Method and related device for determining terminal device type
By acquiring the data traffic of the terminal device and using pre-trained terminal type judgment rules, the problem of poor terminal device type recognition effect in the prior art is solved, and accurate identification and determination of various terminal device types are achieved.
Patent Information
- Application Number
- CN202110420570.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-01-20
- Filing Date
- 2021-04-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-04-19
AI Technical Summary
The prior art is difficult to effectively identify and determine the type of terminal devices, especially in terminal devices that do not support static fingerprint libraries or protocol scanning.
By acquiring the data traffic of the terminal device, the access behavior is determined based on the receiving end identification information of the message, and the type of the terminal device is determined using the pre-trained terminal type judgment rules. This rule is obtained based on historical data traffic training and can be applied to various terminal device types.
It realizes accurate identification of each terminal device type in the network, expands the application scope, and can be applied to terminal devices that do not support static fingerprint library or protocol scanning, improving the effect of terminal device type determination.
Smart Images

Figure CN114785708B_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application titled "An Information Management Method, Device and System" with the application number 202110078112.9, which was filed with the National Intellectual Property Administration on January 20, 2021. The entire content of the aforementioned Chinese patent application is incorporated herein by reference. Technical Field
[0002] This application relates to the field of information technology, and more specifically, to a method for determining the type of a terminal device and related devices. Background Art
[0003] With the development of information technology, it has become a trend to use terminal devices to replace manual labor. This is more prominent in service industries such as banks and hospitals. For example, in a bank, deposits, withdrawals, and transfers can all be achieved through the bank's automated teller machine (ATM); retrieving customer receipts can also be achieved through an electronic receipt cabinet. In a hospital, registering, queuing, and printing diagnostic results can also be achieved using terminal devices.
[0004] Only by comprehensively and effectively identifying the terminal devices in the network can we achieve the so-called "knowing the inventory", so as to recognize risks, find loopholes, and thus realize the security inspection of the network.
[0005] Currently, the type identification of terminal devices relies on commercial fingerprint database scanning and manual static maintenance. However, fingerprint databases generally rely on manual entry, and many terminal devices related to specific industries do not have a complete static fingerprint database. In addition, when collecting data, it is necessary to scan the terminal devices depending on a specific protocol, which requires the terminal devices to support protocol scanning or install a client supporting the inventory function in order to discover assets. Many terminal devices have few interaction messages, and the information required by the fingerprint database cannot be sent out, or the terminal devices themselves simply do not have the hardware or other environment to support protocol scanning or install an inventory client.
[0006] Therefore, how to effectively determine the type of a terminal device is an urgent problem to be solved in this field. Summary of the Invention
[0007] This application provides a method for determining the type of a terminal device and related devices, which can improve the effect of determining the type of a terminal device.
[0008] In a first aspect, an embodiment of the present application provides a method for determining the type of a terminal device, including: obtaining a first data traffic, where the sending end of the first data traffic is a first terminal device; determining the access behavior of the first terminal device according to the identification information of the receiving end of the message in the first data traffic; determining the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device, where the terminal type determination rule indicates the corresponding relationship between the access behavior of the terminal device and the type of the terminal device, and the terminal type determination rule is obtained by training based on historical data traffic.
[0009] The above technical solution can determine the type of each terminal device in the network by using a pre-trained terminal type determination rule, thus laying a foundation for subsequent device inventory. In addition, the terminal type determination rule used in the above technical solution is determined based on historical traffic data, rather than based on a static fingerprint library. Therefore, the above technical solution can be applied to terminal devices that do not support a static fingerprint library or protocol scanning. In this way, the application scope of the above technical solution is wider, and it is a more effective solution for determining the type of terminal devices.
[0010] In combination with the first aspect, in a possible implementation manner of the first aspect, the sending end of the historical data traffic includes multiple types of terminal devices, and the type of the first terminal device is one of the multiple types.
[0011] Optionally, in some embodiments, the sending end of the historical data traffic may not include the first terminal device.
[0012] In combination with the first aspect, in a possible implementation manner of the first aspect, the terminal type determination rule is obtained by training according to the historical data traffic and terminal classification information, where the terminal classification information is used to indicate the multiple types and multiple groups of terminal identification information, each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal, the terminal classification information is further used to indicate the corresponding relationship between the multiple types and the multiple groups of terminal identification information, the multiple types and the multiple groups of terminal identification information are in one-to-one correspondence, each terminal identification information in the multiple terminal identification information includes the identification information of at least one terminal device, and the historical data traffic is determined according to the terminal classification information.
[0013] In combination with the first aspect, in a possible implementation manner of the first aspect, the historical data traffic includes a plurality of reference traffic, the plurality of reference traffic corresponds to the plurality of types one by one, the plurality of reference traffic includes a first reference traffic, and the type corresponding to the first reference traffic is the type of the first terminal device; the terminal type determination rule includes a plurality of sub-rules, the plurality of sub-rules corresponds to the plurality of types one by one, and the sub-rule corresponding to the type of the first terminal device among the plurality of sub-rules is determined according to the first reference traffic and the reference traffic other than the first reference traffic among the plurality of reference traffic.
[0014] In combination with the first aspect, in a possible implementation manner of the first aspect, the first reference traffic is determined according to a first candidate traffic, the first candidate traffic is the traffic corresponding to the type of the first terminal device among a plurality of candidate traffic, and the number of times the access behavior corresponding to each data stream in the first reference traffic appears in the first candidate traffic is greater than the number of times the access behavior corresponding to the data stream that does not belong to the first reference traffic appears in the first candidate traffic.
[0015] In combination with the first aspect, in a possible implementation manner of the first aspect, the terminal type determination rule is determined according to the clustering result obtained by clustering P terminal devices by P server sets, the P terminal devices are determined according to the historical data traffic, the P terminal devices correspond to the P server sets one by one, each server set in the P server sets is a set of servers accessed by the corresponding terminal device, the P terminal devices include terminal devices of the plurality of types, and P is a positive integer greater than or equal to the total number of types of terminal devices.
[0016] In combination with the first aspect, in a possible implementation manner of the first aspect, the historical data traffic is the uplink data stream of the P terminal devices, and the P terminal devices are the sending ends of the historical data traffic.
[0017] In combination with the first aspect, in a possible implementation manner of the first aspect, the ratio of the number of times each terminal device in the P terminal devices acts as the sending end of the synchronization message to the number of times it acts as the receiving end of the synchronization message in the historical data traffic is greater than a second preset ratio.
[0018] In combination with the first aspect, in a possible implementation manner of the first aspect, the historical data traffic includes P reference traffic, the plurality of reference traffic corresponds to the P terminal devices one by one, the P reference traffic corresponds to P candidate traffic one by one, the number of times the access behavior corresponding to each data stream included in the second reference traffic appears in the corresponding second candidate traffic is greater than the number of times the access behavior corresponding to the data stream that does not belong to the second reference traffic appears in the second candidate traffic, and the second reference traffic is any one of the P reference traffic.
[0019] In combination with the first aspect, in a possible implementation manner of the first aspect, the terminal type determination rule is a determination matrix, which includes multiple rows of elements, and the multiple rows of elements correspond to the multiple types one by one; determining the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device includes: determining, according to the access behavior of the first terminal, a target row in the determination matrix that matches the access behavior of the first terminal device; determining that the type of the first terminal device is the type corresponding to the target row.
[0020] In combination with the first aspect, in a possible implementation manner of the first aspect, determining, according to the access behavior of the first terminal, a target row in the determination matrix that corresponds to the access behavior of the first terminal device includes: determining, according to the access behavior of the first terminal, a reference matrix, where the values of the multiple elements included in the reference matrix match the access behavior of the first terminal device; multiplying the determination matrix by the reference matrix to obtain a target matrix, where the multiple elements included in the target matrix correspond to the multiple rows of elements of the determination rule one by one; determining a row of elements corresponding to the element with the largest value in the target matrix as the target row.
[0021] In a second aspect, an embodiment of the present application provides a computer device, which includes units for implementing the first aspect or any possible implementation manner of the first aspect.
[0022] In a third aspect, an embodiment of the present application provides a computer device, which includes a processor for being coupled to a memory and reading and executing instructions and / or program codes in the memory to execute the first aspect or any possible implementation manner of the first aspect.
[0023] In a fourth aspect, an embodiment of the present application provides a chip system, which includes logic circuits for being coupled to an input / output interface and transmitting data through the input / output interface to execute the first aspect or any possible implementation manner of the first aspect.
[0024] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores program codes, and when the computer-readable storage medium runs on a computer, causes the computer to execute the first aspect or any possible implementation manner of the first aspect.
[0025] In a sixth aspect, an embodiment of the present application provides a computer program product, which includes: computer program codes, and when the computer program codes run on a computer, cause the computer to execute the first aspect or any possible implementation manner of the first aspect. Description of the Drawings
[0026] Figure 1 It is a schematic diagram of a possible application scenario provided according to an embodiment of the present application.
[0027] Figure 2 It is a schematic diagram of a centralized deployment solution.
[0028] Figure 3 It is a schematic diagram of a distributed deployment solution.
[0029] Figure 4 It is a schematic flowchart for determining the terminal type judgment rule through supervised learning.
[0030] Figure 5 It is a schematic flowchart for determining the terminal type judgment rule through unsupervised learning.
[0031] Figure 6 It is a schematic flowchart of a method for judging the type of terminal device according to an embodiment of the present application.
[0032] Figure 7 It is a structural block diagram of a computer device provided according to an embodiment of the present application. Detailed implementation manners
[0033] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.
[0034] In the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item)" or similar expressions thereof refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. In addition, in the embodiments of the present application, words such as "first" and "second" do not limit the quantity and execution order.
[0035] It should be noted that in the present application, words such as "exemplary" or "for example" are used to give examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0036] To help those skilled in the art better understand the technical solution of this application, some concepts related to this application are briefly introduced first.
[0037] 1. Data stream
[0038] A data stream can also be simply referred to as a stream. A stream contains several packets. Packets have an upstream direction and a downstream direction. Generally, the direction from the terminal device to the server can be regarded as the upstream direction, and the direction from the server to the terminal device as the downstream direction. A stream is identified by a five-tuple. From the establishment of the connection between the terminal device and the server until the connection is disconnected, the source Internet Protocol (IP) address in all upstream packets transmitted during this period is the terminal device, and the destination IP address is the server; the source IP address in all downstream packets is the server, and the destination IP address is the terminal device. Therefore, it can be considered that all the packets transmitted during this period are the packets in a stream.
[0039] The terminal device as the sender of the upstream packet and the receiver of the downstream packet in the data stream can be the terminal device in the data stream or the terminal device corresponding to the data stream; the server as the receiver of the upstream packet and the sender of the downstream packet in the data stream can be called the server in the data stream or the terminal device corresponding to the data stream. For example, the terminal device A in data stream A means that the sender of all upstream packets in data stream A is terminal device A, and the server A in data stream A means that the sender of all downstream packets in data stream A is server B.
[0040] 2. Traffic
[0041] Traffic can also be referred to as data traffic. Traffic is the set of all data streams counted within a period of time. Traffic can include multiple data streams, and the communication parties of any two streams in the multiple data streams can be the same or different.
[0042] 3. Terminal device
[0043] The terminal device referred to in the embodiments of this application may include Internet of Things terminals and production terminals. Internet of Things terminals are special computer devices with specific uses, such as medical devices, oil sensors, etc. Production terminals are computer devices that run a general operating system (such as Windows operating system, Linux operating system, etc.) but perform specific functions, such as queuing machines, ticket-taking / registration machines, etc.
[0044] Figure 1 is a schematic diagram of a possible application scenario provided according to the embodiments of this application. As Figure 1As shown in the figure, the system 100 includes a network control device 101, network forwarding devices 111 and 112, terminal devices 121, 122, 123, 124, 125, and servers 131 and 132.
[0045] In the embodiments of the present application, the terminal devices (such as Figure 1 the terminal devices 121, 122, 123, 124, 125 shown in the figure) can be computer devices with one or more specific functions (such as ATMs, electronic receipt cabinets, queuing machines, X-ray film printers, cameras, etc.), or can be computer devices with general functions (such as mobile phones, tablets, desktop computers, laptop computers, etc.). The terminal devices referred to in the embodiments of the present application can communicate with the server through the network forwarding device, read the data saved in the server, and / or write data to the server.
[0046] Taking Figure 1 the system 100 shown in the figure as an example, the terminal device 121 can access the server 131 through the network forwarding device 111 and read the data saved in the server 131; the terminal device 124 can access the server 132 through the network forwarding device 112 and write data to the server 132.
[0047] The network forwarding devices (such as Figure 1 the network forwarding devices 111 and 112 shown in the figure) can be switches / routers. The network forwarding devices can monitor the traffic generated by the terminal devices. In some embodiments, the network forwarding devices can also extract the characteristics of the monitored traffic.
[0048] The network control device (such as, Figure 1 the network control device 101 shown in the figure) can be a network controller, a server, or a computer, etc.
[0049] In some embodiments, the network control device can determine the type of the terminal device based on the terminal type determination rule and take inventory of the terminal devices in the network.
[0050] In some other embodiments, the work of determining the type of the terminal device can be implemented by the network forwarding device, and the work of taking inventory of the terminal devices can be implemented by the network control device.
[0051] Figure 2 is a schematic diagram of a centralized deployment solution. In the centralized deployment solution, the determination of the terminal device type and the asset inventory are both implemented by the network control device.
[0052] As Figure 2As shown in the figure, the network control device 200 includes a rule configuration module 201, a rule matching module 202, an asset information extraction module 203, an asset inventory module 204, and an asset library module 205.
[0053] The rule configuration module 201 obtains the terminal type judgment rule and saves the terminal type judgment rule.
[0054] The rule matching module 202 determines the type of the terminal device according to the mirror image of the data traffic and the terminal type judgment rule saved by the rule configuration module 201.
[0055] The asset information extraction module 203 extracts the asset information of the terminal device (such as Internet Protocol (IP) address, port number, and / or Media Access Control (MAC) address, etc.).
[0056] The asset inventory module 204 integrates the asset information extracted by the asset information extraction module 203 according to the judgment result of the rule matching module 202 (such as merging, deduplication, etc.), and then enters the integration result into the asset library module 205.
[0057] The user can obtain the final asset inventory result through the asset library module 205.
[0058] Figure 3 It is a schematic diagram of a distributed deployment solution. In the distributed deployment solution, the determination of the terminal device type and the extraction of asset information can be implemented by the network forwarding device. The network control device is responsible for the final asset inventory work.
[0059] As Figure 3 As shown in the figure, the network control device 310 includes a rule configuration module 311, an asset inventory module 312, and an asset library module 313. The network forwarding device 320 includes a rule matching module 321 and an asset information extraction module 322.
[0060] The rule configuration module 311 obtains the terminal type judgment rule and sends the obtained terminal type judgment rule to the network forwarding device 320.
[0061] The rule matching module 321 obtains the terminal type judgment rule from the network control device 310, determines the type of the terminal device according to the data traffic and the terminal type judgment rule, and reports the judgment result to the network control device 310.
[0062] The asset information extraction module 322 extracts the asset information of the terminal device (such as IP address, port number, and / or MAC address, etc.) and reports the extracted asset information to the network control device 310.
[0063] The asset inventory module 312 integrates (such as merging, deduplicating, etc.) the asset information extracted by the asset information extraction module 322 according to the judgment result of the rule matching module 321, and then enters the integration result into the asset library module 313.
[0064] Users can obtain the final asset inventory result through the asset library module 313.
[0065] Such as Figure 2 shown in the network control device 200 and as Figure 3 shown in the network control device 310 can be the network control device 101 as Figure 1 shown. Such as Figure 3 shown in the network forwarding device 320 can be the network forwarding device 111 or the network forwarding device 112 as Figure 1 shown.
[0066] As described above, the type of the terminal device is determined according to the terminal type judgment rule. The terminal type judgment rule can be trained based on historical data traffic. There are two methods to train the terminal type judgment rule. The first method is supervised learning; the second method is unsupervised learning.
[0067] Figure 4 It is a schematic flowchart for determining the terminal type judgment rule by supervised learning.
[0068] 401, obtain terminal classification information.
[0069] The terminal classification information is used to indicate the types of multiple terminal devices and multiple terminal identification information. The terminal classification information can also indicate the corresponding relationship between multiple types and multiple terminal identification information. The multiple types and the multiple terminal identification information are in one-to-one correspondence.
[0070] For example, Table 1 is a schematic of a terminal classification information.
[0071] Table 1
[0072]
[0073] As shown in Table 1, the IP address range corresponding to the terminal device of type A is 192.101.1.1~192.1.1.10; the IP address range corresponding to the terminal device of type B is 192.101.1.11~192.1.1.20; the IP address range corresponding to the terminal device of type C is 192.101.1.21~192.1.1.30.
[0074] It is understandable that Table 1 is only a schematic illustration of terminal classification information. For example, in Table 1, an IP address is used as an example of terminal identification information. In some other embodiments, the terminal identification information may include any one or more types of identification information that can distinguish different terminal devices. For example, the terminal identification information may include any one or more of the IP address, port number, or MAC address of the terminal device, etc.
[0075] The terminal classification information is obtained by pre-collection. For example, it can be determined according to terminal devices that can support data fingerprints and protocol scanning. Another example is that it can be obtained by manual statistics.
[0076] 402. According to this terminal classification information, obtain historical data traffic.
[0077] After obtaining the terminal classification information, the traffic can be monitored according to the terminal identification information in the terminal classification information, and data streams containing the terminal identification information in the terminal classification information can be extracted.
[0078] Taking the terminal classification information shown in Table 1 as an example, all data streams with source / destination IP addresses within the IP address range shown in Table 1 can be extracted.
[0079] The data streams extracted according to the terminal identification information in the terminal classification information can be called historical data streams. For the convenience of description, it can be assumed that a total of K historical streams are obtained, and the value of K is greater than or equal to the total number of terminal device types. In other words, the historical data traffic in step 402 includes K historical streams.
[0080] For each type of terminal device among the multiple types indicated by the terminal classification information, there is at least one corresponding historical stream among the K historical streams. In other words, the data streams of at least one terminal device of each type are extracted as historical data traffic.
[0081] It is also assumed that the types of terminal devices altogether include three types: A, B, and C, and K can take a positive integer greater than or equal to 3. Among the K historical streams, at least one historical stream corresponds to a terminal device of type A, at least one historical stream corresponds to a terminal device of type B, and at least one historical stream corresponds to a terminal device of type C. In other words, among the K historical streams, the terminal device of at least one historical stream is of type A, the terminal device of at least one historical stream among at least one historical stream is of type B, and the terminal device of at least one historical stream is of type C.
[0082] According to the types of terminal devices corresponding to the historical data traffic, the K historical streams can be divided into multiple reference traffic, and the multiple reference traffic corresponds one-to-one to the multiple types of terminal devices.
[0083] Taking three types of terminal devices, namely A, B, and C, as an example, the K historical traffic flows include reference flow A, reference flow B, and reference flow C. Among them, reference flow A includes at least one historical flow corresponding to the terminal device of type A (that is, the type of the terminal device in each historical flow in reference flow A is type A), reference flow B includes at least one historical flow corresponding to the terminal device of type B (that is, the type of the terminal device in each historical flow in reference flow B is type B), and reference flow C includes at least one historical flow corresponding to the terminal device of type C (that is, the type of the terminal device in each historical flow in reference flow C is type C). For the convenience of description, the historical flows in the reference flows can also be called reference flows.
[0084] Each reference flow is determined from the corresponding candidate flow. The candidate flows are determined according to the terminal classification information. According to the terminal classification information, multiple candidate flows can be determined, and the multiple candidate flows correspond one-to-one to the types of multiple terminal devices. As described above, the historical data traffic includes multiple reference flows, and the multiple reference flows correspond one-to-one to the types of multiple terminal devices. Therefore, the multiple reference flows also correspond one-to-one to the multiple candidate flows. Each reference flow is determined according to the corresponding candidate flow.
[0085] Taking three types of terminal devices, namely A, B, and C, as an example, a total of three candidate flows can be determined, which can be called candidate flow A, candidate flow B, and candidate flow C respectively. Candidate flow A includes multiple candidate flows, and the type of the terminal device in each candidate flow in the multiple candidate flows is type A. Similarly, candidate flow B also includes multiple candidate flows, and the type of the terminal device in each candidate flow in the multiple candidate flows is type B; candidate flow C also includes multiple candidate flows, and the type of the terminal device in each candidate flow in the multiple candidate flows is type C.
[0086] If the access behavior of a candidate flow appears more frequently in the candidate flow that includes this candidate flow, then this candidate flow can be used as a reference flow in the corresponding reference flow.
[0087] Optionally, in some embodiments, the same access behavior may mean that the source IP and the destination IP are the same. Whether the access behaviors of two flows are the same can be judged by the upstream packets or downstream packets of these two flows. If the source IP address and the destination IP address of the upstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior, otherwise it is considered that the access behaviors of these two flows are different. If the source IP address and the destination IP address of the downstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior, otherwise it is considered that the access behaviors of these two flows are different.
[0088] For example, assume that IP 1 to IP 3 are the IP addresses of three terminal devices, and IP A, IP B, and IP C are the IP addresses of three servers. Assume that the source IP address of the upstream packet of candidate flow 1 is IP 1, and the destination IP address of the upstream packet of candidate flow 1 is IP A; the source IP address of the upstream packet of candidate flow 2 is IP 1, and the destination IP address of the upstream packet of candidate flow 2 is IP A; the source IP address of the upstream packet of candidate flow 3 is IP 2, and the destination IP address of the upstream packet of candidate flow 3 is IP A. Then, candidate flow 1 and candidate flow 2 have the same access behavior, and the access behavior of candidate flow 1 and candidate flow 3 is different.
[0089] Optionally, in some other embodiments, the same access behavior may include: the same source IP, the same destination IP, the same source port, and the same destination IP port. Whether the access behaviors of two flows are the same can be determined by the upstream or downstream packets of these two flows. If the source IP address, source port number, destination IP address, and destination port number of the upstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; if any one of the source IP address, source port number, destination IP address, and destination port number of the upstream packets of two flows is different, then it can be considered that these two flows have different access behaviors. If the source IP address, source port number, destination IP address, and destination port number of the downstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; if any one of the source IP address, source port number, destination IP address, and destination port number of the downstream packets of two flows is different, then it can be considered that these two flows have different access behaviors.
[0090] Optionally, in some other embodiments, if the five-tuples of the packets in the same direction (upstream or downstream) of two flows are exactly the same, then it is considered that the access behaviors of these two flows are the same.
[0091] In some embodiments, T candidate flows with the top-ranked number of candidate flows having the same access behavior in the candidate traffic can be selected as the reference flows in the reference traffic corresponding to the candidate traffic, where T is a preset positive integer.
[0092] For example, assume that candidate traffic A includes candidate flows with five access behaviors, namely access behavior 1 to access behavior 5. Among them, there are 100 candidate flows with access behavior 1, 120 candidate flows with access behavior 2, 80 candidate flows with access behavior 3, 20 candidate flows with access behavior 4, and 5 candidate flows with access behavior 5.
[0093] T can be a preset value. Assume the value of T is 3. Assuming the value of T is 3, then the candidate flows with access behavior 1, the candidate flows with access behavior 2, and the candidate flows with access behavior 3 can be selected as the reference flows in the reference traffic.
[0094] T can also be calculated according to a preset ratio. The ratio of the number of candidate flows selected as the historical data traffic to the total number of candidate flows in a candidate traffic is a preset value. Then the value of T can be determined according to this preset value and the total number of candidate flows included in the candidate traffic. For example, assume the total number of candidate flows included in the candidate traffic is T_all and the preset ratio is P T %, then N CAND =ceil(T_all×P T %), where ceil(T_all×P T %) represents the rounding operation on the result of T_all×P T %, and the rounding method can be rounding up, rounding down, or rounding according to the rule of rounding half up. The embodiments of the present application do not limit this.
[0095] The way to select the historical data traffic from the candidate traffic can also be determined according to the total number of flows included in the candidate traffic and a preset ratio. For example, the candidate flows with the same access behavior in candidate traffic A greater than 25% of the total number of flows can be selected. Assume there are 100 candidate flows with access behavior 1, 120 candidate flows with access behavior 2, 80 candidate flows with access behavior 3, 20 candidate flows with access behavior 4, and 5 candidate flows with access behavior 5 in candidate traffic A. Then it can be determined that the proportion of candidate flows with access behavior 1 in the total candidate flows is 30.8%, the proportion of candidate flows with access behavior 2 in the total candidate flows is 36.9%, the proportion of candidate flows with access behavior 3 in the total candidate flows is 24.6%, the proportion of candidate flows with access behavior 4 in the total candidate flows is 6.1%, and the proportion of candidate flows with access behavior 5 in the total candidate flows is 1.5. Then it can be determined that the candidate flows with access behavior 1 and the candidate flows with access behavior 2 are used as the reference flows in reference traffic A.
[0096] 403. Determine the terminal type judgment rule according to the historical data traffic.
[0097] The terminal type judgment rule can include multiple sub - rules, and the multiple sub - rules correspond one by one to the types of the multiple terminal devices. As described above, the historical data traffic includes multiple reference traffics, and the multiple reference traffics correspond one by one to the types of the multiple terminal devices. Therefore, the multiple sub - rules also correspond one by one to multiple groups of historical data traffic. Each sub - rule can be determined according to the corresponding reference traffic and the historical data traffic except the corresponding group of reference traffic.
[0098] Taking three types of terminals, namely A, B, and C, as examples, the terminal type determination rule may include sub-rule A, sub-rule B, and sub-rule C. Among them, sub-rule A corresponds to the terminal device of type A, sub-rule B corresponds to the terminal device of type B, and sub-rule C corresponds to the terminal device of type C.
[0099] Sub-rule A can be determined based on reference traffic A and historical data traffic other than reference traffic A.
[0100] Sub-rule B can be determined based on reference traffic B and historical data traffic other than reference traffic B.
[0101] Sub-rule C can be determined based on reference traffic C and historical data traffic other than reference traffic C.
[0102] Taking sub-rule A as an example below, how to determine the sub-rule will be introduced.
[0103] The access behavior of the terminal device of type A can be obtained according to reference traffic A, and the access behavior of other types of terminal devices can be determined according to the historical data traffic other than reference traffic A. Then, sub-rule A can be determined by using the set difference method.
[0104] The access behavior of the terminal device may include the identification information of the server accessed by the terminal device, etc. The identification information of the server may include any one or more of the IP address, port number, and MAC address of the server.
[0105] By extracting the upstream message, the server accessed by the terminal device can be determined, and then the identification information of the server can be obtained. The access behavior is summarized according to the identification information of the server to obtain each sub-rule.
[0106] In some embodiments, the servers accessed by different types of terminal devices are different. Therefore, the IP address of the server can be used as the basis for judging the type of the terminal device. For example, an ATM with deposit and withdrawal functions can access the server for load deposit (hereinafter referred to as the deposit server) and the server for withdrawal function (hereinafter referred to as the withdrawal server); while an ATM with only withdrawal function can only access the withdrawal server; the electronic receipt cabinet only accesses the server providing receipt services (hereinafter referred to as the receipt server) and cannot access the deposit server or the withdrawal server. The identification information of different servers is different. In this way, different types of terminal devices can be distinguished according to the identification information of the server. For example, an ATM with deposit and withdrawal functions is a terminal device of type A, an ATM with only withdrawal function is a terminal device of type B, and the electronic receipt cabinet is a terminal device of type C. In this case, the IP addresses of the servers accessed by different types of terminal devices are different. According to the historical data traffic, it can be found that the IP address accessed by reference traffic A is IPW and IP D ; The IP address accessed by reference traffic B is IP W ; The IP address accessed by reference traffic C is IP R , where IP W represents the IP address of the withdrawal server, and IP D represents the IP address of the deposit server, and IP R represents the IP address of the receipt server.
[0107] According to reference traffic A, reference traffic B, and reference traffic C, the following sub - rules can be determined:
[0108] Sub - rule A: IP W , IP D ;
[0109] Sub - rule B: IP W ;
[0110] Sub - rule C: IP R ,
[0111] The judgment rule for the terminal type can be represented by a judgment matrix, and this judgment matrix can be expressed as:
[0112]
[0113] M represents this judgment matrix. As described above, the judgment matrix M includes a total of three rows of elements, where the three rows of elements correspond one - to - one with the three sub - rules. In each row of elements, the first element corresponds to IP W , the second element corresponds to IP D , and the third element corresponds to IP R . If the value of an element is 1, it means that the access behavior includes accessing the corresponding server; if the value of an element is 0, it means that the access behavior does not include accessing the corresponding server.
[0114] As described above, sub - rule A is IP W and IP D , so the values of the row of elements in the judgment matrix M corresponding to sub - rule A (i.e., the first row of elements) are 1, 1, 0 in sequence.
[0115] In some other embodiments, the servers accessed by different types of terminal devices may be the same, but the port numbers used by different functions to access the servers are different. In this case, the IP address and port number of the server can be used as the basis for determining the type of terminal device. For example, in a hospital scenario, there are three types of terminal devices: registration / number pickup machines, registration machines, and diagnostic result printers. Server A can provide both registration and number pickup functions, where the registration function is implemented through port A and the number pickup function is implemented through port B. Server B provides the diagnostic result function. Assume that the access behaviors of reference traffic A include two types: access behavior 1 is IP A:Port A, and access behavior 2 is IP A: Port B; the access behavior of reference traffic B is IP A: Port A; the access behavior of reference traffic C is IP B, where IP A represents the IP address of server A, IP B represents the IP address of server B, Port A represents the port number of port A, and Port B represents the port number of port B. By synthesizing the above four access behaviors, it can be found that the difference set between the access behavior of reference traffic A and that of reference traffic B is IP A: Port B; the difference set between reference traffic A and reference traffic C is IP A:Port A, IP A: Port B, and IP B; the difference set between reference traffic B and reference traffic C is also IP A:Port A, IP A: Port B, and IP B. In this way, three sub-rules can be determined:
[0116] Sub-rule A: IP A:Port A, IP A: Port B;
[0117] Sub-rule B: IP A:Port A;
[0118] Sub-rule C: IP B.
[0119] If the judgment matrix is used to represent this terminal type judgment rule, then the judgment matrix can be represented as
[0120]
[0121] M represents this judgment matrix. As described above, the judgment matrix M includes a total of three rows of elements, where the three rows of elements correspond one by one to the three sub-rules. In each row of elements, the first element corresponds to IP A:Port A, the second element corresponds to IP A: PortB, and the third element corresponds to IP B. If the value of an element is 1, it means that the access behavior includes accessing the corresponding server; if the value of an element is 0, it means that the access behavior does not include accessing the corresponding server.
[0122] As described above, the sub-rule A is IP A:Port A, IP A: Port B. Therefore, the values of the elements in the row corresponding to the sub-rule A in the judgment matrix M (i.e., the first row elements) are 1, 1, 0 in sequence.
[0123] Figure 5 It is a schematic flowchart for unsupervised learning to determine the judgment rule of the terminal type.
[0124] 501, collect the traffic in the network to obtain the historical data traffic.
[0125] Optionally, in some embodiments, the historical flows included in the historical data traffic can be divided into multiple reference flows, and the multiple reference flows correspond to multiple IP addresses one by one.
[0126] Suppose there are three IP addresses, namely IP 1, IP 2, and IP 3. Then the historical data traffic can include reference flow 1, reference flow 2, and reference flow 3. Among them, reference flow 1 includes at least one historical flow corresponding to IP 1 (that is, the IP address of the sender or receiver of the packets in each historical flow in reference flow 1 is IP 1), reference flow 2 includes at least one historical flow corresponding to IP 2 (that is, the IP address of the sender or receiver of the packets in each historical flow in reference flow 2 is IP 2), and reference flow 3 includes at least one historical flow corresponding to IP 3 (that is, the IP address of the sender or receiver of the packets in each historical flow in reference flow 3 is IP 3). For ease of description, the historical flows in the reference flows can also be called reference flows.
[0127] Each reference flow is determined from the corresponding candidate flow. The collected traffic can be divided into multiple candidate flows, and the multiple candidate flows correspond to multiple IP addresses one by one. Each candidate flow includes multiple candidate flows. The IP address of the sender or receiver of the candidate flows belonging to the same candidate flow is the IP address corresponding to the candidate flow.
[0128] For example, a total of 100 flows are collected. The source IP addresses of flows 1 to 20 are IP1; the source IP addresses of flows 21 to 40 are IP2, and the source IP addresses of flows 41 to 100 are IP3, where IP1, IP2, and IP3 represent three different IP addresses. Then these 100 flows can be divided into three candidate flows. Candidate flow 1 includes flows 1 to 20, candidate flow 2 includes flows 21 to 40, and candidate flow 3 includes flows 41 to 100.
[0129] If the access behavior of a candidate flow appears more frequently in the candidate flow that includes the candidate flow, then this candidate flow can be used as a reference flow in the corresponding reference flow.
[0130] Optionally, in some embodiments, the same access behavior may refer to the same source IP and destination IP. Whether the access behaviors of two flows are the same can be determined by the upstream packets or downstream packets of these two flows. If the source IP address and destination IP address of the upstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; otherwise, it is considered that the access behaviors of these two flows are different. If the source IP address and destination IP address of the downstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; otherwise, it is considered that the access behaviors of these two flows are different.
[0131] For example, assume that IP 1 to IP 3 are the IP addresses of three terminal devices, and IP A, IP B, and IP C are the IP addresses of three servers. Assume that the source IP address of the upstream packet of candidate flow 1 is IP 1, and the destination IP address of the upstream packet of candidate flow 1 is IP A; the source IP address of the upstream packet of candidate flow 2 is IP 1, and the destination IP address of the upstream packet of candidate flow 2 is IP A; the source IP address of the upstream packet of candidate flow 3 is IP 2, and the destination IP address of the upstream packet of candidate flow 3 is IP A. Then candidate flow 1 and candidate flow 2 have the same access behavior, and the access behaviors of candidate flow 1 and candidate flow 3 are different.
[0132] Optionally, in other embodiments, the same access behavior may include: the same source IP, the same destination IP, the same source port, and the same destination IP port. Whether the access behaviors of two flows are the same can be determined by the upstream packets or downstream packets of these two flows. If the source IP address, source port number, destination IP address, and destination port number of the upstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; if any one of the source IP address, source port number, destination IP address, and destination port number of the upstream packets of two flows is different, then it can be considered that these two flows have different access behaviors. If the source IP address, source port number, destination IP address, and destination port number of the downstream packets of two flows are the same, then it can be considered that these two flows have the same access behavior; if any one of the source IP address, source port number, destination IP address, and destination port number of the downstream packets of two flows is different, then it can be considered that these two flows have different access behaviors.
[0133] Optionally, in other embodiments, if the five-tuples of the packets (upstream or downstream) with the same direction of two flows are exactly the same, then it is considered that the access behaviors of these two flows are the same.
[0134] In some embodiments, T candidate flows with the top-ranked number of candidate flows having the same access behavior in the candidate traffic can be selected as the reference flows in the reference traffic corresponding to the candidate traffic, where T is a preset positive integer.
[0135] For example, assume that candidate traffic A includes candidate flows with five access behaviors from access behavior 1 to access behavior 5. Among them, there are 100 candidate flows with access behavior 1, 120 candidate flows with access behavior 2, 80 candidate flows with access behavior 3, 20 candidate flows with access behavior 4, and 5 candidate flows with access behavior 5.
[0136] T can be a preset value. Assume that the value of T is 3. Assuming that the value of T is 3, then the candidate flows with access behavior 1, the candidate flows with access behavior 2, and the candidate flows with access behavior 3 can be selected as the reference flows in the reference traffic.
[0137] T can also be calculated according to a preset ratio. The ratio of the number of candidate flows selected as the historical data traffic to the total number of candidate flows in a candidate traffic is a preset value. Then, the value of T can be determined according to this preset value and the total number of candidate flows included in the candidate traffic. For example, assume that the total number of candidate flows included in the candidate traffic is T_all, and the preset ratio is P T %, then N CAND =ceil(T_all×P T %), where ceil(T_all×P T %) represents the rounding operation on the result of T_all×P T %. The rounding method can be rounding up, rounding down, or rounding according to the rules of rounding up or down. The embodiments of the present application do not limit this.
[0138] The method of selecting historical data traffic from candidate traffic can also be determined according to the total number of flows included in the candidate traffic and a preset ratio. For example, candidate flows with the same access behavior in candidate traffic A greater than 25% of the total number of flows can be selected. Suppose there are 100 candidate flows with access behavior 1, 120 candidate flows with access behavior 2, 80 candidate flows with access behavior 3, 20 candidate flows with access behavior 4, and 5 candidate flows with access behavior 5 in candidate traffic A. Then it can be determined that the proportion of candidate flows with access behavior 1 in the total candidate flows is 30.8%, the proportion of candidate flows with access behavior 2 in the total candidate flows is 36.9%, the proportion of candidate flows with access behavior 3 in the total candidate flows is 24.6%, the proportion of candidate flows with access behavior 4 in the total candidate flows is 6.1%, and the proportion of candidate flows with access behavior 5 in the total candidate flows is 1.5. Then it can be determined that the candidate flows with access behavior 1 and the candidate flows with access behavior 2 are used as reference flows in reference traffic A.
[0139] 502. Determine the identification information of the terminal device and the identification information of the server for the historical data traffic.
[0140] In other words, the purpose of step 502 is to determine the identity of the identification information in each historical flow in the historical data traffic, that is, whether the IP address, port number, or MAC address, etc. is of the terminal device or the server.
[0141] The identification information of the terminal device can be determined first, and then it can be determined that the other identification information in the data flow is of the server.
[0142] The identification information of the terminal device can be determined in the following three ways:
[0143] Method 1. The traffic in the network collected in step 501 is the uplink traffic collected from the uplink port of the network forwarding device or the terminal device. In this case, it can be determined that the sending end of the uplink traffic is the terminal device and the receiving end is the server.
[0144] Method 2 can be used to count the proportion of each IP address that actively establishes connections. Usually, the number of times a terminal device's IP address actively establishes connections is greater than the number of times the server actively establishes connections. If the proportion of an IP address that actively establishes connections is greater than a preset proportion threshold, then it can be determined that this IP address is the IP address of a terminal device. The proportion of an IP address that actively establishes connections can be judged by counting the sending and receiving of synchronize sequence number (SYN) packets. If an IP address sends a SYN packet, then this IP address is the IP address that actively establishes connections. If the ratio of the number of SYN packets sent by an IP address to the number of SYN packets received by this IP address is greater than the preset proportion threshold, then it can be determined that this IP address is the IP address of a terminal device. After determining the identity of the IP address, the identity of the port number and / or MAC address can be further determined.
[0145] For example, IP 1 sends 9 SYN packets to IP X, and IP X sends 1 SYN packet to IP 1. Then the proportion of SYN packets sent by IP 1 is 90%. Assuming the preset proportion threshold is 80%, then it can be determined that IP 1 is the IP address of a terminal device. Correspondingly, IP X is the IP address of the server.
[0146] Method 3: Count the source IP address and destination IP address of each data stream and determine based on the statistical results. Usually, the number of servers accessed by a terminal device is less than the number of terminal devices accessing a server. For example, usually, an ATM that supports deposit and withdrawal functions may access two servers (a deposit server and a withdrawal server), while an ATM that only supports withdrawal functions may only access the withdrawal server, and there may be thousands of ATMs accessing the withdrawal server. Therefore, an IP address number threshold can be preset. Count the number of different destination IP addresses corresponding to an IP address when it is the source IP address in the historical data stream. If the number of different destination IP addresses corresponding to this IP address is less than the preset IP address number threshold, then this IP address is the IP address of a terminal device; if the number of different IP addresses corresponding to this IP address is greater than or equal to the preset IP address number threshold, then this IP address is the IP address of the server.
[0147] 503. Determine the server set corresponding to each terminal device.
[0148] After determining the identity of the identification information, the server set corresponding to each terminal device can be determined.
[0149] For example, if the servers corresponding to the three historical streams of the terminal device 1 are server 1, server 2, and server 3 respectively, then the server set corresponding to the terminal device 1 includes: server 1, server 2, and server 3. If the servers corresponding to the two historical streams of the terminal device 2 are server 3 and server 4 respectively, then the server set corresponding to the terminal device 2 includes server 3 and server 4.
[0150] 504, cluster the multiple terminal devices according to the multiple server sets to obtain a clustering result.
[0151] The multiple server sets correspond one-to-one with the multiple terminal devices. For example, assume that there are three server sets in total, namely server set 1, server set 2, and server set 3. Server set 1 is the server set corresponding to the terminal device 1, server set 2 is the server set corresponding to the terminal device 2, and server set 3 is the server set corresponding to the terminal device 3. In this case, the terminal devices 1 to 3 can be clustered according to server sets 1 to 3 to obtain a clustering result.
[0152] The clustering algorithm adopted in the embodiments of the present application may be a spectral clustering algorithm.
[0153] Assume that the access matrices of the terminal devices 1 to 3 are shown in Table 2.
[0154] Table 2
[0155]
[0156] As shown in Table 2, the three rows of the access matrix respectively correspond to the terminal devices 1 to 3. For each terminal device among the terminal devices 1 to 3, the value of the element corresponding to the element contained in the server set is 1, otherwise it is 0. For example, the server set corresponding to the terminal device 1 includes server 1, server 2, and server 3. Therefore, in the first row elements of Table 2, the values of the elements corresponding to server 1, server 2, and server 3 are 1, and the values of the elements corresponding to server 4 and server 5 are 0.
[0157] Based on the access matrix shown in Table 2, a similarity matrix can be calculated. The similarity between two terminal devices can be calculated by calculating the vector angle. Assume that IP1 represents the terminal device 1, IP2 represents the terminal device 2, and IP3 represents the terminal device 3. Then, according to the access matrix shown in Table 2, we can obtain: IP1 = (1, 1, 1, 0); IP2 = (1, 1, 1, 0); IP3 = (0, 1, 1, 1). The vector angle between IP1 and IP2 can be determined according to the following formula:
[0158] , (Formula 1)
[0159] wherein is the vector angle between IP1 and IP2 (i.e., the similarity between terminal device 1 and terminal device 2), and |IP| represents the modulus of the vector.
[0160] According to the access matrix and Formula 1, the similarity matrix as shown in Table 3 can be obtained.
[0161] Table 3
[0162]
[0163] The elements in the first row as shown in Table 3 are the similarities between IP1 and IP1, IP1 and IP2, IP1 and IP3 respectively. The elements in the second row are the similarities between IP2 and IP1, IP2 and IP2, IP2 and IP3 respectively. The elements in the third row are the similarities between IP3 and IP1, IP3 and IP2, IP3 and IP3 respectively.
[0164] Through the similarity matrix, the degree matrix can be calculated, that is, the degree matrix is obtained by summing each row of the similarity matrix. Then, according to the degree matrix and the similarity matrix, the Laplacian matrix is determined. The Laplacian matrix can be determined by the following formula:
[0165] L = D - S, (Formula 2)
[0166] where L represents the Laplacian matrix, D represents the degree matrix, and S represents the similarity matrix.
[0167] After obtaining the Laplacian matrix, the Laplacian matrix can be normalized according to the following formula:
[0168] , (Formula 3)
[0169] where L_normal represents the normalized Laplacian matrix, D represents the degree matrix, and L represents the Laplacian matrix.
[0170] After obtaining the normalized Laplacian matrix, the k smallest eigenvalues of the normalized Laplacian matrix can be taken to obtain the corresponding n×k-dimensional eigenvector matrix. Using the K-means algorithm, considering it as n samples (i.e., n terminal devices), each sample has k dimensions, and clustering them into m clusters (C1, C2, … Cm), that is, clustering similar terminal devices together. In addition to the K-means algorithm, other clustering algorithms (such as DBSCAN, etc.) can also be used to cluster terminal devices.
[0171] It can be considered that each terminal device is a vertex in the graph, and the similarity matrix is the adjacency matrix between each vertex. Using the idea of a graph, connected vertices, i.e., similar clusters, are discovered.
[0172] The clustering result may include multiple clusters, each cluster including one or more of the multiple terminal devices, and there is no intersection between any two of the multiple clusters. Still taking the above terminal devices 1 to 3 as an example, the clustering result after clustering may include three clusters, respectively called cluster A, cluster B, and cluster C, where cluster A includes terminal device 1, cluster B includes terminal device 3, and cluster C includes terminal device 2.
[0173] 505. According to the clustering result, determine the terminal type judgment rule.
[0174] Each of the multiple clusters corresponds to a type of terminal device.
[0175] In some embodiments, after obtaining the clustering result, the type of terminal device corresponding to each cluster can be manually determined. In other embodiments, each cluster may include one or more terminal devices that support data fingerprinting and protocol scanning. In this case, the type of terminal device corresponding to each cluster can be determined based on these terminal devices that support data fingerprinting and protocol scanning. Still taking clusters A, B, and C as an example, the type of terminal device corresponding to cluster A is type A, the type of terminal device corresponding to cluster B is type B, and the type of terminal device corresponding to cluster C is type C.
[0176] After determining the type of terminal device corresponding to each cluster, the terminal type judgment rule can be determined according to the access behavior of the terminal devices in each cluster.
[0177] The terminal type judgment rule may include multiple sub-rules, and the multiple sub-rules correspond one-to-one with the types of the multiple terminal devices. As described above, the multiple terminal devices included in the historical data traffic are clustered into multiple clusters, and the multiple clusters correspond one-to-one with the types of the multiple terminal devices. Therefore, the multiple sub-rules also correspond one-to-one with the multiple clusters. Each sub-rule can be determined according to a corresponding cluster and the clusters other than the corresponding cluster.
[0178] Still taking terminals of types A, B, and C as an example, the terminal type judgment rule may include sub-rule A, sub-rule B, and sub-rule C, where sub-rule A corresponds to terminal devices of type A, sub-rule B corresponds to terminal devices of type B, and sub-rule C corresponds to terminal devices of type C.
[0179] Taking sub-rule A as an example below, how to determine the sub-rule is introduced.
[0180] The sub-rule A is determined by the access behavior of the terminal devices in cluster A and the access behavior of the terminal devices in other clusters except cluster A (i.e., cluster B and cluster C) in a set-difference manner. The specific determination method of the terminal type judgment rule is similar to that in the supervised learning-based method, and will not be elaborated here for the sake of brevity.
[0181] In some embodiments, Figure 4 the supervised learning process shown and Figure 5 the unsupervised learning process shown can be implemented by components (such as chips or circuits, etc.) in the network control device or the case control device. In this case, the network control device may further include a rule learning module.
[0182] It can also be implemented by one or more other computer devices. For example, after collecting the historical data traffic, a computer device (such as a server, a workstation) or a cloud service capable of providing supervised learning / unsupervised learning can be used to determine the terminal type judgment rule. Then the determined terminal type judgment rule is sent to the network control device.
[0183] Using the determined terminal type judgment rule, the type of each terminal device in the network can be determined. For example, assume that the terminal type judgment rule is the judgment matrix shown in Table 4.
[0184] Table 4
[0185]
[0186] If a terminal device has the behavior of accessing Server 1, Server 2, and Server 3, then a reference matrix y = [1, 1, 1, 0] can be generated, and [2, 3, 0]' is obtained by matrix multiplication Y×y', where Y represents the judgment matrix and y' represents the transpose matrix of the reference matrix y. Take the position with the largest value in [2, 3, 0] to represent the device type. Here, 3 is the largest, and the position is 2, that is, the second type of device, namely type B.
[0187] Optionally, the access behavior of a terminal device can be counted within an observation period. The observation period can be set as needed. For example, it can be at the granularity of hours (such as 12 hours, 24 hours), or at the granularity of days or weeks. Similarly, the access behavior of the terminal device determined when determining the terminal type judgment rule can also be counted within the observation period.
[0188] Each element in the judgment matrix shown in Table 4 indicates whether a certain type of terminal device has accessed the server. In some other embodiments, the elements in the judgment matrix may also represent the probability that a certain terminal device accesses the server. For example, a statistical period is divided into multiple time windows, and each element in the judgment matrix represents the probability that a certain type of terminal device appears in the multiple time windows. For example, the statistical period is one week, and each time window is 30 minutes, then there are 336 time windows in the entire statistical period. If the terminal devices of type A have accessed server 1 in all 336 time windows, then the value of the element corresponding to type A and server 1 is 1; if the terminal devices of type A have only accessed server 2 in 168 time windows, then the value of the element corresponding to type A and server 2 is 0.5. Assume that Table 5 is the judgment matrix determined according to the access probability.
[0189] Table 5
[0190]
[0191] If a terminal device has accessed server 1, server 2, and server 3 within a time window, then a reference matrix y = [1, 1, 1, 0] can be generated, and [1.5, 2.6, 0]' can be obtained by using matrix multiplication Y×y', where Y represents the judgment matrix and y' represents the transpose matrix of the reference matrix y. Take the position with the largest value in [1.5, 2.6, 0] to represent the device type. Here, 2.6 is the largest, and the position is 2, that is, the second type of device, namely type B.
[0192] In some cases, only some terminal devices in the network can be judged according to the terminal type judgment rules. In other words, it is possible that some terminal devices cannot be judged according to the terminal type judgment rules. For these terminal devices that cannot be judged according to the terminal type judgment rules, an unsupervised learning method can be adopted to cluster these terminal devices to obtain multiple clusters. The multiple clusters correspond one by one to multiple terminal types. Then, the terminal type corresponding to each cluster can be determined manually or by using some terminal devices that support data fingerprint and support protocol scanning.
[0193] Figure 6 It is a schematic flowchart of a method for judging the type of a terminal device according to an embodiment of the present application. Figure 6 The method shown can be executed by a network forwarding device or a network control device.
[0194] 601. Obtain the first data traffic, and the sending end of the first data traffic is the first terminal device.
[0195] 602. Determine the access behavior of the first terminal device according to the identification information of the receiving end of the packets in the first data traffic.
[0196] 603. Determine the type of the first terminal device according to the terminal type judgment rule and the access behavior of the first terminal device, where the terminal type judgment rule indicates the corresponding relationship between the access behavior of the terminal device and the type of the terminal device, and the terminal type judgment rule is obtained by training based on historical data traffic.
[0197] The first data traffic may include the data stream counted within the first time period. Each of the at least one data stream included in the first data traffic has one or more upstream packets, and the sending end of the one or more upstream packets is the first terminal device.
[0198] The historical data traffic is the data stream counted within the second time period, where the end time of the second time period is earlier than the start time of the first time period. In other words, the historical data traffic is the data traffic obtained before the first data traffic is obtained.
[0199] The sending end of the historical data traffic includes multiple types of terminal devices, and the type of the first terminal device is one of the multiple types. The historical data stream includes multiple historical streams, and each of the multiple historical streams includes one or more upstream packets. The sending ends of the upstream packets in the multiple historical streams include multiple terminal devices. Each type of terminal device in the multiple types has at least one corresponding historical stream.
[0200] In some embodiments, the terminal type judgment rule is obtained by training based on the historical data traffic and terminal classification information, where the terminal classification information is used to indicate the multiple types and multiple groups of terminal identification information. Each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal. The terminal classification information is also used to indicate the corresponding relationship between the multiple types and the multiple groups of terminal identification information. The multiple types and the multiple groups of terminal identification information are in one-to-one correspondence. Each terminal identification information in the multiple terminal identification information includes the identification information of at least one terminal device, and the historical data traffic is determined according to the terminal classification information.
[0201] The identification information may include any one or more of the IP address, port number, or MAC address. The terminal identification information may include one or more of the IP address of the terminal device, the port number of the terminal device, or the MAC address of the terminal device. If it is an upstream packet, then the terminal identification information is one or more of the source IP address, source port number, or source MAC address. If it is a downstream packet, then the terminal identification information is one or more of the destination IP address, destination port number, or destination MAC address.
[0202] In some embodiments, the historical data traffic includes a plurality of reference traffic, the plurality of reference traffic corresponds to the plurality of types one by one, the plurality of reference traffic includes a first reference traffic, and the type corresponding to the first reference traffic is the type of the first terminal device; the terminal type determination rule includes a plurality of sub-rules, the plurality of sub-rules corresponds to the plurality of types one by one, and the sub-rule corresponding to the type of the first terminal device among the plurality of sub-rules is determined according to the first reference traffic and the reference traffic other than the first reference traffic among the plurality of reference traffic.
[0203] In some embodiments, the first reference traffic is determined according to a first candidate traffic, the first candidate traffic is the traffic corresponding to the type of the first terminal device among a plurality of candidate traffic, and the number of times the access behavior corresponding to each data stream in the first reference traffic appears in the first candidate traffic is greater than the number of times the access behavior corresponding to the data stream that does not belong to the first reference traffic appears in the first candidate traffic.
[0204] In some embodiments, the terminal type determination rule is determined according to the clustering result obtained by clustering P sets of servers for P terminal devices, the P terminal devices are determined according to the historical data traffic, the P terminal devices correspond to the P sets of servers one by one, each set of servers in the P sets of servers is a set of servers accessed by the corresponding terminal device, the P terminal devices include terminal devices of the plurality of types, and P is a positive integer greater than or equal to the total number of types of terminal devices.
[0205] In some embodiments, the historical data traffic is the uplink data stream of the P terminal devices, and the P terminal devices are the sending ends of the historical data traffic.
[0206] In some embodiments, for each of the P terminal devices, the ratio of the number of times it acts as the sending end of the synchronization message to the number of times it acts as the receiving end of the synchronization message in the historical data traffic is greater than a second preset ratio.
[0207] In some embodiments, the historical data traffic includes P reference traffic, the plurality of reference traffic corresponds to the P terminal devices one by one, the P reference traffic corresponds to P candidate traffic one by one, the number of times the access behavior corresponding to each data stream included in the second reference traffic appears in the corresponding second candidate traffic is greater than the number of times the access behavior corresponding to the data stream that does not belong to the second reference traffic appears in the second candidate traffic, and the second reference traffic is any one of the P reference traffic.
[0208] In some embodiments, the terminal type determination rule is a determination matrix, which includes multiple rows of elements that correspond one-to-one to the multiple types; determining the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device includes: determining, according to the access behavior of the first terminal, a target row in the determination matrix that matches the access behavior of the first terminal device; and determining that the type of the first terminal device is the type corresponding to the target row.
[0209] In some embodiments, determining, according to the access behavior of the first terminal, a target row in the determination matrix that corresponds to the access behavior of the first terminal device includes: determining a reference matrix (such as the reference matrix y in the above embodiments) according to the access behavior of the first terminal, where the values of the multiple elements included in the reference matrix match the access behavior of the first terminal device; multiplying the determination matrix by the reference matrix to obtain a target matrix, where the multiple elements included in the target matrix correspond one-to-one to the multiple rows of elements of the determination rule; and determining the row of elements corresponding to the element with the largest value in the target matrix as the target row.
[0210] Figure 7 is a structural block diagram of a computer device provided according to an embodiment of the present application. As Figure 7 shown, the computer device 700 may be the network control device or the network forwarding device in the above embodiments. As Figure 7 shown, the computer device 700 includes an acquisition unit 701 and a processing unit 702.
[0211] The acquisition unit 701 is configured to acquire a first data traffic, and the sending end of the first data traffic is a first terminal device.
[0212] The processing unit 702 is configured to determine the access behavior of the first terminal device according to the identification information of the receiving end of the packet in the first data traffic.
[0213] The processing unit 702 is further configured to determine the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device, where the terminal type determination rule indicates the correspondence between the access behavior of the terminal device and the type of the terminal device, and the terminal type determination rule is obtained by training based on historical data traffic.
[0214] The acquisition unit 701 may be implemented by a transceiver circuit, and the processing unit 702 may be implemented by a processor. For the specific functions and beneficial effects of the acquisition unit 701 and the processing unit 702, reference may be made to the above embodiments. For the sake of brevity, they will not be elaborated here.
[0215] It should be understood that Figure 7 is only an example and not a limitation. The above computer device including the acquisition unit and the processing unit may not depend onFigure 7 The structure shown.
[0216] When the computer device 700 is a chip, the chip includes an acquisition unit and a processing unit. Among them, the acquisition unit can be an input / output circuit, a communication interface; the processing unit is a processor, a microprocessor or an integrated circuit integrated on the chip.
[0217] An embodiment of the present application also provides a computer device, including a processor and a memory. The processor is used to be coupled with the memory, read and execute instructions and / or program codes in the memory, so as to execute the steps executed by the network control device in the above method embodiment.
[0218] An embodiment of the present application also provides a computer device, including a processor and a memory. The processor is used to be coupled with the memory, read and execute instructions and / or program codes in the memory, so as to execute the learning steps of the terminal type judgment rule in the above method embodiment.
[0219] An embodiment of the present application also provides a computer device, including a processor and a memory. The processor is used to be coupled with the memory, read and execute instructions and / or program codes in the memory, so as to execute the steps executed by the network forwarding device in the above method embodiment.
[0220] It should be understood that the above processor can be a chip. For example, the processor can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processing circuit (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or other integrated chips.
[0221] In the implementation process, the steps of the above method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by a combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.
[0222] It should be noted that the processor in the embodiments of the present application can be an integrated circuit chip with the ability to process signals. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0223] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and directrambus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0224] According to the method provided by the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, when the computer program code runs on a computer, causing the computer to execute each step performed by the network control device in the above embodiments.
[0225] According to the method provided by the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, when the computer program code runs on a computer, causing the computer to execute each step of learning the terminal type judgment rule in the above embodiments.
[0226] According to the method provided by the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, when the computer program code runs on a computer, causing the computer to execute each step performed by the network forwarding device in the above embodiments.
[0227] According to the method provided by the embodiments of the present application, the present application further provides a computer-readable medium, which stores program code. When the program code runs on a computer, it causes the computer to execute each step performed by the network control device in the above embodiments.
[0228] According to the method provided by the embodiments of the present application, the present application further provides a computer-readable medium, which stores program code. When the program code runs on a computer, it causes the computer to execute each step of learning the terminal type judgment rule in the above embodiments.
[0229] According to the method provided by the embodiments of the present application, the present application further provides a computer-readable medium, which stores program code. When the program code runs on a computer, it causes the computer to execute each step performed by the network forwarding device in the above embodiments.
[0230] According to the method provided by the embodiments of the present application, the present application further provides a system, which includes the aforementioned network forwarding device and network control device.
[0231] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0232] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0233] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0234] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0235] In addition, each functional unit in various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0236] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0237] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for determining the type of a terminal device, characterized in that, Including: Obtain a first data traffic, where the sending end of the first data traffic is a first terminal device; Determine the access behavior of the first terminal device according to the identification information of the receiving end of the packets in the first data traffic, where the access behavior of the first terminal device includes the identification information of the server accessed by the first terminal device, and different types of terminal devices access different servers, and the access behavior is used to determine the type of the first terminal device according to the identification information of the server; Determine the type of the first terminal device according to the terminal type judgment rule and the access behavior of the first terminal device, where the terminal type judgment rule is used to indicate the correspondence between the access behavior of the terminal device and the type of the terminal device, and the terminal type judgment rule is obtained by training based on historical data traffic.
2. The method according to claim 1, characterized in that, The sending end of the historical data traffic includes multiple types of terminal devices, and the type of the first terminal device is one of the multiple types.
3. The method according to claim 2, characterized in that, The terminal type judgment rule is obtained by training based on the historical data traffic and terminal classification information, where, The terminal classification information is used to indicate the multiple types and multiple groups of terminal identification information, and each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal device, The terminal classification information is further used to indicate the correspondence between the multiple types and the multiple groups of terminal identification information, and the multiple types and the multiple groups of terminal identification information are in one-to-one correspondence, Each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal device, The historical data traffic is determined according to the terminal classification information.
4. The method according to claim 3, characterized in that, The historical data traffic includes multiple reference flows, the multiple reference flows are in one-to-one correspondence with the multiple types, the multiple reference flows include a first reference flow, and the type corresponding to the first reference flow is the type of the first terminal device; The terminal type judgment rule includes multiple sub-rules, the multiple sub-rules are in one-to-one correspondence with the multiple types, and the sub-rule corresponding to the type of the first terminal device among the multiple sub-rules is determined according to the first reference flow and the reference flows other than the first reference flow among the multiple reference flows.
5. The method according to claim 4, characterized in that, The first reference flow is determined according to a first candidate flow, the first candidate flow is the flow corresponding to the type of the first terminal device among multiple candidate flows, and the number of times the access behavior corresponding to each data stream in the first reference flow appears in the first candidate flow is greater than the number of times the access behavior corresponding to the data stream that does not belong to the first reference flow appears in the first candidate flow.
6. The method according to claim 2, characterized in that, The terminal type determination rule is determined according to the clustering results obtained by clustering P terminal devices based on P server sets. The P terminal devices are determined according to the historical data traffic. The P terminal devices correspond one-to-one with the P server sets. Each server set in the P server sets is a set of servers accessed by the corresponding terminal device. The P terminal devices include the multiple types of terminal devices, and P is a positive integer greater than or equal to the total number of types of terminal devices.
7. The method according to claim 6, characterized in that, The historical data traffic is the upstream data stream of the P terminal devices, and the P terminal devices are the senders of the historical data traffic.
8. The method according to claim 6, characterized in that, For each terminal device in the P terminal devices, the ratio of the number of times it acts as the sender of the synchronization message to the number of times it acts as the receiver of the synchronization message in the historical data traffic is greater than the second preset ratio.
9. The method according to any one of claims 6 to 8, characterized in that, The historical data traffic includes P reference traffic, which correspond one-to-one with the P terminal devices. The P reference traffic correspond one-to-one with P candidate traffic. For each data stream included in the second reference traffic, the number of times the access behavior corresponding to it appears in the corresponding second candidate traffic is greater than the number of times the access behavior corresponding to the data stream not belonging to the second reference traffic appears in the second candidate traffic. The second reference traffic is any one of the P reference traffic.
10. The method according to any one of claims 2 to 8, characterized in that, The terminal type determination rule is a judgment matrix, and the judgment matrix includes multiple rows of elements, which correspond one-to-one with the multiple types. Determining the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device includes: Determining, according to the access behavior of the first terminal device, a target row in the judgment matrix that matches the access behavior of the first terminal device. Determining that the type of the first terminal device is the type corresponding to the target row.
11. The method according to claim 10, characterized in that, Determining, according to the access behavior of the first terminal device, a target row in the judgment matrix that corresponds to the access behavior of the first terminal device includes: Determining a reference matrix according to the access behavior of the first terminal device, where the values of the multiple elements included in the reference matrix match the access behavior of the first terminal device. Multiplying the judgment matrix by the reference matrix to obtain a target matrix, where the multiple elements included in the target matrix correspond one-to-one with the multiple rows of elements of the judgment matrix. Determining the row of elements corresponding to the element with the largest value in the target matrix as the target row.
12. A computer device, characterized in that, Includes: An acquisition unit, configured to acquire first data traffic, where the sender of the first data traffic is a first terminal device. A processing unit, configured to determine the access behavior of the first terminal device according to the identification information of the receiver of the message in the first data traffic, where the access behavior of the first terminal device includes the identification information of the server accessed by the first terminal device. Different types of terminal devices access different servers, and the access behavior is used to determine the type of the first terminal device according to the identification information of the server. The processing unit is further configured to determine the type of the first terminal device according to the terminal type determination rule and the access behavior of the first terminal device, where the terminal type determination rule is used to indicate the correspondence between the access behavior of the terminal device and the type of the terminal device, and the terminal type determination rule is obtained by training based on historical data traffic.
13. The computer device according to claim 12, wherein The sending end of the historical data traffic includes multiple types of terminal devices, and the type of the first terminal device is one of the multiple types.
14. The computer device according to claim 13, wherein The terminal type determination rule is obtained by training based on the historical data traffic and terminal classification information, where the terminal classification information is used to indicate the multiple types and multiple groups of terminal identification information, and each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal device. The terminal classification information is further used to indicate the correspondence between the multiple types and the multiple groups of terminal identification information, and the multiple types and the multiple groups of terminal identification information are in one-to-one correspondence. Each group of terminal identification information in the multiple groups of terminal identification information includes the identification information of at least one terminal device. The historical data traffic is determined according to the terminal classification information.
15. The computer device according to claim 14, wherein The historical data traffic includes multiple reference flows, the multiple reference flows are in one-to-one correspondence with the multiple types, the multiple reference flows include a first reference flow, and the type corresponding to the first reference flow is the type of the first terminal device. The terminal type determination rule includes multiple sub-rules, the multiple sub-rules are in one-to-one correspondence with the multiple types, and the sub-rule corresponding to the type of the first terminal device among the multiple sub-rules is determined according to the first reference flow and the reference flows other than the first reference flow among the multiple reference flows.
16. The computer device according to claim 15, wherein The first reference flow is determined according to a first candidate flow, the first candidate flow is the flow corresponding to the type of the first terminal device among multiple candidate flows, and the number of times the access behavior corresponding to each data stream in the first reference flow appears in the first candidate flow is greater than the number of times the access behavior corresponding to the data stream not belonging to the first reference flow appears in the first candidate flow.
17. The computer device according to claim 13, wherein The terminal type determination rule is determined according to the clustering result obtained by clustering P server sets for P terminal devices, the P terminal devices are determined according to the historical data traffic, the P terminal devices are in one-to-one correspondence with the P server sets, each server set in the P server sets is a set of servers accessed by the corresponding terminal device, the P terminal devices include multiple types of terminal devices, and P is a positive integer greater than or equal to the total number of types of terminal devices.
18. The computer device according to claim 17, wherein The historical data traffic is the uplink data stream of the P terminal devices, and the P terminal devices are the sending end of the historical data traffic.
19. The computer device according to claim 17, wherein The ratio of the number of times each terminal device in the P terminal devices acts as the sending end of the synchronization message to the number of times it acts as the receiving end of the synchronization message in the historical data traffic is greater than a second preset ratio.
20. The computer device according to any one of claims 17 to 19, wherein The historical data traffic includes P reference traffic flows, the P reference traffic flows correspond to the P terminal devices one by one, the P reference traffic flows correspond to P candidate traffic flows one by one, the number of occurrences of the access behavior corresponding to each data stream included in the second reference traffic flow in the corresponding second candidate traffic flow is greater than the number of occurrences of the access behavior corresponding to the data stream not belonging to the second reference traffic flow in the second candidate traffic flow, and the second reference traffic flow is any one of the P reference traffic flows.
21. The computer device according to any one of claims 13 to 19, wherein The terminal type determination rule is a judgment matrix, and the judgment matrix includes multiple rows of elements, and the multiple rows of elements correspond to the multiple types one by one; The processing unit is specifically configured to determine, according to the access behavior of the first terminal device, a target row in the judgment matrix that matches the access behavior of the first terminal device; and determine that the type of the first terminal device is the type corresponding to the target row.
22. The computer device according to claim 21, wherein The processing unit is specifically configured to: Determine a reference matrix according to the access behavior of the first terminal device, where the values of multiple elements included in the reference matrix match the access behavior of the first terminal device; Multiply the judgment matrix by the reference matrix to obtain a target matrix, where the multiple elements included in the target matrix correspond to the multiple rows of elements of the judgment matrix one by one; Determine a row of elements corresponding to the element with the largest value in the target matrix as the target row.
23. A computer device, wherein Comprising: A processor, the processor is used to be coupled with a memory, read and execute instructions and / or program codes in the memory to execute the method according to any one of claims 1 to 11.
24. A chip system, wherein Comprising: Logic circuitry, the logic circuitry is used to be coupled with an input / output interface and transmit data through the input / output interface to execute the method according to any one of claims 1 to 11.
25. A computer-readable storage medium, wherein The computer-readable storage medium stores program codes, and when the program codes run on a computer, the computer is caused to execute the method according to any one of claims 1 to 11.
Citation Information
Patent Citations
Method and system for identifying network device and intelligent terminal
CN106714225A
Method and device for determining device type in target network and electronic device
CN110519106A