Method and device for identifying illegal accounts
By obtaining the target information of the optical network unit in the optical access network, determining the optical network unit suspected of instant dialing behavior and verifying the account, the problem of difficult to quickly identify and interfere with the illegal use of instant dialing IP in the prior art is solved, and efficient identification and intervention of illegal account numbers are achieved.
Patent Information
- Application Number
- CN202211281799.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-19
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-10-19
AI Technical Summary
It is difficult for the existing technology to quickly identify and actively interfere with user accounts that use the IP in seconds in violation of regulations, resulting in the inability to effectively prevent the occurrence of online black industries.
By obtaining the target information of multiple optical network units in the optical access network, including the number of terminals, the trustworthiness degree and the location relationship of the terminal, the optical network unit suspected of having a second dialing behavior is determined, and the corresponding target account is determined through the broadband access server to verify to determine whether it is a violation account.
It has realized the large-scale and rapid screening of user accounts that use IP in seconds for illegal use, which has reduced the workload of manual judgment, improved the recognition efficiency, and effectively identified and intervened in violations.
Smart Images

Figure CN115643078B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology. Specifically, it relates to a method and device for identifying illegal accounts. Background Art
[0002] In recent years, "second-dial IP" has been widely used in business scenarios that require a large number of IP resources in a short period of time. Moreover, due to the characteristics of "second-dial IP" such as a large number of IP resources and an expandable geographical coverage of resources, "second-dial IP" has become one of the "infrastructures" for illegal and criminal activities such as online rumors, telecommunications network fraud, and online gambling.
[0003] In response to the problems of "second-dial IP" and similar online black industries, related technologies generally discover them afterwards and take corresponding measures to crack down. However, this passive model of chasing after illegal and criminal activities cannot quickly identify user accounts that illegally use or occupy second-dial IPs, and is even less able to actively intervene in illegal "second-dial IPs".
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of this application provide a method and device for identifying illegal accounts to at least solve the technical problem of effectively identifying user accounts that illegally use second-dial IPs.
[0006] According to one aspect of the embodiments of this application, a method for identifying illegal accounts is provided, including: obtaining target information of multiple optical network units in an optical access network, where the target information at least includes one of the following: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of the terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; determining a target optical network unit from multiple optical network units based on the target information, where the target optical network unit is an optical network unit suspected of having second-dial behavior; determining a target account corresponding to the target optical network unit through a broadband access server; and verifying the target account to determine whether the target account is an illegal account.
[0007] Optionally, obtaining the target information of multiple optical network units in the optical access network includes: remotely logging in to a network device on the optical line terminal side of the optical access network; and obtaining the target information of multiple optical network units corresponding to the optical line terminal through the network device.
[0008] Optionally, the target information includes first information, and the first information includes the first quantity of the first media access control addresses corresponding to the terminals subordinate to each optical network unit; determining the target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, comparing the first quantity of the first media access control addresses corresponding to the terminals subordinate to the optical network unit with a preset first quantity threshold; when the first quantity is not less than the first quantity threshold, determining the optical network unit as the target optical network unit.
[0009] Optionally, the target information includes second information, and the second information includes the first eigenvalue of the first media access control addresses corresponding to the terminals subordinate to each optical network unit, and the first eigenvalue is used to reflect the source of the terminals corresponding to the first media access control addresses; determining the target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, searching for the first eigenvalue of the first media access control addresses corresponding to the terminals subordinate to the optical network unit from a preset list of trusted eigenvalues, where the list of trusted eigenvalues stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first eigenvalue is not found from the list of trusted eigenvalues, determining the optical network unit as the target optical network unit.
[0010] Optionally, the target information includes third information, and the third information includes the second media access control address and the ranging value corresponding to each optical network unit; determining the target optical network unit from multiple optical network units based on the target information includes: determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same location and the second quantity of the multiple optical network units at the same location exceeds a preset second quantity threshold, determining the multiple optical network units at the same location as the target optical network units.
[0011] Optionally, determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit includes: for each optical network unit, using the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determining that at least two optical network units are located at the same location.
[0012] Optionally, verify the target account to determine whether the target account is a violative account, including: performing user identity verification and business purpose verification on the target account; when the target account fails the user identity verification and / or the target account fails the business purpose verification, determining that the target account is a violative account.
[0013] According to another aspect of the embodiments of the present application, there is also provided an identification device for violative accounts, including: an acquisition module, configured to acquire target information of multiple optical network units in an optical access network, where the target information includes at least one of the following: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of the terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; a first determination module, configured to determine a target optical network unit from multiple optical network units based on the target information, where the target optical network unit is an optical network unit suspected of having a second-dial behavior; a second determination module, configured to determine a target account corresponding to the target optical network unit through a broadband access server; and a verification module, configured to verify the target account to determine whether the target account is a violative account.
[0014] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, which includes a stored program. The device where the non-volatile storage medium is located executes the above-mentioned identification method for violative accounts by running this program.
[0015] According to another aspect of the embodiments of the present application, there is also provided an electronic device, which includes: a memory and a processor. The memory stores a computer program, and the processor is configured to execute the above-mentioned identification method for violative accounts through the computer program.
[0016] In the embodiments of the present application, by acquiring target information of multiple optical network units in an optical access network, where the target information includes at least one of the following: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of the terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; determining a target optical network unit from multiple optical network units based on the target information, where the target optical network unit is an optical network unit suspected of having a second-dial behavior; determining a target account corresponding to the target optical network unit through a broadband access server; and verifying the target account to determine whether the target account is a violative account, it is possible to screen user accounts that violate the use of second-dial IPs on a large scale and quickly, greatly reducing the workload of manual judgment, effectively improving the identification efficiency, and thus solving the technical problem of effectively identifying user accounts that violate the use of second-dial IPs. Description of the Drawings
[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0018] Figure 1 It is a flowchart of a method for identifying a violating account according to an embodiment of the present application;
[0019] Figure 2 It is a structural diagram of a device for identifying illegal accounts according to an embodiment of the present application. DETAILED DESCRIPTION
[0020] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0021] It should be noted that the terms "first", "second", etc. in the specification, claims and drawings of the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0022] In order to better understand the embodiments of the present application, some nouns or terms that appear in the description of the embodiments of the present application are first translated and explained as follows:
[0023] Seconds-to-IP: IP is the most basic identity in cyberspace. Every time you disconnect and reconnect to ordinary broadband Internet, you will get a new IP. On this basis, "seconds-to-IP" is a network service application that uses virtualization and cloud computing technologies and a large amount of broadband resources, cloud hosts, and connections such as Remote Desktop Protocol (RDP), Virtual Network Console (VNC) or Secure Shell Protocol (SSH), automatically disconnects and reconnects to broadband and quickly switches IP in seconds.
[0024] ONU (Optical Network Unit): ONUs are divided into active optical network units and passive optical network units. Generally, a device equipped with an optical receiver, an upstream optical transmitter, and a network monitoring system for multiple bridge-connected amplifiers is called an optical node. A passive optical network uses a single optical fiber to connect to the OLT, and then the OLT connects to the ONU. The ONU provides services such as data, interactive network TV, and voice, truly realizing the "triple-play" application.
[0025] OLT (Optical Line Terminal): It refers to the terminal device used to connect to the optical fiber trunk line. As the core component of the optical access network, it is equivalent to a switch or router in a traditional communication network. At the same time, it is also a multi-service providing platform, generally placed at the central office, providing the optical fiber interface of the passive optical network for users. It is connected to the upper-layer network, completing the upstream access of the passive optical network, and connecting to the user-side device through the passive optical network to realize functions such as control, management, and ranging of the user-side device.
[0026] Broadband Remote Access Server (BRAS): A new type of access gateway for broadband network applications. It is located at the edge layer of the backbone network and can complete the data access of the user bandwidth in the IP / ATM network and the wireless broadband data access, realizing broadband Internet access for commercial buildings and residential users in the community, IP VPN services based on IPSec (IP Security Protocol), building an enterprise internal Intranet, supporting applications such as ISPs wholesaling services to users, etc.
[0027] K-means clustering algorithm: It is an iterative clustering mean algorithm. Its main steps are: initially divide the data into k groups, randomly select K objects as the initial clustering centers, then calculate the distance between each object and each seed clustering center, and assign each object to the clustering center closest to it. The clustering centers and the objects assigned to them represent a cluster. When each sample is assigned, the clustering centers of the cluster will be recalculated according to the existing objects in the cluster.
[0028] Example 1
[0029] In recent years, with the development of technology, "instant IP dialing" has been widely used in business scenarios that require a large number of IP resources in a short period of time, such as the black industrial chains of online voting, game cheating, and information theft. However, when dealing with illegal and criminal acts such as "instant IP dialing", relevant technical departments generally adopt a post-strike model. But this method cannot actively intervene in online black production.
[0030] Therefore, how to accurately screen user accounts that illegally use "instant-dial IP" in advance and effectively improve the identification of user accounts that illegally use "instant-dial IP" has become a major problem.
[0031] To solve the above technical problems, the embodiments of the present application provide a method for identifying illegal accounts. The method for identifying illegal accounts obtains target information of multiple optical network units in an optical access network, performs co-location analysis on the optical network units, analyzes the number of terminals subordinate to the optical network units, and verifies the types of terminals subordinate to the optical network units, so as to timely discover illegal accounts involving "instant-dial IP" in the optical access network, thereby realizing large-scale and rapid screening of user accounts that illegally use "instant-dial IP", greatly reducing the workload of manual judgment, and effectively improving the identification efficiency.
[0032] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0033] Figure 1 is a schematic flowchart of an optional method for identifying illegal accounts according to an embodiment of the present application, as Figure 1 shown, the method at least includes steps S102-S108, where:
[0034] Step S102, obtain target information of multiple optical network units in the optical access network, where the target information includes at least one of the following: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between multiple optical network units.
[0035] Among them, the optical network unit can be but not limited to an optical modem.
[0036] Optionally, the target information of multiple optical network units in the optical access network can be obtained in the following manner: first, remotely log in to the network device on the optical line terminal side of the optical access network; then, obtain the target information of multiple optical network units corresponding to the optical line terminal through the network device.
[0037] For example, the network device on the OLT (i.e., optical line terminal) side of the optical access network can be logged in through remote login methods such as Telnet / H, and the MAC addresses corresponding to all optical modems under the network device and the MAC addresses corresponding to multiple terminals such as computers and routers accessed by each optical modem can be obtained.
[0038] Generally, both the Telnet connection protocol and the H connection protocol are connection protocols based on the TCP / IP protocol for connecting to remote computers, used to manage and monitor production servers and enterprise servers. They can also update the server kernel and install the latest software packages and patches. The essential differences between the above two protocols are as follows: Firstly, the forms of transmitted data are different. The transmitted data and passwords of the Telnet connection protocol are in plain text, which is easily attacked during transmission, while the commands of the H connection protocol are encrypted for confidentiality. Secondly, the transmission ports are different. The port for transmitting data of the Telnet connection protocol is 23, while the port for transmitting data of the H connection protocol is 22.
[0039] Specifically, the first information includes the first quantity of the first media access control addresses corresponding to the terminals under each optical network unit, where the above terminals can be computers, routers, etc. accessed by optical network terminals. In the embodiments of the present application, the first information is used for terminal quantity analysis, that is, by judging the size of the first information of the number of terminals under the optical network unit and a preset quantity threshold, it is determined whether the optical network unit is the target optical network unit.
[0040] The second information includes the first eigenvalue of the first media access control addresses corresponding to the terminals under each optical network unit. The first eigenvalue is used to reflect the source of the terminals corresponding to the first media access control addresses, where the above terminals can also be computers, routers, etc. accessed by optical network terminals. In the embodiments of the present application, the second information is used for terminal type verification, that is, by judging whether the second information of the optical network unit can be searched from a preset list of trusted eigenvalue, it is determined whether the optical network unit is the target optical network unit.
[0041] The third information includes the second media access control addresses and ranging values corresponding to each optical network unit. In the embodiments of the present application, the third information is used for ONU co-location analysis, that is, by using the third information to determine multiple optical network units at the same location, and judging the size of the number of multiple optical network units at the same location and a preset quantity threshold, it is determined whether the multiple optical network units at this location are the target optical network units.
[0042] In the embodiments of the present application, the following method can be used to quickly identify the target optical network units suspected of having instant redial behavior from multiple optical network units according to the above three different pieces of information. The specific implementation method for determining the target optical network units is as shown in step S104.
[0043] Step S104, determine the target optical network units from multiple optical network units based on the target information, where the target optical network units are optical network units suspected of having instant redial behavior.
[0044] Optionally, in the embodiments of the present application, the target optical network unit can be determined according to the first information in the following manner: First, for each optical network unit, compare the first quantity of the first media access control addresses corresponding to the terminals subordinate to the optical network unit with a preset first quantity threshold; then, when the first quantity is not less than the first quantity threshold, determine the optical network unit as the target optical network unit.
[0045] For example, when the terminal subordinate to the optical modem is a router, the target optical network unit can be determined through steps S11 - S13, where
[0046] Step S11: Collect the MAC addresses corresponding to the routers connected to all optical modems at the current moment on the OLT side, and record the MAC addresses corresponding to the collected routers in log Log1, as shown in Table 1.
[0047] Table 1
[0048]
[0049]
[0050] Step S12: Organize the log Log1 as input information to obtain the first quantity Num of the MAC addresses corresponding to the routers connected to each optical modem, and store it in list List1, as shown in Table 2.
[0051] Table 2
[0052]
[0053]
[0054] Step S13: Set the first quantity threshold to 4, and compare the first quantity Num of the MAC addresses corresponding to the routers connected to each optical modem with the first quantity threshold. When the first quantity Num is less than the first preset threshold 4, output the optical modem information corresponding to the first quantity Num and store it in list List2; when the first quantity Num is not less than the first preset threshold 4, determine that the optical modem is a suspicious optical modem and store it in list List3.
[0055] Among them, list List2 is used to store the relevant information of multiple routers produced by multiple trusted manufacturers. The relevant information includes the eigenvalue of the MAC address corresponding to the router, while list List3 is used to store the relevant information of all suspicious optical modems.
[0056] Optionally, in the embodiments of the present application, the target optical network unit may be determined according to the first information in the following manner: for each optical network unit, search for the first eigenvalue of the first media access control address corresponding to the terminal under the optical network unit from a preset list of trusted eigenvalue, where the list of trusted eigenvalue stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first eigenvalue is not found in the list of trusted eigenvalue, determine the optical network unit as the target optical network unit.
[0057] For example, when the terminal under the optical modem is a router, the target optical network unit can be determined through steps S21 - S23, where
[0058] Step S21, collect the MAC addresses of the routers connected to all optical modems at the current moment on the OLT side, and record the MAC addresses of the collected routers in the log Log1;
[0059] Step S22, organize the log Log1 as input information to obtain a relationship list List1 of the PVI ports where each optical modem is located and the MAC addresses of the routers connected to the optical modems. For each router MAC address, there is a fixed eigenvalue used to represent the source of the router to which the MAC address belongs;
[0060] Step S23, obtain the first eigenvalue of each router MAC address connected to the optical modem in the relationship list List1, and search for the first eigenvalue from the list List2 of the MAC address eigenvalues of the preset trusted routers. Each router produced by each trusted manufacturer has a fixed eigenvalue for the corresponding MAC address, and through this eigenvalue, it can be determined whether the MAC address is a trusted MAC address. If the first eigenvalue is not found in the list List2 of the MAC address eigenvalues of the trusted routers, determine that the optical modem is a suspicious optical modem.
[0061] As an optional implementation manner, after obtaining the first eigenvalue of each router MAC address connected to the optical modem in the relationship list List1, it can also be determined whether the optical modem is a suspicious optical modem through a preset blacklist of the eigenvalues of illegal routers. The blacklist of the eigenvalues of illegal routers stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple illegal manufacturers. If the first eigenvalue is found in the blacklist of the eigenvalues of the preset illegal terminals, determine that the optical modem is a suspicious optical modem.
[0062] Optionally, in the embodiments of the present application, the target optical network unit may be determined based on the first information in the following manner: determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same location and the second quantity of the multiple optical network units at the same location exceeds a preset second quantity threshold, determining the multiple optical network units at the same location as the target optical network unit.
[0063] Optionally, for each optical network unit, taking the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit, mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set, and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determining that at least two optical network units are at the same location.
[0064] For example, multiple target optical network units at the same location are determined through steps S31 - S34, where
[0065] Step S31, collecting the MAC addresses of all optical modems at the current moment on the OLT side, denoted as m, and the ranging values corresponding to the MAC addresses, denoted as n, and taking the MAC addresses m of all optical modems and the corresponding ranging values n as elements of a third information sequence, then the third information sequence can be expressed as:
[0066] Step S32, mapping the above third information sequence onto a two-dimensional plane coordinate system, then the coordinates (m i , n i ) of each optical modem can be found on the two-dimensional plane coordinate system;
[0067] Step S33, using the K - mean clustering algorithm to divide all optical modems in the two-dimensional plane coordinate system into multiple optical modem sets, and determining the center point of each optical modem set and the first distance between all optical modems in each optical modem set and the center point according to the coordinates of the multiple optical modems in each optical modem set. When there are at least two optical modems in the optical modem set whose first distance from the center point is not greater than a preset distance threshold, it is determined that at least two optical network units are at the same location;
[0068] Step S34, if the second quantity of the optical modems at the same location exceeds a preset second quantity threshold of 3, determining that the optical modems with the second quantity at the same location are all suspicious optical modems, and storing these optical modems in the list List4.
[0069] It should be noted that the size of the first quantity threshold and the second quantity threshold, as well as the list of credible feature values can be determined according to the use requirements and actual conditions, and no further restrictions are given here. The conventional values listed in the embodiments of the present application are taken for the purpose of explaining the algorithm in detail, and are not used as judgment criteria in actual use.
[0070] In actual application, the above three different methods can be applied separately or in combination to achieve the purpose of improving recognition efficiency.
[0071] Taking the combination of the three methods as an example, multiple suspicious optical modems at the same location can be determined through steps S31-S34, and all suspicious optical modems are stored in suspicious list A; the optical modem information in suspicious list A is passed through steps S11-S13 to determine the comparison result of the first number of MAC addresses corresponding to the terminals under the optical modem and the first number threshold, and suspicious list B is obtained according to the comparison result; the optical modem information in suspicious list A is passed through steps S21-S23 to determine the matching result of the preset trusted feature value list and the feature value of the MAC address corresponding to the terminal under the optical modem, and suspicious list C is obtained according to the matching result, wherein suspicious list B and suspicious list C are both suspicious lists with higher accuracy; the finally determined suspicious list is the intersection of suspicious list B and suspicious list C.
[0072] Step S106: determining a target account corresponding to the target optical network unit through the broadband access server.
[0073] For example, the user accounts corresponding to all optical modems in List 3 and List 4 may be determined through the broadband access server.
[0074] Step S108: verify the target account to determine whether the target account is an illegal account.
[0075] Optionally, whether the target account is a violating account can be determined by the following method: first, user identity authentication and business purpose verification are performed on the target account; when the target account fails user identity authentication and / or the target account fails business purpose verification, the target account is determined to be a violating account.
[0076] In an embodiment of the present application, target information of multiple optical network units in an optical access network is obtained, wherein the target information includes at least one of the following: first information for reflecting the number of terminals under each optical network unit, second information for reflecting the degree of credibility of the terminals under each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; a target optical network unit is determined from multiple optical network units based on the target information, wherein the target optical network unit is an optical network unit suspected of having second dialing behavior; a target account corresponding to the target optical network unit is determined through a broadband access server; and the target account is verified to determine whether the target account is an illegal account, thereby achieving large-scale and rapid screening of user accounts that illegally use second dialing IPs, greatly reducing the workload of manual judgment, effectively improving recognition efficiency, and thus solving the technical problem of effectively identifying user accounts that illegally use second dialing IPs.
[0077] Example 2
[0078] According to an embodiment of the present application, a device for identifying a violating account for implementing the method for identifying a violating account in Embodiment 1 is also provided. Figure 2 As shown, the device for identifying the illegal account at least includes an acquisition module 21, a first determination module 22, a second determination module 23 and a verification module 24, wherein:
[0079] The acquisition module 21 is used to acquire target information of multiple optical network units in the optical access network, wherein the target information includes at least one of the following: first information used to reflect the number of terminals under each optical network unit, second information used to reflect the credibility of the terminals under each optical network unit, and third information used to reflect the positional relationship between multiple optical network units.
[0080] The optical network unit may be, but is not limited to, an optical modem.
[0081] Optionally, the target information of multiple optical network units in the optical access network can be obtained in the following manner: first remotely log in to the network device on the optical line terminal side of the optical access network; then obtain the target information of multiple optical network units corresponding to the optical line terminal through the network device.
[0082] For example, you can log in to the network device on the OLT (optical line terminal) side of the optical access network through remote login methods such as Telnet / H, and obtain the MAC addresses corresponding to all optical modems under the network device and the corresponding MAC addresses of multiple terminals such as computers and routers connected to each optical modem.
[0083] Generally, both the Telnet connection protocol and the H connection protocol are connection protocols based on the TCP / IP protocol for connecting to remote computers, used to manage and monitor production servers and enterprise servers. They can also update the server kernel and install the latest software packages and patches. The essential differences between the above two protocols are as follows: First, the forms of transmitted data are different. The transmitted data and passwords of the Telnet connection protocol are in plain text, which is vulnerable to attacks during transmission, while the commands of the H connection protocol are encrypted for confidentiality. Second, the transmission ports are different. The port for transmitting data of the Telnet connection protocol is 23, while the port for transmitting data of the H connection protocol is 22.
[0084] Specifically, the first information includes the first quantity of the first media access control addresses corresponding to the terminals under each optical network unit, where the above terminals can be computers, routers, etc. accessed by optical network terminals. In the embodiment of the present application, the first information is used for terminal quantity analysis, that is, by judging the size of the first information of the number of terminals under the optical network unit and a preset quantity threshold, it is determined whether the optical network unit is the target optical network unit.
[0085] The second information includes the first characteristic value of the first media access control addresses corresponding to the terminals under each optical network unit. The first characteristic value is used to reflect the source of the terminals corresponding to the first media access control addresses, where the above terminals can also be computers, routers, etc. accessed by optical network terminals. In the embodiment of the present application, the second information is used for terminal type verification, that is, by judging whether the second information of the optical network unit can be searched from a preset list of trusted characteristic values, it is determined whether the optical network unit is the target optical network unit.
[0086] The third information includes the second media access control addresses and ranging values corresponding to each optical network unit. In the embodiment of the present application, the third information is used for ONU co-location analysis, that is, by using the third information to determine multiple optical network units at the same location, and judging the size of the number of multiple optical network units at the same location and a preset quantity threshold, it is determined whether the multiple optical network units at the same location are the target optical network units.
[0087] In the embodiment of the present application, the following method can be used to quickly identify the target optical network units suspected of having the behavior of rapid disconnection and reconnection from multiple optical network units based on the above three different pieces of information. Specifically, the first determination module 22 can be used to determine the target optical network units.
[0088] The first determination module 22 is used to determine the target optical network units from multiple optical network units based on the target information, where the target optical network units are optical network units suspected of having the behavior of rapid disconnection and reconnection.
[0089] Optionally, in the embodiments of the present application, the target optical network unit may be determined by the first determination module 22 according to the first information: First, for each optical network unit, compare the first quantity of the first media access control addresses corresponding to the terminals subordinate to the optical network unit with a preset first quantity threshold; then, when the first quantity is not less than the first quantity threshold, determine the optical network unit as the target optical network unit.
[0090] Optionally, in the embodiments of the present application, the target optical network unit may be determined by the first determination module 22 according to the second information: For each optical network unit, search for the first eigenvalue of the first media access control address corresponding to the terminals subordinate to the optical network unit from a preset list of trusted eigenvalue, where the list of trusted eigenvalue stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first eigenvalue is not found in the list of trusted eigenvalue, determine the optical network unit as the target optical network unit.
[0091] As an optional implementation manner, after obtaining the first eigenvalue of the first media access control address corresponding to the terminals subordinate to the optical network unit, it is also possible to determine whether the optical modem is a suspicious optical modem by using a blacklist of eigenvalues of illegal terminals. The blacklist of eigenvalues of illegal terminals stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple illegal manufacturers. If the first eigenvalue is found in the preset blacklist of eigenvalues of illegal terminals, determine that the optical modem is a suspicious optical modem.
[0092] Optionally, in the embodiments of the present application, the target optical network unit may be determined by the first determination module 22 according to the third information: Determine the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same location and the second quantity of the multiple optical network units at the same location exceeds a preset second quantity threshold, determine the multiple optical network units at the same location as the target optical network units.
[0093] Optionally, for each optical network unit, use the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit, and map the optical network unit to a two-dimensional plane; use a clustering algorithm to divide multiple optical network units into multiple optical network unit sets; for each optical network unit set, determine the center point of the multiple optical network units in the optical network unit set, and determine the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determine that at least two optical network units are located at the same location.
[0094] It should be noted that the size of the first quantity threshold and the second quantity threshold, as well as the list of credible feature values can be determined according to the use requirements and actual conditions, and no limitation is given here. The examples in the present application are examples of obtaining conventional values for explaining the algorithm in detail, and are not used as judgment criteria in actual use.
[0095] In actual application, the above three different information can be applied separately or in combination to achieve the purpose of improving recognition efficiency.
[0096] The second determining module 23 is used to determine the target account corresponding to the target optical network unit through the broadband access server.
[0097] The verification module 24 is used to verify the target account to determine whether the target account is an illegal account.
[0098] Optionally, the verification module 24 can be used to determine whether the target account is a violating account: first, user identity authentication and business purpose verification are performed on the target account; when the target account fails user identity authentication and / or the target account fails business purpose verification, the target account is determined to be a violating account.
[0099] It should be noted that each module in the device for identifying illegal accounts in the embodiment of the present application corresponds one by one to each implementation step of the method for identifying illegal accounts in Example 1. Since a detailed description has been given in Example 1, some details not reflected in this embodiment can be referred to Example 1 and will not be repeated here.
[0100] Example 3
[0101] According to an embodiment of the present application, a non-volatile storage medium is also provided, which includes a stored program, wherein the device where the non-volatile storage medium is located executes the method for identifying illegal accounts in Example 1 by running the program.
[0102] Specifically, the device where the non-volatile storage medium is located implements the following steps by running the program: obtaining target information of multiple optical network units in the optical access network, wherein the target information includes at least one of the following: first information used to reflect the number of terminals under each optical network unit, second information used to reflect the degree of credibility of the terminals under each optical network unit, and third information used to reflect the positional relationship between multiple optical network units; determining a target optical network unit from multiple optical network units based on the target information, wherein the target optical network unit is an optical network unit suspected of having second dialing behavior; determining a target account corresponding to the target optical network unit through a broadband access server; and verifying the target account to determine whether the target account is an illegal account.
[0103] Optionally, obtain the target information of multiple optical network units in the optical access network, including: remotely logging in to the network device on the optical line terminal side in the optical access network; obtaining the target information of multiple optical network units corresponding to the optical line terminal through the network device.
[0104] Optionally, the target information includes first information, and the first information includes the first quantity of the first media access control addresses corresponding to the terminals under each optical network unit; determining the target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, comparing the first quantity of the first media access control addresses corresponding to the terminals under the optical network unit with a preset first quantity threshold; when the first quantity is not less than the first quantity threshold, determining the optical network unit as the target optical network unit.
[0105] Optionally, the target information includes second information, and the second information includes the first eigenvalue of the first media access control addresses corresponding to the terminals under each optical network unit, and the first eigenvalue is used to reflect the source of the terminals corresponding to the first media access control addresses; determining the target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, searching for the first eigenvalue of the first media access control addresses corresponding to the terminals under the optical network unit from a preset list of trusted eigenvalues, where the list of trusted eigenvalues stores the eigenvalues of the media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first eigenvalue is not found in the list of trusted eigenvalues, determining the optical network unit as the target optical network unit.
[0106] Optionally, the target information includes third information, and the third information includes the second media access control address and the ranging value corresponding to each optical network unit; determining the target optical network unit from multiple optical network units based on the target information includes: determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same location and the second quantity of the multiple optical network units at the same location exceeds a preset second quantity threshold, determining the multiple optical network units at the same location as the target optical network units.
[0107] Optionally, determining the positional relationship between multiple optical network units based on the second media access control address and ranging value corresponding to each optical network unit includes: for each optical network unit, using the second media access control address and ranging value corresponding to the optical network unit as the coordinates of the optical network unit, and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide the multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set, and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distances from the center point are not greater than a preset distance threshold, determining that the at least two optical network units are located at the same position.
[0108] Embodiment 4
[0109] According to an embodiment of the present application, a processor is further provided, and the processor is used to run a program, wherein when the program runs, it executes the method for identifying a violating account in Embodiment 1.
[0110] Specifically, when the program runs, it executes the following steps: obtaining target information of multiple optical network units in an optical access network, where the target information includes at least one of the following: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of the terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; determining a target optical network unit from the multiple optical network units based on the target information, where the target optical network unit is an optical network unit suspected of having a second-dial behavior; determining a target account corresponding to the target optical network unit through a broadband access server; verifying the target account to determine whether the target account is a violating account.
[0111] Optionally, obtaining the target information of multiple optical network units in the optical access network includes: remotely logging in to the network device on the optical line terminal side in the optical access network; obtaining the target information of the multiple optical network units corresponding to the optical line terminal through the network device.
[0112] Optionally, the target information includes first information, and the first information includes the first quantity of the first media access control addresses corresponding to the terminals subordinate to each optical network unit; determining a target optical network unit from the multiple optical network units based on the target information includes: for each optical network unit, comparing the first quantity of the first media access control addresses corresponding to the terminals subordinate to the optical network unit with a preset first quantity threshold; when the first quantity is not less than the first quantity threshold, determining that the optical network unit is a target optical network unit.
[0113] Optionally, the target information includes second information, and the second information includes first eigenvalue of the first media access control address corresponding to the terminal under each optical network unit. The first eigenvalue is used to reflect the source of the terminal corresponding to the first media access control address. Determining a target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, searching for the first eigenvalue of the first media access control address corresponding to the terminal under the optical network unit from a preset list of trusted eigenvalues, where the list of trusted eigenvalues stores eigenvalues of media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first eigenvalue is not found in the list of trusted eigenvalues, determining the optical network unit as the target optical network unit.
[0114] Optionally, the target information includes third information, and the third information includes the second media access control address and the ranging value corresponding to each optical network unit. Determining a target optical network unit from multiple optical network units based on the target information includes: determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same location and the second quantity of the multiple optical network units at the same location exceeds a preset second quantity threshold, determining the multiple optical network units at the same location as the target optical network units.
[0115] Optionally, determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit includes: for each optical network unit, using the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determining that at least two optical network units are at the same location.
[0116] Embodiment 5
[0117] According to an embodiment of the present application, an electronic device is further provided. The electronic device includes: a memory and a processor. The memory stores a computer program, and the processor is configured to execute the method for identifying a violated account in Embodiment 1 through the computer program.
[0118] Specifically, the processor is configured to execute the following steps through a computer program: obtaining target information of multiple optical network units in an optical access network, wherein the target information includes at least one of the following: first information for reflecting the number of terminals under each optical network unit, second information for reflecting the degree of credibility of the terminals under each optical network unit, and third information for reflecting the positional relationship between multiple optical network units; determining a target optical network unit from multiple optical network units based on the target information, wherein the target optical network unit is an optical network unit suspected of having second dialing behavior; determining a target account corresponding to the target optical network unit through a broadband access server; and verifying the target account to determine whether the target account is an illegal account.
[0119] Optionally, obtaining target information of multiple optical network units in the optical access network includes: remotely logging into a network device at an optical line terminal side in the optical access network; and obtaining target information of multiple optical network units corresponding to the optical line terminal through the network device.
[0120] Optionally, the target information includes first information, the first information including a first number of first media access control addresses corresponding to terminals under each optical network unit; determining the target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, comparing the first number of first media access control addresses corresponding to terminals under the optical network unit with a preset first number threshold; when the first number is not less than the first number threshold, determining that the optical network unit is a target optical network unit.
[0121] Optionally, the target information includes second information, the second information including a first characteristic value of a first media access control address corresponding to a terminal under each optical network unit, the first characteristic value being used to reflect a source of the terminal corresponding to the first media access control address; determining a target optical network unit from multiple optical network units based on the target information includes: for each optical network unit, searching a preset trusted characteristic value list for the first characteristic value of the first media access control address corresponding to the terminal under the optical network unit, wherein the trusted characteristic value list stores characteristic values of media access control addresses corresponding to multiple terminals produced by multiple trusted manufacturers; when the first characteristic value is not found in the trusted characteristic value list, determining the optical network unit as a target optical network unit.
[0122] Optionally, the target information includes third information, and the third information includes the second media access control address and the ranging value corresponding to each optical network unit; determining a target optical network unit from multiple optical network units based on the target information includes: determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit; if there are multiple optical network units at the same position and the second quantity of the multiple optical network units at the same position exceeds a preset second quantity threshold, determining the multiple optical network units at the same position as the target optical network unit.
[0123] Optionally, determining the positional relationship between multiple optical network units based on the second media access control address and the ranging value corresponding to each optical network unit includes: for each optical network unit, using the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit, and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set, and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determining that at least two optical network units are at the same position.
[0124] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments.
[0125] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0126] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0127] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0128] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0129] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0130] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for identifying a violating account, characterized in that, Including: Obtaining target information of multiple optical network units in an optical access network, where the target information at least includes: first information for reflecting the number of terminals subordinate to each optical network unit, second information for reflecting the trustworthiness of the terminals subordinate to each optical network unit, and third information for reflecting the positional relationship between the multiple optical network units; Determining a target optical network unit from the multiple optical network units based on the target information, where the target optical network unit is an optical network unit suspected of having a second-dial behavior; Determining a target account corresponding to the target optical network unit through a broadband access server; Verifying the target account to determine whether the target account is a violative account; Wherein, the third information includes the second media access control address and ranging value corresponding to each optical network unit, and the process of determining the positional relationship between the multiple optical network units includes: for each optical network unit, using the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit, and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide the multiple optical network units into multiple optical network unit sets; for each optical network unit set, determining the center point of the multiple optical network units in the optical network unit set, and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set whose first distance from the center point is not greater than a preset distance threshold, determining that the at least two optical network units are located at the same position.
2. The method according to claim 1, wherein Obtaining target information of multiple optical network units in an optical access network includes: Remotely logging in to the network device on the optical line terminal side in the optical access network; Obtaining the target information of the multiple optical network units corresponding to the optical line terminal through the network device.
3. The method according to claim 1, wherein The first information includes the first quantity of the first media access control addresses corresponding to the terminals subordinate to each optical network unit; Determining a target optical network unit from the multiple optical network units based on the target information includes: For each optical network unit, comparing the first quantity of the first media access control addresses corresponding to the terminals subordinate to the optical network unit with a preset first quantity threshold; When the first quantity is not less than the first quantity threshold, determining the optical network unit as the target optical network unit.
4. The method according to claim 1, wherein The second information includes the first eigenvalue of the first media access control addresses corresponding to the terminals subordinate to each optical network unit, and the first eigenvalue is used to reflect the source of the terminals corresponding to the first media access control addresses; Determining a target optical network unit from the multiple optical network units based on the target information includes: For each optical network unit, searching a preset trusted feature value list for a first feature value of the first media access control address corresponding to a terminal under the optical network unit, wherein the trusted feature value list stores feature values of media access control addresses corresponding to a plurality of terminals produced by a plurality of trusted manufacturers; When the first characteristic value is not found in the trusted characteristic value list, the optical network unit is determined to be the target optical network unit.
5. The method according to claim 1, characterized in that Determining a target optical network unit from the multiple optical network units based on the target information includes: If there are multiple optical network units at the same location, and a second number of the multiple optical network units at the same location exceeds a preset second number threshold, the multiple optical network units at the same location are determined to be the target optical network units.
6. The method according to claim 1, characterized in that, Verifying the target account to determine whether the target account is an illegal account includes: Performing user identity verification and business purpose verification on the target account; When the target account fails to pass the user identity verification and / or the target account fails to pass the business purpose verification, the target account is determined to be an illegal account.
7. A device for identifying illegal accounts, characterized in that: include: An acquisition module is used to acquire target information of multiple optical network units in an optical access network, wherein the target information at least includes: first information for reflecting the number of terminals under each optical network unit, second information for reflecting the degree of trustworthiness of the terminals under each optical network unit, and third information for reflecting the positional relationship between the multiple optical network units, wherein the third information includes a second media access control address and a ranging value corresponding to each optical network unit, and a process for determining the positional relationship between the multiple optical network units includes: for each optical network unit, using the second media access control address and the ranging value corresponding to the optical network unit as the coordinates of the optical network unit, and mapping the optical network unit to a two-dimensional plane; using a clustering algorithm to divide the multiple optical network units into multiple optical network unit sets; for each of the optical network unit sets, determining the center point of the multiple optical network units in the optical network unit set, and determining the first distance between each optical network unit in the optical network unit set and the center point; if there are at least two optical network units in the optical network unit set and the first distance between the center point is not greater than a preset distance threshold, determining that the at least two optical network units are located at the same position; A first determining module is used to determine a target optical network unit from the multiple optical network units based on the target information, wherein the target optical network unit is an optical network unit suspected of having a second dialing behavior; A second determination module, configured to determine a target account corresponding to the target optical network unit through a broadband access server; The verification module is used to verify the target account to determine whether the target account is an illegal account.
8. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, wherein the device where the non-volatile storage medium is located executes the method for identifying a violating account according to any one of claims 1 to 6 by running the program.
9. An electronic device, characterized in that, Comprising: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the method for identifying a violating account according to any one of claims 1 to 6 through the computer program.
Citation Information
Patent Citations
Method and system for controlling user access
CN112134828A
PCDN violation service detection method and device, electronic equipment and storage medium
CN114389977A