Network traffic APT detection methods, devices, computer equipment and storage media

By collecting long-term network traffic data and combining it with traffic analysis and APT detection strategies, and using multiple classification models for detection, the problem of insufficient detection depth in existing technologies has been solved, achieving more accurate APT detection and security handling.

CN120602222BActive Publication Date: 2025-11-14SHENZHEN CHINA MOTION INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511080746.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-11-14
Estimated Expiration
2045-08-04

AI Technical Summary

Technical Problem

In existing technologies, firewalls and other devices rely on static rule matching and basic protocol analysis to detect APTs in network traffic. However, the detection depth is insufficient, resulting in inaccurate detection results.

Method used

By collecting long-term network traffic data and combining traffic analysis strategies with network traffic APT detection strategies, multiple classification models are used for detection through protocol parsing and behavior analysis to determine the anomaly detection results and execute corresponding security defense strategies.

Benefits of technology

It achieves more accurate APT detection of network traffic, and can promptly identify complex, targeted, and long-term lurking attack behaviors, thus improving the accuracy and effectiveness of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602222B_ABST
    Figure CN120602222B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, computer device, and storage medium for APT detection in network traffic. The method includes: acquiring current network traffic data; acquiring current protocol parsing data and current behavior analysis data of the current network traffic data based on a traffic analysis strategy; determining the current detection result of the current network traffic data according to the network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; if the current detection result is determined to belong to a preset abnormal network traffic type set, then acquiring a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data. This invention can collect current network traffic data over a long period and combine it with a traffic analysis strategy and a network traffic APT detection strategy to perform more accurate network traffic APT detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to methods, apparatus, computer equipment, and storage media for detecting APTs in network traffic. Background Technology

[0002] Network security (also known as cybersecurity) refers to the protection of a network system's hardware, software, and data from accidental or malicious damage, alteration, or disclosure, ensuring continuous, reliable, and uninterrupted network service. Internal networks of various groups (such as large corporations and small to medium-sized enterprises) all have network security needs, making anomaly detection of network traffic particularly important. In addition to short-term, real-time anomaly detection, APT (Advanced Persistent Threat) detection is also necessary. APT detection essentially involves continuous and long-term monitoring of network traffic, enabling the implementation of appropriate protective measures when APT attacks are detected.

[0003] Currently, firewalls and UTM (Unified Threat Management) devices mainly rely on static rule matching and basic protocol analysis to detect APTs in network traffic. However, their detection depth is insufficient, meaning they only check single requests and cannot correlate multi-stage attacks, resulting in inaccurate detection results. Summary of the Invention

[0004] This invention provides a method, apparatus, computer device, and storage medium for APT detection of network traffic, aiming to solve the problem that existing technologies, such as firewalls, mainly rely on static rule matching and basic protocol analysis for APT detection of network traffic, but the detection depth is insufficient, resulting in inaccurate detection results.

[0005] In a first aspect, embodiments of the present invention provide a method for detecting APTs in network traffic, comprising:

[0006] In response to a network traffic detection command, current network traffic data is acquired; wherein the acquisition duration of the current network traffic data exceeds a preset acquisition duration threshold.

[0007] Based on a preset traffic analysis strategy, the current protocol parsing data and current behavior analysis data of the current network traffic data are obtained;

[0008] Based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data, the current detection result of the current network traffic data is determined;

[0009] If it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, then the target security defense strategy corresponding to the current detection result is obtained from multiple preset security defense strategies, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data.

[0010] Secondly, embodiments of the present invention also provide a network traffic APT detection device, which includes:

[0011] A network traffic acquisition unit is used to acquire current network traffic data in response to a network traffic detection command; wherein the acquisition time of the current network traffic data exceeds a preset acquisition time threshold.

[0012] The traffic analysis unit is used to obtain the current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy.

[0013] The APT detection unit is used to determine the current detection result of the current network traffic data based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data.

[0014] The security processing unit is configured to, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, obtain a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

[0015] Thirdly, embodiments of the present invention also provide a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method described in the first aspect above.

[0016] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program, the computer program including program instructions that, when executed by a processor, can implement the method described in the first aspect above.

[0017] This invention provides a method, apparatus, computer device, and storage medium for APT detection in network traffic. The method includes: acquiring current network traffic data in response to a network traffic detection command; acquiring current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy; determining the current detection result of the current network traffic data according to the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; if the current detection result is determined to belong to a preset abnormal network traffic type set, then acquiring a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and executing the target security defense strategy to perform corresponding security processing on the current network traffic data. This invention can collect current network traffic data over a long period of time and combine the traffic analysis strategy and the network traffic APT detection strategy to perform more accurate network traffic APT detection. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a schematic diagram illustrating an application scenario of the network traffic APT detection method provided in this embodiment of the invention.

[0020] Figure 2 A flowchart illustrating the network traffic APT detection method provided in this embodiment of the invention;

[0021] Figure 3 A schematic diagram of a sub-process of the network traffic APT detection method provided in an embodiment of the present invention;

[0022] Figure 4 This is another flowchart illustrating the network traffic APT detection method provided in this embodiment of the invention;

[0023] Figure 5 A schematic block diagram of a network traffic APT detection device provided in an embodiment of the present invention;

[0024] Figure 6 A schematic block diagram of a computer device provided for an embodiment of the present invention. Detailed Implementation

[0025] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0026] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0027] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0028] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0029] Please also refer to Figure 1 and Figure 2 ,in Figure 1 This is a schematic diagram illustrating a scenario of the network traffic APT detection method according to an embodiment of the present invention. Figure 2 This is a flowchart illustrating the network traffic APT detection method provided in an embodiment of the present invention. Figure 1 As shown, the network traffic APT detection method provided in this embodiment of the invention is applied to user terminal 10. User terminal 10 is specifically implemented as a firewall device, gateway, switch, desktop computer, laptop computer, tablet computer, or other computer device, and user terminal 10 is communicatively connected to cloud server 20. Figure 2 As shown, the method includes the following steps S110-S140.

[0030] S110, In response to the network traffic detection command, obtain the current network traffic data.

[0031] Wherein, the collection time of the current network traffic data exceeds the preset collection time threshold.

[0032] In this embodiment, the technical solution is described with the user terminal as the executing entity. More specifically, the technical solution is described using the user terminal as a firewall device, a boundary node, as an example. A network traffic APT detection platform is deployed on the user terminal. After the user registers or logs in to the network traffic APT detection platform with their authorization and consent, they can click the "Start Network Traffic Detection" button on the user interface of the network traffic APT detection platform to begin detecting abnormal network traffic. Updated data can be provided by a cloud server, and the version of the network traffic APT detection platform on the user terminal can be updated periodically or irregularly.

[0033] Because APT attacks are complex, targeted, and long-term insidious, the network traffic detection function of a network traffic APT detection platform can be activated, not just to obtain minute-level traffic data, but to obtain network traffic data from several days or even months to form the current network traffic data, which can then be used as the data to be analyzed. It is important to note that the above network traffic data collection is full traffic collection, not sampled collection. Therefore, the above method achieves automatic collection of network traffic data.

[0034] The current network traffic data includes plaintext traffic data and encrypted traffic data. When the encrypted traffic data is obtained, its TLS handshake metadata (such as JA3 fingerprint, certificate information, etc.) should also be obtained at the same time. TLS stands for Transport Layer Security and represents transport layer security. JA3 is a method for fingerprinting transport layer security applications.

[0035] S120. Based on a preset traffic analysis strategy, obtain the current protocol parsing data and current behavior analysis data of the current network traffic data.

[0036] In this embodiment, a traffic analysis strategy is deployed in the user terminal. This strategy acquires current network traffic data and then parses it using communication protocols to obtain HTTP / HTTPS, TLS / SSL, and DNS resolution results, thus forming the current protocol resolution data. Furthermore, the traffic analysis strategy can also perform behavioral data analysis on the current network traffic data to obtain current behavioral analysis data. Therefore, the traffic analysis strategy can perform traffic analysis at least from the dimensions of communication protocols and traffic data.

[0037] In one embodiment, such as Figure 3 As shown, step S120 includes:

[0038] S121. Obtain the HTTP / HTTPS protocol resolution results, TLS / SSL protocol resolution results, and DNS protocol resolution results from the current network traffic data through the protocol resolution sub-strategy in the traffic analysis strategy, and assemble the current protocol resolution data;

[0039] S122. Obtain the encrypted data fingerprint anomaly features, large data outflow features, malware propagation features, and APT attack behavior features from the current network traffic data through the behavior recognition sub-strategy in the traffic analysis strategy, and compose the current behavior analysis data.

[0040] In this embodiment, when specifically obtaining the HTTP / HTTPS protocol (HTTP stands for Hypertext Transfer Protocol, and HTTPS stands for Hypertext Transfer Protocol Secure) parsing results from the current network traffic data through the protocol parsing sub-policy, the specific steps involve detecting key header fields of the HTTP / HTTPS protocol to determine whether there is an abnormal user agent (user agent represents user agent) in C2 communication and whether there is any data leakage content type. C2 communication, specifically Command and Control Communication, is the command and control channel between the attacker and malicious software (such as Trojans or botnets) implanted in the target system. When obtaining the TLS / SSL protocol (TLS stands for Transport Layer Security, and SSL stands for Secure Sockets Layer) parsing results, the specific steps involve detecting certificate information to determine whether there is certificate expiration. If the certificate information indicates certificate expiration, it is represented by a feature value of 1; otherwise, it is represented by a feature value of 0. Finally, the steps involve obtaining the DNS protocol (DNS stands for Domain Name). When resolving DNS (Domain Name System) results, the specific function is to detect whether a hidden channel exists in the DNS protocol. If a hidden channel exists in the DNS protocol, it is represented by a feature value of 1; if no hidden channel exists in the DNS protocol, it is represented by a feature value of 0.

[0041] By obtaining the encrypted data fingerprint anomaly characteristics, large data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics in the current network traffic data through the protocol parsing sub-policy, it is possible to determine whether there is abnormal APT attack behavior in the current network traffic data from at least the above four feature dimensions.

[0042] In one embodiment, step S121, obtaining the HTTP / HTTPS protocol parsing result from the current network traffic data through the protocol parsing sub-policy, includes:

[0043] The protocol parsing sub-policy determines the identification result of the specified browser identifier in the key header fields of the HTTP / HTTPS protocol in the current network traffic data;

[0044] If the HTTP / HTTPS protocol in the current network traffic data is determined to be an identification result including a specified browser identifier, then the existence of a C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result;

[0045] If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include the specified browser identifier, then the absence of C2 communication anomalies is taken as the HTTP / HTTPS protocol parsing result.

[0046] In this embodiment, when determining whether there is a C2 communication anomaly in the user agent by obtaining the key header fields of the HTTP / HTTPS protocol in the current network traffic data through the protocol parsing sub-policy, it is possible to detect whether the key header fields http.user_agent or https.user_agent of the HTTP / HTTPS protocol include a specified browser identifier (such as Mozilla / 5.0, etc.). Specifically, if it is determined that the HTTP / HTTPS protocol in the current network traffic data includes the specified browser identifier, then the existence of C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result, and represented by the feature value 1; if it is determined that the HTTP / HTTPS protocol in the current network traffic data does not include the specified browser identifier, then the absence of C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result, and represented by the feature value 0.

[0047] In one embodiment, step S122 includes:

[0048] The behavior recognition sub-strategy is used to obtain the JA3 fingerprint in the current network traffic data, and the anomaly detection result of the JA3 fingerprint is used as the anomaly feature of the encrypted data fingerprint.

[0049] The behavior recognition sub-strategy is used to obtain the total traffic, peak traffic, and number of attack sources in the current network traffic data, and to form the large-volume data outflow characteristics.

[0050] The behavior recognition sub-strategy is used to obtain the number of infected hosts, propagation rate, and virus type from the current network traffic data, and to form the malware propagation characteristics.

[0051] The attack phase, duration, and attacker IP address in the current network traffic data are obtained through the behavior recognition sub-strategy, and these are used to form the APT attack behavior characteristics.

[0052] In this embodiment, when specifically obtaining the encrypted data fingerprint abnormal features in the current network traffic data through the behavior recognition sub-strategy, the specific implementation is to detect whether the JA3 fingerprint is abnormal. If the JA3 fingerprint is abnormal, it is represented by feature value 1, and if the JA3 fingerprint is abnormal, it is represented by feature value 0. When acquiring the characteristics of large-volume outflow of data, the specific implementation involves detecting the total traffic of the current network traffic data (e.g., N1GB, where the statistical duration of the total traffic equals the total statistical duration of the current network traffic data, and N1 is a positive number), peak traffic (e.g., in MB / s), and the number of attack sources (obtained by counting the total number of attack sources within the statistical time interval corresponding to the total statistical duration of the current network traffic data). When acquiring the characteristics of malware propagation, the specific implementation involves detecting the number of infected hosts corresponding to the current network traffic data, the propagation rate (obtained by dividing the number of infected hosts by the total statistical duration of the current network traffic data), and the virus type (e.g., ransomware, Trojan, botnet, etc.). When acquiring the characteristics of APT attack behavior, the specific implementation involves detecting the attack stage (e.g., information gathering, information sending, etc.), duration, and attacker IP address corresponding to the current network traffic data. It can be seen that, through the above methods, key information can be obtained from at least these four characteristic dimensions of the current network traffic data, which can then be used to subsequently determine whether the current network traffic data contains abnormal APT attack behavior.

[0053] S130. Based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data, determine the current detection result of the current network traffic data.

[0054] In this embodiment, a network traffic APT detection strategy is pre-deployed in the network traffic APT detection platform of the user terminal. This network traffic APT detection strategy can accurately analyze the current protocol parsing data and current behavior analysis data of the current network traffic data to obtain the current detection result of the current network traffic data.

[0055] In one embodiment, such as Figure 4 As shown, step S130 includes:

[0056] S131. The network traffic APT detection strategy is used to detect abnormal protocols in the current protocol parsing data, and the communication protocols with abnormalities are used to form the first abnormal detection result.

[0057] S132. The abnormal access behavior features in the current behavior analysis data are detected by the network traffic APT detection strategy, and a second abnormal detection result is obtained by combining the abnormal access behavior features.

[0058] S133, The current detection result is composed of the first anomaly detection result and the second anomaly detection result.

[0059] In this embodiment, as a specific implementation of the network traffic APT detection strategy, it is not a static rule, but can employ multiple classification models. The first input data, composed of feature values ​​corresponding to multiple protocol parsing results in the current protocol parsing data, can be input into a first classification model (such as a random forest model) to obtain a first anomaly detection result. For example, the current protocol parsing data includes feature values ​​corresponding to three protocol parsing results, and the first anomaly detection result includes three probability values, each ranging from 0 to 1.

[0060] Alternatively, the second input data, composed of the feature data from the current behavior analysis data, can be input into a second classification model (which can be a different classification model from the first classification model, such as the LightGBM model) to obtain a second anomaly detection result. For example, the current behavior analysis data includes four dimensions of access behavior features, and the second anomaly detection result includes four probability values, all ranging from 0 to 1. Finally, the three probability values ​​from the first anomaly detection result and the four probability values ​​from the second anomaly detection result are concatenated to form a current detection result consisting of seven probability values, all ranging from 0 to 1.

[0061] S140. If it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, then obtain the target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

[0062] In this embodiment, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, it means that the current detection result is the same as one of the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and a security defense strategy needs to be executed in a timely manner. For example, referring to the above example, if the current detection result is a vector consisting of 7 probability values, all ranging from 0 to 1, and the preset abnormal network traffic detection result set also contains a vector consisting of 7 probability values, all ranging from 0 to 1, that is exactly the same as the current detection result, then the security defense strategy corresponding to the abnormal network traffic detection result is used as the target security defense strategy, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data. For example, the target security defense strategy is to block transmission and enhance the boundary protection level.

[0063] If it is determined that the current detection result does not belong to the preset abnormal network traffic detection result set, it means that the current detection result is different from all the abnormal network traffic detection results in the preset abnormal network traffic detection result set. There is no need to execute security defense strategies in a timely manner. At this time, routine network data statistical processing can be performed, such as data statistics and display based on parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable runtime.

[0064] In one embodiment, the method further includes the following after step S140:

[0065] Based on the target security defense strategy, determine the abnormal traffic threat level, malware propagation impact range, and APT attack behavior defense strategy corresponding to the current behavior analysis data in the current network traffic data.

[0066] In this embodiment, when the target security defense strategy is executed to perform corresponding security processing on the current network traffic data, such as the target security defense strategy being the transmission blocking and enhanced boundary protection level as in the example above, the user terminal can further visualize the current behavior analysis data in the current network traffic data. For example, if the current behavior analysis data includes encrypted data fingerprint anomaly characteristics, large-volume data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics, then the large-volume data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics are selected for visualization processing in conjunction with the target security defense strategy. The visualization result corresponding to the large-volume data outflow characteristics is processed as medium risk (i.e., the abnormal traffic threat level is medium risk), the visualization result corresponding to the malware propagation characteristics is processed as medium impact range, and the visualization result corresponding to the APT attack behavior defense recommendation strategy is processed as blocking and enhanced boundary protection level.

[0067] In one embodiment, the method further includes the following after step S140:

[0068] If a data analysis command is detected, the statistical results corresponding to the current network traffic data are obtained and displayed.

[0069] In this embodiment, the user terminal can further collect statistical results on the current network traffic data. These results include parameters such as the number of attack sources, the percentage of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable runtime. These parameters provide a clear and intuitive display of multi-dimensional information corresponding to the current network traffic data.

[0070] As can be seen, the implementation of this method can collect current network traffic data over a long period of time, and then combine traffic analysis strategies and network traffic APT detection strategies to perform more accurate network traffic APT detection.

[0071] Figure 5 This is a schematic block diagram of a network traffic APT detection device provided in an embodiment of the present invention. Figure 5 As shown, corresponding to the above-described network traffic APT detection method, the present invention also provides a network traffic APT detection device 100. This network traffic APT detection device 100 includes a unit for performing the above-described network traffic APT detection method. Please refer to... Figure 5 The network traffic APT detection device 100 includes: a network traffic acquisition unit 110, a traffic analysis unit 120, an APT detection unit 130, and a security processing unit 140.

[0072] The network traffic acquisition unit 110 is used to acquire current network traffic data in response to a network traffic detection command.

[0073] Wherein, the collection time of the current network traffic data exceeds the preset collection time threshold.

[0074] In this embodiment, the technical solution is described with the user terminal as the executing entity. More specifically, the technical solution is described using the user terminal as a firewall device, a boundary node, as an example. A network traffic APT detection platform is deployed on the user terminal. After the user registers or logs in to the network traffic APT detection platform with their authorization and consent, they can click the "Start Network Traffic Detection" button on the user interface of the network traffic APT detection platform to begin detecting abnormal network traffic. Updated data can be provided by a cloud server, and the version of the network traffic APT detection platform on the user terminal can be updated periodically or irregularly.

[0075] Because APT attacks are complex, targeted, and long-term insidious, the network traffic detection function of a network traffic APT detection platform can be activated, not just to obtain minute-level traffic data, but to obtain network traffic data from several days or even months to form the current network traffic data, which can then be used as the data to be analyzed. It is important to note that the above network traffic data collection is full traffic collection, not sampled collection. Therefore, the above method achieves automatic collection of network traffic data.

[0076] The current network traffic data includes plaintext traffic data and encrypted traffic data. When the encrypted traffic data is obtained, its TLS handshake metadata (such as JA3 fingerprint, certificate information, etc.) should also be obtained at the same time. TLS stands for Transport Layer Security and represents transport layer security. JA3 is a method for fingerprinting transport layer security applications.

[0077] The traffic analysis unit 120 is used to obtain the current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy.

[0078] In this embodiment, a traffic analysis strategy is deployed in the user terminal. This strategy acquires current network traffic data and then parses it using communication protocols to obtain HTTP / HTTPS, TLS / SSL, and DNS resolution results, thus forming the current protocol resolution data. Furthermore, the traffic analysis strategy can also perform behavioral data analysis on the current network traffic data to obtain current behavioral analysis data. Therefore, the traffic analysis strategy can perform traffic analysis at least from the dimensions of communication protocols and traffic data.

[0079] In one embodiment, the flow analysis unit 120 is specifically used for:

[0080] The HTTP / HTTPS protocol resolution results, TLS / SSL protocol resolution results, and DNS protocol resolution results in the current network traffic data are obtained through the protocol resolution sub-strategy in the traffic analysis strategy, and then the current protocol resolution data is composed.

[0081] The behavior recognition sub-strategy in the traffic analysis strategy obtains the encrypted data fingerprint anomaly features, large data outflow features, malware propagation features, and APT attack behavior features in the current network traffic data, and assembles them into the current behavior analysis data.

[0082] In this embodiment, when specifically obtaining the HTTP / HTTPS protocol (HTTP stands for Hypertext Transfer Protocol, and HTTPS stands for Hypertext Transfer Protocol Secure) parsing results in the current network traffic data through the protocol parsing sub-policy, the specific steps involve detecting key header fields of the HTTP / HTTPS protocol to determine whether there is an abnormal user agent (user agent represents user agent) in C2 communication and whether there is any data leakage content type. C2 communication, specifically Command and Control Communication, is the command and control channel between the attacker and malicious software (such as Trojans or botnets) implanted in the target system. When obtaining the TLS / SSL protocol (TLS stands for Transport Layer Security, and SSL stands for Secure Sockets Layer) parsing results, the specific steps involve detecting certificate information to determine whether there is certificate expiration. If the certificate information indicates certificate expiration, it is represented by a feature value of 1; otherwise, it is represented by a feature value of 0. Finally, the steps involve obtaining the DNS protocol (DNS stands for Domain Name). When resolving DNS (Domain Name System) results, the specific function is to detect whether a hidden channel exists in the DNS protocol. If a hidden channel exists in the DNS protocol, it is represented by a feature value of 1; if no hidden channel exists in the DNS protocol, it is represented by a feature value of 0.

[0083] By obtaining the encrypted data fingerprint anomaly characteristics, large data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics in the current network traffic data through the protocol parsing sub-policy, it is possible to determine whether there is abnormal APT attack behavior in the current network traffic data from at least the above four feature dimensions.

[0084] In one embodiment, obtaining the HTTP / HTTPS protocol parsing result from the current network traffic data through the protocol parsing sub-policy includes:

[0085] The protocol parsing sub-policy determines the identification result of the specified browser identifier in the key header fields of the HTTP / HTTPS protocol in the current network traffic data;

[0086] If the HTTP / HTTPS protocol in the current network traffic data is determined to be an identification result including a specified browser identifier, then the existence of a C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result;

[0087] If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include the specified browser identifier, then the absence of C2 communication anomalies is taken as the HTTP / HTTPS protocol parsing result.

[0088] In this embodiment, when determining whether there is a C2 communication anomaly in the user agent by obtaining the key header fields of the HTTP / HTTPS protocol in the current network traffic data through the protocol parsing sub-policy, it is possible to detect whether the key header fields http.user_agent or https.user_agent of the HTTP / HTTPS protocol include a specified browser identifier (such as Mozilla / 5.0, etc.). Specifically, if it is determined that the HTTP / HTTPS protocol in the current network traffic data includes the specified browser identifier, then the existence of C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result, and represented by the feature value 1; if it is determined that the HTTP / HTTPS protocol in the current network traffic data does not include the specified browser identifier, then the absence of C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result, and represented by the feature value 0.

[0089] In one embodiment, the flow analysis unit 120 is further specifically used for:

[0090] The behavior recognition sub-strategy is used to obtain the JA3 fingerprint in the current network traffic data, and the anomaly detection result of the JA3 fingerprint is used as the anomaly feature of the encrypted data fingerprint.

[0091] The behavior recognition sub-strategy is used to obtain the total traffic, peak traffic, and number of attack sources in the current network traffic data, and to form the large-volume data outflow characteristics.

[0092] The behavior recognition sub-strategy is used to obtain the number of infected hosts, propagation rate, and virus type from the current network traffic data, and to form the malware propagation characteristics.

[0093] The attack phase, duration, and attacker IP address in the current network traffic data are obtained through the behavior recognition sub-strategy, and these are used to form the APT attack behavior characteristics.

[0094] In this embodiment, when specifically obtaining the encrypted data fingerprint abnormal features in the current network traffic data through the behavior recognition sub-strategy, the specific implementation is to detect whether the JA3 fingerprint is abnormal. If the JA3 fingerprint is abnormal, it is represented by feature value 1, and if the JA3 fingerprint is abnormal, it is represented by feature value 0. When acquiring the characteristics of large-volume outflow of data, the specific implementation involves detecting the total traffic of the current network traffic data (e.g., N1GB, where the statistical duration of the total traffic equals the total statistical duration of the current network traffic data, and N1 is a positive number), peak traffic (e.g., in MB / s), and the number of attack sources (obtained by counting the total number of attack sources within the statistical time interval corresponding to the total statistical duration of the current network traffic data). When acquiring the characteristics of malware propagation, the specific implementation involves detecting the number of infected hosts corresponding to the current network traffic data, the propagation rate (obtained by dividing the number of infected hosts by the total statistical duration of the current network traffic data), and the virus type (e.g., ransomware, Trojan, botnet, etc.). When acquiring the characteristics of APT attack behavior, the specific implementation involves detecting the attack stage (e.g., information gathering, information sending, etc.), duration, and attacker IP address corresponding to the current network traffic data. It can be seen that, through the above methods, key information can be obtained from at least these four characteristic dimensions of the current network traffic data, which can then be used to subsequently determine whether the current network traffic data contains abnormal APT attack behavior.

[0095] The APT detection unit 130 is used to determine the current detection result of the current network traffic data based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data.

[0096] In this embodiment, a network traffic APT detection strategy is pre-deployed in the network traffic APT detection platform of the user terminal. This network traffic APT detection strategy can accurately analyze the current protocol parsing data and current behavior analysis data of the current network traffic data to obtain the current detection result of the current network traffic data.

[0097] In one embodiment, the APT detection unit 130 is specifically used for:

[0098] The network traffic APT detection strategy is used to detect abnormal protocols in the current protocol parsing data, and the communication protocols with abnormalities are used to form the first abnormal detection result.

[0099] The network traffic APT detection strategy is used to detect abnormal access behavior features in the current behavior analysis data, and the abnormal access behavior features are used to form a second anomaly detection result.

[0100] The current detection result is composed of the first anomaly detection result and the second anomaly detection result.

[0101] In this embodiment, as a specific implementation of the network traffic APT detection strategy, it is not a static rule, but can employ multiple classification models. The first input data, composed of feature values ​​corresponding to multiple protocol parsing results in the current protocol parsing data, can be input into a first classification model (such as a random forest model) to obtain a first anomaly detection result. For example, the current protocol parsing data includes feature values ​​corresponding to three protocol parsing results, and the first anomaly detection result includes three probability values, each ranging from 0 to 1.

[0102] Alternatively, the second input data, composed of the feature data from the current behavior analysis data, can be input into a second classification model (which can be a different classification model from the first classification model, such as the LightGBM model) to obtain a second anomaly detection result. For example, the current behavior analysis data includes four dimensions of access behavior features, and the second anomaly detection result includes four probability values, all ranging from 0 to 1. Finally, the three probability values ​​from the first anomaly detection result and the four probability values ​​from the second anomaly detection result are concatenated to form a current detection result consisting of seven probability values, all ranging from 0 to 1.

[0103] The security processing unit 140 is configured to, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, obtain a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data.

[0104] In this embodiment, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, it means that the current detection result is the same as one of the abnormal network traffic detection results in the preset abnormal network traffic detection result set, and a security defense strategy needs to be executed in a timely manner. For example, referring to the above example, if the current detection result is a vector consisting of 7 probability values, all ranging from 0 to 1, and the preset abnormal network traffic detection result set also contains a vector consisting of 7 probability values, all ranging from 0 to 1, that is exactly the same as the current detection result, then the security defense strategy corresponding to the abnormal network traffic detection result is used as the target security defense strategy, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data. For example, the target security defense strategy is to block transmission and enhance the boundary protection level.

[0105] If it is determined that the current detection result does not belong to the preset abnormal network traffic detection result set, it means that the current detection result is different from all the abnormal network traffic detection results in the preset abnormal network traffic detection result set. There is no need to execute security defense strategies in a timely manner. At this time, routine network data statistical processing can be performed, such as data statistics and display based on parameters such as the number of attack sources, the proportion of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable runtime.

[0106] In one embodiment, the network traffic APT detection device 100 further includes:

[0107] The visualization result acquisition unit is used to determine the abnormal traffic threat level, malware propagation impact range, and APT attack behavior defense recommendation strategy corresponding to the current behavior analysis data in the current network traffic data based on the target security defense strategy.

[0108] In this embodiment, when the target security defense strategy is executed to perform corresponding security processing on the current network traffic data, such as the target security defense strategy being the transmission blocking and enhanced boundary protection level as in the example above, the user terminal can further visualize the current behavior analysis data in the current network traffic data. For example, if the current behavior analysis data includes encrypted data fingerprint anomaly characteristics, large-volume data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics, then the large-volume data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics are selected for visualization processing in conjunction with the target security defense strategy. The visualization result corresponding to the large-volume data outflow characteristics is processed as medium risk (i.e., the abnormal traffic threat level is medium risk), the visualization result corresponding to the malware propagation characteristics is processed as medium impact range, and the visualization result corresponding to the APT attack behavior defense recommendation strategy is processed as blocking and enhanced boundary protection level.

[0109] In one embodiment, the network traffic APT detection device 100 further includes:

[0110] The network data statistics unit is used to obtain and display the data statistics results corresponding to the current network traffic data if a data analysis command is detected.

[0111] In this embodiment, the user terminal can further collect statistical results on the current network traffic data. These results include parameters such as the number of attack sources, the percentage of abnormal traffic, the number of alarms triggered today, the type of malicious code, the protection success rate, the number of user behavior records, and the system's stable runtime. These parameters provide a clear and intuitive display of multi-dimensional information corresponding to the current network traffic data.

[0112] It is evident that embodiments implementing this device can collect current network traffic data over a long period of time, and then combine traffic analysis strategies and network traffic APT detection strategies to perform more accurate network traffic APT detection.

[0113] The aforementioned network traffic APT detection device can be implemented as a computer program, which can, for example... Figure 6 It runs on the computer device shown.

[0114] Please see Figure 6 , Figure 6 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. This computer device integrates any of the network traffic APT detection devices provided in the embodiments of the present invention.

[0115] See Figure 6 The computer device 400 includes a processor 402, a memory, and a network interface 405 connected via a system bus 401. The memory may include a storage medium 403 and internal memory 404.

[0116] The storage medium 403 may store an operating system 4031 and a computer program 4032. The computer program 4032 includes program instructions that, when executed, cause the processor 402 to perform a network traffic APT detection method.

[0117] The processor 402 provides computing and control capabilities to support the operation of the entire computer device.

[0118] The internal memory 404 provides an environment for the computer program 4032 in the storage medium 403 to run. When the computer program 4032 is executed by the processor 402, the processor 402 can perform the above-described network traffic APT detection method.

[0119] This network interface 405 is used for network communication with other devices. Those skilled in the art will understand that... Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the computer device to which the present invention is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0120] The processor 402 is used to run the computer program 4032 stored in the memory to implement the above-described network traffic APT detection method.

[0121] It should be understood that, in this embodiment of the invention, the processor 402 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0122] It will be understood by those skilled in the art that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program includes program instructions and can be stored in a storage medium, which is a computer-readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the embodiments of the above methods.

[0123] Therefore, the present invention also provides a computer-readable storage medium. This computer-readable storage medium stores a computer program, wherein the computer program includes program instructions. When executed by a processor, the program instructions cause the processor to perform the aforementioned network traffic APT detection method.

[0124] The storage medium can be any computer-readable storage medium that can store program code, such as a USB flash drive, external hard drive, read-only memory (ROM), magnetic disk, or optical disk.

[0125] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0126] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of each unit is merely a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0127] The steps in the method of this invention can be adjusted, merged, or reduced in order according to actual needs. The units in the device of this invention can be merged, divided, or reduced according to actual needs. Furthermore, the functional units in the various embodiments of this invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0128] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0129] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for detecting APTs in network traffic, characterized in that, include: In response to a network traffic detection command, current network traffic data is acquired; wherein the acquisition time of the current network traffic data exceeds a preset acquisition time threshold; the current network traffic data includes plaintext traffic data and encrypted traffic data, the encrypted traffic data also includes TLS handshake metadata, and the TLS handshake metadata includes at least JA3 fingerprint and certificate information; Based on a preset traffic analysis strategy, the current protocol parsing data and current behavior analysis data of the current network traffic data are obtained; Based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data, the current detection result of the current network traffic data is determined; the network traffic APT detection strategy includes multiple classification models; If it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, then the target security defense strategy corresponding to the current detection result is obtained from multiple preset security defense strategies, and the target security defense strategy is executed to perform corresponding security processing on the current network traffic data. The method of acquiring current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy includes: The HTTP / HTTPS protocol resolution results, TLS / SSL protocol resolution results, and DNS protocol resolution results in the current network traffic data are obtained through the protocol resolution sub-strategy in the traffic analysis strategy, and then the current protocol resolution data is composed. The behavior recognition sub-strategy in the traffic analysis strategy obtains the encrypted data fingerprint anomaly features, large data outflow features, malware propagation features, and APT attack behavior features in the current network traffic data, and assembles them into the current behavior analysis data.

2. The method according to claim 1, characterized in that, The step of obtaining the HTTP / HTTPS protocol parsing result from the current network traffic data through the protocol parsing sub-policy includes: The protocol parsing sub-policy determines the identification result for the specified browser identifier in the key header fields of the HTTP / HTTPS protocol in the current network traffic data; If the HTTP / HTTPS protocol in the current network traffic data is determined to be an identification result including a specified browser identifier, then the existence of a C2 communication anomaly is taken as the HTTP / HTTPS protocol parsing result; If it is determined that the HTTP / HTTPS protocol in the current network traffic data is an identification result that does not include the specified browser identifier, then the absence of C2 communication anomalies is taken as the HTTP / HTTPS protocol parsing result.

3. The method according to claim 1, characterized in that, The step of obtaining the encrypted data fingerprint anomaly characteristics, large-volume data outflow characteristics, malware propagation characteristics, and APT attack behavior characteristics from the current network traffic data through the behavior recognition sub-strategy in the traffic analysis strategy includes: The behavior recognition sub-strategy is used to obtain the JA3 fingerprint in the current network traffic data, and the anomaly detection result of the JA3 fingerprint is used as the anomaly feature of the encrypted data fingerprint. The behavior recognition sub-strategy is used to obtain the total traffic, peak traffic, and number of attack sources in the current network traffic data, and to form the large-volume data outflow characteristics. The behavior recognition sub-strategy is used to obtain the number of infected hosts, propagation rate, and virus type from the current network traffic data, and to form the malware propagation characteristics. The attack phase, duration, and attacker IP address in the current network traffic data are obtained through the behavior recognition sub-strategy, and these are used to form the APT attack behavior characteristics.

4. The method according to claim 1, characterized in that, The step of determining the current detection result of the current network traffic data based on the preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data includes: The network traffic APT detection strategy is used to detect abnormal protocols in the current protocol parsing data, and the communication protocols with abnormalities are used to form the first abnormal detection result. The network traffic APT detection strategy is used to detect abnormal access behavior features in the current behavior analysis data, and the abnormal access behavior features are used to form a second anomaly detection result. The current detection result is composed of the first anomaly detection result and the second anomaly detection result.

5. The method according to claim 1, characterized in that, After the step of determining that the current detection result belongs to a preset abnormal network traffic detection result set, obtaining a target security defense policy corresponding to the current detection result from multiple preset security defense policies, and executing the target security defense policy to perform corresponding security processing on the current network traffic data, the method further includes: Based on the target security defense strategy, determine the abnormal traffic threat level, malware propagation impact range, and APT attack behavior defense strategy corresponding to the current behavior analysis data in the current network traffic data.

6. The method according to claim 1, characterized in that, After the step of determining that the current detection result belongs to a preset abnormal network traffic detection result set, obtaining a target security defense policy corresponding to the current detection result from multiple preset security defense policies, and executing the target security defense policy to perform corresponding security processing on the current network traffic data, the method further includes: If a data analysis command is detected, the statistical results corresponding to the current network traffic data are obtained and displayed.

7. A network traffic APT detection device, characterized in that, include: A network traffic acquisition unit is used to acquire current network traffic data in response to a network traffic detection command; wherein the acquisition time of the current network traffic data exceeds a preset acquisition time threshold; the current network traffic data includes plaintext traffic data and encrypted traffic data, the encrypted traffic data also includes TLS handshake metadata, and the TLS handshake metadata includes at least JA3 fingerprint and certificate information; The traffic analysis unit is used to obtain the current protocol parsing data and current behavior analysis data of the current network traffic data based on a preset traffic analysis strategy. The APT detection unit is used to determine the current detection result of the current network traffic data based on a preset network traffic APT detection strategy, the current protocol parsing data, and the current behavior analysis data; the network traffic APT detection strategy includes multiple classification models; The security processing unit is configured to, if it is determined that the current detection result belongs to a preset abnormal network traffic detection result set, obtain a target security defense strategy corresponding to the current detection result from multiple preset security defense strategies, and execute the target security defense strategy to perform corresponding security processing on the current network traffic data. The flow analysis unit is specifically used for: The HTTP / HTTPS protocol resolution results, TLS / SSL protocol resolution results, and DNS protocol resolution results in the current network traffic data are obtained through the protocol resolution sub-strategy in the traffic analysis strategy, and then the current protocol resolution data is composed. The behavior recognition sub-strategy in the traffic analysis strategy obtains the encrypted data fingerprint anomaly features, large data outflow features, malware propagation features, and APT attack behavior features in the current network traffic data, and assembles them into the current behavior analysis data.

8. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the network traffic APT detection method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions, which, when executed by a processor, can implement the network traffic APT detection method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • APT attack identification method and device, electronic equipment and medium

    CN115378670A

  • Malicious attack defense method based on Web front-end page

    CN116074093A