Method for obtaining network quintuple from SSL object
By hijacking the key functions of the OpenSSL encryption communication suite and combining stack backtracking and stack matching technology, the problem of obtaining HTTP plaintext data and network five-tuple information of HTTPS encrypted traffic in Apache2 and Nginx applications is solved, and effective monitoring and analysis in these two applications is achieved.
Patent Information
- Application Number
- CN202510432435.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The prior art cannot obtain HTTP plaintext data and network quintile information for HTTPS encrypted traffic in Apache2 open source applications and cannot be applied to Nginx applications.
By hijacking key functions in the OpenSSL encryption communication suite and combining stack backtracking and stack matching technology, the association relationship between file descriptor FD and SSL objects is established to indirectly obtain network five-tuple information.
It realizes the acquisition of HTTP plaintext data and network five-tuple information in Apache2 and Nginx applications, supports security monitoring and analysis of traffic, and improves the stability and data security of network services.
Smart Images

Figure CN120281533A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computing network communication, and particularly relates to a method for obtaining network five-tuples from an SSL object. Background Art
[0002] Obtaining the corresponding network five-tuple information and HTTP plaintext traffic in HTTPS encrypted traffic is an important data support for traffic monitoring and analysis.
[0003] A network five-tuple is a professional term in computing network communication, which includes five items: source IP address, source port number, destination IP address, destination port number, and transport layer protocol (for example, TCP protocol and UDP protocol). The HTTP protocol is an unencrypted traffic in network communication. After being encrypted by the SSL / TLS encryption toolkit, HTTP becomes HTTPS, an encrypted traffic. SSL / TLS is a standardized data encryption protocol that protects the confidentiality and integrity of data. OpenSSL is an implemented and widely used encryption communication suite that complies with the SSL / TLS protocol standard. An SSL object is a structure created by the OpenSSL toolkit during runtime, which stores relevant information during encrypted communication, including but not limited to the key of encrypted data, file descriptor FD (identifier for read and write operations), and BIO object. A BIO object is a set of input and output operations for processing the underlying data stream in the OpenSSL encryption communication suite. If the encryption function in OpenSSL is used, the data stream of BIO input and output is encrypted; otherwise, the data stream of BIO input and output is unencrypted. BIO is an important part of SSL / TLS communication.
[0004] In order to obtain the corresponding network five-tuple information in HTTPS encrypted traffic for monitoring and analysis, the prior art adopts the following two methods:
[0005] (1) Parsing packets based on the network layer and transport layer to obtain five-tuple information
[0006] By parsing packets based on the network layer and transport layer, extracting the source address and destination address in the IP header, as well as the source port, destination port, and protocol number in the TCP header according to the TCP / IP protocol, so as to obtain network five-tuple information, as Figure 1 shown.
[0007] The drawback of the above method is that although it can obtain the network five-tuple information, it cannot obtain the plaintext data of HTTPS encrypted traffic. Specifically, the network five-tuple information in the IP header and TCP header is extracted according to the TCP / IP protocol, but the HTTP plaintext data before HTTPS encryption and the HTTP plaintext data after HTTPS decryption cannot be obtained. Although the network five-tuple information can be obtained and there is a certain monitoring ability, without the HTTP plaintext data, it still cannot fully meet the security monitoring and analysis of traffic.
[0008] (2) Obtaining HTTP plaintext data and network five-tuple information based on hijacking the key functions of the OpenSSL encryption communication suite
[0009] Inject it into the running process of the network service of the encrypted communication. By hijacking the two key functions of SSL_read / SSL_write, obtain the SSL object and the HTTP plaintext data stream before or after decryption corresponding to HTTPS from the parameters of these two hijacked functions. The BIO object in the SSL object structure, and the NUM field in the BIO object structure stores the value of the file descriptor FD (the identifier for read and write operations). By judging the type to determine whether it is a socket type, if so, continue the function call, and the network socket information can be obtained from the file descriptor FD. Then continue the function call to obtain the network five-tuple from the network socket, as Figure 2 shown.
[0010] The drawback of the above method is that although this method can be applied to the open-source application Ngnix, it cannot be applied to the widespread open-source application Apache2. Specifically, the method of obtaining HTTP plaintext data and network five-tuple information based on hijacking the key functions of the OpenSSL encryption communication suite is applicable to some open-source applications. For example, in Apache2, by hijacking the two key functions of SSL_read / SSL_write in the OpenSSL encryption communication suite, obtain the SSL object from the parameters of these two hijacked functions, obtain the BIO object from the structure of the SSL object, and then obtain the NUM field (storing the identifier for read and write operations of the file descriptor) from the BIO object. The value of NUM is always 0 and does not belong to the network socket type, so the network five-tuple information cannot be obtained. Summary of the Invention
[0011] The purpose of the present invention aims to solve at least one of the above technical drawbacks.
[0012] Therefore, the purpose of the present invention is to propose a method for obtaining network five-tuples from an SSL object, which can indirectly obtain the correct file descriptor FD from the SSL object and is applicable to the Nginx application and the Apache2 open-source application.
[0013] To achieve the above object, an embodiment of one aspect of the present invention provides a method for obtaining network five-tuple from an SSL object, including the following steps:
[0014] S1, when it is monitored that a client initiates an SSL connection request, function hijacking is performed on the read system call function of the operating system, the SSL_read function, SSL_write function, and SSL_accept function in the OpenSSL encryption communication suite. When there is a network connection between the Apache2 service and the client initiating the connection, the current thread PID, process TGID, and file descriptor FD are obtained in the hijacked read system call;
[0015] S2, backtrack the return address of the function call stack in the user-mode context and perform an address matching operation with the address of the SSL_accept function to determine whether the SSL_accept function is called in the current user-mode context. If so, execute step S3;
[0016] S3, if the SSL_accept function is called, it indicates that the current read call is a handshake operation in a communication, and the current thread PID, process TGID, and SSL object in the SSL_accept function in the user-mode context are recorded;
[0017] S4, match the current thread PID and process TGID obtained from the read system call with the information recorded in the previous SSL_accept to ensure that the information is consistent and belongs to the same session context;
[0018] S5, create a relationship mapping table to store the corresponding relationship between the current thread PID and process TGID, file descriptor FD, and SSL object;
[0019] S6, hijack the SSL_read function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream of the read operation;
[0020] S7, hijack the SSL_write function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream before the write operation;
[0021] S8, according to the relationship mapping table, obtain the corresponding socket structure using the file descriptor FD, and extract the socket connection information from the socket structure;
[0022] S9, extract the network five-tuple information from the socket structure, and the network five-tuple information includes: source IP, source port, destination IP, destination port, and protocol type.
[0023] Further, in the step S1, hijacking the SSL_accept function includes: hijacking at the entry of SSL_accept to obtain the PID of the current process, the TGID of the thread, and the memory address of the SSL object.
[0024] Further, in the step S1, hijacking the read system call function of the operating system includes hijacking at the entry of the kernel read system call to obtain the PID of the current process, the TGID of the thread, and the file descriptor FD.
[0025] Further, in the step S4, if the PID of the current thread and the TGID of the process obtained in the hijacked SSL_accept function and the hijacked read system call in the same call stack are consistent, then the four elements of the PID of the current thread, the TGID of the process, the file descriptor FD, and the SSL object are bound and associated, so as to realize the association of the file descriptor FD and the SSL object through the PID of the current thread and the TGID of the process, and further realize the association of the SSL object and the correct file descriptor FD.
[0026] Further, in the step S5, the relationship mapping table is used to find relevant information in the SSL read and write operations.
[0027] Further, in the step S7, the uprobes tool is used to hijack the SSL_write function call.
[0028] Further, the method is applicable to Nginx applications and Apache2 applications.
[0029] Compared with the prior art, the advantages and beneficial effects of the present invention are as follows:
[0030] 1. The present invention proposes an innovative method of stack backtracking and stack matching, which can indirectly obtain the correct file descriptor FD from the SSL object.
[0031] 2. Based on the method of hijacking the key functions of the OpenSSL encryption communication suite to obtain HTTP plaintext data and network quintuple information, the present invention can be applied to Nginx but not to Apache2. The present invention proposes an innovative method that can be applied to both Nginx and Apache2.
[0032] 3. The present invention can solve the problem of obtaining HTTP plaintext data and network quintuple information in the encryption communication of the widely used open-source application Apache2, which plays a crucial role in the security monitoring and analysis of traffic and the stability of the enterprise's network services and data security.
[0033] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0035] Figure 1 is a schematic architecture diagram of a method for obtaining five-tuple information by parsing data packets based on the network layer and transport layer in the prior art;
[0036] Figure 2 is a schematic architecture diagram of a method for obtaining HTTP plaintext data and network five-tuple information by hijacking key functions of the OpenSSL encryption communication suite in the prior art;
[0037] Figure 3 is a flowchart of a method for obtaining network five-tuples from an SSL object according to an embodiment of the present invention;
[0038] Figure 4 is a schematic architecture diagram of a method for obtaining HTTP plaintext data and network five-tuple information by hijacking two key functions in the OpenSSL encryption communication suite and stack backtracking and stack matching according to an embodiment of the present invention;
[0039] Figure 5 is a specific implementation schematic diagram of a method for obtaining HTTP plaintext data and network five-tuple information by hijacking two key functions in the OpenSSL encryption communication suite and stack backtracking and stack matching according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present invention and should not be construed as limiting the present invention.
[0041] The present invention provides a method for obtaining network quintuples from an SSL object, which involves a method for obtaining network quintuples from encrypted communication on a terminal. The present invention is an improvement based on the method of obtaining HTTP plaintext data and network quintuple information by hijacking two key functions in the OpenSSL encryption communication suite. The improvement lies in that through reverse engineering, a method of backtracking the call stack and stack matching is proposed, that is, a method for obtaining HTTP plaintext data and network quintuple information based on hijacking key functions in the OpenSSL encryption communication suite, stack backtracking, and stack matching. The method of the present invention can realize obtaining the value of the real file descriptor FD from the SSL object, thereby obtaining network quintuple information, solving the problem that in traditional Apache2, the correct value of the file descriptor FD cannot be directly obtained from the SSL object, and overcoming the deficiency that the traditional method cannot obtain both the HTTP plaintext data and the associated network quintuple information in the HTTPS encrypted traffic from the Apache2 application. The method of the present invention can not only be applied to the Nginx application, but also adapt to the widely used open-source Apache2 application.
[0042] As Figure 3 shown, the method for obtaining network quintuples from an SSL object according to an embodiment of the present invention includes the following steps:
[0043] S1, when it is monitored that a client initiates an SSL connection request, function hijacking is performed on the read system call function of the operating system, the SSL_read function, the SSL_write function, and the SSL_accept function in the OpenSSL encryption communication suite. When there is a network connection between the Apache2 service and the client that initiates the connection, the current thread PID, process TGID, and file descriptor FD are obtained in the hijacked read system call.
[0044] Specifically, referring to Figure 5 , first, monitor the client connection request. After the server program starts, monitor the client connection request on the specified port and wait for the client to initiate an SSL connection. This is the starting point of the entire SSL communication, and it is necessary to ensure that the port is correctly opened and has appropriate permissions.
[0045] When it is monitored that a client initiates an SSL connection request, function hijacking is performed on the read system call function of the operating system, the SSL_read function, the SSL_write function, and the SSL_accept function in the OpenSSL encryption communication suite.
[0046] Hijacking the SSL_accept function includes: performing hijacking at the entrance of the SSL_accept to obtain the PID of the current process, the thread TGID, and the memory address of the SSL object.
[0047] Hijack the read system call function of the operating system, including hijacking at the entry of the kernel read system call to obtain the PID of the current process, the TGID of the thread, and the file descriptor FD. The system call is a key point in the SSL_accept process.
[0048] When there is a network connection between the Apache2 service and the client initiating the connection, obtain the three elements of the current thread PID, process TGID, and file descriptor FD in the hijacked read system call.
[0049] S2. Trace back the return address of the function call stack in the user-mode context and perform an address matching operation with the address of the SSL_accept function to determine whether the SSL_accept function is called in the current user-mode context. If so, execute step S3.
[0050] S3. If the SSL_accept function is called, it means that the current read call is a handshake operation in a communication, and record the current thread PID, process TGID, and SSL object in the SSL_accept function in the user-mode context.
[0051] In this step, perform a stack backtrace check: obtain the complete call stack information at the read system call and analyze whether it contains an SSL_accept call. This step is used to verify that the current read call indeed comes from the SSL handshake process.
[0052] S4. Verify the PID / TGID information: match the current thread PID and process TGID obtained from the read system call with the information recorded in the previous SSL_accept to ensure that they belong to the same session context.
[0053] In this step, perform a stack matching: if the current thread PID and process TGID obtained in the hijacked SSL_accept function and the hijacked read system call in the same call stack are consistent, then bind and associate the four elements of the current thread PID, process TGID, file descriptor FD, and SSL object to achieve the purpose of associating the file descriptor FD and the SSL object through the current thread PID and process TGID, and further realize the association between the SSL object and the correct file descriptor FD, and finally correctly obtain the network five-tuple information.
[0054] Reference Figure 4Backtrack the return address of the function call stack in the user-mode context (i.e., stack backtrace) and perform an address matching operation with the address of the SSL_accept function (i.e., stack matching) to determine whether the SSL_accept function is called in the current user-mode context. If the SSL_accept function is called, it indicates that the current read call is a handshake operation in a communication, and record the three elements of the current thread PID, process TGID, and SSL object in the SSL_accept function in the user-mode context.
[0055] S5. Create a relationship mapping table to store the correspondence between the current thread PID and process TGID and the file descriptor FD and SSL object. Among them, the relationship mapping table is used to quickly find relevant information in SSL read and write operations.
[0056] S6. Hijack the SSL_read function: Hijack the SSL_read function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream of the read operation.
[0057] S7. Hijack the SSL_write function: Hijack the SSL_write function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream before the write operation.
[0058] In this step, use the uprobes tool to hijack the SSL_write function call.
[0059] S8. Obtain the Socket connection information: According to the relationship mapping table, use the file descriptor FD to obtain the corresponding socket structure, and extract the detailed information of the socket connection from the socket structure.
[0060] S9. Collect the network five-tuple: Extract the network five-tuple information from the socket structure. Among them, the network five-tuple information includes: source IP, source port, destination IP, destination port, and protocol type. The above information completely describes the network characteristics of the SSL connection.
[0061] In summary, the present invention associates the SSL object with the correct file descriptor FD through the method of backtracking the call stack and stack matching. In the Nginx process, the BIO object in the SSL object structure can be directly used, and the file descriptor FD is in the BIO object structure. Then, it is determined whether the file descriptor FD is of the network socket type. If so, the network quintuple information can be obtained through the file descriptor FD. However, in Apache2, the value of the file descriptor FD directly obtained through the SSL object is 0 and it is not of the network socket type, so the network quintuple cannot be obtained. To solve the above problems, the method of the present invention realizes the association between the SSL object and the file descriptor FD in the read system call through stack backtracking and stack matching techniques, and finally correctly obtains the network quintuple information.
[0062] The method of the present invention is an improvement on the method of hijacking the key functions of the OpenSSL encryption communication suite to obtain HTTP plaintext data and network quintuple information. It proposes a technical method of call stack backtracking and stack matching, which realizes indirectly obtaining the correct file descriptor FD when the file descriptor obtained directly from the SSL object is 0, and finally obtains the network quintuple information. The method of the present invention is applicable to Nginx applications and Apache2 applications.
[0063] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0064] It is not difficult for those skilled in the art to understand that the present invention includes any combination of the above-mentioned invention content, specific implementation manners, and each part shown in the drawings. Due to space limitations and to make the specification concise, the various solutions formed by these combinations are not described one by one. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
[0065] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, replacements, and variations to the above embodiments within the scope of the present invention without departing from the principle and purpose of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for obtaining network five-tuples from an SSL object, characterized in that, It includes the following steps: S1. When it is monitored that the client initiates an SSL connection request, hijack the read system call function of the operating system, the SSL_read function, SSL_write function, and SSL_accept function in the OpenSSL encryption communication suite. When there is a network connection between the Apache2 service and the client that initiates the connection, obtain the current thread PID, process TGID, and file descriptor FD in the hijacked read system call; S2. Trace the return address of the function call stack in the user-mode context and perform an address matching operation with the address of the SSL_accept function to determine whether the SSL_accept function is called in the current user-mode context. If so, execute step S3; S3. If the SSL_accept function is called, it means that the current read call is a handshake operation in a communication, and record the current thread PID, process TGID, and SSL object in the SSL_accept function in the user-mode context; S4. Match the current thread PID and process TGID obtained from the read system call with the information recorded in SSL_accept before to ensure that the information is consistent and belongs to the same session context; S5. Create a relationship mapping table to store the corresponding relationship between the current thread PID and process TGID, file descriptor FD, and SSL object; S6. Hijack the SSL_read function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream of the read operation; S7. Hijack the SSL_write function call, record the current PID, TGID, and SSL object information, and obtain the HTTP plaintext stream before the write operation; S8. According to the relationship mapping table, obtain the corresponding socket structure using the file descriptor FD, and extract the socket connection information from the socket structure; S9. Extract the network quintuple information from the socket structure. The network quintuple information includes: source IP, source port, destination IP, destination port, and protocol type.
2. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein In the S1, hijacking the SSL_accept function includes: hijacking at the entrance of the SSL_accept to obtain the PID of the current process, thread TGID, and the memory address of the SSL object.
3. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein, In the S1, hijacking the read system call function of the operating system includes hijacking at the entrance of the kernel read system call to obtain the PID of the current process, thread TGID, and file descriptor FD.
4. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein In S4, if the current thread PID and the process TGID obtained in the hijacked SSL_accept function and the hijacked read system call in the same call stack are consistent, then the four elements of the current thread PID, the process TGID, the file descriptor FD, and the SSL object are bound and associated, so as to achieve the purpose of associating the file descriptor FD and the SSL object through the current thread PID and the process TGID, and further achieve the association between the SSL object and the correct file descriptor FD.
5. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein In the said S5, the relationship mapping table is used to find relevant information in the SSL read and write operations.
6. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein In the said S7, the uprobe tool is used to hijack the SSL_write function call.
7. The method for obtaining a network five-tuple from an SSL object according to claim 1, wherein The said method is applicable to Nginx application programs and Apache2 application programs.
Citation Information
Patent Citations
High-efficiency dynamic software vulnerability exploiting method
CN101853200A
SSL / TLS network encryption communication information real-time decryption method based on memory analysis
CN111224995A
Method and apparatus to have entitlement follow the end device in network
CN113016167A
Data decryption method and device, equipment and storage medium
CN115883245A
Stateful network protocol fuzz testing method based on API HOOK
CN117319271A