Terminal identification method and device
The clustering method of terminal open port information solves the problem of low terminal recognition rate in the prior art and realizes effective recognition of various types of terminals, especially accurate recognition of dumb terminals and non-networked terminals.
Patent Information
- Application Number
- CN202410332525.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-09-23
AI Technical Summary
Existing terminal identification methods cannot effectively identify various types of terminals, resulting in a low recognition rate. In particular, it is difficult to accurately identify dumb terminals and terminals that are not connected to the network and do not generate business traffic.
By obtaining the open port information of the terminal, the terminals are clustered according to the similarity of the port information, and the terminal clusters belonging to the same type are identified.
The accuracy and recognition rate of terminal identification are improved to meet the identification needs of various types of terminals, including dumb terminals and terminals that are not connected to the network and generate business traffic.
Smart Images

Figure CN120692559A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminal technology, and in particular to a method and device for identifying a terminal. Background Art
[0002] With the development of technologies such as automation, intelligence, and the Internet of Things, a wide variety of terminals have emerged to provide users with relevant services. For example, in government affairs, the emergence of terminals such as government kiosks, queue checkers, evaluators, and information screens facilitates users in handling government affairs. Similarly, in education, the emergence of terminals such as electronic class signs, multimedia teaching devices, and facial recognition devices facilitates work in the education sector.
[0003] In networks, it's often necessary to identify terminals accessing the network to facilitate functions such as asset management, secure access, and network optimization. Terminal identification methods include: Method 1, which identifies the terminal based on a match between its fingerprint and fingerprint information in a fingerprint database; and Method 2, which identifies the terminal based on its traffic characteristics. However, neither of these two methods can effectively identify the rapidly evolving variety of terminals, resulting in low terminal recognition rates. Summary of the Invention
[0004] Based on this, the present application provides a terminal identification method and device, which can ensure effective identification of the terminal even if there are a variety of terminals in the network, and can improve the recognition rate of the terminal to a certain extent.
[0005] In a first aspect, the present application provides a terminal identification method, wherein an identification device obtains open port information of multiple terminals and clusters the multiple terminals based on the open port information of each terminal, thereby identifying at least one cluster to which the multiple terminals belong based on the clustering results. The open port information of each terminal indicates at least one open port of each terminal, and the terminals included in each of the at least one cluster are of the same type. Thus, considering that terminals generally require specific ports to be opened to connect to the server corresponding to the terminal, and different types of terminals require different specific ports to be opened, the method clusters the terminals to be identified based on the open port information of the terminals to be identified. In the clustering results, the open port information of the terminals belonging to the same cluster is similar, and the terminals belonging to the same cluster are likely to be of the same type, thereby achieving effective and accurate identification of the terminals. In scenarios where various types of terminals emerge in an endless stream, the terminal identification rate can be guaranteed, overcoming the problem that current terminal identification methods require the accumulation of terminal fingerprint information or the service traffic (or service messages) after the terminal joins the network, which cannot guarantee the terminal identification rate.
[0006] In some possible implementations, if there is at least one cluster of a known type in the network, then the "multiple terminals" in the method may refer to terminals that are newly connected to the network during the time interval from the last identification of the terminals in the network to the current execution of the method. The identification device clusters the multiple terminals based on the open port information of the multiple terminals, which may include: the identification device determines the cluster of the known type to which each terminal in the multiple terminals belongs based on the similarity between the open port information of the multiple terminals and the open port information of each cluster of the known type. In this way, by comparing the similarity between the open port information of the terminal to be identified and the open port information of the cluster of the known type, the terminal to be identified is classified into a reasonable cluster of the known type, thereby determining the type of the terminal to be identified belonging to the cluster of the known type through the type of the cluster of the known type, thereby completing the clustering and identification of the terminal to be identified.
[0007] In some possible implementations, if no clusters of known types exist in the network, for example, if this method is being executed for the first time to identify terminals in the network, then the identification device clustering the multiple terminals based on their open port information may include: the identification device clustering the multiple terminals based on the similarity of their open port information. Thus, by comparing the similarity of the open port information between the terminals to be identified, the terminals with similar open port information are clustered into a single cluster. The type of each cluster is then used to determine the type of the terminals to be identified belonging to that cluster, thereby completing the clustering and identification of the terminals to be identified.
[0008] In some possible implementations, to further improve the reliability of terminal identification, the terminal type may be identified based on the terminal's open port information in combination with other terminal information. Taking into account the characteristics of how the network assigns addresses to terminals and how users assign addresses to their own terminals, other terminal information may include, but is not limited to, the terminal's Media Access Control (MAC) address and / or the terminal's Internet Protocol (IP) address.
[0009] As an example, the identification device can identify the types of multiple terminals based on the MAC addresses of the multiple terminals and the open port information of the multiple terminals. In this example, the method may also include: the identification device obtains the MAC address of each terminal in the multiple terminals, then the identification device clustering the multiple terminals may include: the identification device clustering the multiple terminals based on the open port information of each terminal and the MAC address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the MAC address between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the MAC address of the terminal and the open port information of the terminal, the type of the terminal can be accurately identified through clustering.
[0010] As another example, the identification device can identify the types of multiple terminals based on the IP addresses of the multiple terminals and the open port information of the multiple terminals. In this example, the method can also include: the identification device obtains the IP address of each of the multiple terminals. Then, the identification device clustering the multiple terminals can include: the identification device clustering the multiple terminals based on the open port information of each terminal and the IP address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the IP addresses between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the IP address and the open port information of the terminal, the terminal type can be accurately identified through clustering.
[0011] As another example, the identification device can identify the types of multiple terminals based on the MAC addresses of multiple terminals, the IP addresses of multiple terminals, and the open port information of multiple terminals. In this example, the method can also include: the identification device obtains the MAC address and IP address of each terminal in the multiple terminals. Then, the identification device clustering the multiple terminals can include: the identification device clustering the multiple terminals based on the open port information of each terminal, the MAC address of each terminal, and the IP address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal, the similarity of the MAC addresses between each terminal, and the similarity of the IP addresses between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the MAC address of the terminal, the IP address of the terminal, and the open port information of the terminal, the type of the terminal can be accurately identified through clustering.
[0012] In some possible implementations, if the identification device and the port scanning device belong to different devices, then the identification device obtaining the open port information of multiple terminals may include: the identification device receiving the open port information of the multiple terminals sent by the port scanning device. In a specific implementation, the port scanning device performs port scanning on the multiple terminals, obtains the open port information of the multiple terminals, and then the device where the port scanning device resides sends the open port information of the multiple terminals to the device where the identification device resides, providing a data foundation for the identification device to implement the method provided in this application to achieve identification of the multiple terminals.
[0013] In other possible implementations, if the identification device and the port scanning device belong to the same device, then the identification device obtains the open port information of multiple terminals, which may include: the device where the identification device is located performs port scanning on each of the multiple terminals to obtain the open port information of each of the multiple terminals. In specific implementation, inside the device where the identification device and the port scanning device are located, the port scanning device first performs port scanning on the multiple terminals to obtain the open port information of the multiple terminals, and then the port scanning device synchronizes the obtained open port information of the multiple terminals to the identification device, providing a data basis for the identification device to implement the method provided in this application to realize the identification of multiple terminals.
[0014] The open port information of each terminal among the multiple terminals may refer to the open port information obtained by a port scanning device through a port scanning of all or some of the designated ports of the terminal. The designated ports may be commonly used ports to be detected (e.g., the top 100 most commonly used ports in a commonly used port list), or may be special ports to be detected (e.g., ports with designated port numbers based on actual application scenario requirements). Therefore, when the port scanning device performs a port scan on the terminal, the port scanning device needs to send port detection messages corresponding to each designated port to the terminal, and the number of port detection messages sent is the same as the number of designated ports of the terminal.
[0015] Wherein, the multiple terminals may be all terminals in the network, and the identification device obtaining the open port information of all terminals in the network may include: the identification device performing a port scan on all terminals in the network to obtain the open port information of the multiple terminals. Alternatively, the multiple terminals may be terminals in a target network segment in the network, and the identification device obtaining the open port information of all terminals in the target network segment in the network may include: the identification device performing a port scan on terminals in the target network segment to obtain the open port information of the multiple terminals. Alternatively, the terminals may be terminals in a target virtual local area network (VLAN) in the network, and the identification device obtaining the open port information of all terminals in the target VLAN in the network may include: the identification device performing a port scan on terminals in the target VLAN to obtain the open port information of the multiple terminals. Alternatively, the multiple terminals may be terminals in a target broadcast domain (Bridge Domain, BD) in the network, and the identification device obtaining the open port information of all terminals in the target BD in the network may include: the identification device performing a port scan on terminals in the target BD to obtain the open port information of the multiple terminals. It can be seen that the range of terminals to be identified in this application can be flexibly designed based on actual needs.
[0016] In some possible implementations, the identification device identifies at least one cluster to which multiple terminals belong based on the clustering results, which may include: the identification device determines the type of each cluster in the at least one cluster, and the type of each cluster is the type of the terminal belonging to the cluster. Therefore, determining the type of each cluster is equivalent to determining the types of multiple terminals, thereby realizing effective identification of the terminals.
[0017] As an example, the identification device determines the type of each cluster in at least one cluster, which may include: automatically identifying the types of some clusters, and displaying the type of one or more clusters whose specific types cannot be identified as unknown types; and manually marking the specific types of the one or more clusters. In this way, through the method of automatic identification + manual marking, the type of each cluster can be determined to ensure the recognition rate of the terminal. Among them, the identification device's marking of the specific type of the unknown type cluster may, for example, include: for any first cluster in the unknown type cluster, identifying the type of one or more terminals in the first cluster, and marking the type as the type of the first cluster. In this way, after automatic identification, the type of the cluster is marked by the identification results of a small number of terminal types in each cluster of the unknown type, thereby achieving efficient marking of the cluster and achieving efficient terminal identification.
[0018] As another example, the identification device determining the type of each cluster in at least one cluster may include automatically identifying the types of all clusters. For example, for any second cluster in at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes a first target port, the identification device determines that the type of the second cluster is the first type corresponding to the first target port. For another example, for any second cluster in at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, the identification device determines that the type of the second cluster is the first type. In this way, for each cluster in the at least one determined cluster, the identification device can automatically identify the type of the cluster, thereby realizing intelligent identification of the terminals.
[0019] As another example, in the step of determining the type of each cluster in at least one cluster, the recognition device may, after automatically identifying the type of the cluster, identify the type of the cluster as a candidate type, prompt and wait for the user to confirm or edit the candidate type to finally determine the type of the cluster. This example can be considered an automatic recognition + manual confirmation method. In this example, the recognition device determining the type of each cluster in at least one cluster may include: for any second cluster in the at least one cluster, determining the type of the second cluster as a first type based on automatic recognition; then, in response to an edit operation or a confirmation operation on the first type of the second cluster, determining the type of the second cluster as a second type. If the user confirms the first type of the second cluster, the second type is the same as the first type. If the user finds that the automatic recognition result (i.e., the first type) is inaccurate, the user may identify the type of the second cluster using any other method, determine the second cluster as the second type, and then perform an edit operation on the first type of the second cluster to change the type of the second cluster from the first type to the second type. In this case, the second type is different from the first type. In this way, the automatic recognition + manual confirmation method can improve the accuracy of terminal recognition while ensuring recognition efficiency.
[0020] In some possible implementations, to further improve the accuracy of terminal identification results, the method may further include: the identification device correcting the clustering results. As an example, when the terminal type is inconsistent with the type of the cluster to which the terminal belongs, the identification device changes the cluster to which the terminal belongs based on the terminal type. In this way, by correcting the clustering results, higher-precision terminal identification can be achieved.
[0021] In some possible implementations, the method may further include: the identification device performing network admission control on the terminal based on the type of the terminal. Alternatively, the method may further include: the identification device sending configuration information to the terminal of that type based on the type of the terminal.
[0022] In some possible implementations, the method may be applied to a network controller, and the identification device may be a functional module of the network controller that is used to implement the method provided in this application. For example, the network controller may be a Network Admission Controller (NAC), and the identification device may be a functional module of the NAC that is used to implement the method provided in this application.
[0023] In a second aspect, the present application also provides a terminal identification method, which is applied to a terminal to be identified. The method may, for example, include: the terminal to be identified receiving a port detection message for a target port of the terminal to be identified; if the target port is open, the terminal to be identified sending a response message to the port detection message for the target port, the response message being used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified. Thus, considering that a terminal generally requires opening a specific port to connect to a server corresponding to the terminal, and different types of terminals require different specific ports to be opened, the method performs a port scan on the terminal to be identified to obtain the open port information of the terminal to be identified, thereby using this information as a basis for identifying the type of the terminal to be identified. In scenarios where various types of terminals emerge in an endless stream, the terminal identification rate can be guaranteed, overcoming the problem that current terminal identification methods require the accumulation of terminal fingerprint information or the service traffic (or service messages) after the terminal joins the network, which cannot guarantee the terminal identification rate.
[0024] It should be noted that for the relevant description of the method of the second aspect, please refer to the corresponding description of the first aspect.
[0025] In a third aspect, the present application also provides a terminal identification device, which can be used in an identification device. The device may include: an acquisition unit and a processing unit. The acquisition unit is configured to acquire open port information for multiple terminals, where the open port information for each terminal indicates at least one open port of each terminal; the processing unit is configured to cluster the multiple terminals based on the open port information for each terminal; and the processing unit is further configured to identify, based on the clustering results, at least one cluster to which the multiple terminals belong, where the terminals included in each cluster are of the same type.
[0026] In some possible implementations, the acquisition unit of the device is further configured to acquire the MAC address of each terminal; and the processing unit is specifically configured to cluster the multiple terminals according to the open port information of each terminal and the MAC address of each terminal.
[0027] In some possible implementations, the acquisition unit of the device is further configured to acquire the IP address of each terminal; and the processing unit is specifically configured to cluster the multiple terminals according to the open port information of each terminal and the IP address of each terminal.
[0028] In some possible implementations, the acquiring unit is specifically configured to receive open port information of multiple terminals sent by a port scanning device.
[0029] In some possible implementations, the acquiring unit is specifically configured to acquire open port information of multiple terminals by performing port scanning on all ports or some designated ports of each terminal.
[0030] In some possible implementations, the acquiring unit specifically performs any one of the following steps:
[0031] Scan ports of all terminals in the network to obtain information about open ports of multiple terminals.
[0032] Alternatively, by performing port scanning on terminals in the target network segment, information on open ports of multiple terminals can be obtained;
[0033] Alternatively, the open port information of multiple terminals can be obtained by performing port scanning on the terminals in the target VLAN;
[0034] Alternatively, the open port information of multiple terminals is obtained by performing port scanning on the terminals in the target BD.
[0035] In some possible implementations, the processing unit is specifically configured to: cluster the multiple terminals according to similarities in the open port information of the multiple terminals.
[0036] In some possible implementations, the processing unit is specifically configured to determine the cluster of the known type to which each of the multiple terminals belongs based on similarities between the open port information of the multiple terminals and the open port information of each cluster of the known type.
[0037] In some possible implementations, the processing unit is specifically configured to: determine a type of each cluster in the at least one cluster.
[0038] As an example, the processing unit is specifically configured to: for one or more clusters whose specific types cannot be identified, display the type of one or more clusters as unknown; and manually mark the specific type of one or more clusters. The processing unit is also configured to mark the specific type of clusters of unknown types. The processing unit is specifically configured to: for any first cluster of the unknown type clusters, identify the type of one or more terminals in the first cluster and mark the type as the type of the first cluster.
[0039] As another example, the processing unit is specifically configured to: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determine the type of the second cluster to be the first type corresponding to the first target port.
[0040] As another example, the processing unit is specifically configured to: for any second cluster in the at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determine that the type of the second cluster is the first type.
[0041] For the second cluster, the processing unit is further configured to, in response to an edit operation or a confirmation operation of the first type on the second cluster, determine that the type of the second cluster is a second type, which is the same as or different from the first type.
[0042] In some possible implementations, the processing unit of the device is further configured to correct the clustering result.
[0043] As an example, the processing unit is specifically configured to: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, change the cluster to which the terminal belongs according to the type of the terminal.
[0044] In some possible implementations, the processing unit of the device is further configured to perform network admission control on the terminal based on the type of the terminal.
[0045] In some possible implementations, the processing unit of the device is further configured to send configuration information to a terminal of the type based on the type of the terminal.
[0046] In some possible implementations, the device is applied to a network controller, that is, the device may be the network controller itself, or may be a functional module belonging to the network controller for implementing the method provided in this application. The network controller may be, for example, a NAC.
[0047] It should be noted that for the relevant description of the device of the third aspect, please refer to the corresponding description of the first aspect.
[0048] In a fourth aspect, the present application also provides a terminal identification device, which is applied to a terminal to be identified. The device may include: a receiving unit and a sending unit. The receiving unit is configured to receive a port detection message for a target port of the terminal to be identified; and the sending unit is configured to send a response message to the port detection message for the target port if the target port is open, wherein the response message is used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified.
[0049] It should be noted that for the relevant description of the device of the fourth aspect, please refer to the corresponding description of the second aspect.
[0050] In a fifth aspect, the present application provides a communication device, the communication device comprising a communication interface and a processor;
[0051] A communication interface for executing the method provided by the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect;
[0052] A processor is used to execute the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0053] In a sixth aspect, the present application further provides a communication device, the communication device comprising a memory and a processor;
[0054] a memory for storing instructions;
[0055] A processor is used to execute the instructions in the memory and execute the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0056] In a seventh aspect, the present application further provides a communication system, the communication system comprising a terminal identification device and a terminal to be identified;
[0057] A terminal identification device, configured to execute the first aspect or any possible implementation of the first aspect to identify the terminal to be identified;
[0058] The terminal to be identified is used to execute the method provided by the aforementioned second aspect or any possible implementation of the second aspect.
[0059] In the eighth aspect, the present application also provides a storage medium, which includes instructions. When the instructions are run on a processor, the processor executes the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0060] In the ninth aspect, the present application also provides a program product, which includes a program. When the program runs on a processor, it executes the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0061] In the tenth aspect, the present application provides a chip comprising a memory and a processor, the memory being used to store instructions, and the processor being used to call and execute the instructions from the memory to implement the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0063] Figure 1 A schematic diagram of a network architecture applicable to an embodiment of the present application;
[0064] Figure 2 A schematic diagram of a flow chart of a terminal identification method 100 provided in an embodiment of the present application;
[0065] Figure 3 A schematic diagram of a network framework applicable to an embodiment of the present application;
[0066] Figure 4 In the embodiment of this application Figure 3 A schematic flow chart of the corresponding method 200;
[0067] Figure 5 A schematic diagram of another applicable network framework in an embodiment of the present application;
[0068] Figure 6 In the embodiment of this application Figure 5 A schematic flow chart of the corresponding method 300;
[0069] Figure 7 4 is a flow chart of a terminal identification method 400 according to an embodiment of the present application;
[0070] Figure 8 This is a schematic structural diagram of a communication device 800 according to an embodiment of the present application;
[0071] Figure 9 This is a schematic structural diagram of a communication device 900 according to an embodiment of the present application;
[0072] Figure 10 This is a structural diagram of a communication device 1000 according to an embodiment of the present application;
[0073] Figure 11 11 is a schematic structural diagram of a communication system 1100 in an embodiment of the present application. DETAILED DESCRIPTION
[0074] With the development of the Internet of Things (IoT), a wide variety of terminals have emerged to meet the increasingly complex functional requirements of various industries in their respective scenarios. Different types of terminals are used to implement different functions. In different business scenarios, users can select and deploy corresponding terminal types based on their needs. It is often necessary to identify the type of terminal accessing the network. This identification is used to perform network asset management, security access, and network optimization based on the identified terminal type. Therefore, accurate identification of terminals in the network is a crucial and necessary step in the network operation.
[0075] The following is an introduction to the currently used terminal identification methods.
[0076] In one method, the identification device can identify the terminal based on the fingerprint information of the terminal. This method can be divided into active terminal identification and passive terminal identification according to the method of obtaining the fingerprint information of the terminal. Among them, active terminal identification can refer to the identification device scanning the terminal through a possible scanning method, obtaining the fingerprint information of the terminal from the response information of the terminal to the scan, and determining the type of the terminal by matching the obtained fingerprint information with the fingerprint information in the fingerprint library. The scanning method that the identification device may use to scan the terminal includes but is not limited to any one of the following methods: Simple Network Management Protocol (SNMP) query scanning method, Network Mapper (NMAP) operating system (OS) scanning method or other dynamically extensible detection script scanning method. Passive terminal identification can refer to the identification device collecting the fingerprint information of the terminal and determining the type of the terminal by matching the collected fingerprint information with the fingerprint information in the fingerprint library.
[0077] Among them, the fingerprint information may refer to information in the relevant information of the terminal that can be used to identify the terminal, and the fingerprint information may include but is not limited to at least one of the following information: Medium Access Control (MAC) Organizationally Unique Identifier (OUI), Dynamic Host Configuration Protocol Option (DHCP Option), Hypertext Transfer Protocol (Hypertext Transfer Protocol) User Agent (UA), Multicast Domain Name Service (mDNS) or Link Layer Discovery Protocol (LLDP).
[0078] A fingerprint library may refer to a database that stores fingerprint information for terminals of known types. The fingerprint library may store multiple sets of correspondences between fingerprint information and corresponding terminal types. Therefore, in the above-mentioned terminal identification method, the identification device matches the fingerprint information of the terminal to be identified with the fingerprint information in the fingerprint library to determine the terminal type. Specifically, the identification device searches for fingerprint information that matches the fingerprint information of the terminal to be identified from the multiple sets of fingerprint information in the fingerprint library, and determines the terminal type in the correspondence relationship where the matching fingerprint information exists as the type of the terminal to be identified.
[0079] It can be seen that in this method, whether the terminal to be identified can be identified depends on whether the fingerprint database has accumulated a corresponding relationship including the fingerprint information of the terminal to be identified. If so, the terminal to be identified can be identified; if not, the terminal to be identified cannot be identified. Therefore, this method of identifying terminals based on their fingerprint information is difficult to guarantee recognition rate for the diverse types of terminals currently used in various industries. If the fingerprint information of a certain type of terminal is not accumulated in the fingerprint database, then this method cannot identify that type of terminal.
[0080] In another approach, the identification device can identify terminals through clustering based on the characteristics of the service traffic or service messages generated by the terminals after they join the network. For example, the identification device clusters multiple terminals to be identified based on the waveform similarity of the service traffic generated by the multiple terminals after they join the network, and manually labels the type corresponding to each cluster to determine that the terminal type is the type of the class to which the terminal belongs. For another example, the identification device clusters multiple terminals to be identified based on the content similarity of the service messages generated by the multiple terminals after they join the network, and manually labels the type corresponding to each cluster to determine that the terminal type is the type of the class to which the terminal belongs. Optionally, this approach can also be used as a method for accumulating a fingerprint library, accumulating identification results into the fingerprint library to improve the recognition rate of terminal identification based on terminal fingerprint information. However, this approach requires that the terminals to be identified must have generated service traffic or service messages after joining the network. Terminals that have connected to the network but have not yet generated service traffic or service messages cannot be identified using this approach. Moreover, the recognition accuracy of this method also depends on the amount of business traffic or business messages generated. Therefore, for terminals that access the network and generate a small amount of business traffic or business messages, the accuracy of the recognition results obtained by this method is difficult to guarantee.
[0081] Therefore, the terminal identification methods currently used are unable to effectively identify the ever-increasing variety of terminals, making it difficult to guarantee the terminal identification rate.
[0082] For example, in scenarios such as automatic admission, since the terminal has no business traffic (or business messages) before joining the network, it is impossible to identify the terminal by clustering the characteristics of business traffic (or business messages). Among them, terminal admission can be understood as when a terminal accesses the network but does not operate normally, the network admission controller (also called the network access controller) in the network determines whether the terminal can be admitted to the network based on the terminal type. The admitted terminal can operate normally in the network and provide the corresponding functions or services of the terminal.
[0083] For another example, for dumb terminals, the terminal identification method based on fingerprint information is not able to obtain the fingerprint information of various dumb terminals based on the current method of obtaining the fingerprint information of the terminal, that is, it is difficult to obtain the fingerprint information of the dumb terminal, resulting in the problem of poor recognition effect of the dumb terminal based on fingerprint information. Among them, dumb terminals can be a type of terminal that is divided according to whether it has a processing function. This type of terminal has no processing function and usually does not have a microprocessor. For example, printers, cameras, etc. are all dumb terminals. According to whether it has a processing function, in addition to dumb terminals, terminals can also include smart terminals (also called smart terminals). Smart terminals can refer to terminals with certain processing functions. This type of terminal has its own microprocessor and control circuit. For example, smart phones, laptops, etc. are all smart terminals. At present, some terminals with single functions and simple systems (such as smart screens) are usually classified as dumb terminals. For example, a dumb terminal's MAC OUI typically uses the first six characters of its MAC address to indicate its manufacturer. This manufacturer is only a reference and is not accurate. It also does not indicate other information, such as the type of dumb terminal. For another example, because dumb terminals cannot open web pages to introduce themselves, their HTTP UA (a common terminal fingerprint) cannot be obtained. Furthermore, except for printers and projection devices, mDNS (a common terminal fingerprint) cannot be obtained from other dumb terminals. Furthermore, LLDP can only be obtained by IP phones, and dumb terminals cannot obtain LLDP (a common terminal fingerprint). Therefore, obtaining the fingerprint information of dumb terminals is quite difficult.
[0084] Based on this, an embodiment of the present application provides a terminal identification method, which achieves effective and accurate identification of the terminal to be identified based on clustering of the open ports of the terminal to be identified. Even if the terminals in the network are diverse, this method can improve the terminal identification rate to a certain extent. In specific implementation, the method may include, for example: first, the identification device obtains the open port information of multiple terminals, and the open port information of each terminal indicates at least one port of each terminal that is in an open state; then, the identification device can cluster the multiple terminals based on the open port information of each terminal, and identify at least one cluster to which the multiple terminals belong based on the clustering results, where the terminals included in each cluster are of the same type. In this way, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, in this method, the open port information of the terminal to be identified is used as the basis for clustering the terminals to be identified. Then, in the clustering results, the open port information of the terminals belonging to the same cluster is similar, and the terminals belonging to the same cluster are likely to be of the same type, thereby achieving effective and accurate identification of the terminals, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or requires business traffic (or business messages) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed.
[0085] The method provided in the embodiment of the present application can be adapted to various scenarios with terminal identification requirements, such as automatic admission of dumb terminals. The method provided in the embodiment of the present application can effectively identify the type of terminal and ensure the recognition rate of the terminal.
[0086] The network architecture adapted by the embodiments of the present application can be found in Figure 1 .like Figure 1As shown, the network architecture may include at least: an identification device 10, a terminal 21 to be identified, a terminal 22, ..., a terminal 2N, where N is an integer greater than or equal to 1. The identification device 10 is used to implement the method provided in the embodiment of the present application (such as the following method 100) to realize the identification of the terminal 21, the terminal 22, ..., the terminal 2N. As an example, the identification device 10 can obtain the open port information 1 of terminal 21, the open port information 2 of terminal 22, ... the open port information N of terminal 2N, and thus cluster the terminals 21 to 2N according to the open port information 1 to the open port information N to obtain the clustering results. The clustering results may include cluster 1, cluster 2, ... cluster M, where M is a positive integer less than N, each cluster includes at least one terminal, and the types of terminals in each cluster are the same. For example, cluster 1 includes terminal 21 and terminal 2N, and terminal 21 and terminal 2N are both printers. For another example, cluster 2 includes terminal 22, terminal 23 and terminal 24, and terminal 22, terminal 23 and terminal 24 are all electronic class signs. For another example, cluster 3 includes terminal 25 and terminal 26, and terminal 25 and terminal 26 are both information screens.
[0087] The open port information is used to indicate the ports in the open state on the corresponding terminal. Based on the open port information, the identification device 20 can determine the port numbers and the number of ports in the open state on the corresponding terminal. For example, open port information 1 is used to indicate that the ports in the open state on terminal 21 are Transmission Control Protocol (TCP) 80 and TCP 81. Based on open port information 1, the number of ports in the open state on terminal 21 is determined to be 2, and the specific port numbers in the open state are TCP 80 and TCP 81. Then, the identification device 20 clusters terminals 21 to 2N based on open port information 1 to open port information N. For example, the identification device 20 can determine the number and / or port numbers of ports in the open state on terminals 21 to 2N based on open port information 1 to open port information N, and group terminals with the same or similar number of open ports and / or a high degree of similarity in open port numbers (e.g., meeting a preset similarity threshold) into the same cluster. Among them, the similarity of the port numbers in the open state can be related to the number of port numbers in the same open state. For example, two port numbers are the same between the port numbers in the open state of terminal 21 and the port numbers in the open state of terminal 22, and four port numbers are the same between the port numbers in the open state of terminal 21 and the port numbers in the open state of terminal 2N. Then, it can be considered that the similarity of the port numbers in the open state of terminal 21 and terminal 2N is higher than the similarity of the port numbers in the open state of terminal 21 and terminal 22.
[0088] In the embodiments of the present application, the identification device can be any communication device in the network that has the ability to implement the methods provided in the embodiments of the present application. The communication device can be a network device such as a switch or router. Alternatively, the identification device can be a functional module, component, or chip in any communication device in the network that has the ability to implement the methods provided in the embodiments of the present application, such as a single board or line card on the network device. The embodiments of the present application do not specifically limit the form and type of the identification device.
[0089] In the embodiments of the present application, a terminal may refer to any terminal that can be deployed in a network, and may be a smart terminal or a dumb terminal. The embodiments of the present application do not specifically limit the form and type of the terminal.
[0090] In order to introduce the embodiments of the present application more clearly, Figure 2 The method provided in the embodiments of the present application is described.
[0091] Figure 2 This is a flow chart of a terminal identification method 100 provided in an embodiment of the present application. In the method 100, the present application embodiment is introduced with the identification device as the execution subject. The identification device can be, for example, Figure 1 The identification device 10 in the embodiment may also correspond to the following Figure 3 The network controller 30 of the network framework shown, Figure 5 The network controller 30 or the communication device 800 of the network framework shown is shown. In the scenario where the identification result of the terminal is used as the NAC's automatic admission judgment for the terminal, the identification device that executes the method 100 can be the NAC itself or a corresponding functional module within the NAC.
[0092] like Figure 2 As shown, the method 100 may include, for example, the following S101 to S103:
[0093] S101: Acquire open port information of a plurality of terminals, where the open port information of each terminal indicates at least one open port of each terminal.
[0094] The "terminal" in the method 100 can be understood as the terminal to be identified, for example, it can include Figure 1One or more of the terminals 21, 22, ..., and 2N in the network. As an example, the terminals to be identified may be all the terminals in the network, then S101 may include: the identification device obtains the open port information of all the terminals in the network. As another example, the terminals to be identified may be terminals belonging to a target network segment in the network, then S101 may include: the identification device obtains the open port information of all the terminals belonging to the target network segment in the network. As yet another example, the terminals to be identified may be terminals belonging to a target VLAN in the network, then S101 may include: the identification device obtains the open port information of all the terminals belonging to the target VLAN in the network. As another example, the terminals to be identified may be terminals belonging to a target BD in the network, then S101 may include: the identification device obtains the open port information of all the terminals belonging to the target BD in the network.
[0095] Typically, a terminal has multiple ports, each of which can be in an open state or a closed state. The terminal can interact with other communication devices through the open ports. For example, the terminal can open a specific port so that the specific port is in an open state, thereby connecting to the server corresponding to the terminal based on the open port. Thus, through the interaction between the terminal and the server, the terminal provides corresponding services to the user. Taking a common terminal such as a printer as an example, the printer can open port 631, and other devices can connect to the printer based on the Internet Printing Protocol (IPP), enabling other devices to manage the printer and use the printer's printing services.
[0096] The open port information of a terminal may refer to any information that can indicate at least one port of the terminal that is in an open state. The specific embodiment of the open port information is not limited in the embodiments of the present application. As an example, the open port information may be an open port set. For example, the ports in the open state of terminal 21 include TCP port 80 and TCP port 81. Then, the open port information 1 of terminal 21 may be represented as an open port set such as {TCP 80, TCP 81}. As another example, the open port information may include the number of ports in the open state and the port number in the open state. Still taking the example that the ports in the open state of terminal 21 include TCP port 80 and TCP port 81, the open port information 1 of terminal 21 may also be represented as {number of ports in the open state: 2; port number in the open state: {TCP80, TCP 81}}.
[0097] The terminal's open port information can be obtained by a port scanning device performing a port scan on each of a plurality of terminals. The process of the port scanning device performing a port scan on a terminal can, for example, include: the port scanning device generating a port probe message corresponding to each port to be detected on the terminal, and sending the generated port probe message to the terminal; if the port to be detected by the port probe message received by the terminal is in an open state, the terminal sends a response message corresponding to the port probe message to the port scanning device; if the port to be detected by the port probe message received by the terminal is not in an open state, the terminal does not generate a response message corresponding to the port probe message; in this way, the port scanning device can determine at least one open port on the terminal based on the received response message to the port probe message, and obtain the terminal's open port information based on the at least one open port determined on the terminal. The number of response messages corresponding to the port probe messages received by the port scanning device is equal to the number of open ports in the detected ports of the terminal.
[0098] For example, the terminal 21 includes 6 ports: TCP port 78, TCP port 79, TCP port 80, TCP port 81, TCP port 82 and TCP port 83. Assuming that the ports in the open state among the 6 ports include: TCP port 80, TCP port 81 and TCP port 83, and the ports to be detected among the 6 ports on the terminal 21 include: TCP port 78, TCP port 79, TCP port 80 and TCP port 81, then, the process of the port scanning device performing a port scan on the terminal 21 may include: the port scanning device generates 4 port detection messages: port detection message 1 to port detection message 4, wherein the port detection message 1 to port detection message 4 are used to detect TCP port 78, TCP port 79, TCP port 80 and TCP port 81 respectively; since the TCP ports 78 and TCP 81 of the terminal 21 are Port 79 is not in an open state, so terminal 21 does not generate a response message for port detection message 1 and port detection message 2. Since TCP port 80 and TCP port 81 of terminal 21 are in an open state, terminal 21 generates response message 3 for port detection message 3 and response message 4 for port detection message 4; terminal 21 sends response message 3 and response message 4 to the port scanning device; the port scanning device determines that TCP port 80 is in an open state according to response message 3, and determines that TCP port 81 is in an open state according to response message 4. Therefore, the port identification device can determine the open port information of the terminal 21, and the open port information is used to indicate that the ports in the terminal 21 that are in an open state include TCP port 80 and TCP port 81.
[0099] The type of port to be detected is different, and the type of port detection message constructed is also different. For example, if the port to be detected is a TCP type port, then the port detection message can be a TCP message; for another example, if the port to be detected is a User Datagram Protocol (UDP) type port, then the port detection message can be a UDP message. The port detection message can include indication information indicating the port to be detected. The indication information can be the port number of the port to be detected, and the indication information can be carried in the destination port (Destination Port, Dst Port) field of the port detection message. For example, if the port to be detected is TCP port 80 of the terminal, then the port detection message can be a TCP message. In the message header of the port detection message, the protocol field = TCP and the Dst Port field = 80.
[0100] The ports to be detected can be flexibly determined according to actual needs. In one case, the ports to be detected can be all the ports of the terminal. Then, during the process of the port scanning device performing port scanning on the terminal, the port scanning device needs to send port detection messages corresponding to each port to the terminal, and the number of port detection messages sent is the same as the number of ports included in the terminal. For another example, the ports to be detected can be a specified portion of the ports of the terminal (which can also be understood as a portion of the specified ports among all the ports of the terminal). The specified portion of ports can be commonly used ports that need to be detected (such as the top 100 most commonly used ports (i.e., Top 100) in a commonly used port list), or can also be designated ports that need to be detected (such as ports with designated port numbers according to actual application scenario requirements). Then, during the process of the port scanning device performing port scanning on the terminal, the port scanning device needs to send port detection messages corresponding to each designated port to the terminal, and the number of port detection messages sent is the same as the number of designated ports of the terminal.
[0101] Regarding the timing of the port scanning device executing the port scanning of the terminal, as an example, upon the start of method 100, the port scanning device is triggered to execute the port scanning process of the terminal to obtain the terminal's open port information. As another example, the port scanning device may pre-execute the port scanning process of the terminal and save the open port information of multiple terminals. When the method 100 is started, the identification device reads the pre-saved open port information of the multiple terminals from the port scanning device.
[0102] If the port scanning device and the identification device belong to the same network device, then the port scanning device obtaining the open port information of the terminal is equivalent to the identification device obtaining the open port information of the terminal. In this case, S101 can be understood as: the network device including the port scanning device and the identification device obtains the open port information of multiple terminals by performing port scanning on the port to be detected of each terminal. Specifically, it can include: the network device sends port detection messages to the multiple terminals and obtains the open port information of the multiple terminals based on the received response messages. Taking the "multiple terminals" in S101 as all terminals in the network as an example, S101 can include: the network device including the port scanning device and the identification device performs port scanning on all terminals in the network to obtain the open port information of the multiple terminals (i.e., all terminals in the network). Taking the "multiple terminals" in S101 as all terminals in the target network segment as an example, S101 can include: the network device including the port scanning device and the identification device performs port scanning on all terminals in the target network segment to obtain the open port information of the multiple terminals (i.e., all terminals in the target network segment). Taking the "multiple terminals" in S101 as all terminals in the target VLAN in the network as an example, S101 may include, for example: the network device including a port scanning device and an identification device performs a port scan on all terminals in the network to obtain open port information of the multiple terminals (i.e., all terminals in the target VLAN in the network). Taking the "multiple terminals" in S101 as all terminals in the target BD in the network as an example, S101 may include, for example: the network device including a port scanning device and an identification device performs a port scan on all terminals in the network to obtain open port information of the multiple terminals (i.e., all terminals in the target BD in the network).
[0103] If the port scanning device and the identification device belong to two network devices, then after the port scanning device obtains the open port information of the terminal, it can send the obtained open port information of the terminal to the identification device. In this case, S101 can be understood as: the network device where the identification device is located receives the open port information of multiple terminals sent by the network device where the port scanning device is located.
[0104] It can be seen that obtaining the open port information of multiple terminals through S101 provides a reliable basis for subsequent terminal identification based on the open port information of the terminals, making it possible to achieve terminal identification with a high recognition rate.
[0105] S102: Cluster the multiple terminals according to the open port information of each terminal.
[0106] In a first possible implementation manner, the identification device may identify the type of the terminal only based on the open port information of the terminal.
[0107] As a first example, if the execution of method 100 is the first identification of terminals in the network and there is no cluster of known type in the network, or if the terminals in the network are re-identified and the known type of cluster is no longer valid, then S102 may include: the identification device clusters the multiple terminals according to the similarity of the open port information of the multiple terminals.
[0108] The similarity between the open port information of the terminals can be determined based on the number and port numbers of the ports in the open state of the terminals, and the calculation strategy for determining the similarity can be designed according to actual needs.
[0109] For example, the similarity between the open port information of the terminals = the number of the same port numbers in the open state * the weight corresponding to the port number - the difference in the number of ports in the open state * the weight corresponding to the number of ports, the weight corresponding to the number of ports is 20%, the weight corresponding to the port number is 80%, the open port information 1 of terminal 1 indicates that the port numbers of terminal 1 in the open state are: TCP 79, TCP 80 and TCP 81, the open port information 2 of terminal 2 indicates that the port numbers of terminal 2 in the open state are: TCP 80 and TCP 81, the open port information 3 of terminal 3 indicates that the port numbers of terminal 3 in the open state are: TCP 78, TCP 80 and TCP 81, and the open port information 4 of terminal 4 indicates that the port numbers of terminal 4 in the open state are: TCP 78, TCP 80, TCP 82 and TCP 83, then, the similarity between the open port information 1 of terminal 1 and the open port information 2 of terminal 2 = 2*80% - 1*20% = 1.4, the similarity between the open port information 1 of terminal 1 and the open port information 3 of terminal 3 = 2*80% - 0*20% = 1.6, and the similarity between the open port information 1 of terminal 1 and the open port information 4 of terminal 4 = 1*80% - 1*20% = 0.6.
[0110] For another example, the similarity between the open port information of the terminals = the number of the same port numbers in the open state + (1-the difference in the number of ports in the open state). It is still assumed that the open port information 1 of terminal 1 indicates that the port numbers of terminal 1 in the open state are: TCP 79, TCP 80 and TCP 81, the open port information 2 of terminal 2 indicates that the port numbers of terminal 2 in the open state are: TCP 80 and TCP 81, the open port information 3 of terminal 3 indicates that the port numbers of terminal 3 in the open state are: TCP78, TCP 80 and TCP 81, and the open port information 4 of terminal 4 indicates that the port numbers of terminal 4 in the open state are: TCP 78, TCP 80 and TCP 82. Then, the similarity between the open port information 1 of terminal 1 and the open port information 2 of terminal 2 = 2+(1-1)=2, the similarity between the open port information 1 of terminal 1 and the open port information 3 of terminal 3 = 2+(1-0)=3, and the similarity between the open port information 1 of terminal 1 and the open port information 4 of terminal 4 = 1+(1-0)=2.
[0111] It should be noted that, generally, the larger the similarity value, the more similar the open ports between the terminals are, and the more likely the terminals are to belong to the same type. Conversely, the smaller the similarity value, the less similar the open ports between the terminals are, and the more likely the terminals are to belong to different types.
[0112] For the identification device in S102 to cluster multiple terminals based on the similarity of the open port information of multiple terminals, it can be implemented by any clustering strategy, clustering algorithm or clustering model, and the embodiments of the present application are not specifically limited. For example, the clustering in S102 can be implemented by a preconfigured clustering strategy, and the clustering strategy can be, for example: preconfigure a similarity range, and divide two terminals whose similarities belong to the similarity range into one cluster, and each terminal can only belong to one cluster. For another example, the clustering in S102 can be implemented by a clustering algorithm, and the clustering algorithm can be, for example, a density-based spatial clustering of applications with noise (Density-Based Spatial Clustering of Applications with Noise, DBSCAN) algorithm or a k-means clustering algorithm (k-means clustering algorithm, K-means).
[0113] In this example, the clustering results obtained in S102 include at least one cluster, each of which includes at least one terminal of the same type. For example, the multiple terminals in S101 include terminals 1 to 10. After clustering in S102, three clusters are obtained: clusters 1 to 3. Cluster 1 includes terminals 1, 3, and 5; cluster 2 includes terminals 2, 4, and 8; and cluster 3 includes terminals 6, 7, 9, and 10.
[0114] As a second example, if, prior to the current execution of method 100, terminals in the network have been identified at least once, and at least one cluster of a known type exists in the network, then the "multiple terminals" in method 100 may refer to terminals newly connected to the network during the time interval between the last identification of the terminals in the network and the execution of method 100. S102 may include: the identification device determining, based on similarity between the open port information of the multiple terminals and the open port information of each cluster of the known type, the cluster of the known type to which each of the multiple terminals belongs, thereby completing clustering of the multiple terminals.
[0115] Among them, the similarity between the open port information of the terminal and the open port information of each cluster of known types can be determined based on the number and port number of the terminals in the open state, and the number and port number of the terminals in the open state at the cluster center of each cluster of known types. The similarity calculation strategy can be designed according to actual needs. For example, the clusters of known types include cluster 1 and cluster 2. The terminal at the cluster center of cluster 1 is terminal 1, and the terminal at the cluster center of cluster 2 is terminal 8. The multiple terminals to be identified include terminal 31, terminal 32, and terminal 33. Then, the identification device needs to calculate the similarity between the open port information of terminal 31, terminal 32, and terminal 33 and the open port information of terminal 1, and calculate the similarity between the open port information of terminal 31, terminal 32, and terminal 33 and the open port information of terminal 8. By comparing the calculated similarities, it is determined whether terminals 31, terminal 32, and terminal 33 should be classified into cluster 1 or cluster 2.
[0116] It should be noted that the calculation method of the similarity between the open port information of the terminals can refer to the relevant description above.
[0117] In S102, the identification device clusters the multiple terminals based on the similarity between the open port information of the multiple terminals and the open port information of each cluster of known types. This may be: for each terminal in the "multiple terminals", the terminal is assigned to the cluster with the greatest similarity to the open port information of the terminal. For example, if the similarity between the open port information of terminal 31 and the open port information of terminal 1 is greater than the similarity between the open port information of terminal 31 and the open port information of terminal 8, then terminal 31 is assigned to cluster 1 where terminal 1 is located. Similarly, if the similarity between the open port information of terminal 32 and the open port information of terminal 1 is less than the similarity between the open port information of terminal 32 and the open port information of terminal 8, then terminal 31 is assigned to cluster 2 where terminal 8 is located.
[0118] It should be noted that the clustering results in this example may include not only clusters of known types after executing S102, but also newly clustered clusters. For the clustering method of the newly clustered clusters, please refer to the relevant instructions of the first example above. For subsequent processing, please refer to the instructions related to the first example below.
[0119] In this example, the clustering results obtained in S102 may include clusters of known types, each of which includes at least one terminal of the same type. For example, the multiple terminals in S101 include terminals 31 to 35, and the clusters of known types include clusters 1 to 3. After clustering in S102, terminals 31 and 33 are added to cluster 1, terminals 32, 34, and 35 are added to cluster 2, and no new terminals are added to cluster 3.
[0120] In a second possible implementation, to further improve the reliability of terminal identification, the terminal type can be identified based on the terminal's open port information combined with other terminal information. Considering the characteristics of how the network assigns addresses to terminals and how users assign addresses to their own terminals, other terminal information may include, but is not limited to, the terminal's Media Access Control (MAC) address and / or the terminal's IP address.
[0121] As an example, before S102, the method may further include: the identification device obtains the MAC address of each terminal from the plurality of terminals. Then, S102 may include: the identification device clustering the plurality of terminals based on the open port information of each terminal and the MAC address of each terminal. The manner in which the identification device obtains the MAC address of each terminal from the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal from the plurality of terminals. For example, the identification device may obtain the open port information of the terminal and the MAC address of the terminal by performing a port scan on all or a specified portion of the ports of the terminal. For another example, the identification device may receive the MAC address of the terminal from a port scanning device that receives the open port information of the terminal.
[0122] In specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the MAC address between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0123] The calculation method of the similarity of the open port information between the terminals can refer to the description above.
[0124] Among them, the similarity of MAC addresses between terminals is calculated based on the prefix similarity of the MAC addresses in one case, that is, starting from the highest bit of the MAC address, the similarity of the two MAC addresses is determined based on the number of consecutive identical bits. The more consecutive identical bits there are, the higher the similarity of the MAC addresses of the two terminals is considered to be; the fewer consecutive identical bits there are, the lower the similarity of the MAC addresses of the two terminals is considered to be. For example, the MAC address of terminal 1 is 000BD4041508, the MAC address of terminal 2 is 000BD4042608, and the MAC address of terminal 3 is 000BD4160508. Since the consecutive identical bits from the highest bit in the MAC addresses of terminal 1 and terminal 2 are 000BD404, and the consecutive identical bits from the highest bit in the MAC addresses of terminal 1 and terminal 3 are 000BD4, the similarity of the MAC addresses of terminal 1 and terminal 2 is higher than the similarity of the MAC addresses of terminal 1 and terminal 3. In this way, if the user assigns MAC addresses to his many terminals based on the prefix of the applied MAC address, the prefix of the MAC address of all terminals is the same as the prefix of the applied MAC address. The prefix of the MAC address is then assigned a specific MAC address to each terminal according to the type of terminal. For example, the prefix of the MAC address applied for by user A is 000BD4. User A assigns 000BD404 to printer terminal 1 and printer terminal 2, and the MAC addresses are: 000BD4041508 and 000BD4042608 respectively. User A assigns 000BD416 to smart screen terminal 3 and smart screen terminal 4, and the MAC addresses are: 000BD4160508 and 000BD4160609 respectively.
[0125] In another case, the MAC address can be considered as a string, and the similarity of the MAC addresses between terminals is calculated based on the similarity of the strings. That is, the number of characters with the same values at corresponding positions in the MAC addresses of the two terminals is checked. The similarity of the two MAC addresses is determined based on the number of characters with the same values. The more characters with the same values, the higher the similarity of the MAC addresses of the two terminals; the fewer characters with the same values, the lower the similarity of the MAC addresses of the two terminals. For example, the MAC address of terminal 1 is 000BD4041508, the MAC address of terminal 2 is 000BD4042608, and the MAC address of terminal 3 is 000BD4160508. Since the MAC addresses of terminal 1 and terminal 2 have the same values for a total of 10 characters, 000BD404 and 08, and the MAC addresses of terminal 1 and terminal 3 have the same values for 9 consecutive characters starting from the highest bit, 000BD4 and 508, the similarity of the MAC addresses of terminal 1 and terminal 2 is higher than that of the MAC addresses of terminal 1 and terminal 3. In this way, it is possible to provide a certain reference for whether two terminals are of the same type based on the character similarity of the MAC addresses.
[0126] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity between the two factors of open port information and MAC address between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals and the similarity of MAC addresses between terminals, or it can be the average or weighted average of the similarity of open port information between terminals and the similarity of MAC addresses between terminals. The weight can be flexibly set according to actual needs.
[0127] As another example, before S102, the method may further include: the identification device obtains the IP address of each terminal from the plurality of terminals. Then, S102 may include: the identification device clustering the plurality of terminals based on the open port information of each terminal and the IP address of each terminal. The manner in which the identification device obtains the IP address of each terminal from the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal from the plurality of terminals. For example, the identification device may perform a port scan on all or a specified portion of the ports of the terminal to obtain the open port information of the terminal and the IP address of the terminal. For another example, the identification device may receive the IP address of the terminal from a port scanning device that receives the open port information of the terminal.
[0128] In a specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the IP addresses between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0129] The calculation method of the similarity of the open port information between terminals can refer to the description of the method of calculating the similarity of the open port information between terminals above. The calculation method of the similarity of the IP addresses between terminals can refer to the calculation method of calculating the similarity of the IP addresses between terminals above.
[0130] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity between the two factors of open port information and IP addresses between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals and the similarity of IP addresses between terminals, or it can be the average or weighted average of the similarity of open port information between terminals and the similarity of IP addresses between terminals. The weight can be flexibly set according to actual needs.
[0131] As another example, before S102, the method may further include: the identification device obtains the MAC address and IP address of each terminal in the plurality of terminals. Then, S102 may include: the identification device clusters the plurality of terminals based on the open port information of each terminal and the MAC address and IP address of each terminal. The manner in which the identification device obtains the MAC address and IP address of each terminal in the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal in the plurality of terminals. For example, the identification device may obtain the open port information of the terminal by performing a port scan on all or a specified portion of the ports of the terminal to obtain the MAC address and IP address of the terminal. For another example, the identification device may receive the MAC address and IP address of the terminal from a port scanning device that receives the open port information of the terminal.
[0132] In specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal, the similarity of the MAC addresses between each terminal, and the similarity of the IP addresses between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0133] For the method for calculating the similarity of open port information between terminals, please refer to the description above regarding the method for calculating the similarity of open port information between terminals. For the method for calculating the similarity of IP addresses between terminals, please refer to the description above regarding the method for calculating the similarity of IP addresses between terminals. For the method for calculating the similarity of MAC addresses between terminals, please refer to the description above regarding the method for calculating the similarity of MAC addresses between terminals.
[0134] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity of the three factors of open port information, MAC address and IP address between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals, the similarity of MAC addresses between terminals and the similarity of IP addresses between terminals, or it can be the average value or weighted average value of the similarity of open port information between terminals, the similarity of MAC addresses between terminals and the similarity of IP addresses between terminals. The weights can be flexibly set according to actual needs.
[0135] It should be noted that in the above three examples, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals. Please refer to the implementation method of the above identification device clustering multiple terminals based on the similarity of open port information between the terminals.
[0136] In this second implementation method, the scenario corresponding to the first example in the above-mentioned first implementation method is described. The scenario corresponding to the second example in the above-mentioned first implementation method is similar to the implementation method in the second example of the first implementation method. Please refer to the relevant description in the second example of the first implementation method.
[0137] S103 : Identify, based on the clustering result, at least one cluster to which the multiple terminals belong, wherein the terminals included in each cluster belong to the same type.
[0138] A cluster is a collection of terminals belonging to a single type in the clustering results. If multiple terminals to be identified belong to the same type, a single cluster corresponding to that type is identified based on the clustering results. If multiple terminals to be identified belong to multiple types, multiple clusters are identified based on the clustering results, with the number of clusters being the same as the number of types the terminals belong to.
[0139] In a specific implementation, S103 may include, for example, determining, based on the clustering results, the type of each cluster in at least one cluster to which the multiple terminals belong. The type of a cluster is the type of all terminals belonging to that cluster. Therefore, determining the type of each cluster is equivalent to identifying the types of the terminals in each cluster, thereby achieving terminal identification. Determining the type of each cluster in S103 may be performed automatically, through a combination of automatic identification and manual confirmation, through manual labeling, or through a combination of automatic identification and manual labeling.
[0140] As an example, for each cluster in the at least one determined cluster, the type of the cluster may be automatically identified based on an automatic matching strategy, a local identification strategy, a machine learning model, or the like.
[0141] Taking the automatic matching strategy as an example, in one case, S103 may include: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determining that the type of the second cluster is the first type corresponding to the first target port. Specifically, the identification device may pre-configure certain correspondences between terminal types and ports as a basis for matching. Then, for each of the at least one determined clusters, the identification device checks whether the open ports indicated by the open port information of each terminal in the cluster match any of the correspondences. If so, the type of the cluster is determined to be the type of the terminal included in the matched correspondence. For example, if the identification device pre-configured correspondences include correspondence 1 between a printer and port 631, and the identification device finds that the open ports indicated by the open port information of each terminal in cluster 1 among the three determined clusters all include port 631, cluster 1 may be considered to match correspondence 1, and the type of cluster 1 is determined to be the terminal type of printer in correspondence 1.
[0142] Taking the local identification strategy as an example, in another case, S103 may include: for any second cluster in at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determining that the type of the second cluster is the first type. Specifically, the identification device may select at least one terminal in each of the at least one determined clusters, identify the type of the selected terminal based on any possible method, and use the type as the type of the cluster. The method for identifying the type of the selected terminal may, for example, adopt fingerprint recognition, business traffic (or business message) clustering, etc. For example, the identification device selects terminal 1 in cluster 1 of the three determined clusters, and determines that terminal 1 is a smart screen based on fingerprint recognition. Then, the identification device may determine that the type of cluster 1 is a smart screen, and the type of all terminals in cluster 1 (including terminal 1) is a smart screen. It should be noted that in this implementation, the fewer terminal types selected, the faster the cluster type is identified and the higher the recognition efficiency; the more terminal types selected, the more accurate and reliable the cluster type is identified, but the recognition efficiency and recognition rate will be affected to a certain extent.
[0143] Thus, the identification result of the terminal may include: the type corresponding to the cluster of the specific type, and further, the number of terminals included in the cluster of the specific type. In order to facilitate users to view, check and manage their own assets, after S103, the method 100 may further include: a page displaying the identification result of the terminal, which may include, for example, a display item corresponding to each cluster in at least one cluster, and the display content of each display item may include, but is not limited to: the type of the corresponding cluster, the number of terminals included in the cluster, and an operation control, which provides the user with several operable operation items, and the operability may include, but is not limited to: viewing operation, editing operation, confirmation operation, etc. The user can view the terminals included in the cluster by clicking the viewing operation; the user can modify the type of the cluster and the type of one or several terminals included in the cluster by clicking the editing operation; the user can confirm the automatically identified type of the cluster by clicking the confirmation operation.
[0144] As another example, for each of the at least one determined clusters, after automatically identifying the type of the cluster, the cluster type can be identified as a candidate type, prompting and waiting for the user to confirm or edit the candidate type to finally determine the type of the cluster. This example can be considered an automatic identification + manual confirmation method. In this example, S103 may include: for any second cluster in the at least one cluster, the identification device determines the type of the second cluster as the first type based on automatic identification; then, in response to an edit operation or confirmation operation on the first type of the second cluster, determining the type of the second cluster as the second type. If the user confirms the first type of the second cluster, the second type is the same as the first type. If the user finds that the automatic identification result (i.e., the first type) is inaccurate, the user can identify the type of the second cluster based on any other method, determine the second cluster as the second type, and then perform an edit operation on the first type of the second cluster to change the type of the second cluster from the first type to the second type. In this case, the second type is different from the first type. In this way, the automatic identification + manual confirmation method can improve the accuracy of terminal recognition while ensuring recognition efficiency.
[0145] As another example, for at least one determined cluster, after automatically identifying the specific types of some clusters, the clusters whose specific types are not identified can be displayed as unknown types, prompting and waiting for the user to manually mark the unknown types, so as to determine the types of all clusters. This example can be regarded as an automatic identification + manual marking method. In this example, S103 may include: for one or more clusters whose specific types cannot be identified, displaying the types of one or more clusters as unknown types; manually marking the specific types of one or more clusters. Among them, the marking method for clusters of unknown types can be, for example: for any first cluster in the cluster of unknown type, identifying the type of one or more terminals in the first cluster, and marking the type as the type of the first cluster. In this way, through the method of automatic identification + manual marking, the type of each cluster can be determined, and the recognition rate of the terminal can be guaranteed.
[0146] It should be noted that in order to further improve the accuracy of the terminal recognition results, the method 100 may also include: a process in which the recognition device corrects the clustering results. As an example, the recognition device correcting the clustering results may include: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, changing the cluster to which the terminal belongs according to the type of the terminal. Specifically, on the page displaying the terminal recognition results, the user can view the terminals belonging to a certain display entry through a viewing operation. If it is found that a terminal does not belong to the same type as other terminals under the entry, the user can migrate the terminal from the entry to another display entry. The type of the cluster corresponding to the migrated entry is the same as the type of the terminal. For example, when the user views the terminals included in cluster 1 corresponding to the printer, it is found that the type of terminal 1 in cluster 1 is a smart screen. Therefore, in response to the user performing a correction operation on the type of terminal 1 (such as after the user clicks the correction operation item corresponding to terminal 1, enters "smart screen" in the pop-up input box and confirms it), the recognition device migrates terminal 1 to cluster 2 corresponding to the smart screen. After the migration, cluster 1 no longer includes terminal 1, and cluster 2 includes terminal 1.
[0147] In some possible implementations, after obtaining identification results for multiple terminals, the identification results can be used in any scenario.
[0148] For example, the recognition results can be integrated into the user's digital map, displaying the user's network topology. When the user selects a point on the digital map, the map will also display the terminals deployed at that point. The displayed terminals are displayed based on the recognition results, and other terminal details can also be displayed. In this way, by integrating terminal recognition results into the digital map, the information provided to the user is enriched, making it easier for users to deploy, manage, and control their network.
[0149] For another example, network access control can be performed on terminals based on their type. For example, terminals 1 and 2, which are electronic signboards, are automatically allowed access and assigned to VLAN 100. Terminals 3, 4, and 5, which are smart screens, are automatically allowed access and assigned to VLAN 200. Terminals 6 to 10, which are smartphones, are automatically blocked and prohibited from accessing the network. In this way, by applying terminal identification results to automatic terminal access control scenarios, rapid and effective terminal management is achieved.
[0150] For another example, configuration information can be sent to various types of terminals based on their type, completing automatic network configuration for each type of terminal. This configuration information can be sent by an identification device or other network device with information configuration capabilities to the network device to which the terminal is connected for network configuration. In this way, by applying the terminal identification results to the terminal's automatic configuration scenario, rapid and efficient terminal configuration is achieved.
[0151] It can be seen that through this method 100, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, the open port information of the terminal to be identified is used as the basis for clustering the terminals to be identified. Then, in the clustering results, the open port information of the terminals belonging to a cluster is similar, and the terminals belonging to a cluster are likely to belong to the same type, thereby achieving effective and accurate identification of the terminals, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or needs to have the business traffic (or business message) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed.
[0152] It should be noted that the embodiment of the present application is explained by taking the identification of the type of terminal as an example. The method provided in the embodiment of the present application can also use the open port information of the terminal, or combine the open port information of the terminal and other information of the terminal to realize the identification of other attribute information of the terminal through clustering. The other attribute information of the terminal may, for example, include but is not limited to at least one of the following information: the manufacturer to which the terminal belongs, the model of the terminal or the operating system used by the terminal. The specific implementation method is not limited in the embodiment of the present application.
[0153] In order to make the method provided in the embodiment of the present application easier to understand, the method provided in the embodiment of the present application is exemplarily described below with reference to two specific network frameworks.
[0154] like Figure 3As shown, the network framework may include: a network controller 30, a network 3 and a terminal 40, and the network 3 may include: a core layer device 31, an aggregation layer device 32, an aggregation layer device 33, an access layer device 34, an access layer device 35 and an access layer device 36. Among them, the network controller 30 at least has the functions corresponding to the identification device and the port scanning device in the method provided in the embodiment of the present application. Figure 3 The network architecture shown is suitable for smaller networks.
[0155] As an example, for Figure 3 The network framework shown in the figure, the terminal identification process can be seen in Figure 4 The method 200 shown. Figure 4 As shown, the method 200 may include, for example:
[0156] S201, the user connects the terminal 40 Figure 3 In the network 3 shown.
[0157] The terminal 40 may be a wired terminal, and then the terminal 40 may be connected to the access layer device 35 via a network cable; the terminal 40 may also be a wireless terminal, and then the terminal 40 may be connected to the access layer device 35 via a service set identifier (SSID).
[0158] S202: The user enables the terminal identification function on the network controller 30 and pre-configures the configuration information and network admission control policy of certain types of terminals in the network.
[0159] S203 , the network controller 30 performs a port scan on the terminal 40 to obtain the MAC address and open port information of the terminal 40 .
[0160] As an example, the network controller 30 can send the port detection message to the terminal 40 through the core layer device 31, the aggregation layer device 32 and the access layer device 35 in sequence. If the detected port on the terminal 40 is in an open state, the response message corresponding to the port is fed back to the network controller 30, so that the network controller 30 can determine the MAC address and open port information of the terminal 40 based on the received response message.
[0161] The scope of the port scan can be: terminals belonging to the target network segment, target VLAN or target BD, or terminals in the entire network. If a port scan is performed on terminals in the entire network, the port scan can be triggered by the Address Resolution Protocol (ARP) when the terminal goes online.
[0162] S204, the network controller 30 performs clustering based on the similarity between the MAC address and the open port information of the terminal to be identified, and obtains a clustering result. Figure 3 Terminal 40 in.
[0163] S205: The user marks the type of each cluster in the clustering result to obtain an identification result of the terminal to be identified.
[0164] S206 , based on the identification result, the network controller 30 automatically sends pre-configured content to the access layer device to which the terminal is connected, thereby achieving automatic control of the terminal.
[0165] The pre-configured content sent may include the configuration information of the corresponding type of terminal in the network and the network access control policy. For example, the identification result determines that terminal 40 belongs to cluster 1, and the type of cluster 1 is a printer. Then, the configuration information 1 and network access control policy 1 of the printer in the network can be sent to the access layer device 35 connected to the terminal 40. The configuration information 1 may include parameters such as the bandwidth and priority of the printer in the network. The network access control policy 1 may include automatic admission of the printer and access to VLAN 20.
[0166] In this way, through the method 200 provided in the embodiment of the present application, accurate identification of the terminal can be achieved in a scenario where the functions of port scanning and terminal identification are integrated into a communication device, providing a reliable data basis for terminal pre-configuration.
[0167] like Figure 5 As shown, the network framework may include: a network controller 30, a network 3, and a terminal 40. The network 3 may include: a core layer device 31, an aggregation layer device 32, an aggregation layer device 33, an access layer device 34, an access layer device 35, and an access layer device 36. Among them, the network controller 30 has at least the function corresponding to the identification device in the method provided in the embodiment of the present application, and any device in the network 3 has the function corresponding to the port scanning device in the method provided in the embodiment of the present application. Figure 6 The method 300 shown is described by taking the access layer device 35 as an example having the function corresponding to the port scanning device in the method provided in the embodiment of the present application. Figure 5 The network architecture shown is suitable for larger networks. In larger networks, the link between the network controller 30 and the terminal 40 may be blocked, or the network controller 30 may perform port scanning on a large number of terminals, which is costly. It is not reasonable to integrate the corresponding functions of the identification device and the port scanning device into the network controller 30.
[0168] As an example, for Figure 5 The network framework shown in the figure, the terminal identification process can be seen in Figure 6 The method 600 shown is as follows. Figure 6 As shown, the method 300 may include, for example:
[0169] S301, the user connects the terminal 40 Figure 5 In the network 3 shown.
[0170] The terminal 40 may be a wired terminal, and then the terminal 40 may be connected to the access layer device 35 via a network cable; the terminal 40 may also be a wireless terminal, and then the terminal 40 may be connected to the access layer device 35 via an SSID.
[0171] S302: The user enables the terminal identification function on the network controller 30 and pre-configures the configuration information and network admission control policy of certain types of terminals in the network.
[0172] S303 , the network controller 30 notifies the access layer device 35 to perform a port scan on the terminal 40 .
[0173] S304 , the access layer device 35 performs a port scan on the terminal 40 to obtain the MAC address and open port information of the terminal 40 .
[0174] As an example, the access layer device 35 can send a port detection message to the terminal 40. If the detected port on the terminal 40 is in an open state, a response message corresponding to the port is fed back to the access layer device 35. Thus, the access layer device 35 can determine the MAC address and open port information of the terminal 40 based on the received response message.
[0175] S305 , the access layer device 35 sends the MAC address and open port information of the terminal 40 to the network controller 30 .
[0176] S306, the network controller 30 performs clustering based on the similarity between the MAC address and the open port information of the terminal to be identified, and obtains a clustering result. Figure 5 Terminal 40 in.
[0177] S307: The user marks the type of each cluster in the clustering result to obtain the identification result of the terminal to be identified.
[0178] S308 , based on the identification result, the network controller 30 automatically sends pre-configured content to the access layer device to which the terminal is connected, thereby achieving automatic control of the terminal.
[0179] As an example, S308 may include: the network controller 30 automatically sends the pre-configured content corresponding to the terminal 40 to the access layer device 35 based on the identification result. The pre-configured content sent may include but is not limited to: configuration information 1 of the terminal 40 in the network and the network access control policy 1 of the terminal 40.
[0180] In this way, through the method 300 provided in the embodiment of the present application, in a scenario where the functions of port scanning and terminal identification are integrated into two communication devices, accurate identification of the terminal can be achieved, providing a reliable data basis for terminal pre-configuration.
[0181] Figure 7 This is a flow chart of a terminal identification method 400 provided in an embodiment of the present application. In the method 400, the present application embodiment is introduced with the terminal to be identified as the execution subject. The terminal to be identified can be, for example, Figure 1 Any terminal in can also correspond to the following Figure 3 or Figure 5 The terminal 40 of the network framework shown may also be the communication device 900 described below.
[0182] like Figure 7 As shown, the method 400 may include, for example, the following S401 to S402:
[0183] S401: Receive a port detection message for the target port of the terminal to be identified.
[0184] S402: If the target port is in an open state, a response message to the port detection message of the target port is sent, where the response message is used to guide identification of the type of the terminal to be identified.
[0185] Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes a target port, and the open port information is used to identify the type of the terminal to be identified.
[0186] In this way, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, in this method 400, a port scan is performed on the terminal to be identified to obtain the open port information of the terminal to be identified, and thus, the type of the terminal to be identified is identified based on this. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or requires business traffic (or business messages) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal.
[0187] It should be noted that for the relevant description of method 400, please refer to the corresponding description of method 100, method 200 or method 300.
[0188] Accordingly, the embodiment of the present application further provides a communication device 800 (also referred to as a terminal identification device 800), such as Figure 8 The communication device 800 can correspond to Figure 1 The identification device 10 in the communication device 800 may also correspond to Figure 3 or Figure 5 The network controller 30 in the embodiment specifically corresponds to the identification device in the network controller 30 for implementing the terminal identification function provided in the embodiment of the present application. The communication device 800 may include: an acquisition unit 801 and a processing unit 802. The processing unit 802 is configured to perform the processing operations in the above method 100, method 200, or method 300; the acquisition unit 801 is configured to perform other operations in the above method 100, method 200, or method 300 except the processing operations.
[0189] As an example, the acquisition unit 801 is configured to acquire the open port information of multiple terminals, where the open port information of each terminal indicates at least one open port of each terminal. The acquisition unit 801 may execute Figure 2 S101 shown.
[0190] The processing unit 802 is configured to cluster multiple terminals based on the open port information of each terminal. The processing unit 802 may execute Figure 2 S102 shown.
[0191] The processing unit 802 is further configured to identify, based on the clustering result, at least one cluster to which the multiple terminals belong, wherein the terminals included in each cluster of the at least one cluster are of the same type. The processing unit 802 may execute Figure 2 S103 shown.
[0192] In some possible implementations, the acquisition unit 801 of the apparatus 800 is further configured to acquire the MAC address of each terminal; and the processing unit 802 is specifically configured to cluster multiple terminals according to the open port information of each terminal and the MAC address of each terminal.
[0193] In some possible implementations, the acquisition unit 801 of the apparatus 800 is further configured to acquire the IP address of each terminal; and the processing unit 802 is specifically configured to cluster multiple terminals according to the open port information of each terminal and the IP address of each terminal.
[0194] In some possible implementations, the acquiring unit 801 is specifically configured to receive open port information of multiple terminals sent by a port scanning device.
[0195] In some possible implementations, the acquiring unit 801 is specifically configured to acquire open port information of multiple terminals by performing port scanning on all ports or some designated ports of each terminal.
[0196] In some possible implementations, the acquiring unit 801 specifically performs any one of the following steps:
[0197] Scan ports of all terminals in the network to obtain information about open ports of multiple terminals.
[0198] Alternatively, by performing port scanning on terminals in the target network segment, information on open ports of multiple terminals can be obtained;
[0199] Alternatively, the open port information of multiple terminals can be obtained by performing port scanning on the terminals in the target VLAN;
[0200] Alternatively, the open port information of multiple terminals is obtained by performing port scanning on the terminals in the target BD.
[0201] In some possible implementations, the processing unit 802 is specifically configured to cluster the multiple terminals according to similarities in the open port information of the multiple terminals.
[0202] In some possible implementations, the processing unit 802 is specifically configured to determine the cluster of the known type to which each of the multiple terminals belongs based on similarities between the open port information of the multiple terminals and the open port information of each cluster of the known type.
[0203] In some possible implementations, the processing unit 802 is specifically configured to determine a type of each cluster in the at least one cluster.
[0204] As an example, processing unit 802 is specifically configured to: display the type of one or more clusters whose specific types cannot be identified as unknown; and manually mark the specific types of one or more clusters. Processing unit 802 of apparatus 800 is further configured to mark the specific types of clusters of unknown types. Processing unit 802 is specifically configured to: for any first cluster of the unknown type clusters, identify the type of one or more terminals in the first cluster and mark the type as the type of the first cluster.
[0205] As another example, the processing unit 802 is specifically configured to: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determine that the type of the second cluster is the first type corresponding to the first target port.
[0206] As another example, the processing unit 802 is specifically configured to: for any second cluster in the at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determine that the type of the second cluster is the first type.
[0207] For the second cluster, the processing unit 802 is further configured to, in response to an edit operation or a confirmation operation of the first type on the second cluster, determine that the type of the second cluster is a second type, which is the same as or different from the first type.
[0208] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to correct the clustering result.
[0209] As an example, the processing unit 802 is specifically configured to: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, change the cluster to which the terminal belongs according to the type of the terminal.
[0210] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to perform network admission control on the terminal based on the type of the terminal.
[0211] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to send configuration information to a terminal of the type based on the type of the terminal.
[0212] In some possible implementations, the apparatus 800 may be a network controller itself, or may be a functional module belonging to the network controller and used to implement the method provided in this application. The network controller may be, for example, a NAC.
[0213] It should be noted that various specific implementation modes of the communication device 800 can refer to the relevant introduction of method 100, method 200 or method 300, which will not be repeated in this embodiment.
[0214] Accordingly, the embodiment of the present application further provides a communication device 900 (also referred to as a terminal identification device 900), such as Figure 9 The communication device 900 is applied to the terminal to be identified. The communication device 900 can correspond to Figure 1 Any terminal in; the communication device 900 can also correspond to Figure 3 or Figure 5 The terminal 40 in the communication device 900 may include: a receiving unit 901 and a sending unit 902.
[0215] The receiving unit 901 is configured to receive a port detection message for the target port of the terminal to be identified. The receiving unit 901 may execute Figure 7 S401 shown.
[0216] The sending unit 902 is configured to send a response message to the port detection message for the target port if the target port is in an open state, and the response message is used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified. The sending unit 901 can execute Figure 7 S402 shown.
[0217] It should be noted that various specific implementation modes of the communication device 900 can be found in the relevant introduction of the method 400, and will not be described in detail in this embodiment.
[0218] See also Figure 10 , the embodiment of the present application provides a communication device 1000. The communication device 1000 can be the execution subject of any of the above embodiments, for example, it can correspond to Figure 1 The identification device 10 or any terminal in the embodiment may correspond to Figure 3 The network controller 30 or terminal 40 in the example may correspond to Figure 5 The network controller 30 or terminal 40 in the communication device 1000 can implement the functions of the corresponding execution entities in the above embodiments. The communication device 1000 includes at least one processor 1001, a bus system 1002, a memory 1003 and at least one communication interface 1004.
[0219] The communication device 1000 is a hardware structure device that can be used to implement Figure 8 The functional modules in the communication device 800 shown in FIG. For example, those skilled in the art may think Figure 8 The obtaining unit 801 and the processing unit 802 in the communication device 800 are implemented by the at least one processor 1001 calling the code in the memory 1003 .
[0220] The communication device 1000 is a hardware structure device that can be used to implement Figure 9 The functional modules in the communication device 900 shown in FIG. For example, those skilled in the art may think Figure 9 The receiving unit 901 and the sending unit 902 in the communication device 900 are implemented by the at least one processor 1001 calling codes in the memory 1003 .
[0221] Optionally, the communication device 1000 may be a network device or a control entity implementing an embodiment of the present application.
[0222] Optionally, the processor 1001 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0223] The bus system 1002 may include a channel for transmitting information between the components.
[0224] The communication interface 1004 is used to communicate with other devices or communication networks.
[0225] The above-mentioned memory 1003 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor via a bus. The memory can also be integrated with the processor.
[0226] The memory 1003 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 1001. The processor 1001 is used to execute the application code stored in the memory 1003, thereby realizing the functions of the method of the present application.
[0227] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as Figure 10 CPU0 and CPU1 in.
[0228] In a specific implementation, as an embodiment, the communication device 1000 may include multiple processors, such as Figure 101 and 1007. Each of these processors may be a single-CPU processor or a multi-CPU processor. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0229] It should be understood that the communication devices in the various product forms mentioned above respectively have any functions implemented by the execution subject in the above method embodiments, which will not be described in detail here.
[0230] The embodiment of the present application also provides a chip, including a processor and an interface circuit, the interface circuit is used to receive instructions and transmit them to the processor; the processor, for example, can be a specific implementation form in the embodiment of the present application, and can be used to execute the above-mentioned method 100, method 200, method 300 or method 400. The processor is coupled to a memory, and the memory is used to store programs or instructions. When the program or instructions are executed by the processor, the chip system implements the method in any of the above-mentioned method embodiments. In a specific implementation, when the chip provided by the present application can be specifically used to implement the operations performed by the communication device 800 described above, the interface circuit can be used to implement the relevant operations performed by the acquisition unit 801 in the communication device 800, and the processor can be used to implement the relevant operations performed by the processing unit 802 in the communication device 800.
[0231] Optionally, there may be one or more processors in the chip system. The processor may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0232] Optionally, the memory in the chip system may be one or more memories. The memory may be integrated with the processor or may be provided separately from the processor, which is not limited in this application. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or provided on different chips. This application does not specifically limit the type of memory or the configuration of the memory and the processor.
[0233] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0234] In addition, an embodiment of the present application also provides a device that communicates with a linear direct-drive optical module, the device includes a first equalizer, and the linear direct-drive optical module includes a second equalizer; the device is used to execute the above-mentioned method 100 or method 200 to tune the parameters of the first equalizer and the second equalizer.
[0235] In addition, the embodiment of the present application also provides a communication system 1100, such as Figure 11 The communication system 1100 may include a terminal 1101 to be identified and an identification device 1102.
[0236] Identification device 1102, configured to execute method 100, method 200, or method 300 to identify multiple terminals, where the multiple terminals include terminal 1101 to be identified;
[0237] The terminal 1101 to be identified is used to execute the above method 400.
[0238] Among them, the identification device 1102 can correspond to the above Figure 1 The identification device 10 shown in FIG. 10 , then the terminal 1101 to be identified may correspond to Figure 1 Any terminal (such as terminal 21) in the above; or, the identification device 1102 may correspond to the above Figure 3 The network controller 30 shown in FIG. 1 , then the terminal 1101 to be identified may correspond to Figure 3 Alternatively, the identification device 1102 may correspond to the above Figure 5 The network controller 30 shown in FIG. 1 , then the terminal 1101 to be identified may correspond to Figure 5 Alternatively, the identification device 1102 may correspond to the above Figure 8The communication device 800 shown in FIG. 1 , then the terminal 1101 to be identified may correspond to Figure 9 The communication device 900 in.
[0239] In addition, an embodiment of the present application further provides a storage medium, in which program code or instructions are stored. When the storage medium is run on a processor, the processor executes a method in any one of the implementation modes of the above embodiments.
[0240] In addition, an embodiment of the present application also provides a program product, which, when executed on a processor, enables the processor to execute any one of the aforementioned methods 100, 200, 300, or 400.
[0241] It should be understood that "determining B based on A" mentioned in the embodiments of the present application does not mean determining B only based on A, but B can also be determined based on A and / or other information.
[0242] It should be understood that the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0243] In this application, ordinal numbers such as "1", "2", "3", "first", "second" and "third" are used to distinguish multiple objects and are not used to limit the order of multiple objects.
[0244] “A and / or B” mentioned in this application should be understood to include the following situations: only A, only B, or both A and B.
[0245] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.
[0246] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments and device embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The device and system embodiments described above are merely schematic. The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.
[0247] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. It should be noted that those skilled in the art may make several improvements and modifications without departing from the scope of protection of the present application, and such improvements and modifications should also be considered as within the scope of protection of the present application.
Claims
1. A terminal identification method, characterized in that: The method comprises: Acquire open port information of a plurality of terminals, where the open port information of each terminal indicates at least one port of each terminal that is in an open state; Clustering the multiple terminals according to the open port information of each terminal; According to the clustering result, at least one cluster to which the plurality of terminals belong is identified, and the terminals included in each of the at least one cluster belong to the same type.
2. The method according to claim 1, characterized in that The method further comprises: Obtaining a media access control MAC address of each terminal; The clustering of the plurality of terminals according to the open port information of each terminal includes: The multiple terminals are clustered according to the open port information of each terminal and the MAC address of each terminal.
3. The method according to claim 1 or 2, characterized in that The obtaining of the open port information of the plurality of terminals includes: Receive the open port information of the multiple terminals sent by the port scanning device.
4. The method according to any one of claims 1 to 3, characterized in that The obtaining of the open port information of the plurality of terminals includes: The open port information of the multiple terminals is obtained by performing port scanning on all ports or part of the designated ports of each terminal.
5. The method according to any one of claims 1 to 4, characterized in that The obtaining of the open port information of the plurality of terminals includes any one of the following: Performing port scanning on all terminals in the network to obtain open port information of the terminals; Alternatively, by performing port scanning on terminals in the target network segment, the open port information of the plurality of terminals is obtained; Alternatively, the open port information of the plurality of terminals is obtained by performing port scanning on the terminals in the target virtual local area network VLAN; Alternatively, the open port information of the plurality of terminals is acquired by performing port scanning on the terminals in the target broadcast domain BD.
6. The method according to any one of claims 1 to 5, characterized in that The clustering of the multiple terminals according to the open port information of the multiple terminals includes: The multiple terminals are clustered according to similarities in the open port information of the multiple terminals.
7. The method according to any one of claims 1 to 5, characterized in that The clustering of the multiple terminals according to the open port information of the multiple terminals includes: The cluster of the known type to which each of the plurality of terminals belongs is determined according to similarities between the open port information of the plurality of terminals and the open port information of each cluster of the known type.
8. The method according to any one of claims 1 to 6, characterized in that The identifying, based on the clustering result, at least one cluster to which the plurality of terminals belong includes: A type of each cluster of the at least one cluster is determined.
9. The method according to claim 8, characterized in that The determining the type of each cluster in the at least one cluster includes: For one or more clusters whose specific types cannot be identified, the types of the one or more clusters are displayed as unknown types; and the specific types of the one or more clusters are manually marked.
10. The method according to claim 9, characterized in that The specific type of marking for the unknown type of cluster includes: For any first cluster of the clusters of unknown type, the type of one or more terminals in the first cluster is identified, and the type is marked as the type of the first cluster.
11. The method according to claim 8, characterized in that The determining the type of each cluster in the at least one cluster comprises: For any second cluster of the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes a first target port, the type of the second cluster is determined to be a first type corresponding to the first target port.
12. The method according to claim 11, characterized in that The determining the type of each cluster in the at least one cluster further includes: In response to an edit operation or a confirmation operation of the first type on the second cluster, the type of the second cluster is determined to be a second type, which is the same as or different from the first type.
13. The method according to any one of claims 1 to 12, characterized in that The method further comprises: The clustering result is corrected.
14. The method according to claim 13, characterized in that The modifying of the clustering result includes: When the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, the cluster to which the terminal belongs is changed according to the type of the terminal.
15. The method according to any one of claims 1 to 14, characterized in that The method further comprises: Perform network access control on terminals based on their types; Alternatively, based on the type of the terminal, the configuration information is sent to the terminal of that type.
16. The method according to any one of claims 1 to 15, characterized in that The method is applied to a network controller.
17. A communication device, characterized in that: The communication device includes an acquisition unit and a processing unit; The processing unit is configured to perform the processing operation in the method according to any one of claims 1 to 16 above; The acquisition unit is used to perform other operations except the processing operation in the method according to any one of claims 1 to 6.
18. A storage medium, characterized in that The storage medium includes instructions, and when the instructions are executed on a processor, the processor is caused to execute the method according to any one of claims 1 to 16.
19. A program product, characterized in that The program product includes a program, and when the program is run on a processor, the method according to any one of claims 1 to 16 is executed.