A system and method for bypass traffic decryption and analysis
The traffic decryption and analysis system performed through bypass solves the monitoring problem in a fully encrypted network environment, realizes full decryption analysis of terminal traffic, reduces deployment costs and false alarm rates, has security evidence collection capabilities, and covers a wide range.
Patent Information
- Application Number
- CN202510042516.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-01-10
AI Technical Summary
In the face of a fully encrypted network environment, existing technologies and traditional network security monitoring technologies are ineffective, with problems such as high reconstruction costs, low terminal decryption rates, high missed reports and false alarm rates, and a lack of security evidence collection and result analysis capabilities.
The traffic decryption and analysis system using bypass includes a network analysis subsystem, a terminal analysis subsystem, and a management and scheduling subsystem. It realizes the decryption and analysis of encrypted traffic through key information extraction, traffic decryption and analysis modules, combined with heartbeat connection and elastic matching mechanism.
It realizes full decryption analysis of terminal traffic, reduces deployment costs, does not require the modification of existing network architecture, has a wide coverage, a high decryption rate, reduces missed alarms and false alarms, and has the ability to collect security evidence and analyze results.
Smart Images

Figure CN119814463B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data communications, and in particular relates to a system and method for bypass traffic decryption and analysis. Background Art
[0002] With the deepening of informatization, the proportion of network traffic encryption is gradually increasing. Except for a few basic protocols or special intranet environments, the application layer is almost fully encrypted. This change is due in part to the maturity of encrypted communication technologies, mainly the TLS protocol, and in part to the further requirements of industry standards and cybersecurity laws and regulations. In this context, traditional network security monitoring technologies based on network traffic analysis are gradually becoming ineffective, making traffic encryption technology a double-edged sword. Although it makes direct end-to-end communication more secure, from the perspective of security monitoring and security management, security risks are actually increasing. For example, network attacks and malicious program communications based on encrypted network traffic become difficult to detect.
[0003] To solve the above problems, the following three technical solutions have gradually emerged in the industry:
[0004] Solution 1: Transfer network traffic encryption and decryption technology to a set of encryption and decryption gateway devices. The network traffic analysis and detection are carried out after decryption by this device. Although this solution achieves a balance between communication security and traffic monitoring to a certain extent, it has the following problems:
[0005] 1. Deploying a separate encryption and decryption gateway system requires restructuring the business system architecture, which is costly. This is especially difficult for legacy or small systems, as it can be difficult to deploy or restructure this architecture.
[0006] 2. This encryption and decryption technology is only used for the server side of network communication. It cannot decrypt traffic for other terminals.
[0007] Solution 2: For servers that require key traffic analysis and monitoring, import the TLS or SSL certificate and private key of their business systems into the traffic analysis and detection system to decrypt and analyze the traffic. This solution does not require adjustments to the business system architecture and is cost-controllable, but it also has serious problems, mainly manifested as follows:
[0008] 1. This technical solution is only effective for a small number of insecure traffic encryption algorithms (for example, RSA-related encryption suites in TLS). The decryption rate is very low in the current network environment. Moreover, as various security regulations are further implemented, relevant traffic encryption algorithms will be completely eliminated, making this technical solution completely ineffective.
[0009] 2. This technical solution is also for the server side of network communication. It cannot decrypt traffic for other terminals.
[0010] Solution 3: Instead of decrypting traffic, use AI technology to analyze and detect encrypted traffic. Although this solution has some effectiveness in a few security analysis scenarios, it also has obvious problems:
[0011] 1. The missed alarm rate and false alarm rate of traffic detection are both very high, making the actual application effect of this technical solution often very unsatisfactory;
[0012] 2. It lacks the support capabilities for security evidence collection and result analysis, and is unable to analyze, confirm, and handle traffic analysis and test results. Summary of the Invention
[0013] In order to solve the problems raised in the above background technology, the present invention provides a system and method for bypass traffic decryption and analysis to solve the problems in the existing technology such as high reconstruction cost, terminal limitations, low decryption rate, high missed alarm rate and false alarm rate, and lack of secure evidence collection and result analysis.
[0014] To achieve the above object, the present invention provides the following technical solutions:
[0015] A system for bypass traffic decryption and analysis, comprising:
[0016] At least one network analysis subsystem; the network analysis subsystem includes a traffic caching module, a traffic decryption module, a traffic analysis module, and a collaborative connection module, and the network analysis subsystem is used for traffic decryption and traffic analysis after decryption;
[0017] At least one terminal analysis subsystem; the terminal analysis subsystem is disposed in the terminal and connected to the network analysis subsystem. The terminal analysis subsystem includes a key information extraction module, a process flow monitoring module, a data push module, and a collaborative connection module. The terminal analysis subsystem is used to monitor the encrypted communication process and extract key negotiation information during the communication process, and send the key negotiation information to the network analysis subsystem;
[0018] Management and scheduling subsystem; the management and scheduling subsystem includes a connection management module, an association analysis module and an information transfer module. The management and scheduling subsystem is used for coverage relationship analysis of the network analysis subsystem and the terminal analysis subsystem.
[0019] A method for bypass traffic decryption and analysis, comprising the following steps:
[0020] S1: All terminal analysis subsystems and network analysis subsystems establish initial registration connections with the management and scheduling subsystem. The management and scheduling subsystem records the network addresses of each terminal analysis subsystem and network analysis subsystem and assigns a unique identification code to each terminal analysis subsystem and network analysis subsystem.
[0021] S2: All terminal analysis subsystems establish a heartbeat connection with the management and scheduling subsystem. The data content of the heartbeat connection includes a heartbeat flag, an asymmetric encryption ciphertext based on the terminal analysis subsystem identification code encrypted with a public key, and a checksum value of the signature information of the asymmetric encryption ciphertext based on the heartbeat flag and the terminal analysis subsystem identification code. Each network analysis subsystem identifies and analyzes the entire traffic flow, identifies the heartbeat communication corresponding to itself in the entire traffic flow based on the asymmetric encryption algorithm calculated with a private key and the checksum signature algorithm, and sends the traffic summary information of the heartbeat communication to the management and scheduling subsystem. At the same time, the source IP of the corresponding heartbeat communication is marked as the target traffic IP, where the traffic summary information includes the identification code, time, communication five-tuple information of the corresponding network analysis subsystem, and the terminal analysis subsystem identification code;
[0022] S3: The management and scheduling system analyzes the traffic summary information provided by each network analysis subsystem and identifies the corresponding relationship between the terminal analysis subsystem and the network analysis subsystem, that is, whether the traffic of the terminal where the terminal analysis subsystem is located can be monitored by the network analysis subsystem;
[0023] S4: The terminal analysis subsystem extracts the time information, five-tuple information, communication front packet sequence number combination hash, communication front packet identification code combination hash, and key negotiation information of the terminal's encrypted communication by hooking the encrypted communication interface function, and sends it to the management and scheduling subsystem;
[0024] S5: The network analysis subsystem stores the entire encrypted traffic corresponding to the target traffic IP address marked in S2 and constructs a fast retrieval index through the time information, five-tuple information, the combined hash of the communication front packet sequence number, and the combined hash of the communication front packet identification code;
[0025] S6: The management and scheduling subsystem forwards the information sent back by the terminal analysis subsystem to the corresponding network analysis subsystem based on the information received from the terminal analysis subsystem and the corresponding relationship between the terminal analysis subsystem and the network analysis subsystem analyzed in S3;
[0026] S7: After receiving the encrypted communication-related information from the management and scheduling subsystem, the network analysis subsystem performs an index elastic match on the stored traffic. If the corresponding communication session traffic is found, the process proceeds to S8. If not, the network analysis subsystem is deemed to have failed to save the corresponding traffic, and the decryption process ends.
[0027] S8: The network analysis subsystem decrypts the corresponding traffic content by combining the encryption negotiation process information in the communication session traffic and the key negotiation information sent by the terminal analysis subsystem;
[0028] S9: Reconstruct the plaintext data based on the decrypted traffic content and simulate the plaintext communication data packets;
[0029] S10: The network analysis subsystem analyzes and detects the decrypted and reconstructed traffic.
[0030] Preferably, the elastic matching process in S7 is specifically as follows:
[0031] S7.1: Extract the time information of the communication-related information received from the terminal analysis subsystem within a specific range and lock the time accuracy to a preset minute-level range of the precise time;
[0032] S7.2: Based on the time range generated in S7.1, the traffic index query is performed in combination with the combined hash of the communication front-end packet sequence number and the communication front-end packet identification code returned by the terminal. If multiple communication records are found, the process proceeds to S7.3; otherwise, the process proceeds to S8.
[0033] S7.3: Match the five-tuple information in the queried communication result with the five-tuple information returned by the terminal. The matching process is as follows: first try to match the entire five-tuple. If it hits, enter S8. Otherwise, exclude the source IP address of the five-tuple and match again. If it hits, enter S8. Otherwise, exclude the destination IP and destination port of the five-tuple and match again. If it hits, enter S8. Otherwise, match only from the source port of the five-tuple. If it hits, enter S8. Otherwise, it is considered a miss and the current decryption process ends.
[0034] Preferably, S8 is specifically as follows: first, the final key is calculated based on the key negotiation process of the encrypted traffic. If the terminal analysis subsystem provides a pre-master key, the calculation process is to first calculate the master key through the pre-master key, and then calculate the final key through the master key. If the terminal analysis subsystem provides a master key, the final key is calculated directly. After obtaining the final key, the content of the encrypted traffic is decrypted based on the final key.
[0035] Preferably, in S10, the traffic analysis and detection operations include traffic protocol parsing, traffic correlation, traffic reassembly, load feature analysis, communication behavior analysis, and file restoration analysis operations.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] 1. For terminal traffic deployed with the terminal analysis subsystem, full decryption analysis can be achieved, which is effective not only for the server but also for the client;
[0038] 2. No modification is required to the existing network architecture, the deployment cost is very low, and it has better application value;
[0039] 3. It is not limited to TLS RSA-related algorithms or TLS protocols. It is effective for traffic that uses a similar TLS negotiation encryption process (for example, SSH protocol traffic), and its technical coverage is very wide.
[0040] 4. It realizes the full reuse of traditional traffic analysis and detection technologies, giving full play to the relevant value of existing technology accumulation, and eliminates the need to implement analysis and detection technology after decryption of encrypted traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 This is a flowchart of the application;
[0042] Figure 2 This is a diagram of the data structure of the heartbeat connection content. DETAILED DESCRIPTION
[0043] To facilitate those skilled in the art to understand the technical content of the present invention, the present invention is further described in detail below with reference to the accompanying drawings and specific examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not intended to limit the present invention.
[0044] Some of the terms involved in this application are now explained:
[0045] TLS protocol: Transport Layer Security protocol, is an encrypted communication protocol that works at the transport layer and has become the standard communication encryption protocol for various business scenarios.
[0046] Data packet: A data format used in computer networks. It is the basic unit of data transmission. In computer network communications, a data packet typically consists of multiple parts, including a frame header, data, and a frame tail.
[0047] TCP sequence number: A field in a TCP (Transmission Control Protocol) segment that identifies the order of data in the segment.
[0048] TCP acknowledgment number: An important field in a TCP (Transmission Control Protocol) segment used to confirm that the receiver has successfully received the data.
[0049] Packet identification code: The packet identification code in the IP protocol header, which is used to uniquely identify the relevant terminal within a specific time range;
[0050] A packet checksum is a verification mechanism used during data transmission to ensure data integrity and accuracy. It applies a specific algorithm to the data in a packet to generate a checksum or checksum, which is appended to the end of the packet or at a specific location. Upon receiving the packet, the receiver uses the same algorithm to calculate the data and compares the result with the checksum provided by the sender to verify whether any errors occurred during transmission.
[0051] Pre-master secret: Intermediate information in the SSL / TLS protocol key negotiation process, which is an important intermediate value information for calculating the master key and the final communication key.
[0052] Master key: intermediate information in the SSL / TLS protocol key negotiation process, calculated from the pre-master key, and is an important intermediate value information for calculating the final communication key;
[0053] Hooking technology: a technology that intervenes and replaces the underlying function call, through which the parameter information of the underlying function can be obtained;
[0054] Heartbeat connection: A communication technology for periodic data transmission, mainly used in scenarios where communication status is maintained or data information is transmitted periodically.
[0055] A system for bypass traffic decryption and analysis, comprising:
[0056] At least one network analysis subsystem; the network analysis subsystem includes a traffic cache module, a traffic decryption module, a traffic analysis module, and a collaborative connection module. The network analysis subsystem is used for traffic decryption and traffic analysis after decryption, wherein the traffic cache module mainly implements the storage of undecrypted traffic; the traffic decryption module mainly implements key calculation, traffic decryption, and traffic simulation based on the key information from the terminal analysis subsystem; the traffic analysis module is mainly responsible for extracting traffic communication information and analyzing and detecting decrypted traffic; the collaborative connection module mainly implements and manages connections such as initial registration of the scheduling subsystem;
[0057] At least one terminal analysis subsystem; the terminal analysis subsystem is set in the terminal, the terminal analysis subsystem is connected to the network analysis subsystem, the terminal analysis subsystem includes a key information extraction module, a process traffic monitoring module, a data push module and a collaborative connection module, the terminal analysis subsystem is used to monitor the encrypted communication process and extract the key negotiation information in the communication process, and send the key negotiation information to the network analysis subsystem, wherein the key information extraction module mainly realizes the extraction of process-related key information based on the hook technology; the process traffic monitoring module mainly realizes the association of process information and communication traffic data and extracts the relevant hash value for identifying communication traffic; the data push module mainly realizes the integration of key information, process information and traffic information and pushes it to the management and scheduling system; the collaborative connection module mainly realizes and maintains the initial registration and heartbeat connection communication of the management and scheduling subsystem;
[0058] Management and scheduling subsystem; the management and scheduling subsystem includes a connection management module, an association analysis module and an information transfer module. The management and scheduling subsystem is used for coverage relationship analysis between the network analysis subsystem and the terminal analysis subsystem, among which the connection management module mainly realizes registration management and heartbeat connection management with the terminal analysis subsystem and the network analysis subsystem; the association analysis module mainly realizes the analysis of the network-end correspondence based on the uploaded relevant information to determine the network analysis subsystem node to which the relevant key information should be sent; the information transfer module mainly realizes the reception of data uploaded by the terminal analysis subsystem and the network analysis subsystem and the forwarding of key-related information.
[0059] A method for traffic decryption and analysis performed in a bypass manner, such as Figure 1 As shown, the following steps are included:
[0060] 1. System preparation stage:
[0061] S1: The terminal analysis subsystem and the network analysis subsystem respectively establish initial registration connections with the management and scheduling subsystem. The management and scheduling subsystem records the network addresses of each subsystem and assigns unique identification codes to the terminal analysis subsystem and the network analysis subsystem respectively.
[0062] S2: The terminal analysis subsystem establishes a heartbeat connection with the management and scheduling subsystem, such as Figure 2As shown, the data content of the heartbeat connection is a combination of a heartbeat flag, a terminal analysis subsystem identification code asymmetric encryption ciphertext (public key encryption) and a check value (signature information based on the heartbeat flag and terminal identification code ciphertext). The network analysis subsystem identifies and analyzes the entire traffic flow, identifies the corresponding heartbeat communication based on the same asymmetric encryption algorithm (private key calculation) and check value signature algorithm, and sends the traffic summary information of the heartbeat communication to the management and scheduling subsystem. At the same time, the source IP of the corresponding communication is marked as the target traffic IP. The traffic summary information includes the current network analysis subsystem identification code, time, communication five-tuple information (source IP, destination IP, source port, destination port, transport layer protocol), and a combination of the terminal analysis subsystem identification code in the traffic flow.
[0063] S3: The management and scheduling system analyzes the traffic summary information provided by each network analysis subsystem and identifies the correspondence between the terminal analysis subsystem and the network analysis subsystem, that is, whether the traffic of the terminal where the terminal analysis subsystem is located can be monitored by the network analysis subsystem.
[0064] 2. Encrypted traffic monitoring stage:
[0065] S4: The terminal analysis subsystem monitors the encrypted traffic key negotiation process in its terminal. By hooking the encrypted communication interface function, it extracts the encrypted communication time information, five-tuple information (source IP, destination IP, source port, destination port, transport layer protocol), the communication front packet sequence number (TCP protocol sequence number) combined hash (the sequence number of the first few data packets in the communication is combined, and then the hash value is generated by the hash algorithm), the communication front packet identification code (IP protocol Identification field) combined hash (the identification code of the first few data packets in the communication is combined, and then the hash value is generated by the hash algorithm), and the key negotiation information (one of the pre-master key, master key, or final key) and sends it to the management and scheduling subsystem;
[0066] S5: The network analysis subsystem stores the entire encrypted traffic corresponding to the target traffic IP address marked in S2 and constructs a fast retrieval index through the hash combination of time information, five-tuple information, communication front packet sequence number, and communication front packet identification code (Identification field of IP protocol);
[0067] S6: The management and scheduling subsystem forwards the information returned by the terminal analysis subsystem to the corresponding network analysis subsystem based on the received information returned by the terminal analysis subsystem and the corresponding relationship between the terminal analysis subsystem and the network analysis subsystem analyzed in S3;
[0068] S7: After receiving the encrypted communication-related information indirectly sent back by the terminal analysis subsystem, the network analysis subsystem performs elastic matching of the stored traffic index to find the corresponding communication session traffic. The following is the specific process of elastic matching:
[0069] S7.1: Extract the time information of the communication-related information received from the terminal analysis subsystem within a specific range and lock the time accuracy to a 10-minute range corresponding to the exact time (excluding the second-level accuracy, and taking 5 minutes before and after). That is, if the received time is 2024-11-11 12:05:06, the corresponding time range is 2024-11-11 12:00:00 to 2024-11-11 12:10:00;
[0070] S7.2: Based on the time range generated in S7.1, the traffic index query is performed in combination with the combined hash of the communication front-end packet sequence number and the communication front-end packet identification code transmitted by the terminal. If multiple communication records are found, the process proceeds to S7.3; otherwise, the process proceeds to S8.
[0071] S7.3: Match the five-tuple information in the queried communication results with the five-tuple information returned by the terminal. The matching process is as follows: first try to match the entire five-tuple. If it hits, enter S8. Otherwise, exclude the source IP address of the five-tuple for matching (to deal with the situation where the source IP changes due to NAT routing conversion). If it hits, enter S8. Otherwise, exclude the destination IP and destination port of the five-tuple for matching (to deal with the situation where NAT routing port mapping occurs). If it hits, enter S8. Otherwise, only match from the source port of the five-tuple. If it hits (to deal with the situation where there is both source IP conversion and port mapping in NAT mode), enter S8. Otherwise, it is considered a miss (that is, the network analysis subsystem fails to successfully save the corresponding traffic), and the current decryption process ends.
[0072] S8: The network analysis subsystem decrypts the corresponding traffic content by combining the encryption negotiation process information (cipher suite, random number, etc.) in the communication session traffic with the key negotiation information sent by the terminal analysis subsystem. This step first calculates the final key based on the key negotiation process of the encrypted traffic. If the terminal analysis subsystem provides a pre-master key (Pre-MasterKey), the calculation process first calculates the master key (MasterKey) from the pre-master key, and then calculates the final key from the master key. If the terminal analysis subsystem provides a master key, the final key is directly calculated. After obtaining the final key, the encrypted traffic content is decrypted based on this key.
[0073] S9: Simulates plaintext communication based on decrypted traffic content. This focuses on the length distribution of the decrypted plaintext content (i.e., the length distribution of each packet). It recalculates the TCP sequence number (SEQ value), TCP acknowledgment number (ACK value), and checksum for each packet, achieving plaintext reconstruction of the entire data stream and simulation of plaintext communication packets.
[0074] S10: The network analysis subsystem analyzes and detects the decrypted and reconstructed traffic. This part is consistent with the technical process related to traditional traffic analysis and detection, including traffic protocol analysis, traffic correlation, traffic reassembly, load feature analysis, communication behavior analysis, file restoration analysis and other related links, all of which can achieve capability upgrades based on the traffic decryption process.
[0075] In this embodiment, the present application realizes the relationship extraction and automatic maintenance between the network analysis subsystem and the terminal analysis subsystem through the design of central collaboration of the management and scheduling subsystem and heartbeat connection of the terminal analysis subsystem. The network analysis subsystem stores the target traffic in full and decrypts it after receiving the key negotiation information to prevent the loss of traffic data in the case of delayed reporting of the key negotiation information. The traffic elasticity identification mechanism constructed based on the time range, the combined hash of the communication front packet sequence number, the combined hash of the communication front packet identification code and the communication five-tuple information can effectively deal with the time difference between the terminal and network traffic information and the inconsistency of the five-tuple information caused by scenarios such as routing forwarding and port mapping, and realize accurate matching of communication data traffic. The terminal analysis subsystem can extract the pre-master key or master key information to infer the final key instead of directly extracting the final key, which can solve the problem that it is inconvenient to directly pass the final key information in some terminal environments. The simulation construction of plaintext traffic is realized through the decrypted traffic content, and the full reuse of mature plaintext traffic analysis system technology is realized.
[0076] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for traffic decryption and analysis performed in a bypass manner, characterized in that: The following steps are involved: S1: All terminal analysis subsystems and network analysis subsystems establish initial registration connections with the management and scheduling subsystem. The management and scheduling subsystem records the network addresses of each terminal analysis subsystem and network analysis subsystem and assigns a unique identification code to each terminal analysis subsystem and network analysis subsystem. S2: All terminal analysis subsystems establish a heartbeat connection with the management and scheduling subsystem. The data content of the heartbeat connection includes a heartbeat flag, an asymmetric encryption ciphertext based on the terminal analysis subsystem identification code encrypted with a public key, and a checksum value of the signature information of the asymmetric encryption ciphertext based on the heartbeat flag and the terminal analysis subsystem identification code. Each network analysis subsystem identifies and analyzes the entire traffic flow, identifies the heartbeat communication corresponding to itself in the entire traffic flow based on the asymmetric encryption algorithm calculated with a private key and the checksum signature algorithm, and sends the traffic summary information of the heartbeat communication to the management and scheduling subsystem. At the same time, the source IP of the corresponding heartbeat communication is marked as the target traffic IP, where the traffic summary information includes the identification code, time, communication five-tuple information of the corresponding network analysis subsystem, and the terminal analysis subsystem identification code; S3: The management and scheduling system analyzes the traffic summary information provided by each network analysis subsystem and identifies the corresponding relationship between the terminal analysis subsystem and the network analysis subsystem, that is, whether the traffic of the terminal where the terminal analysis subsystem is located can be monitored by the network analysis subsystem; S4: The terminal analysis subsystem extracts the time information, five-tuple information, communication front packet sequence number combination hash, communication front packet identification code combination hash, and key negotiation information of the terminal's encrypted communication by hooking the encrypted communication interface function, and sends it to the management and scheduling subsystem; S5: The network analysis subsystem stores the entire encrypted traffic corresponding to the target traffic IP address marked in S2 and constructs a fast retrieval index through the time information, five-tuple information, the combined hash of the communication front packet sequence number, and the combined hash of the communication front packet identification code; S6: The management and scheduling subsystem forwards the information sent back by the terminal analysis subsystem to the corresponding network analysis subsystem based on the information received from the terminal analysis subsystem and the corresponding relationship between the terminal analysis subsystem and the network analysis subsystem analyzed in S3; S7: After receiving the encrypted communication-related information from the management and scheduling subsystem, the network analysis subsystem performs an index elastic match on the stored traffic. If the corresponding communication session traffic is found, the process proceeds to S8. If not, the network analysis subsystem is deemed to have failed to save the corresponding traffic, and the decryption process ends. S8: The network analysis subsystem decrypts the corresponding traffic content by combining the encryption negotiation process information in the communication session traffic and the key negotiation information sent by the terminal analysis subsystem; S9: Reconstruct the plaintext data based on the decrypted traffic content and simulate the plaintext communication data packets; S10: The network analysis subsystem analyzes and detects the decrypted and reconstructed traffic.
2. The method for bypass traffic decryption and analysis according to claim 1, characterized in that: The elastic matching process in S7 is as follows: S7.1: Extract the time information of the communication-related information received from the terminal analysis subsystem within a specific range and lock the time accuracy to a preset minute-level range of the precise time; S7.2: Based on the time range generated in S7.1, the traffic index query is performed in combination with the combined hash of the communication front-end packet sequence number and the communication front-end packet identification code returned by the terminal. If multiple communication records are found, the process proceeds to S7.3; otherwise, the process proceeds to S8. S7.3: Match the five-tuple information in the queried communication result with the five-tuple information returned by the terminal. The matching process is as follows: first try to match the entire five-tuple. If it hits, enter S8. Otherwise, exclude the source IP address of the five-tuple and match again. If it hits, enter S8. Otherwise, exclude the destination IP and destination port of the five-tuple and match again. If it hits, enter S8. Otherwise, match only from the source port of the five-tuple. If it hits, enter S8. Otherwise, it is considered a miss and the current decryption process ends.
3. The method for bypass traffic decryption and analysis according to claim 1, characterized in that: Specifically in S8: First, the final key is calculated based on the key negotiation process of the encrypted traffic. If the terminal analysis subsystem provides a pre-master key, the calculation process is to first calculate the master key through the pre-master key, and then calculate the final key through the master key. If the terminal analysis subsystem provides a master key, the final key is calculated directly. After obtaining the final key, the content of the encrypted traffic is decrypted based on the final key.
4. The method for bypass traffic decryption and analysis according to claim 1, characterized in that: In S10, traffic analysis and detection operations include traffic protocol parsing, traffic correlation, traffic reassembly, load feature analysis, communication behavior analysis, and file restoration analysis operations.
5. A system for bypass traffic decryption and analysis, applied to a method for bypass traffic decryption and analysis as claimed in any one of claims 1 to 4, characterized in that: include: at least one network analysis subsystem; The network analysis subsystem includes a traffic cache module, a traffic decryption module, a traffic analysis module, and a collaborative connection module. The network analysis subsystem is used for traffic decryption and traffic analysis after decryption. at least one terminal analysis subsystem; The terminal analysis subsystem is set in the terminal and connected to the network analysis subsystem. The terminal analysis subsystem includes a key information extraction module, a process flow monitoring module, a data push module and a collaborative connection module. The terminal analysis subsystem is used to monitor the encrypted communication process and extract the key negotiation information during the communication process, and send the key negotiation information to the network analysis subsystem; Management and scheduling subsystem; the management and scheduling subsystem includes a connection management module, an association analysis module and an information transfer module. The management and scheduling subsystem is used for coverage relationship analysis of the network analysis subsystem and the terminal analysis subsystem.
Citation Information
Patent Citations
HTTPS protocol analysis method based on flow analysis
CN115567503A
Dynamic IP device identification system and method for encrypted traffic
CN115766204A