Hidden network construction method and system combining anonymous network and protocol camouflage

By combining anonymous networks and protocol disguise, an overall framework for initial hidden networks is built, which solves the problem that user privacy is easily leaked on the Internet, and realizes efficient protection of user privacy and anti-analysis capabilities of communication content.

CN119966748AActive Publication Date: 2025-05-09NO 15 INST OF CHINA ELECTRONICS TECH GRP

Patent Information

Application Number
CN202510250420.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-05-09
Estimated Expiration
2045-03-04

AI Technical Summary

Technical Problem

In the era of big data, user privacy is easily leaked and identified by attackers on the Internet. The existing anonymous network and protocol disguise technology are limited in effect and are easily discovered.

Method used

Combining anonymous network and protocol disguise, an overall framework for the initial hidden network is built, and the overall framework for the target hidden network is formed through source protocol disguise, transit network path jump and data verification.

Benefits of technology

Effectively improve the level of user privacy protection, prevent information leakage and attack positioning of network actors, and enhance the ability to resist analysis of communication content.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966748A_ABST
    Figure CN119966748A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network security and communication privacy protection. The hidden network construction method combining the anonymous network and the protocol camouflage comprises the steps that an initial hidden network overall framework is constructed, and the initial hidden network overall framework comprises initial source protocol camouflage and initial transfer network path jump; according to the protocol camouflage of the tunnel, selecting the tunnel and adjusting the initial source protocol camouflage to obtain a target source protocol camouflage; performing transfer configuration of the initial transfer network path jump by using a transfer node to obtain a target transfer network path jump; and disguising the target source protocol and skipping the target transfer network path, and performing data verification to obtain a target hidden network overall framework. Through the method, the subject information of network behaviors can be disturbed, and the problems of privacy disclosure, attack positioning and the like caused by user feature portraits in the big data era are effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of network security and communication privacy protection, and in particular, relates to a covert network construction method and system combining anonymous network and protocol camouflage. Background Art

[0002] In the context of the rapid development of the Internet, data sources are diverse and have low value density, which makes computer networks face serious risks of information leakage. When users search, log in, order food, shop, travel and logistics, they will leave traces of network behavior such as search keywords, browsing history, download history, etc. on websites or applications. Through this information, combined with association analysis, aggregated profiling and other technologies, network attackers can infer the user's identity, address, occupation, hobbies, personality, income, political inclination, social relations and behavioral characteristics, and even obtain the user's account password and communication content through information cracking, and then carry out attacks such as precision delivery, infiltration and stealing. Therefore, in the era of big data, user privacy protection has become an issue that needs to be solved urgently.

[0003] To meet this challenge, anonymous network and protocol camouflage technologies are widely used. However, these technologies alone are often of limited effectiveness and are easily detected by attackers. To this end, the present invention proposes a method for constructing a covert network that combines anonymous networks with protocol camouflage. The method starts from three levels: address camouflage, identity concealment, and content hiding, aiming to achieve anti-tracing of user transmission channels and anti-analysis of communication content, thereby effectively improving the level of user privacy protection. Summary of the invention

[0004] Based on this, it is necessary to provide a covert network construction method that combines anonymous network and protocol camouflage to address the above technical problems.

[0005] In a first aspect, the present application provides a method for constructing a covert network combining an anonymous network and protocol camouflage, the method comprising:

[0006] Constructing an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol camouflage and initial transit network path jump;

[0007] According to the protocol disguise of the tunnel, by selecting a tunnel, adjusting the initial source protocol disguise, and obtaining the target source protocol disguise;

[0008] Using the transit node, performing the transit configuration of the initial transit network path jump to obtain the target transit network path jump;

[0009] The target source protocol camouflage and the target transit network path jump are subjected to data verification to obtain the overall framework of the target hidden network.

[0010] In some practicable ways, the step of constructing the overall framework of the initial hidden network includes:

[0011] According to a plurality of preset tunnel protocol camouflage strategies and protocol selection rule parameters, a tunnel protocol camouflage strategy is obtained, wherein the protocol selection rule parameters include at least one of a user's access address, an access keyword, an access time period, and a location of a destination website service provider;

[0012] According to the tunnel protocol camouflage strategy, an initial source protocol camouflage is obtained;

[0013] Deploy a transit node resource pool based on the Tor network to form the anonymous network, wherein the transit node resource pool includes network status evaluation, backhaul strategy and control node dynamic routing selection rules;

[0014] According to the anonymous network, an initial transit network path jump is obtained.

[0015] In some practicable manners, the step of adjusting the initial source protocol masquerade according to the protocol masquerade of the tunnel by selecting a tunnel to obtain the target source protocol masquerade includes:

[0016] According to the protocol selection rule parameters, one of the preset multiple tunnel protocol camouflage strategies is dynamically selected in the tunnel protocol camouflage strategy to obtain the target source protocol camouflage.

[0017] In some practicable methods, the step of dynamically selecting one of a plurality of preset tunnel protocol camouflage strategies in the tunnel protocol camouflage strategy according to the protocol selection rule parameter to obtain the target source protocol camouflage includes:

[0018] According to the protocol selection rule parameters, one of the preset multiple tunnel protocol camouflage strategies is selected in the tunnel protocol camouflage strategy to obtain the current source protocol camouflage;

[0019] The current source protocol camouflage is monitored. If the current source protocol camouflage is in an abnormal state, in the tunnel protocol camouflage strategy, based on a preset selection order rule, one of the preset multiple tunnel protocol camouflage strategies is dynamically selected to obtain the target source protocol camouflage.

[0020] In some practicable manners, the step of using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump includes:

[0021] Use network status evaluation to evaluate the reliability of transit nodes and obtain a list of available nodes;

[0022] Using the return strategy, the available node list is returned to the directory server, and the directory server is used to update the available node list to obtain a reliable transit node list;

[0023] The control node dynamic routing selection rule is utilized to select a transit node in the reliable transit node list to obtain a target transit network path jump.

[0024] In some practicable manners, the step of using the control node dynamic routing selection rule to select a transit node in the reliable transit node list to obtain a target transit network path jump includes:

[0025] The calculation formula for selecting a transfer node from the reliable transfer node list is:

[0026]

[0027] Among them, s i represents the comprehensive score of transit node i, w k represents the weight of the kth evaluation dimension, satisfying f k (x ik ) represents the scoring function of the kth evaluation dimension, and the original parameter x ik Convert to a standardized score (0-1), x ik represents the original parameter value of node i on the kth evaluation dimension, and n represents the total number of evaluation dimensions.

[0028] In some practicable manners, the step of using the return strategy to return the available node list to the directory server, and using the directory server to update the available node list to obtain a reliable transit node list includes:

[0029] Selecting a node from the transit nodes in the transit node resource pool as a directory server to obtain a node directory server;

[0030] The node directory server is used to receive the available node list sent thereto, and the directory server is used to update the available node list to obtain a reliable transit node list.

[0031] In some practicable manners, the step of using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump further includes:

[0032] An encryption and decryption strategy is deployed for each of the transfer nodes.

[0033] In some practicable methods, the step of performing data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network includes:

[0034] Build an initial end-to-end validation model;

[0035] The parameters corresponding to the historical source protocol disguise and the historical transit network path jump are subjected to feature fusion to obtain an initial unified vector for splicing;

[0036] Inputting the concatenated initial unified vector into the initial end-to-end verification model to obtain a target end-to-end verification model;

[0037] Disguise the target source protocol and redirect the target transit network path to form a spliced ​​target unified vector, input the target end-to-end verification model, perform data verification, and obtain a verification result;

[0038] According to the verification result, the initial hidden network overall framework is adjusted to obtain the target hidden network overall framework.

[0039] In a second aspect, the present application provides a covert network construction system combining an anonymous network with protocol camouflage, which is applied to the aforementioned covert network construction method combining an anonymous network with protocol camouflage, and the system includes:

[0040] A construction unit, used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol camouflage and initial transit network path jump;

[0041] A camouflage unit, configured to adjust the initial source protocol camouflage according to the protocol camouflage of the tunnel by selecting a tunnel, and obtain a target source protocol camouflage;

[0042] A jump unit, used to use the transfer node to perform the transfer configuration of the initial transfer network path jump to obtain the target transfer network path jump;

[0043] The verification result unit is used to perform data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network.

[0044] Beneficial effect: A hidden network construction method combining an anonymous network with protocol camouflage, constructing an initial hidden network overall framework, wherein the initial hidden network overall framework includes an initial source protocol camouflage and an initial transit network path jump; according to the protocol camouflage of the tunnel, by selecting a tunnel, adjusting the initial source protocol camouflage, and obtaining a target source protocol camouflage; using a transit node, performing a transit configuration of the initial transit network path jump, and obtaining a target transit network path jump; performing data verification on the target source protocol camouflage and the target transit network path jump, and obtaining a target hidden network overall framework. Through the above method, the subject information of network behavior can be disrupted, and the problems of privacy leakage and attack positioning caused by user feature profiling in the big data era can be effectively avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the conventional technology, the drawings required for use in the embodiments or the conventional technology descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0046] Figure 1 The present invention is a flowchart of a method for constructing a covert network by combining an anonymous network with protocol camouflage in one embodiment. DETAILED DESCRIPTION

[0047] In order to facilitate understanding of the present application, the present application will be described more fully below with reference to the relevant drawings. Embodiments of the present application are provided in the drawings. However, the present application can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive.

[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The term "and / or" used herein includes any and all couplings of one or more related listed items.

[0049] It can be understood that the terms "first", "second", etc. used in the present application can be used in this article to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from another element.

[0050] Some terms involved in this application are explained below to facilitate understanding of this application:

[0051] HTTP tunneling is a technology that uses the HTTP protocol (usually HTTP / 1.1 or HTTP / 2) to establish a communication channel between the client and the server.

[0052] DNS tunneling is a technology that uses the DNS protocol to transmit data. It bypasses the monitoring of network firewalls or other security devices by encapsulating data in DNS queries and responses.

[0053] ICMP tunneling is a technology that uses the ICMP protocol (Internet Control Message Protocol) for data transmission. It bypasses the monitoring of network firewalls or other security devices by encapsulating data in ICMP packets (such as ping requests and responses) for transmission.

[0054] The Tor network (The Onion Router) is an anonymous communication network designed to protect the privacy and anonymity of users, enabling users to browse, communicate and access the Internet anonymously.

[0055] Heartbeat Channel is a dedicated communication channel used to maintain connections, detect node survival status, and synchronize key information.

[0056] Minimum Viability Mode is an emergency communication mechanism. When all preset tunnel protocols (such as HTTP / DNS / ICMP tunnels) fail to work properly, the system automatically downgrades to the most basic and most compatible communication method to maintain minimum network connectivity.

[0057] like Figure 1 As shown, in the first aspect, the present application provides a method for constructing a covert network combining an anonymous network and protocol camouflage, the method comprising:

[0058] S100, construct the overall framework of the initial hidden network.

[0059] The overall framework of the initial hidden network includes initial source protocol camouflage and initial transit network path jump.

[0060] Specifically, constructing the overall framework of the initial hidden network includes the following steps:

[0061] S101, obtaining a tunnel protocol masquerade strategy according to a plurality of preset tunnel protocol masquerade strategies and protocol selection rule parameters.

[0062] The protocol selection rule parameters include at least one of the user's access address, access keywords, access time period, and the location of the destination website service provider.

[0063] It should be noted that multiple tunnel protocol masquerading strategies may include HTTP tunnel, DNS tunnel, ICMP tunnel, etc.

[0064] According to the protocol selection rule parameters, one of HTTP tunnel, DNS tunnel, ICMP tunnel, etc. can be selected. In this way, a tunnel protocol camouflage strategy can be obtained by using a combination of preset multiple tunnel protocol camouflage strategies and protocol selection rule parameters.

[0065] The protocol selection rule parameters are shown in Table 1

[0066]

[0067] Table 1

[0068] S102, obtaining an initial source protocol camouflage according to the tunnel protocol camouflage strategy.

[0069] In the tunnel protocol camouflage strategy, HTTP tunnel, DNS tunnel and ICMP tunnel can be encapsulated to obtain the initial source protocol camouflage.

[0070] S103, deploying a transit node resource pool based on the Tor network to form the anonymous network.

[0071] The transit node resource pool includes network status evaluation, backhaul strategy and control node dynamic routing selection rules.

[0072] It should be noted that a transit node resource pool having network status evaluation, backhaul strategy and control node dynamic routing selection rules is deployed according to the Tor network, thereby forming the anonymous network.

[0073] Exemplarily, network status assessment may include node delay, bandwidth, online rate, load, etc.

[0074] The backhaul strategy means that the intermediate node encrypts the state information and sends it back to the directory server through reverse onion routing at each hop.

[0075] The control node dynamic routing selection rule can represent the rule for dynamic selection of nodes in the directory server.

[0076] S104, obtaining an initial transit network path jump according to the anonymous network.

[0077] It should be noted that the initial transit network path jump is formed based on the combination of network status evaluation, backhaul strategy and control node dynamic routing selection rules of the transit node resource pool deployed in the Tor network.

[0078] Through the above steps, the self-configuration, self-optimization and self-repair of the covert network can be achieved, providing a reliable infrastructure for high-security communication scenarios.

[0079] S200, according to the protocol masquerade of the tunnel, by selecting a tunnel, adjusting the initial source protocol masquerade, and obtaining a target source protocol masquerade.

[0080] Specifically, obtaining the target source protocol disguise may include:

[0081] According to the protocol selection rule parameters, one of the preset multiple tunnel protocol camouflage strategies is dynamically selected in the tunnel protocol camouflage strategy to obtain the target source protocol camouflage.

[0082] It should be noted that, by using the protocol selection rule parameters, a tunnel protocol camouflage strategy is dynamically selected in the encapsulated tunnel protocol camouflage strategy, and this tunnel protocol camouflage strategy is used as the target source protocol camouflage and applied to the initial hidden network overall framework. If the target source protocol camouflage is verified to be ok after subsequent steps, it will be used as part of the target hidden network overall framework.

[0083] Further, obtaining the target source protocol disguise may include the following steps:

[0084] S201, according to protocol selection rule parameters, in the tunnel protocol camouflage strategy, one of the preset multiple tunnel protocol camouflage strategies is selected to obtain the current source protocol camouflage.

[0085] It should be noted that the user's protocol selection rule parameters can be normalized (normalization adopts conventional normalization methods), and all parameters are converted into values ​​0-1. In this way, the user's access address, access keywords, access time period, and the location of the destination website service provider will obtain corresponding values ​​(the values ​​can be normalized based on preset rules). Next, a dynamic selection algorithm for weighted scoring is performed based on the preset weights of the user's access address, access keywords, access time period, and the location of the destination website service provider. In other words, a segment is preset for each measurement in multiple tunnel protocol camouflage strategies. In this way, after obtaining the weighted score, the corresponding tunnel protocol camouflage strategy is selected according to the segment that falls into it as the current source protocol camouflage, as part of the overall framework for building a hidden network.

[0086] S202, monitor the current source protocol camouflage, if the current source protocol camouflage is in an abnormal state, in the tunnel protocol camouflage strategy, based on a preset selection order rule, dynamically select one of the preset multiple tunnel protocol camouflage strategies to obtain the target source protocol camouflage.

[0087] Exemplarily, the monitoring indicators and thresholds of the monitoring indicators (the thresholds can be obtained by optimizing historical data, averaging, etc., for example, based on historical network performance data statistics, the user experience significantly decreases when the packet loss rate is >30% or the delay is >500ms) are shown in Table 2.

[0088]

[0089] Table 2

[0090] After obtaining the monitoring results of the monitoring indicators, they can be reported to the control center through the heartbeat channel after encryption. Next, the control center can evaluate the indicators based on the monitoring results.

[0091] Among them, the indicator evaluation can be calculated using a sliding window. For example, the delay indicator uses a 1-minute sliding window average, that is, if the delay is measured once every 5 seconds, it is measured 12 times in one minute, and the average of the 12 times is taken as the monitoring result of the delay indicator. If the indicator exceeds the threshold, the current protocol is marked as "abnormal state".

[0092] It should be noted that the aforementioned delay is only for illustrative purposes, and multiple conditions can also be combined for judgment, for example, by performing a weighted average calculation on the various indicators of packet loss rate, delay, firewall interception, and encryption failure (weights are assigned to packet loss rate, delay, firewall interception, and encryption failure, and the values ​​formed after normalization with the monitoring results are weighted), and then the value after weighted average calculation is obtained, and this value is used as the standard for protocol switching. A single monitoring indicator can also be used as the standard for switching.

[0093] For example, if the switch is triggered by a high packet loss rate, a protocol with higher bandwidth (such as HTTP tunnel) is preferred. Next, the new protocol key is pre-negotiated, encrypted transmission is carried out through the existing channel, the two protocols are run in parallel for 5 seconds, the old channel is gradually closed, and the routing table is updated to ensure that subsequent traffic uses the new protocol.

[0094] When a single monitoring indicator is used as the protocol standard for switching, for example, the monitoring indicator is: average latency = 650ms (lasting 1 minute), and the weight is adjusted according to the access period (peak): bandwidth weight 0.6. Scoring results: HTTP tunnel (bandwidth 0.9) > ICMP tunnel (0.5) > DNS tunnel (0.3). Switch to HTTP tunnel and enable dynamic port evasion censorship.

[0095] In addition, multiple conditions can be introduced for priority judgment. For example, if both the packet loss rate and the delay exceed the limit at the same time, the high-bandwidth protocol will be switched first. If all protocols fail, the minimum function mode will be enabled and an alarm will be issued.

[0096] In summary, based on the protocol disguise of the tunnel, the entry proxy before the initial transit network path jump repackages the normal http and https access traffic data, disguises it as another application layer protocol, uses the disguised protocol packet header, and uses the data content as the protocol payload. In the process of building the tunnel, multiple protocol disguise methods are pre-set, and protocol disguise selection rules are set. Different disguise protocols are selected according to multiple access attributes such as the user's access address, access keywords, access time period, and the location of the destination website service provider. In the selection of the protocol disguise method, dynamic disguise protocol adaptation rules are set to select the disguise protocol according to the user's source IP address segment and access attributes (such as access time, target access address type, etc.).

[0097] S300, using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump.

[0098] Specifically, obtaining the target transit network path jump may include the following steps:

[0099] S301, using network status evaluation, evaluate the reliability of the transfer node and obtain a list of available nodes.

[0100] Specifically, for network status assessment:

[0101] Latency: The average round-trip time (RTT) from the node to the target server is calculated through the ICMP Ping test. For example: RTT of node A = 150ms, RTT of node B = 300ms.

[0102] Bandwidth: Transmit a 1MB test file and measure throughput (unit: Mbps). For example: Node A bandwidth = 5Mbps, Node B bandwidth = 2Mbps.

[0103] Online rate: Count the heartbeat packet response rate of the node in the last hour (such as node A response rate = 98%, node B = 85%).

[0104] Load: The node agent reports the CPU and memory utilization (e.g., node A CPU = 30%, memory = 40%; node B CPU = 70%, memory = 80%).

[0105] When the threshold rules are latency ≤ 200ms, bandwidth ≥ 1Mbps, online rate ≥ 90%, CPU < 80%, and memory < 70%, node A: meets all conditions and is added to the list of available nodes. Node B: bandwidth = 2Mbps (reaches the standard), but memory = 80% (exceeds the standard), is removed.

[0106] It should be noted that the network status assessment runs an agent on each node to collect its own status data, and then encrypts the data and sends it back to the directory server through the heartbeat channel.

[0107] S302, using the return strategy, the available node list is returned to the directory server, and the directory server is used to update the available node list to obtain a reliable transfer node list.

[0108] The deployment of the directory server may include the following steps:

[0109] Selecting a node from the transit nodes in the transit node resource pool as a directory server to obtain a node directory server;

[0110] The node directory server is used to receive the available node list sent thereto, and the directory server is used to update the available node list to obtain a reliable transit node list.

[0111] This not only makes it easier to uniformly update and maintain the node list, but also provides high reliability. Dedicated nodes can be configured with higher-performance hardware to ensure stable services.

[0112] In addition, a reliable list of transit nodes is obtained. For example, during data transmission, TLS1.3 encryption can be used and the list of available nodes can be transmitted in JSON format.

[0113] Next, processing occurs in the directory server.

[0114] For example, in the directory server: deduplication and merging, merge multi-source data according to node ID, and keep the latest record. Historical stability marking, if the node online rate fluctuation is ≤5% in the past 7 days, mark it as a long-term reliable node. Generate a reliable list, remove nodes that fail the historical stability check, and output the final reliable transit node list.

[0115] S303, using the control node dynamic routing selection rule, selecting a transit node in the reliable transit node list to obtain a target transit network path jump.

[0116] The dynamic routing rules of the control node can be deployed on the entry proxy server or a dedicated control node. In this way, the entry proxy server selects the path according to its own needs without relying on the directory server for real-time calculation. In addition, the routing calculation is relatively complex, and the decentralized deployment can reduce the burden on the directory server.

[0117] It should be noted that the calculation formula for selecting the transfer node in the reliable transfer node list is:

[0118]

[0119] Among them, s i represents the comprehensive score of transit node i, w k represents the weight of the kth evaluation dimension, satisfying represents the scoring function of the kth evaluation dimension, converting the original parameter x ik Convert to a standardized score (0-1), x ik represents the original parameter value of node i on the kth evaluation dimension, and n represents the total number of evaluation dimensions.

[0120] Exemplarily, the calculation formula for selecting a transit node in the reliable transit node list is:

[0121]

[0122] Among them, s i represents the comprehensive score of transit node i, L i represents the delay of transit node i, B i represents the bandwidth of transit node i, R i represents the reliability of transit node i (0-1), w j It means weight w1+w2+w3=1;

[0123]

[0124] Among them, P i represents the probability of selecting the transfer node i, α represents the bandwidth weight parameter, and β represents the reliability weight parameter.

[0125] Finally, it should be noted that in step S300, the step of using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump also includes:

[0126] An encryption and decryption strategy is deployed for each of the transfer nodes.

[0127] Specifically, a lightweight encryption and decryption strategy is deployed for each of the transfer nodes, where lightweight means that the encryption and decryption program occupies less resources (such as CPU, memory), and is suitable for running on transfer nodes with limited performance. For example, efficient encryption algorithms such as AES-128 (instead of AES-256) or ChaCha20 are used. Lightweight encryption and decryption services ensure that the node processing speed is fast and will not become a bottleneck of network performance.

[0128] Furthermore, when constructing the transit network, an encryption and decryption program (such as an implementation of AES or ChaCha20) is installed on each node. Exemplarily, the encryption and decryption program is deployed using a Docker container or a system service. An independent encryption key is generated for each node (such as a dynamically negotiated key using an ECDH algorithm). In this way, the encryption and decryption program automatically runs when the node is started, waiting to process the data packet. When the data packet passes through the node, the encryption and decryption program automatically performs encryption or decryption operations.

[0129] The encryption and decryption strategy means that each node is responsible for encrypting or decrypting the data packets passing through to ensure that the data is not stolen or tampered with during transmission. For example, the entry node: encrypts the user data and then sends it to the next node. The intermediate node: decrypts the data of the previous hop, re-encrypts it and sends it to the next hop. The exit node: decrypts the data and sends it to the target server.

[0130] Data needs to be re-encrypted when transmitted between each hop node to prevent intermediate nodes from stealing data.

[0131] In summary, the transit network (transit network path jump) is constructed, and the transit network resource pool is constructed based on the structure of the Tor network, and network status evaluation, return function and control node dynamic routing selection rules are added to the relay node. During initialization, the transit network resource pool will select a node from the transit node as the directory server to deploy the transit node, that is, distribute lightweight encryption and decryption services to each transit node. The transit network entry proxy server requests the available relay node information from the directory server and sets a transparent transit network selection strategy (the strategy is invisible to users and external observers, and it runs automatically without manual configuration.), selects the hidden communication link based on the node status information and node communication quality returned by the transit network resource node, establishes a hidden link access path, and encrypts and encapsulates the disguised data packet.

[0132] S400, performing data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network.

[0133] Specifically, obtaining the overall framework of the target hidden network may include the following steps:

[0134] S401, construct an initial end-to-end verification model.

[0135] Specifically, the initial end-to-end verification model may use a fully connected neural network (FCN) or a support vector machine (SVM) as a basic model. The fully connected neural network (FCN) or the support vector machine (SVM) as a basic model are both conventional basic models.

[0136] Exemplarily, the training data includes:

[0137] Positive samples: historical successful cases (protocol masquerade + path jump).

[0138] Negative samples: historical failure cases (such as protocol being recognized, path being interrupted).

[0139] Data format: Each sample contains protocol parameters (such as protocol type, encryption algorithm) and path parameters (such as node delay, bandwidth).

[0140] S402, feature fusion is performed on the parameters corresponding to the historical source protocol disguise and the historical transit network path jump to obtain a spliced ​​initial unified vector.

[0141] For example, firstly, the parameters corresponding to the historical source protocol disguise and the historical transit network path jump are feature extracted in a conventional way. Protocol parameters: protocol type (one-hot encoding), encryption algorithm (such as AES=1, ChaCha20=2), encapsulation method (such as DNS subdomain encoding=1, ICMP payload padding=2). Path parameters: node delay (normalized), bandwidth (normalized), online rate (0~1).

[0142] Next, vector concatenation is performed to concatenate the protocol parameters and path parameters into a unified vector to form an initial unified vector. For example, protocol parameters: [1, 0, 0] (HTTP tunnel), [1] (AES encryption), [1] (DNS subdomain encoding). Path parameters: [0.15] (latency), [0.8] (bandwidth), [0.95] (online rate). Unified vector: [1, 0, 0, 1, 1, 0.15, 0.8, 0.95].

[0143] S403: Input the concatenated initial unified vector into the initial end-to-end verification model to obtain a target end-to-end verification model.

[0144] The target end-to-end validation model may refer to a model optimized to a validation set accuracy of more than 90%.

[0145] S404, disguise the target source protocol and redirect the target transit network path to form a concatenated target unified vector, input the vector into the target end-to-end verification model, perform data verification, and obtain a verification result.

[0146] Specifically, the target source protocol masquerading and the target transit network path jump parameters are concatenated into a unified vector, and the target unified vector is input into the target end-to-end verification model to obtain the verification result.

[0147] S405: According to the verification result, the initial hidden network overall framework is adjusted to obtain a target hidden network overall framework.

[0148] It should be noted that if the verification is successful, the current configuration is retained as the overall framework of the target hidden network. For example, the DNS tunnel + ChaCha20 encryption + path [node A → node B → node C] is continued to be used.

[0149] If verification fails, you can do the following:

[0150] Protocol adjustment: switch to an alternative tunnel protocol (such as switching from DNS tunnel to ICMP tunnel).

[0151] Path adjustment: Reselect the transit node (for example, remove the high-latency node D and replace it with node E).

[0152] Revalidate: Input the adjusted configuration into the model until validation passes.

[0153] In summary, the model can be used to quantitatively evaluate network configuration and reduce manual intervention. When verification fails, the protocol and path are automatically optimized to improve network robustness.

[0154] In one embodiment, a dedicated heartbeat channel based on TLS1.3 encryption is established during system operation, and each transit node is connected to at least three directory servers through a star topology. The channel sends a 128-byte heartbeat packet disguised as a DNS TXT record query (example: 3B1A.xn--kgbechtv format pseudo-domain name) in a 30-second period, and automatically increases to an intensive monitoring frequency of once per second when a communication anomaly is detected. The protocol failure judgment adopts a sliding window evaluation model, continuously obtains the protocol health score of the last five detection windows, and performs weighted calculations from three dimensions: port connectivity (weight 40%), network delay (weight 30%), and file throughput (weight 30%). If the last three scores are all below the 0.6 threshold, the emergency mechanism is triggered.

[0155] The specific plan of the emergency mechanism can be pre-set according to historical events to deal with the emergency mechanism. For example, the system can quickly restore communication through steps such as dynamically generating communication ports, encrypting data transmission, node discovery and path optimization.

[0156] The present application discloses a hidden network construction method combining an anonymous network with a protocol disguise, aiming to improve the privacy and security of network communication security. In view of the problem that personal information such as identity, address, occupation, hobbies, and social relationships of users are easily leaked when they surf the Internet, a hidden network construction method combining an anonymous network with a protocol disguise is proposed. A transit network is constructed between the user and the target network. The user's real address is hidden through dynamic link hopping and link address encryption, and a dynamic protocol disguise mechanism is adopted at the entrance agent of the transit network to prevent the user's access path from being intercepted and information leakage caused by deep content analysis. By fragmenting Internet behavior and hiding communication content, the information of the network behavior subject can be disrupted, and the information leakage and precision attack problems caused by the collection and feature profiling of user network behavior can be effectively avoided. The hidden network construction method constructed in this article is used in various communication scenarios that require high privacy and security, and has broad application prospects and practical value. Through dynamic strategy selection, mathematical routing decision-making and intelligent verification, the full life cycle management of the hidden network is realized, and manual intervention is reduced, especially in communication scenarios with high security requirements.

[0157] In a second aspect, the present application provides a covert network construction system combining an anonymous network with protocol camouflage, which is applied to the aforementioned covert network construction method combining an anonymous network with protocol camouflage, and the system includes:

[0158] A construction unit, used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol camouflage and initial transit network path jump;

[0159] A camouflage unit, configured to adjust the initial source protocol camouflage according to the protocol camouflage of the tunnel by selecting a tunnel, and obtain a target source protocol camouflage;

[0160] A jump unit, used to use the transfer node to perform the transfer configuration of the initial transfer network path jump to obtain the target transfer network path jump;

[0161] The verification result unit is used to perform data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network.

[0162] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0163] The various embodiments in the present disclosure are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.

[0164] The protection scope of the present disclosure is not limited to the above-mentioned embodiments. Obviously, those skilled in the art can make various changes and modifications to the present disclosure without departing from the scope and spirit of the present disclosure. If these changes and modifications fall within the scope of the claims of the present disclosure and their equivalents, the intention of the present disclosure also includes these changes and modifications.

Claims

1. A method for constructing a covert network combining an anonymous network and protocol camouflage, characterized in that: Methods include: Constructing an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol camouflage and initial transit network path jump; According to the protocol disguise of the tunnel, by selecting a tunnel, adjusting the initial source protocol disguise, and obtaining the target source protocol disguise; Using the transit node, performing the transit configuration of the initial transit network path jump to obtain the target transit network path jump; The target source protocol camouflage and the target transit network path jump are subjected to data verification to obtain the overall framework of the target hidden network.

2. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 1, characterized in that: The step of constructing the overall framework of the initial hidden network includes: According to a plurality of preset tunnel protocol camouflage strategies and protocol selection rule parameters, a tunnel protocol camouflage strategy is obtained, wherein the protocol selection rule parameters include at least one of a user's access address, an access keyword, an access time period, and a location of a destination website service provider; According to the tunnel protocol camouflage strategy, an initial source protocol camouflage is obtained; Deploy a transit node resource pool based on the Tor network to form the anonymous network, wherein the transit node resource pool includes network status evaluation, backhaul strategy and control node dynamic routing selection rules; According to the anonymous network, an initial transit network path jump is obtained.

3. The method for constructing a hidden network combining an anonymous network and protocol camouflage according to claim 2, characterized in that: The step of adjusting the initial source protocol disguise according to the tunnel protocol disguise by selecting a tunnel to obtain the target source protocol disguise comprises: According to the protocol selection rule parameters, one of the preset multiple tunnel protocol camouflage strategies is dynamically selected in the tunnel protocol camouflage strategy to obtain the target source protocol camouflage.

4. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 3 is characterized in that: The step of dynamically selecting one of a plurality of preset tunnel protocol camouflage strategies in the tunnel protocol camouflage strategy according to the protocol selection rule parameter to obtain the target source protocol camouflage comprises: According to the protocol selection rule parameters, one of the preset multiple tunnel protocol camouflage strategies is selected in the tunnel protocol camouflage strategy to obtain the current source protocol camouflage; The current source protocol camouflage is monitored. If the current source protocol camouflage is in an abnormal state, in the tunnel protocol camouflage strategy, based on a preset selection order rule, one of the preset multiple tunnel protocol camouflage strategies is dynamically selected to obtain the target source protocol camouflage.

5. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 2, characterized in that: The step of using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump includes: Use network status evaluation to evaluate the reliability of transit nodes and obtain a list of available nodes; Using the return strategy, the available node list is returned to the directory server, and the directory server is used to update the available node list to obtain a reliable transit node list; The control node dynamic routing selection rule is utilized to select a transit node in the reliable transit node list to obtain a target transit network path jump.

6. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 5, characterized in that: The step of using the control node dynamic routing selection rule to select a transit node in the reliable transit node list to obtain a target transit network path jump includes: The calculation formula for selecting a transfer node from the reliable transfer node list is: Among them, s i represents the comprehensive score of transit node i, w k represents the weight of the kth evaluation dimension, satisfying f k (x ik ) represents the scoring function of the kth evaluation dimension, and the original parameter x ik Convert to a standardized score (0-1), x ik represents the original parameter value of node i on the kth evaluation dimension, and n represents the total number of evaluation dimensions.

7. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 5, characterized in that: The step of using the return strategy to return the available node list to the directory server, and using the directory server to update the available node list to obtain a reliable transit node list includes: Selecting a node from the transit nodes in the transit node resource pool as a directory server to obtain a node directory server; The node directory server is used to receive the available node list sent thereto, and the directory server is used to update the available node list to obtain a reliable transit node list.

8. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 1, characterized in that: The step of using the transit node to perform the transit configuration of the initial transit network path jump to obtain the target transit network path jump also includes: An encryption and decryption strategy is deployed for each of the transfer nodes.

9. The method for constructing a covert network combining an anonymous network and protocol camouflage according to claim 1, characterized in that: The step of performing data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network includes: Build an initial end-to-end validation model; The parameters corresponding to the historical source protocol disguise and the historical transit network path jump are feature fused to obtain an initial unified vector for splicing; Inputting the concatenated initial unified vector into the initial end-to-end verification model to obtain a target end-to-end verification model; Disguise the target source protocol and redirect the target transit network path to form a spliced ​​target unified vector, input the target end-to-end verification model, perform data verification, and obtain a verification result; According to the verification result, the initial hidden network overall framework is adjusted to obtain the target hidden network overall framework.

10. A covert network construction system combining anonymous network and protocol camouflage, characterized in that: A method for constructing a covert network combining an anonymous network and protocol camouflage applied to any one of claims 1 to 9, the system comprising: A construction unit, used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol camouflage and initial transit network path jump; A camouflage unit, configured to adjust the initial source protocol camouflage according to the protocol camouflage of the tunnel by selecting a tunnel, and obtain a target source protocol camouflage; A jump unit, used to use the transfer node to perform the transfer configuration of the initial transfer network path jump to obtain the target transfer network path jump; The verification result unit is used to perform data verification on the target source protocol disguise and the target transit network path jump to obtain the overall framework of the target hidden network.

Citation Information

Patent Citations

  • Anonymous network dynamic link selection method and device

    CN112995142A

  • Anti-traceability heterogeneous resource deployment and optimal path planning method

    CN114205152A

  • Heterogeneous redundancy protocol resynchronization implementation method

    CN116233150A

  • Method for realizing high-quality transmission of voice streaming media in onion routing network

    CN117834593A

  • Ecological vulnerability graph-based Tor relay node vulnerability assessment method

    CN118413386A

Cited By

  • Network traffic auditing optimization defense method based on traffic feature camouflage

    CN120546982A

  • Network traffic auditing optimization defense method based on traffic feature camouflage

    CN120546982B