Encryption Traffic Capture and Security Incident Analysis Method, Device, Equipment and Medium
By deploying probe services on the server side, using eBPF technology to capture TLS encrypted traffic and conduct in-depth security analysis, the problem of lack of coordination between decryption and analysis processes in the existing technology is solved, transparent decryption of encrypted traffic and systematic security event detection and alarming is achieved, and the scalability and flexibility of the system is improved.
Patent Information
- Application Number
- CN202510354393.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-03-25
AI Technical Summary
When handling encrypted traffic, the decryption and analysis process lacks effective coordination, resulting in a single function, lack of systematic security analysis and response capabilities, insufficient scalability and flexibility, and it is difficult to meet the needs of high concurrency and large-scale distributed deployment.
By deploying probe services on the server side, using eBPF technology to capture TLS encrypted traffic, generate persistent files, and transfer files to the remote data flow security management system through the gRPC protocol, further protocol field extraction and security analysis are carried out, potential security threats are detected, and real-time alarms are generated.
It realizes transparent decryption and in-depth security analysis of encrypted traffic, provides a complete process from data capture to security event detection and alarm, improves the scalability and flexibility of the system, and adapts to the needs of high-concurrency large-scale deployment in distributed environments.
Smart Images

Figure CN119892497B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of network communication technology and information security technology, and particularly relates to methods, devices, equipment and media for encrypted traffic capture and security event analysis. Background Art
[0002] With the popularization of Internet communication and the enhancement of users' privacy protection awareness, HTTPS has become the mainstream encrypted transmission protocol, and a large amount of traffic is encrypted using TLS (Transport Layer Security Protocol). According to statistics, TLS 1.2 occupies most of the HTTPS traffic, but the application proportion of TLS 1.3 is rising rapidly. TLS 1.3 introduces a number of optimizations, such as a faster handshake process, stronger default encryption algorithms, and a more secure key negotiation mechanism. Compared with TLS 1.2, TLS 1.3 deletes the RSA key exchange and comprehensively adopts key negotiation methods based on Forward Secrecy such as ECDHE, significantly improving security, but also bringing challenges to existing traffic decryption and analysis methods. Taking the mainstream open-source packet analysis software Wireshark as an example, when appropriate secrets are provided, Wireshark supports TLS decryption. The three available methods are: (1) using a key log file for each session secret; (2) decrypting using an RSA private key; (3) decrypting using a Pre-Shared Key (PSK).
[0003] In the prior art, when integrating the data decryption and analysis modules, there is a problem of lack of effective coordination between the decryption and subsequent analysis processes, mainly focusing on the work of the security event client (such as an HTTPS server), and there are the following defects:
[0004] 1. Single function: Limited to parsing plaintext packets and completing a single specific function. All work focuses on the client, which will consume the computing resources of the client and is not conducive to iteration and expansion, and the scope of use is limited;
[0005] 2. Lack of systematic security analysis and response capabilities: The prior art usually only focuses on traffic capture and decryption, lacking in-depth analysis of decrypted data and a security event response mechanism. For example, many solutions fail to provide a complete process from data capture to security event detection and alarm, lacking extraction of specific protocol fields, malicious behavior identification, and automated response, making the application scope of the prior art limited to simple monitoring and interception;
[0006] 3. Insufficient scalability and flexibility: In the prior art, the process of traffic capture and decryption is centralized locally, which not only increases the pressure on local system resources but also limits the scalability and adaptability of the solution. In a modern complex distributed environment, single-point traffic capture and processing may not meet the requirements of high concurrency and large-scale distributed deployment, affecting the elasticity and scalability of the system. Summary of the Invention
[0007] The object of the present invention is to provide a method, device, equipment and medium for encrypted traffic capture and security event analysis to solve the problems raised in the above background technology.
[0008] To solve the above technical problems, the technical solution adopted by the present invention is:
[0009] In the first aspect, an encrypted traffic capture and security event analysis method includes the following steps:
[0010] S1. Build a data security protection system, deploy a probe service on the server side of the TLS encryption application, and capture TLS encrypted traffic in the network stack of the operating system using the eBPF technology;
[0011] S2. The probe service obtains decryption data from the memory and generates it into a persistent file;
[0012] S3. Take the probe service as a gRPC client. When the persistent file reaches the preset standard, trigger the reporting mechanism and transmit the persistent file to the remote data liquidity security management system through the gRPC protocol;
[0013] S4. Take the remote data liquidity security management system as a gRPC server, further extract protocol fields and perform security analysis on the decrypted HTTP data, and detect potential security threats in the traffic;
[0014] S5. After the data analysis is completed on the remote server, generate real-time alarms according to the analysis results and respond to potential security events.
[0015] A further improvement of the technical solution of the present invention is that: the data security protection system includes a probe device and a remote security analysis device;
[0016] Among them, the probe device is deployed on the server side supporting the TLS protocol, and captures TLS decryption data through eBPF;
[0017] The remote security analysis device is used to receive the decrypted message file transmitted by the probe device, deeply analyze the data, and generate security alarms.
[0018] A further improvement of the technical solution of the present invention is that: in the S1, the process of capturing TLS encrypted traffic specifically includes:
[0019] Build a data security protection system, analyze the environment of the server operating system to support eBPF technology, evaluate the server performance, ensure that there are sufficient resources to support the operation of eBPF programs and the capture of TLS traffic, and then install the eBPF tool chain;
[0020] Deploy a probe service on the application server that supports the TLS protocol, and load the eBPF program. Among them, the probe service includes the eBPF program, which is designed to hook at specific positions in the network stack to listen for and capture TLS traffic in network communications;
[0021] When the TLS encrypted traffic passes through the server's network stack, the eBPF program hooks to the TLS-related function call points in the kernel state of the operating system through the uprobes mechanism, then identifies and captures the packets of the TLS encrypted traffic, extracts the metadata of the TLS packets through the eBPF program, and transfers it to the probe service through the communication mechanism between the user space and the kernel space;
[0022] Use the relevant fields including the certificate chain and cipher suite information in the TLS protocol to decode the encrypted content in the TLS packet, restore the original plaintext data. This process is completed in the kernel state, with high efficiency and low performance overhead, and restore the decrypted TLS message data to the plaintext message. Among them, the message can include Web requests, response headers, Cookies, URLs, POST data, etc., providing detailed network communication information.
[0023] A further improvement of the technical solution of the present invention lies in: in S2, the process of generating the persistent file specifically includes:
[0024] Use the probe service to obtain the decrypted plaintext data from the memory, select the generation of the persistent file according to the computing power of the security monitoring node and the function of the data liquidity security management system, and then generate the persistent file and write it to disk;
[0025] Select the written message according to the configuration parameters, and then write the decrypted data into the specified persistent file.
[0026] A further improvement of the technical solution of the present invention lies in: in S3, the process of triggering the reporting mechanism specifically includes:
[0027] When the probe service starts, load the gRPC client configuration file, which contains information such as the address and port of the remote server, and initialize the gRPC client to establish a connection with the remote data liquidity security management system, ensuring that the gRPC client configuration is correct and can successfully connect to the remote server;
[0028] The probe service scans the local persistent file directory and checks whether the time and size of the persistent files reach the preset standard thresholds.
[0029] When the persistent files reach the preset standard thresholds, the probe service triggers a reporting mechanism and prepares to report data, including the list of files to be transmitted and file information.
[0030] The persistent files are transmitted in stream form through the gRPC connection to the remote data mobility security management system. After receiving the persistent files, the remote data mobility security management system sends a confirmation message to the probe service. After receiving the confirmation message, the probe service performs file cleaning operations, such as deleting the transmitted files and updating the file status.
[0031] A further improvement of the technical solution of the present invention is that in S4, the process of detecting potential security threats in the traffic specifically includes:
[0032] The gRPC server receives the encrypted data from the probe service through the established gRPC connection, ensures the stability and reliability of the gRPC connection, avoids data loss or transmission errors, and decrypts the received encrypted data using a preset decryption algorithm and key to restore the original data for subsequent protocol field extraction and security analysis.
[0033] The decrypted data is parsed to extract the key information of the request header, request body, response header, and response body. Among them, the key information includes URL, request method, request parameters, response status code, and response content, etc., to ensure the accuracy and integrity of protocol field extraction and avoid missing key information.
[0034] Security analysis is performed on the extracted protocol fields to detect potential security threats in the traffic, including malicious requests, data leakage, DDoS attacks, etc. Among them, the characteristics of malicious requests are detected, the traffic pattern is analyzed, abnormal or suspicious behaviors are identified, and the response content is checked to ensure that no sensitive information is leaked.
[0035] A further improvement of the technical solution of the present invention is that in S5, the process of generating real-time alarms specifically includes:
[0036] A predefined security rule set is used to analyze the extracted protocol fields to detect potential security threats. Among them, the security rules include malicious request characteristics, traffic pattern analysis, and response content check, and historical data is combined to analyze normal behaviors and identify requests that deviate from normal behaviors.
[0037] According to the results of security analysis, corresponding threat response measures are taken. If a malicious attack or abnormal behavior is detected, the attack source can be blocked immediately, and relevant logs and alarm information are recorded. If further investigation or handling is required, the relevant information can be sent to the administrator for subsequent processing to ensure the timeliness and effectiveness of threat response, avoid the spread and escalation of security threats, and record detailed logs and alarm information for subsequent analysis and auditing;
[0038] When the data analysis results meet the set alarm conditions, the system automatically generates alarm information. Among them, the alarm information includes the alarm type, trigger conditions, occurrence time, and recommended response measures, and distributes the alarm information to the administrator through multiple channels such as email, SMS, and push notifications.
[0039] In a second aspect, a probe device for implementing the encrypted traffic capture and security event analysis method is used to implement the encrypted traffic capture and security event analysis method, including an eBPF program module, a packet restoration module, a storage module, and a communication module. Among them, the modules are electrically connected to each other;
[0040] The eBPF program module is used to capture the decrypted data of TLS traffic;
[0041] The packet restoration module is used to convert the captured data into the original protocol format;
[0042] The storage module is used to store the restored packets as persistent files;
[0043] The communication module is used to send the persistent file to the remote security analysis system through the gRPC protocol.
[0044] In a third aspect, a remote security analysis device is used to implement the probe device for implementing the encrypted traffic capture and security event analysis method, including a receiving module, an analysis module, and an alarm module. Among them, the modules are electrically connected to each other;
[0045] The receiving module is used to receive the persistent packet file transmitted by the probe device;
[0046] The analysis module is used to extract fields and perform in-depth analysis on the packet file to detect potential security threats;
[0047] The alarm module is used to generate security event alarm information.
[0048] In a fourth aspect, a computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, the encrypted traffic capture and security event analysis method is implemented.
[0049] Due to the above technical solution, the technical progress achieved by the present invention compared with the prior art is as follows:
[0050] The present invention provides a method, device, equipment and medium for encrypted traffic capture and security event analysis. By means of non-invasive deployment, the problem of TLS decryption is solved. Using eBPF to operate in the kernel state, when capturing TLS traffic and session data, it does not depend on any changes in a specific protocol stack or application layer. Especially in a dynamically expanding distributed system, the deployment is more flexible, without modifying the application code, and a probe service with non-invasive impact can be deployed at low cost.
[0051] The present invention provides a method, device, equipment and medium for encrypted traffic capture and security event analysis. By means of distributed design, the capture and analysis functions are decoupled. Adopting a distributed architecture design reduces the dependence on local performance, and at the same time improves scalability and flexibility.
[0052] The present invention provides a method, device, equipment and medium for encrypted traffic capture and security event analysis. By transmitting data through gRPC, the direct exposure of sensitive information is avoided, and the security and compliance of the system are improved.
[0053] The present invention provides a method, device, equipment and medium for encrypted traffic capture and security event analysis. It supports a distributed architecture, can flexibly adapt to the cloud native environment and large-scale deployment, provides higher scalability than traditional single-machine or local solutions, transmits data through gRPC, avoids direct dependence on the decryption buffer, and supports the deployment requirements in a multi-tenant and distributed environment.
[0054] The present invention provides a method, device, equipment and medium for encrypted traffic capture and security event analysis, covering the complete process from traffic capture, decryption to field extraction and security event warning, and can adapt to the multi-scenario requirements such as traffic analysis, threat detection and compliance auditing. Compared with the patents that are only limited to traffic capture in the past, the practical value is increased. Description of the Drawings
[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.
[0056] Figure 1 It is a schematic diagram of the working process of the present invention. Detailed Embodiments
[0057] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0058] Embodiment 1, as Figure 1 shown, the present invention provides a method for capturing encrypted traffic and analyzing security events, including the following steps:
[0059] Build a data security protection system, deploy a probe service on the server side of the TLS encryption application, use eBPF technology to capture TLS encrypted traffic in the network stack of the operating system, confirm whether the application server where the probe service is deployed supports eBPF technology, deploy the probe service on the application server that supports the TLS protocol, and load the eBPF program. Among them, the probe service includes the eBPF program, which is designed to hook at specific positions in the network stack to listen for and capture TLS traffic in network communications. When the TLS encrypted traffic passes through the server's network stack, the eBPF program hooks into the TLS-related function call points in the operating system kernel mode through the uprobes mechanism, specifically hooking the two user-mode functions SSL_write and SSL_read, and then identifies and captures the data packets of the TLS encrypted traffic. Extract the metadata of the TLS data packets through the eBPF program, transfer it to the probe service through the communication mechanism between the user space and the kernel space, and restore the original HTTP plaintext data. This process is completed in the kernel mode, with high efficiency and low performance overhead, and restore the decrypted TLS message data to the plaintext HTTP message. Among them, the HTTP message can include content such as Web requests, response headers, Cookies, URLs, POST data, etc., providing detailed network communication information; the probe service periodically obtains the decrypted data from the memory and generates it into a persistent file; use the probe service as a gRPC client, when the persistent file reaches the preset standard, trigger the reporting mechanism, and transmit the persistent file to the remote data mobility security management system through the gRPC protocol; use the remote data mobility security management system as a gRPC server, perform further protocol field extraction and security analysis on the decrypted HTTP data, and detect potential security threats in the traffic; after the data analysis is completed on the remote server, generate real-time alarms according to the analysis results and respond to potential security events. The encrypted traffic capture and security event analysis method uses eBPF technology to directly capture the decrypted data of TLS traffic from the server-side kernel mode, realizes the transparent decryption process, avoids the high overhead and data loss problems of traditional user-mode packet capture, restores the TLS traffic to the original protocol format (such as HTTP message) without loss, retains the complete data context, and provides high-quality input for in-depth security analysis; supports the decryption of TLS 1.2 and TLS 1.3 protocols, solves the problem that the forward secrecy (PFS) in the TLS 1.3 protocol causes traditional decryption schemes to fail, integrates persistent storage and gRPC transmission, optimizes the data transfer efficiency in a distributed environment, adapts to the needs of large-scale traffic analysis, combines with a remote security analysis system, and through field extraction and in-depth analysis, real-time identifies potential security threats and generates event alarms;
[0060] The data security protection system includes a probe device and a remote security analysis device;
[0061] Among them, the probe device is deployed on the server side that supports the TLS protocol, and captures TLS decryption data through eBPF;
[0062] The remote security analysis device is used to receive the decrypted packet file transmitted by the probe device, deeply analyze the data, and generate security alerts.
[0063] Embodiment 2, as Figure 1 shown, on the basis of Embodiment 1, the present invention provides a technical solution: Preferably, the process of generating the persistent file specifically includes:
[0064] Use the probe service to obtain the decrypted HTTP plaintext data from the memory, select the generation of the persistent file according to the computing power of the security monitoring node and the function of the data liquidity security management system, and then generate the persistent file to be stored on the disk. Among them, for the selection of generating the persistent file, it is specifically two methods of directly outputting the decrypted HTTP byte stream to the pcapng file; for directly outputting the decrypted HTTP byte stream to the pcapng file, the requirements for the monitoring node are that it consumes a lot of resources, and rewriting the original packet sub-stream to output to the pcapng file, the requirements for the data liquidity security management system are: low requirements, just analyze the HTTP traffic security events, select the disk-written packets according to the configuration parameters, and then write the decrypted data into the specified persistent file. Among them, taking HTTPS traffic as an example, the FULL mode processes all eligible packets, including TCP handshakes, TLS key negotiations, information interactions, etc., and the SIMPLE mode only processes the truly valid traffic packets, and only writes the decrypted HTTP packets to the disk, which can effectively reduce the file size;
[0065] The process of triggering the reporting mechanism specifically includes:
[0066] When the probe service starts, it loads the gRPC client configuration file, which contains information such as the address and port of the remote server, initializes the gRPC client, establishes a connection with the remote data liquidity security management system, ensures that the gRPC client configuration is correct and can successfully connect to the remote server. The probe service scans the local persistent file directory and checks whether the time and size of the persistent file reach the preset standard threshold. When the persistent file reaches the preset standard threshold, the probe service triggers the reporting mechanism and prepares to report data, including the list of files to be transmitted and file information, and transmits the persistent file to the remote data liquidity security management system in the form of a stream through the gRPC connection. After receiving the persistent file, the remote data liquidity security management system sends an acknowledgment message to the probe service. After receiving the acknowledgment message, the probe service performs file cleanup operations, such as deleting the transmitted files and updating the file status;
[0067] The process of detecting potential security threats in traffic specifically includes:
[0068] The gRPC server receives encrypted HTTP data from the probe service through the established gRPC connection, ensuring the stability and reliability of the gRPC connection, avoiding data loss or transmission errors, and decrypting the received encrypted data using a preset decryption algorithm and key to restore the original HTTP data for subsequent protocol field extraction and security analysis. Parse the decrypted HTTP data to extract the key information of the request header, request body, response header, and response body. Among them, the key information includes URL, request method, request parameters, response status code, and response content, etc., ensuring the accuracy and integrity of protocol field extraction and avoiding missing key information. Conduct security analysis on the extracted protocol fields to detect potential security threats in the traffic, including malicious requests, data leakage, DDoS attacks, etc. Among them, detect malicious request characteristics, analyze traffic patterns, identify abnormal or suspicious behaviors, and check the response content to ensure that no sensitive information is leaked;
[0069] The process of generating real-time alerts specifically includes:
[0070] Use a predefined set of security rules to analyze the extracted protocol fields to detect potential security threats. Among them, the security rules include malicious request characteristics, traffic pattern analysis, and response content checking, and combine historical data to analyze normal behaviors and identify requests that deviate from normal behaviors. According to the results of the security analysis, take corresponding threat response measures. If a malicious attack or abnormal behavior is detected, the attack source can be blocked immediately, and relevant logs and alarm information can be recorded. If further investigation or processing is required, the relevant information can be sent to the administrator for subsequent processing to ensure the timeliness and effectiveness of threat response and avoid the spread and escalation of security threats. Record detailed logs and alarm information for subsequent analysis and auditing. When the data analysis results meet the set alarm conditions, the system automatically generates alarm information. Among them, the alarm information includes the alarm type, trigger condition, occurrence time, and recommended response measures, and distributes the alarm information to the administrator through multiple channels such as email, SMS, and push notifications.
[0071] Embodiment 3, as Figure 1 shown, on the basis of Embodiments 1-2, the present invention further provides a probe device for implementing the encrypted traffic capture and security event analysis method, used to implement the encrypted traffic capture and security event analysis method, including an eBPF program module, a message restoration module, a storage module, and a communication module, wherein, the modules are electrically connected to each other;
[0072] The eBPF program module is used to capture the decrypted data of TLS traffic;
[0073] The message restoration module is used to convert the captured data into the original protocol format;
[0074] The storage module is used to store the restored message as a persistent file;
[0075] The communication module is used to send the persistent file to the remote security analysis system through the gRPC protocol;
[0076] In addition, a remote security analysis device, which is a probe device used to implement the encrypted traffic capture and security event analysis method, includes a receiving module, an analysis module, and an alarm module, where the modules are electrically connected to each other;
[0077] The receiving module is used to receive the persistent message file transmitted by the probe device;
[0078] The analysis module is used to extract fields from the message file and perform in-depth analysis to detect potential security threats;
[0079] The alarm module is used to generate security event alarm information;
[0080] Furthermore, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the encrypted traffic capture and security event analysis method;
[0081] Generally speaking, the computer instructions for implementing the method of the present invention can be carried by any combination of one or more computer-readable storage media. The computer-readable storage medium can include any computer-readable medium, except for the signal itself propagating temporarily.
[0082] The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.
[0083] Computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. In particular, the Python language suitable for neural network computing and platform frameworks based on TensorFlow, PyTorch, etc. can be used. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or connected to an external computer (for example, connected through the Internet using an Internet service provider).
[0084] For the above-mentioned computer-readable storage medium, reference can be made to the implementation content and its beneficial effects described in detail for the above-mentioned method, which will not be elaborated here.
[0085] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. Encrypted traffic capture and security incident analysis method, characterized in that: The following steps are involved: S1. Build a data security protection system, deploy a probe service on the server side of the TLS encryption application, and use eBPF technology to capture TLS encrypted traffic in the network stack of the operating system; S2. The probe service obtains the decrypted data from the memory and generates it as a persistent file; S3. Use the probe service as a gRPC client. When the persistent file reaches the preset standard, the reporting mechanism is triggered and the persistent file is transmitted to the remote data liquidity security management system through the gRPC protocol. S4. Use the remote data liquidity security management system as the gRPC server to further extract protocol fields and perform security analysis on the decrypted data to detect potential security threats in the traffic. S5. After the remote server completes the data analysis, it generates real-time alerts based on the analysis results and responds to potential security incidents; The data security protection system includes a probe device and a remote security analysis device; The probe device is deployed on a server supporting the TLS protocol, and captures TLS decrypted data through eBPF; The remote security analysis device is used to receive the decrypted message file transmitted by the probe device, perform in-depth analysis on the data, and generate a security alarm; In S1, the process of capturing TLS encrypted traffic specifically includes: Confirm whether the application server where the probe service is deployed supports eBPF technology; Deploy a probe service on an application server that supports the TLS protocol and load the eBPF program, where the probe service includes the eBPF program. When TLS encrypted traffic passes through the server's network stack, the eBPF program hooks into TLS-related function call points in the operating system kernel state through the uprobe mechanism, thereby identifying and capturing data packets of TLS encrypted traffic, extracting metadata of TLS data packets through the eBPF program, and passing it to the probe service through the communication mechanism between user space and kernel space; Decrypt the encrypted content in the TLS data packet using the relevant fields in the TLS protocol, including the certificate chain and encryption suite information, to recover the original plaintext data, and then restore the decrypted TLS message data to the plaintext message; In S2, the process of generating a persistent file specifically includes: The probe service is used to obtain the decrypted plaintext data from the memory, and the selection of persistent file generation is performed according to the computing power of the security monitoring node and the function of the data liquidity security management system, and then the persistent file is generated and stored on the disk; The disk message is selected according to the configuration parameters, and the decrypted data is written to the specified persistent file.
2. The method for capturing encrypted traffic and analyzing security events according to claim 1, characterized in that: In S3, the process of triggering the reporting mechanism specifically includes: When the probe service starts, it loads the gRPC client configuration file, initializes the gRPC client, and establishes a connection with the remote data liquidity security management system; The probe service scans the local persistent file directory and checks whether the persistent file time and size reach the preset standard threshold; When the number of persistent files reaches the preset standard threshold, the probe service triggers the reporting mechanism and prepares to report data, including the list of files to be transferred and file information; The persistent file is transmitted to the remote data liquidity security management system in the form of a stream through the gRPC connection. After receiving the persistent file, the remote data liquidity security management system sends a confirmation message to the probe service. After receiving the confirmation message, the probe service performs the file cleanup operation.
3. The method for capturing encrypted traffic and analyzing security events according to claim 2, characterized in that: In S4, the process of detecting potential security threats in traffic specifically includes: The gRPC server receives the encrypted data from the probe service through the established gRPC connection, and decrypts the received encrypted data using the preset decryption algorithm and key to restore the original data; Parse the decrypted data and extract the key information of the request header, request body, response header and response body, where the key information includes URL, request method, request parameters, response status code and response content; Perform security analysis on the extracted protocol fields to detect potential security threats in the traffic, including malicious requests, data leakage, and DDoS attacks. Among them, detect malicious request features, analyze traffic patterns, identify abnormal or suspicious behaviors, and check the response content to ensure that no sensitive information is leaked.
4. The method for capturing encrypted traffic and analyzing security events according to claim 3, characterized in that: In S5, the real-time alarm generation process specifically includes: Use predefined security rule sets to analyze extracted protocol fields and detect potential security threats. Security rules include malicious request characteristics, traffic pattern analysis, and response content inspection. Combined with historical data, analyze normal behavior and identify requests that deviate from normal behavior. Take appropriate threat response measures based on the results of security analysis. If malicious attacks or abnormal behaviors are detected, the attack source can be immediately blocked and relevant logs and alarm information can be recorded. If further investigation or processing is required, the relevant information can be sent to the administrator for follow-up processing, and detailed logs and alarm information can be recorded; When the data analysis results meet the set alarm conditions, the system automatically generates alarm information, which includes the alarm type, trigger conditions, occurrence time and recommended response measures, and distributes the alarm information to administrators through multiple channels such as email, SMS and push notifications.
5. A probe device for implementing the encrypted traffic capture and security event analysis method, used to implement the encrypted traffic capture and security event analysis method as described in any one of claims 1 to 4, characterized in that: It includes an eBPF program module, a message restoration module, a storage module, and a communication module, wherein the modules are connected by electrical signals; The eBPF program module is used to capture decrypted data of TLS traffic; The message restoration module is used to convert the captured data into the original protocol format; The storage module is used to store the restored message as a persistent file; The communication module is used to send the persistent file to the remote security analysis system through the gRPC protocol.
6. A remote security analysis device, used to implement the probe device for implementing the encrypted traffic capture and security event analysis method as claimed in claim 5, characterized in that: It includes a receiving module, an analyzing module and an alarm module, wherein the modules are connected by electrical signals; The receiving module is used to receive a persistent message file transmitted by the probe device; The analysis module is used to extract fields and conduct in-depth analysis on message files to detect potential security threats; The alarm module is used to generate security event alarm information.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the encrypted traffic capture and security event analysis method as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Method for capturing network flow and Kubernetes cluster
CN111901203A
Traffic collection and blocking method, system and device and storage medium
CN115514583A
Data security detection method and device based on eBPF, equipment and medium
CN117061166A
Session key capture and security event analysis method and device, equipment and medium
CN119854046A