State secret SSH protocol detection method and device, equipment, storage medium and program product
Through the closed-loop architecture of the National Secret SSH protocol detection method, the full-process, end-to-end detection of the National Secret SSH protocol is achieved, solving the problems of insufficient detection coverage and low accuracy in the existing technology, and improving the coverage and accuracy of the detection results.
Patent Information
- Application Number
- CN202510989380.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-08-15
AI Technical Summary
The existing national secret SSH protocol detection method cannot completely restore the protocol interaction process of the server in real communication, and it is particularly difficult to parse the encrypted data content, resulting in insufficient detection coverage, lack of strong verification results, and the inability to comprehensively evaluate the compliance and mechanism security of the password algorithm implemented by the server.
The closed-loop architecture of protocol driver unit, transmission protocol interaction unit, detection unit and result determination unit is adopted, and the SSH transmission protocol detection layer, authentication protocol detection layer and connection protocol detection layer are used to realize the synchronization detection of the full process, end-to-end encryption algorithm, key negotiation, identity authentication and channel management behavior.
The full-process and end-to-end detection of the National Secret SSH protocol is realized, which improves the coverage, accuracy and timeliness of the detection results, and ensures comprehensive detection and judgment of encryption algorithms, key negotiation and identity authentication implemented by the server.
Smart Images

Figure CN120499054A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, apparatus, device, storage medium, and computer program product for detecting the national secret SSH protocol. Background Art
[0002] The traditional SSH protocol was originally designed to replace plaintext transmission protocols such as Telnet and FTP. After evolving through multiple versions, it has improved encryption algorithms, security authentication methods, and communication integrity, becoming a globally used secure communication protocol.
[0003] The National Encryption SSH Protocol is based on the relevant cryptographic policies, regulations, and technical framework of the People's Republic of China, and is designed with reference to the traditional SSH protocol. It provides a security mechanism compatible with the national cryptographic system for remote operations and secure communications. The release of the National Encryption SSH Protocol marks a significant advancement in my country's secure communications standards.
[0004] In related technologies, protocol detection methods mostly rely on static analysis, packet sniffing, or manual testing, which can usually only detect part of the behavior of a certain layer of the SSH protocol and cannot fully restore the protocol interaction process of the server in real communication. It is especially difficult to parse the encrypted data content, resulting in insufficient detection coverage and lack of strong verification results. In addition, there are currently no mature national secret SSH protocol analysis and detection tools. Conventional methods cannot take into account the verification of national secret mechanisms and cannot comprehensively evaluate the compliance of the cryptographic algorithms implemented by the server and the security of the mechanisms. This makes the national secret SSH tool research and development companies face product testing and certification difficulties, and users have no basis to rely on when selecting. Therefore, there is an urgent need for an SSH protocol detection method that is compatible with national secret standards to improve the integrity, accuracy, and credibility of the detection. Summary of the Invention
[0005] The main purpose of this application is to provide a method, device, equipment, storage medium and program product for detecting the national secret SSH protocol, aiming to solve the technical problem of low accuracy of related technical national secret SSH protocol detection.
[0006] To achieve the above objectives, this application proposes a national secret SSH protocol detection method, including: The protocol driver unit schedules the transport protocol interaction unit to work and realizes interactive connection with the server. The transport protocol interaction unit includes the SSH transport protocol interaction layer, the SSH authentication protocol interaction layer, and the SSH connection protocol interaction layer. During the operation of the scheduling transmission protocol interaction unit, the detection unit performs protocol detection to obtain detection data; the detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer; The test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result judgment unit for compliance judgment, and the judgment result is output.
[0007] In one embodiment, the steps of scheduling the transmission protocol interaction unit to work and realizing an interactive connection with the server include: The protocol driver unit drives the SSH transport protocol detection layer to communicate with the server, establishes a secure data transmission channel, and performs key negotiation with the server. After the data transmission channel is established, the protocol driver unit drives the SSH authentication protocol interaction layer to communicate with the server to perform identity authentication; After the identity authentication is completed, the protocol driver unit drives the SSH connection protocol layer to interactively connect with the server.
[0008] In one embodiment, during the process of scheduling the transmission protocol interaction unit to work, the corresponding detection unit performs protocol detection, and the step of obtaining detection data includes: In the process of establishing a secure data transmission channel, the SSH transport protocol detection layer performs server-side SSH transport layer protocol detection based on the transport layer protocol interaction specification to obtain transport layer protocol detection data. During the identity authentication process, the SSH authentication protocol detection layer performs server-side SSH authentication layer protocol detection based on the authentication layer protocol interaction specification to obtain authentication layer protocol detection data; During the interactive connection between the SSH connection protocol layer and the server, the SSH connection protocol detection layer performs server-side SSH connection layer protocol detection based on the connection layer protocol interaction specification to obtain connection layer protocol detection data.
[0009] In one embodiment, the transport layer protocol detection data includes, in order of acquisition, protocol identification information, server cipher suite information, server key exchange response information, and server service request response message; The test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result determination unit for compliance determination. The step of outputting the determination result includes: When the protocol identification information is obtained, the server identification compliance analysis is performed through the detection result analysis unit, and the compliance analysis result is determined through the result determination unit; If the result determination unit determines that the result is passed, when the server-side cipher suite information is obtained, the cipher suite information is analyzed by the detection result analysis unit, and the cipher suite information analysis result is determined by the result determination unit; If the result determination unit determines that the key exchange response information of the server is passed, the key exchange response correctness analysis is performed by the detection result analysis unit, and the key exchange response correctness is determined by the result determination unit; If the result determination unit determines that the service request response message is passed, the service request response analysis unit is used to analyze the service request response when the service request response message is obtained from the server, and the result determination unit is used to determine the service request response result; If the result determination unit determines that the analysis result of any transport layer protocol detection data is not passed during the process, the detection ends and the transport layer protocol detection abnormality information is output.
[0010] In one embodiment, the authentication layer protocol detection data includes, in order of acquisition, a server authentication challenge message and a server authentication result response message, wherein the server authentication challenge information includes one of a service port command authentication challenge message, a server asymmetric key authentication challenge message, and a server certificate authentication challenge message; The test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result determination unit for compliance determination. The step of outputting the determination result includes: When the server authentication challenge information is obtained, the server authentication challenge information is parsed by the detection result analysis unit, and the challenge information parsing result is determined by the result determination unit; If the result determination unit determines that the authentication result response information is passed, the authentication result response information is analyzed by the detection result analysis unit when the authentication result response information is obtained from the server, and the compliance of the authentication result response information is determined by the result determination unit; If the result determination unit determines that any authentication layer protocol detection data fails the analysis result during the process, the detection ends and authentication layer protocol detection abnormality information is output.
[0011] In one embodiment, the connection layer protocol detection data includes server channel connection response information; The test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result determination unit for compliance determination. The step of outputting the determination result includes: When the server channel connection response information is obtained, the server channel connection response information is parsed by the detection result analysis unit, and the challenge information parsing result is determined by the result determination unit; If the judgment fails, the detection ends and the connection layer protocol detection abnormality information is output.
[0012] In addition, to achieve the above purpose, this application also proposes a national secret SSH protocol detection device, the device comprising: The interactive control module is used to schedule the transmission protocol interaction unit to work through the protocol driver unit to achieve interactive connection with the server; the transmission protocol interaction unit includes the SSH transmission protocol interaction layer, the SSH authentication protocol interaction layer and the SSH connection protocol interaction layer; A detection control module is used to perform protocol detection through the corresponding detection unit to obtain detection data during the process of scheduling the transmission protocol interaction unit to work; the detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer; The analysis control module is used to analyze the test data through the test result analysis unit, and send the test data analysis results to the result judgment unit for compliance judgment and output the judgment results.
[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a national secret SSH protocol detection device, which includes: a memory, a processor, and a computer program stored in the memory and runnable on the processor. The computer program is configured to implement the steps of the above-mentioned national secret SSH protocol detection method.
[0014] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the above-mentioned national secret SSH protocol detection method are implemented.
[0015] In addition, to achieve the above-mentioned purpose, the present application also proposes a computer program product, characterized in that the computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps of the above-mentioned national secret SSH protocol detection method.
[0016] One or more technical solutions proposed in this application have at least the following technical effects: This application uses a closed-loop architecture of "protocol driver unit + three-layer interaction unit + three-layer detection unit + result analysis / judgment unit" to synchronously complete the interaction and detection of the transport layer, authentication layer, and connection layer in the national secret SSH session. It can reproduce and verify the encryption algorithm, key negotiation, identity authentication, and channel management behavior implemented by the server in the entire process and end-to-end. Compared with traditional passive packet capture or single-point detection methods, it not only solves the pain point of difficult ciphertext parsing, but also ensures the coverage, accuracy, and timeliness of the detection results. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0019] Figure 1 This is a flowchart of an embodiment of the national secret SSH protocol detection method provided in this application.
[0020] Figure 2 This is a schematic diagram of the architectural framework for the national secret SSH protocol detection application.
[0021] Figure 3 This is a schematic diagram of the transport layer protocol detection process.
[0022] Figure 4 This is a schematic diagram of the authentication layer protocol detection process.
[0023] Figure 5 This is a schematic diagram of the connection layer protocol detection process.
[0024] Figure 6 This is a structural diagram of the national secret SSH protocol detection equipment.
[0025] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0026] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0027] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0028] In response to the problems caused by the background technology, this application provides a solution. Through the closed-loop architecture of "protocol driver unit + three-layer interaction unit + three-layer detection unit + result analysis / determination unit", the interaction and detection of the transport layer, authentication layer, and connection layer are synchronously completed in the national secret SSH session, and the encryption algorithm, key negotiation, identity authentication and channel management behavior implemented by the server can be reproduced and verified in the entire process and end-to-end.
[0029] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device capable of performing the above functions, such as a national secret SSH protocol detection device. The following uses the national secret SSH protocol detection device as an example to illustrate this embodiment and the following embodiments.
[0030] Based on this, the embodiment of the present application provides a national secret SSH protocol detection method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the national secret SSH protocol detection method of this application.
[0031] In this embodiment, the national secret SSH protocol detection method includes steps S10 to S30: Step S10: The protocol driving unit schedules the transmission protocol interaction unit to work, thereby realizing an interactive connection with the server.
[0032] Step S20: During the process of scheduling the transmission protocol interaction unit to work, the detection unit performs protocol detection to obtain detection data.
[0033] In step S30, the test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result determination unit for compliance determination, and the determination result is output.
[0034] It should be noted that this embodiment adopts modularization and unitization ideas and proposes a national secret SSH protocol detection architecture, such as Figure 2 As shown, Figure 2 This is a schematic diagram of the framework structure of this embodiment. In this embodiment, the national secret SSH protocol detection architecture includes a protocol driver unit, a transmission protocol interaction unit, a detection unit, a detection result analysis unit, and a result judgment unit.
[0035] The transmission protocol interaction unit includes an SSH transmission protocol interaction layer, an SSH authentication protocol interaction layer, and an SSH connection protocol interaction layer. The detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer.
[0036] Each task module runs under the control of the master control program to implement the national secret SSH protocol detection method. Specifically, under the control of the master control program, the protocol driver unit completes the operation and management of the SSH protocol from the transport layer to the connection layer. First, it drives the SSH transport protocol interaction layer to establish a secure transmission channel with the server. After the secure channel is established, it schedules the SSH authentication protocol interaction layer to complete client identity authentication. After authentication is completed, it schedules the SSH connection protocol interaction layer to complete the corresponding remote management interactive connection. While the scheduling module is operating, it also notifies the corresponding detection unit to begin protocol analysis and various detection tasks. The protocol driver module notifies the SSH transport protocol detection layer, SSH authentication protocol detection layer, and SSH connection protocol detection layer to obtain and report detection data to the detection result analysis unit to complete the detection result analysis. Based on the detection result analysis, the result determination module performs a compliance assessment on the national secret SSH protocol implemented by the server-side SSH service in terms of implementation correctness, algorithm compliance, key management security, and cryptographic mechanism effectiveness according to relevant cryptographic standards and specifications, and outputs the assessment result. It is worth mentioning that this embodiment also includes a channel management unit for identifying and managing the channel established between the client and the server.
[0037] As can be understood, this implementation adopts a modular, unitized architecture design to build a national secret detection system covering the three-layer SSH protocol. It can dynamically restore the SSH communication process in real interactive scenarios. By combining the protocol driver and detection linkage mechanism, it can achieve comprehensive detection and judgment of the national secret SSH protocol implemented on the server side in terms of algorithm compliance, mechanism security, implementation correctness, and other dimensions. This effectively improves the automation level of SSH protocol detection and the accuracy of detection results, providing strong technical support for the secure deployment and compliance review of national secret SSH services.
[0038] In a feasible implementation, step S10 includes steps A10 to A30: Step A10: The protocol driver unit drives the SSH transport protocol detection layer to communicate with the server, establishes a secure data transmission channel, and performs key negotiation with the server.
[0039] Step A20: After the data transmission channel is established, the protocol driver unit drives the SSH authentication protocol interaction layer to communicate with the server to perform identity authentication.
[0040] In step A30, after identity authentication is completed, the protocol driver unit drives the SSH connection protocol layer to interactively connect with the server.
[0041] Step S20 includes steps B10 to B30: Step B10: During the process of establishing a secure data transmission channel, the server-side SSH transport layer protocol detection is performed based on the transport layer protocol interaction specification through the SSH transport protocol detection layer to obtain transport layer protocol detection data.
[0042] Step B20: During the identity authentication process, the SSH authentication protocol detection layer performs server-side SSH authentication layer protocol detection based on the authentication layer protocol interaction specification to obtain authentication layer protocol detection data.
[0043] Step B30: During the interactive connection between the SSH connection protocol layer and the server, the SSH connection protocol detection layer performs server-side SSH connection layer protocol detection based on the connection layer protocol interaction specification to obtain connection layer protocol detection data.
[0044] It is understandable that the National Secret SSH Protocol is a protocol family composed of the transport layer protocol, the authentication layer protocol, and the connection layer protocol, which is formed in accordance with relevant Chinese cryptographic policies and regulations, based on my country's cryptographic technology system, and uses the SM2, SM3, and SM4 cryptographic algorithms and digital certificate mechanisms. It is used for secure remote login and secure network services on insecure networks. In the process of connecting and interacting with the National Secret SSH Protocol, the server and the client first establish a secure communication channel (data transmission channel) through the transport layer protocol, negotiate a key with the server, and then authenticate the identities of the client and server communication entities on this secure channel according to the authentication layer protocol. After the identity authentication is completed, an interactive connection is established according to the connection layer protocol, and the corresponding SSH service is officially performed using the secure data transmission channel.
[0045] This embodiment is based on the basic operating mechanism of the national encryption SSH, and implements the national encryption SSH protocol detection during the process of establishing a connection interaction between the client and the server through the detection unit.
[0046] For example, after receiving instructions from the driver scheduling module, the SSH transport protocol detection layer proactively initiates a communication connection with the server and completes key negotiation with the server. Both parties first negotiate a key exchange algorithm, exchange random numbers, generate a random key K, encrypt it with the public key of the server's encryption certificate, and send it to the server. Ultimately, both parties calculate a consistent initial IV, encryption key, and HMAC key. Subsequently, all communications between the client and server utilize this key specification for encryption and data integrity protection.
[0047] During this process, the protocol driver module notifies the SSH transport protocol detection layer to work synchronously, performs server-side transport layer protocol detection according to the transport layer protocol interaction specification standard, obtains and retains all transport layer protocol communication data, and provides the transport layer protocol detection data source for the detection result analysis unit.
[0048] Subsequently, under the support of the transport layer protocol, the SSH authentication protocol interaction layer actively communicates with the server through the established secure data transmission channel to realize complete authentication layer protocol interaction. After receiving instructions from the driver scheduling module, it actively initiates a communication connection with the server, and realizes the server's authentication of the client through authentication methods based on passwords, asymmetric keys, digital certificates, etc., as well as the request, challenge, and response authentication methods adopted by the client and server.
[0049] During this process, the protocol driver module notifies the SSH authentication protocol detection layer to work synchronously and perform server-side authentication layer protocol detection according to the authentication layer protocol interaction specification standard. All authentication layer protocol communication data is retained during the detection process to provide the transport layer protocol detection data source for the detection result analysis unit.
[0050] Subsequently, under the support of the authentication layer protocol, after receiving the instructions from the driver scheduling module, the SSH connection protocol interaction layer actively communicates with the server to realize complete connection layer protocol interaction, and realize secure and reliable remote management such as interactive login sessions, remote command execution, and port forwarding.
[0051] During this process, the protocol driver module notifies the SSH connection protocol detection module to work synchronously while scheduling the SSH connection protocol implementation module to start working. It performs server-side connection layer protocol detection according to the standard specifications of SSH connection layer protocol interaction. During the detection process, all connection layer protocol communication data is retained to provide transport layer protocol detection data for the connection protocol detection result analysis module.
[0052] In another embodiment, step S30 includes steps C11 to C15: Step C11: When the protocol identification information is obtained, the detection result analysis unit performs a compliance analysis on the server identification, and the result determination unit determines the compliance analysis result.
[0053] In step C12, if the result determination unit determines that the test is successful, the key exchange algorithm is analyzed by the detection result analysis unit when the server-side cipher suite information is obtained, and the key exchange algorithm analysis result is determined by the result determination unit.
[0054] Step C13: If the result determination unit determines that the key exchange response is passed, then when the key exchange response information of the server is obtained, the key exchange response correctness analysis is performed by the detection result analysis unit, and the key exchange response correctness is determined by the result determination unit; In step C14, if the result determination unit determines that the service request response is passed, when the service request response information of the server is obtained, the detection result analysis unit performs service request response analysis and the result determination unit performs service request response result determination.
[0055] In step C15 , if the result determination unit determines that the analysis result of any transport layer protocol detection data is failed during the process, the detection ends and transport layer protocol detection abnormality information is output.
[0056] In this embodiment, the transport layer protocol detection data includes, in order of acquisition, protocol identification information, server cipher suite information, server key exchange response information, and server service request response information.
[0057] For example, the SSH transport layer key exchange process is as follows: After the client and server send the version identifier, they immediately start negotiation and exchange negotiation initialization messages. The cipher suite information in the exchange process includes the cookie random number, the key agreement algorithm (fixed to be SM2), the client-to-server symmetric encryption algorithm list, the client-to-server message authentication code algorithm list, the client-to-server compression algorithm list, as well as the server-to-client symmetric encryption algorithm list, the server-to-client message authentication code algorithm list, and the server-to-client compression algorithm list.
[0058] After the key agreement algorithm is agreed upon, the key agreement calculation begins. The client generates an 8-byte random number again and sends a key exchange request to the server. The server sends a key exchange response message to the client (the reply message includes the server's national secret dual certificate, the 8-byte random number generated again by the server, and the signature of the server's signature private key on the random numbers of both parties).
[0059] After receiving the key exchange response message from the server, the client authenticates the server and, after signature verification, generates another 32-byte random key, K, encrypts it using the server's encryption certificate public key, and sends it to the server. At this point, the parameters required for the key exchange process have been completed. Both parties calculate the materials necessary to generate the cipher specifications. Using the same method, they ultimately calculate a consistent initial IV, encryption key, and HMAC key, and both parties determine the transport layer security channel cipher specifications. After the cipher specifications are calculated, both the client and the server conclude key negotiation. Subsequently, all communications between the client and the server utilize this cipher specification for encryption and data integrity protection, establishing a transport layer security channel. The client then sends a service request, preparing for subsequent protocol interactions.
[0060] In the above process, the SSH transport protocol detection layer works synchronously, such as Figure 3 As shown, Figure 3 This is a schematic diagram of the transport layer protocol detection process. Figure 3 As shown: The protocol identification information includes the server protocol identification. After receiving the protocol identification information from the server, the result analysis unit performs an identification compliance analysis, and the result judgment unit judges the analysis result. If it passes, the next step of detection will be carried out. If it fails, it means that the detection is abnormal. The detection ends and the corresponding transport layer protocol detection abnormality information is output.
[0061] If the test passes, the server-side cipher suite information generated during the subsequent key exchange initialization process is received, and the test result analysis unit performs compliance analysis on the server-side cipher suite information. The result judgment unit judges the analysis result. If it passes, the next step of the test is carried out. If it fails, it indicates that the test is abnormal. The test ends and the corresponding transport layer protocol detection abnormality information is output.
[0062] If the test passes, the server-side key exchange response generated during the subsequent key exchange process is received. The test result analysis unit analyzes the key exchange response for correctness, verifies the server-side signature and encryption certificate, and verifies the server's digital signature on the response message. If the server-side response message is abnormal, fails the certificate verification, or fails the digital signature verification, the result determination unit determines that it fails, and the test ends. Otherwise, the next stage of the test is carried out.
[0063] If the test passes, the server-side service request response message generated during the subsequent protocol interaction is received and analyzed by the test result analysis unit. If the server-side service request response message is a failure, the result determination unit determines that it fails and the test ends. Otherwise, the test is normal and the transport layer protocol test is completed.
[0064] Furthermore, step S30 includes steps C21 to C23: In step C21 , when the server authentication challenge information is obtained, the detection result analysis unit analyzes the server authentication challenge information, and the result determination unit determines the challenge information analysis result.
[0065] In step C22, if the result determination unit determines that the authentication result response information is passed, the authentication result response information is analyzed by the detection result analysis unit when the authentication result response information of the server is obtained, and the compliance of the authentication result response information is determined by the result determination unit.
[0066] In step C23 , if the result determination unit determines that any authentication layer protocol detection data fails the analysis, the detection ends and authentication layer protocol detection abnormality information is output.
[0067] In this embodiment, the authentication layer protocol detection data includes, in the order of acquisition, a server authentication challenge message and a server authentication result response message, and the server authentication challenge information includes one of a service port command authentication challenge message, a server asymmetric key authentication challenge message, and a server certificate authentication challenge message.
[0068] Exemplarily, the authentication layer protocol interaction steps and processes are as follows: The client initiates an authentication request message, the server receives the authentication request message, and replies with an authentication challenge message. The message body includes the random challenge value generated by the server, the user password authentication value, the server's dual certificates, and the server's signature value.
[0069] The client sends an authentication response message according to different authentication methods. The message body includes the user name, service name, authentication method, challenge response value, hash algorithm name (fixed to SM3) or the client's asymmetric public key or client dual certificate.
[0070] After the server completes authentication, it sends an authentication result response message (authentication success message or authentication failure message).
[0071] In the above process, the SSH authentication protocol detection layer works synchronously, first confirming the authentication protocol type between the client and the server, where the authentication protocols include password authentication protocol, asymmetric key authentication protocol and digital certificate authentication protocol. Then, after receiving the server authentication challenge information, according to the current authentication protocol type, the service port command authentication challenge message or the server asymmetric key authentication challenge message or the server certificate authentication challenge message is parsed by the detection result analysis unit, and the result judgment unit performs analysis and judgment. If it is judged to be passed, the next link detection is carried out. If it fails, it indicates that the detection is abnormal. The detection ends and the authentication layer protocol detection abnormality information is output.
[0072] If the test passes, after receiving the authentication result response message from the server (authentication success message or authentication failure message), the authentication result response message is parsed by the test result analysis unit, and the result judgment unit makes an analysis result judgment. If it fails, it means the test is abnormal, the test ends, and the authentication layer protocol detection abnormality information is output. If it passes, the test is normal, and the authentication layer protocol test is completed.
[0073] Furthermore, step S30 further includes steps C31-C32: Step C31: when the server channel connection response information is obtained, the detection result analysis unit analyzes the server channel connection response information, and the result determination unit determines the challenge information analysis result.
[0074] Step C32: If the determination fails, the detection ends and the connection layer protocol detection abnormality information is output.
[0075] In this embodiment, the connection layer protocol detection data includes server channel connection response information.
[0076] For example, the connection layer protocol process is as follows: The client initiates a new channel request message; the server sends a server channel connection response message (failure response message or confirmation response message); the client sends a data window size adjustment message; the client sends protocol communication data; the server sends protocol communication data; and the connection is closed.
[0077] During this process, the SSH connection protocol interaction layer works synchronously. After receiving the server channel connection response information (failure response message or confirmation response message), it is analyzed by the detection result analysis unit, and the result judgment unit judges the analysis result. If it fails, it means the detection is abnormal, the detection ends, and the connection layer protocol detection abnormality information is output. If it passes, the detection is normal, and the client data is transmitted through the established channel and the channel is closed normally. The interaction between the client and the server is completed, and the connection is terminated normally.
[0078] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the national secret SSH protocol detection method of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.
[0079] This application also provides a national secret SSH protocol detection device, which includes: The interactive control module is used to schedule the transmission protocol interaction unit to work through the protocol driver unit to achieve interactive connection with the server; the transmission protocol interaction unit includes the SSH transmission protocol interaction layer, the SSH authentication protocol interaction layer and the SSH connection protocol interaction layer; A detection control module is used to perform protocol detection through the corresponding detection unit to obtain detection data during the process of scheduling the transmission protocol interaction unit to work; the detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer; The analysis control module is used to analyze the test data through the test result analysis unit, and send the test data analysis results to the result judgment unit for compliance judgment and output the judgment results.
[0080] The national secret SSH protocol detection device provided in this application, which employs the national secret SSH protocol detection method described in the above-mentioned embodiments, can resolve the technical issue of low accuracy in national secret SSH protocol detection in related technologies. Compared to related technologies, the national secret SSH protocol detection device provided in this application has the same beneficial effects as the national secret SSH protocol detection method described in the above-mentioned embodiments. Other technical features of the national secret SSH protocol detection device are the same as those disclosed in the above-mentioned embodiments and are not further elaborated here.
[0081] The present application provides a national secret SSH protocol detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the national secret SSH protocol detection method in the above embodiment.
[0082] Reference below Figure 3 , which shows a schematic diagram of the structure of a national secret SSH protocol detection device suitable for implementing the embodiments of the present application. The national secret SSH protocol detection device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The national secret SSH protocol detection device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0083] like Figure 3As shown, the national secret SSH protocol detection device may include a processing device 1001 (e.g., a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1002 or programs loaded from storage device 1003 into random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the xxx device. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input device 1007, such as a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output device 1008, such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003, such as a magnetic tape or hard disk; and communication device 1009. The communication device 1009 can allow the national secret SSH protocol detection device to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a national secret SSH protocol detection device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or provided instead.
[0084] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0085] The national secret SSH protocol detection device provided in this application utilizes the national secret SSH protocol detection method described in the above-mentioned embodiment, thereby resolving the technical issue of low accuracy in national secret SSH protocol detection in related technologies. Compared to related technologies, the national secret SSH protocol detection device provided in this application offers the same beneficial effects as the national secret SSH protocol detection method described in the above-mentioned embodiment. Other technical features of the national secret SSH protocol detection device are the same as those disclosed in the above-mentioned embodiment and are not further elaborated here.
[0086] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0087] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0088] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the national encryption SSH protocol detection method in the above embodiment.
[0089] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0090] The above-mentioned computer-readable storage medium may be included in the national secret SSH protocol detection device; or it may exist independently without being assembled into the national secret SSH protocol detection device.
[0091] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the national secret SSH protocol detection device, the national secret SSH protocol detection device: through the protocol driving unit, schedules the transmission protocol interaction unit to work, and realizes an interactive connection with the server; the transmission protocol interaction unit includes the SSH transmission protocol interaction layer, the SSH authentication protocol interaction layer, and the SSH connection protocol interaction layer. In the process of scheduling the transmission protocol interaction unit to work, the detection unit performs protocol detection and obtains detection data; the detection unit includes the SSH transmission protocol detection layer, the SSH authentication protocol detection layer, and the SSH connection protocol detection layer. The detection result analysis unit analyzes the detection data, and sends the detection data analysis result to the result judgment unit for compliance judgment, and outputs the judgment result.
[0092] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0093] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0094] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0095] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned national secret SSH protocol detection method. This computer-readable storage medium can address the technical issue of low accuracy in national secret SSH protocol detection in related art. Compared to related art, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the national secret SSH protocol detection method provided in the aforementioned embodiments, and are not further elaborated here.
[0096] The present application also provides a computer program product, including a computer program, which implements the steps of the above-mentioned national secret SSH protocol detection method when executed by a processor.
[0097] The computer program product provided in this application can solve the technical problem of low accuracy in detecting the national secret SSH protocol in related technologies. Compared with related technologies, the beneficial effects of the computer program product provided in this application are the same as those of the national secret SSH protocol detection method provided in the above embodiment, and will not be elaborated here.
[0098] The above are only some embodiments of the present application and are not intended to limit the patent scope of the present application. All equivalent structural transformations made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A method for detecting the national secret SSH protocol, characterized in that: The method comprises: The protocol driver unit schedules the transmission protocol interaction unit to work and realizes the interactive connection with the server; the transmission protocol interaction unit includes the SSH transmission protocol interaction layer, the SSH authentication protocol interaction layer and the SSH connection protocol interaction layer; During the operation of the scheduling transmission protocol interaction unit, the detection unit performs protocol detection to obtain detection data; the detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer; The test data is analyzed by the test result analysis unit, and the test data analysis result is sent to the result determination unit for compliance determination, and the determination result is output.
2. The method according to claim 1, characterized in that The steps of scheduling the transmission protocol interaction unit to work and realizing the interactive connection with the server through the protocol driving unit include: The protocol driver drives the SSH transport protocol detection layer to communicate with the server, establish a secure data transmission channel, and perform key negotiation with the server. After the data transmission channel is established, the protocol driver unit drives the SSH authentication protocol interaction layer to communicate with the server to perform identity authentication; After the identity authentication is completed, the SSH connection protocol layer is driven to interactively connect with the server through a protocol driving unit.
3. The method according to claim 2, characterized in that In the process of the scheduling transmission protocol interaction unit working, the step of performing protocol detection by the corresponding detection unit to obtain detection data includes: In the process of establishing the secure data transmission channel, the server-side SSH transport layer protocol detection is performed based on the transport layer protocol interaction specification through the SSH transport protocol detection layer to obtain transport layer protocol detection data; During the identity authentication process, the SSH authentication protocol detection layer performs server-side SSH authentication layer protocol detection based on the authentication layer protocol interaction specification to obtain authentication layer protocol detection data; During the interactive connection between the SSH connection protocol layer and the server, the SSH connection protocol detection layer performs server-side SSH connection layer protocol detection based on the connection layer protocol interaction specification to obtain connection layer protocol detection data.
4. The method according to claim 3, characterized in that The transport layer protocol detection data includes, in order of acquisition, protocol identification information, server-side cipher suite information, server-side key exchange response information, and server-side service request response message; The step of analyzing the test data by the test result analysis unit and sending the test data analysis result to the result determination unit for compliance determination, and outputting the determination result includes: When the protocol identification information is obtained, the detection result analysis unit performs a compliance analysis of the server identification, and the result determination unit determines the compliance analysis result; If the result determination unit determines that the result is passed, when the server-side cipher suite information is obtained, the cipher suite information is analyzed by the detection result analysis unit, and the cipher suite information analysis result is determined by the result determination unit; If the result determination unit determines that the key exchange response is passed, then when the key exchange response information of the server is obtained, the key exchange response correctness analysis is performed by the detection result analysis unit, and the key exchange response correctness is determined by the result determination unit; If the result determination unit determines that the service request response message is passed, the service request response is analyzed by the detection result analysis unit when the service request response message is obtained, and the service request response result is determined by the result determination unit; If the result determination unit determines that the analysis result of any transport layer protocol detection data is not passed during the process, the detection ends and the transport layer protocol detection abnormality information is output.
5. The method according to claim 3, characterized in that The authentication layer protocol detection data includes, in order of acquisition, a server authentication challenge message and a server authentication result response message, wherein the server authentication challenge information includes one of a service port command authentication challenge message, a server asymmetric key authentication challenge message, and a server certificate authentication challenge message; The step of analyzing the test data by the test result analysis unit and sending the test data analysis result to the result determination unit for compliance determination, and outputting the determination result includes: When the server authentication challenge information is obtained, the detection result analysis unit performs server authentication challenge information parsing, and the result determination unit determines the challenge information parsing result; If the result determination unit determines that the authentication result response information is passed, the authentication result response information is analyzed by the detection result analysis unit when the authentication result response information of the server is obtained, and the compliance of the authentication result response information is determined by the result determination unit; If the result determination unit determines that any authentication layer protocol detection data fails the analysis result during the process, the detection ends and authentication layer protocol detection abnormality information is output.
6. The method according to claim 3, characterized in that The connection layer protocol detection data includes service end channel connection response information; The step of analyzing the test data by the test result analysis unit and sending the test data analysis result to the result determination unit for compliance determination, and outputting the determination result includes: When the server channel connection response information is obtained, the detection result analysis unit parses the server channel connection response information, and the result determination unit determines the challenge information parsing result; If the judgment fails, the detection ends and the connection layer protocol detection abnormality information is output.
7. A national secret SSH protocol detection device, characterized in that: The device comprises: An interactive control module is used to schedule the transmission protocol interaction unit to work through the protocol driving unit to achieve an interactive connection with the server; the transmission protocol interaction unit includes an SSH transmission protocol interaction layer, an SSH authentication protocol interaction layer, and an SSH connection protocol interaction layer; a detection control module configured to perform protocol detection through a corresponding detection unit to obtain detection data during the operation of the scheduling transmission protocol interaction unit; the detection unit includes an SSH transmission protocol detection layer, an SSH authentication protocol detection layer, and an SSH connection protocol detection layer; The analysis control module is used to analyze the test data through the test result analysis unit, and send the test data analysis result to the result judgment unit for compliance judgment, and output the judgment result.
8. A national secret SSH protocol detection device, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the national secret SSH protocol detection method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the national secret SSH protocol detection method according to any one of claims 1 to 6 are implemented.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the national secret SSH protocol detection method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Sensor network password security protocol test system and method
CN113162947A
System and method for detecting service compliance of SSL VPN security authentication gateway based on active scanning
CN116346688A
Datagram transport layer security protocol security detection method and device
CN118233188A
Graphical visualization of trust relationships between accounts and SSH protocol keys for network attack path detection
US20240106648A1