A message feature obfuscation method

CN116318835BActive Publication Date: 2026-09-18NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310064236.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-12
Publication Date
2026-09-18
Estimated Expiration
2043-01-12

AI Technical Summary

Technical Problem

然而,利用数据包冗余进行流量混淆会极大增加网络负载,产生较大延迟,影响数据传输效率

Benefits of technology

[0037] This invention is applied to the data transmission and reception stage of covert communication links. It comprehensively utilizes encryption, padding, delay, and white noise, combined with corresponding mechanisms, to achieve multi-feature obfuscation of message characteristics, distribution characteristics, time series characteristics, etc. While effectively ensuring the efficiency of information data transmission in the network, it improves the covertness and security of communication and can resist traffic analysis attacks based on machine learning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116318835B_ABST
    Figure CN116318835B_ABST
Patent Text Reader

Abstract

The application discloses a message feature confusion method, which comprises the following steps: after a message is encapsulated according to a preset message format, the message is filled randomly; the filled message is encapsulated again according to a preset encryption format, and a header field is confused; the timing feature of the confused message is confused; and white noise is randomly generated to confuse the message again. The application can eliminate the communication behavior flow feature, hide the communication data flow in massive background flow data, and eliminate the correlation between upstream flow and downstream flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security transmission technology, and in particular relates to a message feature obfuscation method. Background Technology

[0002] Traffic obfuscation techniques aim to ensure that target traffic cannot be identified by attackers in the observed traffic set by performing a series of randomization, mimicry shaping and other operations on traffic.

[0003] Current traditional traffic obfuscation techniques mostly involve reshaping network data packets to obfuscate their characteristics. However, using packet redundancy for traffic obfuscation can significantly increase network load, cause substantial latency, and negatively impact data transmission efficiency.

[0004] As network monitoring and censorship technologies continue to evolve, covert communication technologies are facing the challenge of analyzing computer fingerprints in traffic data and protocols to locate physical hosts and trace communication relationships. Attackers with access to large amounts of internet traffic resources are employing big data correlation and other analytical methods to discover covert channels, enabling them to effectively correlate and trace encrypted traffic in single-proxy VPN communications and simple multi-hop cascading communication links. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a message feature obfuscation method. This method employs a series of techniques, including data payload encryption, message random padding, random data stream delay, and white noise in the traffic flow. The core of this method utilizes a custom obfuscation protocol to encrypt custom header fields and randomly pad variable-length data packets, controlling the data stream communication forwarding process and data volume to eliminate traffic characteristics associated with communication behavior. Finally, it randomizes the transmission of noisy traffic, hiding the communication data traffic within massive background traffic data and eliminating the correlation between upstream and downstream traffic.

[0006] The objective of this invention is achieved through the following technical solution:

[0007] A message signature obfuscation method, the method comprising:

[0008] The message is encapsulated according to the preset message format and then randomly filled in;

[0009] The padded message is re-encapsulated according to a preset encryption format, and the header fields are obfuscated;

[0010] Obfuscating the timing characteristics of messages;

[0011] Randomly generated white noise is used to further obfuscate the messages.

[0012] Furthermore, the preset message format includes message length, padding length, and message payload;

[0013] The message is a variable-length message. The message length and the padding length are preset in bytes. The message payload includes the actual payload and the padding payload. The actual payload occupies bytes equal to the difference between the message length and the padding length. The padding payload occupies bytes equal to the padding length.

[0014] Furthermore, the random filling specifically includes:

[0015] Based on the current sent and received context message length and the current amount of data to be sent, the message is randomly filled with variable-length data messages so that the length of the filled message is within a preset range.

[0016] Furthermore, the preset encryption format includes a key offset, message length, data payload, and data key;

[0017] The key offset indicates the position of the data encryption key within the data payload;

[0018] The message length indicates the total length of the data payload and the data key;

[0019] The data payload includes a padded message;

[0020] The data key is used to encrypt the data payload and is randomly inserted into the encrypted data payload.

[0021] Furthermore, the step of re-encapsulating the padded message according to a preset encryption format and obfuscating the header fields specifically includes:

[0022] Randomly generate an encryption key and XOR the padded message for encryption.

[0023] Randomly generate an offset integer, with the integer range between 0 and the data payload length;

[0024] Insert the encryption key into the data payload according to the offset;

[0025] Calculate the overall data length and re-encapsulate the message.

[0026] Furthermore, the timing characteristics of the obfuscated messages specifically include:

[0027] Based on the characteristics of normal protocol message sequences, a random time delay is added during message processing and transmission.

[0028] Furthermore, the random addition of time delays to message processing and transmission based on the characteristics of normal protocol message sequences specifically includes:

[0029] The data packet transmission time sequence is controlled so that the packet time sequence characteristics conform to the preset protocol communication traffic characteristics, wherein the random delay time of transmission is set within a preset time threshold.

[0030] Furthermore, the method also includes expanding the random delay time sequence based on the actual time the message is sent.

[0031] Furthermore, the randomized transmission of noise traffic specifically includes:

[0032] During the interval between message transmissions, randomly generated padding messages are added to the message queue and encapsulated in the same format as the original message.

[0033] Furthermore, the step of adding randomly generated padding messages to the message queue during the message transmission interval and encapsulating them in the same format as the original message specifically includes:

[0034] During the message transmission interval, TAP messages of random length are randomly generated and placed into the transmission queue according to the current data transmission volume;

[0035] After being encapsulated according to the preset message format and preset encryption format, it is placed into the transmission queue.

[0036] The beneficial effects of this invention are as follows:

[0037] This invention is applied to the data transmission and reception stage of covert communication links. It comprehensively utilizes encryption, padding, delay, and white noise, combined with corresponding mechanisms, to achieve multi-feature obfuscation of message characteristics, distribution characteristics, time series characteristics, etc. While effectively ensuring the efficiency of information data transmission in the network, it improves the covertness and security of communication and can resist traffic analysis attacks based on machine learning. Attached Figure Description

[0038] Figure 1 This is a schematic diagram of the message feature obfuscation method provided in an embodiment of the present invention;

[0039] Figure 2 This is a schematic diagram of the preset message format structure in an embodiment of the present invention;

[0040] Figure 3 This is a schematic diagram of the preset encryption format structure in an embodiment of the present invention. Detailed Implementation

[0041] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and features described therein can be combined with each other.

[0042] Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0043] Current traditional traffic obfuscation techniques mostly involve reshaping network data packets to obfuscate their characteristics. However, using packet redundancy for traffic obfuscation can significantly increase network load, cause substantial latency, and negatively impact data transmission efficiency.

[0044] As network monitoring and censorship technologies continue to evolve, covert communication technologies are facing the challenge of analyzing computer fingerprints in traffic data and protocols to locate physical hosts and trace communication relationships. Attackers with access to large amounts of internet traffic resources are employing big data correlation and other analytical methods to discover covert channels, enabling them to effectively correlate and trace encrypted traffic in single-proxy VPN communications and simple multi-hop cascading communication links.

[0045] To address the aforementioned technical problems, the following embodiments of a message feature obfuscation method of the present invention are proposed.

[0046] Reference Figure 1 ,like Figure 1 The diagram shown is a flowchart of the message signature obfuscation method provided in this embodiment. The method specifically includes the following steps:

[0047] Step S100: Encapsulate the message according to the preset message format and then randomly fill it. Based on the length of the current sent and received context messages and the current amount of data to be sent, randomly fill the message to be sent, making the distribution of messages at each stage more random.

[0048] This embodiment customizes the message format of the obfuscation protocol according to the method requirements, referring to... Figure 2 ,like Figure 2 The diagram shown is a schematic diagram of the preset message format structure in this embodiment.

[0049] Specifically, the message is a variable length message, mainly consisting of four parts: message length, padding length, and message payload (including actual payload and padding payload).

[0050] Message length: occupies 2 bytes, mainly indicating the number of bytes of the sent message payload.

[0051] Padding length: occupies 1 byte and mainly indicates the length of the padding bytes.

[0052] Actual payload: This consists of bytes representing the message length minus the padding length, and is the main transmitted data.

[0053] Padding payload: Occupies the padding length of bytes, placed at the end of the message, and consists of randomly generated meaningless characters.

[0054] The random filling process in this embodiment includes the following steps:

[0055] Step S101: During the covert communication handshake phase, the original message is padded according to the current amount of data being transmitted. The padded length is randomized according to the length of the sent message, so that the message length can be uniformly within the normal data transmission range and avoid the padded length being too long, which would affect the transmission efficiency.

[0056] Step S102: Fill the string with randomly generated meaningless binary data to avoid statistical characteristics of the same string.

[0057] Step S200: Re-encapsulate the padded message according to a preset encryption format and obfuscate the header fields. The transmitted message is re-encapsulated, and the message format of relevant protocols, especially the message header fields, are encrypted and obfuscated to avoid identification of the message format and statistical extraction of field features.

[0058] Depending on the method requirements, customize the obfuscation protocol's encrypted message format, referring to... Figure 3 ,like Figure 3 The diagram shown is a schematic diagram of the preset encryption format structure in this embodiment.

[0059] The message includes: key offset, message length, data payload, and data key;

[0060] The key offset indicates the location of the data encryption key within the data payload.

[0061] Message length, which is the length of the payload plus the data key.

[0062] The data payload is the encrypted data.

[0063] The data key, used to encrypt the data payload, is randomly inserted into the encrypted data payload.

[0064] This step specifically includes the following steps:

[0065] Step S201: First, randomly generate an 8-bit encryption key, and then use an XOR algorithm to XOR encrypt the data.

[0066] Step S202: Then randomly generate an offset integer, with the integer range being from 0 to the data payload length.

[0067] Step S203: Then, the 8-bit encryption key used for encryption is inserted into the encrypted data payload according to the generated offset.

[0068] Step S204: Finally, calculate the overall data length and encapsulate the data message again. In this way, all fields of the message are random fields and do not have any protocol feature fields.

[0069] Step S300: Obfuscate the timing characteristics of the message. Randomly delay the message timing. Based on the statistical characteristics of normal protocol message sequences, randomly add time delays during message processing and transmission to obfuscate the timing characteristics.

[0070] During the covert communication handshake phase, after the encryption of the message is completed, a sending queue is used to control the sending time sequence of the data message, so that the message time sequence characteristics conform to the characteristics of normal protocol communication traffic.

[0071] In order not to affect normal business transmission, the random delay time will be set between 0-10ms. Combined with the actual transmission time, the random delay time sequence will be expanded to eliminate the timing characteristics generated by the inherent network.

[0072] Step S400: Randomly generate white noise to further obfuscate the messages. Randomizing the transmission of noisy traffic makes the covert communication data stream exhibit discrete distribution characteristics, which machine learning-based traffic analysis cannot capture. In addition to normal transmission traffic obfuscation, to prevent the upstream and downstream communication traffic of multi-hop communication networks from having a certain correlation, the protocol is designed to fill messages with TAP and randomly generate white noise for further obfuscation.

[0073] During the intervals between obfuscated message transmissions, TAP messages of random length are randomly generated and placed into the transmission queue based on the current data traffic. The message length is also randomly generated, determined by the amount of data being transmitted in the current data stream. The message content consists of randomly generated meaningless binary characters to avoid the appearance of corresponding message field characteristics.

[0074] Specifically, this embodiment performs Poisson mixing on information based on random time delay, treating whether the traffic "will be reached at a certain time" as discrete time, and using a certain transmission delay time to control the sum of traffic to conform to the Poisson process, thereby preventing third-party observers from guessing whether communication is in progress based on traffic peak and valley changes.

[0075] During the intervals between obfuscated message transmissions, based on the current data traffic, a Poisson mixture is applied to the information using a random delay to generate random-length TAP messages, which are then added with a certain delay and placed into the transmission queue. The message length is randomly generated, determined by the amount of data currently being transmitted. The message content consists of randomly generated, meaningless binary characters to avoid displaying any characteristic message field features.

[0076] Finally, the message is encapsulated according to the format of the obfuscation protocol and placed into the transmission queue.

[0077] The message feature obfuscation method provided in this embodiment is applied to the data transmission and reception stage of covert communication links. It comprehensively utilizes encryption, padding, delay, and white noise, combined with corresponding mechanisms, to obfuscate multiple features such as message features, distribution features, and time series features. While effectively ensuring the efficiency of information data transmission in the network, it improves the covertness and security of communication and can resist traffic analysis attacks based on machine learning.

[0078] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A message feature obfuscation method, characterized in that, The method includes: The message is encapsulated according to the preset message format and then randomly filled in; The padded message is re-encapsulated according to a preset encryption format, and the header fields are obfuscated; Obfuscating the timing characteristics of messages; Randomly generated white noise is used to further obfuscate the messages; The preset message format includes message length, padding length, and message payload; The message is a variable-length message. The message length and the padding length are preset in bytes. The message payload includes the actual payload and the padding payload. The actual payload occupies bytes equal to the difference between the message length and the padding length. The padding payload occupies bytes equal to the padding length. The random filling specifically includes: Based on the current sent and received context message length and the current amount of data to be sent, the message is randomly filled with variable-length data messages so that the length of the filled message is within a preset range. The preset encryption format includes key offset, message length, data payload, and data key; The key offset indicates the position of the data encryption key within the data payload; The message length indicates the total length of the data payload and the data key; The data payload includes a padded message; The data key is used to encrypt the data payload and is randomly inserted into the encrypted data payload. The process of re-encapsulating the padded message according to a preset encryption format and obfuscating the header fields specifically includes: Randomly generate an encryption key and XOR the padded message for encryption. Randomly generate an offset integer, with the integer range between 0 and the data payload length; Insert the encryption key into the data payload according to the offset; Calculate the overall data length and re-encapsulate the message.

2. The message feature obfuscation method as described in claim 1, characterized in that, The timing characteristics of the obfuscated messages specifically include: Based on the characteristics of normal protocol message sequences, a random time delay is added during message processing and transmission.

3. The message feature obfuscation method as described in claim 2, characterized in that, The random addition of time delays to message processing and transmission based on the characteristics of normal protocol message sequences specifically includes: The data packet transmission time sequence is controlled so that the packet time sequence characteristics conform to the preset protocol communication traffic characteristics, wherein the random delay time of transmission is set within a preset time threshold.

4. The message feature obfuscation method as described in claim 3, characterized in that, The method also includes expanding the random delay time sequence based on the actual time the message was sent.

5. The message feature obfuscation method as described in claim 1, characterized in that, The randomized transmission of noise traffic specifically includes: During the interval between message transmissions, randomly generated padding messages are added to the message queue and encapsulated in the same format as the original message.

6. The message feature obfuscation method as described in claim 5, characterized in that, The step of adding randomly generated padding messages to the message queue during the message transmission interval and encapsulating them in the same format as the message specifically includes: During the message transmission interval, TAP messages of random length are randomly generated and placed into the transmission queue according to the current data transmission volume; After being encapsulated according to the preset message format and preset encryption format, it is placed into the transmission queue.