Dynamic TLS Fingerprints for Decryption-Free Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protection devices struggle to accurately detect attack traffic in TLS data streams due to the low accuracy of preset fingerprint databases, leading to inefficient resource usage and potential privacy breaches during decryption.

Innovation Solution

A method for detecting attack traffic using dynamically generated fingerprints based on packet fields of TLS data streams, allowing real-time detection without decryption, and updating these fingerprints to adapt to changing attack patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a preset fingerprint database is used to detect attack traffic, then the detection process is simple, but the detection accuracy is low

Engineering Contradiction:
Improvedetection process simplicityVSAvoiddetection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent transforms the static preset fingerprint database into a dynamic fingerprint generation system. The security protection device generates fingerprints in real-time based on actual traffic characteristics, allowing the detection system to adapt to evolving attack patterns while maintaining operational simplicity through automated dynamic updates.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where detection results and traffic patterns are continuously analyzed to refine and update fingerprints. This feedback loop enables the system to learn from actual attack traffic and improve detection accuracy over time while keeping the detection process straightforward for operators.

Inventive Principle:
Principle #23Feedback

2Reliability

If TLS data streams are decrypted for analysis, then detection thoroughness is improved, but computing resources are consumed and user privacy is compromised

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential fingerprint characteristics from TLS data streams without performing full decryption. By taking out only the necessary identifying features needed for attack detection, the system achieves thorough detection while minimizing computing resource consumption and preserving user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of decrypting and analyzing the actual encrypted data, the system creates and analyzes fingerprint copies or representations of the traffic characteristics. This approach maintains detection thoroughness by analyzing traffic patterns while avoiding the computational overhead and privacy concerns associated with full decryption.

Inventive Principle:
Principle #26Copying

3Reliability

If TLS data streams are decrypted for analysis, then detection thoroughness is improved, but user privacy security is compromised

Engineering Contradiction:
Improvedetection thoroughnessVSAvoiduser privacy security impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the minimal necessary fingerprint information from TLS traffic for detection purposes, leaving the actual encrypted content intact and private. This extraction approach ensures detection thoroughness while preserving user privacy security by not exposing sensitive data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces fingerprints as an intermediary representation between the encrypted traffic and the detection system. This intermediary layer enables thorough detection analysis without requiring direct access to or decryption of the actual user data, thereby maintaining privacy security while achieving detection goals.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250280035A1Method for detecting attack traffic and related device
Publication Date: 2025.09.04 HUAWEI TECH CO LTD
  • US20250280035A1 patent drawing
  • US20250280035A1 patent drawing
  • US20250280035A1 patent drawing

AI summary

This application discloses a method for detecting attack traffic and a related device. The method may be applied to a security protection device. The security protection device obtains a first rate representation value of first traffic in a first time period, where the first traffic includes at least one first data stream, and destination IP addresses of all first data streams are the same, or a destination IP address of the at least one first data stream belongs to one IP group. Then, the security protection device generates at least one fingerprint based on the first rate representation value, where each fingerprint is generated based on a packet field of one of the at least one first data stream, and any fingerprint is used to detect whether a data stream that matches the any fingerprint is attack traffic. The method can improve detection accuracy of attack traffic.