The invention discloses an encrypted communication
confusion framework and method based on multi-factor traffic characteristics, and the method comprises the steps: firstly, capturing and analyzing the TLS
handshake traffic of a target
client, precisely extracting the JA3
fingerprint characteristics of the TLS
handshake traffic, and then generating a
Client Hello message with the same JA3
fingerprint through a TLS customization
library of the
client, thereby achieving the precise
camouflage of the
fingerprint of an
application layer of the
client. Secondly, a parallel
handshake proxy method is adopted, the handshake process of the proxy and the client and the handshake process of the proxy and the back-end
server are processed in parallel, and the handshake time feature is compressed to 1-RTT; and finally, in order to match
server-side features of mainstream
content distribution network service providers, a user-defined multi-level TLS
certificate chain is constructed, so that a
confusion effect is achieved on traffic size features. According to the method, the disguising technology of three dimensions of the client fingerprint, the
connection time sequence and the
server certificate size is combined, the concealment of the encrypted traffic in a
network monitoring environment can be effectively improved, and the practical value is relatively high.