Identification method for Torr Over VPN anonymous network flow and service type thereof

25 min read Original article ↗
Identification method for Torr Over VPN anonymous network flow and service type thereof Download PDF

Info

Publication number
CN116233013B
CN116233013B CN202111470314.4A CN202111470314A CN116233013B CN 116233013 B CN116233013 B CN 116233013B CN 202111470314 A CN202111470314 A CN 202111470314A CN 116233013 B CN116233013 B CN 116233013B
Authority
CN
China
Prior art keywords
traffic
service type
tor
identifying
over vpn
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202111470314.4A
Other languages
Chinese (zh)
Other versions
CN116233013A (en
Inventor
刘伟伟
胡梁宏
曾盛
沈昊
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nanjing University of Science and Technology
Original Assignee
Nanjing University of Science and Technology
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nanjing University of Science and Technology filed Critical Nanjing University of Science and Technology
Priority to CN202111470314.4A priority Critical patent/CN116233013B/en
Publication of CN116233013A publication Critical patent/CN116233013A/en
Application granted granted Critical
Publication of CN116233013B publication Critical patent/CN116233013B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

  • 238000000034 method Methods 0.000 title claims abstract description 30
  • 230000003993 interaction Effects 0.000 claims abstract description 6
  • 239000013598 vector Substances 0.000 claims description 18
  • 230000008569 process Effects 0.000 claims description 6
  • 238000007781 pre-processing Methods 0.000 claims description 3
  • 238000004891 communication Methods 0.000 claims description 2
  • 230000005540 biological transmission Effects 0.000 claims 1
  • 238000013136 deep learning model Methods 0.000 abstract description 4
  • 238000005065 mining Methods 0.000 abstract description 4
  • 230000006399 behavior Effects 0.000 abstract description 3
  • 238000005728 strengthening Methods 0.000 abstract description 3
  • 239000000284 extract Substances 0.000 description 5
  • 238000001514 detection method Methods 0.000 description 4
  • 230000007246 mechanism Effects 0.000 description 4
  • 238000005516 engineering process Methods 0.000 description 3
  • 238000012546 transfer Methods 0.000 description 3
  • 101001121408 Homo sapiens L-amino-acid oxidase Proteins 0.000 description 2
  • 102100026388 L-amino-acid oxidase Human genes 0.000 description 2
  • 239000012634 fragment Substances 0.000 description 2
  • 230000006872 improvement Effects 0.000 description 2
  • 239000003550 marker Substances 0.000 description 2
  • 230000000717 retained effect Effects 0.000 description 2
  • 238000010586 diagram Methods 0.000 description 1
  • 238000004141 dimensional analysis Methods 0.000 description 1
  • 238000011160 research Methods 0.000 description 1
  • 238000012552 review Methods 0.000 description 1

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00—Traffic control in data switching networks
    • H04L47/10—Flow control; Congestion control
    • H04L47/24—Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2483—Traffic characterised by specific attributes, e.g. priority or QoS involving identification of individual flows
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14—Network analysis or design
    • H04L41/145—Network analysis or design involving simulating, designing, planning or modelling of a network
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00—Arrangements for monitoring or testing data switching networks
    • H04L43/04—Processing captured monitoring data, e.g. for logfile generation
    • H04L43/045—Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00—Arrangements for monitoring or testing data switching networks
    • H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00—Traffic control in data switching networks
    • H04L47/10—Flow control; Congestion control
    • H04L47/24—Traffic characterised by specific attributes, e.g. priority or QoS
    • H04L47/2441—Traffic characterised by specific attributes, e.g. priority or QoS relying on flow classification, e.g. using integrated services [IntServ]
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00—Data switching networks
    • H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46—Interconnection of networks
    • H04L12/4633—Interconnection of networks using encapsulation techniques, e.g. tunneling
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00—Data switching networks
    • H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46—Interconnection of networks
    • H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0407—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the identity of one or more communicating identities is hidden
    • H04L63/0421—Anonymous communication, i.e. the party's identifiers are hidden from the other party or parties, e.g. using an anonymizer
    • Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02D—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00—Reducing energy consumption in communication networks
    • Y02D30/50—Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Mining & Analysis (AREA)
  • Health & Medical Sciences (AREA)
  • Cardiology (AREA)
  • General Health & Medical Sciences (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明公开了一种针对Tor Over VPN匿名网络流量及其服务类型的识别方法。该方法包括:基于OpenVPN握手阶段的协议指纹、长度序列与心跳交互等特征筛选得到VPN流量;利用Tor网络建立阶段存在的握手长度序列以及心跳交互行为等机制,结合CNN模型识别出Tor Over VPN流量;最后,利用包间时延、包长度、包负载等特征结合Transformer深度学习模型识别Tor Over VPN流量的不同承载服务类型。本发明通过深入挖掘多维度时空特征、并结合当前主流深度学习模型,可以很好的对Tor Over VPN流量及其承载服务类型进行识别,对于加强Tor流量监管、维护网络安全具有重要意义。

The present invention discloses a method for identifying anonymous network traffic and service types of Tor Over VPN. The method comprises: obtaining VPN traffic based on the features of protocol fingerprint, length sequence and heartbeat interaction in the handshake phase of OpenVPN; identifying Tor Over VPN traffic by using the handshake length sequence and heartbeat interaction behavior in the Tor network establishment phase in combination with a CNN model; finally, identifying different bearer service types of Tor Over VPN traffic by using features such as inter-packet delay, packet length, and packet load in combination with a Transformer deep learning model. The present invention can identify Tor Over VPN traffic and its bearer service types well by deeply mining multi-dimensional spatiotemporal features and combining with the current mainstream deep learning model, which is of great significance for strengthening Tor traffic supervision and maintaining network security.

Description

针对Tor Over VPN匿名网络流量及其服务类型的识别方法Identification Method for Tor Over VPN Anonymous Network Traffic and Its Service Type

技术领域Technical Field

本发明属于网络安全技术领域,特别是一种针对Tor Over VPN匿名网络流量及其服务类型的识别方法,通过提取Tor Over VPN流量的时空维度特征并结合CNN、Transformer等模型进行识别。The present invention belongs to the field of network security technology, and in particular to a method for identifying Tor Over VPN anonymous network traffic and its service type, which extracts the spatiotemporal dimensional features of Tor Over VPN traffic and combines it with CNN, Transformer and other models for identification.

背景技术Background technique

Tor作为当前应用最广泛的匿名通信软件,通过三重加密转发技术实现代理传输用户数据,从而躲避网络安全机构审查。随着检测识别技术的提高,Tor原生模式以及混淆插件模式的使用体验日趋下降,用户逐渐转向Tor Over VPN模式,通过VPN前置代理的方式加密访问境外资源的同时保证匿名通信的目的。Tor, the most widely used anonymous communication software, uses triple encryption forwarding technology to transmit user data through a proxy, thereby evading the review of network security agencies. With the improvement of detection and identification technology, the experience of using Tor native mode and obfuscation plug-in mode is declining, and users are gradually turning to Tor Over VPN mode, which uses VPN front-end proxy to encrypt access to overseas resources while ensuring anonymous communication.

Tor浏览器支持PC、Android、Linux等多个平台,可在官网免费下载安装使用,且各大论坛社区提供相关使用教程。此外,OpenVPN作为当前主流VPN,被各大社区推荐与Tor浏览器结合使用,用以更好的躲避ISP监管。Tor Browser supports multiple platforms such as PC, Android, and Linux. It can be downloaded and installed for free on the official website, and major forum communities provide relevant usage tutorials. In addition, OpenVPN, as the current mainstream VPN, is recommended by major communities to be used in combination with Tor Browser to better avoid ISP supervision.

目前,对Tor Over VPN模式流量的识别研究还较少,因此有必要针对Tor OverVPN匿名网络流量及其访问服务类型进行识别。At present, there is little research on the identification of Tor Over VPN mode traffic, so it is necessary to identify Tor OverVPN anonymous network traffic and its access service types.

发明内容Summary of the invention

本发明的目的在于针对现有技术存在的问题,提供一种针对Tor Over VPN匿名网络流量及其服务类型的识别方法。The purpose of the present invention is to provide a method for identifying Tor Over VPN anonymous network traffic and its service type in view of the problems existing in the prior art.

实现本发明目的的技术解决方案为:一种针对Tor Over VPN匿名网络流量及其服务类型的识别方法,所述方法包括以下步骤:The technical solution to achieve the purpose of the present invention is: a method for identifying Tor Over VPN anonymous network traffic and its service type, the method comprising the following steps:

步骤1,基于五元组信息将输入流量样本分流处理为会话流量,并依据流量类型对其进行标记、分组、编号预处理操作;所述五元组为源地址、目的地址、源端口、目的端口、协议五元组;Step 1: Divert the input traffic sample into session traffic based on the five-tuple information, and perform marking, grouping, and numbering preprocessing operations on the traffic according to the traffic type; the five-tuple is the source address, destination address, source port, destination port, and protocol five-tuple;

步骤2,逐流提取序号为0至N1的数据包负载长度、OpenVPN头部协议字段、心跳数据包特征;Step 2, extract the payload length, OpenVPN header protocol field, and heartbeat data packet features of the data packets with sequence numbers 0 to N1 flow by flow;

步骤3,逐流提取序号为N1至N2的数据包的负载长度、负载信息、轮询数据特征,并将这些特征转化为二维灰度图像;Step 3, extracting the payload length, payload information, and polling data features of the data packets with sequence numbers N1 to N2 flow by flow, and converting these features into a two-dimensional grayscale image;

步骤4,逐流提取序号为N2至N3数据包的长度、负载信息、包间时延、MSS包占比、交互次数,构成时空特征向量;Step 4: extract the length, load information, inter-packet delay, MSS packet ratio, and number of interactions of the data packets with sequence numbers N2 to N3 flow by flow to form a spatiotemporal feature vector;

步骤5,利用步骤2提取的特征对流量进行匹配,识别OpenVPN隧道流量;Step 5, match the traffic using the features extracted in step 2 to identify the OpenVPN tunnel traffic;

步骤6,基于所述二维灰度图像和CNN模型构建Tor Over VPN匿名网络流量识别模型;Step 6, constructing a Tor Over VPN anonymous network traffic identification model based on the two-dimensional grayscale image and the CNN model;

步骤7,基于所述时空特征向量和Transformer模型构建服务类型识别模型;Step 7, constructing a service type identification model based on the spatiotemporal feature vector and the Transformer model;

步骤8,针对待检测的流量样本,执行步骤1至步骤4,之后根据步骤5识别OpenVPN隧道流量,利用步骤6和步骤7构建的模型分别识别Tor Over VPN匿名网络流量和服务类型。Step 8: For the traffic sample to be detected, execute steps 1 to 4, then identify the OpenVPN tunnel traffic according to step 5, and use the models constructed in steps 6 and 7 to identify the Tor Over VPN anonymous network traffic and service type respectively.

进一步地,步骤1中对输入流量样本进行分流处理的同时,将MAC、IP、端口这些字节信息均置0。Furthermore, while the input traffic sample is being diverted in step 1, the byte information of MAC, IP, and port are all set to 0.

进一步地,步骤1中进行编号之前,需去除负载长度为0的数据包。Furthermore, before numbering in step 1, data packets with a payload length of 0 need to be removed.

进一步地,步骤1中所述编号遵循PSH标记位进行编号,满载包需与后续第一个非满载且PSH数据包组成一个分片。Furthermore, the numbering in step 1 is performed in accordance with the PSH marker, and the full packet needs to form a fragment with the first subsequent non-full packet and PSH data packet.

进一步地,步骤2中序号为0至N1的数据包负载长度具体为:Furthermore, the payload length of the data packets with sequence numbers 0 to N1 in step 2 is specifically:

逐流提取序号为0至N1的数据包负载长度,之后将其中固定不变的负载长度按序保留,作为0至N1的数据包负载长度特征,其余负载长度忽略,且将上行数据包长度标记为正数,下行数据包长度标记为负数。The payload lengths of packets with sequence numbers from 0 to N1 are extracted flow by flow, and then the fixed payload lengths are retained in order as the payload length features of packets from 0 to N1. The remaining payload lengths are ignored, and the uplink packet length is marked as a positive number, and the downlink packet length is marked as a negative number.

进一步地,步骤3中将特征转化为二维灰度图像的过程中,若特征长度小于所设定的二维灰度图像的像素,进行填0补充,否则进行截断处理。Furthermore, in the process of converting the feature into a two-dimensional grayscale image in step 3, if the feature length is less than the set pixel of the two-dimensional grayscale image, it is padded with 0, otherwise it is truncated.

进一步地,步骤4中所述时空特征向量中的数据,依据数据包方向进行标记,上行数据包标记为正数,下行数据包标记为负数。Furthermore, the data in the spatiotemporal feature vector in step 4 is marked according to the direction of the data packet, with the uplink data packet marked as a positive number and the downlink data packet marked as a negative number.

进一步地,步骤6所述基于所述二维灰度图像和CNN模型构建Tor Over VPN匿名网络流量识别模型,具体包括:Furthermore, step 6 constructs a Tor Over VPN anonymous network traffic identification model based on the two-dimensional grayscale image and the CNN model, specifically including:

对二维灰度图像添加Tor Over VPN匿名网络流量标签;Add Tor Over VPN anonymous network traffic labels to the 2D grayscale image;

然后利用二维灰度图像对CNN模型进行训练,形成Tor Over VPN匿名网络流量识别模型。Then, the CNN model is trained using two-dimensional grayscale images to form a Tor Over VPN anonymous network traffic identification model.

进一步地,步骤7所述基于所述时空特征向量和Transformer模型构建服务类型识别模型,具体包括:Furthermore, step 7 constructs a service type identification model based on the spatiotemporal feature vector and the Transformer model, specifically including:

对时空特征向量添加服务类型标签;所述服务类型视频播放、文件传输、即时通讯、邮件收发、网页浏览、语音通话;Adding a service type label to the spatiotemporal feature vector; the service type includes video playback, file transfer, instant messaging, email sending and receiving, web browsing, and voice call;

然后利用时空特征向量对Transformer模型进行训练,形成服务类型识别模型。Then, the spatiotemporal feature vectors are used to train the Transformer model to form a service type recognition model.

本发明与现有技术相比,其显著优点为:Compared with the prior art, the present invention has the following significant advantages:

1)通过挖掘VPN隧道建立阶段的长度序列、协议指纹与心跳机制等特征,基于规则匹配方式实现对OpenVPN隧道流量的检测,提高了对加密隧道流量检测的准确率。1) By mining the length sequence, protocol fingerprint and heartbeat mechanism characteristics of the VPN tunnel establishment phase, the OpenVPN tunnel traffic is detected based on the rule matching method, which improves the accuracy of encrypted tunnel traffic detection.

2)通过将负载长度、载荷信息、轮询数据等属性转化为灰度图的形式,并结合CNN模型实现对Tor Over VPN流量的识别,提高了对Tor Over VPN流量的检测能力。2) By converting attributes such as payload length, payload information, and polling data into grayscale images and combining them with the CNN model to identify Tor Over VPN traffic, the detection capability of Tor Over VPN traffic is improved.

3)针对Tor Over VPN流量的承载服务类型识别问题,多维度深层次分析各类流量的时空特性分布差异,选取有效特征构建统一特征向量并结合Transformer时空序列模型对其进行精细化识别,提高了对Tor行为层面的服务类型识别精度。3) To address the problem of identifying the service type carried by Tor Over VPN traffic, we conduct an in-depth multi-dimensional analysis of the differences in the spatiotemporal characteristics of various types of traffic, select effective features to construct a unified feature vector, and use the Transformer spatiotemporal sequence model to perform refined identification, thereby improving the accuracy of service type identification at the Tor behavior level.

总体来说,本发明通过深入挖掘多维度时空特征、并结合当前主流深度学习模型,可以很好的对Tor Over VPN流量及其承载服务类型进行识别,对于加强Tor流量监管、维护网络安全具有重要意义。In general, the present invention can identify Tor Over VPN traffic and its carrying service types well by deeply mining multi-dimensional spatiotemporal features and combining them with the current mainstream deep learning model, which is of great significance for strengthening Tor traffic supervision and maintaining network security.

下面结合附图对本发明作进一步详细描述。The present invention is further described in detail below in conjunction with the accompanying drawings.

附图说明BRIEF DESCRIPTION OF THE DRAWINGS

图1为本发明针对Tor Over VPN匿名网络流量识别方法的流程示意图。FIG1 is a flow chart of a method for identifying anonymous network traffic over Tor Over VPN according to the present invention.

图2为OpenVPN协议格式图。Figure 2 is a diagram of the OpenVPN protocol format.

具体实施方式Detailed ways

为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请进行进一步详细说明。应当理解,此处描述的具体实施例仅仅用以解释本申请,并不用于限定本申请。In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

图1为本发明针对Tor Over VPN匿名网络流量的识别方法的流程示意图。该检测方法包括以下步骤:FIG1 is a flow chart of a method for identifying anonymous network traffic of Tor Over VPN according to the present invention. The detection method comprises the following steps:

输入样本流量为各类协议流量,其中包括Tor Over VPN匿名网络流量;The input sample traffic is various protocol traffic, including Tor Over VPN anonymous network traffic;

VPN流量识别:首先基于五元组与协议进行分流处理,然后基于图2的OpenVPN协议格式、VPN握手建立交互机制与心跳保活等特征对输入流量样本进行识别,输出OpenVPN隧道流量;VPN traffic identification: First, traffic is diverted based on the five-tuple and the protocol. Then, based on the OpenVPN protocol format, VPN handshake interaction mechanism, and heartbeat keep-alive features shown in Figure 2, the input traffic sample is identified and the OpenVPN tunnel traffic is output.

Tor Over VPN流量识别:利用Tor网络建立过程中的长度序列、负载信息、轮询查询机制等特征结合CNN模型对VPN流量的承载内容进行识别,输出Tor Over VPN匿名网络流量;Tor Over VPN traffic identification: Utilize the length sequence, load information, polling query mechanism and other features in the Tor network establishment process combined with the CNN model to identify the content carried by VPN traffic and output Tor Over VPN anonymous network traffic;

服务类型识别:在识别出Tor Over VPN流量的基础上,利用负载信息、心跳机制、包间时延、MSS满载包占比等时空维度特征并结合Transformer模型对使用Tor Over VPN访问不同目标过程中传输的应用数据类别进行识别,识别的类型包括视频播放、文件传输、即时通讯、邮件收发、网页浏览、语音通话等行为。Service type identification: Based on the identification of Tor Over VPN traffic, the application data categories transmitted in the process of using Tor Over VPN to access different targets are identified by using load information, heartbeat mechanism, inter-packet delay, MSS full-load packet ratio and other spatiotemporal dimension features combined with the Transformer model. The identified types include video playback, file transfer, instant messaging, email sending and receiving, web browsing, voice calls and other behaviors.

具体地,在一个实施例中,提供了一种针对Tor Over VPN匿名网络流量及其服务类型的识别方法,所述方法包括以下步骤:Specifically, in one embodiment, a method for identifying Tor Over VPN anonymous network traffic and its service type is provided, the method comprising the following steps:

步骤1,基于五元组信息将输入流量样本分流处理为会话流量,并依据流量类型对其进行标记、分组、编号预处理操作;所述五元组为源地址、目的地址、源端口、目的端口、协议五元组;Step 1: Divert the input traffic sample into session traffic based on the five-tuple information, and perform marking, grouping, and numbering preprocessing operations on the traffic according to the traffic type; the five-tuple is the source address, destination address, source port, destination port, and protocol five-tuple;

这里,对输入流量样本进行分流处理的同时,将MAC、IP、端口这些字节信息均置0。Here, while the input traffic samples are being diverted, the byte information such as MAC, IP, and port are all set to 0.

这里,进行编号之前,需去除负载长度为0的数据包。Here, before numbering, data packets with a payload length of 0 need to be removed.

这里优选地,所述编号遵循PSH标记位进行编号,满载包需与后续第一个非满载且PSH数据包组成一个分片。Preferably, the numbering is performed according to the PSH marker bit, and the full-load packet needs to form a fragment with the first subsequent non-full-load and PSH data packet.

步骤2,逐流提取序号为0至30的数据包负载长度、OpenVPN头部协议字段、心跳数据包特征;Step 2, extract the payload length, OpenVPN header protocol field, and heartbeat data packet features of data packets with sequence numbers from 0 to 30 flow by flow;

这里,序号为0至30的数据包负载长度具体为:Here, the payload lengths of packets numbered 0 to 30 are:

逐流提取序号为0至30的数据包负载长度,之后将其中固定不变的负载长度按序保留,作为0至30的数据包负载长度特征,其余负载长度忽略,且将上行数据包长度标记为正数,下行数据包长度标记为负数。The payload lengths of packets with sequence numbers from 0 to 30 are extracted flow by flow, and then the fixed payload lengths are retained in order as the payload length features of packets from 0 to 30. The remaining payload lengths are ignored, and the uplink packet length is marked as a positive number, and the downlink packet length is marked as a negative number.

步骤3,逐流提取序号为30至120的数据包的负载长度、负载信息、轮询数据特征,并将这些特征转化为二维灰度图像;Step 3, extracting the payload length, payload information, and polling data features of the data packets with sequence numbers from 30 to 120 flow by flow, and converting these features into a two-dimensional grayscale image;

这里,转化为二维灰度图像的过程中,若特征长度小于所设定的二维灰度图像的像素,进行填0补充,否则进行截断处理。Here, in the process of converting to a two-dimensional grayscale image, if the feature length is smaller than the set pixel of the two-dimensional grayscale image, it is filled with 0, otherwise it is truncated.

步骤4,逐流提取序号为120至320数据包的长度、负载信息、包间时延、MSS包占比、交互次数,构成时空特征向量;所述时空特征向量中的数据,依据数据包方向进行标记,上行数据包标记为正数,下行数据包标记为负数。Step 4, extract the length, load information, inter-packet delay, MSS packet ratio, and number of interactions of data packets with sequence numbers 120 to 320 flow by flow to form a spatiotemporal feature vector; the data in the spatiotemporal feature vector is marked according to the direction of the data packet, with the uplink data packet marked as a positive number and the downlink data packet marked as a negative number.

步骤5,利用步骤2提取的特征对流量进行匹配,识别OpenVPN隧道流量;Step 5, match the traffic using the features extracted in step 2 to identify the OpenVPN tunnel traffic;

步骤6,基于所述二维灰度图像和CNN模型构建Tor Over VPN匿名网络流量识别模型,具体过程包括:Step 6: constructing a Tor Over VPN anonymous network traffic identification model based on the two-dimensional grayscale image and the CNN model. The specific process includes:

对二维灰度图像添加Tor Over VPN匿名网络流量标签;Add Tor Over VPN anonymous network traffic labels to the 2D grayscale image;

然后利用二维灰度图像对CNN模型进行训练,形成Tor Over VPN匿名网络流量识别模型。Then, the CNN model is trained using two-dimensional grayscale images to form a Tor Over VPN anonymous network traffic identification model.

步骤7,基于所述时空特征向量和Transformer模型构建服务类型识别模型,具体包括:Step 7, constructing a service type identification model based on the spatiotemporal feature vector and the Transformer model, specifically includes:

对时空特征向量添加服务类型标签;所述服务类型视频播放、文件传输、即时通讯、邮件收发、网页浏览、语音通话;Adding a service type label to the spatiotemporal feature vector; the service type includes video playback, file transfer, instant messaging, email sending and receiving, web browsing, and voice call;

然后利用时空特征向量对Transformer模型进行训练,形成服务类型识别模型。Then, the spatiotemporal feature vectors are used to train the Transformer model to form a service type recognition model.

步骤8,针对待检测的流量样本,执行步骤1至步骤4,之后根据步骤5识别OpenVPN隧道流量,利用步骤6和步骤7构建的模型分别识别Tor Over VPN匿名网络流量和服务类型。Step 8: For the traffic sample to be detected, execute steps 1 to 4, then identify the OpenVPN tunnel traffic according to step 5, and use the models constructed in steps 6 and 7 to identify the Tor Over VPN anonymous network traffic and service type respectively.

本发明通过深入挖掘多维度时空特征、并结合当前主流深度学习模型,可以很好的对Tor Over VPN流量及其承载服务类型进行识别,对于加强Tor流量监管、维护网络安全具有重要意义。By deeply mining multi-dimensional spatiotemporal features and combining them with current mainstream deep learning models, the present invention can well identify Tor Over VPN traffic and its carrying service types, which is of great significance for strengthening Tor traffic supervision and maintaining network security.

以上显示和描述了本发明的基本原理、主要特征及优点。本行业的技术人员应该了解,本发明不受上述实施例的限制,上述实施例和说明书中描述的只是说明本发明的原理,在不脱离本发明精神和范围的前提下,本发明还会有各种变化和改进,这些变化和改进都落入要求保护的本发明范围内。本发明要求保护范围由所附的权利要求书及其等效物界定。The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.

Claims (10)

1. A method for identifying Tor Over VPN anonymous network traffic and its service type, the method comprising the steps of:

Step 1, splitting an input traffic sample into session traffic based on quintuple information, and performing marking, grouping and numbering preprocessing operations on the session traffic according to traffic types; the five-tuple is a source address, a destination address, a source port, a destination port and a protocol five-tuple;

Step 2, extracting the data packet load length, the OpenVPN header protocol field and the heartbeat data packet characteristics with sequence numbers of 0 to N1 from a stream to stream;

Step 3, extracting the load length, load information and polling data characteristics of the data packets with the sequence numbers of N1 to N2 in a flow-by-flow mode, and converting the characteristics into a two-dimensional gray image;

step 4, extracting the length, the load information, the inter-packet time delay, the MSS packet occupation ratio and the interaction times of the data packets with the sequence numbers of N2 to N3 from one stream to another to form a space-time feature vector;

Step 5, matching the flow by utilizing the characteristics extracted in the step 2, and identifying the OpenVPN tunnel flow;

step 6, constructing a Tor Over VPN anonymous network flow identification model based on the two-dimensional gray level image and the CNN model;

Step 7, constructing a service type identification model based on the space-time feature vector and the transducer model;

And 8, executing the steps 1 to 4 aiming at the traffic sample to be detected, and then identifying the OpenVPN tunnel traffic according to the step 5, and respectively identifying the Tor Over VPN anonymous network traffic and the service type by using the models constructed in the step 6 and the step 7.

2. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein in step 1, the byte information of the MAC, IP and port is set to 0 while the incoming traffic sample is split.

3. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein the data packet with the payload length of 0 is removed before numbering in step 1.

4. The method for identifying Tor Over VPN anonymous network traffic and service types thereof according to claim 1 or 3, wherein in step 1, the numbering follows the PSH flag bit for numbering, and the full packet is required to be fragmented with the subsequent first non-full and PSH packet.

5. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein the packet payload length from 0 to N1 in step2 is specifically:

Extracting the data packet load length with the sequence number of 0to N1 in a flow-by-flow manner, reserving the load length which is fixed in the data packet load length in sequence as the data packet load length characteristics of 0to N1, neglecting the rest load lengths, and marking the uplink data packet length as positive number and the downlink data packet length as negative number.

6. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein in the step 3, in the process of converting the feature into the two-dimensional gray image, if the feature length is smaller than the pixel of the set two-dimensional gray image, 0 filling is performed, otherwise, cutoff processing is performed.

7. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein the data in the space-time feature vector in step 4 is marked according to a packet direction, an uplink packet is marked as a positive number, and a downlink packet is marked as a negative number.

8. The method of claim 1, wherein N1 is 30, N2 is 120, and N3 is 320 in step 2.

9. The method for identifying the Tor Over VPN anonymous network traffic and the service type thereof according to claim 1, wherein the constructing the Tor Over VPN anonymous network traffic identification model based on the two-dimensional gray scale image and the CNN model in step 6 specifically comprises:

adding a Torr Over VPN anonymous network flow label to the two-dimensional gray level image;

and training the CNN model by using the two-dimensional gray level image to form a Torr Over VPN anonymous network flow identification model.

10. The method for identifying Tor Over VPN anonymous network traffic and service types thereof according to claim 1, wherein the constructing a service type identification model based on the spatio-temporal feature vector and a transducer model in step 7 specifically comprises:

Adding a service type label to the time space feature vector; the service type video playing, file transmission, instant messaging, mail receiving and sending, web browsing and voice communication;

And then training the transducer model by using the space-time feature vectors to form a service type identification model.

CN202111470314.4A 2021-12-03 2021-12-03 Identification method for Torr Over VPN anonymous network flow and service type thereof Active CN116233013B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202111470314.4A CN116233013B (en) 2021-12-03 2021-12-03 Identification method for Torr Over VPN anonymous network flow and service type thereof

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202111470314.4A CN116233013B (en) 2021-12-03 2021-12-03 Identification method for Torr Over VPN anonymous network flow and service type thereof

Publications (2)

Publication Number Publication Date
CN116233013A CN116233013A (en) 2023-06-06
CN116233013B true CN116233013B (en) 2024-07-16

Family

ID=86587794

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202111470314.4A Active CN116233013B (en) 2021-12-03 2021-12-03 Identification method for Torr Over VPN anonymous network flow and service type thereof

Country Status (1)

Country Link
CN (1) CN116233013B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN118250089B (en) * 2024-05-24 2024-08-02 南京理工大学 Method and system for inferring session attributes of encrypted proxy large language model based on multi-scale characteristics of traffic

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109951444A (en) * 2019-01-29 2019-06-28 中国科学院信息工程研究所 An encrypted anonymous network traffic identification method
CN111224940A (en) * 2019-11-15 2020-06-02 中国科学院信息工程研究所 An anonymous service traffic association identification method and system embedded in an encrypted tunnel

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102129375B1 (en) * 2019-11-01 2020-07-02 (주)에이아이딥 Deep running model based tor site active fingerprinting system and method thereof

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109951444A (en) * 2019-01-29 2019-06-28 中国科学院信息工程研究所 An encrypted anonymous network traffic identification method
CN111224940A (en) * 2019-11-15 2020-06-02 中国科学院信息工程研究所 An anonymous service traffic association identification method and system embedded in an encrypted tunnel

Also Published As

Publication number Publication date
CN116233013A (en) 2023-06-06

Similar Documents

Publication Publication Date Title
CN115398860B (en) Session detection method, device, detection equipment and computer storage medium
CN105162626B (en) Network flow depth recognition system and recognition methods based on many-core processor
CN114124463B (en) Method and system for identifying hidden network encryption application service based on network behavior characteristics
CN105704091B (en) A kind of session analytic method and system based on SSH agreement
CN103916294B (en) The recognition methods of protocol type and device
WO2022088779A1 (en) Deep packet processing method and apparatus, electronic device, and storage medium
US9356844B2 (en) Efficient application recognition in network traffic
WO2021000874A1 (en) Service flow identification method and apparatus, and model generation method and apparatus
KR101292873B1 (en) Network interface card device and method of processing traffic by using the network interface card device
CN114124551B (en) Malicious encryption traffic identification method based on multi-granularity feature extraction under WireGuard protocol
CN103297270A (en) Application type recognition method and network equipment
CN105939297B (en) A kind of TCP message recombination method and device
CN102571613A (en) Method and network device for message forwarding
CN110417729A (en) Service and application classification method and system for encrypted traffic
CN118316603B (en) Encryption flow identification and feature extraction method and device based on FPGA
CN104702564A (en) Tethering user identification method and device
CN117579718A (en) Data message processing method, device, equipment and storage medium
CN112436998A (en) Data transmission method and electronic equipment
CN118802617A (en) DPI-based QUIC traffic analysis methods, equipment, media and products
CN108632201A (en) Encryption device, decryption device and judge message whether the method that encrypt or decrypt
CN106257867A (en) A kind of business recognition method encrypting flow and device
CN116233013A (en) Identification method for Torr Over VPN anonymous network flow and service type thereof
CN116471060A (en) Recognition Method of Encrypted Traffic Overpassing Behavior Based on Random Forest Regression Algorithm
CN116192449A (en) Encrypted traffic application identification method and system
CN107508828A (en) A kind of very-long-range data interaction system and method

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
CB03 Change of inventor or designer information
CB03 Change of inventor or designer information

Inventor after: Liu Weiwei

Inventor after: Hu Lianghong

Inventor after: Zeng Sheng

Inventor after: Shen Hao

Inventor before: Hu Lianghong

Inventor before: Liu Weiwei

Inventor before: Zeng Sheng

Inventor before: Shen Hao

GR01 Patent grant
GR01 Patent grant