Abnormal traffic monitoring method and system based on security gateway

By using JA3 hash fingerprinting for three-level cache matching and a personalized layer design of the Transformer model, the detection accuracy and resource limitations of traditional firewalls under a multi-active architecture are solved, achieving efficient and accurate abnormal traffic monitoring.

CN120915543APending Publication Date: 2025-11-07BEIJING HUITONG JINCAI INFORMATION TECH +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511132998.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-13
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Traditional centralized web application firewalls struggle to dynamically adapt to regional differences in traffic across data centers in a multi-active architecture, leading to decreased accuracy in detecting cross-regional attacks. Furthermore, they are limited by hardware resources and cannot support the operation of large-scale detection models, resulting in insufficient timeliness in fault response.

Method used

A three-level cache matching mechanism based on JA3 hash fingerprinting is used in conjunction with eBPF technology to capture TLS handshake features. An abnormal traffic identification model based on Transformer is used, which includes a common layer that shares global attack features and a personalized layer that adapts to regional traffic differences. The number of personalized layers is dynamically adjusted to improve detection accuracy and efficiency.

Benefits of technology

It enables rapid identification of known fingerprints, improves traffic processing efficiency, reduces computing resource consumption, balances global attack feature sharing and regional difference adaptation, meets compliance requirements for cross-border data transmission, and balances detection performance and resource costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915543A_ABST
    Figure CN120915543A_ABST
Patent Text Reader

Abstract

The invention discloses an abnormal traffic monitoring method and system based on a security gateway, and the method comprises the steps: obtaining a TLS handshake feature in a traffic request in response to the traffic request of a target user, and carrying out the Hash calculation of the TLS handshake feature, and obtaining a JA3 Hash fingerprint; performing three-level cache matching on the JA3 hash fingerprints in sequence, and extracting fingerprint tags of the JA3 hash fingerprints which are not matched in three-level cache; performing feature extraction on the traffic data corresponding to the fingerprint tag to obtain traffic features; and inputting the traffic characteristics into a pre-trained abnormal traffic identification model based on Transform to obtain an abnormal traffic identification result. According to the method provided by the invention, the detection precision of the abnormal traffic is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of traffic monitoring, in particular to an abnormal traffic monitoring method and system based on a security gateway. BACKGROUND

[0002] In today's digital era, multi-active architecture has become a key architecture to ensure the stable operation of core business because it can achieve load balancing and rapid disaster recovery by simultaneously carrying business traffic through multiple data centers. As a core component for resisting external attacks and ensuring data transmission security, the performance of the security gateway directly affects the security and reliability of the system.

[0003] However, in the prior art, the traditional centralized Web application firewall uses a single detection model, which is difficult to dynamically adapt to the regional differences of traffic in each data center under the multi-active architecture, resulting in a significant decrease in cross-regional attack detection accuracy. Moreover, due to the limitation of gateway device hardware resources, it is difficult to support the operation of large detection models, and the fault response mechanism has a time effectiveness defect, with obvious lag in responding to new attacks. SUMMARY

[0004] The present application provides an abnormal traffic monitoring method and system based on a security gateway to solve the technical problem of how to monitor existing abnormal traffic, achieving the effect of improving traffic monitoring efficiency.

[0005] To solve the above technical problems, the present application provides an abnormal traffic monitoring method based on a security gateway, comprising:

[0006] In response to a traffic request of a target user, the TLS handshake feature in the traffic request is obtained, and a JA3 hash fingerprint is obtained by performing hash calculation on the TLS handshake feature;

[0007] The JA3 hash fingerprint is sequentially matched with three levels of cache, and the fingerprint tag of the JA3 hash fingerprint that is not matched with the three levels of cache is extracted;

[0008] The traffic data corresponding to the fingerprint tag is feature-extracted to obtain traffic features;

[0009] The traffic features are input into a pre-trained abnormal traffic recognition model based on Transformer to obtain an abnormal traffic recognition result, wherein the abnormal traffic recognition model comprises a public layer sharing global attack features and a personalized layer adapting to regional traffic differences.

[0010] As one of the preferred solutions, the JA3 hash fingerprint is obtained by obtaining the TLS handshake feature in the traffic request and performing hash calculation on the TLS handshake feature, comprising:

[0011] Capture a ClientHello message in a TLS handshake process based on an eBPF technology, and extract a TLS handshake feature in the ClientHello message;

[0012] Hash calculate the TLS handshake feature according to a CRC32 optimization algorithm to generate a JA3 hash fingerprint.

[0013] As one of the preferred solutions, the JA3 hash fingerprint is sequentially matched with three levels of cache, including:

[0014] The JA3 hash fingerprint is sequentially matched with L1 cache, L2 cache and L3 cache, and when a certain level of cache is matched, subsequent cache query is stopped and the label information corresponding to the JA3 hash fingerprint is obtained.

[0015] Among them, the L1 cache is an eBPF map used to store high-frequency fingerprints, the L2 cache is a Memcached used to store medium-frequency fingerprints, and the L3 cache is a distributed Redis used to store a global fingerprint library.

[0016] As one of the preferred solutions, the traffic data corresponding to the fingerprint label is extracted to obtain traffic features, including:

[0017] The packet size and timing statistics of the traffic data are extracted as basic features.

[0018] The basic features are standardized to obtain standardized features, and the standardized features are linearly projected to obtain projected features.

[0019] The projected features are added with position encoding to obtain traffic features.

[0020] As one of the preferred solutions, the number of layers of the personalized layer is determined by a dynamic adjustment mechanism, and the dynamic adjustment mechanism includes:

[0021] Calculate a global error rate, which includes a first error rate of the public layer parameters and the personalized layer parameters of the federation center cloud on a local test set.

[0022] Calculate a personalized error rate, which includes a second error rate of the public layer parameters and the personalized layer parameters of the local gateway on the local test set.

[0023] Adjust the number of layers of the personalized layer based on a weighted sum minimization target of the global error rate and the personalized error rate, wherein the sum of the weight of the global error rate and the weight of the personalized error rate is 1.

[0024] Another embodiment of the application provides a security gateway-based abnormal traffic monitoring system, comprising:

[0025] An acquisition module is configured to acquire a TLS handshake feature in a traffic request of a target user in response to the traffic request, and perform hash calculation on the TLS handshake feature to obtain a JA3 hash fingerprint;

[0026] A matching module is configured to sequentially perform three-level cache matching on the JA3 hash fingerprint, and extract a fingerprint tag of the JA3 hash fingerprint that is not matched in the three-level cache;

[0027] An extraction module is configured to perform feature extraction on traffic data corresponding to the fingerprint tag to obtain traffic features;

[0028] An identification module is configured to input the traffic features into a pre-trained abnormal traffic identification model based on a Transformer to obtain an abnormal traffic identification result, wherein the abnormal traffic identification model comprises a public layer sharing global attack features and a personalized layer adapting to regional traffic differences.

[0029] As one of the preferred solutions, the acquisition module is specifically configured to:

[0030] Capture a ClientHello message in a TLS handshake process based on an eBPF technology, and extract a TLS handshake feature in the ClientHello message;

[0031] Perform hash calculation on the TLS handshake feature based on a CRC32 optimization algorithm to generate a JA3 hash fingerprint.

[0032] As one of the preferred solutions, the matching module is specifically configured to:

[0033] Match and query the JA3 hash fingerprint in the order of an L1 cache, an L2 cache and an L3 cache, stop subsequent cache query and acquire tag information corresponding to the JA3 hash fingerprint when a certain level of cache matching hits;

[0034] The L1 cache is an eBPF map configured to store high-frequency fingerprints, the L2 cache is a Memcached configured to store medium-frequency fingerprints, and the L3 cache is a distributed Redis configured to store a global fingerprint library.

[0035] As one of the preferred solutions, the extraction module is specifically configured to:

[0036] Extract packet size and timing statistics of traffic data as basic features;

[0037] The base features are standardized to obtain standardized features, and the standardized features are linearly projected to obtain projected features;

[0038] The projected features are added with position coding to obtain traffic features.

[0039] As one of the preferred solutions, the number of layers of the personalized layer is determined by a dynamic adjustment mechanism, and the dynamic adjustment mechanism comprises:

[0040] A global error rate is calculated, and the global error rate comprises a first error rate of the public layer parameters and the personalized layer parameters of the federal collaborative center cloud on a local test set;

[0041] A personalized error rate is calculated, and the personalized error rate comprises a second error rate of the public layer parameters and the personalized layer parameters of the local gateway on the local test set;

[0042] The number of layers of the personalized layer is adjusted based on a weighted sum minimization target of the global error rate and the personalized error rate, wherein the sum of the weight of the global error rate and the weight of the personalized error rate is 1.

[0043] Compared with the prior art, the beneficial effects of the embodiments of the present application are at least one of the following:

[0044] 1) The three-level cache matching mechanism of the JA3 hash fingerprint can quickly identify known fingerprints, greatly improving the traffic processing efficiency. The hierarchical design of L1 to L3 cache combined with high hit rate can reduce invalid detection operations, and the TLS handshake feature capture based on eBPF technology and the hash calculation of CRC32 optimization algorithm ensure the efficiency and accuracy of fingerprint generation, effectively solving the problems of traffic scheduling lag and slow identification response in traditional solutions.

[0045] 2) At the same time, the abnormal traffic identification model based on the Transformer of the present application considers the sharing of global attack features and the adaptation of regional traffic differences through the design of the public layer and the personalized layer, and cooperates with the dynamically adjusted number of personalized layers to improve the accuracy of abnormal traffic detection. And this model only needs to process the traffic data that is not matched in the three-level cache, reduces the consumption of computing resources of the edge node, and also meets the compliance requirements of cross-border data transmission by avoiding the transmission of raw data, balances the detection efficiency and resource cost. BRIEF DESCRIPTION OF DRAWINGS

[0046] Figure 1 is a flowchart of an abnormal traffic monitoring method based on a security gateway in one of the embodiments of the present application;

[0047] Figure 2is a schematic diagram of a Transformer-based abnormal traffic identification model in an embodiment of the present application;

[0048] Figure 3 is a flow chart of traffic scheduling based on JA3 fingerprints in an embodiment of the present application;

[0049] Figure 4 is a schematic diagram of an abnormal traffic monitoring system based on a security gateway in an embodiment of the present application;

[0050] Figure 5 is a general architecture diagram of an abnormal traffic monitoring system in an embodiment of the present application. DETAILED DESCRIPTION

[0051] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. The purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0052] In the description of the present application, the terms "first", "second", "third", etc. are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second", "third", etc. can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0053] In the description of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connecting" should be understood in a broad sense, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium, or it can be the communication inside two elements. The terms "vertical", "horizontal", "left", "right", "up", "down" and similar expressions used in this paper are only for the purpose of description, and cannot be understood as indicating or implying that the devices or elements referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present application. The term "and / or" used in this paper includes any and all combinations of one or more related listed items. For those of ordinary skill in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0054] In the description of the present application, it is necessary to explain that, unless otherwise defined, all technical and scientific terms used in the present application are the same as the meanings commonly understood by the persons skilled in the art. The terms used in the specification of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. The above terms can be understood in the specific meaning in the present application by the person skilled in the art.

[0055] An embodiment of the present application provides a security gateway-based abnormal traffic monitoring method, and specifically, please refer to Figure 1 , Figure 1 A flowchart of the security gateway-based abnormal traffic monitoring method in one embodiment of the present application is shown, which includes steps S1-S4:

[0056] S1: In response to a traffic request of a target user, acquiring a TLS handshake feature in the traffic request, and performing hash calculation on the TLS handshake feature to obtain a JA3 hash fingerprint;

[0057] Preferably, in one embodiment of the present application, the acquiring of the TLS handshake feature in the traffic request and the hash calculation on the TLS handshake feature to obtain the JA3 hash fingerprint comprises:

[0058] Capturing a ClientHello message in a TLS handshake process based on an eBPF technology, and extracting a TLS handshake feature in the ClientHello message;

[0059] According to a CRC32 optimization algorithm, performing hash calculation on the TLS handshake feature to generate a JA3 hash fingerprint.

[0060] In the present application, the process of acquiring the TLS handshake feature and generating the JA3 hash fingerprint is realized by relying on efficient technical means, which is as follows:

[0061] Firstly, the TLS handshake feature is captured based on the eBPF technology. When the traffic request of the target user arrives at a GTM (Global Traffic Manager) edge node and initiates an HTTPS connection, a "ClientHello" message containing parameters such as encryption suite and extension list will be sent in the TLS handshake stage. At this time, the system directly captures the "ClientHello" data packet in the operating system kernel layer through the eBPF technology. This process does not need to copy data to the user end, can be completed within 0.01 ms, and will not interrupt the normal connection process, and the TLS handshake feature is extracted efficiently.

[0062] Subsequently, the JA3 hash fingerprint is generated by using the CRC32 optimization algorithm. After the scheduling engine receives the original "ClientHello" packet, the JA3 hash fingerprint is calculated based on the extracted TLS handshake features and the optimized CRC32 algorithm. The calculation process generates a JA3 fingerprint string in the form of "769,47-53-5-10-49161,23-24-25,0", and then obtains a 256-bit hash digest, i.e., the JA3 hash fingerprint. The fingerprint serves as a unique identifier for the traffic, providing accurate basis for subsequent cache matching and traffic scheduling.

[0063] This technical solution not only ensures the efficiency and real-time performance of TLS handshake feature capture, but also ensures the accuracy and uniqueness of JA3 hash fingerprint generation through the optimized hash algorithm, laying a reliable foundation for subsequent abnormal traffic monitoring, and meeting the dual requirements of processing speed and accuracy under multi-live architecture.

[0064] S2: sequentially performing three-level cache matching on the JA3 hash fingerprint, and extracting the fingerprint label of the JA3 hash fingerprint that does not match any of the three levels of cache;

[0065] Preferably, in an embodiment of the present application, the three-level cache matching of the JA3 hash fingerprint comprises:

[0066] The JA3 hash fingerprint is sequentially matched and queried in the order of L1 cache, L2 cache and L3 cache. When a certain level of cache matching hits, the subsequent cache query is stopped and the label information corresponding to the JA3 hash fingerprint is obtained.

[0067] The L1 cache is an eBPF map for storing high-frequency fingerprints, the L2 cache is a Memcached for storing medium-frequency fingerprints, and the L3 cache is a distributed Redis for storing a global fingerprint library.

[0068] In this embodiment, when the JA3 hash fingerprint is matched in three levels of cache, the matching query is sequentially performed in the order of L1 cache→L2 cache→L3 cache, forming an efficient and hierarchical fingerprint identification mechanism. The specific process is described as follows.

[0069] L1 Cache (eBPF Mapping) Matching: The L1 cache uses eBPF technology to build a kernel-level mapping table, specifically storing 10,000 frequently occurring JA3 hash fingerprints. When a JA3 hash fingerprint is generated, a matching query is first performed in the L1 cache. Because eBPF runs at the operating system kernel level, there is no need to copy data between user space and kernel space, resulting in extremely low latency (<0.01ms) and a hit rate of up to 60%. If a match is found in this cache level, the corresponding tag information (such as "normal traffic," "attack fingerprint," "blacklist fingerprint," etc.) is directly retrieved, and subsequent cache queries cease.

[0070] L2 Cache (Memcached) Matching: If the L1 cache misses, the system automatically queries the L2 cache. The L2 cache uses Memcached as a shared memory cache to store 100,000 frequently occurring JA3 hash fingerprints, with a hit rate of approximately 35%. Memcached's memory-level storage ensures fast query response speeds and can quickly determine whether a fingerprint exists in the mid-frequency database. Once a match is found, the tag information is immediately retrieved and the subsequent process terminates.

[0071] L3 Cache (Distributed Redis) Matching: When both L1 and L2 caches are not matched, the system further queries the L3 cache. The L3 cache is a distributed Redis cluster that stores a global fingerprint database, covering low-frequency and historically occurring JA3 hash fingerprints, with a hit rate of approximately 4.2%. Redis's distributed architecture supports large-scale fingerprint storage and fast retrieval, covering a wider range of fingerprints. If a match is found at this level, the corresponding tag information is also retrieved; if a match is still not found, it is determined that "none of the three caches match".

[0072] For JA3 hash fingerprints that do not match in all three levels of cache, the system initiates a query to the federated coordination center via the gRPC protocol. The center returns the fingerprint's tag (e.g., "first appearance fingerprint") and TTL (Time to Live) value, and simultaneously writes the results to the local cache (updated in the order of L3→L2→L1, dynamically adjusting the cache content), providing a foundation for fast response to subsequent queries of similar fingerprints. This three-level caching mechanism achieves an overall hit rate of up to 99.2%, significantly reducing reliance on queries to the federated center and substantially improving fingerprint matching efficiency. Furthermore, by storing fingerprints of different frequencies in a tiered manner, it balances cache resource consumption with query performance.

[0073] S3: Extract features from the traffic data corresponding to the fingerprint tag to obtain traffic features;

[0074] Preferably, in one embodiment of the present invention, the step of extracting features from the traffic data corresponding to the fingerprint tag to obtain traffic features includes:

[0075] extracting packet size, timing statistics of traffic data as basic features;

[0076] standardizing the basic features to obtain standardized features; performing linear projection on the standardized features to obtain projection features;

[0077] adding position encoding to the projection features to obtain traffic features.

[0078] In the process of extracting features from traffic data corresponding to the fingerprint label to obtain traffic features, the normalization and enhancement of the features are realized through multi-step processing, which is specifically described as follows.

[0079] First, extract the basic features. For traffic data corresponding to the fingerprint label, key information such as packet size and timing statistics is extracted as basic features. These features can intuitively reflect the transmission law and data properties of traffic, and are the basis for subsequent anomaly detection, providing original input dimensions for model identification of malicious traffic.

[0080] Second, standardization and linear projection processing. Perform standardization operation on the extracted basic features, the calculation formula is:

[0081]

[0082] Where x is the basic feature value, x mean is the feature mean, x var is the feature variance, and ε is a small value (used to avoid division by zero).

[0083] Standardization processing can eliminate the scale difference between different features, and avoid that a certain feature dominates the model learning process due to the large value range. Then, linear projection is performed on the standardized features:

[0084] x lp = x s × W p

[0085] Where W p is the projection matrix, through which the standardized features are mapped to a higher dimensional space (dimension can be C=32) to enhance the representation ability of the features and capture more subtle traffic pattern differences.

[0086] Finally, add position encoding. In order to enable the model to capture the timing relationship of traffic features, a position encoding vector PE is added to the projection features. The calculation formula of the position encoding is:

[0087]

[0088] Where θ = 10000, i is the feature dimension index, and C is the projected feature dimension. After adding location encoding, the final traffic feature is x. p =x lp ×PE. This feature includes both the basic attributes and high-dimensional projection information of the traffic flow, as well as temporal and positional relationships, providing comprehensive and effective input data for subsequent Transformer-based abnormal traffic identification models.

[0089] S4: Input the traffic features into a pre-trained Transformer-based abnormal traffic identification model to obtain abnormal traffic identification results, wherein the abnormal traffic identification model includes a common layer that shares global attack features and a personalized layer that adapts to regional traffic differences.

[0090] like Figure 2 As shown, Figure 2 This is a schematic diagram of the architecture of an abnormal traffic identification model based on Transformer, provided in an embodiment of the present invention. In this embodiment, after traffic features are input into a pre-trained abnormal traffic identification model based on Transformer, the model outputs the abnormal traffic identification result through the collaborative processing of a common layer and a personalized layer. This abnormal traffic identification model uses a Transformer block as its core component and, through a layered design of a common layer and a personalized layer, takes into account both global attack patterns and regional traffic characteristics for identification. The specific process is as follows.

[0091] ransformer block core processing: input flow features (including position-encoded projection features x) p First, the data is processed through a series of Transformer blocks. Each Transformer block contains components such as layer normalization, multi-head self-attention (MSA), residual connections, and feedforward networks (FFN).

[0092] Among these, layer normalization mitigates internal covariate bias and ensures stable feature distribution; multi-head self-attention generates query (Q), key (K), and value (V) vectors to calculate global dependencies between features (such as...). And feature representation is enhanced by concatenating 8 independent attention heads; residual connections (such as x) m =MSA(x l )+x i This addresses the vanishing gradient problem in deep networks; the feedforward network introduces a nonlinear transformation through the ReLU activation function to further extract higher-order features; and the final residual connection ensures that the output dimension is consistent with the input dimension, supporting block cascading.

[0093] The traffic features are processed by 6 cascaded Transformer blocks, converted into a one-dimensional vector through flattening operation, projected into a two-dimensional vector (the probability of normal / malicious traffic) through linear projection, and finally classified through cross-entropy loss function to obtain the abnormal traffic identification result.

[0094] The Common Layers are the Transformer block parameters shared by multiple edge detection nodes, which are updated by federated averaging algorithm (weighted average according to the size of each gateway dataset) and used to capture global common attack features (such as SQL injection and DDoS attack patterns commonly used across regions). The Common Layers are set to 5 layers after optimization in the experiment.

[0095] The Personalized Layers are the Transformer blocks unique to each gateway, which are updated only with local data to adapt to regional traffic differences (such as crawler attacks in Shanghai node and payment fraud in Beijing node).

[0096] Preferably, in an embodiment of the present application, the number of layers of the Personalized Layers is determined by a dynamic adjustment mechanism, and the dynamic adjustment mechanism comprises:

[0097] calculating a global error rate, which includes a first error rate of the Common Layer parameters and the Personalized Layer parameters of the federated center cloud on the local test set;

[0098] calculating a personalized error rate, which includes a second error rate of the Common Layer parameters and the Personalized Layer parameters of the local gateway on the local test set;

[0099] adjusting the number of layers of the Personalized Layers based on a weighted sum minimization target of the global error rate and the personalized error rate, wherein the sum of the weight of the global error rate and the weight of the personalized error rate is 1.

[0100] In this embodiment, the number of layers of the Personalized Layers is dynamically determined by the weighted optimization target of the global error rate and the personalized error rate, and the specific process is as follows.

[0101] First, the error rate is calculated, wherein,

[0102] Global error rate: the Common Layer parameters and the Personalized Layer parameters issued by the federated center cloud are evaluated on the test set D j of the local gateway to obtain a first error rate ER C,j , reflecting the adaptation performance of the global model locally;

[0103] Personalization error rate: The public layer parameters and personalized layer parameters updated automatically by the local gateway are compared on the same local test set D. j The second error rate ER was obtained from the above evaluation. P,j This reflects the local model's ability to capture regional features.

[0104] The central cloud server aims to minimize the weighted sum of the global error rate and the personalized error rate, and adjusts the number of personalized layers N using the following function. P :

[0105]

[0106] Where, λ C,j +λ P,j =1, where K is the number of gateways. For example, when a sudden change in traffic in a certain area (such as a surge in web crawler attacks during shopping festivals) leads to an increase in the personalization error rate, the system will automatically increase N. P (For example, increasing from 3 layers to 5 layers) to enhance local feature capture capabilities and reduce false positive rates; conversely, if the global error rate increases, then reduce N. P Strengthen the learning of common global features.

[0107] Through this mechanism, the model can balance global universality and regional adaptability in real time, ensuring that the accuracy of abnormal traffic identification in different data centers under a multi-active architecture is at its optimal level.

[0108] The traffic scheduling process based on JA3 fingerprinting is as follows: Figure 3 As shown, Figure 3 The present invention provides a schematic diagram of a traffic scheduling process based on JA3 fingerprint, which mainly includes three stages: user request initiation and fingerprint extraction, fingerprint status decision, and routing decision execution.

[0109] User request initiation and fingerprint extraction. The user initiates an HTTPS connection request to the nearest GTM edge node, sending a "ClientHello" message containing parameters such as cipher suites and extended lists during the TLS handshake phase. The GTM node captures the "ClientHello" data packet at the operating system kernel level using eBPF technology, avoiding data copying to user space. This process is completed within 0.01m without interrupting the normal connection process. After receiving the raw data packet, the scheduling engine calculates the JA3 fingerprint string (e.g., 769,47-53-5-10-49161,23-24-25,0) using an optimized CRC32 algorithm and generates a 256-bit hash digest as a unique identifier.

[0110] Fingerprint state decision. The scheduling engine queries the fingerprint state by level: L1 cache (kernel eBPF map): stores 10,000 high-frequency fingerprints, hit rate 60%; L2 cache (shared memory Memcached): stores 100,000 medium-frequency fingerprints, hit rate 35%; L3 cache (distributed Redis): stores the global fingerprint library, hit rate 4.2%. When the cache is not hit (about 0.8% probability), a query is initiated to the federation center through the gRPC protocol, and the federation center returns the fingerprint label and TTL value (first appearance / label fingerprint / blacklist). The result is written to the local cache, and the cache expiration time is dynamically set according to the label type.

[0111] Route decision execution. First appearance fingerprint processing: real-time acquisition of each gateway, error rate (ER), CPU load, memory pressure, network delay, geographic distance, dynamic weighted calculation of comprehensive score based on entropy weight method, return of the highest score gateway IP address; Label fingerprint processing: immediately send TCP RST disconnect, respond to HTTP 302 redirection to the first detection gateway (treating gateway), browser automatically jumps to the treating gateway URL; Blacklist fingerprint processing: directly return HTTP 451 status code, carry customized interception page (including appeal entry), record attack information to the audit database.

[0112] Another embodiment of the application provides a security gateway-based abnormal traffic monitoring system, specifically, please refer to Figure 4 , Figure 4 The figure shows a schematic diagram of a security gateway-based abnormal traffic monitoring system in one embodiment of the application, which includes:

[0113] The acquisition module 11 is configured to acquire the TLS handshake feature in the traffic request of the target user in response to the traffic request, and perform hash calculation on the TLS handshake feature to obtain a JA3 hash fingerprint.

[0114] The matching module 12 is configured to sequentially perform three-level cache matching on the JA3 hash fingerprint, and extract the fingerprint label of the JA3 hash fingerprint that is not matched in the three-level cache.

[0115] The extraction module 13 is configured to perform feature extraction on the traffic data corresponding to the fingerprint label to obtain traffic features.

[0116] The identification module 14 is configured to input the traffic features into a pre-trained Transformer-based abnormal traffic identification model to obtain an abnormal traffic identification result, wherein the abnormal traffic identification model includes a public layer sharing global attack features and a personalized layer adapting to regional traffic differences.

[0117] Preferably, in one embodiment of the application, the acquisition module is specifically configured to:

[0118] capture a ClientHello message in a TLS handshake process based on an eBPF technology, and extract a TLS handshake feature in the ClientHello message;

[0119] perform hash calculation on the TLS handshake feature according to a CRC32 optimization algorithm to generate a JA3 hash fingerprint.

[0120] Preferably, in an embodiment of the present application, the matching module is specifically used for:

[0121] perform matching query on the JA3 hash fingerprint in the order of L1 cache, L2 cache and L3 cache, stop subsequent cache query and obtain label information corresponding to the JA3 hash fingerprint when a certain level of cache matching hits;

[0122] The L1 cache is an eBPF map, used for storing high-frequency fingerprints, the L2 cache is a Memcached, used for storing medium-frequency fingerprints, and the L3 cache is a distributed Redis, used for storing a global fingerprint library.

[0123] Preferably, in an embodiment of the present application, the extraction module is specifically used for:

[0124] extract packet size and timing statistics of traffic data as basic features;

[0125] perform standardization processing on the basic features to obtain standardized features, and perform linear projection on the standardized features to obtain projected features;

[0126] add position coding to the projected features to obtain traffic features.

[0127] Preferably, in an embodiment of the present application, the number of layers of the personalized layer is determined through a dynamic adjustment mechanism, and the dynamic adjustment mechanism includes:

[0128] calculate a global error rate, the global error rate including a first error rate of a public layer parameter and a personalized layer parameter of a federation coordination center cloud on a local test set;

[0129] calculate a personalized error rate, the personalized error rate including a second error rate of the public layer parameter and the personalized layer parameter of a local gateway on the local test set;

[0130] adjust the number of layers of the personalized layer based on a weighted sum minimization target of the global error rate and the personalized error rate, wherein the sum of the weight of the global error rate and the weight of the personalized error rate is 1.

[0131] As shown in Figure 5 , the method comprises the following steps: Figure 5The overall architecture diagram of the abnormal flow monitoring system provided by the embodiment of the application, the overall architecture of the application is a "detection-scheduling-federal cooperation" trinity distributed security framework, which aims to solve the core problems of cross-regional attack detection, resource constraint and response delay in multi-live architecture. The design core lies in the deep integration of edge intelligence, federal cooperation and dynamic scheduling, realizing the global optimization and local adaptation of security protection capability. The key components and working logic of the architecture are as follows:

[0132] 1) Edge detection node.

[0133] Local security gateway cluster: deployed at the edge layer of each data center, responsible for real-time traffic detection tasks.

[0134] Lightweight Transformer model: running on resource-constrained gateway, adopting block cascading structure, processing traffic features (packet size, time series statistics, etc.) through feature standardization, linear projection and position coding.

[0135] Personalization-public layer separation design: the bottom layer of the model is the public layer, and the upper layer is the personalized layer, supporting regional attack feature differentiation learning.

[0136] 2) Federal cooperation center cloud.

[0137] Parameter aggregation hub: receiving model parameter increments (non-original data) from each gateway, solving the cross-border transmission compliance risk.

[0138] Double-layer parameter update mechanism: the public layer is weighted average according to the data set weight, and the global attack mode is fused. The personalized layer aggregates parameter update direction and retains local characteristics.

[0139] Dynamic layer number optimization: based on error rate evaluation, real-time adjustment of personalized layer number, balancing global-local performance.

[0140] 3) Intelligent traffic scheduling layer.

[0141] Dynamic GTM driven by JA3 fingerprint:

[0142] Kernel-level fingerprint extraction: capture TLS handshake packets through eBPF, generate JA3 hash (CRC32 optimization), delay <0.01ms.

[0143] Three-level cache decision: L1 (eBPF mapping) → L2 (Memcached) → L3 (Redis), hit rate > 99.2%.

[0144] Scheduling strategy with federal feedback:

[0145] First fingerprint: comprehensive score routing based on gateway load, error rate and geographical distance entropy weight method.

[0146] Attack fingerprint: TCP RST disconnect + HTTP 302 redirect to "treatment gateway" (latest interception model).

[0147] Blacklist fingerprint: HTTP 451 interception page (with appeal entry).

[0148] 4) Closed-loop workflow.

[0149] Traffic access: user requests arrive at the GTM edge node, and the JA3 fingerprint is extracted.

[0150] Collaborative detection: fingerprint triggers gateway local Transformer model, public layer identifies global attack, and personalized layer captures regional features.

[0151] Federal optimization: gateway uploads parameter increments to central cloud, central dynamically aggregates and issues N_P policy.

[0152] Scheduling feedback: new attack label synchronizes GTM in real time, guides similar traffic to the optimal gateway, and forms a "detection-scheduling-training" closed loop.

[0153] Compared with the prior art, the beneficial effects of the embodiments of the present application are at least one of the following:

[0154] 1) The present application uses a three-level cache matching mechanism of JA3 hash fingerprint, which can quickly identify known fingerprints and greatly improve traffic processing efficiency. The hierarchical design of L1 to L3 cache combined with high hit rate can reduce invalid detection operations, and the TLS handshake feature capture based on eBPF technology and the CRC32 optimization algorithm for hash calculation ensure the efficiency and accuracy of fingerprint generation, effectively solving the problems of traffic scheduling lag and slow response in traditional schemes.

[0155] 2) At the same time, the abnormal traffic identification model based on Transformer considers the sharing of global attack features and the adaptation of regional traffic differences through the design of public layer and personalized layer, and cooperates with dynamically adjusted personalized layers to improve the accuracy of abnormal traffic detection. The model only needs to process the traffic data that is not matched in the three-level cache, reducing the consumption of computing resources of the edge node, and also meets the compliance requirements of data cross-border transmission by avoiding the transmission of raw data, balancing the detection efficiency and resource cost.

[0156] The above-described embodiments only express several embodiments of the present application, which are described in detail and specifically, but should not be understood as limiting the scope of the present patent. It should be noted that for ordinary skilled persons in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present patent should be subject to the appended claims.

Claims

1. A method for monitoring abnormal traffic based on a security gateway, characterized in that, Comprise: In response to the traffic request of the target user, the TLS handshake feature in the traffic request is obtained, and the TLS handshake feature is hashed to obtain a JA3 hash fingerprint; The JA3 hash fingerprint is sequentially matched with three levels of cache, and the fingerprint tag of the JA3 hash fingerprint that is not matched with the three levels of cache is extracted; The traffic feature is obtained by extracting the traffic data corresponding to the fingerprint tag; The traffic feature is input into a pre-trained abnormal traffic identification model based on Transformer to obtain an abnormal traffic identification result, wherein the abnormal traffic identification model comprises a public layer sharing global attack features and a personalized layer adapting to regional traffic differences.

2. The security gateway-based abnormal traffic monitoring method of claim 1, wherein, The JA3 hash fingerprint is obtained by hashing the TLS handshake feature in the traffic request, comprising: Capture the ClientHello message in the TLS handshake process based on eBPF technology, and extract the TLS handshake feature in the ClientHello message; According to the CRC32 optimization algorithm, the TLS handshake feature is hashed to generate a JA3 hash fingerprint.

3. The security gateway-based abnormal traffic monitoring method of claim 1, wherein, The JA3 hash fingerprint is sequentially matched with three levels of cache, comprising: The JA3 hash fingerprint is sequentially matched with L1 cache, L2 cache and L3 cache, when a certain level of cache is matched, the subsequent cache query is stopped and the tag information corresponding to the JA3 hash fingerprint is obtained; Wherein, the L1 cache is an eBPF map for storing high-frequency fingerprints, the L2 cache is a Memcached for storing medium-frequency fingerprints, and the L3 cache is a distributed Redis for storing a global fingerprint library.

4. The security gateway-based abnormal traffic monitoring method of claim 1, wherein, The traffic feature is obtained by extracting the traffic data corresponding to the fingerprint tag, comprising: Extract the packet size and timing statistics of the traffic data as basic features; The standardization of the basic features is processed to obtain standardized features, and the linear projection of the standardized features is processed to obtain projection features; The position coding of the projection features is added to obtain the traffic features.

5. The security gateway-based abnormal traffic monitoring method of claim 1, wherein, The number of layers of the personalized layer is determined by a dynamic adjustment mechanism, and the dynamic adjustment mechanism comprises: Calculate the global error rate, which includes the first error rate of the public layer parameters and the personalized layer parameters of the federal collaborative center cloud on the local test set; Calculate the personalized error rate, which includes the second error rate of the public layer parameters and the personalized layer parameters of the local gateway on the local test set; Based on the weighted sum minimization target of the global error rate and the personalized error rate, the number of layers of the personalized layer is adjusted, wherein the sum of the weight of the global error rate and the weight of the personalized error rate is 1.

6. A security gateway based abnormal traffic monitoring system, characterized by, Comprise: The acquisition module is configured to obtain the TLS handshake feature in the traffic request in response to the traffic request of the target user, and hash the TLS handshake feature to obtain a JA3 hash fingerprint; The matching module is configured to sequentially perform three-level cache matching on the JA3 hash fingerprints, and extract a fingerprint label of the JA3 hash fingerprint that is not matched in the three-level caches. The extraction module is configured to perform feature extraction on traffic data corresponding to the fingerprint label, to obtain traffic features. The identification module is configured to input the traffic features into a pre-trained abnormal traffic identification model based on a Transformer, to obtain an abnormal traffic identification result, wherein the abnormal traffic identification model comprises a public layer sharing global attack features and a personalized layer adapting to regional traffic differences.

7. The security gateway-based anomalous traffic monitoring system of claim 6, wherein, The acquisition module is specifically configured to: capture a ClientHello message in a TLS handshake process based on an eBPF technology, and extract a TLS handshake feature in the ClientHello message; perform hash calculation on the TLS handshake feature according to a CRC32 optimization algorithm, to generate a JA3 hash fingerprint.

8. The security gateway-based anomalous traffic monitoring system of claim 6, wherein, The matching module is specifically configured to: sequentially perform matching queries on the JA3 hash fingerprints in the order of an L1 cache, an L2 cache and an L3 cache, and stop subsequent cache queries and acquire label information corresponding to the JA3 hash fingerprint when a matching hit occurs in a certain level of cache; wherein the L1 cache is an eBPF map configured to store high-frequency fingerprints, the L2 cache is a Memcached configured to store medium-frequency fingerprints, and the L3 cache is a distributed Redis configured to store a global fingerprint library.

9. The security gateway-based anomalous traffic monitoring system of claim 6, wherein, The extraction module is specifically configured to: extract packet size and timing statistics of traffic data as basic features; perform standardization processing on the basic features to obtain standardized features, and perform linear projection on the standardized features to obtain projected features; add position encoding to the projected features to obtain traffic features.

10. The security gateway-based anomalous traffic monitoring system of claim 6, wherein, The number of layers of the personalized layer is determined through a dynamic adjustment mechanism, and the dynamic adjustment mechanism comprises: calculating a global error rate, wherein the global error rate comprises a first error rate of a public layer parameter and a personalized layer parameter of a federation center cloud on a local test set; calculating a personalized error rate, wherein the personalized error rate comprises a second error rate of the public layer parameter and the personalized layer parameter of a local gateway on the local test set; adjusting the number of layers of the personalized layer based on a weighted sum minimization target of the global error rate and the personalized error rate, wherein a sum of a weight of the global error rate and a weight of the personalized error rate is 1.

Citation Information

Cited By

  • Protection method, system and device for application layer DDoS attack and medium

    CN121727837A