A network equipment security detection method, system, equipment and medium

By monitoring and analyzing the infrasonic wave characteristic information of network equipment, and using the detection algorithm library to identify and mark eavesdropping devices, the insufficient detection of infrasonic wave eavesdropping attacks in the prior art is solved, and efficient and accurate security detection and prevention are achieved.

CN115955339BActive Publication Date: 2025-08-08BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211602887.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-13
Publication Date
2025-08-08
Estimated Expiration
2042-12-13

AI Technical Summary

Technical Problem

Existing security detection technologies lack detection methods for the use of infrasonic waves to carry out cyber attacks such as eavesdropping, and cannot effectively identify and prevent such attacks.

Method used

By monitoring the infrasound waves generated by network equipment in the target physical area, obtaining the sound wave characteristic information, using the preset detection algorithm library for feature extraction and calculation, determining whether the sound wave contains the preset target information, and marking it as the target device, issuing early warning information.

Benefits of technology

It realizes effective detection of whether network equipment in the target physical area uses infrasonic waves to perform eavesdropping attacks, improves detection accuracy and efficiency, helps to formulate targeted prevention strategies, and reduces the cost of manual investigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115955339B_ABST
    Figure CN115955339B_ABST
Patent Text Reader

Abstract

The present invention relates to a network device security detection method, system, device, and medium, comprising: monitoring the sound waves generated by a number of network devices within a target physical area; upon detecting infrasound waves emitted by any network device, obtaining acoustic wave signature information of the infrasound waves; and determining whether the acoustic wave signature information contains preset target information. If so, marking the network device corresponding to the acoustic wave information as a target device. The present invention can effectively detect whether network devices within the target physical area are using infrasound waves to carry out eavesdropping attacks, helping to more comprehensively defend against network attacks that maliciously steal data and information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a network device security detection method, system, device and medium. Background Art

[0002] Network equipment refers to the components of network environments such as the Internet and local area networks, including servers, printers, and routers. Network device security is crucial for government agencies, research institutes, businesses, and individuals. Therefore, network equipment, especially those used in sensitive areas, must be tested. However, as external intrusion patterns continue to evolve, detection methods must also be continuously adjusted and updated. Infrasound refers to sound waves with a frequency below 20Hz. It is not easily attenuated or absorbed, and can diffract around certain large obstacles. Therefore, it has become a data and information transmission medium for eavesdropping and other cyberattacks. However, existing security detection technologies lack the means to detect cyberattacks such as eavesdropping using infrasound. Summary of the Invention

[0003] In view of this, the present invention provides a network device security detection method, system, device and medium, which monitor and calculate the infrasound waves generated by network devices in a target physical area, and ultimately determine whether there is a security risk that the network devices in the target physical area will eavesdrop on data information through infrasound waves, at least partially solving the problems existing in the prior art.

[0004] The specific content of the invention is as follows:

[0005] A network device security detection method, comprising:

[0006] The acoustic waves generated by several network devices within the target physical area are monitored.

[0007] When infrasound waves emitted by any network device are monitored, acoustic wave characteristic information of the infrasound waves is obtained.

[0008] Determine whether the sound wave characteristic information contains preset target information, and if so, mark the network device corresponding to the sound wave information as a target device.

[0009] Furthermore, after obtaining the acoustic wave characteristic information of the infrasound wave, the method further includes:

[0010] The acoustic wave characteristic information is feature extracted according to a plurality of preset acoustic wave attributes to obtain a feature data set corresponding to the acoustic wave characteristic information; the feature data set includes a feature data group corresponding to each acoustic wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding acoustic wave attribute.

[0011] Furthermore, determining whether the sound wave characteristic information includes preset target information includes:

[0012] The number of attribute feature values contained in each feature data group in the feature data set is determined.

[0013] According to the number of attribute feature values in each feature data group, the first target detection algorithm corresponding to each feature data group is determined from the preset detection algorithm library; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute feature values in its corresponding feature data group.

[0014] Each feature data group is input into its corresponding first target detection algorithm for calculation to obtain a first calculation result.

[0015] Determine whether the sound wave characteristic information includes preset target information according to the first calculation result.

[0016] Furthermore, determining whether the acoustic wave characteristic information includes preset target information according to the first calculation result includes:

[0017] The first calculation result is matched with a preset data information table. If the match is successful, it is determined that the first calculation result contains preset target information.

[0018] Furthermore, after determining that the first calculation result includes preset target information, the method further includes:

[0019] Enumerate and combine the attribute feature values contained in each feature data group.

[0020] According to the number of attribute feature values in each enumeration combination corresponding to each feature data group, several second target detection algorithms corresponding to each feature data group are determined from the preset detection algorithm library; the number of second target detection algorithms corresponding to each feature data group is the same as the number of its corresponding enumeration combinations; the number of input data corresponding to each second target detection algorithm is the same as the number of attribute feature values in its corresponding enumeration combination.

[0021] Each enumeration combination is input into its corresponding second detection algorithm for calculation to obtain a second calculation result.

[0022] Furthermore, after obtaining the acoustic wave characteristic information of the infrasound wave, the method further includes:

[0023] The acoustic wave characteristic information is analyzed to determine the position attribute information of the infrasound wave; the position attribute information includes propagation direction, propagation angle, signal value, and variation amplitude.

[0024] The network device corresponding to the infrasound wave is determined according to the location attribute information.

[0025] Furthermore, after marking the network device corresponding to the sound wave information as a target device, the method further includes:

[0026] An early warning message is issued, wherein the early warning message includes device information of the target device and data information transmitted by the infrasound wave.

[0027] A network equipment security detection system, comprising:

[0028] The acoustic wave monitoring module is used to monitor the acoustic waves generated by several network devices in the target physical area.

[0029] The feature acquisition module is used to acquire the acoustic wave feature information of the infrasound wave when the infrasound wave emitted by any network device is monitored.

[0030] The security detection module is used to determine whether the sound wave characteristic information contains preset target information, and if so, mark the network device corresponding to the sound wave information as a target device.

[0031] A computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the aforementioned network device security detection method when executing the computer program.

[0032] A computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the aforementioned network device security detection method.

[0033] The beneficial effects of the present invention are embodied in:

[0034] The present invention can effectively detect whether network devices in a target physical area use infrasound waves to carry out eavesdropping attacks, helping to more comprehensively defend against network attacks that maliciously steal data information. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0036] Figure 1 This is a flow chart of a network device security detection method according to an embodiment of the present invention;

[0037] Figure 2This is a flow chart of another network device security detection method according to an embodiment of the present invention;

[0038] Figure 3 This is a structural diagram of a network device security detection system according to an embodiment of the present invention. DETAILED DESCRIPTION

[0039] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0040] It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments may be combined with each other; and, based on the embodiments in this disclosure, all other embodiments obtained by persons of ordinary skill in the art without creative work are within the scope of protection of this disclosure.

[0041] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.

[0042] The present invention provides a method for detecting network device security. Figure 1 Shown, including:

[0043] S11: Monitoring sound waves generated by a plurality of network devices within a target physical area.

[0044] S12: When infrasound waves emitted by any network device are detected, acoustic wave characteristic information of the infrasound waves is obtained.

[0045] S13: Determine whether the acoustic wave characteristic information contains preset target information, and if so, mark the network device corresponding to the acoustic wave information as a target device, and determine the target device as a network device that uses infrasound to carry out eavesdropping attacks.

[0046] Figure 1 The embodiment can effectively detect whether network devices in the target physical area use infrasound waves to carry out eavesdropping attacks, helping to more comprehensively defend against network attacks that maliciously steal data information.

[0047] Preferably, after obtaining the acoustic wave characteristic information of the infrasound wave, the method further comprises:

[0048] The acoustic wave characteristic information is feature extracted according to a plurality of preset acoustic wave attributes to obtain a feature data set corresponding to the acoustic wave characteristic information; the feature data set includes a feature data group corresponding to each acoustic wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding acoustic wave attribute.

[0049] Examples of the above preferred solutions are as follows:

[0050] The sound wave characteristic information is A. The preset sound wave attributes include band (a), frequency (b), rhythm (c), and variation (d). The characteristic data contained in each sound wave attribute is:

[0051] Band (a): upper limit (a1), median (a2), lower limit (a3)

[0052] Frequency (b): Frequency in Hertz in binary (b1), octal (b2), or decimal (b3)

[0053] Rhythm (c): The interval period of infrasound is marked with 0, and the excitation period is marked with 1

[0054] Amplitude (d): 1 indicates an increase, and 0 indicates a decrease

[0055] The feature data set corresponding to the acoustic wave feature information can be {(A-a1, A-a2, A-a3), (A-b1, A-b2, A-b3), (A-0, A-1), (A-1, A-0)}, where each "()" is a feature data set.

[0056] In the above preferred solutions, the preset several sound wave attributes can be set according to specific detection requirements and are not limited to the setting method in the example.

[0057] Preferably, the determining whether the sound wave characteristic information contains preset target information includes:

[0058] The number of attribute feature values contained in each feature data group in the feature data set is determined.

[0059] According to the number of attribute feature values in each feature data group, the first target detection algorithm corresponding to each feature data group is determined from the preset detection algorithm library; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute feature values in its corresponding feature data group.

[0060] Each feature data group is input into its corresponding first target detection algorithm for calculation to obtain a first calculation result.

[0061] Determine whether the sound wave characteristic information includes preset target information according to the first calculation result.

[0062] In the above preferred embodiment, the preset detection algorithm library stores detection algorithms for detecting data information transmitted in acoustic signals. The present invention calculates the attribute characteristic values in the feature data set corresponding to each infrasound wave. Compared with directly calculating the acoustic feature information of each infrasound wave, it can effectively improve the accuracy of the calculation results and increase the detection rate. The detection algorithms include known related detection algorithms and detection algorithms customized based on historical infrasound eavesdropping attacks. The use of these detection algorithms can ensure the targeted detection and further improve the detection rate of high-risk eavesdropping attacks. Considering that eavesdropping attacks may bypass detection through encrypted transmission, the preset detection algorithm library also includes a decryption algorithm. When encrypted data is found in the feature data set of the infrasound signal, the encrypted data is decrypted using several decryption algorithms to detect the eavesdropping attack. The present invention determines the first target detection algorithm corresponding to each feature data group from a preset detection algorithm library based on the number of attribute characteristic values in each feature data group, and calculates the attribute characteristic values in the feature data set. This can improve the accuracy of the detection algorithm calculation results, and at the same time achieve the purpose of fully calculating the infrasound waves, ensuring the comprehensiveness of the detection results.

[0063] Preferably, determining whether the sound wave characteristic information contains preset target information according to the first calculation result includes:

[0064] The first calculation result is matched with a preset data information table. If the match is successful, it is determined that the first calculation result contains preset target information. The data information contained in the preset data information table can be set according to the future application scenario of the network device. For example, if it is used in a government agency, the data information contained in the sensitive data information table can be "top secret", "confidential", "secret", "internal", etc.; if it is used in a scientific research institute, the data information contained in the sensitive data information table can be "project", "tender", "sample", "scientific research", etc.; if it is used in an enterprise, the data information contained in the sensitive data information table can be "bid", "plan", "finance", etc.

[0065] Preferably, after determining that the first calculation result includes preset target information, the method further includes:

[0066] Enumerate and combine the attribute feature values contained in each feature data group.

[0067] According to the number of attribute feature values in each enumeration combination corresponding to each feature data group, several second target detection algorithms corresponding to each feature data group are determined from the preset detection algorithm library; the number of second target detection algorithms corresponding to each feature data group is the same as the number of its corresponding enumeration combinations; the number of input data corresponding to each second target detection algorithm is the same as the number of attribute feature values in its corresponding enumeration combination.

[0068] Each enumeration combination is input into its corresponding second detection algorithm for calculation to obtain a second calculation result.

[0069] Furthermore, the attribute feature values included in each feature data group are enumerated and combined in a manner in which the number of attribute feature values included in each feature data group decreases in sequence.

[0070] Based on the above examples, the above preferred solutions are exemplified as follows:

[0071] Taking the characteristic data group corresponding to the band (a) attribute as an example, the number of attribute characteristic values it contains is 3, namely the upper limit value (a1), the median value (a2), and the lower limit value (a3). By enumerating and combining them in a descending order according to the number of attribute characteristic values it contains, 6 enumeration combinations corresponding to the characteristic data group are obtained, namely: (A-a1, A-a2), (A-a1, A-a3), (A-a2, A-a3), (A-a1), (A-a2), and (A-a3). Using the second target detection algorithm to detect and calculate the attribute features of these enumeration combinations can achieve the purpose of fully detecting and calculating each characteristic data group, enriching the detection calculation results. The obtained detection calculation results are helpful for fully analyzing the behavior of infrasound eavesdropping attacks, understanding the mechanism of using infrasound to build eavesdropping paths, including which sound wave attributes are mainly affected, what change trends the affected sound wave attributes show, etc., and helping to formulate efficient and targeted prevention strategies.

[0072] Preferably, after obtaining the acoustic wave characteristic information of the infrasound wave, the method further comprises:

[0073] The acoustic wave characteristic information is analyzed to determine the position attribute information of the infrasound wave; the position attribute information includes propagation direction, propagation angle, signal value, and variation amplitude.

[0074] The network device corresponding to the infrasound wave is determined according to the location attribute information.

[0075] The above preferred solution provides a method for determining the network devices that generate infrasound waves within the target physical area. In a security detection, in order to improve the detection efficiency of network devices, it is often necessary to deploy multiple network devices in the target physical area for detection for centralized detection. Determining the network devices corresponding to the infrasound waves can help to accurately identify network devices with security risks and improve security detection efficiency.

[0076] Preferably, after marking the network device corresponding to the sound wave information as a target device, the method further includes:

[0077] An early warning message is issued, wherein the early warning message includes device information of the target device and data information transmitted by the infrasound wave.

[0078] The above-mentioned preferred solution can help security inspectors to accurately grasp the status of network devices with security risks at the first time and reduce the cost of manual investigation.

[0079] In order to further illustrate the present invention, in combination with the above preferred solutions, the present invention provides another embodiment of a network device security detection method, such as Figure 2 Shown, including:

[0080] S21: Monitoring sound waves generated by a plurality of network devices within a target physical area.

[0081] S22: When infrasound waves emitted by any network device are detected, the acoustic wave characteristic information of the infrasound waves is obtained, and the process proceeds to S23 and S25 respectively.

[0082] S23: Analyze the acoustic wave characteristic information to determine the position attribute information of the infrasound wave; the position attribute information includes propagation direction, propagation angle, signal value, and variation amplitude.

[0083] S24: Determine the network device corresponding to the infrasound wave according to the location attribute information.

[0084] S25: Feature extraction is performed on the sound wave characteristic information according to a plurality of preset sound wave attributes to obtain a feature data set corresponding to the sound wave characteristic information; the feature data set includes a feature data group corresponding to each sound wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding sound wave attribute.

[0085] S26: Determine the number of attribute feature values contained in each feature data group in the feature data set.

[0086] S27: According to the number of attribute characteristic values in each feature data group, determine the first target detection algorithm corresponding to each feature data group from the preset detection algorithm library; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute characteristic values in the feature data group corresponding to it. The preset detection algorithm library stores detection algorithms for detecting data information transmitted in the sound wave signal.

[0087] S28: Input each feature data group into its corresponding first target detection algorithm for calculation to obtain a first calculation result.

[0088] S29: Match the first calculation result with the preset data information table to determine whether the match is successful. If so, determine that the first calculation result contains preset target information, mark the network device corresponding to the sound wave information as the target device, and enter S210. Otherwise, determine that the first calculation result does not contain preset target information.

[0089] S210: For each feature data group, enumerate and combine the attribute feature values contained in each feature data group in a descending order.

[0090] S211: According to the number of attribute feature values in each enumeration combination corresponding to each feature data group, determine a number of second target detection algorithms corresponding to each feature data group from the preset detection algorithm library; the number of second target detection algorithms corresponding to each feature data group is the same as the number of its corresponding enumeration combinations; the number of input data corresponding to each second target detection algorithm is the same as the number of attribute feature values in its corresponding enumeration combination.

[0091] S212: Input each enumeration combination into its corresponding second detection algorithm for calculation to obtain a second calculation result.

[0092] S213: issuing a warning message, wherein the warning message includes device information of the target device and data information transmitted by the infrasound wave, wherein the data information transmitted by the infrasound wave is derived from the first calculation result and the second calculation result.

[0093] Figure 2 The embodiment can effectively detect whether network devices in the target physical area use infrasound waves to carry out eavesdropping attacks. If the detection method of the embodiment of the present invention is used before the network equipment is put into use, it can achieve the technical effect of further improving the security detection means before the network equipment is put into use, and help to more comprehensively resist network attacks that maliciously steal data information. Figure 2The embodiment calculates the attribute characteristic values in the characteristic data set corresponding to each infrasound wave. Compared with directly calculating the sound wave characteristic information of each infrasound wave, it can effectively improve the accuracy of the calculation result and increase the detection rate. Figure 2 The embodiment determines the first target detection algorithm corresponding to each feature data group from a preset detection algorithm library based on the number of attribute feature values in each feature data group, and calculates the attribute feature values in the feature data set. This can further improve the accuracy of the detection algorithm calculation results, and at the same time achieve the purpose of fully calculating the infrasound waves, thereby ensuring the comprehensiveness of the detection results. Figure 2 The embodiment can fully detect and calculate each feature data group and enrich the detection and calculation results. The obtained detection and calculation results help to fully analyze the behavior of infrasound eavesdropping attacks, understand the mechanism of using infrasound to build eavesdropping paths, and help formulate efficient and targeted prevention strategies. Figure 2 The embodiments described above can accurately identify network devices with potential safety hazards, improve security detection efficiency, and help security detection personnel accurately grasp the status of network devices with potential safety hazards in the first place, thereby reducing manual investigation costs.

[0094] Figure 2 The embodiment is based on Figure 1 The preferred embodiment of the present invention is obtained, therefore, Figure 2 The description of the embodiment is relatively simple. Please refer to Figure 1 The embodiment described.

[0095] The present invention also provides an embodiment of a network device security detection system, such as Figure 3 Shown, including:

[0096] The sound wave monitoring module 31 is used to monitor the sound waves generated by a number of network devices in the target physical area.

[0097] The feature acquisition module 32 is configured to acquire acoustic feature information of the infrasound wave when the infrasound wave emitted by any network device is detected.

[0098] The security detection module 33 is configured to determine whether the acoustic wave characteristic information contains preset target information, and if so, mark the network device corresponding to the acoustic wave information as a target device.

[0099] According to the application requirements of the target physical area, the acoustic wave monitoring module 31 can be deployed separately in the target physical area as an independent device, establishing a communication connection with the feature acquisition module 32 and the safety detection module 33, or it can be integrated with the feature acquisition module 32 and the safety detection module 33 and deployed in the target physical area.

[0100] Figure 3The embodiment can effectively detect whether network devices in the target physical area use infrasound waves to carry out eavesdropping attacks, helping to more comprehensively defend against network attacks that maliciously steal data information.

[0101] Preferably, after obtaining the acoustic wave characteristic information of the infrasound wave, the characteristic acquisition module 32 is further configured to:

[0102] The acoustic wave characteristic information is feature extracted according to a plurality of preset acoustic wave attributes to obtain a feature data set corresponding to the acoustic wave characteristic information; the feature data set includes a feature data group corresponding to each acoustic wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding acoustic wave attribute.

[0103] Preferably, the determining whether the sound wave characteristic information contains preset target information includes:

[0104] Determining the number of attribute feature values contained in each feature data group in the feature data set;

[0105] Determining a first target detection algorithm corresponding to each feature data group from a preset detection algorithm library based on the number of attribute feature values in each feature data group; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute feature values in its corresponding feature data group;

[0106] Inputting each feature data group into its corresponding first target detection algorithm for calculation to obtain a first calculation result;

[0107] Determine whether the sound wave characteristic information includes preset target information according to the first calculation result.

[0108] Preferably, determining whether the sound wave characteristic information contains preset target information according to the first calculation result includes:

[0109] The first calculation result is matched with a preset data information table. If the match is successful, it is determined that the first calculation result contains preset target information.

[0110] Preferably, after determining that the first calculation result contains preset target information, the safety detection module 33 is further configured to:

[0111] Enumerate and combine the attribute feature values contained in each feature data group.

[0112] According to the number of attribute feature values in each enumeration combination corresponding to each feature data group, several second target detection algorithms corresponding to each feature data group are determined from the preset detection algorithm library; the number of second target detection algorithms corresponding to each feature data group is the same as the number of its corresponding enumeration combinations; the number of input data corresponding to each second target detection algorithm is the same as the number of attribute feature values in its corresponding enumeration combination.

[0113] Each enumeration combination is input into its corresponding second detection algorithm for calculation to obtain a second calculation result.

[0114] Preferably, after obtaining the acoustic wave characteristic information of the infrasound wave, the characteristic acquisition module 32 is further configured to:

[0115] The acoustic wave characteristic information is analyzed to determine the position attribute information of the infrasound wave; the position attribute information includes propagation direction, propagation angle, signal value, and variation amplitude.

[0116] The network device corresponding to the infrasound wave is determined according to the location attribute information.

[0117] Preferably, after marking the network device corresponding to the sound wave information as a target device, the security detection module 33 is further configured to:

[0118] An early warning message is issued, wherein the early warning message includes device information of the target device and data information transmitted by the infrasound wave.

[0119] Figure 3 The embodiment is Figure 1 、 Figure 2 The system embodiment corresponding to the method embodiment, part of the implementation process and technical effects are the same Figure 1 、 Figure 2 The embodiments are similar, therefore, Figure 3 The description of the embodiment is relatively simple. Please refer to Figure 1 、 Figure 2 The embodiment described.

[0120] The present invention also provides an embodiment of a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in the aforementioned embodiment is implemented. The method can be found in Figure 1 、 Figure 2 The description of the embodiment will not be repeated here.

[0121] An embodiment of the present invention further provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement the method described in the above embodiment.

[0122] The present invention can effectively detect whether network devices in a target physical area use infrasound waves to carry out eavesdropping attacks, helping to more comprehensively defend against network attacks that maliciously steal data information.

[0123] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.

Claims

1. A network device security detection method, characterized in that: include: Monitoring the acoustic waves generated by several network devices within the target physical area; When infrasound waves emitted by any network device are detected, acoustic wave characteristic information of the infrasound waves is obtained; Determining whether the sound wave characteristic information contains preset target information, and if so, marking the network device corresponding to the sound wave characteristic information as a target device; After obtaining the acoustic wave characteristic information of the infrasound wave, the method further includes: performing feature extraction on the acoustic wave characteristic information according to a plurality of preset acoustic wave attributes to obtain a feature data set corresponding to the acoustic wave characteristic information; the feature data set includes a feature data group corresponding to each acoustic wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding acoustic wave attribute; The determining whether the sound wave characteristic information contains preset target information includes: determining the number of attribute feature values contained in each feature data group in the feature data set; determining a first target detection algorithm corresponding to each feature data group from a preset detection algorithm library based on the number of attribute feature values in each feature data group; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute feature values in its corresponding feature data group; inputting each feature data group into its corresponding first target detection algorithm for calculation to obtain a first calculation result; and determining whether the sound wave characteristic information contains preset target information based on the first calculation result; The determining, based on the first calculation result, whether the sound wave characteristic information includes preset target information includes: matching the first calculation result with a preset data information table; if the match is successful, determining that the first calculation result includes preset target information.

2. The method according to claim 1, characterized in that After determining that the first calculation result includes preset target information, the method further includes: Enumerate and combine the attribute feature values contained in each feature data group; Determine, from the preset detection algorithm library, a number of second target detection algorithms corresponding to each feature data group based on the number of attribute feature values in each enumeration combination corresponding to each feature data group; the number of second target detection algorithms corresponding to each feature data group is the same as the number of its corresponding enumeration combinations; and the number of input data corresponding to each second target detection algorithm is the same as the number of attribute feature values in its corresponding enumeration combination; Each enumeration combination is input into its corresponding second detection algorithm for calculation to obtain a second calculation result.

3. The method according to claim 1, characterized in that After obtaining the acoustic wave characteristic information of the infrasound wave, the method further includes: Analyzing the acoustic wave characteristic information to determine position attribute information of the infrasound wave; the position attribute information includes propagation direction, propagation angle, signal value, and variation amplitude; The network device corresponding to the infrasound wave is determined according to the location attribute information.

4. The method according to claim 1, wherein After marking the network device corresponding to the acoustic wave characteristic information as a target device, the method further includes: An early warning message is issued, wherein the early warning message includes device information of the target device and data information transmitted by the infrasound wave.

5. A network equipment security detection system, characterized in that: include: An acoustic wave monitoring module, used to monitor acoustic waves generated by several network devices within a target physical area; A feature acquisition module, configured to acquire acoustic feature information of the infrasound wave when an infrasound wave emitted by any network device is detected; a security detection module, configured to determine whether the acoustic wave characteristic information contains preset target information, and if so, mark the network device corresponding to the acoustic wave characteristic information as a target device; After acquiring the acoustic wave characteristic information of the infrasound wave, the characteristic acquisition module is further configured to: perform feature extraction on the acoustic wave characteristic information according to a plurality of preset acoustic wave attributes to obtain a feature data set corresponding to the acoustic wave characteristic information; the feature data set includes a feature data group corresponding to each acoustic wave attribute, and each feature data group includes a plurality of attribute characteristic values of the corresponding acoustic wave attribute; The determining whether the sound wave characteristic information contains preset target information includes: determining the number of attribute feature values contained in each feature data group in the feature data set; determining a first target detection algorithm corresponding to each feature data group from a preset detection algorithm library based on the number of attribute feature values in each feature data group; wherein the number of input data corresponding to each first target detection algorithm is the same as the number of attribute feature values in its corresponding feature data group; inputting each feature data group into its corresponding first target detection algorithm for calculation to obtain a first calculation result; and determining whether the sound wave characteristic information contains preset target information based on the first calculation result; The determining, based on the first calculation result, whether the sound wave characteristic information includes preset target information includes: matching the first calculation result with a preset data information table; if the match is successful, determining that the first calculation result includes preset target information.

6. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the network device security detection method according to any one of claims 1 to 4 is implemented.

7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the network device security detection method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Building security information interaction management system

    CN108916659A

  • Voice attack detection method and device and network equipment

    CN109981616A