A security protection method fusing dynamic flow washing and encryption threat detection

By deploying smart probes and high-precision traffic mirroring technology at network entry points, combined with traffic feature models and global scrubbing nodes, the problems of latency and blind spots in encrypted traffic processing in existing technologies have been solved, achieving efficient encrypted threat detection and scrubbing, and ensuring network security and business smoothness.

CN120956533BActive Publication Date: 2026-02-06SHENZHEN INTERNET PIONEER TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511475914.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-16
Publication Date
2026-02-06
Estimated Expiration
2045-10-16

AI Technical Summary

Technical Problem

Existing technologies require additional decryption devices when processing encrypted traffic, which leads to longer links, increased response delays, and difficulty in dealing with new types of encryption attacks.

Method used

Smart probes are deployed at network entry points to collect inbound traffic. High-precision traffic mirroring technology is used to transmit inbound traffic to the backend protection system. Suspected malicious traffic is classified based on traffic information and feature models, distributed to global cleaning nodes for cleaning, and SSL/TLS encrypted traffic is decrypted and monitored for threats in real time. Finally, the cleaned and secure traffic is sent back to the original server.

Benefits of technology

It enables monitoring of all inbound traffic, preventing encrypted traffic from becoming a security blind spot, reducing resource waste and latency, and ensuring business smoothness and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956533B_ABST
    Figure CN120956533B_ABST
Patent Text Reader

Abstract

The application provides a security protection method fusing dynamic flow cleaning and encryption threat detection, relates to the technical field of information security protection, and realizes the monitoring of all inbound flows by deploying intelligent probes at network entrances to collect inbound flows and transmitting the inbound flows to a rear protection system in real time through high-precision flow mirror technology, realizes flow shunting by classifying the inbound flows based on flow information and flow feature models to obtain suspected malicious flows and normal flows, avoids the great resource waste caused by deep detection and decryption of all flows, obtains clean flow by dispersing the suspected malicious flows to globally distributed cleaning nodes based on a scheduling mechanism for cleaning, and returns the flow to the original server, thereby greatly reducing the delay caused by security protection to user access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security protection technology, and in particular to a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. Background Technology

[0002] With the rapid development of internet technology, network attack methods have become increasingly complex, and DDoS attacks and encrypted traffic threats have become major risks affecting network security. Currently, the industry mostly adopts distributed traffic scrubbing technology based on Anycast architecture for DDoS protection, which disperses attack traffic through global multi-node linkage; for encrypted traffic threat detection, it relies on next-generation firewalls or intrusion detection systems with SSL decryption capabilities.

[0003] However, existing technologies have significant limitations: they still require additional decryption equipment when processing encrypted traffic, leading to longer connection times and increased response latency. Furthermore, existing encryption threat detection solutions are mostly based on rule bases or static feature matching, making them ill-suited to addressing new types of encryption attacks.

[0004] Therefore, there is an urgent need for an integrated protection solution that can deeply integrate dynamic traffic scrubbing and encrypted threat detection to improve real-time performance, accuracy, and system scalability. Summary of the Invention

[0005] This invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection to solve the problems mentioned in the background art.

[0006] A security protection method integrating dynamic traffic scrubbing and encryption threat detection includes:

[0007] S1: Deploy smart probes at the network entry point to collect inbound traffic and transmit the inbound traffic to the backend protection system in real time through high-precision traffic mirroring technology. The inbound traffic includes plaintext traffic and SSL / TLS encrypted traffic.

[0008] S2: Classify inbound traffic based on traffic information and traffic feature models to obtain suspected malicious traffic and normal traffic;

[0009] S3: Distribute suspected malicious traffic to globally distributed cleaning nodes based on a scheduling mechanism to clean the traffic and obtain clean traffic;

[0010] S4: Decrypts SSL / TLS encrypted traffic in real time, performs threat monitoring on the decrypted traffic, removes threat traffic, and obtains secure traffic;

[0011] S5: Returns normal traffic, cleaned traffic, and secure traffic to the origin server.

[0012] Preferably, in step S1, deploying a smart probe at the network entry point to collect inbound traffic includes:

[0013] Based on the network topology, data collection nodes are set up, and smart probes are deployed at the data collection nodes.

[0014] Inbound traffic is obtained by collecting data from inbound devices using smart probes.

[0015] Preferably, in step S2, the inbound traffic is classified based on traffic information and a traffic feature model to obtain suspected malicious traffic and normal traffic, including:

[0016] Based on historical traffic information of malicious traffic, establish a rule engine to identify malicious traffic based on traffic information;

[0017] Based on the rule engine, the inbound traffic is initially identified to obtain the first malicious traffic. The first malicious traffic is then removed from the inbound traffic to obtain the remaining inbound traffic.

[0018] The remaining inbound traffic is input into the traffic feature model to obtain the second malicious traffic and normal traffic;

[0019] Among them, the first malicious traffic and the second malicious traffic constitute suspected malicious traffic.

[0020] Preferably, the remaining inbound traffic is input into a traffic feature model to obtain the second malicious traffic and normal traffic, including:

[0021] Obtain the traffic information of the remaining inbound traffic, and divide the traffic information into category information features and numerical information features;

[0022] A structured gradient boosting tree was selected as the initial model. The initial model was trained based on the historical category information features and historical numerical information features of the historical inbound traffic to obtain the traffic feature model.

[0023] The category information features are input into the width part of the traffic feature model to obtain the first recognition result, and the numerical information features are input into the depth part of the traffic feature model to obtain the second recognition result.

[0024] Based on the first and second identification results, the malice confidence level of the remaining inbound traffic is obtained;

[0025] The remaining inbound traffic with a confidence level greater than the preset first confidence level is selected as the second malicious traffic, the remaining inbound traffic with a confidence level less than the second preset confidence level is selected as normal traffic, and the other traffic is selected as SSL / TLS encrypted traffic.

[0026] Preferably, in step S3, suspected malicious traffic is distributed to globally distributed cleaning nodes based on a scheduling mechanism for cleaning, resulting in cleaned traffic, including:

[0027] Based on the latency, packet loss rate, and jitter between all cleaning nodes and the user's origin server, the node quality factor of each cleaning node is determined, and the resource load factor of each cleaning node is determined based on the current CPU, memory, and bandwidth utilization of each cleaning node. Based on the node quality factor and the resource load factor, a basic score for each cleaning node is obtained, and cleaning nodes with a basic score greater than the preset score are selected as candidate cleaning nodes.

[0028] Obtain the cleaning scripts of the candidate cleaning nodes, determine the cleaning type that the cleaning scripts match based on historical cleaning data, and obtain the bandwidth cost of the candidate cleaning nodes. Based on the traffic type and initial location of the suspected malicious traffic, match it with the cleaning type and node location of the candidate cleaning nodes to obtain a targeted matching score. Select the candidate cleaning nodes with a targeted matching score greater than the preset score as intermediate cleaning nodes, and select the intermediate cleaning node with the lowest bandwidth cost as the optimal cleaning node.

[0029] Based on the location information of suspected malicious traffic and the optimal cleaning node, the transmission path between the suspected malicious traffic and the optimal cleaning node is selected from the candidate cleaning nodes.

[0030] After inserting a very small unique fragment into the IP packet header of the suspected malicious traffic, the suspected malicious traffic is transmitted through the transmission path to the optimal cleaning node for cleaning, resulting in cleaned traffic.

[0031] Preferably, the interaction of all cleaning nodes is as follows:

[0032] When a cleaning node is cleaning suspected malicious traffic, it will send the cleaning status to other cleaning nodes within seconds through a high-speed internal channel to reach a consensus on the suspected malicious traffic.

[0033] The node status and operation of all cleaning nodes are shared. When a cleaning node malfunctions, an optimal replacement cleaning node is quickly matched to take over the cleaning work based on the information sharing.

[0034] Preferably, in step S4, the SSL / TLS encrypted traffic is decrypted in real time, and the decrypted traffic is subjected to threat monitoring to remove threat traffic and obtain secure traffic, including:

[0035] The SSL / TLS encrypted traffic is decrypted in real time based on a preset hardware acceleration decryption module to obtain decrypted traffic;

[0036] The decryption traffic is subjected to in-depth analysis to identify threat traffic and security traffic, and threat traffic is removed.

[0037] Preferably, the decryption traffic is subjected to in-depth analysis to identify threat traffic and security traffic within the decryption traffic, including:

[0038] Based on historical decrypted traffic, the initial deep learning model is trained to obtain a traffic deep recognition model;

[0039] And according to the preset cycle, combined with the latest historical decrypted traffic, the traffic deep identification model is optimized to obtain the latest traffic deep identification model;

[0040] The decrypted traffic is input into the latest traffic deep identification model to identify threat traffic and security traffic.

[0041] Preferably, in step S5, returning normal traffic, cleaned traffic, and secure traffic to the origin server includes:

[0042] Normal traffic is directly connected to the origin queue. The cleaned traffic is validated for legality based on the cleaned traffic log digest. Once validated, it is added to the origin queue. The security traffic is validated for legality based on the security traffic decryption log digest. Once validated, it is added to the origin queue.

[0043] Normal traffic, cleaned traffic, and safe traffic in the source queue are categorized by type. Based on the type categorization results, the source nodes that meet the criteria for normal traffic, cleaned traffic, and safe traffic are determined.

[0044] Based on the pre-trained network state prediction model, the back-source nodes are identified, the predicted network state is determined, and based on the predicted network state, an initial back-source path composed of back-source nodes is generated according to the minimum latency standard for normal traffic, cleaned traffic, and safe traffic.

[0045] Based on the initial back-to-origin path, normal traffic, cleaned traffic, and safe traffic are backed to the origin, and the real-time network status of the back-to-origin path is obtained. When the real-time network status does not meet the back-to-origin requirements, an adaptive compression and encoding mechanism is activated to compress and encode normal traffic, cleaned traffic, and safe traffic before backing to the origin.

[0046] When the adaptive compression and encoding mechanism is activated, if the initial back-to-origin path still cannot meet the low-latency requirements, the initial back-to-origin path is adaptively adjusted based on the location and network status of other back-to-origin nodes to obtain a dynamic back-to-origin path. Normal traffic, cleaned traffic, and secure traffic are then routed back to the original server according to the dynamic back-to-origin path.

[0047] Preferably, based on the type labeling results, the source nodes that meet the requirements of normal flow, cleaned flow, and safe flow are determined, including:

[0048] Configure a normal origin node for normal traffic;

[0049] Configure a back-to-origin node with verification functionality to clean up the traffic;

[0050] Configure an origin node with encryption for secure traffic.

[0051] Compared with the prior art, the present invention has achieved the following beneficial effects:

[0052] By deploying smart probes at the network entry point to collect inbound traffic and transmitting it in real-time to the backend protection system using high-precision traffic mirroring technology, monitoring of all inbound traffic—including plaintext and SSL / TLS encrypted traffic—is achieved. This eliminates the distinction based on whether traffic is encrypted or not, solving the critical problem of encrypted traffic becoming a security blind spot in traditional solutions. Inbound traffic is categorized based on traffic information and traffic characteristic models to identify suspected malicious and normal traffic, achieving traffic diversion. Only suspected malicious traffic needs to be sent to an expensive scrubbing cluster, and only encrypted traffic requires resource decryption. Normal traffic is directly and quickly routed back to the origin server, avoiding the huge resource waste caused by deep inspection and decryption of all traffic. By distributing suspected malicious traffic to globally distributed cleaning nodes based on a scheduling mechanism, clean traffic is obtained. SSL / TLS encrypted traffic is decrypted in real time, and threat detection is performed on the decrypted traffic to remove threat traffic and obtain safe traffic. This avoids the huge latency and performance bottlenecks caused by traditional serial processing. Finally, normal traffic, clean traffic, and safe traffic are routed back to the original server, minimizing the additional latency caused by security measures to normal user access and ensuring the smoothness and availability of business operations.

[0053] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in this application.

[0054] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0055] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0056] Figure 1 This is a flowchart of a security protection method that integrates dynamic traffic scrubbing and encryption threat detection in an embodiment of the present invention;

[0057] Figure 2 This is a flowchart of inbound traffic collection in an embodiment of the present invention;

[0058] Figure 3 This is a flowchart illustrating the safe flow rate obtained in an embodiment of the present invention. Detailed Implementation

[0059] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0060] Example 1:

[0061] This invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection, such as... Figure 1 As shown, it includes:

[0062] S1: Deploy smart probes at the network entry point to collect inbound traffic and transmit the inbound traffic to the backend protection system in real time through high-precision traffic mirroring technology. The inbound traffic includes plaintext traffic and SSL / TLS encrypted traffic.

[0063] S2: Classify inbound traffic based on traffic information and traffic feature models to obtain suspected malicious traffic and normal traffic;

[0064] S3: Distribute suspected malicious traffic to globally distributed cleaning nodes based on a scheduling mechanism to clean the traffic and obtain clean traffic;

[0065] S4: Decrypts SSL / TLS encrypted traffic in real time, performs threat monitoring on the decrypted traffic, removes threat traffic, and obtains secure traffic;

[0066] S5: Returns normal traffic, cleaned traffic, and secure traffic to the origin server.

[0067] In this embodiment, traffic information includes traffic characteristics, protocol type, source IP reputation database, etc.

[0068] In this embodiment, the scheduling mechanism is, for example, the Anycast scheduling mechanism.

[0069] In this embodiment, inbound traffic is classified based on traffic information and traffic feature models to obtain suspected malicious traffic and normal traffic. Suspected malicious traffic is then distributed to globally distributed cleaning nodes based on a scheduling mechanism for cleaning, resulting in cleaned traffic that is processed in parallel.

[0070] The beneficial effects of the above design scheme are as follows: By deploying smart probes at the network entry point to collect inbound traffic and transmitting it to the backend protection system in real time using high-precision traffic mirroring technology, the inbound traffic, including both plaintext and SSL / TLS encrypted traffic, achieves monitoring of all inbound traffic. It eliminates the distinction based on whether traffic is encrypted or not, solving the key problem of encrypted traffic becoming a security blind spot in traditional solutions. By classifying inbound traffic based on traffic information and traffic characteristic models, it identifies suspected malicious traffic and normal traffic, achieving traffic diversion. Only suspected malicious traffic needs to be sent to an expensive scrubbing cluster, and only encrypted traffic requires resource decryption. Normal traffic is directly and quickly routed back to the origin server, avoiding the huge resource waste caused by deep inspection and decryption of all traffic. By distributing suspected malicious traffic to globally distributed cleaning nodes based on a scheduling mechanism, clean traffic is obtained. SSL / TLS encrypted traffic is decrypted in real time, and threat detection is performed on the decrypted traffic to remove threat traffic and obtain safe traffic. This avoids the huge latency and performance bottlenecks caused by traditional serial processing. Finally, normal traffic, clean traffic, and safe traffic are routed back to the original server, minimizing the additional latency caused by security measures to normal user access and ensuring the smoothness and availability of business operations.

[0071] Example 2:

[0072] Based on Example 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection, such as... Figure 2 As shown, in step S1, deploying a smart probe at the network entry point to collect inbound traffic includes:

[0073] Based on the network topology, data collection nodes are set up, and smart probes are deployed at the data collection nodes.

[0074] Inbound traffic is obtained by collecting data from inbound devices using smart probes.

[0075] The beneficial effects of the above design scheme are as follows: Based on the network topology, a collection node is set, and a smart probe is deployed at the collection node. The data of the inbound station is collected based on the smart probe to obtain the inbound traffic. The deployment of the smart probe covers all the necessary paths of the inbound traffic, ensuring that no traffic is missed, and realizing comprehensive collection of inbound traffic.

[0076] Example 3:

[0077] Based on Embodiment 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. In step S2, inbound traffic is classified based on traffic information and a traffic feature model to obtain suspected malicious traffic and normal traffic, including:

[0078] Based on historical traffic information of malicious traffic, establish a rule engine to identify malicious traffic based on traffic information;

[0079] Based on the rule engine, the inbound traffic is initially identified to obtain the first malicious traffic. The first malicious traffic is then removed from the inbound traffic to obtain the remaining inbound traffic.

[0080] The remaining inbound traffic is input into the traffic feature model to obtain the second malicious traffic and normal traffic;

[0081] Among them, the first malicious traffic and the second malicious traffic constitute suspected malicious traffic.

[0082] In this embodiment, the first malicious traffic is suspected malicious traffic with a high probability, and the second malicious traffic is suspected malicious traffic with a relatively high probability.

[0083] The beneficial effects of the above design scheme are as follows: by first performing preliminary screening of inbound traffic based on the rule engine and then further screening in the input traffic feature model, most of the traffic is processed by the rule engine, while a small portion of the traffic is processed by the model, reducing processing latency, improving processing efficiency, and achieving traffic diversion. Only suspected malicious traffic needs to be sent to the expensive cleaning cluster, only encrypted traffic needs to consume resources for decryption, and normal traffic is directly and quickly returned to the origin, avoiding the huge waste of resources caused by performing deep detection and decryption on all traffic.

[0084] Example 4:

[0085] Based on Embodiment 3, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. The remaining inbound traffic is input into a traffic feature model to obtain second malicious traffic and normal traffic, including:

[0086] Obtain the traffic information of the remaining inbound traffic, and divide the traffic information into category information features and numerical information features;

[0087] A structured gradient boosting tree was selected as the initial model. The initial model was trained based on the historical category information features and historical numerical information features of the historical inbound traffic to obtain the traffic feature model.

[0088] The category information features are input into the width part of the traffic feature model to obtain the first recognition result, and the numerical information features are input into the depth part of the traffic feature model to obtain the second recognition result.

[0089] Based on the first and second identification results, the malice confidence level of the remaining inbound traffic is obtained;

[0090] The remaining inbound traffic with a confidence level greater than the preset first confidence level is selected as the second malicious traffic, the remaining inbound traffic with a confidence level less than the second preset confidence level is selected as normal traffic, and the other traffic is selected as SSL / TLS encrypted traffic.

[0091] In this embodiment, the category feature information includes IP address, TLS version number, protocol type, etc., and the numerical feature information includes entropy value, rate, and ratio.

[0092] In this embodiment, the first confidence level is greater than the second confidence level.

[0093] In this embodiment, after the SSL / TLS encrypted traffic is identified, it will be transferred to S4 for decryption.

[0094] In this embodiment, the structured gradient boosting tree model is feature-friendly, has extremely fast inference speed, and high accuracy, making it very suitable for classification tasks involving such structured data.

[0095] In this embodiment, the width portion is used to memorize uncommon but deterministic patterns that the rule engine cannot cover, while the depth portion is a very shallow neural network with only 2-3 layers, responsible for learning deep interactions and abstract representations of features, and discovering unknown and variant attack patterns.

[0096] The advantages of the above design are: by using a lightweight gradient boosting tree as the initial model, the processing speed of traffic is guaranteed; at the same time, both depth and width components are designed to specifically identify different information features; the outputs of the two components are finally fused to make a joint decision. This structure combines the advantages of memory and generalization, making it more powerful and robust than a single model, ensuring recognition accuracy, and ultimately achieving a dual balance between traffic recognition speed and efficiency.

[0097] Example 5:

[0098] Based on Embodiment 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. In step S3, suspected malicious traffic is distributed to globally distributed scrubbing nodes based on a scheduling mechanism for scrubbing to obtain cleaned traffic, including:

[0099] Based on the latency, packet loss rate, and jitter between all cleaning nodes and the user's origin server, the node quality factor of each cleaning node is determined, and the resource load factor of each cleaning node is determined based on the current CPU, memory, and bandwidth utilization of each cleaning node. Based on the node quality factor and the resource load factor, a basic score for each cleaning node is obtained, and cleaning nodes with a basic score greater than the preset score are selected as candidate cleaning nodes.

[0100] Obtain the cleaning scripts of the candidate cleaning nodes, determine the cleaning type that the cleaning scripts match based on historical cleaning data, and obtain the bandwidth cost of the candidate cleaning nodes. Based on the traffic type and initial location of the suspected malicious traffic, match it with the cleaning type and node location of the candidate cleaning nodes to obtain a targeted matching score. Select the candidate cleaning nodes with a targeted matching score greater than the preset score as intermediate cleaning nodes, and select the intermediate cleaning node with the lowest bandwidth cost as the optimal cleaning node.

[0101] Based on the location information of suspected malicious traffic and the optimal cleaning node, the transmission path between the suspected malicious traffic and the optimal cleaning node is selected from the candidate cleaning nodes.

[0102] After inserting a very small unique fragment into the IP packet header of the suspected malicious traffic, the suspected malicious traffic is transmitted through the transmission path to the optimal cleaning node for cleaning, resulting in cleaned traffic.

[0103] In this embodiment, after inserting a very small unique fragment into the IP packet header of the suspected malicious traffic, the suspected malicious traffic is transmitted to the optimal cleaning node through the transmission path for cleaning. This achieves the accurate, hop-by-hop delivery of the suspected malicious traffic to the designated cleaning node through the predetermined path, and facilitates the return of the traffic to its source.

[0104] The beneficial effects of the above design scheme are as follows: By determining the node quality factor of each cleaning node based on the latency, packet loss rate, and jitter between all cleaning nodes and the user's origin server, it ensures that the cleaned traffic can return to the user's origin server through a high-quality, low-latency, and stable path, guaranteeing the access speed and service continuity for normal users. This achieves security protection without compromising user experience. Furthermore, by determining the resource load factor of each cleaning node based on its current CPU, memory, and bandwidth utilization, it effectively avoids the situation in traditional scheduling where all traffic is scheduled to one or two of the best-performing nodes, leading to overload and crashes. The combination of these two approaches provides a fundamental guarantee for traffic cleaning. The system first establishes a cleaning environment and then obtains cleaning scripts for candidate cleaning nodes. Based on historical cleaning data, it determines the cleaning type that the cleaning scripts should match, improving the efficiency and accuracy of cleaning. It can remove specific types of attacks more thoroughly with less resource consumption, reducing the probability of mistakenly killing normal traffic. By selecting the intermediate cleaning node with the lowest bandwidth cost as the optimal cleaning node, it intelligently selects the area with the lower cost for processing while ensuring performance and security. This can save operators huge bandwidth costs, directly improving the cost-effectiveness and market competitiveness of the product. Traffic can be accurately guided to the designated optimal cleaning node, achieving fast, efficient, and accurate cleaning of suspected malicious traffic.

[0105] Example 6:

[0106] Based on Example 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. The interaction of all scrubbing nodes is as follows:

[0107] When a cleaning node is cleaning suspected malicious traffic, it will send the cleaning status to other cleaning nodes within seconds through a high-speed internal channel to reach a consensus on the suspected malicious traffic.

[0108] The node status and operation of all cleaning nodes are shared. When a cleaning node malfunctions, an optimal replacement cleaning node is quickly matched to take over the cleaning work based on the information sharing.

[0109] The beneficial effects of the above design scheme are as follows: When a cleaning node is cleaning suspected malicious traffic, it sends the cleaning status to other cleaning nodes within seconds through a high-speed internal channel, achieving consensus on suspected malicious traffic and enabling all nodes to quickly identify malicious traffic, thus improving the efficiency of secondary identification. By sharing the node status and operation status among all cleaning nodes, when a cleaning node malfunctions, an optimal backup cleaning node is quickly matched to take over the cleaning work based on information sharing, realizing collaborative work among cleaning nodes and better completing the cleaning of suspected malicious traffic.

[0110] Example 7:

[0111] Based on Example 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection, such as... Figure 3 As shown, in step S4, the SSL / TLS encrypted traffic is decrypted in real time, and the decrypted traffic is subjected to threat monitoring to remove threat traffic and obtain secure traffic, including:

[0112] The SSL / TLS encrypted traffic is decrypted in real time based on a preset hardware acceleration decryption module to obtain decrypted traffic;

[0113] The decryption traffic is subjected to in-depth analysis to identify threat traffic and security traffic, and threat traffic is removed.

[0114] The beneficial effects of the above design scheme are: by decrypting SSL / TLS encrypted traffic in real time and performing threat monitoring on the decrypted traffic to remove threat traffic and obtain secure traffic, the decryption and identification of SSL / TLS encrypted traffic is realized, providing a foundation for security protection.

[0115] Example 8:

[0116] Based on Embodiment 7, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection, performing in-depth analysis of the decrypted traffic to identify threat traffic and secure traffic within the decrypted traffic, including:

[0117] Based on historical decrypted traffic, the initial deep learning model is trained to obtain a traffic deep recognition model;

[0118] And according to the preset cycle, combined with the latest historical decrypted traffic, the traffic deep identification model is optimized to obtain the latest traffic deep identification model;

[0119] The decrypted traffic is input into the latest traffic deep identification model to identify threat traffic and security traffic.

[0120] The beneficial effects of the above design scheme are: by inputting decrypted traffic into the latest traffic deep identification model, threat traffic and security traffic can be identified, achieving accurate classification and identification of decrypted traffic, and providing a foundation for security protection.

[0121] Example 9:

[0122] Based on Embodiment 1, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. In step S5, normal traffic, cleaned traffic, and secure traffic are routed back to the original server, including:

[0123] Normal traffic is directly connected to the origin queue. The cleaned traffic is validated for legality based on the cleaned traffic log digest. Once validated, it is added to the origin queue. The security traffic is validated for legality based on the security traffic decryption log digest. Once validated, it is added to the origin queue.

[0124] Normal traffic, cleaned traffic, and safe traffic in the source queue are categorized by type. Based on the type categorization results, the source nodes that meet the criteria for normal traffic, cleaned traffic, and safe traffic are determined.

[0125] Based on the pre-trained network state prediction model, the back-source nodes are identified, the predicted network state is determined, and based on the predicted network state, an initial back-source path composed of back-source nodes is generated according to the minimum latency standard for normal traffic, cleaned traffic, and safe traffic.

[0126] Based on the initial back-to-origin path, normal traffic, cleaned traffic, and safe traffic are backed to the origin, and the real-time network status of the back-to-origin path is obtained. When the real-time network status does not meet the back-to-origin requirements, an adaptive compression and encoding mechanism is activated to compress and encode normal traffic, cleaned traffic, and safe traffic before backing to the origin.

[0127] When the adaptive compression and encoding mechanism is activated, if the initial back-to-origin path still cannot meet the low-latency requirements, the initial back-to-origin path is adaptively adjusted based on the location and network status of other back-to-origin nodes to obtain a dynamic back-to-origin path. Normal traffic, cleaned traffic, and secure traffic are then routed back to the original server according to the dynamic back-to-origin path.

[0128] In this embodiment, the network state prediction model is obtained by pre-training a machine model based on the historical network parameters of the source node.

[0129] The beneficial effects of the above design scheme are as follows: By directly connecting normal traffic to the origin queue, the legitimacy of cleaned traffic is verified based on the cleaned traffic log digest. Once verified, it is added to the origin queue. Similarly, the legitimacy of secure traffic is verified based on the decryption log digest. Cleaned traffic carries the cleaned log digest, and secure traffic carries the decryption log digest. The origin server does not need to re-execute the complete cleansing or decryption process; traffic legitimacy can be confirmed simply by verifying the digests, reducing computational resource consumption and ensuring traffic legitimacy. Through type tagging, traffic of different types can be allocated to appropriate origin nodes, ensuring the security and speed of the origin process. With minimal latency as the standard, latency-sensitive traffic such as normal and secure traffic is given priority access to the optimal path, improving the business experience. When the real-time status does not meet the requirements for back-to-origin communication, the system reduces the amount of data transmitted through compression encoding, maintaining the continuity of back-to-origin communication in bandwidth-constrained scenarios. The adaptive mechanism can adjust the compression strategy according to the traffic type, avoiding data distortion or parsing anomalies caused by over-compression. The compressed traffic is less sensitive to network jitter, enabling more stable transmission in complex network environments and reducing the number of retransmissions. When compression encoding still cannot meet the low-latency requirements, the system dynamically switches to a better path by sensing the location and network status of other nodes in real time, avoiding back-to-origin interruptions caused by single link failures. The path adjustment comprehensively considers the status of all nodes in the network, rather than being limited to local links, making traffic distribution more in line with the load balancing of global network resources. This minimizes the additional latency caused by security protection measures to normal user access, ensuring the smoothness and availability of services.

[0130] Example 10:

[0131] Based on Embodiment 9, this embodiment of the invention provides a security protection method that integrates dynamic traffic scrubbing and encryption threat detection. According to the type labeling results, it determines the source node that meets the criteria for normal traffic, cleaned traffic, and secure traffic, including:

[0132] Configure a normal origin node for normal traffic;

[0133] Configure a back-to-origin node with verification functionality to clean up the traffic;

[0134] Configure an origin node with encryption for secure traffic.

[0135] The beneficial effects of the above design scheme are: by using type marking, traffic of different types can be allocated to suitable origin nodes, ensuring the security and speed of the origin return process.

[0136] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of this application and its equivalents, this invention also intends to include these modifications and variations.

Claims

1. A security protection method of fusing dynamic traffic washing and encryption threat detection, characterized in that, The application comprises: S1: deploying intelligent probes at the network entrance for inbound traffic collection, and transmitting the inbound traffic to the backend protection system in real time through high-precision traffic mirroring technology, the inbound traffic including plaintext traffic and SSL / TLS encrypted traffic; S2: classifying the inbound traffic based on traffic information and a traffic feature model to obtain suspected malicious traffic and normal traffic, comprising: establishing a rule engine for identifying malicious traffic based on traffic information based on historical malicious traffic historical traffic information; preliminarily identifying the inbound traffic based on the rule engine to obtain first malicious traffic, and removing the first malicious traffic from the inbound traffic to obtain remaining inbound traffic; inputting the remaining inbound traffic into the traffic feature model to obtain second malicious traffic and normal traffic; wherein the first malicious traffic and the second malicious traffic constitute the suspected malicious traffic; wherein inputting the remaining inbound traffic into the traffic feature model to obtain the second malicious traffic and the normal traffic comprises: obtaining traffic information of the remaining inbound traffic, and dividing the traffic information into category information features and numerical information features; selecting a structured gradient boosting tree as an initial model, training the initial model based on historical category information features and historical numerical information features of historical inbound traffic to obtain a traffic feature model; inputting the category information features into the width part of the traffic feature model to obtain a first identification result, and inputting the numerical information features into the depth part of the traffic feature model to obtain a second identification result; obtaining a malicious confidence of the remaining inbound traffic based on the first identification result and the second identification result; selecting the remaining inbound traffic with a confidence greater than a preset first confidence as the second malicious traffic, the remaining inbound traffic with a confidence less than a second preset confidence as the normal traffic, and other traffic as SSL / TLS encrypted traffic; S3: dispersing the suspected malicious traffic to globally distributed cleaning nodes based on a scheduling mechanism for cleaning to obtain clean traffic; S4: performing real-time decryption on the SSL / TLS encrypted traffic, and performing threat monitoring on the decrypted traffic to remove threat traffic to obtain safe traffic; S5: returning the normal traffic, the clean traffic and the safe traffic to the original server.

2. The method of claim 1, wherein the method further comprises: In S1, the intelligent probes are deployed at the network entrance for inbound traffic collection, comprising: based on the network topology, setting a collection node, and deploying intelligent probes at the collection node; based on the intelligent probes, collecting inbound data to obtain inbound traffic.

3. The method of claim 1, wherein the method further comprises: In S3, the suspected malicious traffic is dispersed to globally distributed cleaning nodes based on a scheduling mechanism for cleaning to obtain clean traffic, comprising: based on the delay, packet loss rate and jitter between all cleaning nodes and user source stations, determining a node quality factor of each cleaning node, and based on the current CPU, memory and bandwidth utilization of each cleaning node, determining a resource load factor of each cleaning node, based on the node quality factor and the resource load factor, obtaining a basic score of each cleaning node, and selecting a cleaning node with a basic score greater than a preset score as a candidate cleaning node; Obtain a cleaning script of the alternative cleaning node, determine a cleaning type matched with the cleaning script based on historical cleaning data, and obtain a bandwidth cost of the alternative cleaning node, match the traffic type and the initial position of the suspected malicious traffic with the cleaning type and the node position of the alternative cleaning node to obtain a targeted matching score, select the alternative cleaning node with a targeted matching score greater than a preset score as an intermediate cleaning node, and select the intermediate cleaning node with the lowest bandwidth cost as an optimal cleaning node; Based on the position information of the suspected malicious traffic and the optimal cleaning node, a transmission path between the suspected malicious traffic and the optimal cleaning node is selected from the alternative cleaning nodes; After inserting a unique small segment into the IP header of the suspected malicious traffic, the suspected malicious traffic is transmitted to the optimal cleaning node through the transmission path for cleaning to obtain clean traffic.

4. The method of claim 3, wherein the method further comprises: The interactions of all cleaning nodes are as follows: When a cleaning node is cleaning suspected malicious traffic, it will send the cleaning situation to other cleaning nodes through a high-speed internal channel within seconds, and the suspected malicious traffic is consensus; The node state and node running condition of all cleaning nodes are information sharing, and when an abnormal cleaning node occurs, an optimal substitute cleaning node is quickly matched based on information sharing to replace the cleaning work.

5. The method of claim 1, wherein the method further comprises: In S4, the SSL / TLS encrypted traffic is decrypted in real time, and the decrypted traffic is monitored for threats, and the threat traffic is removed to obtain safe traffic, including: The SSL / TLS encrypted traffic is decrypted in real time based on a preset hardware acceleration decryption module to obtain decrypted traffic; Deep analysis is performed on the decrypted traffic to identify threat traffic and safe traffic in the decrypted traffic, and the threat traffic is removed.

6. The method of claim 5, wherein the method further comprises: Deep analysis is performed on the decrypted traffic to identify threat traffic and safe traffic in the decrypted traffic, including: Based on historical decrypted traffic, an initial deep learning model is trained to obtain a traffic deep identification model; And according to a preset period, the traffic deep identification model is optimized in combination with the latest historical decrypted traffic to obtain the latest traffic deep identification model; The decrypted traffic is input into the latest traffic deep identification model to identify threat traffic and safe traffic.

7. The method of claim 1, wherein the method further comprises: In S5, the normal traffic, clean traffic and safe traffic are returned to the original server, including: The normal traffic is directly connected to the return queue, the legality of the clean traffic is verified based on the cleaning log summary of the clean traffic, and the safe traffic is verified based on the decryption log summary of the safe traffic after passing the verification, and then added to the return queue; The normal traffic, clean traffic and safe traffic in the return queue are respectively marked by type, and the return nodes meeting the normal traffic, clean traffic and safe traffic are determined according to the type marking results; Based on the pre-trained network state prediction model, the return nodes are identified to determine the predicted network state, and the initial return path composed of the return nodes is generated for the normal traffic, clean traffic and safe traffic according to the least delay standard based on the predicted network state; Based on the initial back-to-source path, normal traffic, clean traffic and security traffic are back to source, and the real-time network state of the back-to-source path is obtained. When the real-time network state does not meet the back-to-source demand, an adaptive compression and encoding mechanism is started to compress and encode the normal traffic, clean traffic and security traffic before back to source; When the adaptive compression and encoding mechanism is started, the initial back-to-source path still cannot meet the low delay demand. Based on the location and network state of other back-to-source nodes, the initial back-to-source path is adjusted adaptively to obtain a dynamic back-to-source path. The normal traffic, clean traffic and security traffic are back to the original server according to the dynamic back-to-source path.

8. The method of claim 7, wherein the method further comprises: According to the type marking result, the back-to-source node meeting the normal traffic, clean traffic and security traffic is determined, including: Normal traffic is configured with a common back-to-source node; The clean traffic is configured with a back-to-source node with verification function; The security traffic is configured with a back-to-source node with encryption function.

Citation Information

Patent Citations

  • Encrypted traffic classification method based on deep learning

    CN118449912A

  • Malicious traffic classification and identification method, system and device based on graph convolutional neural network, and medium

    CN119172143A