The invention belongs to the technical field of
network security and communication, and provides a
secure shell protocol flow evidence obtaining decryption method and
system based on key injection, and the method comprises the steps: injecting a user-defined dynamic
library into a
service process, intercepting a key
encryption function, and extracting a
session key as a shared key when a
secure shell protocol
server runs; carrying out session identification on the encrypted traffic in the grabbed network, and completing the recombination of the IP fragment and the TCP fragment to obtain the recombined encrypted traffic; carrying out matching and integrity
verification on the shared key and the recombined encrypted traffic, and then decrypting to generate a
plaintext message; and analyzing the
plaintext message into a structured operation
record according to a channel type, and classifying and storing the structured operation
record in combination with a
timestamp, a
session ID and a
user identifier to form auditing evidence data. According to the method,
system files do not need to be modified, complete decryption and behavior restoration of multiple types of sessions such as Shell, SCP and SFTP can be achieved, and the method is suitable for
network security audit and judicial evidence obtaining scenes.