End network information fusion detection method based on AI assistance
Through the AI-assisted end-network information fusion detection method, the problems of limited application scenarios and high rule update cost of traditional network information security detection are solved, and multi-dimensional analysis of device behavior and efficient abnormal detection are realized.
Patent Information
- Application Number
- CN202510730897.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-08-01
AI Technical Summary
Traditional network information security detection methods have limited application scenarios, small defense scope, high maintenance and update costs, and new rules are formulated dependent on professional experience and knowledge, and the data processing volume is large.
Using AI-assisted end-network information fusion detection method, the device fingerprint is constructed by collecting terminal data, generating unique device IDs, performing multi-source information fusion and abnormal feature evaluation, and using the colony distributed collaboration mechanism to build a dynamic defense network, conducting information integration traceability and causal chain reverse deduction, and combining multi-source data cross-verification and autoencoder for dynamic behavior modeling.
It realizes a comprehensive multi-dimensional analysis of equipment behavior, quickly identify high-risk equipment, reduces the labor for rule updates and data processing, and improves the efficiency and quality of abnormal behavior detection.
Smart Images

Figure CN120415871A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security detection, and in particular to an end-network information fusion detection method assisted by AI. Background Art
[0002] With the popularization of the Internet and the acceleration of the digitalization process, network information security issues have become increasingly prominent. Therefore, strengthening network information security detection and timely discovering and combating abnormal activities are of great significance for maintaining network order, protecting user rights and interests, and promoting the healthy development of the digital economy.
[0003] Traditional detection methods have limited application scenarios and a small defense scope. They mainly rely on means such as rule matching and manual experience. Rule matching is to pre-define a series of clear rules and compare the objects to be detected, including network traffic, user behavior, transaction data, etc., with these rules. If an object meets a certain rule, it is determined as a potential abnormal activity. Abnormal activity actors will continuously change means to bypass rule detection, resulting in a high cost for rule maintenance and update. The formulation of new rules needs to completely rely on the experience and knowledge of professionals to screen and analyze data and then establish, and a large amount of data needs to be processed manually, including a lot of known data. Summary of the Invention
[0004] The purpose of the present invention is to provide an end-network information fusion detection method assisted by AI to solve the problems that existing network information has limited application scenarios, a small defense scope, a high cost for rule maintenance and update, and the formulation of new rules needs to completely rely on the experience and knowledge of professionals to screen and analyze data and then establish, and a large amount of data needs to be processed manually during security detection.
[0005] The purpose of the present invention can be achieved through the following technical solutions: An end-network information fusion detection method assisted by AI includes the following steps:
[0006] S01: Collect terminal data and construct a device fingerprint.
[0007] S02: Generate a unique device ID through a hash algorithm. The device ID is provided with a prefix mark, and the ID prefix mark is used to distinguish the terminal type and establish a virtual identity for the device.
[0008] The prefix mark attached to the device ID includes a mobile phone terminal prefix mark, a laptop computer terminal prefix mark, and a desktop computer terminal prefix mark. Among them, the mobile phone terminal prefix mark is MOB-, the laptop computer terminal prefix mark is LAP-, and the desktop computer terminal prefix mark is DES-. Through the prefix mark, the terminal can be classified, which is convenient for later personnel to classify and detect information as needed and convenient for management.
[0009] S03: Multi-source information fusion, collecting application lists, behavior logs, and traffic characteristics of each different device;
[0010] S04: Abnormal feature evaluation is performed through a multi-source data cross-validation model. When a device issues a network access request, device ID matching is performed. If the device ID that issues the network access request is consistent with the ID of a previously recorded banned device, the device is prohibited from accessing the network. If the device ID that issues the network access request is inconsistent with the ID of a previously recorded banned device, a status evaluation is performed on the application list, behavior log, traffic characteristics, and device fingerprint similarity of the device that issued the network access request. If all of the application list, behavior log, traffic characteristics, and device fingerprint similarity evaluations are abnormal, the device is marked as a banned device. If at least one of the application list, behavior log, traffic characteristics, and device fingerprint similarity evaluations is abnormal, the device is marked as a risky device.
[0011] Analyze device behavior from multiple dimensions, making the analysis more comprehensive and reliable, and improving the detection capability of risky devices.
[0012] S05: A dynamic defense network is built through a distributed collaboration mechanism. When a device is marked as a risky device, the device node acts as a hub to broadcast abnormal information to the surrounding areas, quickly exposing the risky device through communication between nodes.
[0013] When a risky device is discovered, the information can be published in a timely manner and quickly spread among nodes, allowing for rapid prevention and management of the risky device.
[0014] S06: Information integration and traceability tracking, unified recording of the IDs of marked risky devices, and real-time tracking and recording of the behavior of risky devices;
[0015] S07: Reverse deduction of the causal chain: The deceived user sends a request message to the backend. The request message includes the transaction time of the deceived user. The backend obtains the device ID of the deceived user, retrieves the abnormal device ID that interacts with the user's device based on the transaction time, and provides the abnormal device ID to the backend. The backend retrieves the behavior data associated with the abnormal device ID and uses the behavior data as training data for dynamic behavior modeling. The dynamic behavior modeling method is as follows:
[0016] Obtain behavioral data for different abnormal device IDs every day, clean the data for the same abnormal device ID, and remove duplicate data;
[0017] Through cross-validation of multi-source data, known abnormal data under verification are eliminated;
[0018] An autoencoder trained with device data without abnormal behavior is used to confirm the normal behavior feature data in the behavior data and remove the known normal behavior feature data;
[0019] By cross - validating the above - mentioned multi - source data and training the autoencoder with device data without abnormal behavior, the known dangerous behavior data and normal behavior data are removed, and the remaining data is saved;
[0020] The remaining data within a predetermined time is cleaned to remove duplicate data. The data after removing duplicate data is integrated into a training package, and the training package is archived.
[0021] Furthermore, the abnormal feature evaluation includes application list evaluation, behavior log evaluation, and traffic feature evaluation. The application list evaluation is to compare the application list under each different device with the black - production tools in the library. When an application in the application list matches a black - production tool successfully, an abnormal label for the application list is attached to the device. The behavior log evaluation is to retrieve the behavior log and analyze the registration request frequency. If the frequency reaches the preset value, an abnormal label for the behavior log is attached to the device. If automated clicks, silent acquisition of the address book, location, text messages, or code injection occur, an abnormal label for the behavior log is attached to the device. The content of the traffic feature evaluation is that the requested black - production domain name and the IP address change three times within 24 hours. If the requested black - production domain name and / or the IP address change three times within 24 hours, an abnormal label for traffic is attached to the device.
[0022] Furthermore, the abnormal feature evaluation also includes device fingerprint similarity evaluation. The specific method is to retrieve the data of the blocked terminals according to the type of the device terminal sending the access request, match the obtained terminal data with the terminal data of the blocked devices, add the weights of the matching terminal data, and calculate the device fingerprint similarity between the device sending the access request and the blocked device through the formula where A is the total weight of the feature data of the device terminal sending the access request that matches the blocked device, B represents the total weight of the features of the blocked device. If S AB reaches the set threshold, a risk label is attached to the device sending the access request.
[0023] Furthermore, the collected terminal data includes mobile - phone - end data, laptop - computer - end data, and desktop - computer - end data.
[0024] Furthermore, the mobile phone data includes the screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model, processor microarchitecture timing characteristics, instruction set timing fingerprint, physical resolution, and Bluetooth chip ID, and separate feature weights are defined for the screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model, processor microarchitecture timing characteristics, instruction set timing fingerprint, physical resolution, and Bluetooth chip ID respectively.
[0025] Furthermore, the laptop data includes the CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, solid-state drive main control chip model, and WiFi chipset model, and separate feature weights are defined for the CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, solid-state drive main control chip model, and WiFi chipset model respectively.
[0026] Furthermore, the desktop computer data includes the CPU microarchitecture timing fingerprint, motherboard serial number, solid-state drive quantum fingerprint, memory particle timing difference, graphics card rendering fingerprint, and graphics card model, and separate feature weights are defined for the CPU microarchitecture timing fingerprint, motherboard serial number, solid-state drive quantum fingerprint, memory particle timing difference, graphics card rendering fingerprint, and graphics card model respectively.
[0027] Furthermore, a prefix marker is provided for the device ID, and the prefix marker includes a mobile phone prefix marker, a laptop prefix marker, and a desktop computer prefix marker.
[0028] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0029] 1. By using the multi-source data cross-validation method to evaluate anomalies of different devices, high-risk devices are directly blocked, and low-risk devices are notified for prevention. It is possible to analyze the device situation from multiple directions, and the analysis is more comprehensive.
[0030] 2. It is possible to trace and retrieve the behavior data of abnormal device terminals, integrate and clean the behavior data, and package the integrated and cleaned data for manual review by back-end personnel. The back-end personnel inject the obtained abnormal behavior data packets into the multi-source data cross-verification model. The updated multi-source data cross-verification model has stronger and wider capabilities for detecting anomalies in the application list, behavior logs, and traffic characteristics. Moreover, the updated multi-source data cross-verification model is also applied to dynamic behavior modeling, which can eliminate known dangerous behavior data, avoid the accumulation of duplicate data, reduce the data stockpile. Through the mode of screening by the above AI model in cooperation with manual work, the labor volume of personnel can be greatly reduced, and the detection efficiency and quality of abnormal behavior data can be improved, thereby enhancing the detection ability of abnormal data. It can effectively solve the problems that in the existing network information security detection, the formulation of rules needs to rely too much on the experience and knowledge of professional personnel, the cost of rule maintenance and update is relatively high, and the labor volume of manual integration and data analysis is huge. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.
[0032] Figure 1 It is a flowchart of a method for detecting end-network information fusion assisted by AI according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0034] Please refer to Figure 1 As shown, a method for detecting end-network information fusion assisted by AI includes the following steps:
[0035] S01: Collect terminal data and construct device fingerprints. The collection of terminal data includes mobile phone terminal data, laptop computer terminal data, and desktop computer terminal data. The mobile phone terminal data includes screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model, and processor microarchitecture timing characteristics, instruction set timing fingerprint, physical resolution, and Bluetooth chip ID. The laptop computer terminal data includes CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, solid-state drive main control chip model, and WiFi chipset model. The desktop computer data includes CPU microarchitecture timing fingerprint, motherboard serial number, solid-state drive quantum fingerprint, memory particle timing difference, graphics card rendering fingerprint, and graphics card model;
[0036] S02: Generate a unique device ID through a hashing algorithm. The device ID has a prefix marker, which is used to distinguish terminal types, establish a virtual identity for the device, and match the device ID with the blacklist in the library. Problem devices can be quickly identified, and information tracking and management can be carried out on them;
[0037] The prefix markers attached to the device ID include the mobile phone prefix marker, the laptop prefix marker, and the desktop computer prefix marker. Among them, the mobile phone prefix marker is MOB-, the laptop prefix marker is LAP-, and the desktop computer prefix marker is DES-. The terminals can be classified through the prefix markers, which is convenient for later personnel to classify and detect information as needed and facilitates management;
[0038] S03: Multi-source information fusion, collecting the application list, behavior logs, and traffic characteristics under each different device;
[0039] S04: Conduct an abnormal feature evaluation through a multi-source data cross-verification model. When a device sends a network access application, perform device ID matching processing. If the device ID of the device sending the network access application is the same as the pre-recorded blocked device ID, the device is prohibited from accessing the network. If the device ID of the device sending the network access application is different from the pre-recorded blocked device ID, conduct a status evaluation on the application list, behavior logs, traffic characteristics, and device fingerprint similarity of the device sending the network access application. If all of the application list, behavior logs, traffic characteristics, and device fingerprint similarity evaluations are in an abnormal state, mark the device as a blocked device. If there is more than one item in the application list, behavior logs, traffic characteristics, and device fingerprint similarity evaluations that are in an abnormal state, mark the device as a risky device;
[0040] The abnormal feature evaluation includes application list evaluation, behavior log evaluation, and traffic characteristic evaluation. The application list evaluation is to compare the application list under each different device with the black production tools in the library. When an application in the application list matches a black production tool successfully, attach an application list abnormal label to the device. The behavior log evaluation is to retrieve the behavior logs and analyze the registration request frequency. If the frequency reaches the preset value, attach a behavior log abnormal label to the device. If automated clicks, background silent acquisition of the address book, location, text messages, or code injection occur, attach a behavior log abnormal label to the device. The content of the traffic characteristic evaluation is to request a black production domain name and the IP location changes three times within 24 hours. If a request for a black production domain name and / or the IP location changes three times within 24 hours, attach a traffic abnormal label to the device;
[0041] S05: A dynamic defense network is built through a distributed collaboration mechanism. When a device is marked as a risky device, the device node acts as the hub to broadcast abnormal information to the surrounding areas. This information is quickly disclosed through communication between nodes, and connections to the risky device can be blocked through firewalls. Backend personnel can promptly obtain the risky device for tracking and analysis.
[0042] S06: Information integration and traceability, unified recording of the IDs of marked dangerous equipment, and real-time tracking and recording of the behavior of dangerous equipment;
[0043] S07: Reverse deduction of the causal chain. The deceived user sends a request message to the backend. The request message includes the transaction time of the deceived user. The backend obtains the device ID of the deceived user, retrieves the abnormal device ID that interacts with the user's device according to the transaction time, and provides the abnormal device ID to the backend. The backend retrieves the behavioral data under the abnormal device ID and uses the behavioral data as training data for dynamic behavior modeling. The dynamic behavior modeling method is as follows: obtain behavioral data under different abnormal device IDs every day, clean the data under the same abnormal device ID, and remove duplicate data; remove known abnormal data under verification through multi-source data cross-validation; use the autoencoder trained with data from devices without abnormal behavior to confirm normal behavior feature data in the behavior data and remove known normal behavior feature data; remove known dangerous behavior data and normal behavior data through multi-source data cross-validation and training of the autoencoder with data from devices without abnormal behavior, and save the remaining data; clean the remaining data within the predetermined time, remove duplicate data, and integrate the data after removing duplicate data into a training package;
[0044] Through the above-mentioned dynamic behavior modeling method, different training data are eliminated every day based on the autoencoder trained on the data of the device without abnormal behavior and the multi-source data cross-validation, and the remaining data within a natural month are cleaned. The cleaning time can be customized, and the duplicate data are integrated into the training package, which is saved. The training package is manually analyzed to obtain the abnormal behavior data packet, and the abnormal behavior data packet is manually injected into the multi-source data cross-validation model. The updated multi-source data cross-validation model has a stronger and wider detection capability for application lists, behavior logs, and traffic characteristics. The updated multi-source data cross-validation model is also applied to dynamic behavior modeling, which can eliminate known dangerous behavior data, avoid the accumulation of duplicate data, and reduce the data inventory. The above-mentioned AI model screening and manual coordination mode can greatly reduce the workload of personnel, and improve the detection efficiency and quality of abnormal behavior data, thereby improving the detection capability of abnormal data;
[0045] The abnormal feature evaluation also includes the evaluation of device fingerprint similarity. The specific method is to retrieve the corresponding terminal data according to the device terminal type that sends the access request. Each type of terminal is defined with a device fingerprint similarity formula. The device fingerprint similarity between the device that sends the access request and the blocked device is calculated through the formula. If the threshold is reached, the device that sends the access request is blocked.
[0046] When in use, if the device that sends the access request is a laptop computer terminal, its terminal data is obtained, including CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, solid-state drive main control chip model, WiFi chipset model. The weight of the CPU model is defined as 0.2, the weight of the processor microarchitecture timing characteristics is defined as 0.3, the weight of the GPU model is defined as 0.1, the weight of the GPU rendering fingerprint is defined as 0.3, the weight of the physical resolution is defined as 0.1, the weight of the wired network card MAC address is defined as 0.1, the weight of the solid-state drive main control chip model is defined as 0.1, and the weight of the WiFi chipset model is defined as 0.1. The obtained terminal data is matched with the terminal data of the blocked device, and the weights of the matched terminal data are added together to obtain A. Specifically, if the CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, solid-state drive main control chip model, and WiFi chipset model of the device that sends the access request are all the same as the CPU model, processor microarchitecture timing characteristics, GPU model, GPU rendering fingerprint, physical resolution, wired network card MAC address, and solid-state drive main control chip model of the blocked device, and only the WiFi chipset model is different, then the weights of the features with the same information are added together. Specifically, 0.2 + 0.3 + 0.1 + 0.3 + 0.1 + 0.1 + 0.1 = 1.2, and then through the formula Obtain the similarity value between the mobile device that sends the access request and the blocked mobile device. B represents the total weight of the blocked device, that is, 0.2 + 0.3 + 0.1 + 0.3 + 0.1 + 0.1 + 0.1 + 0.1 = 1.3. For S AB Judge the value. If S AB ≥0.76, then mark the device as a risky device. According to the above weight definition, the specific performance is
[0047] If the device sending the access request is a mobile phone, obtain its terminal data, including the screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model and processor microarchitecture timing characteristics, instruction set timing fingerprint, physical resolution, and Bluetooth chip ID. Match the obtained terminal data with the terminal data of the banned device, and add the weights of the matched terminal data to obtain A. The weight of the screen color temperature curve is set to 0.2, the weight of the IMEI is set to 0.3, the weight of the baseband chip ID is set to 0.3, the weight of the SN serial number is set to 0.3, the weight of the CPU model is set to 0.2, the weight of the processor microarchitecture timing characteristics is set to 0.3, the weight of the instruction set timing fingerprint is set to 0.3, the weight of the physical resolution is set to 0.1, and the weight of the Bluetooth chip ID is set to 0.1. Through the formula Obtain the similarity value between the mobile phone device sending the access request and the banned mobile phone device. B represents the total weight of the banned device. For S AB Judge the value. If S AB ≥0.7, mark the device as a risky device;
[0048] If the device sending the access request is a desktop computer, obtain its terminal data, including the CPU microarchitecture timing fingerprint, motherboard serial number, solid-state drive quantum fingerprint, memory particle timing difference, graphics card rendering fingerprint, and graphics card model. The weight of the CPU microarchitecture timing fingerprint is defined as 0.3, the weight of the motherboard serial number is defined as 0.3, the weight of the solid-state drive quantum fingerprint is defined as 0.1, the weight of the memory particle timing difference is defined as 0.1, the weight of the graphics card rendering fingerprint is defined as 0.2, and the weight of the graphics card model is defined as 0.1. Match the obtained terminal data with the terminal data of the banned device, and add the weights of the matched terminal data to obtain A. Through the formula Obtain the similarity value between the desktop computer device sending the access request and the banned desktop computer device. B represents the total weight of the banned device. For S AB Judge the value. If s AB ≥0.72, mark the device as a risky device;
[0049] Through the end-network information fusion technology, the present invention can integrate the local behavior data and network traffic data of terminal devices, make up for the limitations of a single data source, use machine learning to mine abnormal behavior patterns from the fused data, and has the characteristics of wide data source coverage, large data volume, and fast update of abnormal behavior data. It can automatically integrate a large amount of abnormal data, eliminate repetitive data, and finally provide the packaged training package to the back-end personnel in sequence, greatly reducing the workload of the back-end personnel for data processing and enabling rapid analysis and management of key data.
[0050] The preferred embodiments of the present invention disclosed above are only used to assist in the description of the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. An end-network information fusion detection method assisted by AI, characterized in that The steps include: S01: Collect terminal data and build device fingerprint; S02: Generate a unique device ID through a hash algorithm. The device ID has a prefix tag. The ID prefix tag is used to distinguish the terminal type and establish a virtual identity for the device. S03: Multi-source information fusion, collecting application lists, behavior logs, and traffic characteristics of each different device; S04: Abnormal feature evaluation is performed through a multi-source data cross-validation model. When a device issues a network access request, device ID matching is performed. If the device ID that issues the network access request is consistent with the ID of a previously recorded banned device, the device is prohibited from accessing the network. If the device ID that issues the network access request is inconsistent with the ID of a previously recorded banned device, a status evaluation is performed on the application list, behavior log, traffic characteristics, and device fingerprint similarity of the device that issued the network access request. If all of the application list, behavior log, traffic characteristics, and device fingerprint similarity evaluations are abnormal, the device is marked as a banned device. If at least one of the application list, behavior log, traffic characteristics, and device fingerprint similarity evaluations is abnormal, the device is marked as a risky device. S05: A dynamic defense network is built through a distributed collaboration mechanism. When a device is marked as a risky device, the device node acts as a hub to broadcast abnormal information to the surrounding areas, quickly exposing the risky device through communication between nodes. S06: Information integration and traceability tracking, unified recording of the IDs of marked risky devices, and real-time tracking and recording of the behavior of risky devices; S07: Reverse deduction of the causal chain: The deceived user sends a request message to the backend. The request message includes the transaction time of the deceived user. The backend obtains the device ID of the deceived user, retrieves the abnormal device ID that interacts with the user's device based on the transaction time, and provides the abnormal device ID to the backend. The backend retrieves the behavior data associated with the abnormal device ID and uses the behavior data as training data for dynamic behavior modeling. The dynamic behavior modeling method is as follows: Obtain behavioral data for different abnormal device IDs every day, clean the data for the same abnormal device ID, and remove duplicate data; Through cross-validation of multi-source data, known abnormal data under verification are eliminated; An autoencoder trained with data from devices without abnormal behavior identifies normal behavior feature data in the behavior data and removes known normal behavior feature data; Through the above multi-source data cross-validation and the training of the autoencoder with data from devices without abnormal behavior, known dangerous behavior data and normal behavior data are eliminated, and the remaining data is saved; The remaining data within the scheduled time is cleaned, duplicate data is removed, the data after duplicate data removal is integrated into a training package, and the training package is archived.
2. The method for detecting the end-network information fusion based on AI assistance according to claim 1, wherein, The abnormal feature evaluation includes application list evaluation, behavior log evaluation, and traffic feature evaluation. The application list evaluation is to compare the application list under each different device with the black production tools in the library. When an application in the application list matches a black production tool successfully, an application list abnormal label is attached to the device. The behavior log evaluation is to retrieve the behavior log and analyze the registration request frequency. If the frequency reaches the preset value, a behavior log abnormal label is attached to the device. If automated clicks, background silent acquisition of the address book, location, SMS, or code injection occur, a behavior log abnormal label is attached to the device. The content of the traffic feature evaluation is that the black production domain name is requested and the IP location changes three times within 24 hours. If the black production domain name and / or the IP location change three times within 24 hours, a traffic abnormal label is attached to the device.
3. The AI-assisted end-network information fusion detection method according to claim 1, wherein, The abnormal feature evaluation also includes the evaluation of device fingerprint similarity. Specifically, the data of the corresponding blocked terminals is retrieved according to the device terminal type that sends the access request, and the obtained terminal data is matched with the terminal data of the blocked device. The terminal data with consistent matches is weighted and added together. Through the formula Calculate the device fingerprint similarity between the device sending the access request and the blocked device. Among them, A is the total weight of the features of the device terminal sending the access request that matches the blocked device, and B represents the total weight of the features of the blocked device. If S AB Reaches the set threshold, then a risk mark is made for the device that sends the access request.
4. The method for detecting the end - network information fusion based on AI assistance according to claim 1, wherein, The collection of terminal data includes mobile phone data, laptop data, and desktop computer data.
5. A method for detecting end-to-network information fusion assisted by AI according to claim 1 or 4, characterized in that The mobile phone data includes the screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model, and the timing characteristics of the processor microarchitecture, the timing fingerprint of the instruction set, the physical resolution, and the Bluetooth chip ID. The screen color temperature curve, IMEI, baseband chip ID, SN serial number, CPU model, and the timing characteristics of the processor microarchitecture, the timing fingerprint of the instruction set, the physical resolution, and the Bluetooth chip ID are each defined with a separate feature weight.
6. The method for detecting the end-network information fusion assisted by AI according to claim 1, wherein, The laptop data includes the CPU model, the timing characteristics of the processor microarchitecture, the GPU model, the GPU rendering fingerprint, the physical resolution, the MAC address of the wired network card, the model of the solid-state drive main control chip, and the WiFi chipset model. The CPU model, the timing characteristics of the processor microarchitecture, the GPU model, the GPU rendering fingerprint, the physical resolution, the MAC address of the wired network card, the model of the solid-state drive main control chip, and the WiFi chipset model are each defined with a separate feature weight.
7. An AI-assisted end-network information fusion detection method according to claim 1, characterized in that, The desktop computer data includes the timing fingerprint of the CPU microarchitecture, the motherboard serial number, the quantum fingerprint of the solid-state drive, the timing difference of the memory particles, the rendering fingerprint of the graphics card, and the graphics card model. The timing fingerprint of the CPU microarchitecture, the motherboard serial number, the quantum fingerprint of the solid-state drive, the timing difference of the memory particles, the rendering fingerprint of the graphics card, and the graphics card model are each defined with a separate feature weight.
8. An AI-assisted end-network information fusion detection method according to claim 1, characterized in that The device ID has a prefix tag, and the prefix tag includes the mobile phone prefix tag, the laptop prefix tag, and the desktop computer prefix tag.
Citation Information
Cited By
Video tracing fingerprint processing method and system and medium
CN120915965A