Data detection method and device
By acquiring NTP data packets and using their associated DNS data to determine whether there is an NTP hidden channel information, the false alarm and missed response problems of detecting NTP hidden channel information in the prior art are solved, and efficient and accurate detection effects are achieved.
Patent Information
- Application Number
- CN202311635802.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively detect information in NTP hidden channels, and there are problems of false alarms and missed alarms, and the detection cost is high.
By acquiring NTP packets and determining whether there is an information about NTP hidden channel based on their associated DNS data, the detection process is simplified.
It realizes simple and efficient detection of information in NTP hidden channels, reducing detection costs and improving detection accuracy.
Smart Images

Figure CN120074849A_ABST
Abstract
Description
Technical Field
[0001] This application relates to information technology, and more specifically, to a data detection method and apparatus. Background Art
[0002] The Network Time Protocol (NTP) is a network protocol that enables clock synchronization between computer systems with variable latency in a data network through packet switching. A covert channel is an extension of information hiding technology that covertly transmits information from one end to the other by hiding the communication channel.
[0003] Currently, there are problems with NTP covert channel detection methods, such as only being able to detect attack behaviors with small amounts of data, as well as false positives and false negatives. Therefore, how to ensure that the information in the NTP covert channel is detected is an urgent problem to be solved. Summary of the Invention
[0004] This application provides a data detection method and apparatus that can simply and effectively detect the information in the NTP covert channel with relatively low detection costs.
[0005] In a first aspect, a data detection method is provided. The method includes: obtaining a Network Time Protocol (NTP) data packet. Determining whether the NTP data packet contains information about an NTP covert channel based on the Domain Name System (DNS) data associated with the NTP data packet.
[0006] Herein, the information about the NTP covert channel can be understood as the covert information carried in the NTP covert channel. In other words, whether the NTP data packet contains the covert information carried in the NTP covert channel.
[0007] In the above technical solution, by determining whether DNS data exists before the NTP data packet, it is possible to simply and efficiently determine whether the NTP data packet contains information about the NTP covert channel without parsing the NTP data packet.
[0008] In combination with the first aspect, in certain implementations of the first aspect, determining whether the NTP data packet contains information about the NTP covert channel based on the DNS data associated with the NTP data packet includes: determining that the NTP data packet contains information about the NTP covert channel when no DNS data is found.
[0009] In combination with the first aspect, in some implementations of the first aspect, determining whether there is information about an NTP covert channel based on the Domain Name System (DNS) data associated with the NTP packet includes: in the case where DNS data is found, determining whether there is information about an NTP covert channel based on the first Internet Protocol (IP) address and the second IP address included in the DNS data; wherein, the first IP address is the IP address corresponding to the NTP packet.
[0010] In this way, whether the second IP address included in the DNS data matches the first IP address corresponding to the NTP packet also does not require further parsing of the NTP packet. In the case where DNS data can be found, it is possible to further simply and efficiently determine whether there is an NTP covert channel in the NTP packet.
[0011] In combination with the first aspect, in some implementations of the first aspect, the second IP address includes multiple IP addresses. Determining whether there is information about an NTP covert channel based on the first IP address and the second IP address included in the DNS data includes: in the case where the multiple IP addresses do not include the first IP address, determining that there is information about an NTP covert channel in the NTP packet.
[0012] In combination with the first aspect, in some implementations of the first aspect, detecting whether there is an NTP covert channel based on the DNS data associated with the NTP packet includes: in the case where DNS data is found and the multiple IP addresses include the first IP address, parsing the NTP packet to obtain a first timestamp and a second timestamp, where the first timestamp is the server system time when the server receives the NTP request message, and the second timestamp is the server system time when the server sends the NTP response message. The NTP packet includes an NTP request message and an NTP response message. Determining whether there is information about an NTP covert channel based on the first timestamp and the second timestamp.
[0013] In combination with the first aspect, in some implementations of the first aspect, detecting whether there is information about an NTP covert channel based on the first timestamp and the second timestamp includes: in the case where the first timestamp is later than the second timestamp, determining that there is information about an NTP covert channel in the NTP packet. And / or, in the case where the time interval between the first timestamp and the second timestamp is greater than or equal to a preset time duration, determining that there is information about an NTP covert channel in the NTP packet.
[0014] In the above technical solution, the first timestamp and the second timestamp in the server system time can be used to determine whether the server response duration is abnormal, and it is possible to simply and efficiently determine whether there is an NTP covert channel in the NTP packet.
[0015] In combination with the first aspect, in some implementations of the first aspect, determining whether there is information about an NTP covert channel in an NTP data packet based on a first timestamp and a second timestamp includes: when the first timestamp and the second timestamp meet a preset condition, determining whether there is information about an NTP covert channel in the NTP data packet according to whether a first type and a second type match. Wherein, the first type is the type corresponding to a first extended field of an NTP response message of a server, the second type is the type corresponding to a second extended field of an NTP request message of a client, and the NTP data packet includes an NTP response message and an NTP request message.
[0016] In combination with the first aspect, in some implementations of the first aspect, determining whether there is information about an NTP covert channel in an NTP data packet according to a first type and a second type includes: when the first type and the second type do not match, determining that there is information about an NTP covert channel in the NTP data packet.
[0017] In combination with the first aspect, in some implementations of the first aspect, determining whether there is information about an NTP covert channel in an NTP data packet according to a first type and a second type includes: when the first type and the second type match, determining whether there is an NTP covert channel in the NTP data packet according to an abnormal situation of a first payload format and / or a second payload format; wherein, the first payload format is the payload format corresponding to the first extended field, and the second payload format is the payload format corresponding to the second extended field.
[0018] In the above technical solution, by using the types of the extended fields and / or the payloads corresponding to the extended fields in the NTP request message and the NTP response message, it is not only possible to simply and effectively determine whether there is information about an NTP covert channel in the NTP data packet, but also possible to detect a large amount of covert information.
[0019] In a second aspect, a data detection method is provided, and the method includes: obtaining an NTP data packet. Parsing the NTP data packet to obtain a first timestamp and a second timestamp. Determining whether there is information about an NTP covert channel in the NTP data packet according to the first timestamp and the second timestamp, where the NTP data packet includes an NTP request message and an NTP response message.
[0020] In the above technical solution, by using the first timestamp and the second timestamp in the server system time, it is possible to determine whether the server response duration is abnormal, and simply and efficiently determine whether there is an NTP covert channel in the NTP data packet.
[0021] In combination with the second aspect, in some implementations of the second aspect, detecting whether there is information about an NTP covert channel in an NTP data packet according to a first timestamp and a second timestamp includes: when the first timestamp is later than the second timestamp, determining that there is information about an NTP covert channel in the NTP data packet. And / or, when the time interval between the first timestamp and the second timestamp is greater than or equal to a preset time length, determining that there is information about an NTP covert channel in the NTP data packet.
[0022] In a third aspect, a data detection method is provided. The method includes: obtaining an NTP data packet. Parsing the NTP data packet to obtain a first type and a second type. Determining whether there is information about an NTP covert channel in the NTP data packet according to the first type and the second type. Wherein, the first type is the type corresponding to a first extension field of an NTP response message of a server, the second type is the type corresponding to a second extension field of an NTP request message of a client, and the NTP data packet includes an NTP response message and an NTP request message.
[0023] In the above technical solution, through the types of extension fields and / or the payloads corresponding to the extension fields in the NTP request message and the NTP response message, it is not only possible to simply and effectively determine whether there is information about an NTP covert channel in the NTP data packet, but also to detect covert information with a large amount of data.
[0024] In combination with the third aspect, in some implementations of the third aspect, determining whether there is information about an NTP covert channel in the NTP data packet according to the first type and the second type includes: when the first type and the second type do not match, determining that there is information about an NTP covert channel in the NTP data packet.
[0025] In combination with the third aspect, in some implementations of the third aspect, determining whether there is information about an NTP covert channel in the NTP data packet according to the first type and the second type includes: when the first type and the second type match, determining whether there is information about an NTP covert channel in the NTP data packet according to an abnormal condition of a first payload format and / or a second payload format; wherein, the first payload format is the payload format corresponding to the first extension field, and the second payload format is the payload format corresponding to the second extension field.
[0026] In a fourth aspect, a data detection device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to obtain a Network Time Protocol (NTP) data packet. The processing unit is configured to determine whether there is information about an NTP covert channel in the NTP data packet according to Domain Name System (DNS) data associated with the NTP data packet.
[0027] It should be understood that the beneficial effects corresponding to the fourth aspect are similar to those of the first aspect and can refer to the first aspect, which will not be elaborated here.
[0028] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine information on an NTP covert channel in the NTP data packet when DNS data is not searched.
[0029] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine whether there is information on an NTP covert channel in the NTP data packet according to a first network protocol IP address and a second IP address included in the DNS data when the DNS data is searched. The first IP address is the IP address corresponding to the NTP data packet.
[0030] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the second IP address includes multiple IP addresses. The processing unit is specifically configured to determine that there is information on an NTP covert channel in the NTP data packet when the first IP address is not included in the multiple IP addresses.
[0031] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to, when the DNS data is searched and the first IP address is included in the multiple IP addresses, parse the NTP data packet to obtain a first timestamp and a second timestamp. The first timestamp is the server system time when the server receives the NTP request message, and the second timestamp is the server system time when the server sends the NTP response message. The NTP data packet includes an NTP request message and an NTP response message. Determine whether there is information on an NTP covert channel in the NTP data packet according to the first timestamp and the second timestamp.
[0032] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine that there is information on an NTP covert channel in the NTP data packet when the first timestamp is later than the second timestamp. And / or, determine that there is information on an NTP covert channel in the NTP data packet when the interval duration between the first timestamp and the second timestamp is greater than or equal to a preset duration.
[0033] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine whether there is information on an NTP covert channel in the NTP data packet according to a first type and a second type when the first timestamp and the second timestamp meet a preset condition. The first type is the type corresponding to a first extension field of the NTP response message of the server, and the second type is the type corresponding to a second extension field of the NTP request message of the client. The NTP data packet includes an NTP response message and an NTP request message.
[0034] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine information about an NTP covert channel in the NTP data packet when the first type and the second type do not match.
[0035] In combination with the fourth aspect, in some implementation manners of the fourth aspect, the processing unit is specifically configured to determine whether there is information about an NTP covert channel in the NTP data packet according to abnormal conditions of the first payload format and / or the second payload format when the first type and the second type match; wherein, the first payload format is the payload format corresponding to the first extension field, and the second payload format is the payload format corresponding to the second extension field.
[0036] In a fifth aspect, a data detection device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to obtain an NTP data packet. The processing unit is configured to parse the NTP data packet to obtain a first timestamp and a second timestamp. According to the first timestamp and the second timestamp, determine whether there is information about an NTP covert channel in the NTP data packet, and the NTP data packet includes an NTP request message and an NTP response message.
[0037] It should be understood that the beneficial effects corresponding to the fifth aspect are similar to those of the second aspect and can be referred to the second aspect, which will not be elaborated here.
[0038] In combination with the fifth aspect, in some implementation manners of the fifth aspect, the processing unit is specifically configured to: determine that there is information about an NTP covert channel in the NTP data packet when the first timestamp is later than the second timestamp; and / or, determine that there is information about an NTP covert channel in the NTP data packet when the interval duration between the first timestamp and the second timestamp is greater than or equal to a preset duration.
[0039] In a sixth aspect, a data detection device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to obtain an NTP data packet. The processing unit is configured to parse the NTP data packet to obtain a first type and a second type. According to the first type and the second type, determine whether there is information about an NTP covert channel in the NTP data packet. Wherein, the first type is the type corresponding to the first extension field of the NTP response message of the server, and the second type is the type corresponding to the second extension field of the NTP request message of the client, and the NTP data packet includes an NTP response message and an NTP request message.
[0040] It should be understood that the beneficial effects corresponding to the sixth aspect are similar to those of the third aspect and can be referred to the third aspect, which will not be elaborated here.
[0041] In combination with the sixth aspect, in some implementations of the sixth aspect, the processing unit is configured to: determine information on the existence of an NTP covert channel in the NTP data packet when the first type and the second type do not match.
[0042] In combination with the sixth aspect, in some implementations of the sixth aspect, the processing unit is configured to: when the first type and the second type match, determine whether there is information on an NTP covert channel in the NTP data packet according to anomalies in the first payload format and / or the second payload format; where the first payload format is the payload format corresponding to the first extension field, and the second payload format is the payload format corresponding to the second extension field.
[0043] In a seventh aspect, there is provided a data detection device, which includes: a memory for storing a program; a processor for executing the computer program or instruction stored in the memory, and when the computer program or instruction stored in the memory is executed, the processor is configured to execute the method provided by any one of the implementations of the first aspect or the third aspect above.
[0044] In one implementation, the device may be a gateway in the intelligent network connection system of a vehicle.
[0045] In another implementation, the device may be a chip, a chip system, or a circuit in the gateway in the intelligent network connection system of a vehicle.
[0046] In an eighth aspect, the present application provides a processor for executing the method provided by any one of the implementations of the first aspect to the third aspect above. During the execution of these methods, the processes of sending the above information and obtaining / receiving the above information in the above methods can be understood as the process of the processor outputting the above information, and the process of the processor receiving the input above information. When outputting the above information, the processor outputs the above information to an interface for transmission through the interface. After the above information is output by the processor, other processing may be required before it reaches the interface. Similarly, when the processor receives the input above information, the interface obtains / receives the above information and inputs it to the processor. Further, after the interface receives the above information, the above information may require other processing before it is input to the processor.
[0047] For operations such as transmission, sending, and obtaining / receiving involved, if there is no special indication, or if it does not conflict with its actual role or internal logic in the relevant description, it can be understood as operations such as output and reception, input, etc., and can also be understood as operations of transmission, sending, and receiving performed by the radio frequency circuit and the antenna. The present application does not make any limitations in this regard.
[0048] In the implementation process, the above-mentioned processor can be a processor specifically designed to execute these methods, or a processor that executes computer programs or instructions in a memory to execute these methods, such as a general-purpose processor. The above-mentioned memory can be a non-transitory memory, such as a read only memory (ROM), which can be integrated with the processor on the same chip or can be separately provided on different chips. The embodiments of the present application do not limit the type of the memory and the setting manner of the memory and the processor.
[0049] In a ninth aspect, a computer-readable storage medium is provided. The computer-readable medium stores program code for a device to execute, and the program code includes methods provided by any one of the implementations of the first aspect to the third aspect above.
[0050] In a tenth aspect, a computer program product including instructions is provided. When the computer program product runs on a computer, the computer is caused to execute the methods provided by any one of the implementations of the first aspect to the third aspect above.
[0051] In an eleventh aspect, a vehicle is provided. The vehicle includes any possible device in the fourth aspect to the sixth aspect.
[0052] In some possible implementation manners, the vehicle is a vehicle.
[0053] Among them, the vehicle in the present application may include land vehicles, water vehicles, air vehicles, industrial equipment, agricultural equipment, or entertainment equipment, etc. For example, the vehicle can be a vehicle, and the vehicle is a vehicle in a broad sense, and can be a transportation vehicle (such as a commercial vehicle, a passenger vehicle, a motorcycle, a flying vehicle, a train, etc.), an industrial vehicle (such as a forklift, a trailer, a tractor, etc.), an engineering vehicle (such as an excavator, a bulldozer, a crane, etc.), agricultural equipment (such as a lawn mower, a harvester, etc.), entertainment equipment, a toy vehicle, etc. The embodiments of the present application do not specifically limit the type of the vehicle.
[0054] In a twelfth aspect, a chip is provided. The chip includes a processor and a communication interface. The processor reads instructions stored on a memory through the communication interface and executes the methods provided by any one of the implementations of the first aspect to the third aspect above.
[0055] Optionally, as an implementation manner, the chip may further include a memory. A computer program or instruction is stored in the memory, and the processor is configured to execute the computer program or instruction stored on the memory. When the computer program or instruction is executed, the processor is configured to execute the methods provided by any one of the implementations of the first aspect to the third aspect above. Description of the Drawings
[0056] Figure 1 It is a schematic diagram of the time synchronization process of NTP provided by an embodiment of the present application;
[0057] Figure 2 It is a schematic diagram of the message structure of an NTP data packet provided by an embodiment of the present application;
[0058] Figure 3 It is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0059] Figure 4 It is a schematic diagram of the process of a data detection method provided by an embodiment of the present application;
[0060] Figure 5 It is a schematic diagram of the process of another data detection method provided by an embodiment of the present application;
[0061] Figure 6 It is a schematic diagram of the process of yet another data detection method provided by an embodiment of the present application;
[0062] Figure 7 It is a schematic diagram of the process of still another data detection method provided by an embodiment of the present application;
[0063] Figure 8 It is a schematic diagram of the format of an extended field provided by an embodiment of the present application;
[0064] Figure 9 It is the data format of a payload provided by an embodiment of the present application;
[0065] Figure 10 It is a schematic diagram of the process of still another detection method provided by an embodiment of the present application;
[0066] Figure 11 It is a schematic diagram of a data detection device provided by an embodiment of the present application;
[0067] Figure 12 It is a schematic structural diagram of a data detection device provided by an embodiment of the present application;
[0068] Figure 13 It is a schematic diagram of a chip system provided by an embodiment of the present application. Detailed implementation manners
[0069] Next, the technical solutions in the present application will be described in conjunction with the accompanying drawings.
[0070] For ease of understanding of the embodiments of the present application, the following points are explained:
[0071] First, in this application, if there is no special explanation or logical conflict, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0072] Second, in this application, "at least one" means one or more, and "a plurality of" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. In the written description of this application, the character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item) of a, b, and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b, and c. Where a, b, and c can be single or multiple respectively.
[0073] Third, in this application, "first", "second", and various numerical numbers (such as #1, #2, etc.) are used for distinction for the convenience of description and do not limit the scope of the embodiments of this application. For example, to distinguish different timestamps, etc., rather than for describing a specific order or sequence. It should be understood that the objects described in this way can be interchanged under appropriate circumstances so as to be able to describe the solutions other than the embodiments of this application.
[0074] Fourth, in this application, descriptions such as "when...", "in the case of...", and "if" all refer to corresponding processing under certain objective circumstances, not to limit time, and do not require a judgment action to be necessarily made during implementation, nor does it mean the existence of other limitations. Additionally, it does not mean that the judgment action after these conditional conjunctions is the only condition for achieving the result, and other additional conditions can also be included to achieve the result.
[0075] Fifth, in this application, the terms "comprise" and "have" and any of their variations are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0076] Sixth, in this application, "for indicating" may include for direct indication and for indirect indication. When describing the case where a certain indication information is used to indicate A, it may include that the indication information directly indicates A or indirectly indicates A, and it does not mean that A must be carried in the indication information.
[0077] The indication methods involved in the embodiments of this application should be understood to cover various methods that can enable the party to be indicated to obtain the indication information. The indication information can be sent together as a whole, or can be divided into multiple sub-information and sent separately, and the sending periods and / or sending timings of these sub-information can be the same or different. This application does not limit the specific sending method.
[0078] The "indication information" in the embodiments of this application can be explicit indication, that is, directly indicated by signaling, or obtained according to the parameters indicated by signaling, in combination with other rules or in combination with other parameters or through derivation. It can also be implicit indication, that is, obtained according to rules or relationships, or according to other parameters, or through derivation. This application does not make specific limitations on this.
[0079] Seventh, in this application, "storing" may refer to storing in one or more memories. The one or more memories can be separately provided, or can be integrated in an encoder or a decoder, a processor, or a communication device. The one or more memories can also be partly separately provided and partly integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and this application does not limit this.
[0080] Figure 1 It is a schematic diagram of the time synchronization process of an NTP provided by the embodiments of this application.
[0081] As Figure 1 shown, the client sends an NTP request message to the server at timestamp #1 (denoted as T1), and the server receives the NTP request message from the client at timestamp #2 (denoted as T2). The server sends an NTP response message to the client at timestamp #3 (denoted as T3), and the client receives the NTP response message from the server at timestamp #4 (T4). Among them, T1 and T4 are referenced to the time system of the client, and T2 and T3 are referenced to the time system of the server. Among them, T1, T2, and T3 are transmitted on the network, and the client can obtain the synchronized time through T1, T2, T3, and T4.
[0082] Specifically, the two-way network delay between the server and the client is: Tdel = (T4 - T1) - (T3 - T2); the time difference between the system times of the client and the server is denoted as Toff, and the time of the client's clock synchronization is T4 + Toff = T3 + Tdel / 2.
[0083] Figure 2 It is a schematic diagram of the message structure of an NTP data packet provided by an embodiment of the present application.
[0084] As Figure 2 shown, the NTP data packet may include the following fields. Leap Indicator (LI) field: The length of this field is 2 bits, and the binary form of this field is "11" to indicate the alarm status, that is, the clock is not synchronized. Other binary forms of this field are used to indicate that the NTP data packet itself is not processed. Version Number (VN) field: The length of this field is 3 bits, indicating the version number of the NTP data packet. Mode field: The length of this field is 3 bits, indicating the working mode of the NTP data packet. The meanings corresponding to the specific values of this field are shown in Table 1.
[0085] Table 1
[0086]
[0087]
[0088] Stratum field of the system clock: The value range of this field is from 1 to 16. This field defines the accuracy of the clock. A value of 1 for this field indicates the highest clock accuracy, and the clock accuracy decreases sequentially from 1 to 16. A value of 16 for this field indicates that the clock is in an unsynchronized state and cannot be used as a reference clock. Poll field: This field represents the time interval between two consecutive NTP packets. Precision field: This field is used to represent the precision of the system clock. Root delay field: This field is used to identify the round-trip time of the primary reference clock source. Root dispersion field: This field represents the maximum error of the system clock relative to the primary reference clock. Reference identifier field: This field represents the identifier of the reference clock source. Reference timestamp field: This field represents the time when the system clock was last set or updated. Originate timestamp field: This field represents the client system time when the NTP request packet leaves the client, that is, the above timestamp #1 (denoted as T1). Receive timestamp field: This field represents the server system time when the NTP request packet arrives at the server, that is, the above timestamp #2 (denoted as T2). Transmit timestamp field: This field represents the server system time when the NTP response packet leaves the server, that is, the above timestamp #3 (denoted as T3). Extension field: This field is an optional extension field with a minimum padding length of 16 bytes. Key identifier field: The key negotiated between the client and the server, this field is an optional field. Authentication (dgst) field: This field represents the hash value of the NTP header and the extension field calculated using the key, this field is an optional field.
[0089] Covert channels are an extension of information hiding technology, and information is covertly transmitted from one end to the other through covert channels. Therefore, covert channels are one of the important methods to ensure the secure transmission of information. High-performance covert channels can resist attacks and sabotage by third parties and have a large channel capacity and information transmission rate. The popularity of NTP packets and their irreplaceability in time synchronization at the application layer make NTP-based covert channels have the advantages of strong penetration ability and good concealment.
[0090] Currently, the detection methods for NTP-based covert channels are as follows: One method is to use the least significant bit of the timestamp in the NTP packet as the carrier of the encrypted information for covert transmission. The covert information is disguised as a normal NTP packet for covert transmission. Here, the least significant bit refers to the 0th bit in the binary digits representing the timestamp. During the detection process, the least significant bit of the timestamp under normal communication is extracted as the normal data sample. According to the construction method of the NTP covert channel, encrypted data samples are obtained through experimental simulation, and a detection method based on a Bayesian classifier is implemented on the basis of the above training set. Since the carrier of the covert information in this method can carry a relatively small amount of data, it is difficult to detect large amounts of covert information such as file transfer and remote desktop control in the NTP packet data.
[0091] Another method is to determine whether there is an extension field in the NTP packet, and when there is an extension field, judge whether there is covert information in the extension field based on a random forest algorithm model. Since this method is a statistical discrimination method, there will be cases of false positives and false negatives.
[0092] In view of the above problems, the embodiments of the present application propose a data detection method and device, which will be described in detail below in combination with Figures 3 to 13 Detailed description.
[0093] Figure 3 It is a schematic diagram of an application scenario provided by the embodiments of the present application.
[0094] As Figure 3 shown, the data detection method and device provided by the embodiments of the present application can be applied to vehicles, such as the intrusion detection system (IDS) of the gateway (GW) in a vehicle. The vehicle includes a telematics box (T-box), an infotainment system, a comfort system, an autonomous driving system, a powertrain chassis, a body, and an on-board diagnostics (OBD) interface and a gateway. Among them, the gateway communicates with other parts through wireless or wired connections. The detection method and device provided by the embodiments of the present application can be applied to vehicles to detect abnormal NTP packets and thus detect covert channels, or can also be applied to other scenarios, such as cloud environments, mobile phone terminals, etc. in scenarios where the NTP protocol is used, so as to detect covert channels in abnormal NTP packets. The embodiments of the present application do not limit the application scenarios.
[0095] It should be understood that the method provided in the embodiments of the present application can be applied to a data detection device. This detection device can be deployed as an independent network device in a vehicle or other devices using the NTP protocol, or can also be deployed in a gateway, such as deployed in the gateway of a vehicle, or can also be deployed on a component with data node functions, for example, deployed in the T-box of a vehicle.
[0096] Figure 4 FIG. 4 is a schematic flow chart of a data detection method provided by an embodiment of the present application. It should be understood that hereinafter, taking the gateway deployed in the intelligent network connection system of a vehicle as the execution subject for implementing the detection method in the embodiments of the present application as an example for illustration. For example, the method implemented by the gateway can also be implemented by a module of the gateway (such as a chip, a chip system or a processor), and can also be implemented by a logical node, a logical module or software that can implement all or part of the bending pipe function.
[0097] S401, obtain an NTP data packet.
[0098] S402, determine whether the NTP data packet contains information about an NTP covert channel.
[0099] As a possible implementation manner, according to the domain name system (DNS) data associated with the NTP data packet, determine whether the NTP data packet contains information about an NTP covert channel. The following will be combined with Figure 5 be described in detail.
[0100] As a possible implementation manner, according to the time stamp of the server system time, determine whether the NTP data packet contains information about an NTP covert channel. The following will be combined with Figure 6 be described in detail.
[0101] As a possible implementation manner, when the NTP data packet is in the service mode, according to at least one of the type corresponding to the extended field of the NTP data packet and the payload format corresponding to the extended field, determine whether the NTP data packet contains information about an NTP covert channel. The following will be combined with Figure 7 be described in detail.
[0102] As a possible implementation manner, one or more of the above implementation manners can be combined to determine whether the NTP data packet contains information about an NTP covert channel. The following will be combined with Figure 10 describe in detail one of the combined judgment methods.
[0103] Figure 5 FIG. 5 is a schematic flow chart of another data detection method provided by an embodiment of the present application.
[0104] S501, record the first IP address of the server.
[0105] It should be understood that in S401 and S402, when obtaining and parsing the NTP data packet, the corresponding first IP address of the server can be recorded.
[0106] Among them, the first IP address can also be understood as the IP address corresponding to the NTP data packet.
[0107] S502, determine whether DNS data is searched.
[0108] It should be understood that in the case of data detection, DNS data and NTP data should theoretically appear correspondingly.
[0109] S503, if DNS data is searched, then parse the DNS data to obtain the second IP address included in the DNS data.
[0110] It should be understood that the second IP address includes at least one IP address, and at least one IP address corresponds to at least one NTP server. In the case where the second IP address includes multiple IP addresses, the second IP address can also be referred to as an IP address list.
[0111] S504, determine whether the first IP address and the second IP address match.
[0112] As a possible implementation, the second IP address includes multiple IP addresses, and determine whether the multiple IP addresses include the first IP address.
[0113] In other words, in the case where the second IP address includes multiple IP addresses, determine whether the IP address list includes the first IP address.
[0114] It should be understood that theoretically, the first IP address can be informed to the client through the DNS data corresponding to the NTP data.
[0115] As a possible implementation, the second IP address includes one IP address, and determine whether the second IP address is the first IP address.
[0116] S505, if the first IP address and the second IP address do not match, determine that the NTP data packet contains information about the NTP covert channel.
[0117] As a possible implementation, if the second IP address does not include the first IP address, determine that the NTP data packet contains information about the NTP covert channel.
[0118] In other words, in the case where the second IP address includes multiple IP addresses, if the IP address list does not include the first IP address, determine that the NTP data packet contains information about the NTP covert channel.
[0119] It should be understood that DNS data and NTP data packets appear correspondingly. If the list of IP addresses in the DNS data does not include the first IP address, it is determined that there is an NTP covert channel in the NTP data packet.
[0120] As a possible implementation, if the second IP address is not the first IP address, information indicating that there is an NTP covert channel in the NTP data packet is determined.
[0121] Optionally, in S505, if DNS data is not searched in S502, information indicating that there is an NTP covert channel in the NTP data packet is determined.
[0122] It should be understood that since there is an association between DNS data and NTP data packets, if DNS data is not detected before the time node when NTP data is detected, it is determined that there is an NTP covert channel in the NTP data packet.
[0123] Optionally, if the list of IP addresses includes the first IP address, then according to other methods, it is determined whether there is information indicating an NTP covert channel in the NTP data packet.
[0124] It should be understood that in Figure 5 the illustrated embodiment, the NTP data packet is not further parsed. If it is determined that there is information indicating an NTP covert channel in the NTP data packet, it can be considered that the entire NTP data packet is for covert transmission. Figure 5 the illustrated embodiment does not limit the specific location of the covert channel carrying the covert information in the NTP data packet.
[0125] In the above technical solution, by determining whether there is DNS data before the NTP data packet, it is possible to simply and efficiently determine whether there is information indicating an NTP covert channel in the NTP data packet without parsing the NTP data packet.
[0126] Figure 6 It is a schematic flowchart of another data detection method provided by an embodiment of the present application.
[0127] S601, obtain a first timestamp and a second timestamp from the NTP data packet.
[0128] Wherein, the first timestamp is the server system time when the server receives the NTP request message, and the second timestamp is the server system time when the server sends the NTP response message.
[0129] For example, the first timestamp may be Figure 1 the timestamp #2 (denoted as T2) in Figure 1 and the second timestamp may be the timestamp #3 (denoted as T3) in
[0130] S602. Determine whether the server response duration is abnormal according to the first timestamp and the second timestamp.
[0131] As a possible implementation, if the first timestamp is later than the second timestamp, the server response duration is abnormal. S603. Determine the information of the NTP covert channel in the NTP data packet.
[0132] It should be understood that theoretically, the first timestamp of the server should be later than the second timestamp. The timestamp service in the NTP data packet itself provides a time reference for the client to synchronize the clock. In the data detection method of this application, the timestamp of the NTP data packet can be used for the detection of the information of the NTP covert channel. Therefore, in the case where the server response duration is abnormal with the first timestamp later than the second timestamp, it can be determined that there is information about the NTP covert channel in the NTP data packet.
[0133] As a possible implementation, if the interval duration between the first timestamp and the second timestamp is greater than the preset duration, the server response duration is abnormal. S603. Determine that there is information about the NTP covert channel in the NTP data packet.
[0134] Exemplarily, the preset duration can be 30 minutes, or other possible values, which are not limited in the embodiments of this application.
[0135] It should be understood that theoretically, the interval duration between the first timestamp and the second timestamp of the server should be within a reasonable range. The timestamp service in the NTP data itself provides a time reference for the client to synchronize the clock. In the data detection method of this application, the timestamp of the NTP data packet serves for the detection of the information of the NTP covert channel. Therefore, if this interval duration is not within a reasonable range, then it is determined that there is information about the NTP covert channel in the NTP data packet.
[0136] Optionally, if the interval duration between the first timestamp and the second timestamp is less than or equal to the preset duration, then determine whether there is information about the NTP covert channel in the NTP data packet according to other methods.
[0137] It should be understood that the embodiments of this application do not limit whether there is information about the NTP covert channel in the NTP data packet when the interval duration between the first timestamp and the second timestamp is equal to the preset duration.
[0138] It should be understood that the NTP covert channel carrying the covert information in the NTP data packet can be located in the field corresponding to the first timestamp and / or the second timestamp.
[0139] In the above technical solution, the first timestamp and the second timestamp in the server system time can be used to determine whether the server response duration is abnormal, and simply and efficiently determine whether there is an NTP covert channel in the NTP data packet.
[0140] Figure 7 It is a schematic flowchart of another data detection method provided by an embodiment of the present application. In the case of a large number of covert information, the covert information may be carried in the extension field of the NTP data packet.
[0141] S701, when the working mode corresponding to the NTP data packet is the service type, obtain the first type of the first extension field corresponding to the server from the NTP response message, and obtain the second type of the second extension field corresponding to the client from the NTP request message. The NTP data packet includes an NTP response message and an NTP request message.
[0142] Figure 8 It is a schematic diagram of the format of an extension field provided by an embodiment of the present application. As Figure 8 shown, the extension field includes a field type (fieldtype), a length, a value, and an optional padding part. The specific meanings corresponding to the values of the field type of the extension field are shown in Table 2.
[0143] Table 2
[0144]
[0145]
[0146] S702, determine whether the first type and the second type match.
[0147] Exemplarily, if the value of the field type of the second extension field corresponding to the client is 0x0002 and the second type is a no-operation request; the value of the field type of the first extension field corresponding to the server is 0x8002 and the first type is a no-operation response, it is determined that the first type and the second type match.
[0148] Exemplarily, if the value of the field type of the second extension field corresponding to the client is 0x0102 and the second type is an associated message request; the value of the field type of the first extension field corresponding to the server is 0x8102 and the first type is an associated message response, it is determined that the first type and the second type match.
[0149] When the first type and the second type match, S703, obtain the first payload format corresponding to the first extension field and the second payload format corresponding to the second extension field.
[0150] S704, determine the abnormal conditions of the first payload format and / or the second payload format.
[0151] As a possible implementation, determine whether the first payload format matches the second payload format.
[0152] Exemplarily, if the value of the field type of the second extension field corresponding to the client is 0x0002, the second type is a no-operation request, the length field in the second extension field is 0x0000, and there is no value field; the value of the field type of the first extension field corresponding to the server is 0x8002, the first type is a no-operation response, the length field in the first extension field is not 0x0000, or the value field includes specific data; then, the first payload format does not match the second payload format.
[0153] As another possible implementation, determine whether there are abnormal conditions in the specific payloads corresponding to the first payload format or the second payload format.
[0154] Exemplarily, Figure 9 is a data format of a payload provided by an embodiment of the present application. As Figure 9 shown, the data format of the associated message includes an R field, an E field, a code field, a field type field, a length field, an association ID field, a timestamp field, a filestamp field, a value length field, a value field, a signature length field, a signature field, and an optional padding field.
[0155] Specifically, taking the first payload format as an example, the value of the field type of the first extension field corresponding to the server is 0x8102, the first type is an associated message response, obtain the first value corresponding to the length field corresponding to the first extension field, and obtain the second value corresponding to the total field length of the association ID field, the timestamp field, the filestamp field, the value length field, the value field, the signature length field, the signature field, and the optional padding field. If the first value is not equal to the second value, it is determined that there is an abnormal condition in the specific payload corresponding to the first payload format.
[0156] It should be understood that the two possible determination methods in S704 can be implemented separately or in combination. For example, in the case where the first payload format matches the second payload format, determine the accuracy of the specific payload corresponding to the first payload format or the second payload format.
[0157] S705, if there are abnormal conditions in the first payload format and / or the second payload format, determine the information that the NTP data packet has an NTP covert channel.
[0158] As a possible implementation, if the first payload format does not match the second payload format, determine the information that the NTP data packet has an NTP covert channel.
[0159] As another possible implementation, if there are abnormal conditions in the payload corresponding to the first payload format or the second payload format, determine the information that the NTP data packet has an NTP covert channel.
[0160] Optionally, S705, if the first type and the second type in S702 do not match, determine the information that the NTP data packet has an NTP covert channel.
[0161] Optionally, if there are no abnormal conditions in the first payload format and / or the second payload format, then according to other methods, determine whether there is information about an NTP covert channel in the NTP data packet.
[0162] In the above technical solution, through the type of the extended field and / or the payload corresponding to the extended field in the NTP request message and the NTP response message, it is not only possible to simply and effectively determine whether there is information about an NTP covert channel in the NTP data packet, but also possible to detect a large amount of covert information.
[0163] The above Figure 5 、 Figure 6 and Figure 7 The detection methods shown can all be used alone, or can also be used in combination. The embodiments of the present application do not limit the number of combinations of the above detection methods, nor the combination order of the above detection methods. For example, it can be combined in the way as Figure 10 shown.
[0164] Figure 10 is a schematic flowchart of yet another detection method provided by the embodiments of the present application.
[0165] S504, if the first IP address matches the second IP address, then execute S601.
[0166] As a possible implementation, if the second IP address includes multiple IP addresses and the multiple IP addresses include the first IP address, then execute S601.
[0167] As a possible implementation, if the second IP address includes one IP address and the second IP address is the first IP address, then execute S601.
[0168] Optionally, S502, if DNS data is searched, execute S601.
[0169] It should be understood that the detailed steps of S501 to S505 can be referred to Figure 5 , which will not be elaborated here.
[0170] S602, if the response duration of the server is normal, then execute S701.
[0171] In other words, when the first timestamp and the second timestamp meet the preset conditions, execute S701. For example, if the first timestamp is earlier than the second timestamp, execute S701. Another example, if the interval duration between the first timestamp and the second timestamp is less than the preset duration, execute S701. Still another example, if the interval duration between the first timestamp and the second timestamp is less than or equal to the preset duration, execute S701.
[0172] It should be understood that the detailed steps of S601 to S603 can be referred to Figure 6 , which will not be elaborated here.
[0173] S704, if there is no abnormality in the first payload format and / or the second payload format, then determine that there is no information about the NTP covert channel in the NTP data packet.
[0174] It should be understood that the detailed steps of S701 to S705 can be referred to Figure 7 which will not be elaborated here.
[0175] Above, in combination with Figures 4 to 10 the data detection method provided by the embodiments of the present application has been described in detail. It can be understood that, in order to implement the above functions, it includes the corresponding hardware structure and / or software module for executing each function.
[0176] Those skilled in the art should be able to realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described function for a specific application, but such implementation should not be considered to exceed the scope of the present application.
[0177] Next, in combination with Figures 11 to 13 the data detection device provided by the embodiments of the present application will be described in detail. It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, the content that is not described in detail can be referred to the above method embodiments. For the sake of brevity, some content will not be elaborated again.
[0178] Figure 111 is a schematic diagram of a data detection device provided in an embodiment of the present application. The device may include a processing unit 1120, and the processing unit 1120 is used to perform data detection. The device may also include a transceiver unit 1110, and the transceiver unit 1110 may implement a corresponding communication function. The transceiver unit 1110 may also be referred to as a communication interface or a communication unit or an interface unit. It should be understood that for the operations such as sending and receiving involved in this application, if there is no special explanation, or if it does not conflict with its actual function or internal logic in the relevant description, it can be more generally understood as operations such as output and input, rather than sending and receiving operations directly performed by the radio frequency circuit and the antenna.
[0179] Optionally, the device may further include a storage unit, which may be used to store instructions and / or data, and the processing unit 1120 may read the instructions and / or data in the storage unit so that the device implements the aforementioned method embodiment.
[0180] The device can be used to execute the above method embodiments. In this case, the device can be a communication device or a component that can be configured in a communication device. The transceiver unit 1110 is used to execute the transceiver-related operations on the communication device side in the above method embodiments, and the processing unit 1120 is used to execute the processing-related operations in the above method embodiments.
[0181] As a design, the device is used to perform the above Figure 4 , Figure 5 and Figure 10 The method embodiment shown.
[0182] Specifically, the transceiver unit 1110 is used to obtain a Network Time Protocol NTP data packet.
[0183] The processing unit 1120 is configured to determine whether the NTP data packet contains information about an NTP covert channel according to the domain name system DNS data associated with the NTP data packet.
[0184] For matters not described in detail, reference may be made to the above method embodiments.
[0185] As a design, the data detection device is used to perform the above Figure 4 , Figure 6 and Figure 10 The method embodiment shown.
[0186] Specifically, the transceiver unit 1110 is used to obtain an NTP data packet. The processing unit 1120 is used to parse the NTP data packet to obtain a first timestamp and a second timestamp. According to the first timestamp and the second timestamp, it is determined whether the NTP data packet contains information about an NTP covert channel, and the NTP data packet includes an NTP request message and an NTP response message.
[0187] For details not described, reference may be made to the above method embodiments.
[0188] As a design, the data detection device is used to execute the method embodiments described above Figure 4 , Figure 7 and Figure 10 shown.
[0189] Specifically, the transceiver unit 1110 is configured to obtain an NTP data packet. The processing unit 1120 is configured to parse the NTP data packet to obtain a first type and a second type. According to whether the first type and the second type match, it is determined whether there is information about an NTP covert channel in the NTP data packet. Wherein, the first type is the type corresponding to the first extension field of the NTP response message of the server, the second type is the type corresponding to the second extension field of the NTP request message of the client, and the NTP data packet includes an NTP response message and an NTP request message.
[0190] For details not described, reference may be made to the above method embodiments.
[0191] It should be understood that the specific processes of each unit executing the above corresponding steps have been described in detail in the above method embodiments. For the sake of brevity, they will not be repeated here.
[0192] In the above embodiments, the processing unit 1120 may be implemented by at least one processor or processor-related circuit. The transceiver unit 1110 may be implemented by a transceiver or transceiver-related circuit. The storage unit may be implemented by at least one memory.
[0193] Figure 12 is a schematic structural diagram of a data detection device provided by an embodiment of the present application.
[0194] As Figure 12 shown, an embodiment of the present application further provides a data detection device. The device includes a processor 1210, the processor 1210 is coupled to a memory 1220, the memory 1220 is used to store computer programs or instructions and / or data, and the processor 1210 is used to execute the computer programs or instructions and / or data stored in the memory 1220, so that the method in the above method embodiments is executed.
[0195] Optionally, the processor 1210 included in the device is one or more.
[0196] Optionally, as Figure 12 shown, the device may further include a memory 1220.
[0197] Optionally, the memory 1220 included in the device may be one or more.
[0198] Optionally, the memory 1220 can be integrated with the processor 1210 or separately provided.
[0199] Optionally, as Figure 12 shown, the device may further include a transceiver 1230 for receiving and / or transmitting signals. For example, the processor 1210 is used to control the transceiver 1230 to receive and / or transmit signals.
[0200] As a solution, the device is used to implement the method embodiments described above.
[0201] For example, the processor 1210 is used to implement the operations related to processing in the method embodiments described above, and the transceiver 1230 is used to implement the operations related to receiving and transmitting in the method embodiments described above.
[0202] Figure 13 is a schematic diagram of a chip system provided by an embodiment of the present application, as Figure 13 shown. The chip system (or can also be referred to as a processing system) includes a logic circuit 1310 and an input / output interface 1320. The logic circuit is used to be coupled to the input interface and transmit data parameters through the input / output interface to execute the methods in the method embodiments described above. The device installed with this chip system can implement the methods and functions of the embodiments of the present application. For example, the logic circuit 1310 can be the processing circuit in the chip system to implement the control of the device installed with this chip system, and can also be coupled to a storage unit to call the instructions in the storage unit, so that the device can implement the methods and functions of the embodiments of the present application. The input / output interface 1320 can be the input / output circuit in the chip system to output the information processed by the chip system or input the data or signaling information to be processed into the chip system for processing.
[0203] As a solution, the chip system is used to implement the operations performed by the data detection device in the method embodiments described above.
[0204] For example, the logic circuit 1310 is used to implement the operations related to processing in the method embodiments described above, and the input / output interface 1320 is used to implement the operations related to receiving and transmitting in the method embodiments described above.
[0205] The embodiments of the present application further provide a computer-readable storage medium, on which computer instructions for implementing the methods performed by the data detection device in the above method embodiments are stored.
[0206] For example, when the computer program is executed by a computer, the computer can implement the methods performed by the data detection device in the above method embodiments.
[0207] The embodiments of the present application further provide a computer program product including instructions, which, when executed by a computer, cause the computer to implement the method executed by the data detection device in the above method embodiments.
[0208] The embodiments of the present application further provide a vehicle, which may include the above data detection device 1100 or data detection device 1200.
[0209] Optionally, the vehicle may be a car.
[0210] For the explanations and beneficial effects of the relevant content in any of the above provided devices, reference may be made to the corresponding method embodiments provided above, and details are not described herein again.
[0211] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor, or the processor may also be any conventional processor, etc.
[0212] It should also be understood that the memory mentioned in the embodiments of the present application can be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM). For example, the RAM can be used as an external cache. By way of example and not limitation, the RAM can include the following various forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0213] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated in the processor.
[0214] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0215] Those of ordinary skill in the art can realize that the units and steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the protection scope of the present application.
[0216] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0217] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to implement the solution provided in the present application.
[0218] In addition, each functional unit in various embodiments of the present application can be integrated into one unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0219] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD), etc.). For example, the foregoing available media can include, but are not limited to: USB flash drive, removable hard disk, read-only memory ROM, random access memory RAM, magnetic disk, or optical disc and other media that can store program code.
[0220] As described above, the foregoing are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A data detection method, characterized in that, it includes: Obtain a Network Time Protocol (NTP) data packet; Determine whether there is information about an NTP covert channel in the NTP data packet according to the Domain Name System (DNS) data associated with the NTP data packet.
2. The method according to claim 1, characterized in that, the determining whether there is information about an NTP covert channel in the NTP data packet according to the DNS data associated with the NTP data packet includes: When the DNS data is not searched, determine that there is information about the NTP covert channel in the NTP data packet.
3. The method according to claim 1, characterized in that, the determining whether there is information about an NTP covert channel in the NTP data packet according to the DNS data associated with the NTP data packet includes: When the DNS data is searched, determine whether there is information about the NTP covert channel in the NTP data packet according to the first Internet Protocol (IP) address and the second IP address included in the DNS data; wherein, the first IP address is the IP address corresponding to the NTP data packet.
4. The method according to claim 3, characterized in that, the second IP address includes multiple IP addresses, and the determining whether there is information about the NTP covert channel in the NTP data packet according to the first IP address and the second IP address included in the DNS data includes: When the first IP address is not included in the multiple IP addresses, determine that there is information about the NTP covert channel in the NTP data packet.
5. The method according to claim 3, characterized in that, the detecting whether there is an NTP covert channel in the NTP data packet according to the DNS data associated with the NTP data packet includes: When the DNS data is searched and the first IP address is included in the multiple IP addresses, parse the NTP data packet to obtain a first timestamp and a second timestamp, where the first timestamp is the server system time when the server receives the NTP request message, the second timestamp is the server system time when the server sends the NTP response message, and the NTP data packet includes the NTP request message and the NTP response message; Determine whether there is information about the NTP covert channel in the NTP data packet according to the first timestamp and the second timestamp.
6. The method according to claim 5, characterized in that, the detecting whether there is information about the NTP covert channel in the NTP data packet according to the first timestamp and the second timestamp includes: When the first timestamp is later than the second timestamp, determine that there is information about the NTP covert channel in the NTP data packet; and / or, When the interval duration between the first timestamp and the second timestamp is greater than or equal to a preset duration, determine that there is information about the NTP covert channel in the NTP data packet.
7. The method according to claim 5, characterized in that, Determining whether the NTP data packet contains information about the NTP covert channel based on the first timestamp and the second timestamp includes: When the first timestamp and the second timestamp meet a preset condition, determining whether the NTP data packet contains information about the NTP covert channel according to a first type and a second type; wherein, the first type is the type corresponding to a first extension field of an NTP response message of a server, the second type is the type corresponding to a second extension field of an NTP request message of a client, and the NTP data packet includes the NTP response message and the NTP request message.
8. The method according to claim 7, wherein, Determining whether the NTP data packet contains information about the NTP covert channel according to whether the first type and the second type match includes: When the first type and the second type do not match, determining that the NTP data packet contains information about the NTP covert channel.
9. The method according to claim 7, wherein, Determining whether the NTP data packet contains information about the NTP covert channel according to whether the first type and the second type match includes: When the first type and the second type match, determining whether the NTP data packet contains information about the NTP covert channel according to an abnormal condition of a first payload format and / or a second payload format; wherein, the first payload format is the payload format corresponding to the first extension field, and the second payload format is the payload format corresponding to the second extension field.
10. A data detection device, wherein, It includes a transceiver unit and a processing unit: The transceiver unit is configured to obtain a Network Time Protocol (NTP) data packet; The processing unit is configured to determine whether the NTP data packet contains information about an NTP covert channel according to Domain Name System (DNS) data associated with the NTP data packet.
11. The device according to claim 10, wherein, The processing unit is specifically configured to, When the DNS data is not searched, determine that the NTP data packet contains information about the NTP covert channel.
12. The device according to claim 10, wherein, The processing unit is specifically configured to, When the DNS data is searched, determine whether the NTP data packet contains information about the NTP covert channel according to a first Internet Protocol (IP) address and a second IP address included in the DNS data; wherein, the first IP address is the IP address corresponding to the NTP data packet.
13. The device according to claim 12, wherein, The second IP address includes multiple IP addresses, and the processing unit is specifically configured to, When the multiple IP addresses do not include the first IP address, determine that the NTP data packet contains information about the NTP covert channel.
14. The device according to claim 12, wherein, The processing unit is specifically configured to, When the DNS data is searched and the multiple IP addresses include the first IP address, the NTP packet is parsed to obtain a first timestamp and a second timestamp. The first timestamp is the server system time when the server receives the NTP request message, and the second timestamp is the server system time when the server sends the NTP response message. The NTP packet includes the NTP request message and the NTP response message. Based on the first timestamp and the second timestamp, it is determined whether the NTP packet contains information about the NTP covert channel.
15. The apparatus according to claim 14, wherein, the processing unit is specifically configured to, if the first timestamp is later than the second timestamp, determine that the NTP packet contains information about the NTP covert channel; and / or, if the time interval between the first timestamp and the second timestamp is greater than or equal to a preset time length, determine that the NTP packet contains information about the NTP covert channel.
16. The apparatus according to claim 14, wherein, the processing unit is specifically configured to, when the first timestamp and the second timestamp meet a preset condition, determine whether the NTP packet contains information about the NTP covert channel according to a first type and a second type; wherein, the first type is the type corresponding to the first extension field of the NTP response message of the server, and the second type is the type corresponding to the second extension field of the NTP request message of the client. The NTP packet includes the NTP response message and the NTP request message.
17. The apparatus according to claim 16, wherein, the processing unit is specifically configured to, when the first type and the second type do not match, determine that the NTP packet contains information about the NTP covert channel.
18. The apparatus according to claim 16, wherein, the processing unit is specifically configured to, when the first type and the second type match, determine whether the NTP packet contains the NTP covert channel according to the abnormal situation of the first payload format and / or the second payload format; wherein, the first payload format is the payload format corresponding to the first extension field, and the second payload format is the payload format corresponding to the second extension field.
19. A data detection apparatus, wherein, it includes a processor, the processor is coupled with a memory, the memory is used to store a computer program or instruction, and the processor is used to execute the computer program or instruction in the memory, so that the apparatus executes the method according to any one of claims 1 to 9.
20. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program or instruction. When the computer program or instruction runs on a computer, the computer is made to execute the method according to any one of claims 1 to 9.
21. A vehicle, wherein, Comprising the data detection device according to any one of claims 10 to 18.
22. A chip, characterized in that the chip is coupled to a memory and is configured to read and execute program instructions stored in the memory to implement the method according to any one of claims 1 to 9.