An encrypted traffic identification method, device and electronic equipment
Patent Information
- Application Number
- CN202210671337.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-14
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-06-14
AI Technical Summary
[0003]但是,对于加密流量无法提取流量中的载荷特征,因此,相关技术中,为实现对加密流量的识别,DPI设备只能提取流量的其他特征
Smart Images

Figure CN117278233B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network security technology, and in particular to an encrypted traffic identification method, apparatus, and electronic device. Background Technology
[0002] Deep Packet Inspection (DPI) technology can extract the characteristics of the payload in traffic and classify the traffic according to these characteristics. This allows for different processing methods to be adopted in subsequent traffic forwarding processes based on the traffic category, such as discarding the traffic or forwarding it to a specific device. This article refers to the process of traffic classification as identification.
[0003] However, it's impossible to extract payload features from encrypted traffic. Therefore, in related technologies, DPI devices can only extract other features of the traffic to identify encrypted traffic. To improve identification accuracy, DPI devices need to extract more features, and may even require secondary processing of the encrypted traffic, resulting in low classification efficiency. Summary of the Invention
[0004] The purpose of this disclosure is to provide an encrypted traffic identification method, apparatus, and electronic device to improve the identification efficiency of encrypted traffic. The specific technical solution is as follows:
[0005] A first aspect of this disclosure provides a method for identifying encrypted traffic, the method comprising:
[0006] The system acquires target forwarding plane information collected by a mobile network deep packet inspection (DPI) device and target transmission information collected by an IP network DPI device. The target forwarding plane information is used to indicate the routing of target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network.
[0007] Based on the target forwarding plane information and the target transmission information, the target encrypted traffic is identified to obtain a first identification result.
[0008] In one possible embodiment, identifying the target encrypted traffic based on the target forwarding plane information and the target stream transmission information to obtain a first identification result includes:
[0009] The target forwarding plane information and the target transmission information are input into a preset traffic identification model to obtain the first identification result output by the traffic identification model;
[0010] The traffic identification model is pre-trained with sample data, which includes sample forwarding plane information, sample transmission information, and labeling identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of the sample traffic in the IP network.
[0011] In one possible embodiment, it further includes:
[0012] Determine the user information of the user to whom the target encrypted traffic belongs;
[0013] Based on the user information and the first identification result, the target encrypted traffic is identified to obtain a second identification result.
[0014] In one possible embodiment, determining the user information of the user to whom the target encrypted traffic belongs includes:
[0015] The target signaling information collected by the mobile network DPI device is obtained, wherein the target signaling information is used to represent the signaling used to transmit the target encrypted traffic in the mobile network;
[0016] Based on the target terminal information and the target forwarding plane information, determine the user information of the user to whom the target traffic belongs.
[0017] In one possible embodiment, the target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information;
[0018] Wherein, the terminal identification information is used to indicate the terminal forwarding the target encrypted traffic, the type identification information is used to indicate the type of the terminal forwarding the target encrypted traffic, and the slice identification information is used to indicate the slice in the target encrypted traffic.
[0019] In one possible embodiment, the target forwarding plane information includes one or more of the following: the source address of the target encrypted traffic, the source port of the target encrypted traffic, the destination address of the target encrypted traffic, the destination port of the target encrypted traffic, and the transport protocol of the target traffic.
[0020] In one possible embodiment, the target transmission information includes one or more of the following: the data size of each data packet in the target encrypted data stream, and the transmission interval of each data packet in the target encrypted traffic.
[0021] A second aspect of this disclosure provides an encrypted traffic identification device, the device comprising:
[0022] The information acquisition module is used to acquire target forwarding plane information collected by mobile network deep packet inspection (DPI) devices and target transmission information collected by IP network DPI devices. The target forwarding plane information is used to indicate the routing of target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network.
[0023] The first identification module is used to identify the target encrypted traffic based on the target forwarding plane information and the target transmission information, and obtain a first identification result.
[0024] In one possible embodiment, the first identification module identifies the target encrypted traffic based on the target forwarding plane information and the target stream transmission information, and obtains a first identification result, including:
[0025] The target forwarding plane information and the target transmission information are input into a preset traffic identification model to obtain the first identification result output by the traffic identification model;
[0026] The traffic identification model is pre-trained with sample data, which includes sample forwarding plane information, sample transmission information, and labeling identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of the sample traffic in the IP network.
[0027] In one possible embodiment, the device further includes a second identification module for determining user information of the user to whom the target encrypted traffic belongs;
[0028] Based on the user information and the first identification result, the target encrypted traffic is identified to obtain a second identification result.
[0029] In one possible embodiment, the second identification module determines the user information of the user to whom the target encrypted traffic belongs, including:
[0030] The target signaling information collected by the mobile network DPI device is obtained, wherein the target signaling information is used to represent the signaling used to transmit the target encrypted traffic in the mobile network;
[0031] Based on the target terminal information and the target forwarding plane information, determine the user information of the user to whom the target traffic belongs.
[0032] In one possible embodiment, the target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information;
[0033] Wherein, the terminal identification information is used to indicate the terminal forwarding the target encrypted traffic, the type identification information is used to indicate the type of the terminal forwarding the target encrypted traffic, and the slice identification information is used to indicate the slice in the target encrypted traffic.
[0034] In one possible embodiment, the target forwarding plane information includes one or more of the following: the source address of the target encrypted traffic, the source port of the target encrypted traffic, the destination address of the target encrypted traffic, the destination port of the target encrypted traffic, and the transport protocol of the target traffic.
[0035] In one possible embodiment, the target transmission information includes one or more of the following: the data size of each data packet in the target encrypted data stream, and the transmission interval of each data packet in the target encrypted traffic.
[0036] A third aspect of this disclosure provides an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus.
[0037] Memory, used to store computer programs;
[0038] When a processor executes a program stored in memory, it implements any of the steps described in the first aspect above.
[0039] A fourth aspect of this disclosure provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described in the first aspect above. Attached Figure Description
[0040] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other embodiments can be obtained based on these accompanying drawings.
[0041] Figure 1 A flowchart illustrating the encrypted traffic identification method provided in this disclosure;
[0042] Figure 2 Another flowchart illustrating the encrypted traffic identification method provided in this disclosure;
[0043] Figure 3 This is a schematic diagram of the network architecture to which the encrypted traffic identification provided in this disclosure is applied;
[0044] Figure 4Another flowchart illustrating the encrypted traffic identification method provided in this disclosure;
[0045] Figure 5 A schematic diagram of a structure of the encrypted traffic identification device provided in this disclosure;
[0046] Figure 6 This is a schematic diagram of the structure of an electronic device provided in this disclosure. Detailed Implementation
[0047] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art based on this disclosure are within the scope of protection of this disclosure.
[0048] To more clearly illustrate the encrypted traffic identification method provided in this disclosure, a possible application scenario of the encrypted traffic identification method provided in this disclosure will be illustrated below. It is understood that the following example is only one possible application scenario of the encrypted traffic identification method provided in this disclosure. In other possible embodiments, the encrypted traffic identification method provided in this disclosure can also be applied to other possible application scenarios, and the following example does not impose any limitations on this.
[0049] To meet the needs of business monitoring such as internet access log retention and service awareness, as well as mobile malware detection, Trojan and botnet monitoring, and information security management requirements of Internet Data Centers (IDCs) or Internet Service Providers (ISPs), mobile network operators have comprehensively deployed a unified DPI system in their mobile core networks (hereinafter referred to as mobile networks). Currently, DPI technology mainly identifies traffic based on the characteristics of the payload in the traffic, but this method is only applicable to the analysis of plaintext traffic.
[0050] As public awareness of cybersecurity gradually increases, the need for data protection is growing stronger. Statistics show that over 50% of internet traffic is transmitted encrypted, and this percentage continues to rise. Traditional methods for identifying plaintext traffic based on payload characteristics are not applicable to encrypted traffic. Related technologies often employ machine learning to identify the statistical characteristics of encrypted traffic.
[0051] To improve the accuracy of traffic identification, many features are used for identification, and some features involve statistical characteristics. This requires secondary processing of the data stream, resulting in low identification efficiency of DPI devices.
[0052] Based on this, this disclosure provides a method for identifying encrypted traffic, such as... Figure 1 As shown, it includes:
[0053] S101, Obtain the target forwarding plane information collected by the mobile network DPI device and the target transmission information collected by the IP network DPI device.
[0054] S102, based on the target forwarding plane information and the target transmission information, identify the target encrypted traffic and obtain the first identification result.
[0055] The embodiments of this disclosure can combine target forwarding plane information collected by mobile network DPI devices and target transmission information collected by IP network DPI devices to identify target encrypted traffic. Because it simultaneously integrates the characteristics of target encryption in both mobile and IP networks, it effectively enriches the information obtained about the encrypted traffic. Therefore, this information can better characterize the target encrypted traffic, leading to more accurate identification. By enriching the information obtained about the encrypted traffic, the amount of information about the target encrypted traffic that each DPI device needs to extract is effectively reduced, thus significantly improving the efficiency of encrypted traffic identification.
[0056] The following will explain S101-S102 respectively:
[0057] In S101, the forwarding plane information is used to represent the route of the target encrypted traffic in the mobile network. Depending on the transmission method of the target encrypted traffic in the mobile network, the forwarding plane information can represent the route of the target encrypted traffic in the mobile network in different ways. In one possible embodiment, the forwarding plane information can be represented in the form of a five-tuple of the target encrypted traffic, that is, the forwarding plane information includes the source address, source port, destination address, destination port, and transport protocol of the target encrypted traffic. For example, assuming that the target encrypted traffic is sent from network device A to network device B, the address of network device A is AddA, the port of network device A is PortA, the address of network device B is AddB, the port of network device B is PortB, and the protocol used to transmit the target encrypted traffic is Protocol 1, then the forwarding plane information is {AddA, PortA, AddB, PortB, Protocol 1}. In other possible embodiments, the forwarding plane information can also include part of the information in the five-tuple, such as only including any one, two, three, or four of the source address, source port, destination address, destination port, and transport protocol. In another possible embodiment, the forwarding information may also be represented in the form of the tunnel entrance and tunnel exit of the tunnel used to transmit the target encrypted traffic.
[0058] Target transmission information is used to indicate the transmission status of target encrypted traffic in an IP network. For example, target transmission information may include one or more of the following: the data size of each data packet in the target encrypted data stream, and the transmission interval of each data packet in the target encrypted traffic.
[0059] That is, the target transmission information can be {the data size of each data packet}, {the transmission interval of each data packet}, or {the data size of each data packet and the transmission interval of each data packet}. The transmission interval refers to the interval between the transmission times of two adjacent data packets in the time domain. The data size of each data packet can refer to the distribution of the data size of each data packet, or it can refer to the statistical value of the data size of each data packet. For example, assuming there are three data packets with data sizes of 1 unit, 2 units, and 3 units respectively, and the statistical value is the average value, then the data size of each data packet can refer to {1 unit, 2 units, 3 units}, or it can refer to {2 units}. Furthermore, the statistical value can also be other values obtained by statistically analyzing the data size of each data packet, besides the average value, including but not limited to the minimum value, maximum value, median, etc.
[0060] In this context, each data packet in the target encrypted data stream can refer to all data packets in the target encrypted data stream, or it can refer to a portion of the data packets in the target encrypted traffic. For example, each data packet in the target encrypted traffic can refer to the first preset number of traffic packets in the target encrypted traffic. The preset number can be set in advance according to actual needs, or it can be calculated by the execution entity of the encrypted traffic identification method provided in this disclosure according to preset rules. This disclosure does not impose any restrictions on this.
[0061] In S102, the first identification result is used to indicate the category of the target encrypted traffic. The method of category classification can vary depending on the application scenario. For example, in some application scenarios, to avoid malicious attacks, it is necessary to distinguish between normal traffic and malicious attack traffic in order to discard malicious attack traffic. Therefore, in this application scenario, the traffic categories include: normal traffic and malicious attack traffic. In this application scenario, the first identification result is used to indicate whether the target encrypted traffic is malicious attack traffic. In other application scenarios, to ensure the stable operation of important services, it is necessary to distinguish between important services and ordinary services in order to prioritize the forwarding of important services. Therefore, in this application scenario, the traffic categories include: traffic for important services and traffic for ordinary services. In this application scenario, the first identification result is used to indicate whether the target encrypted traffic is traffic for important services.
[0062] The method of identifying target encrypted traffic can vary depending on the application scenario. In one possible embodiment, the identification result corresponding to the target forwarding plane information and the target transmission information can be determined based on the pre-set correspondence between forwarding plane information, transmission information and identification results, and used as the first identification result.
[0063] In another possible embodiment, the target encrypted traffic can be identified based on a traffic identification model trained using machine learning. For example, target forwarding plane information and target transmission information are input into a preset traffic identification model to obtain a first identification result output by the traffic identification model. The traffic identification model in this disclosure can refer to an algorithm model trained using traditional machine learning, or it can refer to a neural network model trained using deep learning; this disclosure makes no limitation in this regard.
[0064] The traffic identification model in this disclosure is pre-trained with sample data, which includes sample forwarding plane information, sample transmission plane information, and labeled identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of sample traffic in the IP network.
[0065] The sample forwarding plane information represents the route in the same way as the target forwarding plane information. Please refer to the relevant explanation of the target forwarding plane information in S101 above, which will not be repeated here. The sample transmission information represents the transmission status in the same way as the target transmission information. Please refer to the relevant explanation of the target transmission information in S101 above, which will not be repeated here.
[0066] The labeling and identification results are the identification results of the sample traffic obtained through labeling. The sample traffic can be encrypted traffic or plaintext traffic, and this disclosure does not impose any restrictions on it.
[0067] It is understandable that, since the traffic identification model is trained in advance with sample data, which includes sample forwarding plane information, sample transmission information, and labeled identification results, the traffic identification model can learn the correspondence between forwarding plane information, transmission information, and identification results during the training process. Based on the learned correspondence, the target forwarding plane information and target transmission information input to the traffic identification model are mapped to the first identification result, and the first identification result is output.
[0068] To more clearly illustrate the encrypted traffic identification method provided in this disclosure, the following will provide illustrative examples in conjunction with specific application scenarios. (See [link to relevant documentation]). Figure 3 , Figure 3 The diagram shown is a schematic representation of the network structure provided in this disclosure, including:
[0069] IP network, mobile network, traffic splitting nodes, mobile network DPI devices, controllers, and encrypted traffic analysis and control platform.
[0070] The IP network includes IP network DPI devices. For plaintext traffic, these devices identify it using a preset identification method. For encrypted traffic, the IP network DPI devices collect transmission information via telemetry and send it as target transmission information to the encrypted traffic analysis and control platform. Furthermore, the IP network DPI devices can determine the traffic processing strategy corresponding to the extracted transmission information and process the encrypted traffic according to the determined strategy.
[0071] The mobile network includes PCF, UDM / HSS, UPF / GW-U, SMF / GW-C, and AMF. PCF, UDM / HSS, UPF / GW-U, SMF / GW-C, and AMF are different network element structures in the mobile network.
[0072] The traffic splitter node is used to copy traffic from the mobile network to the mobile network DPI device according to preset rules based on the network layer information of the mobile network. The mobile network DPI device is used to extract the forwarding plane information of the encrypted traffic and send it as the target forwarding plane information to the encrypted traffic analysis and control platform.
[0073] The controller is used to drive IP network DPI devices to collect target transmission information under the control of the encrypted traffic analysis and control platform.
[0074] An encrypted traffic analysis and control platform is used to identify encrypted traffic based on target forwarding plane information sent by mobile network DPI devices and target transmission information sent by IP network DPI devices, according to any encrypted traffic identification method provided in this disclosure.
[0075] In one possible embodiment, to further improve the accuracy of traffic identification, the encrypted traffic identification method provided in this disclosure can be as follows: Figure 2 As shown, it includes:
[0076] S201, Obtain the target forwarding plane information collected by the mobile network DPI device and the target transmission information collected by the IP network DPI device.
[0077] This step is the same as S101 above, and you can refer to the relevant description of S101 above, so it will not be repeated here.
[0078] S202, Based on the target forwarding plane information and the target transmission information, identify the target encrypted traffic and obtain the first identification result.
[0079] This step is the same as S102 above, and you can refer to the relevant description of S102 above, so it will not be repeated here.
[0080] S203, determine the user information of the user to whom the target encrypted traffic belongs.
[0081] S204. Based on the user information and the first identification result, identify the target encrypted traffic and obtain the second identification result.
[0082] By using this embodiment, the target encrypted traffic can be further identified by combining the user information of the user to whom the target encrypted traffic belongs with the first identification result. It is understood that traffic generated by different users may belong to different categories. For example, taking the aforementioned example of traffic categories being divided into normal traffic and malicious attack traffic, traffic generated by legitimate users is often normal traffic, while traffic generated by illegitimate users is often malicious attack traffic. Therefore, the user information of the user to whom the target encrypted traffic belongs can also reflect the category of the target encrypted traffic to a certain extent. Combining user information with the first identification result allows for more accurate identification of the target encrypted traffic.
[0083] S203-S204 will be explained separately below:
[0084] User information can be determined by obtaining user information sent by electronic devices capable of doing so. Furthermore, since there is interaction between the mobile network and the user's terminal device, user information can also be determined based on information sent by mobile network DPI devices.
[0085] For example, in one possible embodiment, target signaling information collected by a mobile network DPI device may be acquired, wherein the target signaling information is used to represent the signaling used to transmit target encrypted traffic in the mobile network. Based on the target signaling information and target forwarding plane information, user information of the user to whom the target traffic belongs is determined.
[0086] Understandably, since the target signaling information can represent the signaling used to transmit the target encrypted traffic, and the signaling used to transmit the target encrypted traffic will carry information about the terminal that issued these signaling or information about the slice to which these signaling is targeted, the user terminal that sent the target encrypted traffic can be traced based on this information and the routing of the target encrypted traffic, thereby determining the user information.
[0087] The target signaling information can represent the signaling used to transmit target encrypted traffic in the mobile network in different ways depending on the application scenario. For example, in one possible embodiment, the target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information.
[0088] The terminal identification information indicates the terminal forwarding the target encrypted traffic, the type identification information indicates the type of terminal forwarding the target encrypted traffic, and the slice identification information indicates the slice in the target encrypted traffic. The terminal identification information can be obtained from the SUPI field in the signaling plane message collected by the mobile network DPI device, the type identification information can be obtained from the TAC field in the signaling plane message collected by the mobile network DPI device, and the slice identification information can be obtained from the S_NSSAI field in the signaling plane message collected by the mobile network DPI device.
[0089] In S204, the second identification result is used to indicate the category of the target encrypted traffic. Depending on the application scenario, the category division method may be different, and it should be the same as the division method in S102 above. Please refer to the relevant explanation of the first identification result above, which will not be repeated here.
[0090] Taking the aforementioned example of classifying traffic into normal traffic and malicious attack traffic, since the second identification result can be used to indicate whether the target encrypted traffic is malicious attack traffic, the second identification result can be used as the result of Extended Detection and Response (XDR).
[0091] The following example will illustrate the encrypted traffic identification method provided in this publication, using the scenario of classifying traffic into normal traffic and malicious attack traffic, and combining the training and traffic identification phases. (See also...) Figure 4 :
[0092] The training phase includes:
[0093] S411, IP network telemetry acquisition, refers to the acquisition of sample transmission information of sample traffic by IP network DPI devices.
[0094] S412, Mobile Network Service Traffic Collection, refers to the sample forwarding plane information of sample traffic collected by mobile network DPI devices.
[0095] S413, Model Training.
[0096] The sample transmission information and sample forwarding surface information can be input into a preset initial model to obtain the predicted recognition result output by the preset initial model. A loss function is constructed based on the difference between the predicted recognition result and the labeled recognition result. The model parameters of the initial model are adjusted according to the direction of gradient descent of the loss function until the preset convergence condition is reached. The adjusted initial model is then saved in the model library as the traffic recognition model obtained through training.
[0097] The identification phase includes:
[0098] S421, IP network telemetry acquisition, that is, the acquisition of target transmission information of target encrypted traffic by IP network DPI devices.
[0099] S422, Mobile Network Service Traffic Collection, refers to the collection of target forwarding plane information of target encrypted traffic by mobile network DPI devices.
[0100] S423, Mobile Network Signalling Collection, refers to the collection of target signaling information of target encrypted traffic by mobile network DPI devices.
[0101] S424, parsing and identification, involves inputting the target forwarding plane information and target transmission information into the traffic identification model in the model library to obtain the first identification result output by the traffic identification model.
[0102] S425, Associated User, which means determining the user information of the user to whom the target traffic belongs based on the target signaling information and the target forwarding plane information.
[0103] S426, Generate XDR, that is, based on user information and the first identification result, identify the target encrypted traffic and obtain the second identification result, which is used as the XDR result.
[0104] Corresponding to the aforementioned encrypted traffic identification method, this disclosure also provides an encrypted traffic device, such as... Figure 5 As shown, it includes:
[0105] The information acquisition module 501 is used to acquire target forwarding plane information collected by the mobile network deep packet inspection (DPI) device and target transmission information collected by the IP network DPI device. The target forwarding plane information is used to indicate the routing of the target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network.
[0106] The first identification module 502 is used to identify the target encrypted traffic based on the target forwarding plane information and the target transmission information, and obtain a first identification result.
[0107] In one possible embodiment, the first identification module 502 identifies the target encrypted traffic based on the target forwarding plane information and the target stream transmission information, and obtains a first identification result, including:
[0108] The target forwarding plane information and the target transmission information are input into a preset traffic identification model to obtain the first identification result output by the traffic identification model;
[0109] The traffic identification model is pre-trained with sample data, which includes sample forwarding plane information, sample transmission information, and labeling identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of the sample traffic in the IP network.
[0110] In one possible embodiment, the device further includes a second identification module for determining user information of the user to whom the target encrypted traffic belongs;
[0111] Based on the user information and the first identification result, the target encrypted traffic is identified to obtain a second identification result.
[0112] In one possible embodiment, the second identification module determines the user information of the user to whom the target encrypted traffic belongs, including:
[0113] The target signaling information collected by the mobile network DPI device is obtained, wherein the target signaling information is used to represent the signaling used to transmit the target encrypted traffic in the mobile network;
[0114] Based on the target terminal information and the target forwarding plane information, determine the user information of the user to whom the target traffic belongs.
[0115] In one possible embodiment, the target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information;
[0116] Wherein, the terminal identification information is used to indicate the terminal forwarding the target encrypted traffic, the type identification information is used to indicate the type of the terminal forwarding the target encrypted traffic, and the slice identification information is used to indicate the slice in the target encrypted traffic.
[0117] In one possible embodiment, the target forwarding plane information includes one or more of the following: the source address of the target encrypted traffic, the source port of the target encrypted traffic, the destination address of the target encrypted traffic, the destination port of the target encrypted traffic, and the transport protocol of the target traffic.
[0118] In one possible embodiment, the target transmission information includes one or more of the following: the data size of each data packet in the target encrypted data stream, and the transmission interval of each data packet in the target encrypted traffic.
[0119] This disclosure also provides an electronic device, such as... Figure 6As shown, it includes a processor 601, a communication interface 602, a memory 603, and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.
[0120] Memory 603 is used to store computer programs;
[0121] When processor 601 executes a program stored in memory 603, it performs the following steps:
[0122] The system acquires target forwarding plane information collected by a mobile network deep packet inspection (DPI) device and target transmission information collected by an IP network DPI device. The forwarding plane information is used to indicate the routing of target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network.
[0123] Based on the target forwarding plane information and the target transmission information, the target encrypted traffic is identified to obtain a first identification result.
[0124] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0125] The communication interface is used for communication between the aforementioned electronic devices and other devices.
[0126] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0127] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0128] In another embodiment provided in this disclosure, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of any of the encrypted traffic identification methods described above.
[0129] In yet another embodiment provided in this disclosure, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the encrypted traffic identification methods described above.
[0130] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)).
[0131] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0132] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, embodiments of devices, electronic devices, computer-readable storage media, and computer program products are basically similar to the method embodiments, and therefore the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0133] The above description is merely a preferred embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure are included within the scope of protection of this disclosure.
Claims
1. A method for identifying encrypted traffic, characterized in that, The method includes: The system acquires target forwarding plane information collected by a mobile network deep packet inspection (DPI) device and target transmission information collected by an IP network DPI device. The target forwarding plane information is used to indicate the routing of target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network. Based on the target forwarding plane information and the target transmission information, the target encrypted traffic is identified to obtain a first identification result.
2. The method according to claim 1, characterized in that, The step of identifying the target encrypted traffic based on the target forwarding plane information and the target transmission information to obtain a first identification result includes: The target forwarding plane information and the target transmission information are input into a preset traffic identification model to obtain the first identification result output by the traffic identification model; The traffic identification model is pre-trained with sample data, which includes sample forwarding plane information, sample transmission information, and labeling identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of the sample traffic in the IP network.
3. The method according to claim 1, characterized in that, Also includes: Determine the user information of the user to whom the target encrypted traffic belongs; Based on the user information and the first identification result, the target encrypted traffic is identified to obtain a second identification result.
4. The method according to claim 3, characterized in that, The user information for determining the user to whom the target encrypted traffic belongs includes: The target signaling information collected by the mobile network DPI device is obtained, wherein the target signaling information is used to represent the signaling used to transmit the target encrypted traffic in the mobile network; Based on the target signaling information and the target forwarding plane information, determine the user information of the user to whom the target encrypted traffic belongs.
5. The method according to claim 4, characterized in that, The target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information; Wherein, the terminal identification information is used to indicate the terminal forwarding the target encrypted traffic, the type identification information is used to indicate the type of the terminal forwarding the target encrypted traffic, and the slice identification information is used to indicate the slice in the target encrypted traffic.
6. The method according to claim 1, characterized in that, The target forwarding plane information includes one or more of the following: the source address of the target encrypted traffic, the source port of the target encrypted traffic, the destination address of the target encrypted traffic, the destination port of the target encrypted traffic, and the transmission protocol of the target encrypted traffic.
7. The method according to claim 1, characterized in that, The target transmission information includes one or more of the following: the data volume of each data packet in the target encrypted traffic, and the transmission interval of each data packet in the target encrypted traffic.
8. An encrypted traffic identification device, characterized in that, The device includes: The information acquisition module is used to acquire target forwarding plane information collected by mobile network deep packet inspection (DPI) devices and target transmission information collected by IP network DPI devices. The target forwarding plane information is used to indicate the routing of target encrypted traffic in the mobile network, and the target transmission information is used to indicate the transmission status of the target encrypted traffic in the IP network. The first identification module is used to identify the target encrypted traffic based on the target forwarding plane information and the target transmission information, and obtain a first identification result.
9. The apparatus according to claim 8, characterized in that, The first identification module identifies the target encrypted traffic based on the target forwarding plane information and the target transmission information, and obtains a first identification result, including: The target forwarding plane information and the target transmission information are input into a preset traffic identification model to obtain the first identification result output by the traffic identification model; The traffic identification model is pre-trained with sample data, which includes sample forwarding plane information, sample transmission information, and labeling identification results. The sample forwarding plane information is used to represent the routing of sample traffic in the mobile network, and the sample transmission information is used to represent the transmission status of the sample traffic in the IP network.
10. The apparatus according to claim 8, characterized in that, The device further includes a second identification module for determining the user information of the user to whom the target encrypted traffic belongs; Based on the user information and the first identification result, the target encrypted traffic is identified to obtain a second identification result.
11. The apparatus according to claim 10, characterized in that, The second identification module determines the user information of the user to whom the target encrypted traffic belongs, including: The target signaling information collected by the mobile network DPI device is obtained, wherein the target signaling information is used to represent the signaling used to transmit the target encrypted traffic in the mobile network; Based on the target terminal information and the target forwarding plane information, determine the user information of the user to whom the target encrypted traffic belongs.
12. The apparatus according to claim 11, characterized in that, The target signaling information includes one or more of the following: terminal identification information, type identification information, and slice identification information; Wherein, the terminal identification information is used to indicate the terminal forwarding the target encrypted traffic, the type identification information is used to indicate the type of the terminal forwarding the target encrypted traffic, and the slice identification information is used to indicate the slice in the target encrypted traffic.
13. The apparatus according to claim 8, characterized in that, The target forwarding plane information includes one or more of the following: the source address of the target encrypted traffic, the source port of the target encrypted traffic, the destination address of the target encrypted traffic, the destination port of the target encrypted traffic, and the transmission protocol of the target encrypted traffic.
14. The apparatus according to claim 8, characterized in that, The target transmission information includes one or more of the following: the data volume of each data packet in the target encrypted traffic, and the transmission interval of each data packet in the target encrypted traffic.
15. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the steps of the method described in any one of claims 1-7.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-7.
Citation Information
Patent Citations
Internet of things cloud platform traffic safety analysis method and system
CN107888605A
Flow identification method and device
CN112822189A