Session Key Capture and Security Event Analysis Method, Apparatus, Device, and Medium
By using eBPF technology to capture the TLS session key and generate mapping relationships in the operating system network stack, the problem of insufficient encrypted traffic decryption and security analysis capabilities in TLS 1.3 is solved, and efficient decryption and deep security detection are achieved to adapt to large-scale distributed environments.
Patent Information
- Application Number
- CN202510332609.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-03-20
AI Technical Summary
The prior art faces challenges in decrypting and analyzing TLS 1.3 encrypted traffic, especially in distributed architectures, where decryption efficiency and security analysis capabilities are insufficient.
By using eBPF technology to capture TLS session keys in the operating system's network stack, and combining time features and session features to generate mapping relationships, decouple data capture and analysis, supporting decryption and deep security detection of TLS 1.3.
It improves the decryption efficiency and performance of TLS encrypted traffic, enhances the security of the system, and adapts to the traffic monitoring and security protection needs in large-scale distributed environments.
Smart Images

Figure CN119854046B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of network communication technology and information security technology, and particularly to a method, device, equipment and medium for session key capture and security event analysis. Background Art
[0002] With the popularization of Internet communication and the enhancement of users' privacy protection awareness, HTTPS has become the mainstream encryption transmission protocol, and a large amount of traffic is encrypted using TLS (Transport Layer Security Protocol). According to the latest industry statistics, TLS 1.2 occupies most of the HTTPS traffic, but the application proportion of TLS 1.3 is rising rapidly. TLS 1.3 introduces a number of optimizations, such as a faster handshake process, stronger default encryption algorithms, and a more secure key negotiation mechanism. Compared with TLS 1.2, TLS 1.3 deletes the RSA key exchange and comprehensively adopts key negotiation methods based on Forward Secrecy such as ECDHE, which significantly improves security but also poses challenges to existing traffic decryption and analysis methods. Taking the mainstream open-source packet analysis software Wireshark as an example, when appropriate secrets are provided, Wireshark supports TLS decryption. The three available methods are:
[0003] (1) Using a key log file for each session secret, the disadvantages are: relying on application logs, being highly invasive, requiring modification of server applications or depending on specific log configurations, being difficult to be uniformly deployed in a complex distributed architecture, and generating and processing a large-scale Keylog file will bring significant performance overhead;
[0004] (2) Using an RSA private key for decryption, the disadvantages are: relying on static key exchange, only applicable to encryption suites that do not use ECDHE, unable to support TLS 1.3. The leakage of the server private key may lead to large-scale decryption attacks, posing a serious threat to data security;
[0005] (3) Using a Pre-Shared Key (PSK) for decryption, the disadvantages are: it can only work in scenarios where a pre-shared key is explicitly used in the TLS handshake, and the PSK mode is not the mainstream of TLS communication, with a narrow scope of application, complex configuration, and insufficient real-time performance and flexibility. Summary of the Invention
[0006] The purpose of the present invention is to provide a method, device, equipment and medium for session key capture and security event analysis, which decouples data capture and analysis through a distributed architecture, supports the decryption of the TLS encryption protocol and in-depth security detection, improves the decryption efficiency, performance and security of the system, adapts to the traffic monitoring and security protection requirements in a large-scale distributed environment, and solves the problem of insufficient ability to decrypt TLS encrypted traffic and perform real-time security analysis in the prior art.
[0007] To solve the above technical problems, the technical solution adopted by the present invention is as follows:
[0008] In a first aspect, a method for capturing session keys and analyzing security events includes the following steps:
[0009] S1. Establish a data security protection system, deploy a probe service at the security event monitoring end, and capture TLS session keys according to the analysis of TLS handshake messages in the network stack of the operating system by using eBPF technology;
[0010] S2. The probe service combines time characteristics, session characteristics, and the captured keys to generate a mapping relationship and write it to disk as a persistent file, where the session characteristics are the communication five-tuple;
[0011] S3. Use a high-performance tool to capture the original encrypted traffic, save it as a file in pcap / pcapng format, and name it according to time characteristics;
[0012] S4. Use the probe service as a gRPC client. When the persistent file reaches a preset threshold, trigger a reporting mechanism to transmit the persistent key file and the packet persistence problem to the gRPC server end, where the gRPC server end is the data mobility security management system;
[0013] S5. Based on the data mobility security management system, use the five-tuple characteristics of the traffic packets to assist in decrypting the original encrypted traffic;
[0014] S6. Extract protocol fields and perform security analysis on the decrypted data, detect potential security threats, generate real-time alarms, and then transmit the alarm information to the administrator to take corresponding measures.
[0015] A further improvement of the technical solution of the present invention is that in S1, the process of capturing TLS session keys includes:
[0016] Establish a data security protection system including a probe device and a remote security analysis device. Among them, the probe device is deployed on the server side supporting the TLS protocol, captures TLS decrypted data through eBPF, and the remote security analysis device receives the decrypted packet file transmitted by the probe device, deeply analyzes the data, and generates a security alarm;
[0017] Deploy a probe service at the security event monitoring end supporting the TLS protocol. The eBPF program HOOKs into the relevant functions of the network stack of the operating system, intercepts the packets in the TLS handshake stage, and analyzes the encryption parameters and key exchange information contained in the handshake messages. Among them, the probe service interacts with the kernel of the operating system through eBPF technology to realize the monitoring of TLS traffic in the network stack;
[0018] After the TLS handshake is completed, capture the session key generated by the encryption algorithm. The specific capture methods include: kernel-mode capture and user-mode capture. Kernel-mode capture extracts the session key directly from the kernel memory through eBPF, and user-mode capture uses eBPF uprobe to HOOK the TLS library function of the user-mode process to capture the session key generated by the application program.
[0019] A further improvement of the technical solution of the present invention lies in: in S2, the process of the persistent file being written to disk includes:
[0020] The probe service obtains the session key captured during the TLS handshake, the timestamp of the generated key, and the session characteristics, that is, the communication quintuple information, from the memory as the key identifier of the session characteristics. Among them, the communication quintuple includes: source IP address, destination IP address, source port number, destination port number, and protocol type. The source IP address is the IP address of the device sending data, the destination IP address is the IP address of the device receiving data, the source port is the port number used for this session on the device sending data, the destination port is the port number used for this session on the device receiving data, and the protocol type is the network protocol used by the session;
[0021] Associate the captured session key with the corresponding communication quintuple to create a mapping table, where: Key is the communication quintuple, and Value is the session key and its generation time. Then, generate a mapping relationship based on the time characteristics, communication quintuple, and session key;
[0022] Based on the generated mapping relationship, the probe service triggers the file write-to-disk operation, and then writes the generated mapping relationship to disk as a persistent file and stores it on the disk in the form of a JSON file or a binary file.
[0023] A further improvement of the technical solution of the present invention lies in: in S3, the process of capturing the original encrypted traffic includes:
[0024] Configure a high-performance packet capture tool and configure the capture parameters according to requirements. The capture parameters include specifying the capture network interface, setting the filtering rules, and defining the maximum file size or time interval. Among them, the packet capture tools include Wireshark, tcpdump, or Tshark, etc.;
[0025] Enable the packet capture tool to capture the original encrypted traffic in the network, including the traffic in the TLS handshake and data transmission phases, ensuring that the captured data is complete and not tampered with, and retaining all necessary meta-information;
[0026] Save the captured original encrypted traffic as a file in the standard pcap or pcapng format. Among them, the pcap / pcapng file has a standardized format and contains complete network packet information, including the header and payload;
[0027] Name the file according to the time characteristics of packet capture, and store the generated pcap / pcapng file in the specified directory.
[0028] A further improvement of the technical solution of the present invention is that in S4, the process of triggering the reporting mechanism includes:
[0029] Initialize the gRPC client in the probe service, configure the address and port for the gRPC client to connect to the remote gRPC server, ensure that the gRPC server has been started and is listening on the specified address and port, and configure the gRPC server to receive the persistent file from the probe service;
[0030] Set the conditions for triggering the reporting mechanism in the probe service. When the persistent file reaches thresholds such as time and size, the reporting mechanism is triggered. Then, read the persistent file containing the session key from the storage directory of the probe service, and read the pcap / pcapng file containing the original encrypted traffic from the storage directory of the probe service;
[0031] The probe service establishes a connection with the remote data mobility security management system through the gRPC protocol, packages the key-persistent file and the message-persistent file into a gRPC message, and uses the streaming transmission function of gRPC to upload the file in chunks to ensure transmission efficiency and stability;
[0032] After receiving the file, the gRPC server returns an acknowledgement message to the probe service. If the transmission is successful, the probe service deletes the local persistent file to free up storage space. If the transmission fails, the probe service records an error log and retries the upload.
[0033] A further improvement of the technical solution of the present invention is that in S5, the process of decrypting the original encrypted traffic includes:
[0034] Use the data mobility security management system to capture traffic packets in the network, extract the packet header information from the captured traffic packets, and perform session key lookup in the key file in combination with the five-tuple characteristics of the traffic packets. Among them, the session key stores data in a HASH structure, and the Key is the five-tuple characteristic, with higher lookup efficiency;
[0035] Store the extracted five-tuple characteristics in the five-tuple flow table to record the traffic information of each flow, analyze the traffic characteristics in the five-tuple flow table to identify the type of encrypted traffic and potential security threats, and match the extracted five-tuple characteristics with the known traffic characteristics in the traffic characteristic library to identify the application type or protocol of the encrypted traffic;
[0036] Select the corresponding decryption algorithm and key according to the matching result, and then apply the decryption algorithm and key to decrypt the original encrypted traffic to obtain the plaintext traffic data.
[0037] A further improvement of the technical solution of the present invention lies in that: in the S6, the process of generating real-time alarms includes:
[0038] Analyze the decrypted traffic, extract the key fields in the protocol, including the request method, URL path and query parameters, header information, request body content, response status code and response header information and response body content, etc., but not limited to this, and store the extracted fields in a structured format for subsequent analysis;
[0039] Check the legality of the extracted fields, verify whether the field formats, value ranges, etc. conform to the protocol specifications, identify and mark abnormal field values, search for sensitive information in the request / response body, mark and record the discovered sensitive information, analyze the header fields and request / response body content, and detect potential security threats;
[0040] According to the business requirements and security policies, configure alarm rules including based on the results of field legality checks, sensitive information detection results, and threat detection results. When the data meets the alarm rules, trigger the alarm mechanism and generate alarm information, including alarm time, alarm type, trigger rules, and relevant data, etc.;
[0041] Transmit the generated alarm information to the administrator via email, SMS, and instant messaging tools to ensure the accuracy and timeliness of the alarm information, and display the alarm information on the visualization platform, providing detailed alarm details and associated data;
[0042] After receiving the alarm information, the administrator analyzes the alarm reason and trigger rules, and based on the analysis results, determines whether there is indeed a security threat. If it is confirmed that there is a security threat, the administrator needs to take response measures including blocking attacks, fixing vulnerabilities, and strengthening security protection, etc., and record the processing process and results for subsequent auditing and review.
[0043] In a second aspect, a probe device for implementing the session key capture and security event analysis method is used to implement the session key capture and security event analysis method, including an eBPF program module, a storage module, a packet capture module, and a communication module, wherein, the modules are electrically connected to each other;
[0044] The eBPF program module is used to capture the session key data of TLS traffic;
[0045] The storage module stores the session key, generation time, and session five-tuple information as a persistent file according to the HASH data structure;
[0046] The packet capture module is used to capture raw data packets;
[0047] The communication module is used to send the persistent file to the remote security analysis system through the gRPC protocol.
[0048] Thirdly, a remote security analysis device, which is a probe device for implementing the session key capture and security event analysis method, includes a receiving module, a decryption module, an analysis module, and an alarm module, where the modules are electrically connected to each other;
[0049] The receiving module is used to receive the persistent packet file transmitted by the probe device;
[0050] The decryption module efficiently obtains the session key from the key file according to the five-tuple information of the encrypted traffic and performs traffic decryption and restoration;
[0051] The analysis module is used to extract fields from the packet file and perform in-depth analysis to detect potential security threats;
[0052] The alarm module is used to generate security event alarm information.
[0053] Fourthly, a computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, the session key capture and security event analysis method as described is implemented.
[0054] Due to the adoption of the above technical solutions, the technical progress achieved by the present invention compared with the prior art is:
[0055] The present invention provides a session key capture and security event analysis method, device, equipment, and medium. The key file is saved using the HASH structure, and the mapping relationship between the five-tuple, session time point, and session key is increased. On the decryption server side, the mapping relationship search between the encrypted traffic and the session key can be efficiently completed for symmetric decryption, greatly improving the decryption performance. At the same time, the session generation time and session key are saved in the HASH value, which can solve the scenario of releasing old connections in high-concurrency scenarios and the scenario where new connections have the same five-tuples as old connections, and can improve the decryption accuracy.
[0056] The present invention provides a session key capture and security event analysis method, device, equipment, and medium. eBPF operates in the kernel state and does not depend on any changes in a specific protocol stack or application layer when capturing TLS traffic and session data. Especially in a dynamically expanding distributed system, it is more flexible to deploy, does not require modifying the application code, and can deploy a non-intrusive probe service at low cost. The capture and analysis functions are decoupled, and a distributed architecture design is adopted, reducing the dependence on local performance while improving scalability and flexibility.
[0057] The present invention provides a method, apparatus, device, and medium for session key capture and security event analysis. By transmitting data through gRPC, it avoids directly exposing sensitive information (such as session keys or plaintext), improves the security and compliance of the system, supports a distributed architecture, can flexibly adapt to the cloud-native environment and large-scale deployment, provides higher scalability than traditional single-machine or local solutions, and transmits data through gRPC to avoid direct dependence on the decryption buffer, supporting the deployment requirements in multi-tenant and distributed environments.
[0058] The present invention provides a method, apparatus, device, and medium for session key capture and security event analysis, covering the complete process from traffic capture, decryption to field extraction and security event alert, capable of adapting to the multi-scenario requirements such as traffic analysis, threat detection, and compliance auditing, and increasing the practical value compared with the traditional technology limited to traffic capture. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0060] Figure 1 It is a schematic diagram of the working process of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments of the present invention belong to the scope of protection of the present invention.
[0062] Embodiment 1, as Figure 1 shown, the present invention provides a method for session key capture and security event analysis, including the following steps:
[0063] S1. Establish a data security protection system. Deploy a probe service at the security event monitoring end, and use eBPF technology to capture the TLS session key in the network stack of the operating system by analyzing the TLS handshake message. Establish a data security protection system including a probe device and a remote security analysis device. Among them, the probe device is deployed on the server side that supports the TLS protocol, captures the TLS decrypted data through eBPF, and the remote security analysis device receives the decrypted message file transmitted by the probe device, deeply analyzes the data, and generates security alerts. Deploy a probe service at the security event monitoring end that supports the TLS protocol. The eBPF program HOOKs into the relevant functions of the network stack of the operating system (tcp_sendmsg (kernel-mode function), udp_sendmsg (kernel-mode function), SSL_write_key (user-mode function)), intercepts the data packets in the TLS handshake stage, and analyzes the encryption parameters and key exchange information contained in the handshake message. Among them, the probe service interacts with the kernel of the operating system through eBPF technology to achieve monitoring of TLS traffic in the network stack. After the TLS handshake is completed, capture the session key generated by the encryption algorithm. Among them, the specific capture methods include: kernel-mode capture and user-mode capture. Kernel-mode capture directly extracts the session key from the kernel memory through eBPF, and user-mode capture uses eBPF uprobe to HOOK the TLS library function of the user-mode process to capture the session key generated by the application program;
[0064] S2. The probe service combines time characteristics, session characteristics, and the captured key to generate a mapping relationship and write it to disk as a persistent file. Among them, the session characteristics are the communication five-tuple. The probe service obtains the session key captured during the TLS handshake, the timestamp of the generated key, and the session characteristics, that is, the communication five-tuple information, from the memory as the key identifier of the session characteristics. Among them, the communication five-tuple includes: source IP address, destination IP address, source port number, destination port number, and protocol type. The source IP address is the IP address of the device sending the data, the destination IP address is the IP address of the device receiving the data, the source port is the port number used for this session on the device sending the data, the destination port is the port number used for this session on the device receiving the data, and the protocol type is the network protocol used by the session. Associate the captured session key with the corresponding communication five-tuple to create a mapping relationship table. Among them: Key is the communication five-tuple, and Value is the session key and its generation time. Then, based on the time characteristics, communication five-tuple, and session key, generate a mapping relationship. Based on the generated mapping relationship, the probe service triggers a file write-to-disk operation, and then writes the generated mapping relationship to disk as a persistent file and stores it on the disk in the form of a JSON file or a binary file;
[0065] S3. Use a high-performance tool to capture the original encrypted traffic, save it as a file in pcap / pcapng format, and name it according to time characteristics. Configure the high-performance packet capture tool and configure the capture parameters according to requirements. The capture parameters include specifying the capture network interface, setting the filtering rules, and defining the maximum file size or time interval for automatic segmented saving. Among them, the packet capture tools include Wireshark, tcpdump, or Tshark, etc. Enable the packet capture tool to capture the original encrypted traffic including the TLS handshake and data transfer stage traffic in the network, ensure that the captured data is complete and not tampered with, retain all necessary meta-information, and save the captured original encrypted traffic as a file in the standard pcap or pcapng format. Among them, the pcap / pcapng file has a standardized format, which is convenient for subsequent analysis tools to parse and contains complete network packet information, including headers and payloads. Name the file according to the time characteristics of the packet capture to ensure that the file name is unique and easy to identify. Store the generated pcap / pcapng file in the specified directory;
[0066] S4. Use the probe service as a gRPC client. When the persistent file reaches the preset threshold, trigger the reporting mechanism and send the persistent file of the secret key and the persistent file of the message to the gRPC server. Among them, the gRPC server is the data liquidity security management system. Initialize the gRPC client in the probe service, configure the address and port of the gRPC client to connect to the remote gRPC server, ensure that the gRPC server has been started and is listening on the specified address and port, and configure the gRPC server to receive the persistent file from the probe service. Set the condition for triggering the reporting mechanism in the probe service. When the persistent file reaches thresholds such as time and size, trigger the reporting mechanism. Then read the persistent file containing the session secret key from the storage directory of the probe service, and read the pcap / pcapng file containing the original encrypted traffic from the storage directory of the probe service. The probe service establishes a connection with the remote data liquidity security management system through the gRPC protocol, package the persistent file of the secret key and the persistent file of the message as a gRPC message, and use the streaming transmission function of gRPC to upload the file in chunks to ensure the transmission efficiency and stability. After the gRPC server receives the file, it returns a confirmation message to the probe service. If the transmission is successful, the probe service deletes the local persistent file to free up storage space. If the transmission fails, the probe service records the error log and retries the upload;
[0067] S5. Based on the data liquidity security management system, use the five-tuple characteristics of the traffic packet to assist in decrypting the original encrypted traffic;
[0068] S6. Extract protocol fields from the decrypted data and conduct security analysis to detect potential security threats, generate real-time alerts, and then transmit the alert information to the administrator for corresponding measures. By deploying a probe service on the server side of the TLS encryption application, use the eBPF technology to obtain and save the TLS key, save the session key to a persistent file according to the five-tuple session characteristics and time slice characteristics, and at the same time collect the original encrypted traffic through packet capture to generate a persistent file. The probe service transmits the persistent file to the remote data mobility security management system through the gRPC protocol. The remote security system extracts fields and conducts in-depth analysis on the packet content to detect potential security threats and generate security event alerts. According to the session key, as well as the five-tuple and time characteristics of the packet, match the key with the packet. The remote security system can quickly and efficiently complete remote decryption and security event analysis, solving the problem of low efficiency in local processing in the existing solution. By capturing the session key for in-depth field extraction, it provides more complete traffic context information for security analysis and improves the detection ability for complex attack scenarios.
[0069] Example 2, as Figure 1 shown, based on Example 1, the present invention provides a technical solution: Preferably, in S5, the process of decrypting the original encrypted traffic includes:
[0070] Use the data mobility security management system to capture traffic packets in the network, extract the packet header information from the captured traffic packets, and combine the five-tuple characteristics of the traffic packets to search for the session key in the key file. Among them, the session key stores data in a HASH structure, with the Key being the five-tuple characteristics, and the search efficiency is higher. Store the extracted five-tuple characteristics in the five-tuple flow table to record the traffic information of each flow, and analyze the traffic characteristics in the five-tuple flow table to identify the type of encrypted traffic and potential security threats. Match the extracted five-tuple characteristics with the known traffic characteristics in the traffic characteristics library to identify the application type or protocol of the encrypted traffic, select the corresponding decryption algorithm and key according to the matching result, and then apply the decryption algorithm and key to decrypt the original encrypted traffic to obtain the plaintext traffic data, solving the pain points of the prior art that require one-by-one matching of traffic packets and session keys, with low execution efficiency and high resource consumption. At the same time, the session generation time and session key are saved in the HASH value, which can solve the scenario of releasing old connections in high-concurrency scenarios and the scenario where new connections have the same five-tuples as old connections, and can improve the decryption accuracy;
[0071] In S6, the process of generating real-time alerts includes:
[0072] Analyze the decrypted traffic, extract the key fields in the protocol, including the request method, URL path and query parameters, header information, request body content, response status code and response header information and response body content, etc., but not limited to this, and store the extracted fields in a structured format for subsequent analysis. Conduct a legality check on the extracted fields to verify whether the field formats, value ranges, etc. comply with the protocol specifications, identify and mark abnormal field values. Search for sensitive information in the request / response body, mark and record the discovered sensitive information. Analyze the header fields and request / response body content to detect potential security threats. According to business requirements and security policies, configure alarm rules based on the results of field legality checks, sensitive information detection results, and threat detection results. When the data meets the alarm rules, trigger the alarm mechanism and generate alarm information, including alarm time, alarm type, trigger rules, and related data, etc. Transmit the generated alarm information to the administrator via email, SMS, and instant messaging tools to ensure the accuracy and timeliness of the alarm information, and display the alarm information on the visualization platform, providing detailed alarm details and associated data. After receiving the alarm information, the administrator analyzes the alarm reason and trigger rules, and based on the analysis results, determines whether there is indeed a security threat. If it is confirmed that there is a security threat, the administrator needs to take countermeasures including blocking attacks, fixing vulnerabilities, and strengthening security protection, etc., and record the processing process and results for subsequent auditing and review.
[0073] Embodiment 3, as Figure 1 shown, based on Embodiments 1-2, the present invention further provides a probe device for implementing a method for capturing session keys and analyzing security events, including an eBPF program module, a storage module, a packet capture module, and a communication module, wherein, the modules are electrically connected to each other;
[0074] The eBPF program module is used to capture the session key data of TLS traffic;
[0075] The storage module stores the session key, generation time, and session five-tuple information as a persistent file according to the HASH data structure;
[0076] The packet capture module is used to capture the original data packets;
[0077] The communication module is used to send the persistent file to the remote security analysis system via the gRPC protocol;
[0078] Furthermore, a remote security analysis device for implementing the probe device for the method of capturing session keys and analyzing security events includes a receiving module, a decryption module, an analysis module, and an alarm module, wherein, the modules are electrically connected to each other;
[0079] The receiving module is used to receive the persistent message file transmitted by the probe device;
[0080] A decryption module that efficiently obtains a session key from a secret key file based on the five-tuple information of encrypted traffic and decrypts and restores the traffic;
[0081] An analysis module for extracting fields and performing in-depth analysis on a packet file to detect potential security threats;
[0082] An alarm module for generating security event alarm information;
[0083] In addition, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements a method for capturing a session key and analyzing security events;
[0084] Generally speaking, computer instructions for implementing the method of the present invention can be carried by any combination of one or more computer-readable storage media. A computer-readable storage medium can include any computer-readable medium except for a signal propagating temporarily.
[0085] A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0086] Computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. In particular, the Python language suitable for neural network computing and platform frameworks based on TensorFlow, PyTorch, etc. can be used. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or connected to an external computer (for example, connected through the Internet using an Internet service provider).
[0087] For the above-mentioned computer-readable storage medium, reference can be made to the implementation content and its beneficial effects described in detail for the above-mentioned method, which will not be elaborated here.
[0088] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. Session key capture and security event analysis method, characterized in that: The following steps are involved: S1. Establish a data security protection system, deploy a probe service on the security event monitoring end, and use eBPF technology to capture the TLS session key by analyzing the TLS handshake message in the network stack of the operating system; S2. The probe service combines the time feature, session feature, and captured secret key to generate a mapping relationship and save it to disk as a persistent file. The session feature is the communication quintuple. S3. Use high-performance tools to capture the original encrypted traffic, save it as a file in pcap / pcapng format, and name it according to time characteristics; S4. Use the probe service as the gRPC client. When the persistence file reaches the preset threshold, the reporting mechanism is triggered, and the key persistence file and message persistence problem are transmitted to the gRPC server. The gRPC server is the data liquidity security management system. S5, based on the data flow security management system, using the five-tuple characteristics of the traffic message to assist in decrypting the original encrypted traffic; S6. Extract protocol fields and conduct security analysis on the decrypted data to detect potential security threats and generate real-time alerts, which are then passed to administrators to take appropriate measures. In S1, the process of capturing the TLS session key includes: Establish a data security protection system including a probe device and a remote security analysis device. The probe device is deployed on the server side that supports the TLS protocol. The TLS decrypted data is captured through eBPF. The remote security analysis device receives the decrypted message file transmitted by the probe device, performs in-depth analysis on the data, and generates security alerts. Deploy a probe service on the security event monitoring end that supports the TLS protocol. The eBPF program hooks into the network stack related functions of the operating system, intercepts data packets in the TLS handshake phase, and analyzes the encryption parameters and key exchange information contained in the handshake message. After the TLS handshake is completed, the session key generated by the encryption algorithm is captured. The specific capture methods include: kernel state capture and user state capture. Kernel state capture directly extracts the session key from the kernel memory through eBPF. User state capture uses the TLS library function of the eBPF uprobe HOOK user state process to capture the session key generated by the application. In S2, the process of storing persistent files on disk includes: The probe service obtains the session key captured during the TLS handshake process, the timestamp of the key generation, and the session features, namely, the communication five-tuple information, from the memory as the key identifier of the session features. The communication five-tuple includes: source IP address, target IP address, source port number, target port number, and protocol type. Associate the captured session key with the corresponding communication quintuple to create a mapping relationship table, where the Key is the communication quintuple, the Value is the session key and its generation time, and then generate a mapping relationship based on the time feature, the communication quintuple and the session key; Based on the generated mapping relationship, the probe service triggers the file storage operation, and then stores the generated mapping relationship as a persistent file in the form of a JSON file or a binary file. In the S3, the process of capturing the original encrypted traffic includes: Configure a high-performance packet capture tool and configure capture parameters according to requirements. The capture parameters include specifying the capture network interface, setting filtering rules, and defining the maximum file size or time interval. The packet capture tool includes Wireshark, tcpdump, or Tshark. Enable the packet capture tool to capture the original encrypted traffic in the network, including the TLS handshake and data transmission phase traffic; Save the captured raw encrypted traffic as a file in standard pcap or pcapng format; Name the file according to the time characteristics of the captured packet and store the generated pcap / pcapng file in the specified directory.
2. The method for capturing session keys and analyzing security events according to claim 1, characterized in that: In S4, the process of triggering the reporting mechanism includes: Initialize the gRPC client in the probe service, configure the address and port of the gRPC client to connect to the remote gRPC server, and configure the gRPC server to receive persistent files from the probe service; Set the conditions for triggering the reporting mechanism in the probe service. When the persistent file reaches the time and size threshold, the reporting mechanism is triggered, and then the persistent file containing the session key is read from the storage directory of the probe service, and the pcap / pcapng file containing the original encrypted traffic is read from the storage directory of the probe service. The probe service establishes a connection with the remote data liquidity security management system through the gRPC protocol, packages the key persistence file and the message persistence file into a gRPC message, and uses the streaming function of gRPC to upload the file in blocks; After receiving the file, the gRPC server returns a confirmation message to the probe service. If the transmission is successful, the probe service deletes the local persistent file to free up storage space. If the transmission fails, the probe service records the error log and retries the upload.
3. The method for capturing session keys and analyzing security events according to claim 2, characterized in that: In S5, the process of decrypting the original encrypted traffic includes: The data flow security management system is used to capture the traffic packets in the network, and the packet header information is extracted from the captured traffic packets. The session key is searched in the key file in combination with the five-tuple feature of the traffic packet. The session key saves data in a HASH structure, and the key is a five-tuple feature. The extracted five-tuple features are stored in the five-tuple flow table to record the traffic information of each flow, and the traffic features in the five-tuple flow table are analyzed, and the extracted five-tuple features are matched with the known traffic features in the traffic feature library to identify the application type or protocol of the encrypted traffic; The corresponding decryption algorithm and key are selected according to the matching result, and then the decryption algorithm and key are applied to decrypt the original encrypted traffic to obtain the plaintext traffic data.
4. The method for capturing session keys and analyzing security events according to claim 3, characterized in that: In S6, the process of generating a real-time alarm includes: Parse the decrypted traffic to extract key fields in the protocol, including request method, URL path and query parameters, header information, request body content, response status code, response header information and response body content, and store the extracted fields in a structured format; Perform a validity check on the extracted fields, verify whether the field format and value range comply with the protocol specifications, identify and mark abnormal field values, search for sensitive information in the request / response body, mark and record the sensitive information found, analyze the header fields and request / response body content, and detect potential security threats; According to business needs and security policies, configure alarm rules based on field legitimacy check results, sensitive information detection results, and threat detection results. When the data meets the alarm rules, the alarm mechanism is triggered and alarm information is generated, including alarm time, alarm type, triggering rules, and related data; Deliver the generated alarm information to the administrator via email, SMS and instant messaging tools, and display the alarm information on the visualization platform, providing detailed alarm details and related data; After receiving the alarm information, the administrator analyzes the alarm cause and triggering rules, and determines whether there is indeed a security threat based on the analysis results. If it is confirmed that there is a security threat, the administrator needs to take countermeasures including blocking the attack, repairing vulnerabilities, and strengthening security protection, and record the processing process and results.
5. A probe device for implementing the method for capturing session keys and analyzing security events, used to implement the method for capturing session keys and analyzing security events as described in any one of claims 1 to 4, characterized in that: It includes an eBPF program module, a storage module, a packet capture module, and a communication module, wherein the modules are connected by electrical signals; The eBPF program module is used to capture session key data of TLS traffic; The storage module stores the session key, generation time, and session quintuple information as a persistent file according to a HASH data structure; The packet capture module is used to capture original data messages; The communication module is used to send the persistent file to the remote security analysis system through the gRPC protocol.
6. A remote security analysis device, used to implement the probe device for implementing the session key capture and security event analysis method as claimed in claim 5, characterized in that: It includes a receiving module, a decryption module, an analysis module and an alarm module, wherein the modules are connected by electrical signals; The receiving module is used to receive a persistent message file transmitted by the probe device; The decryption module efficiently obtains the session key in the key file according to the five-tuple information of the encrypted traffic and performs traffic decryption and restoration; The analysis module is used to extract fields and conduct in-depth analysis on message files to detect potential security threats; The alarm module is used to generate security event alarm information.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the session key capture and security event analysis method as described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
System and method for monitoring SSL / TLS (secure socket layer / transport layer security) data
CN108156178A
Data tracking and analysis method and device, equipment and storage medium
CN119128555A
Data stream processing method and device based on software defined network
WO2024148851A1