Network Behavior Recognition via Unknown Protocol Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for recognizing network behavior of programs are ineffective in accurately identifying newly-emerging or variant network behaviors, leading to hysteresis and failure to intercept unknown network protocols, thus compromising network security.
Innovation Solution
A method, device, and system that acquire and analyze application layer data to determine if it includes unknown protocols, identifying recognizable programs with known protocols and suspicious programs with unknown protocols, and utilizing a cloud server to judge malicious behavior based on blacklists and whitelists, thereby improving network security by promptly alerting users and intercepting potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional feature code-based detection methods are used, then detection can be performed for known threats, but newly-emerging or variant network behaviors cannot be accurately recognized due to hysteresis
Solution Approach 1:
The patent performs preliminary analysis of application layer data structures and protocols before threats manifest. By examining protocol characteristics, data formats, and communication patterns in advance, the system can identify suspicious behaviors early without waiting for feature codes to be extracted from actual attack samples.
Solution Approach 2:
Instead of starting with known threat features and matching them against traffic (conventional approach), the patent inverts the logic by analyzing unknown protocols and data structures first, then determining whether they represent threats. This allows detection of new behaviors without pre-existing feature knowledge.
2Productivity
If feature code-based detection is implemented, then automatic detection of known programs can be achieved, but detection of new threats requires finding and analyzing samples first
Solution Approach 1:
The system performs preliminary classification of network behaviors by analyzing application layer protocols and data structures before threats occur. This preliminary action creates a foundation for rapid automatic detection of new threats without requiring time-consuming sample collection and analysis.
Solution Approach 2:
The patent skips the traditional time-consuming process of finding, collecting, and analyzing threat samples by directly analyzing application layer data structures and protocols. This rushing through the intermediate steps enables immediate detection capability for new threats.
3Measurement precision
If only known protocols are monitored, then detection precision for recognized programs is maintained, but unknown protocols used by new threats are missed
Solution Approach 1:
The patent creates a universal detection mechanism that handles both known and unknown protocols through a single analysis framework. The system examines application layer data structures, protocol formats, and communication patterns that are universal across different protocol types, enabling detection of both recognized and novel protocols without requiring separate detection mechanisms.
Solution Approach 2:
The system changes the detection parameters from protocol-specific feature codes to protocol-agnostic structural characteristics such as data formats, field arrangements, and communication patterns. This parameter transformation enables the system to adapt to unknown protocols while maintaining precision for known ones.
Data Source
AI summary
The present disclosure discloses a method, device and system for recognizing network behavior of a program. The method comprises: during the program's access to a network, acquiring application layer data in a current network behavior of the program; judging whether the application layer data includes an unknown protocol; if protocols in the application layer data are all known protocols, identifying the current network behavior of the program as a network behavior of a recognizable program; and if the application layer data includes an unknown protocol, identifying the current network behavior of the program as a network behavior of a suspicious program. As such, a accurate recognition of a network behavior of a program is realized, the network behavior of the program including an unknown protocol is identified as a network behavior of a suspicious program, risk prompt information can be sent to a user, and a final selection is performed by the user, thereby solving the problem that conventional solutions for recognizing a network behavior of a program cannot accurately recognize a network behavior of a newly-emerging or new variant program.


