Network traffic APT detection method and device, computer equipment and storage medium

By collecting long-term network traffic data and combining traffic analysis and APT detection strategies, multiple classification models are used for detection, which solves the problem of insufficient detection depth in the existing technology, and achieves more accurate APT detection and security protection.

CN120602222AActive Publication Date: 2025-09-05SHENZHEN CHINA MOTION INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511080746.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-09-05
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

In the prior art, firewalls and other devices rely on static rule matching and basic protocol analysis methods for network traffic APT detection, which is insufficient in detection depth, resulting in inaccurate detection results.

Method used

Collect long-term network traffic data, combine traffic analysis strategies and network traffic APT detection strategies, and use multiple classification models to detect through protocol analysis and behavioral analysis, determine the abnormal detection results, and implement corresponding security defense strategies.

Benefits of technology

It realizes more accurate network traffic APT detection, can timely identify complex advanced persistent threats, and take effective security protection measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602222A_ABST
    Figure CN120602222A_ABST
Patent Text Reader

Abstract

The invention discloses a network traffic APT detection method and apparatus, a computer device and a storage medium. The method comprises the steps of obtaining current network traffic data; obtaining current protocol analysis data and current behavior analysis data of the current network flow data based on the flow analysis strategy; determining a current detection result of the current network flow data according to a network flow APT detection strategy, the current protocol analysis data and the current behavior analysis data; and if it is determined that the current detection result belongs to the preset abnormal network traffic type set, obtaining a target security defense strategy corresponding to the current detection result from a plurality of preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data. According to the embodiment of the invention, more accurate network flow APT detection can be carried out in combination with the flow analysis strategy and the network flow APT detection strategy after long-time current network flow data are collected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a network traffic APT detection method, device, computer equipment and storage medium. Background Art

[0002] Cybersecurity (full name in English) refers to the protection of network system hardware, software, and the data within these systems from accidental or malicious damage, alteration, or leakage, ensuring continuous, reliable, and normal system operation and uninterrupted network services. The intranets of various organizations (such as corporate groups and small and medium-sized non-corporate enterprises) all require network security, making anomaly detection of network traffic particularly important. In addition to short-term, immediate anomaly detection of network traffic, APT (Advanced Persistent Threat) detection is also necessary. The essence of APT detection is the continuous and long-term monitoring of network traffic, enabling the implementation of appropriate protective measures when APT network attacks are detected.

[0003] Currently, firewalls and Unified Threat Management (UTM) devices primarily rely on static rule matching and basic protocol analysis to detect APTs in network traffic. However, these devices lack sufficient detection depth, checking only a single request and failing to correlate multi-stage attacks, leading to inaccurate detection results. Summary of the Invention

[0004] Embodiments of the present invention provide a network traffic APT detection method, apparatus, computer equipment, and storage medium, aiming to solve the problem in the prior art that APT detection of network traffic in devices such as firewalls mainly relies on static rule matching and basic protocol analysis, but the detection depth is insufficient, resulting in inaccurate detection results.

[0005] In a first aspect, an embodiment of the present invention provides a method for detecting APT in network traffic, comprising: In response to the network traffic detection instruction, current network traffic data is acquired; wherein the acquisition time of the current network traffic data exceeds a preset acquisition time threshold; Acquire current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; Determine a current detection result of the current network traffic data based on a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; If it is determined that the current detection result belongs to the preset abnormal network traffic detection result set, a target security defense strategy corresponding to the current detection result is obtained from multiple preset security defense strategies, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data.

[0006] In a second aspect, an embodiment of the present invention further provides a network traffic APT detection device, comprising: A network traffic acquisition unit, configured to acquire current network traffic data in response to a network traffic detection instruction; wherein a collection time of the current network traffic data exceeds a preset collection time threshold; A traffic analysis unit, configured to obtain current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; An APT detection unit, configured to determine a current detection result of the current network traffic data according to a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; A security processing unit is used to obtain a target security defense strategy corresponding to the current detection result from a plurality of preset security defense strategies if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

[0007] In a third aspect, an embodiment of the present invention further provides a computer device comprising a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the method described in the first aspect is implemented.

[0008] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the method described in the first aspect can be implemented.

[0009] Embodiments of the present invention provide a network traffic APT detection method, apparatus, computer equipment, and storage medium. The method includes: obtaining current network traffic data in response to a network traffic detection instruction; obtaining current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; determining a current detection result of the current network traffic data based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; if it is determined that the current detection result belongs to a preset abnormal network traffic type set, obtaining a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data. The embodiment of the present invention can collect current network traffic data for a long period of time and, in combination with the traffic analysis strategy and the network traffic APT detection strategy, perform more accurate network traffic APT detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0011] Figure 1 A schematic diagram of an application scenario of the network traffic APT detection method provided by an embodiment of the present invention; Figure 2 A schematic diagram of the flow of a network traffic APT detection method provided by an embodiment of the present invention; Figure 3 A schematic diagram of a sub-process of a network traffic APT detection method provided by an embodiment of the present invention; Figure 4 Another flowchart of the network traffic APT detection method provided by an embodiment of the present invention; Figure 5 A schematic block diagram of a network traffic APT detection device provided by an embodiment of the present invention; Figure 6 A schematic block diagram of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0012] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0013] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0014] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the present invention. As used in the specification and appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0015] It should be further understood that the term "and / or" used in the present description and appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0016] Please also refer to Figure 1 and Figure 2 ,in Figure 1 Schematic diagram of a network traffic APT detection method according to an embodiment of the present invention. Figure 2 FIG. 1 is a flow chart of a network traffic APT detection method provided by an embodiment of the present invention. Figure 1 As shown, the network traffic APT detection method provided by the embodiment of the present invention is applied to the user terminal 10, which is a computer device such as a firewall device, a gateway, a switch, a desktop computer, a laptop computer, a tablet computer, etc., and the user terminal 10 is connected to the cloud server 20. Figure 2 As shown, the method includes the following steps S110-S140.

[0017] S110 . Responding to a network traffic detection instruction, obtaining current network traffic data.

[0018] The collection time of the current network traffic data exceeds a preset collection time threshold.

[0019] In this embodiment, the technical solution is described using a user terminal as the execution entity. More specifically, the technical solution is described using the user terminal as a firewall device, a border node. A network traffic APT detection platform is deployed on the user terminal. After the user registers or logs in to the network traffic APT detection platform with their authorization and consent, they can click the "Start Network Traffic Detection" button on the user interface of the network traffic APT detection platform to begin detecting abnormal network traffic. Update data can be provided by the cloud server, and the version of the network traffic APT detection platform in the user terminal can be updated regularly or irregularly.

[0020] Because APT attacks are complex, targeted, and long-term, activating the network traffic detection function of the network traffic APT detection platform allows us to not only collect minute-by-minute traffic data but also collect data spanning days or even months to form the current network traffic data, which serves as the target data for analysis. It's important to note that this network traffic data collection is full-scale, not sampled. This approach effectively achieves automated network traffic data collection.

[0021] Among them, the current network traffic data includes plaintext traffic data and can also include encrypted traffic data. When the encrypted traffic data is obtained, its TLS handshake metadata (such as JA3 fingerprint, certificate information, etc., where the full name of TLS is Transport Layer Security and represents transport layer security, and JA3 is a method for fingerprinting transport layer security applications) must also be obtained at the same time.

[0022] S120: Acquire current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy.

[0023] In this embodiment, a traffic analysis policy is deployed in the user terminal. This policy can obtain current network traffic data and then perform communication protocol analysis on it, obtaining HTTP / HTTPS protocol analysis results, TLS / SSL protocol analysis results, DNS protocol analysis results, and other results, thereby forming current protocol analysis data. Of course, the traffic analysis policy can also perform behavioral data analysis on the current network traffic data, thereby obtaining current behavioral analysis data. Thus, the traffic analysis policy can perform traffic analysis at least from the perspectives of communication protocols and traffic data.

[0024] In one embodiment, if Figure 3 As shown, step S120 includes: S121. Obtain HTTP / HTTPS protocol parsing results, TLS / SSL protocol parsing results, and DNS protocol parsing results in the current network traffic data through the protocol parsing sub-strategy in the traffic analysis strategy, and form the current protocol parsing data; S122. Obtain the encrypted data fingerprint abnormality features, large data flow outbound features, malware propagation features and APT attack behavior features in the current network traffic data through the behavior recognition sub-strategy in the traffic analysis strategy, and form the current behavior analysis data.

[0025] In this embodiment, when obtaining the HTTP / HTTPS protocol (HTTP stands for Hypertext Transfer Protocol and represents Hypertext Transfer Protocol, HTTPS stands for Hypertext Transfer Protocol Secure and represents Hypertext Transfer Protocol Secure) parsing results in the current network traffic data through the protocol parsing sub-strategy, specifically, the key fields of the HTTP / HTTPS protocol header are detected to determine whether there is a user agent (user agent) with abnormal C2 communication and whether there is a content type of data leakage, wherein C2 in C2 communication stands for Command and Control Communication and is a command and control channel between an attacker and malware (such as a Trojan horse or a bot) implanted in a target system; when obtaining the TLS / SSL protocol (TLS stands for Transport Layer Security and represents Transport Layer Security Protocol, SSL stands for Secure Sockets Layer and represents Secure Sockets Layer Protocol) parsing results, specifically, the certificate information is detected to determine whether there is a certificate expiration, if the certificate information has a certificate expiration, it is represented by a characteristic value of 1, if the certificate information does not have a certificate expiration, it is represented by a characteristic value of 0; and the DNS protocol (DNS stands for Domain Name System (Domain Name System) resolution results, specifically to detect whether there is a covert channel in the DNS protocol. If there is a covert channel in the DNS protocol, it is indicated by a characteristic value of 1; if there is no covert channel in the DNS protocol, it is indicated by a characteristic value of 0.

[0026] By obtaining the abnormal encrypted data fingerprint characteristics, large data flow transmission characteristics, malware propagation characteristics and APT attack behavior characteristics in the current network traffic data through the protocol parsing sub-strategy, it is possible to determine whether the current network traffic data has abnormal APT attack behavior from at least the above four feature dimensions.

[0027] In one embodiment, obtaining the HTTP / HTTPS protocol parsing result in the current network traffic data through the protocol parsing sub-strategy in step S121 includes: Determine, by the protocol parsing sub-strategy, an identification result for a specified browser identifier in a key field of a header of the HTTP / HTTPS protocol in the current network traffic data; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result including a specified browser identifier, the existence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include a specified browser identifier, then the absence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result.

[0028] In this embodiment, when determining whether a user agent indicating a C2 communication anomaly exists by obtaining a key field in the HTTP / HTTPS protocol header in the current network traffic data through the protocol parsing sub-strategy, a check may be performed to determine whether the key field http.user_agent or https.user_agent in the HTTP / HTTPS protocol header includes a specified browser identifier (e.g., Mozilla / 5.0). Specifically, if the HTTP / HTTPS protocol in the current network traffic data is determined to include the specified browser identifier, the presence of a C2 communication anomaly is considered the HTTP / HTTPS protocol parsing result, and is represented by a feature value of 1. If the HTTP / HTTPS protocol in the current network traffic data is determined to not include the specified browser identifier, the absence of a C2 communication anomaly is considered the HTTP / HTTPS protocol parsing result, and is represented by a feature value of 0.

[0029] In one embodiment, step S122 includes: Obtaining the JA3 fingerprint in the current network traffic data through the behavior recognition sub-strategy, and using the abnormality detection result of the JA3 fingerprint as the abnormal feature of the encrypted data fingerprint; The total flow, peak flow and number of attack sources in the current network flow data are obtained through the behavior identification sub-strategy, and the features of the large-flow outbound transmission of data are formed; The number of infected hosts, the propagation rate, and the virus type in the current network traffic data are obtained through the behavior recognition sub-strategy, and the malware propagation characteristics are formed; The attack phase, duration and attacker IP address in the current network traffic data are obtained through the behavior identification sub-strategy to form the APT attack behavior characteristics.

[0030] In this embodiment, when obtaining the abnormal characteristics of the encrypted data fingerprint in the current network traffic data through the behavior identification sub-strategy, the specific implementation is to detect whether the JA3 fingerprint has an abnormality. If the JA3 fingerprint has an abnormality, it is represented by a characteristic value of 1; if the JA3 fingerprint has an abnormality, it is represented by a characteristic value of 0. When obtaining the characteristics of high-volume data outflow, the specific implementation is to detect the total traffic volume of the current network traffic data (for example, N1GB, where the statistical duration of the total traffic volume is equal to the total statistical duration of the current network traffic data, and N1 is a positive number), peak traffic volume (for example, in MB / S), and the number of attack sources (obtained by counting the total number of attack sources within the statistical time interval corresponding to the statistical duration of the current network traffic data); when obtaining the characteristics of malware propagation, the specific implementation is to detect the number of infected hosts, propagation rate (obtained by dividing the number of infected hosts by the total statistical duration of the current network traffic data), and virus type (for example, ransomware, Trojan, bot, etc.) corresponding to the current network traffic data; and when obtaining the characteristics of APT attack behavior, the specific implementation is to detect the attack phase (for example, information collection, information transmission, etc.), duration, and attacker IP address corresponding to the current network traffic data. Thus, through the above method, key information can be obtained from the current network traffic data from at least the above four characteristic dimensions, which can be used to subsequently determine whether the current network traffic data contains abnormal APT attack behavior.

[0031] S130: Determine a current detection result of the current network traffic data according to a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data.

[0032] In this embodiment, a network traffic APT detection strategy is also pre-deployed in the network traffic APT detection platform of the user terminal. Through this network traffic APT detection strategy, the current protocol parsing data and current behavior analysis data of the current network traffic data can be accurately analyzed to obtain the current detection result of the current network traffic data.

[0033] In one embodiment, if Figure 4 As shown, step S130 includes: S131, detecting abnormal protocols in the current protocol parsing data using the network traffic APT detection strategy, and forming a first abnormality detection result with the communication protocols having abnormalities; S132, detecting abnormal access behavior features in the current behavior analysis data using the network traffic APT detection strategy, and obtaining a second abnormality detection result based on the abnormal access behavior features; S133: The first abnormality detection result and the second abnormality detection result form the current detection result.

[0034] In this embodiment, as a specific example of the network traffic APT detection strategy, it is not a static rule, but rather can utilize multiple classification models. First input data consisting of feature values ​​corresponding to multiple protocol parsing results in the current protocol parsing data can be input into a first classification model (such as a random forest model) to obtain a first anomaly detection result. For example, the current protocol parsing data includes feature values ​​corresponding to three protocol parsing results, and the first anomaly detection result includes three probability values, all ranging from 0 to 1.

[0035] Second input data consisting of the feature data in the current behavior analysis data can also be input into a second classification model (which can use a classification model different from the first classification model, such as a LightGBM model) to obtain a second anomaly detection result. For example, the current behavior analysis data includes four dimensions of access behavior features, and the second anomaly detection result includes four probability values ​​with values ​​ranging from 0 to 1. Finally, the three probability values ​​with values ​​ranging from 0 to 1 in the first anomaly detection result and the four probability values ​​with values ​​ranging from 0 to 1 in the second anomaly detection result are concatenated to form a current detection result consisting of seven probability values ​​with values ​​ranging from 0 to 1.

[0036] S140. If it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, a target security defense strategy corresponding to the current detection result is obtained from a plurality of preset security defense strategies, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data.

[0037] In this embodiment, if it is determined that the current detection result belongs to the preset abnormal network traffic detection result set, it means that the current detection result is the same as one of the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and the security defense strategy needs to be executed in a timely manner. For example, still referring to the above example, the current detection result is a vector composed of 7 probability values ​​whose value ranges are all between 0 and 1, and the preset abnormal network traffic detection result set also has a vector composed of 7 probability values ​​whose value ranges are all between 0 and 1 that is exactly the same as the current detection result, then the security defense strategy corresponding to the abnormal network traffic detection result is used as the target security defense strategy, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data. For example, the target security defense strategy is to block transmission and enhance the boundary protection level.

[0038] If it is determined that the current detection result does not belong to the preset abnormal network traffic detection result set, it means that the current detection result is different from all the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and there is no need to execute the security defense strategy in time. At this time, conventional network data statistical processing can be performed, such as data statistics and display from parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the stable operation time of the system.

[0039] In one embodiment, after step S140, the method further includes: Based on the target security defense strategy, determine the abnormal traffic threat level, malware propagation impact range and APT attack behavior defense recommendation strategy corresponding to the current behavior analysis data in the current network traffic data.

[0040] In this embodiment, when the target security defense strategy is executed to perform corresponding security processing on the current network traffic data, if the target security defense strategy is blocking transmission and enhancing the boundary protection level in the above example, the user terminal can further perform visual processing and display on the current behavior analysis data in the current network traffic data. For example, the current behavior analysis data includes abnormal features of encrypted data fingerprints, features of large data flow outbound transmission, features of malware propagation, and features of APT attack behavior. In this case, the features of large data flow outbound transmission, malware propagation, and APT attack behavior are selected for visual processing and display in combination with the target security defense strategy. The visual display result corresponding to the features of large data flow outbound transmission is processed as medium risk (i.e., the abnormal traffic threat level is medium risk), the visual display result corresponding to the features of malware propagation is processed as medium impact range, and the visual display result corresponding to the recommended APT attack behavior defense strategy is processed as blocking and enhancing the boundary protection level.

[0041] In one embodiment, after step S140, the method further includes: If a data analysis instruction is detected, the data statistics corresponding to the current network traffic data are obtained and displayed.

[0042] In this embodiment, the user terminal can further collect statistics on the current network traffic data. The statistical results include parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable operation time. These parameters can intuitively display multi-dimensional information corresponding to the current network traffic data.

[0043] It can be seen that the embodiment of the method can collect current network traffic data for a long time and then perform more accurate network traffic APT detection in combination with the traffic analysis strategy and the network traffic APT detection strategy.

[0044] Figure 5 FIG is a schematic block diagram of a network traffic APT detection device provided by an embodiment of the present invention. Figure 5 As shown, corresponding to the above network traffic APT detection method, the present invention also provides a network traffic APT detection device 100. The network traffic APT detection device 100 includes a unit for executing the above network traffic APT detection method. Figure 5 The network traffic APT detection device 100 includes: a network traffic acquisition unit 110, a traffic analysis unit 120, an APT detection unit 130 and a security processing unit 140.

[0045] The network traffic acquisition unit 110 is configured to acquire current network traffic data in response to a network traffic detection instruction.

[0046] The collection time of the current network traffic data exceeds a preset collection time threshold.

[0047] In this embodiment, the technical solution is described using a user terminal as the execution entity. More specifically, the technical solution is described using the user terminal as a firewall device, a border node. A network traffic APT detection platform is deployed on the user terminal. After the user registers or logs in to the network traffic APT detection platform with their authorization and consent, they can click the "Start Network Traffic Detection" button on the user interface of the network traffic APT detection platform to begin detecting abnormal network traffic. Update data can be provided by the cloud server, and the version of the network traffic APT detection platform in the user terminal can be updated regularly or irregularly.

[0048] Because APT attacks are complex, targeted, and long-term, activating the network traffic detection function of the network traffic APT detection platform allows us to not only collect minute-by-minute traffic data but also collect data spanning days or even months to form the current network traffic data, which serves as the target data for analysis. It's important to note that this network traffic data collection is full-scale, not sampled. This approach effectively achieves automated network traffic data collection.

[0049] Among them, the current network traffic data includes plaintext traffic data and can also include encrypted traffic data. When the encrypted traffic data is obtained, its TLS handshake metadata (such as JA3 fingerprint, certificate information, etc., where the full name of TLS is Transport Layer Security and represents transport layer security, and JA3 is a method for fingerprinting transport layer security applications) must also be obtained at the same time.

[0050] The traffic analysis unit 120 is configured to obtain current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy.

[0051] In this embodiment, a traffic analysis strategy is deployed in the user terminal. This strategy can obtain current network traffic data and then perform communication protocol analysis on it, obtaining HTTP / HTTPS protocol analysis results, TLS / SSL protocol analysis results, DNS protocol analysis results, and other results, thereby forming current protocol analysis data. Of course, the traffic analysis strategy can also perform behavioral data analysis on the current network traffic data, thereby obtaining current behavioral analysis data. Thus, the traffic analysis strategy can perform traffic analysis at least from the perspectives of communication protocols and traffic data.

[0052] In one embodiment, the traffic analysis unit 120 is specifically configured to: Obtaining the HTTP / HTTPS protocol parsing result, TLS / SSL protocol parsing result, and DNS protocol parsing result in the current network traffic data through the protocol parsing sub-strategy in the traffic analysis strategy, and forming the current protocol parsing data; The behavior identification sub-strategy in the traffic analysis strategy is used to obtain the encrypted data fingerprint abnormality features, large data flow outflow features, malware propagation features and APT attack behavior features in the current network traffic data, and form the current behavior analysis data.

[0053] In this embodiment, when obtaining the HTTP / HTTPS protocol (HTTP stands for Hypertext Transfer Protocol and represents Hypertext Transfer Protocol, HTTPS stands for Hypertext Transfer Protocol Secure and represents Hypertext Transfer Protocol Secure) parsing results in the current network traffic data through the protocol parsing sub-strategy, specifically, the key fields of the HTTP / HTTPS protocol header are detected to determine whether there is a user agent (user agent) with abnormal C2 communication and whether there is a content type of data leakage, wherein C2 in C2 communication stands for Command and Control Communication and is a command and control channel between an attacker and malware (such as a Trojan horse or a bot) implanted in a target system; when obtaining the TLS / SSL protocol (TLS stands for Transport Layer Security and represents Transport Layer Security Protocol, SSL stands for Secure Sockets Layer and represents Secure Sockets Layer Protocol) parsing results, specifically, the certificate information is detected to determine whether the certificate is expired, if the certificate information has a certificate expiration, it is represented by a characteristic value of 1, if the certificate information does not have a certificate expiration, it is represented by a characteristic value of 0; and the DNS protocol (DNS stands for Domain Name System (Domain Name System) resolution results, specifically to detect whether there is a covert channel in the DNS protocol. If there is a covert channel in the DNS protocol, it is indicated by a characteristic value of 1; if there is no covert channel in the DNS protocol, it is indicated by a characteristic value of 0.

[0054] By obtaining the abnormal encrypted data fingerprint characteristics, large data flow transmission characteristics, malware propagation characteristics and APT attack behavior characteristics in the current network traffic data through the protocol parsing sub-strategy, it is possible to determine whether the current network traffic data has abnormal APT attack behavior from at least the above four feature dimensions.

[0055] In one embodiment, obtaining the HTTP / HTTPS protocol parsing result in the current network traffic data through the protocol parsing sub-strategy includes: Determine, by the protocol parsing sub-strategy, an identification result for a specified browser identifier in a key field of a header of the HTTP / HTTPS protocol in the current network traffic data; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result including a specified browser identifier, the existence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include a specified browser identifier, then the absence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result.

[0056] In this embodiment, when determining whether a user agent indicating a C2 communication anomaly exists by obtaining a key field in the HTTP / HTTPS protocol header in the current network traffic data through the protocol parsing sub-strategy, a check may be performed to determine whether the key field http.user_agent or https.user_agent in the HTTP / HTTPS protocol header includes a specified browser identifier (e.g., Mozilla / 5.0). Specifically, if the HTTP / HTTPS protocol in the current network traffic data is determined to include the specified browser identifier, the presence of a C2 communication anomaly is considered the HTTP / HTTPS protocol parsing result, and is represented by a feature value of 1. If the HTTP / HTTPS protocol in the current network traffic data is determined to not include the specified browser identifier, the absence of a C2 communication anomaly is considered the HTTP / HTTPS protocol parsing result, and is represented by a feature value of 0.

[0057] In one embodiment, the traffic analysis unit 120 is further configured to: Obtaining the JA3 fingerprint in the current network traffic data through the behavior recognition sub-strategy, and using the abnormality detection result of the JA3 fingerprint as the abnormal feature of the encrypted data fingerprint; The total flow, peak flow and number of attack sources in the current network flow data are obtained through the behavior identification sub-strategy, and the features of the large-flow outbound transmission of data are formed; The number of infected hosts, the propagation rate, and the virus type in the current network traffic data are obtained through the behavior recognition sub-strategy, and the malware propagation characteristics are formed; The attack phase, duration and attacker IP address in the current network traffic data are obtained through the behavior identification sub-strategy to form the APT attack behavior characteristics.

[0058] In this embodiment, when obtaining the abnormal characteristics of the encrypted data fingerprint in the current network traffic data through the behavior identification sub-strategy, the specific implementation is to detect whether the JA3 fingerprint has an abnormality. If the JA3 fingerprint has an abnormality, it is represented by a characteristic value of 1; if the JA3 fingerprint has an abnormality, it is represented by a characteristic value of 0. When obtaining the characteristics of high-volume data outflow, the specific implementation is to detect the total traffic volume of the current network traffic data (for example, N1GB, where the statistical duration of the total traffic volume is equal to the total statistical duration of the current network traffic data, and N1 is a positive number), peak traffic volume (for example, in MB / S), and the number of attack sources (obtained by counting the total number of attack sources within the statistical time interval corresponding to the statistical duration of the current network traffic data); when obtaining the characteristics of malware propagation, the specific implementation is to detect the number of infected hosts, propagation rate (obtained by dividing the number of infected hosts by the total statistical duration of the current network traffic data), and virus type (for example, ransomware, Trojan, bot, etc.) corresponding to the current network traffic data; and when obtaining the characteristics of APT attack behavior, the specific implementation is to detect the attack phase (for example, information collection, information transmission, etc.), duration, and attacker IP address corresponding to the current network traffic data. Thus, through the above method, key information can be obtained from the current network traffic data from at least the above four characteristic dimensions, which can be used to subsequently determine whether the current network traffic data contains abnormal APT attack behavior.

[0059] The APT detection unit 130 is configured to determine a current detection result of the current network traffic data according to a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data.

[0060] In this embodiment, a network traffic APT detection strategy is also pre-deployed in the network traffic APT detection platform of the user terminal. Through this network traffic APT detection strategy, the current protocol parsing data and current behavior analysis data of the current network traffic data can be accurately analyzed to obtain the current detection result of the current network traffic data.

[0061] In one embodiment, the APT detection unit 130 is specifically configured to: Detecting abnormal protocols in the current protocol parsing data using the network traffic APT detection strategy, and forming a first abnormality detection result with the communication protocol having the abnormality; Detecting abnormal access behavior features in the current behavior analysis data using the network traffic APT detection strategy, and obtaining a second abnormality detection result based on the abnormal access behavior feature composition; The current detection result is composed of the first abnormality detection result and the second abnormality detection result.

[0062] In this embodiment, as a specific example of the network traffic APT detection strategy, it is not a static rule, but rather can utilize multiple classification models. First input data consisting of feature values ​​corresponding to multiple protocol parsing results in the current protocol parsing data can be input into a first classification model (such as a random forest model) to obtain a first anomaly detection result. For example, the current protocol parsing data includes feature values ​​corresponding to three protocol parsing results, and the first anomaly detection result includes three probability values, all ranging from 0 to 1.

[0063] Second input data consisting of the feature data in the current behavior analysis data can also be input into a second classification model (which can use a classification model different from the first classification model, such as a LightGBM model) to obtain a second anomaly detection result. For example, the current behavior analysis data includes four dimensions of access behavior features, and the second anomaly detection result includes four probability values ​​with values ​​ranging from 0 to 1. Finally, the three probability values ​​with values ​​ranging from 0 to 1 in the first anomaly detection result and the four probability values ​​with values ​​ranging from 0 to 1 in the second anomaly detection result are concatenated to form a current detection result consisting of seven probability values ​​with values ​​ranging from 0 to 1.

[0064] The security processing unit 140 is used to obtain a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

[0065] In this embodiment, if it is determined that the current detection result belongs to the preset abnormal network traffic detection result set, it means that the current detection result is the same as one of the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and the security defense strategy needs to be executed in a timely manner. For example, still referring to the above example, the current detection result is a vector composed of 7 probability values ​​whose value ranges are all between 0 and 1, and the preset abnormal network traffic detection result set also has a vector composed of 7 probability values ​​whose value ranges are all between 0 and 1 that is exactly the same as the current detection result, then the security defense strategy corresponding to the abnormal network traffic detection result is used as the target security defense strategy, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data. For example, the target security defense strategy is to block transmission and enhance the boundary protection level.

[0066] If it is determined that the current detection result does not belong to the preset abnormal network traffic detection result set, it means that the current detection result is different from all the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and there is no need to execute the security defense strategy in time. At this time, conventional network data statistical processing can be performed, such as data statistics and display from parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the stable operation time of the system.

[0067] In one embodiment, the network traffic APT detection device 100 further includes: A visualization result acquisition unit is used to determine the abnormal traffic threat level, malware propagation impact range and APT attack behavior defense recommendation strategy corresponding to the current behavior analysis data in the current network traffic data based on the target security defense strategy.

[0068] In this embodiment, when the target security defense strategy is executed to perform corresponding security processing on the current network traffic data, if the target security defense strategy is blocking transmission and enhancing the boundary protection level in the above example, the user terminal can further perform visual processing and display on the current behavior analysis data in the current network traffic data. For example, the current behavior analysis data includes abnormal features of encrypted data fingerprints, features of large data flow outbound transmission, features of malware propagation, and features of APT attack behavior. In this case, the features of large data flow outbound transmission, malware propagation, and APT attack behavior are selected for visual processing and display in combination with the target security defense strategy. The visual display result corresponding to the features of large data flow outbound transmission is processed as medium risk (i.e., the abnormal traffic threat level is medium risk), the visual display result corresponding to the features of malware propagation is processed as medium impact range, and the visual display result corresponding to the recommended APT attack behavior defense strategy is processed as blocking and enhancing the boundary protection level.

[0069] In one embodiment, the network traffic APT detection device 100 further includes: The network data statistics unit is used to obtain and display data statistics results corresponding to the current network traffic data if a data analysis instruction is detected.

[0070] In this embodiment, the user terminal can further collect statistics on the current network traffic data. The statistical results include parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable operation time. These parameters can intuitively display multi-dimensional information corresponding to the current network traffic data.

[0071] It can be seen that the embodiment of the device can collect current network traffic data for a long time and then perform more accurate network traffic APT detection in combination with traffic analysis strategy and network traffic APT detection strategy.

[0072] The above network traffic APT detection device can be implemented in the form of a computer program. The computer program can be used in Figure 6 Runs on the computer device shown.

[0073] See also Figure 6 , Figure 6 This is a schematic block diagram of a computer device provided by an embodiment of the present invention. The computer device integrates any network traffic APT detection device provided by an embodiment of the present invention.

[0074] See Figure 6 The computer device 400 includes a processor 402 , a memory, and a network interface 405 connected via a system bus 401 , wherein the memory may include a storage medium 403 and an internal memory 404 .

[0075] The storage medium 403 may store an operating system 4031 and a computer program 4032. The computer program 4032 includes program instructions, which, when executed, may enable the processor 402 to execute a network traffic APT detection method.

[0076] The processor 402 is used to provide computing and control capabilities to support the operation of the entire computer device.

[0077] The internal memory 404 provides an environment for the operation of the computer program 4032 in the storage medium 403. When the computer program 4032 is executed by the processor 402, the processor 402 can execute the above-mentioned network traffic APT detection method.

[0078] The network interface 405 is used to communicate with other devices through the network. Figure 6 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present invention and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0079] The processor 402 is configured to run a computer program 4032 stored in the memory to implement the aforementioned network traffic APT detection method.

[0080] It should be understood that in the embodiment of the present invention, the processor 402 may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0081] Those skilled in the art will appreciate that all or part of the steps in the method of the above-described embodiment can be implemented by instructing the relevant hardware through a computer program. The computer program includes program instructions, which can be stored in a storage medium that is computer-readable. The program instructions are executed by at least one processor in the computer system to implement the steps in the method of the above-described embodiment.

[0082] Therefore, the present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a processor, the processor executes the above-mentioned network traffic APT detection method.

[0083] The storage medium may be any computer-readable storage medium that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disk.

[0084] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0085] In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the various units is merely a logical functional division, and actual implementation may employ other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not implemented.

[0086] The steps in the methods of the embodiments of the present invention may be adjusted in order, combined, or deleted as needed. The units in the devices of the embodiments of the present invention may be combined, divided, or deleted as needed. Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit.

[0087] If this integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (such as a personal computer, terminal, or network device) to perform all or part of the steps of the method described in various embodiments of the present invention.

[0088] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and such modifications or substitutions are intended to be within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be subject to the scope of protection of the claims.

Claims

1. A network traffic APT detection method, characterized in that: include: In response to the network traffic detection instruction, current network traffic data is acquired; wherein the acquisition time of the current network traffic data exceeds a preset acquisition time threshold; Acquire current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; Determine a current detection result of the current network traffic data based on a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; If it is determined that the current detection result belongs to the preset abnormal network traffic detection result set, a target security defense strategy corresponding to the current detection result is obtained from multiple preset security defense strategies, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data.

2. The method according to claim 1, characterized in that The obtaining of current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy includes: Obtaining the HTTP / HTTPS protocol parsing result, TLS / SSL protocol parsing result, and DNS protocol parsing result in the current network traffic data through the protocol parsing sub-strategy in the traffic analysis strategy, and forming the current protocol parsing data; The behavior identification sub-strategy in the traffic analysis strategy is used to obtain the encrypted data fingerprint abnormality features, large data flow outflow features, malware propagation features and APT attack behavior features in the current network traffic data, and form the current behavior analysis data.

3. The method according to claim 2, characterized in that The obtaining of the HTTP / HTTPS protocol parsing result in the current network traffic data through the protocol parsing sub-strategy includes: Determine, by the protocol parsing sub-strategy, an identification result for a specified browser identifier in a key field of a header of the HTTP / HTTPS protocol in the current network traffic data; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result including a specified browser identifier, the existence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include a specified browser identifier, then the absence of a C2 communication anomaly is used as the HTTP / HTTPS protocol parsing result.

4. The method according to claim 2, characterized in that The method of obtaining the abnormal encrypted data fingerprint features, large data flow outbound features, malware propagation features, and APT attack behavior features in the current network traffic data through the behavior recognition sub-strategy in the traffic analysis strategy includes: Obtaining the JA3 fingerprint in the current network traffic data through the behavior recognition sub-strategy, and using the abnormality detection result of the JA3 fingerprint as the abnormal feature of the encrypted data fingerprint; The total flow, peak flow and number of attack sources in the current network flow data are obtained through the behavior identification sub-strategy, and the features of the large-flow outbound transmission of data are formed; The number of infected hosts, the propagation rate, and the virus type in the current network traffic data are obtained through the behavior recognition sub-strategy, and the malware propagation characteristics are formed; The attack phase, duration and attacker IP address in the current network traffic data are obtained through the behavior identification sub-strategy to form the APT attack behavior characteristics.

5. The method according to claim 1, wherein The determining, based on a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data, a current detection result of the current network traffic data includes: Detecting abnormal protocols in the current protocol parsing data using the network traffic APT detection strategy, and forming a first abnormality detection result with the communication protocol having the abnormality; Detecting abnormal access behavior features in the current behavior analysis data using the network traffic APT detection strategy, and obtaining a second abnormality detection result based on the abnormal access behavior feature composition; The current detection result is composed of the first abnormality detection result and the second abnormality detection result.

6. The method according to claim 1, characterized in that After the step of, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, obtaining a target security defense strategy corresponding to the current detection result from a plurality of preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data, the method further includes: Based on the target security defense strategy, determine the abnormal traffic threat level, malware propagation impact range and APT attack behavior defense recommendation strategy corresponding to the current behavior analysis data in the current network traffic data.

7. The method according to claim 1, characterized in that After the step of, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, obtaining a target security defense strategy corresponding to the current detection result from a plurality of preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data, the method further includes: If a data analysis instruction is detected, the data statistics corresponding to the current network traffic data are obtained and displayed.

8. A network traffic APT detection device, characterized in that: include: A network traffic acquisition unit, configured to acquire current network traffic data in response to a network traffic detection instruction; wherein a collection time of the current network traffic data exceeds a preset collection time threshold; A traffic analysis unit, configured to obtain current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; An APT detection unit, configured to determine a current detection result of the current network traffic data according to a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; A security processing unit is used to obtain a target security defense strategy corresponding to the current detection result from a plurality of preset security defense strategies if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the network traffic APT detection method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions. When the program instructions are executed by a processor, the network traffic APT detection method according to any one of claims 1 to 7 can be implemented.

Citation Information

Patent Citations

  • APT attack detection method, device and system of server and storage medium

    CN114363010A

  • APT attack identification method and device, electronic equipment and medium

    CN115378670A

  • Malicious attack defense method based on Web front-end page

    CN116074093A

  • Data security detection method and device, computer equipment and storage medium

    CN117978435A

  • Advanced persistent threat identification

    US20170070518A1