Encryption protocol reasoning method and system based on graph driving
By constructing semantic graphs and performing multimodal fusion analysis, the problem of identifying unknown encryption protocols was solved, enabling rapid identification and tracing of encryption protocols and improving the accuracy of parsing.
Patent Information
- Application Number
- CN202511350558.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2025-10-28
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies struggle to quickly identify unknown or encrypted protocols, resulting in low accuracy in analytical reasoning and failing to meet the practical needs of modern network attack and defense.
We employ a graph-driven encryption protocol reasoning method. By constructing a semantic graph, we identify protocol field features and communication behavior features. Combined with graph similarity reasoning and multimodal fusion analysis, we identify the behavior categories and reasoning results of encryption protocols.
It improves the accuracy of encryption protocol parsing and reasoning, enables rapid identification and tracing of unknown protocols, breaks through the bottleneck of traditional encrypted traffic being difficult to identify, and has good analogy recognition and self-evolution capabilities.
Smart Images

Figure CN120856473A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of encryption protocol technology, and in particular to a graph-driven encryption protocol reasoning method and system. Background Art
[0002] In today's digital society, cryptographic protocols, as fundamental components of network communication, are directly related to the confidentiality, integrity, and availability of information systems. While standard protocols (such as SSL / TLS, IPSec, and SSH) have been extensively researched and protected against, in scenarios such as APT attacks, malware, and private industrial communication systems, an increasing number of communications rely on unknown or non-standard protocols for information exchange. These protocols are highly proprietary, obfuscated, and even encrypted, often making them impossible to identify and parse using traditional methods.
[0003] Current mainstream network protocol identification technologies mostly rely on known feature libraries (such as protocol signatures, port numbers, and message byte sequences), and are almost powerless against unknown protocols, variant protocols, and encrypted or obfuscated protocols. Meanwhile, protocol reverse engineering still relies on manual methods such as deconstructing fields, comparing message features, and analyzing control flow logic, which is time-consuming and error-prone, failing to meet the practical requirements of "fast identification and fast response" in modern network attack and defense. This results in low accuracy in the parsing and reasoning of encrypted protocols. Summary of the Invention
[0004] The main objective of this invention is to provide a graph-driven encryption protocol reasoning method and system. This addresses the problem that current mainstream network protocol identification technologies largely rely on known feature libraries (such as protocol signatures, port numbers, and message byte sequences), and are largely ineffective for unknown protocols, variant protocols, and encrypted or obfuscated protocols. Meanwhile, protocol reverse engineering still relies on manual methods such as deconstructing fields, comparing message features, and analyzing control flow logic, which are time-consuming and error-prone, failing to meet the practical requirements of "fast identification and fast response" in modern network attack and defense. This results in low accuracy in the parsing and reasoning of encryption protocols.
[0005] To achieve the above objectives, the first aspect of the present invention provides a graph-driven encryption protocol reasoning method, the method comprising: Obtain the protocol traffic data of each encryption protocol and the protocol communication content of each encryption protocol, and construct a semantic graph of each encryption protocol based on the protocol traffic data. Based on the protocol communication content of each encryption protocol, the protocol field features and protocol communication behavior features of each encryption protocol are identified. Based on the semantic graph of each encryption protocol, the protocol behavior category information corresponding to each encryption protocol is identified through a graph similarity reasoning strategy. Based on the protocol field features, protocol communication behavior features, and protocol behavior category information of each encryption protocol, a multimodal fusion analysis strategy is used to identify the ciphertext protocol behavior information of each encryption protocol. Based on the ciphertext protocol behavior information of each encryption protocol, a protocol family migration analysis strategy is used to infer the protocol reasoning results of each encryption protocol.
[0006] Optionally, constructing a semantic graph for each encryption protocol based on the traffic data of each protocol includes: For each protocol traffic data, based on the protocol traffic data, identify the protocol feature data of the encryption protocol; Based on the protocol feature data of the encryption protocol, the entity relationships of the encryption protocol and the field behavior data of the encryption protocol are identified; Based on the entity relationships and field behavior data of the encryption protocol, a semantic graph of the encryption protocol is constructed through a multi-source heterogeneous fusion strategy.
[0007] Optionally, the step of identifying the protocol field characteristics of each encryption protocol and the protocol communication behavior characteristics of each encryption protocol based on the protocol communication content of each encryption protocol includes: For each encryption protocol, based on the protocol communication content of the encryption protocol, the protocol communication behavior information of each encryption protocol is identified, and the behavioral features of each protocol communication behavior information are extracted as the protocol communication behavior features of the encryption protocol. The protocol traffic data of the encryption protocol is processed by field segmentation and identification to obtain each protocol field; The byte entropy feature identification strategy is used to identify the byte entropy feature of each protocol field, and the byte entropy feature of each protocol field is used as the protocol field feature of the encryption protocol.
[0008] Optionally, the step of identifying protocol behavior category information corresponding to each encryption protocol based on the semantic graph of each encryption protocol, through a graph similarity reasoning strategy, includes: Obtain the historical semantic graphs of each historical protocol in the protocol database; For each encryption protocol, based on the historical semantic graph of each historical protocol and the semantic graph of the encryption protocol, a graph similarity matching strategy is used to identify each target historical protocol that the encryption protocol is adapted to. Based on the target historical protocols, the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are identified through protocol analysis strategies. The protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are then used as the protocol behavior category information corresponding to the encryption protocols.
[0009] Optionally, based on the protocol field features of each encryption protocol, the protocol communication behavior features of each encryption protocol, and the protocol behavior category information corresponding to each encryption protocol, the ciphertext protocol behavior information of each encryption protocol is identified through a multimodal fusion analysis strategy, including: For each encryption protocol, based on the protocol communication behavior characteristics of the encryption protocol, the protocol communication interaction mode of the encryption protocol is identified, and based on the protocol behavior category information of the encryption protocol, the protocol risk information of the encryption protocol is identified; Extract the protocol graph structure from the semantic graph of the encryption protocol, and based on the protocol communication interaction mode, the protocol risk information, the protocol graph structure, and the protocol field features, identify the behavior data of each sub-protocol of the encryption protocol through a multimodal fusion analysis strategy; All sub-protocol behavior data are used as ciphertext protocol behavior information of the encryption protocol.
[0010] Optionally, the step of identifying the protocol reasoning result of each encryption protocol by analogy using a protocol family migration analysis strategy based on the ciphertext protocol behavior information of each encryption protocol includes: For each encryption protocol, based on the ciphertext protocol behavior information of the encryption protocol, the corresponding behavioral semantic information of the encryption protocol is identified, and based on the semantic graph of the encryption protocol, the protocol content structure information of the encryption protocol is identified; Based on the behavioral semantic information, the protocol content structure information, and the target historical protocols corresponding to the encryption protocol, the protocol analogy information and protocol evolution information of the encryption protocol are identified through the protocol family migration analysis strategy. The protocol analogy information and the protocol evolution information of the encryption protocol are used as the protocol reasoning results of the encryption protocol.
[0011] Furthermore, to achieve the above objectives, a second aspect of the present invention also provides a graph-driven encryption protocol inference system, the graph-driven encryption protocol inference system comprising: The acquisition module is used to acquire the protocol traffic data of each encryption protocol and the protocol communication content of each encryption protocol, and to construct a semantic graph of each encryption protocol based on the protocol traffic data. The identification module is used to identify the protocol field features and protocol communication behavior features of each encryption protocol based on the protocol communication content of each encryption protocol, and to identify the protocol behavior category information corresponding to each encryption protocol based on the semantic graph of each encryption protocol through a graph similarity reasoning strategy. The analogy module is used to identify the ciphertext protocol behavior information of each encryption protocol based on the protocol field characteristics, protocol communication behavior characteristics, and protocol behavior category information of each encryption protocol through a multimodal fusion analysis strategy. Based on the ciphertext protocol behavior information of each encryption protocol, the module uses a protocol family migration analysis strategy to infer the protocol reasoning result of each encryption protocol.
[0012] Optionally, the acquisition module is specifically used for: For each protocol traffic data, based on the protocol traffic data, identify the protocol feature data of the encryption protocol; Based on the protocol feature data of the encryption protocol, the entity relationships of the encryption protocol and the field behavior data of the encryption protocol are identified; Based on the entity relationships and field behavior data of the encryption protocol, a semantic graph of the encryption protocol is constructed through a multi-source heterogeneous fusion strategy.
[0013] Optionally, the identification module is specifically used for: For each encryption protocol, based on the protocol communication content of the encryption protocol, the protocol communication behavior information of each encryption protocol is identified, and the behavioral features of each protocol communication behavior information are extracted as the protocol communication behavior features of the encryption protocol. The protocol traffic data of the encryption protocol is processed by field segmentation and identification to obtain each protocol field; The byte entropy feature identification strategy is used to identify the byte entropy feature of each protocol field, and the byte entropy feature of each protocol field is used as the protocol field feature of the encryption protocol.
[0014] Optionally, the identification module is specifically used for: Obtain the historical semantic graphs of each historical protocol in the protocol database; For each encryption protocol, based on the historical semantic graph of each historical protocol and the semantic graph of the encryption protocol, a graph similarity matching strategy is used to identify each target historical protocol that the encryption protocol is adapted to. Based on the target historical protocols, the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are identified through protocol analysis strategies. The protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are then used as the protocol behavior category information corresponding to the encryption protocols.
[0015] Optionally, the analogy module is specifically used for: For each encryption protocol, based on the protocol communication behavior characteristics of the encryption protocol, the protocol communication interaction mode of the encryption protocol is identified, and based on the protocol behavior category information of the encryption protocol, the protocol risk information of the encryption protocol is identified; Extract the protocol graph structure from the semantic graph of the encryption protocol, and based on the protocol communication interaction mode, the protocol risk information, the protocol graph structure, and the protocol field features, identify the behavior data of each sub-protocol of the encryption protocol through a multimodal fusion analysis strategy; All sub-protocol behavior data are used as ciphertext protocol behavior information of the encryption protocol.
[0016] Optionally, the analogy module is specifically used for: For each encryption protocol, based on the ciphertext protocol behavior information of the encryption protocol, the corresponding behavioral semantic information of the encryption protocol is identified, and based on the semantic graph of the encryption protocol, the protocol content structure information of the encryption protocol is identified; Based on the behavioral semantic information, the protocol content structure information, and the target historical protocols corresponding to the encryption protocol, the protocol analogy information and protocol evolution information of the encryption protocol are identified through the protocol family migration analysis strategy. The protocol analogy information and the protocol evolution information of the encryption protocol are used as the protocol reasoning results of the encryption protocol.
[0017] Thirdly, this application provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method described in any one of the first aspects.
[0018] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0019] Fifthly, this application provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0020] This invention provides a graph-driven encryption protocol reasoning method and system. The method includes: acquiring protocol traffic data and protocol communication content of each encryption protocol; constructing a semantic graph for each encryption protocol based on the protocol traffic data; identifying protocol field features and protocol communication behavior features of each encryption protocol based on the protocol communication content; identifying protocol behavior category information corresponding to each encryption protocol based on the semantic graph of each encryption protocol using a graph similarity reasoning strategy; identifying ciphertext protocol behavior information of each encryption protocol based on the protocol field features, protocol communication behavior features, and protocol behavior category information of each encryption protocol using a multimodal fusion analysis strategy; and identifying the protocol reasoning result of each encryption protocol by analogy using a protocol family migration analysis strategy based on the ciphertext protocol behavior information. This solution first uses graph similarity matching, path reasoning, and semantic diffusion to classify unknown protocols, identify functional scenarios, and locate potential threat behaviors, providing intelligent support for attack tracing and security protection. Then, by combining the statistical characteristics, interaction patterns, and protocol phase graph structure of encrypted traffic, it identifies encrypted protocol behaviors such as handshake processes, key negotiation, and certificate transmission, breaking through the technical bottleneck of traditional encrypted traffic being "visible but unrecognizable." Finally, it supports comparison and matching of newly discovered protocols with existing graph knowledge, realizing the semantic attribution and structural migration of unknown protocols to known protocols, and possessing good analogical recognition and self-evolution capabilities. This not only improves the comprehensiveness and accuracy of identifying information such as the protocol structure, communication behavior, and protocol actions of encrypted protocols, but also enables effective tracing and deduction of the encrypted protocol, thereby comprehensively improving the accuracy of analytical reasoning about encrypted protocols. Attached Figure Description
[0021] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of a graph-driven encryption protocol reasoning method provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a graph-driven encryption protocol inference system provided in an embodiment of the present invention; Figure 3 An internal structural diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0023] The graph-driven encryption protocol inference method provided in this invention is applied to a graph-driven encryption protocol inference system. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing specific embodiments only and is not intended to limit this application. The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or accompanying drawings of this application are used to distinguish different objects, not to describe a specific order.
[0024] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0026] The graph-driven encryption protocol reasoning method provided in this application can be applied to graph-driven encryption protocol reasoning application environments. This method can be applied to terminals, servers, and systems including both terminals and servers, and is implemented through interaction between the terminals and servers. Terminals can be, but are not limited to, various personal computers, laptops, etc. First, the terminal uses graph similarity matching, path reasoning, and semantic diffusion to classify unknown protocols, identify functional scenarios, and locate potential threat behaviors, providing intelligent support for attack tracing and security protection. Then, combining the statistical characteristics, interaction patterns, and protocol phase graph structure of encrypted traffic, it identifies ciphertext protocol behaviors such as handshake processes, key negotiation, and certificate transmission, overcoming the technical bottleneck of traditional encrypted traffic being "visible but unrecognizable." Finally, it supports comparison and matching of newly discovered protocols with existing graph knowledge, realizing semantic attribution and structural migration from unknown protocols to known protocols, possessing good analogical recognition and self-evolution capabilities. This not only improves the comprehensiveness and accuracy of identifying information such as the protocol structure, communication behavior, and protocol behavior of encryption protocols, but also enables effective tracing and deduction of the encryption protocol, thereby comprehensively improving the accuracy of the analysis and reasoning of encryption protocols.
[0027] In one embodiment, such as Figure 1 As shown, a graph-driven encryption protocol inference method is provided. Taking the application of this method to a terminal as an example, the method includes the following steps: Step S101: Obtain the protocol traffic data and protocol communication content of each encryption protocol, and construct the semantic graph of each encryption protocol based on the protocol traffic data.
[0028] In this embodiment, the terminal acquires the protocol traffic data and protocol communication content of each encryption protocol, and constructs a semantic graph for each encryption protocol based on the protocol traffic data. The protocol traffic data includes encrypted protocol traffic in formats such as pcap, NetFlow, logs, and binary files. The protocol communication content is obtained by collecting communication log information during communication interactions and protocol behavior interactions of the encryption protocol. Then, the terminal constructs the semantic graph of the encryption protocol by performing semantic analysis and entity relationship analysis on the protocol features corresponding to the protocol traffic data. The specific construction process will be explained in detail later.
[0029] Step S102: Based on the protocol communication content of each encryption protocol, identify the protocol field features and protocol communication behavior features of each encryption protocol, and based on the semantic graph of each encryption protocol, identify the protocol behavior category information corresponding to each encryption protocol through a graph similarity reasoning strategy.
[0030] In this embodiment, the terminal identifies the protocol field features and protocol communication behavior features of each encryption protocol based on the protocol communication content of each encryption protocol. Then, based on the semantic graph of each encryption protocol, it identifies the protocol behavior category information corresponding to each encryption protocol through a graph similarity reasoning strategy. This graph similarity reasoning strategy is a graph-driven protocol identification and tracing reasoning mechanism designed by the inventors of this solution, combining graph computing and a graph rule engine. This mechanism can determine the category of unknown protocols, identify functional scenarios, and locate potential threat behaviors through graph similarity matching, path reasoning, and semantic diffusion, providing intelligent support for attack tracing and security protection. The specific reasoning process will be explained in detail later.
[0031] Step S103: Based on the protocol field features of each encryption protocol, the protocol communication behavior features of each encryption protocol, and the protocol behavior category information corresponding to each encryption protocol, the ciphertext protocol behavior information of each encryption protocol is identified through a multimodal fusion analysis strategy. Based on the ciphertext protocol behavior information of each encryption protocol, the protocol reasoning result of each encryption protocol is identified by analogy through a protocol family migration analysis strategy.
[0032] In this embodiment, the terminal identifies the ciphertext protocol behavior information of each encryption protocol based on the protocol field features, protocol communication behavior features, and corresponding protocol behavior category information of each encryption protocol using a multimodal fusion analysis strategy. Based on this ciphertext protocol behavior information, the terminal then uses a protocol family migration analysis strategy to infer the protocol reasoning results of each encryption protocol. This multimodal fusion analysis strategy is a communication protocol unpacking and identification strategy based on a multimodal fusion algorithm. The specific identification process will be explained in detail later. The protocol behavior category information includes information such as category attribution judgment, functional scenario identification, and potential threat behavior location. The ciphertext protocol behavior information includes, but is not limited to, data information of ciphertext protocol behaviors such as handshake processes, key negotiation, and certificate transmission. The specific identification process will be explained in detail later. The protocol family migration analysis strategy uses the "structural similarity reasoning + behavioral semantic mapping" capability of semantic graphs to compare and match the encryption protocol with existing graph knowledge, thereby performing evolutionary and analogical analysis and identification. The specific identification process will be explained in detail later.
[0033] Based on the above scheme, firstly, graph similarity matching, path reasoning, and semantic diffusion are used to classify unknown protocols, identify functional scenarios, and locate potential threat behaviors, providing intelligent support for attack tracing and security protection. Then, by combining the statistical characteristics, interaction patterns, and protocol phase graph structure of encrypted traffic, ciphertext protocol behaviors such as handshake processes, key negotiation, and certificate transmission are identified, overcoming the technical bottleneck of traditional encrypted traffic being "visible but unrecognizable." Finally, it supports comparing and matching newly discovered protocols with existing graph knowledge, realizing the semantic attribution and structural migration of unknown protocols to known protocols, and possessing good analogical recognition and self-evolution capabilities. This not only improves the comprehensiveness and accuracy of identifying information such as the protocol structure, communication behavior, and protocol behavior of encrypted protocols, but also enables effective tracing and deduction of the encrypted protocol, thereby comprehensively improving the accuracy of analytical reasoning about encrypted protocols.
[0034] Optionally, based on the traffic data of each protocol, a semantic graph of each encryption protocol is constructed, including: for each protocol traffic data, identifying the protocol feature data of each encryption protocol based on the protocol traffic data; identifying the entity relationships and field behavior data of the encryption protocol based on the protocol feature data of each encryption protocol; and constructing the semantic graph of the encryption protocol through a multi-source heterogeneous fusion strategy based on the entity relationships and field behavior data of the encryption protocol.
[0035] In this embodiment, for each protocol traffic data, the terminal identifies various protocol feature data of the encryption protocol based on the protocol traffic data. These protocol feature data include static features such as message length, bit entropy, first byte distribution, and content repetition, as well as dynamic features such as inter-packet time interval, sequence direction, and retry mechanism.
[0036] Then, based on the protocol feature data of each encryption protocol, the terminal identifies the entity relationships and field behavior data of the encryption protocol. Among them, the entity relationships are based on the five-element graph modeling framework of "protocol field - message type - communication stage - behavioral logic - encryption semantics".
[0037] Subsequently, based on the entity relationships and field behavior data of the encryption protocol, the terminal constructs a semantic graph of the encryption protocol through a multi-source heterogeneous fusion strategy. This semantic graph is constructed by first filling the initial semantic graph with static protocol features from the protocol data and entity relationships, then adding dynamic features, as well as information such as the reverse engineering results of the encryption protocol, traffic behavior, and field semantics, to the initial semantic graph to obtain the final semantic graph of the encryption protocol.
[0038] Based on the above scheme, an innovative five-element graph modeling framework of "protocol field - message type - communication stage - behavioral logic - encryption semantics" is proposed. By structuring elements such as protocol fields, behaviors, stages, and encryption mechanisms into graphs, an interpretable, evolvable, and reasonable semantic knowledge system is established, realizing a cognitive leap from "raw byte stream" to "semantic graph model".
[0039] Optionally, based on the protocol communication content of each encryption protocol, the protocol field features and protocol communication behavior features of each encryption protocol are identified, including: for each encryption protocol, based on the protocol communication content of the encryption protocol, identifying the protocol communication behavior information of each encryption protocol, and extracting the behavior features of each protocol communication behavior information as the protocol communication behavior features of the encryption protocol; performing field segmentation and identification processing on the protocol traffic data of the encryption protocol to obtain each protocol field; and identifying the byte entropy features of each protocol field through a byte entropy feature identification strategy, and using the byte entropy features of each protocol field as the protocol field features of the encryption protocol.
[0040] In this embodiment, for each encryption protocol, the terminal identifies the communication behavior information of each protocol based on the protocol communication content. The identification process of this communication behavior information can also be achieved by combining the semantic graph of the encryption protocol and performing protocol change deduction processing to obtain the communication behavior information of each protocol.
[0041] Then, the terminal extracts the behavioral features of each protocol communication behavior information as the protocol communication behavior features of the encryption protocol.
[0042] Next, the terminal performs field segmentation and identification processing on the protocol traffic data of the encrypted protocol to obtain the various protocol fields. This field segmentation and identification processing includes message field segmentation and variable-length field segmentation, and the resulting protocol fields are obtained by dividing the protocol traffic data into these traffic fields.
[0043] Finally, the terminal uses a byte entropy feature identification strategy to identify the byte entropy features of each protocol field, and uses these byte entropy features as the protocol field features of the encryption protocol. This byte entropy feature identification strategy involves extracting byte entropy features from each protocol field using a byte histogram feature extraction strategy to obtain the corresponding byte entropy features for each protocol field.
[0044] Based on the above scheme, the protocol communication behavior features of the encryption protocol are extracted by feature extraction, and the byte entropy features of each protocol field are split for identification, which improves the comprehensiveness of the identification of the protocol field features and the protocol communication behavior features of each encryption protocol.
[0045] Optionally, based on the semantic graph of each encryption protocol, a graph similarity reasoning strategy is used to identify the protocol behavior category information corresponding to each encryption protocol. This includes: obtaining the historical semantic graphs of each historical protocol in the protocol database; for each encryption protocol, based on the historical semantic graphs of each historical protocol and the semantic graph of the encryption protocol, using a graph similarity matching strategy to identify each target historical protocol to which the encryption protocol is adapted; and based on each target historical protocol, using a protocol analysis strategy to identify the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocol, and using the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocol as the protocol behavior category information corresponding to the encryption protocol.
[0046] In this embodiment, the terminal acquires the historical semantic graphs of each historical protocol in the protocol database. Then, for each encryption protocol, based on the historical semantic graphs of each historical protocol and the semantic graph of the encryption protocol, the terminal identifies target historical protocols that are compatible with the encryption protocol using a graph similarity matching strategy. This graph similarity matching strategy can use a graph convolutional neural network, combined with graph computation and a graph rule engine, to identify the similarity between the semantic graph and each historical semantic graph, and select historical protocols whose similarity to the historical semantic graph corresponding to a value greater than the maximum similarity preset by the terminal as target historical protocols.
[0047] Based on the historical protocols of each target, the terminal uses a protocol analysis strategy to identify the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocol. The terminal then uses the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocol as the corresponding protocol behavior category information.
[0048] Based on the above scheme, a graph-driven approach is used to identify the protocol attribution information, functional scenario information, and potential threat behavior information of unknown encryption protocols, thereby improving the comprehensiveness of the identification of protocol behavior category information of encryption protocols.
[0049] Optionally, based on the protocol field features, protocol communication behavior features, and protocol behavior category information of each encryption protocol, a multimodal fusion analysis strategy is used to identify the ciphertext protocol behavior information of each encryption protocol. This includes: for each encryption protocol, identifying the protocol communication interaction mode based on the protocol communication behavior features, and identifying the protocol risk information based on the protocol behavior category information; extracting the protocol graph structure from the semantic graph of the encryption protocol, and identifying the behavior data of each sub-protocol of the encryption protocol based on the protocol communication interaction mode, protocol risk information, protocol graph structure, and protocol field features, using a multimodal fusion analysis strategy; and using all sub-protocol behavior data as the ciphertext protocol behavior information of the encryption protocol.
[0050] In this embodiment, for each encryption protocol, the terminal identifies the protocol communication interaction mode based on the protocol communication behavior characteristics of the encryption protocol, and identifies the protocol risk information based on the protocol behavior category information of the encryption protocol. Each communication interaction mode corresponds to one or more protocol communication behavior feature ranges. The terminal identifies the protocol communication interaction mode of the encryption protocol by adapting the feature ranges. The database pre-defines the protocol risk information of each encryption protocol, which corresponds to the protocol affiliation information range, functional scenario information range, and potential threat behavior information range of the encryption protocol. The terminal adapts the protocol risk information corresponding to the protocol behavior category information of the encryption protocol based on the above correspondence in the database.
[0051] The terminal extracts the protocol graph structure from the semantic graph of the encryption protocol, and based on the protocol communication interaction mode, protocol risk information, protocol graph structure, and protocol field features, identifies the behavioral data of each sub-protocol of the encryption protocol through a multimodal fusion analysis strategy. This sub-protocol behavioral data includes, but is not limited to, ciphertext protocol behaviors such as handshake procedures, key negotiation, and certificate transmission.
[0052] Finally, the terminal uses all sub-protocol behavior data as ciphertext protocol behavior information for the encryption protocol.
[0053] Based on the above scheme, by combining the statistical characteristics, interaction patterns and protocol phase graph structure of encrypted traffic, the ciphertext protocol behaviors such as handshake process, key negotiation, and certificate transmission can be identified, breaking through the technical bottleneck of "visible but unrecognizable" traditional encrypted traffic and improving the accuracy of identifying the ciphertext protocol behaviors of encrypted traffic.
[0054] Optionally, based on the ciphertext protocol behavior information of each encryption protocol, the protocol reasoning result of each encryption protocol is identified by analogy using a protocol family migration analysis strategy. This includes: for each encryption protocol, identifying the corresponding behavioral semantic information of the encryption protocol based on the ciphertext protocol behavior information, and identifying the protocol content structure information of the encryption protocol based on the semantic graph of the encryption protocol; based on the behavioral semantic information, the protocol content structure information, and the target historical protocols corresponding to the encryption protocol, identifying the protocol analogy information and the protocol evolution information of the encryption protocol through a protocol family migration analysis strategy; and using the protocol analogy information and the protocol evolution information of the encryption protocol as the protocol reasoning result of the encryption protocol.
[0055] In this embodiment, for each encryption protocol, the terminal identifies the corresponding behavioral semantic information of the encryption protocol based on the encrypted protocol behavior information, and identifies the protocol content structure information of the encryption protocol based on the semantic graph of the encryption protocol.
[0056] Then, based on behavioral semantic information, protocol content structure information, and the corresponding target historical protocols, the terminal uses a protocol family migration analysis strategy to identify the protocol analogy information and protocol evolution information of the encryption protocol. Specifically, the protocol family migration analysis strategy involves performing evolutionary deduction using the semantic graph constructed in this scheme, and then using the historical semantic graphs of each target historical protocol as comparative information for evolutionary deduction. This allows for the evolutionary deduction of the encryption protocol towards each target historical protocol, thereby obtaining the protocol analogy evolution information of the encryption protocol.
[0057] Finally, the terminal uses the protocol analogy information of the encryption protocol as the result of the encryption protocol reasoning.
[0058] Based on the above scheme, by combining the ciphertext protocol behavior information of the encryption protocol, the newly discovered protocol is compared and matched with existing graph knowledge, realizing the semantic attribution and structural migration of the unknown protocol to the known protocol, thereby performing protocol parsing analysis on the encryption protocol and comprehensively improving the accuracy of the parsing and reasoning of the encryption protocol.
[0059] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0060] Based on the same inventive concept, this application also provides a graph-driven encryption protocol inference system for implementing the graph-driven encryption protocol inference method described above. The solution provided by this system is similar to the implementation described in the above method. Therefore, the specific limitations of one or more graph-driven encryption protocol inference system embodiments provided below can be found in the limitations of the graph-driven encryption protocol inference method described above, and will not be repeated here.
[0061] Further reference Figure 2 As a response to the above Figure 1 The implementation of the method shown in this application provides an embodiment of a graph-driven encryption protocol inference system 200. This graph-driven encryption protocol inference system includes an acquisition module 210, an identification module 220, and an analogy module 230, wherein: The acquisition module 210 is used to acquire the protocol traffic data of each encryption protocol and the protocol communication content of each encryption protocol, and to construct a semantic graph of each encryption protocol based on the protocol traffic data. The identification module 220 is used to identify the protocol field features and protocol communication behavior features of each encryption protocol based on the protocol communication content of each encryption protocol, and to identify the protocol behavior category information corresponding to each encryption protocol based on the semantic graph of each encryption protocol through a graph similarity reasoning strategy. The analogy module 230 is used to identify the ciphertext protocol behavior information of each encryption protocol based on the protocol field characteristics of each encryption protocol, the protocol communication behavior characteristics of each encryption protocol, and the protocol behavior category information corresponding to each encryption protocol, through a multimodal fusion analysis strategy, and based on the ciphertext protocol behavior information of each encryption protocol, through a protocol family migration analysis strategy, to infer and identify the protocol reasoning result of each encryption protocol.
[0062] Optionally, the acquisition module 210 is specifically used for: For each protocol traffic data, based on the protocol traffic data, identify the protocol feature data of the encryption protocol; Based on the protocol feature data of the encryption protocol, the entity relationships of the encryption protocol and the field behavior data of the encryption protocol are identified; Based on the entity relationships and field behavior data of the encryption protocol, a semantic graph of the encryption protocol is constructed through a multi-source heterogeneous fusion strategy.
[0063] Optionally, the identification module 220 is specifically used for: For each encryption protocol, based on the protocol communication content of the encryption protocol, the protocol communication behavior information of each encryption protocol is identified, and the behavioral features of each protocol communication behavior information are extracted as the protocol communication behavior features of the encryption protocol. The protocol traffic data of the encryption protocol is processed by field segmentation and identification to obtain each protocol field; The byte entropy feature identification strategy is used to identify the byte entropy feature of each protocol field, and the byte entropy feature of each protocol field is used as the protocol field feature of the encryption protocol.
[0064] Optionally, the identification module 220 is specifically used for: Obtain the historical semantic graphs of each historical protocol in the protocol database; For each encryption protocol, based on the historical semantic graph of each historical protocol and the semantic graph of the encryption protocol, a graph similarity matching strategy is used to identify each target historical protocol that the encryption protocol is adapted to. Based on the target historical protocols, the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are identified through protocol analysis strategies. The protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are then used as the protocol behavior category information corresponding to the encryption protocols.
[0065] Optionally, the analogy module 230 is specifically used for: For each encryption protocol, based on the protocol communication behavior characteristics of the encryption protocol, the protocol communication interaction mode of the encryption protocol is identified, and based on the protocol behavior category information of the encryption protocol, the protocol risk information of the encryption protocol is identified; Extract the protocol graph structure from the semantic graph of the encryption protocol, and based on the protocol communication interaction mode, the protocol risk information, the protocol graph structure, and the protocol field features, identify the behavior data of each sub-protocol of the encryption protocol through a multimodal fusion analysis strategy; All sub-protocol behavior data are used as ciphertext protocol behavior information of the encryption protocol.
[0066] Optionally, the analogy module 230 is specifically used for: For each encryption protocol, based on the ciphertext protocol behavior information of the encryption protocol, the corresponding behavioral semantic information of the encryption protocol is identified, and based on the semantic graph of the encryption protocol, the protocol content structure information of the encryption protocol is identified; Based on the behavioral semantic information, the protocol content structure information, and the target historical protocols corresponding to the encryption protocol, the protocol analogy information and protocol evolution information of the encryption protocol are identified through the protocol family migration analysis strategy. The protocol analogy information and the protocol evolution information of the encryption protocol are used as the protocol reasoning results of the encryption protocol.
[0067] The modules in the graph-driven encryption protocol inference system described above can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.
[0068] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 3As shown, the computer device includes a processor, memory, communication interface, display screen, and input system connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements a graph-driven encryption protocol reasoning method. The display screen can be an LCD screen or an e-ink display. The input system can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0069] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0070] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in any one of the first aspects.
[0071] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0072] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method described in any one of the first aspects.
[0073] It should be noted that the patient information (including but not limited to patient device information, patient personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the patient or fully authorized by all parties.
[0074] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0075] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0076] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A graph-driven encryption protocol reasoning method, characterized in that, The method includes: Obtain the protocol traffic data of each encryption protocol and the protocol communication content of each encryption protocol, and construct a semantic graph of each encryption protocol based on the protocol traffic data. Based on the protocol communication content of each encryption protocol, the protocol field features and protocol communication behavior features of each encryption protocol are identified. Based on the semantic graph of each encryption protocol, the protocol behavior category information corresponding to each encryption protocol is identified through a graph similarity reasoning strategy. Based on the protocol field features, protocol communication behavior features, and protocol behavior category information of each encryption protocol, a multimodal fusion analysis strategy is used to identify the ciphertext protocol behavior information of each encryption protocol. Based on the ciphertext protocol behavior information of each encryption protocol, a protocol family migration analysis strategy is used to infer the protocol reasoning results of each encryption protocol.
2. The method according to claim 1, characterized in that, The construction of a semantic graph for each encryption protocol based on the traffic data of each protocol includes: For each protocol traffic data, based on the protocol traffic data, identify the protocol feature data of the encryption protocol; Based on the protocol feature data of the encryption protocol, the entity relationships of the encryption protocol and the field behavior data of the encryption protocol are identified; Based on the entity relationships and field behavior data of the encryption protocol, a semantic graph of the encryption protocol is constructed through a multi-source heterogeneous fusion strategy.
3. The method according to claim 1, characterized in that, The process of identifying the protocol field characteristics and protocol communication behavior characteristics of each encryption protocol based on the protocol communication content of each encryption protocol includes: For each encryption protocol, based on the protocol communication content of the encryption protocol, the protocol communication behavior information of each encryption protocol is identified, and the behavioral features of each protocol communication behavior information are extracted as the protocol communication behavior features of the encryption protocol. The protocol traffic data of the encryption protocol is processed by field segmentation and identification to obtain each protocol field; The byte entropy feature identification strategy is used to identify the byte entropy feature of each protocol field, and the byte entropy feature of each protocol field is used as the protocol field feature of the encryption protocol.
4. The method according to claim 1, characterized in that, The semantic graph based on each encryption protocol, through a graph similarity reasoning strategy, identifies the protocol behavior category information corresponding to each encryption protocol, including: Obtain the historical semantic graphs of each historical protocol in the protocol database; For each encryption protocol, based on the historical semantic graph of each historical protocol and the semantic graph of the encryption protocol, a graph similarity matching strategy is used to identify each target historical protocol that the encryption protocol is adapted to. Based on the target historical protocols, the protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are identified through protocol analysis strategies. The protocol attribution information, functional scenario information, and potential threat behavior information of the encryption protocols are then used as the protocol behavior category information corresponding to the encryption protocols.
5. The method according to claim 1, characterized in that, Based on the protocol field features of each encryption protocol, the protocol communication behavior features of each encryption protocol, and the protocol behavior category information corresponding to each encryption protocol, a multimodal fusion analysis strategy is used to identify the ciphertext protocol behavior information of each encryption protocol, including: For each encryption protocol, based on the protocol communication behavior characteristics of the encryption protocol, the protocol communication interaction mode of the encryption protocol is identified, and based on the protocol behavior category information of the encryption protocol, the protocol risk information of the encryption protocol is identified; Extract the protocol graph structure from the semantic graph of the encryption protocol, and based on the protocol communication interaction mode, the protocol risk information, the protocol graph structure, and the protocol field features, identify the behavior data of each sub-protocol of the encryption protocol through a multimodal fusion analysis strategy; All sub-protocol behavior data are used as ciphertext protocol behavior information of the encryption protocol.
6. The method according to claim 4, characterized in that, The protocol reasoning results for each encryption protocol, based on the ciphertext protocol behavior information of each encryption protocol, are analogously identified using a protocol family migration analysis strategy, including: For each encryption protocol, based on the ciphertext protocol behavior information of the encryption protocol, the corresponding behavioral semantic information of the encryption protocol is identified, and based on the semantic graph of the encryption protocol, the protocol content structure information of the encryption protocol is identified; Based on the behavioral semantic information, the protocol content structure information, and the target historical protocols corresponding to the encryption protocol, the protocol analogy information and protocol evolution information of the encryption protocol are identified through the protocol family migration analysis strategy. The protocol analogy information and the protocol evolution information of the encryption protocol are used as the protocol reasoning results of the encryption protocol.
7. A graph-driven encryption protocol inference system, characterized in that, The system includes: The acquisition module is used to acquire the protocol traffic data of each encryption protocol and the protocol communication content of each encryption protocol, and to construct a semantic graph of each encryption protocol based on the protocol traffic data. The identification module is used to identify the protocol field features and protocol communication behavior features of each encryption protocol based on the protocol communication content of each encryption protocol, and to identify the protocol behavior category information corresponding to each encryption protocol based on the semantic graph of each encryption protocol through a graph similarity reasoning strategy. The analogy module is used to identify the ciphertext protocol behavior information of each encryption protocol based on the protocol field characteristics, protocol communication behavior characteristics, and protocol behavior category information of each encryption protocol through a multimodal fusion analysis strategy. Based on the ciphertext protocol behavior information of each encryption protocol, the module uses a protocol family migration analysis strategy to infer the protocol reasoning result of each encryption protocol.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Encrypted network abnormal flow detection method based on knowledge graph
CN112788064A
Malicious traffic detection method based on semantic map
CN117375874A
Multi-type encrypted traffic detection method and device
CN117579521A
Network traffic identification method and system for unknown cryptographic protocol
CN120110796A
Malicious encrypted traffic detection method based on cross-modal alignment and graph sequence fusion
CN120639354A