Malicious software encryption communication channel detection method and related device
Through the improved SRU model, malware encrypted communication channel detection is carried out, and feature extraction and weighting are improved by using the bidirectional multi-layer SRU network and attention mechanism layer, which solves the problem of inefficiency in the existing detection methods and realizes high-precision and efficient malware detection.
Patent Information
- Application Number
- CN202510657954.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-22
AI Technical Summary
Existing malware encrypted communication channel detection methods have problems with inefficient training and testing when processing sequence data, especially RNN variants such as LSTM and GRU lead to limited detection speed in serial computing mode.
The improved SRU model is adopted, including a bidirectional multi-layer SRU network, attention mechanism layer and full connection layer, and the detection accuracy and efficiency are improved through feature extraction and weighting processing.
It significantly enhances the detection accuracy and operation efficiency of malware encrypted communication channels, has high-precision and fine-grained classification capabilities, and provides more effective network security protection.
Smart Images

Figure CN120528564A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network and information security, and relates to a method for detecting malicious software encrypted communication channels and related devices. Background Art
[0002] With the increasing use of encrypted communication technology for covert malware operations, detecting malware's encrypted communication channels has become a critical challenge that needs to be addressed. Early detection methods primarily relied on signature matching methods [Anderson B, Quist D, Neil J, et al. Graph-based malware detection using dynamic analysis [J]. Journal in computer Virology, 2011, 7:247-258.]. These methods aggregate and store signatures of known malware to build a database. Detecting these signatures in a communication flow marks them as potential malware communication channels. However, this method is ineffective because encryption masks the signatures. Another technique, behavior-based detection, identifies malware communication channels by observing software behavior patterns, including whether the software frequently accesses specific network ports and whether it exhibits abnormal data transmission behavior [Kim H, Kim J, Kim Y, et al. Improvement of malware detection and classification using API call sequence alignment and visualization [J]. Cluster Computing, 2019, 22:921-929.]. In addition, there are traffic analysis technologies that can detect abnormal encrypted communication traffic by analyzing parameters such as the size, direction, and time distribution of network traffic [CHEN J, PENG B, WU P. Malicious code detection method based on dynamic behavior and machine learning [J]. Computer Engineering, 2021, 47(03): 166-173.]. Although data encryption hides the content of communication, abnormal changes in traffic can still serve as clues. For example, the sudden appearance of a large amount of encrypted traffic or encrypted communication traffic appearing at unusual times may mean that malware is transmitting data.
[0003] In recent years, machine learning and deep learning technologies have also been applied to malware encrypted communication channel detection [Backes M, Manoharan P, Grosse K, et al. Adversarial perturbations against deep neural networks for malware classification [J]. The Computing Research Repository (CoRR), 2016.]. Supervised learning algorithms such as support vector machines can demarcate the boundaries between normal and malicious communications based on data such as encrypted traffic characteristics. Deep neural networks, such as convolutional neural networks (CNNs), can automatically mine patterns of malware encrypted communication from complex traffic and behavioral characteristics. CNNs can effectively process data with spatial characteristics, but during communication interactions, traffic, as the result of data exchange, is essentially constructed sequentially from basic units such as bytes, packets, and network flows. Due to differences in packet transmission order, these units exhibit inherent time series characteristics [Alzubaidi L, Zhang J, Humaidi AJ, et al. Review of deep learning: concepts, CNN architectures, challenges, applications, future directions [J]. Journal of big Data, 2021, 8:1-74.]. When it comes to traffic classification tasks, recurrent neural networks (RNNs), which are better at processing sequence information, are applied to the field of encrypted communication channel detection.
[0004] Traditional RNNs can store past information and pass it on to current and subsequent computations when processing sequential data. However, in practical applications, they also face the limitations of short-term memory. To address this, the long short-term memory (LSTM) network was developed. The introduction of gating mechanisms and cell states is key to the LSTM architecture. Specifically, information is selectively incorporated into or deleted from the cell state based on the decisions made by the gating mechanism [Sherstinsky A. Fundamentals of recurrent neural network (RNN) and long short-term memory (LSTM) network [J]. Physica D: Nonlinear Phenomena, 2020, 404: 132-306.]. The function of the cell state is to enable the transfer of effective information in long sequences, significantly reducing the burden and limitations of short-term memory. Subsequent researchers simplified the LSTM's gating mechanism and proposed the gated recurrent unit (GRU). GRU uses hidden states to transfer information and integrates and optimizes the process of adding and discarding information [Fu R, Zhang Z, Li L. Using LSTM and GRU neural network methods for traffic flow prediction [C] / / 2016 31st Youth academic annual conference of Chinese association of automation (YAC). IEEE, 2016: 324-328.].
[0005] In the field of malware encrypted channel detection, detection methods based on LSTM and GRU have achieved good results. However, RNN variants such as LSTM and GRU still use a serial computation mode during execution. This design results in the hidden state calculation of the current time step being based not only on the current input but also on the output of the previous time step. This limits the efficiency of training and testing, as operations at each time step must wait for the results of the previous time step. During training, due to the strong dependencies between dimensions across different time steps, the detection speed of LSTM and GRU is significantly slower than that of other models. Summary of the Invention
[0006] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide a method and related device for detecting malware encrypted communication channels, which can accurately and quickly detect malware encrypted communication channels.
[0007] To achieve the above objectives, the present invention discloses a method for detecting malware encrypted communication channels, comprising:
[0008] Obtain the original encrypted traffic information of the channel to be detected;
[0009] Preprocessing the original encrypted traffic information of the channel to be detected to obtain input data;
[0010] The input data is input into the improved SRU model, and based on the output result of the improved SRU model, it is determined whether the channel to be detected is a malware encrypted communication channel, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network performs feature extraction on the input data to obtain a characteristic vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector.
[0011] The method for detecting malware encrypted communication channels according to the present invention is further improved in that:
[0012] Furthermore, the original encrypted traffic information of the channel to be detected includes at least one of the source IP address, destination IP address, source port, destination port and protocol type of the channel to be detected.
[0013] Furthermore, the process of preprocessing the original encrypted traffic information of the channel to be detected to obtain input data is as follows:
[0014] The original encrypted traffic information of the channel to be detected is sequentially subjected to traffic segmentation, data cleaning, normalization processing, and dimension transformation to obtain the input data.
[0015] Furthermore, the process of inputting the input data into the improved SRU model and determining whether the channel to be detected is a malware encrypted communication channel according to the output result of the improved SRU model is as follows:
[0016] Input the input data into the bidirectional multi-layer SRU network to obtain the feature vector h N ;
[0017] The feature vector h N Input into the attention mechanism layer to obtain the flow feature vector c;
[0018] Inputting the flow feature vector c into the fully connected layer to obtain the probability that the channel to be detected is a malware encrypted communication channel;
[0019] When the probability that the channel to be detected is a malware encrypted communication channel is greater than or equal to a preset probability threshold, it is determined that the channel to be detected is a malware encrypted communication channel.
[0020] The present invention discloses a malware encrypted communication channel detection system, comprising:
[0021] An acquisition module is used to obtain the original encrypted traffic information of the channel to be detected;
[0022] A preprocessing module, configured to preprocess the original encrypted traffic information of the channel to be detected to obtain input data;
[0023] A judgment module is used to input the input data into the improved SRU model, and judge whether the channel to be detected is a malware encrypted communication channel based on the output result of the improved SRU model, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network performs feature extraction on the input data to obtain a characteristic vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector.
[0024] The malware encrypted communication channel detection system of the present invention is further improved in that:
[0025] Furthermore, the original encrypted traffic information of the channel to be detected includes at least one of the source IP address, destination IP address, source port, destination port and protocol type of the channel to be detected.
[0026] Furthermore, the process of preprocessing the original encrypted traffic information of the channel to be detected to obtain input data is as follows:
[0027] The original encrypted traffic information of the channel to be detected is sequentially subjected to traffic segmentation, data cleaning, normalization processing, and dimension transformation to obtain the input data.
[0028] Furthermore, the judgment module includes:
[0029] The first input unit is used to input the input data into the bidirectional multi-layer SRU network to obtain the feature vector h N ;
[0030] The second input unit is used to input the feature vector h N Input into the attention mechanism layer to obtain the flow feature vector c;
[0031] a third input unit, configured to input the flow feature vector c into the fully connected layer to obtain a probability that the channel to be detected is a malware encrypted communication channel;
[0032] The judgment unit is configured to determine that the channel to be detected is a malware encrypted communication channel when the probability that the channel to be detected is a malware encrypted communication channel is greater than or equal to a preset probability threshold.
[0033] The present invention discloses a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the malware encrypted communication channel detection method are implemented.
[0034] The present invention discloses a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the malware encrypted communication channel detection method are implemented.
[0035] The present invention has the following beneficial effects:
[0036] During specific operation, the malware encrypted communication channel detection method and related devices described in the present invention input the input data into the improved SRU model, and determine whether the channel to be detected is a malware encrypted communication channel based on the output result of the improved SRU model, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer connected in sequence, wherein the bidirectional multi-layer SRU network automatically extracts features while integrating the attention mechanism layer to dynamically assign weights of different features, which can significantly enhance the discrimination of important features, thereby improving the accuracy and operating efficiency of the model, and enabling it to have both high-precision detection capabilities for unknown malware encrypted communication channels and fine-grained classification capabilities for different types of malware encrypted communication channels, providing more effective technical means for network security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The accompanying drawings, which constitute part of the present invention, are intended to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are intended to explain the present invention and do not constitute an undue limitation of the present invention. In the accompanying drawings:
[0038] Figure 1 is a flow chart of the method of the present invention;
[0039] Figure 2 It is the basic structural diagram of SRU in the present invention;
[0040] Figure 3 Schematic diagram of the improved SRU model in the present invention;
[0041] Figure 4 This is a system structure diagram of the present invention. DETAILED DESCRIPTION
[0042] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0043] In the description of the present invention, it is to be understood that the terms “include” and “comprise” indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.
[0044] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0045] It should be further understood that the term "and / or" as used in the present specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present invention generally indicates that the associated objects are in an "or" relationship.
[0046] It should be understood that although the terms "first," "second," and "third" may be used to describe preset ranges in embodiments of the present invention, these preset ranges should not be limited to these terms. These terms are merely used to distinguish one preset range from another. For example, without departing from the scope of embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.
[0047] The word "if," as used herein, may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.
[0048] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0049] The accompanying drawings illustrate various schematic diagrams of structures according to embodiments disclosed herein. These figures are not drawn to scale; for clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.
[0050] Example 1
[0051] refer to Figure 1 The malware encrypted communication channel detection method of the present invention comprises the following steps:
[0052] 1) obtaining original encrypted traffic information of the channel to be detected, wherein the original encrypted traffic information of the channel to be detected includes the source IP address, destination IP address, source port, destination port, and protocol type;
[0053] 2) Preprocessing the original encrypted traffic information of the channel to be detected to obtain input data;
[0054] The specific process of step 2) is:
[0055] 21) Divide the original encrypted traffic information into different bidirectional flows.
[0056] 22) Delete empty and duplicate data packets in the bidirectional flow to prevent such abnormal information from interfering with the prediction process of subsequent models; delete the Ethernet header in the data packets in the bidirectional flow and replace its IP address field with an all-zero value to avoid uncertainty and confusion caused by mechanisms such as dynamic port allocation and network address translation.
[0057] 23) Normalizing the data in the bidirectional stream to reduce the impact of the input data value range on the model, wherein the first n bytes of each stream are taken as the input of the model. When the length of the stream is less than n bytes, zeros are padded to n bytes to ensure the consistency of the input data length. The continuous stream data is converted into a vector f of the same length, and the single byte of the stream is converted into an integer value in the interval [0,1].
[0058] 24) Upgrade and optimize the structure of input data. Assume that the length of the flow data input to SRU at each time step is q bytes, that is, the input dimension of SRU is q. By transforming the dimension of the flow vector, it is converted into a flow matrix x = [x1, x2, ..., x N ] in the form of, where N = n / q.
[0059] 3) Construct an improved SRU model;
[0060] refer to Figure 2 The improved SRU model includes a highly parallel bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer, wherein the output end of the bidirectional multi-layer SRU network is connected to the input end of the attention mechanism layer, and the output end of the attention mechanism layer is connected to the input end of the fully connected layer.
[0061] like Figure 3 As shown, the basic structure of the simple recurrent unit SRU contains the forget gate f t , reset gate r t , cell state c t and the hidden state h t , input data x at time step t t , the SRU calculation process is:
[0062] f t =σ(W f x t +b f ) (1)
[0063] r t =σ(W r x t +b r ) (2)
[0064] c t =f t ⊙c t-1 +(1-f t )⊙(Wx t ) (3)
[0065] h t =r t ⊙g(c t )+(1-rt )⊙x t (4)
[0066] Among them, b f and b r is the parameter vector, W f , W and W r is the weight matrix, and σ represents the sigmoid function.
[0067] In the SRU gated computing framework, the traditional parameter matrix and matrix multiplication operation is replaced by parameter vector and Hadamard product, making c t and f t Each dimension of is independent, which optimizes the computational efficiency and flexibility of the neural network. t-1 When the specific value of any dimension is obtained, the dimension c can be directly determined. t and f t The corresponding result of c is no longer needed t-1 Therefore, SRU not only retains the basic characteristics of serial computing on the time series inherent in RNN, but also can realize dimension-based parallel processing and improve data processing efficiency.
[0068] The present invention uses SRU to extract features from encrypted traffic and implements a dynamic update mechanism of its hidden state according to formula (5).
[0069] h t =SRU(c t-1 ,x t ) (5)
[0070] Among them, x t is the input at the current moment, c t-1 is the unit state at the previous moment.
[0071] The working process of the improved SRU model is as follows:
[0072] 31) Feature extraction;
[0073] Set the input data to be a flow matrix x = [x1, x2, ..., x N ], the bidirectional SRU network consists of a forward SRU and a backward SRU, which are respectively denoted as and Therefore, the input read by the former is x1 to x N , while the latter reads the input x N To x1, similarly, represents the forward hidden state, Represents the backward hidden state. Introducing a skip connection in the SRU network, the input x tIt is directly passed to the subsequent layers to avoid gradient disappearance and ensure the stability and effectiveness of parameter updates when training deep network structures. The calculation of the SRU hidden state is shown in Equations (6) and (7).
[0074]
[0075] Where t∈[1,N].
[0076] Similar to reading input data, Extract x from the encrypted traffic sequence t Previous information, Then extract x t The following information, and Represents the initial hidden state, both are zero vectors, the hidden state of the complete data stream
[0077] The bidirectional SRU is stacked into an M-layer network to further extract the high-order features of the encrypted traffic data. Assume that each flow has N bytes. At time t, the output of the i-1 layer is used as the input of the i-th layer at the current time. The update of the hidden state is shown in Equation (8) and Equation (9). The hidden state of the complete data flow of the i-th layer is Right now:
[0078]
[0079] Where i∈(1,M].
[0080] The hidden states generated at all times in the Mth layer are summarized to obtain the feature vector of the encrypted traffic, as shown in Equation 10.
[0081]
[0082] The extracted feature vector h N The highly aggregated bidirectional contextual information of the entire flow enables the model to classify traffic more accurately.
[0083] 32) Attention mechanism;
[0084] In order to enhance the influence of key information on the detection results in the encrypted communication channel, this paper introduces the attention mechanism into the improved SRU model to dynamically assign corresponding weights to various features and enhance the discrimination of core features. The key step is to calculate the attention weights through an additive function, and then rely on these weights to perform a weighted summation of the hidden states of the input feature vectors. The attention weight α is t The expression is:
[0085]
[0086] Among them, tanh is the activation function, W h is the weight matrix, b is the bias term, and provides translation capability for linear transformation.
[0087] According to the weight α t The hidden states of the feature vectors are weighted summed to generate the context vector, which is the aggregated flow feature vector c, namely:
[0088]
[0089] 4) Inputting the input data into the improved SRU model, and judging whether the channel to be detected is a malware encrypted communication channel according to the output result of the improved SRU model.
[0090] The process of step 4) is:
[0091] 41) Extract features from the input data through a bidirectional multi-layer SRU network to obtain the feature vector h N , where the bidirectional SRU network with skip connections is stacked into M layers to integrate the flow context information to extract high-order features of the flow and output the feature vector h N , that is, the hidden state h at each time step t t A collection of .
[0092] 42) The eigenvector h N Input to the attention mechanism layer, and the attention weight α of each time step t is calculated through the attention mechanism layer t , for the hidden state at each time step Its attention weight α t Perform weighted summation to obtain the weighted flow feature vector c.
[0093] 43) The weighted flow feature vector c output by the attention mechanism layer is input into the fully connected layer, and the probability that the channel to be detected is a malware encrypted communication channel is calculated by the fully connected layer. When the probability is greater than the preset probability threshold, the channel to be detected is considered to be a malware encrypted communication channel.
[0094] Example 2
[0095] refer to Figure 4 The malware encrypted communication channel detection system of the present invention comprises:
[0096] An acquisition module is used to obtain the original encrypted traffic information of the channel to be detected;
[0097] A preprocessing module, configured to preprocess the original encrypted traffic information of the channel to be detected to obtain input data;
[0098] A judgment module is used to input the input data into the improved SRU model, and judge whether the channel to be detected is a malware encrypted communication channel based on the output result of the improved SRU model, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network performs feature extraction on the input data to obtain a characteristic vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector.
[0099] In this embodiment, the original encrypted traffic information of the channel to be detected includes at least one of the source IP address, destination IP address, source port, destination port, and protocol type of the channel to be detected.
[0100] In this embodiment, the process of preprocessing the original encrypted traffic information of the channel to be detected to obtain input data is as follows:
[0101] The original encrypted traffic information of the channel to be detected is sequentially subjected to traffic segmentation, data cleaning, normalization processing, and dimension transformation to obtain the input data.
[0102] In this embodiment, the judgment module includes:
[0103] The first input unit is used to input the input data into the bidirectional multi-layer SRU network to obtain the feature vector h N ;
[0104] The second input unit is used to input the feature vector h N Input into the attention mechanism layer to obtain the flow feature vector c;
[0105] a third input unit, configured to input the flow feature vector c into the fully connected layer to obtain a probability that the channel to be detected is a malware encrypted communication channel;
[0106] The judgment unit is configured to determine that the channel to be detected is a malware encrypted communication channel when the probability that the channel to be detected is a malware encrypted communication channel is greater than or equal to a preset probability threshold.
[0107] The division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0108] Example 3
[0109] A computer device comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the malware encrypted communication channel detection method are implemented, for example, including: obtaining original encrypted traffic information of the channel to be detected; preprocessing the original encrypted traffic information of the channel to be detected to obtain input data; inputting the input data into an improved SRU model, and judging whether the channel to be detected is a malware encrypted communication channel according to the output result of the improved SRU model, wherein the improved SRU model comprises a bidirectional multi-layer SRU network, an attention mechanism layer, and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network extracts features from the input data to obtain a directional vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel according to the weighted flow feature vector. The memory may include internal memory, such as high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device. The processor, network interface, and memory are interconnected via an internal bus. This internal bus may be an Industry Standard Architecture bus, a Peripheral Component Interconnect Standard bus, an Extended Industry Standard Architecture bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory is used to store programs. Specifically, the program may include program code, and the program code includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor.
[0110] Example 4
[0111] A computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the malware encrypted communication channel detection method, for example, including: obtaining original encrypted traffic information of the channel to be detected; preprocessing the original encrypted traffic information of the channel to be detected to obtain input data; inputting the input data into an improved SRU model, and judging whether the channel to be detected is a malware encrypted communication channel based on the output result of the improved SRU model, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer, and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network extracts features from the input data to obtain a characteristic vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector. Specifically, the computer-readable storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. The volatile memory may include random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include a read-only memory (ROM), a hard disk, a flash memory, an optical disk, a magnetic disk, and the like.
[0112] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0113] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0114] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0115] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0116] Those skilled in the art will readily identify other embodiments of the present invention after considering the specification and disclosure of the invention. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the invention being indicated by the following claims.
[0117] It should be understood that the present invention is not limited to the exact construction described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
[0118] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any way. Any simple modification, change and equivalent structural change made to the above embodiment based on the technical essence of the present invention shall still fall within the scope of protection of the technical solution of the present invention.
Claims
1. A method for detecting malware encrypted communication channels, characterized in that: include: Obtain the original encrypted traffic information of the channel to be detected; Preprocessing the original encrypted traffic information of the channel to be detected to obtain input data; The input data is input into an improved simple recurrent unit (SRU) model, and based on the output result of the improved SRU model, it is determined whether the channel to be detected is a malware encrypted communication channel, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer, and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network is used to perform feature extraction on the input data to obtain a directional vector, the attention mechanism layer is used to calculate a weighted flow feature vector based on the feature vector, and the fully connected layer is used to calculate the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector.
2. The malware encrypted communication channel detection method according to claim 1, characterized in that: The original encrypted traffic information of the channel to be detected includes at least one of a source Internet Protocol IP address, a destination IP address, a source port, a destination port, and a protocol type of the channel to be detected.
3. The malware encrypted communication channel detection method according to claim 1, characterized in that: The process of preprocessing the original encrypted traffic information of the channel to be detected to obtain input data is as follows: The original encrypted traffic information of the channel to be detected is sequentially subjected to traffic segmentation, data cleaning, normalization processing, and dimension transformation to obtain the input data.
4. The malware encrypted communication channel detection method according to claim 1, characterized in that: The process of inputting the input data into the improved SRU model and determining whether the channel to be detected is a malware encrypted communication channel according to the output result of the improved SRU model is as follows: Input the input data into the bidirectional multi-layer SRU network to obtain the feature vector h N ; The feature vector h N Input into the attention mechanism layer to obtain the flow feature vector c; Inputting the flow feature vector c into the fully connected layer to obtain the probability that the channel to be detected is a malware encrypted communication channel; When the probability that the channel to be detected is a malware encrypted communication channel is greater than or equal to a preset probability threshold, it is determined that the channel to be detected is a malware encrypted communication channel.
5. A malware encrypted communication channel detection system, characterized in that: include: An acquisition module is used to obtain the original encrypted traffic information of the channel to be detected; A preprocessing module, configured to preprocess the original encrypted traffic information of the channel to be detected to obtain input data; A judgment module is used to input the input data into the improved SRU model, and judge whether the channel to be detected is a malware encrypted communication channel based on the output result of the improved SRU model, wherein the improved SRU model includes a bidirectional multi-layer SRU network, an attention mechanism layer and a fully connected layer connected in sequence, the bidirectional multi-layer SRU network performs feature extraction on the input data to obtain a characteristic vector, the attention mechanism layer calculates a weighted flow feature vector based on the feature vector, and the fully connected layer calculates the probability that the channel to be detected is a malware encrypted communication channel based on the weighted flow feature vector.
6. The malware encrypted communication channel detection system according to claim 5, characterized in that: The original encrypted traffic information of the channel to be detected includes at least one of the source IP address, destination IP address, source port, destination port and protocol type of the channel to be detected.
7. The malware encrypted communication channel detection system according to claim 5, characterized in that: The process of preprocessing the original encrypted traffic information of the channel to be detected to obtain input data is as follows: The original encrypted traffic information of the channel to be detected is sequentially subjected to traffic segmentation, data cleaning, normalization processing, and dimension transformation to obtain the input data.
8. The malware encrypted communication channel detection system according to claim 5, characterized in that: The judgment module includes: The first input unit is used to input the input data into the bidirectional multi-layer SRU network to obtain the feature vector h N ; The second input unit is used to input the feature vector h N Input into the attention mechanism layer to obtain the flow feature vector c; a third input unit, configured to input the flow feature vector c into the fully connected layer to obtain a probability that the channel to be detected is a malware encrypted communication channel; The judgment unit is configured to determine that the channel to be detected is a malware encrypted communication channel when the probability that the channel to be detected is a malware encrypted communication channel is greater than or equal to a preset probability threshold.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the malware encrypted communication channel detection method according to any one of claims 1 to 4 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the malware encrypted communication channel detection method according to any one of claims 1 to 4 are implemented.