A method and system for monitoring encryption protocols
By combining variational mode decomposition and multi-scale permutation entropy analysis techniques with machine learning models, the problems of adaptability and insufficient information in existing encryption protocol monitoring technologies in complex network environments are solved, enabling multi-dimensional in-depth analysis and quantitative evaluation of encrypted traffic.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD
- Filing Date
- 2026-03-04
- Publication Date
- 2026-06-02
AI Technical Summary
Existing encryption protocol monitoring technologies are unable to fully reveal the weak randomness, hidden periodicity, or trend of random sequences in complex and dynamic network environments. They also lack adaptive capabilities, leading to false alarms or missed alarms. Furthermore, the binary judgment information is insufficient and cannot provide detailed information on the anomaly type and severity.
By employing variational mode decomposition and multi-scale permutation entropy analysis techniques, multi-scale entropy spectra are constructed through frequency domain analysis of encrypted session data. Machine learning models are then used to dynamically learn the intrinsic correlation patterns between protocol semantic features and entropy spectra, outputting quantitative risk levels and interpretable diagnostic information.
It enables multi-dimensional and in-depth insights into encrypted traffic, identifies anomalies in specific frequency bands, generates quantitative scores and detailed anomaly reports, adapts to dynamic environmental changes of different encryption protocols, and provides systematic and logical security assessments.
Smart Images

Figure CN122137620A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of cyberspace security technology, and in particular relates to a method and system for monitoring encryption protocols. Background Technology
[0002] The standardized deployment of encryption protocols is the cornerstone of building a secure network communication defense. Existing encryption protocol monitoring technologies typically follow a "protocol parsing - randomness verification - binary judgment" approach. Typically, this method first analyzes the parameters in the protocol handshake process to determine if they conform to standard specifications; secondly, it extracts random numbers or certificate payloads from the communication and uses statistical methods such as frequency statistics based on fixed-length unit divisions (e.g., chi-square test) or pattern verification based on fixed-length runs to determine their randomness; finally, it performs a logical AND operation on the two results to arrive at a binary conclusion of "compliant" or "non-compliant".
[0003] However, the aforementioned technological paradigms suffer from the following interrelated fundamental limitations, which restrict their effectiveness and practicality in complex, dynamic network environments: First, in terms of randomness analysis, existing methods rely on a pre-defined, single test scale, such as a fixed bit unit length or a fixed run length. This is like observing an object with only a microscope of a single resolution, which cannot fully reveal the complex anomalies such as weak randomness, hidden periodicity, or trends that may exist in random sequences at different time or frequency scales, and is insufficient in detecting carefully constructed pseudo-random sequences in advanced threats.
[0004] Secondly, in terms of the judgment logic, the pass threshold for randomness testing is often statically preset, failing to consider the differentiated requirements for randomness quality of different encryption protocols (such as TLS 1.2 and TLS 1.3, IPsec and SSH) due to different security objectives and algorithm characteristics. This "one-size-fits-all" judgment standard lacks adaptability and is prone to false positives or false negatives in actual deployment.
[0005] Finally, in terms of output, simple binary judgments lack sufficient information. They cannot inform security personnel of the specific type of anomaly (whether it's a protocol version issue or a random number quality problem), its severity, or the confidence level of the judgment, thus failing to provide effective decision support for subsequent risk management and prioritization.
[0006] Therefore, the cybersecurity field urgently needs an innovative technical solution that can go beyond simple threshold comparisons, gain in-depth insights into the intrinsic characteristics of encrypted traffic from multiple scales and dimensions, and achieve dynamic, quantitative, and correlated intelligent assessment. Summary of the Invention
[0007] The purpose of this invention is to provide a method and system for monitoring encryption protocols. The randomness parameters in an encryption protocol session are treated as a non-stationary signal. Variational mode decomposition and multi-scale permutation entropy analysis techniques are introduced to deeply characterize its complexity distribution in different frequency bands, i.e., the "entropy spectrum". Machine learning models are used to dynamically learn the intrinsic correlation pattern between the "entropy spectrum" features and the protocol semantic features. Finally, an intelligent assessment system that can output quantitative risk levels and interpretable diagnostic information is constructed.
[0008] To achieve the above objectives, the present invention provides a method for monitoring encryption protocols, comprising the following steps: Step 1: Parse the encrypted session data and simultaneously extract the protocol semantic feature vector. and randomness of the original data sequence ; Step 2: Process the original random data sequence Variational mode decomposition based on frequency domain analysis is performed to obtain multiple eigenmode function components. The permutation entropy of each component is calculated, and a multi-scale entropy spectrum is constructed. ; Step 3: Transfer the protocol semantic feature vector With multiscale entropy spectrum After fusion, the input to the pre-trained association model outputs a risk feature vector representing multi-dimensional anomalies. ; Step 4: Based on the protocol semantic feature vector Matching dynamic assessment strategies, combined with risk feature vectors Calculate the comprehensive risk score and according to Output a graded compliance conclusion.
[0009] Preferably, in step 2, a multi-scale entropy spectrum is constructed. The specific process is as follows: S201, Regarding the random original data sequence Perform a Fast Fourier Transform and determine the number of modes in the variational mode decomposition based on its frequency domain information. and penalty factor The specific expression is as follows: ; In the formula, Represents the randomness of the original data sequence In the index Time-domain amplitude at that point Represents the first frequency domain after transformation Complex representation of each frequency component The imaginary unit, For sequence The total length; S202. By solving the constrained variational problem, Decomposed into IMF components The expression is as follows: ; In the formula, Indicates the problem to be solved A set of intrinsic mode function components For the first One component; This represents the set of center frequencies corresponding to each component. Indicates time Find the partial derivative; For Dirac δ Function; * indicates convolution operation; S203, for each Calculate the normalized permutation entropy The expression is as follows: ; In the formula, The embedding dimension set in the permutation entropy calculation determines the length of the permutation pattern; Indicates the first Possible arrangement patterns in components The probability of it appearing in; S204. Construct the multi-scale entropy spectrum, as shown in the following expression: ; In the formula, For the first The center frequency of each component.
[0010] Preferably, when calculating permutation entropy, the embedding dimension Based on the randomness of the original data sequence length Adaptive selection, satisfying much smaller .
[0011] Preferably, in step 3, the association model is a gradient boosting decision tree model, which is trained using historical data, including protocol semantic feature vectors extracted from compliant and abnormal traffic. and randomness of the original data sequence The characteristics and risk dimensions are labeled.
[0012] Preferably, in step 4, the dynamic evaluation strategy includes a risk threshold vector bound to the protocol type and version. and weight vector Calculate the comprehensive risk score The formula is: ; In the formula, Risk feature vector The dimension; Represents the weight vector The Middle The weight values of each dimension are used to measure the importance of the corresponding risk dimension; Represents risk feature vector The Middle Dimensional abnormal scores; Represents the risk threshold vector The Middle The threshold of the dimension; Let be a unit step function; where , , .
[0013] Preferably, in step 4, according to The specific steps for outputting the tiered compliance conclusion are: (1) The comprehensive risk score... It is compared with a preset risk level threshold and mapped to one of four levels: "safe," "low risk," "medium risk," and "high risk," based on the risk feature vector. Scores in each dimension and its corresponding threshold This generates a description of the main dimensions that lead to the risk.
[0014] Preferably, the association between the level, rating, and main dimension description includes: Safety: Overall Risk Score The main dimension descriptions indicate the scores for all risk dimensions. None of them exceeded their corresponding thresholds. Or, described as empty; Low risk: Overall risk score satisfy ,in, The first preset threshold is used; the main dimension description indicates the existence of individual risk dimension scores. Slightly exceeding its threshold The indicated risk dimension includes at least one of the following: agreement negotiation consistency risk or excessive regularity risk of high-frequency noise components; Medium risk: Overall risk score satisfy ,in The second preset threshold and The main dimension description indicates the presence of one or more key risk dimension scores. Clearly exceeds its threshold The indicated risk dimension includes at least one of the following: insufficient randomness risk of low-frequency trend components or periodic anomaly risk of specific frequency bands. High risk: Comprehensive risk score satisfy The main dimension description indicates the presence of at least one core risk dimension score. Significantly exceeding its threshold Or there may be multiple key risk dimensions that are significantly abnormal at the same time. The indicated risk dimensions include a combination of risk of agreement negotiation consistency and risk of insufficient randomness of low-frequency trend components, or severe anomalies of periodic anomaly risk in a specific frequency band.
[0015] The present invention also provides an encryption protocol monitoring system, comprising: The protocol parsing and feature extraction module is used to perform deep parsing of the input encrypted session data packets, identify and decode the encryption protocol, and simultaneously perform the encoding and generation of protocol semantic feature vectors and the extraction of random raw data sequences. The variational mode decomposition and entropy spectrum analysis engine is used to perform fast Fourier transform on the extracted random raw data sequence to determine the decomposition parameters, perform variational mode decomposition to obtain multiple intrinsic mode function components, calculate the permutation entropy of each component, and construct a multi-scale entropy spectrum based on the center frequency and entropy value of the component. The deep association assessment module is loaded with a pre-trained association model, which is used to receive protocol semantic feature vectors and multi-scale entropy spectrum. After feature fusion, the association model is used for inference and outputs a multi-dimensional risk feature vector. The dynamic strategy rating engine manages a strategy library containing evaluation strategies for various protocol types. It matches the corresponding strategy based on the input protocol semantic feature vector, uses the matched strategy to quantify and score the risk feature vector, and maps and outputs graded compliance conclusions and key risk descriptions based on the scoring results.
[0016] Preferably, the variational mode decomposition and entropy spectrum analysis engine includes: The frequency domain analysis unit is used to perform fast Fourier transform and analyze random raw data sequences to determine variational mode decomposition parameters; Variational mode decomposition processor is used to adaptively decompose a sequence into multiple intrinsic mode function components based on parameters; The permutation entropy calculation unit is used to calculate the permutation entropy value for each intrinsic mode function component. The entropy spectrum builder is used to assemble and generate a structured multiscale entropy spectrum based on the center frequency of each component and the calculated permutation entropy value.
[0017] Preferred dynamic strategy rating engines include: The policy library management unit is used to store and maintain risk threshold vectors and weight vectors associated with different encryption protocol types and versions; The risk scoring calculator is used to calculate the comprehensive risk score by matching the risk threshold vector and weight vector obtained from the protocol semantic feature vector. The grading decision-maker is used to convert the comprehensive risk score into a final grading compliance conclusion based on the predefined mapping relationship between the scoring range and the risk level, and generate a readable report containing risk items.
[0018] Therefore, the above-mentioned encryption protocol monitoring method and system of the present invention have the following beneficial effects: (1) Variational mode decomposition can adaptively decompose random sequences into different frequency bands. Combined with multi-scale permutation entropy analysis, it realizes a dual in-depth examination of randomness in the frequency domain and complexity domain, which can effectively reveal weak periodicity or complexity anomalies in specific frequency bands that cannot be found by traditional methods. (2) Output multidimensional risk vectors, quantitative scores and classification conclusions, which not only indicate whether there is an anomaly, but also clearly explain in which frequency band the anomaly is, what kind of anomaly it is and the severity of the anomaly. The generated report can directly guide the safety response. (3) By learning the normal mode through the association model and by implementing the evaluation criteria adaptively with the protocol type through the dynamic policy library, the system can flexibly adapt to various encryption environments and can continuously evolve through updates; (4) From raw traffic analysis to adaptive frequency band decomposition, from multi-scale entropy analysis to intelligent correlation diagnosis, and then to strategic quantitative rating, the four main steps are closely linked to form a complete and autonomous technical closed loop with strong systematicity and logic.
[0019] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0020] Figure 1 This is an overall flowchart of an encryption protocol monitoring method according to the present invention; Figure 2 This is a block diagram of the overall structure of an encryption protocol monitoring system according to the present invention. Detailed Implementation
[0021] The following detailed description of embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0022] Please see Figure 1A method for monitoring encryption protocols includes the following steps: Step 1: Parse the encrypted session data and simultaneously extract the protocol semantic feature vector. and randomness of the original data sequence ; Step 2: Process the original random data sequence Variational mode decomposition based on frequency domain analysis is performed to obtain multiple eigenmode function components. The permutation entropy of each component is calculated, and a multi-scale entropy spectrum is constructed. The specific process is as follows: S201, Regarding the random original data sequence Perform a Fast Fourier Transform and determine the number of modes in the variational mode decomposition based on its frequency domain information. and penalty factor The specific expression is as follows: ; In the formula, Represents the randomness of the original data sequence In the index Time-domain amplitude at that point Represents the first frequency domain after transformation Complex representation of each frequency component The imaginary unit, For sequence The total length; S202. By solving the constrained variational problem, Decomposed into IMF components The expression is as follows: ; In the formula, Indicates the problem to be solved A set of intrinsic mode function components For the first One component; This represents the set of center frequencies corresponding to each component. Indicates time Find the partial derivative; For Dirac δ Function; * indicates convolution operation; S203, for each Calculate the normalized permutation entropy The expression is as follows: ; In the formula, The embedding dimension set in the permutation entropy calculation determines the length of the permutation pattern; Indicates the first Possible arrangement patterns in components The probability of it appearing in; S204. Construct the multi-scale entropy spectrum, as shown in the following expression: ; In the formula, For the first The center frequency of each component.
[0023] Among them, when calculating the permutation entropy, the embedding dimension Based on the randomness of the original data sequence length Adaptive selection, satisfying much smaller This ensures that it can be used to estimate probabilities. The sample size is large enough that the probability estimate is... It is a reliable and stable approximation of the true probability.
[0024] Step 3: Transfer the protocol semantic feature vector With multiscale entropy spectrum After fusion, the input to the pre-trained association model outputs a risk feature vector representing multi-dimensional anomalies. The correlation model is a gradient boosting decision tree model, which is trained using historical data, including protocol semantic feature vectors extracted from compliant and abnormal traffic. and randomness of the original data sequence The characteristics and risk dimensions are labeled.
[0025] Step 4: Based on the protocol semantic feature vector Matching dynamic assessment strategies, combined with risk feature vectors Calculate the comprehensive risk score and according to Output tiered compliance conclusions; the dynamic assessment strategy includes a risk threshold vector tied to protocol type and version. and weight vector Calculate the comprehensive risk score The formula is: ; In the formula, Risk feature vector The dimension; Represents the weight vector The Middle The weight values of each dimension are used to measure the importance of the corresponding risk dimension; Represents risk feature vector The Middle Dimensional abnormal scores; Represents the risk threshold vector The Middle The threshold of the dimension; Let be a unit step function; where , , .
[0026] according to The specific steps for outputting the tiered compliance conclusion are: (1) The comprehensive risk score... It is compared with a preset risk level threshold and mapped to one of four levels: "safe," "low risk," "medium risk," and "high risk," based on the risk feature vector. Scores in each dimension and its corresponding threshold This generates a description of the main dimensions that lead to the risk.
[0027] The relationship between grades, ratings, and key dimension descriptions includes: Safety: Overall Risk Score The main dimension descriptions indicate the scores for all risk dimensions. None of them exceeded their corresponding thresholds. Or, described as empty; Low risk: Overall risk score satisfy ,in, The first preset threshold is used; the main dimension description indicates the existence of individual risk dimension scores. Slightly exceeding its threshold The indicated risk dimension includes at least one of the following: agreement negotiation consistency risk or excessive regularity risk of high-frequency noise components; Medium risk: Overall risk score satisfy ,in The second preset threshold and The main dimension description indicates the presence of one or more key risk dimension scores. Clearly exceeds its threshold The indicated risk dimension includes at least one of the following: insufficient randomness risk of low-frequency trend components or periodic anomaly risk of specific frequency bands. High risk: Comprehensive risk score satisfy The main dimension description indicates the presence of at least one core risk dimension score. Significantly exceeding its threshold Or there may be multiple key risk dimensions that are significantly abnormal at the same time. The indicated risk dimensions include a combination of risk of agreement negotiation consistency and risk of insufficient randomness of low-frequency trend components, or severe anomalies of periodic anomaly risk in a specific frequency band.
[0028] Please see Figure 2 An encryption protocol monitoring system, comprising: The protocol parsing and feature extraction module is used to perform deep parsing of the input encrypted session data packets, identify and decode the encryption protocol, and simultaneously perform the encoding and generation of protocol semantic feature vectors and the extraction of random raw data sequences. The variational mode decomposition and entropy spectrum analysis engine is used to perform Fast Fourier Transform on the extracted random raw data sequence to determine the decomposition parameters, perform variational mode decomposition to obtain multiple intrinsic mode function components, calculate the permutation entropy of each component, and construct a multi-scale entropy spectrum based on the center frequency and entropy value of the component. Specifically, it includes: a frequency domain analysis unit, used to perform Fast Fourier Transform on the random raw data sequence and analyze it to determine the variational mode decomposition parameters; a variational mode decomposition processor, used to adaptively decompose the sequence into multiple intrinsic mode function components according to the parameters; a permutation entropy calculation unit, used to calculate the permutation entropy value of each intrinsic mode function component; and an entropy spectrum builder, used to assemble and generate a structured multi-scale entropy spectrum based on the center frequency of each component and the calculated permutation entropy value. The deep association assessment module is loaded with a pre-trained association model, which is used to receive protocol semantic feature vectors and multi-scale entropy spectrum. After feature fusion, the association model is used for inference and outputs a multi-dimensional risk feature vector. The dynamic policy rating engine manages a policy library containing evaluation policies for various protocol types. It matches corresponding policies to the input protocol semantic feature vectors, quantifies and scores the risk feature vectors using the matched policies, and maps and outputs a graded compliance conclusion and key risk descriptions based on the scoring results. Specifically, it includes: a policy library management unit for storing and maintaining risk threshold vectors and weight vectors associated with different encryption protocol types and versions; a risk scoring calculator for calculating a comprehensive risk score based on the risk threshold vectors and weight vectors matched to the protocol semantic feature vectors; and a graded decision-maker for converting the comprehensive risk score into a final graded compliance conclusion based on a predefined mapping relationship between scoring intervals and risk levels, and generating a readable report containing risk items.
[0029] Example A financial institution's data center needs to monitor all inbound and outbound TLS 1.3 encrypted sessions in real time to detect weak randomness, protocol tampering, or abnormal handshake behavior, and ensure that the encryption protocol is used in accordance with the security policy.
[0030] System deployment architecture: Data capture layer: Deploy traffic mirroring at the network egress point to capture all TLS 1.3 handshake packets and subsequent data transmission packets.
[0031] Processing engine layer: Deploy the encryption protocol monitoring system of this invention (including four major modules: protocol parsing, VMD entropy spectrum analysis, correlation model, and dynamic rating).
[0032] Policy Management Layer: Configure the risk threshold vector corresponding to TLS 1.3 and weight vector And set a grading threshold ( , ); Output and Response Layer: Risk reports are output to the SIEM system and trigger corresponding alarms or blocking actions.
[0033] The specific implementation process is as follows: Step 1: Protocol parsing and feature extraction: The input is a TLS 1.3 ClientHello packet; the system parses the protocol version, cipher suite, extended list, random number, and other fields, and outputs: Protocol semantic feature vector ,in For feature dimensions; Randomness of raw data sequence A 32-byte random number extracted from ClientHello. ; Step 2: Variational Mode Decomposition and Entropy Spectrum Construction: right Perform FFT analysis to determine the number of modes. and penalty factor ;if Setting the value too small, such as less than the actual number of modes present in the signal, will lead to under-decomposition, meaning that multiple signal components of different frequencies are forcibly mixed in the same IMF, causing "mode aliasing." This makes the permutation entropy of the subsequently calculated IMF unable to accurately represent the randomness of a single mode, potentially masking true anomalies. If... Setting the value too high can lead to over-decomposition, where a true pattern is meaninglessly split into multiple IMFs with similar frequencies, generating a large number of meaningless components with potentially anomalous entropy values. This introduces false anomalies and causes false alarms. Considering that in encryption protocol analysis, a 32-byte (256-bit) random number sequence should ideally be pure Gaussian white noise, in reality or under attack, it may contain various "non-random" components. Therefore, the sequence can be decomposed into five representative frequency bands: including a trend component, a main random component (low to mid-frequency), detail noise, and high-frequency components. If... If the bandwidth is set too small, the bandwidth of each IMF will be too wide, making it impossible to effectively separate components with similar frequencies, which will also lead to mode aliasing. If If the setting is too large, the bandwidth of each IMF is restricted to an extremely narrow range, which may cause a signal with a natural bandwidth, such as a modulated wave, to be incorrectly decomposed into multiple discrete frequency components, resulting in over-decomposition and feature distortion. The expression for the Fast Fourier Transform is: ; In the formula, Represents the randomness of the original data sequence In the index Time-domain amplitude at that point Represents the first frequency domain after transformation Complex representation of each frequency component The imaginary unit, For sequence The total length; Perform variational mode decomposition to solve the following constrained variational problem: ; In the formula, Indicates the problem to be solved A set of intrinsic mode function components For the first One component; This represents the set of center frequencies corresponding to each component. Indicates time Find the partial derivative; For Dirac δ Function; * indicates convolution operation; Decomposition yields Each intrinsic mode function component .
[0034] For each Calculate the normalized permutation entropy: ; in For embedded dimensions, For the first The probability of a certain permutation pattern appearing in a component.
[0035] Constructing a multi-scale entropy spectrum: ; Assume the output of this example is: ; Step 3: Association Model Inference: Will and After fusion, the pre-trained gradient boosting decision tree model is input, and the output is a risk feature vector: ; Assumption The output in this example is: ; The dimensions are represented in the following order: protocol version risk, cipher suite risk, low-frequency randomness risk, medium-frequency periodicity risk, high-frequency noise risk, and handshake consistency risk.
[0036] Step 4: Dynamic Strategy Rating and Output: Risk threshold vectors from the policy library matched according to TLS 1.3 T and weight vector W : ; ; Calculate the overall risk score R: ; in Unit step function: ; Substitute the data into this example: ; Grading determination: R=0.93, which satisfies It was determined to be low risk.
[0037] Key dimensions described: There is a risk of "insufficient randomness in low-frequency trend components" and a risk of "consistency in protocol negotiation".
[0038] Step 5: Reporting and Response: The system outputs a structured report: Protocol type: TLS 1.3; Session ID: xxx; Risk level: Low risk; Overall score: 0.93; Key anomaly dimensions: Insufficient low-frequency randomness (score 2.3 > threshold 2.0); Handshake consistency anomaly (score 1.5 > threshold 1.0); Recommendation: Check the compliance of the random number generator and handshake process.
[0039] The report was pushed to the SIEM system and logged. In this case, no blocking action was triggered.
[0040] Therefore, this invention employs the aforementioned encryption protocol monitoring method and system. Its core lies in using variational mode decomposition and multi-scale permutation entropy analysis techniques to deeply characterize the randomness parameters in the encryption session in both the frequency and complexity domains, forming an "entropy spectrum" feature. This method first analyzes the encryption protocol, extracting the protocol semantic feature vector and the original random data sequence. Then, it uses Fast Fourier Transform to guide variational mode decomposition, adaptively decomposing the random sequence into multiple intrinsic mode function components, and constructing a multi-scale entropy spectrum based on permutation entropy. Next, it fuses and analyzes the protocol semantic features and entropy spectrum features using a pre-trained association model, outputting... The system generates risk feature vectors representing multi-dimensional anomalies. Finally, combining a dynamic evaluation strategy bound to the protocol type, it calculates a quantitative comprehensive risk score and maps it to four levels of conclusion: "safe, low risk, medium risk, and high risk," while also outputting descriptions of specific risk dimensions. The system comprises four modules: protocol parsing and feature extraction, variational mode decomposition and entropy spectrum analysis, deep correlation evaluation, and dynamic policy rating, realizing a complete technical closed loop from traffic parsing to intelligent diagnosis. This invention significantly improves the adaptability, accuracy, and operability of encrypted protocol monitoring and is suitable for security compliance auditing and threat detection in complex network environments.
[0041] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for monitoring encryption protocols, characterized in that, Includes the following steps: Step 1: Parse the encrypted session data and simultaneously extract the protocol semantic feature vector. and randomness of the original data sequence ; Step 2: Process the random original data sequence Variational mode decomposition based on frequency domain analysis is performed to obtain multiple eigenmode function components. The permutation entropy of each component is calculated, and a multi-scale entropy spectrum is constructed. ; Step 3: Transfer the protocol semantic feature vector With multiscale entropy spectrum After fusion, the input to the pre-trained association model outputs a risk feature vector representing multi-dimensional anomalies. ; Step 4: Based on the protocol semantic feature vector Matching dynamic assessment strategies, combined with risk feature vectors Calculate the comprehensive risk score and according to Output a graded compliance conclusion.
2. The encryption protocol monitoring method according to claim 1, characterized in that: In step 2, construct the multi-scale entropy spectrum. The specific process is as follows: S201, Regarding the random original data sequence Perform a Fast Fourier Transform and determine the number of modes in the variational mode decomposition based on its frequency domain information. and penalty factor ; The specific expression is as follows: ; In the formula, Represents the randomness of the original data sequence In the index Time-domain amplitude at that point Represents the first frequency domain after transformation Complex representation of each frequency component The imaginary unit, For sequence The total length; S202. By solving the constrained variational problem, Decomposed into IMF components The expression is as follows: ; In the formula, Indicates the problem to be solved A set of intrinsic mode function components For the first One component; This represents the set of center frequencies corresponding to each component. Indicates time Find the partial derivative; For Dirac δ Function; * indicates convolution operation; S203, for each Calculate the normalized permutation entropy The expression is as follows: ; In the formula, The embedding dimension set in the permutation entropy calculation determines the length of the permutation pattern; Indicates the first Possible arrangement patterns in components The probability of it appearing in; S204. Construct the multi-scale entropy spectrum, as shown in the following expression: ; In the formula, For the first The center frequency of each component.
3. The encryption protocol monitoring method according to claim 2, characterized in that: When calculating permutation entropy, the embedding dimension Based on the randomness of the original data sequence length Adaptive selection, satisfying much smaller .
4. The encryption protocol monitoring method according to claim 3, characterized in that: In step 3, the association model is a gradient boosting decision tree model, which is trained using historical data, including protocol semantic feature vectors extracted from compliant and abnormal traffic. and randomness of the original data sequence The characteristics and risk dimensions are labeled.
5. The encryption protocol monitoring method according to claim 4, characterized in that: In step 4, the dynamic evaluation strategy includes a risk threshold vector bound to the protocol type and version. and weight vector Calculate the comprehensive risk score The formula is: ; In the formula, Risk feature vector The dimension; Represents the weight vector The Middle The weight values of each dimension are used to measure the importance of the corresponding risk dimension; Represents risk feature vector The Middle Dimensional abnormal scores; Represents the risk threshold vector The Middle The threshold of the dimension; Let be a unit step function; where , , .
6. The encryption protocol monitoring method according to claim 5, characterized in that, In step 4, according to The specific steps for outputting the tiered compliance conclusion are: (1) The comprehensive risk score... It is compared with a preset risk level threshold and mapped to one of four levels: "safe," "low risk," "medium risk," and "high risk," based on the risk feature vector. Scores in each dimension and its corresponding threshold This generates a description of the main dimensions that lead to the risk.
7. The encryption protocol monitoring method according to claim 6, characterized in that, The relationship between grades, ratings, and key dimension descriptions includes: Safety: Overall Risk Score The main dimension descriptions indicate the scores for all risk dimensions. None of them exceeded their corresponding thresholds. Or, described as empty; Low risk: Overall risk score satisfy ,in, The first preset threshold is used; the main dimension description indicates the existence of individual risk dimension scores. Slightly exceeding its threshold The indicated risk dimension includes at least one of the following: agreement negotiation consistency risk or excessive regularity risk of high-frequency noise components; Medium risk: Overall risk score satisfy ,in The second preset threshold and The main dimension description indicates the presence of one or more key risk dimension scores. Clearly exceeds its threshold The indicated risk dimension includes at least one of the following: insufficient randomness risk of low-frequency trend components or periodic anomaly risk of specific frequency bands. High risk: Comprehensive risk score satisfy The main dimension description indicates the presence of at least one core risk dimension score. Significantly exceeding its threshold Or there may be multiple key risk dimensions that are significantly abnormal at the same time. The indicated risk dimensions include a combination of risk of agreement negotiation consistency and risk of insufficient randomness of low-frequency trend components, or severe anomalies of periodic anomaly risk in a specific frequency band.
8. An encryption protocol monitoring system, applied to an encryption protocol monitoring method as described in any one of claims 1-7, characterized in that, include: The protocol parsing and feature extraction module is used to perform deep parsing of the input encrypted session data packets, identify and decode the encryption protocol, and simultaneously perform the encoding and generation of protocol semantic feature vectors and the extraction of random raw data sequences. The variational mode decomposition and entropy spectrum analysis engine is used to perform fast Fourier transform on the extracted random raw data sequence to determine the decomposition parameters, perform variational mode decomposition to obtain multiple intrinsic mode function components, calculate the permutation entropy of each component, and construct a multi-scale entropy spectrum based on the center frequency and entropy value of the component. The deep association assessment module is loaded with a pre-trained association model, which is used to receive protocol semantic feature vectors and multi-scale entropy spectrum. After feature fusion, the association model is used for inference and outputs a multi-dimensional risk feature vector. The dynamic strategy rating engine manages a strategy library containing evaluation strategies for various protocol types. It matches the corresponding strategy based on the input protocol semantic feature vector, uses the matched strategy to quantify and score the risk feature vector, and maps and outputs graded compliance conclusions and key risk descriptions based on the scoring results.
9. The encryption protocol monitoring system according to claim 8, characterized in that, The variational mode decomposition and entropy spectrum analysis engine includes: The frequency domain analysis unit is used to perform fast Fourier transform and analyze the random raw data sequence to determine the variational mode decomposition parameters; Variational mode decomposition processor is used to adaptively decompose a sequence into multiple intrinsic mode function components based on parameters; The permutation entropy calculation unit is used to calculate the permutation entropy value for each intrinsic mode function component. The entropy spectrum builder is used to assemble and generate a structured multiscale entropy spectrum based on the center frequency of each component and the calculated permutation entropy value.
10. The encryption protocol monitoring system according to claim 9, characterized in that, The dynamic strategy rating engine includes: The policy library management unit is used to store and maintain risk threshold vectors and weight vectors associated with different encryption protocol types and versions; The risk scoring calculator is used to calculate the comprehensive risk score by matching the risk threshold vector and weight vector obtained from the protocol semantic feature vector. The grading decision-maker is used to convert the comprehensive risk score into a final grading compliance conclusion based on the predefined mapping relationship between the scoring range and the risk level, and generate a readable report containing risk items.