Traffic detection method and device and electronic equipment
The original SSL message and handshake information are parsed from the HTTPS mirror traffic through the SSL parser, and an SSL connection is established with the Nginx proxy module through the simulated client and server. The original SSL message is decrypted using the same master key and the security detection operation is performed, which solves the problem that the existing technology cannot detect HTTPS traffic, and realizes security detection and system performance optimization of HTTPS traffic.
Patent Information
- Application Number
- CN202510108863.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The existing technology cannot realize effective detection of HTTPS traffic and cannot solve the problem of HTTPS traffic detection.
The original SSL message and the original SSL handshake information are parsed from the HTTPS mirror traffic through the SSL parser, and an SSL connection is established with the Nginx proxy module through the simulated client and the simulated server. The original SSL message is decrypted using the same master key to perform security detection operations.
It realizes security detection of HTTPS traffic, reduces the running load of the SSL parser, optimizes the system performance, and solves the problem of the performance bottleneck of the SSL parser.
Smart Images

Figure CN119995968A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of flow monitoring, and in particular to a flow detection method, device and electronic equipment. Background Art
[0002] At present, the traffic detection technology for the Hypertext Transfer Protocol is generally obtained through a bypass WEB application early warning system based on the Nginx proxy module, but the Nginx proxy module in the system cannot successfully perform SSL handshake with the simulated client and the simulated server.
[0003] Based on this, the above technology can only realize the flow detection of the flow detection of the Hypertext Transfer Protocol, and cannot solve the flow detection of the Hypertext Transfer Protocol Security. Summary of the invention
[0004] The purpose of the present invention is to provide a flow detection method, device and electronic device to alleviate the technical problem that the prior art can only realize HTTP flow detection but cannot solve the HTTPS flow detection, so as to realize HTTPS flow detection.
[0005] In the first aspect, an embodiment of the present invention provides a traffic detection method, comprising: when the received mirror traffic is HTTPS mirror traffic, an SSL parser parses the HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server; the SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the traffic direction of the HTTPS mirror traffic, and sends the original SSL handshake information to the Nginx proxy module through the simulated client; the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the first SSL connection and the second SSL connection use the same master key; the Nginx proxy module decrypts the original SSL message based on the master key and then performs a security detection operation.
[0006] In a preferred embodiment of the present invention, the SSL parser parses the above-mentioned HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server, including: for the mirror traffic of the first HTTPS traffic sent by the client to the server in the above-mentioned HTTPS mirror traffic, the above-mentioned SSL parser parses the above-mentioned HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information of the above-mentioned first HTTPS traffic; the above-mentioned SSL parser sends the above-mentioned original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the traffic direction of the above-mentioned HTTPS mirror traffic, including: the above-mentioned SSL parser sends the original SSL message of the above-mentioned first HTTPS traffic to the Nginx proxy module through the simulated client.
[0007] In a preferred embodiment of the present invention, the above-mentioned SSL parser parses the above-mentioned HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server, including: for the mirror traffic of the second HTTPS traffic sent by the server to the client in the above-mentioned HTTPS mirror traffic, the above-mentioned SSL parser parses the above-mentioned HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information of the above-mentioned second HTTPS traffic; the above-mentioned SSL parser sends the above-mentioned original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the traffic direction of the above-mentioned HTTPS mirror traffic, including: the above-mentioned SSL parser sends the original SSL message of the above-mentioned second HTTPS traffic to the Nginx proxy module through the simulated server.
[0008] In a preferred embodiment of the present invention, the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, including: the Nginx proxy module receives the original SSL handshake information sent by the simulated client, and performs a random number exchange with the simulated client based on the server random number in the original SSL handshake information; after completing the random number exchange between the Nginx proxy module and the simulated client, the Nginx proxy module uses the pre-master key in the original SSL handshake information to jointly generate the master key with the simulated client to complete the establishment of the first SSL connection between the Nginx proxy module and the simulated server.
[0009] In a preferred embodiment of the present invention, the Nginx proxy module establishes a second SSL connection between the Nginx proxy module and the simulated server based on the original SSL handshake information, including: the Nginx proxy module performs a random number exchange with the simulated server according to the client random number in the original SSL handshake information; after the random number exchange between the Nginx proxy module and the simulated server is completed, the Nginx proxy module uses the pre-master key in the original SSL handshake information and the simulated server to jointly generate the master key to complete the establishment of the second SSL connection between the Nginx proxy module and the simulated server.
[0010] In a preferred embodiment of the present invention, during the establishment of the first SSL connection, the original SSL handshake information sent by the simulated client is appended before the first SSL handshake message sent by the simulated client to the Nginx proxy module;
[0011] During the process of establishing the second SSL connection, the client random number in the original SSL handshake information is carried in the first SSL handshake message sent by the Nginx proxy module to the simulated server.
[0012] In a preferred embodiment of the present invention, the above-mentioned Nginx proxy module decrypts the above-mentioned original SSL message based on the above-mentioned master key, including: the above-mentioned Nginx proxy module decrypts the encrypted data in the above-mentioned original SSL message based on the above-mentioned master key through a preset hardware acceleration device to obtain the plaintext of the above-mentioned original SSL message.
[0013] In a preferred embodiment of the present invention, the above-mentioned SSL parser, the above-mentioned simulated client and the above-mentioned simulated server are deployed in a bypass process; the above-mentioned SSL parser is connected to the above-mentioned simulated client and the above-mentioned simulated server respectively.
[0014] In a second aspect, an embodiment of the present invention further provides a flow detection device, comprising: an SSL parser, which is used to parse the HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server from the HTTPS mirror traffic when the received mirror traffic is HTTPS mirror traffic, and send the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirror traffic, and send the original SSL handshake information to the Nginx proxy module through the simulated client; a simulated client, which is used to receive the original SSL message and the original SSL handshake information sent by the SSL parser according to the flow direction of the HTTPS mirror traffic SSL handshake information, and send it to the Nginx proxy module; the simulation server is used to receive the above-mentioned original SSL message sent by the above-mentioned SSL parser according to the traffic direction of the above-mentioned HTTPS mirror traffic, and send it to the Nginx proxy module; the above-mentioned Nginx proxy module is used to establish a first SSL connection between the above-mentioned Nginx proxy module and the above-mentioned simulation client based on the above-mentioned original SSL handshake information, and establish a second SSL connection between the above-mentioned Nginx proxy module and the above-mentioned simulation server; wherein the master key used by the above-mentioned first SSL connection is the same as that used by the above-mentioned second SSL connection; the above-mentioned Nginx proxy module is also used to perform security detection operations after decrypting the above-mentioned original SSL message based on the above-mentioned master key.
[0015] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a processor and a memory, wherein the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement the flow detection method.
[0016] The embodiments of the present invention have the following beneficial technical effects:
[0017] The embodiment of the present invention provides a flow detection method, device and electronic device, including: when the received mirrored flow is HTTPS mirrored flow, an SSL parser parses the HTTPS mirrored flow to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server; the SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirrored flow, and sends the original SSL handshake information to the Nginx proxy module through the simulated client; the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the master key used by the first SSL connection is the same as that used by the second SSL connection; the Nginx proxy module performs a security detection operation after decrypting the original SSL message based on the master key. The method establishes an SSL connection with the Nginx proxy module by simulating the client and the server respectively and uses the same master key for decryption, which not only realizes the security detection of HTTPS traffic, but also greatly reduces the running load of the SSL parser compared to executing the parsing and decryption of HTTPS traffic by the SSL parser, effectively solves the performance bottleneck of the SSL parser, and thus optimizes the overall performance of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 A flow chart of a flow detection method provided by an embodiment of the present invention;
[0020] Figure 2 A schematic diagram of the structure of a flow detection device provided by an embodiment of the present invention;
[0021] Figure 3 A flow chart of another flow detection method provided by an embodiment of the present invention;
[0022] Figure 4 A schematic diagram of a simulation of original SSL handshake information transmitted by a client to an Nginx proxy module provided by an embodiment of the present invention;
[0023] Figure 5 A schematic diagram of simulating a client to establish an SSL connection with an Nginx proxy module provided by an embodiment of the present invention;
[0024] Figure 6 A schematic diagram of establishing an SSL connection between an Nginx proxy module and a simulated server provided in an embodiment of the present invention;
[0025] Figure 7 A schematic diagram of the structure of a flow detection device for an extended QAT hardware acceleration card provided by an embodiment of the present invention;
[0026] Figure 8 A schematic diagram of the structure of another flow detection device provided by an embodiment of the present invention;
[0027] Fig. 9 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention.
[0028] Icons: 31-SSL parser; 32-simulated client; 33-Nginx proxy module; 34-simulated server; 41-memory; 42-processor; 43-bus; 44-communication interface. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.
[0030] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0031] HTTPS: (full name: Hypertext Transfer Protocol Secure) is an HTTP channel with security as its goal. It ensures the security of the transmission process through transmission encryption and identity authentication based on HTTP. HTTPS adds SSL to HTTP. The security foundation of HTTPS is SSL, so the details of encryption require SSL. HTTPS has a default port different from HTTP and an encryption / authentication layer (between HTTP and TCP).
[0032] SSL: (Secure Sockets Layer), and its successor Transport Layer Security (TLS) is a security protocol that provides security and data integrity for network communications.
[0033] TLS: The Transport Layer Security Protocol (TLS) is used to provide confidentiality and data integrity between two communicating applications. The protocol consists of two layers: TLS Record Protocol and TLS Handshake Protocol. The lower layer is the TLS Record Protocol, which is located on a reliable transport protocol (such as TCP) and has nothing to do with specific applications. Therefore, the TLS protocol is generally classified as a transport layer security protocol.
[0034] HTTP: Hyper Text Transfer Protocol (HTTP) is a simple request-response protocol that usually runs on top of TCP. It specifies what messages a client may send to a server and what responses it may get.
[0035] RSA: Public key cryptography is a cryptographic system that uses different encryption keys and decryption keys, and it is computationally infeasible to derive the decryption key from a known encryption key.
[0036] DH: (DiffieHellman) key exchange protocol / algorithm.
[0037] Nginx is a high-performance HTTP and Nginx proxy module that also provides IMAP / POP3 / SMTP services.
[0038] Message: A message is a unit of data exchanged and transmitted in a network, i.e., a block of data to be sent by a station at one time. A message contains the complete data information to be sent, and its length is very inconsistent, unlimited and variable.
[0039] DPDK: Data Plane Development Kit (DPDK) is developed by 6WIND, Intel and other companies. It mainly runs on Linux system. It is a collection of function libraries and drivers for fast data packet processing. It can greatly improve data processing performance and throughput, and improve the work efficiency of data plane applications.
[0040] Plain text: refers to unencrypted text (or string of characters) that can be understood by ordinary people. It is a cryptographic term. In a communication system, it may be a bit stream, such as text, bitmap, digitized voice or digitized video image.
[0041] Transmission Control Protocol: (TCP) is a connection-oriented, reliable, byte stream-based transport layer communication protocol.
[0042] However, currently, when simulating a client and a server, the original message is usually sent to the detection server for parsing, and the random number in the message that the detection server replies to the simulated client and the simulated server must be different from the original message. Therefore, the detection server cannot successfully and securely connect with the simulated client and the simulated server, and cannot support traffic detection of the Hypertext Transfer Protocol Security.
[0043] Based on this, the embodiment of the present invention provides a flow detection method, device and electronic device. The method parses HTTPS flow through an SSL parser and converts it into original SSL message data, and establishes SSL connections using the same master key with a simulated client and a simulated server respectively through an Nginx proxy module using the same handshake information as the original SSL connection, and uses the master key to decrypt the above SSL message data to obtain HTTP plaintext, thereby realizing security detection of the Hypertext Transfer Protocol Security. For ease of understanding, a flow detection method is first introduced.
[0044] Example 1
[0045] In this embodiment, Figure 1 A flow chart of a flow detection method provided by an embodiment of the present invention. The method can be applied to a flow detection device, which may include an SSL parser, a simulated client, and a simulated server deployed in a bypass process. Figure 1 As can be seen, the method includes:
[0046] Step S101: When the received mirrored traffic is HTTPS mirrored traffic, the SSL parser parses the HTTPS mirrored traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server.
[0047] In some examples, the HTTPS mirror traffic is sent by the data plane (DPDK) to the SSL parser, and the traffic type of the mirror traffic includes HTTPS mirror traffic and HTTP mirror traffic.
[0048] In some examples, before the above step S101, the method further includes: determining whether the above traffic type is HTTPS mirror traffic.
[0049] Among them, the data plane can be the data plane of the traffic detection device, and can also collect mirror traffic from other links. For example, the real traffic of the client requesting to access the server and / or the real traffic of the server responding to the client can be obtained through the forwarding device, and the obtained real traffic can be copied to obtain mirror traffic, which is received by the data plane of the traffic detection device.
[0050] The above original SSL handshake information may include: client random number, server random number, key suite, compression algorithm and pre-master key.
[0051] Step S102: The SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirror flow, and sends the original SSL handshake information to the Nginx proxy module through the simulated client.
[0052] The traffic direction of the HTTPS mirror traffic can be divided into: a request direction and a response direction. The request direction indicates that the original traffic of the HTTPS mirror traffic is the HTTPS traffic sent from the client to the server, and the response direction indicates that the original traffic of the HTTPS mirror traffic is the HTTPS traffic sent from the server to the client.
[0053] Step S103: Based on the original SSL handshake information, the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the master key used by the first SSL connection is the same as that used by the second SSL connection.
[0054] This application establishes two SSL connections between the Nginx proxy module and the client and server by using the same master key. This method ensures the transparency and consistency of communication, while simplifying key management and improving proxy efficiency.
[0055] Step S104: the Nginx proxy module decrypts the original SSL message based on the master key and then performs a security detection operation.
[0056] For ease of understanding, Figure 2 A schematic structural diagram of a flow detection device provided in an embodiment of the present invention.
[0057] Depend on Figure 2 As can be seen, the data plane is responsible for receiving the mirrored traffic; the bypass process is used to process the above-mentioned mirrored traffic, which includes: HTTP parser, SSL parser, simulated client, and simulated server.
[0058] The SSL parser can be used to classify the recorded messages of the SSL or TLS protocol, put the request messages into the simulated client's sending queue, and put the response messages into the simulated server's sending queue. In addition, the original SSL handshake information should be attached to the beginning of the first TCP data message sent by the simulated client.
[0059] The HTTP parser is used to classify HTTP protocol messages, put HTTP request messages into the sending queue of the simulated client, and put HTTP response messages into the sending queue of the simulated server.
[0060] The simulated client is used to send the messages in the send queue to the Nginx proxy module (i.e. Figure 2 Nginx service in ).
[0061] The simulated server is used to send the messages in the sending queue to the Nginx proxy module.
[0062] The Nginx proxy module is used to receive messages from simulated clients and simulated servers. If it is an HTTP message, it is directly detected. If it is an HTTPS message, it is first decrypted into HTTP plain text and then detected.
[0063] The embodiment of the present invention provides a flow detection method, comprising: when the received mirrored flow is HTTPS mirrored flow, an SSL parser parses the HTTPS mirrored flow to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server; the SSL parser sends the original SSL message and the simulated client and the simulated server to the Nginx proxy module according to the flow direction of the HTTPS mirrored flow, and sends the original SSL handshake information to the Nginx proxy module through the simulated client; the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the master key used by the first SSL connection is the same as that used by the second SSL connection; the Nginx proxy module performs a security detection operation after decrypting the original SSL message based on the master key. This method introduces a simulated client and simulated server to establish a two-way SSL connection with the Nginx proxy module and use the same master key for decryption. It not only achieves security detection of HTTPS traffic, but also reduces the running load of the SSL parser and optimizes system performance by concentrating SSL handshake and message decryption in the Nginx proxy module.
[0064] Example 2
[0065] Based on the above embodiments, Figure 3 A flow chart of another flow detection method provided by an embodiment of the present invention.
[0066] Depend on Figure 3 As can be seen, the method includes:
[0067] Step S201: When the received mirrored traffic is HTTPS mirrored traffic, for the mirrored traffic of the first HTTPS traffic sent by the client to the server in the HTTPS mirrored traffic, the SSL parser parses the HTTPS mirrored traffic to obtain the original SSL message and original SSL handshake information of the first HTTPS traffic.
[0068] In some embodiments of the present application, step S201 also includes: for the mirror traffic of the second HTTPS traffic sent by the server to the client in the above-mentioned HTTPS mirror traffic, the above-mentioned SSL parser parses the above-mentioned HTTPS mirror traffic to obtain the original SSL message and original SSL handshake information of the above-mentioned second HTTPS traffic.
[0069] Step S202: The SSL parser sends the original SSL message of the first HTTPS traffic to the Nginx proxy module through the simulated client, and sends the original SSL message of the second HTTPS traffic to the Nginx proxy module through the simulated server.
[0070] Step S203: The SSL parser sends the original SSL handshake information to the Nginx proxy module through a simulated client.
[0071] The present invention has the following beneficial technical effects: the method realizes accurate SSL message parsing and decryption for the first HTTPS mirror traffic from the client to the server and the second HTTPS mirror traffic from the server to the second client through the collaborative work of the SSL parser and the Nginx proxy module, and ensures the security and consistency of the decryption process by establishing a two-way SSL connection, thereby improving the accuracy and efficiency of security detection, optimizing the SSL processing flow and reducing the system load.
[0072] Step S204: Based on the original SSL handshake information, the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the master key used by the first SSL connection is the same as that used by the second SSL connection.
[0073] Among them, the above-mentioned SSL parser, the above-mentioned simulated client and the above-mentioned simulated server are deployed in a bypass process; the above-mentioned SSL parser is connected to the above-mentioned simulated client and the above-mentioned simulated server respectively.
[0074] In some examples, the Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, including: the Nginx proxy module receives the original SSL handshake information sent by the simulated client, and performs a random number exchange with the simulated client based on the server random number in the original SSL handshake information; after completing the random number exchange between the Nginx proxy module and the simulated client, the Nginx proxy module uses the pre-master key in the original SSL handshake information to jointly generate the master key with the simulated client to complete the establishment of the first SSL connection between the Nginx proxy module and the simulated server.
[0075] Furthermore, the Nginx proxy module establishes a second SSL connection between the Nginx proxy module and the simulated server based on the original SSL handshake information, including: the Nginx proxy module performs a random number exchange with the simulated server according to the client random number in the original SSL handshake information; after completing the random number exchange between the Nginx proxy module and the simulated server, the Nginx proxy module uses the pre-master key in the original SSL handshake information and the simulated server to jointly generate the master key to complete the establishment of the second SSL connection between the Nginx proxy module and the simulated server.
[0076] In which, during the process of establishing the above-mentioned first SSL connection, the above-mentioned original SSL handshake information sent by the above-mentioned simulated client is attached before the first SSL handshake message sent by the above-mentioned simulated client to the above-mentioned Nginx proxy module; during the process of establishing the above-mentioned second SSL connection, the client random number in the above-mentioned original SSL handshake information is carried in the first SSL handshake message sent by the above-mentioned Nginx proxy module to the above-mentioned simulated server.
[0077] Here, the method uses the Nginx proxy module to exchange random numbers with the simulated client and server respectively and jointly generate a master key, thereby ensuring the security and consistency of the first SSL connection and the second SSL connection, improving the accuracy and security of HTTPS mirror traffic decryption, and optimizing the SSL handshake process, reducing the system load, and enhancing the performance and reliability of the overall system.
[0078] Step S205: The Nginx proxy module decrypts the original SSL message based on the master key and then performs a security detection operation.
[0079] In some examples, the Nginx proxy module decrypts the original SSL message based on the master key through a preset hardware acceleration device to obtain the plain text of the original SSL message.
[0080] The embodiment of the present invention provides a traffic detection method, comprising: when the received mirror traffic is HTTPS mirror traffic, for the mirror traffic of the first HTTPS traffic sent by the client to the server in the HTTPS mirror traffic, the SSL parser parses the HTTPS mirror traffic to obtain the original SSL message and original SSL handshake information of the first HTTPS traffic; for the mirror traffic of the second HTTPS traffic sent by the server to the client in the HTTPS mirror traffic, the SSL parser parses the HTTPS mirror traffic to obtain the original SSL message of the second HTTPS traffic, and the SSL parser sends the original SSL message of the first HTTPS traffic to the server through The simulated client sends the original SSL message of the second HTTPS traffic to the Nginx proxy module through the simulated server, and the original SSL handshake information is sent to the Nginx proxy module through the simulated client; the Nginx proxy module establishes the first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and establishes the second SSL connection between the Nginx proxy module and the simulated server; wherein the master key used for the first SSL connection is the same as that used for the second SSL connection; the Nginx proxy module performs security detection operations after decrypting the original SSL message based on the master key. This method realizes accurate SSL message parsing and decryption for the HTTPS mirror traffic from the client to the server through the collaborative work of the SSL parser and the Nginx proxy module, and ensures the security and consistency of the decryption process by establishing a two-way SSL connection, thereby improving the accuracy and efficiency of security detection, while optimizing the SSL processing flow and reducing the system load.
[0081] Example 3
[0082] For ease of understanding, this embodiment, based on Embodiment 2, will further detail the steps of the flow detection method during specific operations.
[0083] First, in the bypass process, if the mirrored traffic received by the data plane is determined to be HTTPS traffic, the HTTPS traffic message is sent to the SSL parser for processing. The SSL parser puts the message in the request direction of the HTTPS mirrored traffic into the sending queue of the simulated client, and puts the message in the response direction into the sending queue of the simulated server, so as to divide the traffic data message of the above HTTPS mirrored traffic into the mirrored traffic of the first HTTPS traffic sent from the client to the server and the mirrored traffic of the second HTTPS traffic sent from the server to the client; and the original SSL message carried by the above traffic data message is parsed by the above SSL parser to obtain the original SSL handshake information; wherein, the above original SSL handshake information includes: client random number, server random number, key suite, compression algorithm and pre-master key.
[0084] Then, the SSL parser appends the original SSL handshake information of the simulated client before the first SSL handshake message sent by the simulated client to the Nginx proxy module, and obtains the SSL handshake message to be sent by the simulated client to the Nginx proxy module.
[0085] The simulated client sends the above SSL handshake message to the Nginx proxy module, and performs an SSL handshake with the Nginx proxy module. After the Nginx proxy module parses the additional original SSL handshake information from the SSL handshake message of the simulated client, when replying to the SSL handshake message of the simulated client, it will use the server random number and pre-master key therein to establish the first SSL connection between the Nginx proxy module and the simulated client. In this process, the Nginx proxy module will calculate the same master key as the original SSL connection, and then decrypt the subsequent SSL encrypted data to obtain the plaintext of the HTTP request, and perform security detection on the plaintext of the HTTP request.
[0086] Furthermore, after the HTTP request detection is completed, the Nginx proxy module will establish an SSL connection with the simulated server. The Nginx proxy module will use the original SSL handshake information to establish a second SSL connection between the Nginx proxy module and the simulated server. During this process, the Nginx proxy module also calculates the same master key as the original SSL connection, and then decrypts the subsequent SSL encrypted data to obtain the plaintext of the HTTP response, and performs security detection on the plaintext of the HTTP request.
[0087] For ease of understanding, Figure 4 A schematic diagram of a simulation of original SSL handshake information transmitted by a client to an Nginx proxy module is provided in an embodiment of the present invention.
[0088] Depend on Figure 4 As shown, the simulated client needs to pass the original SSL handshake information to the Nginx proxy module, so that the Nginx proxy module uses the same handshake information to perform SSL handshake with the simulated client and simulated server, and calculates the same master key, thereby decrypting and security testing the HTTPS traffic transmitted between the client and the server.
[0089] The original SSL handshake information includes: client random number, session ID, server random number, encryption suite and pre-master key. The session ID is used to uniquely identify the session.
[0090] The original SSL handshake information may also include a compression algorithm, which is used to reduce the size of the message data so as to transmit the message more efficiently.
[0091] The above information in the original SSL handshake information can be assembled in TLV format and sent to the Nginx proxy module together with the first SSL handshake message to be sent by the simulated client to the Nginx proxy module as a payload of the TCP protocol.
[0092] Among them, TLV (Type-Length-Value) is a simple and flexible format for encoding data. It represents each data item as three components, including: Type, which identifies the type of the data item, usually a fixed length field, such as one or two bytes. Length, which specifies the length of the subsequent value field, is also a fixed length field used to indicate the size of the actual data part. Value: contains the actual data content, and the length is specified by the previous length field.
[0093] Furthermore, during the SSL handshake process between the Nginx proxy module and the simulated client, the simulated client acts as a client and the Nginx proxy module acts as a server.
[0094] During the SSL handshake process between the Nginx proxy module and the simulated server, the Nginx proxy module acts as the client and the simulated server acts as the server.
[0095] The SSL handshake process between the Nginx proxy module and the simulated client, and the SSL handshake process between the Nginx proxy module and the simulated server involve the following messages:
[0096] The ClientHello message is the first message in the TLS (Transport Layer Security) or SSL (Secure Sockets Layer) handshake protocol and is initiated by the client.
[0097] The ServerHello message is the second message in the TLS or SSL handshake protocol and is sent by the server after receiving the ClientHello message from the client.
[0098] The ClientKeyExchange message is an important message in the TLS or SSL handshake protocol, and is sent by the client after receiving the server's ServerHello, certificate, server key exchange and other messages.
[0099] Furthermore, Figure 5 A schematic diagram of a simulation client and an Nginx proxy module establishing an SSL connection is provided in an embodiment of the present invention. Figure 5 As shown, the simulated client sends the original SSL handshake information and the original ClientHello message to the Nginx proxy module (i.e., Nginx); the Nginx proxy module parses the original SSL handshake information, and uses the server random number, session id, encryption suite, and compression algorithm therein to construct the ServerHello message; the Nginx proxy module constructs the Certificate message based on the pre-imported site certificate; the Nginx proxy module constructs the ServerHelloDone message, and replies the ServerHello+Certificate+ServerHelloDone message to the simulated client; the simulated client sends the original ClientKeyExchange message, ChangeCipherSepc message, and Finished message to the Nginx proxy module; since the key information of the SSL handshake is exactly the same as the key information of the SSL handshake of the original SSL connection, the Nginx proxy module will calculate the same master key, can decrypt the received Finished message normally, and construct the ChangeSipherSpec message and the Finished message to send to the simulated client to complete the SSL handshake.
[0100] Among them, the ClientHello message is the first message in the TLS or SSL handshake protocol, initiated by the simulated client; the ServerHello message is the second message in the TLS or SSL handshake protocol, sent by the Nginx proxy module after receiving the ClientHello message from the simulated client; the ServerHelloDone message is a short message in the TLS or SSL handshake protocol, sent by the Nginx proxy module after sending ServerHello, certificate, and server key; the Finished message is an important message in the TLS or SSL handshake protocol, used to confirm the successful completion of the handshake process and verify the integrity and authenticity of all previously exchanged data.
[0101] For ease of understanding, Figure 6 A schematic diagram of establishing an SSL connection between an Nginx proxy module and a simulated server provided by an embodiment of the present invention. Figure 6 As shown, the Nginx proxy module uses the client random number, encryption suite, and compression algorithm in the original SSL handshake information to construct a ClientHello message and sends it to the simulated server; the simulated server returns the original ServerHello, Certificate, and ServerHelloDone messages; the Nginx proxy module uses the pre-master key in the original SSL handshake information to construct a ClientKeyExchange message; because the key information of the SSL handshake is exactly the same as the SSL handshake key information of the original SSL connection, the Nginx proxy module calculates the same master key and constructs a ChangeSipherSpec message and a Finished message, and then sends the ClientKeyExchange message, ChangeCipherSpec message, and Finished message to the simulated server; the simulated server returns the original ChangeCipherSpec message and Finished message to the Nginx proxy module; the Nginx proxy module can correctly decrypt the original Finished message to complete the SSL handshake.
[0102] In some embodiments of the present application, when it is determined that the above-mentioned mirrored traffic is HTTP mirrored traffic, the above-mentioned HTTP mirrored traffic is parsed by an HTTP parser connected to the data plane to obtain HTTP traffic data; and the above-mentioned HTTP mirrored traffic is security checked according to the HTTP traffic data by the above-mentioned Nginx proxy module.
[0103] Here, the above-mentioned HTTP traffic data can be divided into: request data and response data; the above-mentioned method includes: the HTTP parser sends the above-mentioned request data to the sending queue of the above-mentioned simulated client, and sends the above-mentioned response data to the sending queue of the simulated server; the simulated client sends the above-mentioned request data to the above-mentioned Nginx proxy module; when the above-mentioned Nginx proxy module receives the above-mentioned request data, it establishes a TCP connection with the simulated server and forwards the above-mentioned request data to the simulated server; after the simulated server receives the above-mentioned request data, it sends the response data in the sending queue to nginx for security detection, so as to complete the security detection of HTTP traffic by the Nginx proxy module.
[0104] In one implementation manner, the key suite of the master key is constructed based on an RSA key exchange algorithm.
[0105] In some embodiments, the step in which the Nginx proxy module decrypts the original SSL message based on the master key includes: the Nginx proxy module decrypts the encrypted data in the original SSL message based on the master key through a preset hardware acceleration device to obtain the plaintext of the original SSL message.
[0106] Here, the Nginx proxy module can send the master key and the encrypted data in the original SSL message to a preset QAT acceleration card, and decrypt the encrypted data in the original SSL message through the QAT acceleration card to obtain the plain text of the original SSL message.
[0107] For ease of understanding, Figure 7 A schematic diagram of the structure of a flow detection device for an extended QAT hardware acceleration card provided in an embodiment of the present invention.
[0108] Depend on Figure 7 As shown, since the SSL encryption and decryption implemented by software consumes a lot of performance, the above-mentioned traffic detection device can also be expanded with a QAT hardware acceleration card. After the expansion, the Nginx proxy module will send the master key and the encrypted data in the original SSL message to the QAT hardware acceleration card for decryption, thereby reducing the performance consumption of SSL encryption and decryption and enabling the device to handle more traffic.
[0109] Furthermore, the expanded traffic detection device adds three parts: QAT hardware acceleration card, QAT engine, and QAT driver. Specifically, when the Nginx proxy module is initialized, it will initialize the QAT engine. After that, the process of SSL decryption by the Nginx proxy module becomes: the Nginx proxy module sends the SSL ciphertext to the QAT engine, then to the QAT driver, and then to the QAT hardware acceleration card. After that, the Nginx proxy module will process other data asynchronously. Among them, the QAT hardware acceleration card performs decryption, and the QAT engine will keep trying to obtain the result. If the decryption is completed, it will notify the Nginx proxy module to obtain the HTTP plaintext; after the Nginx proxy module obtains the HTTP plaintext, it will perform security detection on the HTTP plaintext.
[0110] In an embodiment of the present invention, a flow detection device for implementing a flow detection method can be mounted on a forwarding device, so that the forwarding device makes a mirror image of the flow and uploads it to the flow detection device, thereby performing security detection and early warning on HTTP or HTTPS flow.
[0111] Example 2
[0112] Based on the above embodiments, Figure 8 A schematic structural diagram of another flow detection device provided in an embodiment of the present invention.
[0113] Depend on Figure 8 As shown, the device comprises:
[0114] The SSL parser 31 is used for parsing the original SSL message and the original SSL handshake information transmitted between the client and the server from the above HTTPS mirror traffic when the received mirror traffic is HTTPS mirror traffic, and sending the above original SSL message to the Nginx proxy module 33 through the simulated client 32 and the simulated server 34 according to the traffic direction of the above HTTPS mirror traffic, and sending the original SSL handshake information to the Nginx proxy module 33 through the simulated client 32.
[0115] The simulated client 32 is used to receive the original SSL message and the original SSL handshake information sent by the SSL parser 31 according to the traffic direction of the HTTPS mirror traffic, and send them to the Nginx proxy module 33.
[0116] The simulation server 34 is used to receive the original SSL message sent by the above-mentioned SSL parser 31 according to the traffic direction of the above-mentioned HTTPS mirror traffic, and send it to the Nginx proxy module 33.
[0117] The above-mentioned Nginx proxy module 33 is used to establish a first SSL connection between the above-mentioned Nginx proxy module 33 and the above-mentioned simulated client 32 based on the above-mentioned original SSL handshake information, and to establish a second SSL connection between the above-mentioned Nginx proxy module 33 and the above-mentioned simulated server 34; wherein, the master key used by the above-mentioned first SSL connection is the same as that used by the above-mentioned second SSL connection; and after decrypting the above-mentioned original SSL message based on the above-mentioned master key, a security detection operation is performed.
[0118] In some of the embodiments, the SSL parser 31 is also used to parse the mirror traffic of the first HTTPS traffic sent by the client to the server in the HTTPS mirror traffic to obtain the original SSL message and original SSL handshake information of the first HTTPS traffic; and send the original SSL message of the first HTTPS traffic to the Nginx proxy module 33 through the simulated client 32.
[0119] In some of the embodiments, the SSL parser 31 is also used to parse the mirror traffic of the second HTTPS traffic sent by the server to the client in the HTTPS mirror traffic to obtain the original SSL message of the second HTTPS traffic; and send the original SSL message of the second HTTPS traffic to the Nginx proxy module 33 through the simulated server 34.
[0120] In some of the embodiments, during the establishment of the first SSL connection, the original SSL handshake information sent by the simulated client 32 is attached before the first SSL handshake message sent by the simulated client 32 to the Nginx proxy module; during the establishment of the second SSL connection, the client random number in the original SSL handshake information is carried in the first SSL handshake message sent by the Nginx proxy module to the simulated server.
[0121] In some of the embodiments, the Nginx proxy module 33 is also used to: receive the original SSL handshake information sent by the simulated client 32, and perform a random number exchange with the simulated client 32 based on the server random number in the original SSL handshake information; after the random number exchange with the simulated client 32 is completed, use the pre-master key in the original SSL handshake information and the simulated client 32 to jointly generate the master key to complete the establishment of the first SSL connection between the Nginx proxy module 33 and the simulated server 34.
[0122] In some of the embodiments, the Nginx proxy module 33 is also used to perform a random number exchange with the simulated server 34 based on the client random number in the original SSL handshake information; after the random number exchange with the simulated server 34 is completed, the master key is generated together with the simulated server 34 using the pre-master key in the original SSL handshake information to complete the establishment of a second SSL connection between the Nginx proxy module 33 and the simulated server 34.
[0123] In some of the implementation modes, the Nginx proxy module 33 is further used to: decrypt the original SSL message based on the master key through a preset hardware acceleration device to obtain the plain text of the original SSL message.
[0124] In some of the embodiments, the SSL parser 31, the simulated client 32 and the simulated server 34 are deployed in a bypass process; the SSL parser 31 is connected to the simulated client 32 and the simulated server 34 respectively.
[0125] The flow detection device provided in the embodiment of the present invention has the same technical features as the flow detection method provided in the above embodiment, so it can also solve the same technical problems and achieve the same technical effects. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the device described above can refer to the corresponding process in the above method embodiment, and will not be repeated here.
[0126] Example 4
[0127] This embodiment provides an electronic device, including a processor and a memory, wherein the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement the steps of the flow detection device method.
[0128] This embodiment provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the flow detection device method are implemented.
[0129] See also Fig. 9 The schematic diagram of the structure of an electronic device shown in the figure comprises: a memory 41 and a processor 42. The memory 41 stores a computer program that can be run on the processor 42. When the processor executes the computer program, the steps provided by the above-mentioned flow detection device method are implemented.
[0130] like Fig. 9As shown, the device further includes: a bus 43 and a communication interface 44, a processor 42, a communication interface 44 and a memory 41 are connected via the bus 43; the processor 42 is used to execute executable modules stored in the memory 41, such as computer programs.
[0131] The memory 41 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 44 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used.
[0132] The bus 43 may be an ISA bus, a PCI bus, or an EISA bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig. 9 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0133] Among them, the memory 41 is used to store the program, and the processor 42 executes the program after receiving the execution instruction. The method performed by the flow detection device disclosed in any embodiment of the present invention can be applied to the processor 42, or implemented by the processor 42. The processor 42 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 42. The above processor 42 can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present invention can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present invention can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 41, and the processor 42 reads the information in the memory 41 and completes the steps of the above method in combination with its hardware.
[0134] Furthermore, an embodiment of the present invention also provides a machine-readable storage medium, which stores machine-executable instructions. When the machine-executable instructions are called and executed by the processor 42, the machine-executable instructions prompt the processor 42 to implement the above-mentioned flow detection device method.
[0135] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0136] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the above-mentioned units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0137] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0138] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0139] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0140] The embodiments or examples of the present disclosure are not exhaustive, but are only illustrative of some embodiments or examples, and are not intended to be specific limitations on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment or example can be implemented as an independent example, and the steps can be combined arbitrarily. For example, the scheme after removing some steps in a certain embodiment or example can also be implemented as an independent example, and the order of the steps in a certain embodiment or example can be arbitrarily exchanged. In addition, the optional methods or optional examples in a certain embodiment or example can be combined arbitrarily; in addition, the various embodiments or examples can be combined arbitrarily, for example, some or all steps of different embodiments or examples can be combined arbitrarily, and a certain embodiment or example can be combined arbitrarily with the optional methods or optional examples of other embodiments or examples.
[0141] Furthermore, the terms “first”, “second”, and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.
[0142] The above are only preferred implementations of the present application. It should be pointed out that ordinary technicians in this technical field can make several improvements and modifications without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A flow detection method, characterized in that: include: When the received mirrored traffic is HTTPS mirrored traffic, the SSL parser parses the HTTPS mirrored traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server; The SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirror traffic, and sends the original SSL handshake information to the Nginx proxy module through the simulated client; The Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and establishes a second SSL connection between the Nginx proxy module and the simulated server; wherein the first SSL connection and the second SSL connection use the same master key; The Nginx proxy module performs a security detection operation after decrypting the original SSL message based on the master key.
2. The flow detection method according to claim 1, characterized in that: The SSL parser parses the HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server, including: For the mirrored traffic of the first HTTPS traffic sent from the client to the server in the HTTPS mirrored traffic, the SSL parser parses the HTTPS mirrored traffic to obtain the original SSL message and original SSL handshake information of the first HTTPS traffic; The SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirror flow, including: The SSL parser sends the original SSL message of the first HTTPS traffic to the Nginx proxy module through a simulated client.
3. The flow detection method according to claim 1, characterized in that: The SSL parser parses the HTTPS mirror traffic to obtain the original SSL message and original SSL handshake information transmitted between the client and the server, including: For the mirrored traffic of the second HTTPS traffic sent by the server to the client in the HTTPS mirrored traffic, the SSL parser parses the HTTPS mirrored traffic to obtain the original SSL message and original SSL handshake information of the second HTTPS traffic; The SSL parser sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the flow direction of the HTTPS mirror flow, including: The SSL parser sends the original SSL message of the second HTTPS traffic to the Nginx proxy module through the simulated server.
4. The flow detection method according to claim 1, characterized in that: The Nginx proxy module establishes a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, including: The Nginx proxy module receives the original SSL handshake information sent by the simulated client, and performs random number exchange with the simulated client according to the server random number in the original SSL handshake information; After completing the random number exchange between the Nginx proxy module and the simulated client, the Nginx proxy module uses the pre-master key in the original SSL handshake information and the simulated client to jointly generate the master key to complete the establishment of the first SSL connection between the Nginx proxy module and the simulated server.
5. The flow detection method according to claim 4, characterized in that: The Nginx proxy module establishes a second SSL connection between the Nginx proxy module and the simulated server based on the original SSL handshake information, including: The Nginx proxy module executes a random number exchange with the simulated server according to the client random number in the original SSL handshake information; After completing the random number exchange between the Nginx proxy module and the simulated server, the Nginx proxy module uses the pre-master key in the original SSL handshake information and the simulated server to jointly generate the master key to complete the establishment of a second SSL connection between the Nginx proxy module and the simulated server.
6. The flow detection method according to any one of claims 1 to 5, characterized in that: During the establishment of the first SSL connection, the original SSL handshake information sent by the simulated client is appended before the first SSL handshake message sent by the simulated client to the Nginx proxy module; During the establishment of the second SSL connection, the client random number in the original SSL handshake information is carried in the first SSL handshake message sent by the Nginx proxy module to the simulated server.
7. The flow detection method according to claim 1, characterized in that: The Nginx proxy module decrypts the original SSL message based on the master key, including: The Nginx proxy module decrypts the encrypted data in the original SSL message based on the master key through a preset hardware acceleration device to obtain the plain text of the original SSL message.
8. The flow detection method according to claim 1, characterized in that: The SSL parser, the simulated client and the simulated server are deployed in a bypass process; the SSL parser is connected to the simulated client and the simulated server respectively.
9. A flow detection device, characterized in that: include: An SSL parser, for when the received mirror traffic is HTTPS mirror traffic, the SSL parser parses the HTTPS mirror traffic to obtain the original SSL message and the original SSL handshake information transmitted between the client and the server, and sends the original SSL message to the Nginx proxy module through the simulated client and the simulated server according to the traffic direction of the HTTPS mirror traffic, and sends the original SSL handshake information to the Nginx proxy module through the simulated client; A simulated client is used to receive the original SSL message and the original SSL handshake information sent by the SSL parser according to the traffic direction of the HTTPS mirror traffic, and send them to the Nginx proxy module; The simulation server is used to receive the original SSL message sent by the SSL parser according to the traffic direction of the HTTPS mirror traffic, and send it to the Nginx proxy module; The Nginx proxy module is used to establish a first SSL connection between the Nginx proxy module and the simulated client based on the original SSL handshake information, and to establish a second SSL connection between the Nginx proxy module and the simulated server; wherein the first SSL connection and the second SSL connection use the same master key; The Nginx proxy module is also used to perform security detection operations after decrypting the original SSL message based on the master key.
10. An electronic device, characterized in that: The electronic device includes a processor and a memory, wherein the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement the flow detection method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Data transmission method and device, transmission node and storage medium
CN115865417A
Detection method and device for bypass monitoring HTTPS
CN116055475A
Method for realizing bypass decryption of HTTPS data traffic
CN117254966A
Bypass method and device based on nginx, electronic equipment and storage medium
CN117376402A
HTTPS flow data processing method and system, electronic equipment and storage medium
CN117811819A