Summary of the invention
The embodiment of the invention provides a kind of message flow recognition method and device to the problem that exists in the prior art, improves the message recognition accuracy.
The embodiment of the invention provides a kind of message flow recognition method, comprising:
From the message flow of input, filter out the message flow that meets first transport layer protocol;
From the said message flow that meets first transport layer protocol, filter out the message flow that meets first cryptographic protocol;
According to agreement to be identified, send the handshake message that meets said first cryptographic protocol and said first transport layer protocol to said destination or the source end that meets the message flow of first cryptographic protocol;
If shake hands successfully, the message flow of then confirming input is the message flow that meets said agreement to be identified, breaks off the communication of the success of this time shaking hands.
The embodiment of the invention also provides a kind of message flow recognition device, comprising:
The host-host protocol filtering module is used for filtering out the message flow that meets first transport layer protocol from the message flow of input;
The cryptographic protocol filtering module is used for filtering out the message flow that meets first cryptographic protocol from the said message flow that meets first transport layer protocol;
Handshake module is connected with said cryptographic protocol filtering module, is used for according to agreement to be identified, sends the handshake message that meets said first cryptographic protocol and said first transport layer protocol to said destination or the source end that meets the message flow of first cryptographic protocol;
Determination module is connected with said handshake module, is used for after said handshake module is shaken hands success, and the message flow of confirming input is the message flow that meets said agreement to be identified;
Break off module, be used for after said handshake module is shaken hands success, breaking off the communication of the success of this time shaking hands.
In message flow recognition method that the embodiment of the invention provides and the device; At first from the message flow of input, filter out the message flow that meets first transport layer protocol and first cryptographic protocol; Simulation meets the client of agreement to be identified then; Initiatively shake hands,, can confirm that then the message flow of importing meets agreement to be identified if shake hands successfully with the destination or the source end of the message flow of importing; Thereby the message flow of having avoided all being met first transport layer protocol and first cryptographic protocol is identified as the message flow that meets agreement to be identified, has improved the message recognition accuracy.
Embodiment
For the purpose, technical scheme and the advantage that make the embodiment of the invention clearer; To combine the accompanying drawing in the embodiment of the invention below; Technical scheme in the embodiment of the invention is carried out clear, intactly description; Obviously, described embodiment is the present invention's part embodiment, rather than whole embodiment.Based on the embodiment among the present invention, those of ordinary skills are not making the every other embodiment that is obtained under the creative work prerequisite, all belong to the scope of the present invention's protection.
Be illustrated in figure 1 as message flow recognition method embodiment flow chart of the present invention, comprise:
Step 101, from the input message flow filter out the message flow that meets first transport layer protocol;
Step 102, from the said message flow that meets first transport layer protocol, filter out the message flow that meets first cryptographic protocol;
Step 103, according to agreement to be identified, send the handshake message that meets said first cryptographic protocol and said first transport layer protocol to the destination or the source end of the said message flow that meets first cryptographic protocol;
If step 104 is shaken hands successfully, the message flow of then confirming input is the message flow that meets said agreement to be identified, breaks off the communication of the success of this time shaking hands.
Message flow recognition method provided by the invention can be used to discern that to adopt the message flow that meet to be identified agreement of various cryptographic protocols after encrypting, agreement to be identified can be the agreement of desire identification such as P2P file sharing protocol.First cryptographic protocol can comprise message flow encryption (Message StreamEncryption; Abbreviation MSE), protocol header is encrypted (Protocol Header Encryption; Be called for short PHE) etc.; The P2P file sharing protocol can comprise bit stream (BitTorrent is called for short BT) agreement, Ares agreement, eDonkey agreement etc.First transport layer protocol is the agreement that is used to transmit the P2P message flow, can be transmission control protocol (Transmission Control Protocol is called for short TCP) or UDP (User Datagram Protocol is called for short UDP).
Be the implementation procedure that example is explained the method that the embodiment of the invention one provides with BT message flow how to discern employing TCP transport layer protocol, MSE cryptographic protocol below.The BT agreement is an agreement to be identified, and the MSE agreement is first cryptographic protocol, and TCP is first transport layer protocol.
BT is a famous P2P file sharing protocol, and encryption of using in the BT client or fuzzy technology are the MSE technology.Encrypt based on the MSE agreement in the BT message flow or fuzzy, make Virtual network operator or Internet Service Provider can't discern the BT message flow.
The MSE agreement is used DH (Diffie-Hellman) agreement to carry out encryption key and is consulted; And use stream cipher AES RC4 to carry out data encryption; Message checking hash function adopts SHA-1, and DH parameter P is the safe prime of 768 bits (96 byte), and DH parameter G equals 2.
The process that the MSE agreement is carried out key agreement and data communication is following:
Password is consulted and data communication is that example is introduced to carry out between customer end A and the service end B.At first; Customer end A sends partial content and random number in the key for service end B; Wherein random number is mainly used in the internuncial statistical analysis identification based on length of opposing, a part from key to customer end A and random number that service end B sends, thus accomplish key agreement process.Carry out the selection and the parameter negotiation of cryptographic algorithm then between customer end A and the service end B, customer end A adopts the key and the cryptographic algorithm that consult that message flow is encrypted after consulting to accomplish, and sends to service end B to the message flow after encrypting.
The MSE agreement does not explicitly call for its bearing protocol, but mainly operates on the TCP at present.
To adopt MSE to encrypt BT message flow afterwards in order identifying, at first from the message flow of input, to filter out the message flow that meets Transmission Control Protocol, after leaching the message flow that meets the MSE agreement.Because except the BT message flow; Other message flows also possibly adopt the Transmission Control Protocol transmission; And adopt MSE agreement encryption or fuzzy, so, need further to simulate the BT client for fear of other message flows mistakes except the BT message flow are identified as the BT message flow; Source end or destination to the message flow of importing that meets the MSE agreement send the handshake message that meets Transmission Control Protocol and MSE agreement and BT agreement; If shake hands successfully, can confirm that then the current message flow that meets Transmission Control Protocol and MSE agreement that filters out is the message flow that meets the BT agreement, the source end or the destination of the current message flow that meets Transmission Control Protocol and MSE agreement that filters out are the BT client.The failure if shake hands can confirm that then the current message flow that meets Transmission Control Protocol and MSE agreement that filters out is not the message flow that meets the BT agreement.
Through above-mentioned method, just can identify and adopt Transmission Control Protocol transmission and MSE agreement to encrypt BT message flow afterwards, and can avoid the message flow mistake that meets other agreements that has adopted Transmission Control Protocol transmission and MSE agreement to encrypt is identified as the BT message flow.
Step 101 can adopt the combined method of port identification method or characteristic keyword recognition method or port identification method and characteristic keyword recognition method.The port identification method specifically is the COM1 of the message flow of the said input of identification, if meet preset port, then confirms as the message flow that meets first transport layer protocol.Characteristic keyword recognition method specifically is the characteristic keyword of the message flow of the said input of identification, if meet preset characteristic keyword, then confirms as the message flow of first transport layer protocol.
Step 102 can adopt characteristic keyword recognition method.Particularly, discern the said characteristic keyword that meets the message flow of first transport layer protocol,, then confirm as the message flow that meets first cryptographic protocol if meet preset characteristic indication.
Step 103 can adopt following process and destination or source end to shake hands: the handshake message that generates agreement to be identified; According to first transport layer protocol, said handshake message is encapsulated; According to first cryptographic protocol, the handshake message after the encapsulation is encrypted; Send the handshake message after encrypting to destination or source end.
The message flow recognition method that the embodiment of the invention provides; At first from the message flow of input, filter out the message flow that meets first transport layer protocol and first cryptographic protocol; Simulation meets the client of agreement to be identified then; Initiatively shake hands,, can confirm that then the message flow of importing meets agreement to be identified if shake hands successfully with the destination or the source end of the message flow of importing; Thereby the message flow of having avoided all being met first transport layer protocol and first cryptographic protocol is identified as the message flow that meets agreement to be identified, has improved the message recognition accuracy.
Be illustrated in figure 2 as the structural representation of message flow recognition device one embodiment of the present invention, this device comprises host-host protocol filtering module 11, cryptographic protocol filtering module 12, handshake module 13, determination module 14 and breaks off module 15.Host-host protocol filtering module 11 is used for filtering out the message flow that meets first transport layer protocol from the message flow of input; Cryptographic protocol filtering module 12 is used for filtering out the message flow that meets first cryptographic protocol from the said message flow that meets first transport layer protocol; Handshake module 13 is connected with cryptographic protocol filtering module 12, is used for according to agreement to be identified, sends the handshake message that meets said first cryptographic protocol and said first transport layer protocol to said destination or the source end that meets the message flow of first cryptographic protocol; Determination module 14 is connected with handshake module 13, is used for after said handshake module 13 is shaken hands success, and the message flow of confirming input is the message flow that meets said agreement to be identified.Disconnection module 15 is used for after said handshake module 13 is shaken hands success, breaking off the communication of the success of this time shaking hands.
Message flow recognition device as shown in Figure 2 can be degree of depth protocal analysis (Deep PacketInspection; Be called for short DPI) device; The DPI device can be the fire compartment wall with DPI function, is equivalent in existing DPI device, increase cryptographic protocol filtering module, handshake module, determination module and disconnection module.
Be illustrated in figure 3 as the structural representation of another embodiment of message flow recognition device of the present invention, among this embodiment, the cryptographic protocol filtering module be arranged in the DPI device 16, this DPI device 16 can be the fire compartment wall that possesses the DPI function.
Among the embodiment as shown in Figures 2 and 3, handshake module can comprise the generation submodule, encapsulation submodule, encryption submodule and transmission submodule.Wherein, generate the handshake message that submodule can be used to generate agreement to be identified; The encapsulation submodule can be used for according to first transport layer protocol, and the handshake message that generates the submodule generation is encapsulated; Encrypt submodule and can be used for, the handshake message after the encapsulation of encapsulation submodule is encrypted according to first cryptographic protocol; Sending submodule can be used for sending the handshake message of encrypting after submodule is encrypted to destination or source end.
The host-host protocol filtering module specifically can be used to discern the COM1 of the message flow of input, if meet preset port, then confirms as the message flow that meets first transport layer protocol; And/or the characteristic keyword of the message flow of identification input, if meet preset characteristic keyword, then confirm as the message flow of first transport layer protocol.
The cryptographic protocol filtering module specifically can be used to discern the characteristic keyword of the message flow that meets first transport layer protocol, if meet preset characteristic indication, then confirms as the message flow that meets first cryptographic protocol.
Be the operation principle that example is explained message flow recognition device of the present invention how to discern the BT message flow that adopts Transmission Control Protocol transmission and MSE agreement to encrypt below.
The host-host protocol filtering module filters out the message flow that meets first transport layer protocol from the message flow of input after; The cryptographic protocol filtering module filters out the message flow that meets the MSE agreement from the said message flow that meets first transport layer protocol; Because except the BT message flow; Other message flows also possibly adopt the MSE agreement to message flow encryption or fuzzy; So for fear of other message flow mistakes except the BT message flow are identified as the BT message flow, handshake module needs further simulation BT client, according to the BT agreement; Source end or destination to the message flow of importing that meets the MSE agreement send the handshake message that meets MSE agreement and Transmission Control Protocol; If shake hands successfully, then determination module can confirm that the current message flow that meets the MSE agreement that filters out is the message flow that meets the BT agreement, and the far-end or the destination of the current message flow that meets the MSE agreement that filters out are the BT client.The failure if shake hands, then determination module can confirm that the current message flow that meets the MSE agreement that filters out is not the message flow that meets the BT agreement.
Determination module confirms that the current message flow that meets the MSE agreement that filters out is to meet after the message flow of BT agreement, can report the result of message flow identification to the DPI device, and breaks off and being connected of BT client by breaking off module.
Message flow recognition device provided by the invention can be deployed in the network exit in a territory, so just can discern the all-network message flow of this device of flowing through.
The message flow recognition device that the embodiment of the invention provides; At first from the message flow of input, filter out the message flow that meets first transport layer protocol and first cryptographic protocol; Simulation meets the client of agreement to be identified then; Initiatively shake hands,, can confirm that then the message flow of importing meets agreement to be identified if shake hands successfully with the destination or the source end of the message flow of importing; Thereby the message flow of having avoided all being met first transport layer protocol and first cryptographic protocol is identified as the message flow that meets agreement to be identified, has improved the message recognition accuracy.
One of ordinary skill in the art will appreciate that: all or part of step that realizes said method embodiment can be accomplished through the relevant hardware of program command; Aforesaid program can be stored in the computer read/write memory medium; This program the step that comprises said method embodiment when carrying out; And aforesaid storage medium comprises: various media that can be program code stored such as ROM, RAM, magnetic disc or CD.
What should explain at last is: above embodiment is only in order to explaining technical scheme of the present invention, but not to its restriction; Although with reference to previous embodiment the present invention has been carried out detailed explanation, those of ordinary skill in the art is to be understood that: it still can be made amendment to the technical scheme that aforementioned each embodiment put down in writing, and perhaps part technical characterictic wherein is equal to replacement; And these are revised or replacement, do not make the spirit and the scope of the essence disengaging various embodiments of the present invention technical scheme of relevant art scheme.