Router visitor management method and device, electronic equipment and readable storage medium
By detecting the network behavior of guest accounts and generating control strategies, the security risk of router guests arbitrarily accessing the network is resolved, the network behavior of guest accounts can be monitored and controlled, and network security is guaranteed.
Patent Information
- Application Number
- CN202310573881.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-05-18
AI Technical Summary
In the existing router guest login system, guests can access the network at will after obtaining the password, which poses a network security risk and cannot effectively control network behavior.
By detecting the network behavior of guest accounts, control strategies are determined, including permission restrictions on network resources, time, and number of visits, and different control strategies are generated to control network access for guest accounts.
It enables monitoring and control of the network behavior of visitor accounts, avoids network risks and ensures network security.
Smart Images

Figure CN116668104B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of router technology, and in particular to a method, device, electronic device, and readable storage medium for managing and controlling router visitors. Background Art
[0002] Routers, as network connection devices, are widely used in our lives and work. In recent years, with the popularization of smart mobile terminals, the use of routers has become increasingly widespread. Whether at home or at work, routers can conveniently connect to the internet. In addition, to create a relatively secure network environment, various router manufacturers have launched their own guest login systems, allowing guests to log in to their accounts and perform subsequent network access operations. However, if a guest obtains a password from the appropriate channels before the first login and successfully connects to the router using the password, they can freely access the network, which poses certain network risks. For example, a stranger could log in to the router using the password without the router owner's consent and access the router's NAS (Network Attached Storage) information. Therefore, how to manage the network of guest accounts based on their network behavior has become an urgent problem that needs to be solved. Summary of the Invention
[0003] The main purpose of this application is to provide a router visitor management method, device, electronic device and readable storage medium, aiming to solve the technical problem of how to perform network management on guest accounts based on their network behavior.
[0004] To achieve the above objectives, the present application provides a method for managing and controlling router visitors, which includes the following steps:
[0005] When detecting that at least one guest account terminal is connected to the router, detecting whether network access control needs to be performed on the guest account in the guest account terminal;
[0006] If network access control is required for the guest account, determining the network behavior of the guest account;
[0007] A control policy for controlling network access is determined based on the behavior type of the network behavior, and network access control is performed on the guest account based on the control policy, wherein the control policy includes permission restrictions on network resources, network time, and number of network accesses.
[0008] Optionally, the step of determining a control policy for controlling network access according to the behavior type of the network behavior includes:
[0009] If there are multiple guest account terminals connected to the router, determine the user roles corresponding to the guest accounts of all guest account terminals connected to the router, wherein the user roles include at least a first user role and a second user role with a lower priority than the first user role;
[0010] If the behavior type of the network behavior corresponding to the second user role is occupying a large amount of bandwidth, and the network behaviors of the first user role and the second user role are in the same time period, then the control strategy for controlling network access is determined to limit the traffic of the guest account corresponding to the second user role, where occupying a large amount of bandwidth includes that the bandwidth usage ratio at a time node is greater than a preset threshold.
[0011] Optionally, the step of determining a control policy for controlling network access according to the behavior type of the network behavior includes:
[0012] Matching the behavior type of the network behavior with a preset network behavior whitelist;
[0013] If the behavior type matches the network behavior whitelist, determining that the control policy for controlling network access is to allow access to the network;
[0014] If the behavior type does not match the network behavior whitelist, then the behavior type is matched with a preset network behavior blacklist;
[0015] If the behavior type matches the network behavior blacklist, the control policy for controlling network access is determined to be limiting network access time.
[0016] Optionally, the step of determining a control policy for controlling network access according to the behavior type of the network behavior includes:
[0017] If the behavior type of the network behavior is to access restricted network resources, a control policy for controlling network access is determined to restrict the guest account from logging in to connect to the router, wherein the restricted network resources include at least NAS.
[0018] Optionally, the step of determining a control policy for controlling network access according to the behavior type of the network behavior includes:
[0019] Scoring the behavior type of the network behavior according to a preset scoring rule to obtain a scoring score;
[0020] Summarize the evaluation scores of all network behaviors of the guest account from the time of the last login to the router to the current time to obtain a target score;
[0021] A score interval in which the target score is located is determined, and a control policy corresponding to the score interval is used as a control policy for controlling network access, wherein there are at least two score intervals, and different score intervals correspond to different control policies.
[0022] Optionally, after the step of performing network access control on the guest account according to the control policy, the following steps are included:
[0023] If it is detected that the guest account has logged out of the router, the logout time of the guest account is recorded;
[0024] If it is not the first time for the guest account to log out of the router, the time interval between each logout time node of the guest account and the last logout time node is counted;
[0025] If it is detected that at least two time intervals are consecutively less than the preset time interval, the guest account is prohibited from logging in again within the preset time period.
[0026] Optionally, when detecting that at least one guest account terminal is connected to the router, the step of detecting whether network access control needs to be performed on the guest account in the guest account terminal includes:
[0027] When detecting that at least one guest account terminal is connected to the router, obtaining user role tag information sent by the administrator account, wherein the user role tag information includes a user role corresponding to each guest account and a priority corresponding to the user role;
[0028] Determining, based on the user role tag information, a user role corresponding to each guest account in the guest account terminal and a priority corresponding to each guest account;
[0029] If there exists a guest account corresponding to a priority level less than or equal to the preset priority level, it is determined that network access control needs to be performed on the guest account corresponding to the priority level less than or equal to the preset priority level.
[0030] In addition, to achieve the above-mentioned purpose, the present application also provides a router visitor control device, which includes:
[0031] a detection module, configured to detect whether network access control needs to be performed on the guest account in the guest account terminal when detecting that at least one guest account terminal is connected to the router;
[0032] a determination module, configured to determine the network behavior of the guest account if network access control is required for the guest account;
[0033] The control module is configured to determine a control policy for controlling network access according to a behavior type of the network behavior, and perform network access control on the guest account according to the control policy, wherein the control policy comprises permission limits on network resources, network time, and network access times.
[0034] The application further provides an electronic device, which is a physical device, and comprises a memory, a processor, and a program of the router guest management method stored in the memory and executable on the processor, and the program of the router guest management method can implement the steps of the router guest management method when executed by the processor.
[0035] The application further provides a readable storage medium, which is a computer readable storage medium, and stores a program for implementing the router guest management method, and the program for implementing the router guest management method can implement the steps of the router guest management method when executed by a processor.
[0036] The application further provides a computer program product comprising a computer program, which can implement the steps of the router guest management method when executed by a processor.
[0037] The technical solution of the application is that when a terminal of a guest account accesses a router and network access control needs to be performed on the guest account in the terminal of the guest account, the network behavior of the guest account is determined, a control policy for controlling network access is determined according to a behavior type of the network behavior, and network access control is performed on the guest account according to the control policy, so that the phenomenon that network control cannot be performed on a guest who has connected to a router and network risks exist can be avoided, and the control policy is generated according to the network behavior of the guest account, and network access control is performed on the guest account according to the control policy, so that the network behavior of the guest account can be monitored, network control can be performed on the guest account according to the network behavior of the guest account, and the network behavior of the guest account that has network risks can be controlled in time. BRIEF DESCRIPTION OF DRAWINGS
[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the application and serve to explain the principles of the application together with the specification.
[0039] In order to more clearly illustrate the technical solutions in the embodiments or the prior art, the accompanying drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0040] Figure 1 This is a schematic diagram of the architecture of the router in the router visitor control method of this application;
[0041] Figure 2 This is a flowchart of the first embodiment of the router visitor control method of this application;
[0042] Figure 3 This is a flow chart of the second embodiment of the router visitor control method of this application;
[0043] Figure 4 This is a schematic diagram of a module structure of the router visitor control device of this application;
[0044] Figure 5 Schematic diagram of the device structure of the hardware operating environment involved in the electronic device in this embodiment.
[0045] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0046] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0047] In this embodiment, the router visitor management method of the present application can be applied to the router, referring to Figure 1The router includes various modules, such as MCU (Microcontroller Unit), Flash, Button, power supply, WAN (Wide Area Network), LAN (Local Area Network), 2.4G module, and antenna connected to the 2.4G module, 5G module, and antenna connected to the 5G module. Among them, the power supply module can be a power supply interface, which can be plugged into an AC to DC power adapter. Flash can be used to save the default visitor control profile and customer-defined visitor control profile. Flash can also receive location information and air quality information transmitted by the MCU and complete the storage. The 2.4G module or the 5G module can be used to implement WiFi function. The WAN can be connected to the optical fiber to access the external network. Users can connect to the LAN via a network cable to achieve Internet access. In addition, the main MIC, noise reduction MIC and voice encoding module can be set in the router to complete the voice input function of the router; the speaker and voice decoding module can be set in the router to complete the sound output function of the router.
[0048] Example 1
[0049] Based on this, please refer to Figure 2 This embodiment provides a method for managing and controlling router visitors, the method comprising:
[0050] Step S10, when detecting that at least one guest account terminal is connected to the router, detecting whether network access control needs to be performed on the guest account in the guest account terminal;
[0051] Step S20: If network access control is required for the guest account, determine the network behavior of the guest account;
[0052] Step S30, determining a control policy for controlling network access based on the behavior type of the network behavior, and performing network access control on the guest account based on the control policy, wherein the control policy includes permission restrictions on network resources, network time, and number of network accesses.
[0053] Since current routers cannot perform network control on guest accounts based on their network behavior, in this embodiment, different control policies can be pre-set on the router, and then different control policies can be executed based on the network behavior of the guest accounts, so as to achieve network control on guest accounts based on their network behavior.
[0054] In an optional embodiment, the router is pre-configured with multiple control policies when it leaves the factory, and the control policies may include permission restrictions on at least one of network resources, network time, and the number of network accesses. Optionally, different visitor control logics can be generated according to different control policies, and the visitor control logics can be set with access control levels, and then stored in a preset access control list. For example, four levels are set in the access control list, namely Level 1: limited Internet access time (for example, only 30 minutes of access) and limited resource access rights (such as no access to NAS (Network Attached Storage)). Level 2: Restricted access time period (for example, only access from 8 am to 8 pm) and limited Internet access time. Level 3: Normal permissions, all resources can be accessed, and access time is not restricted. Level 4: Complete prohibition of network access, that is, visitors cannot access the network through the router, such as unable to transmit data packets.
[0055] In this embodiment, an access control level can be selected in the access control list as the default access control level. When it is detected that at least one guest account is connected to the router, network access control can be performed on the guest account according to the default access control level. When the guest account accesses the network through the router, it can be determined whether network access control is required for the guest account. If not, the guest account can directly access the network according to the default access control level or the access control level set by the administrator account. When network access control is required for the guest account, the network behavior of the guest account can be detected each time it accesses the network, and a new control policy can be determined based on the detection results. Then, network access control can be performed on the guest account according to the new control policy. In particular, when there is a conflict between the new control policy and the guest control logic corresponding to the default access control level, the new control policy will be executed first; when there is no conflict between the new control policy and the default access control level, the new control policy and the guest control logic corresponding to the default access control level will be executed simultaneously.
[0056] Optionally, for step S10, when it is detected that at least one guest account terminal is connected to the router, it is detected whether network access control needs to be performed on the guest account in the guest account terminal;
[0057] In this embodiment, since the host has told the guest the password before the guest account logs in for the first time, in order to control the guest's subsequent access to the network, the guest login information corresponding to the guest account can be recorded and different access control strategies can be implemented based on this.
[0058] Optionally, upon detecting at least one guest account terminal connected to the router, the router may first check the guest accounts of all guest account terminals connected to the router to determine whether network access control is required. Furthermore, the guest accounts may be checked sequentially in the order in which the guest account terminals connected to the router.
[0059] Optionally, when detecting whether network access control is required for a guest account, the determination can be made based on the guest account's user role. For example, the guest account corresponding to the highest-priority user role does not require network access control. Alternatively, the determination can be made based on the permissions set by the administrator account. For example, the administrator account can set a setting in the account management interface that does not require network access control for at least one guest account. Other methods are also possible and are not limited here.
[0060] Optionally, for step S20, if network access control is required for the guest account, the network behavior of the guest account is determined;
[0061] In this embodiment, when it is determined that network access control is required for a guest account, the guest account's network behavior needs to be monitored in real time, where network behavior may include watching videos, playing games, accessing NAS, etc. Optionally, the collection of the guest account's network behavior may be performed from the time the guest account last logged into the system in the router until the guest account terminal where the guest account resides is disconnected from the router, and the corresponding network behavior may be determined based on the data packets sent by the guest account to the router each time.
[0062] Optionally, for step S30, a control policy for controlling network access is determined based on the behavior type of the network behavior, and network access control is performed on the guest account based on the control policy, wherein the control policy includes permission restrictions on network resources, network time, and number of network accesses.
[0063] Optionally, the behavior types of network behavior may include studying, playing games, watching videos, listening to music, and accessing restricted network resources. Optionally, after collecting the network behavior of the guest account, the behavior type of the network behavior is promptly determined, and then different control strategies are determined based on this behavior type. Optionally, different control strategies can be set based on different behavior types. For example, the network behavior of the guest account can be recorded and evaluated based on the behavior type of the network behavior to obtain different control strategies, such as those shown in Table 1 below.
[0064]
[0065] Table 1
[0066] Optionally, when evaluating the behavior type of network behavior, the network behavior can be matched with the evaluation table according to a pre-set evaluation table, as shown in Table 1 above, to determine the behavior type of the network behavior, as well as the corresponding evaluation basis and control strategy.
[0067] Alternatively, a corresponding control policy can be determined based on the guest account terminal address and the type of network access behavior of the guest account at the guest account terminal address. The guest account terminal address can be first determined, and then a determination can be made as to whether it is within the preset address range corresponding to the router. If so, a control policy can be determined based on the type of network behavior of the guest account, and network management and control of the guest account can be performed based on the control policy. However, if it is not, a guest control logic corresponding to an access control level can be selected from a pre-set access control list to manage the guest account. For example, if the preset address range corresponding to the router is the living room, and the guest account terminal address is not in the living room, but in the hallway outside the living room, it can be determined that freeloading is occurring. A guest control logic corresponding to an access control level can be selected from the access control list, such as Level 1 or Level 4. However, if the guest account terminal address is also in the living room, the guest account's network behavior can be detected to determine a control policy based on the type of network behavior, and network management and control of the guest account can be performed based on the control policy.
[0068] Optionally, the corresponding control policy can be determined based on the scenario in which the router is located and the network behavior of the guest account. For example, if the scenario in which the router is located is a family gathering, the network behavior of the guest account can be controlled. If the scenario in which the router is located is a gathering of friends, the network behavior of the guest account can be controlled. The control policy can be determined based on the type of network behavior, and the network control of the guest account can be performed based on the control policy. The scenario in which the router is located can be determined based on the scenario characteristics input by the administrator.
[0069] In this embodiment, when at least one guest account terminal is connected to the router and network access control of the guest account in the guest account terminal is required, the network behavior of the guest account is determined, and a control policy for controlling network access is determined according to the behavior type of the network behavior, and network access control of the guest account is then performed according to the control policy. This can avoid the current phenomenon that network management and control of guests connected to the router cannot be performed, resulting in network risks. In addition, a control policy is generated according to the network behavior of the guest account, and network access control of the guest account is performed according to the control policy. This can monitor the network behavior of the guest account, and perform network management and control of the guest account according to the network behavior of the guest account. When the guest account performs network behavior with network risks on the router, timely management and avoidance can be performed.
[0070] Example 2
[0071] Based on the first embodiment of the present application, in another embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 3 Step S30, determining a control strategy for controlling network access based on the behavior type of the network behavior, includes:
[0072] Step a: If multiple guest account terminals are connected to the router, determine the user roles corresponding to the guest accounts of all guest account terminals connected to the router, wherein the user roles include at least a first user role and a second user role with a lower priority than the first user role;
[0073] In step b, if the behavior type of the network behavior corresponding to the second user role is occupying a large amount of bandwidth, and the network behaviors of the first user role and the second user role are in the same time period, then the control strategy for controlling network access is determined to limit the traffic of the guest account corresponding to the second user role, wherein occupying a large amount of bandwidth includes that the bandwidth usage ratio at a time node is greater than a preset threshold.
[0074] In this embodiment, when determining a control policy for controlling network access based on the network behavior of a guest account, it is also necessary to detect whether multiple guest account terminals are currently connected to the router. If multiple guest account terminals are determined to be connected to the router, the user role corresponding to each guest account terminal must be determined. Optionally, when each guest account terminal first connects to the router and logs in, the administrator account can assign a user role to each guest account to determine the user role corresponding to each guest account. Each subsequent guest account login can use the user role assigned by the administrator account until the administrator account adjusts the user role corresponding to the guest account. Furthermore, the user roles assigned to guest accounts can include at least multiple types, each type of user role can have multiple roles, and each type of user role has different priorities. For example, user roles that can be set include owner, family, friend, child, etc. Therefore, in this embodiment, if there are multiple currently logged-in guest accounts, and each guest account has a different type of user role, network management and control needs to be performed based on the different user roles. Optionally, in this embodiment, the type corresponding to the first user role is different from the type of the second user role, and the first user role has a higher priority than the second user role. For example, the priority of the master is higher than that of relatives.
[0075] Optionally, when the user roles corresponding to the guest account currently logged into the router include the first user role and the second user role, it is necessary to detect the network behavior of the second user role. If it is detected that the first user role and the second user role are surfing the Internet in the same time period, that is, both have network behavior, and it is detected that the second user role has a network behavior at a certain time node within the time period that occupies a large amount of bandwidth, it is necessary to limit the traffic of the second user role. Therefore, it can be determined that the control strategy for controlling network access is to limit the traffic of the guest account corresponding to the second user role, that is, to limit the bandwidth, such as limiting the maximum network speed to a preset network speed value. And occupying a large amount of bandwidth can include the proportion of bandwidth usage at a time node being greater than a preset threshold. For example, the network behavior of the second user role at a time node is watching videos, which occupies a large amount of bandwidth.
[0076] In this embodiment, when there are multiple guest account terminals accessing the router, the user roles corresponding to the guest accounts can be determined, including the first user role and the second user role. If the behavior type of the network behavior corresponding to the second user role is occupying a large amount of bandwidth, and the network behaviors of the two are in the same time period, the traffic of the guest account corresponding to the second user role can be restricted, thereby preventing the network operations of the low-priority guest account from affecting the network speed of the high-priority guest account.
[0077] Furthermore, the step of determining a control strategy for controlling network access according to the behavior type of the network behavior includes:
[0078] Step c, matching the behavior type of the network behavior with a preset network behavior whitelist;
[0079] Step d: If the behavior type matches the network behavior whitelist, determining the control policy for controlling network access to allow access to the network;
[0080] Step e: if the behavior type does not match the network behavior whitelist, then matching the behavior type with a preset network behavior blacklist;
[0081] Step f: If the behavior type matches the network behavior blacklist, determining that the control policy for controlling network access is to limit network access time.
[0082] In this embodiment, when determining a control policy for controlling network access based on the network behavior of a guest account, it is also necessary to match the behavior type of each guest account's network behavior with at least one of a preset network behavior whitelist and a preset network behavior blacklist to determine the corresponding control policy. Optionally, the behavior type of the guest account's network behavior can also be matched with a preset network behavior graylist.
[0083] Optionally, after determining the behavior type of the guest account's network behavior, the behavior type is matched with the network behavior whitelist. If the two match, the control policy is determined to allow access to the network, and the guest account can now perform network access operations normally. For example, if the network behavior whitelist includes learning, such as browsing CSDN, Tencent Learning Classroom, listening to online courses, etc., if the guest account's network behavior is taking online courses, it can be considered that the guest account's behavior type is learning. At this time, it can be considered that the behavior type matches the network behavior whitelist. However, if the guest account's network behavior is playing King of Glory, it can be determined that the guest account's network behavior type is playing games. At this time, it can be determined that the behavior type does not match the network behavior whitelist, and this behavior type needs to be matched with the network behavior blacklist. If the network behavior blacklist includes things like playing games, it can be determined that the behavior type matches the network behavior blacklist, and the corresponding control policy is to limit network access time, such as only being able to use the network for 30 minutes.
[0084] Optionally, each network behavior and its corresponding behavior type in the network behavior whitelist and the network behavior blacklist may be set in advance by an administrator account, and the behavior types in the network behavior whitelist and the network behavior blacklist are different.
[0085] Optionally, a network behavior gray list can be set in the router, and a valid time limit can be set for the network behavior gray list, for example, the network behavior gray list can be set to be valid only from 9 am to 10 am.
[0086] Optionally, at least one behavior type can be filtered from the network behavior blacklist to the network behavior graylist, and when the network behavior graylist is in a valid state, the behavior type in the network behavior blacklist that matches the network behavior graylist is in an invalid state and cannot be matched with the behavior type of the guest account's network behavior, but other behavior types in the network behavior blacklist are in a normal state. For example, if the network behavior graylist contains playing chess and card games, and the valid time of the network behavior graylist is from 9 a.m. to 10 a.m., then the behavior type of the guest account's network behavior from 9 a.m. to 10 a.m., in addition to matching with the network behavior whitelist and the network behavior blacklist, also needs to be matched with the network behavior graylist. And when the behavior type of the network behavior is playing games, and it is playing chess and card games, it is determined to match the network behavior graylist. At this time, the control policy for controlling network access can be determined as that when the network behavior graylist is in a valid state, the guest account can have normal network access.
[0087] In this embodiment, the behavior type of the network behavior is matched with the network behavior whitelist, and when there is no match, it is matched with the network behavior blacklist to determine the corresponding control policy, thereby ensuring the effectiveness of the acquired control policy.
[0088] Furthermore, the step of determining a control strategy for controlling network access according to the behavior type of the network behavior includes:
[0089] Step g: If the behavior type of the network behavior is to access restricted network resources, determine the control policy for controlling network access to restrict the guest account from logging in to connect to the router, wherein the restricted network resources include at least NAS.
[0090] In this embodiment, when the network behavior type is detected as accessing restricted network resources, the network access control policy can be directly determined to restrict guest accounts from logging into and connecting to the router, thereby preventing the guest account from accessing the restricted network resources. For example, if the restricted network resources include NAS, and the guest account's network behavior is accessing the NAS, the guest account can be directly restricted from logging into and connecting to the router.
[0091] In this embodiment, when it is determined that the behavior type of the network behavior is to access restricted network resources, the guest account is restricted from logging into the router, thereby ensuring the security of the restricted network resources.
[0092] Furthermore, the step of determining a control strategy for controlling network access according to the behavior type of the network behavior includes:
[0093] Step h, scoring the behavior type of the network behavior according to a preset scoring rule to obtain a scoring score;
[0094] Step i: Summarize the evaluation scores corresponding to all network behaviors of the guest account from the time point of the last login to the router to the current time point to obtain a target score;
[0095] Step j: determining the score interval in which the target score is located, and using the control strategy corresponding to the score interval as the control strategy for controlling network access, wherein there are at least two score intervals, and different score intervals correspond to different control strategies.
[0096] In this embodiment, a scoring rule can be set in advance, and the behavior type of the guest account's network behavior can be scored according to the scoring rule. Optionally, the scoring rule can be a rule set in advance by the user for scoring the behavior type of each network behavior, such as shown in Table 2 below.
[0097] Optionally, because guest accounts have diverse network behaviors, you can perform a comprehensive assessment of their network behavior and implement different control policies. For example, you can set a corresponding assessment score, with an initial score of 100. If the comprehensive assessment score is less than 60, login is prohibited. If the score is between 60 and 80, login is allowed but with limited network bandwidth. If the score is greater than 80, login is allowed without restriction.
[0098] For example, as shown in Table 2 below,
[0099]
[0100] Table 2
[0101] Optionally, after scoring the behavior type of the guest account's network behavior and obtaining a score, all scores corresponding to the guest account's most recent login time point up to the current time point can be aggregated to obtain a target score. In other words, the target score is the sum of the scores corresponding to each network behavior during the guest account's current login period.
[0102] Optionally, after determining the target score, it is also necessary to determine the preset score intervals, such as a score interval of less than 60 points, a score interval of 60-80 points, and a score interval of greater than 80 points. If the target score is 90 points, it can be determined that the target score is in a score interval greater than 80 points. At this time, the control policy corresponding to the score interval can be directly used as the control policy for controlling the guest account's network access. Optionally, there are at least two score intervals, such as a score interval of less than 60 points, and the corresponding control policy can be to prohibit the guest account from logging into the router. For example, for a score interval of 60-80 points, the corresponding control policy can be to allow the guest account to log in to the router and limit the guest account's network bandwidth. For example, for a score interval greater than 80 points, the corresponding control policy can be to allow the guest account to log in and access the network normally.
[0103] Optionally, an effective network usage time can be set for each guest account, such as 1 hour; when the guest account performs network operations, if the first type of network behavior of the guest account is detected, the effective network usage time of the guest account can be adjusted, such as increasing by 30 minutes or decreasing by 30 minutes. For example, if the behavior type is learning, the effective network usage time of the guest account is increased; if the behavior type is playing games, the effective network usage time of the guest account is reduced. Optionally, the target score corresponding to the guest account can be detected. When the target score is greater than a preset score (such as 80 points), the effective network usage time of the guest account can be increased; when the target score is less than another score (such as 65 points), the effective network usage time of the guest account can be reduced.
[0104] In the embodiment, the behavior type of the network behavior is scored according to the evaluation score rule to obtain an evaluation score, all the evaluation scores corresponding to all the network behaviors of the visitor account from the time node of the last login of the router to the current time node are summarized to obtain a target score, and then the control strategy corresponding to the score interval in which the target score is located is taken as the control strategy for controlling the network access, so that the effectiveness of the obtained control strategy is ensured.
[0105] Further, after the step of controlling the network access of the visitor account according to the control strategy, the method further includes:
[0106] Step k, if it is detected that the visitor account logs out of the router, the time node of the logout of the visitor account is recorded;
[0107] Step l, if the visitor account is not logging out of the router for the first time, the time interval between each time node of the logout of the visitor account and the last time node of the logout is counted, and if it is detected that there are at least two time intervals less than a preset time interval in succession, the visitor account is prohibited from logging in again within a preset time period.
[0108] In the embodiment, when the router detects that the visitor account logs out of the router, that is, logs out of the visitor login system in the router, the time node of the logout of the visitor account each time is recorded in real time. For example, the visitor account logs out of the router at 3 pm, and the time node of the logout is 3 pm.
[0109] In the router, the time interval between each time node of the logout of the visitor account and the last time node of the logout is counted, and when it is detected that there are at least two time intervals less than a preset time interval in succession, it can be considered that the visitor account is maliciously logged in, and at this time, the visitor account can be prohibited from logging in again within a preset time period. The preset time interval can be any time interval set in advance by the user, such as 1 minute. The preset time period can be a time range set in advance by the administrator account, such as one day or one week. Alternatively, when the visitor account logs out for the first time, no statistical calculation is performed, and only when the visitor account logs out for the second time and subsequent logout operations, the step of counting the time interval between each time node of the logout of the visitor account is executed.
[0110] In this embodiment, when a guest account is detected to have logged out of the router, the logout time node is recorded, and when it is not the first time for the guest account to log out of the router, the time interval between each logout time node and the last logout time node is counted. If it is detected that there are at least two consecutive time intervals that are less than the preset time interval, the guest account can be prohibited from logging in again within the preset time period, thereby avoiding the phenomenon of malicious guest account logging into the router.
[0111] Furthermore, when it is detected that at least one guest account terminal is connected to the router, the step of detecting whether network access control needs to be performed on the guest account in the guest account terminal includes:
[0112] Step m: when detecting that at least one guest account terminal is connected to the router, obtaining user role tag information sent by the administrator account, wherein the user role tag information includes the user role corresponding to each guest account and the priority corresponding to the user role;
[0113] Step n: determining the user role corresponding to each guest account in the guest account terminal and the priority corresponding to each guest account based on the user role tag information;
[0114] In step o, if there exists a guest account corresponding to a priority level less than or equal to the preset priority level, it is determined that network access control needs to be performed on the guest account corresponding to the priority level less than or equal to the preset priority level.
[0115] In this embodiment, upon detecting that at least one guest account terminal has accessed the router, the administrator account can assign a user role to each guest account and set the priorities of different user roles. For example, the administrator account can assign user roles to three guest accounts, labeling them as family, relatives, and friends, respectively, and setting the priority order to family, relatives, and friends. Therefore, after obtaining the user role tagging information sent by the administrator account, the user role corresponding to each guest account and its corresponding priority can be directly determined. A determination can then be made based on the priority corresponding to each guest account to determine whether network access control is required. Furthermore, the priority corresponding to each guest account can be determined, and guest accounts with a priority less than or equal to a preset priority can be determined to require network access control. The preset priority can be any priority set in advance by the user, such as allowing only the user role with the highest priority to be exempt from network access control.
[0116] In this embodiment, when detecting that at least one guest account terminal is connected to the router, the user role tag information sent by the administrator account is obtained, and the user role corresponding to each guest account and its corresponding priority are determined based on the user role tag information, and network access control is performed on the guest accounts corresponding to the priority less than or equal to the preset priority, thereby achieving network management and control of low-priority guest accounts and ensuring network security.
[0117] Example 3
[0118] The present application also provides a router visitor management device, please refer to Figure 4 , the router visitor management and control device includes:
[0119] The detection module A10 is configured to detect whether network access control needs to be performed on the guest account in the guest account terminal when detecting that at least one guest account terminal is connected to the router;
[0120] A determination module A20, configured to determine the network behavior of the guest account if network access control is required for the guest account;
[0121] The control module A30 is used to determine a control policy for controlling network access based on the behavior type of the network behavior, and perform network access control on the guest account based on the control policy, wherein the control policy includes permission restrictions on network resources, network time, and number of network accesses.
[0122] Optionally, the control module A30 is configured to:
[0123] If there are multiple guest account terminals connected to the router, determine the user roles corresponding to the guest accounts of all guest account terminals connected to the router, wherein the user roles include at least a first user role and a second user role with a lower priority than the first user role;
[0124] If the behavior type of the network behavior corresponding to the second user role is occupying a large amount of bandwidth, and the network behaviors of the first user role and the second user role are in the same time period, then the control strategy for controlling network access is determined to limit the traffic of the guest account corresponding to the second user role, where occupying a large amount of bandwidth includes that the bandwidth usage ratio at a time node is greater than a preset threshold.
[0125] Optionally, the control module A30 is configured to:
[0126] Matching the behavior type of the network behavior with a preset network behavior whitelist;
[0127] If the behavior type matches the network behavior whitelist, determining that the control policy for controlling network access is to allow access to the network;
[0128] If the behavior type does not match the network behavior whitelist, then the behavior type is matched with a preset network behavior blacklist;
[0129] If the behavior type matches the network behavior blacklist, the control policy for controlling network access is determined to be limiting network access time.
[0130] Optionally, the control module A30 is configured to:
[0131] If the behavior type of the network behavior is to access restricted network resources, a control policy for controlling network access is determined to restrict the guest account from logging in to connect to the router, wherein the restricted network resources include at least NAS.
[0132] Optionally, the control module A30 is configured to:
[0133] Scoring the behavior type of the network behavior according to a preset scoring rule to obtain a scoring score;
[0134] Summarize the evaluation scores of all network behaviors of the guest account from the time of the last login to the router to the current time to obtain a target score;
[0135] A score interval in which the target score is located is determined, and a control policy corresponding to the score interval is used as a control policy for controlling network access, wherein there are at least two score intervals, and different score intervals correspond to different control policies.
[0136] Optionally, the control module A30 is configured to:
[0137] If it is detected that the guest account has logged out of the router, the logout time of the guest account is recorded;
[0138] If it is not the first time for the guest account to log out of the router, the time interval between each logout time node of the guest account and the last logout time node is counted;
[0139] If it is detected that at least two time intervals are consecutively shorter than the preset time interval, the guest account is prohibited from logging in again within the preset time period.
[0140] Optionally, the detection module A10 is configured to:
[0141] When detecting that at least one guest account terminal is connected to the router, obtaining user role tag information sent by the administrator account, wherein the user role tag information includes a user role corresponding to each guest account and a priority corresponding to the user role;
[0142] Determining, based on the user role tag information, a user role corresponding to each guest account in the guest account terminal and a priority corresponding to each guest account;
[0143] If there exists a guest account corresponding to a priority level less than or equal to the preset priority level, it is determined that network access control needs to be performed on the guest account corresponding to the priority level less than or equal to the preset priority level.
[0144] The router visitor control device provided in the embodiments of the present invention, employing the router visitor control method of any of the first and second embodiments above, can implement network control of guest accounts based on their network behavior. Compared to the prior art, the router visitor control device provided in the embodiments of the present invention has the same beneficial effects as the router visitor control method provided in the above embodiments. Other technical features of the router visitor control device are the same as those disclosed in the above embodiments and are not further elaborated here.
[0145] Example 4
[0146] An embodiment of the present invention provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the router visitor management method of the first embodiment above.
[0147] Reference below Figure 5 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. Figure 5 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.
[0148] like Figure 5 As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.
[0149] Typically, the following systems can be connected to the I / O interface: input devices such as a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices such as a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices such as a magnetic tape, hard disk, etc.; and communication devices. The communication device can allow the electronic device to communicate with other devices wirelessly or by wire to exchange data. Although the figures show electronic devices with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have instead.
[0150] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0151] The electronic device provided by the present invention utilizes the router visitor management method of the above-mentioned embodiment to implement network management of guest accounts based on their network behavior. Compared with the prior art, the beneficial effects of the electronic device provided by the embodiment of the present invention are the same as those of the router visitor management method provided by the above-mentioned embodiment. Other technical features of the electronic device are the same as those disclosed in the above-mentioned embodiment and are not further described here.
[0152] It should be understood that various parts of the present disclosure can be implemented with hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in an appropriate manner.
[0153] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
[0154] Example 5
[0155] An embodiment of the present invention provides a computer-readable storage medium having computer-readable program instructions stored thereon, and the computer-readable program instructions are used to execute the router visitor management and control method in the above embodiment.
[0156] The computer-readable storage medium provided in the embodiment of the present invention can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination thereof. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.
[0157] The computer-readable storage medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0158] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by an electronic device, the electronic device can perform the steps in the above embodiments.
[0159] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0160] The flow charts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the system, method and computer program product according to various embodiments of the present invention. In this regard, each box in the flow chart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0161] The modules involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0162] The computer-readable storage medium provided by the present invention stores computer-readable program instructions for executing the aforementioned router visitor management method, enabling network management of guest accounts based on their network behavior. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided by the embodiments of the present invention are the same as those of the router visitor management method provided by the aforementioned embodiments 1 or 2, and are not further elaborated here.
[0163] Example 6
[0164] An embodiment of the present invention further provides a computer program product, including a computer program, which implements the steps of the above-mentioned router visitor management and control method when executed by a processor.
[0165] The computer program product provided in this application enables network management and control of guest accounts based on their network behavior. Compared to the prior art, the beneficial effects of the computer program product provided in this embodiment of the present invention are the same as those of the router guest management and control method provided in any of the above embodiments, and will not be elaborated here.
[0166] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent processing scope of the present application.
Claims
1. A router visitor management and control method, characterized in that: The router visitor management method comprises the following steps: When detecting that at least one guest account terminal is connected to the router, detecting whether network access control needs to be performed on the guest account in the guest account terminal; If network access control is required for the guest account, determining the network behavior of the guest account; Determining a control policy for controlling network access based on the behavior type of the network behavior, and performing network access control on the guest account based on the control policy, wherein different behavior types correspond to different control policies, and the control policies include permission restrictions on network resources, network time, and number of network accesses. Determining the control policy for controlling network access based on the behavior type of the network behavior includes: determining the network access control policy based on the behavior type and the guest account terminal address or the scenario where the router is located; The step of detecting whether network access control needs to be performed on a guest account in the guest account terminal when detecting that at least one guest account terminal is connected to the router includes: When detecting that at least one guest account terminal is connected to the router, obtaining user role tag information sent by the administrator account, wherein the user role tag information includes a user role corresponding to each guest account and a priority corresponding to the user role; Determining, based on the user role tag information, a user role corresponding to each guest account in the guest account terminal and a priority corresponding to each guest account; If there exists a guest account whose corresponding priority is lower than the preset priority, it is determined that network access control needs to be performed on the guest account corresponding to the priority lower than the preset priority.
2. The router visitor management method according to claim 1, wherein: The step of determining a control strategy for controlling network access based on the behavior type of the network behavior includes: If there are multiple guest account terminals connected to the router, determine the user roles corresponding to the guest accounts of all guest account terminals connected to the router, wherein the user roles include at least a first user role and a second user role with a lower priority than the first user role; If the behavior type of the network behavior corresponding to the second user role is occupying a large amount of bandwidth, and the network behaviors of the first user role and the second user role are in the same time period, then the control strategy for controlling network access is determined to limit the traffic of the guest account corresponding to the second user role, where occupying a large amount of bandwidth includes that the bandwidth usage ratio at a time node is greater than a preset threshold.
3. The router visitor management and control method according to claim 1, wherein: The step of determining a control strategy for controlling network access based on the behavior type of the network behavior includes: Matching the behavior type of the network behavior with a preset network behavior whitelist; If the behavior type matches the network behavior whitelist, determining that the control policy for controlling network access is to allow access to the network; If the behavior type does not match the network behavior whitelist, then the behavior type is matched with a preset network behavior blacklist; If the behavior type matches the network behavior blacklist, the control policy for controlling network access is determined to be limiting network access time.
4. The router visitor management method according to claim 1, wherein: The step of determining a control strategy for controlling network access based on the behavior type of the network behavior includes: If the behavior type of the network behavior is to access restricted network resources, a control policy for controlling network access is determined to restrict the guest account from logging in to connect to the router, wherein the restricted network resources include at least NAS.
5. The method for managing and controlling router visitors according to claim 1, wherein: The step of determining a control strategy for controlling network access based on the behavior type of the network behavior includes: Scoring the behavior type of the network behavior according to a preset scoring rule to obtain a scoring score; Summarize the evaluation scores of all network behaviors of the guest account from the time of the last login to the router to the current time to obtain a target score; A score interval in which the target score is located is determined, and a control policy corresponding to the score interval is used as a control policy for controlling network access, wherein there are at least two score intervals, and different score intervals correspond to different control policies.
6. The method for managing and controlling router visitors according to any one of claims 1 to 5, wherein: After the step of performing network access control on the guest account according to the control policy, the method further includes: If it is detected that the guest account has logged out of the router, the logout time of the guest account is recorded; If it is not the first time for the guest account to log out of the router, the time interval between each logout time node of the guest account and the last logout time node is counted; If it is detected that at least two time intervals are consecutively less than the preset time interval, the guest account is prohibited from logging in again within the preset time period.
7. A router visitor management and control device, characterized in that: The router visitor management and control device includes: A detection module, configured to detect whether it is necessary to perform network access control on the guest account in the guest account terminal when detecting that at least one guest account terminal is connected to the router; wherein, the detecting whether it is necessary to perform network access control on the guest account in the guest account terminal when detecting that at least one guest account terminal is connected to the router comprises: obtaining user role tag information sent by an administrator account when detecting that at least one guest account terminal is connected to the router, wherein the user role tag information comprises a user role corresponding to each guest account and a priority corresponding to the user role; determining the user role corresponding to each guest account in the guest account terminal and the priority corresponding to each guest account based on the user role tag information; if there is a guest account corresponding to a priority lower than a preset priority, determining that it is necessary to perform network access control on the guest account corresponding to the priority lower than the preset priority; a determination module, configured to determine the network behavior of the guest account if network access control is required for the guest account; A control module is used to determine a control strategy for controlling network access based on the behavior type of the network behavior, and to control network access of the guest account based on the control strategy, wherein different behavior types correspond to different control strategies, and the control strategies include permission restrictions on network resources, network time, and the number of network accesses. The control strategy for controlling network access based on the behavior type of the network behavior includes: determining the network access control strategy based on the behavior type and the guest account terminal address or the scenario where the router is located.
8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the steps of the router visitor management method according to any one of claims 1 to 6.
9. A readable storage medium, characterized in that: The readable storage medium is a computer-readable storage medium, and a program for implementing the router visitor control method is stored on the computer-readable storage medium. The program for implementing the router visitor control method is executed by a processor to implement the steps of the router visitor control method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Wireless access point and bandwidth allocation method thereof
CN101594270A
Network access control device for mobile terminal and mobile terminal equipment
CN102118749A
Network access control method and device thereof
CN103516681A
Wireless network management method and system, electronic equipment and storage medium
CN110351719A