Encrypted traffic analysis method and system based on network center information

By responding to encrypted traffic analysis conditions in real time in the network center information processing system, traversing and triggering corresponding encrypted traffic analysis strategies, the problem of difficult to identify and analyze encrypted traffic in the existing technology is solved, real-time identification and analysis of encrypted traffic is realized, and network security protection capabilities are improved.

CN120185883AInactive Publication Date: 2025-06-20NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT SHANDONG BRANCH +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510335795.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively identify and analyze encrypted traffic, resulting in the failure of traditional network monitoring and defense methods, and the inability to detect and respond to network security threats in a timely manner.

Method used

By responding to encrypted traffic analysis conditions in real time in the network center information processing system, traversing and triggering the corresponding encrypted traffic analysis strategy, the encrypted traffic monitoring module and analysis strategy are used for accurate identification and analysis.

Benefits of technology

Real-time identification and analysis of encrypted traffic is realized, and potential network security threats are discovered and dealt with in a timely manner, the overall security protection capability of the network system is improved, and false alarms and underreports are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185883A_ABST
    Figure CN120185883A_ABST
Patent Text Reader

Abstract

The invention provides an encrypted traffic analysis method and system based on network center information, and belongs to the technical field of network center information processing. Traversing an encrypted traffic monitoring module matched with the encrypted traffic analysis condition and all encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module; when it is determined that a target encrypted traffic analysis strategy exists, corresponding encrypted traffic analysis based on the target encrypted traffic analysis strategy is triggered, and the target encrypted traffic analysis strategy is the encrypted traffic analysis strategy monitored by the encrypted traffic monitoring module. And responding to an encrypted traffic analysis condition in real time, and traversing and triggering a corresponding encrypted traffic analysis strategy. Potential network security threats can be found and dealt with in time, and the overall security protection capability of a network system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network-centric information processing, and in particular relates to an encrypted traffic analysis method, system, device and medium based on network-centric information. Background Art

[0002] With the rapid development of network technology, the Internet has become an indispensable part of people's daily life and work. However, network security issues have become increasingly prominent, and the identification and analysis of encrypted traffic have become an important challenge in the field of network security. The wide application of encrypted traffic, although protecting the privacy and integrity of user data to a certain extent, also provides a hidden channel for malicious behavior, making traditional network monitoring and defense means based on plaintext content ineffective.

[0003] At present, as the core hub of information transmission and processing, the network center aggregates a large amount of network traffic data, including encrypted traffic, network logs, device information, etc. These data contain rich network behavior characteristics and are of great significance for identifying and preventing network threats. However, due to the complexity and dynamics of encrypted traffic, traditional rule- or signature-based detection methods are difficult to cope with. Therefore, how to effectively extract and analyze encrypted traffic characteristics from massive network-centric information has become an urgent problem to be solved. Summary of the Invention

[0004] The present invention proposes an encrypted traffic analysis method based on network-centric information, which can respond to encrypted traffic analysis conditions in real time, traverse and trigger corresponding encrypted traffic analysis strategies, timely discover and respond to potential network security threats, and improve the overall security protection ability of the network system.

[0005] The method includes: When responding to an encrypted traffic analysis condition, traverse the encrypted traffic monitoring modules that match the encrypted traffic analysis condition and all the encrypted traffic analysis strategies monitored by the encrypted traffic monitoring modules; The encrypted traffic analysis condition includes that the encrypted communication status of the node terminal changes or the preset encrypted traffic analysis time is reached, and execute the encrypted traffic analysis strategy; When it is determined that there is a target encrypted traffic analysis strategy, trigger corresponding encrypted traffic analysis based on the target encrypted traffic analysis strategy, and the target encrypted traffic analysis strategy is the encrypted traffic analysis strategy monitored by the encrypted traffic monitoring module.

[0006] Further, it should be noted that the method further includes: Traverse the encrypted traffic monitoring modules that match the encrypted traffic analysis condition; Configure a communication channel for the encrypted traffic monitoring module; Traverse all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module; Parse using all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module.

[0007] Furthermore, it should be noted that in the method, after determining the target encrypted traffic analysis policy, the analysis control module triggers the encrypted information communication module to perform corresponding encrypted traffic analysis according to the target encrypted traffic analysis policy, and obtains the analysis information of the encrypted traffic analysis.

[0008] Furthermore, it should be noted that in the method, when the encrypted traffic analysis condition includes a change in the encrypted communication status of the node terminal, a target encrypted traffic analysis policy that matches the changed encrypted communication status is determined from all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module.

[0009] Furthermore, it should be noted that in the method, when the encrypted traffic analysis condition includes reaching the preset encrypted traffic analysis time, if there is information update in the node terminal, a target encrypted traffic analysis policy that matches the updated information is determined from all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module.

[0010] Furthermore, it should be noted that the method further includes: after deploying all the encrypted traffic monitoring modules, loading all the encrypted traffic monitoring modules; Create an encrypted traffic analysis scenario for each of the encrypted traffic monitoring modules to initialize each of the encrypted traffic monitoring modules.

[0011] Furthermore, it should be noted that the method further includes: after deploying all the encrypted traffic analysis policies, loading all the encrypted traffic analysis policies; After successfully checking the legality of any one of the encrypted traffic analysis policies, map any one of the encrypted traffic analysis policies to the corresponding encrypted traffic monitoring module to initialize any one of the encrypted traffic analysis policies; wherein, the encrypted traffic analysis policies of the same machine learning algorithm correspond to one encrypted traffic monitoring module.

[0012] This application also provides an encrypted traffic analysis system based on network center information. The system includes: a network monitoring server and multiple node terminals; The multiple node terminals are respectively communicatively connected to the network monitoring server; The network monitoring server includes: an encrypted traffic analysis policy table, an analysis control module, an encrypted information communication module, and an encrypted traffic monitoring module; When the analysis control module responds to the encrypted traffic analysis condition, it traverses the encrypted traffic monitoring modules that match the encrypted traffic analysis condition and all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring modules. The encrypted traffic analysis condition includes that the encrypted communication status of the node terminal changes, or when the preset encrypted traffic analysis time is reached, the encrypted traffic analysis policy is executed. When it is determined that there is a target encrypted traffic analysis policy, trigger the corresponding encrypted traffic analysis based on the target encrypted traffic analysis policy, where the target encrypted traffic analysis policy is the encrypted traffic analysis policy monitored by the encrypted traffic monitoring module.

[0013] According to another embodiment of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the encrypted traffic analysis method based on network center information are implemented.

[0014] According to still another embodiment of the present application, a storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the encrypted traffic analysis method based on network center information are implemented.

[0015] From the above technical solutions, the following advantages of the present invention can be seen: The encrypted traffic analysis method based on network center information proposed by the present invention can respond to the encrypted traffic analysis condition in real time, traverse and trigger the corresponding encrypted traffic analysis policy. Timely discover and respond to potential network security threats, and improve the overall security protection ability of the network system. By traversing the encrypted traffic monitoring modules that match the encrypted traffic analysis condition, the method can accurately identify the target encrypted traffic analysis policy and perform encrypted traffic analysis. Accurately identify malicious encrypted traffic and take corresponding defensive measures to effectively prevent data leakage and network attacks. Through the traversal and matching method, the method can utilize network resources for encrypted traffic analysis. Improve the efficiency of network traffic management. It can also be based on the change of the encrypted traffic analysis condition. The method can adjust the traversed encrypted traffic monitoring modules and analysis policies to adapt to different network environments and analysis requirements. Through encrypted traffic analysis and identification, the situation of false alarms and missed alarms can be reduced, and the stability and reliability of the network system can be improved. Description of the Drawings

[0016] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 Flowchart of the encrypted traffic analysis method based on network - centric information; Figure 2 Flowchart of the embodiment of the encrypted traffic analysis method based on network - centric information; Figure 3 Schematic diagram of the encrypted traffic analysis system based on network - centric information. Detailed implementation manners

[0018] Hereinafter, various embodiments of the encrypted traffic analysis method based on network - centric information will be described more comprehensively. The present disclosure can have various embodiments, and adjustments and changes can be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but the present disclosure should be understood to cover all adjustments, equivalents, and / or alternative solutions falling within the spirit and scope of the various embodiments of the present disclosure.

[0019] Hereinafter, the term "comprising" or "may comprise" that can be used in various embodiments of the present disclosure indicates the presence of the disclosed functions, operations, or elements, and does not limit the addition of one or more functions, operations, or elements. In addition, as used in various embodiments of the present disclosure, the terms "comprising", "having" and their cognates are only intended to indicate a specific feature, number, step, operation, element, component, or combination of the foregoing items, and should not be construed as first excluding the existence of one or more other features, numbers, steps, operations, elements, components, or the possibility of adding one or more features, numbers, steps, operations, elements, components, or combination of the foregoing items.

[0020] The encrypted traffic analysis method based on network - centric information can acquire and process associated data based on artificial intelligence technology. Among them, the encrypted traffic analysis method based on network - centric information uses a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, a theory, method, technology, and application device for perceiving the environment, acquiring knowledge, and using knowledge to obtain the best results.

[0021] In an embodiment of the present invention, computer program code for performing the operations of the present disclosure can be written in one or more programming languages or combinations thereof. The above - mentioned programming languages include, but are not limited to, object - oriented programming languages - such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages.

[0022] The system of the present application includes: a network monitoring server and multiple node terminals; the multiple node terminals are respectively communicatively connected to the network monitoring server.

[0023] A node terminal is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. Its hardware includes, but is not limited to, microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0024] The node terminal can be any electronic product that can interact with users. For example, personal computers, tablet computers, smart phones, personal digital assistants (PDAs), Internet Protocol Televisions (IPTVs), smart wearable devices, etc.

[0025] The network monitoring server is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers.

[0026] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0027] Please refer to Figure 1 The figure shows a flowchart of an encrypted traffic analysis method based on network center information in a specific embodiment. The method includes the following specific implementation processes.

[0028] In this embodiment, the network monitoring server includes: an encrypted traffic analysis policy table, an analysis control module, an encrypted information communication module, and an encrypted traffic monitoring module.

[0029] It should be noted that the encrypted traffic analysis policy list includes multiple encrypted traffic analysis policies, which can be encrypted traffic analysis policies customized in advance according to actual situations. The encrypted traffic analysis policy list defines various encrypted information communication scenarios that require encrypted traffic analysis. The encrypted traffic analysis policy list can configure corresponding encrypted traffic analysis policies according to various types of encrypted traffic information and send them to the node terminal.

[0030] The encryption traffic analysis policy table of this embodiment may include multiple encryption traffic analysis policies. Each encryption traffic analysis policy corresponds to an encryption traffic analysis requirement that clearly specifies an encrypted information communication scenario, etc., and this embodiment does not make excessive limitations and descriptions on this.

[0031] For the encryption traffic analysis policy of this embodiment, the specific content of the encryption traffic analysis policy includes collecting and recording network traffic data. This includes packet capture, traffic mirroring, traffic proxy, network flow logging, etc. Extract and analyze the metadata of the traffic (such as source IP, destination IP, port number, traffic size, duration, etc.) to identify abnormal behaviors. Of course, machine learning algorithms can be used to extract features from the traffic data to better understand and analyze network traffic.

[0032] The encryption traffic analysis policy of this embodiment also distinguishes different communication behaviors by identifying the protocol types in the network traffic. It is possible to understand the basic structure and pattern of the encrypted traffic. Perform protocol parsing on the decrypted traffic to identify traffic that does not conform to the specifications.

[0033] Use machine learning algorithms to identify normal and abnormal traffic patterns and detect potential malicious activities. Study the time distribution and pattern characteristics of the traffic through methods such as time series analysis and clustering analysis.

[0034] Under legal circumstances, use SSL / TLS decryption technology to deeply analyze the encrypted traffic and identify potential threats. Perform content analysis on the decrypted traffic to discover hidden security threats or abnormal behaviors.

[0035] This embodiment also involves user behavior analysis, monitoring the behavior patterns of users, and identifying activities that do not conform to normal behaviors, such as abnormal logins or data access. Monitor the behavior patterns of devices and identify abnormal device communications or activities.

[0036] Identify behaviors that deviate from the normal range by comparing the actual traffic with a predefined normal traffic model. Once suspicious activities are detected, automatically execute a series of predefined operations (such as isolating infected devices, removing malware, or notifying the security administrator).

[0037] The analysis control module of this embodiment is used to parse the encryption traffic analysis policy and control the execution of programmable scripts according to the policy to determine whether the current state of the node terminal matches a certain or certain encryption traffic analysis policies.

[0038] In this embodiment, the analysis control module needs to interpret or parse these encrypted traffic analysis policies according to the machine learning algorithms of the encrypted traffic analysis policies. In this embodiment, an encrypted traffic monitoring module is configured to execute the parsing of the encrypted traffic analysis policies. The encrypted traffic monitoring module of this embodiment matches the machine learning algorithms of the encrypted traffic analysis policies and is used to monitor the encrypted traffic analysis policies of the machine learning algorithms. The relationship between the encrypted traffic monitoring module and the encrypted traffic analysis policies is a one-to-many mapping relationship. Specifically, one encrypted traffic monitoring module can process at least one encrypted traffic analysis policy of the same machine learning algorithm. The encrypted traffic analysis policies of different machine learning algorithms correspond to different encrypted traffic monitoring modules, and the encrypted traffic analysis policies of the same machine learning algorithm correspond to one encrypted traffic monitoring module.

[0039] The number of encrypted traffic monitoring modules in this embodiment is not limited. For example, it can have one or more. The encrypted traffic monitoring modules in this embodiment can be extended according to actual needs to support new demand machine learning algorithms.

[0040] This embodiment also configures an analysis control module to control the operation of the encrypted traffic monitoring module. The analysis control module of this embodiment can load the encrypted traffic monitoring module during the initialization phase and create an independent encrypted traffic analysis scenario for the encrypted traffic monitoring module, so that each encrypted traffic monitoring module can be deployed independently without interference.

[0041] The encrypted information communication module of this embodiment is used to execute corresponding information transmission and communication after a certain encrypted traffic analysis policy is successfully matched. For example, it can perform corresponding encrypted traffic analysis according to different traffic analysis channels and different analysis durations. This embodiment does not make too many limitations and details on this.

[0042] The method of this embodiment may include the following implementation steps: S201. When responding to the encrypted traffic analysis condition, traverse the encrypted traffic monitoring modules that match the encrypted traffic analysis condition and all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring modules. The encrypted traffic analysis condition includes that the encrypted communication status of the node terminal changes, or the preset encrypted traffic analysis time is reached, and execute the encrypted traffic analysis policy.

[0043] The encrypted traffic analysis condition in this embodiment can be pre-customized by the user according to actual needs and is used to judge the trigger condition for controlling the encrypted traffic analysis policy. For example, the trigger condition may include but is not limited to at least one of the following: the encrypted communication status of the node terminal changes, the preset encrypted traffic analysis time is reached, or other custom trigger conditions, etc.

[0044] The encryption traffic analysis time in this embodiment can refer to the period of encryption traffic analysis that is pre-customized by the system or user according to actual needs. For example, it can be an empirical value set according to user experience, etc.

[0045] In this embodiment, when the analysis control module obtains the encryption traffic analysis conditions that meet this embodiment, it can traverse the encryption traffic monitoring modules that match the encryption traffic analysis conditions of this embodiment and all the encryption traffic analysis policies monitored by the encryption traffic monitoring modules. This embodiment can traverse all / entire encryption traffic monitoring modules in the system and all the encryption traffic analysis policies monitored by each encryption traffic monitoring module.

[0046] Such as Figure 2 shown, the method may further include the following implementation steps: S301. Traverse the encryption traffic monitoring modules that match the encryption traffic analysis conditions.

[0047] The encryption traffic monitoring module in this embodiment can refer to the encryption traffic monitoring module used to process a certain type of encryption traffic analysis policy, which can be related to the encryption traffic analysis conditions. Specifically, when the communication status of the node terminal changes in the encryption traffic analysis conditions, the encryption traffic monitoring module can be the encryption traffic monitoring module deployed in the system for processing the information related to the changed encrypted communication status.

[0048] S302. Configure a communication channel for the encryption traffic monitoring module.

[0049] S303. Traverse all the encryption traffic analysis policies monitored by the encryption traffic monitoring module.

[0050] S304. Parse using all the encryption traffic analysis policies monitored by the encryption traffic monitoring module.

[0051] S202. When it is determined that there is a target encryption traffic analysis policy, trigger corresponding encryption traffic analysis based on the target encryption traffic analysis policy, where the target encryption traffic analysis policy is the encryption traffic analysis policy monitored by the encryption traffic monitoring module.

[0052] After determining the target encryption traffic analysis policy of this embodiment, the analysis control module triggers the encryption information communication module to perform corresponding encryption traffic analysis according to the target encryption traffic analysis policy, so as to obtain the analysis information of the encryption traffic analysis.

[0053] When the node terminal in this embodiment meets the conditions for encrypted traffic analysis, it traverses the encrypted traffic monitoring modules that match the encrypted traffic analysis conditions and all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring modules. The encrypted traffic analysis conditions include that the encrypted communication status of the node terminal changes and the preset encrypted traffic analysis time is reached. The encrypted traffic analysis policies are used to indicate the encrypted traffic analysis requirements for corresponding encrypted information communication scenarios. When it is determined that there is a target encrypted traffic analysis policy, the corresponding encrypted traffic analysis is triggered based on the target encrypted traffic analysis policy, and the target encrypted traffic analysis policy is the encrypted traffic analysis policy monitored by the encrypted traffic monitoring module.

[0054] This embodiment further includes the following implementation steps: S501. When the encrypted traffic analysis condition includes that the encrypted communication status of the node terminal changes, a target encrypted traffic analysis policy that matches the changed encrypted communication status is determined from all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module.

[0055] It can be understood that each encrypted traffic analysis policy has corresponding analysis parameters, and different encrypted traffic analysis policies can correspond to different analysis parameters. The analysis parameters can include, for example, the encrypted communication status of the node terminal, the internal information running on the node terminal, or other information.

[0056] This embodiment can determine the encrypted traffic analysis policy that matches it based on the analysis parameters. When the encrypted traffic analysis condition in this embodiment includes that the encrypted communication status of the node terminal changes, this embodiment can determine a target encrypted traffic analysis policy that matches the changed encrypted communication status from all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module according to the changed encrypted communication status of the node terminal.

[0057] S502. When the encrypted traffic analysis condition includes reaching the preset encrypted traffic analysis time, if there is information update on the node terminal, a target encrypted traffic analysis policy that matches the updated information is determined from all the encrypted traffic analysis policies monitored by the encrypted traffic monitoring module.

[0058] In the method involved in this embodiment, when the encrypted communication state changes or reaches the preset encrypted traffic analysis time and there is information update in the node terminal, a policy matching the target state or the updated information can be dynamically determined from all the encrypted traffic analysis policies. This mechanism enables the system to adjust the analysis policy in real time according to the actual changes in the network environment, improving the accuracy and timeliness of the analysis. By precisely matching the encrypted communication state or the updated information, the system can more accurately identify potential abnormal traffic or security threats. By adjusting the analysis policy in real time according to the encrypted communication state or the updated information, the system can discover and respond to potential security threats more promptly. The policy matching mechanism simplifies the management and maintenance of the system. System administrators can easily add, delete, or modify analysis policies according to actual needs without making large-scale modifications or reconstructions to the entire system. This improves the maintainability and usability of the system.

[0059] This application also provides some alternative embodiments. After the encrypted information communication module of this embodiment obtains the analysis information of this embodiment in the encrypted traffic analysis, it can upload the analysis information of this embodiment to the network monitoring server.

[0060] This embodiment can initialize the analysis control module.

[0061] This embodiment may further include the following implementation steps: S601. After deploying all the encrypted traffic monitoring modules, load all the encrypted traffic monitoring modules.

[0062] S602. Create an encrypted traffic analysis scenario for each of the encrypted traffic monitoring modules to initialize each of the encrypted traffic monitoring modules.

[0063] During the initialization process of the analysis control module, the analysis control module can first complete the deployment of all the encrypted traffic monitoring modules in the set first directory, then load all the encrypted traffic monitoring modules, and create an independent encrypted traffic analysis scenario for each encrypted traffic monitoring module in all the encrypted traffic monitoring modules, so that each encrypted traffic monitoring module can be independently deployed. After creating the encrypted traffic analysis scenario, perform initialization such as parameter configuration on the analysis control module to complete the initialization of the analysis control module.

[0064] In this embodiment, by completing the deployment of all the encrypted traffic monitoring modules in the set first directory and loading them one by one, the system realizes modular management. Each encrypted traffic monitoring module can be independently deployed and run, reducing the coupling degree between modules and improving the stability and reliability of the system. Creating an independent encrypted traffic analysis scenario for each encrypted traffic monitoring module enables each module to analyze specific encrypted traffic, improving the pertinence and accuracy of the analysis.

[0065] During the initialization process of the analysis control module, the sequence of first deploying the modules, then loading the modules, and finally creating the analysis scenarios makes the initialization process more orderly. By creating independent analysis scenarios for each module, the system can dynamically allocate resources such as computing resources and storage resources according to actual needs, thus achieving efficient utilization of resources. By creating independent analysis scenarios for each encrypted traffic monitoring module and performing specialized initialization configurations on them, the system can more accurately identify and analyze abnormal behaviors in encrypted traffic, providing stronger protection for network security.

[0066] The method of this embodiment further includes the following implementation steps: S701. After deploying all the encrypted traffic analysis policies, load all the encrypted traffic analysis policies.

[0067] S702. After successfully checking the legality of any one of the encrypted traffic analysis policies, map any one of the encrypted traffic analysis policies to the corresponding encrypted traffic monitoring module to initialize any one of the encrypted traffic analysis policies; wherein, the encrypted traffic analysis policies of the same machine learning algorithm correspond to one encrypted traffic monitoring module.

[0068] During the initialization process of the encrypted traffic analysis policy list, the analysis control module completes the deployment of all encrypted traffic analysis policies in the set second directory, and then loads all the encrypted traffic analysis policies in the list.

[0069] This embodiment uses the encrypted traffic monitoring module to check the corresponding encrypted traffic analysis policies; check whether there are logical judgment errors in the encrypted traffic analysis policies, or check whether the encrypted traffic analysis policies match the node terminals, etc.

[0070] After the check of the encrypted traffic analysis policies of this embodiment is completed, map any one of the encrypted traffic analysis policies to the corresponding encrypted traffic monitoring module according to the machine learning algorithm to which the encrypted traffic analysis policy belongs; according to this embodiment, all the encrypted traffic analysis policies in the list can be checked and mapped to the encrypted traffic monitoring module.

[0071] This embodiment uses the encrypted traffic monitoring modules of multiple machine learning algorithms to improve the analysis ability of the encrypted traffic analysis policy for the encrypted information communication scenario of encrypted traffic analysis.

[0072] The encrypted traffic analysis method based on network center information provided in this embodiment can achieve more accurate and efficient analysis by classifying the encrypted traffic analysis policies according to machine learning algorithms and mapping them to the corresponding encrypted traffic monitoring modules. Each monitoring module specializes in processing traffic related to specific algorithms, which can optimize resource allocation and improve processing speed. By detecting the effectiveness of the analysis policies, false positives or false negatives caused by policy errors are reduced, and the accuracy of the analysis is improved. The method supports unified loading after all policies are deployed, facilitating dynamic updates of the policies. When adding or modifying analysis policies, they are deployed and loaded according to the established process without large-scale adjustments to the entire system. By decoupling the policies from the monitoring modules, the system can be more easily extended with new analysis algorithms and policies, enhancing system security. In this embodiment, the encrypted traffic analysis policies are mapped to the corresponding monitoring modules, and each monitoring module can be optimized for its proficient algorithms, improving resource utilization efficiency. By centrally managing and uniformly loading the policies, duplicate waste and conflicts of resources can be avoided, enhancing the overall performance of the system. The method provides policy deployment, loading, checking, and mapping processes, facilitating maintenance and management by system administrators.

[0073] The following is an embodiment of an encrypted traffic analysis system based on network center information provided by the present disclosure. This system belongs to the same inventive concept as the encrypted traffic analysis method based on network center information in the above embodiments. Details not described in detail in the embodiment of the encrypted traffic analysis system based on network center information can refer to the embodiments of the encrypted traffic analysis method based on network center information above.

[0074] As Figure 3 shown, the overall system architecture includes a network monitoring server and multiple node terminals. The network monitoring server, as the core of the system, is responsible for monitoring encrypted traffic, formulating and executing analysis policies, and communication management with node terminals. Node terminals are deployed at various key positions in the network to collect network traffic information and send encrypted traffic data to the network monitoring server for processing.

[0075] An encrypted traffic analysis policy table is set on the network monitoring server, and this policy table contains various analysis policies for different types of encrypted traffic. The formulation of the analysis policies is based on the actual requirements of network security and can include aspects such as traffic feature recognition, encrypted protocol parsing, and abnormal behavior detection.

[0076] Meanwhile, an analysis control module is configured to set conditions for triggering encrypted traffic analysis, such as a change in the encrypted communication status of the node terminal or the arrival of a preset encrypted traffic analysis time.

[0077] Establish a communication connection between the network monitoring server and the node terminal. The encrypted information communication module is responsible for the instruction issuance and status feedback between the server and the terminal to achieve real-time control and supervision of the system.

[0078] Based on the encrypted traffic monitoring module, real-time monitoring of the encrypted traffic in the network is carried out. The encrypted traffic monitoring module can also capture the encrypted traffic data in the network in real time and perform preliminary screening and classification according to the preset analysis strategy. When the encrypted traffic analysis conditions are met, the analysis control module will traverse the encrypted traffic monitoring modules that match the conditions and all the encrypted traffic analysis strategies they monitor, determine the target encrypted traffic analysis strategy, and trigger the corresponding encrypted traffic analysis process.

[0079] The deployment and implementation method of the encrypted traffic analysis system based on network center information provided by the present invention in actual applications. The system can achieve comprehensive monitoring and in-depth analysis of the encrypted traffic in the network, providing strong support for network security protection.

[0080] The system of this embodiment also involves system initialization, mainly including the software configuration of the network monitoring server and the formulation and loading of encrypted traffic analysis strategies.

[0081] In terms of the network monitoring server, it is necessary to install and configure the necessary operating system, database software, and the core software components of the encrypted traffic analysis system. These components include, but are not limited to, the software implementation of the encrypted traffic analysis strategy table, the analysis control module, the encrypted information communication module, and the encrypted traffic monitoring module.

[0082] The formulation of encrypted traffic analysis strategies is one of the key steps in system initialization. The strategy formulation should be based on the actual security requirements of the network, clarify which types of encrypted traffic need to be monitored and analyzed, and under what conditions the analysis operation is triggered. The strategy can include filtering rules for specific protocols, ports, source / destination addresses, etc., as well as the detailed steps and expected results of the analysis operation.

[0083] The formulated encrypted traffic analysis strategies will be loaded into the encrypted traffic analysis strategy table of the network monitoring server. This process can be completed through a dedicated strategy management tool or manual configuration to ensure that the strategies can be correctly parsed and executed by the system.

[0084] The configuration of the node terminal mainly includes installing and starting the encrypted information communication module, and setting the communication parameters with the network monitoring server. The node terminal needs to be able to report its encrypted communication status to the network monitoring server in real time and cooperate with the collection and forwarding operations of encrypted traffic when receiving analysis instructions.

[0085] After configuration is completed, the node terminal will be in a standby state, waiting for further instructions from the network monitoring server. After the system deployment and initialization are completed, the encrypted traffic analysis system will start to run normally and execute the preset encrypted traffic analysis tasks. The encrypted traffic monitoring module of the network monitoring server will continuously monitor the encrypted traffic in the network. Through technical means such as deep packet inspection and traffic statistics, the monitoring module can identify the encrypted traffic that meets the analysis policy in real time and mark it as data to be analyzed. When the encrypted traffic monitoring module detects a change in the encrypted communication status of the node terminal or reaches the preset encrypted traffic analysis time, the analysis condition will be triggered. At this time, the analysis control module will be activated and start to execute the corresponding analysis operations.

[0086] The analysis control module of this embodiment will first traverse the encrypted traffic monitoring module that matches the trigger condition and all the encrypted traffic analysis policies it monitors. Through the policy matching algorithm, it determines whether there is a target encrypted traffic analysis policy. Once a matching policy is found, the analysis control module will trigger the corresponding encrypted traffic analysis based on this policy.

[0087] After the encrypted traffic analysis is completed, the system will generate a detailed analysis report. The report content includes but is not limited to key information such as the source, destination, protocol type, and transmission content of the encrypted traffic, as well as possible security risks and recommended countermeasures. It can be displayed to the network administrator through the management interface so that further security measures can be taken in a timely manner.

[0088] This application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of the encrypted traffic analysis method based on network center information.

[0089] The electronic device that implements the encrypted traffic analysis method based on network center information combines the units and algorithm steps of each example described in the embodiments disclosed herein and can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but this implementation should not be considered to exceed the scope of the present invention.

[0090] Through the description of the above embodiments, those skilled in the art can easily understand that the encrypted traffic analysis method based on network-centric information described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, according to the technical solution of the disclosed embodiments of the encrypted traffic analysis method based on network-centric information, it can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the indexing method according to the disclosed embodiments of the present disclosure.

[0091] The present application also provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the encrypted traffic analysis method based on network-centric information are implemented.

[0092] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for analyzing encrypted traffic based on network center information, characterized in that: Methods include: In response to the encrypted traffic analysis condition, traverse the encrypted traffic monitoring module that matches the encrypted traffic analysis condition and all encrypted traffic analysis policies monitored by the encrypted traffic monitoring module; The encrypted traffic analysis conditions include the encrypted communication state of the node terminal changes, or the preset encrypted traffic analysis time is reached, and the encrypted traffic analysis strategy is executed; When it is determined that there is a target encrypted traffic analysis policy, a corresponding encrypted traffic analysis based on the target encrypted traffic analysis policy is triggered, and the target encrypted traffic analysis policy is an encrypted traffic analysis policy monitored by an encrypted traffic monitoring module.

2. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: The method also includes: Traversing the encrypted traffic monitoring modules that match the encrypted traffic analysis condition; Configuring a communication channel for the encrypted traffic monitoring module; Traversing all encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module; All encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module are analyzed.

3. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: In the method, after determining the target encrypted traffic analysis strategy, the analysis control module triggers the encryption information communication module to perform corresponding encrypted traffic analysis according to the target encrypted traffic analysis strategy to obtain analysis information of the encrypted traffic analysis.

4. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: In the method, when the encrypted traffic analysis condition includes a change in the encrypted communication state of the node terminal, a target encrypted traffic analysis strategy that matches the changed encrypted communication state is determined from all encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module.

5. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: In the method, when the encrypted traffic analysis condition includes the arrival of the preset encrypted traffic analysis time, if there is information update on the node terminal, then a target encrypted traffic analysis strategy that matches the updated information is determined from all encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module.

6. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: The method further includes: after all encrypted traffic monitoring modules are deployed, loading all the encrypted traffic monitoring modules; An encrypted traffic analysis scenario is created for each of the encrypted traffic monitoring modules to initialize each of the encrypted traffic monitoring modules.

7. The encrypted traffic analysis method based on network center information according to claim 1 is characterized in that: The method further includes: after all encrypted traffic analysis policies are deployed, loading all of the encrypted traffic analysis policies; After successfully performing a legitimacy check on any of the encrypted traffic analysis policies, any of the encrypted traffic analysis policies are mapped to a corresponding encrypted traffic monitoring module to initialize any of the encrypted traffic analysis policies; wherein, the encrypted traffic analysis policies of the same machine learning algorithm correspond to one encrypted traffic monitoring module.

8. An encrypted traffic analysis system based on network center information, characterized in that: The system is used to implement the encrypted traffic analysis method based on network center information as described in any one of claims 1 to 7; The system includes: a network monitoring server and multiple node terminals; A plurality of node terminals are respectively connected to the network monitoring server for communication; The network monitoring server includes: an encrypted traffic analysis strategy table, an analysis control module, an encrypted information communication module and an encrypted traffic monitoring module; When the analysis control module responds to the encrypted traffic analysis condition, it traverses the encrypted traffic monitoring module that matches the encrypted traffic analysis condition and all encrypted traffic analysis strategies monitored by the encrypted traffic monitoring module; The encrypted traffic analysis conditions include the encrypted communication state of the node terminal changes, or the preset encrypted traffic analysis time is reached, and the encrypted traffic analysis strategy is executed; When it is determined that there is a target encrypted traffic analysis policy, a corresponding encrypted traffic analysis based on the target encrypted traffic analysis policy is triggered, and the target encrypted traffic analysis policy is the encrypted traffic analysis policy monitored by the encrypted traffic monitoring module.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the encrypted traffic analysis method based on network-centric information as described in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the encrypted traffic analysis method based on network-centric information as described in any one of claims 1 to 7 are implemented.