Multi-protocol rapid identification method and system for VPN (Virtual Private Network) outburst network data

By collecting and analyzing the combination characteristics of VPN network packets, using a multi-protocol combination recognition model for protocol identification, and decrypting the data packets when the identification results are consistent, the problems of miscontrol and slow recognition speed caused by VPN data encryption are solved, and the accuracy and speed of protocol identification are improved.

CN120128514AActive Publication Date: 2025-06-10LIZHUANG INFORMATION TECH (SUZHOU) CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510600555.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-06-10
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

In the prior art, due to the encryption characteristics of VPN data, data missed control and missing key information, which affects the speed of protocol identification.

Method used

By collecting VPN network packets from the target network, extracting combination features (including traffic characteristics and behavioral characteristics), setting up a multi-protocol combination recognition model, and performing protocol type identification of data packets. When the recognition results are consistent, the parsing plug-in is called to obtain the decryption key and decrypt the data packet.

Benefits of technology

It improves the accuracy and security of VPN network data protocol identification, speeds up the response speed of protocol identification, and ensures the reliability of identification results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128514A_ABST
    Figure CN120128514A_ABST
Patent Text Reader

Abstract

The invention provides a multi-protocol rapid identification method and system for VPN (Virtual Private Network) outburst network data, and relates to the technical field of network communication, and the method comprises the steps: collecting VPN outburst network data packets from a target network by using a plurality of collection ends; combined features are extracted, wherein the combined features comprise flow features and behavior features; setting a multi-protocol combination recognition model, and performing protocol type recognition on the combination features; when the first protocol type identification result is consistent with the second protocol type identification result, calling an analysis plug-in according to the protocol type to obtain a decryption key; and decrypting the VPN protruding network data packet. According to the method and the device, the technical problem that the protocol identification speed is further influenced due to key information loss caused by data control omission due to the encryption characteristic of VPN data is solved, protocol identification is performed by setting combined characteristics (flow characteristics and behavior characteristics), and whether two identification results are the same or not is compared, so that the protocol type identification result is quickly determined, and the protocol identification speed is improved. And the overall identification speed and accuracy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technologies, and particularly to a multi-protocol fast recognition method and system for VPN breakthrough network data. Background Art

[0002] With the development of the network, information exchange at home and abroad has become increasingly frequent. The VPN method has two major characteristics. On the one hand, VPN can transmit encrypted data packets on a public network to ensure the privacy and integrity of communication content. On the other hand, VPN has good camouflage ability and can simulate common network protocols for transmission, easily bypassing firewalls and freely entering and leaving. In the prior art, the recognition of VPN breakthrough network data mainly relies on traffic behavior feature analysis, including packet length distribution, connection duration, uplink and downlink traffic ratio, typical ports, and IPs, etc. It may recognize disguised protocols and faces problems such as low recognition accuracy and slow processing speed.

[0003] In summary, in the prior art, there is a technical problem that due to the encryption characteristics of VPN data, data leakage control leads to the lack of key information, further affecting the protocol recognition speed. Summary of the Invention

[0004] The purpose of this application is to provide a multi-protocol fast recognition method and system for VPN breakthrough network data to solve the technical problem in the prior art that due to the encryption characteristics of VPN data, data leakage control leads to the lack of key information, further affecting the protocol recognition speed.

[0005] In view of the above problems, this application provides a multi-protocol fast recognition method and system for VPN breakthrough network data.

[0006] In the first aspect, this application provides a multi-protocol fast recognition method for VPN breakthrough network data. The multi-protocol fast recognition method for VPN breakthrough network data is implemented through a multi-protocol fast recognition system for VPN breakthrough network data. Among them, the multi-protocol fast recognition method for VPN breakthrough network data includes: collecting VPN breakthrough network data packets from a target network using multiple collection ends; extracting combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavior features for communication modeling; setting a multi-protocol combined recognition model, and respectively performing protocol type recognition on the combined features of the VPN breakthrough network data packets according to the multi-protocol combined recognition model to obtain a first protocol type recognition result and a second protocol type recognition result; when the first protocol type recognition result and the second protocol type recognition result are consistent, calling a parsing plugin according to the output protocol type, and parsing the decryption key corresponding to the protocol type based on the parsing plugin; decrypting the VPN breakthrough network data packets using the decryption key, and outputting VPN plaintext data packets at multiple ends.

[0007] Optionally, by analyzing the five-tuple information of the VPN breakout network data packets, traffic characteristics for fingerprint modeling are extracted. The traffic characteristics include packet size, transmission delay, packet interval, data traffic pattern, and port number. By analyzing the timing behavior information of the VPN breakout network data packets, behavioral characteristics of the modeled communication are extracted. The behavioral characteristics include communication connection characteristics, communication duration, data flow direction, connection retry behavior, and uplink / downlink paths.

[0008] Optionally, initialize a combined recognition model, where the initialized combined recognition model is a dual-channel protocol recognition architecture. Generate protocol training sample data, which includes known VPN protocol data samples and corresponding combined feature samples of the known VPN protocol data samples, and disguised VPN multi-protocol data samples and corresponding combined feature samples of the disguised VPN multi-protocol data samples. Among them, the combined feature samples include traffic feature samples and behavioral feature samples. Perform dual-channel training on the initialized combined recognition model according to the protocol training sample data, and output a multi-protocol combined recognition model.

[0009] Optionally, the multi-protocol combined recognition model includes a protocol classification channel trained based on a lightweight neural network and a protocol classification channel trained based on a temporal neural network. Among them, the protocol classification channel trained based on the lightweight neural network performs protocol type recognition on the traffic characteristics of the VPN breakout network data packets and outputs a first protocol type recognition result. The protocol classification channel trained based on the temporal neural network performs protocol type recognition on the behavioral characteristics of the VPN breakout network data packets and outputs a second protocol type recognition result.

[0010] Optionally, when the first protocol type recognition result and the second protocol type recognition result are inconsistent, identify the VPN breakout network data packet as disguised VPN breakout network data. Extract high-dimensional combined features from the disguised VPN breakout network data, where the high-dimensional combined features include high-dimensional traffic features and high-dimensional behavioral features, and the feature convolution scale of the high-dimensional combined features is smaller than that of the combined features. Evaluate the feature credibility of the high-dimensional traffic features and the high-dimensional behavioral features, and output the traffic feature credibility and the behavioral feature credibility. By comparing the traffic feature credibility and the behavioral feature credibility, call a parsing plugin to decrypt the disguised VPN breakout network data.

[0011] Optionally, if the traffic feature credibility is greater than or equal to the behavioral feature credibility, call a parsing plugin to decrypt the disguised VPN breakout network data according to the first protocol type. If the traffic feature credibility is less than the behavioral feature credibility, call a parsing plugin to decrypt the disguised VPN breakout network data according to the second protocol type.

[0012] Optionally, a parsing plugin is called according to the output protocol type. The parsing plugin is obtained by calling through a parsing plugin management module, and the parsing plugin management module includes multiple parsing plugins, and each parsing plugin corresponds to a protocol type. Among them, the parsing plugin has a built-in protocol feature library and a key export rule for exporting a corresponding decryption key according to the protocol type.

[0013] Optionally, the VPN plaintext data packet is output through multiple output ports at multiple ends. Among them, the multiple output ports are connected to a configuration switch, and the configuration switch is used to filter the VPN plaintext data packet to obtain a filtered VPN plaintext data packet.

[0014] Optionally, the real-time load status of the multiple output ports is detected to generate multiple real-time load metrics. The multiple real-time load metrics are sorted in descending order of the metric size to generate an output port queue list. When a VPN plaintext data packet is obtained, the VPN plaintext data packet is output according to the first output port in the output port queue list, and the output port queue list is updated at the same time.

[0015] In a second aspect, the present application also provides a multi-protocol rapid recognition system for VPN breakthrough network data, which is used to execute the multi-protocol rapid recognition method for VPN breakthrough network data as described in the first aspect. The multi-protocol rapid recognition system for VPN breakthrough network data includes: a data packet acquisition module for acquiring VPN breakthrough network data packets from a target network using multiple acquisition ends; a combined feature extraction module for extracting combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavior features for modeling communication; a protocol type recognition module for setting a multi-protocol combined recognition model and respectively performing protocol type recognition on the combined features of the VPN breakthrough network data packets according to the multi-protocol combined recognition model to obtain a first protocol type recognition result and a second protocol type recognition result; a plugin parsing module for, when the first protocol type recognition result and the second protocol type recognition result are consistent, calling a parsing plugin according to the output protocol type and parsing the decryption key corresponding to the protocol type based on the parsing plugin; and a data packet decryption module for decrypting the VPN breakthrough network data packet using the decryption key and outputting the VPN plaintext data packet at multiple ends.

[0016] One or more technical solutions provided in the present application have at least the following beneficial effects: Collect VPN breakthrough network data packets from the target network using multiple collection ends; extract the combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavior features for communication modeling; set up a multi-protocol combination recognition model, and identify the protocol types of the combined features of the VPN breakthrough network data packets respectively according to the multi-protocol combination recognition model to obtain the first protocol type recognition result and the second protocol type recognition result; when the first protocol type recognition result and the second protocol type recognition result are consistent, call the parsing plugin according to the output protocol type, and decrypt the decryption key corresponding to the protocol type based on the parsing plugin; decrypt the VPN breakthrough network data packets using the decryption key, and output the VPN plaintext data packets at multiple ends. That is to say, by setting combined features (traffic features and behavior features), performing protocol recognition processes respectively, obtaining two candidate recognition results, comparing whether the two recognition results are the same, calling the parsing plugin for decryption when the recognition results are consistent, and mutually verifying the two independent recognition channels to ensure the reliability of the recognition results. Only when the judgments on both sides are consistent is the recognition considered correct, quickly determining the protocol of the VPN breakthrough network data, accelerating the response speed of protocol recognition, and thus improving the accuracy and security of VPN breakthrough network data protocol recognition.

[0017] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the specific embodiments of the present application. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understandable through the following description. Brief Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary, and for those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0019] Figure 1 It is a schematic flowchart of the multi-protocol fast recognition method for VPN breakthrough network data of the present application; Figure 2 It is a schematic structural diagram of the multi-protocol fast recognition system for VPN breakthrough network data of the present application.

[0020] Description of the reference numerals: data packet collection module 11, combined feature extraction module 12, protocol type recognition module 13, plugin parsing module 14, data packet decryption module 15. Detailed implementation manners

[0021] By providing a multi - protocol fast recognition method and system for VPN breakthrough network data, this application solves the technical problem in the prior art that due to the encryption characteristics of VPN data, data leakage control leads to the lack of key information, further affecting the protocol recognition speed. By setting combined features (traffic features and behavior features), performing protocol recognition processes respectively to obtain two candidate recognition results, comparing whether the two recognition results are the same, when the recognition results are consistent, calling a parsing plugin for decryption, and mutually verifying the two independent recognition channels to ensure the reliability of the recognition results. Only when the judgments on both sides are consistent is the recognition considered correct, quickly determining the protocol of VPN breakthrough network data, accelerating the response speed of protocol recognition, thereby improving the accuracy and security of VPN breakthrough network data protocol recognition.

[0022] Next, the technical solutions in this application will be described clearly and completely with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments of this application. It should be understood that this application is not limited by the example embodiments described here. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application. Additionally, it should be noted that for the convenience of description, only parts related to this application are shown in the accompanying drawings rather than all of them.

[0023] Embodiment 1, please refer to the attached Figure 1 , this application provides a multi - protocol fast recognition method for VPN breakthrough network data. Among them, the multi - protocol fast recognition method for VPN breakthrough network data is executed by a multi - protocol fast recognition system for VPN breakthrough network data. The multi - protocol fast recognition method for VPN breakthrough network data specifically includes the following steps: S100: Collect VPN breakthrough network data packets from a target network using multiple collection ends.

[0024] Specifically, according to the topology of the target network, several key nodes are determined and collection devices are deployed on these nodes to obtain multiple collection ends for capturing and collecting data packets. The target network is a network environment that needs to be monitored and secured against threats, including a large amount of internal communication and inbound and outbound traffic, and is a key area for security monitoring and data collection. A collection end refers to a data packet collection device or monitoring node deployed in the target network, which can be a network traffic mirroring device (such as network card mirroring, mirroring ports of network switches), a network security monitoring system (such as IDS / IPS, NetFlow collector), or a dedicated hardware device. Multiple collection ends are usually deployed at different locations in the network to obtain comprehensive and redundant traffic data. VPN breakthrough network data packets refer to encrypted data packets transmitted from the target network when using VPN technology to penetrate the internal network or when restricted by a firewall.

[0025] Multiple collection ends collect data packets in different regions of the target network respectively. According to preset rules (such as specific protocol ports, tunnel encapsulation characteristics, encrypted traffic ratio, etc.), the collected traffic data is filtered and pre-labeled, and the multi-layer encryption identifiers unique to the VPN tunnel (such as specific SSL handshakes, abnormal TLS SNI fields, etc.) are screened to distinguish data packets that may belong to VPN breakthrough from a large number of data packets. Through multi-end collection, comprehensive data coverage is achieved, avoiding the problem of single-point missed collection, and greatly enhancing the integrity and redundancy of the data.

[0026] S200: Extract the combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavioral features for modeling communication.

[0027] Furthermore, step S200 of this application includes: By analyzing the five-tuple information of the VPN breakthrough network data packets, traffic features for fingerprint modeling are extracted, where the traffic features include data packet size, transmission delay, data packet interval, data traffic pattern, and port number; by analyzing the temporal behavior information of the VPN breakthrough network data packets, behavioral features for modeling communication are extracted, where the behavioral features include communication connection features, communication duration, data flow direction, connection retry behavior, and upstream and downstream paths.

[0028] Specifically, the combined features of the VPN breakthrough network data packets are composed of two types of data features, which are used to describe and model the overall attributes of the data packets, including traffic features for fingerprint modeling and behavioral features for modeling communication. The traffic features for fingerprint modeling are a set of features established by analyzing the static attributes in network traffic to create a traffic fingerprint for uniquely identifying a specific protocol or application. The behavioral features for modeling communication are obtained by capturing the packet timing and interaction process to describe the dynamic behavior information within a communication session, that is, the communication context.

[0029] For each captured VPN breakout packet, first use a network packet analysis tool (such as Wireshark, tcpdump) to read its five-tuple information. The five-tuple information is used to identify the source and destination of the packet, supporting subsequent preliminary classification based on port numbers, protocol types, etc., as well as packet filtering, including source IP address, source port number, destination IP address, destination port number, and protocol type. By analyzing the five-tuple information of VPN breakout packets, traffic characteristics for fingerprint modeling are extracted, including packet size, transmission delay, packet interval, data traffic pattern, and port number. The packet size is the number of bytes of each packet and is an important static feature for identifying communication patterns; the transmission delay is the time elapsed from the packet being sent to being received, which is used to reflect network latency and the encryption negotiation process; the packet interval is the time interval between consecutive packets, reflecting burstiness or stability; the data traffic pattern is used to describe the uplink and downlink distribution, periodic behavior, or burst traffic phenomenon of packets in a session; the port number in the transport layer is used to distinguish different services or protocols, such as VPN often using ports 1194 or 443.

[0030] By analyzing the temporal behavior information of VPN breakout packets, that is, the time-related information during the capture process of the packets, including timestamps, packet order, interval time, and the time distribution of each stage in the communication session. By analyzing the temporal behavior of the packets, behavioral characteristics for modeling communication are extracted, constructing a description of the communication context, including dynamic characteristics during processes such as session establishment, data interaction, disconnection, or reconnection. In the data collection phase, each packet will carry an accurate timestamp. Using this timestamp information, the order and interval of packet arrivals can be obtained. Through temporal information, the key stages in the connection establishment process are identified, obtaining communication connection characteristics, that is, the methods and processes used to establish a communication connection, mainly focusing on information such as the handshake process, connection initialization, and security negotiation; the communication duration is the duration of a complete communication session from establishment to disconnection, that is, the time difference between the first packet (usually the start of the handshake) and the last packet (disconnection or session end); the data flow direction is obtained by analyzing the source and destination IP information of the packets and counting the number and bytes of uplink and downlink packets, which is the transmission direction of the packets in the session, the distribution of uplink (from the client to the server) and downlink (from the server to the client); the connection retry behavior is the behavior of re-establishing a connection after disconnection due to network jitter, encryption negotiation failure, or other abnormal factors during the communication process, usually obtained by comparing the session interruption time with the start time of the new session and counting the retry times and time intervals; the uplink and downlink paths are the network paths and hop counts that the packets pass through from the sender to the receiver.

[0031] By extracting the combined features of VPN breakthrough network data packets, comprehensively identifying the features of data packets, and combining traffic features and behavior features, the accuracy and reliability of protocol identification can be improved.

[0032] S300: Set up a multi-protocol combination recognition model, and perform protocol type recognition on the combined features of the VPN breakthrough network data packets according to the multi-protocol combination recognition model to obtain the first protocol type recognition result and the second protocol type recognition result.

[0033] Furthermore, S300 of the present application includes: Initialize the combination recognition model, where the initialized combination recognition model is a dual-channel protocol recognition architecture; generate protocol training sample data, where the protocol training sample data includes known VPN protocol data samples and the combined feature samples corresponding to the known VPN protocol data samples, and disguised VPN multi-protocol data samples and the combined feature samples corresponding to the disguised VPN multi-protocol data samples; among them, the combined feature samples include traffic feature samples and behavior feature samples; perform dual-channel training on the initialized combination recognition model according to the protocol training sample data, and output a multi-protocol combination recognition model.

[0034] Specifically, initializing the combination recognition model is an overall model for protocol recognition and classification of VPN breakthrough network data packets. This model is a dual-channel protocol recognition architecture, which realizes the recognition of multi-layer encapsulation and multi-protocol mixing. The combination recognition model consists of two parallel recognition channels, one focusing on processing traffic features and the other on temporal behavior features.

[0035] Construct protocol training sample data, including the combined feature samples of standard VPN traffic data samples captured from the actual network environment, which have been labeled and preprocessed, and data samples that make the VPN traffic disguise as other protocols through certain processing or technical means, representing samples with anti-interference and confusion characteristics. Both types of protocol training sample data include traffic feature samples and behavior feature samples. In short, capture the original VPN traffic data in the target network, and at the same time, collect the disguised traffic data. Perform preliminary annotation on the captured data through expert experience or automated rules, mark the VPN traffic among them as known VPN protocol samples, and mark the traffic after disguise processing as disguised VPN multi-protocol samples.

[0036] By introducing disguised VPN multi - protocol samples, the model can learn how to distinguish real VPN traffic from disguised traffic under interference, enhancing the robustness of the model. Using protocol training sample data, a two - channel training is carried out on the initialized combined recognition model. During the training process, the lightweight neural network channel focuses on learning traffic features, while the temporal neural network channel focuses on learning behavioral features. Normalize and augment the protocol training sample data, such as logarithmic transformation and mean normalization, to ensure that each feature is within a reasonable range. Construct a lightweight neural network training channel for learning traffic features. The model can be designed as an input layer - 3 fully - connected layers - output layer, using the ReLU activation function and finally adopting Softmax to output classification probabilities. Construct a temporal neural network training channel for capturing behavioral features. Design a 2 - layer LSTM network. After several hidden units in each layer, send the final state to the fully - connected layer to obtain the classification output.

[0037] Distribute each training sample to both channels simultaneously: the traffic features are input into the lightweight network, and the behavioral features are input into the temporal network. Use the standard supervised training method to update the model parameters of both parts, and monitor the loss function and accuracy during the training process. Conduct supervised learning training on the lightweight channel and the temporal channel separately, and adjust the parameters until the classification accuracy converges. At the same time, guide the joint optimization of the two channels through the joint loss function to ensure that the output results perform well in both static and dynamic feature dimensions. Set hyperparameters such as batch size, learning rate, and number of training epochs, and conduct cross - validation through the validation set to ensure the convergence effect. After training, save the two - channel model as a multi - protocol combined recognition model.

[0038] Through the two - channel architecture, the recognition accuracy is improved by using traffic and behavioral features respectively, and a combined feature (including traffic and behavioral features) is constructed using known VPN samples and disguised VPN samples to conduct joint training on the model, achieving high - precision and high - robustness multi - protocol combined recognition. The overall model has a low misjudgment rate and excellent anti - interference ability in a complex and changeable network environment.

[0039] Furthermore, the present application further includes the following steps: The multi - protocol combined recognition model includes a protocol classification channel trained based on a lightweight neural network and a protocol classification channel trained based on a temporal neural network; among them, the protocol classification channel trained based on the lightweight neural network identifies the protocol type of the traffic features of the VPN breakout network data packet and outputs the first protocol type recognition result, and the protocol classification channel trained based on the temporal neural network identifies the protocol type of the behavioral features of the VPN breakout network data packet and outputs the second protocol type recognition result.

[0040] Specifically, the multi - protocol combination recognition model includes a protocol classification channel trained based on a lightweight neural network and a protocol classification channel trained based on a temporal neural network. Among them, the protocol classification channel trained based on the lightweight neural network is a neural network channel that specifically models and classifies the static traffic characteristics in VPN data packets (such as packet size, transmission delay, packet interval, traffic pattern, port number, etc.); the protocol classification channel trained based on the temporal neural network is a neural network channel that focuses on capturing the dynamic behavioral characteristics of VPN data packets in terms of time series (such as handshake delay, communication duration, data flow direction, connection retry situation, and upstream and downstream paths, etc.).

[0041] Input the combined features of the extracted VPN breakout data packets into the multi - protocol combination recognition model. The protocol classification channel trained based on the lightweight neural network performs protocol type recognition on the traffic characteristics and outputs the first protocol type recognition result; the protocol classification channel trained based on the temporal neural network performs protocol type recognition on the behavioral characteristics and outputs the second protocol type recognition result.

[0042] The first protocol type recognition result is output by the protocol classification channel trained based on the lightweight neural network, which mainly reflects the contribution of traffic characteristics to the determination of the protocol type and represents that the data packet is determined as a specific protocol type in the dimension of traffic characteristics; the second protocol type recognition result is output by the protocol classification channel trained based on the temporal neural network, which mainly identifies the protocol type based on dynamic communication behaviors and represents that the data packet is determined as a specific protocol type in the dimension of behavioral characteristics, and is used to compare and verify with the first result (traffic characteristic recognition).

[0043] By setting up a multi - protocol combination recognition model with dual channels to perform protocol recognition on VPN breakout data packets, it has strong anti - confusion, anti - encryption, and anti - port spoofing capabilities. Through dual - channel consistency judgment, it reduces misjudgment and missed judgment, accurately identifies the protocol type of VPN breakout data packets, thereby improving the accuracy and reliability of protocol recognition.

[0044] Furthermore, the present application further includes the following steps: When the first protocol type recognition result and the second protocol type recognition result are inconsistent, mark the VPN breakout data packet as disguised VPN breakout data; extract high - dimensional combined features from the disguised VPN breakout data, where the high - dimensional combined features include high - dimensional traffic features and high - dimensional behavioral features, and the feature convolution scale of the high - dimensional combined features is smaller than the convolution scale of the combined features; perform feature credibility evaluation on the high - dimensional traffic features and the high - dimensional behavioral features, and output the traffic feature credibility and the behavioral feature credibility; by comparing the traffic feature credibility and the behavioral feature credibility, call the parsing plugin to decrypt the disguised VPN breakout data.

[0045] If the credibility of the traffic feature is greater than or equal to the credibility of the behavior feature, call the parsing plugin according to the first protocol type to decrypt the disguised VPN breakout data; if the credibility of the traffic feature is less than the credibility of the behavior feature, call the parsing plugin according to the second protocol type to decrypt the disguised VPN breakout data.

[0046] Specifically, when the protocol recognition result of the traffic feature by the protocol classification channel trained based on the lightweight neural network is inconsistent with the protocol recognition result of the behavior feature by the protocol classification channel trained based on the temporal neural network, it is determined that the data packet has the risk of protocol disguise, so it is marked as disguised VPN breakout data. Perform more in-depth feature extraction on the disguised VPN breakout data packet, including high-dimensional traffic features and high-dimensional behavior features. That is to say, on the basis of the original combined features, a finer-grained modeling of the data structure is carried out by means of a convolution scale smaller than that of the original combined features. For example, for traffic features, some port mutations, rate fluctuations, and atypical flow direction features will be extracted; for behavior features, the anomalies in its connection behavior will be analyzed, such as frequent connection retries in a short time or an abnormally stable connection pattern.

[0047] Evaluate the credibility of the extracted high-dimensional traffic features and high-dimensional behavior features to determine which type of feature can better represent the real protocol type. Evaluate the credibility of the extracted high-dimensional traffic features and high-dimensional behavior features, and analyze the credibility of each feature, that is, the degree to which the feature can accurately reflect the characteristics of the data packet. The credibility is generally a score from 0 to 1, and the higher the score, the more credible the feature is and the more suitable it is for subsequent parsing or classification.

[0048] Input the extracted high-dimensional traffic features and high-dimensional behavior features into the credibility evaluation network; use a multi-layer perceptron (MLP) + attention weight mechanism to calculate two credibility values. For each input feature, perform feature mapping through the multi-layer perceptron to generate hidden layer feature representations. The MLP network consists of multiple hidden layers and activation functions, and can learn the deep relationships of the input features. Use the attention weight mechanism to dynamically assign the importance weights of the features. Based on the context relationship of the features, each feature is assigned a weight, indicating its relative importance in calculating the credibility. For example, for traffic features, the attention mechanism will focus on features such as packet size and transmission delay that have a decisive impact on protocol recognition; for behavior features, the attention mechanism may increase the attention to connection retry frequency and session persistence.

[0049] The weighted feature representation is mapped through the Sigmoid activation function to obtain the credibility value of the feature. The range of the credibility value is between [0, 1], indicating the reliability of the feature in protocol type recognition. If the credibility of the traffic feature is greater than or equal to the credibility of the behavior feature, it means that the traffic feature contributes more to protocol recognition. Therefore, it is inclined to use the traffic feature to perform decryption, select the first protocol type, and call the parsing plugin related to this protocol type for decryption operations. The parsing plugin will decrypt the data packet according to the protocol type obtained from the traffic feature, thereby restoring the VPN plaintext data packet.

[0050] If the credibility of the traffic feature is less than the credibility of the behavior feature, select the second protocol type and call the corresponding parsing plugin for decryption. At this time, the behavior feature is considered more reliable, so the protocol type based on the behavior feature is selected for decryption.

[0051] Exemplarily, high-dimensional feature extraction is performed on the disguised VPN breakthrough network data packet, and the high-dimensional traffic features obtained are: the data packet size is 1400 bytes, the transmission delay is 15 ms, and the port number is 443; the high-dimensional behavior features are: the connection duration is 250 s, the number of retries is 2 times, and the data flow direction is upstream; the multi-layer perceptron (MLP) and the attention mechanism are used to evaluate the high-dimensional traffic features and high-dimensional behavior features, and the credibility of the traffic feature is 0.88, and the credibility of the behavior feature is 0.75. Each feature is input separately. Therefore, the traffic feature has 3 inputs (such as data packet size, transmission delay, port number), and the behavior feature has 3 inputs (such as connection duration, number of retries, data flow direction). For the traffic feature, after standardization, the data packet size is 0.85, the transmission delay is 0.75, and the port number is 0.8; for the behavior feature, after standardization, the connection duration is 0.9, the number of retries is 0.8, and the data flow direction is 1. The MLP will calculate the weighted sum of the hidden layer, and then process it through the activation function ReLU. Finally, the output credibility value is MLP 流量 (0.85, 0.75, 0.80) = 0.88, MLP 行为 (0.90, 0.80, 1.0) = 0.75. Therefore, the first protocol type corresponding to the traffic feature is selected for decryption, and the parsing plugin matching this protocol type is called. Through the built-in protocol feature library and key derivation rules, the decryption key is obtained.

[0052] By extracting and evaluating features in the high-dimensional space, the disguised VPN breakthrough network data is accurately identified and parsed, improving the recognition ability of tampered or disguised protocol types, selecting the most likely protocol type for decryption, and improving the decryption success rate.

[0053] S400: When the first protocol type recognition result is consistent with the second protocol type recognition result, call the parsing plugin according to the output protocol type, and parse the decryption key corresponding to the protocol type based on the parsing plugin.

[0054] Further, S400 of the present application includes: Call the parsing plugin according to the output protocol type. The parsing plugin is obtained by calling through the parsing plugin management module. The parsing plugin management module includes multiple parsing plugins, and each parsing plugin corresponds to a protocol type; wherein, the parsing plugin has a built-in protocol feature library and a key export rule for exporting the corresponding decryption key according to the protocol type.

[0055] Specifically, when the protocol type recognition results output by the lightweight neural network channel and the temporal neural network channel in the multi-protocol combination recognition model are consistent, it indicates that the current judgment of the VPN breakthrough network data packet type has a high credibility, and the recognition result is directly output. Call the corresponding parsing plugin through the parsing plugin management module according to the output protocol type. The parsing plugin management module includes multiple parsing plugins, and each parsing plugin corresponds to a protocol type. For example, the OpenVPN protocol corresponds to the OpenVPN_Parser.dll parsing plugin; the WireGuard protocol corresponds to the WireGuard_KeyExtractor.py parsing plugin; the L2TP / IPSec protocol corresponds to the IPSecHandler.so parsing plugin, etc.

[0056] The parsing plugin has a built-in protocol feature library and a key export rule. Among them, the protocol feature library contains relevant feature information of a specific protocol type for identifying and parsing data packets of that protocol type; the key export rule is used to export the corresponding decryption key according to the protocol type. Specifically, the parsing plugin retrieves its built-in protocol feature library to verify whether the currently captured data packet fully conforms to the structural features of the protocol. For example, whether the data packet header is 0x38 0x13, whether there is a handshake phase HMAC verification field, and whether the encrypted handshake is based on TLS1.2. After passing the verification, the plugin extracts the key from specific data fields according to the key export rule. The extracted key is confirmed for validity through the algorithm verification mechanism (such as HMAC check, symmetric decryption attempt) inside the plugin. If the verification passes, the key is returned to the upper layer module as the decryption key for the current session for plaintext restoration.

[0057] By calling the parsing plugin, accurately parsing the VPN breakthrough network data packet according to the recognized protocol type and exporting the corresponding decryption key improves the accuracy and efficiency of protocol parsing.

[0058] S500: Decrypt the VPN breakthrough network data packet using the decryption key and output the VPN plaintext data packet on multiple terminals.

[0059] Furthermore, the S500 of the present application includes: The VPN plaintext data packet is output through multiple output ports in a multi-terminal manner. Among them, the multiple output ports are connected to a configuration switch; the configuration switch is used to filter the VPN plaintext data packet to obtain the filtered VPN plaintext data packet.

[0060] Specifically, the decryption key obtained through the parsing plugin is used to decrypt the VPN breakthrough network data packet to restore the VPN plaintext data packet, including original plaintext data such as HTTP requests, DNS queries, FTP commands, and remote desktop transmissions, which can clearly identify communication content, website addresses, user behaviors, etc. It can decrypt and decompress all PPTP data and output plaintext data packets; it can decrypt and decompress L2TP data encrypted using the DES algorithm and output plaintext data packets; it can decrypt wumaVPN, AtomVPN, OfficeVPN and other SS tunnel data in real time and output plaintext data packets.

[0061] After successful decryption, the VPN plaintext data packet is pushed to multiple output ports for multi-terminal output, and the multiple output ports are connected to the configuration switch. The configuration switch is a configurable logic module used to define which plaintext data should be output and which should be filtered out, including protocol type filtering, port filtering, content keyword filtering, etc.

[0062] The configuration switch obtains a preset filtering rule through the user side. For example, only HTTP plaintext data is output, DNS data packets are excluded, plaintext content without keywords "login" and "token" is filtered out, and port command content in FTP protocol plaintext is retained. The VPN plaintext data packet is filtered according to the preset filtering rule, and only the data packet that meets the filtering rule is allowed to pass, so as to obtain the filtered VPN plaintext data packet. The plaintext packet is still retained after passing through the filtering module and output to all ports. For example, if only data packets containing the HTTP protocol need to be transmitted to port A, the configuration switch can be set to only allow data packets of the HTTP protocol to pass and block other types of data packets.

[0063] Through multi-terminal output and the configuration switch, the VPN breakthrough network data packet is decrypted and filtered, effectively screening out data packets that meet specific conditions, enhancing the security and compliance of the data. The use of the configuration switch further enhances the control ability of data transmission, ensuring that only data packets that meet specific conditions are transmitted to subsequent ports, thereby improving the accuracy and efficiency of data processing.

[0064] Furthermore, the present application further includes the following steps: Detect the real-time load status of the multiple output ports to generate multiple real-time load metrics; sort the multiple real-time load metrics in descending order of metric size to generate an output port queue list. When a VPN plaintext packet is obtained, output the VPN plaintext packet according to the first output port in the output port queue list, and update the output port queue list at the same time.

[0065] Specifically, after decrypting the plaintext packet from the VPN traffic, to avoid overloading the output ports, detect the real-time load status of all output ports (such as the current traffic volume being processed, speed, etc.) to generate multiple real-time load metrics. The real-time load status is the data transmission volume and workload borne by the output port at the current moment, and the real-time load metric is a metric used to quantify the load status of the output port, which can be the data transmission rate, queue length, etc.

[0066] Sort the multiple real-time load metrics in descending order of metric size, place the port with the lightest load at the head of the queue, and construct an output port queue list. When a new plaintext packet arrives, output it from the first output port in the output port queue list, that is, select the first port with the lightest load in the queue list for output. After the output is completed, the real-time load status will change, so update the load information of the output port and re-sort the queue so that the next packet can be reasonably allocated to the port with the lightest current load to achieve dynamic load balancing output.

[0067] By detecting and adjusting the use of the output ports in real time, load balancing of multi-terminal output is achieved, avoiding overloading of a single port, ensuring that VPN plaintext packets can always be transmitted to the port with the lowest current load and the strongest transmission capacity, thereby improving the efficiency and overall performance of data processing.

[0068] In summary, the multi-protocol fast identification method for VPN breakthrough network data provided by this application has the following beneficial effects: Collect VPN breakthrough network data packets from a target network using multiple collection ends; extract combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavioral features for communication modeling; set up a multi-protocol combination recognition model, and respectively perform protocol type recognition on the combined features of the VPN breakthrough network data packets according to the multi-protocol combination recognition model to obtain a first protocol type recognition result and a second protocol type recognition result; when the first protocol type recognition result and the second protocol type recognition result are consistent, call a parsing plugin according to the output protocol type, and parse the decryption key corresponding to the protocol type based on the parsing plugin; decrypt the VPN breakthrough network data packets using the decryption key, and output VPN plaintext data packets at multiple ends. That is to say, by setting combined features (traffic features and behavioral features), respectively performing protocol recognition processes, obtaining two candidate recognition results, comparing whether the two recognition results are the same, calling a parsing plugin for decryption when the recognition results are consistent, and mutually verifying the two independent recognition channels to ensure the reliability of the recognition results. Only when the judgments on both sides are consistent is the recognition considered correct, quickly determining the protocol of the VPN breakthrough network data, accelerating the response speed of protocol recognition, and thus improving the accuracy and security of VPN breakthrough network data protocol recognition.

[0069] Embodiment 2. Based on the same inventive concept as the multi-protocol fast recognition method for VPN breakthrough network data in the foregoing Embodiment 1, the present application also provides a multi-protocol fast recognition system for VPN breakthrough network data. Please refer to the appendix Figure 2 , the multi-protocol fast recognition system for VPN breakthrough network data includes: A data packet collection module 11 for collecting VPN breakthrough network data packets from a target network using multiple collection ends; a combined feature extraction module 12 for extracting combined features of the VPN breakthrough network data packets, where the combined features include traffic features for fingerprint modeling and behavioral features for communication modeling; a protocol type recognition module 13 for setting up a multi-protocol combination recognition model and respectively performing protocol type recognition on the combined features of the VPN breakthrough network data packets according to the multi-protocol combination recognition model to obtain a first protocol type recognition result and a second protocol type recognition result; a plugin parsing module 14 for, when the first protocol type recognition result and the second protocol type recognition result are consistent, calling a parsing plugin according to the output protocol type and parsing the decryption key corresponding to the protocol type based on the parsing plugin; a data packet decryption module 15 for decrypting the VPN breakthrough network data packets using the decryption key and outputting VPN plaintext data packets at multiple ends.

[0070] Furthermore, the combined feature extraction module 12 in the multi-protocol fast recognition system for VPN breakthrough network data is further used for: By analyzing the five-tuple information of the VPN breakthrough network data packets, traffic characteristics for fingerprint modeling are extracted. The traffic characteristics include packet size, transmission delay, packet interval, data traffic pattern, and port number. By analyzing the temporal behavior information of the VPN breakthrough network data packets, behavior characteristics of the modeled communication are extracted. The behavior characteristics include communication connection characteristics, communication duration, data flow direction, connection retry behavior, and uplink / downlink paths.

[0071] Furthermore, the protocol type recognition module 13 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: Initialize a combined recognition model, where the initialized combined recognition model is a dual-channel protocol recognition architecture; generate protocol training sample data, which includes known VPN protocol data samples and corresponding combined feature samples of the known VPN protocol data samples, and disguised VPN multi-protocol data samples and corresponding combined feature samples of the disguised VPN multi-protocol data samples. Among them, the combined feature samples include traffic feature samples and behavior feature samples; perform dual-channel training on the initialized combined recognition model according to the protocol training sample data, and output a multi-protocol combined recognition model.

[0072] Furthermore, the protocol type recognition module 13 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: The multi-protocol combined recognition model includes a protocol classification channel trained based on a lightweight neural network and a protocol classification channel trained based on a temporal neural network. Among them, the protocol classification channel trained based on the lightweight neural network performs protocol type recognition on the traffic characteristics of the VPN breakthrough network data packets and outputs a first protocol type recognition result. The protocol classification channel trained based on the temporal neural network performs protocol type recognition on the behavior characteristics of the VPN breakthrough network data packets and outputs a second protocol type recognition result.

[0073] Furthermore, the protocol type recognition module 13 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: When the first protocol type recognition result and the second protocol type recognition result are inconsistent, label the VPN breakthrough network data packet as disguised VPN breakthrough network data; extract high-dimensional combined features from the disguised VPN breakthrough network data, where the high-dimensional combined features include high-dimensional traffic features and high-dimensional behavior features, and the feature convolution scale of the high-dimensional combined features is smaller than that of the combined features; perform feature credibility evaluation on the high-dimensional traffic features and the high-dimensional behavior features, and output traffic feature credibility and behavior feature credibility; decrypt the disguised VPN breakthrough network data by calling a parsing plugin by comparing the traffic feature credibility and the behavior feature credibility.

[0074] Furthermore, the protocol type identification module 13 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: If the credibility of the traffic feature is greater than or equal to the credibility of the behavior feature, call the parsing plugin according to the first protocol type to decrypt the disguised VPN breakthrough network data; if the credibility of the traffic feature is less than the credibility of the behavior feature, call the parsing plugin according to the second protocol type to decrypt the disguised VPN breakthrough network data.

[0075] Furthermore, the plugin parsing module 14 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: Call the parsing plugin according to the output protocol type, and the parsing plugin is obtained by calling through the parsing plugin management module. The parsing plugin management module includes multiple parsing plugins, and each parsing plugin corresponds to a protocol type; wherein, the parsing plugin has a built-in protocol feature library and a key derivation rule for deriving the corresponding decryption key according to the protocol type.

[0076] Furthermore, the data packet decryption module 15 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: The VPN plaintext data packet is output through multiple output ports in a multi-terminal manner, wherein the multiple output ports are connected to a configuration switch; the configuration switch is used to filter the VPN plaintext data packet to obtain the filtered VPN plaintext data packet.

[0077] Furthermore, the data packet decryption module 15 in the multi-protocol rapid identification system for VPN breakthrough network data is further configured to: Detect the real-time load status of the multiple output ports to generate multiple real-time load metrics; sort the multiple real-time load metrics in descending order of the metric size to generate an output port queue list. When the VPN plaintext data packet is obtained, output the VPN plaintext data packet according to the first output port in the output port queue list, and update the output port queue list at the same time.

[0078] The various embodiments in this specification are described in a progressive manner, and the key point of each embodiment is to illustrate the differences from other embodiments. The multi-protocol rapid identification method and specific examples for VPN breakthrough network data in the foregoing Figure 1 The multi-protocol rapid identification method and specific examples for VPN breakthrough network data in Embodiment 1 are equally applicable to the multi-protocol rapid identification system for VPN breakthrough network data in this embodiment. Through the foregoing detailed description of the multi-protocol rapid identification method for VPN breakthrough network data, those skilled in the art can clearly know the multi-protocol rapid identification system for VPN breakthrough network data in this embodiment. Therefore, for the sake of brevity of the specification, it will not be elaborated herein.

[0079] The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0080] Obviously, those skilled in the art can also make several improvements and modifications to the present application without departing from the principles of the present application, and these improvements and modifications also fall within the protection scope of the present application.

Claims

1. A multi-protocol rapid identification method for VPN burst data, characterized in that: include: Collect VPN packets from the target network using multiple collection terminals; Extracting the combined features of the VPN burst data packets, wherein the combined features include flow features for fingerprint modeling and behavior features for modeling communication; Setting a multi-protocol combination identification model, and performing protocol type identification on the combination features of the VPN burst network data packet according to the multi-protocol combination identification model, to obtain a first protocol type identification result and a second protocol type identification result; When the first protocol type identification result and the second protocol type identification result are consistent, calling the parsing plug-in according to the output protocol type, and parsing the decryption key corresponding to the protocol type based on the parsing plug-in; The VPN burst data packet is decrypted using the decryption key, and multiple terminals output the VPN plaintext data packet.

2. The multi-protocol rapid identification method for VPN burst data according to claim 1, characterized in that: Extracting the combined features of the VPN burst data packet includes: By analyzing the five-tuple information of the VPN burst data packet, the traffic features for fingerprint modeling are extracted, wherein the traffic features include data packet size, transmission delay, data packet interval, data traffic mode and port number; By analyzing the timing behavior information of the VPN burst data packets, the behavior characteristics of the modeled communication are extracted, and the behavior characteristics include communication connection characteristics, communication duration, data flow direction, connection retry behavior and uplink and downlink paths.

3. The multi-protocol rapid identification method for VPN burst data according to claim 1, characterized in that: The VPN plaintext data packet is output through multiple output ports, wherein the multiple output ports are connected to a configuration switch; The VPN plaintext data packet is filtered using the configuration switch to obtain the filtered VPN plaintext data packet.

4. The multi-protocol rapid identification method for VPN burst data according to claim 3, characterized in that: The VPN plaintext data packet is output through multiple output ports, and further includes: Detecting the real-time load status of the multiple output ports and generating multiple real-time load indicators; Arrange the multiple real-time load indicators in descending order according to their index sizes, generate an output port queue table, and after obtaining a VPN plaintext data packet; The VPN plaintext data packet is output according to the first-order output port in the output port queue table, and the output port queue table is updated at the same time.

5. The multi-protocol rapid identification method for VPN burst data according to claim 1, characterized in that: According to the multi-protocol combination identification model, the combined features of the VPN burst network data packet are respectively identified by protocol type, and a first protocol type identification result and a second protocol type identification result are obtained, including: The multi-protocol combination identification model includes a protocol classification channel based on lightweight neural network training and a protocol classification channel based on temporal neural network training; Among them, the protocol classification channel based on lightweight neural network training performs protocol type identification on the traffic characteristics of the VPN sudden network data packet and outputs a first protocol type identification result, and the protocol classification channel based on timing neural network training performs protocol type identification on the behavioral characteristics of the VPN sudden network data packet and outputs a second protocol type identification result.

6. The multi-protocol rapid identification method for VPN burst data according to claim 5, characterized in that: Set up a multi-protocol combination recognition model, including: Initialize a combined recognition model, wherein the initialization combined recognition model is a dual-channel protocol recognition architecture; Generate protocol training sample data, wherein the protocol training sample data includes a known VPN protocol data sample and a combined feature sample corresponding to the known VPN protocol data sample, and a disguised VPN multi-protocol data sample and a combined feature sample corresponding to the disguised VPN multi-protocol data sample; Wherein, the combined feature sample includes a flow feature sample and a behavior feature sample; The initialized combination recognition model is dual-channel trained according to the protocol training sample data to output a multi-protocol combination recognition model.

7. The multi-protocol rapid identification method for VPN burst data according to claim 1, characterized in that: When the first protocol type identification result and the second protocol type identification result are inconsistent, marking the VPN burst data packet as camouflaged VPN burst data; Extracting high-dimensional combined features from the disguised VPN burst data, wherein the high-dimensional combined features include high-dimensional flow features and high-dimensional behavior features, and the feature convolution scale of the high-dimensional combined features is smaller than the convolution scale of the combined features; Performing feature credibility evaluation on the high-dimensional traffic feature and the high-dimensional behavior feature, and outputting traffic feature credibility and behavior feature credibility; By comparing the credibility of the traffic feature and the credibility of the behavior feature, the parsing plug-in is called to decrypt the disguised VPN network data.

8. The multi-protocol rapid identification method for VPN burst data according to claim 7, characterized in that: By comparing the credibility of the traffic feature and the credibility of the behavior feature, calling the parsing plug-in to decrypt the disguised VPN network data, including: If the credibility of the traffic feature is greater than or equal to the credibility of the behavior feature, calling the parsing plug-in according to the first protocol type to decrypt the disguised VPN network data; If the credibility of the traffic feature is less than the credibility of the behavior feature, the parsing plug-in is called according to the second protocol type to decrypt the disguised VPN network data.

9. The multi-protocol rapid identification method for VPN burst data according to claim 1, characterized in that: Calling a parsing plug-in according to the output protocol type, the parsing plug-in is acquired by calling a parsing plug-in management module, the parsing plug-in management module includes a plurality of parsing plug-ins, each parsing plug-in corresponds to a protocol type; The parsing plug-in has a built-in protocol feature library and key derivation rules, which are used to derive the corresponding decryption key according to the protocol type.

10. A multi-protocol rapid identification system for VPN burst data, characterized in that: The method for implementing the multi-protocol rapid identification method for VPN burst data according to any one of claims 1 to 9, the multi-protocol rapid identification system for VPN burst data comprises: The data packet collection module is used to collect VPN burst data packets from the target network using multiple collection terminals; A combined feature extraction module, used to extract the combined features of the VPN burst data packets, wherein the combined features include flow features for fingerprint modeling and behavior features for modeling communication; A protocol type identification module, used to set a multi-protocol combination identification model, and perform protocol type identification on the combination features of the VPN burst network data packet according to the multi-protocol combination identification model to obtain a first protocol type identification result and a second protocol type identification result; A plug-in parsing module, configured to call a parsing plug-in according to the outputted protocol type when the first protocol type identification result and the second protocol type identification result are consistent, and parse a decryption key corresponding to the protocol type based on the parsing plug-in; The data packet decryption module is used to decrypt the VPN burst data packet using the decryption key and output the VPN plaintext data packet at multiple ends.

Citation Information

Patent Citations

  • Data flow type identification method and related equipment

    CN112511457A

  • Encrypted traffic protocol identification method and device based on automatic machine learning

    CN112671757A

  • Mobile application encryption protocol message type analysis method and system

    CN115277888A

  • Internet of Things protocol automatic identification system and method based on data model

    CN119299538A

  • Protocol identification method and device for accessing distributed power supply to power grid, medium and terminal

    CN119341959A