Encrypted data stream anomaly detection method and related device
By constructing data differential characteristics in the encrypted data stream and comparing them with preset characteristics, the problem of insufficient accuracy in the abnormal detection of encrypted data streams in the prior art is solved, and more efficient abnormal data identification and network security guarantee are achieved.
Patent Information
- Application Number
- CN202311591046.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art is difficult to accurately detect abnormal data in encrypted data streams, resulting in hidden dangers of network attacks and virus transmission.
By obtaining the data length difference information of multiple encrypted data packets in the encrypted data stream, the data difference characteristics are constructed, and compared with the preset abnormal difference characteristics, when the characteristic similarity reaches the preset threshold, it is determined that the encrypted data stream is an abnormal data stream.
It improves the accuracy of abnormal detection of encrypted data streams, can more effectively identify abnormal characteristics in encrypted data streams, and reduces network security threats.
Smart Images

Figure CN120050049A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information security technology, and in particular, to an abnormal detection method for encrypted data streams and related devices. Background Art
[0002] With the development of Internet technology, the demand for information security and privacy protection has become stronger. At present, many network data transmissions adopt data stream encryption technology. However, while data stream encryption technology ensures network security, it is also used by attackers to hide abnormal data, thereby conducting network attacks and virus propagation. Therefore, the abnormal detection of encrypted data streams is crucial for ensuring network security. Summary of the Invention
[0003] This application provides an abnormal detection method for encrypted data streams and related devices, aiming to improve the accuracy of abnormal detection of encrypted data streams.
[0004] In a first aspect, an embodiment of this application provides an abnormal detection method for encrypted data streams. The method includes:
[0005] Obtain an encrypted data stream; the encrypted data stream contains multiple encrypted data packets;
[0006] Based on the data lengths of the multiple encrypted data packets, obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets;
[0007] When the difference information meets the first preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0008] In a second aspect, an embodiment of this application further provides an abnormal detection device for encrypted data streams. The device includes:
[0009] An obtaining module, configured to obtain an encrypted data stream; the encrypted data stream contains multiple encrypted data packets;
[0010] A processing module, configured to obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets based on the data lengths of the multiple encrypted data packets;
[0011] A judgment module, configured to determine that the encrypted data stream is an abnormal data stream when the difference information meets the first preset abnormal condition.
[0012] Through the above method, the difference information obtained by reprocessing the data packet category and data packet length can more specifically characterize the deep difference features of the encrypted data stream. Therefore, the accuracy of the abnormal detection result obtained based on the difference information is higher.
[0013] Optionally, based on the data lengths of the multiple encrypted data packets, obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets. The processing module is further configured to:
[0014] Based on the data lengths of at least one encrypted data packet, obtain the total first data length of the encrypted data packets transmitted in the forward direction and the total second data length of the encrypted data packets transmitted in the reverse direction among the at least one encrypted data packet;
[0015] Obtain the length deviation between the total first data length and the total second data length, and use the length deviation as the difference information.
[0016] In this way, by calculating the total data length deviation of the data packets transmitted in the forward direction and the reverse direction, obtain the data distribution information of the encrypted data stream. As a kind of deep feature information, the data distribution information can improve the accuracy of anomaly detection.
[0017] Optionally, based on the data lengths of the multiple encrypted data packets, obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets. The processing module is further configured to:
[0018] Respectively based on the data lengths of the multiple encrypted data packets, obtain the data amounts of the corresponding encrypted data packets;
[0019] Based on the data amounts of the multiple encrypted data packets, obtain the total first data amount of the encrypted data packets transmitted in the forward direction and the total second data amount of the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets;
[0020] Obtain the data amount ratio between the total first data amount and the total second data amount, and use the data amount ratio as the difference information.
[0021] In this way, by calculating the ratio of the total data amounts of the data packets transmitted in the forward direction and the reverse direction, obtain the data balance degree of the encrypted data packets. As another kind of deep feature information, the data distribution information can improve the accuracy of anomaly detection.
[0022] Optionally, the determination module is further configured to:
[0023] Use the difference information as a feature element to construct the data difference feature of the encrypted data stream;
[0024] When the feature similarity between the data difference feature and the preset anomaly difference feature reaches a first preset threshold, determine that the difference information meets the first preset anomaly condition.
[0025] In this way, by comparing the data difference features with the preset abnormal difference features, when there are abnormal differences in the data difference features, it can be determined that the encrypted data stream is an abnormal encrypted data stream.
[0026] Optionally, after obtaining the encrypted data stream, the processing module is further configured to:
[0027] Convert the data length of each of the multiple encrypted data packets from time-domain data to frequency-domain data;
[0028] Divide the obtained frequency-domain data into one or more frequency-domain data groups, and obtain the corresponding frequency-domain diagrams for each of the one or more frequency-domain data groups, where each of the frequency-domain data groups contains N frequency-domain data, and N is a preset integer;
[0029] Based on the obtained frequency-domain diagrams, obtain the data frequency-domain features of the encrypted data stream;
[0030] Then when the difference information meets the first preset abnormal condition, determining that the encrypted data stream is an abnormal data stream specifically includes:
[0031] When the difference information meets the first preset abnormal condition and the obtained data frequency-domain features meet the second preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0032] In this way, the data length is converted from time-domain data to frequency-domain data, thereby mining the data frequency-domain features of the encrypted data stream. As a kind of deep data feature, the data frequency-domain features can effectively represent the feature information of the encrypted data stream and improve the accuracy of abnormal detection.
[0033] Optionally, the judgment module is further configured to:
[0034] When the feature similarity between the data frequency-domain features and the preset abnormal frequency-domain features reaches the second preset threshold, determine that the data frequency-domain features meet the second preset abnormal condition.
[0035] In this way, by comparing the feature similarity between the data frequency-domain features of the encrypted data stream and the preset abnormal frequency-domain features, referring to the abnormal feature information of the existing abnormal encrypted data stream, an accurate judgment can be made on whether there are abnormalities in the encrypted data stream.
[0036] Optionally, after obtaining the encrypted data stream, the processing module is further configured to:
[0037] Convert multiple encrypted data packets from text files to binary files respectively;
[0038] Convert the obtained multiple binary files into corresponding binary images respectively;
[0039] Feature extraction is respectively performed on each of the obtained binary images to obtain the data image features of the corresponding encrypted data packets;
[0040] When the difference information meets the first preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream, specifically including:
[0041] When the difference information meets the first preset abnormal condition and the obtained multiple data image features meet the third preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream.
[0042] In this way, by visualizing the text file into an image and then extracting the image features, feature extraction is performed on the text file from the image perspective, realizing the diversification of feature extraction and improving the accuracy of anomaly detection.
[0043] Optionally, the judgment module is further configured to:
[0044] Respectively obtain the feature similarities between multiple data image features and preset abnormal image features;
[0045] When there is a feature similarity that reaches the third preset threshold among the obtained multiple feature similarities, it is determined that the multiple data image features meet the third preset abnormal condition.
[0046] In this way, by comparing the data image features of multiple encrypted data packets with the abnormal image features respectively in terms of feature similarity, the abnormal information existing in the encrypted data packets can be detected comprehensively and accurately, improving the accuracy of anomaly detection.
[0047] Optionally, after obtaining the encrypted data stream, the processing module is further configured to:
[0048] Based on the number of the multiple encrypted data packets, as well as the data lengths and transmission rates of the multiple encrypted data packets respectively, obtain the data transmission features of the encrypted data stream;
[0049] When the difference information meets the first preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream, specifically including:
[0050] When the difference information meets the first preset abnormal condition and the obtained data transmission features meet the fourth preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream.
[0051] In this way, by extracting features from multiple attributes of the encrypted data packets, the diversification of feature extraction is realized, and the differential features of the encrypted data packets can be characterized more comprehensively, which helps to improve the accuracy of anomaly detection.
[0052] Optionally, the judgment module is further configured to:
[0053] When the feature similarity between the data transmission feature and the preset abnormal transmission feature reaches the fourth preset threshold, it is determined that the data transmission feature meets the fourth preset abnormal condition.
[0054] In this way, by comparing the feature similarity between the data transmission feature of the encrypted data stream and the preset abnormal transmission feature, and referring to the abnormal feature information of the existing abnormal encrypted data stream obtained by statistical methods, an efficient and accurate judgment can be made on whether there is an abnormality in the encrypted data stream.
[0055] Optionally, the encrypted data stream carries a data request end identifier. Before obtaining the difference information between the forward-transmitted encrypted data packets and the backward-transmitted encrypted data packets among the multiple encrypted data packets based on the data lengths of the respective encrypted data packets, the processing module is further configured to:
[0056] Search for the data request end identifier in the preset abnormal identifier library to obtain a search result;
[0057] Determine that the search result indicates that the data request end identifier does not exist in the abnormal identifier library.
[0058] In this way, when it is determined that the search result indicates that the data request end identifier exists in the abnormal identifier library, it can be determined that the encrypted data stream is an abnormal data stream, and subsequent detection steps are not required, which can reduce the computational amount in the abnormal detection process and avoid repeated detection of the encrypted data stream corresponding to the same IP address multiple times, thereby improving the abnormal detection efficiency.
[0059] Optionally, the processing module further executes based on a traffic detection model:
[0060] When the difference information does not meet the first preset abnormal condition, obtain other data stream features of the encrypted data stream; the other data stream features include at least one of the following: data frequency domain feature, data visualization feature, and data transmission feature;
[0061] Fuse the data difference feature and the obtained other data stream features to obtain a fused feature;
[0062] Based on the fused feature, obtain the abnormal detection result of the encrypted data stream.
[0063] In this way, based on the fused feature containing various deep feature information, the differential features of the encrypted data stream can be comprehensively and multi-angularly reflected, thereby improving the abnormal detection accuracy.
[0064] Optionally, the processing module is further configured to train a traffic detection model:
[0065] Obtain a preset training sample set; each training sample includes: a sample encrypted data stream and a corresponding sample label; the training sample is a positive sample or a negative sample;
[0066] Based on a training sample set, perform multiple rounds of iterative training on the traffic detection model to be trained; wherein, in one round of iteration, perform the following operations:
[0067] Based on the sample fusion features of the selected training samples, obtain the sample anomaly detection results of the sample encrypted data stream; wherein, the sample fusion features are obtained based on the data difference features, data frequency domain features, data visualization features, and data transmission features of the sample encrypted data stream;
[0068] Based on a preset target loss function, obtain the loss value between the sample anomaly detection results and the corresponding sample labels; wherein, a first coordination factor and a second coordination factor are set in the target loss function, the first coordination factor is used to adjust the convergence speed of the target loss function, and the second coordination factor is used to adjust the contribution of positive samples and negative samples to model training;
[0069] Based on the loss value, adjust the model parameters.
[0070] In this way, by introducing a coordination factor into the target loss function, the problems of unbalanced positive and negative samples and inaccurate model detection are solved, making the model more adaptable and improving the anomaly detection accuracy.
[0071] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method described in any item of the first aspect is implemented.
[0072] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any item of the first aspect are implemented.
[0073] In a fifth aspect, an embodiment of the present application provides a computer program product. When the computer program product is called by a computer, the computer is made to execute the method described in the first aspect.
[0074] An embodiment of the present application provides an anomaly detection method for encrypted data streams.
[0075] First, obtain an encrypted data stream containing multiple encrypted data packets. Then, based on the data lengths of the respective encrypted data packets, obtain the difference information between the forward-transmitted encrypted data packets and the reverse-transmitted encrypted data packets. In this way, by classifying the multiple encrypted data packets into two categories and analyzing the differences between the two categories based on the data length attribute of the encrypted data packets, the deep features of the encrypted data stream are mined.
[0076] Finally, when the obtained difference information meets the preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream. Since the difference information is the characteristic information obtained by reprocessing based on the data packet category and the data packet length, the difference characteristics can more specifically describe the distinguishing characteristics of the encrypted data stream. Therefore, the accuracy of the abnormal detection result obtained based on the difference information is higher.
[0077] On the other hand, the above method has low requirements for the storage capacity and computing capacity of the device and can be easily applied to network protection devices. Brief Description of the Drawings
[0078] Figure 1 It is a schematic diagram of an application scenario in an embodiment of the present application;
[0079] Figure 2 It is a schematic flowchart of a method for detecting anomalies in an encrypted data stream in an embodiment of the present application;
[0080] Figure 3 It is a first schematic flowchart of a method for obtaining difference information of an encrypted data stream in an embodiment of the present application;
[0081] Figure 4 It is a second schematic flowchart of a method for obtaining difference information of an encrypted data stream in an embodiment of the present application;
[0082] Figure 5 It is a schematic diagram of the logic for determining that the difference information meets the preset abnormal condition in an embodiment of the present application;
[0083] Figure 6 It is a schematic flowchart of a method for detecting anomalies based on frequency domain information in an embodiment of the present application;
[0084] Figure 7 It is a schematic diagram of the logic for detecting anomalies based on frequency domain information in an embodiment of the present application;
[0085] Figure 8 It is a schematic flowchart of a method for detecting anomalies based on data image characteristics in an embodiment of the present application;
[0086] Figure 9 It is a schematic diagram of the logic for obtaining data image characteristics in an embodiment of the present application;
[0087] Figure 10 It is a schematic flowchart of a method for detecting anomalies based on data transmission characteristics in an embodiment of the present application;
[0088] Figure 11 It is a schematic flowchart of a method for detecting anomalies based on feature fusion in an embodiment of the present application;
[0089] Figure 12Schematic logic diagram of an anomaly detection method based on feature fusion in an embodiment of the present application;
[0090] Figure 13 Schematic flowchart of a traffic detection model training method in an embodiment of the present application;
[0091] Figure 14 Schematic logic diagram of a traffic detection model training method in an embodiment of the present application;
[0092] Figure 15 Schematic structural diagram of an anomaly detection device for encrypted data streams in an embodiment of the present application;
[0093] Figure 16 Schematic structural diagram of an electronic device in an embodiment of the present application. Detailed implementation manners
[0094] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments recorded in this application document without creative efforts shall fall within the scope of protection of the technical solutions of the present application.
[0095] Terms such as "first" and "second" in the specification, claims, and the above-mentioned drawings of the present application are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein.
[0096] Some terms in the embodiments of the present application are explained below to facilitate understanding by those skilled in the art.
[0097] (1) Flow duration: The total duration during which data is transmitted between two ends that have established a communication connection.
[0098] (2) Time domain: Describes the relationship between a mathematical function or a physical signal and time.
[0099] (3) Frequency domain: A coordinate system that describes the characteristics of a signal in terms of frequency. The horizontal axis is frequency, and the vertical axis is the amplitude of the signal at that frequency.
[0100] (4) Data visualization: After converting a text file into a binary file, the numbers 1 and 0 contained in the binary file are evenly segmented, and each segment of numbers is used as the pixel value of each row of pixel points in an image to obtain a binary image.
[0101] The design concept of the embodiments of the present application is briefly introduced as follows:
[0102] During the process of network data transmission, data stream encryption technology is a widely used network security protection technology. However, network attackers will also use encrypted data streams to hide abnormal data to avoid being blocked by network protection devices, and then carry out network attacks and virus propagation.
[0103] Under the related technology, since the data in the encrypted data stream is encrypted, traditional plaintext-based traffic analysis methods are difficult to be directly applied. Therefore, a detection method based on machine learning is usually adopted to realize the anomaly detection of the encrypted data stream: directly extract traffic features from the encrypted data stream, for example, flow duration, interval time between data packets, data packet length, data packet payload size, byte transmission rate, etc. Then, use the extracted traffic features and the corresponding traffic labels to train the encrypted data stream detection model. Finally, deploy the trained encrypted data stream detection model in the network protection device to detect abnormal encrypted data.
[0104] However, the following problems exist in the above method:
[0105] 1. Most of the extracted traffic features are obtained by direct statistical methods, such as the number of data packets, data packet length, and transmission rate features. These features are shallow features, and the shallow features have poor pertinence. Therefore, they cannot accurately describe the discriminative features of abnormal encrypted data, resulting in insufficient accuracy when the encrypted data stream detection model detects the encrypted data stream for anomalies.
[0106] 2. When the storage capacity and computing power of the network protection device are limited, it is impossible to provide conditions to support the deployment of the encrypted data stream detection model.
[0107] In view of this, the embodiments of the present application propose an anomaly detection method and related device for encrypted data streams.
[0108] In the embodiments of the present application, by constructing deep features of the encrypted data stream, such as data difference features, data frequency domain features, and data imaging features, a more accurate and comprehensive description of the distinguishing features of the encrypted data stream is provided. By calculating the feature similarity between these features and the preset features in the feature library, it is determined whether the encrypted data stream is an abnormal data stream, providing a fast, efficient, and accurate detection method for the abnormal detection of the encrypted data stream. This method can be easily applied to network protection devices with limited storage capacity and computing power. Moreover, the embodiments of the application also provide a model detection method. By using a data stream detection model deployed in the cloud, the aforementioned deep features and data transmission features are fused to obtain an abnormal detection result. In this solution, the loss function in the model training process is improved. By setting a coordination factor to adjust the convergence speed of the loss function and adjusting the contribution degrees of the positive samples and the negative samples to model training, the accuracy of abnormal detection of the data traffic model is improved.
[0109] The preferred embodiments of the present application will be described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. And without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0110] As Figure 1 shown, it is a schematic diagram of an application scenario in the embodiments of the present application. This application scenario includes two communication devices 110 and 130, and a network protection device 120. After the communication devices 110 and 130 establish a communication connection, they perform encrypted data transmission with each other. The encrypted data packets sent during the data transmission pass through the security protection device 120. The security protection device 120 collects the encrypted data packets to obtain an encrypted data stream. Then, the security protection device 120 performs abnormal detection on the encrypted data stream.
[0111] Based on the above system architecture, referring to Figure 2 shown, it is a schematic flowchart of a method for abnormal detection of an encrypted data stream in the embodiments of the present application. The following will be described in detail with reference to the attached Figure 2 drawings for the specific steps to be executed:
[0112] Step 21: Obtain an encrypted data stream.
[0113] Among them, the encrypted data stream contains multiple encrypted data packets.
[0114] Step 22: Based on the data lengths of the respective encrypted data packets, obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets.
[0115] In the embodiments of the present application, the difference information obtained based on the data lengths of multiple encrypted data packets can be one type of difference information or multiple types of difference information, and the embodiments of the present application do not make a limitation in this regard.
[0116] Specifically, as Figure 3 shown, it is the first process schematic diagram of a method for obtaining difference information of an encrypted data stream in the embodiments of the present application. When performing step 22, the security protection device specifically performs the following steps:
[0117] Step 31: Based on the data lengths of at least one encrypted data packet, obtain the first total data length of the encrypted data packets transmitted in the forward direction and the second total data length of the encrypted data packets transmitted in the reverse direction in at least one encrypted data packet;
[0118] In the embodiments of the present application, the data length of an encrypted data packet refers to the number of bytes contained in the encrypted data packet. After calculating the total data length of the encrypted data packets transmitted in the forward direction and the total data length of the encrypted data packets transmitted in the reverse direction, it is also necessary to calculate the average data length of the encrypted data packets included in the encrypted data stream.
[0119] Step 32: Obtain the length deviation between the first total data length and the second total data length, and use the length deviation as the difference information.
[0120] In the embodiments of the present application, the forward transmission direction is represented as 1, and the reverse transmission direction is represented as -1. The length deviation is calculated using the following formula:
[0121]
[0122] where lenth i represents the data length of each encrypted data packet in the encrypted data stream, dir represents the transmission direction of the corresponding data packet, taking a value of 1 or -1, and AveLenth represents the average data length of the multiple encrypted data packets included in the encrypted data stream.
[0123] For example, if the obtained encrypted data stream contains 6 data packets, the data lengths of the data packets transmitted in the forward direction are 700, 800, and 900 respectively, and the total data length is 2400; the data lengths of the data packets transmitted in the reverse direction are 500, 600, and 700 respectively, and the total data length is 1800. Then the average data length is 700, and the corresponding length deviation is (2400 - 1800) / 700 = 0.86.
[0124] On the other hand, as Figure 4 shown, it is the second process schematic diagram of a method for obtaining difference information of an encrypted data stream in the embodiments of the present application. When performing step 22, the security protection device can also specifically perform the following steps:
[0125] Step 41: Based on the data lengths of multiple encrypted data packets respectively, obtain the data volumes of the corresponding encrypted data packets.
[0126] In the embodiments of the present application, assuming that the data length of an encrypted data packet is L, the data volume of the encrypted data packet is calculated according to the following formula:
[0127] Q = L * log 2 L
[0128] It should be noted that other functional transformations can also be performed on the data length here to obtain the corresponding data volume, and the embodiments of the present application do not limit this.
[0129] Step 42: Based on the data volumes of at least one encrypted data packet respectively, obtain the first total data volume of the encrypted data packets transmitted in the forward direction and the second total data volume of the encrypted data packets transmitted in the reverse direction among at least one encrypted data packet.
[0130] Step 43: Obtain the data volume ratio between the first total data volume and the second total data volume, and use the data volume ratio as the difference information.
[0131] In the embodiments of the present application, the data volume ratio is calculated according to the following formula:
[0132]
[0133] where p i represents the length of the i-th data packet, dir i represents the transmission direction of the i-th data packet, taking values of 1 or -1, j is the number of forward data packets, k is the number of backward data packets, and δ is a constant, usually taking a relatively small constant, such as 0.01.
[0134] Step 23: When the difference information meets the first preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0135] Specifically, as Figure 5 shown, it is a logical schematic diagram for determining that the difference information meets the preset abnormal condition in the embodiments of the present application. The difference information meets the first preset abnormal condition, which is determined in the following way: using one or more pieces of difference information as characteristic elements to construct the data difference characteristics of the encrypted data stream; when the feature similarity between the data difference characteristics and the preset abnormal difference characteristics reaches the first preset threshold, it is determined that the difference information meets the first preset abnormal condition.
[0136] In the embodiments of the present application, assuming that the data difference characteristic x 1 is represented as (x 10 , x 11 , x 12 …, x1m )), the abnormal difference feature x 2 is (x 20 , x 21 , x 22 …, x 2m ). Then the calculation formula of the feature similarity is as follows:
[0137]
[0138] For example, assume that the data difference feature consists of two feature elements, namely the length deviation of 0.86 and the data volume ratio of -0.6 as described above, that is, x 1 is (0.86, -0.6). Assume that the abnormal difference feature x 2 is (0.7, -0.5). Substituting into the above formula, the obtained feature similarity is 0.75. Assume that the first preset threshold is 0.7, and the feature similarity reaches the first preset threshold, then it is determined that the length deviation of 0.86 and the data volume ratio of -0.6 meet the first preset abnormal condition.
[0139] It should be noted that the first preset threshold can be set according to the actual situation, and the embodiments of the present application do not limit this.
[0140] Furthermore, as shown in Figure 6 and Figure 7 , which are respectively the flow schematic diagram and the logic schematic diagram for anomaly detection based on frequency domain information in the embodiments of the present application. After obtaining the encrypted data stream, the security protection device can also perform the following steps:
[0141] Step 61: Convert the data lengths of multiple encrypted data packets from time domain data to frequency domain data.
[0142] In the embodiments of the present application, the Fourier transform method is used to convert the data length from time domain data to frequency domain data.
[0143] Step 62: Divide the obtained frequency domain data into one or more frequency domain data groups, and obtain the frequency domain diagram corresponding to each of at least one frequency domain data group.
[0144] Among them, each frequency domain data group contains N frequency domain data, and N is a preset integer.
[0145] In the embodiments of the present application, the frequency domain data groups are divided in the order of the time of data packet transmission, and furthermore, by the method of filling 0 for the missing data, it is ensured that the number of frequency domain data included in each frequency domain group is the same.
[0146] For example, if 100 frequency-domain data are divided into 4 groups, each frequency-domain group contains 25 frequency-domain data; if 90 frequency-domain data are divided into 4 groups, and each frequency-domain group contains 25, 25, 25, and 15 frequency-domain data respectively, then 10 frequency-domain data are added to the last group to ensure that the number of frequency-domain data contained in the 4 frequency-domain groups is the same.
[0147] Step 63: Based on the obtained frequency-domain diagrams, obtain the data frequency-domain characteristics of the encrypted data stream.
[0148] In the embodiment of the present application, an averaging process is performed on the obtained segmented frequency-domain diagrams, that is, the amplitudes corresponding to the same frequency in each of the obtained frequency-domain diagrams are averaged to obtain an overall frequency-domain diagram containing the frequency-domain characteristics of all encrypted data packets in the encrypted data stream. Then, a Fourier transform is performed on the obtained overall frequency-domain diagram to further extract the fluctuation information therein; then, for the processed overall frequency-domain diagram, the M values with larger amplitudes are taken as the frequency-domain information of the encrypted data stream.
[0149] Step 64: When the difference information meets the first preset abnormal condition and the obtained data frequency-domain characteristics meet the second preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0150] Specifically, the determination that the data frequency-domain characteristics meet the second preset abnormal condition is made in the following manner:
[0151] When the feature similarity between the data frequency-domain characteristics and the preset abnormal frequency-domain characteristics reaches the second preset threshold, it is determined that the data frequency-domain characteristics meet the second preset abnormal condition.
[0152] In the embodiment of the present application, the calculation method of the feature similarity between the data frequency-domain characteristics and the preset abnormal frequency-domain characteristics is the same as the method for calculating the feature similarity in step 23, which will not be elaborated here.
[0153] It should be noted that the second preset threshold can be set according to the actual situation, and the embodiment of the present application does not limit this.
[0154] Furthermore, as Figure 8 shown, which is a schematic flowchart of anomaly detection based on data visualization features in the embodiment of the present application. After obtaining the encrypted data stream, the security protection device further performs the following steps:
[0155] Step 81: Convert multiple encrypted data packets from text files to binary files respectively.
[0156] For example, as Figure 9 shown, which is a schematic logic diagram of obtaining data visualization features in the embodiment of the present application. For each encrypted data packet, each character contained therein is converted into the corresponding binary code.
[0157] Step 82: Convert the obtained multiple binary files into corresponding binary images respectively.
[0158] In the embodiment of the present application, the numbers 1 and 0 included in the binary file are equally grouped. For example, every 10 numbers from the front to the back are grouped as a group. If the last group has less than 10 numbers, 0s are filled in. Each group serves as the pixel values of a row of pixel points of the binary image.
[0159] Step 83: Extract features from each obtained binary image respectively to obtain the data image feature of the corresponding encrypted data packet.
[0160] In the embodiment of the present application, the feature extraction method is to intercept a sub-image of n*n size in the binary image as the data image feature. It should be noted that the value of n can be determined according to the actual situation, and the embodiment of the present application does not limit this.
[0161] Step 84: When the difference information meets the first preset abnormal condition and the obtained multiple data image features meet the third preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0162] Specifically, the determination that the obtained multiple data image features meet the third preset abnormal condition is made in the following way:
[0163] Respectively obtain the feature similarity between the multiple data image features and the preset abnormal image features; when at least one of the obtained multiple feature similarities reaches the third preset threshold, determine that the multiple data image features meet the third preset abnormal condition.
[0164] In the embodiment of the present application, the calculation method of the feature similarity between the data image feature and the preset abnormal image feature is the same as the method for calculating the feature similarity in step 23, and will not be elaborated here.
[0165] It should be noted that the third preset threshold can be set according to the actual situation, and the embodiment of the present application does not limit this.
[0166] Further, as Figure 10 shown, which are respectively the schematic flowcharts of abnormal detection based on data transmission features in the embodiment of the present application. After obtaining the encrypted data stream, the security protection device can also perform the following steps:
[0167] Step 1001: Obtain the data transmission feature of the encrypted data stream based on the number of multiple encrypted data packets, as well as the data length and transmission rate of each of the multiple encrypted data packets.
[0168] In the embodiments of the present application, specifically, the selection of feature elements can be performed from the following information of multiple encrypted data packets to construct data transmission features:
[0169] Flow duration, number of forward data packets, number of reverse data packets, total byte size of forward data packets, total byte size of reverse data packets, minimum number of packets between forward data packets, maximum number of packets between forward data packets, minimum number of packets between reverse data packets, maximum number of packets between reverse data packets, maximum byte size of data packets, average value of forward data packet lengths, standard variance of forward data packet lengths, average value of reverse data packet lengths, standard variance of reverse data packet lengths, proportion of forward header lengths, proportion of reverse header lengths, number of bytes of forward sub - flows, proportion of the number of bytes of forward sub - flows, proportion of the number of bytes of reverse sub - flows, proportion of data packets with cwe flag, average size of forward data packets, average size of reverse data packets, proportion of data packets with fin flag, proportion of data packets with syn flag, proportion of data packets with rst flag, proportion of data packets with push flag, proportion of data packets with ack flag, proportion of data packets with urg flag, proportion of data packets with ece flag, minimum segment size observed in the forward direction, average byte - number batching rate in the forward direction, average packet - chunk rate in the forward direction, average bulk - cargo rate in the forward direction, average byte - number batching rate in the reverse direction, average packet - chunk rate in the reverse direction, average bulk - cargo rate in the reverse direction, download - upload ratio, average size of data packets, flow byte - transfer rate, data - packet transfer rate.
[0170] Step 1002: When the difference information meets the first preset abnormal condition and the obtained data transmission features meet the fourth preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0171] Specifically, the way to determine that the obtained data transmission features meet the fourth preset abnormal condition is as follows:
[0172] When the feature similarity between the data transmission features and the preset abnormal transmission features reaches the fourth preset threshold, it is determined that the data transmission features meet the fourth preset abnormal condition.
[0173] In the embodiments of the present application, the calculation method of the feature similarity between the data transmission features and the abnormal transmission features is the same as the method for calculating the feature similarity in step 23, which will not be elaborated here.
[0174] It should be noted that the fourth preset threshold can be set according to the actual situation, and the embodiments of the present application do not limit this.
[0175] The above is the method for abnormal detection of encrypted data streams by constructing multiple features. Before this, the encrypted data streams can also be preliminarily screened based on the data request - end identifier:
[0176] The encrypted data stream carries the identifier of the data requesting end. In the embodiments of the present application, the identifier of the data requesting end is the IP address of the data requesting end.
[0177] Search for the identifier of the data requesting end in the preset exception identifier library to obtain a search result.
[0178] In the embodiments of the present application, the exception identifier library stores the blacklisted IPs collected historically.
[0179] When it is determined that the search result indicates the existence of the identifier of the data requesting end in the exception identifier library, it can be determined that the encrypted data stream is an abnormal data stream, and there is no need to perform subsequent detection steps; when it is determined that the search result indicates the non-existence of the identifier of the data requesting end in the exception identifier library, the method of constructing the foregoing features is used to perform anomaly detection on the encrypted data stream.
[0180] In this way, the computational complexity of the anomaly detection process can be reduced, and repeated detection of the encrypted data stream corresponding to the same IP address can be avoided, thereby improving the anomaly detection efficiency.
[0181] To further improve the anomaly detection accuracy of the encrypted data stream, as Figure 11 and Figure 12 shown, the embodiments of the present application also provide an anomaly detection method based on feature fusion, which specifically includes the following steps:
[0182] Step 1101: When the difference information does not meet the first preset anomaly condition, obtain at least one other data stream feature of the encrypted data stream.
[0183] Among them, the other data stream features include at least one of the following: data frequency domain feature, data visualization feature, and data transmission feature.
[0184] Step 1102: Fuse the data difference feature and the obtained at least one other data stream feature to obtain a fusion feature.
[0185] In the embodiments of the present application, after the data difference feature and other data stream features are partially or fully input into the traffic detection model, the traffic detection model uses the method of feature splicing to fuse the data difference feature and other data stream features.
[0186] Step 1103: Obtain the anomaly detection result of the encrypted data stream based on the fusion feature.
[0187] In the embodiments of the present application, the traffic detection model obtains the prediction probability that the encrypted data stream belongs to an abnormal data stream based on the fusion feature. When the prediction probability is greater than the prediction threshold, it is determined that the encrypted data stream is an abnormal data stream.
[0188] The above anomaly detection method based on feature fusion is executed by a traffic detection model. Further, as Figure 13 and Figure 14 shown, the training process of the traffic detection model is as follows:
[0189] Step 1301: Obtain a preset training sample set.
[0190] Each training sample includes: a sample encrypted data stream and a corresponding sample label; the training sample is a positive sample or a negative sample;
[0191] Step 1302: Based on the training sample set, perform multiple rounds of iterative training on the traffic detection model to be trained; among them, in one round of iteration, perform the following operations:
[0192] (1) Based on the sample fusion features of the selected training samples, obtain the sample anomaly detection results of the sample encrypted data stream.
[0193] The sample fusion features are obtained based on at least one of the data difference features, data frequency domain features, data visualization features, and data transmission features of the sample encrypted data stream;
[0194] (2) Based on a preset target loss function, obtain the loss value between the sample anomaly detection result and the corresponding sample label.
[0195] The target loss function is set with a first coordination factor and a second coordination factor. The first coordination factor is used to adjust the convergence speed of the target loss function, and the second coordination factor is used to adjust the contribution of positive samples and negative samples to model training; among them, the positive sample is a normal encrypted data stream, and the negative sample is an abnormal encrypted data stream.
[0196] (3) Based on the loss value, adjust the model parameters.
[0197] In the embodiments of the present application, the traffic detection model is trained based on the XGBoost (eXtreme Gradient Boosting) algorithm, and the target loss function used in the training process is optimized based on the classical binary cross-entropy loss function. Specifically:
[0198]
[0199] Among them, y is the labeled label, obtained by labeling the encrypted data stream in the training sample, with a normal label of 0 and an abnormal label of 1; y' is the predicted probability, which is the probability that the traffic detection model predicts the encrypted data stream as abnormal by inputting the encrypted data stream in the training sample into the traffic detection model; γ is the first coordination factor, and α is the second coordination factor.
[0200] When γ is greater than 1, the convergence speed of the loss function can be increased; when γ is less than 1, the convergence speed of the loss function can be decreased. According to the above formula, it can be known that the value of α ranges from 0.1 to 0.5. The coordination parameter α of the loss function corresponding to the positive sample is less than or equal to 0.5, and the coordination parameter α of the loss function corresponding to the negative sample is greater than or equal to 0.5. The gap between the loss values corresponding to the positive and negative samples can be appropriately reduced, the contribution degree of the negative sample to model training can be increased, and the contribution degree of the positive sample to model training can be decreased, thereby solving the problem of imbalance between positive and negative samples in the anomaly detection process.
[0201] In addition, although the operations of the method of the present application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0202] Based on the same technical concept, refer to Figure 13 As shown, the embodiment of the present application further provides an anomaly detection device for encrypted data streams. The device includes:
[0203] An acquisition module 1501, configured to acquire an encrypted data stream; the encrypted data stream includes multiple encrypted data packets;
[0204] A processing module 1502, configured to obtain difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets based on the data lengths of the respective encrypted data packets;
[0205] A judgment module 1503, configured to determine that the encrypted data stream is an abnormal data stream when the difference information meets a first preset anomaly condition.
[0206] Optionally, based on the data lengths of the respective encrypted data packets, to obtain difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets, the processing module 1502 is further configured to:
[0207] Based on the data lengths of one or more encrypted data packets, obtain a first total data length of the encrypted data packets transmitted in the forward direction and a second total data length of the encrypted data packets transmitted in the reverse direction among the one or more encrypted data packets;
[0208] Obtain a length deviation between the first total data length and the second total data length, and use the length deviation as the difference information.
[0209] Optionally, based on the data lengths of multiple encrypted data packets, obtain the difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the multiple encrypted data packets. The processing module 1502 is further configured to:
[0210] Based on the data lengths of multiple encrypted data packets respectively, obtain the data amounts of the corresponding encrypted data packets;
[0211] Based on the data amounts of one or more encrypted data packets respectively, obtain the first total data amount of the encrypted data packets transmitted in the forward direction and the second total data amount of the encrypted data packets transmitted in the reverse direction among the one or more encrypted data packets;
[0212] Obtain the data amount ratio between the first total data amount and the second total data amount, and use the data amount ratio as the difference information.
[0213] Optionally, the determination module 1503 is further configured to:
[0214] Use the difference information as a feature element to construct the data difference feature of the encrypted data stream;
[0215] When the feature similarity between the data difference feature and the preset abnormal difference feature reaches the first preset threshold, determine that the difference information meets the first preset abnormal condition.
[0216] Optionally, after obtaining the encrypted data stream, the processing module 1502 is further configured to:
[0217] Convert the data lengths of multiple encrypted data packets from time-domain data to frequency-domain data;
[0218] Divide the obtained frequency-domain data into one or more frequency-domain data groups, and obtain the corresponding frequency-domain diagrams of the one or more frequency-domain data groups, where each frequency-domain data group contains N frequency-domain data, and N is a preset integer;
[0219] Based on the obtained one or more frequency-domain diagrams, obtain one or more frequency-domain information of the encrypted data stream;
[0220] Then when the difference information meets the first preset abnormal condition, determine that the encrypted data stream is an abnormal data stream. The determination module 1503 is specifically further configured to:
[0221] When the difference information meets the first preset abnormal condition and the obtained one or more frequency-domain information meet the second preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
[0222] Optionally, the determination module 1503 is further configured to:
[0223] Use the one or more frequency-domain information as feature elements to construct the data frequency-domain feature of the encrypted data stream;
[0224] When the feature similarity between the data frequency-domain features and the preset abnormal frequency-domain features reaches the second preset threshold, it is determined that one or more frequency-domain information satisfy the second preset abnormal condition.
[0225] Optionally, after obtaining the encrypted data stream, the processing module 1502 is further configured to:
[0226] Convert multiple encrypted data packets from text files to binary files respectively;
[0227] Convert the obtained multiple binary files into corresponding binary images respectively;
[0228] Extract features from each obtained binary image respectively to obtain the data image feature of the corresponding encrypted data packet;
[0229] Then when the difference information satisfies the first preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream. Specifically, the judgment module 1503 is further configured to:
[0230] When the difference information satisfies the first preset abnormal condition and the obtained multiple data image features satisfy the third preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream.
[0231] Optionally, the judgment module 1503 is further configured to:
[0232] Obtain the feature similarity between multiple data image features and the preset abnormal image features respectively;
[0233] When there is one or more feature similarities that reach the third preset threshold among the obtained multiple feature similarities, it is determined that the multiple data image features satisfy the third preset abnormal condition.
[0234] Optionally, after obtaining the encrypted data stream, the processing module 1502 is further configured to:
[0235] Obtain the data transmission feature of the encrypted data stream based on the number of multiple encrypted data packets, and the respective data lengths and transmission rates of the multiple encrypted data packets;
[0236] Then when the difference information satisfies the first preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream. Specifically, the judgment module 1503 is further configured to:
[0237] When the difference information satisfies the first preset abnormal condition and the obtained data transmission feature satisfies the fourth preset abnormal condition, it is determined that the encrypted data stream is an abnormal data stream.
[0238] Optionally, the judgment module 1503 is further configured to:
[0239] When the feature similarity between the data transmission feature and the preset abnormal transmission feature reaches the fourth preset threshold, it is determined that the data transmission feature meets the fourth preset abnormal condition.
[0240] Optionally, the encrypted data stream carries a data request end identifier. Before obtaining the difference information between the forward-transmitted encrypted data packets and the backward-transmitted encrypted data packets among the multiple encrypted data packets based on the data lengths of the respective encrypted data packets, the processing module 1502 is further configured to:
[0241] Search for the data request end identifier in the preset abnormal identifier library to obtain a search result;
[0242] Determine that the search result indicates that the data request end identifier does not exist in the abnormal identifier library.
[0243] Optionally, the processing module 1502 further executes based on the traffic detection model:
[0244] When the difference information does not meet the first preset abnormal condition, obtain at least one other data stream feature of the encrypted data stream; the other data stream features include at least one of the following: data frequency domain feature, data visualization feature, and data transmission feature;
[0245] Fuse the data difference feature and the obtained at least one other data stream feature to obtain a fused feature;
[0246] Based on the fused feature, obtain the abnormal detection result of the encrypted data stream.
[0247] Optionally, the processing module 1502 is further configured to train the traffic detection model:
[0248] Obtain a preset training sample set; each training sample includes: a sample encrypted data stream and a corresponding sample label; the training sample is a positive sample or a negative sample;
[0249] Based on the training sample set, perform multiple rounds of iterative training on the traffic detection model to be trained; wherein, in one round of iteration, the following operations are performed:
[0250] Based on the sample fused feature of the selected training sample, obtain the sample abnormal detection result of the sample encrypted data stream; wherein, the sample fused feature is obtained based on at least one of the data difference feature, data frequency domain feature, data visualization feature, and data transmission feature of the sample encrypted data stream;
[0251] Based on the preset target loss function, obtain the loss value between the sample abnormal detection result and the corresponding sample label; wherein, a first coordination factor and a second coordination factor are set in the target loss function, the first coordination factor is used to adjust the convergence speed of the target loss function, and the second coordination factor is used to adjust the contribution of positive samples and negative samples to model training;
[0252] Adjust the model parameters based on the loss value.
[0253] Based on the same technical concept, an embodiment of the present application further provides an electronic device, which can implement the method flow of anomaly detection of the encrypted data stream provided in the above embodiments of the present application.
[0254] In one embodiment, the electronic device can be a server, a terminal device or other electronic devices.
[0255] Refer to Figure 16 As shown, the electronic device may include:
[0256] At least one processor 1601, and a memory 1602 connected to at least one processor 1601. In the embodiments of the present application, the specific connection medium between the processor 1601 and the memory 1602 is not limited. Figure 16 In the example, the processor 1601 and the memory 1602 are connected through a bus 1600. The bus 1600 is Figure 16 shown as a thick line in the figure. The connection manners between other components are only for illustrative purposes and are not limiting. The bus 1600 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 16 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 1601 can also be called a controller, and the name is not limited.
[0257] In the embodiments of the present application, the memory 1602 stores instructions executable by at least one processor 1601. By executing the instructions stored in the memory 1602, at least one processor 1601 can execute an anomaly detection method for an encrypted data stream described above. The processor 1601 can implement Figure 15 the functions of each module in the device shown in the figure.
[0258] Among them, the processor 1601 is the control center of the device, and can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 1602 and calling the data stored in the memory 1602, various functions of the device and process data, so as to monitor the device as a whole.
[0259] In a possible design, the processor 1601 may include one or more processing units. The processor 1601 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communications. It can be understood that the above-mentioned modem processor may not be integrated into the processor 1601. In some embodiments, the processor 1601 and the memory 1602 may be implemented on the same chip, and in some embodiments, they may also be separately implemented on independent chips.
[0260] The processor 1601 may be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of an abnormal detection method for an encrypted data stream disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0261] As a non-volatile computer-readable storage medium, the memory 1602 can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 1602 may include at least one type of storage medium. For example, it may include flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (RAM), a static random access memory (SRAM), a programmable read-only memory (PROM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic memory, a magnetic disk, an optical disk, and so on. The memory 1602 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1602 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0262] By programming the design of the processor 1601, the code corresponding to the abnormal detection method for an encrypted data stream introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute when running Figure 2Steps of an anomaly detection method for encrypted data streams in the illustrated embodiments. How to design and program the processor 1601 is a well-known technique to those skilled in the art and will not be elaborated here.
[0263] Based on the same inventive concept, an embodiment of the present application also provides a storage medium storing computer instructions, which, when run on a computer, cause the computer to execute an anomaly detection method for encrypted data streams discussed above.
[0264] In some possible implementation manners, various aspects of an anomaly detection method for encrypted data streams provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in an anomaly detection method for encrypted data streams according to various exemplary embodiments of the present application described above in this specification.
[0265] It should be noted that although several units or subunits of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0266] In addition, although the operations of the method of the present application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0267] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0268] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to the application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce a means for implementing the functions specified in a process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.
[0269] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction means that implements the functions specified in a process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.
[0270] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in a process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.
[0271] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.
Claims
1. An abnormal detection method for encrypted data streams, characterized in that, it includes: Obtain an encrypted data stream; the encrypted data stream contains multiple encrypted data packets; Based on the data lengths of the multiple encrypted data packets respectively, obtain the difference information between the encrypted data packets transmitted forward and the encrypted data packets transmitted backward among the multiple encrypted data packets; When the difference information meets the first preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
2. The method according to claim 1, characterized in that, The step of obtaining the difference information between the encrypted data packets transmitted forward and the encrypted data packets transmitted backward among the multiple encrypted data packets based on the data lengths of the multiple encrypted data packets respectively includes: Based on the data lengths of the multiple encrypted data packets respectively, obtain the first total data length of the encrypted data packets transmitted forward and the second total data length of the encrypted data packets transmitted backward among the multiple encrypted data packets; Obtain the length deviation between the first total data length and the second total data length, and use the length deviation as the difference information.
3. The method according to claim 1, characterized in that, The step of obtaining the difference information between the encrypted data packets transmitted forward and the encrypted data packets transmitted backward among the multiple encrypted data packets based on the data lengths of the multiple encrypted data packets respectively includes: Based on the data lengths of the multiple encrypted data packets respectively, obtain the data volume of the corresponding encrypted data packets; Based on the data volumes of the multiple encrypted data packets respectively, obtain the first total data volume of the encrypted data packets transmitted forward and the second total data volume of the encrypted data packets transmitted backward among the multiple encrypted data packets; Obtain the data volume ratio between the first total data volume and the second total data volume, and use the data volume ratio as the difference information.
4. The method according to claim 1, characterized in that, The determination that the difference information meets the first preset abnormal condition is made in the following way: Use the difference information as a feature element to construct the data difference feature of the encrypted data stream; When the feature similarity between the data difference feature and the preset abnormal difference feature reaches the first preset threshold, determine that the difference information meets the first preset abnormal condition.
5. The method according to any one of claims 1-4, characterized in that, After obtaining the encrypted data stream, it further includes: Convert the data lengths of the multiple encrypted data packets from time-domain data to frequency-domain data; Divide the obtained frequency-domain data into one or more frequency-domain data groups, and obtain the corresponding frequency-domain diagrams for the one or more frequency-domain data groups, wherein each frequency-domain data group contains N frequency-domain data, and N is a preset integer; Based on the obtained frequency-domain diagrams, obtain the data frequency-domain feature of the encrypted data stream; Then when the difference information meets the first preset abnormal condition, the determination that the encrypted data stream is an abnormal data stream specifically includes: When the difference information meets the first preset abnormal condition and the obtained data frequency domain feature meets the second preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
6. The method according to claim 5, wherein, the determination that the data frequency domain feature meets the second preset abnormal condition is made in the following manner: When the feature similarity between the data frequency domain feature and the preset abnormal frequency domain feature reaches the second preset threshold, determine that the data frequency domain feature meets the second preset abnormal condition.
7. The method according to any one of claims 1-4, wherein, after obtaining the encrypted data stream, further includes: respectively converting the multiple encrypted data packets from text files into binary files; respectively converting the obtained multiple binary files into corresponding binary images; respectively performing feature extraction on the obtained binary images to obtain the data image feature of the corresponding encrypted data packet; then when the difference information meets the first preset abnormal condition, determining that the encrypted data stream is an abnormal data stream, specifically including: when the difference information meets the first preset abnormal condition and the obtained multiple data image features meet the third preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
8. The method according to claim 7, wherein, the determination that the obtained multiple data image features meet the third preset abnormal condition is made in the following manner: respectively obtaining the feature similarity between the multiple data image features and the preset abnormal image features; when there is a feature similarity that reaches the third preset threshold among the obtained multiple feature similarities, determine that the multiple data image features meet the third preset abnormal condition.
9. The method according to any one of claims 1-4, wherein, after obtaining the encrypted data stream, further includes: obtaining the data transmission feature of the encrypted data stream based on the number of the multiple encrypted data packets, and the data length and transmission rate of each of the multiple encrypted data packets; then when the difference information meets the first preset abnormal condition, determining that the encrypted data stream is an abnormal data stream, specifically including: when the difference information meets the first preset abnormal condition and the obtained data transmission feature meets the fourth preset abnormal condition, determine that the encrypted data stream is an abnormal data stream.
10. The method according to claim 9, wherein, the determination that the obtained data transmission feature meets the fourth preset abnormal condition is made in the following manner: when the feature similarity between the data transmission feature and the preset abnormal transmission feature reaches the fourth preset threshold, determine that the data transmission feature meets the fourth preset abnormal condition.
11. The method according to any one of claims 1-4, wherein, the encrypted data stream carries a data request end identifier; then before obtaining the difference information between the encrypted data packets transmitted forward and the encrypted data packets transmitted backward among the multiple encrypted data packets based on the data length of each of the multiple encrypted data packets, further includes: In a preset exception identification library, search for the data request end identifier to obtain a search result; Determine that the search result indicates that the data request end identifier does not exist in the exception identification library.
12. The method according to claim 4, wherein, further comprising: When the difference information does not meet the first preset exception condition, obtain one or more other data stream characteristics of the encrypted data stream; The other data stream characteristics include at least one of the following: data frequency domain characteristics, data visualization characteristics, and data transmission characteristics; Fuse the data difference characteristics and the obtained other data stream characteristics to obtain a fused characteristic; Based on the fused characteristic, obtain an anomaly detection result of the encrypted data stream.
13. The method according to claim 12, wherein, The method is executed by a traffic detection model, and the training process of the traffic detection model is as follows: Obtain a preset training sample set; each training sample includes: a sample encrypted data stream and a corresponding sample label; the training sample is a positive sample or a negative sample; Based on the training sample set, perform multiple rounds of iterative training on the traffic detection model to be trained; wherein, in one round of iteration, perform the following operations: Based on the sample fused characteristic of the selected training sample, obtain a sample anomaly detection result of the sample encrypted data stream; wherein, the sample fused characteristic is obtained based on one or more of the data difference characteristic, data frequency domain characteristic, data visualization characteristic, and data transmission characteristic of the sample encrypted data stream; Based on a preset target loss function, obtain a loss value between the sample anomaly detection result and the corresponding sample label; wherein, a first coordination factor and a second coordination factor are set in the target loss function, the first coordination factor is used to adjust the convergence speed of the target loss function, and the second coordination factor is used to adjust the contribution of the positive sample and the negative sample to model training; Based on the loss value, adjust the model parameters.
14. An anomaly detection device for an encrypted data stream, wherein, comprising: An acquisition module, configured to acquire an encrypted data stream; the encrypted data stream includes a plurality of encrypted data packets; A processing module, configured to obtain difference information between the encrypted data packets transmitted in the forward direction and the encrypted data packets transmitted in the reverse direction among the plurality of encrypted data packets based on the data lengths of the respective encrypted data packets; A judgment module, configured to determine that the encrypted data stream is an abnormal data stream when the difference information meets a first preset exception condition.
15. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the computer program, the method according to any one of claims 1-13 is implemented.
16. A computer-readable storage medium, on which a computer program is stored, wherein, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-13 are implemented.
Citation Information
Cited By
Encrypted traffic anomaly detection method and device, electronic equipment and storage medium
CN121841788A