Encrypted Traffic Identification Method and System Based on Network Topology Analysis

By collecting and analyzing encrypted traffic datasets, generating multimodal probe data packets, and using differential topology response to identify encrypted traffic behavior, this technology solves the problem of insufficient encrypted traffic identification capabilities in existing technologies, achieves efficient encrypted traffic detection and application identification, and improves the accuracy of network security monitoring.

CN120934919BActive Publication Date: 2026-03-06LIZHUANG INFORMATION TECH (SUZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-15
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

Existing passive analysis methods are unable to effectively identify highly concealed encrypted traffic, resulting in insufficient encrypted traffic identification capabilities and affecting the accuracy of network security monitoring.

Method used

By collecting encrypted traffic datasets of the target network topology, analyzing encrypted traffic behavior and generating multimodal probe data packets, the application type of encrypted traffic behavior is identified using differential topology response, and topology response fingerprint features are extracted for identification.

Benefits of technology

Without compromising encryption, topology changes are used to activate and identify the application types behind encrypted traffic, improving the accuracy of encrypted traffic identification and the precision of network security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934919B_ABST
    Figure CN120934919B_ABST
Patent Text Reader

Abstract

This application provides a method and system for identifying encrypted traffic based on network topology analysis, relating to the field of network security technology. The method includes: collecting an encrypted traffic dataset of a target network topology; obtaining identifiers for encrypted traffic behavior; generating a first probe data packet corresponding to the identifiers for encrypted traffic behavior using a multimodal probe triggering module; probing the identifiers for encrypted traffic behavior; and outputting a differential topology response; extracting topology response fingerprint features to identify a first application type corresponding to the identifiers for encrypted traffic behavior. This application solves the technical problem in existing technologies where passive analysis methods struggle to effectively identify highly concealed, disguised traffic in the face of encryption protocols, resulting in insufficient encrypted traffic identification capabilities. By using a multimodal probe triggering module and differential topology response analysis, probe packets are injected when suspicious encrypted traffic behavior is detected, and traffic behavior is identified by observing changes in the topology response, thus improving the accuracy of encrypted traffic identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method and system for identifying encrypted traffic based on network topology analysis. Background Technology

[0002] Existing passive analysis methods primarily rely on identifying the static characteristics of encrypted traffic, but they are significantly inadequate when facing modern encryption protocols. Because many encryption protocols and malware mimic the traffic patterns of common applications or evade detection by maintaining extremely low communication frequencies, they appear indistinguishable from normal traffic under passive observation. This prevents traditional analysis methods from effectively extracting usable identifying features, thus impacting the accuracy of encrypted traffic identification. Especially when dealing with complex attacks such as advanced persistent threats, network security detection accuracy drops dramatically. As encryption protocols and attack methods continue to evolve, existing passive analysis methods cannot adapt to these changes, leading to a significant decrease in the detection accuracy of network security defense mechanisms when facing these highly concealed traffic patterns.

[0003] In summary, existing technologies suffer from the technical problem that passive analysis methods struggle to effectively identify highly concealed spoofed traffic when faced with encryption protocols, resulting in insufficient encrypted traffic identification capabilities and further impacting the accuracy of network security monitoring. Summary of the Invention

[0004] The purpose of this application is to provide a method and system for identifying encrypted traffic based on network topology analysis, in order to solve the technical problem in the prior art that passive analysis methods are unable to effectively identify highly concealed disguised traffic in the face of encryption protocols, resulting in insufficient encrypted traffic identification capability and further affecting the accuracy of network security monitoring.

[0005] In view of the above problems, this application provides a method and system for identifying encrypted traffic based on network topology analysis.

[0006] In a first aspect, this application provides a method for identifying encrypted traffic based on network topology analysis. This method is implemented through a system for identifying encrypted traffic based on network topology analysis. The method includes: collecting an encrypted traffic dataset of a target network topology; analyzing the encrypted traffic dataset to obtain identifiers for encrypted traffic behavior, wherein the anomaly degree of the identifiers for the encrypted traffic behavior is greater than a preset anomaly degree threshold; generating a first probe data packet corresponding to the identifiers for the encrypted traffic behavior using a multimodal probe triggering module; probing the identifiers for the encrypted traffic behavior using the first probe data packet; outputting a differential topology response, wherein the differential topology response is a differential topology response of the identifiers for the encrypted traffic behavior based on the target network topology before and after the probe execution; extracting topology response fingerprint features from the differential topology response; and identifying a first application type corresponding to the identifiers for the encrypted traffic behavior based on the topology response fingerprint features.

[0007] Optionally, the encrypted traffic behavior set of the encrypted traffic dataset is analyzed; anomaly analysis is performed on each encrypted traffic behavior in the encrypted traffic behavior set, including communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; anomaly degree index is calculated and output for each encrypted traffic behavior according to the communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; based on the anomaly degree index of each encrypted traffic behavior, encrypted traffic behaviors with an anomaly degree greater than a preset anomaly degree threshold are identified and the identified encrypted traffic behaviors are output.

[0008] Optionally, the multimodal detection triggering module includes at least one detection data packet from a different protocol layer, including the transport layer, the TLS layer, and the application layer.

[0009] Optionally, the initial features of the identified encrypted traffic behavior are extracted, including IP port information, system AS number, handshake negotiation parameters, and initial traffic pattern; the initial features are compared with the historical feature database to obtain a candidate probe pattern set; a matching score is calculated based on the candidate probe pattern set, and the candidate probe pattern set is sorted according to the matching score calculation result to output the priority probe pattern; the first probe data packet corresponding to the identified encrypted traffic behavior is constructed based on the priority probe pattern.

[0010] Optionally, multiple matching score calculation items are defined, including the historical recognition success rate of each candidate detection mode, the protocol compatibility of each candidate detection mode for detecting encrypted traffic behavior, and the detection cost of each candidate detection mode for detecting encrypted traffic behavior. Multiple weight coefficients corresponding to the multiple matching score calculation items are obtained; weight calculations are performed on the multiple matching score calculation items according to the multiple weight coefficients to obtain the matching score set corresponding to the candidate detection mode set, and the matching score calculation result is output.

[0011] Optionally, a multimodal detection triggering module is used to generate a second probe data packet corresponding to the identified encrypted traffic behavior. The second probe data packet is a probe data packet composed of the second priority detection mode of the first probe data packet. The identified encrypted traffic behavior is detected based on the second probe data packet, and the second application type corresponding to the identified encrypted traffic behavior is identified. The second application type and the first application type are analyzed, and the analysis result of the application type corresponding to the identified encrypted traffic behavior is output.

[0012] Optionally, the identifier encrypted traffic behavior is parsed based on the target network topology to output the topology response before the probe is executed; the identifier encrypted traffic behavior is probed using the first probe data packet to obtain the probe encrypted response behavior of the identifier encrypted traffic behavior; the probe encrypted response behavior is parsed based on the target network topology to output the topology response after the probe is executed; the topology response before the probe is executed and the topology response after the probe is executed are analyzed to output the differential topology response.

[0013] Optionally, the topology response before and after the probe is executed is analyzed, and a differential topology response is output; wherein, the differential topology response includes the number and distribution of newly added nodes before and after the probe is executed, the density and direction of newly added connecting edges, changes in path switching, and changes in network community structure.

[0014] Optionally, the topology response fingerprint feature includes a spliced ​​fingerprint feature of node diffusion features, edge connection features, cascade diffusion patterns, and cross-layer linkage features; the topology response fingerprint feature is compared with known fingerprints in a known fingerprint feature library to obtain the first application type corresponding to the identified encrypted traffic behavior, wherein the known fingerprint feature library is a mapping database between known fingerprint feature samples and the first application type.

[0015] Secondly, this application also provides an encrypted traffic identification system based on network topology analysis, used to execute the encrypted traffic identification method based on network topology analysis as described in the first aspect, wherein the encrypted traffic identification system based on network topology analysis includes: a data acquisition unit for acquiring an encrypted traffic dataset of a target network topology; a behavior identification unit for analyzing the encrypted traffic dataset to obtain an identifier encrypted traffic behavior, wherein the anomaly degree of the identifier encrypted traffic behavior is greater than a preset anomaly degree threshold; a multimodal detection unit for generating a first detection data packet corresponding to the identifier encrypted traffic behavior using a multimodal detection trigger module, detecting the identifier encrypted traffic behavior using the first detection data packet, and outputting a differential topology response, wherein the differential topology response is the differential topology response of the identifier encrypted traffic behavior based on the target network topology before and after the detection is executed; and a fingerprint feature identification unit for extracting the topology response fingerprint feature of the differential topology response, and identifying a first application type corresponding to the identifier encrypted traffic behavior based on the topology response fingerprint feature.

[0016] One or more technical solutions provided in this application have at least the following beneficial effects: They collect encrypted traffic datasets of the target network topology; analyze the encrypted traffic datasets to obtain identifiers of encrypted traffic behavior, wherein the anomaly degree of the identifiers of the encrypted traffic behavior is greater than a preset anomaly degree threshold; use a multimodal detection triggering module to generate a first probe data packet corresponding to the identifiers of the encrypted traffic behavior; use the first probe data packet to probe the identifiers of the encrypted traffic behavior; output a differential topology response, where the differential topology response is the differential topology response of the identifiers of the encrypted traffic behavior based on the target network topology before and after the probe execution; extract the topology response fingerprint features of the differential topology response; and identify the first application type corresponding to the identifiers of the encrypted traffic behavior based on the topology response fingerprint features. In other words, by injecting small and legitimate probe packets into the target encrypted traffic, combined with the observation of the topology response, and without compromising encryption, the application type behind the encrypted traffic is activated and identified through topology changes, achieving efficient encrypted traffic detection and application identification. This overcomes the problems of traffic masquerading and concealment, improves the accuracy of encrypted traffic identification, and thus enhances the precision of network security monitoring.

[0017] The above description is merely an overview of the technical solution of this application. To better understand the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating the encrypted traffic identification method based on network topology analysis proposed in this application.

[0020] Figure 2 This is a schematic diagram of the encrypted traffic identification system based on network topology analysis in this application.

[0021] Explanation of reference numerals in the attached figures: Data acquisition unit 11, Behavior identification unit 12, Multimodal detection unit 13, Fingerprint feature recognition unit 14. Detailed Implementation

[0022] This application provides a method and system for identifying encrypted traffic based on network topology analysis. It addresses the technical problem in existing technologies where passive analysis methods struggle to effectively identify highly concealed, disguised traffic in the face of encryption protocols, leading to insufficient encrypted traffic identification capabilities and further impacting the accuracy of network security monitoring. By injecting tiny, legitimate probe packets into the target encrypted traffic and combining this with observation of topology responses, the application type behind the encrypted traffic is activated and identified through topology changes without compromising encryption. This achieves efficient encrypted traffic detection and application identification, overcoming the problems of traffic disguise and concealment, improving the accuracy of encrypted traffic identification, and thus enhancing the precision of network security monitoring.

[0023] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.

[0024] Example 1, please refer to the appendix. Figure 1 This application provides a method for identifying encrypted traffic based on network topology analysis. The method is executed by a system for identifying encrypted traffic based on network topology analysis, and specifically includes the following steps:

[0025] Collect encrypted traffic datasets of the target network topology.

[0026] Specifically, network topology refers to the connection methods and structure between various nodes in a network, describing the network layout and the physical or logical connections between devices. Target network topology refers to the specific network environment or structure of interest when performing encrypted traffic analysis. A specific target network is selected for monitoring; for example, suppose an internal corporate network is chosen, containing multiple computers, servers, routers, and other devices. The target network topology includes multiple subnets, each with different services and functions. Network traffic monitoring tools, such as Wireshark, tcpdump, or other network traffic analysis software, are deployed to capture all data packets transmitted in the network in real time, including encrypted traffic. The monitoring tools will record the transmitted encrypted traffic packets and their related metadata. By deploying traffic capture devices, such as gateways, routers, and switches, at key locations in the network, all encrypted traffic passing through these nodes is collected, including information such as the size, frequency, and protocol type of the encrypted traffic.

[0027] Encrypted traffic refers to traffic that uses encryption protocols to encrypt data during transmission. This protects data security and privacy, preventing theft or tampering during transmission. After capture and recording, the collected encrypted traffic data is organized into an encrypted traffic dataset. This dataset includes the raw encrypted traffic data and various statistical characteristics of encrypted communication, such as traffic rate, latency, encryption algorithm type, target port number, and information related to the TLS / SSL handshake phase. By collecting encrypted traffic datasets of the target network topology, detailed information about encrypted traffic in the network can be obtained, enabling the identification of potential network risks and the timely detection of abnormal behavior within encrypted traffic, thereby improving overall network security.

[0028] The encrypted traffic dataset is analyzed to obtain identifiers for encrypted traffic behaviors, wherein the anomaly degree of the identifiers for encrypted traffic behaviors is greater than a preset anomaly degree threshold.

[0029] Furthermore, this application also includes the following steps: analyzing the encrypted traffic behavior set of the encrypted traffic dataset; performing anomaly analysis on each encrypted traffic behavior in the encrypted traffic behavior set, including communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; calculating and outputting the anomaly degree index of each encrypted traffic behavior according to the communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; and identifying encrypted traffic behaviors with an anomaly degree greater than a preset anomaly degree threshold based on the anomaly degree index of each encrypted traffic behavior, and outputting the identified encrypted traffic behaviors.

[0030] Specifically, the collected encrypted traffic dataset is analyzed to categorize different communication activities into different sets of encrypted traffic behaviors. An encrypted traffic behavior set refers to various behaviors categorized according to different communication characteristics within the collected encrypted traffic dataset; each behavior represents a specific traffic pattern or communication activity. For example, one behavior set might be all encrypted traffic originating from a specific external IP address, while another set might be all traffic using the TLS protocol.

[0031] Anomaly analysis is performed on each encrypted traffic behavior within the encrypted traffic behavior set, including anomalies in communication objects, communication patterns, behavior deviating from the baseline, and TSL authentication. Anomalies in communication objects refer to communication behavior within encrypted traffic where the source IP, destination IP, and port are analyzed to identify communication objects that do not match normal communication objects. This may be an indication of attacker spoofing or unauthorized access. For example, if an internal device frequently communicates with an uncommon external IP address, it may indicate potential malicious activity.

[0032] Anomaly in communication patterns refers to a discrepancy between the communication pattern in encrypted traffic and the normal traffic pattern. Attackers may alter the communication pattern to evade detection. By analyzing characteristics such as the communication frequency, packet size, and duration of encrypted traffic, behaviors that deviate from the normal pattern can be identified. For example, if a server typically processes 50GB of traffic per day but processes 500GB of encrypted traffic on a particular day, this could indicate an anomaly.

[0033] A baseline refers to the expected pattern of normal traffic behavior in a network. When encrypted traffic behavior deviates significantly from historical data or a preset baseline, it is considered an abnormal deviation from the baseline. In other words, a baseline model of normal traffic is established through the analysis of historical data. If encrypted traffic behavior deviates significantly from this baseline, it is considered abnormal. For example, if an application typically updates weekly, but one update abnormally increases encrypted traffic by 100 times, malware may be transmitting data abnormally.

[0034] TLS authentication anomalies refer to problems in the authentication process of the TLS protocol, such as certificate verification failures or protocol version inconsistencies. These can be indicators that an attacker is attempting a man-in-the-middle attack or other malicious activity using an incorrect TLS certificate. Problems in the TLS authentication process can be detected by analyzing the certificate, protocol version, and encryption algorithm used in the TLS handshake. Finding non-compliant certificates or protocol version mismatches could be a signal of an attack, such as a man-in-the-middle attack.

[0035] Based on anomalies identified through anomaly analysis, including communication object anomalies, communication pattern anomalies, behavior deviation from baseline anomalies, and TLS authentication anomalies, an anomaly score is calculated for each encrypted traffic behavior. This score is generated by integrating the results of various anomaly analyses to quantify the degree of anomaly in the traffic behavior. When calculating the anomaly score, different weights are assigned to each type of anomaly, and then a weighted average or other algorithm is used to derive the final anomaly score. For example, communication object anomalies may have a higher weight because they are directly related to the identification of the attack source. The formula for calculating the anomaly score is: A = w1 * Communication Object Anomaly Score + w2 * Communication Pattern Anomaly Score + w3 * Behavior Deviation from Baseline Anomaly Score + w4 * TLS Authentication Anomaly Score, where w1, w2, w3, and w4 are the weights of each anomaly type, adjusted according to their impact on security threats. By comprehensively calculating the results of various anomaly analyses, a score representing the degree of anomaly is obtained. Generally, a higher anomaly score indicates that the traffic behavior deviates more from normal patterns.

[0036] After calculating the anomaly score for each encrypted traffic behavior, it is compared with a preset anomaly score threshold. The preset anomaly score threshold is a pre-defined anomaly score value used as a standard for identifying abnormal traffic. If the anomaly score of a traffic behavior exceeds the preset anomaly score threshold, the behavior is identified as abnormal traffic. The identification process includes recording information such as the source and destination IP addresses, communication frequency, and anomaly score, and then performing further security analysis. Identifying abnormal encrypted traffic behavior refers to identifying such behavior. For example, in monitoring encrypted traffic in an enterprise network, a specific internal device (IP address 192.168.1.100) frequently communicates with an external IP address (IP address 203.0.113.15) using encrypted communication, approximately 10 times per minute, exceeding the normal range. The anomaly score of this communication target is identified as 8.5. Normally, the communication frequency is about once per minute, but this increases to 10 times per minute, indicating an abnormal communication pattern. The anomaly score of this communication pattern is identified as 7.0. Historical data shows that this application transmits approximately [missing data - likely data from another source] per month. The application initially showed 10GB of data, but this month the data transfer volume surged to 500GB, a 50-fold deviation from the baseline, clearly anomaly. The behavior deviation from the baseline anomaly score was identified as 9.0. During a TLS handshake in a certain encrypted communication, an expired certificate and an incompatible TLS protocol version were detected, causing authentication failure, resulting in a TLS authentication anomaly score of 6.0. The weights for communication object anomaly, communication mode anomaly, behavior deviation from the baseline anomaly, and TLS authentication anomaly were set to 0.4, 0.2, 0.3, and 0.1 respectively. Substituting these weights into the aforementioned anomaly score calculation formula yielded 8.1. Assuming a preset anomaly score threshold of 7.0, the anomaly score of this encrypted traffic behavior exceeded the preset threshold, and therefore it was identified as abnormal traffic.

[0037] By performing anomaly analysis on encrypted traffic behavior sets, potential security threats and malicious behaviors can be identified. This not only detects covert traffic that is difficult to identify with traditional passive analysis, but also accurately identifies anomalies in communication objects, communication modes, and TLS authentication in encrypted traffic, thereby improving the identification capabilities of network security monitoring.

[0038] A multimodal detection triggering module generates a first probe data packet corresponding to the identified encrypted traffic behavior. The first probe data packet is used to probe the identified encrypted traffic behavior, and a differential topology response is output. The differential topology response is the differential topology response of the identified encrypted traffic behavior based on the target network topology before and after the probe is executed.

[0039] Furthermore, this application also includes the following steps: the multimodal detection triggering module includes at least one detection data packet of different protocol layers, the protocol layers including the transport layer, the TLS layer and the application layer.

[0040] Furthermore, this application also includes the following steps: extracting the initial features of the identified encrypted traffic behavior, including IP port information, system AS number, handshake negotiation parameters, and initial traffic pattern; comparing the initial features with a historical feature database to obtain a candidate probe pattern set; calculating the matching score based on the candidate probe pattern set, sorting the candidate probe pattern set according to the matching score calculation result, and outputting the priority probe pattern; and constructing the first probe data packet corresponding to the identified encrypted traffic behavior based on the priority probe pattern.

[0041] Furthermore, this application also includes the following steps: defining multiple matching score calculation items, wherein the multiple matching score calculation items include the historical recognition success rate of each candidate detection mode, the protocol compatibility of each candidate detection mode for detecting encrypted traffic behavior, and the detection cost of each candidate detection mode for detecting encrypted traffic behavior; obtaining multiple weight coefficients corresponding to the multiple matching score calculation items; performing weight calculation on the multiple matching score calculation items according to the multiple weight coefficients, obtaining the matching score set corresponding to the candidate detection mode set, and outputting the matching score calculation result.

[0042] Specifically, the multimodal probe triggering module is a module capable of generating probe data packets at different protocol layers. This allows for in-depth detection and analysis of network behavior. The multimodal probe triggering module generates a first probe data packet corresponding to the encrypted traffic behavior, with the aim of triggering and analyzing encrypted traffic in the network. Probe data packets at different protocol layers can be used for traffic detection at different levels, such as TLS handshake packets, HTTP / 2 frames, and QUIC probe frames. The most suitable protocol layer is selected for probing based on the behavior of the target encrypted traffic. For example, a TLS Hello packet can be generated at the TLS layer, while an HTTP / 2 Ping frame can be generated at the application layer. Network protocols can be divided into multiple layers, such as the transport layer, TLS layer, and application layer. Different layers handle different network functions. The transport layer mainly handles data transmission, such as TCP / UDP; the TLS layer is responsible for security encryption; and the application layer involves actual application protocols, such as HTTP and FTP.

[0043] The initial characteristics that identify encrypted traffic behavior are extracted, including IP port information, system AS number, handshake negotiation parameters, and initial traffic pattern. Initial characteristics refer to the basic information extracted when identifying encrypted traffic behavior, used to identify and classify the traffic. For example, IP address and port number indicate the communication endpoint of the traffic, system AS number represents the network autonomous system, handshake negotiation parameters involve the initialization process of encryption protocols such as TLS, and initial traffic pattern includes parameters such as the size, frequency, and time of the initial traffic, helping to identify the nature of the traffic.

[0044] The extracted initial features will be compared with data in a historical feature database. This database contains past application-response mappings and probe success rates. The application-response mapping is the mapping relationship between historical applications and their response patterns; for example, a specific encrypted traffic behavior corresponds to the response characteristics of a particular application. Probe success rate statistics are statistical information on the successful identification of traffic applications by different probe patterns in the past. For example, for a TLS connection, based on the handshake negotiation parameters and traffic pattern, it is matched with historically identified application behaviors to find the most similar behavior pattern. The historical feature database is a dataset containing past traffic behaviors and probe success rates, storing feature data and corresponding response results for various applications throughout history. This data is used to compare with the characteristics of current traffic to help infer the application type and protocol of the current traffic.

[0045] By comparing the initial features with the historical feature library, a set of candidate detection patterns is generated, which includes possible detection patterns. Each pattern is generated based on the characteristics of the current traffic and takes into account cross-protocol layer detection methods, such as TCP option detection, TLS Hello extension detection, HTTP / 2PING, QUIC detection frames, etc.

[0046] A matching score calculation term is defined for each candidate probe mode, including the historical success rate of each candidate probe mode, the protocol compatibility of each candidate probe mode in detecting encrypted traffic behavior, and the probe cost of each candidate probe mode in detecting encrypted traffic behavior. The historical success rate of each candidate probe mode represents the frequency with which it has successfully identified encrypted traffic in the past; a higher historical success rate indicates better performance of the probe mode under similar conditions. The protocol compatibility of each candidate probe mode in detecting encrypted traffic behavior measures the compatibility between the candidate probe mode and the protocol used by the target encrypted traffic. For example, if the target traffic uses TLS 1.3, but a probe mode is only applicable to TLS 1.2, then the protocol compatibility of that mode is low. The probe cost of each candidate probe mode in detecting encrypted traffic behavior includes computation time, bandwidth consumption, and possible network latency. Low-cost modes have less impact on performance and are therefore given priority.

[0047] This process obtains multiple weight coefficients corresponding to various matching score calculation items. Each weight coefficient reflects its contribution to the final matching score. The selection of weight coefficients can be adjusted based on actual needs. For example, historical recognition success rate is considered the most important, so it is given a high weight, such as 0.5; protocol compatibility may be slightly less important, such as 0.3; and detection cost has a lower weight, such as 0.2. The weights of historical recognition success rate, protocol compatibility, and detection cost can be adjusted according to actual requirements.

[0048] For each candidate probe pattern in the candidate probe pattern set, the final matching score is calculated according to the defined matching score calculation item. The calculation formula is as follows: Matching Score = a1 * Historical recognition success rate of each candidate probe pattern + a2 * Protocol compatibility of each candidate probe pattern for detecting encrypted traffic behavior + a3 * Detection cost of each candidate probe pattern for detecting encrypted traffic behavior, where a1, a2, and a3 are the weight coefficients corresponding to the historical recognition success rate of each candidate probe pattern, the protocol compatibility of each candidate probe pattern for detecting encrypted traffic behavior, and the detection cost of each candidate probe pattern for detecting encrypted traffic behavior, respectively.

[0049] After obtaining the matching score calculation results for the candidate probe mode set, the candidate probe mode set is sorted, and the priority probe mode is output. The higher the matching score of the probe mode, the higher its matching degree with the target traffic, and it should be selected for probe first. For example, candidate probe mode A is TLS 1.2 handshake extension probe, with a historical recognition success rate of 0.9, protocol compatibility of 0.9, and probe cost of 0.5; candidate probe mode B is TCP option probe, with a historical recognition success rate of 0.7, protocol compatibility of 0.7, and probe cost of 0.2; candidate probe mode C is HTTP / 2PING probe, with a historical recognition success rate of 0.85, protocol compatibility of 0.8, and probe cost of 0.8. Assuming that the weight coefficients corresponding to the historical recognition success rate of each candidate probe mode, the protocol compatibility of each candidate probe mode for detecting encrypted traffic behavior, and the probe cost of each candidate probe mode for detecting encrypted traffic behavior are 0.5, 0.3, and 0.2, respectively, then the matching scores are calculated as follows: Mode A is 0.82, Mode B is 0.6, and Mode C is 0.825. Based on the calculated matching scores, the ranking is: Pattern C, Pattern A, and Pattern B. Therefore, Pattern C is prioritized for detection, followed by Pattern A, and finally Pattern B. Using the selected Pattern C (HTTP / 2PING probe), a probe packet suitable for the HTTP / 2PING protocol is constructed and sent to the target encrypted traffic. The response is observed to further identify the application behavior of the traffic.

[0050] The first probe packet is generated based on the selected priority probe mode and will be used to probe the target encrypted traffic in order to obtain more information and identify the actual behavior and application type of the traffic. The first probe packet is a packet built based on the priority probe mode and is used for preliminary probing of encrypted traffic behavior. This first probe packet is sent to the target traffic for further analysis of the traffic response. By employing a multimodal probe trigger module and comparing initial features, the most suitable probe mode is selected based on the characteristics of the current traffic, and appropriate probe packets are generated according to different protocol layers, thereby improving the ability to identify and analyze encrypted traffic. Through multi-layered probing and efficient pattern matching, the application type behind the traffic can be effectively identified, improving the response speed and accuracy of the network security protection system.

[0051] Furthermore, this application also includes the following steps: performing topology parsing on the identifier encrypted traffic behavior based on the target network topology, and outputting the topology response before probe execution; probing the identifier encrypted traffic behavior using the first probe data packet, obtaining the probe encrypted response behavior of the identifier encrypted traffic behavior, performing topology parsing on the probe encrypted response behavior based on the target network topology, and outputting the topology response after probe execution; analyzing the topology response before probe execution and the topology response after probe execution, and outputting the differential topology response.

[0052] Furthermore, this application also includes the following steps: analyzing the topology response before and after the probe execution, and outputting a differential topology response; wherein the differential topology response includes the number and distribution of newly added nodes before and after the probe execution, the density and direction of newly added connection edges, changes in path switching, and changes in network community structure.

[0053] Specifically, topology analysis is performed on encrypted traffic behavior based on the target network topology. This involves analyzing the structure of nodes and connections in the network to detect the topological response before execution. Topology analysis considers not only physical connections, such as the connections between routers and switches, but also logical connections, such as how devices in a virtual network are interconnected. Topology analysis refers to the process of analyzing the network topology to identify the nodes, connections, and data flow paths within the network. It is used to understand how data packets flow in the network and which nodes and connections are transmitting data. It identifies all critical nodes in the network, including user equipment, network devices, and security devices. Connection relationships are identified between nodes, including wired connections, wireless connections, and VPN connections.

[0054] Identify the network area requiring encrypted traffic analysis. For example, assuming the target network is an internal LAN or a cross-regional WAN, the probe scope can include a local network or the entire network. Output the initial state of the network topology, i.e., the topology response before probe execution, including node information, connection information, and traffic routing. Node information lists all nodes in the network, such as servers, computers, and routers. Connection information lists the connection relationships and data flow paths between nodes. Traffic routing displays the traffic transmission path from source to destination, including any intermediary devices and communication protocols.

[0055] The encrypted traffic behavior is probed using a first probe packet to obtain the probe's encrypted response behavior. This is done by sending the first probe packet to the encrypted traffic behavior via network monitoring equipment. For example, if the target traffic behavior is TLS-encrypted communication, a TLS Hello extended probe packet might be sent. Upon receiving this probe packet, the target server will return an encrypted response according to the protocol. The encrypted traffic behavior responds according to the rules of the encryption protocol, obtaining the probe's encrypted response behavior, such as a TLS handshake response, an HTTP / 2 response frame, or a QUIC protocol response. The response behavior can include multiple layers of content, such as negotiation parameters from the handshake phase, protocol version, certificate information, and encryption algorithm. The probe's encrypted response behavior refers to the response of the target encrypted traffic after receiving the probe packet, reflecting the behavioral characteristics, application type, and potential network state of the encrypted traffic.

[0056] Similarly, based on the target network topology, topology analysis is performed on the probe's encrypted response behavior. The sending and receiving of probe packets may cause changes in the behavior of certain nodes in the network, or the addition of new connections and paths. These changes are analyzed based on the target network topology. For example, a TLS protocol response may cause a change in the traffic path between a device on the internal network and an external server, or a newly added network node may enter the network through a proxy or VPN connection. Analyzing these changes helps identify the traffic flow in the network and the new connections between nodes. After the probe is executed, the changes in the network topology response are output, i.e., the post-probe topology response, including new nodes, new connections, changes in connections, and changes in nodes and paths. The post-probe topology response refers to the changes in nodes and connections in the network during the response triggered by the probe packets. Compared to the topology response before the probe, the post-probe topology response reflects the specific changes in the network topology structure due to the probe of encrypted traffic behavior.

[0057] By comparing the topology response before and after the probe, changes in the network are analyzed, reflecting the impact of encrypted traffic probes on the network topology and helping to reveal potential security threats or network anomalies. Differential topology response refers to comparing the topology response before and after the probe to reveal changes in the network, including the number and distribution of new nodes, the density and direction of new connection edges, changes in path switching, and changes in network community structure. The number and distribution of new nodes refer to the newly added devices or nodes in the network before and after the probe, and their locations within the network; the density and direction of new connection edges refer to the number of new connection paths and their flow direction; changes in path switching refer to the changes in network traffic transmission paths before and after the probe; changes in network community structure refer to changes in the relationships or aggregation patterns between nodes in the network, which may reflect changes in network structure, such as network segmentation or attacker manipulation of the network structure.

[0058] Analyze the newly added nodes in the network after the probe is executed, and their distribution locations, such as newly added proxy servers and VPN servers. Analyze the number and direction of new connection paths in the network after the probe. For example, traffic that previously traveled through a single router may now travel through multiple proxy servers after the probe. Analyze whether traffic paths have changed; for example, some traffic that previously traveled through one network path may now travel through another. The probe may also cause changes in the network's community structure. For example, devices that were originally in one community may join another community through a new path, forming new connection patterns.

[0059] For example, encrypted traffic probing is performed in an enterprise network with the following target network topology: the internal network contains 50 computers, 2 file servers, and 1 database server; the external network contains 1 public web server; and network devices include 1 router, 2 switches, and 1 firewall. Through topology resolution, the following nodes and connections are identified: nodes include 50 computers, 2 file servers, 1 database server, 1 web server, 1 router, 2 switches, and 1 firewall; connections include computers connected to the router via switches, the router connected to the firewall, and the firewall communicating with the external web server. A TLS Hello extended probe packet is sent. Upon receiving the packet, the target web server responds with a TLS handshake, returning a TLS handshake response and selecting the TLS 1.2 protocol. At this point, the network topology changes: to better handle encrypted traffic, a proxy server is added; the proxy server is added between the internal and external networks, and the new communication path begins forwarding traffic through the proxy server. By comparing the topology responses before and after the probe, the differential topology response was obtained: a new proxy server was added, connecting the internal network switch and the external network web server; the new connection path went from the internal network computer to the web server through the proxy server, enhancing data encryption; previously, the internal network computer accessed the web server directly through the router, but now the traffic is forwarded through the proxy server; the direct communication path between the internal network computer and the web server was replaced by the proxy server, forming a new community connection.

[0060] By performing differential analysis on the topology response before and after the probe, the impact of encrypted traffic probes on network topology can be identified. This not only helps monitor changes in traffic transmission paths but also detects potential bypass behaviors, such as attackers bypassing firewalls through proxy servers. Differential topology responses help reveal new nodes, connections, and path changes in the network, enhancing the ability to monitor potential network attacks and improving network security protection levels.

[0061] Extract the topology response fingerprint features of the differential topology response, and identify the first application type corresponding to the identifier encrypted traffic behavior based on the topology response fingerprint features.

[0062] Furthermore, this application also includes the following steps: wherein the topology response fingerprint feature includes a spliced ​​fingerprint feature of node diffusion features, edge connection features, cascade diffusion mode and cross-layer linkage features; the topology response fingerprint feature is compared with the known fingerprints in the known fingerprint feature library to obtain the first application type corresponding to the identified encrypted traffic behavior, wherein the known fingerprint feature library is a mapping database between known fingerprint feature samples and the first application type.

[0063] Specifically, topological response fingerprint features are extracted from differential topological responses to describe patterns of network topology change. These fingerprint features include concatenated fingerprint features of node diffusion, edge connectivity, cascade diffusion patterns, and cross-layer linkage. Node diffusion features describe the number, distribution, and roles of newly added nodes in the network topology, such as newly added proxy servers or devices, reflecting trends and helping to identify traffic sources and destinations. Edge connectivity features describe the density, direction, and connection methods of newly added connection paths in the network topology, revealing the transmission path and its changes from source to destination nodes. Cascade diffusion patterns represent changes in transmission paths between nodes, such as path switching through proxies, tunnels, or other intermediary devices, identifying traffic diffusion trends, especially in encrypted traffic via path switching through intermediary servers. Cross-layer linkage features are the interaction and linkage characteristics between different protocol layers, helping to reveal the complex protocol interaction patterns behind encrypted traffic behavior. The extracted features are concatenated into a topological response fingerprint feature, containing multi-dimensional information for further similarity comparison.

[0064] The similarity score between a topology response fingerprint feature and a known fingerprint feature database is calculated by comparing the fingerprint feature with known fingerprints in the database. The database contains various encrypted traffic application types, with each entry corresponding to a known application type (e.g., video streaming, cloud storage, online games). Each newly extracted topology response fingerprint feature is compared with all known fingerprints in the database, and the degree of matching between the traffic behavior and the known application type is evaluated by calculating the similarity score. If the similarity score between a topology response fingerprint feature and a known fingerprint exceeds a set threshold, the encrypted traffic behavior is considered to belong to that known application type.

[0065] By comparing similarity scores, the first application type corresponding to the identified encrypted traffic behavior is determined, identifying that the target traffic behavior is generated by a known application (such as video streaming, cloud storage, file transfer, etc.). The first application type is the application type of the target encrypted traffic behavior obtained through similarity comparison. The application type corresponding to the traffic behavior is identified by comparing it with fingerprint features in a known fingerprint database. For example, if the topology response fingerprint has a high similarity to a known fingerprint feature marked as a video streaming application, then the encrypted traffic behavior is identified as a video streaming application. For example, suppose that after analyzing the differential topology response, the following fingerprint features are extracted: a new proxy server node is added; a new connection path is added between the proxy server and the internal network computer and the external network web server; traffic is forwarded to the external network web server through the proxy server, increasing the path of traffic extension; the proxy server forwards traffic between the application layer and the transport layer. A similarity comparison with the known fingerprint feature database shows: a fingerprint similarity of 0.92 with a known video streaming application and a fingerprint similarity of 0.68 with a known cloud storage application. Based on the similarity comparison results, the encrypted traffic behavior is considered to belong to a video streaming application because its similarity is higher than that of a cloud storage application. By extracting, splicing, and comparing topological response fingerprint features, the application type of encrypted traffic behavior can be accurately identified.

[0066] Furthermore, this application also includes the following steps: generating a second probe data packet corresponding to the identified encrypted traffic behavior using a multimodal detection triggering module, wherein the second probe data packet is a probe data packet composed of the second priority detection mode of the first probe data packet; detecting the identified encrypted traffic behavior according to the second probe data packet and identifying the second application type corresponding to the identified encrypted traffic behavior; analyzing the second application type and the first application type, and outputting the application type analysis result corresponding to the identified encrypted traffic behavior.

[0067] Specifically, the first probe data packet generated by the multimodal probe triggering module is used for preliminary identification of encrypted traffic behavior. The multimodal probe triggering module then generates a second probe data packet corresponding to the identified encrypted traffic behavior. This second probe data packet is composed of probe data packets using the secondary priority probe modes of the first probe data packet. The selection of the secondary priority probe mode is based on its matching score, and the secondary priority probe mode typically supplements the first probe mode to further verify the type of traffic. For example, if the first probe mode is an HTTP / 2PING probe, the secondary priority mode might be a TLS 1.2 handshake extension probe.

[0068] Using a second probe packet to probe the target encrypted traffic, by sending the second probe packet, triggering a response from the target traffic, and analyzing the response packet, provides more details about the traffic behavior, helping to identify the actual application type of the encrypted traffic. The purpose of the second probe is to verify the results of the first probe through further probing. For example, if the first probe mode suggests that the traffic may be a TLS-encrypted video streaming application, the second probe may further confirm whether it is a video streaming application or other types of traffic, such as cloud storage or file transfer.

[0069] By analyzing the response to the second probe packet, a second application type corresponding to the encrypted traffic behavior is identified. The second application type is identified based on the results of the second-priority probe mode; it may be the same as or different from the first application type. The second application type, derived from the results of the second probe mode, provides further confirmation of the encrypted traffic behavior. If the first probe packet has already given a preliminary application type, the second probe will confirm or correct this type by providing supplementary information.

[0070] Once the first and second application types are identified, they are analyzed. If they match, the traffic is confirmed to belong to that application type; otherwise, the application type is reassessed to identify potential anomalous behavior or mixed traffic from multiple applications. Comparing the first and second application types reduces false positives and false negatives. Application type analysis compares the results of two probes to analyze the application type corresponding to the encrypted traffic, more accurately determining which applications or services the target traffic originates from. For example, in one scenario, suppose we are analyzing encrypted traffic behavior on a target server. We choose to construct a first probe packet based on the TLS Hello extension and send it to the target server. Analyzing the response, we initially determine that the encrypted traffic might be a video streaming application, such as Netflix. Based on the results of the first probe packet, we select HTTP / 2PING probing as the second probe mode to further confirm the application type of the traffic, especially if the first probe fails to fully verify it. After sending the HTTP / 2PING probe packet, the target server returns a Pong frame, further confirming that the encrypted traffic does indeed belong to an HTTP / 2-based streaming service. Through the second probe, we confirm that the second application type of the encrypted traffic behavior is a video streaming application, further verifying the results of the first probe. Since the first application type and the second application type are the same, it is confirmed that the encrypted traffic does indeed belong to a video streaming application, and the output application type analysis result is a video streaming application.

[0071] By employing secondary verification based on a secondary priority probing mode, the application type of encrypted traffic is further confirmed after the initial probing, reducing false positives and false negatives. Utilizing a multimodal probing trigger module for both initial and secondary probing, the characteristics of different protocol layers are fully leveraged to accurately identify the application type of encrypted traffic, effectively handling complex or ambiguous encrypted traffic, providing more accurate network traffic analysis results, and enhancing network security monitoring and protection capabilities.

[0072] In summary, the encrypted traffic identification method based on network topology analysis provided in this application has the following beneficial effects:

[0073] By collecting encrypted traffic datasets of the target network topology, analyzing the encrypted traffic datasets to obtain identifiers for encrypted traffic behaviors, wherein the anomaly degree of the identifiers for encrypted traffic behaviors is greater than a preset anomaly degree threshold, a multimodal detection trigger module generates a first probe data packet corresponding to the identifiers for encrypted traffic behaviors, and uses the first probe data packet to probe the identifiers for encrypted traffic behaviors, outputting a differential topology response, which is a differential topology response of the identifiers for encrypted traffic behaviors based on the target network topology before and after the probe execution; extracting the topology response fingerprint features of the differential topology response, and identifying the first application type corresponding to the identifiers for encrypted traffic behaviors based on the topology response fingerprint features. In other words, by injecting small and legitimate probe packets into the target encrypted traffic, combined with the observation of the topology response, the application type behind the encrypted traffic is activated and identified through topology changes without compromising encryption, achieving efficient encrypted traffic detection and application identification, overcoming traffic masquerading and concealment problems, improving the accuracy of encrypted traffic identification, and thus enhancing the precision of network security monitoring.

[0074] Example 2: Based on the same inventive concept as the encrypted traffic identification method based on network topology analysis in Example 1, this application also provides an encrypted traffic identification system based on network topology analysis. Please refer to the appendix. Figure 2 The encrypted traffic identification system based on network topology analysis includes:

[0075] The data acquisition unit 11 is used to acquire an encrypted traffic dataset of the target network topology; the behavior identification unit 12 is used to analyze the encrypted traffic dataset to obtain an identifier encrypted traffic behavior, wherein the abnormality of the identifier encrypted traffic behavior is greater than a preset abnormality threshold; the multimodal detection unit 13 is used to generate a first detection data packet corresponding to the identifier encrypted traffic behavior using a multimodal detection trigger module, use the first detection data packet to detect the identifier encrypted traffic behavior, and output a differential topology response, wherein the differential topology response is the differential topology response of the identifier encrypted traffic behavior based on the target network topology before and after the detection is performed; the fingerprint feature recognition unit 14 is used to extract the topology response fingerprint feature of the differential topology response, and identify the first application type corresponding to the identifier encrypted traffic behavior based on the topology response fingerprint feature.

[0076] Furthermore, the behavior identification unit 12 in the encrypted traffic identification system based on network topology analysis is also used to: analyze the encrypted traffic behavior set of the encrypted traffic dataset; perform anomaly analysis on each encrypted traffic behavior in the encrypted traffic behavior set, including communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; calculate and output the anomaly degree index of each encrypted traffic behavior according to the communication object anomaly, communication mode anomaly, behavior deviation from baseline anomaly, and TSL authentication anomaly; and identify encrypted traffic behaviors with an anomaly degree greater than a preset anomaly degree threshold according to the anomaly degree index of each encrypted traffic behavior, and output the identified encrypted traffic behaviors.

[0077] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used for: the multimodal detection triggering module includes at least one probe data packet of different protocol layers, the protocol layers including the transport layer, the TLS layer and the application layer.

[0078] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used to: extract the initial features of the identified encrypted traffic behavior, including IP port information, system AS number, handshake negotiation parameters, and initial traffic pattern; compare the initial features with the historical feature database to obtain a candidate detection pattern set; calculate the matching score based on the candidate detection pattern set, sort the candidate detection pattern set according to the matching score calculation result, and output the priority detection pattern; and construct the first detection data packet corresponding to the identified encrypted traffic behavior based on the priority detection pattern.

[0079] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used to: define multiple matching score calculation items, the multiple matching score calculation items including the historical identification success rate of each candidate detection mode, the protocol compatibility of each candidate detection mode for detecting encrypted traffic behavior, and the detection cost of each candidate detection mode for detecting encrypted traffic behavior; obtain multiple weight coefficients corresponding to the multiple matching score calculation items; perform weight calculation on the multiple matching score calculation items according to the multiple weight coefficients, obtain the matching score set corresponding to the candidate detection mode set, and output the matching score calculation result.

[0080] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used to: generate a second detection data packet corresponding to the identified encrypted traffic behavior using a multimodal detection trigger module, wherein the second detection data packet is a detection data packet composed of the second priority detection mode of the first detection data packet; detect the identified encrypted traffic behavior according to the second detection data packet and identify the second application type corresponding to the identified encrypted traffic behavior; analyze the second application type and the first application type, and output the application type analysis result corresponding to the identified encrypted traffic behavior.

[0081] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used to: perform topology parsing on the identified encrypted traffic behavior based on the target network topology, and output the topology response before detection execution; use the first detection data packet to detect the identified encrypted traffic behavior, obtain the detection encrypted response behavior of the identified encrypted traffic behavior, perform topology parsing on the detection encrypted response behavior based on the target network topology, and output the topology response after detection execution; analyze the topology response before detection execution and the topology response after detection execution, and output the differential topology response.

[0082] Furthermore, the multimodal detection unit 13 in the encrypted traffic identification system based on network topology analysis is also used to: analyze the topology response before and after the detection execution, and output a differential topology response; wherein, the differential topology response includes the number and distribution of newly added nodes before and after the detection execution, the density and direction of newly added connection edges, the path switching changes, and the changes in the network community structure.

[0083] Furthermore, the fingerprint feature recognition unit 14 in the encrypted traffic identification system based on network topology analysis is also used for: wherein the topology response fingerprint feature includes a spliced ​​fingerprint feature of node diffusion features, edge connection features, cascade diffusion mode and cross-layer linkage features; comparing the similarity of the topology response fingerprint feature with known fingerprints in the known fingerprint feature library to obtain the first application type corresponding to the identified encrypted traffic behavior, wherein the known fingerprint feature library is a mapping database between known fingerprint feature samples and the first application type.

[0084] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Figure 1 The encrypted traffic identification method and specific examples based on network topology analysis in Example 1 are also applicable to the encrypted traffic identification system based on network topology analysis in this example. Through the foregoing detailed description of the encrypted traffic identification method based on network topology analysis, those skilled in the art can clearly understand the encrypted traffic identification system based on network topology analysis in this example. Therefore, for the sake of brevity, it will not be described in detail here.

[0085] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0086] Obviously, those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A method for encrypted traffic identification based on network topology analysis, characterized in that, The method comprises the following steps: Collecting an encrypted traffic dataset of a target network topology; Analyzing the encrypted traffic dataset to obtain an identified encrypted traffic behavior, wherein the abnormality of the identified encrypted traffic behavior is greater than a preset abnormality threshold; Using a multi-modal detection triggering module to generate a first detection data packet corresponding to the identified encrypted traffic behavior, detecting the identified encrypted traffic behavior using the first detection data packet, and outputting a differential topology response, which is a differential topology response of the identified encrypted traffic behavior before and after detection execution based on the target network topology; Extracting a topology response fingerprint feature of the differential topology response, and identifying a first application type corresponding to the identified encrypted traffic behavior according to the topology response fingerprint feature; Detecting the identified encrypted traffic behavior using the first detection data packet and outputting a differential topology response, comprising: Topologically analyzing the identified encrypted traffic behavior based on the target network topology, and outputting a topology response before detection execution; Detecting the identified encrypted traffic behavior using the first detection data packet, obtaining a detection encrypted response behavior of the identified encrypted traffic behavior, topologically analyzing the detection encrypted response behavior based on the target network topology, and outputting a topology response after detection execution; Analyzing the topology response before detection execution and the topology response after detection execution, and outputting a differential topology response; Wherein, the differential topology response includes the number and distribution of newly added nodes, the density and direction of newly added connection edges, the switching change of the path and the change of the network community structure before and after the detection execution; According to the topology response fingerprint feature, the first application type corresponding to the identified encrypted traffic behavior is identified, comprising: Wherein, the topology response fingerprint feature includes node diffusion feature, edge connection feature, cascading diffusion mode and splicing fingerprint feature of cross-layer linkage feature; The topology response fingerprint feature is compared with the known fingerprint in the known fingerprint feature library to obtain the first application type corresponding to the identified encrypted traffic behavior, wherein the known fingerprint feature library is a mapping database between known fingerprint feature samples and first application types.

2. The method of claim 1, wherein, Analyzing the encrypted traffic dataset to obtain an identified encrypted traffic behavior, comprising: Analyzing an encrypted traffic behavior set of the encrypted traffic dataset; Performing abnormality analysis on each encrypted traffic behavior in the encrypted traffic behavior set, including communication object abnormality, communication mode abnormality, behavior deviation baseline abnormality and TLS authentication abnormality; According to the communication object abnormality, the communication mode abnormality, the behavior deviation baseline abnormality and the TLS authentication abnormality, the abnormality index of each encrypted traffic behavior is calculated and outputted; According to the abnormality index of each encrypted traffic behavior, the encrypted traffic behavior with an abnormality greater than a preset abnormality threshold is identified, and an identified encrypted traffic behavior is outputted.

3. The method of claim 1, wherein, The multi-modal detection triggering module includes at least one detection data packet of different protocol layers, and the protocol layers include a transport layer, a TLS layer and an application layer.

4. The method for encrypted traffic identification based on network topology analysis as claimed in claim 3, wherein, Using a multi-modal detection triggering module to generate a first detection data packet corresponding to the identified encrypted traffic behavior, comprising: extracting initial features of the identified encrypted traffic behavior, including IP port information, system AS number, handshake negotiation parameters, and initial traffic pattern; performing similarity comparison between the initial features and a historical feature library to obtain a candidate probe mode set; performing matching score calculation according to the candidate probe mode set, sorting the candidate probe mode set according to the matching score calculation result, and outputting a priority probe mode; constructing a first probe data packet corresponding to the identified encrypted traffic behavior according to the priority probe mode.

5. The method of claim 4, wherein, The matching score calculation according to the candidate probe mode set comprises: defining a plurality of matching score calculation items, including the historical identification success rate of each candidate probe mode, the protocol compatibility of each candidate probe mode for probing the identified encrypted traffic behavior, and the probing cost of each candidate probe mode for probing the identified encrypted traffic behavior; obtaining a plurality of weight coefficients corresponding to the plurality of matching score calculation items; performing weight calculation on the plurality of matching score calculation items according to the plurality of weight coefficients, obtaining a matching score set corresponding to the candidate probe mode set, and outputting a matching score calculation result.

6. The method of network topology analysis based encrypted traffic identification as claimed in claim 3, wherein, The multi-modal probe triggering module is used to generate a first probe data packet corresponding to the identified encrypted traffic behavior, and also comprises: The multi-modal probe triggering module is used to generate a second probe data packet corresponding to the identified encrypted traffic behavior, and the second probe data packet is a probe data packet composed of a sub-priority probe mode of the first probe data packet; probing the identified encrypted traffic behavior according to the second probe data packet and identifying a second application type corresponding to the identified encrypted traffic behavior; analyzing the second application type and the first application type to output an application type analysis result corresponding to the identified encrypted traffic behavior.

7. A system for encrypted traffic identification based on network topology analysis, characterized in that, The system for implementing the steps of the encrypted traffic identification method based on network topology analysis in any one of claims 1 to 6 comprises: a data acquisition unit for acquiring an encrypted traffic data set of a target network topology; a behavior identification unit for analyzing the encrypted traffic data set to obtain an identified encrypted traffic behavior, wherein the abnormality degree of the identified encrypted traffic behavior is greater than a preset abnormality threshold; a multi-modal probe unit for generating a first probe data packet corresponding to the identified encrypted traffic behavior using a multi-modal probe triggering module, probing the identified encrypted traffic behavior using the first probe data packet, and outputting a differential topology response, which is a differential topology response of the identified encrypted traffic behavior before and after probing based on the target network topology; a fingerprint feature identification unit for extracting a topology response fingerprint feature of the differential topology response, and identifying a first application type corresponding to the identified encrypted traffic behavior according to the topology response fingerprint feature.

Citation Information

Patent Citations

  • Method and system for detecting flow of peer-to-peer network

    CN101753456A

  • Malicious encryption server identification method and system based on active detection

    CN116232702A