Cryptographic algorithm identification method and apparatus, and electronic device
Through the combination of hierarchical classifiers and multi-layer perceptron networks, the problem of low recognition efficiency of cryptographic algorithms in the prior art is solved, and efficient and accurate recognition of complex and variable encryption algorithms is achieved.
Patent Information
- Application Number
- CN202510493584.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, when cryptographic algorithm recognition methods face a wide variety of algorithms, complex and variable implementation methods and malware confusion methods, there are problems such as insufficient model performance and poor recognition efficiency.
The hierarchical classifier recognition method is adopted. First, the cipher principle category of the cipher message is determined through the primary classifier, and then the specific encryption algorithm type is identified through the secondary classifier, and the multi-layer perceptron network is used for preliminary classification, and deep identification is combined with models such as random forests, neural networks, KNNs and decision trees.
It improves the accuracy and system efficiency of password algorithm recognition, can effectively distinguish complex and changeable encryption algorithms, reduce false alarms and missed reports, and improves the means to fight malware confusion.
Smart Images

Figure CN120301657A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology. Specifically, it relates to a method, device, and electronic device for identifying cryptographic algorithms. Background Art
[0002] In today's highly information-based society, cryptographic algorithms, as a key technology for information protection, play a crucial role in fields such as Internet security, financial transactions, and communication. With the continuous progress of technology, cryptographic algorithms have evolved from simple to complex and from static to dynamic, forming a diverse system including block ciphers, public key ciphers, stream ciphers, and Hash functions. These algorithms not only enhance data security but also provide means for cybercriminals to conceal their activities. For example, malicious software can be hidden through advanced encryption techniques, making it difficult for traditional security measures to detect.
[0003] However, there are still some prominent difficulties in the practical application of cryptographic algorithm identification technologies in related art. Firstly, traditional identification methods, such as comparison based on fixed fingerprints or simple statistical features, often fail to effectively distinguish various complex encryption algorithms. Especially when the algorithm implementation methods are highly diverse, the identification accuracy is greatly reduced, and false positives and false negatives become common. Secondly, malicious software developers often use multi-layer encryption or obfuscation techniques, splitting, inlining, virtualizing, etc. to optimize the algorithm implementation, thus increasing the difficulty of interfering with analysis tools and signature matching, making related cryptographic identification methods ineffective in anti-obfuscation and anti-optimization. Thirdly, although identification methods based on machine learning or deep learning can theoretically improve the identification performance, the high dependence of their models means that it is often difficult to make accurate judgments for unknown or newly emerging encryption algorithm variants, resulting in poor identification effects. In addition, more advanced technical means such as side-channel analysis or hardware-level identification have high deployment costs and limited application scopes in practice, and are also difficult to promote on a large scale.
[0004] No effective solution has been proposed for the above problems. Summary of the Invention
[0005] Embodiments of this application provide a method, device, and electronic device for identifying cryptographic algorithms, so as to at least solve the technical problems of insufficient model performance and poor identification efficiency when the cryptographic algorithm identification technology in related art faces challenges such as a large variety of algorithm types, complex and changeable implementation methods, and malicious software obfuscation means.
[0006] According to one aspect of the embodiments of the present application, a method for identifying a cryptographic algorithm is provided, including: obtaining a cryptographic message and determining a feature vector corresponding to the cryptographic message, where the cryptographic message includes an encrypted message and an unencrypted message; identifying the feature vector through a first-level classifier to obtain a first classification result, where the first classification result is used to represent the cryptographic principle category to which the cryptographic message belongs; determining a second-level classifier according to the first classification result, and identifying the feature vector through the second-level classifier to obtain a second classification result, where the second classification result is used to represent the encryption algorithm type to which the encrypted message belongs.
[0007] Optionally, determining the feature vector corresponding to the cryptographic message includes: obtaining the statistical features of the cryptographic message, where the statistical features at least include the total amount index, variation index, average index, and information entropy of the ASCII code bytes in the cryptographic message; obtaining the entropy features of the cryptographic message, where the entropy features at least include the inter-group bit entropy and intra-group bit entropy of the cryptographic message; fusing the statistical features and the entropy features to obtain the feature vector.
[0008] Optionally, obtaining the entropy features of the cryptographic message includes: dividing the encrypted message according to a first preset packet length to obtain a first packet message; determining the bit position of each bit in the first packet message; determining the occurrence frequency of the target bit at the bit position to obtain a first bit frequency, where the target bit includes bit 0 and bit 1; determining the inter-group bit entropy of the cryptographic message according to the first bit frequency.
[0009] Optionally, obtaining the entropy features of the cryptographic message further includes: dividing the encrypted message according to a second preset packet length to obtain a second packet message; determining the occurrence frequency of each bit in the second packet message to obtain a second bit frequency; determining the intra-group bit entropy of the cryptographic message according to the second bit frequency.
[0010] Optionally, the first-level classifier is a multi-layer perceptron network, where the multi-layer perceptron network includes a first fully connected layer, a second fully connected layer, and an activation function. The first fully connected layer and the second fully connected layer are used to perform feature mapping on the feature vector, and the activation function is used to perform a non-linear transformation on the feature vector.
[0011] Optionally, the multi-layer perceptron network is trained in the following manner: obtaining historical cryptographic messages and determining the category labels corresponding to the historical cryptographic messages, where the historical cryptographic messages include historical encrypted messages and historical unencrypted messages, and the category labels are used to represent the true cryptographic principle categories to which the historical cryptographic messages belong; determining the historical feature vectors corresponding to the historical cryptographic messages; training the initial classifier according to the historical feature vectors and the category labels until the preset number of iterations is reached and then stopping the training to obtain the multi-layer perceptron network.
[0012] Optionally, the method further includes: determining the cipher principle category in the first classification result, where the cipher principle category includes an encryption algorithm category and a non-encryption algorithm category, and the encryption algorithm category includes at least one of the following: block cipher, public key cipher, stream cipher, and hash function; in the case where the first classification result indicates that the cipher message belongs to the encryption algorithm category, using a secondary classifier to identify the cipher message, and determining the second classification result obtained by the secondary classifier as the identification result of the cipher message; in the case where the first classification result indicates that the cipher message belongs to the non-encryption algorithm category, determining the first classification result as the identification result of the cipher message.
[0013] Optionally, determining a secondary classifier according to the first classification result and identifying the feature vector through the secondary classifier includes: in the case where the first classification result indicates that the cipher message belongs to a block cipher, using a first classifier corresponding to the block cipher to identify the feature vector; in the case where the first classification result indicates that the cipher message belongs to a public key cipher, using a second classifier corresponding to the public key cipher to identify the feature vector; in the case where the first classification result indicates that the cipher message belongs to a stream cipher, using a third classifier corresponding to the stream cipher to identify the feature vector; in the case where the first classification result indicates that the cipher message belongs to a hash function, using a fourth classifier corresponding to the hash function to identify the feature vector.
[0014] According to another aspect of the embodiments of the present application, there is also provided an apparatus for identifying a cipher algorithm, including: an acquisition module, configured to acquire a cipher message and determine a feature vector corresponding to the cipher message, where the cipher message includes an encrypted message and a non-encrypted message; a first identification module, configured to identify the feature vector through a primary classifier to obtain a first classification result, where the first classification result is used to represent the cipher principle category to which the cipher message belongs; a second identification module, configured to determine a secondary classifier according to the first classification result and identify the feature vector through the secondary classifier to obtain a second classification result, where the second classification result is used to represent the encryption algorithm type to which the encrypted message belongs.
[0015] According to yet another aspect of the embodiments of the present application, there is also provided an electronic device, including: a memory and a processor, where the memory is configured to store program instructions; the processor is connected to the memory and is configured to execute to implement the above-mentioned method for identifying a cipher algorithm.
[0016] According to still another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored computer program, and the device where the non-volatile storage medium is located executes the above-mentioned method for identifying a cipher algorithm by running the computer program.
[0017] According to another aspect of the embodiments of the present application, there is also provided a computer program product, including computer instructions, which implement the above-mentioned password algorithm recognition method when executed by a processor.
[0018] In the embodiments of the present application, by obtaining a password message and determining a feature vector corresponding to the password message, where the password message includes an encrypted message and an unencrypted message; by using a first-level classifier to identify the feature vector to obtain a first classification result, where the first classification result is used to represent the password principle category to which the password message belongs; determining a second-level classifier according to the first classification result, and using the second-level classifier to identify the feature vector to obtain a second classification result, where the second classification result is used to represent the encryption algorithm type to which the encrypted message belongs, the purpose of accurately classifying the password algorithm is achieved, thereby realizing the technical effect of improving the accuracy of password algorithm recognition and the system efficiency, and further solving the technical problems of insufficient model performance and poor recognition efficiency in the password algorithm recognition technology in the related art when facing challenges such as a large number of algorithm types, complex and changeable implementation methods, and malicious software obfuscation means. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0020] Figure 1 is a hardware structure diagram of a computer terminal for implementing the password algorithm recognition method according to the embodiments of the present application;
[0021] Figure 2 is a flowchart of a password algorithm recognition method according to the embodiments of the present application;
[0022] Figure 3 is a schematic framework diagram of the second-level classification of a password algorithm according to the embodiments of the present application;
[0023] Figure 4 is a structure diagram of a password algorithm recognition device according to the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0025] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0026] First, some nouns or terms that appear in the process of explaining the embodiments of this application are applicable to the following explanations:
[0027] MLP (Multi-Layer Perceptron): A feedforward neural network composed of at least three layers of nodes, including an input layer, one or more hidden layers, and an output layer. MLP classifies and predicts by learning the complex non-linear relationship between input data and output data.
[0028] RF (Random Forest): An ensemble learning method that classifies and regresses by constructing multiple decision trees. In the construction process of each decision tree in the random forest, samples and features are randomly selected, thereby improving the prediction accuracy and anti-overfitting ability of the model.
[0029] Decision Tree (DT): A tree-structured prediction model where each internal node represents a test on a feature, each branch represents a test result, and each leaf node represents a class. The decision tree classifies and regresses by recursively splitting features.
[0030] KNN (K-Nearest Neighbors): An instance-based learning method used for classification and regression tasks and has wide applications in pattern recognition and data mining. The basic principle of the KNN algorithm is to make predictions based on the "voting" results of the K nearest training instances of the input instance in the feature space.
[0031] National Cryptography Encryption Algorithm: Refers to the cryptographic algorithm standards recognized and recommended by the National Cryptography Administration, such as SM4, SM9, etc., which are used for data encryption and secure transmission.
[0032] Entropy: In information theory, entropy is a measure of the uncertainty of information and is usually used to describe the randomness and unpredictability of information. In cryptography, entropy is used to measure the complexity and randomness of passwords.
[0033] Z-score normalization: A data preprocessing method that standardizes data by converting it into a distribution with a mean of 0 and a standard deviation of 1, which helps to eliminate the dimensional differences between different features and makes the model easier to learn.
[0034] To solve the problem of low efficiency in identifying cryptographic algorithms in related technologies, an embodiment of the present application provides a method for identifying cryptographic algorithms, which can run on Figure 1 the computer terminal shown below. The following describes this computer terminal.
[0035] The method embodiment for identifying cryptographic algorithms provided by the embodiments of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal for implementing the method for identifying cryptographic algorithms is shown. As Figure 1 shown, the computer terminal 10 may include one or more processors (the processors may include, but are not limited to, processing devices such as a microprocessor MCU or a field programmable gate array FPGA, shown as 102a, 102b,..., 102n in the figure), a memory 104 for storing data, and a transmission module 106 for communication functions connected by wired and / or wireless networks. In addition, it may further include: a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, and a BUS bus. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.
[0036] It should be noted that the above one or more processors and / or other data processing circuits are usually referred to as "data processing circuits" in this article. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or may be wholly or partially incorporated into any one of the other elements in the computer terminal 10. As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0037] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the password algorithm recognition method in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned password algorithm recognition method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, intranet, local area network, mobile communication network, and combinations thereof.
[0038] The transmission module 106 is used to receive or send data via a network. Specific examples of the above network may include the wireless network provided by the communication provider of the computer terminal 10. In one instance, the transmission module 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one instance, the transmission module 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0039] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10.
[0040] It should be noted here that in some alternative embodiments, the above Figure 1 shown computer terminal may include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware elements and software elements. It should be pointed out that Figure 1 is only an example of a specific specific instance, and is intended to show the types of components that may exist in the above computer terminal.
[0041] Under the above operating environment, the embodiments of the present application provide an embodiment of a password algorithm recognition method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0042] Figure 2 is a flowchart of a password algorithm recognition method according to an embodiment of the present application, as Figure 2As shown, the method includes the following steps:
[0043] Step S202: Obtain a ciphertext message and determine the corresponding feature vector, where the ciphertext message includes an encrypted message and an unencrypted message.
[0044] In the above step S202, first, it is necessary to obtain message samples of various cryptographic algorithms (referred to as ciphertext messages) from network traffic or other data sources, including encrypted messages of types such as block ciphers, public-key ciphers, stream ciphers, and Hash functions, as well as some unencrypted messages. For each ciphertext message, perform feature extraction to generate a feature vector representing the characteristics of the message. Among them, feature extraction includes, but is not limited to, extracting ASCII code byte features of the ciphertext message, statistical metrics (such as the mode, median, and average of byte frequencies), variation metrics (such as variance and average difference), information entropy, and entropy features for specific encryption principles, such as inter-block bit entropy and intra-block bit entropy.
[0045] Step S204: Identify the feature vector through a primary classifier to obtain a first classification result, where the first classification result is used to represent the category of the cryptographic principle to which the ciphertext message belongs.
[0046] In the above step S204, the primary classifier is responsible for initially classifying the extracted feature vector to determine the basic encryption principle category to which the ciphertext message belongs. Among them, the primary classifier can adopt a multi-layer perceptron (MLP) network. By learning the relationship between the features of the encrypted message and the encryption principle category, the ciphertext message is classified into major categories such as block ciphers, public-key ciphers, stream ciphers, Hash functions, and other encryption algorithms or non-encryption algorithms (non-cryptographic algorithms).
[0047] Step S206: Determine a secondary classifier based on the first classification result, and identify the feature vector through the secondary classifier to obtain a second classification result, where the second classification result is used to represent the type of encryption algorithm to which the encrypted message belongs.
[0048] In the above step S206, the secondary classifier can be dynamically selected and applied according to the first classification result to perform a deeper analysis on the feature vector to determine the specific algorithm type used in the encrypted message. For example, if the first-level classifier determines that the message belongs to the block cipher category, the system will call a secondary classifier optimized for block ciphers (such as random forest) to further identify the feature vector to determine specific algorithms such as AES and DES. Similarly, for different categories such as public-key cryptography, stream ciphers, and hash functions, algorithms such as neural networks, KNN models, and decision trees are respectively used for identification. This hierarchical identification strategy can significantly improve the identification accuracy and reduce the processing complexity because each secondary classifier is optimized and trained for algorithms under a specific category, can more effectively process the features of this category, and reduce false positives and false negatives.
[0049] Through the above steps S202 to S206, the purpose of accurately classifying the cryptographic algorithm is achieved, thereby realizing the technical effect of improving the identification accuracy of the cryptographic algorithm and the system efficiency, and further solving the technical problems of insufficient model performance and poor identification efficiency in the cryptographic algorithm identification technology in the related art when facing the challenges of a large variety of algorithm types, complex and changeable implementation methods, and malicious software obfuscation means. The following is a detailed description.
[0050] In the above step S202, determining the feature vector corresponding to the cryptographic message includes: obtaining the statistical features of the cryptographic message, where the statistical features at least include the total amount index, variation index, average index, and information entropy of the ASCII code bytes in the cryptographic message; obtaining the entropy features of the cryptographic message, where the entropy features at least include the inter-group bit entropy and intra-group bit entropy of the cryptographic message; fusing the statistical features and entropy features to obtain the feature vector.
[0051] In the embodiment of the present application, determining the feature vector corresponding to the cryptographic message is a multi-stage process, aiming to comprehensively capture and quantify the internal characteristics of the cryptographic message and provide data support for subsequent algorithm identification. The specific steps can be as follows:
[0052] S1: Obtain the statistical features of the cryptographic message.
[0053] The extraction of statistical features first focuses on the ASCII code byte part in the cryptographic message. Although this part may account for a relatively small proportion in the encrypted data, its existence is closely related to the usage scenarios of specific encryption algorithms. The purpose of statistical analysis is to reveal the distribution laws and features of the ASCII code bytes, mainly including:
[0054] Total amount index: Calculate the total number or total length of the ASCII code bytes in the cryptographic message to reflect the proportion of the ASCII code part in the message.
[0055] Variation index: Use statistics such as variance and mean difference to measure the dispersion degree of the ASCII code byte frequency distribution, which is used to reflect the randomness and regularity in the encrypted data.
[0056] Average index: Calculate the mode, median, and average of the ASCII code byte frequency, which is used to describe the central tendency of the byte distribution, so as to distinguish the usage patterns of different encryption algorithms.
[0057] Information entropy: Based on information theory, information entropy is used to measure the information uncertainty of the ASCII code part in the ciphertext, that is, the randomness degree of the data. A high entropy value means that the data has strong randomness, and vice versa may indicate that the data is more regular or ordered.
[0058] S2: Obtain the entropy characteristics of the ciphertext.
[0059] The extraction of entropy characteristics focuses on the binary bit stream of the ciphertext, that is, the 0-1 bit string. The acquisition of this part of the characteristics is particularly important because the binary bit stream directly reflects the output characteristics of the encryption algorithm. The entropy characteristics mainly cover the inter-group bit entropy and the intra-group bit entropy, and their calculation is based on the binary bit sequence of the final encrypted ciphertext.
[0060] Optionally, obtain the inter-group bit entropy of the ciphertext, including: dividing the encrypted ciphertext according to the first preset group length to obtain the first group of ciphertexts; determining the bit position of each bit in the first group of ciphertexts; determining the occurrence frequency of the target bit at the bit position to obtain the first bit frequency, where the target bit includes bit 0 and bit 1; determining the inter-group bit entropy of the ciphertext according to the first bit frequency.
[0061] In the embodiment of the present application, the inter-group bit entropy focuses on the randomness and difference of the bit patterns between different groups in the ciphertext, which reflects the entropy distribution characteristics of the encrypted data at the group level, that is, the uncertainty of the bit distribution between groups. The specific acquisition method is analyzed as follows:
[0062] First, divide the entire encrypted ciphertext according to the preset group length. Taking the group length of 128 bits of the SM4 algorithm as an example, divide the encrypted ciphertext with a length of M into groups to obtain the first group of ciphertexts, providing a data unit convenient for subsequent analysis.
[0063] Secondly, in each group of ciphertexts, determine the specific position of each bit. For example, for a 128-bit group, the bit position can range from 0 to 127, so as to facilitate the subsequent frequency calculation for specific bit positions, thereby evaluating the regularity and randomness of the bit distribution.
[0064] Next, for each bit position within each grouped packet, count the occurrences of bit 0 and bit 1, and calculate their frequencies at that position, which is the ratio of the number of occurrences to the total number of bits.
[0065] Finally, using the formula for calculating information entropy, calculate the entropy value of each packet at a specific bit position based on the first bit frequency. The higher the entropy value, the more random the bit distribution at that position and the greater the uncertainty. The specific formula is as follows:
[0066]
[0067] In the formula, H m represents the inter-packet bit entropy, and P mn represents the first bit frequency, where 0 ≤ m ≤ 127 and n = 0, 1.
[0068] Optionally, obtaining the intra-packet bit entropy of the ciphertext packet includes: dividing the encrypted packet according to the second preset packet length to obtain the second grouped packet; determining the occurrence frequency of each bit in the second grouped packet to obtain the second bit frequency; and determining the intra-packet bit entropy of the ciphertext packet based on the second bit frequency.
[0069] In the embodiments of the present application, the intra-packet bit entropy focuses on the randomness and information density of the bits within each packet of the ciphertext packet, reveals the entropy value of the bit sequence within the same packet, and is used to evaluate the degree of uncertainty of the data within that packet. The specific acquisition method is analyzed as follows:
[0070] First, in the same way as the packet division method for the inter-packet bit entropy, divide the entire encrypted packet according to the preset packet length. Here, still taking the packet length of 128 bits of the SM4 algorithm as an example, divide the encrypted packet with length M into packets to obtain the second grouped packet.
[0071] Secondly, in each grouped packet, count the occurrences of each bit and calculate the proportion of them in the total number of bits in that packet, which is the second bit frequency.
[0072] Finally, using the calculated second bit frequency, apply the formula for calculating information entropy to quantitatively evaluate the randomness degree of the bit pattern within each packet. Among them, the higher the intra-packet bit entropy, the more random the bit pattern within that packet, and a lower entropy value indicates that there is a certain regularity in the pattern. The specific formula is as follows:
[0073]
[0074] In the formula, H n represents the intra-packet bit entropy, and P nm represents the second bit frequency, n = 0, 1.
[0075] S3: Integrate the statistical features and entropy features to obtain a feature vector.
[0076] Integrate the above-obtained statistical features and entropy features into a feature vector. This feature vector contains a comprehensive description of the cipher text at the ASCII byte level and binary bit level, including but not limited to the statistical information of ASCII bytes, the entropy value of the bit sequence, etc.
[0077] S4: Standardize the feature vector.
[0078] In machine learning and deep learning models, standardizing the feature vector is a crucial preprocessing step, especially when using algorithms like MLP that are sensitive to data scales. Standardization helps the model learn the relationships between features more effectively, avoiding issues such as unstable training or poor model performance caused by different scales of feature values.
[0079] In the embodiment of this application, when standardizing the feature vector, Z-score standardization is specifically adopted. Z-score standardization is a common feature scaling method that transforms feature values by subtracting the mean of the feature and then dividing by the standard deviation, thus converting the data into a normal distribution with a mean of 0 and a standard deviation of 1. The standardized feature vector not only helps improve the performance of algorithms based on distance metrics (such as K-Nearest Neighbor, KNN), but also benefits various machine learning models such as neural networks and support vector machines, as these models are usually sensitive to feature scales. In addition, Z-score standardization helps improve the quality of feature engineering. By unifying the feature values to the same scale, it simplifies the model's understanding of the interactions between features, further enhancing the model's generalization ability and stability.
[0080] In summary, through in-depth analysis of the cipher text, step S202 extracts statistical features and entropy features that can reflect its internal structure and encryption principle, and integrates these features into a feature vector, providing a comprehensive and accurate data representation for the subsequent first-level classifier and second-level classifier. It is an important cornerstone in the entire recognition process.
[0081] In the above step S204, the first-level classifier is a multi-layer perceptron network. Among them, the multi-layer perceptron network includes a first fully connected layer, a second fully connected layer, and an activation function. The first fully connected layer and the second fully connected layer are used to perform feature mapping on the feature vector, and the activation function is used to perform a non-linear transformation on the feature vector.
[0082] In the embodiment of the present application, the first-level classifier adopts an MLP network, and its core components include a first fully connected layer, a second fully connected layer, and an activation function. The MLP network performs deep feature mapping and information integration on the standardized feature vectors through these two fully connected layers, aiming to capture and learn the complex non-linear relationships between these features. The introduction of the activation function further enhances the non-linear processing ability of the model, enabling the model to better adapt to and distinguish the algorithm features under different encryption principles.
[0083] Specifically, after the feature vectors are standardized, the first fully connected layer starts to perform preliminary linear combinations on these features to explore the preliminary associations between the features. Subsequently, the activation function (such as ReLU) performs a non-linear transformation on the feature output after the linear combination, breaking the limitation of the linear relationship and enabling the model to learn more complex and advanced combination ways between the features. On this basis, the second fully connected layer further performs deep integration and mapping on the features after the non-linear transformation, and finally generates a high-level representation that can reflect the characteristics of the encryption algorithm for subsequent classification decisions.
[0084] Optionally, the multi-layer perceptron network is trained in the following way: obtaining historical ciphertext messages and determining the corresponding class labels for the historical ciphertext messages, where the historical ciphertext messages include historical encrypted messages and historical non-encrypted messages, and the class labels are used to represent the true cipher principle categories to which the historical ciphertext messages belong; determining the historical feature vectors corresponding to the historical ciphertext messages; training the initial classifier based on the historical feature vectors and the class labels until the training stops after reaching the preset number of iterations, and obtaining the multi-layer perceptron network.
[0085] In the embodiment of the present application, the training of the MLP network is completed by using historical ciphertext messages and their corresponding class labels. The training process involves learning the mapping relationship between the features of encrypted messages and the encryption principles from historical data, so as to build a model that can accurately perform preliminary classification of cipher algorithms. The specific analysis is as follows:
[0086] First, collect a large number of historical ciphertext message samples covering different types of encryption algorithms (such as block ciphers, public key ciphers, stream ciphers, Hash functions) and non-encrypted messages. For each sample, determine the true cipher principle category to which it belongs as the class label, which serves as the supervision information during the training process and is used to guide the model to learn the correct classification rules.
[0087] Secondly, extract the feature vectors of the historical ciphertext messages, including the extraction of statistical analysis features and information entropy features of the ASCII code byte part, and at the same time perform standardization processing to ensure the consistency and comparability of the features.
[0088] Next, the initial classifier is trained using the extracted historical feature vectors and class labels. In each training cycle, the MLP network maps the historical feature vectors to the output layer through forward propagation to predict the class of the sample. According to the difference between the prediction result and the actual class label, the network weights are adjusted through backpropagation until the preset number of iterations is reached. At this time, the model is considered to have fully learned the association between the features and the encryption principle and can accurately identify and classify the cipher text messages.
[0089] Through the above training process, the MLP network can gradually optimize its internal parameters and improve the recognition accuracy of historical cipher text messages. This training stage is the basis of the recognition method, ensuring that the first-level classifier can quickly and accurately classify the cipher text according to the features of the encrypted message into the corresponding major categories of encryption principles in practical applications, providing a pre-screening for the accurate recognition of the second-level classifier. This hierarchical training and recognition strategy can significantly improve the overall recognition efficiency and robustness of the model.
[0090] In step S204 above, after the feature vectors are recognized by the first-level classifier, it further includes: determining the cipher principle category in the first classification result, where the cipher principle category includes encryption algorithm categories and non-encryption algorithm categories, and the encryption algorithm categories include at least one of the following: block cipher, public key cipher, stream cipher, and hash function; in the case where the first classification result indicates that the cipher text message belongs to the encryption algorithm category, the second-level classifier is used to recognize the cipher text message, and the second classification result obtained by the second-level classifier is determined as the recognition result of the cipher text message; in the case where the first classification result indicates that the cipher text message belongs to the non-encryption algorithm category, the first classification result is determined as the recognition result of the cipher text message.
[0091] In the embodiment of the present application, the first-level classifier and the second-level classifier together constitute a hierarchical recognition mechanism for cipher text message recognition, and the second-level classification framework is as Figure 3 shown.
[0092] Specifically, the first-level classifier uses the MLP network to preliminarily recognize the feature vectors extracted from the cipher text message and processed by standardization, quickly determine whether the cipher text message belongs to the encryption algorithm category, and further classify it into major categories such as block cipher, public key cipher, stream cipher, hash function and other types of encryption algorithms and non-encryption algorithms (non-cipher algorithms).
[0093] When the first-level classifier recognizes that the cipher text message belongs to the encryption algorithm category, the message and its feature vectors are continuously passed to the corresponding second-level classifier. For the characteristics of each type of encryption algorithm, the second-level classifier uses a specific classification model (such as Figure 3The classifiers A, B, C, and D) in it are used for deeper identification to distinguish different specific encryption algorithms belonging to the same major category, such as RSA, DES, DSA, SHA algorithms, etc.
[0094] Conversely, if the first-level classifier determines that the cryptographic message belongs to the non-encryption algorithm category, that is, the message is not generated by an encryption algorithm, the first classification result will be directly adopted as the final identification result without further secondary identification. This not only improves the identification speed of non-encrypted messages but also saves computing resources, making the system more efficient in practical applications.
[0095] In summary, through the combination of the preliminary screening of the first-level classifier and the refined identification of the second-level classifier, the hierarchical identification mechanism proposed in this patent application realizes the efficient and accurate identification of cryptographic messages, avoiding over-computation of non-encrypted messages and ensuring in-depth discrimination of various specific algorithms in the encryption algorithm category. This design not only improves the identification speed but also greatly enhances the robustness and accuracy of the identification system.
[0096] In step S206 above, a second-level classifier is determined according to the first classification result, and the feature vector is identified by the second-level classifier, including: when the first classification result indicates that the cryptographic message belongs to a block cipher, the first classifier corresponding to the block cipher is used to identify the feature vector; when the first classification result indicates that the cryptographic message belongs to a public-key cipher, the second classifier corresponding to the public-key cipher is used to identify the feature vector; when the first classification result indicates that the cryptographic message belongs to a stream cipher, the third classifier corresponding to the stream cipher is used to identify the feature vector; when the first classification result indicates that the cryptographic message belongs to a hash function, the fourth classifier corresponding to the hash function is used to identify the feature vector.
[0097] In the embodiment of the present application, after the first-level classifier makes a preliminary identification of the feature vector and obtains the first classification result, the corresponding second-level classifier can be dynamically determined and enabled according to this result. The core of this mechanism is to use the second-level classifier to classify the cryptographic message more precisely to identify the specific encryption algorithm type to which it belongs. The specific analysis is as follows:
[0098] 1. Use the first classifier to identify block ciphers.
[0099] When the first-level classifier determines that the password message belongs to the block cipher category, the first classifier is used for identification, such as a random forest model. This is because the encryption process of block ciphers (such as AES, DES) involves multiple rounds of iteration and complex non-linear transformations, resulting in a relatively complex feature distribution. At the same time, the feature vectors of block ciphers usually contain a large number of statistical features (such as byte frequency distribution, information entropy, etc.) and have a high dimension. The random forest model, by integrating multiple decision trees, has a strong ability to resist overfitting, can effectively process high-dimensional feature data, and has a strong ability to model non-linear relationships between features.
[0100] 2. Use the second classifier to identify public-key ciphers.
[0101] When the first-level classifier determines that the password message belongs to the public-key cipher category, the second classifier is used for identification, such as a neural network model. This is because public-key ciphers usually have mathematical complexity and non-linear characteristics. Among them, mathematical complexity means that public-key ciphers are formed based on complex mathematical problems (such as large number factorization, elliptic curve discrete logarithm), and their features usually have high mathematical complexity; secondly, the feature distribution of public-key ciphers is usually non-linear and difficult to classify through simple linear models. The neural network can capture complex feature relationships through multi-layer non-linear transformations and can achieve high accuracy in dealing with existing complex classification tasks. Therefore, the neural network model is suitable for processing the high-dimensional non-linear features of public-key ciphers.
[0102] 3. Use the third classifier to identify stream ciphers.
[0103] When the first-level classifier determines that the password message belongs to the stream cipher category, the third classifier is used for identification, such as the KNN model. This is because the encryption process of stream ciphers is usually linear, their feature distribution is relatively simple, and the dimension of the feature vector is low. For such a simple cipher structure, a low-cost and simple classifier can be used. The KNN model has a simple structure and a fast training speed, and is suitable for processing stream ciphers with simple features.
[0104] 4. Use the fourth classifier to identify hash functions.
[0105] When the first-level classifier determines that the password message belongs to the hash function category, the fourth classifier is used for identification, such as a decision tree model. This is because the output of hash functions usually has a high information entropy, the feature distribution is relatively uniform and discrete, and the relationship between features is relatively simple. The decision tree can output clear classification rules, has a fast training and inference speed, is suitable for processing discrete features, and can effectively capture the high information entropy features of hash functions.
[0106] Through the above dynamic selection mechanism, that is, according to the encryption principle type of the password message, the most suitable secondary classifier is intelligently matched, realizing the in-depth recognition of the password message. This strategy not only greatly improves the recognition accuracy, but also significantly optimizes the processing efficiency, avoiding unnecessary waste of computing resources. For non-encryption algorithm categories, the recognition process can be directly terminated without further analysis, demonstrating the flexibility and efficiency of the recognition system in practical applications.
[0107] In the embodiments of the present application, by deeply mining the ASCII code byte features and entropy features in the encrypted message and combining the secondary hierarchical recognition mechanism, the limitations of traditional recognition methods in the face of complex and variable password algorithms are effectively overcome. First, the MLP network is used as the primary classifier to preliminarily classify messages with different encryption principles, which not only greatly improves the recognition accuracy but also alleviates the data imbalance problem, especially performing well when dealing with algorithms with similar features. Second, the secondary classifier is dynamically selected, and different machine learning models (such as random forest, neural network, KNN, and decision tree) are used for block ciphers, public key ciphers, stream ciphers, and hash functions, realizing the refinement and efficiency of algorithm recognition, while reducing the consumption of computing resources and improving the system execution efficiency. This "divide and conquer" strategy, combined with comprehensive feature extraction and deep learning technology, not only significantly improves the recognition accuracy of password algorithms but also has the ability to dynamically adapt to different scenario requirements, providing a more intelligent and accurate technical means for network security protection and encryption algorithm management, especially showing significant beneficial effects in combating encrypted malware and improving security analysis efficiency.
[0108] According to the embodiments of the present application, a device for recognizing password algorithms is provided. It should be noted that the device for recognizing password algorithms in the embodiments of the present application can be used to execute the method for recognizing password algorithms provided in the embodiments of the present application. The following introduces the device for recognizing password algorithms provided in the embodiments of the present application.
[0109] Figure 4 is a structural diagram of a device for recognizing password algorithms provided in the embodiments of the present application. As Figure 4 shown, the device includes:
[0110] An acquisition module 40, configured to acquire a password message and determine a feature vector corresponding to the password message, where the password message includes an encrypted message and a non-encrypted message;
[0111] A first recognition module 42, configured to recognize the feature vector through a primary classifier to obtain a first classification result, where the first classification result is used to represent the password principle category to which the password message belongs;
[0112] The second recognition module 44 is configured to determine a secondary classifier according to the first classification result, and recognize the feature vector through the secondary classifier to obtain a second classification result, where the second classification result is used to represent the type of encryption algorithm to which the encrypted message belongs.
[0113] Through the acquisition module, the first recognition module, and the second recognition module in the above-mentioned recognition device for cryptographic algorithms, the purpose of accurately classifying cryptographic algorithms is achieved, thereby realizing the technical effect of improving the recognition accuracy and system efficiency of cryptographic algorithms, and further solving the technical problems of insufficient model performance and poor recognition efficiency in the cryptographic algorithm recognition technology in the related art when facing challenges such as a large variety of algorithm types, complex and changeable implementation methods, and malicious software obfuscation means.
[0114] In the recognition device for cryptographic algorithms provided in the embodiment of the present application, the acquisition module is further configured to acquire statistical features of the cryptographic message, where the statistical features at least include the total amount index, variation index, average index, and information entropy of ASCII code bytes in the cryptographic message; acquire entropy features of the cryptographic message, where the entropy features at least include the inter-group bit entropy and intra-group bit entropy of the cryptographic message; and fuse the statistical features and entropy features to obtain a feature vector.
[0115] In the recognition device for cryptographic algorithms provided in the embodiment of the present application, the acquisition module is further configured to divide the encrypted message according to a first preset packet length to obtain a first packet message; determine the bit position of each bit in the first packet message; determine the occurrence frequency of the target bit at the bit position to obtain a first bit frequency, where the target bit includes bit 0 and bit 1; and determine the inter-group bit entropy of the cryptographic message according to the first bit frequency.
[0116] In the recognition device for cryptographic algorithms provided in the embodiment of the present application, the acquisition module is further configured to divide the encrypted message according to a second preset packet length to obtain a second packet message; determine the occurrence frequency of each bit in the second packet message to obtain a second bit frequency; and determine the intra-group bit entropy of the cryptographic message according to the second bit frequency.
[0117] In the recognition device for cryptographic algorithms provided in the embodiment of the present application, a training model 46 is further included. The training module is configured to acquire historical cryptographic messages and determine category labels corresponding to the historical cryptographic messages, where the historical cryptographic messages include historical encrypted messages and historical non-encrypted messages, and the category labels are used to represent the true cryptographic principle categories to which the historical cryptographic messages belong; determine historical feature vectors corresponding to the historical cryptographic messages; and train an initial classifier according to the historical feature vectors and category labels until the training stops after reaching a preset number of iterations, to obtain a multi-layer perceptron network.
[0118] In the password algorithm recognition device provided in the embodiment of the present application, the first recognition module is further configured to determine the password principle category in the first classification result, where the password principle category includes an encryption algorithm category and a non-encryption algorithm category, and the encryption algorithm category includes at least one of the following: block cipher, public key cipher, stream cipher, and hash function; when the first classification result indicates that the password message belongs to the encryption algorithm category, a secondary classifier is used to recognize the password message, and the second classification result obtained by the secondary classifier is determined as the recognition result of the password message; when the first classification result indicates that the password message belongs to the non-encryption algorithm category, the first classification result is determined as the recognition result of the password message.
[0119] In the password algorithm recognition device provided in the embodiment of the present application, the second recognition module is further configured to, when the first classification result indicates that the password message belongs to a block cipher, use a first classifier corresponding to the block cipher to recognize the feature vector; when the first classification result indicates that the password message belongs to a public key cipher, use a second classifier corresponding to the public key cipher to recognize the feature vector; when the first classification result indicates that the password message belongs to a stream cipher, use a third classifier corresponding to the stream cipher to recognize the feature vector; when the first classification result indicates that the password message belongs to a hash function, use a fourth classifier corresponding to the hash function to recognize the feature vector.
[0120] The embodiment of the present application further provides an electronic device, including: a memory and a processor, where the memory is used to store program instructions; the processor is connected to the memory and is used to execute the password algorithm recognition method described above.
[0121] It should be noted that the above electronic device is used to execute Figure 2 the password algorithm recognition method shown, so the relevant explanations in the above password algorithm recognition method also apply to this electronic device and will not be elaborated here.
[0122] The embodiment of the present application further provides a non-volatile storage medium, which includes a stored computer program, where the device where the non-volatile storage medium is located executes the password algorithm recognition method described above by running the computer program.
[0123] It should be noted that the above non-volatile storage medium is used to execute Figure 2 the password algorithm recognition method shown, so the relevant explanations in the above password algorithm recognition method also apply to this non-volatile storage medium and will not be elaborated here.
[0124] The embodiment of the present application further provides a computer program product, including computer instructions, which implement the password algorithm recognition method described above when executed by a processor.
[0125] It should be noted that the above computer program product is used to execute Figure 2 the recognition method of the cipher algorithm shown, so the relevant explanations in the above recognition method of the cipher algorithm also apply to this computer program product, and will not be elaborated here.
[0126] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0127] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0128] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0129] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0130] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0131] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0132] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can still be made, and these improvements and modifications should also be regarded as the protection scope of this application.
Claims
1. A method for identifying a cryptographic algorithm, characterized in that, Including: Obtain a ciphertext message and determine a feature vector corresponding to the ciphertext message, where the ciphertext message includes an encrypted message and an unencrypted message; Identify the feature vector through a first-level classifier to obtain a first classification result, where the first classification result is used to represent the cipher principle category to which the ciphertext message belongs; Determine a second-level classifier according to the first classification result, and identify the feature vector through the second-level classifier to obtain a second classification result, where the second classification result is used to represent the encryption algorithm type to which the encrypted message belongs.
2. The method according to claim 1, wherein Determining the feature vector corresponding to the ciphertext message includes: Obtain the statistical features of the ciphertext message, where the statistical features at least include the total amount index, variation index, average index, and information entropy of the ASCII code bytes in the ciphertext message; Obtain the entropy features of the ciphertext message, where the entropy features at least include the inter-group bit entropy and intra-group bit entropy of the ciphertext message; Fuse the statistical features and the entropy features to obtain the feature vector.
3. The method according to claim 2, wherein Obtaining the entropy features of the ciphertext message includes: Divide the encrypted message according to a first preset packet length to obtain a first packet message; Determine the bit position of each bit in the first packet message; Determine the occurrence frequency of the target bit in the bit position to obtain a first bit frequency, where the target bit includes bit 0 and bit 1; Determine the inter-group bit entropy of the ciphertext message according to the first bit frequency.
4. The method according to claim 3, wherein Obtaining the entropy features of the ciphertext message further includes: Divide the encrypted message according to a second preset packet length to obtain a second packet message; Determine the occurrence frequency of each bit in the second packet message to obtain a second bit frequency; Determine the intra-group bit entropy of the ciphertext message according to the second bit frequency.
5. The method according to claim 1, wherein The first-level classifier is a multi-layer perceptron network, where the multi-layer perceptron network includes a first fully connected layer, a second fully connected layer, and an activation function. The first fully connected layer and the second fully connected layer are used to perform feature mapping on the feature vector, and the activation function is used to perform a non-linear transformation on the feature vector.
6. The method according to claim 5, wherein The multi-layer perceptron network is trained in the following manner: Obtain historical ciphertext messages and determine category labels corresponding to the historical ciphertext messages, where the historical ciphertext messages include historical encrypted messages and historical unencrypted messages, and the category labels are used to represent the true cipher principle categories to which the historical ciphertext messages belong; Determine historical feature vectors corresponding to the historical ciphertext messages; Train an initial classifier according to the historical feature vectors and the category labels until the training stops after reaching a preset number of iterations, and obtain the multi-layer perceptron network.
7. The method according to claim 1, wherein The method further includes: Determine the cipher principle category in the first classification result, where the cipher principle category includes an encryption algorithm category and a non-encryption algorithm category, and the encryption algorithm category includes at least one of the following: block cipher, public key cipher, stream cipher, and hash function; When the first classification result indicates that the cryptographic message belongs to the category of encryption algorithms, the secondary classifier is used to identify the cryptographic message, and the second classification result obtained by the secondary classifier is determined as the identification result of the cryptographic message; When the first classification result indicates that the cryptographic message belongs to the category of non-encryption algorithms, the first classification result is determined as the identification result of the cryptographic message.
8. The method according to claim 7, wherein Determining a secondary classifier according to the first classification result, and identifying the feature vector through the secondary classifier, including: When the first classification result indicates that the cryptographic message belongs to block cipher, the first classifier corresponding to the block cipher is used to identify the feature vector; When the first classification result indicates that the cryptographic message belongs to public-key cipher, the second classifier corresponding to the public-key cipher is used to identify the feature vector; When the first classification result indicates that the cryptographic message belongs to stream cipher, the third classifier corresponding to the stream cipher is used to identify the feature vector; When the first classification result indicates that the cryptographic message belongs to hash function, the fourth classifier corresponding to the hash function is used to identify the feature vector.
9. An identification device for a cryptographic algorithm, characterized in that, Including: An acquisition module, configured to acquire a cryptographic message and determine a feature vector corresponding to the cryptographic message, where the cryptographic message includes an encrypted message and a non-encrypted message; A first identification module, configured to identify the feature vector through a primary classifier to obtain a first classification result, where the first classification result is used to represent the category of cryptographic principle to which the cryptographic message belongs; A second identification module, configured to determine a secondary classifier according to the first classification result, and identify the feature vector through the secondary classifier to obtain a second classification result, where the second classification result is used to represent the type of encryption algorithm to which the encrypted message belongs.
10. An electronic device, characterized in that, Including: A memory and a processor, where the memory is configured to store program instructions; The processor is connected to the memory and is configured to execute the method for identifying a cryptographic algorithm according to any one of claims 1 to 8.
11. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, where the device where the non-volatile storage medium is located executes the method for identifying a cryptographic algorithm according to any one of claims 1 to 8 by running the computer program.
12. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, the method for identifying a cryptographic algorithm according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Ensemble learning-based cryptographic algorithm multilayer composite identification method
CN114070547A
General cryptographic algorithm identification method based on ciphertext features
CN114528564A
Ciphertext encryption algorithm identification method and device
CN119155026A
Method, computing device and computer-readable medium for classification of encrypted data using neural network
US20220405474A1
Encrypted traffic identification method, and system, terminal and storage medium
WO2022094926A1