Transverse movement behavior detection method and device for encrypted traffic

By using eBPF to capture the encrypted network traffic in an intranet environment, extracting and matching metadata fields, and identifying lateral movement behavior, the problem of low recognition accuracy in the prior art is solved, and the accuracy of network security monitoring is improved.

CN119995939AActive Publication Date: 2025-05-13CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411996921.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-13
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

Existing methods for identifying network attacks are difficult to accurately identify lateral movement behaviors, especially in intranet environments, resulting in a low accuracy rate of attack recognition.

Method used

By capturing the encrypted valid packets using eBPF on the target host, extracting the metadata fields in the header protocol stack, and determining the filtering rules based on the communication type with the target host, matching to identify lateral movement behavior.

Benefits of technology

It improves the accuracy of recognition of lateral mobile attack behavior, reduces false alarms and missed reports, and enhances network security monitoring capabilities in intranet environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995939A_ABST
    Figure CN119995939A_ABST
Patent Text Reader

Abstract

The invention provides a transverse movement behavior detection method and device for encrypted traffic, and relates to the technical field of network security, and the method comprises the steps: firstly, mounting an eBPF probe to a key position of a network protocol stack, and capturing network traffic data to be encrypted; and secondly, screening communication traffic related to the lateral movement attack, matching the related communication traffic with a predefined lateral movement rule, and if the traffic is matched with the lateral movement attack rule, determining that the target host has a lateral movement behavior. Otherwise, finally, further analyzing the traffic abnormality by using the dynamically adjusted behavior model, and triggering a safety alarm when a suspicious behavior is detected. According to the embodiment of the invention, the encrypted lateral movement attack behavior can be identified by using the eBPF in combination with the known attack characteristics and the behavior analysis model, so that the identification accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and device for detecting lateral movement behavior of encrypted traffic. Background Art

[0002] Lateral movement is a common and high-risk attack method in modern network attacks, which usually occurs in the intranet environment. After the attacker gains control of a host in the intranet, he will use the host to access other hosts in the intranet, gradually expanding his control range until he accesses critical data or systems. Lateral movement not only allows the attacker to obtain more system permissions, but may even cause the entire intranet to crash and leak data.

[0003] Existing methods for identifying network attacks generally target a single host, obtaining the traffic data of a single host for analysis to determine whether the host has been attacked. However, lateral movement behavior mainly involves a host attacking other hosts to expand the control range. Therefore, if lateral movement behavior is identified simply by using the method of targeting a single host attack, the accuracy of the identification is relatively low. Summary of the invention

[0004] The present invention provides a method and device for detecting lateral movement behavior of encrypted traffic, which identifies lateral movement attack behavior through communication association between multiple hosts in the same intranet, thereby improving the accuracy of identification.

[0005] In a first aspect, an embodiment of the present invention provides a method for detecting lateral movement behavior of encrypted traffic, comprising:

[0006] Use eBPF to capture valid messages before encryption on the target host;

[0007] Extracting metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splicing the metadata fields that meet the filtering rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host;

[0008] Matching the spliced ​​metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field that determines whether the lateral movement behavior will occur in a valid message of the communication type of the filtering rule;

[0009] If there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

[0010] The above method can extract valid message metadata fields from multiple valid messages before encryption according to the communication type between the target host and other hosts in the same intranet, and use the metadata fields and preset fields corresponding to the filtering rules for matching. When there is a match, it is determined that there is lateral movement behavior. In this way, lateral movement attack behavior can be identified through the communication association between multiple hosts in the same intranet, thereby improving the accuracy of identification.

[0011] In a possible implementation, before extracting the metadata field that complies with the filtering rule in the packet header protocol stack of the valid message, the method further includes:

[0012] Delete the valid message that does not contain the predetermined intranet IP address formation rule.

[0013] The above method can delete valid messages that do not contain the rules for forming a predetermined intranet IP address, that is, delete valid messages that do not belong to communications between intranets. This avoids the problem of traffic interference between the host and external devices and improves the purity of network traffic data.

[0014] In a possible implementation, extracting the metadata field that complies with the filtering rule in the packet header protocol stack of the valid message includes:

[0015] According to each filtering rule, multiple valid messages are divided to obtain valid messages corresponding to each filtering rule;

[0016] According to the preset fields corresponding to each filtering rule, the metadata fields are extracted from the valid messages corresponding to each filtering rule.

[0017] The above method can filter out different metadata fields according to different filtering rules determined according to different communication types, thereby determining whether the target host has lateral movement behavior for valid messages of different communication types, thereby improving the accuracy of determination.

[0018] In a possible implementation, the metadata field includes a plurality of individual fields and statistical fields; according to the preset fields corresponding to each filtering rule, the metadata field is extracted from the valid message corresponding to each filtering rule, including:

[0019] For each filtering rule, if the metadata field corresponding to the filtering rule is a separate field, extract the separate field in each valid message corresponding to the filtering rule;

[0020] If the metadata field corresponding to the filtering rule is a statistical field, the number of messages containing all the individual fields corresponding to the filtering rule is counted from the multiple valid messages corresponding to the filtering rule, and the counted number is used as the statistical field.

[0021] In a possible implementation, eBPF is used to capture valid messages before encryption on the target host, including:

[0022] On the target host, multiple valid messages before encryption are obtained by mounting the eBPF program on the application layer and transport layer of the encryption protocol.

[0023] The above method can obtain multiple network flow data before encryption through the eBPF program mounted on the application layer and transport layer of the encryption protocol on the target host, so that plain text information can be obtained, thereby improving the accuracy of recognition.

[0024] In one possible implementation, the method further includes:

[0025] If there is no match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, the spliced ​​metadata field is input into the prediction model to obtain a prediction result, wherein the prediction result is that the target host has lateral movement behavior or the target host does not have lateral movement behavior.

[0026] The above method can further make predictions through the prediction model when it is determined by using the filtering rules that the target host has no lateral movement behavior, thereby improving the accuracy of identification.

[0027] In one possible implementation, the method further includes:

[0028] Determine whether the target host actually has lateral movement behavior;

[0029] If the actual situation is different from the predicted result, the parameters in the prediction model are adjusted according to the actual situation until the prediction result of the prediction model for the multiple spliced ​​metadata fields is the same as the actual situation, or a modification interface is provided to the maintenance user, and the prediction model is updated according to the parameters of the prediction model input by the maintenance user in the modification interface.

[0030] The above method can automatically adjust the prediction model or allow the user to modify the parameters of the prediction model when the actual situation is different from the prediction result, thereby improving the accuracy of the prediction model.

[0031] In a second aspect, an embodiment of the present invention provides a device for detecting lateral movement behavior of encrypted traffic, including:

[0032] The capture module is used to capture valid messages before encryption on the target host using eBPF;

[0033] An extraction module, used to extract metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splice the metadata fields that meet the filtering rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host;

[0034] A matching module is used to match the spliced ​​metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field for determining whether the lateral movement behavior will occur in a valid message of the communication type of the filtering rule; if there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

[0035] In a third aspect, an embodiment of the present invention provides an electronic device, including:

[0036] processor;

[0037] A processor is used to execute the computer program or instructions in the memory so that the lateral movement behavior detection method of encrypted traffic as described in any one of the first aspects is executed.

[0038] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium. When instructions in the storage medium are executed by a processor, the processor is enabled to execute the method for detecting lateral movement behavior of encrypted traffic as described in any one of the first aspects.

[0039] In a fifth aspect, an embodiment of the present invention provides a computer program product, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method for detecting lateral movement behavior of encrypted traffic as described in any one of the first aspects.

[0040] In addition, the technical effects brought about by any implementation method in the second to fifth aspects can refer to the technical effects brought about by different implementation methods in the first aspect, and will not be repeated here.

[0041] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 A structural diagram of an intranet system provided by an embodiment of the present invention;

[0043] Figure 2 A flow chart of a method for detecting lateral movement behavior of encrypted traffic provided by an embodiment of the present invention;

[0044] Figure 3A flowchart of a method for dividing a plurality of network flow data into arrays provided by an embodiment of the present invention;

[0045] Figure 4 A schematic diagram of matching an array and a lateral movement attack rule provided by an embodiment of the present invention;

[0046] Figure 5 A schematic diagram of capturing network traffic data before encryption provided by an embodiment of the present invention;

[0047] Figure 6 A flowchart of another method for detecting lateral movement behavior of encrypted traffic provided by an embodiment of the present invention;

[0048] Figure 7 A schematic diagram of adjusting parameters of a prediction model provided by an embodiment of the present invention;

[0049] Figure 8 A structural diagram of a device for detecting lateral movement of encrypted traffic provided by an embodiment of the present invention;

[0050] Fig. 9 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0051] In order to make the purpose, technical scheme and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0052] In the description of the embodiments of the present application, unless otherwise specified, in the description of the embodiments of the present application, "plurality" refers to two or more than two.

[0053] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.

[0054] Glossary:

[0055] Intranet: It can also be understood as a local area network, such as an Internet cafe, campus network, unit office network, etc. The intranet needs a server or router as a gateway to access the Internet. The server as a gateway has a public network IP, and the IPs of other intranet computers can be set at will based on it, provided that the first three numbers of the IP must be the same as it, and the fourth number can be selected from 0-255 but must be different from the server's IP.

[0056] eBPF (extended Berkeley Packet Filter) program: An efficient program running in the kernel for monitoring and analyzing system events, especially network traffic and system calls.

[0057] Lateral movement behavior: After successfully invading a host, a network attacker uses the host to further access other hosts and expand the scope of the attack.

[0058] Encrypted traffic: Data transmitted via encryption protocols (such as TLS, SSL, SSH, etc.), whose contents cannot be directly viewed without authorization.

[0059] The present invention is described in detail below with reference to the accompanying drawings:

[0060] Combination Figure 1 As shown, an embodiment of the present invention provides an intranet system, including multiple hosts and a gateway 100; the multiple hosts include host 1, host 2, ..., host n; the gateway 100 provides a public IP, the IP address of host 1, the IP address of host 2, ..., the IP address of host n are set according to the public IP, and the first three numbers of the IP address of host 1, the IP address of host 2, ..., the IP address of host n are the same as the public IP address. When host 1 is attacked, the attacker is likely to attack host 2 based on host 1, or other hosts in the intranet system such as host 3, thereby forming a lateral movement attack behavior.

[0061] However, existing attack identification methods mainly identify the network behavior of a single host and do not pay special attention to the characteristics of lateral movement attack behavior, which makes the existing attack methods have a relatively low recognition accuracy for lateral movement attack behavior.

[0062] Based on this, an embodiment of the present invention provides a lateral movement behavior detection solution, which identifies lateral movement attack behaviors through communication associations between multiple hosts in the same intranet, thereby improving the accuracy of identification.

[0063] The following describes in detail the detection scheme provided by the embodiments of the present invention in conjunction with the accompanying drawings.

[0064] Combination Figure 2 As shown, an embodiment of the present invention provides a method for detecting lateral movement behavior of encrypted traffic, including:

[0065] S200: Use eBPF to capture valid messages before encryption on the target host.

[0066] For example, the target host can be Figure 1 Capturing the valid messages that need to be encrypted on the target host when they are not encrypted can help understand the content inside the valid messages.

[0067] S201: extracting metadata fields that meet filtering rules in the packet header protocol stack of the valid message, and splicing the metadata fields that meet the rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host.

[0068] The communication type includes different types determined based on communication protocols and types determined by different communication commands. The communication protocol is a network protocol used for lateral movement, such as SSH (Secure Shell), SMB (Server Message Block), and TLS (Transport Layer Security). The communication command is a command used for lateral movement, such as PsExec. For example, the communication type includes a type containing SSH, a type containing SMB, a type containing TLS, and a type containing PsExec.

[0069] The filtering rules include: determining filtering rules based on a type containing SSH, determining filtering rules based on a type containing SMB, determining filtering rules based on a type containing TLS, and determining filtering rules based on a type containing PsExec.

[0070] S202: Match the concatenated metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field where lateral movement behavior will occur in valid messages of the communication type of the filtering rule.

[0071] Among them, the fields where lateral movement behavior will occur are different for different communication types, and the preset fields corresponding to different filtering rules can be determined according to different communication types.

[0072] Specifically, when matching, any of the spliced ​​metadata fields and any preset fields corresponding to the filtering rules can be combined arbitrarily to perform matching processing. Exemplarily, the spliced ​​metadata fields come from four communication types, and the spliced ​​metadata fields include a first array 41, a second array 42, a third array 43, and a fourth array 44. The preset fields corresponding to the filtering rules come from four communication types, and the preset fields corresponding to the filtering rules include a first rule set 45, a second rule set 46, a third rule set 47, and a fourth rule set 48. Combining the four arrays and the four rule sets, there are 16 arbitrary combinations. For example, combining Figure 3 As shown, the first array 41 is combined with the first rule set 45 to the fourth rule set 48, the second array 42 is combined with the first rule set 45 to the fourth rule set 48, the third array 43 is combined with the first rule set 45 to the fourth rule set 48, and the fourth array 44 is combined with the first rule set 45 to the fourth rule set 48. Based on the above 16 combinations, the concatenated metadata fields in the matching are matched with the preset fields corresponding to the filtering rules.

[0073] S203: If there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

[0074] The embodiment of the present invention can extract metadata fields according to the communication type between the target host and other hosts in the same intranet, and use the metadata fields and preset fields corresponding to the filtering rules for matching. If a match occurs, it is determined that the target host has a lateral movement attack behavior. In this way, the lateral movement attack behavior can be identified through the communication association between multiple hosts in the same intranet, thereby improving the accuracy of identification.

[0075] In some embodiments, using eBPF to capture valid packets before encryption on a target host includes:

[0076] On the target host, multiple valid messages before encryption are obtained by mounting the eBPF program on the application layer and transport layer of the encryption protocol.

[0077] Among them, the eBPF probe is mounted on the target host through the kernel module to capture network traffic. The eBPF program allows user-defined code to be executed in the kernel space to efficiently capture and process network events.

[0078] In detail, the first point is the mount point selection: the eBPF program can be mounted to different locations in the network protocol stack. The specific mount point should be selected at the application layer (such as TLS, SSL) and transport layer (such as TCP) of the encryption protocol. In order to capture the plaintext data before encryption, you can mount it on functions such as tcp_sendmsg, tls_push_record, or tls_do_encryption. The tcp_sendmsg function is responsible for processing the sending operation in the TCP protocol stack. By mounting the eBPF program to this function, you can obtain the plaintext data of the transport layer before the data packet is encrypted. Combined with Figure 5 As shown, tls_push_record, tls_do_encryption, or similar functions hook eBPF to this function to capture the plaintext data before TLS / SSL encrypts the data.

[0079] The second point is probe type: eBPF provides different probe types for different system events. For network traffic, you can use eBPF probes of type kprobe or tracepoint, depending on the function you want to monitor. Kprobe can be used to capture kernel function calls, such as monitoring tcp_sendmsg. Tracepoint can be used to monitor events defined in the kernel, such as traffic sent by the network protocol stack.

[0080] The third point captures content: After the probe is mounted, the eBPF program will capture the network traffic packets sent by the host. It is necessary to capture the application layer data that will be encrypted, such as HTTP requests, user login information, etc. These data are still plain text before flowing through the encryption layer of the protocol stack. After the deployment of the eBPF-based traffic capture deployment module is completed, proceed to the second step.

[0081] Fourth, privacy protection measures: In order to protect user privacy, the present invention has taken a number of privacy protection measures when using eBPF to capture traffic data. First, the system only captures and analyzes necessary data to avoid collecting too much user information. All captured data is encrypted when stored to prevent unauthorized access. The system also strictly controls access rights to captured data, and only authorized personnel and systems can access the data. In addition, during the analysis process, information related to user identity is anonymized to ensure that user privacy is not leaked. The present invention also complies with relevant privacy laws and regulations to ensure that the data processing process meets legal requirements.

[0082] In some embodiments, before extracting the metadata field that meets the filtering rule in the packet header protocol stack of the valid message, the method further includes:

[0083] Delete the valid message that does not contain the predetermined intranet IP address formation rule.

[0084] Among them, the authentication information and credential transmission data between hosts are typical features of lateral movement behavior. Since the IP address of each host in the intranet is formed according to the public IP address of the gateway, the public IP address is found, and the predetermined intranet IP address formation rule is the same as the first three data of the public IP address.

[0085] Specifically, the network traffic data that is different from the first three data of the public network IP address is regarded as the network traffic data that does not contain the predetermined intranet IP address to form a rule, and these network traffic data can be deleted. For example, the intranet IP range is IP internal , then the filtered flow F S It can be expressed as F S ={S|S 通信IP特征 ∈IP internal}.

[0086] In some embodiments, extracting metadata fields that meet filtering rules in a packet header protocol stack of a valid message includes:

[0087] According to each filtering rule, multiple valid messages are divided to obtain valid messages corresponding to each filtering rule;

[0088] According to the preset fields corresponding to each filtering rule, the metadata fields are extracted from the valid messages corresponding to each filtering rule.

[0089] Specifically, set the filtering rules to P, F P ={S∈F S |S 协议 ∈P}, the captured multiple valid messages are filtered through the above conditions to obtain the valid message F containing only protocol P P , and so on, different network protocols and different commands are set respectively, and multiple groups of valid messages containing only one protocol or command are obtained. Each group of valid messages is a valid message corresponding to each filtering rule.

[0090] Exemplary, combined Figure 4 As shown, the captured multiple valid messages are divided into four arrays according to SSH, SMB, TLS, and PsExec, where the valid messages in the first array all contain SSH, the valid messages in the second array all contain SMB, the valid messages in the third array all contain TLS, and the valid messages in the fourth array all contain PsExec.

[0091] For example, combined with Figure 3As shown, the valid messages in the first array 41 include SSH, the valid messages in the second array 42 include SMB, the valid messages in the third array 43 include TLS, and the valid messages in the fourth array 44 include PsExec. The first rule set 45 is a preset field corresponding to the valid message including SSH, the second rule set 46 is a preset field corresponding to the valid message including SMB, the third rule set 47 is a preset field corresponding to the valid message including TLS, and the fourth rule set 48 is a preset field corresponding to the valid message including PsExec. Then, the first array 41 including SSH and the first rule set 45 are matched, the second array 42 including SMB and the second rule set 46 are matched, the third array 43 including TLS and the third rule set 47 are matched, and the fourth array 44 including PsExec and the fourth rule set 48 are matched. In this way, a total of 4 groups are matched for matching processing. Compared with 16 combinations, the amount of calculation is relatively small, which improves the processing efficiency.

[0092] In some embodiments, the metadata field includes multiple individual fields and statistical fields; according to the preset fields corresponding to each filtering rule, the metadata field is extracted from the valid message corresponding to each filtering rule, including:

[0093] For each filtering rule, if the metadata field corresponding to the filtering rule is a separate field, extract the separate field in each valid message corresponding to the filtering rule;

[0094] If the metadata field corresponding to the filtering rule is a statistical field, the number of messages containing all the individual fields corresponding to the filtering rule is counted from the multiple valid messages corresponding to the filtering rule, and the counted number is used as the statistical field.

[0095] In detail, after capturing all valid packets from the host, we will focus on identifying communications related to lateral movement attacks. Individual fields include some or all of the following network protocols, communication domain name characteristics, IP characteristics, and port characteristics; statistical fields include the number of executions. Assume that a filtering rule is expressed as:

[0096] S = <protocol, communication domain name characteristics, IP characteristics, port characteristics, content characteristics, number of transmissions>.

[0097] For example, traffic patterns of PsExec or SSH commands are known attack vectors, and detecting these patterns can reveal attacker activity. In addition, unusual file sharing requests (such as SMB protocols) may also be a sign of lateral movement. Specifically, the filtering rules contain the following:

[0098] Filter rule 1: When S = <SSH, example.com, 192.168.1.10, 22, login failed, number of times>, it indicates that the SSH login requests fail frequently. The individual fields of Filter rule 1 include SSH, example.com, 192.168.1.10, 22, login failed (login failure), and the statistical field is 5 times. For the valid packets corresponding to this filter rule, these packets extract the individual fields. When having this individual field, it can be counted as 1. If the number of valid packets with the above situation is 10 times, then the statistical field is 10. Then the concatenated metadata field is

[0099] SSH, example.com, 192.168.1.10, 22, login failed, 10.

[0100] When judging whether there is a rule match between the concatenated metadata field and the preset field corresponding to the filter rule, judge whether the statistical number of times exceeds the preset number of times. For example, the preset number of times is 5 times, but the statistical number of times is 10 times. Since 10 times exceeds 5 times, it is determined that there is a lateral movement behavior of the target host.

[0101] Similarly, Filter rule 2: When S = <

[0102] SMB, fileserver, 192.168.1.20, 445, file access, number of times>, it indicates that the SMB file sharing request is abnormal. The individual fields of Filter rule 2 include SMB, fileserver (file server), 192.168.1.20, 445, file access (file access).

[0103] When judging whether there is a rule match between the concatenated metadata field and the preset field corresponding to the filter rule, judge the number of valid packets with SMB, fileserver (file server), 192.168.1.20, 445, and file access, that is, whether the statistical number of times exceeds the preset number of times. For example, the preset number of times is 10 times, and the statistical number of times is 11 times. Since 11 times exceeds 10 times, it is determined that there is a lateral movement behavior of the target host.

[0104] Rule 3: When S = <PsExec, admin, 192.168.1.30, 135, command execution, number of times>, it indicates the execution of the PsExec command. The individual fields of Rule 3 include PsExec, admin (administration), 192.168.1.30, 135, command execution (command execution), and the statistical field is 2 times.

[0105] Determine the number of valid packets with PsExec, admin (management), 192.168.1.30, 135, and command execution, that is, check if the statistical count exceeds a preset count. For example, if the preset count is 1 time and the statistical count is 2 times, and 2 times exceeds 1 time, then it is determined that there is a lateral movement behavior on the target host.

[0106] Rule 4: When S = <TLS, secure.com, 192.168.1.40, 443, password attempt, count>, it indicates frequent password attempt failures during a TLS connection. The individual fields of Rule 4 include TLS, secure.com, 192.168.1.40, 443, password attempt (password attempt), and the statistical field is 8 times.

[0107] Determine the number of valid packets with TLS, secure.com, 192.168.1.40, 443, and password attempt, that is, check if the statistical count exceeds a preset count. For example, if the preset count is 7 times and the statistical count is 8 times, and 8 times exceeds 7 times, then it is determined that there is a lateral movement behavior on the target host.

[0108] In some embodiments, after determining that there is a lateral movement behavior on the target host, the method further includes:

[0109] Extract display data of a preset type from the concatenated metadata fields that match the filtering rules;

[0110] Generate an alarm message based on the display data, and display the alarm message to the user so that the user can handle the lateral movement behavior of the target host according to the alarm message.

[0111] Specifically, after determining that there is a lateral movement behavior on the target host, a security alarm will be immediately triggered. The alarm message includes detailed information about the suspicious traffic, such as the source IP address, target IP address, port number, transmitted data, behavior analysis results, etc. This information will be recorded in the log system for further investigation by the security team. The system can also automatically block the relevant network connections when detecting the lateral movement behavior to prevent the attack from spreading further.

[0112] Combined with Figure 6 As shown, an embodiment of the present invention also provides a method for detecting lateral movement behavior of encrypted traffic, including:

[0113] S600: Use eBPF to capture valid packets before encryption on the target host;

[0114] S601: extracting metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splicing the metadata fields that meet the rules;

[0115] S602: Match the concatenated metadata fields with the preset fields corresponding to the filtering rules in pairs;

[0116] S603: Determine whether the concatenated metadata field matches the preset field corresponding to the filtering rule; if so, execute S604; otherwise, execute S605;

[0117] S604: Determine that the target host has lateral movement behavior;

[0118] S605: Input the spliced ​​metadata fields into the prediction model to obtain a prediction result.

[0119] For steps 600 to 604, please refer to Figure 2 The content of step 605 is explained. If no match occurs between any array and any lateral movement attack rule, a prediction model is input from multiple spliced ​​metadata fields to obtain a prediction result, wherein the prediction result is that the target host has lateral movement behavior or the target host does not have lateral movement behavior.

[0120] In detail, in addition to rule-based detection, the embodiments of the present invention also perform a deeper analysis of the captured traffic by using a trained behavioral analysis model. These pre-trained models are usually provided by well-known network security institutions or research institutions as open source. They are trained with a large amount of normal host traffic and known attack traffic and have the ability to identify potential attack characteristics. In actual applications, by inputting captured traffic data, the prediction model can quickly assess the degree of abnormality of the traffic and identify potential lateral movement behaviors. The advantage of the pre-trained model is that it has been extensively trained with data, has high accuracy and stability, can be deployed immediately and start detection, saving the time and resources required for model training.

[0121] Example 1: Assume that a host (A) initiates frequent SSH login requests to multiple hosts (B, C, D) in a short period of time, and the failure rate of each login request is abnormally high. After the behavior model detects this traffic pattern, it will mark the host's behavior as a suspicious lateral movement attempt.

[0122] Example 2: The traffic of a host suddenly increases, and the protocol of the traffic uses encrypted communication (such as HTTPS). The behavior model can identify abnormal file transfer patterns in the HTTPS traffic (such as a large number of small file transfers in a short period of time) through historical training traffic data and mark it as a potential data leakage behavior.

[0123] In some embodiments, the method further comprises:

[0124] Determine whether the target host actually has lateral movement behavior;

[0125] If the actual situation is different from the predicted result, the parameters in the prediction model are adjusted according to the actual situation until the prediction result of the prediction model for the multiple spliced ​​metadata fields is the same as the actual situation, or a modification interface is provided to the maintenance user, and the prediction model is updated according to the parameters of the prediction model input by the maintenance user in the modification interface.

[0126] In detail, in order to adapt to the ever-changing network environment and new attack methods, combined with Figure 7 As shown, the parameters of the prediction model provided by the embodiment of the present invention can be dynamically adjusted according to actual conditions. The automated system continuously monitors network traffic, collects false alarm and missed alarm cases, and uses reinforcement learning algorithms to automatically adjust model parameters to reduce false alarm rates and improve detection accuracy. In certain specific networks, certain traffic patterns may be legitimate business needs. The model will gradually learn these legitimate behaviors and adjust parameters. Maintenance users of the security team can manually intervene in model adjustments, especially when new attack methods or complex network changes emerge. Based on threat intelligence and actual detection conditions, maintenance users of the security team can fine-tune the model, update the rule base and parameter settings. The pre-trained model can also receive threat intelligence updates, automatically adjust detection strategies, and improve the ability to detect new types of attacks.

[0127] Example 3: During a certain detection, the system mistakenly marked a legitimate internal network scanning operation as suspicious behavior. Through the false alarm feedback mechanism and manual intervention, the model gradually learned that the behavior was a normal operation and maintenance activity, and then dynamically adjusted the rules to prevent subsequent similar activities from being incorrectly marked.

[0128] By using the pre-trained model and fine-tuning it in combination with the actual network environment, the present invention can dynamically adjust the detection strategy to improve the accuracy and flexibility of lateral movement attack detection. If suspicious lateral movement behavior is identified, the fifth step alarm is triggered.

[0129] Through the scheme introduced in the present invention, the embodiments of the present invention have the following beneficial effects:

[0130] 1. Pre-encryption traffic capture based on eBPF: By deploying eBPF probes in the operating system, the present invention can capture the plaintext content of traffic before it is encrypted. Compared with the traditional method based on encrypted traffic metadata analysis, malicious behavior can be detected more intuitively, improving the accuracy of attack detection.

[0131] 2. Fine-grained lateral movement detection mechanism: The present invention can perform fine-grained analysis on the captured plaintext data before encryption, and can dynamically adjust the detection strategy according to changes in the network environment by combining rule detection and deep learning technology. This application can adapt to new attack methods and improve the flexibility of detection.

[0132] 3. Real-time performance and low system overhead: eBPF probes can run efficiently in the system kernel without affecting the normal performance of the host, and can capture and analyze traffic in real time. Compared with existing network traffic monitoring solutions, the present invention has stronger real-time performance and is suitable for security protection in large-scale network environments.

[0133] like Figure 8 As shown, the present invention also provides a device for detecting lateral movement behavior of encrypted traffic, comprising:

[0134] A capture module 800 is used to capture valid messages before encryption on a target host using eBPF;

[0135] The extraction module 801 is used to extract the metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splice the metadata fields that meet the filtering rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host;

[0136] The matching module 802 is used to match the spliced ​​metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field for determining whether the lateral movement behavior will occur in a valid message of the communication type of the filtering rule; if there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

[0137] Optionally, the device further includes: a deletion module, which is arranged between the capture module 800 and the extraction module 801;

[0138] The deleting module is used to delete the valid message that does not contain the predetermined intranet IP address formation rule.

[0139] Optionally, the extraction module 801 is specifically used to divide the multiple valid messages according to each filtering rule to obtain the valid messages corresponding to each filtering rule;

[0140] According to the preset fields corresponding to each filtering rule, the metadata fields are extracted from the valid messages corresponding to each filtering rule.

[0141] Optionally, the metadata field includes multiple individual fields and statistical fields; the extraction module 801 is specifically used to:

[0142] For each filtering rule, if the metadata field corresponding to the filtering rule is a separate field, extract the separate field in each valid message corresponding to the filtering rule;

[0143] If the metadata field corresponding to the filtering rule is a statistical field, the number of messages containing all the individual fields corresponding to the filtering rule is counted from the multiple valid messages corresponding to the filtering rule, and the counted number is used as the statistical field.

[0144] Optionally, the capture module 800 is specifically used to capture multiple valid messages before encryption on the target host through an eBPF program mounted on the application layer or transport layer of the encryption protocol.

[0145] Optionally, the device further comprises: a prediction module, the prediction module being after the matching module;

[0146] The prediction module is used to input the spliced ​​metadata field into the prediction model to obtain a prediction result if no match occurs between the spliced ​​metadata field and the preset field corresponding to the filtering rule, wherein the prediction result is that the target host has lateral movement behavior or the target host does not have lateral movement behavior.

[0147] Optionally, the device further comprises: an adjustment module, the adjustment module being after the prediction module;

[0148] An adjustment module, used to determine whether the target host has an actual situation of lateral movement behavior;

[0149] If the actual situation is different from the predicted result, the parameters in the prediction model are adjusted according to the actual situation until the prediction result of the prediction model for the multiple spliced ​​metadata fields is the same as the actual situation, or a modification interface is provided to the maintenance user, and the prediction model is updated according to the parameters of the prediction model input by the maintenance user in the modification interface.

[0150] In addition, combined Figure 1-Figure 8 The method and device for detecting lateral movement behavior of encrypted traffic described in the embodiments of the present invention may be implemented by an electronic device.

[0151] Electronic devices, including: processors;

[0152] a memory for storing instructions executable by the processor;

[0153] The processor is configured to execute the instructions to implement the lateral movement behavior detection method of encrypted traffic as described in any one of the above descriptions.

[0154] The electronic device may be any host in the intranet, or may be a device connected to a host in the intranet.

[0155] Based on the above introduction, an exemplary Fig. 9 electronic equipment structure.

[0156] The electronic device may include a processor 910 and a memory 920 storing computer program instructions.

[0157] Specifically, the processor 910 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present invention.

[0158] The memory 920 may include a large capacity memory for data or instructions. For example, but not limitation, the memory 920 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In appropriate cases, the memory 920 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 920 may be inside or outside the data processing device. In a specific embodiment, the memory 920 is a non-volatile solid-state memory. In a specific embodiment, the memory 920 includes a read-only memory (ROM). In appropriate cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM) or a flash memory or a combination of two or more of these.

[0159] The processor 910 implements any one of the methods for performing tasks in the above embodiments by reading and executing computer program instructions stored in the memory 920 .

[0160] In one example, the electronic device may further include a communication interface 930 and a bus 940. Fig. 9 As shown, the processor 910, the memory 920, and the communication interface 930 are connected via a bus 940 and communicate with each other.

[0161] The communication interface 930 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiment of the present invention.

[0162] Bus 940 includes hardware, software or both, and the parts of electronic equipment are coupled to each other.For example, but not limitation, bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industrial standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industrial standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 940 may include one or more buses. Although the embodiment of the present invention describes and shows a specific bus, the present invention considers any suitable bus or interconnection.

[0163] The electronic device can execute the lateral movement behavior detection method of the encrypted traffic in the embodiment of the present invention based on the received task, thereby realizing the combination Figure 1-Figure 8 A method and apparatus for detecting lateral movement behavior of encrypted traffic is described.

[0164] In addition, in combination with the electronic device in the above embodiments, an embodiment of the present invention may provide a storage medium, and when the instructions in the storage medium are executed by the processor of the electronic device, the electronic device can execute the lateral movement behavior detection method of encrypted traffic as described in any one of the above items.

[0165] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0166] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0167] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0168] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0169] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A method for detecting lateral movement of encrypted traffic, characterized in that: include: Use eBPF to capture valid messages before encryption on the target host; Extracting metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splicing the metadata fields that meet the filtering rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host; Matching the spliced ​​metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field that determines whether the lateral movement behavior will occur in a valid message of the communication type of the filtering rule; If there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

2. The method for detecting lateral movement of encrypted traffic according to claim 1, characterized in that: Before extracting the metadata field that meets the filtering rule in the packet header protocol stack of the valid message, the method further includes: Delete the valid message that does not contain the predetermined intranet IP address formation rule.

3. The method for detecting lateral movement of encrypted traffic according to claim 1, characterized in that: Extracting metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, including: According to each filtering rule, multiple valid messages are divided to obtain valid messages corresponding to each filtering rule; According to the preset fields corresponding to each filtering rule, the metadata fields are extracted from the valid messages corresponding to each filtering rule.

4. The method for detecting lateral movement of encrypted traffic according to claim 3, characterized in that: The metadata field includes a plurality of individual fields and statistical fields; according to the preset fields corresponding to each filtering rule, the metadata field is extracted from the valid message corresponding to each filtering rule, including: For each filtering rule, if the metadata field corresponding to the filtering rule is a separate field, extract the separate field in each valid message corresponding to the filtering rule; If the metadata field corresponding to the filtering rule is a statistical field, the number of messages containing all the individual fields corresponding to the filtering rule is counted from the multiple valid messages corresponding to the filtering rule, and the counted number is used as the statistical field.

5. The method for detecting lateral movement of encrypted traffic according to claim 1, characterized in that: Use eBPF to capture valid messages before encryption on the target host, including: On the target host, multiple valid messages before encryption are obtained by mounting the eBPF program on the application layer or transport layer of the encryption protocol.

6. The method for detecting lateral movement of encrypted traffic according to any one of claims 1 to 5, characterized in that: The method further comprises: If there is no match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, the spliced ​​metadata field is input into the prediction model to obtain a prediction result, wherein the prediction result is that the target host has lateral movement behavior or the target host does not have lateral movement behavior.

7. The method for detecting lateral movement of encrypted traffic according to claim 6, characterized in that: The method further comprises: Determine whether the target host actually has lateral movement behavior; If the actual situation is different from the predicted result, the parameters in the prediction model are adjusted according to the actual situation until the prediction result of the prediction model for the multiple spliced ​​metadata fields is the same as the actual situation, or a modification interface is provided to the maintenance user, and the prediction model is updated according to the parameters of the prediction model input by the maintenance user in the modification interface.

8. A device for detecting lateral movement of encrypted traffic, characterized in that: include: The capture module is used to capture valid messages before encryption on the target host using eBPF; An extraction module, used to extract metadata fields that meet the filtering rules in the packet header protocol stack of the valid message, and splice the metadata fields that meet the filtering rules; wherein the filtering rules are determined according to the communication type between the target host and other hosts in the same intranet as the target host; A matching module is used to match the spliced ​​metadata field with the preset field corresponding to the filtering rule; wherein the preset field corresponding to the filtering rule is a field for determining whether the lateral movement behavior will occur in a valid message of the communication type of the filtering rule; if there is a rule match between the spliced ​​metadata field and the preset field corresponding to the filtering rule, it is determined that the target host has lateral movement behavior.

9. An electronic device, characterized in that: include: Memory, used to store computer programs or instructions; A processor is used to execute the computer program or instructions in the memory so that the lateral movement behavior detection method of encrypted traffic as described in any one of claims 1-7 is executed.

10. A computer-readable storage medium, characterized in that: When the instructions in the storage medium are executed by a processor, the processor is enabled to execute the lateral movement behavior detection method for encrypted traffic as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Simulation detection method, device and equipment for intranet attack and medium

    CN115208659A

  • Network lateral movement attack detection method and device, equipment and storage medium

    CN116980211A

  • Lateral movement attack detection method, program product, electronic device and storage medium

    CN118250080A

  • Network attack behavior prediction method, device, equipment, medium and product

    CN118487861A

  • Extracting Encryption Metadata and Terminating Malicious Connections Using Machine Learning

    US20180124085A1