Server port service identification method and device

By extracting the preset field information in the server response handshake packet, calculating the hash value and matching it with the JA3S fingerprint database, the server port service is accurately identified, solving the problem of not being able to identify the server port service under TLS encrypted communication.

CN120050053APending Publication Date: 2025-05-27INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410559719.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-08
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art cannot identify the server-side port service using TLS for encrypted communication in the upper layer of TCP plaintext transmission.

Method used

By determining the port identification and IP address of the service port to be identified, establish a secure transport layer protocol connection, send the client requesting the handshake packet, receive and extract the preset field information in the server response handshake packet, splice it into a string, calculate the hash value, and match it with the hash value in the preset JA3S fingerprint database to identify the service running on the port.

Benefits of technology

It realizes accurate identification of server port services, solving the problem of not being able to identify server port services under TLS encrypted communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050053A_ABST
    Figure CN120050053A_ABST
Patent Text Reader

Abstract

The invention provides a server port service identification method and device, and relates to the technical field of network security and financial science and technology, and the method comprises the steps: determining a port identifier and an IP address of a to-be-identified service port; establishing a secure transport layer protocol connection with a corresponding server according to the IP address, and sending a client request handshake packet to a to-be-identified service port of the server according to the port identifier of the to-be-identified service port; receiving a server response handshake packet returned by the to-be-identified service port, and extracting preset field information from the server response handshake packet; splicing the extracted preset field information into a character string according to a preset sequence; determining a hash value corresponding to the spliced character string; the Hash value is matched with a Hash value contained in each piece of JA3S fingerprint data stored in a preset JA3S fingerprint database; and if the matching is successful, outputting the information of the port operation service contained in the corresponding JA3S fingerprint data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of network security and fintech, and particularly to a method and device for identifying server port services. Background Art

[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely by including it in this section.

[0003] Server port service identification refers to identifying the services or applications running on the server port. The prior art identifies the services or applications of the port by checking the network data stream of the port. In order to ensure the secure processing of banking services and customer information and avoid leakage during data transmission, currently, many bank applications and services use TLS (Transport Layer Security Protocol) for encrypted communication on top of the traditional TCP (Transmission Control Protocol) plaintext transmission, resulting in the inability to identify the server port services. Summary of the Invention

[0004] In an embodiment of the present invention, a method for identifying server port services is proposed to accurately identify server port services, including:

[0005] Determine the port identifier and IP address of the service port to be identified;

[0006] Establish a Transport Layer Security Protocol connection with the corresponding server according to the IP address, and send a client request handshake packet to the service port to be identified of the server according to the port identifier of the service port to be identified;

[0007] Receive the server response handshake packet returned by the service port to be identified, and extract the preset field information from the server response handshake packet; wherein, the server response handshake packet contains the Transport Layer Security Protocol information adopted by the service port to be identified;

[0008] Concatenate the extracted preset field information into a string in a predetermined order;

[0009] Determine the hash value corresponding to the concatenated string;

[0010] Match the hash value with the hash value included in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, output the information of the port running service included in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data includes at least a predetermined hash value and the information of the port running service corresponding thereto; the predetermined hash value is determined according to the Transport Layer Security Protocol information adopted by the port.

[0011] In an embodiment of the present invention, a server port service identification device is proposed to accurately identify server port services, including:

[0012] An acquisition module, configured to acquire the port and IP address of the service to be identified;

[0013] A connection module, configured to establish a Secure Sockets Layer (SSL) or Transport Layer Security (TLS) connection with the corresponding server according to the IP address, and send a client request handshake packet to the port of the service to be identified on the server;

[0014] An extraction module, configured to receive the server response handshake packet returned by the port of the service to be identified, and extract preset field information from the server response handshake packet; wherein, the server response handshake packet contains the SSL / TLS protocol information applied by the port of the service to be identified;

[0015] A splicing module, configured to splice the extracted preset field information into a string in a predetermined order;

[0016] A determination module, configured to determine the hash value corresponding to the spliced string;

[0017] A matching module, configured to match the hash value with the hash value included in each JA3S fingerprint data stored in a preset JA3S fingerprint database; if the match is successful, output the port service information included in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data includes at least a pre-determined hash value and the corresponding port service information; the pre-determined hash value is determined according to the SSL / TLS protocol information applied by the port.

[0018] In an embodiment of the present invention, a computer device is proposed, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, a server port service identification method is implemented.

[0019] In an embodiment of the present invention, a computer-readable storage medium is proposed, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, a server port service identification method is implemented.

[0020] In an embodiment of the present invention, a computer program product is proposed, where the computer program product includes a computer program, and when the computer program is executed by a processor, a server port service identification method is implemented.

[0021] The server port service identification method and device proposed in the embodiments of the present invention can solve the problem that in the case of TCP plaintext transmission with TLS used for encrypted communication at the upper layer, the prior art cannot identify the services of the server ports; in the embodiments of the present invention, the port identifier and IP address of the service port to be identified are determined; a Secure Sockets Layer (SSL) connection is established with the corresponding server according to the IP address, and a client request handshake packet is sent to the service port to be identified on the server according to the port identifier of the service port to be identified; the server response handshake packet returned by the service port to be identified is received, and preset field information is extracted from the server response handshake packet; wherein, the server response handshake packet contains the information of the Secure Sockets Layer protocol adopted by the service port to be identified; the extracted preset field information is concatenated into a string in a predetermined order; the hash value corresponding to the concatenated string is determined; the hash value is matched with the hash value contained in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, the information of the service running on the port contained in the corresponding JA3S fingerprint data is output; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data at least contains a pre-determined hash value and the information of the service running on the corresponding port; the pre-determined hash value is determined according to the information of the Secure Sockets Layer protocol adopted by the port. The embodiments of the present invention use the handshake information of the Secure Sockets Layer protocol to identify the service running on the port. Specifically, the preset field information extracted from the server response handshake packet is concatenated to obtain a string, and further the hash value corresponding to the concatenated string is determined. By matching the hash value with the hash value contained in the JA3S fingerprint data, the information of the service running on the port is determined. The embodiments of the present invention can accurately identify the services of the server ports. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0023] Figure 1 It is a flowchart of the server port service identification method according to the embodiments of the present invention.

[0024] Figure 2 It is a specific example diagram of the server port service identification method according to the embodiments of the present invention.

[0025] Figure 3 It is a specific example diagram of the server port service identification method according to the embodiments of the present invention.

[0026] Figure 4 It is a schematic diagram of the server port service identification device according to the embodiments of the present invention;

[0027] Figure 5 It is a schematic diagram of the computer device according to an embodiment of the present invention. Detailed implementation manners

[0028] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer and more understandable, the following further describes the embodiments of the present invention in detail with reference to the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.

[0029] The term "and / or" herein merely describes an association relationship and means that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "at least one" herein means any one of a plurality or any combination of at least two of a plurality. For example, including at least one of A, B, and C may represent including any one or more elements selected from the set composed of A, B, and C.

[0030] In the description of this specification, the terms "comprising", "including", "having", "containing", etc. are all open-ended terms, that is, they are meant to include but not limited to. The description with reference to terms such as "an embodiment", "a specific embodiment", "some embodiments", "for example", etc. means that the specific features, structures or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic descriptions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. The step sequences involved in each embodiment are used to schematically illustrate the implementation of the present application, and the step sequences are not limited and can be adjusted appropriately as needed.

[0031] Next, with reference to several representative embodiments of the present invention, the principles and spirits of the present invention are elaborated in detail.

[0032] Figure 1 It is a schematic flowchart of the method for identifying the server port service according to an embodiment of the present invention. As Figure 1 shown, the method includes:

[0033] Step 101, determining the port identifier and IP address of the service port to be identified;

[0034] Step 102, establishing a Secure Sockets Layer (SSL) connection with the corresponding server according to the IP address, and sending a client request handshake packet to the service port to be identified of the server according to the port identifier of the service port to be identified;

[0035] Step 103: Receive the server response handshake packet returned by the service port to be recognized, and extract the preset field information from the server response handshake packet; wherein, the server response handshake packet contains the secure transport layer protocol information adopted by the service port to be recognized.

[0036] Step 104: Concatenate the extracted preset field information into a string in a predetermined order.

[0037] Step 105: Determine the hash value corresponding to the concatenated string.

[0038] Step 106: Match the hash value with the hash value included in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, output the information of the service running on the port included in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data includes at least a predetermined hash value and the information of the service running on the corresponding port; the predetermined hash value is determined according to the secure transport layer protocol information adopted by the port.

[0039] From Figure 1 the process shown above, it can be known that in the embodiment of the present invention, the port identifier and IP address of the service port to be recognized are determined; a secure transport layer protocol connection is established with the corresponding server according to the IP address, and a client request handshake packet is sent to the service port to be recognized on the server according to the port identifier of the service port to be recognized; the server response handshake packet returned by the service port to be recognized is received, and the preset field information is extracted from the server response handshake packet; wherein, the server response handshake packet contains the secure transport layer protocol information adopted by the service port to be recognized; the extracted preset field information is concatenated into a string in a predetermined order; the hash value corresponding to the concatenated string is determined; the hash value is matched with the hash value included in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, output the information of the service running on the port included in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data includes at least a predetermined hash value and the information of the service running on the corresponding port; the predetermined hash value is determined according to the secure transport layer protocol information adopted by the port. In the embodiment of the present invention, the service running on the port is identified by using the handshake information of the secure transport layer protocol. Specifically, the preset field information extracted from the server response handshake packet is concatenated to obtain a string, and further the hash value corresponding to the concatenated string is determined. By matching the hash value with the hash value included in the JA3S fingerprint data, the information of the service running on the port is determined. The embodiment of the present invention can accurately identify the service of the server port.

[0040] To more clearly explain the above server port service identification method, the following will be described in detail in conjunction with each step.

[0041] In an embodiment of the present invention, a Secure Sockets Layer (SSL) protocol connection is established with the corresponding server according to the IP address; specifically, according to the IP address, the SSL library in Python is used to establish an SSL protocol connection with the corresponding server.

[0042] In an embodiment of the present invention, preset field information is extracted from the server response handshake packet, including:

[0043] Using a preset regular expression, preset field information is extracted from the server response handshake packet.

[0044] Figure 2 It is a specific example diagram of the server port service identification method of the embodiment of the present invention.

[0045] In an embodiment of the present invention, referring to Figure 2 , extracting preset field information from the server response handshake packet can also be implemented according to the following steps:

[0046] Step 201, input the server response handshake packet into the field information extraction model; wherein, the field information extraction model is trained from a natural language processing model based on historical server response handshake packets and corresponding preset field information;

[0047] Step 202, output the preset field information.

[0048] In specific implementation, it is necessary to pre-obtain historical server response handshake packets and corresponding preset field information, including the SSL protocol version, the name of the encryption algorithm supported by the SSL protocol, and the extended content (or type) supported by the SSL protocol; use the above data to train a natural language processing model to obtain a field information extraction model; wherein, the natural language processing model includes: TextRank model, etc. Use the trained field information extraction model to extract the preset field information from the server response handshake packet.

[0049] In an embodiment of the present invention, the preset field information includes one or a combination of more of the following: the SSL protocol version, the name of the encryption algorithm supported by the SSL protocol, and the extended content supported by the SSL protocol.

[0050] In an embodiment of the present invention, the hash value corresponding to the concatenated string is determined; specifically, the MD5 algorithm is used to determine the hash value corresponding to the concatenated string.

[0051] During specific implementation, arrange the Secure Transport Layer Protocol version, the names of supported encryption algorithms, and the order of supported extension contents, and use "," to separate each field. Among the supported encryption algorithms and supported extension contents (or types), use "-" to connect different fields, concatenate them into a long string, and use the MD5 algorithm to determine the hash value corresponding to the concatenated string.

[0052] In an embodiment of the present invention, after matching the hash value with the hash value included in each JA3S fingerprint data stored in the preset JA3S fingerprint database, it further includes:

[0053] If the match fails, output the port identifier of the service port to be recognized, the IP address, extract the preset field information from the server response handshake packet, and the hash value corresponding to the concatenated string;

[0054] Send a reminder message that the port service cannot be recognized.

[0055] Figure 3 It is a specific instance diagram of the service port service recognition method in the embodiment of the present invention.

[0056] During specific implementation, refer to Figure 3 , and query whether there is service information in the preset JA3S fingerprint database according to the following steps:

[0057] Step 301, match the hash value with the hash value included in each JA3S fingerprint data stored in the preset JA3S fingerprint database;

[0058] Step 302, if the match is successful, output the information of the port running service included in the corresponding JA3S fingerprint data;

[0059] Step 303, if the match fails, output the port identifier of the service port to be recognized, the IP address, extract the preset field information from the server response handshake packet, and the hash value corresponding to the concatenated string, and wait for subsequent manual research and judgment.

[0060] The present invention pre-establishes a JA3S fingerprint database, uses MySQL to establish the JA3S fingerprint database, creates a JA3S fingerprint data table in the JA3S fingerprint database, and the structure of the JA3S fingerprint data table is as follows: Id (unique identifier, auto-increment, integer), server_hash (fingerprint hash value, index, string), app_name (service or application name, string), app_info (supplementary description of service or application, string); the method for obtaining JA3S fingerprint data is as follows:

[0061] 1. First, it is necessary to list a list of services, applications, and middleware that use TLS (Transport Layer Security) communication and are difficult to identify through direct requests. However, for HTTPS services, an HTTP fingerprint can be obtained by sending an HTTP request after establishing a connection. The judgment significance of JA3S fingerprint data is not great. This invention mainly examines that even when a port is open and a TLS connection is established, it is still difficult to determine what specific service or application it is;

[0062] 2. The list of services, applications, and middleware is mainly gradually accumulated by collecting assets and applications in daily work. For example, middleware such as Cobalt Strike, Trickbot, and Emotet used in security offense and defense;

[0063] 3. After obtaining the list of applications and middleware, determine whether there is a method of containerized deployment by keyword matching: Use Python to simulate browser behavior. After opening the project website, obtain the HTML source code of the web page. Through a preset regular expression, pull all docker pull and docker run commands in the web page and output them to the log; Use Python to simulate browser behavior. After opening the project website, obtain the HTML source code of the web page. By parsing the HTML page, extract all the code parts wrapped by preformatted text tags and output them to the log; Determine whether the repository contains files with "docker-compose.*" (defining and running containers) and output them to the log; Allow manual input of containerized deployment commands;

[0064] 4. If there is a method of containerized deployment, instantiate it using the docker run or docker-compose command;

[0065] 5. Through the docker ps command, list the containers in the instantiation and obtain the ports mapped to the host;

[0066] 6. Use the SSL library of Python to establish a TLS connection with the server and send a client request handshake packet;

[0067] 7. Wait for the server to return a server response handshake packet. If the connection is not successfully established, judge the reason for the failure: the port is not open, the port does not use TLS encrypted communication, etc.;

[0068] 8. Use the SSL library of Python to extract the required fields from the server response handshake packet: TLSVersion (Transport Layer Security protocol version), Cipher (the name of the encryption algorithm supported by the Transport Layer Security protocol), Extensions (the extended content supported by the Transport Layer Security protocol);

[0069] 9. Arrange the above data in the order of the Secure Transport Layer Protocol version, the names of supported encryption algorithms, and the supported extended content, and use "," to separate each field. For the supported encryption algorithms and the supported extended content (or types), use "-" to connect different fields and concatenate them into a long string.

[0070] 10. Calculate the hash value k of this string;

[0071] 11. Insert the hash value, the service or application name, and the supplementary description into the JA3S fingerprint database.

[0072] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and accompanying drawings, this does not require or imply that these operations must be performed in this specific order, or that all the shown operations must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.

[0073] The implementation of the server port service identification device can refer to the implementation of the above method, and the repeated parts will not be described again. The terms "module" or "unit" used hereinafter may be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0074] Based on the same inventive concept, the present invention also proposes a server port service identification device, as Figure 4 shown, the device includes:

[0075] A determination module 401, configured to determine the port identifier and IP address of the service port to be identified;

[0076] A connection module 402, configured to establish a Secure Transport Layer Protocol connection with the corresponding server according to the IP address, and send a client request handshake packet to the service port to be identified on the server according to the port identifier of the service port to be identified;

[0077] An extraction module 403, configured to receive the server response handshake packet returned by the service port to be identified, and extract preset field information from the server response handshake packet; wherein, the server response handshake packet contains the Secure Transport Layer Protocol information adopted by the service port to be identified;

[0078] A splicing module 404, configured to splice the extracted preset field information into a string in a predetermined order;

[0079] A calculation module 405, configured to determine the hash value corresponding to the spliced string;

[0080] A matching module 406 is configured to match the hash value with the hash values included in each JA3S fingerprint data stored in a preset JA3S fingerprint database; if the match is successful, output the information of the port running service included in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data includes at least a pre-determined hash value and the information of the corresponding port running service; the pre-determined hash value is determined according to the information of the secure transport layer protocol adopted by the port.

[0081] In an embodiment of the present invention, the connection module 402 is specifically configured to:

[0082] Establish a secure transport layer protocol connection with the corresponding server using the SSL library in Python according to the IP address.

[0083] In an embodiment of the present invention, the extraction module 403 is specifically configured to:

[0084] Extract preset field information from the server response handshake packet using a preset regular expression.

[0085] In an embodiment of the present invention, the extraction module 403 is specifically configured to:

[0086] Input the server response handshake packet into a field information extraction model and output the preset field information; wherein, the field information extraction model is obtained by training a natural language processing model according to historical server response handshake packets and corresponding preset field information.

[0087] In an embodiment of the present invention, the preset field information includes one or more combinations of: the version of the secure transport layer protocol, the name of the encryption algorithm supported by the secure transport layer protocol, and the extended content supported by the secure transport layer protocol.

[0088] In an embodiment of the present invention, the calculation module 405 is specifically configured to:

[0089] Use the MD5 algorithm to determine the hash value corresponding to the concatenated string.

[0090] In an embodiment of the present invention, it further includes:

[0091] A message reminder module, configured to, after matching the hash value with the hash values included in each JA3S fingerprint data stored in the preset JA3S fingerprint database, if the match fails, output the port identifier of the service port to be identified, the IP address, the preset field information extracted from the server response handshake packet, and the hash value corresponding to the concatenated string; and send a reminder message that the port service cannot be identified.

[0092] It should be noted that although several modules of the server port service identification device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present invention, the features and functions of two or more of the above-described modules may be embodied in one module. Conversely, the features and functions of one module described above may be further divided and embodied by multiple modules.

[0093] Based on the foregoing inventive concept, as Figure 5 shown, the present invention further provides a computer device 500, including a memory 501, a processor 502, and a computer program 503 stored on the memory 501 and executable on the processor 502. When the processor 502 executes the computer program 503, the foregoing server port service identification method is implemented.

[0094] Based on the foregoing inventive concept, the present invention provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the foregoing server port service identification method is implemented.

[0095] Based on the foregoing inventive concept, the present invention provides a computer program product including a computer program, and when the computer program is executed by a processor, the server port service identification method is implemented.

[0096] The server port service identification method and device provided by the embodiments of the present invention can solve the problem that in the upper layer of TCP plaintext transmission, TLS is used for encrypted communication, resulting in the inability of the prior art to identify the server port service. The embodiments of the present invention determine the port identifier and IP address of the service port to be identified; establish a Secure Transport Layer Protocol connection with the corresponding server according to the IP address, and send a client request handshake packet to the service port to be identified of the server according to the port identifier of the service port to be identified; receive the server response handshake packet returned by the service port to be identified, and extract preset field information from the server response handshake packet; wherein, the server response handshake packet contains the Secure Transport Layer Protocol information adopted by the service port to be identified; splice the extracted preset field information into a string in a predetermined order; determine the hash value corresponding to the spliced string; match the hash value with the hash value contained in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, output the information of the port running service contained in the corresponding JA3S fingerprint data; wherein, multiple JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data at least contains a pre-determined hash value and the information of the corresponding port running service; the pre-determined hash value is determined according to the Secure Transport Layer Protocol information adopted by the port. The embodiments of the present invention use the handshake information of the Secure Transport Layer Protocol to identify the service running on the port. Specifically, the preset field information extracted from the server response handshake packet is spliced to obtain a string, and further the hash value corresponding to the spliced string is determined. By matching the hash value with the hash value contained in the JA3S fingerprint data, the information of the port running service is determined. The embodiments of the present invention can accurately identify the server port service.

[0097] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0098] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for realizing the processFigure 1 one process or multiple processes and / or blocks Figure 1 a device for the functions specified in one block or multiple blocks.

[0099] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device that implements the functions in the process Figure 1 one process or multiple processes and / or blocks Figure 1 specified in one block or multiple blocks.

[0100] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the process Figure 1 one process or multiple processes and / or blocks Figure 1 specified in one block or multiple blocks.

[0101] In the specific embodiments described above, the objectives, technical solutions, and beneficial effects of the present invention have been further elaborated in detail. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A server port service identification method, characterized in that: include: Determine the port identifier and IP address of the service port to be identified; Establish a secure transport layer protocol connection with the corresponding server according to the IP address, and send a client request handshake packet to the service port to be identified on the server according to the port identifier of the service port to be identified; Receive a server response handshake packet returned by the service port to be identified, and extract preset field information from the server response handshake packet; wherein the server response handshake packet includes the secure transport layer protocol information adopted by the service port to be identified; Concatenate the extracted preset field information into a character string in a predetermined order; Determine the hash value corresponding to the concatenated string; The hash value is matched with the hash value contained in each JA3S fingerprint data stored in the preset JA3S fingerprint database; if the match is successful, the information of the port running service contained in the corresponding JA3S fingerprint data is output; wherein, a plurality of JA3S fingerprint data are stored in the preset fingerprint database, and each JA3S fingerprint data at least contains a predetermined hash value and the corresponding port running service information; the predetermined hash value is determined according to the secure transport layer protocol information adopted by the port.

2. The method according to claim 1, characterized in that Establish a secure transport layer protocol connection with the corresponding server based on the IP address, including: According to the IP address, use the SSL library in Python to establish a secure transport layer protocol connection with the corresponding server.

3. The method according to claim 1, characterized in that Extract the preset field information from the server response handshake packet, including: Use the preset regular expression to extract the preset field information in the server response handshake packet.

4. The method according to claim 1, characterized in that Extract the preset field information from the server response handshake packet, including: The server response handshake packet is input into a field information extraction model, and preset field information is output; wherein the field information extraction model is obtained by training a natural language processing model based on historical server response handshake packets and corresponding preset field information.

5. The method according to claim 1, characterized in that The preset field information includes: one or more combinations of the secure transport layer protocol version, the name of the encryption algorithm supported by the secure transport layer protocol, and the extended content supported by the secure transport layer protocol.

6. The method according to claim 1, characterized in that Determine the hash value corresponding to the concatenated string, including: Use the MD5 algorithm to determine the hash value corresponding to the concatenated string.

7. The method according to claim 1, characterized in that After matching the hash value with the hash value contained in each JA3S fingerprint data stored in the preset JA3S fingerprint database, the method further includes: If the match fails, output the port identifier of the service port to be identified, the IP address, the preset field information extracted from the server response handshake packet, and the hash value corresponding to the concatenated string; Issues a warning message that the port service cannot be recognized.

8. A server port service identification device, characterized in that: include: A determination module, used to determine the port identifier and IP address of the service port to be identified; A connection module is used to establish a secure transport layer protocol connection with the corresponding server according to the IP address, and send a client request handshake packet to the service port to be identified on the server according to the port identifier of the service port to be identified; The extraction module is used to receive the server response handshake packet returned by the service port to be identified, and extract the preset field information from the server response handshake packet; wherein the server response handshake packet contains the secure transport layer protocol information adopted by the service port to be identified; A concatenation module, used to concatenate the extracted preset field information into a character string in a predetermined order; A calculation module, used to determine the hash value corresponding to the concatenated string; A matching module is used to match the hash value with the hash value contained in each JA3S fingerprint data stored in a preset JA3S fingerprint database; if the match is successful, the information of the port running service contained in the corresponding JA3S fingerprint data is output; wherein the preset fingerprint database stores multiple JA3S fingerprint data, each JA3S fingerprint data at least includes a predetermined hash value and the corresponding port running service information; the predetermined hash value is determined according to the secure transport layer protocol information adopted by the port.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.