A malicious encrypted traffic detection method, device and electronic equipment
By extracting feature information from encrypted traffic samples to train a machine learning model, the problem of low efficiency in detecting malicious encrypted traffic in existing technologies is solved, achieving efficient and accurate malicious traffic identification, applicable to any communication protocol.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-15
- Publication Date
- 2026-03-31
AI Technical Summary
Existing technologies struggle to effectively detect malicious traffic in encrypted communication protocols when decryption is impossible. Rule-based and file-based detection methods fail to extract valid rules or behavioral characteristics, resulting in low efficiency in detecting malicious encrypted traffic.
By extracting basic traffic and interaction features from malicious and normal encrypted traffic sample data, and training a machine learning model, a malicious encrypted traffic detection model is constructed to identify the characteristic information of client-server interactions.
It improves the efficiency and accuracy of detecting malicious encrypted traffic, avoids interference from handshake negotiation and certificate information, and can detect malicious traffic under any communication protocol.
Smart Images

Figure CN116647350B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and more specifically, to a method, apparatus, and electronic device for detecting malicious encrypted traffic. Background Technology
[0002] Currently, malicious traffic using encrypted communication protocols such as TLS is growing rapidly. In scenarios where traffic decryption is impossible, most current traffic security detection technologies face severe challenges in dealing with malicious encrypted traffic. Among detection methods built based on plaintext protocol analysis, rule-based detection methods cannot extract effective detection rules from encrypted data to detect malicious encrypted traffic; file-based detection methods cannot detect malicious encrypted traffic because they cannot recover files from encrypted traffic; moreover, it is difficult to extract clear malicious behavior from encrypted traffic for detection. Summary of the Invention
[0003] To address the aforementioned problems, the present invention aims to provide a method, apparatus, and electronic device for detecting malicious encrypted traffic.
[0004] In a first aspect, embodiments of the present invention provide a method for detecting malicious encrypted traffic, including:
[0005] Obtain malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein, the malicious encrypted traffic sample data and the normal encrypted traffic sample data each include multiple messages exchanged between the client and the server;
[0006] The malicious encrypted traffic sample data is used to extract a first basic traffic feature and a first traffic interaction feature, and the normal encrypted traffic sample data is used to extract a second basic traffic feature and a second traffic interaction feature. The first basic traffic feature represents feature information related to the length, number, and time interval of messages arriving at the client or server in the malicious encrypted traffic sample. The first traffic interaction feature represents feature information of messages generated when the client and server interact in the malicious encrypted traffic sample. The second basic traffic feature represents feature information related to the length, number, and time interval of messages arriving at the client or server in the normal encrypted traffic sample. The second traffic interaction feature represents feature information of messages generated when the client and server interact in the normal encrypted traffic sample.
[0007] Using the obtained first basic traffic feature, first deep traffic feature, second basic traffic feature and second deep traffic feature, the machine learning model is trained to obtain a malicious encrypted traffic detection model.
[0008] The obtained malicious encrypted traffic detection model is used to detect malicious encrypted traffic.
[0009] Secondly, embodiments of the present invention also provide a malicious encrypted traffic detection device, comprising:
[0010] The acquisition module is used to acquire malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein, the malicious encrypted traffic sample data and the normal encrypted traffic sample data each include multiple messages exchanged between the client and the server.
[0011] An extraction module is configured to extract a first basic traffic feature and a first traffic interaction feature from the malicious encrypted traffic sample data, and to extract a second basic traffic feature and a second traffic interaction feature from the normal encrypted traffic sample data; wherein, the first basic traffic feature represents feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the malicious encrypted traffic sample; the first traffic interaction feature represents feature information of messages generated when the client and server interact in the malicious encrypted traffic sample; the second basic traffic feature represents feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the normal encrypted traffic sample; the second traffic interaction feature represents feature information of messages generated when the client and server interact in the normal encrypted traffic sample.
[0012] The training module is used to train the machine learning model using the obtained first basic traffic feature, first deep traffic feature, second basic traffic feature and second deep traffic feature to obtain a malicious encrypted traffic detection model.
[0013] The detection module is used to detect malicious encrypted traffic using the obtained malicious encrypted traffic detection model.
[0014] Thirdly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, performs the steps of the method described in the first aspect above.
[0015] Fourthly, embodiments of the present invention also provide an electronic device, the electronic device including a memory, a processor and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor using the steps of the method described in the first aspect above.
[0016] In the solutions provided by the first to fourth aspects of the present invention, a first basic traffic feature and a first traffic interaction feature are extracted from the acquired malicious encrypted traffic sample data, and a second basic traffic feature and a second traffic interaction feature are extracted from the normal encrypted traffic sample data. The first basic traffic feature and the second basic traffic feature are feature information related to message length, message quantity, and the time interval between message arrival at the client or server. The first traffic interaction feature and the second traffic interaction feature are feature information of messages generated when the client interacts with the server. Then, the first traffic interaction feature and the second traffic interaction feature, as feature information of messages generated when the client interacts with the server, are used to train a machine learning model to obtain a malicious encrypted traffic detection model. Compared with related technologies that use rule-based detection, file-based detection, and methods that extract malicious behavior from encrypted traffic, which cannot detect malicious traffic from encrypted traffic, this method utilizes the first traffic interaction feature and the second traffic interaction feature, as feature information of messages generated when the client interacts with the server. The malicious encrypted traffic detection model trained on a machine learning model using features can effectively detect malicious encrypted traffic in messages generated during client-server interactions by identifying the features of these messages, significantly improving detection efficiency. Furthermore, by using first and second traffic interaction features—the key features of messages generated during client-server interactions—to train the machine learning model, rather than using features related to handshake negotiation or certificates, the model is less susceptible to interference from easily forged information like handshakes and certificates, allowing for more accurate detection. Moreover, by not using features related to communication protocols, the model can detect malicious traffic using any communication protocol, expanding its application scope.
[0017] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 A flowchart of a malicious encrypted traffic detection method provided in Embodiment 1 of the present invention is shown;
[0020] Figure 2 This diagram illustrates the structure of a malicious encrypted traffic detection device provided in Embodiment 2 of the present invention.
[0021] Figure 3 A schematic diagram of the structure of an electronic device provided in Embodiment 3 of the present invention is shown. Detailed Implementation
[0022] In the description of this invention, it should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," and "counterclockwise," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.
[0023] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0024] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0025] Currently, malicious traffic using encrypted communication protocols such as TLS is growing rapidly. In scenarios where traffic decryption is impossible, most current traffic security detection technologies face severe challenges in dealing with malicious encrypted traffic. Among detection methods built based on plaintext protocol analysis, rule-based detection methods cannot extract effective detection rules from encrypted data to detect malicious encrypted traffic; file-based detection methods cannot detect malicious encrypted traffic because they cannot recover files from encrypted traffic; moreover, it is difficult to extract clear malicious behavior from encrypted traffic for detection.
[0026] Based on this, embodiments of this application propose a method, apparatus, and electronic device for detecting malicious encrypted traffic. The method extracts a first basic traffic feature and a first traffic interaction feature from acquired malicious encrypted traffic sample data, and extracts a second basic traffic feature and a second traffic interaction feature from normal encrypted traffic sample data. The first and second basic traffic features are feature information related to message length, message quantity, and the time interval between message arrival at the client or server. The first and second traffic interaction features are feature information of messages generated during client-server interaction. Then, a machine learning model is trained using the first and second traffic interaction features, which are feature information of messages generated during client-server interaction, to obtain a malicious encrypted traffic detection model. This malicious encrypted traffic detection model, trained using the first and second traffic interaction features, can effectively detect malicious encrypted traffic in messages generated during client-server interaction by identifying the feature information of messages generated during client-server interaction, significantly improving the detection efficiency of malicious encrypted traffic.
[0027] In the following embodiments, only the client and the server interact, that is: the message received by the client must be sent by the server; and the message received by the server must be sent by the client.
[0028] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0029] Example 1
[0030] This embodiment proposes a method for detecting malicious encrypted traffic, with the execution subject being a computing device.
[0031] See Figure 1The flowchart shown illustrates a method for detecting malicious encrypted traffic. This embodiment proposes a method for detecting malicious encrypted traffic, including the following specific steps:
[0032] Step 100: Obtain malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein, the malicious encrypted traffic sample data and the normal encrypted traffic sample data each include multiple messages exchanged between the client and the server.
[0033] In step 100 above, the normal encrypted traffic sample data is obtained by the computing device from the Internet; the malicious encrypted traffic sample data is obtained by the computing device from the malicious traffic environment it has built.
[0034] After obtaining malicious encrypted traffic sample data and normal encrypted traffic sample data, the following preprocessing operations can be performed on the malicious encrypted traffic sample data and normal encrypted traffic sample data: the malicious encrypted traffic sample data and the normal encrypted traffic sample data are cleaned and split respectively to obtain the cleaned and split malicious encrypted traffic sample data and the normal encrypted traffic sample data.
[0035] After preprocessing the malicious encrypted traffic sample data and the normal encrypted traffic sample data, the following step 102 can be performed: extract the first basic traffic feature and the first traffic interaction feature from the malicious encrypted traffic sample data, and extract the second basic traffic feature and the second traffic interaction feature from the normal encrypted traffic sample data.
[0036] Step 102: Extract the first basic traffic feature and the first traffic interaction feature from the malicious encrypted traffic sample data, and extract the second basic traffic feature and the second traffic interaction feature from the normal encrypted traffic sample data; wherein, the first basic traffic feature is used to represent feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the malicious encrypted traffic sample; the first traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the malicious encrypted traffic sample; the second basic traffic feature is used to represent feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the normal encrypted traffic sample; the second traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the normal encrypted traffic sample.
[0037] In step 102 above, after obtaining the malicious encrypted traffic sample data, the computing device can determine the messages sent by the client and the messages sent by the server in the malicious encrypted traffic sample data based on the four-tuples carried in the messages; determine the length of each message in the malicious encrypted traffic sample data; and determine the arrival time of each message to the client or the server. Based on the messages sent by the client, the number of messages sent by the client can be counted. Based on the messages sent by the server, the number of messages sent by the server can be counted.
[0038] By processing the message-related parameters obtained above, the first basic traffic characteristic can be obtained.
[0039] The first basic traffic characteristics include, but are not limited to: the sum of the lengths of all messages sent by the client, the number of all messages sent by the client, the maximum / minimum length of messages sent by the client, the average length of all messages sent by the client, the length similarity of all messages sent by the client, the message length difference coefficient of all messages sent by the client, the sum of the lengths of all messages sent by the server, the number of all messages sent by the server, the maximum / minimum length of messages sent by the server, the average length of all messages sent by the server, the length similarity of all messages sent by the server, the message length difference coefficient of all messages sent by the server, and the message length of all messages sent by the server. Similarity, maximum / minimum / average time interval between arrival times of two adjacent messages sent by the server and received by the client, difference coefficient between arrival times of two adjacent messages sent by the server and received by the client, message length transition matrix of all messages sent by the client, transition matrix of time interval between arrival times of two adjacent messages sent by the server and received by the client, maximum / minimum / average time interval between arrival times of two adjacent messages sent by the client and received by the server, difference coefficient between arrival times of two adjacent messages sent by the client and received by the server, message length transition matrix of all messages sent by the server, transition matrix of time interval between arrival times of two adjacent messages sent by the client and received by the server.
[0040] Given the message lengths of all messages from the client or server, the specific process of calculating the message length difference coefficient, message length similarity, and message length transition matrix for all messages from the client / server is existing technology and will not be elaborated here.
[0041] Given the arrival times of all messages at the client or server, the specific process of calculating the difference coefficient and transition matrix between the arrival times of two adjacent messages sent by the server and received by the client, as well as the difference coefficient and transition matrix between the arrival times of two adjacent messages sent by the client and received by the server, is existing technology and will not be elaborated here.
[0042] By determining the arrival time of each message on the client or server, we can ascertain how many interactions the client initiated with the server. Each interaction is initiated by the client, which sends at least one message to the server. Upon receiving a message from the client, the server also sends at least one message back to the client in response, thus completing one interaction.
[0043] Therefore, the computing device can obtain the number of interactions, the messages sent by the client and server in each interaction, the time when the client or server sends a message in each interaction, the time when each message arrives at the client or server in each interaction, the start and end times of each interaction, and the message length and number of all messages in each interaction.
[0044] The start time of each interaction is the time when the client initiates the interaction and sends the first message to the server; the end time of each interaction is the time when the client receives the last message from the server during the interaction.
[0045] This allows us to obtain the duration of each interaction, the time interval between two adjacent interactions, the total length and number of messages sent by the client in each interaction, and the total length and number of messages sent by the server in each interaction.
[0046] Based on the data obtained above, the first traffic interaction characteristics can be obtained, including but not limited to: the number of interactions, the maximum / minimum / average / difference coefficient of the time interval between adjacent interactions, the maximum / minimum / average / difference coefficient of the duration of each interaction, the maximum / minimum / average / difference coefficient of the number of messages sent by the client in each interaction, the maximum / minimum / average / difference coefficient / similarity of the number of messages sent by the server in each interaction, the maximum / minimum / average / difference coefficient / similarity of the total length of messages sent by the client in each interaction, the maximum / minimum / average / difference coefficient / similarity of the total length of messages sent by the server in each interaction, the transition matrix of the time interval between adjacent interactions, the transition matrix of the duration of each interaction, the transition matrix of the number of messages sent by the client in each interaction, the transition matrix of the number of messages sent by the server in each interaction, the transition matrix of the total length of messages sent by the client in each interaction, and the transition matrix of the total length of messages sent by the server in each interaction.
[0047] Given the time interval between adjacent interactions, the specific process of calculating the difference coefficient of the time interval between adjacent interactions and the transition matrix is existing technology and will not be elaborated here.
[0048] Given the duration of each interaction, the specific process of calculating the difference coefficient and transition matrix for the duration of each interaction is existing technology and will not be elaborated here.
[0049] Given the number of messages sent by the client in each interaction, the specific process of calculating the difference coefficient / similarity / transition matrix of the number of messages sent by the client in each interaction is the existing technology, and will not be elaborated here.
[0050] Given the total message length of the messages sent by the client in each interaction, the specific process of calculating the difference coefficient / similarity / transition matrix of the total message length sent by the client in each interaction is the existing technology, and will not be elaborated here.
[0051] Given the number of messages sent by the server in each interaction, the specific process of calculating the difference coefficient / similarity / transition matrix of the number of messages sent by the server in each interaction is the existing technology, and will not be elaborated here.
[0052] Given the total message length of the messages sent by the server in each interaction, the specific process of calculating the difference coefficient / similarity / transition matrix of the total message length sent by the server in each interaction is the existing technology, and will not be elaborated here.
[0053] The specific process of extracting the second basic traffic feature and the second traffic interaction feature from the normal encrypted traffic sample data is similar to the process of extracting the first basic traffic feature and the first traffic interaction feature from the malicious encrypted traffic sample data, as described above, and will not be repeated here.
[0054] After extracting the first basic traffic feature, the first traffic interaction feature, the second basic traffic feature, and the second traffic interaction feature through the above step 102, the following step 104 can be performed to train the machine learning model and obtain the malicious encrypted traffic detection model.
[0055] Step 104: Using the obtained first basic traffic feature, first deep traffic feature, second basic traffic feature and second deep traffic feature, train the machine learning model to obtain a malicious encrypted traffic detection model.
[0056] In order to train the machine learning model and obtain a malicious encrypted traffic detection model, step 104 above can perform the following steps (1) to (2):
[0057] (1) Perform feature engineering on the obtained first basic flow feature, first deep flow feature, second basic flow feature and second deep flow feature to obtain a candidate feature set for training the model;
[0058] (2) Input the candidate feature set into the machine learning model and train the machine learning model to obtain a malicious encrypted traffic detection model.
[0059] In step (1) above, the specific process of performing feature engineering on the obtained first basic flow feature, first deep flow feature, second basic flow feature and second deep flow feature to obtain a candidate feature set for training the model is existing technology and will not be described in detail here.
[0060] In step (2) above, the algorithms used to train the machine learning model include, but are not limited to: Decision Tree, Logistic Regression, Random Forest, Linear Regression, Adaboost, and SVM.
[0061] Step 106: Use the obtained malicious encrypted traffic detection model to detect malicious encrypted traffic.
[0062] The malicious encrypted traffic detection method proposed in this embodiment can comprehensively extract encrypted data session behavior features from malicious TLS encrypted traffic that are unrelated to handshakes, certificates, and background traffic. It extracts features from both basic message traffic characteristics and traffic interaction characteristics. Compared to existing methods for constructing behavioral feature sets to detect malicious encrypted traffic, the features used in this method are more comprehensive, objective, and accurate in reflecting the details of encrypted data sessions. Through feature engineering methods, a more accurate set of candidate features can be obtained, which is more conducive to the training and testing of machine learning models. Ultimately, the resulting malicious encrypted traffic detection model can more comprehensively and accurately identify malicious encrypted traffic, achieving good identification results.
[0063] In summary, the malicious encrypted traffic detection method proposed in this embodiment extracts a first basic traffic feature and a first traffic interaction feature from the acquired malicious encrypted traffic sample data, and extracts a second basic traffic feature and a second traffic interaction feature from normal encrypted traffic sample data. The first and second basic traffic features are feature information related to message length, message quantity, and the time interval between message arrival at the client or server. The first and second traffic interaction features are feature information of messages generated during client-server interaction. Then, the first and second traffic interaction features, as feature information of messages generated during client-server interaction, are used to train a machine learning model to obtain a malicious encrypted traffic detection model. Compared with related technologies that use rule-based detection, file-based detection, and methods that extract malicious behavior from encrypted traffic, which cannot detect malicious encrypted traffic, this method utilizes the first and second traffic interaction features, as feature information of messages generated during client-server interaction. The malicious encrypted traffic detection model trained on a machine learning model using features can effectively detect malicious encrypted traffic in messages generated during client-server interactions by identifying the features of these messages, significantly improving detection efficiency. Furthermore, by using first and second traffic interaction features—the key features of messages generated during client-server interactions—to train the machine learning model, rather than using features related to handshake negotiation or certificates, the model is less susceptible to interference from easily forged information like handshakes and certificates, allowing for more accurate detection. Moreover, by not using features related to communication protocols, the model can detect malicious traffic using any communication protocol, expanding its application scope.
[0064] Example 2
[0065] This embodiment proposes a malicious encrypted traffic detection device for executing the malicious encrypted traffic detection method proposed in Embodiment 1 above.
[0066] See Figure 2 The diagram shown illustrates the structure of a malicious encrypted traffic detection device. This embodiment proposes a malicious encrypted traffic detection device, comprising:
[0067] The acquisition module 200 is used to acquire malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein, the malicious encrypted traffic sample data and the normal encrypted traffic sample data each include multiple messages exchanged between the client and the server.
[0068] Extraction module 202 is used to extract a first basic traffic feature and a first traffic interaction feature from the malicious encrypted traffic sample data, and to extract a second basic traffic feature and a second traffic interaction feature from the normal encrypted traffic sample data; wherein, the first basic traffic feature is used to represent feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the malicious encrypted traffic sample; the first traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the malicious encrypted traffic sample; the second basic traffic feature is used to represent feature information related to the length of messages, the number of messages, and the time interval between messages arriving at the client or server in the normal encrypted traffic sample; the second traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the normal encrypted traffic sample.
[0069] Training module 204 is used to train a machine learning model using the obtained first basic traffic features, first deep traffic features, second basic traffic features and second deep traffic features to obtain a malicious encrypted traffic detection model.
[0070] The detection module 206 is used to detect malicious encrypted traffic using the obtained malicious encrypted traffic detection model.
[0071] The malicious encrypted traffic detection device proposed in this embodiment also includes:
[0072] The preprocessing module is used to clean and split the malicious encrypted traffic sample data and the normal encrypted traffic sample data respectively, so as to obtain the cleaned and split malicious encrypted traffic sample data and the normal encrypted traffic sample data.
[0073] The training module is specifically used for:
[0074] The obtained first basic flow feature, first deep flow feature, second basic flow feature and second deep flow feature are subjected to feature engineering to obtain a candidate feature set for training the model;
[0075] The candidate feature set is input into the machine learning model, and the machine learning model is trained to obtain a malicious encrypted traffic detection model.
[0076] In summary, the malicious encrypted traffic detection device proposed in this embodiment extracts a first basic traffic feature and a first traffic interaction feature from the acquired malicious encrypted traffic sample data, and extracts a second basic traffic feature and a second traffic interaction feature from normal encrypted traffic sample data. The first and second basic traffic features are feature information related to message length, message quantity, and the time interval between message arrival at the client or server. The first and second traffic interaction features are feature information of messages generated when the client interacts with the server. Then, the first and second traffic interaction features, as feature information of messages generated when the client interacts with the server, are used to train a machine learning model to obtain a malicious encrypted traffic detection model. Compared with related technologies that use rule-based detection, file-based detection, and methods that extract malicious behavior from encrypted traffic, which cannot detect malicious encrypted traffic, this device utilizes the first and second traffic interaction features, as feature information of messages generated when the client interacts with the server. The malicious encrypted traffic detection model trained on a machine learning model using features can effectively detect malicious encrypted traffic in messages generated during client-server interactions by identifying the features of these messages, significantly improving detection efficiency. Furthermore, by using first and second traffic interaction features—the key features of messages generated during client-server interactions—to train the machine learning model, rather than using features related to handshake negotiation or certificates, the model is less susceptible to interference from easily forged information like handshakes and certificates, allowing for more accurate detection. Moreover, by not using features related to communication protocols, the model can detect malicious traffic using any communication protocol, expanding its application scope.
[0077] Example 3
[0078] This embodiment proposes a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it executes the steps of the malicious encrypted traffic detection method described in Embodiment 1 above. For specific implementation details, please refer to Method Embodiment 1, which will not be repeated here.
[0079] In addition, see Figure 3The diagram shows the structure of an electronic device. This embodiment also proposes an electronic device, which includes a bus 51, a processor 52, a transceiver 53, a bus interface 54, a memory 55, and a user interface 56. The electronic device includes a memory 55.
[0080] In this embodiment, the electronic device further includes: one or more programs stored in memory 55 and executable on processor 52, configured to be executed by the processor to perform the one or more programs for steps (1) to (4):
[0081] (1) Obtain malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein, the malicious encrypted traffic sample data and the normal encrypted traffic sample data respectively include multiple messages exchanged between the client and the server;
[0082] (2) Extract the first basic traffic feature and the first traffic interaction feature from the malicious encrypted traffic sample data, and extract the second basic traffic feature and the second traffic interaction feature from the normal encrypted traffic sample data; wherein, the first basic traffic feature is used to represent feature information related to the length of the message, the number of messages, and the time interval between messages arriving at the client or server in the malicious encrypted traffic sample; the first traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the malicious encrypted traffic sample; the second basic traffic feature is used to represent feature information related to the length of the message, the number of messages, and the time interval between messages arriving at the client or server in the normal encrypted traffic sample; the second traffic interaction feature is used to represent feature information of messages generated when the client and server interact in the normal encrypted traffic sample.
[0083] (3) Using the obtained first basic traffic feature, first deep traffic feature, second basic traffic feature and second deep traffic feature, the machine learning model is trained to obtain a malicious encrypted traffic detection model.
[0084] (4) Utilize the obtained malicious encrypted traffic detection model to detect malicious encrypted traffic.
[0085] Transceiver 53 is used to receive and send data under the control of processor 52.
[0086] The bus architecture (represented by bus 51) can include any number of interconnected buses and bridges, linking various circuits including one or more processors represented by processor 52 and memory represented by memory 55. Bus 51 can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be further described in this embodiment. Bus interface 54 provides an interface between bus 51 and transceiver 53. Transceiver 53 can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. For example, transceiver 53 receives external data from other devices. Transceiver 53 is used to transmit data processed by processor 52 to other devices. Depending on the nature of the computing system, a user interface 56 may also be provided, such as a keypad, display, speaker, microphone, or joystick.
[0087] Processor 52 is responsible for managing bus 51 and general processing, such as running a general-purpose operating system as described above. Memory 55 can be used to store data used by processor 52 during operation.
[0088] Optionally, the processor 52 may be, but is not limited to, a central processing unit, a microcontroller, a microprocessor, or a programmable logic device.
[0089] It is understood that the memory 55 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDRSDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). The memory 55 of the systems and methods described in this embodiment is intended to include, but is not limited to, these and any other suitable types of memory.
[0090] In some implementations, memory 55 stores elements such as executable modules or data structures, or subsets thereof, or extended sets thereof: operating system 551 and application programs 552.
[0091] The operating system 551 includes various system programs, such as the framework layer, core library layer, and driver layer, used to implement various basic business functions and handle hardware-based tasks. The application program 552 includes various applications, such as a media player and a browser, used to implement various application functions. The program implementing the method of this embodiment can be included in the application program 552.
[0092] In summary, this embodiment proposes a computer-readable storage medium and electronic device that extracts a first basic traffic feature and a first traffic interaction feature from acquired malicious encrypted traffic sample data, and extracts a second basic traffic feature and a second traffic interaction feature from normal encrypted traffic sample data. The first and second basic traffic features are feature information related to message length, message quantity, and the time interval between message arrival at the client or server. The first and second traffic interaction features are feature information of messages generated during client-server interaction. Then, the first and second traffic interaction features, as feature information of messages generated during client-server interaction, are used to train a machine learning model to obtain a malicious encrypted traffic detection model. Compared to related technologies that use rule-based detection, file-based detection, and methods that extract malicious behavior from encrypted traffic, which cannot detect malicious encrypted traffic, this model utilizes the first and second traffic interaction features, as feature information of messages generated during client-server interaction. The malicious encrypted traffic detection model trained on the machine learning model using interaction features can effectively detect malicious encrypted traffic in messages generated during client-server interactions by identifying the features of these messages, significantly improving detection efficiency. Furthermore, by using first and second traffic interaction features—the characteristic information of messages generated during client-server interactions—to train the machine learning model, rather than using features related to handshake negotiation and certificates, the model is not affected by easily forged information such as handshake negotiations and certificates, allowing for more accurate detection of malicious encrypted traffic. Moreover, by not using features related to communication protocols, the trained model can detect malicious traffic using any communication protocol, expanding its application scope.
[0093] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A method for detecting malicious encrypted traffic, characterized in that, The method comprises the following steps: obtaining malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein the malicious encrypted traffic sample data and the normal encrypted traffic sample data respectively comprise a plurality of messages exchanged between a client and a server; extracting first basic traffic features and first traffic interaction features from the malicious encrypted traffic sample data, and extracting second basic traffic features and second traffic interaction features from the normal encrypted traffic sample data; wherein the first basic traffic features are used to represent feature information related to the length of a message, the number of messages, and the time interval at which a message arrives at the client or the server in the malicious encrypted traffic sample data; the first traffic interaction features are used to represent feature information of messages generated when the client and the server interact in the malicious encrypted traffic sample data; the second basic traffic features are used to represent feature information related to the length of a message, the number of messages, and the time interval at which a message arrives at the client or the server in the normal encrypted traffic sample data; the second traffic interaction features are used to represent feature information of messages generated when the client and the server interact in the normal encrypted traffic sample data; the first basic traffic features are obtained according to the four-tuple carried by the messages in the malicious encrypted traffic sample data, and the second basic traffic features are obtained according to the four-tuple carried by the messages in the normal encrypted traffic sample data; the first traffic interaction features and the second traffic interaction features do not include certificate features; training a machine learning model using the first basic traffic features without communication protocol-related feature information, the first traffic interaction features without certificate features, the second basic traffic features without communication protocol-related feature information, and the second traffic interaction features without certificate features, to obtain a malicious encrypted traffic detection model; detecting malicious encrypted traffic using the obtained malicious encrypted traffic detection model; training a machine learning model using the first basic traffic features without communication protocol-related feature information, the first traffic interaction features without certificate features, the second basic traffic features without communication protocol-related feature information, and the second traffic interaction features without certificate features, to obtain a malicious encrypted traffic detection model, comprising: performing feature engineering processing on the obtained first basic traffic features without communication protocol-related feature information, the first traffic interaction features without certificate features, the second basic traffic features without communication protocol-related feature information, and the second traffic interaction features without certificate features, to obtain a candidate feature set for training the model; inputting the candidate feature set into the machine learning model to train the machine learning model and obtain a malicious encrypted traffic detection model.
2. The method of claim 1, wherein, After the step of obtaining malicious encrypted traffic sample data and normal encrypted traffic sample data, the method further comprises the following steps: The malicious encrypted traffic sample data and the normal encrypted traffic sample data are respectively cleaned and split to obtain cleaned and split malicious encrypted traffic sample data and normal encrypted traffic sample data.
3. A malicious encrypted traffic detection apparatus characterized by, Comprise: An acquisition module is configured to acquire malicious encrypted traffic sample data and normal encrypted traffic sample data; wherein the malicious encrypted traffic sample data and the normal encrypted traffic sample data respectively comprise a plurality of messages exchanged between a client and a server; An extraction module is configured to extract first basic traffic features and first traffic interaction features in the malicious encrypted traffic sample data from the malicious encrypted traffic sample data, and extract second basic traffic features and second traffic interaction features in the normal encrypted traffic sample data from the normal encrypted traffic sample data; wherein the first basic traffic features are used to represent feature information related to lengths of messages, numbers of messages, and time intervals at which messages arrive at the client or the server in the malicious encrypted traffic sample data; the first traffic interaction features are used to represent feature information of messages generated when the client and the server interact in the malicious encrypted traffic sample data; the second basic traffic features are used to represent feature information related to lengths of messages, numbers of messages, and time intervals at which messages arrive at the client or the server in the normal encrypted traffic sample data; the second traffic interaction features are used to represent feature information of messages generated when the client and the server interact in the normal encrypted traffic sample data; the first basic traffic features are obtained according to four-tuples carried by messages in the malicious encrypted traffic sample data, and the second basic traffic features are obtained according to four-tuples carried by messages in the normal encrypted traffic sample data; the first traffic interaction features and the second traffic interaction features do not include certificate features; A training module is configured to train a machine learning model by using the first basic traffic features without communication protocol related feature information, the first traffic interaction features without certificate features, the second basic traffic features without communication protocol related feature information, and the second traffic interaction features without certificate features, to obtain a malicious encrypted traffic detection model; A detection module is configured to detect malicious encrypted traffic by using the obtained malicious encrypted traffic detection model. The training module is specifically configured to: perform feature engineering processing on the obtained first basic traffic features, first traffic interaction features, second basic traffic features, and second traffic interaction features to obtain an alternative feature set for training the model; input the alternative feature set into the machine learning model to train the machine learning model, and obtain a malicious encrypted traffic detection model.
4. The apparatus of claim 3, wherein, Further comprise: A preprocessing module is configured to clean and split the malicious encrypted traffic sample data and the normal encrypted traffic sample data respectively to obtain cleaned and split malicious encrypted traffic sample data and normal encrypted traffic sample data.
5. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, which is executed by a processor, performs the steps of the method as claimed in claim 1 or 2.
6. An electronic device, comprising: The electronic device includes memory, a processor, and one or more programs, wherein the one or more programs are stored in the memory and are configured to, with the processor, perform the steps of the method as claimed in claim 1 or 2.
Citation Information
Patent Citations
Traffic characteristic recognition method, device and system for terminal network application
CN108234345A
Encrypted malicious traffic detection method and apparatus, electronic device, and storage medium
CN109379377A