An encrypted traffic restoration system, method, device and storage medium

By constructing virtual servers and virtual clients and utilizing traffic decryption to obtain the plaintext traffic of encrypted traffic, the problem of needing to change the network topology in existing technologies is solved, enabling large-scale application.

CN119814303BActive Publication Date: 2025-12-19CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510021222.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-12-19
Estimated Expiration
2045-01-07

AI Technical Summary

Technical Problem

Existing methods for restoring encrypted traffic require special configurations on both the client and server sides, altering the original network topology and thus hindering large-scale application.

Method used

By constructing virtual servers and virtual clients, and utilizing the traffic decryption functions of the virtual clients and virtual servers to obtain decrypted traffic, the original network topology can be avoided.

Benefits of technology

It enables the acquisition of plaintext traffic from encrypted traffic without altering the network topology, supporting large-scale applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814303B_ABST
    Figure CN119814303B_ABST
Patent Text Reader

Abstract

The application discloses an encrypted traffic restoration system, method and device and a storage medium, relates to the technical field of network security, and comprises a data forwarding plane, a self-defined transmission control protocol stack, a virtual service layer and a virtual service layer. The data forwarding plane is used for receiving encrypted traffic and performing data analysis on the encrypted traffic. The self-defined transmission control protocol stack is used for monitoring the analyzed traffic and determining the connection relationship between a target service end and a target client. The virtual service layer is used for constructing a virtual service end and a virtual client, determining a virtual sender and a virtual receiver, and sequentially transmitting the analyzed traffic to an actual receiver through the virtual sender and the virtual receiver. The virtual service end and the virtual client are both configured with traffic decryption and encryption functions, so that the decrypted traffic obtained through the decryption function can be subjected to data security detection. The plaintext traffic is obtained through the decryption function between the virtual service end and the virtual client, thereby avoiding the problem of changing the original network structure in the encrypted traffic restoration process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an encrypted traffic restoration system, method, device, and storage medium. Background Technology

[0002] With the widespread adoption of encryption technology and increasing demands for data privacy and security, encrypted traffic has experienced explosive growth. According to the latest transparency report, 100% of the top 100 websites on the internet support HTTPS (Hypertext Transfer Protocol Secure) encryption, with 97% of them using HTTPS by default. While encryption technology protects user privacy, it also makes data security checks and network threat detection more difficult, making online fraud and illegal activities more covert and easier to evade detection of ransomware, phishing attacks, and data breaches.

[0003] Current methods for restoring encrypted traffic involve obtaining the corresponding plaintext data from the encrypted traffic via a proxy. This approach requires special configuration support on the client side, which alters the client's original network structure, hindering its large-scale application. Therefore, achieving encrypted traffic restoration without altering the client's original network structure remains a problem to be solved in this field. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide an encrypted traffic recovery system, method, device, and storage medium. This system constructs a virtual server and a virtual client, and utilizes the traffic decryption functions of the virtual client and virtual server to obtain the decrypted traffic, thus acquiring the decrypted traffic without altering the original network topology. The specific solution is as follows:

[0005] Firstly, this application provides an encrypted traffic restoration system, comprising:

[0006] The data forwarding plane is used to receive encrypted traffic transmitted by the actual sender and to parse the encrypted traffic to obtain the corresponding parsed traffic.

[0007] A custom transmission control protocol stack is used to monitor the parsed traffic and determine the connection relationship between the target server and the target client based on the monitoring results.

[0008] A virtual service layer is used to construct a virtual server and a virtual client based on the connection relationship and a transport layer security protocol. Based on the flow information of the encrypted traffic, a virtual sender and a virtual receiver are determined from the virtual server and the virtual client. The parsed traffic is then transmitted sequentially through the virtual sender and the virtual receiver to the actual receiver corresponding to the actual sender. Furthermore, both the virtual server and the virtual client are pre-configured with automatic decryption functions for the received parsed traffic and automatic encryption functions for the decrypted traffic, so as to perform data security checks on the decrypted traffic obtained through the automatic decryption function.

[0009] Optionally, the data forwarding plane includes:

[0010] The protocol identification module is used to identify the data transmission protocol corresponding to the encrypted traffic flowing through the encrypted traffic restoration system, so as to obtain the corresponding protocol identification result;

[0011] The parsing module is used to parse the encrypted traffic into data frames based on the protocol identification result, so as to obtain the corresponding parsed traffic.

[0012] Optionally, the data forwarding plane further includes:

[0013] The forwarding module is used to forward unencrypted traffic sent by the actual sender through the encrypted traffic restoration system directly to the actual receiver that has established a communication connection with the data forwarding interface in advance, when the traffic flowing through the encrypted traffic restoration system is unencrypted traffic.

[0014] Optionally, the custom transmission control protocol stack includes:

[0015] The Transmission Control Protocol (TCP) service interface is used to monitor the parsed traffic in order to determine all device ports and all Internet Protocol addresses corresponding to the encrypted traffic, and to obtain the corresponding port monitoring results and address monitoring results.

[0016] The connection relationship determination module is used to determine the connection relationship between the target server and the target client based on the port listening results and the address listening results.

[0017] Optionally, the data forwarding plane further includes:

[0018] A forwarding path determination module is used to determine the forwarding path of the parsed traffic in the encrypted traffic restoration system based on the flow direction information of the encrypted traffic;

[0019] The forwarding control module is used to control the corresponding custom transmission control protocol stack, the virtual server, and the virtual client to forward the parsed traffic based on the forwarding path.

[0020] Optionally, the encrypted traffic restoration system further includes:

[0021] A network device system platform is used to configure the system working environment for the encrypted traffic restoration system based on preset application requirements; the system working environment includes a system bootloader, an operating system, and drivers.

[0022] Secondly, this application discloses a method for restoring encrypted traffic, including:

[0023] Receive encrypted traffic transmitted by the actual sender, and parse the encrypted traffic to obtain the corresponding parsed traffic;

[0024] The parsed traffic is monitored across all ports, and the connection relationship between the target server and the target client is determined based on the monitoring results.

[0025] Based on the connection relationship, a virtual server and a virtual client based on a transport layer security protocol are constructed. The virtual sender and virtual receiver are determined from the virtual server and the virtual client according to the flow information of the encrypted traffic. The parsed traffic is then transmitted sequentially through the virtual sender and the virtual receiver to the actual receiver corresponding to the actual sender. Furthermore, both the virtual server and the virtual client are pre-configured with automatic decryption functions for the received parsed traffic and automatic encryption functions for the decrypted traffic, so as to perform data security checks on the decrypted traffic obtained through the automatic decryption function.

[0026] Thirdly, this application provides an electronic device, which includes a processor and a memory; wherein the memory is used to store a computer program, which is loaded and executed by the processor to implement the aforementioned encrypted traffic restoration method.

[0027] Fourthly, this application provides a computer-readable storage medium for storing a computer program that, when executed by a processor, implements the aforementioned encrypted traffic restoration method.

[0028] The encrypted traffic restoration system in this application includes: a data forwarding plane for receiving encrypted traffic transmitted by the actual sender and parsing the encrypted traffic to obtain the corresponding parsed traffic; a custom transmission control protocol stack for monitoring the parsed traffic and determining the connection relationship between the target server and the target client based on the monitoring results; and a virtual service layer for constructing virtual servers and virtual clients based on the connection relationship and a transport layer security protocol, determining the virtual sender and virtual receiver from the virtual server and virtual client based on the encrypted traffic flow information, and sequentially transmitting the parsed traffic to the actual receiver corresponding to the actual sender through the virtual sender and virtual receiver; furthermore, both the virtual server and virtual client are pre-configured with automatic decryption functions for the received parsed traffic and automatic encryption functions for the decrypted traffic, so as to perform data security detection on the decrypted traffic obtained through the automatic decryption function. Therefore, this application determines the connection relationship between the target client and the target server by using a custom transmission control protocol stack, constructs a virtual client and a virtual server by using the connection relationship through a virtual service layer, and obtains the decrypted traffic by using the traffic decryption function of the virtual client and the virtual server. When obtaining the decrypted traffic, the problem of needing to change the original network topology is avoided. Moreover, the process of obtaining the plaintext traffic corresponding to the encrypted traffic does not require special configuration on the server and the client, which can realize large-scale application.

[0029] This application also provides an encrypted traffic restoration method, which has the same beneficial effects as the above-mentioned encrypted traffic restoration system. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0031] Figure 1 This is a schematic diagram of an encrypted traffic restoration system disclosed in this application;

[0032] Figure 2 This is a schematic diagram of the overall structure of an encrypted traffic restoration system disclosed in this application;

[0033] Figure 3 This is a schematic diagram of data pass-through disclosed in this application;

[0034] Figure 4 This is a schematic diagram of an encrypted traffic transmission path disclosed in this application;

[0035] Figure 5 This is a flowchart of an encrypted traffic restoration method disclosed in this application;

[0036] Figure 6 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0037] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0038] Existing encrypted traffic recovery systems obtain plaintext traffic through proxies. While proxies can retrieve the plaintext traffic corresponding to encrypted traffic, they require special configurations on both the client and server sides and alter the original network topology, making large-scale applications impossible. In contrast, the encrypted traffic recovery system provided in this application can obtain decrypted traffic by constructing virtual servers and virtual clients and utilizing their traffic decryption functions, thus acquiring decrypted traffic without altering the original network topology.

[0039] See Figure 1 As shown, an embodiment of the present invention discloses an encrypted traffic restoration system, comprising:

[0040] The data forwarding plane 11 is used to receive encrypted traffic transmitted by the actual sender and to parse the encrypted traffic to obtain the corresponding parsed traffic.

[0041] In this embodiment, the data forwarding plane 11 specifically includes: a protocol identification module, used to identify the data transmission protocol corresponding to the encrypted traffic flowing through the encrypted traffic restoration system, so as to obtain the corresponding protocol identification result; and a parsing module, used to parse the encrypted traffic into data frames based on the protocol identification result, so as to obtain the parsed traffic corresponding to the encrypted traffic. The overall structure of the encrypted traffic restoration system is as follows: Figure 2 As shown, it can be understood that the data transmission protocol of encrypted traffic flowing through the encrypted traffic recovery system can be of several types, and the data forwarding plane can achieve full protocol visibility from the link layer to the application layer, such as... Figure 3As shown, in one specific implementation, the protocol identification module in the data forwarding plane 11 performs a layer-by-layer full protocol analysis from the link layer to the application layer, identifying encrypted traffic of ICMP (Internet Control Message Protocol), TCP (Transmission Control Protocol), and UDP (User Datagram Protocol). The parsing module then parses the encrypted traffic according to the identification results to obtain the corresponding parsed traffic. After obtaining the parsed traffic, the data forwarding plane 11 also uploads and pushes the parsed traffic into the custom transmission control protocol stack 12, and receives data sent by the custom transmission control protocol stack 12 to achieve data forwarding. It should be noted that the data forwarding plane 11 also includes a forwarding module, which, when the traffic sent by the actual sender flowing through the encrypted traffic restoration system is unencrypted traffic, directly forwards the unencrypted traffic to the actual receiver that has established a communication connection with the data forwarding interface through the local data forwarding interface. That is, if the received traffic is unencrypted traffic, there is no need to upload the unencrypted traffic to the custom transmission control protocol stack 12; the data forwarding plane 11 can be used to directly forward the unencrypted traffic to the actual receiver. It should also be noted that the aforementioned data forwarding plane 11 is used to control the transmission path of traffic in the encrypted traffic restoration system. The aforementioned data forwarding plane 11 also includes: a forwarding path determination module, used to determine the forwarding path of the parsed traffic in the encrypted traffic restoration system based on the flow information of the encrypted traffic; and a forwarding control module, used to control the corresponding custom transmission control protocol stack 12, virtual server, and virtual client to forward the parsed traffic based on the forwarding path. It is understood that before using the data forwarding plane 11 to parse the encrypted traffic, the encrypted traffic restoration system must first be connected in series to the communication link between the actual sender and the actual receiver. By parsing encrypted traffic, the encrypted traffic can be forwarded according to the corresponding parsing results, and the reliability of the data forwarding process is improved by using the data forwarding plane 11 to control the forwarding of traffic.

[0042] A custom control transmission protocol stack 12 is used to monitor the parsed traffic and determine the connection relationship between the target server and the target client based on the corresponding monitoring results.

[0043] In this embodiment, the custom transmission control protocol stack 12 includes: a transmission control protocol service interface, used to monitor the parsed traffic to determine all device ports and all Internet Protocol addresses corresponding to the encrypted traffic, and obtain the corresponding port monitoring results and address monitoring results; and a connection relationship determination module, used to determine the connection relationship between the target server and the target client based on the port monitoring results and address monitoring results. The biggest difference between the custom transmission control protocol stack 12 and the traditional TCP protocol stack is the TCP service interface, which supports full IP and full port monitoring. The connection relationship determination module in the custom transmission control protocol stack 12 can determine the connection relationship between the target server and the target client based on the monitoring results including the source IP address, destination IP address, source port, and destination port. By monitoring the parsed traffic with all IP addresses and all ports, the actual sender and actual receiver corresponding to the parsed traffic can be determined from several actual senders and several actual receivers, i.e., the target server and the target client; and the connection relationship between the target client and the target server is determined based on the monitoring results, ensuring the reliability of the virtual sender and virtual receiver constructed by the virtual service layer 13 using this connection relationship.

[0044] The virtual service layer 13 is used to construct a virtual server and a virtual client based on the connection relationship and a transport layer security protocol. It determines the virtual sender and virtual receiver from the virtual server and the virtual client according to the flow information of the encrypted traffic, and transmits the parsed traffic to the actual receiver corresponding to the actual sender through the virtual sender and the virtual receiver in sequence. Furthermore, both the virtual server and the virtual client are pre-configured with automatic decryption functions for the received parsed traffic and automatic encryption functions for the decrypted traffic, so as to perform data security detection on the decrypted traffic obtained through the automatic decryption function.

[0045] In this embodiment, it can be understood that the traffic flowing through the encrypted traffic restoration system can be sent from the target client to the target server, or from the target server to the target client. In practical applications, it is necessary to determine the actual sender and receiver of the traffic from the target client and the target server based on the traffic flow information. In one specific implementation, such as Figure 4As shown, if the actual sender is the target server, the specific forwarding process of encrypted traffic in the encrypted traffic restoration system is as follows: Data forwarding plane 11 receives the encrypted traffic from the target server and uploads the encrypted traffic to the custom transmission control protocol stack 12. Custom transmission control protocol stack 12 uploads the encrypted traffic to the virtual server. The virtual server uses the automatic decryption function to decrypt the encrypted traffic and outputs the obtained plaintext traffic. At the same time, it sends the plaintext traffic to the virtual client. After receiving the plaintext traffic, the virtual client uses the automatic encryption function to encrypt the plaintext traffic again and sends the encrypted traffic down to the custom transmission control protocol stack 12. Custom transmission control protocol stack 12 sends the encrypted traffic down to data forwarding plane 11 and forwards the encrypted traffic to the actual receiver through the data forwarding plane.

[0046] It should be noted that the aforementioned encrypted traffic restoration system also includes a network device system platform, used to configure the system operating environment for the encrypted traffic restoration system based on preset application requirements; the aforementioned system operating environment includes a system bootloader, operating system, and drivers. Specifically, the aforementioned system operating environment includes a system bootloader, OS (Operating System), drivers, FS (File System), libraries, and related network tools. Through virtual service layer 13, a virtual server and virtual client based on TLS (Transport Layer Security) are constructed based on the connection relationship between the target server and the target client. The traffic decryption function in the virtual server and virtual client can obtain and output the plaintext traffic corresponding to the encrypted traffic, so as to perform data security detection on the obtained decrypted traffic. Through data communication between the virtual server and virtual client, the encrypted traffic stream sent by the actual sender can be forwarded to the actual receiver after passing through the encrypted traffic restoration system without changing the network attributes of the traffic data. From the user's perspective, the network attributes of the data entering and leaving the device do not change, but the system actually completes a forward proxy of a session and obtains the session plaintext data information.

[0047] Therefore, this embodiment can forward encrypted traffic based on the parsing results by parsing the encrypted traffic, and improve the reliability of the data forwarding process by controlling the traffic forwarding using the data forwarding plane 11. Through data communication between the virtual server and the virtual client, the encrypted traffic sent by the actual sender can be forwarded to the actual receiver after passing through the encrypted traffic restoration system without any change in the network attributes of the traffic data. The traffic decryption function in the virtual server and the virtual client can obtain and output the plaintext traffic corresponding to the encrypted traffic, so as to perform data security detection on the decrypted traffic obtained.

[0048] As can be seen from the previous embodiment, this application can obtain decrypted traffic by constructing a virtual server and a virtual client, and by utilizing the traffic decryption function of the virtual client and the virtual server, without changing the original network topology. Next, this embodiment will describe the corresponding encrypted traffic restoration method. See [link to documentation]. Figure 5 As shown in the embodiments of this application, an encrypted traffic restoration method is also disclosed, including:

[0049] Step S11: Receive the encrypted traffic transmitted by the actual sender, and parse the encrypted traffic to obtain the corresponding parsed traffic.

[0050] Step S12: Perform full port monitoring on the parsed traffic and determine the connection relationship between the target server and the target client based on the monitoring results.

[0051] Step S13: Based on the connection relationship, construct a virtual server and a virtual client based on the transport layer security protocol. Determine the virtual sender and virtual receiver from the virtual server and the virtual client according to the flow information of the encrypted traffic. Then, transmit the parsed traffic to the actual receiver corresponding to the actual sender through the virtual sender and the virtual receiver in sequence. Furthermore, both the virtual server and the virtual client are pre-configured with automatic decryption function for the received parsed traffic and automatic encryption function for the decrypted traffic, so as to perform data security detection on the decrypted traffic obtained through the automatic decryption function.

[0052] The encrypted traffic restoration method disclosed in this embodiment has the same technical effect as the corresponding content disclosed in the previous embodiments, and will not be described again here.

[0053] This embodiment first receives encrypted traffic and parses it. Then, it monitors the parsed traffic to determine the connection between the target server and the target client. Finally, it constructs a virtual server and a virtual client, identifies a virtual sender and a virtual receiver, and transmits the parsed traffic sequentially to the actual receiver through these virtual senders and receivers. The automatic decryption function of the virtual sender and receiver is used to obtain the plaintext traffic corresponding to the encrypted traffic. Therefore, this application uses a custom transmission control protocol stack to determine the connection between the target client and the target server, constructs a virtual client and a virtual server through the virtual service layer, and uses the traffic decryption function of the virtual client and virtual server to obtain the decrypted traffic. This avoids the need to change the original network topology when obtaining the decrypted traffic, and the process of obtaining the corresponding plaintext traffic does not require special configuration on the server and client sides, enabling large-scale application.

[0054] Furthermore, embodiments of this application also disclose an electronic device, Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0055] Figure 6 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the encrypted traffic restoration method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0056] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0057] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0058] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the encrypted traffic restoration method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0059] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned encrypted traffic restoration method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.

[0060] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0061] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0062] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0063] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0064] The technical solutions provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. An encrypted traffic restoration system, characterized by, Comprise: Data forwarding plane for receiving encrypted traffic transmitted by actual sender and performing data analysis on the encrypted traffic to obtain corresponding analyzed traffic; Custom transport control protocol stack for monitoring the analyzed traffic and determining connection relationship between target server and target client according to corresponding monitoring result; Virtual service layer for constructing virtual server and virtual client based on transport layer security protocol based on the connection relationship, determining virtual sender and virtual receiver from the virtual server and the virtual client according to flow direction information of the encrypted traffic, and transmitting the analyzed traffic to actual receiver corresponding to the actual sender through the virtual sender and the virtual receiver in turn; and the virtual server and the virtual client are both preconfigured with automatic decryption function for received analyzed traffic and automatic encryption function for decrypted traffic, so as to perform data security detection on the decrypted traffic obtained through the automatic decryption function.

2. The encrypted traffic recovery system of claim 1, wherein, The data forwarding plane comprises: Protocol identification module for identifying data transmission protocol corresponding to encrypted traffic flowing through the encrypted traffic restoration system to obtain corresponding protocol identification result; Analysis module for performing data frame analysis on the encrypted traffic based on the protocol identification result to obtain corresponding analyzed traffic of the encrypted traffic.

3. The encrypted traffic restoration system of claim 1, wherein, The data forwarding plane further comprises: Forwarding module for forwarding non-encrypted traffic transmitted by the actual sender and flowing through the encrypted traffic restoration system to the actual receiver pre-established communication connection with the data forwarding interface through the local data forwarding interface.

4. The encrypted traffic restoration system of claim 1, wherein, The custom transport control protocol stack comprises: Transport control protocol service interface for monitoring the analyzed traffic to determine all device ports and all internet protocol addresses corresponding to the encrypted traffic, to obtain corresponding port monitoring result and address monitoring result; Connection relationship determination module for determining connection relationship between target server and target client based on the port monitoring result and the address monitoring result.

5. The encrypted traffic restoration system of claim 1, wherein, The data forwarding plane further comprises: Forwarding path determination module for determining forwarding path of the analyzed traffic in the encrypted traffic restoration system based on the flow direction information of the encrypted traffic; Forwarding control module for controlling corresponding custom transport control protocol stack, virtual server and virtual client to forward the analyzed traffic based on the forwarding path.

6. The encrypted traffic restoration system of claim 1, wherein, Further comprising: Network device system platform for configuring system working environment for the encrypted traffic restoration system based on preset application requirement; The system working environment comprises system boot program, operating system and driver.

7. A method of encrypted traffic restoration, the method comprising: Comprise: Receiving encrypted traffic transmitted by actual sender and performing data analysis on the encrypted traffic to obtain corresponding analyzed traffic; Monitoring the analyzed traffic and determining connection relationship between target server and target client according to corresponding monitoring result; construct a virtual service end and a virtual client based on a transport layer security protocol based on the connection relationship, and determine a virtual sender and a virtual receiver from the virtual service end and the virtual client according to flow direction information of the encrypted traffic, and in turn transmit the parsed traffic to an actual receiver corresponding to the actual sender through the virtual sender and the virtual receiver; and the virtual service end and the virtual client are both pre-configured with an automatic decryption function for the received parsed traffic and an automatic encryption function for the decrypted traffic, so as to perform data security detection on the decrypted traffic obtained through the automatic decryption function.

8. The encrypted traffic recovery method of claim 7, wherein, Before the encrypted traffic transmitted by the actual sender is received and the encrypted traffic is parsed to obtain corresponding parsed traffic, the method further includes: The encrypted traffic restoration system is connected in series to a communication link between the actual sender and the actual receiver.

9. An electronic device, comprising: The electronic device includes a processor and a memory; wherein the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the encrypted traffic restoration method of claim 7 or 8.

10. A computer-readable storage medium, characterized in that, A computer program is stored, and the computer program is executed by a processor to implement the encrypted traffic restoration method of claim 7 or 8.

Citation Information

Patent Citations

  • Virtual private network service implementation method and device

    CN116248358A

  • Session processing method, system and device, equipment and storage medium

    CN117749865A