A method and system based on SSL sharding and blocking

By diversion of communication data between the terminal and the server and reorganizing and parsing ClientHello messages, extracting server names and matching, blocking malicious connections, the problem of inability to effectively block malicious communication in the existing technology is solved, and real-time security protection and network stability of the terminal are achieved.

CN119172316BActive Publication Date: 2025-07-11WUHAN BOYIXUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411212795.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2025-07-11
Estimated Expiration
2044-08-30

AI Technical Summary

Technical Problem

The existing blocking methods cannot effectively block the spread of malware, resulting in a surge in terminal traffic and network blockage. It is difficult for existing technology to identify and block malicious communications to clienthello subcontract transmission during the TLS authentication process, and the blocking effect is limited.

Method used

By diversion of communication data between the terminal and the server, reorganize and parse the ClientHello message to extract the server name, match the malicious website library, and send blocking data packets when the match is successful, blocking the connection between the terminal and the server.

Benefits of technology

Real-time blocking of malicious communications is achieved, terminal security is improved, traffic surges and network blockage are avoided, and blocking success rate is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119172316B_ABST
    Figure CN119172316B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of computer technology, and discloses a method and system based on SSL sharding and blocking. The method includes: shunting data interacted between a terminal and a server through an egress router of the terminal mobile network and a gateway general packet radio service support node (GGSN) connected to the egress router of the mobile network; reorganizing and parsing the shunted data clienthello to obtain the servername of the server; matching according to the parsed servername of the server in a malicious website library; if the matching is successful, sending a blocking data packet to the egress router of the mobile network to block the connection between the terminal and the server. The present invention adopts a bypass blocking technology to avoid the phenomenon that the terminal still sends requests after the website is blocked, resulting in a sharp increase in terminal traffic and network congestion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to, but is not limited to, the field of computer technology, and particularly relates to a method and system based on SSL sharding blocking. Background Art

[0002] Existing blocking means are bad information monitoring systems, spam and multimedia message spam systems. The spam and multimedia message spam systems can only block spam messages and multimedia message spam by their content and sending numbers. They are aimed at the spread of advertisements, illegal, pornographic, and mafia-related content, and can play a certain role in the spread of mobile malware through spam messages and multimedia message spam. However, this way of spreading accounts for a relatively small proportion. The bad information monitoring system can block the URLs for spreading malware. By simply blocking the URLs, it can only prevent mobile phone users from continuing to access. However, the malicious programs on the mobile phone terminals will still continuously request these websites, resulting in a sharp increase in access traffic, a large loss of user traffic, and even network congestion. Summary of the Invention

[0003] In view of the problems existing in the prior art, the present invention provides a method and system based on SSL sharding blocking.

[0004] The present invention is implemented as follows. A method based on SSL sharding blocking includes:

[0005] S1: Shunt the data that the terminal interacts with the server through the terminal mobile network egress router and the gateway general packet radio service support node GGSN connected to the mobile network egress router.

[0006] S2: Recombine and parse the shunted data clienthello to obtain the servername of the server.

[0007] S3: Match according to the parsed servername of the server in the malicious website library; if the match is successful, send a blocking data packet to the mobile network egress router to block the connection between the terminal and the server.

[0008] Further, the S2 specifically includes:

[0009] S21: Initialize the SSL blocking rule library.

[0010] S22: Packet processing.

[0011] S23: Judge whether the SSL traffic and the number of online packets are less than 10. If it is false, execute step S22.

[0012] S24: Look up the recombination node in the clienthello recombination table based on the quadruple for hashing. If found, the recombination of the clienthello is required;

[0013] S25: Determine whether the clienthello of the recombined packet is complete. If not, execute S22;

[0014] S26: Extract the server_name field from the clienthello.

[0015] Another object of the present invention is to provide a system based on SSL sharding blocking for implementing the method based on SSL sharding blocking. The system includes:

[0016] A shunt module for shunting the data interacted between the terminal and the server through the terminal mobile network egress router and the gateway general packet radio service support node GGSN connected to the mobile network egress router;

[0017] A recombination and parsing module, connected to the shunt module, for recombining and parsing the shunted data clienthello to obtain the servername of the server;

[0018] A blocking module, connected to the recombination and parsing module, for matching in the malicious website library according to the parsed servername of the server; if the match is successful, a blocking data packet is sent to the mobile network egress router to block the connection between the terminal and the server.

[0019] Another object of the present invention is to provide a computer device. The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the method based on SSL sharding blocking.

[0020] Another object of the present invention is to provide a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor executes the steps of the method based on SSL sharding blocking.

[0021] Another object of the present invention is to provide an information data processing terminal for implementing the system based on SSL sharding blocking.

[0022] First, the present invention adopts a bypass blocking technology to avoid the phenomenon that the terminal still sends requests after the website is blocked, resulting in a sharp increase in terminal traffic and network congestion.

[0023] This solution adopts the bypass blocking technology. By reorganizing the clienthello to parse out the domain name, then calculating the hash value of the domain name, it quickly matches malicious domain names. For the matched traffic, it sends TCP Reset packets and at the same time sends blocking messages to the client and the server to achieve the blocking of malicious domain names, avoiding the phenomenon that the mobile phone still continuously sends requests after the website is blocked, resulting in a sharp increase in terminal traffic and network congestion.

[0024] Second, the technical solution of the present invention solves the technical problem that people have been eager to solve but have never succeeded in:

[0025] During the TLS authentication process of many existing illegal websites, the clienthello is transmitted in packets to avoid filing detection, resulting in a low blocking success rate and limited blocking effect.

[0026] In the solution of the embodiment of the present invention, the fragmented clienthello is quickly reorganized, the domain name is extracted from the clienthello, and then the domain name is matched in the malicious domain name rule library. If it is matched, the domain name is blocked bidirectionally.

[0027] Third, the method based on SSL fragmentation blocking realizes the real-time blocking and security protection of malicious communication through the following steps:

[0028] 1. Data diversion: In network communication, the terminal device interacts with the server through the mobile network egress router. To monitor and process this communication traffic, the system first diverts the data stream of the terminal at the mobile network egress router and the connected gateway (such as GGSN). The main purpose of this process is to intercept and divert the communication data between the terminal and the server for subsequent detailed parsing and processing.

[0029] 2. ClientHello reorganization and parsing: In the diverted communication data, the system pays special attention to the ClientHello message in the SSL / TLS handshake process. The ClientHello message is the initial request sent by the client when establishing an SSL / TLS connection, containing many key information such as supported encryption algorithms, session IDs, etc. By reorganizing and parsing the ClientHello message, the system can extract important fields, especially the server name, which is crucial for subsequent security detection.

[0030] 3. Server name matching: The parsed server name is matched against the entries in the malicious website library pre-set in the system. The malicious website library contains information about some known malicious or insecure websites. By comparing the server name, the system can determine whether the terminal is attempting to communicate with a malicious server. If it is found that the server name exists in the malicious website library, it indicates that the terminal is attempting to access an insecure website.

[0031] 4. Block communication: After confirming the match between the server name and the malicious website library, the system immediately generates and sends a blocking data packet to the mobile network egress router. The purpose of this data packet is to quickly interrupt the SSL connection between the terminal and the server, thereby preventing the terminal from continuing to communicate with the malicious server. Through this real-time blocking mechanism, the system can effectively prevent the potential harm caused by malicious websites to terminal devices and users.

[0032] This technical solution has made significant technological progress in improving terminal security by real-time monitoring and blocking insecure SSL connections, and has solved the problem in the prior art that it is difficult to effectively identify and block malicious communications. Brief Description of the Drawings

[0033] Figure 1 is a flowchart of a method based on SSL sharding and blocking provided by an embodiment of the present invention;

[0034] Figure 2 is a flowchart of a method for reorganizing and parsing the shunted data clienthello to obtain the servername of the server provided by an embodiment of the present invention;

[0035] Figure 3 is a structural diagram of a system based on SSL sharding and blocking provided by an embodiment of the present invention;

[0036] In the figure: 1. Shunting module; 2. Reorganizing and parsing module; 3. Blocking module. Detailed Embodiments

[0037] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the following further details the present invention with reference to embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0038] As Figure 1 shown, an embodiment of the present invention provides a method based on SSL sharding and blocking, and the method includes:

[0039] S1: Shunt the data interacted by the terminal with the server through the terminal mobile network egress router and the gateway general packet radio service support node GGSN connected to the mobile network egress router;

[0040] S2: Reorganize and parse the shunted data clienthello to obtain the servername of the server.

[0041] S3: Match according to the parsed servername of the server in the malicious website library; if the match is successful, send a blocking data packet to the mobile network egress router to block the connection between the terminal and the server.

[0042] The working principle of the SSL sharding blocking method includes the following four steps:

[0043] 1. Data sharding: In a network environment, a terminal device communicates with a server through a terminal mobile network egress router. To monitor and control this communication traffic, first, the data stream of the terminal is sharded through the mobile network egress router and the connected gateway General Packet Radio Service Support Node (GGSN). The purpose of this step is to intercept and shard the communication data between the terminal and the server for subsequent parsing and processing.

[0044] 2. ClientHello reorganization and parsing: Among the sharded data, the focus is on the ClientHello message in the SSL / TLS handshake process. ClientHello is part of the SSL / TLS protocol and contains the initial information when the client initiates a connection. By reorganizing and parsing the ClientHello message, the system can extract important fields such as the server name (servername), which is crucial for subsequent security detection.

[0045] 3. Server name matching: The parsed server name (servername) is used to match against a pre-set malicious website library. The malicious website library contains information about some known insecure or illegal websites. By matching the server name, the system can determine whether the terminal is attempting to communicate with a malicious server. If a match is found for the server name in the malicious website library, it indicates that the terminal is attempting to access an insecure or malicious website.

[0046] 4. Block communication: Once a malicious website match is successful, the system generates and sends a blocking data packet to the mobile network egress router. The role of this data packet is to immediately block the SSL connection between the terminal and the server, thereby preventing the terminal from continuing to communicate with the malicious server. This blocking mechanism effectively protects the terminal device and its users from malicious websites by intervening in the communication traffic in real-time.

[0047] As Figure 2 shown, the specific content of S2 includes:

[0048] S21: Initialize the SSL blocking rule library;

[0049] S22: Packet processing;

[0050] S23: Determine if the SSL traffic and the number of online packets are less than 10. If false, execute step S22;

[0051] S24: Do a hash based on the quadruple to find the recombination node in the clienthello recombination table. If found, the clienthello needs to be recombined;

[0052] S25: Determine if the clienthello of the recombined packet is complete. If not, execute S22;

[0053] S26: Extract the server_name field from the clienthello.

[0054] As Figure 3 shown, an embodiment of the present invention provides an SSL sharding blocking-based system for implementing the method of SSL sharding blocking. The system includes:

[0055] A shunting module 1 for shunting the data that the terminal interacts with the server through the terminal mobile network egress router and the gateway general packet radio service support node GGSN connected to the mobile network egress router;

[0056] A recombination and parsing module 2, connected to the shunting module 1, recombines and parses the shunted data clienthello to obtain the servername of the server;

[0057] A blocking module 3, connected to the recombination and parsing module 2, matches according to the parsed servername of the server in the malicious website library; if the match is successful, a blocking data packet is sent to the mobile network egress router to block the connection between the terminal and the server.

[0058] An embodiment of the present invention provides a computer device. The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the method of SSL sharding blocking.

[0059] An embodiment of the present invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor executes the steps of the method of SSL sharding blocking.

[0060] An embodiment of the present invention provides an information data processing terminal, and the information data processing terminal is used to implement the system based on SSL sharding and blocking.

[0061] Embodiment 1: Mobile network communication security protection method based on SSL sharding and blocking

[0062] In a mobile network environment, a user's mobile terminal device communicates with an Internet server through a mobile network egress router. To ensure communication security, the system first sets up a shunting module between the mobile network egress router and the GGSN (General Packet Radio Service Support Node) to shunt the communication data between the user and the server. The system focuses on monitoring the ClientHello message during the SSL / TLS handshake process. By extracting the server name field in the ClientHello message and matching it with the names in a preset malicious website library, if a match is found, the system immediately generates and sends a blocking data packet to prevent communication between the mobile terminal and the server, ensuring the user's network security.

[0063] Embodiment 2: Enterprise intranet security protection method based on SSL sharding and blocking

[0064] In an enterprise internal network, all employees' computers communicate with external servers through an intranet gateway. To prevent employees from accidentally accessing malicious websites, the system installs a shunting device at the intranet gateway to monitor and shunt all data flows in and out of the intranet. The system parses the ClientHello message in real time during the SSL / TLS handshake phase, extracts the server name field, and compares it with a blacklist defined by the enterprise. If it is found that an employee's computer is attempting to access a server in the blacklist, the system will immediately issue a blocking command to terminate the access request to ensure the security of the enterprise intranet.

[0065] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated designed hardware. Those of ordinary skill in the art can understand that the above devices and methods can be implemented using computer-executable instructions and / or included in processor control code, such as provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and their modules of the present invention can be implemented by hardware circuits of programmable hardware devices such as very large scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above hardware circuits and software such as firmware.

[0066] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be covered within the protection scope of the present invention.

Claims

1. A method based on SSL sharding and blocking, characterized in that The method includes: S1: Shunt the data that the terminal interacts with the server through the terminal mobile network egress router and the Gateway General Packet Radio Service Support Node (GGSN) connected to the mobile network egress router; S2: Reorganize and parse the shunted data clienthello to obtain the servername of the server; S3: Match according to the parsed servername of the server in the malicious website library; if the match is successful, send a blocking data packet to the mobile network egress router to block the connection between the terminal and the server; The specific steps of S2 include: S21: Initialize the SSL blocking rule library; S22: Packet processing; S23: Judge that the SSL traffic and the number of online packets are less than 10. If it is false, execute step S22; S24: Look up the reorganization node in the clienthello reorganization table according to the quadruple by hashing. If found, the clienthello needs to be reorganized; S25: Judge whether the clienthello of the reorganized packet is complete. If it is incomplete, execute S22; S26: Extract the server_name field from the clienthello.

2. An SSL sharding blocking-based system for implementing the method of SSL sharding blocking as described in claim 1, characterized in that, The system includes: A shunt module, which is used to shunt the data that the terminal interacts with the server through the terminal mobile network egress router and the Gateway General Packet Radio Service Support Node (GGSN) connected to the mobile network egress router; A reorganization and parsing module, connected to the shunt module, reorganizes and parses the shunted data clienthello to obtain the servername of the server; A blocking module, connected to the reorganization and parsing module, matches according to the parsed servername of the server in the malicious website library; if the match is successful, send a blocking data packet to the mobile network egress router to block the connection between the terminal and the server.

3. A computer device, characterized in that, The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the method based on SSL sharding and blocking as claimed in claim 1.

4. A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor executes the steps of the method based on SSL sharding and blocking as claimed in claim 1.

5. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the system based on SSL sharding and blocking as claimed in claim 2.

6. A mobile network communication security protection method based on SSL sharding and blocking, characterized in that, It includes the following steps: Shunt the communication data between the terminal device and the server through the mobile network egress router and the GGSN; Reorganize and parse the ClientHello message in the shunted SSL / TLS handshake message, and extract the server name (servername) field. The specific steps include: S21: Initialize the SSL blocking rule library; S22: Packet processing; S23: Judge that the SSL traffic and the number of online packets are less than 10. If it is false, execute step S22; S24: Look up the recombination node in the clienthello recombination table based on the quadruple for hashing. If found, the recombination of the clienthello is required; S25: Determine whether the clienthello of the recombined packet is complete. If not, execute S22; S26: Extract the server_name field from the clienthello; Match the extracted server name with the names in the malicious website library; If the match is successful, generate and send a blocking data packet to the mobile network egress router to prevent the SSL connection between the terminal device and the server.

Citation Information

Patent Citations

  • Blocking method, device and system for malicious website

    CN104980408A

  • Website access monitoring method and device, server and computer readable storage medium

    CN112448920A