Encrypted traffic detection method and device, computer equipment and storage medium
By judging and fuzzing the handshake parameters and transmission characteristics of encrypted traffic, combined with twin network analysis, the accuracy and false alarm rate problems of existing encrypted traffic detection methods are solved, and efficient and accurate malicious traffic recognition is achieved.
Patent Information
- Application Number
- CN202510681702.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-07-18
AI Technical Summary
The existing encryption traffic detection methods have low accuracy and high false alarm rate, making it difficult to effectively identify malicious encrypted traffic.
By obtaining the handshake parameter characteristics and transmission characteristics of the encrypted traffic, the rule judgment results and fuzzy processing results are used for preliminary screening, and combining the text description of candidate malicious traffic analysis by the twin network, the target malicious traffic is further screened out.
It improves the accuracy and speed of malicious encrypted traffic detection, reduces the false alarm rate, and realizes efficient screening and identification of large-scale encrypted traffic.
Smart Images

Figure CN120342758A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and more particularly, to a method, apparatus, computer device, and storage medium for detecting encrypted traffic. Background Art
[0002] With the development of Internet technologies, the requirements for the security of data communication processes are getting higher and higher, and more and more communication processes are gradually adopting data encryption transmission methods. However, the encrypted transmission also provides convenience for malicious attackers to initiate malicious encrypted traffic. For example, malicious attackers use encrypted channels to spread viruses, Trojans, initiate advanced persistent threat attacks, etc., and initiate malicious encrypted traffic, thus affecting the security of encrypted traffic.
[0003] Therefore, how to detect malicious encrypted traffic in a timely manner during the process of secure encrypted transmission has become an important task. At present, although some detection methods for detecting malicious encrypted traffic have been proposed, these methods generally have problems such as low accuracy and high false alarm rate, and have relatively large drawbacks. Summary of the Invention
[0004] In view of this, this application provides a method, apparatus, computer device, and storage medium for detecting encrypted traffic.
[0005] Specifically, this application is implemented through the following technical solutions:
[0006] In a first aspect, an embodiment of this application provides a method for detecting encrypted traffic, including:
[0007] Obtain the traffic characteristics of each piece of encrypted traffic; the traffic characteristics include the handshake parameter characteristics of the encrypted traffic in the communication handshake phase and the transmission characteristics in the data transmission phase;
[0008] Use the rule determination result of the handshake parameter characteristics and / or the fuzzy processing result of the traffic characteristics to perform a security detection on the encrypted traffic, and determine candidate malicious traffic with potential risks in each piece of the encrypted traffic;
[0009] Generate a text description of the candidate malicious traffic according to the fuzzy processing result and the traffic characteristics;
[0010] According to the text description of each piece of the candidate malicious traffic and the text descriptions of each piece of sample malicious traffic, screen out target malicious traffic with security risks from the candidate malicious traffic.
[0011] In a possible implementation manner, according to the text description of each piece of the candidate malicious traffic and the text descriptions of each piece of sample malicious traffic, screening out target malicious traffic with security risks from the candidate malicious traffic includes:
[0012] For any one of the candidate malicious traffic flows, determine the similarity between the candidate malicious traffic flow and each sample malicious traffic flow according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow;
[0013] In the case where there is a target similarity greater than a set threshold among the similarities, determine the candidate malicious traffic flow as the target malicious traffic flow.
[0014] In a possible implementation manner, the method further includes:
[0015] Determine the security risk reason of the target malicious traffic flow according to the security risk reason of the sample malicious traffic flow corresponding to the target similarity.
[0016] In a possible implementation manner, the determining the similarity between the candidate malicious traffic flow and each sample malicious traffic flow according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow includes:
[0017] Using a siamese network with shared weights, output a first embedding feature of the candidate malicious traffic flow and second embedding features of each sample malicious traffic flow according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow;
[0018] Determine the similarity between the candidate malicious traffic flow and each sample malicious traffic flow according to the first embedding feature and the second embedding features.
[0019] In a possible implementation manner, the rule determination result is used to indicate whether the handshake parameter feature conforms to a preset detection rule;
[0020] Perform a security detection on the encrypted traffic using the rule determination result of the handshake parameter feature or the fuzzy processing result of the traffic feature, and determine candidate malicious traffic flows with potential risks among each encrypted traffic flow, including:
[0021] Using the rule determination result of the handshake parameter feature, screen out candidate malicious traffic flows whose corresponding handshake parameter features do not conform to the preset detection rule from the encrypted traffic flow, or,
[0022] Using the fuzzy processing result of the traffic feature, determine the security score of the encrypted traffic flow, and use the security score to screen out the candidate malicious traffic flows from the encrypted traffic flow.
[0023] In a possible implementation manner, the fuzzy processing result includes at least one traffic feature and its fuzzy result parameter;
[0024] Determining the security score of the encrypted traffic by using the fuzzy processing result of the traffic feature includes:
[0025] Determining an initial score of the fuzzy processing result by using the weight corresponding to the fuzzy result parameter of each traffic feature in the fuzzy processing result;
[0026] Determining the security score of the encrypted traffic based on the initial score of each fuzzy processing result.
[0027] In a possible implementation manner, performing a security detection on the encrypted traffic by using the rule determination result of the handshake parameter feature and the fuzzy processing result of the traffic feature, and determining candidate malicious traffic with potential risks in each piece of the encrypted traffic, including:
[0028] Filtering out candidate malicious traffic with corresponding handshake parameter features not conforming to the preset detection rule and target encrypted traffic conforming to the preset detection rule from the encrypted traffic by using the rule determination result;
[0029] Determining the security score of the target encrypted traffic by using the fuzzy processing result of the traffic feature of the target encrypted traffic;
[0030] Filtering out the candidate malicious traffic from the target encrypted traffic by using the security score of the target encrypted traffic.
[0031] In a possible implementation manner, the twin network is trained according to the following steps:
[0032] Obtaining sample encrypted traffic; the sample encrypted traffic includes multiple pieces of sample malicious traffic and multiple pieces of sample candidate malicious traffic;
[0033] Using the twin network to be trained, and outputting a first sample feature of each piece of the sample candidate malicious traffic and a second sample feature of each piece of the sample malicious traffic according to the text description of each piece of the sample candidate malicious traffic and the text description of each piece of the sample malicious traffic;
[0034] Determining the sample similarity between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic according to the first sample feature and the second sample feature;
[0035] Determining the prediction loss of the twin network to be trained according to the class consistency label between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic and the sample similarity between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic;
[0036] Performing iterative training on the twin network to be trained by using the prediction loss until the training cutoff condition is satisfied, and obtaining the trained twin network.
[0037] In a second aspect, an embodiment of the present application further provides a detection device for encrypted traffic, including:
[0038] An acquisition module, configured to acquire the traffic characteristics of each piece of encrypted traffic; the traffic characteristics include the handshake parameter characteristics of the encrypted traffic in the communication handshake phase and the transmission characteristics in the data transmission phase;
[0039] A determination module, configured to perform a security detection on the encrypted traffic by using the rule determination result of the handshake parameter characteristics and / or the fuzzy processing result of the traffic characteristics, and determine candidate malicious traffic with potential risks in each piece of the encrypted traffic;
[0040] A generation module, configured to generate a text description of the candidate malicious traffic according to the fuzzy processing result and the traffic characteristics;
[0041] A screening module, configured to screen out target malicious traffic with security risks from the candidate malicious traffic according to the text description of each piece of the candidate malicious traffic and the text description of each piece of sample malicious traffic.
[0042] In a third aspect, an alternative implementation of the present application further provides a computer-readable storage medium, including a computer program, which when run, implements the steps in the first aspect or any possible implementation manner in the first aspect.
[0043] In a fourth aspect, an alternative implementation of the present application further provides a computer device, including a processor and a memory. The memory stores machine-readable instructions executable by the processor. The processor is configured to execute the machine-readable instructions stored in the memory, and when the machine-readable instructions are executed by the processor, the steps in the first aspect or any possible implementation manner in the first aspect are executed.
[0044] The detection method, device, computer equipment and storage medium for encrypted traffic provided by the embodiments of the present application can determine whether there are potential risks in the encrypted traffic during the handshake stage by making rule judgments on the handshake parameter characteristics of the encrypted traffic during the communication handshake stage, and / or can determine whether there are potential risks in the encrypted traffic during the transmission stage by using the fuzzy processing results obtained by performing fuzzy processing on the transmission characteristics. Therefore, by performing security detection on the encrypted traffic by using the rule judgment results and / or the fuzzy processing results, it is possible to quickly screen out some candidate malicious traffic with potential risks from a large number of encrypted traffic. Then, by using the text descriptions of the candidate malicious traffic and the text descriptions of each sample malicious traffic, further risk detection is performed on the candidate malicious traffic, which can reduce the scale of the traffic to be detected while accurately eliminating the candidate malicious traffic that may be misdetected, thereby improving the accuracy and speed of malicious encrypted traffic detection and avoiding the false alarm problem. Generally speaking, the present application first uses the rule judgment results and / or the fuzzy processing results to perform a preliminary screening on a large number of encrypted traffic, and then performs a further screening on the candidate malicious traffic obtained from the preliminary screening, which can effectively reduce the false alarm rate and improve the detection accuracy.
[0045] To make the above objects, features and advantages of the present application more obvious and understandable, the following specifically gives preferred embodiments and detailed descriptions in conjunction with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 The flowchart of a detection method for encrypted traffic provided by the embodiments of the present application is shown;
[0047] Figure 2 The schematic structural diagram of a twin network provided by the embodiments of the present application is shown;
[0048] Figure 3 The architecture diagram of a detection method for encrypted traffic provided by the embodiments of the present application is shown;
[0049] Figure 4 The schematic hardware structure diagram of a computer device where the detection device for encrypted traffic provided by the embodiments of the present application is located is shown;
[0050] Figure 5 The schematic diagram of a detection device for encrypted traffic provided by the embodiments of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0052] The terms used in this application are for the purpose of describing particular embodiments only and are not intended to limit the present application. The singular forms "a", "the", and "said" used in this application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0053] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0054] It has been found through research that current malicious encrypted traffic detection methods generally include the following: 1. Determine whether the encrypted traffic is malicious encrypted traffic by checking whether the Internet Protocol (IP) address of the encrypted traffic and / or the domain name of the issuing authority in the public key certificate corresponding to the encrypted traffic is located in a preset malicious encrypted traffic information table. 2. Use a deep learning model to detect the flow characteristics, certificate characteristics, domain name characteristics, etc. of the encrypted traffic to determine whether the encrypted traffic is malicious encrypted traffic. 3. Convert the payload data of the encrypted traffic into a picture, and then use a convolutional neural network to process the picture to determine whether the encrypted traffic is malicious traffic. 4. Based on the bert language representation model, perform security detection on the encrypted traffic to determine whether the encrypted traffic is malicious traffic. For method 1, it strongly depends on the construction of the malicious encrypted traffic information table. However, the IP or domain name of malicious traffic changes rapidly, making it difficult to quickly iterate and update the encrypted traffic information table. Therefore, the detection accuracy is relatively poor. For methods 2-4, although the use of deep learning networks is proposed, since malicious encrypted traffic accounts for a relatively small proportion compared to a large amount of normal encrypted traffic in daily monitoring, although the model accuracy is high, the large amount of normal encrypted traffic will amplify the false alarm problem, and the drawbacks are also very obvious. Therefore, how to improve the accuracy of malicious encrypted traffic detection while reducing the risk of false alarms has become a technical issue worthy of attention.
[0055] Based on the above research, the present application provides a detection method, device, computer device, and storage medium for encrypted traffic. By performing rule determination on the handshake parameter characteristics of encrypted traffic in the communication handshake stage, it can be determined whether there are potential risks in the handshake stage of the encrypted traffic, and / or, using the fuzzy processing result obtained by fuzzy processing the transmission characteristics, it can be determined whether there are potential risks in the transmission stage of the encrypted traffic. Therefore, using the rule determination result and / or the fuzzy processing result to perform security detection on the encrypted traffic can quickly screen out some candidate malicious traffic with potential risks from a large number of encrypted traffic. Then, using the text description of the candidate malicious traffic and the text descriptions of each sample malicious traffic to further detect the risk of the candidate malicious traffic can reduce the scale of the traffic to be detected while accurately eliminating the candidate malicious traffic that may be misdetected, thereby improving the accuracy and speed of malicious encrypted traffic detection and avoiding false alarm problems. Generally speaking, the present application first uses the rule determination result and / or the fuzzy processing result to preliminarily screen a large number of encrypted traffic, and then further screens the candidate malicious traffic obtained from the preliminary screening, which can effectively reduce the false alarm rate and improve the detection accuracy.
[0056] Regarding the defects existing in the above solutions, they are all the results obtained by the inventors through practice and careful research. Therefore, the process of discovering the above problems and the solutions proposed by this application for the above problems in the following text all belong to the contributions made by the inventors to this application during the process of this application.
[0057] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0058] It can be understood that before using the technical solutions disclosed in each embodiment of this application, the types, usage scopes, usage scenarios, etc. of the personal information involved in this application should be informed to the user and the user's authorization should be obtained through appropriate means in accordance with relevant laws and regulations.
[0059] To facilitate the understanding of this embodiment, first, a method for detecting encrypted traffic disclosed in an embodiment of this application will be introduced in detail. The execution subject of the method for detecting encrypted traffic provided in an embodiment of this application is generally a terminal device or other processing device with certain computing capabilities. Among them, the terminal device can be a user equipment (UE), a mobile device, a terminal, a personal digital assistant device (Personal Digital Assistant, PDA), a handheld device, a computer device, etc.; in some possible implementation manners, the method for detecting encrypted traffic can be implemented by a processor calling computer-readable instructions stored in a memory.
[0060] Next, the method for detecting encrypted traffic provided in an embodiment of this application will be described by taking the execution subject as a computer device as an example.
[0061] As Figure 1 shown, it is a flowchart of a method for detecting encrypted traffic provided in an embodiment of this application, which may include the following steps:
[0062] S101: Obtain the traffic characteristics of each encrypted traffic; the traffic characteristics include the handshake parameter characteristics of the encrypted traffic in the communication handshake stage and the transmission characteristics in the data transmission stage.
[0063] Here, the encrypted traffic can be each data packet sent during the communication between two communication parties. The two communication parties can use Transport Layer Security / Secure Sockets Layer (TLS / SSL) for identity authentication and data encryption.
[0064] The communication process between two communication parties may include a communication handshake stage based on the TLS / SSL encryption protocol and a data transmission stage after the handshake is successful. The handshake parameter features are the information features transmitted by the two communication parties during the communication handshake stage. For example, during the communication handshake stage of encryption protocols such as TLS / SSL, some of the information transmitted in this stage is unencrypted, and the unencrypted information can be analyzed to obtain the handshake parameter features. After the handshake is completed, the data sender among the two communication parties can send various data packets to the data receiver during the data transmission stage. By analyzing the unencrypted information during the sending process of the data packets, the transmission features can be obtained.
[0065] In the embodiments of the present application, the handshake stage features may include, but are not limited to: the certificate information of various certificates during the network protocol communication process, the version information of the TLS / SSL encryption protocol, the encryption suite selection information, the secret key information, etc. Among them, the certificate information may include the subject alternative name of the certificate, the certificate revocation status, the certificate validity period, the certificate issuing authority, etc. The version information of the TLS / SSL encryption protocol may include the version number of the encryption protocol; the encryption suite selection information may include the target encryption suite used, the encryption strength of the target encryption suite, whether the target encryption suite supports forward secrecy, whether the target encryption suite includes a reliable message authentication code (MAC), etc.; the secret key information may include the secret key length, the secret key type, etc. Certificates may include, for example, Domain Validation (DV) certificates for verifying the ownership of domain names, Organization Validation (OV) certificates for verifying enterprise identities, Extended Validation (EV) certificates for the highest level of verification, etc. Forward secrecy is an encryption feature that ensures that even if the long-term private key is leaked in the future, an attacker cannot decrypt past communication sessions.
[0066] The transmission features may include, but are not limited to: traffic volume (including the duration of traffic peaks, the magnitude of traffic surges, traffic density), transmission rate, connection frequency, packet interval, source IP address and destination IP address, IP reputation, degree of anonymity, communication time period, whether there are known security vulnerabilities in the encryption suite, whether the traffic path of the encrypted traffic retrieved from the firewall platform bypasses the firewall or Intrusion Prevention System (IPS). The degree of anonymity can be determined by analyzing the metadata and protocol features exposed in the encrypted traffic, and this information can indirectly reveal the identities or behavior patterns of the two communication parties.
[0067] In specific implementation, since there is a vast amount of encrypted traffic in daily monitoring, when performing detection, various handshake parameter features of each encrypted traffic of both communication parties in the communication handshake stage and various transmission features in the data transmission stage can be obtained, and the handshake parameter features and transmission features of each encrypted traffic are used as the traffic features of the encrypted traffic.
[0068] S102: Use the rule determination result of the handshake parameter features and / or the fuzzy processing result of the traffic features to perform security detection on the encrypted traffic, and determine the candidate malicious traffic with potential risks in each encrypted traffic.
[0069] Here, the rule determination result is used to indicate whether the handshake parameter features of the encrypted traffic conform to the preset detection rules. Here, the preset detection rules can be each rule that the handshake parameter features of secure encrypted traffic should conform to, and they can be set according to experience.
[0070] The preset detection rules can include but are not limited to: the certificate validity period detection rule, that is, whether the certificate is within the validity period, and an expired certificate will lead to trust failure; the domain name consistency detection rule, that is, ensuring that the actual site domain name accessed by the subject name of the certificate matches the preset site domain name, such as the certificate *.example.com matching a.example.com; the certificate revocation status detection, that is, determining whether the certificate is marked as revoked by the issuer; the TLS / SSL version detection rule, that is, determining that the version number of TLS / SSL is the latest version, and if it is an old version, it is determined that there are known security vulnerabilities in the TLS / SSL protocol; the cipher suite encryption strength detection rule, that is, checking whether the used cipher suite provides sufficient password strength; the key length detection rule, that is, determining that the used key length meets the requirements, for example, the key length of the Advanced Encryption Standard (AES) is at least 128 bits; the forward secrecy detection rule, that is, determining whether the used cipher suite supports forward secrecy to prevent historical sessions from being decrypted when the private key is leaked in the future; the integrity check rule, that is, determining that the used cipher suite contains a reliable MAC algorithm or a cryptographic hash function to ensure data integrity.
[0071] In specific implementation, for each handshake parameter feature, the target detection rule that matches it can be found from the preset detection rules, and it is determined whether the handshake parameter feature conforms to the target detection rule, so as to obtain the rule determination result corresponding to the handshake parameter feature.
[0072] The present application also proposes a detection method based on fuzzy inference. Fuzzy inference is an important inference method for solving uncertainty problems. Since the content of the data packets of encrypted traffic cannot be directly interpreted, fuzzy inference can identify potential malicious encrypted traffic by analyzing the non-encrypted information and behavior patterns of encrypted traffic, which has practical significance for the preliminary screening and anomaly detection of large-scale encrypted traffic. Specifically, each traffic feature can be fuzzified to obtain the fuzzy inference result of the traffic feature. The fuzzy inference result can include at least one traffic feature and the fuzzy result parameter corresponding to the feature. Among them, the fuzzy result parameter is selected from each fuzzy result parameter included in the fuzzy result set corresponding to the traffic feature. The fuzzy inference result is used to indicate the fuzzy inference result corresponding to the traffic feature.
[0073] The fuzzy result set corresponding to the traffic feature can include, but is not limited to, various sets shown in Table 1 below:
[0074]
[0075]
[0076] (Table 1)
[0077] In specific implementation, for each traffic feature, according to the specific parameters of the traffic feature and the parameter ranges of each fuzzy result parameter in the fuzzy set corresponding to the traffic feature, the fuzzy result parameter corresponding to the traffic feature can be determined. Then, based on experience, historical data, and known malicious traffic patterns, fuzzy rules can be established according to each traffic feature and its corresponding fuzzy result parameter, and the established fuzzy rules can be stored in the fuzzy rule library as the fuzzy processing result. Exemplarily, the fuzzy rules can include, but are not limited to, the following rules:
[0078] IF (The transmission rate is 'extremely high') AND (The packet interval is 'extremely unstable') THEN (The risk level is'very likely malicious'); IF (The encryption suite selected during the handshake phase is "known security vulnerabilities exist") THEN (The trust level is 'low'); IF (The traffic surge amplitude is'sharp') AND "The traffic peak duration is 'extremely short' or'short') THEN (The attack possibility is 'possible'); IF (The correlation between the source IP and the destination IP is 'irrelevant') AND (The geographical location gap between the two is 'extremely large') THEN (The probability of abnormal communication is 'high'); IF (The communication time period is 'non-business hours') AND (The traffic density is 'dense') THEN (The risk of abnormal activities is'medium to high'); IF (The certificate issuing authority is 'unknown' or The certificate validity period is 'about to expire') THEN (The certificate trust level is 'low'); IF (The strength of the encryption suite is 'weak') AND (The protocol version is 'outdated') THEN (The communication security rating is 'low'); IF (The traffic path bypasses the 'firewall' or 'IPS') THEN (The attempt to evade detection is'strong').
[0079] Specifically, the security detection can include detecting whether the handshake parameter features are secure and whether the obfuscation processing results are secure. During specific implementation, at least one of the rule determination results of the handshake parameter features and the obfuscation processing results of the traffic features can be used to perform security detection on each encrypted traffic respectively to determine whether there are potential risks in each encrypted traffic, that is, to determine whether the encrypted traffic is suspicious malicious encrypted traffic. For example, according to the rule determination results of each handshake parameter feature, determine the proportion of the handshake parameter features that meet the preset detection rules, and determine whether there are potential risks in the encrypted traffic according to this proportion. Or, set different determination weights for each handshake parameter feature, determine the determination score of the encrypted traffic according to the determination weights of the handshake parameter features that meet the preset detection rules, and screen out the candidate malicious traffic with potential risks according to the determination score. According to each obfuscation processing result, determine the proportion of the traffic features that meet the preset results, and determine whether there are potential risks in the encrypted traffic according to this proportion. Use the encrypted traffic with potential risks as candidate malicious traffic and perform further screening using S103 and S104 later to eliminate the falsely reported candidate malicious traffic. For the non-candidate malicious traffic in the encrypted traffic, it can be used as secure encrypted traffic.
[0080] It is understandable that some encrypted traffic may only have some of the traffic features that can be obtained, and the remaining traffic features cannot be obtained. For such encrypted traffic, it can be directly used as candidate encrypted traffic. At the same time, the obtained traffic features of this encrypted traffic can be obfuscated to obtain the corresponding obfuscation processing results, and then based on this obfuscation processing result, the obtained traffic features and the unobtained traffic features, generate a text description.
[0081] In this way, due to the large overall scale of encrypted traffic and the small proportion of malicious encrypted traffic, rapid screening can be achieved for a vast amount of traffic by using the rule determination results of handshake parameter features and / or the fuzzy processing results of traffic features, enabling fast filtering of massive traffic.
[0082] In one embodiment, the rule determination result is used to indicate whether the handshake parameter features conform to a preset detection rule. An encrypted traffic can have multiple handshake parameter features, and there can be a rule determination result for each of these multiple handshake parameter features. For the step of "performing security detection on encrypted traffic by using the rule determination result of handshake parameter features or the fuzzy processing result of traffic features to identify candidate malicious traffic with potential risks in each encrypted traffic" in S102, it can be implemented according to the following steps:
[0083] Using the rule determination result of handshake parameter features, screen out candidate malicious traffic whose corresponding handshake parameter features do not conform to the preset detection rule from the encrypted traffic; or, using the fuzzy processing result of traffic features, determine the security score of the encrypted traffic, and use the security score to screen out candidate malicious traffic from the encrypted traffic.
[0084] Here, the embodiment of the present application can be provided with a weak handshake - stage filter and a weak fuzzy - inference filter. Among them, the weak handshake - stage filter is used to perform rule determination on handshake parameter features and screen out candidate malicious traffic. The weak fuzzy - inference filter is used to perform fuzzy processing on traffic features and screen out candidate malicious traffic.
[0085] In specific applications, either of the two filters can be used to filter encrypted traffic, or both filters can be used simultaneously to filter encrypted traffic.
[0086] Specifically, if it is determined to use the weak handshake - stage filter for screening malicious traffic, after obtaining the traffic features of any encrypted traffic, the handshake parameter features in the traffic features can be input into the weak handshake - stage filter. The filter performs rule determination on each handshake parameter feature according to the preset detection rule to obtain the rule determination results corresponding to each handshake parameter feature. Then, if the rule determination results corresponding to each handshake parameter feature all indicate conformity to the preset detection rule, it can be determined that the encrypted traffic may be secure encrypted traffic. If there is at least one rule determination result corresponding to a handshake parameter feature that indicates non - conformity to the preset detection rule, then this encrypted traffic can be regarded as candidate malicious traffic with potential risks. In this way, by using the weak handshake - stage filter, if it is determined that the rule determination results corresponding to each handshake parameter feature all indicate conformity to the preset detection rule, it can be considered that the corresponding encrypted traffic has relatively high security and credibility, realizing a preliminary judgment of the security and credibility of the traffic and completing the first - stage filtering of encrypted traffic.
[0087] Optionally, if it is determined to use the handshake-phase weak filter to screen malicious traffic, the handshake parameter features can also be collected when the encrypted traffic is in the communication handshake phase. After the handshake parameter features are collected, the handshake parameter features can be input into the handshake-phase weak filter to determine whether the encrypted traffic is candidate malicious traffic.
[0088] Alternatively, if it is determined to use the fuzzy inference weak filter to screen malicious traffic, after obtaining the traffic features of any encrypted traffic, the traffic features can be input into the fuzzy inference weak filter, and the filter is used to perform fuzzy processing on the traffic features to obtain a fuzzy processing result (that is, according to the specific parameters of the traffic features and the parameter ranges of the respective fuzzy result parameters in the fuzzy set corresponding to the traffic features, determine the fuzzy result parameters corresponding to the traffic features). Then, the fuzzy inference weak filter can determine the security score of the encrypted traffic according to the respective fuzzy processing results corresponding to the encrypted traffic. For example, a scoring process can be performed on the respective fuzzy processing results corresponding to the encrypted traffic to obtain an initial score for each fuzzy processing result, and then the mean / minimum value / variance, etc. of the initial scores of the respective fuzzy processing results can be used as the security score of the encrypted traffic. Then, the encrypted traffic with a security score less than the set score threshold can be used as candidate malicious traffic. Among them, the set score threshold can be determined according to the security scores corresponding to each secure encrypted traffic and each sample malicious traffic in the sample dataset.
[0089] In one embodiment, the fuzzy processing result may include at least one traffic feature and its fuzzy result parameter, and the fuzzy processing result corresponding to one encrypted traffic may include one or more. The fuzzy result parameter is used to indicate the fuzzy degree of the traffic feature.
[0090] For the above steps of determining the security score, it can be determined according to the following sub-steps 1 and 2:
[0091] Sub-step 1: Use the weights corresponding to the fuzzy result parameters of each traffic feature in the fuzzy processing result to determine the initial score of the fuzzy processing result.
[0092] Here, considering that different traffic characteristics have different degrees of influence on whether encrypted traffic poses a security risk, and even for the same traffic characteristic, the degree of influence on whether encrypted traffic poses a security risk is different at different levels of fuzziness, so this application can pre-set weights for each traffic characteristic at each level of fuzziness respectively. That is, for any traffic characteristic, corresponding weights can be pre-set for different fuzzy result parameters corresponding to this traffic characteristic. For example, the fuzzy set of the strength of the encryption suite is [extremely weak, weak, medium, strong, extremely strong]. The "extremely weak" encryption suite has a relatively high degree of influence on traffic security. Therefore, the weight corresponding to the fuzzy result parameter "extremely weak" is relatively high, while the "strong" and "extremely strong" encryption suites are generally considered secure, and the membership degrees corresponding to the fuzzy result parameters "strong" and "extremely strong" are relatively low.
[0093] Exemplarily, for any fuzzy processing result corresponding to encrypted traffic, the minimum weight can be selected from the weights corresponding to the fuzzy result parameters of each traffic characteristic in this fuzzy processing result, and this weight is used as the initial score of this fuzzy processing result.
[0094] For example, for the fuzzy processing result IF (the traffic surge amplitude is'sharp') AND (the packet interval is 'extremely unstable') THEN (the risk level is'very likely malicious'), the weight corresponding to the fuzzy result parameter'sharp' of the traffic surge amplitude is 0.85, and the weight of the fuzzy result parameter 'extremely unstable' of the packet interval is 0.9. Then the initial score of this fuzzy processing result = min(μ(sharp), μ(extremely unstable)) = min(0.85, 0.9) = 0.85. Where, u represents the weight corresponding to the fuzzy processing result.
[0095] Sub-step 2: Determine the security score of the encrypted traffic based on the initial score of each fuzzy processing result.
[0096] Here, a corresponding target weighting coefficient can be pre-set for each fuzzy rule, that is, a corresponding target weighting coefficient is pre-set for each fuzzy processing result. The target weighting coefficient can be set according to experience, and the embodiments of this application do not make specific limitations.
[0097] Specifically in implementation, for any encrypted traffic, the target weighting coefficient corresponding to each fuzzy processing result can be obtained, and then the initial scores of each fuzzy processing result are weighted and summed using the target weighting coefficients of each fuzzy processing result to obtain the security score of the encrypted traffic. For example, the security score can be determined according to the following formula (1):
[0098] Score = sum(Wi * RULEi); (Formula 1)
[0099] Among them, Score represents the security score of the encrypted traffic, Wi represents the target weighting coefficient of the i-th fuzzy processing result, and RULEi represents the initial score of the i-th fuzzy processing result.
[0100] In another embodiment, if it is determined to use the handshake phase weak filter and the fuzzy inference weak filter, after obtaining the traffic characteristics of the encrypted traffic, the handshake parameter characteristics can be input into the handshake phase weak filter, and at the same time, the traffic characteristics can be input into the fuzzy inference weak filter. The two filters are used to screen malicious traffic simultaneously to obtain the candidate malicious traffic output by each filter. Alternatively, if it is determined to use the handshake phase weak filter and the fuzzy inference weak filter simultaneously, after obtaining the handshake parameter characteristics, the handshake parameter characteristics can be input into the handshake phase weak filter to obtain the candidate malicious traffic screened by the handshake phase weak filter. After obtaining the transmission characteristics, the transmission characteristics and the handshake parameter characteristics can be output to the fuzzy inference weak filter to obtain the candidate malicious traffic screened by the fuzzy inference weak filter.
[0101] Alternatively, two filters can also be used to perform two-stage filtering on the encrypted traffic. Specifically, the handshake phase weak filter can be used to perform the first filtering on the encrypted traffic to obtain the candidate malicious traffic screened by the handshake phase weak filter and the target encrypted traffic without security risks, and then the fuzzy inference weak filter can be used to perform the second filtering on each target encrypted traffic to obtain the candidate malicious traffic screened by the fuzzy inference weak filter.
[0102] Specifically, the screening of the candidate malicious traffic can be implemented according to the following steps A to C:
[0103] Step A: Using the rule determination result, screen out the candidate malicious traffic whose corresponding handshake parameter characteristics do not conform to the preset detection rule and the target encrypted traffic that conforms to the preset detection rule from the encrypted traffic.
[0104] In specific implementation, for each encrypted traffic, the handshake parameter characteristics in the traffic characteristics of the encrypted traffic can be input into the handshake phase weak filter, and the filter can be used to perform rule determination on each handshake parameter characteristic according to the preset detection rule to obtain the rule determination result corresponding to each handshake parameter characteristic. Then, if the rule determination results corresponding to each handshake parameter characteristic all indicate compliance with the preset detection rule, it can be determined that the encrypted traffic may be safe target encrypted traffic. If there is at least one rule determination result corresponding to the handshake parameter characteristic that indicates non-compliance with the preset detection rule, the encrypted traffic can be regarded as candidate malicious traffic with potential risks.
[0105] Step B: Using the fuzzy processing result of the traffic characteristics of the target encrypted traffic, determine the security score of the target encrypted traffic.
[0106] In specific implementation, for each target encrypted traffic, the traffic characteristics of the target encrypted traffic can be input into the fuzzy inference weak filter, and the filter is used to perform fuzzy processing on the traffic characteristics to obtain a fuzzy processing result. Then, the fuzzy inference weak filter can determine the security score of the target encrypted traffic according to each fuzzy processing result corresponding to the target encrypted traffic.
[0107] Step C: Use the security score of the target encrypted traffic to screen out candidate malicious traffic from the target encrypted traffic.
[0108] In specific implementation, candidate malicious traffic with a security score lower than the set score threshold can be screened out from each target encrypted traffic.
[0109] S103: Generate a text description of the candidate malicious traffic according to the fuzzy processing result and the traffic characteristics.
[0110] Here, the text description is used to describe the overall session characteristic information of the candidate encrypted traffic. For example, the text description of a certain candidate malicious traffic can be:
[0111] At exactly 10:00 p.m. on the Xth day of the Xth month in 2024, a short but high-intensity session event was recorded from the source IP address 192.XX.1XX.X to the target IP address 1X.X2.1X1.X1. The session activity lasted only X seconds, but a significant traffic peak occurred in a short period of time, and the traffic surge amplitude increased several times compared to the normal period. In terms of transmission rate, the data transmission speed during the session was extremely fast, and the data throughput per second far exceeded the conventional network communication standard, showing strong suddenness and potential destructiveness. In terms of connection frequency, the session initiator tried a high-frequency connection request at the same time, intending to cause instant overload to the target server. The packet interval was extremely stable and extremely close, and the session used a large number of concurrent small packet sending methods to try to avoid some security mechanisms based on interval detection. Regarding the security authentication level, due to the lack of specific results of real-time packet capture analysis, it is impossible to accurately describe information such as the encrypted communication version number used in the attack, the validity period of the certificate, the certificate issuing authority, and whether the certificate has been revoked. The IP reputation assessment result shows that the source IP address 192.XX.1XX.X that initiated the attack had a low trust score at that time and had a high correlation with known malicious activities. And the target IP address 1X.X2.1X1.X1 became the target of this attack. In addition, the attacker had a relatively high degree of anonymity and might have used proxy servers or other anonymous network technical means to hide their true identity and location information.
[0112] Exemplarily, for each candidate malicious traffic, session information can be generated and beautified based on the traffic characteristics and fuzzing results of the candidate malicious traffic to obtain a text description of the candidate malicious traffic. For example, a trained text generation model can be used to generate a session description based on the traffic characteristics and fuzzing results.
[0113] S104: Based on the text description of each candidate malicious traffic and the text descriptions of each sample malicious traffic, screen out the target malicious traffic with security risks from the candidate malicious traffic.
[0114] Here, the sample malicious traffic is malicious encrypted traffic in the sample dataset, and the sample dataset can include multiple determined malicious encrypted traffic. The target malicious traffic is the malicious encrypted traffic with security risks among the candidate malicious traffic.
[0115] In specific implementation, for each candidate malicious traffic, the overall text consistency degree between the candidate malicious traffic and each sample malicious traffic can be determined based on the text description of the candidate malicious traffic and the text descriptions of each sample malicious traffic. When the text consistency degree is greater than the set degree, it is determined that the candidate malicious traffic is the target malicious traffic with security risks; on the contrary, when the text consistency degree is not greater than the set degree, it is determined that the candidate malicious traffic is a misreported malicious traffic.
[0116] For example, for each candidate malicious traffic, the text description of the candidate malicious traffic and the text descriptions of each sample malicious traffic can be input into a text consistency analysis network together to obtain the text consistency degree of the candidate malicious traffic.
[0117] In one embodiment, the above S104 can be implemented according to the following steps:
[0118] S104-1: For any candidate malicious traffic, determine the similarity between the candidate malicious traffic and each sample malicious traffic based on the text description of the candidate malicious traffic and the text descriptions of each sample malicious traffic.
[0119] Exemplarily, the semantic similarity between the text description of the candidate malicious traffic and the text description of each sample malicious traffic can be calculated, and the semantic similarity is used as the similarity between the text description of the candidate malicious traffic and the sample malicious traffic.
[0120] In one embodiment, the above S104-1 can be implemented according to the following steps:
[0121] Using a Siamese network with shared weights, based on the text description of the candidate malicious traffic and the text descriptions of each sample malicious traffic, output the first embedding feature of the candidate malicious traffic and the second embedding features of each sample malicious traffic; determine the similarity between the candidate malicious traffic and each sample malicious traffic according to the first embedding feature and the second embedding features.
[0122] Here, a Siamese neural network is a coupled architecture based on two artificial neural networks with the same structure and shared weights. By designing a Siamese network with shared weights, not only can the network parameters be reduced and the computational overhead be lowered, but also the two sub-networks can encode two inputs in the same feature space, thereby focusing on learning the relative differences between the inputs.
[0123] In the embodiments of the present application, the Siamese network can be a network architecture that uses a Bidirectional Long Short-Term Memory (Bi-LSTM) + Attention mechanism for text feature extraction. Among them, Bi-LSTM can capture the bidirectional context information of the input sequence, understand and model long-term dependencies. The Attention mechanism allows dynamic allocation of shared weights according to the importance of the input at different time steps to the output, focusing on the most relevant or important part of the sequence when generating predictions while ignoring the less important parts, thereby effectively reducing noise and highlighting key information.
[0124] As Figure 2 shown, it is a schematic structural diagram of a Siamese network provided by the embodiments of the present application. Among them, the two sub-networks in the Siamese network are both artificial neural networks, and the two sub-networks are respectively defined as network1 and network2, and network1 and network2 share weights. For each sub-network, it can include a feature embedding layer, a Bi-LSTM layer, an Attention layer, and a linear layer. One of Input1 and Input2 is the text description of the candidate malicious traffic, and the other is the text description of the sample malicious traffic. For any input, after the input enters the corresponding sub-network, it is sequentially processed by the embedding layer, the Bi-LSTM layer, the Attention layer, and the linear layer to obtain the high-dimensional embedding feature representation corresponding to the input. Figure 2 The feature representation 1 (G(input1)) and the feature representation 2 (G(input2)) in are the high-dimensional embedding feature representations corresponding to Input1 and Input2 respectively. Figure 2The loss in is the loss used in the process of training the Siamese network, which will be introduced later.
[0125] The first embedding feature and the second embedding feature can be high-dimensional embedding feature representations respectively output by the Siamese network. Specifically, the first embedding feature is the high-dimensional embedding feature representation corresponding to the candidate malicious traffic, and the second embedding feature is the high-dimensional embedding feature representation corresponding to the sample malicious traffic.
[0126] Taking Figure 2 as an example, for any candidate malicious traffic, traffic groups respectively composed of the candidate malicious traffic and each sample malicious traffic can be determined. Each traffic group includes the candidate malicious traffic, and the sample malicious traffic included in each traffic group is different. For each traffic group, the text description of the candidate malicious traffic in the traffic group can be used as Figure 2 Input1 in and input into a sub-network in the Siamese network to obtain the first embedding feature of the candidate malicious traffic; at the same time, the sample malicious traffic in the traffic group can be used as Figure 2 Input2 in and input into another sub-network in the Siamese network to obtain the second embedding feature of the sample malicious traffic. Then, the Euclidean distance between the first embedding feature and the second embedding feature can be calculated, and the Euclidean distance is used as the similarity between the candidate malicious traffic and the sample malicious traffic.
[0127] S104-2: In the case that there is a target similarity greater than the set threshold in the similarities, determine the candidate malicious traffic as the target malicious traffic.
[0128] Here, the set threshold can be set according to experience, and the embodiments of the present application do not specifically limit it.
[0129] In specific implementation, for each candidate malicious traffic, it can be determined whether there is a target similarity greater than the set threshold from the similarities between the candidate malicious traffic and each sample malicious traffic. If so, determine that the candidate malicious traffic is the target malicious traffic with security risks. If not, it can be determined that the candidate malicious traffic belongs to the misreported malicious traffic, and actually the candidate malicious traffic is secure encrypted traffic.
[0130] Optionally, if there is only one similarity greater than the set threshold among the similarities between the candidate malicious traffic and each sample malicious traffic, this similarity can be directly used as the target similarity. If there are multiple similarities greater than the set threshold among the similarities between the candidate malicious traffic and each sample malicious traffic, the highest similarity can be used as the target similarity.
[0131] In one embodiment, the Siamese network is trained according to the following steps B1 to B5:
[0132] B1: Obtain sample encrypted traffic; the sample encrypted traffic includes multiple sample malicious traffic and multiple sample candidate malicious traffic.
[0133] Here, the sample candidate malicious traffic is malicious traffic that is used as a sample and has potential risks. Among these traffic, there are malicious traffic with real security risks and secure encrypted traffic that belongs to false positives. The sample malicious traffic is malicious traffic that is used as a sample and has security risks.
[0134] Exemplarily, the sample encrypted traffic can be obtained from the sample dataset.
[0135] B2: Use the twin network to be trained, and according to the text description of each sample candidate malicious traffic and the text description of each sample malicious traffic, output the first sample feature of each sample candidate malicious traffic and the second sample feature of each sample malicious traffic.
[0136] Here, the first sample feature is the high-dimensional embedded feature representation corresponding to the sample candidate malicious traffic, and the second sample feature is the high-dimensional embedded feature representation corresponding to the sample malicious traffic.
[0137] In specific implementation, a sample candidate malicious traffic and a sample malicious traffic can be used as a sample group. The two traffic included in different sample groups are not exactly the same. A sample candidate malicious traffic can be divided into multiple sample groups, and a sample malicious traffic can also be divided into multiple sample groups. For each sample group, the text descriptions corresponding to the sample candidate malicious traffic and the sample malicious traffic in the sample group can be respectively input into different sub-networks of the twin network to be trained, and the first sample feature of the sample candidate malicious traffic and the second sample feature of the sample malicious traffic output by the twin network to be trained can be obtained.
[0138] For example, the text description of the sample candidate malicious traffic in the sample group can be used as Input1 and input into a sub-network of the twin network to be trained to obtain the first sample feature G(input1) of the sample candidate malicious traffic. At the same time, the text description of the sample malicious traffic in the sample group can be used as Input2 and input into another sub-network of the twin network to be trained to obtain the second sample feature G(input2) of the sample malicious traffic.
[0139] B3: Determine the sample similarity between each sample candidate malicious traffic and each sample malicious traffic according to the first sample feature and the second sample feature.
[0140] Exemplarily, for each sample candidate malicious traffic and each sample malicious traffic, the Euclidean distance between the first sample feature of the sample candidate malicious traffic and the second sample feature of the sample malicious traffic can be calculated, and this distance can be used as the sample similarity between the sample candidate malicious traffic and the sample malicious traffic.
[0141] B4: Determine the prediction loss of the twin network to be trained according to the class consistency label between each sample candidate malicious traffic and each sample malicious traffic, and the sample similarity between each sample candidate malicious traffic and each sample malicious traffic.
[0142] Here, the class consistency label is used to indicate whether the sample candidate malicious traffic and the sample malicious traffic have the same class. This label can be determined manually or output by the twin network to be trained. The value of the class consistency label can be 0 or 1. Among them, 0 indicates that the sample candidate malicious traffic and the sample malicious traffic do not belong to the same class, and 1 indicates that the sample candidate malicious traffic and the sample malicious traffic belong to the same class. The prediction loss is used to characterize the loss of the twin network to be trained during feature extraction, and this loss is the Figure 2 Loss in
[0143] Specifically, the following formula two can be used to determine the prediction loss:
[0144]
[0145] Among them, Loss represents the prediction loss, the value of N is the number of samples, Y represents the class consistency label between the sample candidate malicious traffic and the sample malicious traffic, represents the sample similarity between the sample candidate malicious traffic and each sample malicious traffic, and m represents a set threshold.
[0146] Specifically, the information such as the class consistency label between each sample candidate malicious traffic and each sample malicious traffic, and the sample similarity between each sample candidate malicious traffic and each sample malicious traffic can be substituted into the above formula one, and the prediction loss of the twin network to be trained can be obtained.
[0147] B5: Use the prediction loss to iteratively train the twin network to be trained until the training cut-off condition is met, and obtain the trained twin network.
[0148] Here, the training cut-off condition includes that the number of rounds of iterative training reaches the preset number of rounds and / or the prediction accuracy of the trained twin network reaches the set accuracy.
[0149] Exemplarily, the prediction loss can be used to continuously iteratively train the twin network to be trained until the training cut-off condition is met, and the trained network is obtained as the trained twin network.
[0150] In one embodiment, since the data packets of encrypted traffic are encrypted data packets and the content in the data packets cannot be obtained, it is impossible to determine the security risk reason of the target malicious traffic by analyzing the data packets. For the method of using a deep learning network to detect malicious encrypted traffic in the prior art, since the interpretability of deep learning belongs to the black box mode and the reason for the detection result cannot be given, combined with the reason of message encryption of encrypted traffic itself, the detection method in the prior art cannot give the reason why the encrypted traffic is malicious encrypted traffic. To solve the problem that the risk reason is unexplainable, the embodiment of the present application can also determine the security risk reason of the target malicious traffic according to the security risk reason of the sample malicious traffic corresponding to the target similarity. In this way, the determination that the encrypted traffic is the target malicious traffic can be explained.
[0151] Here, the sample malicious traffic corresponding to the target similarity is the sample malicious traffic whose similarity with the target malicious traffic is the target similarity. For each sample malicious traffic, the security risk reason corresponding to the malicious traffic can be determined in advance. The security risk reason is the reason why the malicious traffic has a security risk and is also the reason why the malicious traffic is determined to be malicious.
[0152] Exemplarily, in the case where the target similarity is determined, the security risk reason of the sample malicious traffic corresponding to the target similarity can be obtained and used as the security risk reason of the target malicious traffic. At the same time, this reason is also the explanation reason for determining the candidate malicious traffic as the target malicious traffic. In the present application, the siamese network is used to offset the false alarm problem of the supervised binary classification weak filter on the one hand and solve the interpretability problem of encrypted traffic alarms on the other hand.
[0153] In the above embodiments, by performing rule determination on the handshake parameter features of encrypted traffic in the communication handshake stage, it can be determined whether there is a potential risk in the handshake stage of the encrypted traffic, and / or, using the fuzzy processing result obtained by performing fuzzy processing on the transmission features, it can be determined whether there is a potential risk in the transmission stage of the encrypted traffic. Therefore, using the rule determination result and / or the fuzzy processing result to perform security detection on the encrypted traffic can quickly screen out some candidate malicious traffic with potential risks from a large amount of encrypted traffic. Then, using the text description of the candidate malicious traffic and the text description of each sample malicious traffic to perform further risk detection on the candidate malicious traffic can reduce the scale of the traffic to be detected while accurately eliminating the candidate malicious traffic that may be misdetected, thereby improving the accuracy and speed of malicious encrypted traffic detection and avoiding false alarm problems. Generally speaking, the present application first uses the rule determination result and / or the fuzzy processing result to perform a preliminary screening on a large amount of encrypted traffic, and then performs a further screening on the candidate malicious traffic obtained by the preliminary screening, which can effectively reduce the false alarm rate and improve the detection accuracy.
[0154] As shown in Figure 3 , the figure is an architecture diagram of a method for detecting encrypted traffic provided by an embodiment of the present application. Among them, after obtaining daily encrypted traffic, a weak filter can be first used to screen candidate malicious traffic. Specifically, the handshake parameter features of the encrypted traffic can be first input into the handshake-phase weak filter for the first filtering to obtain candidate malicious traffic and target encrypted traffic. The traffic features of the target encrypted traffic are input into the fuzzy inference weak filter for the second filtering to determine candidate malicious traffic from the target encrypted traffic. Among them, when determining candidate malicious traffic from the target encrypted traffic, a set score threshold determined according to the security scores corresponding to each secure encrypted traffic and each sample malicious traffic in the sample dataset needs to be used. After determining the candidate malicious traffic, the text description of the candidate malicious traffic and the text description of the sample malicious traffic in the sample dataset can be respectively input into the sub-networks in the siamese network with shared weights to obtain the first embedding feature of the candidate malicious traffic and the second embedding features of each sample malicious traffic. Then, the similarity between the candidate malicious traffic and the sample malicious traffic can be determined according to the first embedding feature and the second embedding feature, and the target malicious traffic with security risks can be determined from the candidate malicious traffic according to the similarity. At the same time, the security risk reason of the target malicious traffic can be determined according to the security risk reason of the sample malicious traffic with the highest similarity to the target malicious traffic, so as to realize the explanation of the judgment result.
[0155] Corresponding to the foregoing embodiment of the method for detecting encrypted traffic, the present application also provides an embodiment of a device for detecting encrypted traffic.
[0156] The embodiment of the device for detecting encrypted traffic of the present application can be applied to a computer device. The device embodiment can be implemented by software, or by hardware or a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor of the computer device where it is located reading the corresponding computer program instructions in the non-volatile memory into the memory and running. From the hardware level, as Figure 4 shown, the figure is a hardware structure diagram of the computer device where the device for detecting encrypted traffic of the present application is located. In addition to Figure 4 the processor, memory, network interface, and non-volatile memory shown, the computer device where the device in the embodiment is located usually also includes other hardware according to the actual functions of the computer device, which will not be elaborated here.
[0157] Please refer to Figure 5 , as shown in the figure is a schematic diagram of a device 500 for detecting encrypted traffic provided by an embodiment of the present application, including:
[0158] An acquisition module 501, configured to acquire the traffic characteristics of each encrypted traffic flow; the traffic characteristics include the handshake parameter characteristics of the encrypted traffic flow in the communication handshake phase and the transmission characteristics in the data transmission phase;
[0159] A determination module 502, configured to perform a security detection on the encrypted traffic flow by using the rule determination result of the handshake parameter characteristics and / or the fuzzy processing result of the traffic characteristics, and determine candidate malicious traffic flows with potential risks among each of the encrypted traffic flows;
[0160] A generation module 503, configured to generate a text description of the candidate malicious traffic flow according to the fuzzy processing result and the traffic characteristics;
[0161] A screening module 504, configured to screen out target malicious traffic flows with security risks from the candidate malicious traffic flows according to the text description of each candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow.
[0162] In a possible implementation manner, when the screening module 504 screens out target malicious traffic flows with security risks from the candidate malicious traffic flows according to the text description of each candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow, it is configured to:
[0163] For any one of the candidate malicious traffic flows, determine the similarity between the candidate malicious traffic flow and each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow;
[0164] In the case that there is a target similarity greater than a set threshold in the similarities, determine the candidate malicious traffic flow as the target malicious traffic flow.
[0165] In a possible implementation manner, the screening module 504 is further configured to:
[0166] Determine the security risk cause of the target malicious traffic flow according to the security risk cause of the sample malicious traffic flow corresponding to the target similarity.
[0167] In a possible implementation manner, when the screening module 504 determines the similarity between the candidate malicious traffic flow and each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow, it is configured to:
[0168] Use a siamese network with shared weights to output a first embedding feature of the candidate malicious traffic flow and second embedding features of each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow;
[0169] Determine the similarity between the candidate malicious traffic and each sample malicious traffic according to the first embedding feature and the second embedding feature.
[0170] In a possible implementation, the rule determination result is used to indicate whether the handshake parameter feature conforms to a preset detection rule;
[0171] When the determination module 502 uses the rule determination result of the handshake parameter feature or the fuzzy processing result of the traffic feature to perform a security detection on the encrypted traffic and determines candidate malicious traffic with potential risks in each encrypted traffic, it is used for:
[0172] Using the rule determination result of the handshake parameter feature, screen out candidate malicious traffic whose corresponding handshake parameter feature does not conform to the preset detection rule from the encrypted traffic, or,
[0173] Using the fuzzy processing result of the traffic feature, determine the security score of the encrypted traffic, and use the security score to screen out the candidate malicious traffic from the encrypted traffic.
[0174] In a possible implementation, the fuzzy processing result includes at least one traffic feature and its fuzzy result parameter;
[0175] When the determination module 502 uses the fuzzy processing result of the traffic feature to determine the security score of the encrypted traffic, it is used for:
[0176] Using the weight corresponding to the fuzzy result parameter of each traffic feature in the fuzzy processing result, determine the initial score of the fuzzy processing result;
[0177] Based on the initial score of each fuzzy processing result, determine the security score of the encrypted traffic.
[0178] In a possible implementation, when the determination module 502 uses the rule determination result of the handshake parameter feature and the fuzzy processing result of the traffic feature to perform a security detection on the encrypted traffic and determines candidate malicious traffic with potential risks in each encrypted traffic, it is used for:
[0179] Using the rule determination result, screen out candidate malicious traffic whose corresponding handshake parameter feature does not conform to the preset detection rule and target encrypted traffic that conforms to the preset detection rule from the encrypted traffic;
[0180] Using the fuzzy processing result of the traffic feature of the target encrypted traffic, determine the security score of the target encrypted traffic;
[0181] Filter out the candidate malicious traffic from the target encrypted traffic by using the security score of the target encrypted traffic.
[0182] In a possible implementation manner, the apparatus further includes a training module 505, configured to train the siamese network according to the following steps:
[0183] Obtain sample encrypted traffic; the sample encrypted traffic includes multiple sample malicious traffic and multiple sample candidate malicious traffic;
[0184] Use the siamese network to be trained, and according to the text description of each sample candidate malicious traffic and the text description of each sample malicious traffic, output the first sample feature of each sample candidate malicious traffic and the second sample feature of each sample malicious traffic;
[0185] Determine the sample similarity between each sample candidate malicious traffic and each sample malicious traffic according to the first sample feature and the second sample feature;
[0186] Determine the prediction loss of the siamese network to be trained according to the class consistency label between each sample candidate malicious traffic and each sample malicious traffic and the sample similarity between each sample candidate malicious traffic and each sample malicious traffic;
[0187] Use the prediction loss to iteratively train the siamese network to be trained until the training termination condition is met, and obtain the trained siamese network.
[0188] The description of the processing flow of each module in the apparatus and the interaction flow between modules can refer to the relevant description in the above method embodiments, and will not be elaborated here.
[0189] The implementation process of the functions and roles of each unit in the above apparatus is specifically detailed in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0190] For the apparatus embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The apparatus embodiment described above is only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the present application. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0191] The embodiments of the subject matter and the functional operations described in this specification can be implemented in digital electronic circuitry, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or one or more combinations of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible non-transitory program carrier to be executed by, or to control the operation of, a data processing apparatus. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, generated to encode and transmit information to a suitable receiver apparatus for execution by the data processing apparatus. A computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or one or more combinations of them.
[0192] The processes and logical flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform the functions corresponding by operating on input data and generating output. The processes and logical flows can also be performed by, or the apparatus can be implemented as, special purpose logic circuitry, e.g., an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit).
[0193] Computers suitable for executing a computer program include, by way of example, general and / or special purpose microprocessors, or any other type of central processing unit. Generally, a central processing unit will receive instructions and data from a read only memory and / or a random access memory. Basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, etc., or the computer will be operatively coupled to such mass storage devices to receive data therefrom or to transfer data thereto, or both. However, a computer need not have such devices. In addition, a computer may be embedded in another device, such as a mobile telephone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a Global Positioning System (GPS) receiver, or a portable storage device such as a Universal Serial Bus (USB) flash drive, to name just a few.
[0194] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. The processor and the memory may be supplemented by, or incorporated in, special purpose logic circuitry.
[0195] Although this specification contains many specific implementation details, these should not be construed as limiting the scope of any invention or the scope of what is claimed, but rather as mainly describing the features of specific embodiments of particular inventions. Certain features that are described in multiple embodiments in this specification may also be implemented in combination in a single embodiment. On the other hand, the various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although features may operate in certain combinations as described above and even be claimed as such initially, one or more features from the claimed combination may in some cases be removed from the combination, and the claimed combination may be directed to a sub-combination or a variation of the sub-combination.
[0196] Similarly, although the operations are depicted in the drawings in a particular order, this should not be understood as requiring that the operations be performed in the particular order shown or sequentially, or that all of the illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. In addition, the separation of the various system modules and components in the above embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.
[0197] Thus, particular embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the acts recited in the claims may be performed in a different order and still achieve the desired result. In addition, the processes depicted in the drawings are not necessarily in the particular order or sequential order shown to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.
[0198] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of protection of the present application.
Claims
1. A method for detecting encrypted traffic, characterized in that, The method includes: Obtaining the traffic characteristics of each encrypted traffic flow; the traffic characteristics include the handshake parameter characteristics of the encrypted traffic flow in the communication handshake stage and the transmission characteristics in the data transmission stage; Using the rule determination result of the handshake parameter characteristics and / or the fuzzy processing result of the traffic characteristics, performing a security detection on the encrypted traffic flow, and determining candidate malicious traffic flows with potential risks in each of the encrypted traffic flows; Generating a text description of the candidate malicious traffic flow according to the fuzzy processing result and the traffic characteristics; Screening out target malicious traffic flows with security risks from the candidate malicious traffic flows according to the text description of each candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow.
2. The method according to claim 1, wherein Screening out target malicious traffic flows with security risks from the candidate malicious traffic flows according to the text description of each candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow includes: For any one of the candidate malicious traffic flows, determining the similarity between the candidate malicious traffic flow and each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow; When there is a target similarity greater than a set threshold in the similarities, determining the candidate malicious traffic flow as a target malicious traffic flow.
3. The method according to claim 2, wherein The method further includes: Determining the security risk reason of the target malicious traffic flow according to the security risk reason of the sample malicious traffic flow corresponding to the target similarity.
4. The method according to claim 2 or 3, characterized in that, The determining the similarity between the candidate malicious traffic flow and each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow includes: Using a siamese network with shared weights, and outputting a first embedding feature of the candidate malicious traffic flow and second embedding features of each of the sample malicious traffic flows according to the text description of the candidate malicious traffic flow and the text descriptions of each sample malicious traffic flow; Determining the similarity between the candidate malicious traffic flow and each of the sample malicious traffic flows according to the first embedding feature and the second embedding features.
5. The method according to claim 1, wherein The rule determination result is used to indicate whether the handshake parameter characteristics conform to a preset detection rule; Using the rule determination result of the handshake parameter characteristics or the fuzzy processing result of the traffic characteristics, performing a security detection on the encrypted traffic flow, and determining candidate malicious traffic flows with potential risks in each of the encrypted traffic flows includes: Using the rule determination result of the handshake parameter characteristics, screening out candidate malicious traffic flows whose corresponding handshake parameter characteristics do not conform to the preset detection rule from the encrypted traffic flow, or, Using the fuzzy processing result of the traffic characteristics, determining the security score of the encrypted traffic flow, and using the security score to screen out the candidate malicious traffic flows from the encrypted traffic flow.
6. The method according to claim 5, wherein The fuzzy processing result includes at least one traffic characteristic and its fuzzy result parameter; The using the fuzzy processing result of the traffic characteristics to determine the security score of the encrypted traffic flow includes: Determining an initial score of the fuzzy processing result by using the weights corresponding to the fuzzy result parameters of each traffic characteristic in the fuzzy processing result; Determine the security score of the encrypted traffic based on the initial scores of each of the obfuscation results.
7. The method according to claim 1, characterized in that, Use the rule determination result of the handshake parameter feature and the obfuscation result of the traffic feature to perform a security detection on the encrypted traffic, and determine candidate malicious traffic with potential risks in each piece of the encrypted traffic, including: Use the rule determination result to screen out candidate malicious traffic whose corresponding handshake parameter features do not conform to the preset detection rules and target encrypted traffic that conforms to the preset detection rules from the encrypted traffic; Determine the security score of the target encrypted traffic using the obfuscation result of the traffic feature of the target encrypted traffic; Use the security score of the target encrypted traffic to screen out the candidate malicious traffic from the target encrypted traffic.
8. The method according to claim 4, characterized in that, The siamese network is trained according to the following steps: Obtain sample encrypted traffic; the sample encrypted traffic includes multiple pieces of sample malicious traffic and multiple pieces of sample candidate malicious traffic; Use the siamese network to be trained to output a first sample feature of each piece of the sample candidate malicious traffic and a second sample feature of each piece of the sample malicious traffic according to the text description of each piece of the sample candidate malicious traffic and the text description of each piece of the sample malicious traffic; Determine the sample similarity between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic according to the first sample feature and the second sample feature; Determine the prediction loss of the siamese network to be trained according to the class consistency label between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic and the sample similarity between each piece of the sample candidate malicious traffic and each piece of the sample malicious traffic; Use the prediction loss to perform iterative training on the siamese network to be trained until the training cut-off condition is met, and obtain the trained siamese network.
9. A detection device for encrypted traffic, characterized in that, The device includes: An acquisition module, configured to acquire the traffic features of each piece of encrypted traffic; the traffic features include handshake parameter features in the communication handshake stage of the encrypted traffic and transmission features in the data transmission stage; A determination module, configured to perform a security detection on the encrypted traffic using the rule determination result of the handshake parameter feature and / or the obfuscation result of the traffic feature, and determine candidate malicious traffic with potential risks in each piece of the encrypted traffic; A generation module, configured to generate a text description of the candidate malicious traffic according to the obfuscation result and the traffic feature; A screening module, configured to screen out target malicious traffic with security risks from the candidate malicious traffic according to the text description of each piece of the candidate malicious traffic and the text descriptions of each piece of the sample malicious traffic.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the detection method for encrypted traffic according to any one of claims 1 to 8.
11. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the detection method for encrypted traffic according to any one of claims 1 to 8.