| 引用本文: | 吴桦,罗浩,赵士顺,刘嵩涛,程光,胡晓艳.面向HTTP/2流量多路复用特征的加密视频识别方法.软件学报,2025,36(7):3375-3404 |
| |
|
| |
|
|
| 本文已被:浏览 1128次 下载 2118次 |
 码上扫一扫! |
|
|
| 面向HTTP/2流量多路复用特征的加密视频识别方法 |
|
吴桦1,2,3, 罗浩1, 赵士顺1, 刘嵩涛1, 程光1,2,3,4, 胡晓艳1,2,3
|
|
1.东南大学 网络空间安全学院, 江苏 南京 211189;2.网络通信与安全紫金山实验室, 江苏 南京 211111;3.网络空间国际治理研究基地(东南大学), 江苏 南京 211189;4.江苏省泛在网络安全工程研究中心, 江苏 南京 211189
|
|
| 摘要: |
| 视频应用平台的兴起使得视频得以快速传播并渗透社会生活的各个方面. 网络中传播的视频也混杂了一些公害视频, 因此网络空间安全监管迫切需要准确地识别网络中加密传播的公害视频. 已有方法在网络主要接入点采集流量数据, 提取加密视频流量的特征, 基于公害视频库, 通过流量特征的匹配识别出被传输的公害视频. 然而随着视频加密传输协议的更新, 使用新型多路复用技术的HTTP/2协议已经大规模部署应用, 这导致传统的基于HTTP/1.1传输特征的流量分析方法无法识别使用HTTP/2传输的加密视频. 此外, 当前的研究大多针对的是播放时分辨率固定的视频, 很少考虑到流媒体自适应播放时分辨率切换给识别带来的影响. 针对以上问题, 详细分析了视频平台使用HTTP/2协议传输视频时音视频数据长度发生偏移的原理, 并提出了将多路复用的加密数据精准修正还原为组合音视频数据单元长度的方法, 从而构建出精准还原的加密视频修正指纹. 然后, 利用加密视频修正指纹和大型视频明文指纹库, 提出了视频修正指纹滑动匹配机制和以隐马尔可夫模型与维特比算法为基础的加密视频识别模型. 该模型使用动态规划方法解决了视频分辨率自适应切换带来的问题, 其在40万级的Facebook和Instagram真实指纹库场景中, 对固定分辨率和自适应分辨率的加密视频的识别准确率分别达到了98.41%和97.91%. 使用Triller、Twitter和芒果TV这3个视频平台进行了方法通用性和泛化性验证. 与类似工作在识别效果、泛化性和时间开销方面的比较进一步验证了所提出的方法具有较高的应用价值. |
| 关键词: HTTP/2 DASH 大型数据集 修正指纹 HMM 加密视频识别 |
| DOI:10.13328/j.cnki.jos.007236 |
| 分类号:TP393 |
| 基金项目:国家重点研发计划(2021YFB3101403) |
|
| Encrypted Video Identification Method for HTTP/2 Traffic Multiplexing Features |
|
WU Hua1,2,3, LUO Hao1, ZHAO Shi-Shun1, LIU Song-Tao1, CHENG Guang1,2,3,4, HU Xiao-Yan1,2,3
|
|
1.School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China;2.Purple Mountain Laboratories for Network and Communication Security, Nanjing 211111, China;3.International Governance Research Base of Cyberspace (Southeast University), Nanjing 211189, China;4.Jiangsu Province Engineering Research Center of Security for Ubiquitous Network, Nanjing 211189, China
|
| Abstract: |
| The rise of video platforms has led to the rapid dissemination of videos, integrating them into various aspects of social life. Videos transmitted in the network may include harmful content, highlighting an urgent need for cyberspace security supervision to accurately identify harmful videos that are encrypted and transmitted in the network. The existing methods collect traffic data at main network access points to extract the features of encrypted video traffic and identify the harmful videos by matching the traffic features based on harmful video databases. However, with the progress of encryption protocol for video transmission, HTTP/2 using new multiplexing technologies has been widely applied, which makes the traditional traffic analysis method based on HTTP/1.1 features fail to identify encrypted videos using HTTP/2. Moreover, the current research mostly focuses on videos with a fixed resolution during playback. Few studies have considered the impact of resolution switching in video identification. To address the above problems, this study analyzes the factors that cause offsets in the length of the audio/video data during the HTTP/2 transmission process and proposes a method to precisely reconstruct corrected fingerprints for encrypted videos by calculating the size of the combined audio and video segments in the encrypted traffic. The study also proposes an encrypted video identification model based on the hidden Markov model and the Viterbi algorithm by using the corrected fingerprints of encrypted videos and a large plaintext fingerprint database for videos. The model applies dynamic planning to solve the problems caused by adaptive video resolution switching. The proposed model achieves identification accuracy of 98.41% and 97.91% respectively for encrypted videos with fixed and adaptive resolutions in 400000-level fingerprint databases, namely Facebook and Instagram. The study validates the generality and generalization of the proposed method using three video platforms: Triller, Twitter, and Mango TV. The higher application value of the proposed method has been validated through comparisons with similar work in terms of recognition effectiveness, generalization, and time overhead. |
| Key words: HTTP/2 DASH large database corrected fingerprinting HMM encrypted video identification |
|
|
|
|