TLS Fingerprint Generation Method, Apparatus, Device, and Medium Based on Merkle Tree

Through the Merkel tree-based TLS fingerprint generation method, the problem of insufficient existing TLS fingerprint expression capabilities is solved, and more refined TLS information expression and higher reliability of network security analysis are achieved.

CN120150928BActive Publication Date: 2025-07-22PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510630221.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-07-22
Estimated Expiration
2045-05-16

AI Technical Summary

Technical Problem

The existing TLS fingerprint generation methods have insufficient feature dimensions and limited expression capabilities, which make them very susceptible to forgery and counterfeiting by attackers, which in turn affects the reliability of network security analysis operations.

Method used

The TLS fingerprint generation method based on Merkel tree is adopted, and a TLS configuration tree with a binary tree structure is constructed by classifying multiple TLS information, calculating the hash value layer by layer, and finally generating the unique root node hash value as the target TLS fingerprint.

Benefits of technology

It improves the expression ability of TLS fingerprints, enhances the reliability of network security analysis operations, and can express the content of multiple TLS information more accurately and detects tampering behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150928B_ABST
    Figure CN120150928B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method, device, equipment, and medium for generating a TLS fingerprint based on a Merkle tree, belonging to the field of network security technology. The method includes: classifying a plurality of acquired TLS information to obtain the category information of each TLS information and the classification chain information, where the classification chain information includes the hierarchical categories sequentially associated with the category information at each level; constructing a TLS configuration tree with a binary tree structure including a plurality of target nodes, and selecting target levels one by one, and selecting two adjacent target nodes in the target level, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculating the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated to obtain the target TLS fingerprint corresponding to the target system. The present application can improve the expression ability of the generated TLS fingerprint, and further improve the reliability of related network security analysis operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and in particular, to a method, apparatus, device, and medium for generating TLS fingerprints based on Merkle trees. Background Art

[0002] A Transport Layer Security (TLS) fingerprint is a unique identifier generated by analyzing specific parameters used by a client or server during the TLS handshake process. TLS fingerprints can be used to identify different software versions, operating systems, or configurations, and thus enable a series of network security analysis operations.

[0003] In related technologies, TLS information (such as protocol version, cipher suite, extension type, etc.) collected from a client or server is combined into a string according to a predetermined rule, and then a hash function is applied to this string, and the output fixed-length hash value is used as the TLS fingerprint. However, the TLS fingerprint obtained by this method is a single and indivisible identifier, which has the problems of insufficient feature dimensions and limited expressive ability, and cannot cover enough TLS differentiation information. Therefore, it is extremely easy to be forged and counterfeited by attackers, and thus the reliability of related network security analysis operations using this TLS fingerprint is low. Summary of the Invention

[0004] The main objective of the embodiments of this application is to propose a method, apparatus, device, and medium for generating TLS fingerprints based on Merkle trees, aiming to improve the expressive ability of the generated TLS fingerprints, and thus improve the reliability of related network security analysis operations.

[0005] To achieve the above objective, a first aspect of the embodiments of this application proposes a method for generating TLS fingerprints based on Merkle trees, including:

[0006] Obtain multiple TLS information of a target system;

[0007] Perform classification processing on the multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level;

[0008] Based on the classification chain information, construct a TLS configuration tree with a binary tree structure, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes. Determine the initial hash value of each bottom node according to at least one TLS information under the same classification chain information;

[0009] Select target levels one by one, and select two adjacent target nodes in the target levels, where the level categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the level category in the upper level according to the two target hash values corresponding to the two target nodes, until a unique root node hash value is generated, and obtain the target TLS fingerprint corresponding to the target system. The initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value.

[0010] In some embodiments, classifying a plurality of TLS information to obtain category information of each TLS information, including:

[0011] Parse any TLS information to obtain the functional fields corresponding to the TLS information;

[0012] Match the functional fields with a plurality of predefined first initial information to determine the matched first initial information as the category information corresponding to the TLS information, where the first initial information at least includes protocol version information, cipher suite information, certificate chain information, and extended sequence information.

[0013] In some embodiments, determining corresponding classification chain information based on the category information, including:

[0014] Match the category information with a plurality of predefined second initial information to determine the matched second initial information as the level category of the upper level to which the category information belongs, where the second initial information at least includes TLS basic information, TLS extension information, TLS certificate information, and TLS configuration information;

[0015] Take the level category as the new category information and repeat the matching until the second initial information representing the boundary is matched, and obtain the classification chain information.

[0016] In some embodiments, based on the classification chain information, construct a TLS configuration tree in a binary tree structure with the same category information as the bottom nodes and the level categories as the nodes at different levels above the bottom nodes, including:

[0017] Based on the classification chain information, construct an initial TLS configuration tree in a tree structure with the same category information as the bottom nodes and the level categories as the nodes at different levels above the bottom nodes, where the initial TLS configuration tree includes a plurality of target nodes;

[0018] Traverse the initial TLS configuration tree to determine the number of child nodes of each target node;

[0019] If the number of child nodes of any one is not equal to the specified number of the level, add a preset null value node to the corresponding target node;

[0020] When the number of child nodes of all target nodes meets the requirements of the binary tree structure, a TLS configuration tree is obtained.

[0021] In some embodiments, determining the initial hash value of each underlying node according to at least one TLS information under the same classification chain information includes:

[0022] Obtain a normalization rule table and a hash function;

[0023] According to the normalization rule table, convert at least one TLS information under the same classification chain information into a corresponding feature string, and splice all feature strings to obtain a TLS string;

[0024] Calculate the hash value of each TLS string based on the hash function, and use the hash value of the TLS string as the initial hash value of the corresponding underlying node.

[0025] In some embodiments, after determining the initial hash value of each underlying node according to at least one TLS information under the same classification chain information, it further includes:

[0026] Obtain a security policy table, and determine the initial security value of each TLS information based on the security policy table;

[0027] Determine the initial security label of the corresponding target node according to the initial security value of at least one TLS information under the same classification chain information;

[0028] Select the target level one by one, and select two adjacent target nodes in the target level, where the level categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the level category in the upper level according to the two target hash values corresponding to the two target nodes, and determine the security label corresponding to the target node in the upper level according to the security labels of the two target nodes;

[0029] When a unique root node hash value is generated, the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the underlying node is located, the initial value of the target node is the underlying node, the initial value of the target hash value is the initial hash value, and the initial value of the security label is the initial security label.

[0030] In some embodiments, determining the initial security label of the corresponding target node according to the initial security value of at least one TLS information under the same classification chain information includes:

[0031] Obtain a default label, where the default label includes a preset number of label bits arranged in a fixed order;

[0032] Select dynamic tag bits from multiple tag bits according to the classification chain information, and update the dynamic tag bits to obtain updated tag bits according to the security state characterized by the initial security values of at least one TLS information under the same classification chain information;

[0033] Update the default tag based on the updated tag bits to obtain the initial security tags of each target node.

[0034] To achieve the above object, a second aspect of the embodiments of the present application proposes a TLS fingerprint generation device based on a Merkle tree, including:

[0035] An acquisition module, configured to acquire multiple TLS information of a target system;

[0036] A classification processing module, configured to perform classification processing on multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated at each level of the category information;

[0037] A TLS configuration tree determination module, configured to construct a TLS configuration tree with a binary tree structure based on the classification chain information, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, and determine the initial hash value of each bottom node according to at least one TLS information under the same classification chain information;

[0038] A target TLS fingerprint generation module, configured to select target levels one by one, and select two adjacent target nodes in the target levels, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated, and obtain the target TLS fingerprint corresponding to the target system. The initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value.

[0039] To achieve the above object, a third aspect of the embodiments of the present application proposes an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the above-mentioned Merkle tree-based TLS fingerprint generation method in the first aspect.

[0040] To achieve the above object, a fourth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned Merkle tree-based TLS fingerprint generation method in the first aspect.

[0041] The TLS fingerprint generation method, device, equipment, and medium based on Merkle tree proposed in this application obtain multiple TLS information of the target system; classify the multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level; based on the classification chain information, a TLS configuration tree with a binary tree structure is constructed with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes. According to at least one TLS information under the same classification chain information, the initial hash value of each bottom node is determined; the target level is selected one by one, and two adjacent target nodes in the target level are selected, where the hierarchical categories corresponding to the target nodes in the upper level are the same; the target hash value of the target node corresponding to the hierarchical category in the upper level is calculated according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated, and the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value. This application uses the Merkle tree with a multi-level relationship as the target TLS fingerprint corresponding to the target system. Compared with the fingerprint obtained by simple hashing in the traditional method, the target TLS fingerprint under the Merkle tree structure obtained in the embodiments of this application can express the content of multiple TLS information more precisely, thereby improving the expression ability of the target TLS fingerprint, and further helping to improve the reliability of related network security analysis operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 FIG. is a schematic diagram of an optional implementation environment of a TLS fingerprint generation device based on Merkle tree provided in an embodiment of this application;

[0043] Figure 2 FIG. is a schematic diagram of an optional device module of a TLS fingerprint generation device based on Merkle tree provided in an embodiment of this application;

[0044] Figure 3 FIG. is an optional flowchart of a TLS fingerprint generation method based on Merkle tree provided in an embodiment of this application;

[0045] Figure 4 is Figure 3 An optional implementation flowchart of step 102 in;

[0046] Figure 5 is Figure 3 Another optional implementation flowchart of step 102 in;

[0047] Figure 6It is a schematic diagram of an optional initial TLS configuration tree for the TLS fingerprint generation method provided by an embodiment of the present application;

[0048] Figure 7 It is Figure 3 An optional implementation flowchart of step 103 in

[0049] Figure 8 It is a schematic diagram of an optional TLS configuration tree construction for the TLS fingerprint generation method provided by an embodiment of the present application;

[0050] Figure 9 It is Figure 3 Another optional implementation flowchart of step 103 in

[0051] Figure 10 It is Figure 3 Another optional implementation flowchart of step 103 in

[0052] Figure 11 It is a schematic diagram of an optional Merkle tree construction for the TLS fingerprint generation method provided by an embodiment of the present application;

[0053] Figure 12 It is Figure 10 An optional implementation flowchart of step 103.3.2 in

[0054] Figure 13 It is another optional schematic diagram of device modules for the TLS fingerprint generation device provided by an embodiment of the present application;

[0055] Figure 14 It is a schematic diagram of the hardware structure of the electronic device provided by an embodiment of the present application. Detailed implementation manners

[0056] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0057] It should be noted that although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from the module division in the device or the order in the flowchart. The terms "first", "second", etc. in the description, claims and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.

[0058] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used herein are for the purpose of describing embodiments of this application only and are not intended to limit this application.

[0059] A TLS fingerprint is a unique identifier generated by analyzing specific parameters used by a client or server during a TLS handshake. TLS fingerprints can be used to identify different software versions, operating systems, or configurations, thereby enabling a series of network security analysis operations.

[0060] In related technologies, TLS information (such as protocol version, cipher suite, extension type, etc.) collected from a client or server is combined into a string according to a predetermined rule, and then a hash function is applied to this string, and the output fixed-length hash value is used as the TLS fingerprint. However, the TLS fingerprint obtained by this method is a single, indivisible identifier, which has the problems of insufficient feature dimensions and limited expressive ability, and is thus extremely easy to be forged and counterfeited by attackers, resulting in low reliability of related network security analysis operations using this TLS fingerprint.

[0061] Based on this, the embodiments of this application provide a method, apparatus, device, and medium for generating a TLS fingerprint based on a Merkle tree, aiming to improve the expressive ability of the generated TLS fingerprint, and thus improve the reliability of related network security analysis operations.

[0062] Exemplarily, as Figure 1 shown, Figure 1FIG. 0 is a schematic diagram of an optional implementation environment of a TLS fingerprint generation device based on a Merkle tree provided by an embodiment of the present application. The implementation environment includes a client 11 and a server 12, where the client 11 and the server 12 are communicatively connected. When data transmission is required between the client 11 and the server 12, in order to ensure the security of data transmission, it is necessary to collect TLS fingerprints so as to perform security analysis on the TLS information represented by the TLS fingerprints. In response to this situation, the TLS fingerprint generation device based on a Merkle tree proposed by the embodiment of the present application (for the convenience of description, hereinafter may also be simply referred to as the "fingerprint generation device") will perform the following operation steps: obtaining a plurality of TLS information of a target system; classifying the plurality of TLS information to obtain category information of each TLS information, and determining corresponding classification chain information based on the category information, where the classification chain information includes the hierarchical categories sequentially associated with the category information at each level; based on the classification chain information, constructing a TLS configuration tree in a binary tree structure with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, and determining the initial hash value of each bottom node according to at least one TLS information under the same classification chain information; selecting a target level one by one, and selecting two adjacent target nodes in the target level, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculating the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated, obtaining the target TLS fingerprint corresponding to the target system, where the initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value, where the target system may be the client 11 or the server 12. In this way, the hierarchical tree structure of the target TLS fingerprint realizes the efficient organization and accurate expression of a plurality of TLS information, thereby helping to improve the reliability of related network security analysis operations.

[0063] Among them, the server 12 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery network (Content Delivery Network, CDN), and big data and artificial intelligence platforms. In addition, the server 12 may also be a node server in a blockchain network. The client 11 may be a mobile phone, a computer, a smart voice interaction device, a smart wearable device, a smart home appliance, a vehicle-mounted terminal, etc., but is not limited thereto. The client 11 and the server 12 may be directly or indirectly connected through wired or wireless communication methods, and the embodiments of the present application do not make limitations here.

[0064] It should be noted that in the embodiments of the present application, when it comes to information related to user characteristics such as user basic information or user identity, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of the present application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained first. After clearly obtaining the user's separate permission or separate consent, the necessary data for the normal operation of the embodiments of the present application will be obtained. For example, before the embodiments of the present application obtain multiple TLS information of the target system, the authorization or consent of the relevant personnel of the target system will be obtained first, otherwise, multiple TLS information that cannot be applied to the embodiments of the present application will be obtained. In addition, other relevant data obtained by the fingerprint generation device of the present application are all authorized data, which will not be elaborated here one by one.

[0065] In some embodiments, as Figure 2 shown, Figure 2 is an optional schematic diagram of device modules of the TLS fingerprint generation device based on the Merkle tree provided by the embodiments of the present application. The fingerprint generation device mainly includes two modules:

[0066] (1)TLS Information Collection Module

[0067] First, the client and the server establish interactions such as TLS handshake connections and TLS certificate verification. As Figure 2 shown, the client first sends a ClientHello message to the server to indicate that it wants to establish a secure connection and provide information such as the encryption algorithms it supports. Then, the server responds with a ServerHello message. Next, the client sends a certificate to the server to prove its identity, and the server responds with a CertificateVerify message after verifying the certificate, thereby establishing a secure environment between the client and the server, and extracting multiple TLS information during the interaction between the two, such as TLS version, cipher suite, TLS extension, and certificate chain.

[0068] Among them, obtaining multiple TLS information of the target system can be achieved through two methods:

[0069] <1>Active method, which refers to the process of directly establishing a TLS connection with the target system using a scanning tool or program to obtain the TLS information of the target system. Among them, the scanning tool can be OpenSSL (OpenSSL is an open-source software library package) or TestSSL (TestSSL is a command-line tool);

[0070] Exemplarily, assume that you want to evaluate the TLS versions and cipher suites supported by a certain website server. You can use tools such as OpenSSL to attempt to establish a TLS connection with the website server and collect multiple TLS information of the website server during this process.

[0071] <2>Passive method. The passive method does not require direct interaction with the target system, but analyzes the TLS information contained in the network traffic by listening. This method is applicable to existing communication flows and does not require initiating new connection requests;

[0072] Exemplarily, assume that a monitoring tool is deployed in an enterprise network. This monitoring tool can capture all data packets entering and leaving the enterprise network. By analyzing these data packets, especially those based on the TLS protocol, relevant TLS information can be obtained. Among them, the monitoring tool can be TCPDUMP (TCPDUMP is a command-line network packet capture tool), Wireshark (Wireshark is a graphical interface network protocol analyzer), etc.

[0073] It should be noted that the specific method for obtaining multiple TLS information of the target system can be set according to the actual situation, and the specific tool for obtaining TLS information can also be selected according to the actual situation. The embodiments of the present application do not limit this.

[0074] (2) Target TLS fingerprint construction module

[0075] Next, after completing the collection of TLS information, classify multiple TLS information, including classification to construct a TLS configuration tree. Among them, the TLS configuration tree includes multiple target nodes; then, determine the hash value corresponding to each target node; then, construct a Merkle tree based on the TLS configuration tree and use the Merkle tree as the target TLS fingerprint of the target system.

[0076] After understanding the general working process of the fingerprint generation device, the embodiments of the present application will continue to describe in depth from the dimension of the fingerprint generation device, and the beneficial effects of the TLS fingerprint generation method based on the Merkle tree applied to the fingerprint generation device (for the convenience of description, hereinafter may also be simply referred to as "fingerprint generation method") will gradually emerge. Among them, the fingerprint generation device can be integrated in a computer device, such as a server. As Figure 3 shown, Figure 3 is an optional flowchart of the TLS fingerprint generation method based on the Merkle tree provided by the embodiments of the present application, Figure 3 The flowchart shown may include but is not limited to the following steps 101 to step 104. The specific process of the fingerprint generation device when executing the fingerprint generation method is as follows. It should be noted first that this embodiment Figure 3The order of steps 101 to 104 is not specifically limited and can be adjusted according to actual needs, or some steps can be reduced or added.

[0077] Step 101: Obtain multiple TLS information of the target system.

[0078] The following is a detailed description of step 101.

[0079] Among them, TLS information refers to various parameters and data involved in the communication process using the TLS protocol. TLS information includes, but is not limited to, content such as encryption algorithms, certificate information, and protocol versions. The target system refers to the system that generates the target TLS fingerprint, and the target system can be a server, a network device, or an application program, etc.

[0080] Furthermore, the embodiments of the present application will obtain multiple TLS information of the target system as detailed as possible. Exemplarily, when the target system establishes a TLS handshake with other systems based on the Internet Protocol Address (IP address) or domain name, and during the verification based on relevant certificates, the fingerprint generation device will collect multiple TLS information from these two processes as the basis for constructing the Merkle tree subsequently.

[0081] Furthermore, as shown in Table 1, Table 2, and Table 3 below, common relevant TLS information is listed. Among them, Table 1 is an optional example table of TLS information provided by the embodiments of the present application, Table 2 is an optional example table of certificate chain information provided by the embodiments of the present application, and Table 3 is an optional example table of extended sequence information provided by the embodiments of the present application:

[0082] Table 1

[0083]

[0084] Continued Table 1

[0085]

[0086] Table 2

[0087]

[0088] Table 3

[0089]

[0090] It should be noted that Table 1, Table 2, and Table 3 are only for illustrative purposes, and the specific TLS information of the target system obtained by the fingerprint generation device can be set according to the actual situation. It should also be noted that in order to simplify the generation and subsequent processing of TLS fingerprints, the traditional method does not include certificate configuration information in the obtained TLS information, resulting in insufficient feature dimensions and limited expression ability of the TLS fingerprints generated by the traditional method, which are extremely vulnerable to forgery and imitation by attackers in actual applications, thus threatening relevant network security operations. In contrast, the fingerprint generation device of the embodiment of the present application obtains as comprehensive TLS information as possible, especially the certificate configuration information related to the certificate, so as to construct a target TLS fingerprint with strong expression ability based on multiple TLS information in multiple aspects and dimensions later.

[0091] Step 102: Classify multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level.

[0092] The following provides a detailed description of step 102.

[0093] Among them, the category information refers to the identifier or attribute obtained after classifying the TLS information, which reflects the characteristics and nature of the TLS information; the classification chain information describes the complete path of a TLS information in the tree-like classification system, reflecting the logical attribution relationship of each TLS information from the bottom to the top in the system. The classification chain information includes the category information and at least one hierarchical category; the hierarchical category is used to represent the classification criteria or characteristics at different levels above the category information.

[0094] Furthermore, in the embodiment of the present application, by classifying multiple TLS information, each TLS information is classified into a specific category, and the classification chain information is constructed based on these category information, so as to form a target TLS fingerprint under the binary tree structure according to the classification chain information and the category information later.

[0095] In some embodiments, as Figure 4 shown, Figure 4 is Figure 3 An optional implementation flowchart of step 102 in

[0096] 102.1.1 Parse any TLS information to obtain the function fields corresponding to the TLS information;

[0097] 102.1.2 Match the function field with multiple predefined first initial information, and determine that the matched first initial information is the category information corresponding to the TLS information. The first initial information at least includes protocol version information, cipher suite information, certificate chain information, and extension sequence information.

[0098] The following provides a detailed description of steps 102.1.1 to 102.1.2.

[0099] Among them, the function field is a keyword field extracted from the TLS information, which can reflect the characteristics and functions of the corresponding TLS information. Based on the function field, multiple TLS information can be classified; the first initial information refers to the predefined category to which the TLS information belongs.

[0100] Exemplarily, a certain TLS information is obtained as TLSv1.3; the function field of this TLS information is parsed as TLSv; the function field TLSv is matched with multiple predefined first initial information, and it is determined that the category information to which this TLS information belongs is "protocol version information".

[0101] Furthermore, to implement the fingerprint generation method proposed in the embodiments of the present application, the predefined first initial information at least includes the following:

[0102] (1) Protocol version information (TLS version): The protocol version information refers to the specific version number used in TLS communication, which indicates the adopted protocol standard and its characteristics, affects the selection of encryption algorithms and security, and there are differences in security and performance among different versions of the TLS protocol. Newer versions usually provide stronger security guarantees and higher efficiency.

[0103] (2) Cipher suite information (cipher suite): The cipher suite information refers to the combination of encryption algorithms negotiated during the TLS handshake, which determines the security and integrity of data transmission. Specifically, it can include symmetric encryption algorithms (Advanced Encryption Standard, AES), asymmetric encryption (Rivest-Shamir-Adleman Algorithm, RSA), and hash algorithm 256 (Secure Hash Algorithm 256-bit, SHA-256), etc.

[0104] (3) Certificate chain information (certificate chain): The certificate chain information refers to the certificate chain information provided by the target system to other systems or other devices during a communication connection. The certificate chain information usually includes a server certificate, one or more intermediate certificates, and a root certificate. The certificate chain information is used to verify the identity of the target system, ensure the legality of the connection, and prevent man-in-the-middle attacks.

[0105] (4)Extended Sequence Information (Extended Sequence): Extended sequence information is an optional extension field used during the TLS handshake process. It characterizes additional functions or parameters that the target system is allowed to use, such as supported compression algorithms, Server Name Indication (SNI), and Application-Layer Protocol Negotiation (ALPN). The extended sequence information makes the TLS protocol more flexible, capable of supporting various application scenarios and requirements, and enhancing the adaptability and functionality of the protocol.

[0106] It should be noted that the predefined first initial information may also include support signature information, shared key information, certificate validity period information, certificate revocation status, certificate public key information, certificate issuance information, etc. The specific content represented by the first initial information can be set according to the actual situation, and the embodiments of the present application do not limit this, so that the functional fields that can be parsed by the fingerprint generation device during actual operation can match the corresponding first initial information.

[0107] In some embodiments, as Figure 5 shown, Figure 5 is Figure 3 Another optional implementation flowchart of step 102 in

[0108] 102.2.1 Match the category information with multiple predefined second initial information, and determine the matched second initial information as the hierarchical category at the upper level to which the category information belongs. Among them, the second initial information at least includes TLS basic information, TLS extended information, TLS certificate information, and TLS configuration information;

[0109] 102.2.2 Use the hierarchical category as the new category information and repeat the matching until the second initial information characterized as the boundary is matched, and the classification chain information is obtained.

[0110] The following will describe steps 102.2.1 to 102.2.2 in detail.

[0111] Among them, the second initial information refers to another set of predefined, higher-level classification labels different from the first initial information, which reflects the information representation result obtained by logically aggregating the first initial information; determining the second initial information that matches the category information as the hierarchical category, and the hierarchical category is used to describe the higher-level features of the TLS information above the category information.

[0112] Furthermore, to implement the fingerprint generation method proposed in the embodiments of the present application, the predefined second initial information at least includes the following content:

[0113] (1)TLS basic information (corresponding to the basic configuration in Figure 6 ): TLS basic information refers to the most basic protocol parameters and features in a TLS connection. Moreover, the protocol version information and cipher suite information in the example category information of this application belong to TLS basic information.

[0114] (2)TLS extension information (corresponding to the extension configuration in Figure 6 ): TLS extension information refers to the optional extension fields negotiated during the TLS handshake process, which allows the client and server to support additional functions or parameters. Moreover, the extension sequence information in the example category information of this application belongs to TLS extension information.

[0115] (3)TLS certificate information (corresponding to the certificate configuration in Figure 6 ): TLS certificate information refers to the digital certificate and its related attributes associated with a TLS connection. Moreover, the certificate chain information in the example category information of this application belongs to TLS certificate information.

[0116] (4)TLS configuration information (corresponding to the TLS configuration in Figure 6 ): TLS configuration information refers to all parameters related to the TLS connection process. Moreover, the TLS basic information, TLS extension information, and TLS certificate information in the examples of this application belong to TLS configuration information; TLS configuration information is characterized as the end boundary of all classification chain information.

[0117] It should be noted that the predefined second initial information may further include key information, session resumption information, application layer protocol information, etc. The specific content represented by the second initial information can be set according to the actual situation, and this application example does not limit this, so that the fingerprint generation device can match the corresponding second initial information according to the category information to which the TLS information belongs during actual use.

[0118] Exemplarily, as Figure 6 shown, Figure 6 is a schematic diagram of an optional initial TLS configuration tree for the TLS fingerprint generation method based on the Merkle tree provided by the example of this application. Figure 6It is shown in the figure that the obtained TLS information a is "Version 1" and the TLS information b is "Cipher Suite 1"; based on steps 102.1.1 to 102.1.2, it is determined that the category information of TLS information a is "TLS Version", and the category information of TLS information b is "Cipher Suite"; then, the category information is matched with multiple predefined second initial information, and it is determined that the upper-level hierarchical categories of "TLS Version" and "Cipher Suite" are both "Basic Configuration"; then, the hierarchical category is used as the new category information and continues to be matched with multiple second initial information, and it is determined that the upper-level hierarchical category of "Basic Configuration" is "TLS Configuration" characterized as the boundary, and thus the classification chain information of TLS information a is "TLS Version - Basic Configuration - TLS Configuration", and the classification chain information of TLS information b is "Cipher Suite - Basic Configuration - TLS Configuration".

[0119] Moreover, hierarchical processing can be performed on multiple second initial information in advance so that steps 102.2.1 and 102.2.2 can match the corresponding-level second initial information. For example, in Figure 6 the example, "TLS Version" belongs to both "Basic Configuration" and "TSL Configuration", but the pre-processed hierarchical result restricts that the second initial information that can be matched with "TLS Version" is only basic information, certificate configuration, and extension configuration. Therefore, in this match, it will not be erroneously determined that the upper-level hierarchical category to which the category information belongs is "TLS Configuration".

[0120] Step 103, based on the classification chain information, with the same category information as the bottom-level node and the hierarchical category as the nodes at different levels above the bottom-level node, construct a TLS configuration tree in a binary tree structure, and determine the initial hash value of each bottom-level node according to at least one TLS information under the same classification chain information.

[0121] Step 104, select the target level one by one, and select two adjacent target nodes in the target level, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated, and the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the bottom-level node is located, the initial value of the target node is the bottom-level node, and the initial value of the target hash value is the initial hash value.

[0122] The following gives a detailed description of steps 103 and 104.

[0123] Among them, the binary tree structure is a tree-shaped data structure. The TLS configuration tree stipulates that each node has at most two child nodes, and the two child nodes are usually distinguished as the left child node and the right child node; moreover, the TLS configuration tree has a special node called the root node (without a parent node), and the node without child nodes is called the leaf node. Other nodes except the root node and the leaf node are called non-leaf nodes. Except for the root node, each node has a parent node.

[0124] Furthermore, the TLS configuration tree of the binary tree structure can cover more TLS information, thereby enhancing the expression ability of the target TLS fingerprint obtained subsequently, so that the target TLS fingerprint obtained based on the Merkle tree can be used for security analysis or data integrity verification in the future; at the same time, the target TLS fingerprint obtained based on the TLS configuration tree is also a binary tree structure, which enables relevant systems or devices to quickly retrieve the information contained in the target TLS fingerprint after obtaining the target TLS fingerprint.

[0125] Among them, the target level refers to the level at which the hash value is currently being calculated. The initial value of the target level is the level where the bottom-level nodes (leaf nodes) are located. The initial value of the target node is the bottom-level node, and the initial value of the target hash value is the initial hash value. In the tree-shaped data structure, the root node refers to the node without a parent node, and it is the top-level node of the entire tree structure. As Figure 6 shown, the root node of the TLS configuration tree is "TLS configuration".

[0126] Furthermore, the embodiments of the present application construct a Merkle tree by merging hash values layer by layer upward, and finally use the Merkle tree with a multi-level relationship as the target TLS fingerprint corresponding to the target system. Specifically, starting from the bottom layer of the TLS configuration tree, each time two adjacent nodes with the same parent node are selected, the hash values calculated by them are concatenated and then hashed again to obtain the hash value of the parent node; repeat this process until the root node hash value is calculated to form a complete Merkle tree structure.

[0127] Furthermore, compared with the fingerprint obtained by simple hashing in the traditional method, the target TLS fingerprint under the Merkle tree structure obtained in the embodiments of the present application can more finely express the content of multiple TLS information, thereby improving the expression ability of the target TLS fingerprint; at the same time, the characteristics of the Merkle tree make any modification of the TLS information will cause a change in the final fingerprint, which is convenient for subsequent effective detection of tampering behavior and improves the reliability of relevant network security operations.

[0128] In some embodiments, as Figure 7 shown, Figure 7 is Figure 3Step 103 in [document] is an optional implementation flowchart. Based on the classification chain information, a TLS configuration tree in a binary tree structure is constructed with the same category information as the bottom layer nodes and hierarchical categories as nodes at different levels above the bottom layer nodes, including the following steps:

[0129] 103.1.1 Based on the classification chain information, an initial TLS configuration tree in a tree structure is constructed with the same category information as the bottom layer nodes and hierarchical categories as nodes at different levels above the bottom layer nodes. Among them, the initial TLS configuration tree includes multiple target nodes;

[0130] 103.1.2 Traverse the initial TLS configuration tree to determine the number of child nodes of each target node;

[0131] 103.1.3 If the number of child nodes of any one is not equal to the specified number of the corresponding level, add a preset null value node to the corresponding target node;

[0132] 103.1.4 Until the number of child nodes of all target nodes meets the requirements of the binary tree structure, the TLS configuration tree is obtained.

[0133] The following gives a detailed description of steps 103.1.1 to 103.1.4.

[0134] In some embodiments, as Figure 6 shown, Figure 6 is an initial TLS configuration tree in a multi-tree structure with a depth of 4 constructed based on the obtained multiple TLS information. Among them, the multiple TLS information includes n versions, m suites, j certificates, and k extensions. The specific values represented by n, m, j, and k can be set according to actual situations. Specifically, the category information of "Version 1" is "TLS version", and the classification chain information of "Version 1" is "TLS version - Basic configuration - TLS configuration". The category information of "Version n" is "TLS version", and the classification chain information of "Version n" is also "TLS version - Basic configuration - TLS configuration". That is, "TLS version" is the same category information corresponding to the multiple TLS information. Therefore, "TLS version" is used as the bottom layer node, and the nodes at different levels above the category information are determined according to the classification chain information corresponding to "TLS version". In this example, the node at the upper level of "TLS version" is "Basic configuration", and the node at the upper level of "Basic configuration" is "TLS configuration". Similar operations are performed according to the category information and classification chain information corresponding to other TLS information, and the initial TLS configuration tree is obtained. Among them, each node in the initial TLS configuration tree is called a target node. For example, Figure 6 in [document], "TLS configuration", "Basic configuration", and "Certificate chain" are all target nodes.

[0135] Further, in order to ensure the balance of the finally obtained TLS configuration tree, "null nodes" ("NULL") may be introduced. Null nodes actually do not contain valid data, but are used to fill the tree positions that have not been assigned actual data due to insufficient data volume, so as to maintain the integrity and symmetry of the tree structure, thereby ensuring that the properties such as the height and hierarchical relationship of the finally generated TLS configuration tree meet the design requirements.

[0136] Specifically, check whether the initial TLS configuration tree meets the structural requirements of a binary tree, that is, each target node except the bottom layer nodes has exactly two child nodes. If the number of child nodes does not meet the requirements, add preset null nodes to the corresponding target nodes until a TLS configuration tree that meets the binary tree structural requirements is obtained.

[0137] Or, as Figure 8 shown, Figure 8 FIG. is an optional TLS configuration tree construction schematic diagram of the TLS fingerprint generation method based on the Merkle tree provided by the embodiment of the present application. First, it determines the height of the finally generated TLS configuration tree according to the data block characterized as "category information". For example, if the number N of category information is equal to 2 n (N≥2, n≥1, N = 2n), then a TLS configuration tree with a height of n + 1 can just be constructed; if the number of data blocks is not equal to 2 n , assuming N is less than 2 a and greater than or equal to 2 b (N≥1, a>b≥1, 2a>N≥2b), then (2a - N) null nodes ("NULL" data blocks) need to be supplemented so as to calculate the hash values of each data block later and then construct a TLS configuration tree with a height of (a + 1). Further, in order to improve data management efficiency, corresponding security labels can also be added to each data block.

[0138] In some embodiments, as Figure 9 shown, Figure 9 is Figure 3 Another optional implementation flowchart of step 103 in. Determine the initial hash value of each bottom layer node according to at least one TLS information under the same classification chain information, including the following steps:

[0139] 103.2.1 Obtain a standardization rule table and a hash function;

[0140] 103.2.2 According to the standardization rule table, convert at least one TLS information under the same classification chain information into a corresponding feature string, and splice all the feature strings to obtain a TLS string;

[0141] 103.2.3 Calculate the hash value of each TLS string based on the hash function, and use the hash value of the TLS string as the initial hash value of the corresponding underlying node.

[0142] The following describes steps 103.2.1 to 103.2.3 in detail.

[0143] Among them, the standardization rule table is a set of predefined rules for converting TLS information in different formats into a simplified and unified feature string. The hash function is a special function that maps data of any length to a fixed-length output value, which is usually called the hash value or digest value. The hash function can be the Message Digest Algorithm 5 (MD5), Secure Hash Algorithm 256 (SHA-256), etc. The embodiments of the present application do not limit the hash function selected in the actual application process.

[0144] Furthermore, as shown in Table 4, Table 4 is an optional standardization conversion example table provided by the embodiments of the present application, which exemplifies an optional standardization rule for TLS information. In actual application, the mapping rule from TLS information to the feature string can be adaptively set according to the actual situation, and the embodiments of the present application do not limit this.

[0145] Table 4

[0146]

[0147] Exemplarily, the classification chain information of "Version 1" to "Version n" is the same. Therefore, after converting "Version 1" to "Version n" into the corresponding feature strings, concatenate all the feature strings of "Version 1" to "Version n" to obtain the TLS string corresponding to "TLS version"; then, use the hash function to determine the hash value corresponding to this TLS string, and use this hash value as the initial hash value of the underlying node representing "TLS version".

[0148] In some embodiments, as Figure 10 shown, Figure 10 is Figure 3 Another optional implementation flowchart of step 103 in. After determining the initial hash value of each underlying node according to at least one TLS information under the same classification chain information, the following steps are further included:

[0149] 103.3.1 Obtain the security policy table and determine the initial security value of each TLS information based on the security policy table;

[0150] 103.3.2 Determine the initial security label of the corresponding target node according to the initial security value of at least one TLS information under the same classification chain information;

[0151] 103.3.3 Select the target levels one by one, and select two adjacent target nodes in the target level, where the level categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the level category in the upper level according to the two target hash values corresponding to the two target nodes, and determine the security label corresponding to the target node in the upper level according to the security labels of the two target nodes;

[0152] 103.3.4 Until the unique root node hash value is generated, obtain the target TLS fingerprint corresponding to the target system. The initial value of the target level is the level where the bottom node is located, the initial value of the target node is the bottom node, the initial value of the target hash value is the initial hash value, and the initial value of the security label is the initial security label.

[0153] The following gives a detailed description of steps 103.3.1 to 103.3.4.

[0154] Among them, the security policy table is a set of predefined rules and criteria for evaluating the security of each TLS information and helping to identify potential security risks. As shown in Table 5, Table 5 is an optional security policy example table provided by the embodiments of the present application:

[0155] Table 5

[0156]

[0157] It should be noted that Table 5 only shows some security identification rules. The actual security policy table contains more detailed and complex security identification rules. This is only an example for easy understanding and does not mean that the actual security identification rules are limited to Table 5.

[0158] Further, after determining the initial security values corresponding to each TLS information based on the security policy table, the initial security label of the corresponding target node will be determined according to the initial security values of at least one TLS information under the same classification chain information. Suppose that multiple obtained TLS information all belong to the target node characterized as "TLS version". When the initial security values of all TLS information under the "TLS version" target node are characterized as "secure", the initial security label corresponding to the "TLS version" target node is also characterized as "secure". Otherwise, as long as there is one initial security value characterized as "insecure", the initial security label of the "TLS version" target node is also characterized as "insecure". Of course, this is only an example of a feasible initial security label setting rule, and it can be adjusted according to the actual situation. For example, it is stipulated that only when the number of initial security values characterized as "insecure" under the same category of information reaches a certain number (greater than 1), the initial security label of the "TLS version" target node is characterized as "insecure".

[0159] In some embodiments, in addition to determining the target TLS fingerprint only according to the hash value corresponding to each TLS information, the target TLS fingerprint can also be determined in combination with the security label. As Figure 11 shown Figure 11 is an optional Merkle tree construction schematic diagram of the TLS fingerprint generation method based on the Merkle tree provided by the embodiment of the present application, Figure 11 which simply shows the construction process of a Merkle tree with a height of 4. Among them, Figure 11 A, B, C, D, E, F, G, H, I, J, K, L, M, N, O in are all target nodes. In particular, O is the root node; for any target node, it includes two parts: a hash value (Hash) and a security label (Label). Specifically, for the hash value part: perform a hash calculation on the "TLS string" or "NULL". If Hash(x) represents the hash value of a certain target node x, then for any pair of adjacent target nodes x1 and x2, the hash value of their father (upper layer) node x3 can be expressed as Hash(Hash(x1)+Hash(x2)), where "+" represents the string concatenation operation; taking the target node I in Figure 11 as an example, HashI=(HashA+HashB), HashM=(HashI+HashJ), HashO=(HashM+HashN). Furthermore, until a unique root node hash value is generated, the constructed Merkle tree is obtained, and this Merkle tree is used as the target TLS fingerprint corresponding to the target system, Figure 11 and the root node hash value in is "HashO".

[0160] Furthermore, for the security label part used to characterize the security attributes of target nodes: First, determine the initial security label corresponding to the underlying target node. Then, the security label of each non-leaf target node in the Merkle tree is obtained through a logical operation, namely the "AND operation", based on the security labels of its two child nodes. Specifically, if Label(y) represents the security label of a certain target node y, then for any pair of adjacent target nodes y1 and y2, the security label corresponding to their parent (upper-layer) node y3 can be expressed as Label(y1) & Label(y2), where "&" represents the "AND operation". For example, Figure 11 the security label of target node I in

[0161] is LabelA & LabelB, and the security label of target node O is LabelM & LabelN.

[0162] It can be understood that while the embodiments of the present application determine the hash values corresponding to each target node layer by layer, they also aggregate the security labels layer by layer upward to obtain the security labels reflecting the security status of each target node. In this way, the target TLS fingerprint can not only uniquely identify each TLS information but also reflect its security, facilitating subsequent security assessment and risk management, and thus more effectively identifying and responding to potential security threats.

[0163] In some embodiments, as Figure 12 shown, Figure 12 is Figure 10 an optional implementation flowchart of step 103.3.2 in

[0164] A.1 Obtain the default label, where the default label includes a preset number of label bits arranged in a fixed order;

[0165] A.2 Select dynamic tag bits from multiple tag bits according to the classification chain information, and update the dynamic tag bits to obtain updated tag bits according to the security state characterized by the initial security values of at least one TLS information under the same classification chain information;

[0166] A.3 Update the default tag based on the updated tag bits to obtain the initial security tags of each target node.

[0167] The following will describe steps A.1 to A.3 in detail.

[0168] Among them, the default tag is a predefined fixed-length binary tag, such as "00000000" which contains 8 tag bits. Each tag bit is arranged in a fixed order, and each tag bit corresponds to a type of security attribute. The value corresponding to each tag bit is used to identify the security state of the corresponding TLS information. Among them, the dynamic tag bits are the tag bits selected from the default tag. Different classification chain information corresponds to different dynamic tag bits to identify the security states of multiple TLS information under the same category information. For example, the last tag bit is used to identify the security state of the target node characterized as "TLS version".

[0169] In some embodiments, the security tag design scheme is shown in Table 6. Table 6 is an optional security tag design example table provided by the embodiments of the present application. Among them, in order to efficiently transmit security tags, a binary identification method can be adopted. Each bit (tag bit) starting from the end sequentially identifies the security of the TLS version, the security of the cipher suite, the security of the extension sequence, the security of the certificate signature algorithm, the security of the certificate status, and the security of the software (only for example, and does not represent that the embodiments of the present application limit this). For example, if the corresponding bit is 0, it means secure, and if it is 1, it means insecure. And this security tag design scheme can be extended according to different security requirements.

[0170] Table 6

[0171]

[0172] Continued Table 6

[0173]

[0174] As Figure 13 shown, Figure 13 is another optional schematic diagram of the device modules of the TLS fingerprint generation device based on the Merkle tree provided by the embodiments of the present application. The fingerprint generation device may include the following modules 201 to 204:

[0175] An acquisition module 201, configured to acquire multiple TLS information of a target system;

[0176] The classification processing module 202 is used to classify and process multiple TLS information, obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level.

[0177] The TLS configuration tree determination module 203 is used to construct a binary tree structure of the TLS configuration tree based on the classification chain information, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, and determine the initial hash value of each bottom node according to at least one TLS information under the same classification chain information.

[0178] The target TLS fingerprint generation module 204 is used to select the target levels one by one, and select two adjacent target nodes in the target levels, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes, until a unique root node hash value is generated, and the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value.

[0179] The TLS fingerprint generation method, device, equipment and medium based on the Merkle tree proposed in this application obtain multiple TLS information of the target system; classify and process the multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level; based on the classification chain information, construct a binary tree structure of the TLS configuration tree with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, and determine the initial hash value of each bottom node according to at least one TLS information under the same classification chain information; select the target levels one by one, and select two adjacent target nodes in the target levels, where the hierarchical categories corresponding to the target nodes in the upper level are the same; calculate the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes, until a unique root node hash value is generated, and the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the bottom nodes are located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value. In this application, the Merkle tree with a multi-level relationship is used as the target TLS fingerprint corresponding to the target system. Compared with the fingerprint obtained by simple hashing in the traditional method, the target TLS fingerprint under the Merkle tree structure obtained in the embodiments of this application can express the content of multiple TLS information more precisely, thereby improving the expression ability of the target TLS fingerprint, and further helping to improve the reliability of relevant network security analysis operations.

[0180] The specific implementation manner of the fingerprint generation device is basically the same as the specific embodiment of the above fingerprint generation method, and will not be described in detail here.

[0181] In addition, the embodiments of the present application can acquire and process relevant TLS information based on artificial intelligence technology. Among them, artificial intelligence (AI) uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, sense the environment, acquire knowledge, and use knowledge to obtain the best results in theory, methods, technologies, and application systems.

[0182] Furthermore, the basic technologies of artificial intelligence generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technologies, operation / interaction systems, and mechatronics. The software technologies of artificial intelligence mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0183] The fingerprint generation method provided by the embodiments of the present application also relates to the field of artificial intelligence technology. The fingerprint generation method provided by the embodiments of the present application can be applied to terminals, can also be applied to server sides, or can be software running on terminals or server sides. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc.; the server side can be configured as an independent physical server, can also be configured as a server cluster or distributed system composed of multiple physical servers, or can be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the fingerprint generation method, etc., but is not limited to the above forms.

[0184] This application can be used in many general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0185] An embodiment of this application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above fingerprint generation method is implemented. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.

[0186] As Figure 14 shown, Figure 14 is a schematic diagram of the hardware structure of the electronic device provided by an embodiment of this application. The electronic device includes:

[0187] A processor 301, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of this application;

[0188] A memory 302, which can be implemented in forms such as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 302 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 302 and are called by the processor 301 to execute the fingerprint generation method of the embodiments of this application;

[0189] An input / output interface 303, which is used to implement information input and output;

[0190] A communication interface 304, which is used to implement the communication interaction between this device and other devices. It can achieve communication through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);

[0191] A bus 305, which transmits information between various components of the device (such as a processor 301, a memory 302, an input / output interface 303, and a communication interface 304);

[0192] Among them, the processor 301, the memory 302, the input / output interface 303, and the communication interface 304 are communicatively connected to each other inside the device through the bus 305.

[0193] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above fingerprint generation method is implemented.

[0194] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely provided relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0195] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0196] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine some steps, or different steps.

[0197] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0198] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or a suitable combination thereof.

[0199] As used in the specification of this application and the above-mentioned drawings, the terms "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data may be interchanged under appropriate circumstances so that the embodiments of this application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0200] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or a similar expression means any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0201] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned unit division is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.

[0202] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0203] In addition, the functional units in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0204] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0205] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.

Claims

1. A method for generating TLS fingerprints based on a Merkle tree, characterized in that, Including: Obtain multiple TLS information of the target system; Classify and process the multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information. The classification chain information includes the hierarchical categories sequentially associated with the category information at each level; Based on the classification chain information, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, construct a TLS configuration tree in a binary tree structure, and determine the initial hash value of each bottom node according to at least one of the TLS information under the same classification chain information; Select a target level one by one, and select two adjacent target nodes in the target level, where the hierarchical categories corresponding to the target nodes in the upper level are the same; Calculate the target hash value of the target node corresponding to the hierarchical category in the upper level according to the two target hash values corresponding to the two target nodes until a unique root node hash value is generated, and obtain the target TLS fingerprint corresponding to the target system. The initial value of the target level is the level where the bottom node is located, the initial value of the target node is the bottom node, and the initial value of the target hash value is the initial hash value.

2. The TLS fingerprint generation method based on the Merkle tree according to claim 1, wherein, The classifying and processing the multiple TLS information to obtain the category information of each TLS information includes: Parse any one of the TLS information to obtain the function field corresponding to the TLS information; Match the function field with multiple predefined first initial information, and determine the matched first initial information as the category information corresponding to the TLS information, where the first initial information at least includes protocol version information, cipher suite information, certificate chain information, and extension sequence information.

3. The TLS fingerprint generation method based on Merkle tree according to claim 2, wherein The determining the corresponding classification chain information based on the category information includes: Match the category information with multiple predefined second initial information, and determine the matched second initial information as the hierarchical category of the upper level to which the category information belongs, where the second initial information at least includes TLS basic information, TLS extension information, TLS certificate information, and TLS configuration information; Use the hierarchical category as the new category information and repeat the matching until the second initial information characterized as the boundary is matched to obtain the classification chain information.

4. The TLS fingerprint generation method based on the Merkle tree according to claim 1, wherein The constructing a TLS configuration tree in a binary tree structure based on the classification chain information, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, includes: Based on the classification chain information, with the same category information as the bottom nodes and the hierarchical categories as the nodes at different levels above the bottom nodes, construct an initial TLS configuration tree in a tree structure, where the initial TLS configuration tree includes multiple target nodes; Traverse the initial TLS configuration tree to determine the number of child nodes of each target node; If the number of child nodes of any one is not equal to the specified number of the level where it is located, add a preset null value node to the corresponding target node; When the number of child nodes of all the target nodes meets the requirements of the binary tree structure, the TLS configuration tree is obtained.

5. The TLS fingerprint generation method based on Merkle tree according to claim 1, characterized in that, Determining the initial hash value of each of the bottom nodes according to at least one of the TLS information under the same classification chain information includes: Obtaining a normalization rule table and a hash function; According to the normalization rule table, converting at least one of the TLS information under the same classification chain information into corresponding feature strings, and concatenating all the feature strings to obtain a TLS string; Calculating the hash value of each TLS string based on the hash function, and taking the hash value of the TLS string as the initial hash value of the corresponding bottom node.

6. The TLS fingerprint generation method based on the Merkle tree according to claim 1, characterized in that After determining the initial hash value of each of the bottom nodes according to at least one of the TLS information under the same classification chain information, it further includes: Obtaining a security policy table, and determining the initial security value of each of the TLS information based on the security policy table; Determining the initial security label of the corresponding target node according to the initial security value of at least one of the TLS information under the same classification chain information; Selecting the target levels one by one, and selecting two adjacent target nodes in the target levels, where the target nodes have the same corresponding level category in the upper level; calculating the target hash value of the target node corresponding to the level category in the upper level according to the two target hash values corresponding to the two target nodes, and determining the security label corresponding to the target node in the upper level according to the security labels of the two target nodes; When a unique root node hash value is generated, the target TLS fingerprint corresponding to the target system is obtained, the initial value of the target level is the level where the bottom node is located, the initial value of the target node is the bottom node, the initial value of the target hash value is the initial hash value, and the initial value of the security label is the initial security label.

7. The TLS fingerprint generation method based on Merkle tree according to claim 6, wherein Determining the initial security label of the corresponding target node according to the initial security value of at least one of the TLS information under the same classification chain information includes: Obtaining a default label, where the default label includes a preset number of label bits arranged in a fixed order; Selecting dynamic label bits from the multiple label bits according to the classification chain information, and updating the dynamic label bits according to the security state characterized by the initial security value of at least one of the TLS information under the same classification chain information to obtain updated label bits; Updating the default label based on the updated label bits to obtain the initial security label of each of the target nodes.

8. A TLS fingerprint generation device based on a Merkle tree, characterized in that, It includes: An acquisition module, configured to acquire multiple TLS information of a target system; A classification processing module, configured to perform classification processing on the multiple TLS information to obtain the category information of each TLS information, and determine the corresponding classification chain information based on the category information, where the classification chain information includes the level categories sequentially associated with the category information at each level; The TLS configuration tree determination module is configured to construct a TLS configuration tree in a binary tree structure with the same category information as the underlying nodes and the hierarchical categories as nodes at different levels above the underlying nodes based on the classification chain information, and determine the initial hash value of each underlying node according to at least one of the TLS information under the same classification chain information; The target TLS fingerprint generation module is configured to sequentially select target levels and select two adjacent target nodes in the target levels, where the hierarchical categories corresponding to the target nodes in the upper level are the same; The target hash value of the target node corresponding to the hierarchical category in the upper level is calculated according to the two target hash values corresponding to the two target nodes until the unique root node hash value is generated, and the target TLS fingerprint corresponding to the target system is obtained. The initial value of the target level is the level where the underlying node is located, the initial value of the target node is the underlying node, and the initial value of the target hash value is the initial hash value.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the method for generating a TLS fingerprint based on a Merkle tree according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method for generating a TLS fingerprint based on a Merkle tree according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Block chain-based network threat intelligence sharing method, system and device, and medium

    CN118353606A

  • Multi-instance architecture supporting trusted blockchain-based network

    US20200014527A1