Multi-layer Network Forensics Method, System, Electronic Device and Medium

By establishing communication tunnels layer by layer in a multi-layer network environment and segmenting evidence collection tasks, the problem of accessing intranet servers across multi-layer firewalls is solved, and efficient two-way communication and data transmission are achieved.

CN119420551BActive Publication Date: 2025-07-22SHANGHAI HONGLIAN NETWORK CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411559477.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-07-22
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

Although the existing multi-layer firewall design improves network security, it increases the complexity of cross-layer communication, making it difficult for external users to directly access the intranet server.

Method used

By detecting the network environment, obtaining the communication protocol and port of the relay node, establishing communication tunnels layer by layer, and dividing the evidence forensics into subtasks, distributing them to the target nodes through multi-layer communication tunnels, realizing bidirectional communication and data transmission across multi-layer firewalls.

Benefits of technology

Penetrating the multi-layer network firewall, achieving two-way communication and data transmission with multiple target nodes in different NAT subnets, reducing dependence on manual intervention and ensuring the concealment and security of forensic data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420551B_ABST
    Figure CN119420551B_ABST
Patent Text Reader

Abstract

The present application provides a multi-layer network forensics method, system, electronic device and medium. The multi-layer network forensics method includes: detecting the network environment and starting the forensics software to obtain the available basic communication protocols and ports between the NAT subnet relay node and the lower-layer devices; establishing communication tunnels layer by layer between the relay node and each jump server, and between each jump server and the target node according to the communication protocols and ports; receiving a forensics task and splitting the sub-tasks and instructions according to the forensics task to achieve the forensics purpose; distributing the forensics sub-tasks to each distributed target node through the multi-layer communication tunnels; receiving the data packets fed back by the target node through the multi-layer communication tunnels and displaying the forensics results. Such a multi-layer network forensics method can penetrate multiple layers of network firewalls and achieve two-way communication and data transmission with multiple target nodes in different NAT subnets simultaneously.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of electronic data forensics, and relates to a multi-layer network forensics method, in particular to a multi-layer network forensics method, system, electronic device and medium. Background Art

[0002] In the modern network security system, accessing an intranet server across multiple firewalls is a complex and challenging task. As the first line of defense for network security, a firewall effectively prevents external threats by monitoring and filtering the data traffic in and out of the network. However, this security policy also poses problems for legitimate communications. In the network architectures of enterprises or other organizations, multiple firewalls are usually deployed to enhance security. External users or applications often need to go through multiple layers of firewalls to establish communication with the intranet server. Although this design improves the security of the system, it also greatly increases the complexity of cross-layer communication. Especially when accessing an intranet server, the firewall usually blocks unauthorized communication requests, making it difficult for external users to directly access intranet resources.

[0003] In summary, although the existing multi-layer firewall technology performs excellently in protecting the intranet security, its blockage of the internal and external network communication also makes it a difficult technical problem to directly access the intranet server. Summary of the Invention

[0004] In view of the above-mentioned disadvantages of the prior art, the purpose of this application is to provide a multi-layer network forensics method, system, electronic device and medium, which is used to solve the problem of difficult access to the intranet server across multiple firewalls.

[0005] In a first aspect, this application provides a multi-layer network forensics method, and the multi-layer network forensics method includes: detecting the network environment and starting the forensics software, and obtaining the communication protocol and port with the relay node; establishing communication tunnels layer by layer between the relay node and each jump server, and between each jump server and the target node according to the communication protocol and port; receiving a forensics task instruction and splitting the forensics task according to the forensics task instruction to obtain forensics subtasks; distributing the forensics subtasks to the target node through multiple communication tunnels; receiving the data packets fed back by the target node through multiple communication tunnels and displaying the forensics results.

[0006] In this application, the communication protocol and port of the relay node are obtained, and communication tunnels are established layer by layer between the relay node and each jump board machine, and between each jump board machine and the target node. The evidence collection subtasks after the evidence collection task is divided are distributed to the target node through the multi-layer communication tunnel. After the target node executes the evidence collection subtask, it receives and displays the data packets fed back through the communication tunnel. This multi-layer network evidence collection method can penetrate multi-layer network firewalls and realize two-way communication and data transmission with multiple target nodes in different NAT subnets at the same time.

[0007] In an implementation of the first aspect, detecting the network environment and starting the forensic software to obtain the communication protocol with the relay node includes: detecting the network environment and starting the forensic software, sending a protocol request to the relay node; matching the protocol request with the communication protocol of the relay node, if the match is successful, establishing a communication connection with the relay node, if the match fails, changing the communication protocol and sending a protocol request.

[0008] In an implementation of the first aspect, the multi-layer network forensics method also includes: determining whether a proxy or routing address translation is required, and if so, initializing the proxy and routing address translation, using the relay node to reversely break through the firewall restrictions, using each of the jump servers to establish a communication connection between the relay node and the target node, and establishing an external bastion host based on the communication connection; if not required, directly establishing an external bastion host.

[0009] In an implementation of the first aspect, establishing communication tunnels layer by layer between the relay node and each jump machine, and between each jump machine and the target node according to the communication protocol and port includes: starting the forensic software on each jump machine in turn, and connecting each jump machine layer by layer according to the communication protocol and port; generating an encryption key when each jump machine is connected layer by layer using a dynamic key exchange mechanism; and establishing communication tunnels layer by layer between the relay node and each jump machine, and between each jump machine and the target node using the encryption key and the layer-by-layer connection of each jump machine.

[0010] In this implementation, multi-layer encryption and protocol camouflage make it difficult for forensic data to be detected during transmission, ensuring the concealment of forensic data. The establishment of communication tunnels can maintain high availability under different network conditions, enhancing the security of forensic data. In addition, the automated tunnel establishment and maintenance process also reduces manual intervention and reduces dependence on manual labor.

[0011] In an implementation of the first aspect, distributing the forensic subtask to the target node through multiple layers of the communication tunnel includes: using a task distribution algorithm to distribute the forensic subtask from the relay node to each layer of the communication tunnel step by step; using an inter-layer load balancing algorithm to evenly distribute the tasks of each layer of the communication tunnel and transmit them to the target node.

[0012] In this implementation manner, after the forensics task is split and distributed to the target nodes, it supports resume from breakpoint and shard transmission, and can still ensure the sending and receiving of forensics data in a weak network environment. The distributed task distribution and execution mechanism can distribute forensics tasks to all devices in the link at the same time, split the subtasks to different devices, and achieve efficient task distribution and execution.

[0013] In an implementation manner of the first aspect, receiving the data packets fed back by the target nodes through multiple layers of the communication tunnels includes: using a dynamic routing algorithm to perform shard processing on the forensics data packets fed back by the target nodes to obtain shard data packets; performing transmission target confirmation and data source confirmation when the shard data packets are transmitted through each layer of the jump servers, and incorporating the numbers of the jump servers into the shard data packets; receiving the shard data packets and obtaining the complete link for transmitting the data packets through multiple layers of the communication tunnels according to the numbers of the shard data packets.

[0014] In this implementation manner, encoding the data transmitted by each jump server and performing verification on the encoding and then integrating the data packets can ensure the correctness and integrity of the forensics data transmission.

[0015] In an implementation manner of the first aspect, the multi-layer network forensics method further includes: determining whether it is necessary to horizontally expand the communication network, and if so, delivering and starting the forensics software to other jump servers, and if not, obtaining forensics subtasks and performing forensics operations.

[0016] In a second aspect, the present application provides a multi-layer network forensics system, which includes: a protocol acquisition module, configured to detect the network environment and start the forensics software, and obtain the communication protocol and port with the relay node; a tunnel establishment module, configured to layer by layer establish communication tunnels between the relay node and each jump server, and between each jump server and the target node according to the communication protocol and port; a task splitting module, configured to receive a forensics task instruction and split the forensics task according to the forensics task instruction to obtain forensics subtasks; a task distribution module, configured to distribute the forensics subtasks to the target nodes through multiple layers of the communication tunnels; a data acquisition module, configured to receive the data packets fed back by the target nodes through multiple layers of the communication tunnels and display the forensics results.

[0017] In a third aspect, the present application provides an electronic device, which includes: a memory, configured to store a computer program; a processor, where the processor is configured to execute the computer program stored in the memory, so that the electronic device executes the multi-layer network forensics method according to any one of the first aspect.

[0018] Fourthly, the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the multi-layer network forensics method described in any one of the first aspects is implemented. Description of the Drawings

[0019] Figure 1A It shows a schematic diagram of an application scenario of the multi-layer network forensics method described in the present application.

[0020] Figure 1B It shows a schematic diagram of the structure of the end-cloud interaction scenario in these implementation manners.

[0021] Figure 2 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0022] Figure 3 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0023] Figure 4 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0024] Figure 5 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0025] Figure 6 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0026] Figure 7 It shows a schematic flowchart of the multi-layer network forensics method described in the embodiments of the present application.

[0027] Figure 8 It shows a schematic diagram of the structure of the multi-layer network forensics system described in the embodiments of the present application.

[0028] Figure 9 It shows a schematic diagram of the structure of the electronic device described in the embodiments of the present application.

[0029] Description of Element Numbers

[0030] 1 Forensics Device

[0031] 11 Local Server

[0032] 12 Relay Server

[0033] 13 Target Server

[0034] 2 End-Cloud Interaction System

[0035] 20 Terminal

[0036] 21 Cloud server

[0037] 100 Multi-layer network forensics system

[0038] 110 Protocol acquisition module

[0039] 120 Tunnel establishment module

[0040] 130 Task segmentation module

[0041] 140 Task distribution module

[0042] 150 Data acquisition module

[0043] 900 Electronic device

[0044] 910 Memory

[0045] 920 Processor

[0046] 930 Display

[0047] Steps S11~S15

[0048] Steps S111~S113

[0049] Steps S121~S123

[0050] Steps S141~S142

[0051] Steps S151~S153 Specific implementation manners

[0052] The following uses specific specific examples to illustrate the implementation manners of the present application. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0053] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner. Therefore, only the components related to the present application are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and proportion of each component in actual implementation can be an arbitrary change, and the component layout type may also be more complex.

[0054] In a complex network environment, especially in large cloud services or enterprise-level network architectures, internal network servers are usually located behind multiple layers of subnets and their firewalls and can only be accessed through one or more jump servers. Such a network structure and the above-mentioned difficulties pose great challenges to remote forensics. Traditional forensics methods are difficult to directly access these multi-layer internal network servers and often require the assistance of network administrators to configure complex network access rules at the routing level. Or use some proxy software multiple times to repeatedly deploy and enable it in each layer of jump servers. This not only has low penetration efficiency but may also expose sensitive information.

[0055] At least for the above problems, the embodiments of the present application provide a multi-layer network forensics method, and the multi-layer network forensics method includes: detecting the network environment and starting the forensics software to obtain the communication protocol and port with the relay node; establishing communication tunnels layer by layer between the relay node and each jump server and between each jump server and the target node according to the communication protocol and port; receiving a forensics task instruction and splitting the forensics task according to the forensics task instruction to obtain forensics subtasks; distributing the forensics subtasks to the target node through multiple layers of the communication tunnels; receiving the data packets fed back by the target node through multiple layers of the communication tunnels and displaying the forensics results.

[0056] In the embodiments of the present application, the communication protocol and port of the relay node are obtained, and based on this, communication tunnels are established layer by layer between the relay node and each jump server and between each jump server and the target node. The forensics subtasks after splitting the forensics task are distributed to the target node through multiple layers of communication tunnels, and after the target node executes the forensics subtasks, it receives the data packets fed back through the communication tunnels and displays them. Such a multi-layer network forensics method can penetrate multiple layers of network firewalls and achieve two-way communication and data transmission with the target node.

[0057] Figure 1A Shown is a schematic diagram of an application scenario of the multi-layer network forensics method described in the present application. The forensics device 1 can be used to implement the multi-layer network forensics method provided by the embodiments of the present application, but the application scenario of the multi-layer network forensics method provided by the embodiments of the present application is not limited to Figure 1A the forensics device 1 shown. As Figure 1A shown, the forensics device 1 includes a local server 11, a relay server 12, and a target server 13.

[0058] Among them, Figure 1A the local server 11 in can be a single local server or a local server cluster or a cloud computing center composed of multiple local servers, etc., and are not specifically limited here. Although Figure 1A only one local server 11, one relay server 12, and one target server 13 are shown in, it should be understood that Figure 1AThe examples in it are only for understanding this solution, and the specific number of servers should be flexibly determined according to the actual situation.

[0059] In some other implementation manners, the evidence collection device 1 may also not include the relay server 12, but only include the local server 11 with data sending and receiving functions and the target server 13. The local server 11 with a display function may include a tablet computer, a laptop computer, a personal digital assistant, a mobile phone, a personal computer (abbreviated as PC) and a voice interaction device, or may also be a monitoring device, a face recognition device, etc., which is not limited herein.

[0060] In still some other implementation manners, the multi-layer network evidence collection method described in this application can be applied to an end-cloud interaction scenario. Figure 1B Shown is a schematic structural diagram of the end-cloud interaction scenario in these implementation manners. As Figure 1B shown, the end-cloud interaction system 2 includes a terminal 20 and a cloud server 21, and communication can be performed between the terminal 20 and the cloud server 21, and the communication method is not limited to wired or wireless methods.

[0061] Among them, the terminal 20 can be mobile or fixed. For example, the terminal 20 can be a wireless terminal or a wired terminal. The wireless terminal can refer to a device with wireless sending and receiving functions and can be deployed indoors, outdoors and in industrial workshops. The terminal 20 can be a mobile phone, a tablet computer, a laptop computer, etc., which is not limited herein. The cloud server 21 can include one or more servers, or include one or more processing nodes, or include one or more virtual machines running on the server. The cloud server 21 can also be referred to as a server cluster, a management platform, a data processing center, etc., which is not limited in the embodiments of this application.

[0062] Next, the technical solutions in the embodiments of this application will be described in detail with reference to the accompanying drawings in the embodiments of this application.

[0063] The following embodiments of this application provide a multi-layer network evidence collection method, and this method can be implemented, for example, by Figure 1A the local server 11 shown in Figure 1B or the cloud server 21 shown in Figure 2 Shown is a schematic flowchart of the multi-layer network evidence collection method described in the embodiments of this application. As Figure 2 shown, the multi-layer network evidence collection method includes steps S11 to S15.

[0064] Step S11, detect the network environment and start the evidence collection software, and obtain the communication protocol and port with the relay node.

[0065] Optionally, the multi-layer network evidence collection method is implemented between a control node, a relay node and a target node, the control node is a forensic server for issuing forensic tasks, the relay node is a proxy server for directly communicating with the target node and hiding the real address of the control node, and the target node is an intranet server storing evidence data. In some possible implementations, the relay node is used as a relay node of the control node to exchange data with the target node, and in other possible implementations, the relay node may not be used, and the control node may be directly used to exchange data with the target node, and the present application is not limited thereto.

[0066] In some possible implementations, the forensic software is a cross-platform software program that can achieve the following functions: (1) Establish a communication tunnel using common open ports, including 80 / TCP, 443 / TCP, and 53 / UDP. (2) Encapsulate the acquired data packets in ordinary HTTP or HTTPS traffic, and encapsulate them in UDP packets in the form of data stream slices, to achieve the development of protocol camouflage technology by dynamically combining and nesting the two. (3) Perform traffic obfuscation on the acquired data packets, so that the content of the data packets is encrypted, compressed and obfuscated but the appearance is consistent with normal traffic. (4) Split large forensic tasks and develop breakpoint resumption and session recovery mechanisms. (5) Implement routing address translation (NAT) penetration technology to establish a reliable point-to-point connection for UDP packets, such as STUN (Session traversal utilities for NAT). (6) Establish a new data link layer on the open system interconnection OSI application layer, and after the network communication is established, use the unique address of the new data link layer to exchange data. (7) Add a traffic noise module during data exchange to mix fake data into real data to interfere with deep packet inspection. (8) Split large forensic tasks according to the task segmentation algorithm to achieve distributed task scheduling. (9) Ensure the integrity and consistency of data transmitted in multi-layer communication tunnels.

[0067] Step S12, establishing communication tunnels layer by layer between the relay node and each jump server, and between each jump server and the target node according to the communication protocol and port.

[0068] Optionally, a jump server (also called a jump server or bastion server) is an intermediary device used to securely access and manage other servers or devices within the network. It is usually deployed in a relatively trusted network environment, and all access to key servers must go through the jump server.

[0069] Step S13: Receive the forensic task instruction and split the forensic task according to the forensic task instruction to obtain forensic subtasks.

[0070] Step S14: Distribute the forensic subtasks to the target nodes through multiple layers of the communication tunnels.

[0071] Step S15: Receive the data packets fed back by the target nodes through multiple layers of the communication tunnels and display the forensic results.

[0072] In some possible implementation manners, detect the network environment and start the forensic software to obtain the communication protocols and ports with the relay nodes. The forensic software includes the software installed on the control node, the relay node software installed on the relay nodes, and the target node software installed on the target nodes. Connect the jump server to the control node through the Internet, and layer by layer establish communication tunnels between the relay nodes and each jump server, and between each jump server and the target node according to the communication protocols and ports. When establishing the communication tunnels, use the STUN technology to penetrate the Network Address Translation (NAT) and the firewall. NAT (Network Address Translation) is a technology widely used to save IP addresses and enhance network security, but it also brings some problems, especially in the case of need for peer-to-peer communication. The NAT penetration technology is to solve these problems so that the hosts located behind different NAT devices can communicate directly. STUN (Session Traversal Utilities for NAT) is a commonly used NAT penetration technology.

[0073] Receive the forensic task instruction and split the forensic task according to the forensic task instruction to obtain forensic subtasks. Optionally, split the forensic task into three subtasks: file location, data reading, and data transmission. Distribute the forensic subtasks to the target nodes through multiple layers of the communication tunnels. After the forensic operations are performed on the target nodes, the control node receives the data packets fed back by the target nodes through multiple layers of the communication tunnels and displays the forensic results on the operation interface.

[0074] In some other possible implementation manners, detect the network environment and start the forensic software to obtain the available basic communication protocols and ports between the NAT subnet relay nodes and the lower-layer devices. Layer by layer establish communication tunnels between the relay nodes and each jump server, and between each jump server and the target node according to the communication protocols and ports. Receive the forensic task and perform subtask and instruction splitting according to the forensic task to achieve the forensic purpose. Distribute the forensic subtasks to each distributed target node through multiple layers of the communication tunnels. Receive the data packets fed back by the target nodes through multiple layers of the communication tunnels and display the forensic results.

[0075] In the embodiments of the present application, the communication protocol and ports of the relay node are obtained, and communication tunnels are established layer by layer between the relay node and each jump server, and between each jump server and the target node. The forensics subtasks after splitting the forensics task are distributed to the target node through the multi-layer communication tunnel, and the target node receives the data packets fed back through the communication tunnel and displays them after executing the forensics subtasks. This multi-layer network forensics method can penetrate multiple network firewalls and achieve two-way communication and data transmission with multiple target nodes in different NAT subnets simultaneously. Figure 3 It shows a schematic flow chart of the multi-layer network forensics method described in the embodiments of the present application, as Figure 3 shown, the step S11 includes steps S111 to S113.

[0076] Step S111, detect the network environment and start the forensics software, and send a protocol request to the relay node.

[0077] Step S112, match the protocol request with the communication protocol of the relay node.

[0078] Step S113, if the match is successful, establish a communication connection with the relay node, if the match fails, replace the communication protocol and send a protocol request.

[0079] In some possible implementation manners, detect the network environment and start the forensics software, select any communication protocol and send a protocol request to the relay node. Common open ports include 80 / TCP, 443 / TCP, 53 / UDP. 80 / TCP is the port used by the HTTP protocol. Most websites and web services transfer data through this port. When accessing a website, port 80 is usually used to transfer web content. 443 / TCP: This is the port used by the HTTPS protocol. HTTPS is a secure version of HTTP and uses SSL / TLS encryption to protect the security of data transmission. 53 / UDP: This is the port used by DNS (Domain Name System). DNS is used to convert domain names (such as www.xxxx.com) into IP addresses. DNS requests usually use the UDP protocol because they are usually small and fast requests. Match the communication protocol corresponding to the protocol request with the communication protocol of the relay node. If the match is successful, establish a communication connection with the relay node. If the match fails, replace the communication protocol and send a protocol request.

[0080] In some other possible implementation manners, the network environment is detected and the forensics software is started, and the protocol request is sent to the relay node by selecting the 443 / TCP communication protocol and port. The TCP communication protocol and the 443 port corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. After failed matching, the protocol request is sent to the relay node by changing to the 80 / TCP communication protocol and port. Again, the TCP communication protocol and the 80 port corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. After failed matching, the protocol request is sent to the relay node by changing to the 53 / UDP communication protocol and port. Again, the UDP communication protocol and the 53 port corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. It should be noted that the above is only one way to illustrate the acquisition of the communication protocol and port in this application, and the order of sending the protocol request is not limited thereto.

[0081] In an embodiment of the present application, the multi-layer network forensics method further includes: determining whether proxy or routing address translation is required. If so, the proxy and routing address translation are initialized, and the firewall restriction is reversely broken through by using the relay node, and communication connections are established between the relay node and the target node by using each of the jump servers, and an external bastion host is established according to the communication connections. If not, the external bastion host is directly established.

[0082] In some possible implementation manners, the target node is usually located behind the multi-layer subnet and its firewall, and the firewall will strictly filter the passed protocols, which may prevent the protocols used by common forensics tools. The network address translation (NAT) makes it difficult to directly address the internal network server. Therefore, it is necessary to determine whether proxy or routing address translation is required after communication tunnels are established layer by layer between the relay node and each jump server and between each jump server and the target node according to the communication protocol and port. If so, the STUN handshake service for initializing the proxy and routing address translation is initialized, and the firewall restriction is reversely broken through by using the proxy of the relay node, and communication connections are established between the relay node and the target node by using each of the jump servers, and an external bastion host is established according to the communication connections. If not, the external bastion host is directly established. The STUN handshake is a process for establishing peer-to-peer connections in a network address translation (NAT) environment. The STUN protocol helps a device obtain its public IP address and port, so that it can penetrate the NAT and directly communicate with devices located in different networks. The STUN handshake is to enable a device to know its address in the external network, so as to achieve direct communication with other devices.

[0083] Figure 4The flowchart of the multi-layer network evidence collection method described in the embodiment of the present application is shown as follows: Figure 4 As shown, the step S12 includes steps S121 to S123.

[0084] Step S121, start the forensic software on each of the jump boards in turn, and connect each of the jump boards layer by layer according to the communication protocol and port.

[0085] Step S122, using a dynamic key exchange mechanism to generate encryption keys when each of the jump servers is connected layer by layer.

[0086] Step S123, using the encryption key and the layer-by-layer connection of each jump server, a communication tunnel is established layer by layer between the relay node and each jump server, and between each jump server and the target node.

[0087] In some possible implementations, the forensic software is started on the forensic server, and the forensic server is used as the control node of the network. The forensic software is started on each of the jump boards in turn, and each node is connected to the control node through the previous node to achieve layer-by-layer connection of each jump board. An encryption key is generated by using a dynamic key exchange mechanism when each jump board is connected layer by layer, and a unique encryption key is generated for each jump connection. Communication tunnels are established layer by layer between the relay node and each jump board, and between each jump board and the target node using the encryption key and the layer-by-layer connection of each jump board. During the establishment of the communication tunnel, the network environment of each node is automatically detected, and the communication protocol and port are selected. Optionally, a distributed node network is established based on the control node, the jump board and the target node, and multiple relay nodes with dispersed address locations are used as transit support for the communication tunnel.

[0088] Figure 5 The flowchart of the multi-layer network evidence collection method described in the embodiment of the present application is shown as follows: Figure 5 As shown, the step S14 includes steps S141 to S142.

[0089] Step S141, using a task distribution algorithm to distribute the evidence collection subtask from the relay node to each layer of the communication tunnel step by step.

[0090] Step S142, using an inter-layer load balancing algorithm to evenly distribute the tasks of the communication tunnels at each layer and transmit them to the target node.

[0091] In some possible implementation manners, a tree - shaped network topology link is established among the control node, the relay node, the jump server, and the target node. All servers in the link are used for a hierarchical forensic task allocation strategy. A top - down task distribution algorithm is used to allocate the forensic subtasks from the root node to each layer of the communication tunnels step by step. An inter - layer load - balancing algorithm is used to evenly distribute and transmit the tasks of each layer of the communication tunnels to the target node. A bottom - up result aggregation algorithm is used to ensure that data effectively flows to the root node.

[0092] In some other possible implementation manners, the forensic task is configured through the software interface of the control node, and the target is specified as the " / dev / vda" disk on the target node. The forensic task is automatically decomposed into three subtasks: a file location subtask, a data reading subtask, and a data transmission subtask. The control node uses a task distribution algorithm to allocate the forensic subtasks from the relay node to each layer of the communication tunnels step by step. After receiving the task, the target node performs file location and data reading operations. During the reading process, the target node reports the progress to the upper - level node and the control node every time it reads 1MB of data.

[0093] The target node encrypts the read data with AES - 256, and divides it into data packets with a size not exceeding 1452 bytes. Each data packet is encoded as a seemingly normal DNS query or response and sent to the relay node through port 53 / UDP. The relay node receives the data packet, decrypts, verifies, and re - encrypts it, and then disguises it as an HTTP GET request and sends it to another relay node through port 80 / TCP. The other relay node repeats a similar process, disguises the data as HTTPS traffic and sends it to the control node through port 443 / TCP.

[0094] Figure 6 Shown is a schematic flowchart of the multi - layer network forensic method described in the embodiments of the present application. As Figure 6 shown, step S15 includes steps S151 to S153.

[0095] Step S151: Use a dynamic routing algorithm to fragment the forensic data packets fed back by the target node to obtain fragmented data packets.

[0096] Step S152: When the fragmented data packets are transmitted through each layer of the jump servers, perform transmission target confirmation and data source confirmation, and incorporate the number of the jump server into the fragmented data packets.

[0097] Step S153: Receive the fragmented data packets and obtain the complete link for transmitting the data packets through multiple layers of the communication tunnels according to the numbers of the fragmented data packets.

[0098] In some possible implementation manners, after receiving all data packets, the control node decrypts, performs integrity verification, and reorganizes them, and finally restores the complete disk image of " / dev / vda". A forensic report is automatically generated, including information such as file hash values, transmission times, and network paths, and the results are presented on the software interface of the control node.

[0099] In some other possible implementation manners, the forensic data packets fed back by the target node are fragmented by using a dynamic routing algorithm, and the fragmented data packet results are retrieved through the fragmented message numbers; the target of transmission and the source of data are confirmed during the transmission of the fragmented data packets on each layer of the jump server, and the device number of the jump server is incorporated into the fragmented data packets; the fragmented data packets are received and decoded according to the content of the fragmented data packets and then forwarded to the target device or relay device of the upper layer or the lower layer of the communication tunnel.

[0100] In an embodiment of the present application, the multi-layer network forensic method further includes: determining whether it is necessary to horizontally expand the communication network, and if so, delivering and starting the forensic software to other jump servers, and if not, obtaining a forensic sub-task and performing a forensic operation.

[0101] Figure 7 Shown is a schematic flowchart of the multi-layer network forensic method described in the embodiment of the present application, as Figure 7 shown, the overall working process of the multi-layer network forensic method is as follows:

[0102] In some possible implementation manners, the network environment is detected and the forensic software is started, and a protocol request is sent to the relay node by selecting the 443 / TCP communication protocol and port. The TCP communication protocol and port 443 corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. After failure of matching, the 80 / TCP communication protocol and port are replaced to send a protocol request to the relay node. Again, the TCP communication protocol and port 80 corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. After failure of matching, the 53 / UDP communication protocol and port are replaced to send a protocol request to the relay node. Again, the UDP communication protocol and port 53 corresponding to the protocol request are matched with the communication protocol of the relay node. After successful matching, a communication connection is established with the relay node. The forensic software includes the software installed on the control node, the relay node software installed on the relay node, and the target node software installed on the target node.

[0103] Start the forensic software on each of the jump boards in turn, connect each node to the control node through the previous node, and realize the layer-by-layer connection of each of the jump boards. Generate an encryption key when each of the jump boards is connected layer by layer using a dynamic key exchange mechanism, and generate a unique encryption key for each jump connection. Use the encryption key and the layer-by-layer connection of each of the jump boards to establish communication tunnels layer by layer between the relay node and each jump board, and between each of the jump boards and the target node. During the establishment of the communication tunnel, automatically detect the network environment of each node, and select the communication protocol and port. Optionally, establish a distributed node network based on the control node, the jump board and the target node, and use multiple relay nodes with dispersed address locations as transit support for the communication tunnel.

[0104] The target node is usually located behind a multi-layer subnet and its firewall. The firewall will strictly filter the protocols that pass through it, which may block the protocols used by common forensic tools. Routing address translation NAT makes it difficult to directly address the intranet server. Therefore, it is necessary to determine whether a proxy or routing address translation is needed after establishing communication tunnels layer by layer between the relay node and each jump server, and between each jump server and the target node according to the communication protocol and port. If necessary, initialize the STUN handshake service of the proxy and routing address translation, reversely break through the firewall restrictions through the proxy of the relay node, establish a communication connection between the relay node and the target node using each jump server, and establish an external bastion host based on the communication connection. If not needed, directly establish an external bastion host.

[0105] Determine whether it is necessary to horizontally expand the communication network. If so, deliver and start the evidence collection software to other jump servers. If not, obtain the evidence collection subtask and perform the evidence collection operation.

[0106] The forensic task is configured through the software interface of the control node, and the target is specified as the " / dev / vda" disk on the target node. The forensic task is automatically decomposed into three subtasks: file location subtask, data reading subtask and data transmission subtask. The control node uses the task distribution algorithm to distribute the forensic subtasks from the relay node to the communication tunnels at each layer step by step. After receiving the task, the target node performs file location and data reading operations. During the reading process, the target node reports the progress to the superior node and the control node every time it reads 1MB of data.

[0107] The target node encrypts the read data using AES-256 and divides it into data packets with a size not exceeding 1452 bytes. Each data packet is encoded as a seemingly normal DNS query or response and sent to the relay node through port 53 / UDP. The relay node receives the data packets, decrypts, verifies, and re-encrypts them, and then disguises them as an HTTP GET request and sends them to another relay node through port 80 / TCP. The other relay node repeats a similar process and sends the data disguised as HTTPS traffic through port 443 / TCP to the control node.

[0108] After receiving all the data packets, the control node decrypts, performs integrity checks, and recombines them to finally restore the complete " / dev / vda" disk image. A forensic report is automatically generated, including information such as file hash values, transmission times, and network paths, and the results are presented on the software interface of the control node.

[0109] In the embodiments of the present application, the communication protocols and ports of the relay nodes are obtained, and communication tunnels are established layer by layer between the relay nodes and each jump server, and between each jump server and the target node based on this. The forensic subtasks obtained after splitting the forensic tasks are distributed to the target node through multiple layers of communication tunnels, and the target node receives the data packets fed back through the communication tunnels and displays them after executing the forensic subtasks. Such a multi-layer network forensics method can penetrate multiple layers of network firewalls and achieve two-way communication and data transmission with the target node.

[0110] Figure 8 Shown is a schematic structural diagram of the multi-layer network forensics system described in the embodiments of the present application, as Figure 8 shown, the multi-layer network forensics system 100 includes a protocol acquisition module 110, a tunnel establishment module 120, a task splitting module 130, a task distribution module 140, and a data acquisition module 150.

[0111] The protocol acquisition module 110 is used to detect the network environment and start the forensic software, and obtain the communication protocols and ports of the relay nodes.

[0112] The tunnel establishment module 120 is used to establish communication tunnels layer by layer between the relay nodes and each jump server, and between each jump server and the target node according to the communication protocols and ports.

[0113] The task splitting module 130 is used to receive the forensic task instructions and split the forensic tasks according to the forensic task instructions to obtain forensic subtasks.

[0114] The task distribution module 140 is used to distribute the forensic subtasks to the target node through multiple layers of the communication tunnels.

[0115] The data acquisition module 150 is configured to receive the data packets fed back by the target node through multiple layers of the communication tunnels and display the forensic results.

[0116] In some possible implementation manners, the protocol acquisition module 110 is configured to detect the network environment and start the forensic software, and acquire the communication protocol and ports of the relay nodes. The forensic software includes the software installed on the control node, the relay node software installed on the relay nodes, and the target node software installed on the target nodes. The tunnel establishment module 120 is configured to connect the jump server to the control node through the Internet, and layer by layer establish communication tunnels between the relay nodes and each jump server, and between each jump server and the target node according to the communication protocol and ports. When establishing the communication tunnels, the STUN technology is used to penetrate the network address translation (NAT) and the firewall. The task segmentation module 130 is configured to receive the forensic task instruction and segment the forensic task according to the forensic task instruction to obtain forensic subtasks. Optionally, the forensic task is segmented into three subtasks: file location, data reading, and data transmission. The task distribution module 140 is configured to distribute the forensic subtasks to the target node through multiple layers of the communication tunnels. The data acquisition module 150 is configured to, after the target node executes the forensic operation, receive the data packets fed back by the target node through multiple layers of the communication tunnels and display the forensic results on the operation interface.

[0117] In the embodiments of the present application, the protocol acquisition module 110 is configured to acquire the communication protocol and ports of the relay nodes, and the tunnel establishment module 120 thereby layer by layer establishes communication tunnels between the relay nodes and each jump server, and between each jump server and the target node. The task segmentation module 130 is configured to segment the forensic task, and the task distribution module 140 is configured to distribute the forensic subtasks to the target node through multiple layers of communication tunnels. After the target node executes the forensic subtasks, the data acquisition module 150 is configured to receive the data packets fed back through the communication tunnels and display them. Such a multi-layer network forensic system 100 can penetrate multiple layers of network firewalls, and realize two-way communication and data transmission with multiple target nodes in different NAT subnets simultaneously.

[0118] In several embodiments provided in the present application, it should be understood that the disclosed system, apparatus, or method can be implemented in other ways. For example, the apparatus embodiments described above are only illustrative. For example, the division of the modules / units is only a logical function division, and there may be other division manners in actual implementation. For example, multiple modules or units may be combined or integrated into another system, or some features may be ignored or not executed. Another point, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, and the indirect coupling or communication connection of the apparatus or module or unit may be in an electrical, mechanical, or other form.

[0119] The module / unit described as a separate component may or may not be physically separated. The components shown as modules / units may or may not be physical modules, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules / units can be selected according to actual needs to achieve the objectives of the embodiments of the present application. For example, in various embodiments of the present application, each functional module / unit can be integrated in a processing module, or each module / unit can exist physically alone, or two or more modules / units can be integrated in one module / unit.

[0120] Those of ordinary skill in the art should further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0121] Embodiments of the present application also provide an electronic device. Figure 9 The structural schematic diagram of the electronic device 900 described in the embodiments of the present application is shown. As Figure 9 shown, in this embodiment, the electronic device 900 includes a memory 910 and a processor 920.

[0122] The memory 910 is used to store computer programs; preferably, the memory 910 includes various media that can store program codes, such as ROM, RAM, magnetic disks, USB flash drives, memory cards, or optical discs.

[0123] Specifically, the memory 910 may include a computer system readable medium in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The electronic device 900 may further include other removable / non-removable, volatile / non-volatile computer system storage media. The memory 910 may include at least one program product, and this program product has a set (for example, at least one) of program modules, and these program modules are configured to execute the functions of the embodiments of the present application.

[0124] The processor 920 is connected to the memory 910 and is used to execute the computer programs stored in the memory 910, so that the electronic device 900 executes the multi-layer network forensics method described in any embodiment of the present application.

[0125] Optionally, the processor 920 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0126] Optionally, the electronic device 900 in this embodiment may further include a display 930. The display 930 is communicatively connected to the memory 910 and the processor 920, and is configured to display a relevant graphical user interface (GUI) interaction interface of the multi-layer network forensics method described in the embodiments of the present application.

[0127] The embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the multi-layer network forensics method described in any embodiment of the present application.

[0128] The descriptions of the processes or structures corresponding to the above respective drawings each have their own focuses. For parts not detailed in a certain process or structure, reference may be made to the relevant descriptions of other processes or structures.

[0129] The above embodiments are only illustrative of the principles and effects of the present application, and are not used to limit the present application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed by the present application should still be covered by the claims of the present application.

Claims

1. A multi-layer network forensics method, characterized in that, include: Detect the network environment and start the forensic software to obtain the communication protocol and port with the relay node; Establish communication tunnels layer by layer between the relay node and each jump board machine, and between each jump board machine and the target node according to the communication protocol and port; Receiving a forensic task instruction and dividing the forensic task according to the forensic task instruction to obtain forensic subtasks; Distribute the evidence collection subtask to the target node through multiple layers of the communication tunnel; the evidence collection subtask includes a file location subtask, a data reading subtask and a data transmission subtask, and use a task distribution algorithm to distribute the evidence collection subtask from the relay node to each layer of the communication tunnel step by step, and use an inter-layer load balancing algorithm to evenly distribute the tasks of each layer of the communication tunnel and transmit them to the target node; Receive data packets fed back by the target node through multiple layers of the communication tunnel and display the forensic results.

2. The multi-layer network forensics method according to claim 1, wherein, Detect the network environment and start the forensic software to obtain the communication protocol with the relay node including: Detecting the network environment and starting the forensic software, and sending a protocol request to the relay node; The protocol request is matched with the communication protocol of the relay node. If the match is successful, a communication connection is established with the relay node. If the match fails, the communication protocol is changed and a protocol request is sent.

3. The multi-layer network forensics method according to claim 1, wherein Also includes: Determine whether a proxy or routing address translation is needed. If necessary, initialize the proxy and routing address translation, use the relay node to reversely break through the firewall restrictions, use each jump server to communicate between the relay node and the target node, and establish an external bastion host based on the communication connection; if not, directly establish an external bastion host.

4. The multi-layer network forensics method according to claim 1, characterized in that Establishing communication tunnels layer by layer between the relay node and each jump board machine, and between each jump board machine and the target node according to the communication protocol and port includes: Starting the evidence collection software on each of the jump boards in turn, and connecting each of the jump boards layer by layer according to the communication protocol and port; Generate encryption keys when each of the jump servers is connected layer by layer using a dynamic key exchange mechanism; Communication tunnels are established layer by layer between the relay node and each jump board, and between each jump board and the target node by using the encryption key and the layer by layer connection of each jump board.

5. The multi-layer network forensics method according to claim 1, wherein Receiving the data packet fed back by the target node through the multiple layers of the communication tunnel comprises: Using a dynamic routing algorithm to fragment the forensic data packet fed back by the target node to obtain fragmented data packets; The fragmented data packet is transmitted by the jump board machine at each layer, and the transmission target and data source are confirmed, and the jump board machine number is included in the fragmented data packet; The fragmented data packets are received and, according to the serial numbers of the fragmented data packets, a complete link for transmitting the data packets through multiple layers of the communication tunnel is obtained.

6. The multi-layer network forensics method according to claim 1, wherein Also includes: Determine whether it is necessary to horizontally expand the communication network. If so, deliver and start the evidence collection software to other jump servers. If not, obtain the evidence collection subtask and perform the evidence collection operation.

7. A multi-layer network forensics system, characterized in that, include: The protocol acquisition module is used to detect the network environment and start the forensic software to obtain the communication protocol and port with the relay node; A tunnel establishment module, used to establish communication tunnels layer by layer between the relay node and each jump board machine, and between each jump board machine and the target node according to the communication protocol and port; A task segmentation module, used for receiving a forensic task instruction and performing forensic task segmentation according to the forensic task instruction to obtain forensic subtasks; A task distribution module is used to distribute the evidence collection subtask to the target node through multiple layers of the communication tunnel; wherein the evidence collection subtask includes a file location subtask, a data reading subtask and a data transmission subtask, and the task distribution module is used to use a task distribution algorithm to distribute the evidence collection subtask from the relay node to each layer of the communication tunnel step by step, and use an inter-layer load balancing algorithm to evenly distribute the tasks of each layer of the communication tunnel and transmit them to the target node; The data acquisition module is used to receive data packets fed back by the target node through multiple layers of the communication tunnel and display the evidence collection results.

8. An electronic device, characterized in that, The electronic device comprises: Memory for storing computer programs; A processor, wherein the processor is used to execute the computer program stored in the memory so that the electronic device executes the multi-layer network forensics method as described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, the multi-layer network forensics method described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Intranet penetration method

    CN113965338A