QUIC tunnel detection method and device based on behavior detection feature recognition
By obtaining basic information about network traffic in real time at the network entrance or exit, and based on the behavior detection feature recognition method, the problem of difficulty in detecting QUIC tunnel traffic in the existing technology is solved, and the accurate identification and confirmation of QUIC tunnel traffic is achieved, and network security is improved.
Patent Information
- Application Number
- CN202510162709.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-06
AI Technical Summary
The prior art is difficult to effectively identify and detect QUIC tunnel traffic, especially in complex network environments brought about by multiplexing and dynamic ports, making tunnel attacks difficult to detect and defend.
Using a method based on behavior detection feature recognition, the basic information of network traffic is obtained in real time at the network entrance or exit, and traffic behavior feature detection and scoring is performed based on this information, thereby identifying and confirming the QUIC tunnel. Specific steps include capturing network traffic, extracting basic information of QUIC data packets, detecting traffic characteristics and scoring, and comprehensively rating to confirm tunnel traffic.
It effectively improves the accuracy of detecting QUIC tunnel traffic, reduces false alarms, and can accurately identify tunnel attacks in complex network environments, enhancing network security.
Smart Images

Figure CN120110718A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a QUIC tunnel detection method and device based on behavior detection feature recognition. Background Art
[0002] The tunnel technology based on the QUIC protocol uses its strong encryption, UDP-based transmission, multiplexing and dynamic ports to bypass firewalls and traditional detection methods, disguised as legitimate Web traffic to achieve data exfiltration or hidden communication. Since QUIC encrypts the header and data by default, traditional detection technology based on plaintext traffic is difficult to effectively identify its communication content, which may make it abused as a tool to penetrate network restrictions or carry out malicious activities.
[0003] Tunnel attacks are attacks that hide the content of communications and bypass security mechanisms by encapsulating malicious traffic in legitimate protocols. Attackers usually use encryption and protocol encapsulation technologies (such as HTTP, HTTPS, DNS, QUIC, etc.) to disguise malicious traffic and make it look like normal communication, thereby bypassing the monitoring of firewalls and intrusion detection systems. Tunnel attacks further increase the difficulty of detection through means such as dynamic ports, randomized communication patterns, and multiplexing.
[0004] In view of this, the present invention is proposed. Summary of the invention
[0005] The main purpose of the present invention is to disclose a QUIC tunnel detection method and device based on behavior detection feature recognition, which is used to solve the problem of high-speed and highly concealed tunnel attacks caused by the complexity brought about by multiplexing and dynamic ports in the prior art.
[0006] To achieve the above objectives, according to one aspect of the present invention, a QUIC tunnel detection method based on behavior detection feature recognition is provided, and the following technical solutions are adopted:
[0007] The QUIC tunnel detection method based on behavior detection feature recognition includes: obtaining basic information of network traffic in real time at the network entrance or exit; detecting and scoring traffic behavior features based on the basic information; and identifying the traffic features based on the scores and confirming the QUIC tunnel.
[0008] Furthermore, the real-time acquisition of basic information of network traffic at the network inlet or outlet includes: deploying a traffic capture device at the network inlet or outlet, and capturing network traffic in real time through a packet capture tool; aggregating the captured network traffic by session to analyze traffic characteristics of different sessions; extracting basic information of each QUIC data packet, which basic information includes but is not limited to: QUIC packet type, frame type, and extension field.
[0009] Furthermore, the detection and scoring of traffic behavior characteristics based on basic information includes: for each captured QUIC data packet or session, scoring each feature based on different traffic characteristics, with the score ranging from 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest.
[0010] Furthermore, scoring each feature based on different traffic characteristics includes: detecting whether there is a 0-RTT data packet, and giving a corresponding score based on the detection situation; analyzing whether there is a small-flow heartbeat packet interaction in the traffic, and giving a corresponding score based on the number of small-flow packets; detecting whether the session contains a PING Frame, and giving a corresponding score based on the detection situation.
[0011] Furthermore, traffic characteristics are identified and the QUIC tunnel is confirmed based on the score, including: detecting the ALPN field and giving a score based on the scoring criteria; further analyzing and detecting the extended fields customized by the tunnel tool, and giving a score based on the scoring criteria.
[0012] Furthermore, identifying the traffic characteristics and confirming the QUIC tunnel based on the score also includes: setting weights and comprehensive scores, and confirming the corresponding tunnel traffic based on the total score: ALPN field: weight is 0.3, 0-RTT data packet: weight is 0.2, small traffic heartbeat packet: weight is 0.2, PING Frame detection: weight is 0.3; total score analysis: total score = Σ(feature score × weight), and the total score range is 0 to 1; the total score is greater than the first threshold, and it is judged as high-risk tunnel traffic; the total score is between the first threshold and the second threshold, and it is judged as medium-risk tunnel traffic; the total score is lower than the second threshold, and it is judged as low-risk tunnel traffic.
[0013] According to another aspect of the present invention, a QUIC tunnel detection device based on behavior detection feature recognition is provided, and the following technical solution is adopted:
[0014] A QUIC tunnel detection device based on behavior detection feature recognition includes: an acquisition module, which is used to obtain basic information of network traffic in real time at a network entrance or exit; a detection module, which is used to detect and score traffic behavior features based on the basic information; and a confirmation module, which is used to identify traffic features according to the scores and confirm the QUIC tunnel.
[0015] Furthermore, the acquisition module includes: a deployment module, which is used to deploy a traffic capture device at the network inlet or outlet, and capture network traffic in real time through a packet capture tool; an aggregation module, which is used to aggregate the captured network traffic by session so as to analyze the traffic characteristics of different sessions; an extraction module, which is used to extract basic information of each QUIC data packet, and the basic information includes but is not limited to: QUIC packet type, frame type and extension field.
[0016] Furthermore, the detection module includes: a scoring module for scoring each feature of each captured QUIC data packet or session based on different traffic characteristics, with the score ranging from 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest.
[0017] Furthermore, the scoring module includes: a first detection submodule, which is used to detect whether there is a 0-RTT data packet, and give a corresponding score based on the detection situation; an analysis module, which is used to analyze whether there is a small-flow heartbeat packet interaction in the traffic, and give a corresponding score based on the number of small-flow packets; a second detection submodule, which is used to detect whether a PINGFrame is included in the session, and give a corresponding score based on the detection situation.
[0018] The present invention proposes a detection method based on QUIC tunnel that is suitable for real network environment. This technical method mainly combines the statistical characteristics of flow behavior and the threshold judgment method for detection, avoiding reliance on a relatively single frequency detection, reducing false alarms, and improving detection accuracy; this technical method not only determines the attack results through the threshold, but also uses the threshold to filter out data packets that affect the detection effect (retransmission, congestion, packet loss, disorder), which can reduce the problem of poor detection effect caused by factors such as unstable network environment. This technical method provides a solution for detecting attack results, which can effectively detect the QUIC tunnel traffic of existing tools. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0020] Figure 1 This is a flow chart of a QUIC tunnel detection method based on behavior detection feature recognition according to an embodiment of the present invention;
[0021] Figure 2 This is a flowchart of another QUIC tunnel detection method based on behavior detection feature recognition according to an embodiment of the present invention;
[0022] Figure 3 This is a schematic diagram of the structure of a QUIC tunnel detection device based on behavior detection feature recognition according to an embodiment of the present invention. DETAILED DESCRIPTION
[0023] The embodiments of the present invention are described in detail below with reference to the accompanying drawings, but the present invention can be implemented in many different ways as defined and covered by the claims.
[0024] Figure 1 This is a flow chart of the QUIC tunnel detection method based on behavior detection feature recognition described in an embodiment of the present invention.
[0025] See also Figure 1 As shown, a QUIC tunnel detection method based on behavior detection feature recognition includes:
[0026] S101: Obtain basic information of network traffic in real time at the network entrance or exit;
[0027] S103: Detect and score traffic behavior characteristics based on basic information;
[0028] S105: Identify traffic characteristics based on the score and confirm the QUIC tunnel.
[0029] Specifically, during data collection, deploy traffic capture devices at the network entrance or exit, and capture network traffic in real time through packet capture tools such as Wireshark or custom traffic monitoring tools. Aggregate the captured QUIC traffic by session to analyze the traffic characteristics of different sessions. Extract the basic information of each QUIC data packet, including: QUIC packet type, such as Initial, Handshake, 0-RTT, Short Header; frame type PING, Crypto, ACK, etc.; extended fields, such as ALPN; perform traffic behavior feature detection and scoring.
[0030] For each captured QUIC packet or session, you can score each feature based on different traffic characteristics, such as packet size, frame type, ALPN protocol, TLS extension field, etc. The score range is 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest. Further, check whether there is a 0-RTT packet:
[0031] RTT (Zero Round-Trip Time) is an optimization feature in the QUIC protocol, which aims to allow the client to send application data in advance before the handshake is completed, so as to significantly reduce connection latency and improve communication efficiency.
[0032] The test contents are as follows:
[0033] Check if you capture the 0-RTT packet sent immediately after the QUIC Initial Packet.
[0034] If no 0-RTT packets are found in the entire session, and the traffic pattern meets the characteristics of tunnel communication, such as high latency and abnormal communication frequency, it is initially judged as potential tunnel traffic. Compare it with normal business traffic, such as the behavior of HTTP / 3, and analyze the existence and frequency of its 0-RTT packets.
[0035] The scoring criteria are as follows:
[0036] If there are 0-RTT packets, the score is lower, such as 0.3, indicating that it is more likely to be normal traffic.
[0037] If there are no 0-RTT packets, the score is higher, such as 0.8, indicating the possibility of tunnel traffic.
[0038] Further, analyze whether there is a small amount of heartbeat packet interaction in the traffic:
[0039] During QUIC protocol communication, tunnel tools usually implement a heartbeat detection mechanism to maintain the activity of the tunnel connection.
[0040] The test contents are as follows:
[0041] Extract the data packet size for each session and count the number of small packets with a size less than 200 bytes.
[0042] The detection threshold n is set to 60. When the number of continuously captured packets reaches 60 and meets the tunnel traffic characteristics, it is preliminarily determined to be tunnel heartbeat behavior.
[0043] Dynamically adjust the threshold to adapt to the actual network environment and optimize the accuracy of detection.
[0044] The scoring criteria are:
[0045] If the number of packets captured continuously exceeds the threshold, the score will be gradually increased. The maximum score is 0.7 points.
[0046] If the number of small packets far exceeds the threshold and meets the tunnel characteristics, the score is 0.9 points.
[0047] Furthermore, check whether the session contains a PING Frame:
[0048] A common goal of tunneling tools is to hide real network traffic through encrypted tunnels. Therefore, some tunneling tools will deliberately avoid sending explicit PING Frames, especially when they do not need to keep the connection active or perform RTT measurements. This design is to reduce the features that can be detected by traffic analysis tools, but this field will exist in normal business traffic.
[0049] The detection contents are as follows:
[0050] If no PING Frame is found in some sessions and their traffic characteristics are abnormal, it is possible that the tunnel tool hides its heartbeat characteristics through evasive design.
[0051] The scoring criteria are:
[0052] If there is no PING Frame and the traffic is abnormal, the score is 0.8 points.
[0053] If there is a PING Frame, the score is reduced to 0.3 points.
[0054] On the other hand, traffic characteristics are identified:
[0055] During the communication between two parties of QUIC, Initial Packet is exchanged in the initial stage, in which the Initial Packet of the sender contains ClientHello message. The extended field of ClientHello message is parsed.
[0056] Further, ALPN field detection is performed:
[0057] The test contents are as follows:
[0058] If the field value is a non-standard protocol, such as quic-tun or quic-h3-tunnel, it is considered suspected tunnel traffic.
[0059] Establish an ALPN whitelist, add standard protocols such as h3 to the whitelist, and reject traffic that does not comply with the whitelist rules.
[0060] The scoring criteria are:
[0061] If the ALPN field value is a non-standard protocol, such as quic-tun or quic-h3-tunnel, the score is 0.9, which is close to 1, indicating high suspicion.
[0062] If it is a standard protocol, such as HTTP / 3, the score is 0.4, indicating normal traffic.
[0063] At the same time, the characteristics of the customized extended fields of the tunnel tool are further analyzed, and the detection contents are as follows:
[0064] Compare the length and content of the TLS extension fields in the ClientHello message, looking for features consistent with custom extension fields of known tunneling tools.
[0065] Record abnormal extended field values and update the feature library to improve detection capabilities.
[0066] The scoring criteria are:
[0067] If a suspicious custom extension field is found, the score is 0.8 points.
[0068] If no suspicious custom extension fields are found, the score is 0.2 points.
[0069] The specific weights can be set according to the actual situation:
[0070] Confirm the tunnel
[0071] Setting weights and comprehensive scores:
[0072] ALPN field: weight is 0.3 points; 0-RTT data packet: weight is 0.2 points; low-traffic heartbeat packet: weight is 0.2 points; PING Frame detection: weight is 0.3 points.
[0073] Overall score analysis:
[0074] Total score = Σ(feature score × weight), and the final score ranges from 0 to 1. A higher score indicates a greater likelihood of tunnel traffic.
[0075] High risk (score>0.8): It is judged as tunnel traffic.
[0076] Medium risk (score 0.5-0.8): Tunnel traffic may exist and further manual verification is required.
[0077] Low risk (score < 0.5 points): The traffic is consistent with normal business behavior and no further intervention is required.
[0078] Figure 2 This is a flowchart of another QUIC tunnel detection method based on behavior detection feature recognition described in an embodiment of the present invention.
[0079] See also Figure 2 As shown, the QUIC tunnel detection method based on behavior detection feature recognition includes:
[0080] Step 20: Data collection;
[0081] Step 21: Determine whether the session is complete. If so, execute step 22. If not, discard the session and return to step 20.
[0082] Step 22: Check whether there is 0-RIT and PING Frame. If not, execute step 24. If yes, discard and return to execute step 20.
[0083] Step 23: Check whether there is a heartbeat feature; if so, execute step 24; if not, discard and return to step 20;
[0084] Step 24: Parse the Initial Packet;
[0085] Step 25: Check whether ALPH and other extensions meet business expectations. If yes, go to step 29; if no, go to step 28.
[0086] Step 28: Confirm the score;
[0087] Step 29: Determine whether there is a valid server name. If so, return to step 20. If not, go to step 28.
[0088] Step 26: Determine whether the score is greater than 0.8 points. If so, go to step 27. If not, return to step 20.
[0089] Step 27: Confirm the tunnel.
[0090] Figure 3 This is a schematic diagram of the structure of a QUIC tunnel detection device based on behavior detection feature recognition according to an embodiment of the present invention.
[0091] See also Figure 3 As shown, a QUIC tunnel detection device based on behavior detection feature recognition includes: an acquisition module 30, which is used to obtain basic information of network traffic in real time at a network entrance or exit; a detection module 32, which is used to detect and score traffic behavior features based on the basic information; and a confirmation module 34, which is used to identify traffic features according to the score and confirm the QUIC tunnel.
[0092] Preferably, the acquisition module 30 includes: a deployment module (not shown in the figure), which is used to deploy a traffic capture device at the network entrance or exit, and capture network traffic in real time through a packet capture tool; an aggregation module (not shown in the figure), which is used to aggregate the captured network traffic by session, so as to analyze the traffic characteristics of different sessions; an extraction module (not shown in the figure), which is used to extract basic information of each QUIC data packet, and the basic information includes but is not limited to: QUIC packet type, frame type and extension field.
[0093] Preferably, the detection module includes 32: a scoring module (not shown in the figure), which is used to score each feature based on different traffic characteristics for each captured QUIC data packet or session, with the score ranging from 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest.
[0094] Preferably, the scoring module includes: a first detection submodule (not shown in the figure), which is used to detect whether there is a 0-RTT data packet, and give a corresponding score based on the detection situation; an analysis module (not shown in the figure), which is used to analyze whether there is a small-flow heartbeat packet interaction in the traffic, and give a corresponding score based on the number of small-flow packets; a second detection submodule (not shown in the figure), which is used to detect whether a PING Frame is included in the session, and give a corresponding score based on the detection situation.
[0095] The present invention mainly combines the statistical characteristics of traffic behavior and the threshold judgment method for detection, avoiding reliance on a relatively single frequency detection, reducing false alarms, and improving detection accuracy; the technical method not only determines the attack results through the threshold, but also uses the threshold to filter out data packets that affect the detection effect (retransmission, congestion, packet loss, disorder), which can reduce the problem of poor detection results caused by factors such as unstable network environment. The technical method provides a solution for detecting attack results and can effectively detect the quic tunnel traffic of existing tools.
[0096] The above only describes some exemplary embodiments of the present embodiment by way of illustration. It is undoubted that, for those skilled in the art, the described embodiments can be modified in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.
Claims
1. A QUIC tunnel detection method based on behavior detection feature recognition, characterized in that: include: Obtain basic information about network traffic in real time at the network entrance or exit; Detect and score traffic behavior characteristics based on basic information; Traffic characteristics are identified based on the scores and QUIC tunnels are confirmed.
2. The QUIC tunnel detection method according to claim 1, characterized in that: The basic information of network traffic obtained in real time at the network entrance or exit includes: Deploy traffic capture devices at the network entrance or exit, and use packet capture tools to capture network traffic in real time; Aggregate the captured network traffic by session to analyze the traffic characteristics of different sessions; Extract basic information of each QUIC data packet, including but not limited to: QUIC packet type, frame type, and extension fields.
3. The QUIC tunnel detection method according to claim 2, characterized in that: The traffic behavior feature detection and scoring based on basic information includes: For each captured QUIC packet or session, each feature is scored based on different traffic characteristics, with scores ranging from 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest.
4. The QUIC tunnel detection method according to claim 3, characterized in that: Scoring each feature based on different traffic characteristics includes: Detect whether there are 0-RTT data packets and give corresponding scores based on the detection results; Analyze whether there is small-volume heartbeat packet interaction in the traffic, and give a corresponding score based on the number of small-volume packets; Detect whether the session contains a PING Frame and give a corresponding score based on the detection result.
5. The QUIC tunnel detection method according to claim 4, characterized in that: Traffic characteristics are identified based on the scores and QUIC tunnels are confirmed to include: For ALPN field detection, a score is given according to the scoring criteria; For the customized extended fields of the tunnel tool, further features are analyzed and detected, and scores are given according to the scoring criteria.
6. The QUIC tunnel detection method according to claim 5, characterized in that: Identifying traffic characteristics and confirming QUIC tunnels based on scores also includes: Set weights and comprehensive scores, and determine the corresponding tunnel flow based on the total score: ALPN field: weight is 0.3; 0-RTT data packet: weight is 0.2; Small traffic heartbeat packet: weight is 0.2; PING Frame detection: weight is 0.3; Overall score analysis: Total score = Σ(feature score × weight), and the total score ranges from 0 to 1; If the total score is greater than the first threshold, it is determined to be high-risk tunnel traffic; If the total score is between the first threshold and the second threshold, it is judged as medium-risk tunnel traffic; The total score is lower than the second threshold and is determined to be low-risk tunnel traffic.
7. A QUIC tunnel detection device based on behavior detection feature recognition, characterized in that: include: The acquisition module is used to obtain basic information of network traffic in real time at the network entrance or exit; The detection module is used to detect and score traffic behavior characteristics based on basic information; The confirmation module is used to identify traffic characteristics and confirm the QUIC tunnel based on the score.
8. The QUIC tunnel detection device according to claim 7, characterized in that: The acquisition module comprises: Deployment module, used to deploy traffic capture devices at the network entrance or exit, and capture network traffic in real time through packet capture tools; Aggregation module, used to aggregate the captured network traffic by session, so as to analyze the traffic characteristics of different sessions; The extraction module is used to extract basic information of each QUIC data packet, which includes but is not limited to: QUIC packet type, frame type and extension field.
9. The QUIC tunnel detection device according to claim 8, characterized in that: The detection module comprises: The scoring module is used to score each feature based on different traffic characteristics for each captured QUIC packet or session, with the score ranging from 0 to 1, where 1 represents the strongest tunnel traffic feature and 0 represents the weakest.
10. The QUIC tunnel detection device according to claim 8, characterized in that: The scoring modules include: The first detection submodule is used to detect whether there is a 0-RTT data packet and give a corresponding score according to the detection situation; The analysis module is used to analyze whether there is a small flow of heartbeat packet interaction in the traffic, and give a corresponding score according to the number of small flow packets; The second detection submodule is used to detect whether the session contains a PING Frame and give a corresponding score based on the detection result.