the communication data to be encrypted to obtain quintuple information corresponding to the communication data to be encrypted;
[0128] The encryption judgment unit is used to determine whether to encrypt the communication data to be encrypted according to the existence of the five-tuple information corresponding to the communication data to be encrypted in the preset storage container.
[0129] Optionally, the device further includes:
[0130] A transmission data packet acquisition module is used to monitor the address layer corresponding to the driver framework and obtain transmission data packets;
[0131] A first five-tuple information acquisition module is used to perform packet parsing on the transmission data packet to obtain parsed communication data and five-tuple information corresponding to the parsed communication data;
[0132] The communication data transmission module is used to decrypt the parsed communication data if the five-tuple information corresponding to the parsed communication data exists in the preset storage container to obtain decrypted communication data, and transmit the decrypted communication data to the server after performing a data packet reassembly operation.
[0133] Optionally, the device further includes:
[0134] A disconnection request acquisition module, configured to monitor the second session layer corresponding to the driver framework and acquire a socket connection disconnection request;
[0135] A second five-tuple information acquisition module is used to parse the socket disconnection request to obtain five-tuple information corresponding to the socket disconnection request;
[0136] The information removing module is configured to remove the five-tuple information corresponding to the Socket disconnection request from the preset storage container if the five-tuple information corresponding to the Socket disconnection request exists in the preset storage container, so as to update the preset storage container.
[0137] The network communication device provided by the embodiment of the present invention can execute the network communication method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0138] Example 5
[0139] Figure 5 A schematic diagram of the structure of an electronic device 50 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0140] like Figure 5 As shown, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52, a random access memory (RAM) 53, etc., which is communicatively connected to the at least one processor 51. The memory stores a computer program that can be executed by the at least one processor. The processor 51 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 52 or the computer program loaded from the storage unit 58 into the random access memory (RAM) 53. Various programs and data required for the operation of the electronic device 50 can also be stored in the RAM 53. The processor 51, ROM 52, and RAM 53 are connected to each other via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.
[0141] Multiple components in the electronic device 50 are connected to the I / O interface 55, including an input unit 56, such as a keyboard, a mouse, etc.; an output unit 57, such as various types of displays, speakers, etc.; a storage unit 58, such as a magnetic disk, an optical disk, etc.; and a communication unit 59, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 59 allows the electronic device 50 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0142] The processor 51 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 51 executes the various methods and processes described above, such as the network communication method.
[0143] In some embodiments, the network communication method can be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the network communication method described above can be performed. Alternatively, in other embodiments, processor 51 can be configured to perform the network communication method in any other appropriate manner (e.g., by means of firmware).
[0144] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0145] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0146] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0147] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0148] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0149] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0150] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0151] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A network communication method, characterized in that: include: Monitor the data stream layer corresponding to the driver framework of the client's operating system to obtain the communication data to be encrypted; Determining whether to encrypt the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and based on a preset storage container; wherein the preset storage container stores a storage path of the application to be protected; the data analysis result is used to determine whether the communication data to be encrypted is communication data corresponding to the application to be protected, and to determine whether the storage path of the application associated with the communication data to be encrypted is within the preset storage container; If so, encrypting the communication data to be encrypted to generate encrypted communication data; When the address layer corresponding to the driving framework monitors the transmission data packet of the encrypted communication data, the encrypted communication data is decrypted, and the decrypted communication data obtained after decryption is reassembled into a data packet and then transmitted to the server; Wherein, the network communication method further includes: Monitor the first session layer corresponding to the driver framework to obtain a socket connection creation request; Parsing the socket connection creation request to obtain a target process identifier and target five-tuple information corresponding to the socket connection creation request; Determining whether to update the preset storage container according to the target process identifier and the target quintuple information; If so, the target quintuple information is stored in the preset storage container to update the preset storage container.
2. The method according to claim 1, characterized in that The determining whether to update the preset storage container according to the target process identifier and the target quintuple information includes: Obtaining the path information of the program to be protected of the client; Determining, according to the target process identifier, a target application process that generates the Socket connection creation request; If the communication transmission protocol in the target quintuple information meets the preset protocol judgment condition, then determining the target program path corresponding to the target application process; Determining whether the target application process meets a preset program protection condition based on the target program path and the to-be-protected program path information, and obtaining a program protection condition determination result; According to the program protection condition judgment result, it is determined whether to update the preset storage container.
3. The method according to claim 2, characterized in that The program path information to be protected includes at least one reference program path of the application to be protected; Accordingly, judging whether the target application process meets the preset program protection condition based on the target program path and the path information of the program to be protected, and obtaining the program protection condition judgment result, includes: Obtaining a program protection condition judgment result based on a matching condition between the target program path and each reference program path; Accordingly, determining whether to update the preset storage container according to the program protection condition judgment result includes: If there is a reference program path that matches the target program path, determining to update the preset storage container; If there is no reference program path matching the target program path, the preset storage container is not updated.
4. The method according to any one of claims 1 to 3, characterized in that The step of determining whether to encrypt the communication data to be encrypted based on a preset storage container according to a result of data analysis of the communication data to be encrypted includes: Parsing the communication data to be encrypted to obtain quintuple information corresponding to the communication data to be encrypted; Whether to encrypt the communication data to be encrypted is determined according to whether the quintuple information corresponding to the communication data to be encrypted exists in the preset storage container.
5. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Monitor the address layer corresponding to the driver framework to obtain transmission data packets; Parsing the transmission data packet to obtain parsed communication data and quintuple information corresponding to the parsed communication data; If the five-tuple information corresponding to the parsed communication data exists in the preset storage container, the parsed communication data is decrypted to obtain decrypted communication data, and the decrypted communication data is reassembled into data packets and then transmitted to the server.
6. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Monitor the second session layer corresponding to the driver framework to obtain a socket disconnection request; Parsing the Socket disconnection request to obtain quintuple information corresponding to the Socket disconnection request; If the quintuple information corresponding to the Socket disconnection request exists in the preset storage container, the quintuple information corresponding to the Socket disconnection request is removed from the preset storage container to update the preset storage container.
7. A network communication device, characterized in that: include: The encrypted data acquisition module is used to monitor the data stream layer corresponding to the driver framework of the client's operating system to obtain the communication data to be encrypted; an encryption processing determination module, configured to determine whether to encrypt the communication data to be encrypted based on a data analysis result of the communication data to be encrypted and based on a preset storage container; wherein the preset storage container stores a storage path of the application to be protected; the data analysis result is used to determine whether the communication data to be encrypted is communication data corresponding to the application to be protected, and to determine whether the storage path of the application associated with the communication data to be encrypted is within the preset storage container; an encrypted data generating module, configured to, if it is determined that the communication data to be encrypted is to be encrypted, encrypt the communication data to be encrypted to generate encrypted communication data; a communication data decryption module, configured to decrypt the encrypted communication data when the address layer corresponding to the driver framework monitors the transmission data packet of the encrypted communication data, and to reassemble the decrypted communication data obtained after decryption and transmit it to the server; Wherein, the network communication device further includes: A creation request acquisition module is used to monitor the first session layer corresponding to the driver framework and obtain a socket connection creation request; A creation request parsing module is used to parse the socket connection creation request to obtain the target process identifier and target five-tuple information corresponding to the socket connection creation request; An update judgment module, configured to determine whether to update the preset storage container based on the target process identifier and the target quintuple information; The container updating module is configured to store the target quintuple information in the preset storage container if it is determined to update the preset storage container, so as to update the preset storage container.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the network communication method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network communication method according to any one of claims 1 to 6 when executed.