Encrypted packet detection method and related device

By transmitting the original data and handle information of encrypted data packets between user mode and kernel mode and integrating them using the proxy center, the problem that traditional traffic sniffing technology cannot obtain the original content of encrypted data packets is solved, and the network security detection capability is improved.

CN119652653BActive Publication Date: 2025-10-10CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411982301.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-10-10
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Traditional traffic sniffing technology cannot obtain the original content of encrypted data packets, resulting in the failure of TLS-based network security monitoring and increasing system risks.

Method used

The original data packet and handle information of the encrypted data packet to be detected are transmitted between the user state and the kernel state, integrated through the proxy center, and connection tracking is initiated using the security proxy policy information to obtain the five-tuple information and restore it to the decrypted data packet.

Benefits of technology

It effectively solves the problem that traditional traffic sniffing technology cannot observe the original content of communications, improves the security detection capability of the communication system, reduces performance consumption, and improves network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652653B_ABST
    Figure CN119652653B_ABST
Patent Text Reader

Abstract

The present disclosure provides a kind of encrypted data packet detection method and related equipment, it is related to network security technical field.The method comprises: user state runs first data acquisition program, obtains the original data packet and handle information of the encrypted data packet to be detected;Send handle information and original data packet to proxy center;According to the security proxy strategy information, initiate the preset security communication protocol connection tracking, kernel state carries out connection tracking, runs second data acquisition program, obtains the quintuple information of the encrypted data packet to be detected according to handle information, and sends to proxy center, and the quintuple information is integrated with original data packet according to handle information in proxy center, obtains decrypted data packet, is restored to four layer decrypted data packet in low performance consumption, for security analysis, effectively improve communication system safety detection, improve network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to an encrypted data packet detection method, an encrypted data packet detection device, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] With the widespread use of Transport Layer Security (TLS) in network environments, network traffic security detection has become increasingly difficult.

[0003] In related technologies, security monitoring is performed through traditional traffic sniffing technology. However, traditional traffic sniffing technology can only obtain encrypted data and cannot reveal the original content of the communication. This network security monitoring method cannot be applied to TSL-based network security monitoring. Encrypted traffic leads to increasing system risks, which has become a major challenge for enterprises.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute prior art known to ordinary technicians in the field. Summary of the Invention

[0005] The present disclosure provides an encrypted data packet detection method and related equipment, which at least to a certain extent overcomes the problem that the traffic sniffing technology in the related art cannot be applied to TSL-based network security monitoring and has low security.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by practice of the present disclosure.

[0007] According to one aspect of the present disclosure, there is provided an encrypted data packet detection method, which is applied to the user state, and the method includes: running a first data acquisition program to obtain the original data packet and handle information of the encrypted data packet to be detected, the original data packet is the data packet before encryption or after decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection; sending the handle information and the original data packet to the proxy center; initiating the preset secure communication protocol connection tracking according to the security proxy policy information so that the kernel state performs connection tracking, running a second data acquisition program, obtaining the five-tuple information of the encrypted data packet to be detected according to the handle information, and sending the five-tuple information of the encrypted data packet to be detected to the proxy center, the proxy center integrating the five-tuple information with the original data packet according to the handle information to obtain the decrypted data packet corresponding to the encrypted data packet to be detected.

[0008] In one embodiment of the present disclosure, the first data acquisition program supports multiple user-state libraries, and the user-state libraries include at least one of the free software library GnuTLS, the network security service NSS, and the open secure socket layer protocol OpenSSL.

[0009] In one embodiment of the present disclosure, the method further includes: when the user state library is OpenSSL, the first data acquisition program is set in the Secure Sockets Layer Write Application Programming Interface and the Secure Sockets Layer Read Application Programming Interface of the OpenSSL; when the user state library is GnuTLS, the first data acquisition program is set in the Record Sending Application Programming Interface and the Record Receiving Application Programming Interface of the GnuTLS; when the user state library is NSS, the first data acquisition program is set in the Write Application Programming Interface, Send Application Programming Interface, Read Application Programming Interface and Receive Application Programming Interface of the NSS.

[0010] According to another aspect of the present disclosure, a method for detecting encrypted data packets is provided, which is applied to a proxy center, and the method includes: receiving handle information and an original data packet of an encrypted data packet to be detected sent by a user state, the handle information and the original data packet are obtained by running a first data acquisition program in the user state, and the original data packet is a data packet before or after encryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is transmitted between the user state and the kernel state in a connection based on a preset secure communication protocol; receiving five-tuple information of the encrypted data packet to be detected sent by the kernel state, the five-tuple information is connection tracking for the kernel state, and a second data acquisition program is run to obtain the connection tracking according to the handle information of the encrypted data packet to be detected, and the connection tracking is initiated by the user state according to the security proxy policy information; integrating the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

[0011] According to another aspect of the present disclosure, an encrypted data packet detection device is provided, which is applied to the user state, and the device includes: a data acquisition module, which is used to run a first data acquisition program to obtain the original data packet and handle information of the encrypted data packet to be detected, the original data packet is the data packet before encryption or after decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection; a data sending module, which is used to send the handle information and the original data packet to the proxy center; a tracking initiation module, which is used to initiate the preset secure communication protocol connection tracking according to the security proxy policy information, so that the kernel state performs connection tracking, runs a second data acquisition program, obtains the five-tuple information of the encrypted data packet to be detected according to the handle information, and sends the five-tuple information of the encrypted data packet to be detected to the proxy center, the proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain the decrypted data packet corresponding to the encrypted data packet to be detected.

[0012] According to another aspect of the present disclosure, an encrypted data packet detection device is provided, which is applied to an agent center, and the device includes: a data receiving module, which is used to receive handle information and original data packets of the encrypted data packet to be detected sent by the user state, the handle information and the original data packet are obtained by running a first data acquisition program in the user state, and the original data packet is a data packet before or after encryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection; an information receiving module, which is used to receive five-tuple information of the encrypted data packet to be detected sent by the kernel state, the five-tuple information is obtained by running a second data acquisition program for connection tracking in the kernel state according to the handle information of the encrypted data packet to be detected, and the connection tracking is initiated by the user state according to the security agent policy information; a data integration module, which is used to integrate the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

[0013] According to another aspect of the present disclosure, an encrypted data packet detection system is provided, including a user state, a kernel state and a proxy center, wherein: the user state is used to run a first data acquisition program to obtain the original data packet and handle information of the encrypted data packet to be detected, the original data packet is the data packet before encryption or after decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; the preset secure communication protocol connection tracking is initiated according to the security proxy policy information; the kernel state is used to run a second data acquisition program for connection tracking, obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and send the five-tuple information of the encrypted data packet to be detected to the proxy center; the proxy center is used to integrate the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

[0014] According to another aspect of the present disclosure, an electronic device is provided, comprising: a processor and a memory, wherein the memory is used to store executable instructions of the processor; wherein the processor is configured to perform the above-mentioned encrypted data packet detection method by executing the executable instructions.

[0015] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the encrypted data packet detection method described above is implemented.

[0016] According to another aspect of the present disclosure, a computer program product is provided, which includes a computer program or computer instructions, and the computer program or the computer instructions are loaded and executed by a processor to enable a computer to implement the above-mentioned encrypted data packet detection method.

[0017] In an embodiment of the present disclosure, a first data acquisition program is run in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected, where the original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The encrypted data packet to be detected is transmitted between the user mode and the kernel mode based on a preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; a preset secure communication protocol connection tracking is initiated according to the security proxy policy information so that the kernel mode performs connection tracking, and a second data acquisition program is run to obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and the five-tuple information of the encrypted data packet to be detected is sent to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected. By improving the existing host security management center and the proxy center for security analysis, it is achieved that the encrypted data packet on the cloud is restored to a four-layer decrypted data packet under low performance consumption, effectively solving the difficulty that traditional traffic sniffing technology cannot truly observe the original content of the communication, which brings to system security monitoring and analysis, effectively improving the security detection of the communication system and improving network security.

[0018] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification, are used to explain the principles of the present disclosure. Obviously, the drawings described below are only some embodiments of the present disclosure, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0020] Figure 1 A schematic diagram showing an exemplary architecture of an encrypted data packet detection method according to an embodiment of the present disclosure.

[0021] Figure 2 A flow chart of an encrypted data packet detection method in an embodiment of the present disclosure is shown.

[0022] Figure 3 A flow chart of another method for detecting encrypted data packets in an embodiment of the present disclosure is shown.

[0023] Figure 4 A schematic structural diagram of an encrypted data packet detection system in an embodiment of the present disclosure is shown.

[0024] Figure 5 A schematic diagram of an encrypted data packet detection principle in an embodiment of the present disclosure is shown.

[0025] Figure 6An interactive diagram illustrating an encrypted data packet detection method in an embodiment of the present disclosure is shown.

[0026] Figure 7 A schematic structural diagram of an encrypted data packet detection device in an embodiment of the present disclosure is shown.

[0027] Figure 8 A schematic structural diagram of another encrypted data packet detection device in an embodiment of the present disclosure is shown.

[0028] Figure 9 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0029] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0030] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0031] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:

[0032] Secure Sockets Layer (SSL) is a protocol that provides secure communications on the Internet. It is used to provide data encryption, identity authentication, and message integrity protection above the network layer and below the application layer to ensure the security and privacy of data during transmission.

[0033] Transport Layer Security (TLS) is a protocol used to provide security in network communications. It is the successor to SSL. Its main users are to protect data transmission between clients and servers to prevent data from being eavesdropped or tampered with.

[0034] The free software library, GNU Transport Layer Security Library, referred to as GnuTLS, is used to implement secure network communications in applications, mainly providing support for TLS or SSL and other related encryption protocols.

[0035] Network Security Services, or NSS, is an open-source security library primarily used for developing secure Internet communication applications. It provides a wide range of security features, including SSL or TLS protocol support, certificate management, key and password management, random number generation, and digital signature verification. It is widely used in browsers, email clients, and other applications that require secure communication.

[0036] Open Secure Sockets Layer (OpenSSL) is an open secure sockets layer protocol package. Applications can use OpenSSL for secure communication to avoid eavesdropping and confirm the identity of the other end of the connection. It is widely used on web servers on the Internet.

[0037] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0038] Figure 1 A schematic diagram showing an exemplary system architecture that can be applied to the encrypted data packet detection method according to an embodiment of the present disclosure.

[0039] like Figure 1 As shown, the system architecture 100 may include a terminal device 110 , a network 120 and a server 130 .

[0040] The network 120 is a medium for providing a communication link between the terminal device 110 and the server 130 , and may be a wired network or a wireless network.

[0041] A user may use the terminal device 110 to interact with the server 130 via the network 120 to receive or send messages.

[0042] The terminal device 110 can be any electronic device with a display function, including but not limited to a smart phone, a tablet computer, a display screen, and a desktop computer.

[0043] The client of the application that can be installed on the terminal device 110 is the same, or the client of the same type of application based on different operating systems. Based on the different terminal platforms, the specific form of the client of the application can also be different, for example, the application client can be a mobile phone client, a PC client, etc.

[0044] Exemplarily, the terminal device 110 is installed with various communication client applications, which can perform data transmission with the kernel state through the data transmission module via the communication client application, run a first data acquisition program, obtain the original data packet and handle information of the encrypted data packet to be detected, and upload them to the server 130. The terminal device 110 can also initiate connection tracking based on the security proxy policy information, so that the kernel state performs connection tracking, and obtain the five-tuple information of the encrypted data packet to be detected based on the handle information, and send the five-tuple information to the server 130.

[0045] Server 130 can be a server that provides various services, such as a background management server that supports the devices operated by users using terminal device 110, such as a security management center. The background management server establishes an agent center, which can analyze and process received request data (such as the handle information of the encrypted data packet to be tested, the original data packet, and the five-tuple information, etc.), obtain processing results (such as the decrypted data packet corresponding to the encrypted data packet to be tested, etc.), and send the decrypted data packet to the security management center for analysis and processing.

[0046] Optionally, server 130 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0047] Those skilled in the art will know that Figure 1 The number of terminal devices, networks, and servers in the embodiment is merely illustrative, and any number of terminal devices, networks, and servers may be provided based on actual needs. This embodiment of the present disclosure does not limit this.

[0048] With the widespread use of TLS in modern network environments, network traffic security detection has become increasingly difficult.

[0049] Traditional network security monitoring relies on traffic sniffing technology. A sniffer is a software device that monitors network data flow and analyzes protocol data. It can be used for both legitimate network management and to steal network information. However, traffic sniffing technology can only capture encrypted data and cannot truly observe the original data during the communication process. This technology is ineffective for TSL-based network traffic security detection. The increasing system risks caused by encrypted traffic have become a serious challenge for enterprises.

[0050] Therefore, there is an urgent need to design a detection method that can target encrypted data packets in order to build a benign and healthy network ecological environment.

[0051] Based on this, the present disclosure provides an encrypted data packet detection method, which runs a first data acquisition program in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected. The original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on the transmission between the user mode and the kernel mode in the preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; the preset secure communication protocol connection tracking is initiated according to the security proxy policy information so that the kernel mode performs connection tracking, and a second data acquisition program is run to obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and the five-tuple information of the encrypted data packet to be detected is sent to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected for security analysis. By improving the existing host security management center and the proxy center, the encrypted data packet on the cloud can be restored to a four-layer decrypted data packet with low performance consumption, effectively solving the problem that traditional traffic sniffing technology cannot truly observe the original content of the communication, which brings difficulties to system security monitoring and analysis, effectively improving the security detection of the communication system and improving network security.

[0052] This exemplary implementation is described in detail below with reference to the accompanying drawings and examples.

[0053] First, embodiments of the present disclosure provide a method for detecting encrypted data packets. This method can be performed by any electronic device with computing processing capabilities. In some embodiments, the method can be performed in user mode, and the encrypted data detection device can be configured in a terminal device; in some embodiments, the method can be performed by a proxy center, and the encrypted data packet detection device can be configured in a server.

[0054] Figure 2 FIG. 1 shows a flow chart of a method for detecting encrypted data packets according to an embodiment of the present disclosure. Figure 2 As shown, in one embodiment, the encrypted data packet detection method provided in the embodiment of the present disclosure is applied in user mode and includes the following steps:

[0055] S202. Run the first data acquisition program to obtain the original data packet and handle information of the encrypted data packet to be detected. The original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection.

[0056] The first data acquisition program can be a network packet capture tool, a proxy tool, a library using a programming language, etc. Network packet capture tools can include Wireshark, tcpdump, Fiddler, etc. Wireshark can be used for network analysis and can capture SSL / TLS packets on specific ports by configuring filters; tcpdump is a lightweight command-line tool suitable for Unix / Linux systems that captures SSL traffic by specifying ports; Fiddler can capture network packets, including SSL packets, and provide filtering functions. The proxy tool can be Burp Suite, which is a versatile network security testing tool that can intercept HTTPS requests and responses by configuring a proxy and perform man-in-the-middle attacks on SSL certificates, thereby capturing SSL packets. Libraries using programming languages ​​can be Python's Scapy, pcap, and tshark libraries, which can be used to capture and analyze network packets and SSL packets by writing code.

[0057] The above-mentioned preset secure communication protocol can be SSL or TLS.

[0058] The encrypted data packet to be detected is an encrypted data packet sent by the application. Before sending the original data packet, the application encrypts the original data packet to obtain the encrypted data packet to be detected.

[0059] The encrypted data packet to be detected may also be an encrypted data packet received by the application. After receiving the encrypted data packet to be detected, the application may decrypt the encrypted data packet to be detected to obtain a decrypted data packet, also called an original data packet.

[0060] The handle information of the encrypted data packet to be inspected is a pointer to a system resource, used to manage system resources such as files, processes, threads, and communication ports. The handle provides a secure way to access or operate system resources. It hides the specific implementation details of the resource, freeing users from worrying about the resource's physical location or status, and helps the operating system manage resource access rights and synchronization.

[0061] Handles can include file handles, process handles, thread handles, window handles, event handles, mutex handles, semaphore handles, and timer handles. File handles are used to access files or devices; process handles are used to control another process; thread handles are used to control or monitor a process; window handles are used to operate windows and controls; event handles are used to synchronize threads or processes; mutex handles are used to synchronize access to shared resources; semaphore handles are used to control the number of accesses to a resource; and timer handles are used to create and control timers. For example, in the Windows operating system, a handle is a 32-bit value represented by the HANDLE type, which is a pointer to a kernel object.

[0062] The handle information is an identifier used to access resources in the system. It does not directly contain the address of the resource, but points to a kernel object managed by the operating system.

[0063] In one embodiment, the first data acquisition program supports multiple user-state libraries, including at least one of the free software library GnuTLS, the network security service NSS, and the open secure socket layer protocol OpenSSL.

[0064] GnuTLS is an open-source library for secure communications. It implements the SSL, TLS, and DTLS protocols, providing encryption, authentication, and data integrity features. It can be used in various network applications to ensure secure communications. For encryption, GnuTLS supports a variety of encryption algorithms and key exchange mechanisms, such as AES and Camellia, ensuring data security during transmission. For authentication, it supports multiple certificate formats, helping to verify the identities of both communicating parties and preventing man-in-the-middle attacks. For data integrity, it provides data integrity checks to ensure that transmitted data has not been tampered with.

[0065] NSS supports and protects secure network communications, providing a set of application programming interfaces (APIs) to implement security features. NSS can detect and prevent network attacks, protect network systems from them, manage network security, provide security reports, monitor network security in real time, and respond to network attacks in real time. It also provides security auditing, security management, and security policy enforcement, and can store keys, certificates, and other security information.

[0066] OpenSSL provides a variety of cryptographic algorithms and security features to protect data communications and information storage. It supports both symmetric and asymmetric encryption algorithms for data encryption and decryption. It can also generate, sign, and verify digital certificates, and supports the SSL / TLS protocol to ensure the security and privacy of data transmission. OpenSSL can perform encryption and decryption, digital certificate management, cryptographic tools, and SSL / TLS protocol implementation.

[0067] In one embodiment, the first data acquisition program may be provided at an application programming interface (API) for data interaction in a user-state library.

[0068] In one embodiment, the encrypted traffic packet detection method provided by the embodiment of the present disclosure also includes: when the user state library is OpenSSL, the first data acquisition program is set in the secure socket layer write application programming interface SSL_Write API and the secure socket layer read application programming interface SSL_Read API of OpenSSL; when the user state library is GnuTLS, the first data acquisition program is set in the record sending application programming interface GnuTLS_Record_Send API and the record receiving application programming interface GnuTLS_Record_Recv API; when the user state library is NSS, the first data acquisition program is set in the write application programming interface PR_Write API, the send application programming interface PR_Send API, the read application programming interface PR_Read API and the receive application programming interface PR_Recv API of NSS.

[0069] In OpenSSL's SSL_Write API and SSL_Read API, the handle information of the encrypted data packet to be detected is obtained through the first data acquisition program. When reading and writing data in the SSL_Write API and SSL_Read API connection, the first data acquisition program will copy the original data packet before or after encryption, and send the original data packet to the data cache program of the proxy center for caching.

[0070] SSL_Write is used to write encrypted data streams, and SSL_Read is used to read encrypted data streams.

[0071] In one embodiment, if it is GnuTLS, a first data acquisition program and a second data acquisition program are added at the GnuTLS_Record_Send API and the GnuTLS_Record_Recv API; if it is NSS, a first data acquisition program and a second data acquisition program are added at the PR_Write API, PR_Send API, PR_Read API, and PR_Recv API.

[0072] S204: Send the handle information and the original data packet to the proxy center.

[0073] The proxy center can implement functions such as request forwarding and response processing, data caching and acceleration, enhanced network security, breaking access restrictions, and optimized network structure. The proxy center can serve as a bridge between the client and the security management center. The proxy center can receive handle information and original data packets sent by the user state and cache the handle information and original data packets in the data cache program to track the encrypted data packets to be detected.

[0074] S206. Initiate connection tracking of the preset secure communication protocol according to the security proxy policy information, so that the kernel state performs connection tracking, run the second data acquisition program, obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and send the five-tuple information of the encrypted data packet to be detected to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

[0075] Security proxy policy information includes, but is not limited to, packet filtering, access control, logging and auditing, intrusion detection and prevention, virus and malware protection, authentication and authorization, encryption and key management, threat intelligence integration, and other policies. For packet filtering, the proxy center uses packet filtering technology to inspect packets entering and leaving the network, and allows or denies the transmission of packets based on preset security policies. The inspection content includes checking the source address, destination address, port number, etc. to prevent unauthorized access; for access control, the proxy center implements strict access control policies to ensure that only authorized users and devices can access network resources, including user identity verification, device newcomer scoring, and user and device binding relationship management; for logging and auditing, the proxy center records all network activities, including user logins, access records, etc., to facilitate subsequent auditing and monitoring; for intrusion detection and prevention, the proxy center monitors network traffic, identifies abnormal behavior, and takes timely measures to prevent potential attacks. It should be noted that the present disclosure does not specifically limit the content of security proxy policy information.

[0076] It should be noted that the implementation method of the second data acquisition program is the same as that of the first data acquisition program, and will not be repeated here.

[0077] In one embodiment, an SSL / TLS connection is formed between the user state and kernel state of the kernel space through the kernel state and user state data transmission module.

[0078] Perform SSL / TLS connection tracking in kernel mode, run a second data acquisition program, obtain five-tuple information of the encrypted data packet to be detected according to the handle information, and send the five-tuple of the encrypted data packet to be detected to the proxy center.

[0079] The five-tuple information of the encrypted data packet to be detected can identify a network communication. The five-tuple information includes the source IP, source port number, destination IP, destination port number and protocol number. The source IP identifies the source host, the source port number identifies the process in the source host that sends the encrypted data packet to be detected in this communication, the destination IP identifies the destination host, the destination port number identifies the process in the destination host that receives the data packet to be detected in this communication, and the protocol number identifies the data format agreed upon by both the sending process and the receiving process.

[0080] After receiving the handle information, original data packet and five-tuple information of the encrypted data packet to be detected, the proxy center combines the original data packet and five-tuple information with the same handle information to obtain the four-layer decrypted data packet corresponding to the encrypted data packet to be detected, and sends the four-layer decrypted data packet to the security management center for subsequent analysis and processing to obtain the detection results.

[0081] In one embodiment, the proxy center can filter the original data packet and quintuple information according to the handle information to obtain the original data packet and quintuple information with the same handle information, and integrate the original data packet and quintuple information to restore the data packet.

[0082] It should be noted that the present disclosure does not specifically limit the detection method of the four-layer decrypted data packet.

[0083] In an embodiment of the present disclosure, a first data acquisition program is run in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected. The original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The encrypted data packet to be detected is transmitted between the user mode and the kernel mode based on a preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; the preset secure communication protocol connection tracking is initiated according to the security proxy policy information so that the kernel mode performs connection tracking, and a second data acquisition program is run to obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and the five-tuple information of the encrypted data packet to be detected is sent to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected. By improving the existing host security management center and the proxy center, the encrypted data packet on the cloud can be restored to a four-layer decrypted data packet for security analysis under low performance consumption, effectively solving the difficulty that traditional traffic sniffing technology cannot truly observe the original content of the communication, which brings to system security monitoring and analysis, effectively improving the security detection of the communication system and improving network security.

[0084] Figure 3 FIG. 1 shows another flow chart of an encrypted data packet detection method according to an embodiment of the present disclosure. Figure 3 As shown, in one embodiment, the encrypted data packet detection method of the embodiment of the present disclosure is applied to a proxy center, and the method includes the following steps:

[0085] S302. Receive the handle information and original data packet of the encrypted data packet to be detected sent by the user state. The handle information and the original data packet are obtained by running the first data acquisition program in the user state. The original data packet is the data packet before encryption or after decryption obtained when the application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection.

[0086] In one embodiment, after receiving the handle information of the encrypted data packet to be detected and the original data packet, the proxy center may cache the data in a data cache program.

[0087] S304. Receive the five-tuple information of the encrypted data packet to be detected sent by the kernel state. The five-tuple information is used for connection tracking in the kernel state. The second data acquisition program is run to obtain the information based on the handle information of the encrypted data packet to be detected. The connection tracking is initiated by the user state according to the security proxy policy information.

[0088] In one embodiment, after the proxy center receives the five-tuple information of the encrypted data packet to be detected sent by the kernel state, it can cache it in the data cache program.

[0089] S306, integrating the quintuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the to-be-detected encrypted data packet.

[0090] In one embodiment, the data caching program combines the original data packet with the quintuple information again to restore the to-be-detected encrypted data packet into a four-layer decrypted data packet.

[0091] In the embodiment of the present disclosure, the proxy center receives handle information and an original data packet of a to-be-detected encrypted data packet sent by a user state, the handle information and the original data packet are obtained by running a first data acquisition program in the user state, the original data packet is a data packet before encryption or after decryption obtained when an application program encrypts or decrypts data, and connection tracking of the to-be-detected encrypted data packet is based on transmission between the user state and a kernel state in a preset secure communication protocol connection; the proxy center receives quintuple information of the to-be-detected encrypted data packet sent by the kernel state, the quintuple information is obtained by running a second data acquisition program in the kernel state according to handle information of the to-be-detected encrypted data packet, and the connection tracking is initiated by the user state according to security proxy policy information; the proxy center integrates the quintuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the to-be-detected encrypted data packet, which is used for security analysis, and by improving an existing host security management center and a proxy center, the encrypted data packet on the cloud is restored into a four-layer decrypted data packet under low performance consumption, the difficulty brought by the fact that traditional flow sniffing technology cannot truly observe the original content of communication for system security monitoring and analysis is effectively solved, and the security detection of the communication system is effectively improved.

[0092] Figure 4 A structure schematic diagram of an encrypted data packet detection system in the embodiment of the present disclosure is shown. As shown in Figure 4 In one embodiment, the encrypted data packet detection system in the embodiment of the present disclosure includes a user state 410, a kernel state 420, a proxy center 430, and a security management center 440, wherein:

[0093] The user state 410 is configured to run a first data acquisition program to obtain original data packet and handle information of a to-be-detected encrypted data packet, the original data packet is a data packet before encryption or after decryption obtained when an application program encrypts or decrypts data, and connection tracking of the to-be-detected encrypted data packet is based on transmission between the user state 410 and the kernel state 420 in a preset secure communication protocol connection; the user state 410 is further configured to send the handle information and the original data packet to the proxy center 430; and the user state 410 is further configured to initiate connection tracking of the preset secure communication protocol according to security proxy policy information.

[0094] The kernel state 420 is configured to run a second data acquisition program to perform connection tracking, obtain quintuple information of the to-be-detected encrypted data packet according to the handle information, and send the quintuple information of the to-be-detected encrypted data packet to the proxy center 430.

[0095] The proxy center 430 is used to integrate the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected;

[0096] The security management center 440 is used to process the decrypted data packets to obtain detection results.

[0097] like Figure 5 As shown, the security management center 440 provides unified management, builds an agent center (Agent Center) 430 corresponding to the security management center 440, and improves the agent center 430 so that the agent center 430 has the ability to utilize the host operating system eBPF. The agent center 430 has data caching, SOCKET analysis, and data packet repackaging functions.

[0098] A first data acquisition program is inserted into the user state 410 of the operating system kernel space, and a second data acquisition program is inserted into the kernel state 420. The first data acquisition program and the second data acquisition program can support eBPF tracing technology across multiple user state SSL / TLS libraries, and support multiple user state libraries such as OpenSSL, GnuTLS, and NSS. In the SSL_Write API and SSL_Read API of OpenSSL, the handle information of the encrypted data packet to be detected is obtained through the first data acquisition program. When reading and writing data in the SSL_WriteAPI and SSL_Read API connection, the first data acquisition program will copy the original data packet before or after encryption, and send the original data packet to the data cache program of the proxy center 430 for caching.

[0099] The user state 410 initiates connection tracking according to the security proxy policy information. The kernel state 420 performs connection tracking, runs the second data acquisition program, obtains the five-tuple information of the encrypted data packet to be detected according to the handle information, and sends the five-tuple information to the proxy center 430.

[0100] The proxy center 430 combines the original data packet and the five-tuple information corresponding to the same handle information, thereby restoring the encrypted data packet to be detected into a four-layer decrypted data packet, and sends the four-layer decrypted data packet to the security management center 440, so that the security management center 440 performs security detection on the four-layer decrypted data packet to obtain the detection results.

[0101] In one embodiment, if it is GnuTLS, a first data acquisition program and a second data acquisition program are added at the GnuTLS_Record_Send API and the GnuTLS_Record_Recv API; if it is NSS, a first data acquisition program and a second data acquisition program are added at the PR_Write API, PR_Send API, PR_Read API, and PR_Recv API.

[0102] It should be noted that the principle of solving the problem in this system embodiment is similar to that in the above method embodiment, so the implementation of this system embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0103] In an embodiment of the present disclosure, a first data acquisition program is run in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected. The original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on the transmission between the user mode and the kernel mode in the preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; the preset secure communication protocol connection tracking is initiated according to the security proxy policy information; the kernel state is used to run a second data acquisition program for connection tracking, obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and send the five-tuple information of the encrypted data packet to be detected to the proxy center; the proxy center is used to integrate the five-tuple information with the original data packet according to the handle information to obtain the decrypted data packet corresponding to the encrypted data packet to be detected. By improving the existing host security management center and the proxy center, the encrypted data packet on the cloud can be restored to a four-layer decrypted data packet for security analysis under low performance consumption, effectively solving the difficulty that traditional traffic sniffing technology cannot truly observe the original content of the communication, which brings to system security monitoring and analysis, effectively improving the security detection of the communication system and improving network security.

[0104] In the present disclosure, by adding a first data acquisition program in the user state of the operating system kernel space, the first data acquisition program can support eBPF tracing technology across multiple user-state SSL / TLS libraries, such as OpenSSL, GnuTLS, NSS and other user-state libraries; by adding a second data acquisition program in the kernel state of the kernel space, the handle information of the encrypted data packet to be detected is obtained through the second acquisition program, and connection tracking is initiated according to the security proxy policy information. The five-tuple information of the encrypted data packet to be detected is obtained in the kernel space using the handle information, and the original data packet before / after encryption and the five-tuple information are combined twice in the proxy center to obtain a decrypted data packet corresponding to the encrypted data packet to be detected, so that the security management center can perform security analysis on the decrypted data packet to obtain the detection result, thereby realizing security monitoring of encrypted traffic on the cloud with low performance consumption, and can restore the encrypted traffic to four-layer decrypted data packets one by one with high accuracy.

[0105] In order to deepen the understanding of the technical solution of the present disclosure, Figure 6 A specific example is given to illustrate.

[0106] Figure 6 An interactive diagram of an encrypted data packet detection method according to an embodiment of the present disclosure is shown. Figure 6 As shown, the encrypted data packet detection method provided by the example of the present disclosure includes the following steps:

[0107] S601 , the user state 410 and the kernel state 420 read and write data from the TLS / SSL connection through SSL_Write / Read.

[0108] S602 , when the application encrypts and decrypts data, the user state 410 runs a first data acquisition program, copies the original data packet before or after encryption, obtains the handle information of the encrypted data packet to be detected, and sends it to the proxy center 430 .

[0109] S630: The proxy center 430 caches the original data packet and handle information of the encrypted data packet to be detected.

[0110] S640: The user state 410 initiates connection tracking according to the security proxy policy information.

[0111] S605: Kernel state 420 performs connection tracking.

[0112] S606 , the kernel state 420 obtains the five-tuple information of the encrypted data packet to be detected according to the handle information, and sends the five-tuple information to the proxy center 430 .

[0113] S607: The proxy center 430 caches the five-tuple information of the encrypted data packet to be detected.

[0114] S608, the agent center 430 carries out data integration, restores the data packet, obtains the four-layer decryption data packet, and sends to the security management center 440.

[0115] S609, the security management center 440 analyzes and processes the four-layer decryption data packet, and obtains the detection result.

[0116] It should be noted that the above examples take OpenSSL (SSL_Write / Read) as an example for illustration. If it is GnuTLS, it is GnuTLS_Record_Send and GnuTLS_Record_Recv; if it is NSS, it is PR_Write, PR_Send, PR_Read and PR_Recv.

[0117] Based on the same inventive concept, the encryption data packet detection device is also provided in the embodiments of the present disclosure, as follows. Since the principle of solving the problem of the device embodiment is similar to the above-mentioned method embodiment, the implementation of the device embodiment can be referred to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.

[0118] Figure 7 A structure diagram of an encryption data packet detection device in the embodiments of the present disclosure is shown, as shown in the encryption data packet detection device, applied to the user state, comprising a data acquisition module 710, a data sending module 720 and a tracking initiation module 730. Wherein: Figure 7

[0119] The data acquisition module 710 is used to run the first data acquisition program, acquire the original data packet and handle information of the to-be-detected encrypted data packet, the original data packet is the data packet before encryption or after decryption obtained when the application program is encrypted and decrypted, and the to-be-detected encrypted data packet connection tracking is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection;

[0120] The data sending module 720 is used to send the handle information and the original data packet to the agent center;

[0121] The tracking initiation module 730 is used to initiate the preset secure communication protocol connection tracking according to the security agent policy information, so that the kernel state performs connection tracking, runs the second data acquisition program, acquires the five-tuple information of the to-be-detected encrypted data packet according to the handle information, and sends the five-tuple information of the to-be-detected encrypted data packet to the agent center. The agent center integrates the five-tuple information and the original data packet according to the handle information, and obtains the decrypted data packet corresponding to the to-be-detected encrypted data packet.

[0122] ​In one embodiment, the first data acquisition program supports multiple user-state libraries, and the user-state libraries include at least one of the free software library GnuTLS, the network security service NSS, and the open secure socket layer protocol OpenSSL.

[0123] In one embodiment, when the user-state library is OpenSSL, the first data acquisition program is set at the Secure Sockets Layer write API and the Secure Sockets Layer read API of OpenSSL; when the user-state library is GnuTLS, the first data acquisition program is set at the record sending API and the record receiving API of GnuTLS; when the user-state library is NSS, the first data acquisition program is set at the write API, send API, read API and receive API of NSS.

[0124] In an embodiment of the present disclosure, a first data acquisition program is run in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected. The original data packet is the data packet before or after encryption obtained when the application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on the transmission between the user mode and the kernel mode in the preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; the preset secure communication protocol connection tracking is initiated according to the security proxy policy information so that the kernel mode performs connection tracking, and a second data acquisition program is run to obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and the five-tuple information of the encrypted data packet to be detected is sent to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected. By improving the existing host security management center and the proxy center, the encrypted data packet on the cloud can be restored to a four-layer decrypted data packet for security analysis under low performance consumption, effectively solving the difficulty that traditional traffic sniffing technology cannot truly observe the original content of the communication, which brings to system security monitoring and analysis, effectively improving the security detection of the communication system and improving network security.

[0125] Figure 8 A schematic diagram of the structure of an encrypted data packet detection device according to an embodiment of the present disclosure is shown. Figure 8 As shown, the encrypted data packet detection device is applied to the agent center and includes a data receiving module 810, an information receiving module 820 and a data integration module 830.

[0126] The data receiving module 810 is configured to receive handle information and original data packets of the to-be-detected encrypted data packets sent by the user mode, the handle information and the original data packets being obtained by running a first data obtaining program in the user mode, the original data packets being data packets before encryption or after decryption obtained when an application program encrypts or decrypts data, and the to-be-detected encrypted data packet connection tracking being based on transmission between the user mode and the kernel mode in a preset secure communication protocol connection.

[0127] The information receiving module 820 is configured to receive quintuple information of the to-be-detected encrypted data packets sent by the kernel mode, the quintuple information being obtained by running a second data obtaining program in the kernel mode according to the handle information of the to-be-detected encrypted data packets, and the connection tracking being initiated by the user mode according to security proxy strategy information.

[0128] The data integrating module 830 is configured to integrate the quintuple information and the original data packets according to the handle information, to obtain decrypted data packets corresponding to the to-be-detected encrypted data packets.

[0129] In the embodiment of the present disclosure, the proxy center receives handle information and original data packets of to-be-detected encrypted data packets sent by the user mode, the handle information and the original data packets being obtained by running a first data obtaining program in the user mode, the original data packets being data packets before encryption or after decryption obtained when an application program encrypts or decrypts data, and the to-be-detected encrypted data packet connection tracking being based on transmission between the user mode and the kernel mode in a preset secure communication protocol connection; receives quintuple information of the to-be-detected encrypted data packets sent by the kernel mode, the quintuple information being obtained by running a second data obtaining program in the kernel mode according to the handle information of the to-be-detected encrypted data packets, and the connection tracking being initiated by the user mode according to security proxy strategy information; and integrates the quintuple information and the original data packets according to the handle information, to obtain decrypted data packets corresponding to the to-be-detected encrypted data packets. By improving the existing host security management center and the proxy center, the encrypted data packets on the cloud are restored to four-layer decrypted data packets for security analysis under low performance consumption, effectively solving the difficulty that traditional flow sniffing technology cannot truly observe the original content of communication, effectively improving the communication system security detection, and improving the network security.

[0130] Those skilled in the art can understand that each aspect of the present disclosure can be implemented as a system, a method or a program product. Therefore, each aspect of the present disclosure can be specifically implemented as a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" here.

[0131] The electronic device 900 according to this embodiment of the present disclosure will be described below with reference to Figure 9 .Figure 9 The electronic device 900 shown is merely an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0132] like Figure 9 As shown, electronic device 900 is implemented as a general-purpose computing device. Components of electronic device 900 may include, but are not limited to, at least one processing unit 910, at least one storage unit 920, and a bus 930 connecting various system components (including storage unit 920 and processing unit 910).

[0133] The storage unit stores program codes, which can be executed by the processing unit 910, so that the processing unit 910 performs the steps described in the "Exemplary Method" section above according to various exemplary embodiments of the present disclosure. For example, the processing unit 910 can perform the following steps: Figure 2 The method embodiment in the embodiment comprises the following steps: running a first data acquisition program in user mode to obtain the original data packet and handle information of the encrypted data packet to be detected, the original data packet being the data packet before encryption or after decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on the transmission between the user mode and the kernel mode in the preset secure communication protocol connection; sending the handle information and the original data packet to the proxy center; initiating the preset secure communication protocol connection tracking according to the secure proxy policy information so that the kernel mode performs connection tracking, running a second data acquisition program, obtaining the five-tuple information of the encrypted data packet to be detected according to the handle information, and sending the five-tuple information of the encrypted data packet to be detected to the proxy center, the proxy center integrating the five-tuple information with the original data packet according to the handle information to obtain the decrypted data packet corresponding to the encrypted data packet to be detected.

[0134] For example, the processing unit 910 may also execute the following steps: Figure 3 The method embodiment in the embodiment comprises the following steps: an agent center, the method comprising: receiving handle information and an original data packet of an encrypted data packet to be detected sent from a user state, the handle information and the original data packet being obtained by running a first data acquisition program in the user state, the original data packet being a data packet before or after encryption obtained when the application encrypts and decrypts data, the connection tracking of the encrypted data packet to be detected being transmitted between the user state and the kernel state in a connection based on a preset secure communication protocol; receiving five-tuple information of an encrypted data packet to be detected sent from the kernel state, the five-tuple information being connection tracking for the kernel state, running a second data acquisition program, and obtaining it according to the handle information of the encrypted data packet to be detected, the connection tracking being initiated by the user state according to the security proxy policy information; integrating the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

[0135] The storage unit 920 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 9201 and / or a cache memory unit 9202 , and may further include a read-only memory unit (ROM) 9203 .

[0136] The storage unit 920 may also include a program / utility 9204 having a set (at least one) of program modules 9205, such program modules 9205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0137] Bus 930 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0138] The electronic device 900 may also communicate with one or more external devices 940 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), one or more devices that enable a user to interact with the electronic device 900, and / or any device that enables the electronic device 900 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed through an input / output (I / O) interface 950. Furthermore, the electronic device 900 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 960. Figure 9 As shown, the network adapter 960 communicates with other modules of the electronic device 900 via the bus 930. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 900, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0139] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0140] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is further provided, which may be a readable signal medium or a readable storage medium. In an exemplary embodiment of the present disclosure, a computer program product is further provided, which includes a computer program or computer instructions, which are loaded and executed by a processor to cause a computer to implement the steps of the method disclosed in the above embodiment.

[0141] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fibers, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0142] In the present disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0143] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0144] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and the like, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0145] It should be noted that although several modules or units of the device for action execution are mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units to be concretized.

[0146] Furthermore, although the steps of the method of the present disclosure are described in a particular order in the accompanying drawings, this does not require or imply that the steps must be performed in this particular order, or that all steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps.

[0147] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0148] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the appended claims.

Claims

1. A method for detecting encrypted data packets, applied in user mode, characterized in that: The method comprises: Running a first data acquisition program to acquire original data packets and handle information of the encrypted data packets to be detected, wherein the original data packets are data packets before or after encryption or decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packets to be detected is based on transmission between the user state and the kernel state in a connection using a preset secure communication protocol; Sending the handle information and the original data packet to an agent center; The preset secure communication protocol connection tracking is initiated according to the secure proxy policy information to enable the kernel state to perform connection tracking, and a second data acquisition program is run to obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and the five-tuple information of the encrypted data packet to be detected is sent to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

2. The method for detecting encrypted data packets according to claim 1, wherein: The first data acquisition program supports multiple user state libraries, and the user state libraries include at least one of the free software library GnuTLS, the network security service NSS, and the open secure socket layer protocol OpenSSL.

3. The method for detecting encrypted data packets according to claim 2, wherein: The method further comprises: When the user state library is OpenSSL, the first data acquisition program is set in the secure socket layer write application programming interface and the secure socket layer read application programming interface of the OpenSSL; When the user state library is GnuTLS, the first data acquisition program is set in the record sending application programming interface and the record receiving application programming interface of the GnuTLS; When the user state library is NSS, the first data acquisition program is set in the write application programming interface, the send application programming interface, the read application programming interface and the receive application programming interface of the NSS.

4. A method for detecting encrypted data packets, applied to an agent center, characterized in that: The method comprises: Receiving handle information and an original data packet of an encrypted data packet to be detected sent by a user state, wherein the handle information and the original data packet are obtained by running a first data acquisition program in the user state, and the original data packet is a data packet before encryption or after decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packet to be detected is based on transmission between the user state and the kernel state in a preset secure communication protocol connection; receiving five-tuple information of the encrypted data packet to be detected sent by the kernel state, the five-tuple information being used for connection tracking by the kernel state, and running a second data acquisition program to acquire the information based on the handle information of the encrypted data packet to be detected, wherein the connection tracking is initiated by the user state according to the security proxy policy information; The five-tuple information is integrated with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

5. An encrypted data packet detection device, applied to user mode, characterized in that: The device comprises: a data acquisition module, configured to run a first data acquisition program to acquire original data packets and handle information of encrypted data packets to be detected, wherein the original data packets are data packets before or after encryption or decryption obtained when the application encrypts and decrypts data, and the connection tracking of the encrypted data packets to be detected is based on transmission between the user state and the kernel state in a connection using a preset secure communication protocol; A data sending module, configured to send the handle information and the original data packet to an agent center; A tracking initiation module is used to initiate the preset secure communication protocol connection tracking according to the security proxy policy information, so that the kernel state performs connection tracking, runs a second data acquisition program, obtains the five-tuple information of the encrypted data packet to be detected according to the handle information, and sends the five-tuple information of the encrypted data packet to be detected to the proxy center. The proxy center integrates the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

6. An encrypted data packet detection device, applied to an agent center, comprising: a data receiving module, configured to receive handle information and an original data packet of an encrypted data packet to be detected, sent from a user state, wherein the handle information and the original data packet are obtained by executing a first data acquisition program in the user state, and the original data packet is a data packet before encryption or after decryption obtained when an application encrypts and decrypts data. The connection tracking of the encrypted data packet to be detected is based on transmission between the user state and the kernel state in a connection using a preset secure communication protocol; an information receiving module, configured to receive quintuple information of the encrypted data packet to be detected sent by the kernel state, the quintuple information being used for connection tracking by the kernel state, and running a second data acquisition program to obtain the information based on the handle information of the encrypted data packet to be detected, wherein the connection tracking is initiated by the user state according to the security proxy policy information; A data integration module is used to integrate the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

7. An encrypted data packet detection system, characterized in that: It includes user state, kernel state and agent center, among which: The user state is used to run a first data acquisition program to obtain the original data packet and handle information of the encrypted data packet to be detected, wherein the original data packet is a data packet before encryption or after decryption obtained when the application encrypts and decrypts data; the connection tracking of the encrypted data packet to be detected is based on the transmission between the user state and the kernel state in the preset secure communication protocol connection; the handle information and the original data packet are sent to the proxy center; and the preset secure communication protocol connection tracking is initiated according to the secure proxy policy information; The kernel state is used to run a second data acquisition program to perform connection tracking, obtain the five-tuple information of the encrypted data packet to be detected according to the handle information, and send the five-tuple information of the encrypted data packet to be detected to the proxy center; The proxy center is used to integrate the five-tuple information with the original data packet according to the handle information to obtain a decrypted data packet corresponding to the encrypted data packet to be detected.

8. An electronic device, characterized in that: include: A processor and a memory, wherein the memory is used to store executable instructions of the processor; The processor is configured to execute the encrypted data packet detection method according to any one of claims 1 to 3, or the encrypted data packet detection method according to claim 4, by executing the executable instructions.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the encrypted data packet detection method according to any one of claims 1 to 3, or implements the encrypted data packet detection method according to claim 4.

10. A computer program product having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the encrypted data packet detection method according to any one of claims 1 to 3 is implemented, or the encrypted data packet detection method according to claim 4 is implemented.

Citation Information

Patent Citations

  • Network security detection system and network security detection method thereof

    CN113783880A

  • Data processing method and device, electronic equipment and storage medium

    CN117560197A