A Security Shell Protocol Traffic Detection Method and Device for Complex Bearings Inside Tunnels

By performing feature extraction and frequency domain characterization of tunnel mixed traffic, combined with recurrent neural network and multi-head attention mechanism, effective detection and positioning of SSH traffic in tunnels is achieved, solving the problem of difficulty in identifying SSH traffic in mixed traffic in the prior art, and improving the sensitivity and specificity of detection.

CN120090887BActive Publication Date: 2025-06-24NANJING UNIV OF INFORMATION SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510580678.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-06-24
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify and analyze SSH traffic in mixed traffic in tunnels, especially when encryption and packaging characteristics make traditional traffic analysis methods poor.

Method used

A secure shell protocol traffic detection method for complex bearings in the tunnel is adopted. By collecting the tunnel mixed traffic, extracting the length, arrival time interval and direction characteristics of the data packet, constructing burst sequences, performing frequency domain characterization, and calculating statistical features. The encoder and decoder architecture based on recurrent neural networks are used to detect and locate SSH traffic in combination with the multi-head attention mechanism.

Benefits of technology

It significantly improves the detection sensitivity and specificity in a mixed flow environment, can more effectively deal with the identification challenges caused by the coexistence of complex behaviors in the tunnel, and improves the refined recognition ability of SSH traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090887B_ABST
    Figure CN120090887B_ABST
Patent Text Reader

Abstract

The present invention provides a method and device for detecting Secure Shell (SSH) traffic in a tunnel with complex bearers. The method includes: Step 1, collecting tunnel mixed traffic and extracting three features of the packet length, arrival time interval, and direction of a specified number of packets in each flow; Step 2, constructing packets with the same direction and consecutive ones into the same burst and building a burst feature sequence; Step 3, mapping each packet in the burst to a frequency domain signal to obtain a mixed frequency domain signal of the burst traffic in the frequency domain representation; Step 4, obtaining the statistical features of the mixed frequency domain signal; Step 5, inputting the statistical features of the mixed frequency domain signal into an encoder-decoder architecture based on a recurrent neural network to obtain a prediction label at the burst level and a prediction label at the flow level, and determining whether there is SSH traffic in the mixed traffic and locating the burst where it is located. This method effectively solves the problem of SSH traffic detection under complex bearers in the tunnel and significantly improves the detection accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent network traffic analysis, and specifically relates to a method and device for detecting Secure Shell (SSH) protocol traffic with complex bearers in a tunnel. Background Art

[0002] With the continuous development of tunneling technology, it has become a widely used method for encapsulating protocol data packets in a network. Tunneling technology not only provides privacy protection and secure communication for data transmission but also plays an important role in aspects such as remote access and cross-region network connection. By encapsulating the data of one protocol into another protocol, it can achieve protocol compatibility and bypass network restrictions. However, with the wide application of tunneling technology, it also brings some new challenges, especially in the monitoring and management of network traffic. Tunneling technologies such as Shadowsocks, Vmess, and Trojan combine encryption and encapsulation mechanisms, further enhancing the security of data transmission, but this also makes malicious activities and evasion of censorship more complex, posing great difficulties for network management.

[0003] Currently, research on encrypted tunnel traffic mainly focuses on the identification and classification of tunnel protocols, malicious traffic detection, and mixed traffic analysis. Tunnel traffic usually has encryption characteristics, which greatly reduces the effectiveness of traditional traffic identification methods based on ports and protocols. In addition, tunnel traffic often disguises itself as normal traffic (such as HTTPS or DNS), making traffic analysis and identification more difficult. Existing research mostly uses machine learning (ML) or deep learning (DL) methods, relying on the metadata of network traffic to identify and classify traffic in encrypted tunnels without decrypting the data. At the same time, with the diversification of web applications, the normalization patterns of traffic become more complex, increasing the difficulty of distinguishing malicious traffic from normal traffic.

[0004] Mixed traffic analysis assumes that multiple types of traffic are transmitted in a tunnel, and this complex scenario is more realistic. It includes the identification and classification of various network behaviors. Past research has conducted relevant analyses on mixed tunnel traffic, such as calculating the quantity and proportion of encrypted traffic in a tunnel. In this process, monitoring sensitive traffic is particularly crucial, especially when the tunnel involves multiple network behaviors. Remote management tools such as the SSH protocol are often exploited by attackers to hide malicious behaviors in mixed traffic. Once an attacker obtains remote control through SSH, they can initiate various attacks and steal data or implant malicious programs. In this regard, traffic detection methods based on a single behavior often struggle to effectively respond, and methods capable of identifying mixed tunnel traffic are needed.

[0005] Currently, research on mixed traffic within tunnels is still relatively limited. The tunnel encapsulation characteristics make it difficult to separate traffic between multiple network behaviors coexisting in the tunnel, which makes it more complicated to analyze data packets of sensitive behaviors. Traditional traffic analysis methods do not work well for encrypted and encapsulated tunnels because they mask key business identifiers and payload structures. As network behaviors become more complex, sensitive traffic and normal traffic are completely mixed together, increasing the difficulty of detection. Therefore, detailed analysis and identification technology for mixed traffic within tunnels remains an important issue that needs to be solved in the field of network security. Summary of the invention

[0006] Purpose of the invention: The technical problem to be solved by the present invention is to provide a method and device for detecting Secure Shell (SSH) traffic for complex bearers in a tunnel in view of the deficiencies in the prior art.

[0007] The method comprises the following steps:

[0008] Step 1: Collect the mixed traffic in the tunnel, extract the three features of packet length, arrival time interval and direction of the specified number of packets in each flow, normalize the length of the packet, normalize the arrival time interval of the packet and smooth the feature distribution;

[0009] Step 2: Constructing continuous data packets with the same direction into the same burst to obtain a burst sequence of tunnel mixed traffic. For the burst sequence, the burst is divided into a forward burst and a reverse burst according to different directions of the data. The data packets from the source address to the destination address are regarded as forward burst data packets, and the data packets from the destination address to the source address are regarded as reverse burst data packets. At the same time, a burst feature sequence is constructed according to the data packet length and arrival time interval of the forward and reverse burst data packets.

[0010] Step 3: Based on the burst feature sequence obtained in step 2, a frequency-domain-based mixed traffic representation is introduced to map each data packet in the burst into a frequency-domain signal, and the frequency-domain signals of the data packets in the same burst are linearly added to obtain a mixed frequency-domain signal of the burst traffic in the frequency-domain representation. Each mixed frequency-domain signal represents a forward or reverse burst in the tunnel mixed traffic.

[0011] Step 4: Time-sample the mixed frequency domain signal obtained in step 3 to obtain the frequency domain discrete features of burst traffic. The four core statistical features of the discrete features are calculated. , get the mixed frequency domain signal statistical characteristics of each burst ,in represents the mean, represents the variance, represents peak value, and E represents energy;

[0012] Step 5: Input the statistical features of the mixed frequency-domain signal obtained in Step 4 into an encoder-decoder architecture based on a recurrent neural network. The architecture uses a Gated Recurrent Unit (GRU) as the basic unit of the encoder and decoder. Obtain the prediction label at the burst level according to the output of the decoder to locate the burst position where the SSH traffic is located. Further, splice the output features of each GRU in the decoder, and input the spliced feature vector into a detection module based on a multi-head attention mechanism to obtain the prediction label at the flow level to determine whether there is SSH traffic in the mixed traffic.

[0013] In Step 1, the following formula is used to normalize the packet time interval and the packet length to normalize and smooth the feature distribution:

[0014] ,

[0015] ,

[0016] ,

[0017] where represents the normalized packet length, represents the maximum packet length, represents the normalized packet time interval, represents the packet time interval, represents the minimum time interval, represents the packet time interval after smooth distribution, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

[0018] In Step 2, the burst consists of a group of consecutive packets in the same direction. The packets come from requests or responses in the mixed flow, and the direction of the packet is determined by the destination address and the source address. Among them, the forward burst is represented as:

[0019] ,

[0020] The reverse burst is represented as:

[0021] ,

[0022] where represents the forward burst, represents the reverse burst, represents the th forward burst packet from the source address to the destination address in the mixed traffic, represents the nth forward burst packet from the source address to the destination address in the mixed traffic, where n is a positive integer; represents the mth reverse burst packet from the destination address to the source address in the mixed traffic, represents the kth reverse burst packet from the destination address to the source address in the mixed traffic, where k is a positive integer; represents the number of packets in the burst.

[0023] In step 3, the frequency-domain-based mixed traffic characterization includes the following steps:

[0024] Step 3-1: Map the packet length to the amplitude of the frequency-domain signal , and use the reciprocal of the packet time interval as the angular frequency of the mapped frequency-domain signal .

[0025] Step 3-2: If the burst is a forward burst , map the packet to the frequency signal , where t represents the time variable of the signal; if the burst is a reverse burst , map the packet to the frequency signal . represents the time variable of the signal;

[0026] Step 3-3: Repeat steps 3-1 to 3-2 to map all packets in the burst to frequency signals , and superimpose the mapped frequency signals of all packets in the same burst to obtain the final mixed frequency-domain signal .

[0027] In step 4, the time sampling of the mixed frequency-domain signal obtained in step 3 means sampling within the maximum period range of the mixed frequency-domain signal at N points, where N is the number of sampling points, and is the discrete signal value at the nth sampling point after sampling, obtaining the signal sequence . is the number of sampling points, is the nth discrete signal value at the sampling point;

[0028] According to the sampled signal sequence, calculate the mean , variance , peak , and energy of the signal , which are four core statistical features.

[0029] In step 5, the encoder-decoder architecture based on the recurrent neural network uses the gated recurrent unit (GRU) as the basic unit to capture sudden short-term temporal dependencies. The encoder passes the cumulative information of the hybrid flow to the decoder through the forward and backward hidden states;

[0030] The state update process of the gated recurrent unit (GRU) is expressed as:

[0031] ,

[0032] where, represents the updated hidden state at time step i; represents the hidden state of the previous time step; represents the current burst, and the function represents the gating strategy adopted by the gated recurrent unit (GRU).

[0033] In step 5, the prediction label at the burst level is obtained by processing the output of the decoder through the sigmoid activation function;

[0034] The prediction label at the flow level is obtained through the following steps: First, the outputs of the decoder for all bursts are concatenated to obtain a feature vector (the decoder is constructed by GRU, and its input comes from the output of the encoder. The main role of the encoder is to extract the deep feature representation of the input sequence. The encoder reads each element of the input sequence step by step and can output a context information representing the entire input sequence. The role of the decoder is to gradually generate the output sequence based on the context representation generated by the encoder. At each time step, the decoder receives the output of the previous moment and the current hidden state and predicts the output value at the current step), and then the feature vector is processed by the detection module based on the multi-head attention mechanism to obtain the flow feature vector. Finally, the flow feature vector passes through the sigmoid activation function to obtain the prediction label at the flow level.

[0035] In step 5, the encoder-decoder architecture based on the recurrent neural network can analyze tunnel traffic at the burst level and the flow level. The burst-level loss aims to improve the sensitivity of the model in detecting SSH traffic at the burst level, while the flow-level loss improves the specificity of the model in detecting SSH traffic at the flow level. The weighted binary cross-entropy loss at the burst level is:

[0036] ,

[0037] where is the weighted binary cross-entropy loss at the burst level; is the prediction label at the burst level; is the true label at the burst level; is the number of packets in the burst; is the true label of the burst level of the i-th data packet; is the predicted label of the burst level of the i-th data packet; is the weight matrix of burst loss, which increases the loss weight of bursts containing SSH traffic to address the problem of data imbalance, and its value is set to the number of SSH data packets in the burst;

[0038] The binary cross-entropy loss at the flow level is:

[0039] ,

[0040] where is the binary cross-entropy loss at the flow level; is the predicted label at the flow level; is the true label at the flow level;

[0041] A multi-scale supervised training model is adopted to obtain the final combined loss based on the burst-level and flow-level losses :

[0042] ,

[0043] where is a hyperparameter that balances the flow loss and burst loss. By adjusting , the model can be adjusted to pay more attention to the flow-level loss.

[0044] The present invention also provides a Secure Shell protocol traffic detection device for complex bearers inside tunnels implemented by the described method, including: a burst packet module for performing burst packetization on data packets; a feature extraction module for extracting the spatio-temporal features of data packets and performing preprocessing; a frequency-domain mapping module for mapping the spatio-temporal features of data packets into frequency-domain signals and characterizing burst traffic; a sampling module for sampling the frequency-domain features to obtain four statistical features of the signal, namely mean, variance, peak value, and energy; a detection module based on the encoder-decoder architecture of a recurrent neural network for determining whether there is SSH traffic in the tunnel hybrid traffic and locating the burst where it is located.

[0045] The present invention also provides a storage medium storing a computer program or instruction, which, when the computer program or instruction runs on a computer, executes the steps of the described method.

[0046] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) Aiming at the difficulty of behavior recognition caused by the coexistence of multiple network behaviors in the mixed tunnel traffic, the present invention proposes a novel SSH behavior detection method. This method integrates the feature information at the flow level and the burst level, and through the introduction of a multi-scale supervision strategy, realizes the joint optimization of the flow level and the burst level during the model training process, significantly improving the detection sensitivity and specificity in the mixed traffic environment, so as to more effectively cope with the recognition challenges caused by the coexistence of complex behaviors in the tunnel.

[0047] (2) To effectively capture the temporal patterns and burst structures in the mixed tunnel traffic, the present invention transforms and extracts features from the original traffic from the frequency domain perspective, and constructs a burst-level traffic characterization method with a unified structure. This frequency domain representation method can not only accurately reflect the periodic and burst behavior characteristics hidden in the traffic, but also has the ability to uniformly model bursts of different lengths. While reducing the feature dimension and the complexity of the traffic pattern, it retains important semantic information and physical interpretability, providing a more expressive feature basis for the refined recognition of SSH behaviors. Brief Description of the Drawings

[0048] Figure 1 It is the overall flowchart of an SSH traffic detection method for complex bearers in a tunnel.

[0049] Figure 2 It is a schematic diagram of packet grouping in a tunnel.

[0050] Figure 3 It is a schematic diagram of the original spatio-temporal features and preprocessed spatio-temporal features of a burst.

[0051] Figure 4 It is the structural diagram of the tunnel SSH traffic detection model. Detailed Embodiment

[0052] The following further specific descriptions of the present invention are made in conjunction with the drawings and specific embodiments, and the above and / or other advantages of the present invention will become clearer.

[0053] Facing the complex network behaviors carried in the tunnel, detecting sensitive behaviors in the tunnel mixed traffic. The sensitive traffic and the normal traffic are completely mixed together, increasing the difficulty of detection. Therefore, the embodiment of the present invention provides a secure shell protocol traffic detection method for complex bearers in a tunnel, referring to Figure 1 , and specifically includes the following steps:

[0054] Step 1, the present invention first collects the tunnel mixed traffic, extracts three features of the packet length, arrival time interval, and direction of a specified number of packets in each flow, normalizes the packet length, and normalizes and smooths the feature distribution of the packet arrival time interval. The specific processing methods are as follows: By dividing each packet length by the maximum packet length to obtain the normalized packet length , by using a conversion function to normalize the packet time interval to obtain the normalized packet time interval , and by performing a smooth distribution process on to obtain the smoothed packet time interval feature . The specific formulas for the normalization and feature distribution smoothing operations are as follows:

[0055] ,

[0056] ,

[0057] ,

[0058] where represents the normalized packet length, represents the packet length, represents the maximum packet length, represents the normalized packet time interval, represents the packet time interval, represents the minimum time interval, represents the smoothed packet time interval, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

[0059] Step 2, referring to Figure 2 , divide the packet direction according to the source address and destination address of the packet. If the source address and destination address of the packet are from the user side to the server side, it is divided into the forward direction; if the source address and destination address of the packet are from the server side to the user side, it is divided into the reverse direction. Secondly, then divide the packets with the same direction and continuity in the tunnel flow into the same burst according to the continuity of the packets.

[0060] Referring to Figure 3 , after all the packets are divided into bursts, obtain the burst feature sequence according to the packet length and arrival time interval of the packets in each burst.

[0061] Step 3, Based on the frequency-domain hybrid traffic characterization method, each data packet in a burst is mapped to a frequency-domain signal according to the burst feature sequence, and the signals mapped by the data packets in the same burst are linearly added in the frequency-domain space to obtain the hybrid frequency-domain signal of the burst traffic in the frequency-domain characterization. The specific implementation steps are as follows:

[0062] Step 3-1, Map the length of the preprocessed data packet to the amplitude A of the signal, and take the reciprocal of the time interval of the preprocessed data packet as the angular frequency of the mapped signal ;

[0063] Step 3-2, Map the data packet to a frequency-domain signal according to the data packet direction. If the burst is a forward burst , then map the data packet to . If the burst is a reverse burst , then map the data packet to ;

[0064] Step 3-3, Repeat the above steps 3-1 and 3-2 to map all the data packets in the burst to , and superimpose the mapped signals of all the data packets in the same burst to obtain the hybrid frequency-domain signal .

[0065] Step 4, In order to analyze the burst signal, it is necessary to sample it first. The sampling process is carried out within the maximum period range of the signal. The selection of the number of sampling points N takes into account both the periodicity of the signal and the computational requirements of the data. The purpose of sampling is to discretize the continuous frequency-domain signal into a finite number of sample points for subsequent calculations. Specifically, within the range of [0, 2 , perform N-point sampling on the burst hybrid frequency-domain signal . The sampled signal sequence is . Further calculate the mean , variance , peak value , and energy of the signal based on the sampled signal sequence, and further obtain the statistical characteristics of the hybrid frequency-domain signal of each burst

[0066] Step 5: Input the statistical features of the mixed frequency-domain signal into the encoder-decoder architecture based on a recurrent neural network. Obtain the prediction labels at the burst level according to the decoder output. Concatenate the decoder output and send it into the detection module based on the attention mechanism to get the prediction labels at the flow level. Calculate the binary cross-entropy loss based on the two-level prediction labels, and locate the burst where the SSH traffic is located and determine whether there is SSH traffic in the tunnel mixed traffic according to the binary cross-entropy loss.

[0067] In this method, both the encoder and the decoder consist of four hidden layers, and the size of each hidden layer is set to 128. The encoder is responsible for receiving the frequency-domain statistical features of the burst traffic and converting them into a context vector (hidden state), which contains the key information about the input traffic. The decoder receives the hidden state of the encoder and uses the forward and backward hidden states to pass the cumulative information of the mixed flow to the output layer of the model.

[0068] Refer to Figure 4 , after the statistical features of the mixed frequency-domain signal are fed into the encoder-decoder, the decoder output of each burst is obtained. The decoder output is processed by an activation function to get the prediction labels at the burst level, which are used to locate the burst position where the SSH traffic is located. At the same time, the decoder outputs are concatenated to obtain a feature vector, and then the feature vector is processed by the attention module to get the flow feature vector. Finally, the flow feature vector passes through an activation function to get the prediction labels at the flow level, which are used to judge whether there is SSH traffic in the mixed traffic.

[0069] Analyze the tunnel traffic at the burst level and the flow level respectively according to the prediction labels. The burst-level loss aims to improve the sensitivity of the model to detect SSH traffic at the burst level, while the flow-level loss improves the specificity of the model to detect SSH traffic at the flow level. The specific formulas are as follows:

[0070] Weighted binary cross-entropy loss at the burst level:

[0071] ,

[0072] where is the weighted binary cross-entropy loss at the burst level; is the prediction label at the burst level; is the true label at the burst level; k is the number of data packets in the burst; is the weight matrix for the SSH burst loss, which increases the loss weight of the burst containing SSH traffic to solve the problem of data imbalance, and its value is set to the number of SSH data packets in the burst;

[0073] Binary cross-entropy loss at the flow level:

[0074] ,

[0075] where is the binary cross - entropy loss at the flow level; is the predicted label at the flow level; is the true label at the flow level.

[0076] A multi - scale supervised training model is adopted to obtain the final combined loss based on the burst - level and flow - level losses , and the specific calculation formula is as follows:

[0077] ,

[0078] where is a hyperparameter that balances the flow loss and the burst loss. By adjusting , the model can be adjusted to pay more attention to the flow - level loss.

[0079] A specific embodiment of the method of the present invention in the context of a tunnel mixed - traffic environment is as follows: Figure 2 The medium - tunnel mixed flow contains data packets. Packets and packet are continuous in time and both in the forward direction and are divided into a forward burst . Packet is divided into a negative burst because there are no packets with the same direction and continuous . Packets , , are divided into a forward burst . By analogy until the nth data packet, the mixed traffic is finally divided into a sequence of alternating forward and negative bursts. The traditional method fails to fully focus on the specific network behavior patterns contained in the traffic, while the burst - division strategy of the present invention significantly enhances the ability to capture the behavioral characteristics of encrypted protocols by simulating the SSH protocol request - response interaction pattern (e.g., forward bursts are client requests and reverse bursts are server responses).

[0080] Furthermore, the spatio - temporal features in the N bursts are extracted and the normalization and optimization distribution method described in step 2 is performed on the spatio - temporal features of the bursts, obtaining the normalized length and optimized interval as shown in Figure 3 . The prior art directly uses the original distribution of packet time intervals (which is vulnerable to network jitter interference), while the present invention optimizes the packet time - interval distribution through non - linear transformation (such as the combination of tanh and sigmoid functions), highlighting the subtle features of packets, improving the feature stability under the same network - delay fluctuations, and effectively suppressing the influence of noise.

[0081] Execute the frequency characterization method in step 3 according to the normalized length and the smoothed packet time interval. Burst 1 is characterized as , burst 2 is characterized as , burst 3 is characterized as . By mapping the spatio-temporal features of the packets into frequency-domain signals (forward bursts are modeled based on sine signals, and reverse bursts are modeled based on cosine signals), the present invention breaks through the limitation of traditional methods that rely on plaintext content or simple statistics. Even when the SSH traffic is encrypted or nested in tunnels, the network behavior interaction features can still be extracted through waveform superposition (such as the mixture of multi-frequency signals in burst 3). Then, within the range of [0, 2 , sample the burst frequency-domain signal at 500 points to obtain the sampling sequence of each burst, and at the same time obtain the burst statistical features according to the formula described in step 4. Traditional deep learning models need to process high-dimensional raw data (such as packet sequences), while the present invention reduces the dimension through frequency-domain sampling, with a lower computational complexity compared to traditional methods and a significantly improved inference speed in devices. Further, according to the steps described in step 5, send the burst statistical features into the encoder and decoder to obtain the decoder output of each burst, obtain the burst-level and flow-level prediction labels through two processing methods, and still obtain the final combined loss according to the calculation formula in step 5. The prior art only supports flow-level detection and cannot locate the specific location of SSH traffic, while the GRU-attention architecture of the present invention can not only mark bursts but also comprehensively judge the flow-level risk, meeting the requirements of precise control and efficient detection at the same time.

[0082] The present invention provides a method and device for detecting Secure Shell protocol traffic for complex bearers within tunnels. There are many methods and ways to specifically implement this technical solution. The above description is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Each component not clearly defined in this embodiment can be implemented using the prior art.

Claims

1. A secure shell protocol traffic detection method for complex bearers in tunnels, characterized in that: The following steps are involved: Step 1: Collect the mixed traffic in the tunnel, extract the three features of packet length, arrival time interval and direction of the specified number of packets in each flow, normalize the length of the packet, normalize the arrival time interval of the packet and smooth the feature distribution; Step 2: Constructing continuous data packets with the same direction into the same burst to obtain a burst sequence of tunnel mixed traffic. For the burst sequence, the burst is divided into a forward burst and a reverse burst according to different directions of the data. The data packets from the source address to the destination address are regarded as forward burst data packets, and the data packets from the destination address to the source address are regarded as reverse burst data packets. At the same time, a burst feature sequence is constructed according to the data packet length and arrival time interval of the forward and reverse burst data packets. Step 3: Based on the burst feature sequence obtained in step 2, a frequency-domain-based mixed traffic representation is introduced to map each data packet in the burst into a frequency-domain signal, and the frequency-domain signals of the data packets in the same burst are linearly added to obtain a mixed frequency-domain signal of the burst traffic in the frequency-domain representation. Each mixed frequency-domain signal represents a forward or reverse burst in the tunnel mixed traffic. Step 4: Perform time sampling on the mixed frequency domain signal obtained in step 3 to obtain the frequency domain discrete features of burst traffic. The four core statistical features of the discrete features are calculated. , get the mixed frequency domain signal statistical characteristics of each burst ,in represents the mean, represents the variance, represents the peak value, Indicates energy; Step 5, inputting the mixed frequency domain signal statistical features obtained in step 4 into the encoder and decoder architecture based on the recurrent neural network, wherein the architecture uses the gated recurrent unit GRU as the basic unit of the encoder and decoder; obtaining a burst-level prediction label according to the output of the decoder, which is used to locate the burst position of the SSH traffic; further splicing the output features of each gated recurrent unit GRU in the decoder, and inputting the spliced ​​feature vector into the detection module based on the multi-head attention mechanism to obtain a flow-level prediction label, which is used to determine whether there is SSH traffic in the mixed traffic.

2. The method according to claim 1, characterized in that In step 1, the following formula is used to calculate the packet time interval and packet length Normalize and smooth feature distribution: , , , in Indicates the normalized packet length, Indicates the maximum packet length, represents the normalized packet time interval, Indicates the packet time interval, Indicates the minimum time interval, Indicates the time interval between packets after smooth distribution, tanh is the hyperbolic tangent function, arctanh is the inverse hyperbolic tangent function, and sigmoid is the activation function.

3. The method according to claim 2, characterized in that In step 2, the burst consists of a group of continuous data packets in the same direction, the data packets come from requests or responses in the mixed flow, and the direction of the data packets is determined by the destination address and the source address, wherein the forward burst is represented as: , The reverse burst is expressed as: , in Indicates a positive burst, Indicates reverse burst, Indicates the mixed traffic from the source address to the destination address. Forward burst packets, Indicates the mixed traffic from the source address to the destination address. Forward burst packets, Indicates the mth reverse burst packet from the destination address to the source address in the mixed traffic. Indicates the mixed traffic from the destination address to the source address. Reverse burst packets, Indicates the number of packets in the burst.

4. The method according to claim 3, characterized in that In step 3, the frequency domain-based mixed traffic characterization includes the following steps: Step 3-1, set the packet length Mapped to the amplitude of the frequency domain signal , the inverse of the packet time interval As the angular frequency of the mapped frequency domain signal ; Step 3-2, if the burst is a forward burst , then the data packet is mapped into a frequency signal , if the burst is a reverse burst , then the data packet is mapped into a frequency signal , A time variable representing a signal; Step 3-3, repeat steps 3-1 to 3-2 to map all packets in the burst into frequency signals , the frequency signal of all packets in the same burst is mapped Superposition is performed to obtain the final mixed frequency domain signal .

5. The method according to claim 4, characterized in that In step 4, the time sampling of the mixed frequency domain signal obtained in step 3 refers to the time sampling of the mixed frequency domain signal. Within the maximum cycle range of conduct Point sampling, after sampling, the signal sequence is obtained ],in is the number of sampling points, For the Discrete signal value at sampling points; According to the sampled signal sequence, calculate the signal The mean ,variance , Peak ,energy Four core statistical features.

6. The method according to claim 5, characterized in that In step 5, the encoder and decoder architecture based on the recurrent neural network uses the gated recurrent unit GRU as the basic unit to capture the bursty short-term temporal dependencies, and the encoder passes the accumulated information of the mixed stream to the decoder through the forward and backward hidden states; The state update process of the gated recurrent unit GRU is expressed as: , in, represents the updated hidden state at time step i, represents the hidden state at the previous time step, Indicates the current burst, function Represents the gating strategy adopted by the gated recurrent unit GRU.

7. The method according to claim 6, characterized in that In step 5, the prediction label of the burst level is obtained by processing the decoder output through the sigmoid activation function; The flow-level prediction label is obtained by the following steps: first, all burst decoder outputs are spliced ​​to obtain a feature vector, then the feature vector is processed by a detection module based on a multi-head attention mechanism to obtain a flow feature vector, and finally the flow feature vector is passed through a sigmoid activation function to obtain a flow-level prediction label.

8. The method according to claim 7, characterized in that In step 5, the encoder and decoder architecture based on the recurrent neural network can analyze the tunnel traffic at the burst level and the flow level, and the weighted binary cross entropy loss at the burst level is: , in is the weighted binary cross entropy loss at the burst level; is the prediction label at the burst level; is the true label at the burst level; is the number of packets in the burst; is the true label of the burst level of the i-th packet; is the predicted label of the burst level of the i-th packet; is the weight matrix of burst loss; The binary cross entropy loss at the flow level is: , in is the binary cross entropy loss at the flow level; is the predicted label at the flow level; is the true label at the flow level; A multi-scale supervised training model is used to obtain the final combined loss based on the burst level and flow level losses. : , in is a hyperparameter that balances flow loss and burst loss.

9. A secure shell protocol flow detection device for complex bearers in a tunnel implemented by the method according to any one of claims 1 to 8, characterized in that: include: A burst grouping module is used to group data packets into bursts; a feature extraction module is used to extract the spatiotemporal features of data packets and perform preprocessing; The frequency domain mapping module is used to map the spatiotemporal characteristics of the data packet into frequency domain signals and characterize the burst traffic; the sampling module is used to sample the frequency domain characteristics to obtain the four statistical characteristics of the signal: mean, variance, peak value and energy; The detection module, based on the encoder and decoder architecture of recurrent neural networks, is used to determine whether there is SSH traffic in the tunnel mixed traffic and locate the burst.

10. A storage medium, characterized in that: A computer program or instruction is stored, and when the computer program or instruction is run on a computer, the steps of the method according to any one of claims 1 to 8 are executed.

Citation Information

Patent Citations

  • Calculation method of automatic processing tool based on abnormal link identification

    CN119324880A

  • Malicious activity detection by cross-trace analysis and deep learning

    US20200076842A1