IP Address Attribution Query Method, Device, Electronic Device and Storage Medium

The method improves IPv6 IP address geolocation query efficiency by converting IP addresses to binary data and using a trained fuzzy prediction model, addressing database crashes and ensuring fast and accurate geolocation results.

CN115827665BActive Publication Date: 2025-07-15CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211441614.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-17
Publication Date
2025-07-15
Estimated Expiration
2042-11-17

AI Technical Summary

Technical Problem

The existing IP address home query method is inefficient in the query when the database does not have the IP address to be queried, which can easily lead to database crashes and cannot meet the user's needs for quick query.

Method used

The binary data query method based on IPv6 addresses is adopted, combined with the red and black tree storage structure and the fuzzy prediction model, and the fuzzy prediction model is trained through the machine learning model to predict the home information of the IP address.

Benefits of technology

Improve the efficiency and accuracy of IP address home query, prevent database crashes, and ensure the implementation of fast query.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115827665B_ABST
    Figure CN115827665B_ABST
Patent Text Reader

Abstract

The present application provides a method, apparatus, electronic device, and storage medium for querying the IP address location, which relates to the field of communication technologies. The method includes: receiving a target IP address sent by a client, and converting the target IP address into binary data to obtain an IP address to be queried; querying whether the IP address to be queried exists in a pre-established IP database; in the case where the IP address to be queried does not exist, inputting the IP address to be queried into a pre-established fuzzy prediction model for the fuzzy prediction model to make a prediction to obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses stored in the pre-established IP database and the location information corresponding to the existing IP addresses. The above method improves the efficiency of querying the IP address location.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a method, apparatus, electronic device, and storage medium for querying the location of an IP address. Background Art

[0002] The Internet Protocol (IP) is a network layer protocol, and an IP address is an address provided for hosts on the Internet, also known as an Internet protocol address. Common IP addresses are divided into two categories: IPv4 and IPv6. Since the biggest problem with IPv4 is the shortage of network address resources, which severely restricts the application and development of the Internet, IPv6 has become the next-generation IP protocol to replace IPv4.

[0003] Most of the existing methods for querying the location of an IP address are based on IPv4 addresses. Compared with IPv4 addresses with 32 bits in binary form, since IPv6 addresses use 128-bit addresses in binary form, when the number of IPv6 address clusters is small, the existing methods for querying the location of an IP address can achieve the query effect. However, in actual applications, with the growth of the production of smart terminals and the increase in users, the number of IPv6 addresses in the IPv6 address cluster will only become larger and larger. Therefore, the existing methods for querying the location of an IP address have low query efficiency. Especially when the IP address to be queried does not exist in the database, it is easy to cause the database to crash, and then unable to respond to other query instructions normally, and finally unable to meet the user's demand for quick query.

[0004] Therefore, the existing methods for querying the location of an IP address have the technical problem of low query efficiency when the IP address to be queried does not exist in the database. Summary of the Invention

[0005] This application provides a method, apparatus, electronic device, and storage medium for querying the location of an IP address, so as to solve the technical problem of low query efficiency in the prior art when the IP address to be queried does not exist in the database.

[0006] According to the first aspect of this application, a method for querying the location of an IP address is provided, including:

[0007] Receiving a target IP address sent by a client, and converting the target IP address into binary data to obtain an IP address to be queried;

[0008] Querying whether the IP address to be queried exists in a pre-established IP database;

[0009] In the case where the IP address to be queried does not exist, input the IP address to be queried into a pre-established fuzzy prediction model for the fuzzy prediction model to make a prediction and obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses stored in the pre-established IP database and the location information corresponding to the existing IP addresses.

[0010] Optionally, establishing an IP database includes:

[0011] Detect the IP addresses on the target network and obtain the detected IP addresses and the location information corresponding to the detected IP addresses;

[0012] Convert the detected IP addresses into binary data;

[0013] Establish a red-black tree storage structure and write the binary data corresponding to the detected IP addresses and the location information into the red-black tree storage structure correspondingly to obtain the IP database.

[0014] Optionally, querying whether the IP address to be queried exists in the pre-established IP database includes:

[0015] Search from the root node of the IP database in the order from the high-order bit to the low-order bit of the binary data corresponding to the IP address to be queried, and determine the root node as the current node, and repeat the following steps:

[0016] When the current node is not empty, compare the existing IP address stored in the current node with the IP address to be queried;

[0017] If the comparison result is that the existing IP address stored in the current node is greater than the IP address to be queried, then determine the left child node of the current node as the current node;

[0018] If the comparison result is that the existing IP address stored in the current node is less than the IP address to be queried, then determine the right child node of the current node as the current node;

[0019] If the comparison result is that the existing IP address stored in the current node is equal to the IP address to be queried, then the repetition process ends and it is determined that the IP address to be queried exists.

[0020] Optionally, the detecting the IP addresses on the target network includes:

[0021] Probe the IP addresses on the target network through active detection and passive collection methods respectively to obtain the first IP addresses detected actively and the second IP addresses collected passively;

[0022] Deduplicate the first IP addresses detected actively and the second IP addresses collected passively to obtain the detected IP addresses.

[0023] Optionally, establishing the fuzzy prediction model includes:

[0024] Segment the binary data corresponding to each existing IP address stored in the IP database to obtain segmented binary data;

[0025] Divide the existing IP addresses with the same value for each bit in the preset bits within the preset segment stored in the IP database into the same IP address group, and determine the number of the IP address groups and the number of existing IP addresses included in each IP address group;

[0026] Determine the IP address groups with the number of existing IP addresses reaching the preset threshold as the IP address groups to be analyzed;

[0027] For the IP address groups to be analyzed, perform correlation analysis on the location information corresponding to all existing IP addresses included in the IP address groups to be analyzed to obtain a correlation analysis result;

[0028] Train a machine learning model according to the correlation analysis result to obtain the fuzzy prediction model.

[0029] Optionally, the performing correlation analysis on the location information corresponding to all existing IP addresses included in the IP address groups to be analyzed to obtain a correlation analysis result includes:

[0030] Perform normal distribution statistics on the location information corresponding to all existing IP addresses included in the IP address groups to be analyzed to obtain a statistical result, and determine the statistical result as the correlation analysis result.

[0031] Optionally, the IP address location query method further includes:

[0032] In the case where the IP address to be queried exists, extract the location information corresponding to the target IP address from the pre-established IP database.

[0033] According to the second aspect of the present application, there is provided an IP address location query device, including:

[0034] A receiving and conversion module, configured to receive a target IP address sent by a client, and convert the target IP address into binary data to obtain an IP address to be queried;

[0035] A query module, configured to query whether the IP address to be queried exists in a pre-established IP database;

[0036] A prediction module, configured to, when the IP address to be queried does not exist, input the IP address to be queried into a pre-established fuzzy prediction model for the fuzzy prediction model to perform prediction, so as to obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with existing IP addresses in the pre-established IP database and the location information corresponding to the existing IP addresses.

[0037] According to a third aspect of the present application, there is provided an electronic device, including: at least one processor and a memory;

[0038] The memory stores computer-executable instructions;

[0039] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the IP address location query method as described in the first aspect above.

[0040] According to a fourth aspect of the present application, there is provided a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the IP address location query method as described in the first aspect above.

[0041] According to a fifth aspect of the present application, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the IP address location query method as described in the first aspect.

[0042] An IP address location query method provided by the present application includes: receiving a target IP address sent by a client, and converting the target IP address into binary data to obtain an IP address to be queried; querying whether the IP address to be queried exists in a pre-established IP database; when the IP address to be queried does not exist, inputting the IP address to be queried into a pre-established fuzzy prediction model for the fuzzy prediction model to perform prediction, so as to obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with existing IP addresses stored in the pre-established IP database and the location information corresponding to the existing IP addresses.

[0043] The query in this application uses a query based on binary data. Compared with the query methods of other base data, it has the advantage of high query rate caused by easy recognition. And this application takes into account the situation that the IP address to be queried does not exist in the IP database, and provides a fuzzy prediction model obtained by training a machine learning model with the existing IP addresses stored in the pre-established IP database and the corresponding location information of the existing IP addresses, thereby obtaining an accurate prediction result, improving the output rate of the location information, preventing the IP database from crashing, and thus improving the IP address location query efficiency as a whole.

[0044] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of this application, nor is it used to limit the scope of this application. Other features of this application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0046] Figure 1 It is a schematic flowchart of a method for querying the location of an IP address provided by an embodiment of this application;

[0047] Figure 2 It is a schematic flowchart of establishing an IP database provided by an embodiment of this application;

[0048] Figure 3 provided by an embodiment of this application Figure 1 It is a schematic flowchart of S102 in

[0049] Figure 4 It is a schematic flowchart of establishing a fuzzy prediction model provided by an embodiment of this application;

[0050] Figure 5 It is a schematic structural diagram of an IP address location query device provided by an embodiment of this application;

[0051] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of this application.

[0052] Through the above accompanying drawings, the clear embodiments of this application have been shown, and there will be more detailed descriptions later. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application.

[0054] Most of the existing technologies perform queries based on IPv4 addresses. However, when querying IPv4 addresses, the existing IP address location query methods have the defect of low query efficiency. Especially when the IP address to be queried does not exist in the database, it is likely to cause the database to crash, and then unable to respond to other query instructions normally, and ultimately unable to meet the user's need for quick query.

[0055] To solve the above technical problems, the overall inventive concept of the present application is how to provide a method applied to the communication field and improve the query of location information.

[0056] The following uses specific embodiments to detail the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These several specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0057] Figure 1 It is a schematic flowchart of an IP address location query method provided by an embodiment of the present application. As Figure 1 shown, the method of this embodiment includes:

[0058] S101: Receive the target IP address sent by the client, and convert the target IP address into binary data to obtain the IP address to be queried.

[0059] It should be understood that the embodiment of the present application improves the query method based on IPv6 addresses. If it is applied to IPv4 address queries, the same query effect can also be achieved. For ease of understanding, the present application takes the target IP address as an IPv6 address as an example for the following description. The IPv6 address itself is hexadecimal data, but hexadecimal data cannot be directly read by electronic devices. Therefore, the search in hexadecimal data form results in a slow search speed. Based on this, the embodiment of the present application converts the IPv6 address in hexadecimal data form into an IPv6 address in binary data form.

[0060] S102: Query whether the IP address to be queried exists in the pre-established IP database.

[0061] In the embodiments of the present application, the data in the pre-established IP database is stored in binary data, and the storage structure of the IP database in the embodiments of the present application is optimized. For a detailed description, see Embodiment 2 below, and no specific elaboration will be made here. Through the IP database with an optimized storage structure, the embodiments of the present application can improve the storage efficiency and analysis query efficiency of IP addresses, and thus can provide accurate and fast IP address query services for users.

[0062] S103: In the case where there is no IP address to be queried, input the IP address to be queried into the pre-established fuzzy prediction model for the fuzzy prediction model to make a prediction and obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses stored in the pre-established IP database and the location information corresponding to the existing IP addresses.

[0063] The embodiments of the present application do not specifically limit the granularity of the division of the location. It can be national, provincial, municipal, regional, etc. For example: when the division granularity is regional, the location information is C Street, B District, A City.

[0064] Compared with the prior art, in the case of a large number of IPv6 address clusters in the embodiments of the present application, by improving the storage structure of the IP database and the fuzzy prediction model, the IPv6 address can be quickly located, and the efficiency of returning the location information corresponding to the IPv6 address can be improved.

[0065] In a possible implementation manner, the following step S104 is further included, where:

[0066] S104: In the case where there is an IP address to be queried, extract the location information corresponding to the target IP address from the pre-established IP database.

[0067] In the embodiments of the present application, if the IP address to be queried exists in the pre-established IP database, the location information corresponding to the target IP address can be directly output, and there is no need to go through the prediction process again. Due to the storage in binary data form and the optimization of the structure of the IP database, the efficiency of querying the location information can be improved.

[0068] Based on the above embodiments, the technical solution of the present application will be described in more detail below with reference to several specific embodiments.

[0069] Embodiment 2:

[0070] Figure 2 It is a schematic flowchart of the process for establishing an IP database provided by the embodiments of the present application. Before implementing S102 in Embodiment 1, the specific process of establishing the IP database can be described in detail through Embodiment 2. As Figure 2As shown in the figure, the process of establishing an IP database includes the following steps S201 to S203, where:

[0071] S201: Detect the IP addresses on the target network and obtain the detected IP addresses and the corresponding location information of the detected IP addresses.

[0072] It should be understood that in S201, a detection module can be provided, and this detection module is used to start the detection process. Since the detection level affects the accuracy of the fuzzy prediction model, detecting IP addresses is an important task. The detection process in this application is specifically described in the following S2011 to S2012 and will not be elaborated here.

[0073] S202: Convert the detected IP addresses into binary data.

[0074] Since the IPv6 addresses collected by the detection module in S201 are hexadecimal data, according to the characteristics of the eight-segment, four-digit, and hexadecimal of the IPv6 address, first convert the IPv6 address into eight-segment binary data, so as to write it into the corresponding persistent area of the IP address group in the IP database according to the numerical value of each bit in each segment of the binary data in S203. The writing process can refer to the following step S402 and will not be elaborated here.

[0075] Whether querying the location information of the IP address to be queried or storing the existing IP addresses, they are all processed in the form of binary data, so the storage efficiency and query efficiency can be improved.

[0076] S203: Establish a red-black tree storage structure and write the binary data corresponding to the detected IP addresses and the location information into the red-black tree storage structure to obtain an IP database.

[0077] In the embodiment of this application, since the red-black tree storage structure is an efficient and optimized storage structure, the IP database with the red-black tree storage structure as the framework can improve the query efficiency when the user queries the address.

[0078] In a possible implementation manner, in S201, detecting the IP addresses on the target network includes the following steps S2011 to S2012:

[0079] S2011: Detect the IP addresses on the target network through the active detection method and the passive collection method respectively to obtain the first IP addresses detected actively and the second IP addresses collected passively.

[0080] S2012: Remove duplicates from the first IP addresses detected actively and the second IP addresses collected passively to obtain the detected IP addresses.

[0081] When the related technology conducts IPv6 address detection, there is a limitation of limited detection resources. In order to increase the IPv6 address resources, the detection module provided in the embodiments of the present application has two detection methods, which can achieve a large amount of supplement of IP addresses.

[0082] In the embodiments of the present application, IPv6 addresses are scanned and discovered through the active detection method. First, a network probe is provided, and then the network probe is used to detect the resource information (or related information) of the IP address, such as: IPv6 address, corresponding location information, activity, source identifier, identification information, geographical information, etc.

[0083] The above target network may refer to the backbone network provided by the operator. Therefore, S201 is the collection of surviving IPv6 addresses based on the dynamic backbone network. In the embodiments of the present application, IPv6 addresses are scanned and discovered through the passive collection method. First, the detection module starts the passive collection process, and then based on the above backbone network, active IPv6 addresses are discovered, and their corresponding resource information is collected. After that, the active IPv6 address is marked as a seed address, and then the detection of IPv6 addresses continues to support the data collection level through a large amount of data. On this basis, the relevant information of IPv6 addresses can be updated in real time. By executing S2011 - S2012, the embodiments of the present application can collect more IPv6 addresses based on the real-time data on the backbone network provided by the operator, thereby ensuring the resource level.

[0084] Since the collection of IPv6 addresses adopts a combination of active detection and passive collection, passive collection mainly collects the monitoring data periodically pushed by the routing of a certain operator's backbone network to collect each active IPv6 address in the backbone network; while active detection is mainly based on the interaction ability of network devices, sending packets of multiple different protocols to the target device, and analyzing all response packets sent by the target device to determine the resource information of the active IPv6 address. Therefore, the two detection methods provided in the embodiments of the present application can ensure the resource level.

[0085] Figure 3 For the embodiments of the present application Figure 1 is the flowchart of S102. In Figure 1 the illustrated embodiment and Figure 2 the illustrated embodiment, on this basis, this embodiment focuses on Figure 1 refining S102 in Figure 3 As shown, the method of this embodiment includes:

[0086] S301: Starting from the root node of the IP database, search in the order from the high - order bit to the low - order bit of the binary data corresponding to the IP address to be queried, and determine the root node as the current node. Repeat the following steps S302 - S305, where:

[0087] S302: When the current node is not empty, compare the existing IP address stored in the current node with the IP address to be queried.

[0088] In addition, when the current node is empty, the embodiment of the present application returns a null value, that is, it is determined that the IP address to be queried does not exist.

[0089] S303: If the comparison result is that the existing IP address stored in the current node is greater than the IP address to be queried, then determine the left child node of the current node as the current node, and then execute S302.

[0090] S304: If the comparison result is that the existing IP address stored in the current node is less than the IP address to be queried, then determine the right child node of the current node as the current node, and then execute S302.

[0091] S305: If the comparison result is that the existing IP address stored in the current node is equal to the IP address to be queried, then the repetition process ends, and it is determined that the IP address to be queried exists.

[0092] By performing the operations of S301 to S305 above, the present application can quickly query the IP address to be queried.

[0093] In summary, the embodiment of the present application first obtains the IP address to be queried, then converts the IP address to be queried into binary data, and then based on the optimized data storage structure, quickly locates the binary data corresponding to the IP address through the red - black tree and returns the corresponding location information. If the IP address cannot be queried in the IP database, then the corresponding location information can be predicted through the binary data corresponding to the IP address. Therefore, the embodiment of the present application can effectively improve the query efficiency and result output rate.

[0094] Embodiment 3:

[0095] Figure 4 It is a flow chart of establishing a fuzzy prediction model provided by the embodiment of the present application. Before S103 in Embodiment 1 is implemented, the specific process of establishing the fuzzy prediction model can be described in detail through Embodiment 3. As Figure 4 shown, establishing a fuzzy prediction model includes the following steps S401 - S405, where:

[0096] S401: Segment the binary data corresponding to each existing IP address stored in the IP database to obtain the segmented binary data.

[0097] S402: Divide the existing IP addresses stored in the IP database, where the values of each bit in the preset bits within the preset segment are the same, into the same IP address group, and determine the number of IP address groups and the number of existing IP addresses included in each IP address group.

[0098] The above-mentioned same IP address group can be a set of IP addresses under the same network segment. During the execution of S402, according to the number of bits, the existing IP addresses with different values in at least one bit within the preset segment can be divided into different IP address groups. Each segment is 16 bits, and the preset bits within the preset segment can refer to 32 bits in the first 2 segments or 34 bits in the first 3 segments. Further, in the embodiments of the present application, the existing IP addresses belonging to different IP address groups can be written into different persistent regions in the memory. This persistent region can be understood as a certain space in the memory, a table in a database, or a document. For example: when the number of bits is the first 3 bits in the first segment, all existing IP addresses starting with 111 are placed in the first persistent region, all existing IP addresses starting with 110 are placed in the second persistent region, and all existing IP addresses starting with 100 are placed in the third persistent region. The storage of divided regions provides convenience for subsequent correlation analysis.

[0099] S403: Determine the IP address groups to be analyzed as the IP address groups with the number of existing IP addresses reaching the preset threshold.

[0100] Specifically, in the embodiments of the present application, the number of known IP addresses stored in each region every day can be counted. If the number of known IP addresses stored in a certain region reaches the preset threshold, then in the embodiments of the present application, all the known IP addresses stored in this region are subjected to correlation analysis, and then the address attribution distribution rule of this region is obtained to determine the approximate attribution information of the IP addresses in this network segment.

[0101] S404: For the IP address groups to be analyzed, perform correlation analysis on the attribution information corresponding to all the existing IP addresses included in the IP address groups to be analyzed to obtain the correlation analysis result.

[0102] S405: Train a machine learning model according to the correlation analysis result to obtain a fuzzy prediction model.

[0103] The above-mentioned fuzzy prediction model supports the fuzzy speculation function.

[0104] Further, in the embodiments of the present application, the parameters in the fuzzy prediction model need to be updated in a timely manner, and the update process is not introduced in detail in the embodiments of the present application.

[0105] In the embodiments of the present application, by performing correlation analysis on the resource information (including location information) of existing IP addresses in the same network segment, the machine learning model can learn the distribution rule of the existing IP addresses in the network segment in terms of location.

[0106] In a possible implementation manner, in step S404: perform correlation analysis on the location information corresponding to all existing IP addresses included in the IP address group to be analyzed, and obtain a correlation analysis result, including:

[0107] Perform normal distribution statistics on the location information corresponding to all existing IP addresses included in the IP address group to be analyzed, obtain a statistical result, and determine the statistical result as the correlation analysis result.

[0108] During the correlation analysis process, in the embodiments of the present application, the binary data of each known IP address can be first segmented according to the address segment. For example, there are one hundred IP addresses stored in a certain area, and the characteristic is that the data of the first five segments is the same. After the present application obtains the IP address to be queried, based on the data of its first five segments, the approximate location information of the IP address in the corresponding persistent area can be deduced.

[0109] Specifically, after determining the persistent area and the corresponding preset segment, convert the location information corresponding to all IP addresses in the same persistent area through geographical information. The converted data is longitude and latitude coordinates, denoted as x and y respectively. In the embodiments of the present application, the IP address longitude set and the IP address latitude set corresponding to the persistent area can be respectively created, and then the longitude set and the latitude set are respectively input into the model to train the discrete rule of the IP address, so as to infer the approximate range of the longitude and latitude of the IP address to be queried, and further determine the corresponding location information.

[0110] Through the correlation analysis result in the embodiments of the present application, a fuzzy prediction model with higher accuracy can be effectively trained, thereby improving the prediction accuracy and result output rate.

[0111] Embodiment 4:

[0112] Figure 5 It is a schematic structural diagram of an IP address location query device provided by the embodiments of the present application. The device in this embodiment can be in the form of software and / or hardware. As Figure 5 shown, the IP address location query device provided by this embodiment includes: a receiving and conversion module 51, a query module 52, and a prediction module 53. Among them:

[0113] The receiving and conversion module is used to receive the target IP address sent by the client and convert the target IP address into binary data to obtain the IP address to be queried.

[0114] A query module, configured to query whether a to-be-query IP address exists in a pre-established IP database.

[0115] A prediction module, configured to, when the to-be-query IP address does not exist, input the to-be-query IP address into a pre-established fuzzy prediction model for the fuzzy prediction model to perform prediction and obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses in the pre-established IP database and the location information corresponding to the existing IP addresses.

[0116] In a possible implementation, the IP address location query device is further configured to:

[0117] Detect the IP addresses on the target network and obtain the detected IP addresses and the location information corresponding to the detected IP addresses.

[0118] Convert the detected IP addresses into binary data.

[0119] Establish a red-black tree storage structure and write the binary data corresponding to the detected IP addresses and the location information into the red-black tree storage structure correspondingly to obtain the IP database.

[0120] In a possible implementation, the query module is further configured to:

[0121] Search from the root node of the IP database in the order from high to low of the binary data corresponding to the to-be-query IP address, and determine the root node as the current node, and repeatedly execute the following steps:

[0122] When the current node is not empty, compare the existing IP address stored in the current node with the to-be-query IP address.

[0123] If the comparison result is that the existing IP address stored in the current node is greater than the to-be-query IP address, determine the left child node of the current node as the current node.

[0124] If the comparison result is that the existing IP address stored in the current node is less than the to-be-query IP address, determine the right child node of the current node as the current node.

[0125] If the comparison result is that the existing IP address stored in the current node is equal to the to-be-query IP address, end the repeated execution process and determine that the to-be-query IP address exists.

[0126] In a possible implementation, the IP address location query device is further configured to:

[0127] Probe the IP addresses on the target network through active detection and passive collection methods respectively to obtain the first IP addresses detected actively and the second IP addresses collected passively.

[0128] Deduplicate the first IP addresses detected actively and the second IP addresses collected passively to obtain the detected IP addresses.

[0129] In a possible implementation, the IP address location query device is further configured to:

[0130] Segment the binary data corresponding to each existing IP address stored in the IP database to obtain the segmented binary data.

[0131] Divide the existing IP addresses with the same value for each bit in the preset bits within the preset segment stored in the IP database into the same IP address group, and determine the number of IP address groups and the number of existing IP addresses included in each IP address group.

[0132] Determine the IP address groups to be analyzed as the IP address groups with the number of existing IP addresses reaching the preset threshold.

[0133] For the IP address groups to be analyzed, perform correlation analysis on the location information corresponding to all the existing IP addresses included in the IP address groups to be analyzed to obtain the correlation analysis result.

[0134] Train a machine learning model according to the correlation analysis result to obtain a fuzzy prediction model.

[0135] In a possible implementation, the IP address location query device is further configured to:

[0136] Perform normal distribution statistics on the location information corresponding to all the existing IP addresses included in the IP address groups to be analyzed to obtain the statistical result, and determine the statistical result as the correlation analysis result.

[0137] In a possible implementation, the IP address location query device is further configured to:

[0138] In the case of an IP address to be queried, extract the location information corresponding to the target IP address from the pre-established IP database.

[0139] The IP address location query device provided in this embodiment can be used to execute the IP address location query method provided in any of the above method embodiments. The implementation principle and technical effects are similar and will not be elaborated here.

[0140] Another IP address location query device provided by the embodiments of the present application includes a detection module, a data processing module, an IP database, a data analysis module, and a query module, where:

[0141] The detection module is used to detect and collect resource information of IPv6 addresses in the data on the backbone network of the operator.

[0142] The data processing module is used to convert the known IPv6 addresses into binary data, and store the converted IPv6 addresses and the resource information corresponding to the IPv6 addresses into the IP database.

[0143] The data analysis module is used to perform correlation analysis on the IPv6 addresses in the same network segment, and train a model using the correlation analysis results to obtain a fuzzy prediction model, so as to output the predicted location information when the IPv6 address to be queried cannot be found in the IP database.

[0144] The query module is used to search for the IPv6 address to be queried in the IP database.

[0145] In the technical solution of the present application, the processing of the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0146] According to the embodiments of the present application, the present application also provides an electronic device and a readable storage medium.

[0147] Figure 6 It is a schematic structural diagram of an electronic device provided by the embodiments of the present application. The electronic device includes a receiver 60, a transmitter 61, at least one processor 62, and a memory 63. The electronic device composed of the above components can be used to implement the above several specific embodiments of the present application, which will not be elaborated here.

[0148] The embodiments of the present application also provide a computer-readable storage medium. Computer-executable instructions are stored in the computer-readable storage medium. When the processor executes the computer-executable instructions, each step in the method in the above embodiments is implemented.

[0149] The embodiments of the present application also provide a computer program product, including a computer program. When the computer program is executed by the processor, each step in the method in the above embodiments is implemented.

[0150] The various embodiments of the systems and techniques described above in this application can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0151] The program code for implementing the methods of this application can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or electronic device.

[0152] In the context of this application, a computer-readable storage medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can be a machine-readable signal medium or a machine-readable storage medium. A computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a computer-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0153] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0154] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data electronic device), or a computing system that includes middleware components (e.g., an application electronic device), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0155] It should be understood that the various forms of the processes shown above can be reordered, added to, or deleted. For example, the steps recited in the disclosure of this application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution disclosed in this application can be achieved, and this is not limited herein.

[0156] The above specific embodiments do not constitute a limitation on the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this application should be included within the protection scope of this application.

Claims

1. A method for querying the location of an IP address, characterized in that, Including: Receiving a target IP address sent by a client, and converting the target IP address into binary data to obtain an IP address to be queried; Querying whether the IP address to be queried exists in a pre-established IP database; In the case where the IP address to be queried does not exist, inputting the IP address to be queried into a pre-established fuzzy prediction model for the fuzzy prediction model to make a prediction to obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses stored in the pre-established IP database and the location information corresponding to the existing IP addresses; Establishing the fuzzy prediction model includes: Segmenting the binary data corresponding to each existing IP address stored in the IP database to obtain segmented binary data; Dividing the existing IP addresses with the same value for each bit in a preset bit within a preset segment in the IP database into the same IP address group, and determining the number of the IP address groups and the number of existing IP addresses included in each IP address group; Determining the IP address groups with the number of existing IP addresses reaching a preset threshold as the IP address groups to be analyzed; For the IP address groups to be analyzed, performing correlation analysis on the location information corresponding to all the existing IP addresses included in the IP address groups to be analyzed to obtain a correlation analysis result; Training a machine learning model according to the correlation analysis result to obtain the fuzzy prediction model.

2. The method according to claim 1, wherein Establishing an IP database includes: Detecting the IP addresses on a target network, and obtaining the detected IP addresses and the location information corresponding to the detected IP addresses; Converting the detected IP addresses into binary data; Establishing a red-black tree storage structure, and correspondingly writing the binary data corresponding to the detected IP addresses and the location information into the red-black tree storage structure to obtain the IP database.

3. The method according to claim 2, wherein The querying whether the IP address to be queried exists in the pre-established IP database includes: Searching starting from the root node of the IP database in the order from the high bit to the low bit of the binary data corresponding to the IP address to be queried, and determining the root node as the current node, and repeatedly executing the following steps: When the current node is not empty, comparing the existing IP address stored in the current node with the IP address to be queried; If the comparison result is that the existing IP address stored in the current node is greater than the IP address to be queried, determining the left child node of the current node as the current node; If the comparison result is that the existing IP address stored in the current node is less than the IP address to be queried, determining the right child node of the current node as the current node; If the comparison result is that the existing IP address stored in the current node is equal to the IP address to be queried, ending the repeated execution process and determining that the IP address to be queried exists.

4. The method according to claim 2, characterized in that, The detecting the IP addresses on a target network includes: Probe the IP addresses on the target network through active detection and passive collection methods respectively, to obtain the first IP addresses detected actively and the second IP addresses collected passively. Deduplicate the first IP addresses detected actively and the second IP addresses collected passively to obtain the detected IP addresses.

5. The method according to claim 1, characterized in that, Perform correlation analysis on the location information corresponding to all existing IP addresses included in the IP address group to be analyzed, and obtain the correlation analysis results, including: Perform normal distribution statistics on the location information corresponding to all existing IP addresses included in the IP address group to be analyzed, obtain the statistical results, and determine the statistical results as the correlation analysis results.

6. The method according to claim 1, characterized in that, It also includes: In the case where the IP address to be queried exists, extract the location information corresponding to the target IP address from the pre-established IP database.

7. An IP address location query device, characterized in that, It includes: A receiving conversion module, configured to receive the target IP address sent by the client and convert the target IP address into binary data to obtain the IP address to be queried. A query module, configured to query whether the IP address to be queried exists in the pre-established IP database. A prediction module, configured to, in the case where the IP address to be queried does not exist, input the IP address to be queried into the pre-established fuzzy prediction model for the fuzzy prediction model to make a prediction and obtain the location information corresponding to the target IP address; wherein, the fuzzy prediction model is obtained by training a machine learning model with the existing IP addresses in the pre-established IP database and the location information corresponding to the existing IP addresses. Establishing the fuzzy prediction model includes: Segment the binary data corresponding to each existing IP address stored in the IP database to obtain the segmented binary data. Divide the existing IP addresses with the same value for each bit in the preset bits within the preset segment stored in the IP database into the same IP address group, and determine the number of the IP address groups and the number of existing IP addresses included in each IP address group. Determine the IP address groups with the number of existing IP addresses reaching the preset threshold as the IP address groups to be analyzed. For the IP address groups to be analyzed, perform correlation analysis on the location information corresponding to all existing IP addresses included in the IP address groups to be analyzed to obtain the correlation analysis results. Train a machine learning model according to the correlation analysis results to obtain the fuzzy prediction model.

8. An electronic device, characterized in that, It includes: At least one processor and a memory; The memory stores computer execution instructions; The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the IP address location query method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by the processor, they are used to implement the IP address location query method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • IP attribution query method and device, electronic equipment and storage medium

    CN110519408A

  • Method for realizing address code classification by using fuzzy address

    CN110609936A