Anonymity network and protocol camouflage combined hidden network construction method and system

By combining anonymous networks with protocol spoofing to construct covert networks, and dynamically adjusting protocol spoofing and path hopping, the problem of insufficient privacy protection in existing technologies is solved, achieving efficient user privacy protection and making it suitable for high-security communication scenarios.

CN119966748BActive Publication Date: 2026-03-31NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing anonymous network and protocol masquerading technologies are easily detected by attackers when used alone, and cannot effectively protect user privacy, especially in the era of big data, where they face the risks of information leakage and attack location.

Method used

This paper combines anonymous networks and protocol masquerading to construct covert networks. By building an initial overall framework for the hidden network, including initial source protocol masquerading and relay network path jumping, and utilizing tunnel protocol masquerading and relay node resource pools, the protocol masquerading and path jumping are dynamically adjusted and data verification is performed to form the overall framework of the target hidden network.

Benefits of technology

It effectively disrupts the information of network actors, prevents the leakage of user profiles and privacy, improves the level of user privacy protection, and is suitable for high-security communication scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966748B_ABST
    Figure CN119966748B_ABST
Patent Text Reader

Abstract

The application belongs to the field of network security and communication privacy protection. A hidden network construction method combining anonymous network and protocol camouflage includes constructing an initial hidden network overall framework, wherein the initial hidden network overall framework includes an initial source protocol camouflage and an initial transit network path jump; according to the protocol camouflage of the tunnel, the initial source protocol camouflage is adjusted by selecting a tunnel to obtain a target source protocol camouflage; the initial transit network path jump is configured by using a transit node to obtain a target transit network path jump; and the target source protocol camouflage and the target transit network path jump are verified to obtain a target hidden network overall framework. Through the above method, the subject information of network behavior can be disturbed, and problems such as privacy leakage and attack positioning caused by user feature portrait in the big data era can be effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security and communication privacy protection, and in particular relates to a method and system for constructing covert networks that combine anonymous networks with protocol masquerading. Background Technology

[0002] In the context of rapid internet development, the diverse sources and low value density of data have exposed computer networks to serious risks of information leakage. Users leave traces of their online behavior on websites and applications through activities such as searching, logging in, ordering food, shopping, traveling, and logistics. Attackers can use this information, combined with techniques like correlation analysis and profile aggregation, to infer a user's identity, address, occupation, hobbies, personality, income, political leanings, social relationships, and behavioral characteristics. They can even use hacking techniques to obtain user account passwords and communication content, enabling targeted attacks, infiltration, and data theft. Therefore, in the era of big data, user privacy protection has become a pressing issue.

[0003] To address this challenge, anonymous networks and protocol masquerading techniques are widely used. However, using these techniques alone often has limited effectiveness and is easily detected by attackers. Therefore, this invention proposes a method for constructing covert networks that combines anonymous networks and protocol masquerading. This method addresses the issue from three levels: address masquerading, identity concealment, and content hiding, aiming to achieve anti-tracing of user transmission channels and resistance to analysis of communication content, thereby effectively improving the level of user privacy protection. Summary of the Invention

[0004] Therefore, it is necessary to provide a method for constructing covert networks that combines anonymous networks with protocol spoofing to address the aforementioned technical problems.

[0005] Firstly, this application provides a method for constructing a covert network that combines anonymous networks with protocol masquerading, the method comprising:

[0006] Construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol masquerading and initial transit network path hopping;

[0007] Based on the protocol masquerading of the tunnel, the target source protocol masquerading is obtained by selecting a tunnel and adjusting the initial source protocol masquerading;

[0008] By utilizing the relay node, the initial relay network path jump is configured to obtain the target relay network path jump;

[0009] Data verification is performed on the target source protocol spoofing and the target relay network path jump to obtain the overall framework of the target hiding network.

[0010] In some feasible approaches, the step of constructing the initial hidden network overall framework includes:

[0011] Based on multiple preset tunnel protocol masquerading strategies and protocol selection rule parameters, a tunnel protocol masquerading strategy is obtained. The protocol selection rule parameters include at least one of the following: user's access address, access keywords, access time period, and the location of the destination website service provider.

[0012] Based on the tunnel protocol masquerading strategy, the initial source protocol masquerading is obtained;

[0013] The anonymous network is formed by deploying a relay node resource pool based on the Tor network, wherein the relay node resource pool includes network status assessment, backhaul strategy and control node dynamic routing selection rules;

[0014] Based on the anonymous network, the initial transit network path is obtained.

[0015] In some feasible methods, the step of adjusting the initial source protocol spoofing to obtain the target source protocol spoofing by selecting a tunnel based on the tunnel's protocol spoofing includes:

[0016] Based on the protocol selection rule parameters, one of the preset tunnel protocol masquerading strategies is dynamically selected in the tunnel protocol masquerading strategy to obtain the target source protocol masquerading.

[0017] In some feasible methods, the step of dynamically selecting one of a plurality of preset tunnel protocol spoofing strategies from the tunnel protocol spoofing strategy according to the protocol selection rule parameters to obtain the target source protocol spoofing includes:

[0018] Based on the protocol selection rule parameters, one of the preset tunnel protocol masquerading strategies is selected from the tunnel protocol masquerading strategy to obtain the current source protocol masquerading.

[0019] The current source protocol spoofing is monitored. If the current source protocol spoofing is in an abnormal state, the tunnel protocol spoofing strategy dynamically selects one of a number of preset tunnel protocol spoofing strategies based on a preset selection order rule to obtain the target source protocol spoofing.

[0020] In some feasible methods, the step of using a relay node to configure the initial relay network path to obtain the target relay network path includes:

[0021] The reliability of relay nodes is assessed using network status evaluation to obtain a list of available nodes;

[0022] Using a backhaul strategy, the list of available nodes is backhauled to the directory server, and the directory server is used to update the list of available nodes to obtain a reliable list of relay nodes.

[0023] Using the dynamic routing rules of the control node, a transit node is selected from the list of reliable transit nodes to obtain the target transit network path jump.

[0024] In some feasible methods, the step of selecting a transit node from the list of reliable transit nodes using the dynamic routing rules of the control node to obtain the target transit network path includes:

[0025] The formula for selecting relay nodes from the list of reliable relay nodes is as follows:

[0026]

[0027] Among them, s i w represents the overall score of transit node i. k This represents the weight of the k-th evaluation dimension, satisfying... f k (x ik ) represents the scoring function for the k-th evaluation dimension, where the original parameter x is... ik Convert to standardized scores (0-1), x ik represents the original parameter value of node i in the k-th evaluation dimension, and n represents the total number of evaluation dimensions.

[0028] In some feasible methods, the step of using a backhaul strategy to send the list of available nodes back to the directory server, and using the directory server to update the list of available nodes to obtain a reliable list of relay nodes includes:

[0029] Select one node from the relay nodes in the relay node resource pool as a directory server to obtain the node directory server;

[0030] The system utilizes a node directory server to receive the list of available nodes sent to it, and uses the directory server to update the list of available nodes to obtain a reliable list of relay nodes.

[0031] In some feasible methods, the step of using a relay node to configure the initial relay network path to obtain the target relay network path further includes:

[0032] Deploy encryption and decryption strategies for each of the aforementioned relay nodes.

[0033] In some feasible methods, the step of performing data verification on the target source protocol spoofing and the target transit network path jump to obtain the overall framework of the target hidden network includes:

[0034] Build an initial end-to-end verification model;

[0035] The parameters corresponding to the historical source protocol spoofing and historical transit network path jump are fused to obtain a spliced ​​initial unified vector;

[0036] The concatenated initial unified vector is input into the initial end-to-end verification model to obtain the target end-to-end verification model;

[0037] The target source protocol spoofing and the target relay network path jump are combined to form a spliced ​​target unified vector, which is then input into the target end-to-end verification model for data verification to obtain the verification result.

[0038] Based on the verification results, the initial hidden network overall framework is adjusted to obtain the target hidden network overall framework.

[0039] Secondly, this application provides a covert network construction system that combines anonymous networks with protocol spoofing, applied to the aforementioned covert network construction method that combines anonymous networks with protocol spoofing. The system includes:

[0040] A construction unit is used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol masquerading and initial relay network path hopping;

[0041] The camouflage unit is used to camouflage according to the tunnel's protocol. By selecting a tunnel, the initial source protocol camouflage is adjusted to obtain the target source protocol camouflage.

[0042] The jump unit is used to configure the initial relay network path jump using the relay node, and obtain the target relay network path jump.

[0043] The verification result unit is used to perform data verification on the target source protocol spoofing and the target transit network path jump to obtain the overall framework of the target hidden network.

[0044] Beneficial Effects: A method for constructing covert networks combining anonymity and protocol masquerading constructs an initial overall framework for the hidden network. This initial framework includes initial source protocol masquerading and initial relay network path redirection. Based on the protocol masquerading of the tunnel, the initial source protocol masquerading is adjusted by selecting a tunnel to obtain a target source protocol masquerading. Relay nodes are used to configure the initial relay network path redirection to obtain a target relay network path redirection. Data verification is performed on the target source protocol masquerading and the target relay network path redirection to obtain the overall framework of the target hidden network. This method can disrupt the main information of network behavior, effectively avoiding privacy leaks and attack location issues caused by user profile profiling in the era of big data. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments of this application or the conventional technology, the drawings used in the description of the embodiments or the conventional technology will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is a flowchart of a method for constructing a covert network that combines anonymous network and protocol masquerading, as shown in one embodiment. Detailed Implementation

[0047] To facilitate understanding of this application, a more complete description will be provided below with reference to the accompanying drawings, which illustrate embodiments of the present application. However, the present application can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided so that the disclosure of this application will be thorough and complete.

[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein in the specification of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The term "and / or" as used herein includes any and all couplings of one or more of the associated listed items.

[0049] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish one element from another.

[0050] The following explanations of some terms used in this application are provided to aid in understanding the application:

[0051] HTTP tunneling is a technology that uses the HTTP protocol (usually HTTP / 1.1 or HTTP / 2) to establish a communication channel between a client and a server.

[0052] DNS tunneling is a technology that uses the DNS protocol for data transmission. It bypasses network firewalls or other security devices by encapsulating data in DNS queries and responses.

[0053] ICMP tunneling is a technology that uses the ICMP (Internet Control Message Protocol) for data transmission. It bypasses network firewalls or other security devices by encapsulating data in ICMP packets (such as ping requests and responses) for transmission.

[0054] Tor (The Onion Router) is an anonymous communication network designed to protect user privacy and anonymity, enabling users to browse, communicate, and access the internet anonymously.

[0055] A heartbeat channel is a dedicated communication channel used to maintain connections, detect node liveness, and synchronize critical information.

[0056] Minimum Viability Mode is an emergency communication mechanism that automatically downgrades to the most basic and most compatible communication method when all preset tunneling protocols (such as HTTP / DNS / ICMP tunnels) fail to function properly, in order to maintain a minimum level of network connectivity.

[0057] like Figure 1 As shown, in a first aspect, this application provides a method for constructing a covert network that combines anonymous networks with protocol masquerading, the method comprising:

[0058] S100, construct the initial hidden network overall framework.

[0059] The initial hidden network framework includes initial source protocol masquerading and initial relay network path hopping.

[0060] Specifically, constructing the initial hidden network framework includes the following steps:

[0061] S101. Based on multiple preset tunnel protocol masquerading strategies and protocol selection rule parameters, a tunnel protocol masquerading strategy is obtained.

[0062] The protocol selection rule parameters include at least one of the following: user's access address, access keywords, access time period, and the location of the destination website service provider.

[0063] It should be noted that various tunneling protocol masquerading strategies may include HTTP tunneling, DNS tunneling, ICMP tunneling, etc.

[0064] Based on the protocol selection rule parameters, one can choose from HTTP tunneling, DNS tunneling, ICMP tunneling, etc. Thus, by combining multiple preset tunnel protocol masquerading strategies with the protocol selection rule parameters, a tunnel protocol masquerading strategy can be obtained.

[0065] Protocol selection rule parameters are shown in Table 1

[0066]

[0067] Table 1

[0068] S102, Based on the tunnel protocol masquerading strategy, the initial source protocol masquerading is obtained.

[0069] The tunnel protocol masquerading strategy can encapsulate HTTP tunnels, DNS tunnels, and ICMP tunnels to obtain the initial source protocol masquerading.

[0070] S103, Deploy a relay node resource pool based on the Tor network to form the anonymous network.

[0071] The relay node resource pool includes network status assessment, backhaul strategy, and dynamic routing selection rules for control nodes.

[0072] It should be noted that the anonymous network is formed by deploying a relay node resource pool with network status assessment, backhaul strategy, and dynamic routing selection rules for control nodes according to the Tor network deployment.

[0073] For example, network condition assessment may include node latency, bandwidth, online rate, and load.

[0074] The backhaul strategy can mean that each intermediate node encrypts and sends its state information back to the directory server via a reverse onion route at each hop.

[0075] The dynamic routing rules for control nodes can represent the rules for the dynamic selection of nodes in the directory server.

[0076] S104, Based on the anonymous network, obtain the initial transit network path jump.

[0077] It should be noted that the combination of network status assessment, backhaul strategy, and dynamic routing selection rules of the control node based on the Tor network deployment of relay node resource pool forms the initial relay network path jump.

[0078] Through the above steps, the covert network can be self-configured, self-optimized, and self-repaired, providing a reliable infrastructure for high-security communication scenarios.

[0079] S200, based on the tunnel's protocol masquerading, by selecting a tunnel, the initial source protocol masquerading is adjusted to obtain the target source protocol masquerading.

[0080] Specifically, obtaining the target source protocol spoofing can include:

[0081] Based on the protocol selection rule parameters, one of the preset tunnel protocol masquerading strategies is dynamically selected in the tunnel protocol masquerading strategy to obtain the target source protocol masquerading.

[0082] It should be noted that, by using the protocol selection rule parameters, a tunnel protocol masquerading strategy is dynamically selected from the encapsulated tunnel protocol masquerading strategy, and this tunnel protocol masquerading strategy is used as the target source protocol masquerading and applied to the initial hidden network overall framework. If the target source protocol masquerading is verified to be problem-free after subsequent steps, it will be used as part of the target hidden network overall framework.

[0083] Furthermore, obtaining the target source protocol spoofing may include the following steps:

[0084] S201, according to the protocol selection rule parameters, select one of the preset tunnel protocol masquerading strategies in the tunnel protocol masquerading strategy to obtain the current source protocol masquerading.

[0085] It should be noted that the user's protocol selection rule parameters can be normalized (using conventional normalization methods), converting all parameters into values ​​between 0 and 1. This will give the user's access address, access keywords, access time period, and destination website service provider's location corresponding values ​​(these values ​​can be normalized based on preset rules). Next, a dynamic selection algorithm with weighted scoring is applied based on preset weights for the user's access address, access keywords, access time period, and destination website service provider's location. In other words, a segment is preset for each measurement in multiple tunnel protocol masquerading strategies. After obtaining the weighted score, the segment to which the score falls determines the selection of the corresponding tunnel protocol masquerading strategy as the current source protocol masquerading, thus forming part of the overall framework for constructing the hidden network.

[0086] S202, monitor the current source protocol spoofing. If the current source protocol spoofing is in an abnormal state, dynamically select one of the preset multiple tunnel protocol spoofing strategies based on the preset selection order rules in the tunnel protocol spoofing strategy to obtain the target source protocol spoofing.

[0087] For example, the monitoring metrics and their thresholds (the thresholds can be obtained by optimizing based on historical data, averages, etc., for example, based on historical network performance data statistics, when the packet loss rate is >30% or the latency is >500ms, the user experience will significantly decrease) are shown in Table 2.

[0088]

[0089] Table 2

[0090] After obtaining the monitoring results of the monitoring indicators, they can be encrypted and reported to the control center through the heartbeat channel. The control center can then evaluate the indicators based on the monitoring results.

[0091] The evaluation of indicators can be calculated using a sliding window. For example, the delay indicator uses the average of a 1-minute sliding window. That is, if the delay is measured every 5 seconds, it is measured 12 times within one minute, and the average of the 12 measurements is taken as the monitoring result of the delay indicator. If the indicator exceeds the threshold, the current protocol is marked as "abnormal".

[0092] It should be noted that the aforementioned latency is merely an illustrative example. Multiple conditions can be combined for judgment. For instance, a weighted average can be calculated based on various metrics such as packet loss rate, latency, firewall interception, and encryption failure (assigning weights to packet loss rate, latency, firewall interception, and encryption failure, and then weighting the calculated value after normalizing the monitoring results). This weighted average value can then be used as the standard for protocol switching. Alternatively, a single monitoring metric can be used as the switching standard.

[0093] For example, if a switchover is triggered due to a high packet loss rate, a protocol with higher bandwidth (such as an HTTP tunnel) is selected first. Next, a new protocol key is pre-negotiated, and the data is transmitted encrypted through the existing channel. The two protocols run in parallel for 5 seconds, the old channel is gradually closed, the routing table is updated, and subsequent traffic is ensured to use the new protocol.

[0094] When using a single monitoring metric as the protocol standard for switching, for example, the monitoring metric is: average latency = 650ms (lasting 1 minute), with weights adjusted based on access time (peak): bandwidth weight 0.6. The scoring results are: HTTP tunnel (bandwidth 0.9) > ICMP tunnel (0.5) > DNS tunnel (0.3). Switch to HTTP tunnel and enable dynamic port evasion.

[0095] Additionally, a multi-condition priority decision can be introduced. For example, if both packet loss rate and latency exceed limits simultaneously, a high-bandwidth protocol will be switched to first. If all protocols fail, the minimum functional mode will be activated and an alarm will be triggered.

[0096] In summary, based on tunnel-based protocol masquerading, the entry proxy before the initial relay network path redirection re-encapsulates normal HTTP and HTTPS access traffic data, disguising it as another application layer protocol. It uses the masqueraded protocol header while presenting the data content as the protocol payload. During tunnel construction, multiple protocol masquerading methods are pre-set, along with protocol masquerading selection rules. Different masquerading protocols are selected based on multiple access attributes, such as the user's access address, access keywords, access time, and the location of the destination website service provider. In the selection of protocol masquerading methods, dynamic masquerading protocol adaptation rules are set, selecting the masquerading protocol based on the user's source IP address range and access attributes (such as access time and target access address type).

[0097] S300, using the relay node, perform the relay configuration for the initial relay network path jump to obtain the target relay network path jump.

[0098] Specifically, obtaining the target transit network path may include the following steps:

[0099] S301 uses network status assessment to evaluate the reliability of relay nodes and obtain a list of available nodes.

[0100] Specifically, for network state assessment:

[0101] Latency: Calculate the average round-trip time (RTT) from the node to the target server using an ICMP Ping test. For example: Node A's RTT = 150ms, Node B's RTT = 300ms.

[0102] Bandwidth: Transmit a 1MB test file and measure throughput (unit: Mbps). For example: Node A bandwidth = 5Mbps, Node B bandwidth = 2Mbps.

[0103] Online rate: The heartbeat response rate of the statistical nodes in the most recent hour (e.g., node A response rate = 98%, node B = 85%).

[0104] Load: CPU and memory utilization are reported by the node agent (e.g., node A CPU = 30%, memory = 40%; node B CPU = 70%, memory = 80%).

[0105] When the threshold rules are: latency ≤ 200ms, bandwidth ≥ 1Mbps, online rate ≥ 90%, CPU < 80%, and memory < 70%, Node A: meets all conditions and is added to the list of available nodes. Node B: bandwidth = 2Mbps (meets the standard), but memory = 80% (exceeds the standard), and is removed.

[0106] It should be noted that the network status assessment runs an Agent on each node to collect its own status data. Then, the data is encrypted and sent back to the directory server through a heartbeat channel.

[0107] S302, using the backhaul strategy, the list of available nodes is backhauled to the directory server, and the directory server is used to update the list of available nodes to obtain a reliable list of relay nodes.

[0108] The deployment of a directory server may include the following steps:

[0109] Select one node from the relay nodes in the relay node resource pool as a directory server to obtain the node directory server;

[0110] The system utilizes a node directory server to receive the list of available nodes sent to it, and uses the directory server to update the list of available nodes to obtain a reliable list of relay nodes.

[0111] This not only facilitates unified updating and maintenance of the node list, but also provides high reliability. Dedicated nodes can be configured with higher performance hardware to ensure service stability.

[0112] Additionally, a reliable list of relay nodes is obtained. For example, during data backhaul, the list of available nodes can be backhauled in JSON format using TLS 1.3 encryption.

[0113] Next, the processing will take place on the directory server.

[0114] For example, in a directory server: deduplication and merging: merge multi-source data based on node ID, retaining the latest record. Historical stability marking: if a node's online rate fluctuation is ≤5% in the past 7 days, it is marked as a long-term reliable node. Generating a reliable list: remove nodes that fail the historical stability check, and output the final list of reliable relay nodes.

[0115] S303, using the dynamic routing selection rules of the control node, select a transit node from the list of reliable transit nodes to obtain the target transit network path jump.

[0116] Dynamic routing rules for control nodes can be deployed on ingress proxy servers or dedicated control nodes. This allows the ingress proxy server to select paths based on its own needs, without relying on the directory server for real-time calculations. Furthermore, routing calculations are complex, and distributed deployment can reduce the burden on the directory server.

[0117] It should be noted that the formula for selecting relay nodes from the list of reliable relay nodes is as follows:

[0118]

[0119] Among them, s i w represents the overall score of transit node i. k This represents the weight of the k-th evaluation dimension, satisfying... This represents the scoring function for the k-th evaluation dimension, using the original parameter x. ik Convert to standardized scores (0-1), x ik represents the original parameter value of node i in the k-th evaluation dimension, and n represents the total number of evaluation dimensions.

[0120] For example, the formula for selecting a transit node from the list of reliable transit nodes is as follows:

[0121]

[0122] Among them, s i L represents the overall score of transit node i. i B represents the delay of relay node i. i R represents the bandwidth of relay node i. i w represents the reliability of relay node i (0~1). j This indicates that the weights w1 + w2 + w3 = 1;

[0123]

[0124] Among them, P i This represents the probability of selecting relay node i, where α represents the bandwidth weight parameter and β represents the reliability weight parameter.

[0125] Finally, it should be noted that in step S300, the step of using a relay node to perform the relay configuration for the initial relay network path jump to obtain the target relay network path jump further includes:

[0126] Deploy encryption and decryption strategies for each of the aforementioned relay nodes.

[0127] Specifically, a lightweight encryption / decryption strategy is deployed for each relay node. "Lightweight" means that the encryption / decryption program consumes few resources (such as CPU and memory), making it suitable for running on relay nodes with limited performance. For example, efficient encryption algorithms such as AES-128 (instead of AES-256) or ChaCha20 are used. The lightweight encryption / decryption service ensures fast node processing speed and does not become a network performance bottleneck.

[0128] Furthermore, when building the relay network, encryption / decryption programs (such as implementations of AES or ChaCha20) are installed on each node. For example, the encryption / decryption programs are deployed using Docker containers or system services. A unique encryption key is generated for each node (e.g., dynamically negotiated key using the ECDH algorithm). In this way, the encryption / decryption programs run automatically when the node starts up, waiting to process data packets. As data packets pass through the node, the encryption / decryption programs automatically perform encryption or decryption operations.

[0129] An encryption / decryption strategy means that each node is responsible for encrypting or decrypting data packets that pass through it, ensuring that the data is not stolen or tampered with during transmission. For example, the ingress node encrypts the user data and then sends it to the next node. Intermediate nodes decrypt the data from the previous hop, re-encrypt it, and send it to the next hop. The egress node decrypts the data and sends it to the target server.

[0130] Data needs to be re-encrypted when it is transmitted between each hop node to prevent intermediate nodes from stealing the data.

[0131] In summary, the relay network (relay network path hopping) is constructed based on the Tor network structure, building a relay network resource pool and adding network status assessment, backhaul functions, and dynamic routing selection rules for control nodes to the relay nodes. During initialization, the relay network resource pool selects one node from the relay nodes to serve as a directory server, deploying the relay nodes by distributing lightweight encryption / decryption services to each relay node. The relay network entry proxy server requests available relay node information from the directory server and sets a transparent relay network selection policy (the policy is invisible to users and external observers, and runs automatically without manual configuration). Based on the node status information and communication quality returned by the relay network resource nodes, it selects a covert communication link, establishes a hidden link access path, and encrypts and encapsulates the disguised data packets.

[0132] S400, perform data verification on the target source protocol masquerading and the target relay network path jump to obtain the overall framework of the target hiding network.

[0133] Specifically, obtaining the overall framework of the target hiding network may include the following steps:

[0134] S401, Build the initial end-to-end verification model.

[0135] Specifically, the initial end-to-end validation model can use a fully connected neural network (FCN) or a support vector machine (SVM) as the base model. Both fully connected neural networks (FCN) and support vector machines (SVM) are conventional base models.

[0136] For example, the training data includes:

[0137] Positive examples: Historical successful cases (protocol spoofing + path redirection).

[0138] Negative samples: historical failure cases (such as protocol being identified, path interruption).

[0139] Data format: Each sample contains protocol parameters (such as protocol type and encryption algorithm) and path parameters (such as node latency and bandwidth).

[0140] S402, the parameters corresponding to the historical source protocol spoofing and the historical transit network path jump are fused to obtain the spliced ​​initial unified vector.

[0141] For example, firstly, features are extracted from the parameters corresponding to historical source protocol spoofing and historical relay network path hops, using a conventional method. Protocol parameters include: protocol type (One-hot encoding), encryption algorithm (e.g., AES=1, ChaCha20=2), and encapsulation method (e.g., DNS subdomain encoding=1, ICMP payload padding=2). Path parameters include: node latency (normalized), bandwidth (normalized), and online rate (0-1).

[0142] Next, vector concatenation is performed, combining the protocol parameters and path parameters into a unified vector to form the initial unified vector. For example, the protocol parameters are: [1,0,0] (HTTP tunnel), [1] (AES encryption), [1] (DNS subdomain encoding). The path parameters are: [0.15] (latency), [0.8] (bandwidth), [0.95] (online rate). The unified vector is: [1,0,0,1,1,0.15,0.8,0.95].

[0143] S403, input the spliced ​​initial unified vector into the initial end-to-end verification model to obtain the target end-to-end verification model.

[0144] The target end-to-end validation model can be defined as a model optimized to achieve a validation set accuracy of >90%.

[0145] S404, the target source protocol spoofing and the target relay network path jump are combined to form a spliced ​​target unified vector, which is input into the target end-to-end verification model for data verification to obtain the verification result.

[0146] Specifically, the parameters of the target source protocol spoofing and the target relay network path hopping are concatenated into a unified vector. This unified vector is then input into the target end-to-end verification model to obtain the verification results.

[0147] S405, Based on the verification results, the initial hidden network overall framework is adjusted to obtain the target hidden network overall framework.

[0148] It should be noted that if the verification passes, the current configuration is retained, and the overall network framework is hidden from the target. For example, DNS tunneling + ChaCha20 encryption + path [Node A → Node B → Node C] continues.

[0149] If verification fails, please try the following:

[0150] Protocol adjustment: Switch to an alternative tunneling protocol (e.g., switch from a DNS tunnel to an ICMP tunnel).

[0151] Path adjustment: Reselect transit nodes (e.g., remove high-latency node D and replace it with node E).

[0152] Revalidate: Input the adjusted configuration into the model until validation passes.

[0153] In summary, network configuration is evaluated through model quantification, reducing manual intervention. When verification fails, protocols and paths are automatically optimized, improving network robustness.

[0154] In one embodiment, a dedicated heartbeat channel based on TLS 1.3 encryption is established during system operation, using a star topology to maintain connections between each relay node and at least three directory servers. This channel sends 128-byte heartbeat packets disguised as DNS TXT record queries (example: 3B1A.xn--kgbechtv format pseudo-domain) every 30 seconds. When communication anomalies are detected, the monitoring frequency is automatically increased to once per second. Protocol failure determination uses a sliding window evaluation model, continuously acquiring protocol health scores for the most recent five detection windows. These scores are weighted across three dimensions: port connectivity (40% weight), network latency (30% weight), and file throughput (30% weight). If the scores for the most recent three tests are all below a threshold of 0.6, an emergency mechanism is triggered.

[0155] The specific plans for the emergency response mechanism can be pre-configured based on historical events to prepare for contingencies. For example, the system can quickly restore communication through steps such as dynamically generating communication ports, encrypting data transmission, node discovery, and path optimization.

[0156] This application presents a method for constructing covert networks that combines anonymity and protocol masquerading, aiming to improve the privacy and security of network communication. Addressing the issue of easy leakage of personal information such as user identity, address, occupation, hobbies, and social relationships during internet access, this method proposes a covert network construction approach that combines anonymity and protocol masquerading. A relay network is constructed between the user and the target network. Dynamic link hopping and link address encryption are used to hide the user's real address. A dynamic protocol masquerading mechanism is employed at the entry proxy of the relay network to prevent information leakage caused by interception of user access paths and deep content parsing. By fragmenting internet behavior and hiding communication content, the information of network behavior subjects can be disrupted, effectively avoiding information leakage and targeted attacks caused by user network behavior collection and feature profiling. The covert network construction method constructed in this paper can be used in various communication scenarios requiring high privacy and security, and has broad application prospects and practical value. Through dynamic policy selection, mathematical routing decisions, and intelligent verification, the entire lifecycle management of the covert network is achieved, reducing manual intervention, especially in communication scenarios with high security requirements.

[0157] Secondly, this application provides a covert network construction system that combines anonymous networks with protocol spoofing, applied to the aforementioned covert network construction method that combines anonymous networks with protocol spoofing. The system includes:

[0158] A construction unit is used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol masquerading and initial relay network path hopping;

[0159] The camouflage unit is used to camouflage according to the tunnel's protocol. By selecting a tunnel, the initial source protocol camouflage is adjusted to obtain the target source protocol camouflage.

[0160] The jump unit is used to configure the initial relay network path jump using the relay node, and obtain the target relay network path jump.

[0161] The verification result unit is used to perform data verification on the target source protocol spoofing and the target transit network path jump to obtain the overall framework of the target hidden network.

[0162] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0163] The various embodiments in this disclosure are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

[0164] The scope of protection of this disclosure is not limited to the embodiments described above. Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from its scope and spirit. If such modifications and variations fall within the scope of the claims of this disclosure and their equivalents, then the intent of this disclosure also includes such modifications and variations.

Claims

1. A method for constructing a covert network by combining an anonymous network and a protocol camouflage, characterized in that, The method comprises: constructing an initial hidden network overall framework, wherein the initial hidden network overall framework comprises an initial source protocol camouflage and an initial transit network path hop; adjusting the initial source protocol camouflage to obtain a target source protocol camouflage by selecting a tunnel according to the protocol camouflage of the tunnel; configuring the initial transit network path hop by using a transit node to obtain a target transit network path hop; verifying data of the target source protocol camouflage and the target transit network path hop to obtain a target hidden network overall framework; wherein the step of constructing the initial hidden network overall framework comprises: obtaining a tunnel protocol camouflage strategy according to a plurality of preset tunnel protocol camouflage strategies and protocol selection rule parameters, wherein the protocol selection rule parameters comprise at least one of an access address, an access keyword, an access time period, and a location of a destination website service provider; obtaining an initial source protocol camouflage according to the tunnel protocol camouflage strategy; deploying a transit node resource pool based on a Tor network to form the anonymous network, wherein the transit node resource pool comprises network state evaluation, a backhaul strategy, and control node dynamic routing selection rules; obtaining an initial transit network path hop according to the anonymous network; the step of configuring the initial transit network path hop by using the transit node to obtain the target transit network path hop comprises: evaluating the reliability of the transit node by using network state evaluation to obtain a list of available nodes; backhauling the list of available nodes to a directory server by using the backhaul strategy, and updating the list of available nodes by using the directory server to obtain a list of reliable transit nodes; selecting a transit node in the list of reliable transit nodes by using the control node dynamic routing selection rules to obtain the target transit network path hop; the calculation formula for selecting the transit node in the list of reliable transit nodes is: ; wherein, represents the transit node a composite score, represents the weight of the th evaluation dimension, satisfying , represents the score function of the th evaluation dimension, which converts the original parameter into a normalized score (0~1), represents the original parameter value of the node in the th evaluation dimension, represents the total number of evaluation dimensions; the step of verifying data of the target source protocol camouflage and the target transit network path hop to obtain the target hidden network overall framework comprises: constructing an initial end-to-end verification model; performing feature fusion on parameters corresponding to a historical source protocol camouflage and a historical transit network path hop to obtain a spliced initial unified vector; inputting the spliced initial unified vector into the initial end-to-end verification model to obtain a target end-to-end verification model; forming a spliced target unified vector by using the target source protocol camouflage and the target transit network path hop, and inputting the spliced target unified vector into the target end-to-end verification model to perform data verification to obtain a verification result; adjusting the initial hidden network overall framework according to the verification result to obtain a target hidden network overall framework; if the verification result fails, performing one of protocol adjustment, path adjustment, and re-verification, wherein the protocol adjustment comprises switching to a backup tunnel protocol, the path adjustment comprises reselecting a transit node, and the re-verification comprises inputting the adjusted configuration into the target end-to-end verification model until the verification passes.

2. The method according to claim 1, wherein the anonymous network and protocol camouflage combined covert network construction method is characterized in that, The step of obtaining the target source protocol spoofing by selecting a tunnel and adjusting the initial source protocol spoofing based on the tunnel's protocol spoofing includes: Based on the protocol selection rule parameters, one of the preset tunnel protocol masquerading strategies is dynamically selected in the tunnel protocol masquerading strategy to obtain the target source protocol masquerading.

3. The method according to claim 2, wherein the anonymous network and protocol camouflage combined covert network construction method is characterized in that, The step of dynamically selecting one of a plurality of preset tunnel protocol spoofing strategies from the tunnel protocol spoofing strategy according to the protocol selection rule parameters to obtain the target source protocol spoofing includes: Based on the protocol selection rule parameters, one of the preset tunnel protocol masquerading strategies is selected from the tunnel protocol masquerading strategy to obtain the current source protocol masquerading. The current source protocol spoofing is monitored. If the current source protocol spoofing is in an abnormal state, the tunnel protocol spoofing strategy dynamically selects one of a number of preset tunnel protocol spoofing strategies based on a preset selection order rule to obtain the target source protocol spoofing.

4. The method of claim 1, wherein the anonymous network combined with protocol camouflage stealth network construction method is characterized in that, The steps of using a backhaul strategy to send the list of available nodes back to the directory server, and using the directory server to update the list of available nodes to obtain a reliable list of relay nodes include: Select one node from the relay nodes in the relay node resource pool as a directory server to obtain the node directory server; The system utilizes a node directory server to receive the list of available nodes sent to it, and uses the directory server to update the list of available nodes to obtain a reliable list of relay nodes.

5. The method of claim 1, wherein the anonymous network combined with protocol camouflage stealth network construction method is characterized in that, The step of using a relay node to configure the initial relay network path jump to obtain the target relay network path jump further includes: Deploy encryption and decryption strategies for each of the aforementioned relay nodes.

6. A covert network construction system combining an anonymous network and protocol camouflage, characterized by, The method for constructing a covert network combining anonymous network and protocol masquerading as described in any one of claims 1-5, the system comprising: A construction unit is used to construct an initial hidden network overall framework, wherein the initial hidden network overall framework includes initial source protocol masquerading and initial relay network path hopping; The camouflage unit is used to camouflage according to the tunnel's protocol. By selecting a tunnel, the initial source protocol camouflage is adjusted to obtain the target source protocol camouflage. The jump unit is used to configure the initial relay network path jump using the relay node, and obtain the target relay network path jump. The verification result unit is used to perform data verification on the target source protocol spoofing and the target transit network path jump to obtain the overall framework of the target hidden network.