Network quantum security risk assessment method and device based on deep packet inspection

Through the network quantum security risk assessment method based on deep packet detection, the encryption algorithm used in the encryption protocol is identified, which solves the problem of lack of cognition and response capabilities for quantum computing threats in the prior art, and realizes efficient evaluation and monitoring of network quantum security risks.

CN120017269APending Publication Date: 2025-05-16REGULAR QUANTUM (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510300381.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Existing network security monitoring systems lack the ability to recognize and respond to quantum computing threats, and are unable to promptly detect and evaluate quantum security risks in the network.

Method used

The network quantum security risk assessment method based on deep packet detection is used to evaluate the system's network quantum security risks by obtaining network traffic, extracting encryption parameters in the target message, and using the preset algorithm feature library for matching and analysis, the encryption algorithm used in the encryption protocol is accurately identified, thereby evaluating the system's network quantum security risks.

Benefits of technology

It improves the ability to evaluate the quantum security risks of the system network, and can accurately identify the encryption algorithms used in the encryption protocol, helping network administrators quickly discover and repair potential quantum security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017269A_ABST
    Figure CN120017269A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network quantum security risk assessment method based on deep packet inspection, which is applied to any one of two communication parties performing network communication by using at least one encryption protocol, and comprises the following steps: acquiring network traffic of a system; extracting encryption parameters included in the target message from the loads of the plurality of target data packets according to a preset rule by adopting a deep packet detection technology; matching and analyzing the encryption parameters by using a preset algorithm feature library to obtain an encryption algorithm used by an encryption protocol corresponding to the target message; determining a target encryption protocol using a non-quantum security encryption algorithm; the traffic and the connection state of the network path associated with the target encryption protocol are used for evaluating the network quantum security risk of the system. Therefore, the load of the data packet in the network flow is detected through the deep packet detection technology, and the encryption algorithm used by the encryption protocol can be accurately identified, so that the network quantum security risk assessment capability of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a network quantum security risk assessment method and device based on deep packet inspection. Background Art

[0002] With the rapid development of quantum computing technology, traditional asymmetric encryption algorithms are facing increasingly severe security threats. For example, for elliptic curve cryptography (ECC) and RSA (Rivest-Shamir-Adleman) encryption algorithms, the security of these algorithms is mainly based on the computational complexity of large number factorization and discrete logarithm problems, and quantum computers have the potential to solve these problems in polynomial time, thereby cracking existing encryption systems.

[0003] However, existing network security monitoring systems mainly focus on traditional network attacks, such as malware and distributed denial of service (DDoS) attacks, and lack in-depth analysis of specific algorithms used in encrypted communications. Therefore, they generally lack the ability to recognize and respond to quantum computing threats.

[0004] Although some systems can identify the type of encryption protocol, such as transport layer security (TLS) or internet protocol security (IPsec), they cannot accurately identify the specific encryption algorithm used within the protocol. This makes it difficult for network administrators to promptly discover and assess quantum security risks in the network. Summary of the invention

[0005] The present application provides a network quantum security risk assessment method, device and computer storage medium based on deep packet inspection, which can accurately identify the encryption algorithm used by the encryption protocol, thereby improving the ability to assess the system network quantum security risk.

[0006] In the first aspect, the present application provides a network quantum security risk assessment method based on deep packet inspection, which is applied to any one of the two communicating parties that use at least one encryption protocol for network communication, and the method includes: obtaining the network traffic of the system; the network traffic includes multiple target data packets, and the payloads of the multiple target data packets are used to transmit target messages corresponding to at least one encryption protocol; the target message is a negotiation message sent by the communicating parties to determine the encryption parameters during the handshake phase of the encryption protocol; using deep packet inspection technology to extract the encryption parameters included in the target message from the payloads of multiple target data packets according to preset rules; the preset rules include matching conditions for specifying target messages and encryption parameters; using a preset algorithm feature library to match and analyze the encryption parameters to obtain the encryption algorithm used by the encryption protocol corresponding to the target message; according to the encryption algorithm used, determining the target encryption protocol that uses a non-quantum secure encryption algorithm from at least one encryption protocol; the traffic and connection status of the network path associated with the target encryption protocol are used to assess the network quantum security risk of the system.

[0007] Therefore, by detecting the payload of data packets in network traffic through deep packet inspection technology, the encryption algorithm used by the encryption protocol can be accurately identified, thereby improving the system's network quantum security risk assessment capabilities.

[0008] In one possible implementation, extracting encryption parameters included in a target message includes: performing a security check on a target message corresponding to at least one encryption protocol using preset rules to obtain a target message that complies with the security check; and extracting the encryption parameters included in the target message from the target message that complies with the security check.

[0009] In one possible implementation, a security check is performed on a target message corresponding to at least one encryption protocol using preset rules to obtain a target message that complies with the security check, including: using preset rules to perform a security check on the encryption protocol type of at least one target message to obtain a target message that complies with the preset encryption protocol type; for a target message that complies with the preset encryption protocol type, determining the encryption protocol version used by the target message; and performing a security check on the message type of the target message according to the encryption protocol version to obtain a target message that complies with the security check.

[0010] In one possible implementation, encryption parameters are matched and analyzed using a preset algorithm feature library, including: matching and analyzing encryption algorithm features included in the encryption parameters with the preset algorithm feature library; the preset algorithm feature library includes multiple key-value pairs, each key-value pair represents a correspondence between an encryption algorithm and multiple encryption algorithm features of the encryption algorithm.

[0011] In a possible implementation, the encryption parameters are matched and analyzed using a preset algorithm feature library, including: using an AC automaton to match and analyze the encryption parameters and the preset algorithm feature library.

[0012] In one possible implementation, determining a target encryption protocol that uses a non-quantum-safe encryption algorithm from at least one encryption protocol includes: obtaining a quantum security performance of the encryption algorithm used according to preset quantum security assessment data; and determining a target encryption protocol that uses a non-quantum-safe encryption algorithm from at least one encryption protocol according to the quantum security performance of the encryption algorithm used.

[0013] In one possible implementation, the method also includes: counting a first number of target messages corresponding to at least one encryption protocol in the network traffic; classifying the encryption parameters included in the target messages, and counting a second number of encryption parameters in each category in the classification; the first number and the second number are used to evaluate the network quantum security risk of the system.

[0014] In one possible implementation, the traffic and connection status of the network path associated with the target encryption protocol are monitored by a data visualization tool.

[0015] In the second aspect, the present application provides a network quantum security risk assessment device based on deep packet inspection, which is deployed on either party of the communication using at least one encryption protocol for network communication, and the device includes: an acquisition module, used to obtain the network traffic of the system; the network traffic includes multiple target data packets, and the payloads of the multiple target data packets are used to transmit target messages corresponding to at least one encryption protocol; the target message is a negotiation message sent by the communicating parties to determine the encryption parameters during the handshake phase of the encryption protocol; an extraction module, used to extract the encryption parameters included in the target message from the payloads of multiple target data packets according to preset rules using deep packet inspection technology; the preset rules include matching conditions for specifying target messages and encryption parameters; a matching and analysis module, used to match and analyze encryption parameters using a preset algorithm feature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message; an output module, used to determine the target encryption protocol using a non-quantum secure encryption algorithm from at least one encryption protocol based on the encryption algorithm used; the traffic and connection status of the network path associated with the target encryption protocol are used to assess the network quantum security risk of the system.

[0016] In a third aspect, the present application provides a computer storage medium having instructions stored therein. When the instructions are executed on a computer, the computer executes the method described in the first aspect or any possible implementation of the first aspect.

[0017] It can be understood that the beneficial effects of the second to third aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 An architecture diagram of a network quantum security risk assessment system based on deep packet inspection provided in an embodiment of the present application;

[0020] Figure 2 A deep packet inspection technology workflow diagram provided in an embodiment of the present application;

[0021] Figure 3 A flow chart of a network quantum security risk assessment method based on deep packet inspection provided in an embodiment of the present application;

[0022] Figure 4 TLS protocol handshake message detection flow chart provided for the embodiment of the present application;

[0023] Figure 5 A schematic diagram of a network quantum security risk assessment device based on deep packet inspection provided in an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0025] The following is an introduction to the relevant technologies involved in this application:

[0026] 1. Deep Packet Inspection (DPI): An advanced packet filtering technology that can check the payload of a packet rather than just its header information. It is used in network security, traffic management, content filtering and other fields. In the present invention, this technology is used to deeply analyze the handshake message of the encryption protocol and extract the encryption parameter suite information.

[0027] 2. Quantum risk resistance: refers to the ability to resist or reduce the security threats posed by quantum computing to existing encryption systems. It is used in the fields of cryptography, network security, information protection, etc. In this invention, quantum risk resistance refers to the ability to identify and monitor encryption algorithms that are vulnerable to quantum computing attacks.

[0028] 3. Real-time monitoring: refers to observing, recording and analyzing at the same time or within a short period of time when an event occurs. It is used in network management, security monitoring, industrial control and other fields. In this invention, this technology is used to continuously analyze network traffic and timely discover and report potential quantum security risks.

[0029] 4. Quantum computing: refers to the computing method that uses the principles of quantum mechanics to process information. It is used in the fields of cryptanalysis, optimization problems, and simulation of quantum systems. In this invention, it represents a potential threat to classical encryption algorithms, especially RSA, ECC, DH (Diffie-Hellman) and other algorithms.

[0030] 5. Encryption protocol: refers to a series of rules and steps used to protect communication security. It is used in network communication, data transmission, identity authentication and other fields. In this invention, the focus is on the key exchange and encryption algorithm selection process in common security protocols such as TLS and IPsec. With the rapid development of quantum computing technology, traditional asymmetric encryption algorithms are facing increasingly severe security threats. However, current network security monitoring systems generally lack the ability to recognize and respond to quantum computing threats. This makes it impossible for network managers to promptly discover and evaluate quantum security risks in the network.

[0031] In addition, most existing visualization tools can only display network topology and traffic statistics, but lack an intuitive presentation of the security of encryption algorithms, which makes it difficult for network administrators to quickly locate and evaluate potential quantum security risk points.

[0032] In view of this, the embodiment of the present application uses deep packet inspection technology to perform in-depth inspection on data packets in network traffic, and can obtain at least one target message corresponding to the encryption protocol in the handshake phase from the payload of the data packet. Then, the encryption parameters included in the target message are matched and analyzed using the preset algorithm feature library, and the encryption algorithm used by the encryption protocol can be accurately identified.

[0033] Furthermore, by judging the quantum security of the encryption algorithm used in the encryption protocol, the network quantum security status of the network topology associated with the encryption protocol with quantum security risks can be monitored and displayed in real time, thereby improving the system's network quantum security risk assessment capabilities and assisting network managers to quickly discover risks and troubleshoot problems.

[0034] For example, Figure 1The figure shows an architecture diagram of a network quantum security risk assessment system based on deep packet inspection provided in an embodiment of the present application.

[0035] like Figure 1 As shown, the network quantum security risk assessment system based on deep packet inspection is deployed on either of the two communicating parties that use at least one encryption protocol for network communication. The two communicating parties can be a client and a server.

[0036] The network quantum security risk assessment system includes: a network traffic collection module 110, a deep packet inspection module 120, an algorithm identification module 130, a visualization and monitoring module 140 and a network management module 150. Figure 1 The connection relationship shown in .

[0037] The network traffic collection module 110 is used to capture the network traffic passing through the system network interface, and the network traffic includes a large number of data packets. The data packet includes a header and a payload. The header contains the metadata of the data packet, such as the source address, the destination address, the network protocol type, etc., and the payload contains the actual data to be transmitted.

[0038] The deep packet inspection module 120 analyzes the collected data packets using deep packet inspection technology. The deep packet inspection technology enables the deep packet inspection module 120 to detect not only the header information of the data packet, but also the messages related to network applications, services, and encryption protocols included in the data packet payload.

[0039] Information related to encryption protocols includes negotiation messages used to implement encryption protocol handshakes. Encryption protocol handshakes are a key step in establishing secure communications, and involve a series of message exchanges between the client and the server to negotiate encryption parameters, verify identities, and establish encrypted communication channels.

[0040] The deep packet inspection module 120 also extracts a target message from the detected negotiation message, where the target message is a negotiation message sent by both communicating parties to determine encryption parameters during the handshake phase of the encryption protocol.

[0041] The target message includes encryption parameters, which include information such as encryption algorithm, authentication method and key. After completing the handshake of the encryption protocol, the communicating parties can transmit data on the established communication channel based on the encryption protocol.

[0042] The algorithm identification module 130 is responsible for identifying and classifying the encryption algorithm of the encryption parameter transmission according to the preset algorithm feature library.

[0043] The visualization and monitoring module 140 is used to determine the target encryption protocol that uses a non-quantum safe encryption algorithm from the encryption protocols included in the network traffic according to the processing results of the algorithm identification module 130, analyze the network path associated with the target encryption protocol, perform real-time analysis on the traffic and connection status of the associated network path, and present the analysis results to the network management personnel in a graphical manner.

[0044] The network management module 150 is used to manage and protect the network based on the analysis results provided by the visualization and monitoring module 140. It provides network management tools for network management personnel to make decisions, such as adjusting security policies, responding to security incidents, etc.

[0045] In summary, the network quantum security risk assessment system based on deep packet inspection can realize the network traffic analysis and monitoring process from data collection to analysis, identification, visualization, and finally management and decision-making by network administrators. This process is designed to help network administrators monitor and protect the network environment more effectively.

[0046] For example, Figure 2 A workflow diagram of a deep packet inspection technology provided in an embodiment of the present application is shown in FIG.

[0047] like Figure 2 As shown in the figure, the deep packet inspection technology workflow consists of Figure 1 The deep packet inspection module 120 in the embodiment is implemented, and mainly includes the following operation steps:

[0048] Step S201, receiving network traffic.

[0049] For example, receiving Figure 1 The network traffic collected by the network traffic collection module 110 includes a large number of data packets.

[0050] Step S202, parsing the header information of the data packet.

[0051] Exemplarily, when processing network traffic, the deep packet inspection module 120 analyzes header information of data packets included in the network traffic to identify the type and structure of the data packets.

[0052] Step S203, extracting the target message.

[0053] For example, since each message related to network applications, services, and encryption protocols may be divided into multiple data packets for transmission because its size exceeds the maximum transmission unit of the network, the deep packet inspection module 120 also groups packets according to the type and structure of the data packets to restore the complete messages related to network applications, services, and encryption protocols; and extracts the target message from these messages, which is the negotiation message sent by the communicating parties to determine the encryption parameters during the handshake phase of the encryption protocol.

[0054] Step S204, extracting the encryption algorithm.

[0055] Exemplarily, the target message includes encryption parameters such as encryption algorithm, authentication method and key, etc. By parsing the encryption parameters in the target message, the encryption algorithm used by the encryption protocol can be obtained.

[0056] Finally, the analysis results of the above steps S201-204 are presented, which may be through screen display, log recording or other methods.

[0057] For example, Figure 3 A flowchart of a network quantum security risk assessment method based on deep packet inspection provided by an embodiment of the present application is shown in FIG. The network quantum security risk assessment method can be implemented by any computing unit, server, device, or device cluster with computing and processing capabilities. The network quantum security risk assessment method is applied to any of the two communicating parties using at least one encryption protocol for network communication, and mainly includes the following operating steps:

[0058] Step S301, obtaining the network traffic of the system. The network traffic includes multiple target data packets, and the payloads of the multiple target data packets are used to transmit at least one target message corresponding to an encryption protocol. The target message is a negotiation message sent by both communicating parties to determine encryption parameters during the handshake phase of the encryption protocol.

[0059] In one implementation, the network traffic collection module 110 is deployed at key nodes of the network, such as routers, switches, firewalls or other network monitoring devices, so as to monitor and control the data flow in and out of the network.

[0060] Network traffic includes a large number of data packets, which are used to transmit messages related to network applications, services, and encryption protocols. Among them, the payloads of multiple target data packets in the large number of data packets are used to transmit target messages corresponding to at least one encryption protocol. The target message is a negotiation message sent by the communicating parties during the handshake phase of the encryption protocol to determine the encryption parameters. The encryption parameters include information such as encryption algorithm, authentication method, and key.

[0061] For both communicating parties, they can use at least one encryption protocol for data transmission at the same time. However, in a given communication session, they will negotiate and select a commonly supported encryption protocol to use. This negotiation usually occurs in the handshake phase. For example, during the TLS handshake process, the client and server will determine the encryption protocol to be used in the end by exchanging their respective capabilities (such as a list of supported encryption parameter suites).

[0062] For example, in the TLS V1.2 protocol, the client sends a list of encryption parameter suites it supports in the ClientHello message, and the server selects an encryption parameter suite that both parties support in the ServerHello message. Therefore, the target message is the ServerHello message sent by the server. The encryption parameter suite is a collection of encryption information such as encryption algorithm, authentication method, and key. For example, TLS_RSA_WITH_AES_128_CBC_SHA represents RSA key exchange, AES 128-bit encryption, and SHA1 MAC algorithm.

[0063] In the TLS 1.3 protocol, the client guesses the encryption algorithm that the server may use in the ClientHello phase and sends the parameters used in the guessed algorithm to the server, so there is no need to negotiate the encryption parameters again in the ServerHello phase. Therefore, the target message at this time is the ClientHello message sent by the client.

[0064] Step S302: Deep packet inspection technology is used to extract encryption parameters included in the target message from the payloads of multiple target data packets according to preset rules. The preset rules include matching conditions for specifying target messages and encryption parameters.

[0065] In one implementation, because deep packet inspection technology can analyze the payload of a data packet, it can be used Figure 1 The deep packet inspection module 120 in Figure 2 The illustrated workflow parses messages related to network applications, services, and encryption protocols from network traffic, and extracts target messages and encryption parameters included in the target messages from these messages.

[0066] For example, in the deep packet inspection module 120, the existing network traffic (i.e., the network traffic collected by the network traffic collection module 110) is obtained based on the open source deep packet inspection engine Suricata, and a large number of data packets in the network traffic are detected and processed.

[0067] Optionally, step S301 may be skipped, and network traffic may be captured in real time by monitoring the network interface based on the open source deep packet inspection engine Suricata, so as to detect and process a large number of data packets in the network traffic.

[0068] Exemplarily, a preset rule is set in the deep packet inspection module 120, and the target message and the encryption parameters included in the target message are extracted according to the matching conditions of the target message and the encryption parameters specified by the preset rule.

[0069] For example, if the encryption protocol used by both parties is expected to include at least TLS V1.3, a preset rule can be set in the system that includes the following:

[0070] flowbits: isset, tls.handshake;

[0071] ss1.version:1.3;

[0072] pcre: " / ClientHello / R", " / \\x00\\x0a(.*?)([\\x00-\\xff]{2})(.*?)([\\x00-\\xff]{2}) / s";

[0073] The above content is used to specify the detection of the Client Hello message in the TLS V1.3 encryption protocol handshake process and check the encryption parameter suite included in it. Specifically, the flowbits command is used to track the state of the flow, and isset indicates that a specific flow state "tls.handshake" is set.

[0074] ssl.version specifies that the TLS version to be detected is V1.3.

[0075] pcre represents a regular expression, which is used to match the encryption parameter suite in the Client Hello message and the message. " / ClientHello / R" represents the Client Hello message, "\\x00\\x0a" is the starting byte of the encryption parameter suite in the Client Hello message, and the following pattern matches any byte until a sequence of two arbitrary bytes is encountered, which usually indicates the length of the encryption parameter suite.

[0076] It is understandable that different preset rules may be set in the system for different types and versions of encryption protocols to extract the target message and the encryption parameters included in the target message.

[0077] The process of extracting encryption parameters included in a target message based on preset rules includes: using preset rules to perform a security check on the encryption protocol type of at least one target message to obtain a target message that conforms to the preset encryption protocol type; for a target message that conforms to the preset encryption protocol type, determining the encryption protocol version used by the target message; performing a security check on the target message type according to the encryption protocol version to obtain a target message that conforms to the security check; and extracting the encryption parameters included in the target message from the target message that conforms to the security check.

[0078] For example, for messages detected related to network applications, services, and encryption protocols, the above-mentioned preset rules are used to match the target message and the encryption parameters included in the target message. This includes using "tls.handshake" for security detection of the protocol type, determining the encryption protocol version based on "ssl.version: 1.3", and performing security detection of the message type based on the regular expression " / ClientHello / R", and extracting the encryption parameter suite included in the target message based on the regular expression " / \x00\x0a(.*?)([\x00-\xff]{2})(.*?)([\x00-\xff]{2}) / s".

[0079] It can be understood that different target messages may correspond to different regular expressions for extracting the encryption parameter suite.

[0080] Step S303: Use the preset algorithm feature library to match and analyze the encryption parameters to obtain the encryption algorithm used by the encryption protocol corresponding to the target message.

[0081] In one implementation, the encryption algorithm features in the encryption parameters included in the target message corresponding to at least one encryption protocol are matched and analyzed with the preset algorithm feature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message.

[0082] Exemplarily, the preset algorithm feature library includes multiple key-value pairs, and each key-value pair represents the correspondence between an encryption algorithm and multiple encryption algorithm features of the encryption algorithm.

[0083] For example, the preset algorithm feature library includes the following data structure algorithm_features for storing various encryption algorithms and their corresponding feature strings,

[0084]

[0085]

[0086] This data structure is a set of key-value pairs, where the key represents the encryption algorithm category, such as RSA, DH, ECC, quantum_safe, symmetric categories, and the value is a list of specific algorithms or feature strings under this category. These specific algorithms or feature strings are keywords used to identify specific algorithms in network traffic. For example, the RSA algorithm may be associated with strings such as "RSA" and "RSAES-PKCS1-v1-5".

[0087] In one implementation, an AC automaton (Aho-Corasick automaton) is used to match and analyze encryption parameters and a preset algorithm signature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message. The AC automaton is an efficient algorithm for multi-pattern string search that can match multiple patterns in a single traversal. In this implementation, the AC automaton contains three main functions:

[0088] 1. State transfer function (goto): This function defines how to transfer from one state to another based on the input characters.

[0089] 2. Output function: This function stores the matching results associated with each state, that is, the algorithm feature string matched in this state.

[0090] 3. Failure function: This function is used to quickly jump to the next possible matching state to continue searching when the current state cannot be matched.

[0091] The implementation involves two main steps:

[0092] First, add words: add each algorithm feature string to the automaton, and update the state transition and output functions.

[0093] Second, construct a failure function: use a breadth-first search algorithm to calculate the failure state of each state to optimize the matching efficiency.

[0094] The algorithm identification process uses the constructed AC automaton to match the input encryption parameter suite string. This process includes:

[0095] First, initialize the current state to the starting state.

[0096] Secondly, iterate over each character of the input string, update the current state according to the state transition function and failure function, and check whether there is a matching algorithm feature string.

[0097] If there is output in the current state, the corresponding algorithm is added to the result list.

[0098] Finally, after the traversal is completed, the list of recognized algorithms is returned. If no algorithm is recognized, "unknown" is returned.

[0099] This implementation method can efficiently identify encryption algorithms in network traffic and provide valuable information for network security analysis and monitoring.

[0100] Step S304: Determine a target encryption protocol that uses a non-quantum-safe encryption algorithm from at least one encryption protocol based on the encryption algorithm used. The traffic and connection status of the network path associated with the target encryption protocol are used to assess the network quantum security risk of the system.

[0101] In one implementation, the quantum security performance of the encryption algorithm used by the encryption protocol is obtained according to preset quantum security assessment data. According to the quantum security performance of the encryption algorithm used by the encryption protocol, a target encryption protocol using a non-quantum security encryption algorithm is determined from at least one encryption protocol.

[0102] The preset quantum security assessment data includes quantum security performance data of different encryption algorithms. The encryption algorithm used by the encryption protocol is matched with the preset quantum security assessment data to obtain the quantum security performance of the encryption algorithm used by the encryption protocol. The encryption protocol using a non-quantum security encryption algorithm is the target encryption protocol in at least one encryption protocol.

[0103] Exemplarily, the visualization and monitoring module 140 and the network management module 150 in the figure are also used to monitor, analyze and display the traffic and connection status of the network path associated with the target encryption protocol, so as to manage and protect the system's network environment.

[0104] Optionally, the traffic and connection status of the network path associated with the target encryption protocol are monitored by a data visualization tool, such as using the open source data visualization and monitoring platform Grafana to implement the above monitoring.

[0105] In one implementation, in step S303, using Figure 1 The deep packet inspection module 120 in the system counts a first number of target messages corresponding to at least one encryption protocol in the network traffic; classifies the encryption parameters included in the target message, and counts a second number of encryption parameters in each category in the classification. The first number and the second number are combined with the traffic and connection status of the network path associated with the target encryption protocol to evaluate the network quantum security risk of the system.

[0106] Therefore, this solution uses deep packet inspection technology to deeply analyze network traffic, identify encryption algorithms that are vulnerable to quantum attacks, and monitor network paths that use these algorithms in real time, thereby helping network managers to promptly discover and repair potential quantum security risks and improving the system's network quantum security risk assessment capabilities. In addition, the preset algorithm feature library and preset quantum security assessment data can be updated based on the latest progress in quantum computing research, thereby improving the ability to identify new or custom encryption algorithms and assess network quantum security risks.

[0107] For example, Figure 4The TLS protocol handshake message detection flow chart provided by the embodiment of the present application is shown in FIG. The TLS protocol handshake message detection process is implemented in Python. Before the detection, two rules for the TLS protocol have been set in the system according to the method in step S302. Among them, one preset rule is set for TLS V1.3, and the other preset rule is set for TLS V1.0-1.2. Figure 4 As shown in the figure, the TLS protocol handshake message detection process mainly includes the following running steps:

[0108] Step S401, import necessary libraries.

[0109] For example, before running the main function, you first need to import the required Python libraries. For example, import everything from scapy.all so that you can access all the functions provided by the Scapy library without specifying a module. At the same time, you also import the Counter class from the collections module so that you can call this class for counting and statistics in subsequent steps.

[0110] Step S402, defining encryption parameter suites that are vulnerable to quantum computing attacks and quantum safe.

[0111] For example, two lists are defined: vulnerable_ciphers and

[0112] quantum-safe-ciphers, which are used to store encryption parameter suites that are vulnerable to quantum computing attacks and quantum-safe, respectively.

[0113] Step S403, run the main function.

[0114] Exemplarily, the network traffic is saved in a PCAP format that can be read by the open source deep packet inspection engine Suricata, and a saving path for the network traffic is set.

[0115] Step S404, define the analyze-pcap function.

[0116] Exemplarily, this function is used to analyze the entire PCAP file.

[0117] Step S405, using Suricata to read the PCAP file.

[0118] Exemplarily, the PCAP file is read using Suricata's rdpcap function, and possible exceptions such as file not found or read error are handled.

[0119] Step S406, parsing the data packets in the PCAP file.

[0120] Exemplarily, Suricata is used to traverse each data packet in the PCAP file for parsing to obtain messages related to network applications, services, and encryption protocols.

[0121] Step S407, define the analyze-tls-handshake function.

[0122] Exemplarily, this function is used to analyze the parsed message.

[0123] Step S408, checking whether the message has a TLS layer.

[0124] Exemplarily, for the currently analyzed message, a security check of the protocol type is performed according to preset rules. If there is no TLS layer, step S408 is continued to be performed on the next message. If there is no next message, step S415 is entered.

[0125] Step S409: Check whether it is TLS Handshake.

[0126] Exemplarily, for the currently analyzed message, continue to perform security detection of the protocol type. If the data packet is not TLS Handshake, continue to perform step S408 on the next message. If there is no next message, proceed to step S415.

[0127] Step S410, checking the TLS version.

[0128] For example, the program needs to distinguish between TLS V1.3 and earlier versions TLS V1.0-1.2.

[0129] Step S411, extracting the encryption parameter suite of version V1.3.

[0130] For example, the encryption parameter suite extraction method for TLS V1.3 may be different from that for other versions. The program needs to check the Client Hello message and extract the encryption parameter suite.

[0131] Step S412, extracting the encryption parameter suite of versions V1.0-1.2.

[0132] For example, for TLS V1.0-1.2, the program needs to check the Service Hello message and extract the encryption parameter suite.

[0133] Step S413, analyzing the encryption parameter suite.

[0134] Exemplarily, the program will check whether the extracted encryption parameter suite is present in a list of vulnerable or quantum-safe ones.

[0135] Step S414, returning the encryption parameter suite analysis result.

[0136] Exemplarily, the analyze-tls-handshake function will return the classification result of the encryption parameter suite, which may be "vulnerable", "quantum-safe" or "unknown". Continue to implement step S408 for the next message, and proceed to step S415 if there is no next message.

[0137] Step S415, statistical analysis results.

[0138] Exemplarily, a Counter is used to record the number of analysis results so as to count a first number of TLSHandshake messages and a second number of encryption parameter suites of various types of analysis results.

[0139] Step S416, saving the analysis results.

[0140] Exemplarily, the program prints the analysis results for Figure 1 The algorithm identification module 130, or the visualization and monitoring module 140, or the network management module 150 is called.

[0141] For example, Figure 5 A schematic diagram of a network quantum security risk assessment device based on deep packet inspection provided by an embodiment of the present application is shown. The device is deployed on either party of a communication using at least one encryption protocol for network communication. Figure 5 As shown, the network quantum security risk assessment device 500 includes the following modules:

[0142] The acquisition module 510 is used to acquire the network traffic of the system. The network traffic includes multiple target data packets, and the payloads of the multiple target data packets are used to transmit at least one target message corresponding to the encryption protocol. The target message is a negotiation message sent by the communicating parties to determine the encryption parameters during the handshake phase of the encryption protocol.

[0143] The extraction module 520 is used to extract the encryption parameters included in the target message from the payloads of the plurality of target data packets according to preset rules using deep packet inspection technology. The preset rules include matching conditions for specifying the target message and the encryption parameters.

[0144] The matching and analysis module 530 is used to match and analyze encryption parameters using a preset algorithm feature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message.

[0145] The output module 540 is used to determine a target encryption protocol using a non-quantum-safe encryption algorithm from at least one encryption protocol according to the encryption algorithm used. The traffic and connection status of the network path associated with the target encryption protocol are used to evaluate the network quantum security risk of the system.

[0146] Based on the method in the above embodiment, the embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program runs on a processor, the processor executes the above embodiment. Figure 3 The method shown.

[0147] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0148] The professionals should also be further aware that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0149] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0150] The specific implementation methods described above further illustrate the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only the specific implementation method of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.

Claims

1. A network quantum security risk assessment method based on deep packet inspection, applied to any one of two parties in a network communication using at least one encryption protocol, the method comprising: Get the system's network traffic; The network traffic includes a plurality of target data packets, and the payloads of the plurality of target data packets are used to transmit a target message corresponding to at least one encryption protocol; The target message is a negotiation message for determining encryption parameters sent by both communicating parties during the handshake phase of the encryption protocol; Extracting the encryption parameters included in the target message from the payloads of the plurality of target data packets according to preset rules using deep packet inspection technology; the preset rules include specifying matching conditions between the target message and the encryption parameters; Matching and analyzing the encryption parameters using a preset algorithm feature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message; According to the encryption algorithm used, a target encryption protocol using a non-quantum safe encryption algorithm is determined from at least one encryption protocol; the traffic and connection status of the network path associated with the target encryption protocol are used to evaluate the network quantum security risk of the system.

2. The method according to claim 1, wherein extracting the encryption parameters included in the target message comprises: Performing a security check on a target message corresponding to at least one encryption protocol using the preset rule to obtain a target message that meets the security check; An encryption parameter included in the target message that meets the security check is extracted from the target message.

3. The method according to claim 2, wherein the step of performing a security check on a target message corresponding to at least one encryption protocol using the preset rule to obtain a target message that complies with the security check comprises: Using the preset rule to perform a security check of the encryption protocol type on at least one target message to obtain a target message that conforms to the preset encryption protocol type; For a target message that conforms to a preset encryption protocol type, determining the encryption protocol version used by the target message; A security check of the target message type is performed on the target message according to the encryption protocol version to obtain a target message that meets the security check.

4. According to the method of claim 1, the matching and analyzing of the encryption parameters by using a preset algorithm feature library comprises: The encryption algorithm features included in the encryption parameters are matched and analyzed with the preset algorithm feature library; the preset algorithm feature library includes multiple key-value pairs, each key-value pair represents a corresponding relationship between an encryption algorithm and multiple encryption algorithm features of the encryption algorithm.

5. According to the method of claim 1, the matching and analyzing of the encryption parameters by using a preset algorithm feature library comprises: The encryption parameters and the preset algorithm feature library are matched and analyzed using an AC automaton.

6. The method according to claim 1, wherein determining a target encryption protocol using a non-quantum-safe encryption algorithm from at least one encryption protocol comprises: Obtaining the quantum security performance of the encryption algorithm used according to preset quantum security assessment data; According to the quantum security performance of the encryption algorithm used, a target encryption protocol using a non-quantum security encryption algorithm is determined from at least one encryption protocol.

7. The method according to claim 1, further comprising: Counting a first number of target messages corresponding to at least one encryption protocol in the network traffic; The encryption parameters included in the target message are classified, and the second quantity of the encryption parameters in each category in the classification is counted; the first quantity and the second quantity are used to evaluate the network quantum security risk of the system.

8. According to the method of claim 1, the traffic and connection status of the network path associated with the target encryption protocol are monitored by a data visualization tool.

9. A network quantum security risk assessment device based on deep packet inspection, deployed on either party of a communication using at least one encryption protocol for network communication, the device comprising: Acquisition module, used to obtain the system's network traffic; The network traffic includes a plurality of target data packets, and the payloads of the plurality of target data packets are used to transmit a target message corresponding to at least one encryption protocol; The target message is a negotiation message for determining encryption parameters sent by both communicating parties during the handshake phase of the encryption protocol; An extraction module, configured to extract the encryption parameters included in the target message from the payloads of the plurality of target data packets according to a preset rule by using a deep packet inspection technology; the preset rule includes specifying a matching condition between the target message and the encryption parameters; A matching and analysis module, used to match and analyze the encryption parameters using a preset algorithm feature library to obtain the encryption algorithm used by the encryption protocol corresponding to the target message; An output module is used to determine a target encryption protocol that uses a non-quantum security encryption algorithm from at least one encryption protocol according to the encryption algorithm used; the traffic and connection status of the network path associated with the target encryption protocol are used to evaluate the network quantum security risk of the system.

10. A computer storage medium storing instructions, wherein when the instructions are executed on a computer, the computer executes the method according to any one of claims 1 to 8.