CN112118270B - 一种针对基于ssl加密的vpn流量识别方法 - Google Patents
一种针对基于ssl加密的vpn流量识别方法 Download PDFInfo
- Publication number
- CN112118270B CN112118270B CN202011181962.3A CN202011181962A CN112118270B CN 112118270 B CN112118270 B CN 112118270B CN 202011181962 A CN202011181962 A CN 202011181962A CN 112118270 B CN112118270 B CN 112118270B
- Authority
- CN
- China
- Prior art keywords
- ssl
- flow
- bit
- data
- signature
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 61
- 230000002457 bidirectional effect Effects 0.000 claims abstract description 15
- 230000007246 mechanism Effects 0.000 claims abstract description 15
- 238000007781 pre-processing Methods 0.000 claims abstract description 14
- 238000005516 engineering process Methods 0.000 claims abstract description 10
- 230000007704 transition Effects 0.000 claims description 20
- 230000008569 process Effects 0.000 claims description 16
- 238000006243 chemical reaction Methods 0.000 claims description 13
- 238000012360 testing method Methods 0.000 claims description 12
- 238000012549 training Methods 0.000 claims description 11
- 239000013598 vector Substances 0.000 claims description 11
- 230000000694 effects Effects 0.000 claims description 8
- 238000002474 experimental method Methods 0.000 claims description 4
- 238000000605 extraction Methods 0.000 claims description 4
- 238000001914 filtration Methods 0.000 claims description 3
- 230000006872 improvement Effects 0.000 description 8
- 238000010801 machine learning Methods 0.000 description 5
- 230000005540 biological transmission Effects 0.000 description 3
- 238000011160 research Methods 0.000 description 3
- 230000009286 beneficial effect Effects 0.000 description 2
- 238000007796 conventional method Methods 0.000 description 2
- 238000013461 design Methods 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 230000001965 increasing effect Effects 0.000 description 2
- 241000700605 Viruses Species 0.000 description 1
- 230000006854 communication Effects 0.000 description 1
- 230000001010 compromised effect Effects 0.000 description 1
- 238000013136 deep learning model Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000002708 enhancing effect Effects 0.000 description 1
- 238000007477 logistic regression Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/14—Network analysis or design
- H04L41/145—Network analysis or design involving simulating, designing, planning or modelling of a network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/24—Traffic characterised by specific attributes, e.g. priority or QoS
- H04L47/2483—Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (9)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011181962.3A CN112118270B (zh) | 2020-10-29 | 2020-10-29 | 一种针对基于ssl加密的vpn流量识别方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011181962.3A CN112118270B (zh) | 2020-10-29 | 2020-10-29 | 一种针对基于ssl加密的vpn流量识别方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN112118270A CN112118270A (zh) | 2020-12-22 |
CN112118270B true CN112118270B (zh) | 2023-01-06 |
Family
ID=73794699
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011181962.3A Active CN112118270B (zh) | 2020-10-29 | 2020-10-29 | 一种针对基于ssl加密的vpn流量识别方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN112118270B (zh) |
Families Citing this family (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN112910881A (zh) * | 2021-01-28 | 2021-06-04 | 武汉市博畅软件开发有限公司 | 一种基于通信协议的数据监控方法及系统 |
CN113949531B (zh) * | 2021-09-14 | 2022-06-17 | 北京邮电大学 | 一种恶意加密流量检测方法及装置 |
CN113949672A (zh) * | 2021-10-18 | 2022-01-18 | 南京中孚信息技术有限公司 | 一种新型vpn识别通用技术及装置 |
US20230133720A1 (en) * | 2021-10-29 | 2023-05-04 | Nokia Solutions And Networks Oy | Encryption segments for security in communication networks |
CN115051828A (zh) * | 2022-04-22 | 2022-09-13 | 江苏科技大学 | 面向类别不平衡下的ssl vpn加密流量识别分类方法 |
CN115174170B (zh) * | 2022-06-23 | 2023-05-09 | 东北电力大学 | 一种基于集成学习的vpn加密流量识别方法 |
CN117729054B (zh) * | 2024-02-07 | 2024-04-16 | 北京马赫谷科技有限公司 | 一种基于全流量存储的vpn流量识别方法和系统 |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105871832A (zh) * | 2016-03-29 | 2016-08-17 | 北京理工大学 | 一种基于协议属性的网络应用加密流量识别方法及其装置 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111385145B (zh) * | 2020-03-04 | 2023-04-25 | 南京信息工程大学 | 一种基于集成学习的加密流量识别方法 |
-
2020
- 2020-10-29 CN CN202011181962.3A patent/CN112118270B/zh active Active
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN105871832A (zh) * | 2016-03-29 | 2016-08-17 | 北京理工大学 | 一种基于协议属性的网络应用加密流量识别方法及其装置 |
Also Published As
Publication number | Publication date |
---|---|
CN112118270A (zh) | 2020-12-22 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN112118270B (zh) | 一种针对基于ssl加密的vpn流量识别方法 | |
CN109951444B (zh) | 一种加密匿名网络流量识别方法 | |
CN110012029B (zh) | 一种区分加密和非加密压缩流量的方法和系统 | |
CN108199863B (zh) | 一种基于两阶段序列特征学习的网络流量分类方法及系统 | |
CN113329023A (zh) | 一种加密流量恶意性检测模型建立、检测方法及系统 | |
CN110611640A (zh) | 一种基于随机森林的dns协议隐蔽通道检测方法 | |
Ahn et al. | Explaining deep learning-based traffic classification using a genetic algorithm | |
Niu et al. | A heuristic statistical testing based approach for encrypted network traffic identification | |
CN109831422A (zh) | 一种基于端到端序列网络的加密流量分类方法 | |
CN111611280A (zh) | 一种基于cnn和sae的加密流量识别方法 | |
CN111385145A (zh) | 一种基于集成学习的加密流量识别方法 | |
Wang et al. | Using entropy to classify traffic more deeply | |
Ding et al. | Adversarial sample attack and defense method for encrypted traffic data | |
CN117056797A (zh) | 基于非平衡数据的加密流量分类方法、设备及介质 | |
Maonan et al. | CENTIME: a direct comprehensive traffic features extraction for encrypted traffic classification | |
Dener et al. | RFSE-GRU: Data balanced classification model for mobile encrypted traffic in big data environment | |
Zheng et al. | Detecting malicious tls network traffic based on communication channel features | |
Alizadeh et al. | Timely classification and verification of network traffic using Gaussian mixture models | |
Li et al. | TCMal: A Hybrid Deep Learning Model for Encrypted Malicious Traffic Classification | |
CN113746707B (zh) | 一种基于分类器及网络结构的加密流量分类方法 | |
Tang et al. | Malware Traffic Classification Based on Recurrence Quantification Analysis. | |
CN115051828A (zh) | 面向类别不平衡下的ssl vpn加密流量识别分类方法 | |
Doroud et al. | Encrypted traffic detection: Beyond the port number era | |
Shimoni et al. | Malicious traffic detection using traffic fingerprint | |
Huang et al. | Research on Flow Classification Model Based on Similarity and Machine Learning Algorithm |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240112 Address after: 230000 floor 1, building 2, phase I, e-commerce Park, Jinggang Road, Shushan Economic Development Zone, Hefei City, Anhui Province Patentee after: Dragon totem Technology (Hefei) Co.,Ltd. Address before: 212003, No. 2, Mengxi Road, Zhenjiang, Jiangsu Patentee before: JIANGSU University OF SCIENCE AND TECHNOLOGY |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20240424 Address after: 710000, Building 10, Taihua Jinmao International, No. 16 Fenghui South Road, High tech Zone, Xi'an City, Shaanxi Province, China, 2803 Patentee after: Shaanxi Hongyi Shuzhi Technology Co.,Ltd. Country or region after: China Address before: 230000 floor 1, building 2, phase I, e-commerce Park, Jinggang Road, Shushan Economic Development Zone, Hefei City, Anhui Province Patentee before: Dragon totem Technology (Hefei) Co.,Ltd. Country or region before: China |