Network traffic obfuscation processing method, system and device based on traffic simulation, medium and product

By dynamically generating and filtering simulated traffic, the problems of easy identification of traffic characteristics and increased load in existing technologies are solved, achieving high security and low-impact obfuscation processing of network traffic.

CN121664686APending Publication Date: 2026-03-13NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-18
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

In existing network traffic obfuscation techniques, the low similarity of extra traffic characteristics makes it easy for attackers to identify. However, adding too much extra traffic increases the line load, and the receiver's inability to filter the extra traffic affects upper-layer applications.

Method used

The traffic feature configuration module generates dynamic simulated traffic, which, combined with the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module, enables the diversity and variability of traffic features, ensuring that normal business flows pass through first and filtering additional traffic at the receiving end.

Benefits of technology

It improves the similarity between simulated traffic and real data, reduces the difficulty of identifying additional traffic, minimizes the negative impact on the network, and achieves effective masking and transparent filtering of traffic characteristics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664686A_ABST
    Figure CN121664686A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network communication, and provides a network traffic confusion processing method, system and device based on traffic simulation, a medium and a product, a traffic feature configuration module receives configuration information from an upper layer system and distributes the configuration information to other modules; the real-time monitoring and adjusting module circularly calculates the total amount of additional flow needing to be added and sends the total amount to the additional flow simulation module; the additional flow simulation module generates an additional flow data packet needing to be added in each time slot according to the total amount of additional flow needing to be added, and sends the additional flow data packet to the flow decision and scrambling module; the traffic decision-making and scrambling module monitors a normal service flow and an additional traffic data packet in real time; and the traffic descrambling and filtering module performs type identification on the received traffic data and filters additional traffic. According to the invention, network traffic confusion is realized through a traffic simulation technology, network traffic characteristics can be fully masked, and negative effects generated by additional traffic are greatly reduced on the premise of good security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication technology, and more specifically, to a method, system, device, medium, and product for network traffic obfuscation processing based on traffic simulation. Background Technology

[0002] In today's digital age, network communication has become a crucial support for social operation and business functioning. Currently, mainstream network communication security technologies primarily focus on data content encryption, ensuring the confidentiality and integrity of information transmission and preventing data theft or tampering during transmission. However, in special network environments that carry and transmit important and sensitive information, simply protecting the confidentiality of data content is far from sufficient. These networks also require additional protection for network traffic characteristics, including traffic volume, transmission frequency, data intervals, and bandwidth usage. Although these traffic characteristics themselves cannot directly reveal the specific content of the data, their changing patterns accurately reflect the operational status of specific services or security software. Once attackers obtain this critical information, they may launch attacks at critical moments, causing irreparable damage to critical business operations.

[0003] Current technologies for protecting network traffic and bandwidth usage characteristics primarily involve obfuscating traffic by inserting extra traffic into normal traffic. However, practical applications have revealed several problems with this approach: First, the inserted extra traffic features are relatively simple, containing only limited information such as packet count, packet length, traffic volume, and bandwidth. This simplistic pattern makes it easy for attackers to distinguish between important and extra traffic through feature analysis. Second, existing technologies only send the extra traffic to the external network at the sender's end, without fully considering the potential interference to the receiver's services. This one-sided traffic insertion method may adversely affect the overall network operation. Finally, existing technologies employ a uniform approach to masking all traffic. Since this requires masking the entire network's traffic, a large traffic threshold is necessary. This not only increases network load but may also lead to link overload and impact network performance. This technical solution has significant limitations in practical applications and requires further improvement and refinement. Summary of the Invention

[0004] This invention aims to provide a network traffic obfuscation processing method, system, device, medium, and product based on traffic simulation, to solve the following problems: 1. Extra traffic has low similarity to important data characteristics, making it easy for attackers to identify; 2. In order to achieve sufficient traffic obfuscation, too much extra traffic was added, resulting in an excessive increase in line load; 3. The receiving end cannot filter the extra traffic, so it will send the extra traffic to the upper layer application, which will increase the processing burden of the upper layer application and has a certain risk of misidentification.

[0005] In a first aspect, the present invention provides a network traffic obfuscation processing method based on traffic simulation, comprising: The traffic feature configuration module receives configuration information from the upper layer system and distributes the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. The real-time monitoring and adjustment module continuously calculates the total amount of additional traffic needed and sends the total amount of additional traffic needed to the additional traffic simulation module. The additional traffic simulation module generates additional traffic data packets to be added in each time interval according to the total amount of additional traffic to be added, and sends the additional traffic data packets to the traffic decision and scrambling module; The traffic decision and scrambling module monitors normal traffic flow and additional traffic data packets in real time, and ensures that normal traffic flow has priority. The traffic descrambling and filtering module identifies the type of the received traffic data and filters out extra traffic.

[0006] In a preferred embodiment, the processing flow of the traffic feature configuration module includes: Receive configuration information from the upper layer system; the configuration information includes Layer 2 protocol information, Layer 3 protocol information, maximum packet length, minimum packet length, location of additional traffic feature value, location of additional traffic feature value, location of additional traffic feature mask, preset important information masking traffic, and data monitoring time slot interval; The location of the extra traffic feature value, the extra traffic feature value, and the location of the extra traffic feature mask are combined into an outbound extra traffic configuration packet and sent to the external integrated network. The configuration information required for generating additional traffic is sent to the additional traffic simulation module; the configuration information required for generating additional traffic includes maximum packet length, minimum packet length, additional traffic feature location, additional traffic feature value, Layer 2 protocol information, and Layer 3 protocol information; Important information is masked by the preset traffic flow and data monitoring time slot intervals and sent to the real-time monitoring and adjustment module. Send the locations of additional traffic feature values ​​and additional traffic feature masks to the traffic decision and scrambling module; When acting as a receiver, it receives additional traffic configuration packets from an external integrated network, obtains the location of additional traffic feature values, additional traffic feature values, and additional traffic feature mask locations of incoming data, and sends them to the traffic descrambling and filtering module.

[0007] In a preferred embodiment, the single-process flow of the real-time monitoring and adjustment module includes: Receiving important information masks traffic presets and data monitoring time slot intervals; Collect important data traffic from the internal integrated network, and calculate the size of important data traffic within a unit time slot based on the data monitoring time slot interval; Based on the important information masking traffic preset and the important data traffic size of the current time slot, calculate the total amount of additional traffic that needs to be added in the next time slot; The calculated total amount of additional traffic is sent to the additional traffic simulation module via an internal interface.

[0008] In a preferred embodiment, the processing flow of the additional traffic simulation module in each time interval includes: Based on the total amount of additional traffic to be received, generate a random packet length between the maximum and minimum packet lengths. Based on the random packet length, virtual extra traffic data packets are constructed using the extra traffic feature location, extra traffic feature value, Layer 2 protocol information, and Layer 3 protocol information as traffic features. When the traffic decision and scrambling module allows the reception of additional traffic, the additional traffic data packets are sent to the traffic decision and scrambling module. After each successful transmission of a virtual extra traffic data packet, the total amount of extra traffic already transmitted is subtracted from the total amount of extra traffic to be added. When the total amount decreases to less than or equal to zero, the extra traffic generation operation in the current time slot is stopped.

[0009] In a preferred embodiment, the processing flow of the traffic decision and scrambling module includes: Determine whether there is a normal business flow being sent or waiting to be sent in the normal business flow interface. If there is no normal business flow being sent, allow the extra traffic simulation module to send extra traffic. Upon receiving the extra traffic data packet, extract the extra traffic feature value and the extra traffic mask value based on the extra traffic feature location and the extra traffic feature mask location; The extra traffic feature value is scrambled using an extra traffic mask value; The scrambled additional traffic feature values ​​are then refilled into the additional traffic data packets; Send the processed additional traffic packets to the external integrated network; If a normal service flow needs to be sent when an extra traffic data packet is already in the sending state, the normal service flow should be buffered first, and the normal service flow data packet should be sent only after the current extra traffic data packet has been sent.

[0010] In a preferred embodiment, the processing flow of the traffic descrambling and filtering module includes: Receive data packets from an external integrated network, and extract additional traffic feature values ​​and additional traffic mask values ​​based on the additional traffic feature location and additional traffic feature mask location in the configuration information; The extra traffic feature value is descrambled using an extra traffic mask value. The descrambled extra traffic feature value is then compared with the extra traffic feature value in the configuration information. If they match, the received data packet is determined to be extra traffic and is discarded. If they do not match, it is normal business traffic and is sent to the internal integrated network.

[0011] Secondly, the present invention provides a network traffic obfuscation processing system based on traffic simulation, comprising: The traffic feature configuration module is used to receive configuration information from the upper layer system and distribute the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. The real-time monitoring and adjustment module is used to repeatedly calculate the total amount of additional traffic that needs to be added, and then send the total amount of additional traffic that needs to be added to the additional traffic simulation module. The additional traffic simulation module is used to generate additional traffic data packets to be added in each time interval according to the total amount of additional traffic to be added, and send the additional traffic data packets to the traffic decision and scrambling module; The traffic decision and scrambling module is used to monitor normal business flows and additional traffic data packets in real time, and to ensure that normal business flows have priority. The traffic descrambling and filtering module is used to identify the type of received traffic data and filter out extra traffic.

[0012] Thirdly, the present invention provides an electronic device, comprising: At least one processor; and a memory communicatively connected to said at least one processor; The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the instructions stored in the memory to perform the method described above.

[0013] Fourthly, the present invention provides a computer-readable storage medium for storing instructions that, when executed, cause the above-described method to be implemented.

[0014] Fifthly, the present invention provides a computer program product that, when invoked by a computer, causes the computer to execute the above-described method.

[0015] Due to the adoption of the above technical solution, the beneficial effects of the present invention are: First, through precise feature configuration, the present invention dynamically constructs simulated traffic that is highly similar to the real data to be protected, making it difficult for attackers to distinguish between real and simulated data through intercepted data.

[0016] Second, the present invention employs key features and feature masking technology to make the feature values ​​in the simulated traffic diverse and variable, which significantly increases the difficulty of identifying additional traffic features after the data is intercepted and improves data security.

[0017] Third, by targeting important traffic masking, this invention can reduce the amount of extra traffic inserted, thus protecting important data features while also reducing the negative impact of extra traffic on the entire link.

[0018] Fourth, this invention enables the receiver to filter additional traffic coming from the external network through the interaction of additional traffic configuration packets, thereby making the additional traffic transparent to upper-layer applications and isolating the impact of additional traffic on upper-layer applications.

[0019] In summary, this invention, through innovative traffic simulation technology, overcomes the shortcomings of existing technologies, achieves network traffic obfuscation, can fully mask network traffic characteristics, and greatly reduces the negative impact of extra traffic on the entire network communication system while maintaining good security. Attached Figure Description

[0020] Figure 1 This invention provides a schematic diagram of a network traffic obfuscation processing method and system based on traffic simulation.

[0021] Figure 2 This is a flowchart of the traffic feature configuration module in an embodiment of the present invention.

[0022] Figure 3 This is a flowchart of the real-time monitoring and adjustment module in an embodiment of the present invention.

[0023] Figure 4 This is a flowchart of the additional traffic simulation module in an embodiment of the present invention.

[0024] Figure 5 This is a flowchart of the traffic decision and scrambling module in an embodiment of the present invention.

[0025] Figure 6 This is a flowchart of the traffic descrambling and filtering module in an embodiment of the present invention.

[0026] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0028] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0029] like Figure 1 As shown, this embodiment of the invention provides a network traffic obfuscation processing method based on traffic simulation, including: S100, the traffic characteristic configuration module receives configuration information from the upper-layer system and distributes the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. For example... Figure 2 As shown, the processing flow of the traffic feature configuration module is as follows: S101, Receive configuration information from the upper layer system; the configuration information includes Layer 2 protocol information, Layer 3 protocol information, maximum packet length, minimum packet length, location of additional traffic feature value, location of additional traffic feature value, location of additional traffic feature mask, preset important information masking traffic, and data monitoring time slot interval; S102, the location of the extra traffic feature value, the extra traffic feature value and the location of the extra traffic feature mask are combined into an outgoing extra traffic configuration packet and sent to the external integrated network to ensure that the receiving system can correctly identify the extra traffic of the local machine, thereby achieving accurate classification and management of traffic; S103, The configuration information required for generating additional traffic is sent to the additional traffic simulation module for generating additional traffic; the configuration information required for generating additional traffic includes maximum packet length, minimum packet length, additional traffic feature location, additional traffic feature value, Layer 2 protocol information and Layer 3 protocol information; S104 sends important information such as the traffic preset and data monitoring time slot interval to the real-time monitoring adjustment module for real-time traffic monitoring time slot configuration and calculation of the total amount of additional traffic to be added. S105, send the location of the extra traffic feature value and the location of the extra traffic feature mask to the traffic decision and scrambling module for scrambling the extra traffic and masking the extra traffic feature value; S106, when acting as a receiver, receives an additional traffic configuration packet from an external integrated network, obtains the location of the additional traffic feature value, the additional traffic feature value, and the location of the additional traffic feature mask of the incoming data, and sends them to the traffic descrambling and filtering module for descrambling and filtering the incoming external data to ensure that the additional traffic is not sent to the internal integrated network.

[0030] Through the processing flow of the traffic feature configuration module described above, the system can receive and process configuration information from upper-layer systems or other external systems, ensuring that the additional traffic features are highly similar to the important business traffic features while still being identifiable by the receiver, so that the generated additional traffic does not affect the normal business flow.

[0031] S200, the real-time monitoring and adjustment module calculates the total amount of additional traffic needed based on the received configuration information in a loop, and (periodically) sends the total amount of additional traffic needed to the additional traffic simulation module. For example... Figure 3 As shown, the single-processing flow of the real-time monitoring and adjustment module is as follows: S201, receive important information to cover traffic preset and data monitoring time slot interval; S202 collects important data traffic from the internal integrated network and calculates the amount of important data traffic within a unit time slot based on the data monitoring time slot interval; S203, calculate the total amount of additional traffic to be added in the next time slot based on the preset important information coverage traffic and the important data traffic size of the current time slot; wherein, if the important data traffic size of the current time slot is greater than or equal to the preset important information coverage traffic, no additional traffic is added; if the important data traffic size of the current time slot is less than the preset important information coverage traffic, the total amount of additional traffic to be added in the next time slot is the difference between the important data traffic size of the current time slot and the preset important information coverage traffic. S104 sends the calculated total amount of additional traffic to the additional traffic simulation module through the internal interface to generate a specified amount of additional traffic.

[0032] Through the processing flow of the above real-time monitoring and adjustment module, the system can adjust the total amount of additional traffic to be added in real time according to the changes in the size of important data traffic in each time interval, so as to achieve dynamic adaptive adjustment of additional traffic.

[0033] The S300 additional traffic simulation module generates additional traffic data packets to be added in each time interval according to the total amount of additional traffic required, and sends the additional traffic data packets to the traffic decision and scrambling module. For example... Figure 4 As shown, the processing flow of the additional traffic simulation module in each time interval is as follows: S301, based on the total amount of additional traffic to be received, generates a random packet length between the maximum and minimum packet lengths; S302, based on the random packet length, construct a virtual extra traffic data packet using the extra traffic feature location, extra traffic feature value, Layer 2 protocol information, and Layer 3 protocol information as traffic features; S303, when the traffic decision and scrambling module allows the reception of additional traffic, send the additional traffic data packet to the traffic decision and scrambling module; S304: After each successful transmission of a virtual extra traffic data packet, the total amount of extra traffic already transmitted is subtracted from the total amount of extra traffic to be added. When the total amount decreases to less than or equal to zero, the extra traffic generation operation in the current time slot is stopped to avoid interference with normal business flow.

[0034] Through the processing flow of the above-mentioned additional traffic simulation module, the system can efficiently generate and send virtual additional traffic in each time interval, while ensuring precise control of the total traffic volume and collaborative work between modules.

[0035] The S400's traffic decision and scrambling module monitors normal service flows and extra traffic data packets in real time, ensuring that normal service flows have priority. For example... Figure 5 As shown, the processing flow of the traffic decision and scrambling module is as follows: S401 determines whether there is a normal service flow being sent or waiting to be sent in the normal service flow interface. The normal service flow has the highest priority to ensure low latency and high reliability of normal services. If there is no normal service flow being sent, the additional traffic simulation module is allowed to send additional traffic. S402, after receiving the extra traffic data packet, extract the extra traffic feature value and the extra traffic mask value based on the extra traffic feature location and the extra traffic feature mask location; S403, use an additional traffic mask value to scramble the additional traffic feature value; S404, the scrambled additional traffic feature values ​​are refilled into the additional traffic data packet; S405 sends processed additional traffic packets to the external integrated network; S406 If a normal service flow needs to be sent when an extra traffic data packet is already in the sending state, the normal service flow should be buffered first, and the normal service flow data packet should be sent only after the current extra traffic data packet has been sent, in order to avoid abnormal situations such as mixed packets and truncated packets sent to the external network.

[0036] Through the processing flow of the traffic decision and scrambling module described above, the system can dynamically adjust the timing of sending additional traffic. While ensuring that normal business flow is not affected, the system can ensure that the data traffic sent to the external network is at a relatively stable level by adding additional traffic. At the same time, the system can scramble the characteristics of the additional traffic to ensure the diversity of changes in the characteristics of the additional traffic and enhance data security.

[0037] The S500's traffic descrambling and filtering module identifies the type of received traffic data and filters out extra traffic. For example... Figure 6 As shown, the processing flow of the traffic descrambling and filtering module is as follows: S501 receives data packets from an external integrated network and extracts additional traffic feature values ​​and additional traffic mask values ​​based on the additional traffic feature location and additional traffic feature mask location in the configuration information. S502 uses an extra traffic mask value to descramble the extra traffic feature value, and compares the descrambled extra traffic feature value with the extra traffic feature value in the configuration information. If they match, the received data packet is determined to be extra traffic and the current data packet is discarded. If they do not match, it is normal service traffic and is sent to the internal integrated network.

[0038] Through the processing flow of the above traffic decision and scrambling modules, the system can identify the type of incoming data, thereby filtering out extra traffic and ensuring that extra traffic does not affect internal business, achieving a seamless design for internal users.

[0039] Based on the same technological concept, such as Figure 1 As shown, this embodiment of the invention also provides a network traffic obfuscation processing system based on traffic simulation, comprising: The traffic feature configuration module is used to receive configuration information from the upper layer system and distribute the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. The real-time monitoring and adjustment module is used to repeatedly calculate the total amount of additional traffic that needs to be added, and then send the total amount of additional traffic that needs to be added to the additional traffic simulation module. The additional traffic simulation module is used to generate additional traffic data packets to be added in each time interval according to the total amount of additional traffic to be added, and send the additional traffic data packets to the traffic decision and scrambling module; The traffic decision and scrambling module is used to monitor normal business flows and additional traffic data packets in real time, and to ensure that normal business flows have priority. The traffic descrambling and filtering module is used to identify the type of received traffic data and filter out extra traffic.

[0040] The working principles of each functional module in the above system can be referred to the description in the aforementioned method embodiments, and will not be repeated here.

[0041] Based on the same technical concept, embodiments of the present invention also provide an electronic device that can implement the network traffic obfuscation processing method based on traffic simulation provided in the above embodiments of the present invention. In one embodiment, the electronic device may be a server, a terminal device, or other electronic device. Figure 7 As shown, the electronic device may include: At least one processor and a memory connected to the at least one processor. In this embodiment of the invention, the specific connection medium between the processor and the memory is not limited. Figure 7 The example used is the connection between the processor and memory via a bus. The bus... Figure 7 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. Buses can be divided into address buses, data buses, control buses, etc., but for ease of representation, [the specific bus type is not shown here]. Figure 7 The processor is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, a processor can also be called a controller; there are no restrictions on the name.

[0042] In this embodiment of the invention, the memory stores instructions that can be executed by at least one processor. By executing the instructions stored in the memory, at least one processor can execute the network traffic obfuscation processing method based on traffic simulation described above.

[0043] The processor is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory and calling data stored in memory, it can monitor the device's various functions and process data, thereby enabling overall monitoring of the device.

[0044] In an alternative design, the processor may include one or more processing units. The processor may integrate an application processor and a modem processor, wherein the application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles wireless communication. It is understood that the modem processor may also not be integrated into the processor. In some embodiments, the processor and memory may be implemented on the same chip; in some embodiments, they may also be implemented separately on separate chips.

[0045] The processor can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the network traffic obfuscation processing method based on traffic simulation disclosed in the embodiments of this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0046] Memory, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory can include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, etc. Memory is any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. In embodiments of the present invention, memory can also be a circuit or any other device capable of implementing storage functions, used to store program instructions and / or data.

[0047] By designing and programming the processor, the code corresponding to the network traffic obfuscation processing method based on traffic simulation described in the foregoing embodiments can be embedded into the chip, thereby enabling the chip to execute the steps of the method described in the foregoing embodiments during runtime. How to design and program the processor is a technique well known to those skilled in the art, and will not be elaborated here.

[0048] Based on the same inventive concept, embodiments of the present invention also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform a network traffic obfuscation processing method based on traffic simulation as described above.

[0049] In some alternative embodiments, the present invention also provides that various aspects of a network traffic obfuscation processing method based on traffic simulation can also be implemented as a program product comprising program code that, when the program product is run on a device, causes the control device to perform the steps in a network traffic obfuscation processing method based on traffic simulation according to various exemplary embodiments of the present invention as described above.

[0050] It should be noted that although several units or sub-units of the apparatus have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the invention, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units. Furthermore, although the operation of the method of the invention is described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0051] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0052] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a server, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0053] Program code for performing the operations of this invention can be written using any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0054] In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0055] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0056] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0057] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A network traffic obfuscation processing method based on traffic simulation, characterized in that, include: The traffic feature configuration module receives configuration information from the upper layer system and distributes the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. The real-time monitoring and adjustment module continuously calculates the total amount of additional traffic needed and sends the total amount of additional traffic needed to the additional traffic simulation module. The additional traffic simulation module generates additional traffic data packets to be added in each time interval according to the total amount of additional traffic to be added, and sends the additional traffic data packets to the traffic decision and scrambling module; The traffic decision and scrambling module monitors normal traffic flow and additional traffic data packets in real time, and ensures that normal traffic flow has priority. The traffic descrambling and filtering module identifies the type of the received traffic data and filters out extra traffic.

2. The network traffic obfuscation processing method based on traffic simulation according to claim 1, characterized in that, The processing flow of the traffic feature configuration module includes: Receive configuration information from the upper layer system; the configuration information includes Layer 2 protocol information, Layer 3 protocol information, maximum packet length, minimum packet length, location of additional traffic feature value, location of additional traffic feature value, location of additional traffic feature mask, preset important information masking traffic, and data monitoring time slot interval; The location of the extra traffic feature value, the extra traffic feature value, and the location of the extra traffic feature mask are combined into an outbound extra traffic configuration packet and sent to the external integrated network. The configuration information required for generating additional traffic is sent to the additional traffic simulation module; the configuration information required for generating additional traffic includes maximum packet length, minimum packet length, additional traffic feature location, additional traffic feature value, Layer 2 protocol information, and Layer 3 protocol information; Important information is masked by the preset traffic flow and data monitoring time slot intervals and sent to the real-time monitoring and adjustment module. Send the locations of additional traffic feature values ​​and additional traffic feature masks to the traffic decision and scrambling module; When acting as a receiver, it receives additional traffic configuration packets from an external integrated network, obtains the location of additional traffic feature values, additional traffic feature values, and additional traffic feature mask locations of incoming data, and sends them to the traffic descrambling and filtering module.

3. The network traffic obfuscation processing method based on traffic simulation according to claim 2, characterized in that, The single-processing flow of the real-time monitoring and adjustment module includes: Receiving important information masks traffic presets and data monitoring time slot intervals; Collect important data traffic from the internal integrated network, and calculate the size of important data traffic within a unit time slot based on the data monitoring time slot interval; Based on the important information masking traffic preset and the important data traffic size of the current time slot, calculate the total amount of additional traffic that needs to be added in the next time slot; The calculated total amount of additional traffic is sent to the additional traffic simulation module via an internal interface.

4. The network traffic obfuscation processing method based on traffic simulation according to claim 3, characterized in that, The processing flow of the additional traffic simulation module in each time interval includes: Based on the total amount of additional traffic to be received, generate a random packet length between the maximum and minimum packet lengths. Based on the random packet length, virtual extra traffic data packets are constructed using the extra traffic feature location, extra traffic feature value, Layer 2 protocol information, and Layer 3 protocol information as traffic features. When the traffic decision and scrambling module allows the reception of additional traffic, the additional traffic data packets are sent to the traffic decision and scrambling module. After each successful transmission of a virtual extra traffic data packet, the total amount of extra traffic already transmitted is subtracted from the total amount of extra traffic to be added. When the total amount decreases to less than or equal to zero, the extra traffic generation operation in the current time slot is stopped.

5. The network traffic obfuscation processing method based on traffic simulation according to claim 4, characterized in that, The processing flow of the traffic decision and scrambling module includes: Determine whether there is a normal business flow being sent or waiting to be sent in the normal business flow interface. If there is no normal business flow being sent, allow the extra traffic simulation module to send extra traffic. Upon receiving the extra traffic data packet, extract the extra traffic feature value and the extra traffic mask value based on the extra traffic feature location and the extra traffic feature mask location; The extra traffic feature value is scrambled using an extra traffic mask value; The scrambled additional traffic feature values ​​are then refilled into the additional traffic data packets; Send the processed additional traffic packets to the external integrated network; If a normal service flow needs to be sent when an extra traffic data packet is already in the sending state, the normal service flow should be buffered first, and the normal service flow data packet should be sent only after the current extra traffic data packet has been sent.

6. The network traffic obfuscation processing method based on traffic simulation according to claim 5, characterized in that, The processing flow of the traffic descrambling and filtering module includes: Receive data packets from an external integrated network, and extract additional traffic feature values ​​and additional traffic mask values ​​based on the additional traffic feature location and additional traffic feature mask location in the configuration information; The extra traffic feature value is descrambled using an extra traffic mask value. The descrambled extra traffic feature value is then compared with the extra traffic feature value in the configuration information. If they match, the received data packet is determined to be extra traffic and is discarded. If they do not match, it is normal business traffic and is sent to the internal integrated network.

7. A network traffic obfuscation processing system based on traffic simulation, characterized in that, include: The traffic feature configuration module is used to receive configuration information from the upper layer system and distribute the configuration information to the real-time monitoring and adjustment module, the additional traffic simulation module, the traffic decision and scrambling module, and the traffic descrambling and filtering module. The real-time monitoring and adjustment module is used to repeatedly calculate the total amount of additional traffic that needs to be added, and then send the total amount of additional traffic that needs to be added to the additional traffic simulation module. The additional traffic simulation module is used to generate additional traffic data packets to be added in each time interval according to the total amount of additional traffic to be added, and send the additional traffic data packets to the traffic decision and scrambling module; The traffic decision and scrambling module is used to monitor normal business flows and additional traffic data packets in real time, and to ensure that normal business flows have priority. The traffic descrambling and filtering module is used to identify the type of received traffic data and filter out extra traffic.

8. An electronic device, characterized in that, include: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which executes the instructions stored in the memory to perform the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store instructions that, when executed, cause the method as described in any one of claims 1-6 to be implemented.

10. A computer program product, characterized in that, When the computer program product is invoked by a computer, it causes the computer to perform the method as described in any one of claims 1-6.