Unknown domain name identification method, computer device and storage medium

By obtaining network access records from user terminals, identifying known domains associated with unknown domains and updating the DPI feature database, the problem of DPI devices being unable to identify new websites and applications is solved, thus improving the traffic recognition rate.

CN114338601BActive Publication Date: 2026-04-07ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-30
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

The DPI device's feature library is not updated in a timely manner, which makes it unable to accurately identify new websites and applications, thus reducing the traffic recognition rate.

Method used

By acquiring network access records from multiple user terminals, known domains associated with unknown domains are identified, and these associated domains are stored or output to update the DPI feature library, thereby improving the recognition rate of unknown domains.

Benefits of technology

The DPI feature library has improved its ability to identify unknown domain names, ensuring accurate processing and analysis of new websites and applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114338601B_ABST
    Figure CN114338601B_ABST
Patent Text Reader

Abstract

This invention provides a method, device, and storage medium for identifying unknown domain names, belonging to the field of Internet technology. The method includes: acquiring network access records from multiple user terminals, the network access records including domain names, and at least one user terminal's network access record including an unknown domain name; determining domain names associated with the unknown domain name based on the network access records of the multiple user terminals; storing and / or outputting the domain names associated with the unknown domain name to update a DPI feature library based on the associated domain names, the DPI feature library being used to identify the application category of the unknown domain name. The technical solution of this invention solves the problem of being unable to identify unknown domain names due to insufficient information, improving the recognition rate of unknown domain names by the DPI feature library.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet information technology, and in particular to a method for identifying unknown domain names, a computer device, and a storage medium. Background Technology

[0002] In the mobile internet, operators use DPI (Distributed Traffic Indicator) devices to identify protocol or application information in user internet traffic, thereby enabling functions such as protocol or application-based statistics, QoS, rate limiting, blocking, billing, and analysis. In recent years, with the widespread adoption of 4G, new websites and applications have emerged rapidly. DPI devices identify website and application traffic based on protocol and application feature libraries. If the DPI feature library is not updated in a timely manner, the traffic identification rate will decrease, thus failing to meet the telecom operators' needs for accurate and timely processing and analysis of new websites and applications on the network. Summary of the Invention

[0003] This invention provides a method, computer device, and storage medium for identifying unknown domain names, aiming to improve the recognition rate of unknown domain names by the DPI feature library.

[0004] In a first aspect, embodiments of the present invention provide a method for identifying unknown domain names, including:

[0005] Obtain network access records of multiple user terminals, wherein the network access records include domain names, and at least one of the user terminals includes an unknown domain name in its network access records;

[0006] The domain name associated with the unknown domain name is determined based on the network access records of the multiple user terminals;

[0007] Store and / or output domain names associated with the unknown domain name in order to update the DPI feature library based on the associated domain names, the DPI feature library being used to identify the application category of the unknown domain name.

[0008] Secondly, embodiments of the present invention also provide a computer device, the computer device including a processor, a memory, a computer program stored in the memory and executable by the processor, and a data bus for implementing connection communication between the processor and the memory, wherein when the computer program is executed by the processor, it implements the steps of any of the unknown domain name identification methods provided in this specification.

[0009] Thirdly, embodiments of the present invention also provide a storage medium for computer-readable storage, the storage medium storing one or more programs, the one or more programs being executable by one or more processors to implement the steps of any of the methods for identifying unknown domain names provided in this specification.

[0010] This invention provides a method, computer device, and storage medium for identifying unknown domain names. The method involves acquiring network access records from multiple user terminals, where each record includes known domain names, and at least one user terminal's network access record includes an unknown domain name. Based on the network access records from the multiple user terminals, known domain names associated with the unknown domain names are determined. These known domain names are then stored and / or output to update a Data Point Indicator (DPI) feature library, which is used to identify the application category of the unknown domain name. This solution addresses the problem of insufficient information preventing the identification of unknown domain names and improves the DPI feature library's accuracy in identifying unknown domain names. Attached Figure Description

[0011] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a flowchart illustrating an unknown domain name identification method provided in an embodiment of the present invention;

[0013] Figure 2 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] The flowchart shown in the attached diagram is for illustrative purposes only and does not necessarily include all content and operations / steps, nor does it necessarily have to be performed in the order described. For example, some operations / steps can be broken down, combined, or partially merged, so the actual execution order may change depending on the actual situation.

[0016] It should be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0017] This invention provides a method for identifying unknown domain names, a computer device, and a storage medium. The method for identifying unknown domain names can be applied to mobile terminals, such as tablet computers, laptops, and desktop computers.

[0018] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0019] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating a method for handling unknown domain names provided in an embodiment of the present invention.

[0020] like Figure 1 As shown, the unknown domain name method includes steps S101 to S103.

[0021] Step S101: Obtain network access records of multiple user terminals, wherein the network access records include domain names, and at least one of the user terminals has network access records including unknown domain names.

[0022] For example, obtaining network access records of as many user terminals as possible could involve hundreds, thousands, or even tens of thousands of user terminals.

[0023] For example, network access records of multiple user terminals in one network segment can be obtained, or network access records of multiple user terminals in multiple network segments can be obtained randomly.

[0024] For example, network access records of multiple user terminals can be obtained based on the load situation, or only network access records of user terminals managed by one or more processes can be obtained.

[0025] For example, network access records of multiple user terminals over a period of time can be obtained to increase the base number of domain names in the network access records.

[0026] For example, if the obtained network access records include an unknown domain name, the acquisition of network access records for that user terminal is paused. If no unknown domain name is obtained, network access records are continuously acquired for a period of time until an unknown domain name is obtained or the acquisition time ends.

[0027] For example, the domain name and unknown domain are not first-level domain names, but can be second-level domain names or lower-level domain names and / or subdomain names.

[0028] For example, in the domain name "www.xliemgne.com", "com" is the first-level domain, "xliemegne.com" is the second-level domain, and "www.xliemgne.com" is the third-level domain. The third-level domain is also called a subdomain of the second-level domain.

[0029] In some embodiments, obtaining network access records of multiple user terminals, wherein the network access records include domain names, and at least one user terminal's network access record includes an unknown domain name, includes: obtaining network access records of multiple user terminals, wherein the network access records include known domain names, and at least one user terminal's network access record includes an unknown domain name; determining a domain name associated with the unknown domain name based on the network access records of the multiple user terminals includes: determining a known domain name associated with the unknown domain name based on the network access records of the multiple user terminals; storing and / or outputting the domain name associated with the unknown domain name includes: storing and / or outputting the known domain name associated with the unknown domain name.

[0030] For example, when a user terminal accesses the network, it should access a website address, from which relevant domain name information can be obtained.

[0031] For example, the network access records of the user terminal include one or more domain names, wherein the domain names may include one or more known domain names, or one or more unknown domain names.

[0032] In some embodiments, obtaining network access records of multiple user terminals includes: obtaining domain name information accessed by the user terminals; if the domain name information accessed by a user terminal includes the unknown domain name, generating a corresponding network access record based on the domain name information accessed by the user terminal, wherein the network access record of the user terminal includes known domain names and unknown domain names; if the domain name information accessed by a user terminal does not include the unknown domain name, generating a corresponding network access record based on the domain name information accessed by the user terminal, wherein the network access record includes known domain names.

[0033] For example, the network access records of the user terminal only include one or more known domain names, and the network access records generated by the corresponding user terminal should only include known domain names.

[0034] For example, the network access records of at least one user terminal among multiple user terminals include at least one unknown domain name.

[0035] For example, the network access records may also include HTTP and HTTPS traffic, and the HOST domain name and SNI domain name are extracted according to HTTP and HTTPS respectively.

[0036] For example, the HOST domain extracted from HTTP refers to the domain name portion of the HOST field value extracted from HTTP GET or POST request information. In the string "GET / HTTP / 1.1\r\nHost:www.xliemgne.com:8080\r\n\r\n", if the HOST field is "www.xliemgne.com:8080", then the HOST field domain name is "www.xliemgne.com:8080".

[0037] For example, the SNI domain extracted for HTTPS refers to the domain name extracted from the SNI field value of the ClientHello message in HTTPS.

[0038] For example, the HOST domain and SNI domain can be extracted based on the access time.

[0039] For example, in order to preserve storage space and save memory resources, the network access records are stored and processed in different forms.

[0040] In some embodiments, if the number of network access records obtained from the user terminal exceeds the maximum storage threshold, the network access records to be retained are determined according to the order of acquisition.

[0041] For example, the acquisition order can be determined based on the access time of the network access records. If the network access records are continuously acquired for 5 days and the network access records exceed the maximum storage threshold, the network access records acquired on the current day will replace the network access records from 5 days ago.

[0042] For example, the maximum storage threshold can be preset so that network access records do not consume excessive memory resources.

[0043] In other embodiments, the corresponding hash value is obtained by using a hash algorithm based on the longer domain name in the network access record, and then stored in the form of a hash value.

[0044] In other embodiments, different domain names are numbered. When obtaining and saving network access records, only the numerical value of the number needs to be saved. For example, "www.aabb.com" is numbered 1, "www.bbdd.com" is numbered 2, "www.aacc.com" is numbered 3, "www.bbcc.com" is numbered 4, and "www.aadd.com" is numbered 5. If the network access records of user A's terminal are "www.aabb.com, www.aacc.com, www.bbcc.com" and the network access records of user B's terminal are "www.aacc.com, www.bbdd.com, www.aadd.com", then when saving, the network access records of user A's terminal can be "1,3,4" and the network access records of user B's terminal can be "3,2,5".

[0045] By acquiring and storing data in the system in a simple manner, the system's operating speed can be maintained, and excessive memory resources can be avoided.

[0046] Step S102: Determine the domain name associated with the unknown domain name based on the network access records of the multiple user terminals.

[0047] For example, the network access records of a user terminal may not contain the same domain name. For example, the network access records of user A terminal may contain the following domain names: "www.aabb.com, www.aacc.com, www.bbcc.com".

[0048] For example, the domain names in the network access records of different user terminals can be the same, such as the network access records of user terminal B: "www.aacc.com, www.bbdd.com, www.aadd.com".

[0049] For example, if multiple user terminals' network access records all show the same unknown domain name and the same domain name, then these identical domain names can be considered to be associated with the unknown domain name. This association can be due to the same or similar source or application type.

[0050] In some embodiments, determining the domain name associated with the unknown domain name based on the network access records of the plurality of user terminals includes: determining a first terminal based on the terminals whose network access records include the unknown domain name, and determining a second terminal based on the terminals whose network access records do not include the unknown domain name; generating a first domain name set based on the network access records of the first terminal; generating a second domain name set based on the network access records of the second terminal; and determining the domain name associated with the unknown domain name based on the first domain name set and the second domain name set.

[0051] For example, a first terminal is determined based on terminals whose network access records include the unknown domain name, and a second terminal is determined based on terminals whose network access records do not include the unknown domain name. It is understood that both the first and second terminals include several user terminals.

[0052] For example, if the network access record of the user terminal includes an unknown domain name, the corresponding user terminal is identified as the first terminal. It can be understood that the terminal whose network access record does not include an unknown domain name is identified as the second terminal.

[0053] For example, the identifier of the user terminal is determined based on the network access records of the user terminal, and the user terminal is determined to be a first terminal or a second terminal based on the identifier.

[0054] For example, if the user terminal's network access records include unknown domain names, the terminal identifier is determined to be FoundFlag=1; if the user terminal's network access records do not include unknown domain names, the terminal identifier is determined to be FoundFlag=0.

[0055] For example, a terminal is identified as the first terminal based on the terminal identifier FoundFlag=1; and a terminal is identified as the second terminal based on the terminal identifier FoundFlag=0.

[0056] For example, after dividing the multiple user terminals into a first terminal and a second terminal, a first domain name set is generated based on the network access records of the multiple user terminals belonging to the first terminal. It can be understood that a second domain name set is generated based on the network access records of the multiple user terminals belonging to the second terminal.

[0057] For example, the first set of domain names may be the sum of network access records of multiple user terminals belonging to the first terminal.

[0058] In some embodiments, generating a first domain name set based on the network access records of the first terminal and generating a second domain name set based on the network access records of the second terminal includes: extracting non-repeating domain names from the network access records of multiple first terminals to generate the first domain name set, and extracting non-repeating domain names from the network access records of multiple second terminals to generate the second domain name set.

[0059] For example, when generating the first / second domain set, if it is found that the first / second domain set already includes the currently obtained network access record, the currently obtained network access record will not be stored in the first / second domain set.

[0060] For example, if both user A and user B's terminals are the first terminal, and the network access record of user A's terminal "www.aabb.com" was previously stored in the first domain set, and the network access record of user B's terminal "www.aabb.com" is currently obtained, then user B's terminal "www.aabb.com" will not be stored in the first domain set.

[0061] For example, both the first and second domain name sets can be known domain names to analyze the association information of unknown domain names.

[0062] For example, a known domain name may appear only in the first domain name set, only in the second domain name set, or appear in both the first and second domain name sets.

[0063] For example, assuming the continuous acquisition period is 10 minutes, the network access records of the user terminal are continuously acquired within 10 minutes. If the acquired network access records of the user terminal include unknown domain names, the terminal is marked as a first terminal and the acquisition of network access records of the terminal is paused, and the corresponding network access records are stored in the first domain name set. If the acquired network access records of the user terminal do not include unknown domain names within the acquisition period, the terminal is marked as a second terminal and the corresponding network access records are stored in the second domain name set. It can be understood that when the network access records already exist in the corresponding domain name set, they are not stored in the domain name set.

[0064] In some embodiments, determining the domain name associated with the unknown domain name based on the first domain name set and the second domain name set includes: determining the domain name associated with the unknown domain name based on domain names that are in the first domain name set but not in the second domain name set.

[0065] For example, the first domain name set can be {a,b,d}, and the second domain name set can be {a,c,d,e,h}. Based on the domain name that exists in the first domain name set but not in the second domain name set, i.e., b, it is determined as the domain name associated with the unknown domain name.

[0066] By determining the domain names associated with the unknown domain name based on the first domain name set and the second domain name set, the amount of computation can be reduced and the association with the unknown domain name can be strengthened.

[0067] Step S103: Store and / or output the domain names associated with the unknown domain name so as to update the DPI feature library based on the associated domain names, the DPI feature library being used to identify the application category of the unknown domain name.

[0068] For example, the associated domain name can be stored in memory for use when needed, or output to the DPI manufacturer so that the DPI manufacturer can update the DPI feature library based on the domain name associated with the unknown domain name, thereby improving the operator's DPI feature library's recognition rate of unknown domain names.

[0069] In some embodiments, determining the domain name associated with the unknown domain name based on the network access records includes: determining the frequency value of each domain name in the network access records including the unknown domain name; and determining the domain name associated with the unknown domain name based on the frequency value of each domain name.

[0070] For example, the frequency value of each domain name can be determined using the Term Frequency-Inverse Document Frequency (TF-IDF) algorithm.

[0071] For example, the frequency value of the domains in the first domain set is determined, and the domains associated with the unknown domains are determined based on the frequency value of the domains in the first domain set.

[0072] In some embodiments, determining the domain name associated with the unknown domain name based on the frequency value of each domain name includes: sorting the domain names according to the frequency value of each domain name; determining a cutoff frequency threshold based on the frequency value of the sorted domain names; and determining the domain name corresponding to the frequency value greater than or equal to the cutoff frequency threshold as the domain name associated with the unknown domain name.

[0073] For example, multiple unknown domain names are denoted as Ui, i = 1, 2, 3..., and the set of corresponding domain names can be determined based on the unknown domain names (S1). For example, if the unknown domain name appears on user A's terminal and the unknown domain name also appears on user B's terminal, the domain names in the network access records of user A and user B's terminals are taken as a set (S1).

[0074] Understandably, the user terminal with the unknown domain name is identified as the first terminal. The term frequency-inverse document algorithm first determines the term frequency (TF value) of the domain name, and then determines the frequency value of the unknown domain name based on the inverse document value (IDF).

[0075] The term frequency (TF value) is the ratio of the first terminal where the corresponding unknown domain name appears to all first terminals. For example, if there are multiple unknown domain names a and b, and in the first terminals, there are 10 terminals where the unknown domain name a appears and 40 terminals where b appears, then the term frequency (TF value) of a is 0.25.

[0076] The inverse document value can be the ratio of the total number of all unknown domain names (COUNT(Ui)) to the number of times the corresponding domain name appears in the set (S1), and then the inverse document value (idf value) is determined by performing a common logarithm operation on the ratio, i.e., a logarithm with base 10.

[0077] The term frequency-inverse document frequency (tf-idf) is the product of the term frequency and the inverse document value.

[0078] For example, the domain names are sorted according to their frequency values, and the cutoff frequency is determined based on the sorted frequency values.

[0079] For example, if the frequency value of domain a is 0.5, domain b is 0.3, domain c is 0.7, domain d is 0.65, and domain e is 0.2, the sorted domains are {c, d, a, b, e}. For instance, the frequency value of the third domain is set as the cutoff frequency threshold.

[0080] For example, the domain name corresponding to a frequency value greater than or equal to the cutoff frequency threshold is determined as the domain name associated with the unknown domain name.

[0081] For example, if the frequency of domain name a is set as the cutoff frequency threshold, then domain names c, d, and a are the associated domain names.

[0082] Sort domain names by frequency value and determine the cutoff frequency threshold, and determine the associated domain names based on the cutoff frequency threshold. This can reduce the amount of computer processing and provide a more intuitive view of the degree of association between domain names and unknown domain names.

[0083] By acquiring network access records from multiple user terminals, including domain names, and at least one user terminal's network access record including an unknown domain name; determining domain names associated with the unknown domain names based on the network access records of the multiple user terminals; storing and / or outputting the domain names associated with the unknown domain names to update the DPI feature library based on the domain names, the DPI feature library being used to identify the application category of the unknown domain names. Utilizing the domain names associated with unknown domain names, the application type and / or source of the unknown domain names can be inferred, effectively solving the problem of unclear source / application type due to insufficient information for unknown domain names, improving the update rate and frequency of the DPI feature library, and maintaining the recognition rate of the DPI feature library for unknown domain names.

[0084] Please see Figure 2 , Figure 2 This is a schematic block diagram of the structure of a computer device provided in an embodiment of the present invention.

[0085] like Figure 2As shown, the computer device 300 includes a processor 301 and a memory 302, which are connected via a bus 303, such as an I2C (Inter-integrated Circuit) bus.

[0086] Specifically, processor 301 provides computing and control capabilities to support the operation of the entire computer device. Processor 301 can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0087] Specifically, the memory 302 can be a Flash chip, a read-only memory (ROM) disk, an optical disk, a USB flash drive, or a portable hard drive, etc.

[0088] Those skilled in the art will understand that Figure 2 The structure shown is merely a block diagram of a portion of the structure related to the embodiments of the present invention, and does not constitute a limitation on the computer device to which the embodiments of the present invention are applied. A specific server may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0089] The processor is used to run a computer program stored in a memory, and when executing the computer program, implements any of the unknown domain name identification methods provided in the embodiments of the present invention.

[0090] In one embodiment, the processor is configured to run a computer program stored in memory, and when executing the computer program, perform the following steps:

[0091] Obtain network access records of multiple user terminals, wherein the network access records include domain names, and at least one of the user terminals includes an unknown domain name in its network access records;

[0092] The domain name associated with the unknown domain name is determined based on the network access records of the multiple user terminals;

[0093] Store and / or output domain names associated with the unknown domain name in order to update the DPI feature library based on the associated domain names, the DPI feature library being used to identify the application category of the unknown domain name.

[0094] In one embodiment, when the processor determines the domain name associated with the unknown domain name based on the network access records of the plurality of user terminals, it is configured to:

[0095] The first terminal is determined based on the network access records that include the unknown domain name, and the second terminal is determined based on the network access records that do not include the unknown domain name.

[0096] A first domain name set is generated based on the network access records of the first terminal;

[0097] A second set of domain names is generated based on the network access records of the second terminal;

[0098] The domain name associated with the unknown domain name is determined based on the first domain name set and the second domain name set.

[0099] In one embodiment, when the processor determines the domain name associated with the unknown domain name based on the first domain name set and the second domain name set, it is configured to:

[0100] The domain name associated with the unknown domain name is determined based on the domain names that are in the first domain name set but not in the second domain name set.

[0101] In one embodiment, when the processor generates a first domain name set based on the network access records of the first terminal and a second domain name set based on the network access records of the second terminal, it is configured to:

[0102] The first domain name set is generated by extracting unique domain names from the network access records of multiple first terminals, and the second domain name set is generated by extracting unique domain names from the network access records of multiple second terminals.

[0103] In one embodiment, when the processor acquires network access records of multiple user terminals, wherein the network access records include domain names, and at least one user terminal's network access record includes an unknown domain name, it is configured to:

[0104] Obtain network access records from multiple user terminals, wherein the network access records include known domain names, and at least one of the user terminals includes network access records from unknown domain names.

[0105] When determining the domain name associated with the unknown domain name based on the network access records of the multiple user terminals, the method is used to: determine the known domain name associated with the unknown domain name based on the network access records of the multiple user terminals.

[0106] When storing and / or outputting domain names associated with the unknown domain name, the method is used to: store and / or output known domain names associated with the unknown domain name.

[0107] In one embodiment, when the processor acquires network access records of multiple user terminals, it is configured to:

[0108] Obtain the domain name information accessed by the user terminal;

[0109] If a user terminal accesses domain name information that includes the unknown domain name, a corresponding network access record is generated based on the domain name information accessed by the user terminal. The network access record of the user terminal includes known domain names and unknown domain names.

[0110] If the domain name information accessed by a user terminal does not include the unknown domain name, a corresponding network access record is generated based on the domain name information accessed by the user terminal, and the network access record of the user terminal includes known domain names.

[0111] In one embodiment, when the processor determines the known domain name associated with the unknown domain name based on the network access record, it is configured to:

[0112] Determine the frequency value of each known domain name in the network access records including the unknown domain name;

[0113] The known domain names associated with the unknown domain names are determined based on the frequency values ​​of each known domain name.

[0114] In one embodiment, when the processor determines the known domain name associated with the unknown domain name based on the frequency value of each known domain name, it is configured to: sort the known domain names according to the frequency value of each known domain name;

[0115] Determine the cutoff frequency threshold based on the known frequency values ​​of the sorted domain names;

[0116] Known domains corresponding to frequency values ​​greater than or equal to the cutoff frequency threshold are identified as known domains associated with the unknown domain.

[0117] It should be noted that those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the computer device described above can be referred to the corresponding process in the aforementioned embodiment of the unknown domain name identification method, and will not be repeated here.

[0118] This invention also provides a storage medium for computer-readable storage, wherein the storage medium stores one or more programs that can be executed by one or more processors to implement the steps of any of the methods for identifying unknown domain names provided in the specification of this invention.

[0119] The storage medium can be an internal storage unit of the computer device described in the foregoing embodiments, such as the hard disk or memory of the computer device. The storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card equipped on the computer device.

[0120] It will be understood by those skilled in the art that all or some of the steps, systems, or apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware embodiments, the division between functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0121] It should be understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. It should be noted that, herein, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0122] The sequence numbers of the above embodiments of the present invention are merely for descriptive purposes and do not represent the superiority or inferiority of the embodiments. The above descriptions are only specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for identifying unknown domain names, characterized in that, The method includes: Obtain network access records of multiple user terminals, the network access records including known domain names, and at least one of the user terminals including unknown domain names in its network access records, wherein the known domain names and the unknown domain names are non-first-level domain names; Based on the network access records of the multiple user terminals, a known domain name associated with the unknown domain name is determined; Store and / or output known domains associated with the unknown domain to update the DPI feature library based on the associated known domains, the DPI feature library being used to identify the application category of the unknown domain.

2. The method for identifying unknown domain names according to claim 1, characterized in that, The step of determining the known domain name associated with the unknown domain name based on the network access records of the multiple user terminals includes: The first terminal is determined based on the network access records that include the unknown domain name, and the second terminal is determined based on the network access records that do not include the unknown domain name. A first domain name set is generated based on the network access records of the first terminal; A second set of domain names is generated based on the network access records of the second terminal; Based on the first set of domain names and the second set of domain names, a known domain name associated with the unknown domain name is determined.

3. The method for identifying unknown domain names according to claim 2, characterized in that, The step of determining the known domain name associated with the unknown domain name based on the first domain name set and the second domain name set includes: The known domain name associated with the unknown domain name is determined based on the known domain names that are in the first domain name set but not in the second domain name set.

4. The method for identifying unknown domain names according to claim 2, characterized in that, The step of generating a first domain name set based on the network access records of the first terminal and generating a second domain name set based on the network access records of the second terminal includes: The first domain name set is generated by extracting unique domain names from the network access records of multiple first terminals, and the second domain name set is generated by extracting unique domain names from the network access records of multiple second terminals.

5. The method for identifying unknown domain names according to claim 1, characterized in that, The acquisition of network access records from multiple user terminals includes: Obtain the domain name information accessed by the user terminal; If a user terminal accesses domain information that includes the unknown domain, a corresponding network access record is generated based on the domain information accessed by the user terminal. The network access record of the user terminal includes known domains and unknown domains. If the domain name information accessed by a user terminal does not include the unknown domain name, a corresponding network access record is generated based on the domain name information accessed by the user terminal, and the network access record of the user terminal includes known domain names.

6. The method for identifying unknown domain names according to any one of claims 1-4, characterized in that, The step of determining the known domain name associated with the unknown domain name based on the network access records includes: Determine the frequency value of each known domain name in the network access records including the unknown domain name; The known domain names associated with the unknown domain names are determined based on the frequency values ​​of each known domain name.

7. The method for identifying unknown domain names according to claim 6, characterized in that, The step of determining the known domain names associated with the unknown domain name based on the frequency values ​​of each known domain name includes: The known domain names are sorted according to their frequency values. Determine the cutoff frequency threshold based on the known frequency values ​​of the sorted domain names; Known domains corresponding to frequency values ​​greater than or equal to the cutoff frequency threshold are identified as known domains associated with the unknown domain.

8. A computer device, characterized in that, The computer device includes a processor, a memory, a computer program stored in the memory and executable by the processor, and a data bus for enabling communication between the processor and the memory, wherein when the computer program is executed by the processor, it implements the steps of the unknown domain name identification method as described in any one of claims 1 to 7.

9. A storage medium for computer-readable storage, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the unknown domain name identification method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and device for generating DPI (Deep Packet Inspection) rule

    CN106301825A

  • Domain name recognition method and device, storage medium and electronic device

    CN110198292A