A traffic analysis method and device, electronic equipment and storage medium
By constructing a forward spatiotemporal correlated background traffic set and parsing the traffic data, the problem of not being able to identify the browser type of encrypted traffic in existing technologies is solved, and a higher browser identification accuracy is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA ACADEMY OF INFORMATION & COMM
- Filing Date
- 2023-10-12
- Publication Date
- 2026-04-21
AI Technical Summary
Existing technologies cannot effectively identify the browser type of encrypted traffic, resulting in low accuracy of traffic analysis methods.
By filtering target encrypted traffic data, a forward spatiotemporal correlated background traffic set is constructed, and the traffic data is parsed according to its priority order to determine the browser type of the encrypted traffic.
It improves the accuracy of browser identification based on encrypted traffic data and expands the ability to observe encrypted traffic in cyberspace.
Smart Images

Figure CN117221423B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network technology, and in particular to a traffic analysis method, apparatus, electronic device and storage medium. Background Technology
[0002] With the rapid development of data communication and computer network technologies, encryption protocols and applications are becoming increasingly prevalent due to considerations such as protecting privacy, improving data security, meeting compliance requirements, and providing higher security on public wireless networks. Recently, encrypted network traffic has accounted for nearly or exceeded 90%. To improve network management and network security, network traffic monitoring is essential. Network traffic monitoring refers to the real-time monitoring and analysis of network transmission data to gain an understanding of the network, detect potential security threats, and identify abnormal behavior. Given that encrypted traffic has become the dominant type of internet traffic, the analysis of encrypted traffic has become particularly important.
[0003] In network traffic monitoring systems, to observe the application type generating encrypted traffic macroscopically, it's necessary to determine which app or browser the encrypted traffic originates from, such as Edge, Chrome, or Safari. Determining the app source of encrypted traffic primarily involves analyzing information such as the Server Name Indication (SNI) and the Serial Number (SN) in the certificate information during the DPI (Deep Packet Inspection) process of establishing a TLS (Transport Layer Security) connection.
[0004] In the process of realizing this invention, the inventors discovered the following defects in the prior art: the DPI traffic analysis method for encrypted traffic cannot determine which browser initiated the traffic data, and current theoretical research and engineering practice cannot provide a method to directly identify the browser based on the analysis results of encrypted traffic. Summary of the Invention
[0005] This invention provides a traffic analysis method, apparatus, electronic device, and storage medium that can improve the accuracy of browser identification based on traffic analysis.
[0006] According to one aspect of the present invention, a flow analysis method is provided, comprising:
[0007] Target encrypted traffic data is filtered based on the full network traffic data;
[0008] The forward spatiotemporal correlation background traffic set of the target encrypted traffic data is determined based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data;
[0009] The traffic data in the forward spatiotemporal correlated background traffic set is parsed according to the priority order of the forward spatiotemporal correlated background traffic set;
[0010] The encrypted traffic browser identification result is determined based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0011] According to another aspect of the present invention, a flow analysis apparatus is provided, comprising:
[0012] The target encrypted traffic data filtering module is used to filter target encrypted traffic data based on the full network traffic data.
[0013] A forward spatiotemporal correlation background traffic set determination module is used to determine the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data;
[0014] The forward spatiotemporal correlation background traffic set parsing module is used to parse the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set;
[0015] The browser identification result determination module is used to determine the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0016] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0017] At least one processor; and
[0018] A memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the traffic analysis method according to any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the traffic analysis method according to any embodiment of the present invention.
[0021] This invention, in its embodiments, filters target encrypted traffic data based on full network traffic data, parses the target encrypted traffic data to obtain parsed correlation data, and then determines the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data. Furthermore, it parses the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set, thereby determining the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set. This solves the problem in existing traffic analysis methods that cannot identify browser types based on network connections initiated from encrypted traffic data, enabling browser identification based on encrypted traffic data and thus improving the accuracy of browser identification based on traffic analysis.
[0022] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a flowchart of a traffic analysis method provided in Embodiment 1 of the present invention;
[0025] Figure 2 This is a flowchart of a traffic analysis method provided in Embodiment 2 of the present invention;
[0026] Figure 3 This is a schematic diagram illustrating the correlation effect between forward spatiotemporal correlation background traffic concentrated traffic data and target encrypted traffic data, provided in Embodiment 2 of the present invention.
[0027] Figure 4 This is a schematic diagram of a flow analysis device provided in Embodiment 3 of the present invention;
[0028] Figure 5 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. Detailed Implementation
[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0031] Example 1
[0032] Figure 1 This is a flowchart of a traffic analysis method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of identifying browsers based on encrypted traffic data. The method can be executed by a traffic analysis device, which can be implemented in software and / or hardware, and is generally integrated into an electronic device. This electronic device can be a terminal device or a server device, as long as it can be used to analyze traffic data. The embodiments of the present invention do not limit the specific type of electronic device. Correspondingly, as... Figure 1 As shown, the method includes the following operations:
[0033] S110. Filter target encrypted traffic data based on the full network traffic data.
[0034] The full network traffic data can be continuous, complete network traffic data collected at a designated network traffic detection location. The target encrypted traffic data can be one or more types of encrypted traffic data whose app category cannot be identified. For example, the target encrypted traffic data can be TLS encrypted traffic data or SSL (Secure Sockets Layer) encrypted traffic data, etc.
[0035] In this embodiment of the invention, when performing browser analysis on traffic data, the full network traffic data can be collected first, and the target encrypted traffic data can be obtained by filtering from the full network traffic data.
[0036] S120. Determine the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data.
[0037] The parsing and association data can be related data obtained after parsing the target encrypted traffic data. For example, parsing and association data can include, but is not limited to, the IP address of the target encrypted traffic data and related information from the first packet. The forward spatiotemporal association background traffic set can be a set of traffic data associated with the IP data in the target encrypted traffic data, and whose data collection time is before the data collection time of the target encrypted traffic data. The preceding capture period can be understood as the period during which the traffic data in the forward spatiotemporal association background traffic set is captured before the capture time of the target encrypted traffic data.
[0038] To accurately analyze the target encrypted traffic data, after identifying it, the data can be further parsed to obtain its parsed correlation data. This parsed correlation data is then used to further filter the forward spatiotemporal correlation background traffic set of the target encrypted traffic data from the full network traffic data. The traffic data included in the forward spatiotemporal correlation background traffic set consists of traffic data collected within a period preceding the target encrypted traffic data.
[0039] S130. The traffic data in the forward spatiotemporal correlation background traffic set is parsed according to the priority order of the forward spatiotemporal correlation background traffic set.
[0040] In this embodiment of the invention, there can be multiple forward spatiotemporal correlation background traffic sets. Different forward spatiotemporal correlation background traffic sets can be configured with different priority orders. It is understood that a higher priority order indicates a higher degree of correlation between the forward spatiotemporal correlation background traffic set and the target encrypted traffic data. Therefore, the current reference forward spatiotemporal correlation background traffic set can be determined according to the priority order of the forward spatiotemporal correlation background traffic sets, which is the forward spatiotemporal correlation background traffic set with the highest correlation to the target encrypted traffic data. The traffic data in the current reference forward spatiotemporal correlation background traffic set is then parsed to analyze and determine the browser type involved in the target encrypted traffic data.
[0041] S140. Determine the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0042] Among them, the encrypted traffic browser identification result can be the identification result of the browser involved in the target encrypted traffic data.
[0043] Since the traffic data in the forward spatiotemporal correlation background traffic set is closely related to the target encrypted traffic data in terms of IP address and time-related information, after determining the current reference forward spatiotemporal correlation background traffic set, the traffic data included in the current reference forward spatiotemporal correlation background traffic set can be parsed to obtain traffic data parsing results containing browser-related information such as browser version and browser type. Furthermore, the encrypted traffic browser identification result corresponding to the target encrypted traffic data can be determined based on the traffic data parsing results of the forward spatiotemporal correlation background traffic set.
[0044] This invention, in its embodiments, filters target encrypted traffic data based on full network traffic data, parses the target encrypted traffic data to obtain parsed correlation data, and then determines the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data. Furthermore, it parses the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set, thereby determining the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set. This solves the problem in existing traffic analysis methods that cannot identify browser types based on network connections initiated from encrypted traffic data, enabling browser identification based on encrypted traffic data and thus improving the accuracy of browser identification based on traffic analysis.
[0045] Example 2
[0046] Figure 2 This is a flowchart of a traffic analysis method provided in Embodiment 2 of the present invention. This embodiment is based on the above embodiment and is further specified. In this embodiment, various specific optional implementation methods are given for operations such as filtering target encrypted traffic data, determining the forward spatiotemporal correlation background traffic set of the target encrypted traffic data, and parsing the traffic data in the forward spatiotemporal correlation background traffic set. Correspondingly, such as Figure 2 As shown, the method in this embodiment may include:
[0047] S210. Filter target encrypted traffic data based on the full network traffic data.
[0048] In an optional embodiment of the present invention, the target encrypted traffic data may include encrypted traffic data without an APP source; the step of filtering the target encrypted traffic data based on the full network traffic data may include: filtering target protocol encrypted traffic data from the full network traffic data; extracting target fields from the target protocol encrypted traffic data and matching the target fields with a target field preset library; if it is determined that the target field fails to match the target field preset library, the target protocol encrypted traffic data is determined as the target encrypted traffic data.
[0049] The target protocol encrypted traffic data can be traffic data of a certain protocol type, such as, but not limited to, TLS traffic data or SSL traffic data. The target field can be a reference field used to determine whether the traffic data is encrypted. The target field pre-built library can be used to store relevant value information for the field, used to determine whether the value of the target field is unencrypted data.
[0050] For example, taking TLS-encrypted traffic data as the target encrypted traffic data, continuous full-volume network traffic data can be collected at one or more designated traffic monitoring locations. For each collected data stream, the DPI result of the first packet after establishing a TCP (Transmission Control Protocol) connection is determined. If it possesses the byte characteristics of a ClientHello (handshake message type) packet, it can be identified as TLS-encrypted traffic. If it is identified as TLS-encrypted traffic, the SNI field and certificate number (SN) field group from the ClientHello in the handshake information of the TLS-encrypted traffic can be further extracted as target fields. Based on the SN's pre-built library, it can be determined whether the TLS-encrypted traffic was generated by a certain application. If the SN cannot determine which application the TLS-encrypted traffic originated from, the TLS-encrypted traffic can be treated as target encrypted traffic data initiated by a browser for subsequent processing.
[0051] S220. Parse the target encrypted traffic data to obtain the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data.
[0052] The first packet capture time can be the capture time of the first data packet in the target encrypted traffic data.
[0053] Specifically, when parsing target encrypted traffic data, the source IP address of the target encrypted traffic data can be obtained. S Destination IP address is the IP address D And the first packet capture time, i.e., T B Data such as [IP] S IPD ,T B ], as the parsing and association data of the target encrypted traffic data.
[0054] S230. Based on the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data, filter the forward spatiotemporal correlated background traffic set from the full network traffic data.
[0055] Accordingly, after obtaining the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data, the associated data [IP] can be parsed and linked as described above. S IP D ,T B [This refers to the forward spatiotemporal correlation background traffic set used to filter target encrypted traffic data from the full network traffic data.]
[0056] It is understandable that, since browser-related information is generally stored in HTTP (Hypertext Transfer Protocol) request packets, the data in the forward spatiotemporal correlation background traffic set may optionally include HTTP request packet information.
[0057] In an optional embodiment of the present invention, the step of filtering the forward spatiotemporally correlated background traffic set from the full network traffic data based on the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data may include: determining the forward time window length of the forward spatiotemporally correlated background traffic set based on the first packet capture time of the target encrypted traffic data; determining the target IP of the traffic data in the forward spatiotemporally correlated background traffic set based on the source IP address and destination IP address of the target encrypted traffic data; and filtering the traffic data of the target IP within the forward time window length from the full network traffic data as the forward spatiotemporally correlated background traffic set.
[0058] The forward time window length can be the length of the time window used to collect forward spatiotemporally correlated background traffic data.
[0059] Optionally, the forward time window length can vary depending on the different forward spatiotemporally correlated background traffic sets. It's understandable that the closer the capture time of the traffic data in the forward spatiotemporally correlated background traffic set is to the capture time of the target encrypted traffic data, the higher the correlation between the two. Therefore, the forward time window length for each forward spatiotemporally correlated background traffic set can be determined by sequentially moving backward from the first packet capture time of the target encrypted traffic data. Correspondingly, after determining the forward time window length for each forward spatiotemporally correlated background traffic set, the target IP type can be further determined based on the source and destination IP addresses of the target encrypted traffic data. This allows for the selection of traffic data from the target IP within each forward time window length from the full network traffic data, thus serving as the forward spatiotemporally correlated background traffic set.
[0060] In an optional embodiment of the present invention, the forward spatiotemporal correlated background traffic set may include a first forward spatiotemporal correlated background traffic set collected within a first forward time window length, a second forward spatiotemporal correlated background traffic set collected within a second forward time window length, and a third forward spatiotemporal correlated background traffic set collected within a third forward time window length, wherein: the source IP address of the first forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the first forward spatiotemporal correlated background traffic set is the same as the destination IP address of the target encrypted traffic data; the source IP address of the second forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data; the source IP address of the third forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the third forward spatiotemporal correlated background traffic set is a browser standard service IP address; the traffic in the first forward spatiotemporal correlated background traffic set, the second forward spatiotemporal correlated background traffic set, and the third forward spatiotemporal correlated background traffic set is HTTP request traffic.
[0061] The specific time lengths of the first, second, and third forward time windows can be set according to actual needs. For example, the first forward time window length can be 100ms, the second forward time window length can be 500ms, and the third forward time window length can be 1000ms, etc. This embodiment of the invention does not limit the specific time length values of each forward time window. The first, second, and third forward spatiotemporally correlated background traffic sets can be forward spatiotemporally correlated background traffic sets composed of traffic data collected in different time periods. It is understood that the priority order of the first, second, and third forward spatiotemporally correlated background traffic sets is different. The closer the acquisition time of the traffic data is to the acquisition time of the target encrypted traffic data, the higher the priority of the corresponding forward spatiotemporally correlated background traffic set, indicating a higher degree of correlation between the forward spatiotemporally correlated background traffic set and the target encrypted traffic data.
[0062] Figure 3 This is a schematic diagram illustrating the correlation effect between forward spatiotemporal correlation of background traffic data and target encrypted traffic data, as provided in Embodiment 2 of the present invention. In a specific example, such as... Figure 3 As shown, taking TLS encrypted traffic as the target encrypted traffic data as an example, this will be explained in detail. Assuming there is a three-level forward spatiotemporal correlation background traffic set, this three-level forward spatiotemporal correlation background traffic set can be constructed in the following way:
[0063] First, construct the first forward spatiotemporal correlation background traffic set S1 of the TLS encrypted traffic. The traffic data in S1 can be the data collected at a distance T from the time of the first packet data collection in the TLS encrypted traffic. B HTTP request traffic with the same source and destination IP addresses as TLS encrypted traffic is collected within the forward time window w1, which is pushed forward 100ms. Since the source and destination IP addresses are the same and the traffic collection time is closest, the traffic data in S1 has the highest correlation with the TLS encrypted traffic data.
[0064] Secondly, a second forward spatiotemporal correlation background traffic set S2 is constructed for the TLS encrypted traffic. The traffic data in S2 can be the data collected at a distance T from the first packet data acquisition time in the TLS encrypted traffic. B The HTTP request traffic collected in the forward time window w2 within a 500ms advance is the same as the TLS encrypted traffic, sharing the same source IP address. Because the source IP addresses are the same and the traffic collection times are relatively close, the traffic data in S2 has a high degree of correlation with the TLS encrypted traffic data.
[0065] Finally, a third forward spatiotemporal correlation background traffic set S3 is constructed for the TLS encrypted traffic. The traffic data in S3 can be the data collected at a distance T from the time of the first packet data acquisition in the TLS encrypted traffic. B HTTP request traffic collected within the forward time window w3 (pushing forward 1000ms) that shares the same source IP address as TLS-encrypted traffic and has a destination IP address that is a browser standard service IP address. For example, the browser standard service IP address may include, but is not limited to, IP addresses in the IPSetService set of known common services related to browsers, such as weather forecasts, stock subscriptions, email subscriptions, and ad tracking services. Because the source IP address is the same and the traffic collection time is relatively close, the traffic data in S3 has a high correlation with the TLS-encrypted traffic data, but a lower correlation compared to S2.
[0066] S240. Determine the current forward spatiotemporal correlation background traffic set to be parsed according to the priority order of the forward spatiotemporal correlation background traffic set.
[0067] The current set of forward spatiotemporal correlation background traffic for parsing can be the set of spatiotemporal correlation background traffic for the data currently to be parsed. Optionally, the current set of forward spatiotemporal correlation background traffic for parsing can be determined sequentially according to the priority order of the forward spatiotemporal correlation background traffic sets.
[0068] S250. If it is determined that there are multiple valid fields in the current parsed forward spatiotemporal correlation background traffic set, the valid field with the shortest traffic collection time of each valid field and the first packet data collection time interval of the target encrypted traffic data is determined as the target valid field.
[0069] Among them, a valid field can be a field type that includes browser-related identification information. For example, if the UA field is parsed from the HTTP traffic, and the UA field is the User-Agent field in the HTTP request header, which is used to identify the client application or device that sent the request, it usually contains information such as the operating system, browser, and device type. Therefore, the UA field parsed from the HTTP traffic can usually contain information such as the type and version of common browsers, so the UA field that includes the browser type and version information can be determined as a valid field.
[0070] Understandably, multiple traffic data points within a current parsing set of forward spatiotemporal correlation background traffic may yield multiple valid fields. To improve the browser's recognition accuracy, when multiple valid fields exist in the current parsing set of forward spatiotemporal correlation background traffic, a baseline target valid field can be selected from these fields. Specifically, the traffic acquisition time of the traffic data corresponding to each valid field can be assessed, and the valid field with the shortest time interval between its acquisition time and the first packet acquisition time of the target encrypted traffic data can be identified as the target valid field.
[0071] S260. Parse the target valid fields of the current forward spatiotemporal correlation background traffic set, and generate the traffic data parsing result of the forward spatiotemporal correlation background traffic set based on the parsing result of the target valid fields.
[0072] Accordingly, after determining the target valid fields, the target valid fields of the current forward spatiotemporal correlation background traffic set can be parsed. For example, the parsing results of the target valid fields can be organized into JSON (JavaScript Object Notation) format, and the final traffic data parsing result of the forward spatiotemporal correlation background traffic set can be generated based on the parsing results of the target valid fields.
[0073] In an optional embodiment of the present invention, parsing the target valid fields of the currently parsed forward spatiotemporal correlated background traffic set, and generating the traffic data parsing result of the forward spatiotemporal correlated background traffic set based on the parsing result of the target valid fields, may include: determining the values of browser type and browser version based on the parsing result of the target valid fields; determining the browser type identification confidence level based on the priority order of the currently parsed forward spatiotemporal correlated background traffic set; and constructing the traffic data parsing result of the forward spatiotemporal correlated background traffic set based on the browser type, browser version, and browser type identification confidence level.
[0074] Among them, browser type identification confidence score can be used to identify the degree of confidence in the browser type identification results.
[0075] In a specific example, let's continue using the TLS encrypted traffic mentioned above as the target encrypted traffic data. Assume there are three levels of forward spatiotemporal correlation background traffic sets, S1, S2, and S3. S1 has a higher priority than S2, and S2 has a higher priority than S3. The i-th level forward spatiotemporal correlation background traffic set S is parsed level by level according to priority. i The UA field in the HTTP / 2 header is considered a valid HTTP / 2 UA field if it contains both browser type (type) and browser version information (version). If S... iIf the data contains multiple valid User Agent (UA) fields, then the first packet (T) of the TLS encrypted traffic data that is closest in time to the target encrypted traffic data will be selected. B The valid User Agent (UA) field is used as the target valid field, and the JSON field {"T":"type","V":"version","C":"4-i"} is output based on the result of the connection to the target valid field as the traffic data parsing result of the forward spatiotemporal correlation background traffic set. In the above JSON field, "type" is the specific value of the browser type "type" in the target valid field, "version" is the specific value of the browser version information "version" in the target valid field, and the value of "4-i" can be determined based on the value of i. If the i-th level forward spatiotemporal correlation background traffic set has output traffic data parsing results, then UA parsing of subsequent forward spatiotemporal correlation background traffic sets will not be performed.
[0076] Specifically, if the UA field in the HTTP traffic parsed in the S1 set contains the common browser type and browser version, then the UA is considered valid. If S1 contains multiple valid UA fields, the valid UA field whose traffic collection time is closest to the time of the first packet in the TLS encrypted traffic is selected. The browser type and browser version contained in it are used as the values of "T" and "V" in the output JSON field {"T":"type","V":"version","C":"3"}, and the confidence score of the browser type identification "C" = "3" is output together.
[0077] Correspondingly, if no valid UA field is parsed in the HTTP traffic of set S1, then set S1 can be parsed. If the UA field containing the common browser type (type) and browser version (version) is parsed in the HTTP traffic of set S2, then the UA is considered valid. If S2 contains multiple valid UA fields, the valid UA field whose traffic collection time is closest to the first packet data time in the TLS encrypted traffic is selected. The browser type (type) and browser version (version) contained in this field are used as the values of "T" and "V" in the output JSON field {"T":"type","V":"version","C":"2"}, and the identification confidence score of the browser type "C" = "2" is output together.
[0078] Correspondingly, if no valid UA field is parsed in the HTTP traffic of set S2, then set S3 can be parsed. If the UA field in the HTTP traffic of set S3 contains the common browser type (type) and browser version (version), then the UA is considered valid. If S3 contains multiple valid UA fields, the valid UA field whose traffic collection time is closest to the time of the first packet in the TLS encrypted traffic is selected. The browser type (type) and browser version (version) contained in this field are used as the values of "T" and "V" in the output JSON field {"T":"type","V":"version","C":"1"}, and the confidence score for identifying the browser type "C" = "1" is output together.
[0079] If no valid User Agent (UA) field is parsed after processing all forward spatiotemporal correlated background traffic sets, then the JSON field {"T":"0","V":"0","C":"0"} can be output.
[0080] S270. Determine the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0081] In a specific example, taking the TLS encrypted traffic mentioned above as the target encrypted traffic data, the JSON fields output in the above process can be stored in the traffic record table corresponding to the target encrypted traffic data. The field values of "T", "V" and "C" correspond to the browser type, browser version and browser type identification confidence level in the table, respectively.
[0082] The above technical solution collects continuous and complete network traffic data at traffic monitoring locations, identifies encrypted traffic, and filters out target encrypted traffic data that cannot be tagged with an app. For the filtered target encrypted traffic data, a multi-level forward spatiotemporal correlation background traffic set containing HTTP request packets can be constructed based on its parsed associated data. Furthermore, for each level of the forward spatiotemporal correlation background traffic set, the effective UA field is parsed level by level, outputting JSON fields. Based on the output JSON fields, the browser type, browser version, and browser type identification confidence level are recorded and stored in a data table recording browser-related attributes of encrypted traffic. Compared to existing technologies, this invention, for the first time, uses the DPI results of the forward spatiotemporal correlation background traffic of encrypted network traffic for cross-completion analysis, improving the accuracy of browser identification and effectively expanding the browser identification capability dimension of large-scale network space encrypted traffic observation. This can play an important role in application scenarios such as network security and traffic management.
[0083] It should be noted that any arrangement or combination of the technical features in the above embodiments also falls within the protection scope of this invention.
[0084] Example 3
[0085] Figure 4 This is a schematic diagram of a flow analysis device provided in Embodiment 3 of the present invention, as shown below. Figure 4 As shown, the device includes: a target encrypted traffic data filtering module 310, a forward spatiotemporal correlation background traffic set determination module 320, a forward spatiotemporal correlation background traffic set parsing module 330, and a browser recognition result determination module 340, wherein:
[0086] The target encrypted traffic data filtering module 310 is used to filter target encrypted traffic data based on the full network traffic data.
[0087] The forward spatiotemporal correlation background traffic set determination module 320 is used to determine the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data;
[0088] The forward spatiotemporal correlation background traffic set parsing module 330 is used to parse the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set;
[0089] The browser identification result determination module 340 is used to determine the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0090] This invention, in its embodiments, filters target encrypted traffic data based on full network traffic data, parses the target encrypted traffic data to obtain parsed correlation data, and then determines the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data. Furthermore, it parses the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set, thereby determining the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set. This solves the problem in existing traffic analysis methods that cannot identify browser types based on network connections initiated from encrypted traffic data, enabling browser identification based on encrypted traffic data and thus improving the accuracy of browser identification based on traffic analysis.
[0091] Optionally, the target encrypted traffic data includes encrypted traffic data without an APP source; the target encrypted traffic data filtering module 310 is specifically used to: filter target protocol encrypted traffic data from the full network traffic data; extract target fields from the target protocol encrypted traffic data and match the target fields with a target field preset library; if it is determined that the target field fails to match the target field preset library, the target protocol encrypted traffic data is determined as the target encrypted traffic data.
[0092] Optionally, the forward spatiotemporal correlation background traffic set determination module 320 is specifically used to: parse the target encrypted traffic data, obtain the source IP address, destination IP address and first packet capture time of the target encrypted traffic data; and filter the forward spatiotemporal correlation background traffic set from the full network traffic data based on the source IP address, destination IP address and first packet capture time of the target encrypted traffic data.
[0093] Optionally, the forward spatiotemporal correlation background traffic set determination module 320 is specifically used for: determining the forward time window length of the forward spatiotemporal correlation background traffic set based on the first packet capture time of the target encrypted traffic data; determining the target IP of the traffic data in the forward spatiotemporal correlation background traffic set based on the source IP address and destination IP address of the target encrypted traffic data; and filtering the traffic data of the target IP within the forward time window length from the full network traffic data as the forward spatiotemporal correlation background traffic set.
[0094] Optionally, the forward spatiotemporal correlated background traffic set includes a first forward spatiotemporal correlated background traffic set collected within a first forward time window, a second forward spatiotemporal correlated background traffic set collected within a second forward time window, and a third forward spatiotemporal correlated background traffic set collected within a third forward time window, wherein: the source IP address of the first forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the first forward spatiotemporal correlated background traffic set is the same as the destination IP address of the target encrypted traffic data; the source IP address of the second forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data; the source IP address of the third forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the third forward spatiotemporal correlated background traffic set is a browser standard service IP address; the traffic in the first forward spatiotemporal correlated background traffic set, the second forward spatiotemporal correlated background traffic set, and the third forward spatiotemporal correlated background traffic set is HTTP request traffic.
[0095] Optionally, the forward spatiotemporal correlation background traffic set parsing module 330 is specifically used for: determining the current forward spatiotemporal correlation background traffic set to be parsed according to the priority order of the forward spatiotemporal correlation background traffic sets; when it is determined that there are multiple valid fields in the current forward spatiotemporal correlation background traffic set to be parsed, determining the valid field with the shortest time interval between the traffic collection time of each valid field and the first packet data collection time of the target encrypted traffic data as the target valid field; parsing the target valid field of the current forward spatiotemporal correlation background traffic set to be parsed, and generating the traffic data parsing result of the forward spatiotemporal correlation background traffic set based on the parsing result of the target valid field.
[0096] Optionally, the forward spatiotemporal correlation background traffic set parsing module 330 is specifically used to: determine the values of browser type and browser version based on the parsing results of the target valid fields; determine the browser type identification confidence level based on the priority order of the current parsing of the forward spatiotemporal correlation background traffic set; and construct the traffic data parsing result of the forward spatiotemporal correlation background traffic set based on the browser type, browser version, and the browser type identification confidence level.
[0097] The above-described flow analysis device can execute the flow analysis method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in this embodiment can be found in the flow analysis method provided in any embodiment of the present invention.
[0098] Since the flow analysis device described above is capable of executing the flow analysis method in the embodiments of the present invention, those skilled in the art can understand the specific implementation and various variations of the flow analysis device in this embodiment based on the flow analysis method described in the embodiments of the present invention. Therefore, how the flow analysis device implements the flow analysis method in the embodiments of the present invention will not be described in detail here. Any device used by those skilled in the art to implement the flow analysis method in the embodiments of the present invention falls within the scope of protection of this application.
[0099] Example 4
[0100] Figure 5A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0101] like Figure 5 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0102] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0103] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as traffic analysis methods.
[0104] In some embodiments, the traffic analysis method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the traffic analysis method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the traffic analysis method by any other suitable means (e.g., by means of firmware).
[0105] For example, a traffic analysis method may include the following operations:
[0106] Target encrypted traffic data is filtered based on the full network traffic data;
[0107] The forward spatiotemporal correlation background traffic set of the target encrypted traffic data is determined based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data;
[0108] The traffic data in the forward spatiotemporal correlated background traffic set is parsed according to the priority order of the forward spatiotemporal correlated background traffic set;
[0109] The encrypted traffic browser identification result is determined based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set.
[0110] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0111] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0112] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0113] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0114] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0115] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
Claims
1. A traffic analysis method, characterized by, include: Target encrypted traffic data is filtered based on the full network traffic data; The forward spatiotemporal correlation background traffic set of the target encrypted traffic data is determined based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data; The traffic data in the forward spatiotemporal correlated background traffic set is parsed according to the priority order of the forward spatiotemporal correlated background traffic set; The encrypted traffic browser identification result is determined based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set; The step of determining the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data of the target encrypted traffic data includes: Parse the target encrypted traffic data to obtain the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data; The forward time window length of the forward spatiotemporal correlated background traffic set is determined based on the first packet capture time of the target encrypted traffic data; The target IP of the forward spatiotemporally correlated background traffic set data is determined based on the source IP address and destination IP address of the target encrypted traffic data. Traffic data of the target IP within the forward time window length is selected from the full network traffic data and used as the forward spatiotemporal correlation background traffic set.
2. The method of claim 1, wherein, The target encrypted traffic data includes encrypted traffic data without an app source; The step of filtering target encrypted traffic data based on full network traffic data includes: Filter target protocol encrypted traffic data from full network traffic data; Extract the target field from the target protocol encrypted traffic data and match the target field with the target field preset library; If it is determined that the target field fails to match the target field preset library, the target protocol encrypted traffic data is identified as the target encrypted traffic data.
3. The method of claim 1, wherein, The forward spatiotemporal correlated background traffic set includes a first forward spatiotemporal correlated background traffic set collected within a first forward time window, a second forward spatiotemporal correlated background traffic set collected within a second forward time window, and a third forward spatiotemporal correlated background traffic set collected within a third forward time window, wherein: The source IP address of the first forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the first forward spatiotemporal correlated background traffic set is the same as the destination IP address of the target encrypted traffic data. The source IP address of the second forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data; The source IP address of the third forward spatiotemporal correlated background traffic set is the same as the source IP address of the target encrypted traffic data, and the destination IP address of the third forward spatiotemporal correlated background traffic set is the browser standard service IP address. The traffic in the first forward spatiotemporal correlation background traffic set, the second forward spatiotemporal correlation background traffic set, and the third forward spatiotemporal correlation background traffic set is Hypertext Transfer Protocol (HTTP) request traffic.
4. The method of claim 1, wherein, The step of parsing the traffic data in the forward spatiotemporal correlated background traffic set according to the priority order of the forward spatiotemporal correlated background traffic set includes: The current set of forward spatiotemporal correlation background traffic is determined according to the priority order of the forward spatiotemporal correlation background traffic set; If it is determined that there are multiple valid fields in the current parsed forward spatiotemporal correlation background traffic set, the valid field with the shortest traffic collection time of each valid field and the first packet data collection time interval of the target encrypted traffic data is determined as the target valid field; The target valid fields of the current forward spatiotemporal correlation background traffic set are parsed, and the traffic data parsing result of the forward spatiotemporal correlation background traffic set is generated based on the parsing result of the target valid fields.
5. The method of claim 4, wherein, Parsing the target valid fields of the currently parsed forward spatiotemporal correlation background traffic set, and generating the traffic data parsing result of the forward spatiotemporal correlation background traffic set based on the parsing result of the target valid fields, includes: The values of browser type and browser version are determined based on the parsing results of the target valid fields; The browser type identification confidence level is determined based on the priority order of the currently parsed forward spatiotemporal correlation background traffic set; The traffic data parsing results of the forward spatiotemporal correlation background traffic set are constructed based on the browser type, browser version, and browser type identification confidence level.
6. A traffic analysis device, characterized by include: The target encrypted traffic data filtering module is used to filter target encrypted traffic data based on the full network traffic data. A forward spatiotemporal correlation background traffic set determination module is used to determine the forward spatiotemporal correlation background traffic set of the target encrypted traffic data based on the parsed correlation data of the target encrypted traffic data; wherein, the capture period of the traffic data in the forward spatiotemporal correlation background traffic set is the preceding capture period of the target encrypted traffic data; The forward spatiotemporal correlation background traffic set parsing module is used to parse the traffic data in the forward spatiotemporal correlation background traffic set according to the priority order of the forward spatiotemporal correlation background traffic set; The browser identification result determination module is used to determine the encrypted traffic browser identification result based on the traffic data parsing result of the forward spatiotemporal correlation background traffic set; The forward spatiotemporal correlation background traffic set determination module is specifically used for: parsing the target encrypted traffic data to obtain the source IP address, destination IP address, and first packet capture time of the target encrypted traffic data; determining the forward time window length of the forward spatiotemporal correlation background traffic set based on the first packet capture time of the target encrypted traffic data; determining the target IP of the traffic data in the forward spatiotemporal correlation background traffic set based on the source IP address and destination IP address of the target encrypted traffic data; and filtering the traffic data of the target IP within the forward time window length from the full network traffic data as the forward spatiotemporal correlation background traffic set.
7. An electronic device, comprising: The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the traffic analysis method of any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing a processor to implement the traffic analysis method of any one of claims 1-5 when executed.
Citation Information
Patent Citations
Analyzing encrypted traffic behavior using contextual traffic data
US20180103056A1