An advanced persistent threat encrypted traffic detection method, device and electronic equipment

By performing image transformation and convolutional neural network training on APT encrypted traffic data, session attribute images are generated, solving the problem that existing technologies cannot comprehensively detect APT malicious traffic and achieving more efficient and accurate detection results.

CN116436620BActive Publication Date: 2026-06-02CHINA INFORMATION TECH SECURITY EVALUATION CENT

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA INFORMATION TECH SECURITY EVALUATION CENT
Filing Date
2021-12-29
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing technologies that use a single session to detect APT malicious traffic cannot fully detect encrypted traffic from advanced persistent threats.

Method used

By acquiring APT encrypted traffic data and normal traffic data, image conversion is performed to generate session attribute images, and a recognition model is trained using a convolutional neural network model to achieve comprehensive detection of network traffic.

Benefits of technology

The identification model trained using dual-entity, multi-session features can detect APT malicious traffic more comprehensively and accurately, reducing the workload of feature engineering and improving detection efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116436620B_ABST
    Figure CN116436620B_ABST
Patent Text Reader

Abstract

The application provides an APT encrypted traffic detection method and device and electronic equipment, which can use an APT identification model trained according to the double-entity multi-session characteristics of APT encrypted traffic to detect whether the obtained network traffic is APT encrypted traffic, so that APT malicious traffic can be detected as comprehensively and accurately as possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and more specifically, to a method, apparatus, and electronic device for detecting encrypted traffic of advanced persistent threats. Background Technology

[0002] Currently, Advanced Persistent Threats (APTs) refer to covert and persistent computer network intrusion processes. APTs comprise three elements: advanced, persistent, and threat. "Advanced" emphasizes the use of sophisticated malware and techniques to exploit vulnerabilities in systems; "persistent" refers to the continuous monitoring of specific targets and the acquisition of data from them; and "threat" refers to cyberattacks planned and executed by humans.

[0003] Using a single session to detect APT malicious traffic has the drawback of not being able to comprehensively detect APT malicious traffic. Summary of the Invention

[0004] To address the aforementioned problems, the present invention aims to provide an APT encrypted traffic detection method, apparatus, and electronic device.

[0005] In a first aspect, embodiments of the present invention provide a method for detecting APT encrypted traffic, comprising:

[0006] Obtain APT encrypted traffic data and normal traffic data;

[0007] The APT encrypted traffic data is processed to obtain first session attribute information, and the normal traffic data is processed to obtain second session attribute information.

[0008] The first session attribute information is converted into an image to obtain a first session attribute image, and the second session attribute information is converted into an image to obtain a second session attribute image.

[0009] The convolutional neural network model is trained using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic;

[0010] When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic.

[0011] Secondly, embodiments of the present invention also provide an APT encrypted traffic detection device, comprising:

[0012] The acquisition module is used to acquire APT encrypted traffic data and normal traffic data;

[0013] The processing module is used to process the APT encrypted traffic data to obtain first session attribute information, and to process the normal traffic data to obtain second session attribute information.

[0014] The conversion module is used to convert the first session attribute information into an image to obtain a first session attribute image, and to convert the second session attribute information into an image to obtain a second session attribute image.

[0015] The training module is used to train a convolutional neural network model using the first session attribute image and the second session attribute image, thereby training an APT identification model for identifying the APT encrypted traffic.

[0016] The detection module is used to detect whether the acquired network traffic is APT encrypted traffic using the APT identification model when network traffic is acquired.

[0017] Thirdly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the steps of the method described in the first aspect above.

[0018] Fourthly, embodiments of the present invention also provide an electronic device, the electronic device including a memory, a processor and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor using the steps of the method described in the first aspect above.

[0019] In the solutions provided by the first to fourth aspects of the present invention, after acquiring APT encrypted traffic data and normal traffic data, the APT encrypted traffic data is image-converted to obtain a first session attribute image, and the second session attribute information is image-converted to obtain a second session attribute image. A convolutional neural network model is trained using the first and second session attribute images to obtain an APT identification model for recognizing APT encrypted traffic. When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic. Compared with the related technologies that use a single session to detect malicious APT traffic, the APT identification model trained using the dual-entity, multi-session features of APT encrypted traffic can detect whether the acquired network traffic is APT encrypted traffic, thus enabling the most comprehensive and accurate detection of malicious APT traffic.

[0020] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 A flowchart of an APT encrypted traffic detection method provided in Embodiment 1 of the present invention is shown;

[0023] Figure 2 This diagram illustrates the session attribute image between communication entity 1 (IP-1) and communication entity 2 (IP-2) in the APT encrypted traffic detection method provided in Embodiment 1 of the present invention.

[0024] Figure 3 This diagram illustrates the structure of an APT encrypted traffic detection device provided in Embodiment 2 of the present invention.

[0025] Figure 4 A schematic diagram of the structure of an electronic device provided in Embodiment 3 of the present invention is shown. Detailed Implementation

[0026] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.

[0027] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0028] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0029] Currently, APT refers to a stealthy and persistent computer network intrusion process. Advanced long-term threats (APTs) comprise three elements: advanced, long-term, and threat. "Advanced" emphasizes the use of sophisticated malware and techniques to exploit vulnerabilities in systems; "long-term" refers to the continuous monitoring of specific targets and the acquisition of data from them; and "threat" refers to cyberattacks planned and executed by human intervention.

[0030] Using a single session to detect APT malicious traffic has the drawback of not being able to comprehensively detect APT malicious traffic.

[0031] Based on this, this embodiment proposes an APT encrypted traffic detection method, device, and electronic device. After acquiring APT encrypted traffic data and normal traffic data, the APT encrypted traffic data is image-converted to obtain a first session attribute image, and the second session attribute information is image-converted to obtain a second session attribute image. A convolutional neural network model is trained using the first and second session attribute images to obtain an APT identification model for recognizing APT encrypted traffic. When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic. The APT identification model trained using the dual-entity multi-session features of APT encrypted traffic can detect whether the acquired network traffic is APT encrypted traffic, which can detect APT malicious traffic as comprehensively and accurately as possible.

[0032] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0033] Example 1

[0034] The APT encrypted traffic detection method proposed in this embodiment is executed by a third-party computing device other than the client and server conducting the session.

[0035] See Figure 1 The flowchart shown illustrates an APT encrypted traffic detection method. This embodiment proposes an APT encrypted traffic detection method, which includes the following specific steps:

[0036] Step 100: Obtain APT encrypted traffic data and normal traffic data.

[0037] In step 100 above, the third-party computing device can generate APT encrypted traffic data by running an APT malware sample in a virtual machine running on the third-party computing device itself. The third-party computing device collects these generated APT encrypted traffic data and the continuous multiple sessions generated during the command and control phase. That is, the APT encrypted traffic data includes: multiple sessions generated by the APT malware sample during the command and control phase.

[0038] The normal traffic data refers to multiple sessions formed by the traffic data generated during network communication between the third-party computing device and a normal application or browser obtained from the network, and the server responding to normal network services.

[0039] Step 102: Process the APT encrypted traffic data to obtain first session attribute information, and process the normal traffic data to obtain second session attribute information.

[0040] In step 102 above, in order to obtain the first session attribute information, the following steps (1) to (3) can be performed:

[0041] (1) Perform protocol parsing on the APT encrypted traffic data to determine the quadruple of the APT encrypted traffic data;

[0042] (2) According to the source IP address and destination IP address recorded in the quadruple, the multiple sessions in the APT encrypted traffic data are grouped to obtain APT dual-entity multi-session groups; wherein, each session in the APT dual-entity multi-session group has the same source IP address and destination IP address;

[0043] (3) Obtain the occurrence time, uplink data volume and downlink data volume of each session in the multi-session group of the APT dual entity as the first session attribute information from the multi-session group of the APT dual entity.

[0044] In step (1) above, the specific process of parsing the APT encrypted traffic data to determine the quadruple of the APT encrypted traffic data is existing technology and will not be described in detail here.

[0045] In step (2) above, each session in the APT dual-entity multi-session packet has the same source IP address and destination IP address, that is, each session in the same APT dual-entity multi-session packet has the same source IP address and destination IP address.

[0046] The term "dual entity" refers to the two parties conducting a session in the network. In the APT encrypted traffic detection method proposed in this embodiment, the dual entity refers to the client using the source IP address and the server using the destination IP address.

[0047] In step (3) above, the uplink data is used to represent the data sent by the client to the server in the session.

[0048] The amount of upstream data refers to how much data the client sends to the server during the session.

[0049] The downlink data is used to represent the data sent from the server to the client during the session.

[0050] The amount of upstream data refers to how much data the server sends to the client during the session.

[0051] The process of obtaining the second session attribute information is similar to the process of obtaining the first session attribute information, and will not be described in detail here.

[0052] The second session attribute information includes: the occurrence time, uplink data volume, and downlink data volume of each session in the dual-entity multi-session group in normal traffic data.

[0053] Step 104: Perform image conversion on the first session attribute information to obtain a first session attribute image, and perform image conversion on the second session attribute information to obtain a second session attribute image.

[0054] To obtain the first session attribute image, the following steps (1) to (3) can be performed:

[0055] (1) Determine the time interval between each session by using the occurrence time of each session;

[0056] (2) Combine the bar charts representing the amount of uplink data and the bar charts representing the amount of downlink data in each session to obtain a bar chart of each session;

[0057] (3) According to the time interval between each session, set the bar chart of each session to a rectangular coordinate system with the session occurrence time as the horizontal axis and the session data volume as the vertical axis to obtain the first session attribute image; wherein, in the first session attribute image, the bar chart of the uplink data volume in each session is located above the horizontal axis, and the bar chart of the downlink data volume in each session is located above the horizontal axis.

[0058] The specific process of obtaining the second session attribute image is similar to the process of obtaining the first session attribute image described above, and will not be repeated here.

[0059] In one implementation, such as Figure 2 The diagram shows a session attribute graph between communication entity 1 (IP-1) and communication entity 2 (IP-2). Each bar represents the session attribute information, such as the time of occurrence, the amount of uplink data, and the amount of downlink data.

[0060] The content of step 104 confirms that by using the process described in steps (1) to (3) of step 104, the first session attribute information of APT encrypted traffic data and the second session attribute information of normal traffic data are cleverly converted into a bar chart of sessions. The bar chart of sessions specifically represents the session attribute features of APT encrypted traffic data and normal traffic data. As a result, the APT identification model obtained after training the convolutional neural network model using the first session attribute image and the second session attribute image can effectively identify the session attribute features of APT traffic data, thereby enabling comprehensive and effective identification of APT traffic data.

[0061] After obtaining the first session attribute image and the second session attribute image through the above step 104, the following step 106 can be performed to train the APT recognition model.

[0062] Step 106: Train the convolutional neural network model using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic.

[0063] In step 106 above, the convolutional neural network model can be, but is not limited to, LeNet and AlexNet.

[0064] The specific process of training a convolutional neural network model using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic is existing technology and will not be elaborated here.

[0065] Step 108: When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic.

[0066] In step 108 above, after obtaining the network traffic, the session attribute information in the network traffic can be extracted first, and then the session attribute information in the network traffic can be converted into a session attribute image with multiple session histograms. Then, the session attribute image of the network traffic with multiple session histograms is input into the APT identification model to detect whether the obtained network traffic is APT encrypted traffic.

[0067] In the process of using the APT identification model to detect whether the acquired network traffic is APT encrypted traffic, the network traffic can be periodically detected for APT encrypted traffic. The periodic period is determined by the network traffic characteristics of the model deployment environment and the evolution speed of APT. If the network traffic changes more significantly or the APT evolves faster, the update period should be shorter.

[0068] The APT encrypted traffic detection method proposed in this embodiment has the following characteristics:

[0069] 1. The APT encrypted traffic detection method proposed in this embodiment uses a dual-entity, multi-session approach, which better utilizes the multi-session data characteristics of the command and control phase. The multi-session data generated by APTs between two entities within a fixed time period has many identifiable features. Compared to mainstream machine learning detection methods that rely on single-session detection, this method can better identify features such as uplink / downlink relationships, uplink / downlink ratios, and time intervals. It has a wider detection dimension, utilizes richer information, and provides more comprehensive, accurate, and reliable detection results for determining whether network traffic is APT encrypted traffic.

[0070] 2. The APT encrypted traffic detection method proposed in this embodiment utilizes convolutional neural networks to achieve image recognition and traffic classification. This eliminates the need for manually designed features, reducing the workload of feature engineering. Compared to traditional machine learning-based threat traffic detection methods, this method converts various session data features between two entities and multiple sessions to be identified into image data, using image recognition to achieve traffic identification. This fully leverages the image recognition advantages of convolutional neural networks, improving recognition accuracy while significantly reducing the feature engineering workload of traditional machine learning methods, thus improving model training and application efficiency.

[0071] In summary, this embodiment proposes an APT encrypted traffic detection method. After acquiring APT encrypted traffic data and normal traffic data, the APT encrypted traffic data is image-converted to obtain a first session attribute image, and the second session attribute information is image-converted to obtain a second session attribute image. A convolutional neural network model is trained using the first and second session attribute images to obtain an APT identification model for recognizing APT encrypted traffic. When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic. Compared with related technologies that use a single session to detect malicious APT traffic, this method utilizes the APT identification model trained with the dual-entity, multi-session features of APT encrypted traffic to detect whether the acquired network traffic is APT encrypted traffic, thus enabling more comprehensive and accurate detection of malicious APT traffic.

[0072] Example 2

[0073] This embodiment proposes an APT encrypted traffic detection device for executing the APT encrypted traffic detection method proposed in Embodiment 1 above.

[0074] See Figure 3 The diagram shows the structure of an APT encrypted traffic detection device. The APT encrypted traffic detection device proposed in this embodiment includes:

[0075] Module 300 is used to acquire APT encrypted traffic data and normal traffic data;

[0076] The processing module 302 is used to process the APT encrypted traffic data to obtain first session attribute information, and to process the normal traffic data to obtain second session attribute information.

[0077] The conversion module 304 is used to convert the first session attribute information into an image to obtain a first session attribute image, and to convert the second session attribute information into an image to obtain a second session attribute image.

[0078] Training module 306 is used to train a convolutional neural network model using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic.

[0079] The detection module 308 is used to detect whether the acquired network traffic is APT encrypted traffic using the APT identification model when network traffic is acquired.

[0080] The APT encrypted traffic data includes: multiple sessions; the processing module is specifically used for:

[0081] The APT encrypted traffic data is parsed to determine the quadruple of the APT encrypted traffic data;

[0082] Based on the source IP address and destination IP address recorded in the quadruple, the multiple sessions in the APT encrypted traffic data are grouped to obtain APT dual-entity multi-session packets; wherein, each session in the APT dual-entity multi-session packets has the same source IP address and destination IP address;

[0083] The occurrence time, uplink data volume, and downlink data volume of each session in the multi-session group of the APT dual entity are obtained from the multi-session group of the APT dual entity as the first session attribute information.

[0084] The conversion module is specifically used for:

[0085] Determine the time interval between each session by using the occurrence time of each session;

[0086] By combining the bar charts representing the amount of uplink data and the bar charts representing the amount of downlink data in each session, a bar chart of each session is obtained.

[0087] Based on the time interval between each session, the bar charts of each session are respectively set into a Cartesian coordinate system with the session occurrence time as the horizontal axis and the session data volume as the vertical axis to obtain a first session attribute image; wherein, in the first session attribute image, the bar charts of the uplink data volume in each session are located above the horizontal axis, and the bar charts of the downlink data volume in each session are located above the horizontal axis.

[0088] In summary, this embodiment proposes an APT encrypted traffic detection device. After acquiring APT encrypted traffic data and normal traffic data, the device performs image conversion on the APT encrypted traffic data to obtain a first session attribute image, and performs image conversion on the second session attribute information to obtain a second session attribute image. A convolutional neural network model is trained using the first and second session attribute images to obtain an APT identification model for recognizing APT encrypted traffic. When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic. Compared with related technologies that use a single session to detect malicious APT traffic, this device utilizes the APT identification model trained with the dual-entity, multi-session features of APT encrypted traffic to detect whether the acquired network traffic is APT encrypted traffic, thus enabling more comprehensive and accurate detection of malicious APT traffic.

[0089] Example 3

[0090] This embodiment proposes a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it executes the steps of the APT encrypted traffic detection method described in Embodiment 1 above. For specific implementation details, please refer to Method Embodiment 1, which will not be repeated here.

[0091] In addition, see Figure 3 The diagram shows the structure of an electronic device. This embodiment also proposes an electronic device, which includes a bus 51, a processor 52, a transceiver 53, a bus interface 54, a memory 55, and a user interface 56. The electronic device includes a memory 55.

[0092] In this embodiment, the electronic device further includes: one or more programs stored in the memory 55 and executable on the processor 52, configured to be executed by the processor to perform the one or more programs for steps (1) to (5):

[0093] (1) Obtain APT encrypted traffic data and normal traffic data;

[0094] (2) Process the APT encrypted traffic data to obtain first session attribute information, and process the normal traffic data to obtain second session attribute information;

[0095] (3) The first session attribute information is converted into an image to obtain a first session attribute image, and the second session attribute information is converted into an image to obtain a second session attribute image;

[0096] (4) The convolutional neural network model is trained using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic.

[0097] (5) When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic.

[0098] Transceiver 53 is used to receive and send data under the control of processor 52.

[0099] The bus architecture (represented by bus 51) can include any number of interconnected buses and bridges, linking various circuits including one or more processors represented by processor 52 and memory represented by memory 55. Bus 51 can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be further described in this embodiment. Bus interface 54 provides an interface between bus 51 and transceiver 53. Transceiver 53 can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. For example, transceiver 53 receives external data from other devices. Transceiver 53 is used to transmit data processed by processor 52 to other devices. Depending on the nature of the computing system, a user interface 56 may also be provided, such as a keypad, display, speaker, microphone, or joystick.

[0100] Processor 52 is responsible for managing bus 51 and general processing, such as running a general-purpose operating system as described above. Memory 55 can be used to store data used by processor 52 during operation.

[0101] Optionally, the processor 52 may be, but is not limited to, a central processing unit, a microcontroller, a microprocessor, or a programmable logic device.

[0102] It is understood that the memory 55 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDRSDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). The memory 55 of the systems and methods described in this embodiment is intended to include, but is not limited to, these and any other suitable types of memory.

[0103] In some implementations, memory 55 stores elements such as executable modules or data structures, or subsets thereof, or extended sets thereof: operating system 551 and application programs 552.

[0104] The operating system 551 includes various system programs, such as the framework layer, core library layer, and driver layer, used to implement various basic business functions and handle hardware-based tasks. The application program 552 includes various applications, such as a media player and a browser, used to implement various application functions. The program implementing the method of this embodiment can be included in the application program 552.

[0105] In summary, this embodiment proposes a computer-readable storage medium and electronic device. After acquiring APT encrypted traffic data and normal traffic data, the APT encrypted traffic data is image-converted to obtain a first session attribute image, and the second session attribute information is image-converted to obtain a second session attribute image. A convolutional neural network model is trained using the first and second session attribute images to obtain an APT identification model for recognizing APT encrypted traffic. When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic. Compared with related technologies that use a single session to detect malicious APT traffic, the APT identification model trained using the dual-entity, multi-session features of APT encrypted traffic can detect whether the acquired network traffic is APT encrypted traffic, thus enabling more comprehensive and accurate detection of malicious APT traffic.

[0106] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for detecting encrypted traffic of Advanced Persistent Threat (APT), characterized in that, include: Obtain APT encrypted traffic data and normal traffic data; The APT encrypted traffic data is parsed to determine the quadruple of the APT encrypted traffic data; Based on the source IP address and destination IP address recorded in the quadruple, multiple sessions in the APT encrypted traffic data are grouped to obtain APT dual-entity multi-session packets; wherein each session in the APT dual-entity multi-session packets has the same source IP address and destination IP address; the occurrence time, uplink data volume, and downlink data volume of each session are obtained from the APT dual-entity multi-session packets as the first session attribute information; and the normal traffic data is processed in the same way to obtain the second session attribute information; The time interval between each session is determined by using the occurrence time of each session; the bar charts representing the uplink data volume and downlink data volume in each session are stitched together to obtain a bar chart of each session; according to the time interval between each session, the bar charts of each session are respectively set into a rectangular coordinate system with the session occurrence time as the horizontal axis and the session data volume as the vertical axis to obtain a first session attribute image; and the second session attribute information is transformed in the same way to obtain a second session attribute image; The convolutional neural network model is trained using the first session attribute image and the second session attribute image to obtain an APT identification model for identifying the APT encrypted traffic; When network traffic is acquired, the APT identification model is used to detect whether the acquired network traffic is APT encrypted traffic.

2. The method according to claim 1, characterized in that, In the first session attribute image, the bar chart of the uplink data volume in each session is located above the horizontal axis of the coordinate system, and the bar chart of the downlink data volume in each session is located above the horizontal axis of the coordinate system.

3. A device for detecting encrypted traffic of Advanced Persistent Threat (APT), characterized in that, include: The acquisition module is used to acquire APT encrypted traffic data and normal traffic data; The processing module is used to perform protocol parsing on the APT encrypted traffic data to determine the four-tuple of the APT encrypted traffic data; group multiple sessions in the APT encrypted traffic data according to the source IP address and destination IP address recorded in the four-tuple to obtain APT dual-entity multi-session packets; wherein each session in the APT dual-entity multi-session packets has the same source IP address and destination IP address; obtain the occurrence time, uplink data volume, and downlink data volume of each session from the APT dual-entity multi-session packets as first session attribute information; and process the normal traffic data in the same way to obtain second session attribute information; The conversion module is used to determine the time interval between each session by utilizing the occurrence time of each session; to stitch together the bar charts representing the uplink data volume and downlink data volume in each session to obtain a bar chart of each session; to set the bar charts of each session onto a Cartesian coordinate system with the session occurrence time as the horizontal axis and the session data volume as the vertical axis according to the time interval between each session to obtain a first session attribute image; and to perform image conversion on the second session attribute information in the same way to obtain a second session attribute image; The training module is used to train a convolutional neural network model using the first session attribute image and the second session attribute image, thereby training an APT identification model for identifying the APT encrypted traffic. The detection module is used to detect whether the acquired network traffic is APT encrypted traffic using the APT identification model when network traffic is acquired.

4. The apparatus according to claim 3, characterized in that, The conversion module is also used for: In the first session attribute image, the bar chart of the uplink data volume in each session is located above the horizontal axis of the coordinate system, and the bar chart of the downlink data volume in each session is located above the horizontal axis of the coordinate system.

5. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program, when executed by a processor, performs the steps of the method described in any one of claims 1-2.

6. An electronic device, characterized in that, The electronic device includes a memory, a processor, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor of the steps of the method according to any one of claims 1-2.