Encrypted traffic anomaly detection method and system for MQTTS protocol
Through the three-level structured analysis of the MQTTS protocol and the hierarchical sliding window design, combined with combined entropy detection and spectrum analysis, the traffic identification problem of IoT devices in an encrypted environment is solved, and high reliability and high accuracy abnormal detection is achieved.
Patent Information
- Application Number
- CN202510604965.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-11
AI Technical Summary
When facing encryption protocols such as MQTTS, existing IoT device identification technology cannot effectively process the encrypted protocol fields, resulting in the failure of the device fingerprint, and lacks anti-interference capabilities in an open network environment, making it difficult to distinguish between IoT and non-IoT traffic, and lacks the ability to hierarchically resolve protocol frame structure, forming a security blind spot.
By performing three-level structural analysis of the traffic data information under the MQTTS protocol, the field features of the fixed header layer, variable header layer and payload layer are extracted, and a layered sliding window design is adopted, combining entropy detection indicators, layered low-rank decomposition and spectrum analysis are combined, and the joint judgment value is calculated for encrypted traffic anomaly detection.
It realizes fine-grained feature extraction of encrypted traffic without decryption, can accurately detect abnormal traffic, improves the reliability and accuracy of detection, and breaks through the limitations of traditional methods.
Smart Images

Figure CN120301680A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of electrical automation, and particularly relates to an encrypted traffic anomaly detection method and system for the MQTTS protocol. Background Art
[0002] With the development of economic technology and the improvement of people's living standards, electric energy has become an essential secondary energy source in people's production and life, bringing endless convenience to people's production and life. Therefore, ensuring the stable and reliable supply of electric energy has become one of the most important tasks of the power system.
[0003] At present, a large number of Internet of Things (IoT) devices are operating in the power system, so the identification of IoT devices is particularly important. Currently, IoT device identification technology mainly relies on plaintext packet parsing or global traffic statistical features. However, with the wide application of encrypted protocols such as MQTTS in the IoT field, traditional methods face serious limitations: First, the existing plaintext parsing schemes based on deep packet inspection cannot process encrypted protocol fields, which will cause the fingerprints of devices to become invalid; Second, the existing schemes based on traffic statistical features have insufficient anti-interference ability in an open network environment, and can neither distinguish IoT traffic from non-IoT traffic nor resist the malicious behavior of attackers forging statistical characteristics; Finally, the existing schemes also lack the hierarchical parsing ability for protocol frame structures, forming obvious security blind spots in an encrypted environment. Summary of the Invention
[0004] One object of the present invention is to provide an encrypted traffic anomaly detection method for the MQTTS protocol with high reliability and good accuracy.
[0005] Another object of the present invention is to provide a system for implementing the encrypted traffic anomaly detection method for the MQTTS protocol.
[0006] The encrypted traffic anomaly detection method for the MQTTS protocol provided by the present invention includes the following steps:
[0007] S1. Real-time obtain traffic data information under the MQTTS protocol;
[0008] S2. Perform structured parsing of the protocol frame structure on the data information obtained in step S1 to extract keyword field features;
[0009] S3. Design a hierarchical sliding window according to the keyword field features obtained in step S2 to achieve feature monitoring at multiple time granularities;
[0010] S4. Calculate a combined entropy detection index, perform hierarchical low-rank decomposition and residual calculation, and perform spectrum analysis according to the monitoring information obtained in step S3;
[0011] S5. Calculate the joint decision value of the traffic data information based on the calculation results of the combined entropy detection index and the residual obtained in step S4;
[0012] S6. Complete the encrypted traffic anomaly detection for the MQTTS protocol according to the joint decision value obtained in step S5.
[0013] The step of performing structured parsing of the protocol frame structure on the data information obtained in step S1 to extract key field features in step S2 specifically includes the following steps:
[0014] Based on the data information obtained in step S1, perform three-level structured parsing on the MQTTS protocol message, and extract the field features of the fixed header layer, variable header layer, and payload layer respectively;
[0015] Fixed header layer:
[0016] Parse the control message type and QoS level fields, and calculate the type transition probability matrix using the following formula:
[0017]
[0018] where P type (i,j) is the transition probability from message type i to message type j within the sliding window W1(t), and at the same time P type (i,j) is the element in the i-th row and j-th column of the type transition probability matrix;
[0019] Variable header layer:
[0020] Analyze the message identifier sequence, and calculate the Topic name feature using the following formula:
[0021]
[0022] where L topic is the Topic name feature; N is the number of messages within the sliding window; len(Topic k ) is the length of the Topic of the k-th message;
[0023] Payload layer:
[0024] For the encrypted content, obtain the encrypted payload length; calculate the length distribution feature using the following formula:
[0025] L payload =[μ l ,σ l ,max(l i )]
[0026] where L payloadis the length distribution feature; μ l is the mean value of the load lengths within the sliding window W2(t); σ l is the standard deviation of the load lengths within the sliding window W2(t); l i is the load length of the i-th message; [] is the vector symbol.
[0027] The design of the hierarchical sliding window described in step S3 specifically includes the following steps:
[0028] In the fixed header layer, a first-period sliding window is adopted to track in real time the changes in the control message type and flag bits;
[0029] In the variable header layer and the payload layer, a second-period sliding window is adopted to analyze in real time the evolution laws of the message identifier sequence and Topic features, as well as the change trend of the encrypted data length distribution;
[0030] The following formula is used to set the first-period window:
[0031] W1(t) = {p t-n , p t-n+1 ,..., p t}
[0032] where W1(t) is the first-period window; p t is the t-th message; n is the message capacity within the first-period window;
[0033] The following formula is used to set the second-period window:
[0034] W2(t) = {p t-m , p t-m+1 ,..., p t}
[0035] where W2(t) is the second-period window; m is the message capacity within the second-period window; Since high-frequency short-time features reflecting instantaneous behavior patterns are extracted in the fixed header layer, and low-frequency long-time features are extracted in the variable header layer and the payload layer, m is generally greater than n;
[0036] The calculation of the combined entropy detection index, hierarchical low-rank decomposition and residual calculation, and spectrum analysis are carried out according to the monitoring information obtained in step S4, specifically including the following steps:
[0037] According to the monitoring information obtained in step S3, the fixed header type entropy, variable header type entropy, and payload type entropy are calculated respectively, and the combined entropy detection index is calculated;
[0038] Based on the monitoring information obtained in step S3, a feature tensor is constructed based on the multi-dimensional feature space of time, fields, devices, and statistics, and hierarchical low-rank decomposition and residual calculation are performed.
[0039] For the monitoring information obtained according to step S3, calculate the fixed header type entropy, variable header type entropy, and payload type entropy respectively, and calculate the combined entropy detection index, which specifically includes the following steps:
[0040] The fixed header type entropy is calculated using the following formula:
[0041]
[0042] In the formula, H type is the fixed header type entropy;
[0043] The variable header type entropy is calculated using the following formula:
[0044]
[0045] In the formula, H topic is the variable header type entropy; H(T k ) is the character entropy of each Topic, and T k is the Topic name string in the kth message, and P(c) is the occurrence frequency of each character in the Topic string;
[0046] The payload type entropy is calculated using the following formula:
[0047]
[0048] In the formula, H payload is the payload type entropy; P(b) is the probability that the payload length falls within the interval b; BH is the preset set of payload length binning intervals;
[0049] The combined entropy detection index H is calculated using the following formula:
[0050] H = αH type + βH topic + γH payload
[0051] In the formula, α is the first weight; β is the second weight; γ is the third weight.
[0052] For the monitoring information obtained according to step S3, a feature tensor is constructed based on the multi-dimensional feature space of time, fields, devices, and statistics, and hierarchical low-rank decomposition and residual calculation are performed, which specifically includes the following steps:
[0053] The constructed feature tensor x is expressed as Where A is the device dimension; B is the time window dimension, and T is the window length, τ is the window step size; C is the protocol field dimension; D is the statistic feature dimension;
[0054] For the constructed feature tensor x, the hierarchical Tucker decomposition algorithm is used for decomposition;
[0055] The following formula is used for residual calculation:
[0056]
[0057] Where R is the residual value; x is the result of the hierarchical Tucker decomposition of the feature tensor x; is the reconstructed tensor, and Where G is the core tensor; × k is the k-mode product; U k is the factor matrix of the k-th mode;
[0058] The core tensor G and the factor matrix U of the Tucker decomposition k are obtained by high-order singular value decomposition, and the Frobenius norm of the residual tensor R is used to generate the anomaly score.
[0059] According to the calculation results of the combined entropy detection index and the residual calculation result obtained in step S4 in step S5, calculate the joint decision value of the traffic data information, which specifically includes the following steps:
[0060] The following formula is used to calculate the joint decision value Score of the traffic data information:
[0061]
[0062] In the formula, α1 is the weight of the combined entropy detection index; β1 is the weight of the residual value; γ1 is the weight of the frequency domain similarity; μ H is the mean value of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; σ H is the standard deviation of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; ||R|| is the anomaly discrimination function of the residual value; μ R is the average value of the residual values of the traffic data information under the historical MQTTS protocol; σ R is the standard deviation of the residual values of the traffic data information under the historical MQTTS protocol; σ S is the standard deviation of the frequency domain similarity of the traffic data information under the historical MQTTS protocol.
[0063] According to the joint decision value obtained in step S5 in step S6, complete the encrypted traffic anomaly detection for the MQTTS protocol, which specifically includes the following steps:
[0064] If the combined decision value obtained in step S5 is greater than the set dynamic threshold τ, it is directly determined that the encrypted traffic of the MQTTS protocol is abnormal.
[0065] The present invention also provides a system for implementing the method for detecting abnormal encrypted traffic for the MQTTS protocol, including a data acquisition module, a data parsing module, a feature monitoring module, a parameter calculation module, a decision calculation module, and an anomaly detection module; the data acquisition module, the data parsing module, the feature monitoring module, the parameter calculation module, the decision calculation module, and the anomaly detection module are connected in series in sequence; the data acquisition module is used to obtain traffic data information under the MQTTS protocol in real time and upload the data information to the data parsing module; the data parsing module is used to perform structured parsing of the protocol frame structure on the obtained data information according to the received data information to extract keyword field features and upload the data information to the feature monitoring module; the feature monitoring module is used to design a hierarchical sliding window according to the received data information and the obtained keyword field features to achieve feature monitoring at multiple time granularities and upload the data information to the parameter calculation module; the parameter calculation module is used to calculate the combined entropy detection index, perform hierarchical low-rank decomposition and residual calculation, and perform spectrum analysis according to the received data information and the obtained monitoring information, and upload the data information to the decision calculation module; the decision calculation module is used to calculate the combined decision value of the traffic data information according to the received data information and the calculation results of the combined entropy detection index and the residual calculation results, and upload the data information to the anomaly detection module; the anomaly detection module is used to complete the detection of abnormal encrypted traffic for the MQTTS protocol according to the received data information and the obtained combined decision value.
[0066] The method and system for detecting abnormal encrypted traffic for the MQTTS protocol provided by the present invention not only realizes the detection of abnormal encrypted traffic for the MQTTS protocol by extracting and monitoring keyword field features from traffic data information under the MQTTS protocol, as well as calculating and determining information entropy, residual, and frequency domain similarity, but also has better reliability and accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 It is a schematic flowchart of the method of the present invention.
[0068] Figure 2 It is a schematic diagram of the functional modules of the system of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0069] As Figure 1 shown is a schematic flowchart of the method of the present invention: The method for detecting abnormal encrypted traffic for the MQTTS protocol disclosed by the present invention includes the following steps:
[0070] S1. Obtain the traffic data information under the MQTTS protocol in real time;
[0071] S2. Perform structured parsing of the protocol frame structure on the data information obtained in step S1 to extract keyword field features; specifically including the following steps:
[0072] Based on the data information obtained in step S1, perform three-level structured parsing on the MQTTS protocol message, and extract the field features of the fixed header layer, variable header layer, and payload layer respectively;
[0073] Fixed header layer:
[0074] Parse the control message type and QoS level fields, and calculate the type transition probability matrix using the following formula:
[0075]
[0076] In the formula, P type (i,j) is the transition probability from message type i to message type j within the sliding window W1(t). At the same time, P type (i,j) is the element in the i-th row and j-th column of the type transition probability matrix;
[0077] Variable header layer:
[0078] Analyze the message identifier sequence, and calculate the Topic name feature using the following formula:
[0079]
[0080] In the formula, L topic is the Topic name feature; N is the number of messages within the sliding window; len(Topic k ) is the length of the Topic of the k-th message;
[0081] For the encrypted content, obtain the encrypted payload length; calculate the length distribution feature using the following formula:
[0082] L payload =[μ l ,σ l ,max(l i )]
[0083] In the formula, L payload is the length distribution feature; μ l is the mean value of the payload length within the sliding window W2(t); σ l is the standard deviation of the payload length within the sliding window W2(t); l i is the payload length of the i-th message; [] is the vector symbol;
[0084] Through this hierarchical parsing method, fine-grained feature extraction of encrypted traffic can be achieved without decryption, providing fine-grained feature input for subsequent anomaly detection;
[0085] S4. Based on the keyword field features obtained in step S3, design a hierarchical sliding window to achieve feature monitoring at multiple time granularities; specifically including the following steps:
[0086] In the fixed header layer, adopt the first-period sliding window to track the changes of control message types and flag bits in real time;
[0087] In the variable header layer and the payload layer, adopt the second-period sliding window to analyze the evolution law of the message identifier sequence and Topic features in real time, as well as the change trend of the encrypted data length distribution;
[0088] The following formula is used to set the first-period window:
[0089] W1(t) = {p t-n , p t-n+1 ,..., p t}
[0090] Where W1(t) is the first-period window; p t is the t-th message; n is the message capacity within the first-period window;
[0091] The following formula is used to set the second-period window:
[0092] W2(t) = {p t-m , p t-m+1 ,..., p t}
[0093] Where W2(t) is the second-period window; m is the message capacity within the second-period window; Since high-frequency short-time features reflecting instantaneous behavior patterns are extracted in the fixed header layer, and low-frequency long-time features are extracted in the variable header layer and the payload layer, m is generally greater than n;
[0094] Through this hierarchical design, refined monitoring of protocol features is achieved;
[0095] S4. According to the monitoring information obtained in step S3, calculate the combined entropy detection index, perform hierarchical low-rank decomposition and residual calculation, and perform spectrum analysis; specifically including the following steps:
[0096] According to the monitoring information obtained in step S3, calculate the fixed header type entropy, variable header type entropy, and payload type entropy respectively, and calculate the combined entropy detection index; specifically including the following steps:
[0097] The fixed header type entropy is calculated using the following formula:
[0098]
[0099] where H type is the fixed header type entropy;
[0100] The variable header type entropy is calculated using the following formula:
[0101]
[0102] where H topic is the variable header type entropy; H(T k ) is the character entropy of each Topic, and T k is the Topic name string in the k-th message, and P(c) is the frequency of occurrence of each character in the Topic string;
[0103] The payload type entropy is calculated using the following formula:
[0104]
[0105] where H payload is the payload type entropy; P(b) is the probability that the payload length falls within the interval b; BH is the set of preset payload length binning intervals;
[0106] The combined entropy detection index H is calculated using the following formula:
[0107] H = αH type + βH topic + γH payload
[0108] where α is the first weight; β is the second weight; γ is the third weight;
[0109] By constructing the combined entropy detection index, a comprehensive evaluation of the abnormal behaviors of each layer of the protocol is realized;
[0110] According to the monitoring information obtained in step S3, based on the multi-dimensional feature space of time, field, device, and statistic, a feature tensor is constructed, and hierarchical low-rank decomposition and residual calculation are performed; specifically, the following steps are included:
[0111] The constructed feature tensor x is expressed as where A is the device dimension; B is the time window dimension, and Let \(T\) be the window length and \(\tau\) be the window step size; \(C\) is the dimension of the protocol field, generally 3 layers. When \(C = 1\), it is the fixed header entropy; when \(C = 2\), it is the Topic length feature; when \(C = 3\), it is the payload length feature; \(D\) is the dimension of the statistic feature, storing the statistics of each feature, including 5 indicators: mean, standard deviation, maximum value, entropy value, and binned probability.
[0112] For the constructed feature tensor \(x\), a hierarchical Tucker decomposition algorithm is used for decomposition.
[0113] The following formula is used for residual calculation:
[0114]
[0115] where \(R\) is the residual value; \(x\) is the result of the hierarchical Tucker decomposition of the feature tensor \(x\); is the reconstructed tensor, and where \(G\) is the core tensor; \(\times\) k is the k-mode product; \(U\) k is the factor matrix of the k-th mode;
[0116] In the specific implementation process, under normal traffic, the norm of the residual approaches zero; while under abnormal traffic, the norm of the residual increases significantly.
[0117] The core tensor \(G\) and factor matrix \(U\) of the Tucker decomposition k are obtained through high-order singular value decomposition, and the Frobenius norm of the residual tensor \(R\) is used to generate the anomaly score.
[0118] By constructing a feature tensor, the behavior patterns of IoT devices are comprehensively characterized; in the time dimension, the feature evolution process is recorded, the field dimension covers the key features of each layer of the protocol, the device dimension distinguishes different terminal characteristics, and the statistic dimension integrates multiple indicators such as mean and variance; this model breaks through the limitations of the traditional two-dimensional feature matrix and can capture the spatio-temporal correlation characteristics in device communication more completely.
[0119] By setting appropriate rank constraints for the fixed header, variable header, and payload feature dimensions respectively, while retaining the main behavior patterns, the abnormal components are effectively separated; after tensor decomposition using the alternating least squares method, by analyzing the decomposition residuals of each field dimension, the specific protocol fields that may have anomalies are accurately located.
[0120] S5. According to the calculation results of the combined entropy detection index and the residual calculation results obtained in step S4, calculate the joint decision value of the traffic data information; specifically, it includes the following steps:
[0121] The following formula is used to calculate the joint decision value Score of the traffic data information:
[0122]
[0123] where α1 is the weight of the combined entropy detection index; β1 is the weight of the residual value; γ1 is the weight of the frequency domain similarity; μ H is the mean value of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; σ H is the standard deviation of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; ||R|| is the anomaly discrimination function of the residual value; μ R is the average value of the residual value of the traffic data information under the historical MQTTS protocol; σ R is the standard deviation of the residual value of the traffic data information under the historical MQTTS protocol; σ S is the standard deviation of the frequency domain similarity of the traffic data information under the historical MQTTS protocol;
[0124] S6. According to the joint decision value obtained in step S5, complete the encrypted traffic anomaly detection for the MQTTS protocol; specifically, it includes the following steps:
[0125] If the joint decision value obtained in step S5 is greater than the set dynamic threshold τ, it is directly determined that the encrypted traffic of the MQTTS protocol is abnormal;
[0126] In specific implementation, the joint decision value can also be calculated according to the existing normal traffic and abnormal traffic, so as to determine the value range of the dynamic threshold.
[0127] Through multi-level protocol parsing and multi-dimensional feature fusion analysis, the present invention realizes the refined anomaly detection of MQTTS encrypted traffic; its beneficial effects are mainly reflected in: First, adopting a three-level structured parsing method, without cracking the encrypted content, the keyword field features of each layer of the protocol are completely extracted; Second, through the hierarchical sliding window design, the multi-time granularity monitoring of the protocol features is realized, taking into account both real-time and long-term trend analysis; Third, combining information entropy calculation, four-dimensional tensor modeling and frequency domain analysis, a comprehensive device behavior characterization system is constructed; Finally, based on the multi-dimensional joint decision mechanism, the accuracy and interpretability of attack detection are significantly improved; The solution of the present invention effectively solves the key technical problems such as insufficient feature extraction and single detection dimension in the security monitoring of Internet of Things encrypted traffic, and provides an innovative solution for the total detection in the encrypted protocol environment such as MQTTS.
[0128] Such as Figure 2The following is a schematic diagram of the functional modules of the system of the present invention: The system for implementing the method for detecting abnormal encrypted traffic for the MQTTS protocol disclosed in the present invention includes a data acquisition module, a data parsing module, a feature monitoring module, a parameter calculation module, a decision calculation module, and an abnormal detection module; the data acquisition module, the data parsing module, the feature monitoring module, the parameter calculation module, the decision calculation module, and the abnormal detection module are connected in series in sequence; the data acquisition module is used to acquire traffic data information under the MQTTS protocol in real time and upload the data information to the data parsing module; the data parsing module is used to perform structured parsing of the protocol frame structure on the acquired data information according to the received data information to extract keyword field features and upload the data information to the feature monitoring module; the feature monitoring module is used to design a hierarchical sliding window according to the received data information and the obtained keyword field features to achieve feature monitoring at multiple time granularities and upload the data information to the parameter calculation module; the parameter calculation module is used to calculate the combined entropy detection index, perform hierarchical low-rank decomposition and residual calculation, and perform spectrum analysis according to the received data information and the obtained monitoring information, and upload the data information to the decision calculation module; the decision calculation module is used to calculate the joint decision value of the traffic data information according to the received data information and the obtained combined entropy detection index calculation result and residual calculation result, and upload the data information to the abnormal detection module; the abnormal detection module is used to complete the detection of abnormal encrypted traffic for the MQTTS protocol according to the received data information and the obtained joint decision value.
Claims
1. An encrypted traffic anomaly detection method for the MQTTS protocol, comprising the following steps: S1. Real-time obtain traffic data information under the MQTTS protocol; S2. Perform structured parsing of the protocol frame structure on the data information obtained in step S1 to extract keyword field features; S3. Design a hierarchical sliding window based on the keyword field features obtained in step S2 to achieve feature monitoring at multiple time granularities; S4. According to the monitoring information obtained in step S3, calculate combined entropy detection metrics, perform hierarchical low-rank decomposition and residual calculation, and perform spectral analysis; S5. Calculate the joint decision value of the traffic data information based on the combined entropy detection metric calculation result and the residual calculation result obtained in step S4; S6. Complete the encrypted traffic anomaly detection for the MQTTS protocol based on the joint decision value obtained in step S5.
2. The encryption traffic anomaly detection method for the MQTTS protocol according to claim 1, characterized in that The step of performing structured parsing of the protocol frame structure on the data information obtained in step S1 to extract keyword field features specifically includes the following steps: Based on the data information obtained in step S1, perform three-level structured parsing on the MQTTS protocol message to extract the field features of the fixed header layer, variable header layer, and payload layer respectively; Fixed header layer: Parse the control message type and QoS level fields, and calculate the type transition probability matrix using the following formula: where P type (i, j) is the transition probability from message type i to message type j within the sliding window W1(t), and at the same time P type (i, j) is the element in the i-th row and j-th column of the type transition probability matrix; Variable header layer: Analyze the message identifier sequence, and calculate the Topic name feature using the following formula: where L topic is the Topic name feature; N is the number of messages in the sliding window; len(Topic k ) is the length of the Topic of the k-th message; Payload layer: For the encrypted content, obtain the encrypted payload length; calculate the length distribution feature using the following formula: L payload = [μ l , σ l , max(l i )] where L payload is the length distribution characteristic; μ l is the mean value of the load lengths within the sliding window W2(t); σ l is the standard deviation of the load lengths within the sliding window W2(t); l i is the load length of the i-th message; [] is the vector symbol.
3. The encrypted traffic anomaly detection method for the MQTTS protocol according to claim 2, characterized in that The step of designing a hierarchical sliding window described in step S3 specifically includes the following steps: In the fixed header layer, use a first-period sliding window to track the changes of the control message type and flag bits in real time; In the variable header layer and payload layer, use a second-period sliding window to analyze the evolution law of the message identifier sequence and Topic features in real time, as well as the change trend of the encrypted data length distribution; Set the first-period window using the following formula: W1(t) = {p t-n , p t-n+1 ,..., p t} where W1(t) is the first-period window; p t is the t-th packet; n is the packet capacity within the first-period window; Set the second-period window using the following formula: W2(t) = {p t-m , p t-m+1 ,..., p t} Where W2(t) is the second-period window; m is the message capacity within the second-period window.
4. The encryption traffic anomaly detection method for the MQTTS protocol according to claim 3, wherein The step of calculating combined entropy detection metrics, performing hierarchical low-rank decomposition and residual calculation, and performing spectral analysis according to the monitoring information obtained in step S3 described in step S4 specifically includes the following steps: According to the monitoring information obtained in step S3, calculate the fixed header type entropy, variable header type entropy, and payload type entropy respectively, and calculate the combined entropy detection metric; According to the monitoring information obtained in step S3, based on the multi-dimensional feature space of time, field, device, and statistic, Construct a feature tensor, and perform hierarchical low-rank decomposition and residual calculation.
5. The encryption traffic anomaly detection method for the MQTTS protocol according to claim 4, characterized in that The step of calculating the fixed header type entropy, variable header type entropy, and payload type entropy respectively according to the monitoring information obtained in step S3, and calculating the combined entropy detection metric specifically includes the following steps: Calculate the fixed header type entropy using the following formula: where H type is the entropy of the fixed header type; Calculate the variable header type entropy using the following formula: Where H topic is the variable header type entropy; H(T k ) is the character entropy of each Topic, and T k is the Topic name string in the k-th message, and P(c) is the occurrence frequency of each character in the statistical Topic string; Calculate the payload type entropy using the following formula: where H payload is the payload type entropy; P(b) is the probability that the payload length falls within the interval b; BH is a preset set of payload length bin intervals; The combined entropy detection index H is calculated using the following formula: H = αH type + βH topic + γH payload where α is the first weight; β is the second weight; γ is the third weight.
6. The encrypted traffic anomaly detection method for the MQTTS protocol according to claim 5, wherein Based on the monitoring information obtained in step S3, a feature tensor is constructed in a multi-dimensional feature space of time, field, device, and statistic, and hierarchical low-rank decomposition and residual calculation are performed. The specific steps are as follows: The constructed feature tensor x is represented as where A is the device dimension; B is the time window dimension, and T is the window length, τ is the window step; C is the protocol field dimension; D is the statistic feature dimension; For the constructed feature tensor x, hierarchical Tucker decomposition algorithm is used for decomposition; The following formula is used for residual calculation: where R is the residual value; x is the hierarchical Tucker decomposition result of the feature tensor x; is the reconstructed tensor, and where G is the core tensor; × k is the k-mode product; U k is the factor matrix of the k-th mode; The core tensor G and factor matrix U of Tucker decomposition k Obtained by high-order singular value decomposition, the Frobenius norm of the residual tensor R is used to generate the anomaly score.
7. The encrypted traffic anomaly detection method for the MQTTS protocol according to claim 6, characterized in that Based on the combined entropy detection index calculation result and residual calculation result obtained in step S4 in step S5, the joint decision value of the traffic data information is calculated. The specific steps are as follows: The joint decision value Score of the traffic data information is calculated using the following formula: Where α1 is the weight of the combined entropy detection index; β1 is the weight of the residual value; γ1 is the weight of the frequency domain similarity; μ H is the mean value of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; σ H is the standard deviation of the combined entropy detection index of the traffic data information under the historical MQTTS protocol; ||R|| is the abnormal discrimination function of the residual value; μ R is the average value of the residual values of the traffic data information under the historical MQTTS protocol; σ R is the standard deviation of the residual values of the traffic data information under the historical MQTTS protocol; σ S is the standard deviation of the frequency domain similarity of the traffic data information under the historical MQTTS protocol.
8. The method for detecting abnormal encrypted traffic for the MQTTS protocol according to claim 7, characterized in that Based on the joint decision value obtained in step S5 in step S6, the encrypted traffic anomaly detection for the MQTTS protocol is completed. The specific steps are as follows: If the joint decision value obtained in step S5 is greater than the set dynamic threshold τ, it is directly determined that the encrypted traffic of the MQTTS protocol is abnormal.
9. A system for implementing the encrypted traffic anomaly detection method for the MQTTS protocol according to any one of claims 1 to 8, characterized in that It includes a data acquisition module, a data parsing module, a feature monitoring module, a parameter calculation module, a decision calculation module, and an anomaly detection module; the data acquisition module, the data parsing module, the feature monitoring module, the parameter calculation module, the decision calculation module, and the anomaly detection module are connected in series in sequence; the data acquisition module is used to obtain the traffic data information under the MQTTS protocol in real time and upload the data information to the data parsing module; The data parsing module is used to perform structured parsing of the protocol frame structure on the obtained data information according to the received data information to extract the keyword field features and upload the data information to the feature monitoring module; The feature monitoring module is used to design a hierarchical sliding window according to the received data information and the obtained keyword field features to achieve feature monitoring of multiple time granularities and upload the data information to the parameter calculation module; The parameter calculation module is used to calculate the combined entropy detection index, perform hierarchical low-rank decomposition and residual calculation, and perform spectrum analysis according to the received data information and the obtained monitoring information, and upload the data information to the decision calculation module; The decision calculation module is used to calculate the joint decision value of the traffic data information according to the received data information and the obtained combined entropy detection index calculation result and residual calculation result, and upload the data information to the anomaly detection module; The anomaly detection module is used to complete the encrypted traffic anomaly detection for the MQTTS protocol according to the received data information and the obtained joint decision value.
Citation Information
Cited By
Malicious encrypted traffic detection method and system based on ciphertext entropy
CN121396686A
A malicious encrypted traffic detection method and system based on ciphertext entropy value
CN121396686B