DPI-based iot terminal detection method, system and storage medium

CN116866241BActive Publication Date: 2026-09-25E SURFING IOT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311019272.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-11
Publication Date
2026-09-25
Estimated Expiration
2043-08-11

AI Technical Summary

Technical Problem

目前主要基于模组型号判断物联网卡是否用于真实物联网终端,由于外部环境和技术升级变化,存在终端IMEI篡改和老旧终端场景误判问题,现有检测方法无法对所有物联网卡是否用于真实物联网终端场景进行识别,物联网终端识别不够全面,精准度较低

Benefits of technology

[0014]本发明实施例提供了一种基于DPI的物联网终端检测方法、系统及存储介质。其中,所述方法包括:DPI数据采集平台采集物联网终端的二进制原始码流,并对所述二进制原始码流进行解码、合成、各协议关联、客户信息回填,形成DPI数据文件;实时数据处理平台基于文件分块剪枝提取算法对所述DPI数据文件进行分块剪枝得到有效内容,并对所述有效内容进行解析形成数据流;并行分治决策平台基于所述数据流使用并行决策树分类算法模型对物联网终端进行识别得到识别评价结果。本发明实施例的技术方案,先通过DPI数据采集平台能够快速采集形成DPI数据文件,再通过实时数据处理平台对DPI数据文件进行分块剪枝得到有效内容,并对所述有效内容进行解析形成数据流;最后通过并行分治决策平台对物联网终端进行识别得到识别评价结果,整个识别检测过程不仅避免了从单一终端属性维度进行错误识别,而且还可实现快速解析、高效数据处理以及精准结果分类,进而提升了物联网终端识别的全面性和精准性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116866241B_ABST
    Figure CN116866241B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a kind of based on DPI's internet of things terminal detection method, system and storage medium.The method belongs to the technical field of internet of things, it includes: DPI data acquisition platform acquires the binary original code stream of internet of things terminal, and the binary original code stream is decoded, synthesis, each protocol association, customer information backfilling, forms DPI data file;Real-time data processing platform is based on file block pruning extraction algorithm to the DPI data file is blocked and pruned to obtain effective content, and the effective content is parsed to form data stream;Parallel divide and conquer decision platform is based on the data stream using parallel decision tree classification algorithm model and identifies internet of things terminal to obtain identification evaluation result.The embodiment of the application not only avoids from single terminal attribute dimension to carry out error identification, and also can realize fast analysis, efficient data processing and accurate result classification, to further improve the comprehensiveness and accuracy of internet of things terminal identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, and in particular to a DPI-based IoT terminal detection method, system, and storage medium. Background Technology

[0002] IoT SIM cards use their own dedicated IoT number segments and support basic communication services including SMS, wireless data, and voice through dedicated network elements. They provide intelligent connectivity services such as autonomous communication connection management and terminal management for IoT terminals. Currently, determining whether an IoT SIM card is used in a real IoT terminal is mainly based on the module model. However, due to changes in the external environment and technological upgrades, there are issues with terminal IMEI tampering and misjudgments in older terminal scenarios. Existing detection methods cannot identify whether all IoT SIM cards are used in real IoT terminal scenarios, resulting in incomplete and low-accuracy IoT terminal identification. Summary of the Invention

[0003] This invention provides a DPI-based method, system, and storage medium for detecting IoT terminals, aiming to improve the comprehensiveness and accuracy of existing IoT terminal identification.

[0004] In a first aspect, embodiments of the present invention provide a DPI-based method for detecting IoT terminals, comprising:

[0005] The DPI data acquisition platform collects the binary raw code stream from IoT terminals, and decodes, synthesizes, associates various protocols, and backfills customer information into the binary raw code stream to form a DPI data file.

[0006] The real-time data processing platform uses a file block pruning and extraction algorithm to prune the DPI data file to obtain effective content, and then parses the effective content to form a data stream.

[0007] The parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model to identify IoT terminals based on the data stream and obtain identification evaluation results.

[0008] Secondly, embodiments of the present invention also provide a DPI-based IoT terminal detection system, comprising: a data acquisition unit configured in a DPI data acquisition platform, a block pruning unit configured in a real-time data processing platform, and an identification unit configured in a parallel divide-and-conquer decision-making platform, wherein...

[0009] The acquisition unit is used by the DPI data acquisition platform to acquire the binary raw code stream of the Internet of Things terminal, and to decode, synthesize, associate various protocols, and backfill customer information into the binary raw code stream to form a DPI data file.

[0010] The block pruning unit is used by the real-time data processing platform to perform block pruning on the DPI data file based on the file block pruning extraction algorithm to obtain effective content, and to parse the effective content to form a data stream;

[0011] The identification unit is used by the parallel divide-and-conquer decision platform to identify IoT terminals based on the data stream using a parallel decision tree classification algorithm model to obtain identification evaluation results.

[0012] Thirdly, embodiments of the present invention also provide a DPI-based IoT terminal detection system, which includes a DPI data acquisition platform, a real-time data processing platform, and a row-divide-and-conquer decision platform. Each of the DPI data acquisition platform, the real-time data processing platform, and the row-divide-and-conquer decision platform includes a memory and a processor. The memory stores a computer program. When the processor of the DPI data acquisition platform, the real-time data processing platform, and the row-divide-and-conquer decision platform executes the computer program, it implements the above-described method.

[0013] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the above-described method.

[0014] This invention provides a method, system, and storage medium for detecting IoT terminals based on Data Point Injection (DPI). The method includes: a DPI data acquisition platform acquiring the binary raw code stream of the IoT terminal, decoding, synthesizing, associating various protocols, and backfilling customer information into the binary raw code stream to form a DPI data file; a real-time data processing platform performing block pruning on the DPI data file using a file block pruning extraction algorithm to obtain effective content, and parsing the effective content to form a data stream; and a parallel divide-and-conquer decision platform using a parallel decision tree classification algorithm model to identify the IoT terminal and obtain an identification evaluation result. The technical solution of this invention first uses a DPI data acquisition platform to quickly acquire and form a DPI data file, then uses a real-time data processing platform to perform block pruning on the DPI data file to obtain effective content, and then parses the effective content to form a data stream; finally, the parallel divide-and-conquer decision platform identifies the IoT terminal to obtain an identification evaluation result. The entire identification and detection process not only avoids erroneous identification from a single terminal attribute dimension, but also achieves rapid parsing, efficient data processing, and accurate result classification, thereby improving the comprehensiveness and accuracy of IoT terminal identification. Attached Figure Description

[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 A schematic diagram of a DPI-based Internet of Things (IoT) terminal detection system provided in an embodiment of the present invention;

[0017] Figure 2 A flowchart illustrating a DPI-based IoT terminal detection method provided in an embodiment of the present invention;

[0018] Figure 3 A schematic diagram of a sub-process of an IoT terminal detection method based on DPI provided in an embodiment of the present invention;

[0019] Figure 4 A schematic diagram of a sub-process of an IoT terminal detection method based on DPI provided in an embodiment of the present invention;

[0020] Figure 5 A schematic diagram of a sub-process of an IoT terminal detection method based on DPI provided in an embodiment of the present invention;

[0021] Figure 6 A schematic diagram of access application feature engineering in a DPI-based IoT terminal detection method provided in an embodiment of the present invention;

[0022] Figure 7 This is a schematic diagram of parallel decision tree classification in a DPI-based IoT terminal detection method provided in an embodiment of the present invention;

[0023] Figure 8 This is a schematic diagram of a sub-process in a DPI-based IoT terminal detection method provided in an embodiment of the present invention;

[0024] Figure 9 This is a schematic diagram of the prediction result output in a DPI-based IoT terminal detection method provided in an embodiment of the present invention.

[0025] Figure 10 A schematic block diagram of a DPI-based Internet of Things (IoT) terminal detection system provided for an embodiment of the present invention;

[0026] Figure 11 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. Detailed Implementation

[0027] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0028] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0029] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0030] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0031] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrases "if determined" or "if [described condition or event] is detected" may be interpreted, depending on the context, as "once determined," "in response to determination," "once [described condition or event] is detected," or "in response to detection of [described condition or event]."

[0032] Please see Figure 1 , Figure 1 This is a schematic diagram of a DPI-based IoT terminal detection system provided in an embodiment of the present invention. The DPI-based IoT terminal detection system includes a DPI data acquisition platform, a real-time data processing platform, and a row-divide-and-conquer decision-making platform. It should be noted that... Figure 1 The data acquisition system is a DPI data acquisition platform, and the real-time data processing system is a real-time data processing platform. Specifically, such as... Figure 1As shown, the data acquisition system collects log information from each provincial node (e.g., provincial node 1, provincial node 2, provincial node 3, and provincial node 4) using DPI (Deep Packet Inspection). This log information is then processed by big data front-end nodes 1, 2, 3, and 4 to obtain the processed log information. This log information includes communication logs and full internet access logs. Understandably, as... Figure 1 As shown, in this embodiment, each provincial node can also send network security event logs, feature rule instructions, and traffic filtering instructions to the real-time data processing system. It should also be noted that in this embodiment, the real-time data processing platform communicates with the DPI data acquisition platform and the parallel divide-and-conquer decision-making platform. Data processing is performed after this connection, which not only avoids incorrect identification based on a single terminal attribute dimension but also enables rapid parsing, efficient data processing, and accurate result classification, thereby improving the comprehensiveness and accuracy of IoT terminal identification.

[0033] Figure 2 This is a flowchart illustrating a DPI-based IoT terminal detection method provided in an embodiment of the present invention. The DPI-based IoT terminal detection method of this invention can be applied to a DPI-based IoT terminal detection system. For example, it can be implemented through software programs configured on the DPI-based IoT terminal detection system to improve the comprehensiveness and accuracy of IoT terminal identification. Figure 2 As shown, the method includes the following steps S100-S120.

[0034] The S100 and DPI data acquisition platform collect the binary raw code stream from IoT terminals, and decode, synthesize, associate various protocols, and backfill customer information into the binary raw code stream to form a DPI data file.

[0035] In this embodiment of the invention, the DPI data acquisition platform is equipped with DPI acquisition devices in the form of spectrometers, mirroring systems, and aggregation / splitting mechanisms. It should be noted that the DPI data acquisition platform includes acquisition probes, a DPI data synthesis module, aggregation and splitting devices, and a storage module. The DPI data acquisition platform collects network behavior data from IoT terminals and performs decoding, synthesis, protocol association, and customer information backfilling to form a DPI data file. The DPI data file is XDR (Extended Detection and Response) call log data. Specifically, the acquisition probes collect binary raw bitstreams from the user plane and signaling plane of IoT terminals at the core network element interface. These binary raw bitstreams are decoded and synthesized to obtain a synthesized bitstream, which is then sent to the DPI data synthesis module. The DPI data synthesis module performs protocol association and customer information backfilling on the synthesized bitstream to form a target bitstream. The aggregation and splitting device sends the target bitstream to the storage module for storage, thereby generating the DPI data file.

[0036] S110. The real-time data processing platform performs block pruning on the DPI data file based on the file block pruning extraction algorithm to obtain effective content, and parses the effective content to form a data stream.

[0037] In embodiments of the present invention, such as Figure 3 As shown, step S110 may include the following steps S111-S114: S111, the real-time data processing platform constructs a tag tree based on the file block pruning extraction algorithm, and sets weights and fractal thresholds for each block stage in the file block pruning extraction algorithm from bottom to top; S112, the real-time data processing platform performs block pruning on the DPI data file according to the set weights and fractal thresholds until all useless information nodes are removed to obtain effective content, wherein the fractal thresholds are continuously adjusted during the block pruning process; S113, the effective content is parsed to generate multi-stream business data streams, and the multi-stream business data streams are integrated to form an initial data stream; S114, content-class variables are added to store parsing operators to dynamically parse the initial data stream to form the data stream. More specifically, step S114 is as follows: Figure 4As shown, it specifically includes the following steps S1141-S1145: S1141, configuring a temporary data flow variable in said initial data flow, and adding a content-type variable to store the parsed stream processing operator; S1142, acquiring the parsing logic of current data by parsing said temporary data flow variable to update said stream processing operator; S1143, generating a hash key-value pair according to the name corresponding to said initial data flow, and storing said key-value pair and said stream processing operator in a hash list; S1144, calculating a stream processing result according to said stream processing operator, updating said stream processing result with the key value in said hash key-value pair until all said stream processing operators are traversed, to obtain a target hash key-value pair; S1145, parsing said target hash key-value pair to generate structured parsing data, and taking said structured parsing data as said data flow.

[0038] For ease of understanding, the specific operation steps executed on the real-time data processing platform are introduced as follows:

[0039] Step 1: Based on the file block pruning extraction algorithm, construct a label tree, and assign weights to each block stage from bottom to top;

[0040] Step 2: If the block node is a leaf node, assign its weight ω i = 1, if the node is a non-leaf node and N is the set of all child nodes of the node, its weight ω i = ∑ j∈N ω j ;

[0041] Step 3: Assign the maximum weight of sibling nodes as ω max , set a variable Q as a fractal threshold, and prune node i when R < Q;

[0042] Step 4: Continuously call the file block pruning extraction algorithm to remove all useless information nodes, and parse the valid content of the file into a data flow dataStream i .

[0043] Step 5: Through the real-time data processing platform with a distributed stream architecture, implement concurrent parsing of multi-stream service data flow dataStream i and integrate them to form dataStream;

[0044] Step 6: Configure an empty data flow temp in dataStream, and add a content-type variable for storing the parsed operator β;

[0045] Step 7: Preferentially parse the data flow temp, acquire the parsing logic of current data by parsing temp data, and update the parsed operator β;

[0046] Step 8: Store the name of each data stream to be processed using a hashmap, and generate...<key,value> =<stream,datastream> Simultaneously, the operators for data stream processing are stored in a hashlist;

[0047] Step 9: Calculate the stream processing result according to the stream processing operators on the datastream;

[0048] Step 10: Update the value of the stream in the hashmap to data-set;

[0049] Step 11: Traverse the next operator to be processed, read the value of key = stream, and perform the same parsing logic on the value of stream to obtain the dataset;

[0050] Step 12: Iterate through each operator of the data stream processing until all parsing logic is completed, and finally store the result in the stream;

[0051] Step 13: Parse the datastream again, use the latest parsing logic to process the data, generate structured DPI parsing data dpi_net_d, realize real-time control of the parsing logic, and ensure continuous and uninterrupted real-time parsing.

[0052] It should be noted that, in this embodiment, the real-time data processing platform is based on a file segmentation and pruning extraction algorithm. By pruning and segmenting the DPI data file, it integrates IoT traffic data, business acceptance data, RADIUS data, and real-time alarm data. Through comprehensive data analysis and dynamic matching, it establishes a real-time, reliable, and accurate risk identification and processing process. The optimized data processing engine supports millisecond-level processing capability for TB-level risk data.

[0053] S120. The parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model to identify IoT terminals based on the data stream and obtain identification evaluation results.

[0054] In embodiments of the present invention, such as Figure 5As shown, step S120 specifically includes steps S121-S122: S121, the parallel divide-and-conquer decision platform establishes an access application feature engineering based on the data stream, wherein the access application feature engineering includes the access terminal name, access terminal OS, access terminal CPU, access browser, access application category, access protocol, access time, access traffic, and access data packet size; S122, the access application feature engineering is input into the parallel decision tree classification algorithm model to identify the IoT terminal and obtain the identification evaluation result, wherein the parallel decision tree classification algorithm model includes a tree building module, an update module, a classification module, and an evaluation module. Specifically, as shown... Figure 6 As shown, step S122 may specifically include steps S1221-S1224: S1221, inputting training samples into the tree building module, so that the tree building module splits the access application feature engineering and adds leaf nodes to build an initial tree by means of preset constraint rules; S1222, inputting the access application feature engineering into the update module, so that the update module updates the initial tree according to the nodes in the access application feature engineering to obtain an updated tree; S1223, inputting unclassified samples into the classification module to classify the updated tree to obtain a classification tree; S1224, inputting the classification tree and test samples into the evaluation module to obtain the recognition evaluation result.

[0055] To facilitate understanding, the specific operational steps performed in the divide-and-conquer decision-making platform are described below:

[0056] Step 1: As Figure 7 As shown, an application access feature engineering is established through data flow. This feature engineering includes terminal name, terminal OS, terminal CPU, browser, application category, access protocol, access time, access traffic, and data packet size. It should be noted that the application access feature engineering is... Figure 7 DPI feature engineering in;

[0057] Step 2: As Figure 8 As shown, a parallel decision tree classification algorithm is used, comprising a tree construction module, an update module, an evaluation module, and a classification module. It should be noted that... Figure 8 In this module, the samples to be classified by the decision tree are access application feature engineering, the tree building module is the Hoeffding tree building module, the classification module is the decision tree classification module, and the evaluation module is the algorithm evaluation module.

[0058] Step 3: The tree building module performs splitting based on Hoeffding constraints and other relevant requirements. The number of new leaf nodes is equal to the number of values ​​of the decision attribute of that leaf node. This process is recursively performed to build the tree.

[0059] Step 4: Using the input training samples, call the method of inserting leaf nodes of the decision tree to insert the training samples from the root node to the corresponding leaf nodes, and update the statistical information of the leaf nodes.

[0060] Step 5: The update module inserts each training sample used for updating from the root node of the current decision tree until it is sorted to the leaf node. The statistical values ​​of the leaf node are updated accordingly. When the statistical values ​​meet the calculation requirements, the information gain of each attribute of the leaf node and the Hoeffding boundary value at this time are calculated.

[0061] Step 6: Determine whether to split the leaf node based on the Hoeffding value and other requirements, and output an continuously updated decision tree for classification during the process;

[0062] Step 7: Input unclassified samples into the classification module, and call the method to find the leaf node corresponding to the sample to find the correct leaf node in a certain order;

[0063] Step 8: Assign the leaf node to the class to which the prediction belongs and output the prediction result, as shown in the output. Figure 9 As shown, in Figure 9 In this context, the terminals include various devices such as modules, modems, smartphones, and mobile phones. Understandably, the parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model to identify various terminals.

[0064] Step 9: Call the evaluation method to evaluate the current decision tree model using parameters such as recall, precision, and resource occupancy.

[0065] Step 10: Optimize and improve the model based on the monitoring results to increase the accuracy of monitoring.

[0066] It should be noted that in this embodiment, the parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model to identify and verify IoT terminals. The parallel decision tree classification algorithm model can be evaluated from three aspects: precision, recall, and resource utilization. The higher the precision of the model, the higher the probability that a terminal is identified as a real IoT terminal. The higher the recall of the model, the more comprehensively it can detect non-IoT terminals among the terminals under test. The lower the resource utilization, the more efficient the algorithm is.

[0067] It should also be noted that, in this embodiment, by segmenting the DPI data file, extracting field content based on the weight of tree nodes, continuously pruning, and removing invalid information nodes and fields, the parsing of useless information is reduced, thus comprehensively improving file parsing efficiency; by dynamically and automatically adjusting the data parsing process through data parsing stream processing operators, the data is ensured to be without loss and complete, thereby significantly improving real-time data processing capabilities; by constructing real-time behavioral feature engineering, misjudgments caused by judging from a single dimension of terminal IMEI information are fundamentally avoided, improving the precision and recall of subsequent detection, and facilitating the generation of a list of non-IoT real terminals; by decomposing the original computing task into several sub-tasks for processing, and using each computer node to balance the load, the computing resource requirements are greatly saved, ensuring high-speed, high-quality updates and output of recognition results.

[0068] Figure 10 This is a schematic block diagram of a DPI-based Internet of Things (IoT) terminal detection system 200 provided in an embodiment of the present invention. Figure 10 As shown, corresponding to the DPI-based IoT terminal detection method applied to the DPI data acquisition platform, real-time data processing platform, and row-divide-and-conquer decision platform described above, the DPI-based IoT terminal detection system 200 includes a unit for executing the aforementioned DPI-based IoT terminal detection method. Specifically, please refer to... Figure 10 The DPI-based IoT terminal detection system 200 includes an acquisition unit 101 configured in the DPI data acquisition platform, a block pruning unit 201 configured in the real-time data processing platform, and an identification unit 301 configured in the parallel divide-and-conquer decision platform.

[0069] The acquisition unit 101 is used by the DPI data acquisition platform to acquire the binary raw code stream of the IoT terminal, and to decode, synthesize, associate various protocols, and backfill customer information in the binary raw code stream to form a DPI data file; the block pruning unit 201 is used by the real-time data processing platform to perform block pruning on the DPI data file based on the file block pruning extraction algorithm to obtain effective content, and to parse the effective content to form a data stream; the identification unit 301 is used by the parallel divide-and-conquer decision platform to identify the IoT terminal based on the data stream using a parallel decision tree classification algorithm model to obtain identification evaluation results.

[0070] In some embodiments, such as this one, the acquisition unit 101 includes an acquisition subunit, an association backfilling unit, and a storage generation unit.

[0071] The acquisition subunit is used to acquire binary raw code streams from the core network element interface of the Internet of Things terminal user plane and signaling plane through the acquisition probe, and decode and synthesize the binary raw code streams to obtain a synthesized code stream, which is then sent to the DPI data synthesis module. The association backfilling unit is used by the DPI data synthesis module to perform protocol association and customer information backfilling on the synthesized code stream to form a target code stream. The storage and generation unit is used by the aggregation and distribution device to send the target code stream to the storage module for storage to generate the DPI data file.

[0072] In some embodiments, such as this one, the block pruning unit 201 includes a construction setting unit, a culling unit, a first parsing unit, and a second parsing unit.

[0073] The construction and setting unit is used by the real-time data processing platform to construct a label tree based on the file block pruning extraction algorithm, and to set weights and fractal thresholds for each block stage in the file block pruning extraction algorithm from bottom to top; the elimination unit is used by the real-time data processing platform to perform block pruning on the DPI data file according to the set weights and fractal thresholds until all useless information nodes are eliminated to obtain effective content, wherein the fractal thresholds are continuously adjusted during the block pruning process; the first parsing unit is used to parse the effective content to generate multi-stream business data streams, and to integrate the multi-stream business data streams to form an initial data stream; the second parsing unit is used to add content-class variables to store parsing operators to dynamically parse the initial data stream to form the data stream.

[0074] In some embodiments, such as this embodiment, the second parsing unit includes an add storage unit, a first update unit, a generate storage unit, a second update unit, and a third parsing unit.

[0075] The storage unit is configured to configure temporary data stream variables in the initial data stream and add content-type variables to store the parsed stream processing operators. The first update unit is used to obtain the parsing logic of the current data by parsing the temporary data stream variables to update the stream processing operators. The storage unit generates hash key-value pairs according to the name corresponding to the initial data stream and stores the key-value pairs and the stream processing operators in a hash list. The second update unit calculates the stream processing result according to the stream processing operators and updates the stream processing result with the key-value pairs in the hash key-value pairs until all the stream processing operators have been traversed to obtain the target hash key-value pairs. The third parsing unit parses the target hash key-value pairs to generate structured parsed data and uses the structured parsed data as the data stream.

[0076] In some embodiments, such as this one, the identification unit 301 includes an establishment unit and an input identification unit.

[0077] The establishment unit is used by the parallel divide-and-conquer decision platform to establish an access application feature engineering based on the data stream. The access application feature engineering includes the access terminal name, access terminal OS, access terminal CPU, access browser, access application category, access protocol, access time, access traffic, and access data packet size. The input recognition unit is used to input the access application feature engineering into the parallel decision tree classification algorithm model to identify the IoT terminal and obtain the recognition evaluation result.

[0078] In some embodiments, such as this one, the input recognition unit includes an establishment subunit, a third update unit, a classification unit, and a recognition subunit.

[0079] The tree-building subunit is used to input training samples into the tree-building module, so that the tree-building module can split the access application feature engineering according to preset constraint rules to add leaf nodes to build an initial tree; the third update unit is used to input the access application feature engineering into the update module, so that the update module can update the initial tree according to the nodes in the access application feature engineering to obtain an updated tree; the classification unit is used to input unclassified samples into the classification module to classify the updated tree to obtain a classification tree; the recognition subunit is used to input the classification tree and test samples into the evaluation module to obtain recognition and evaluation results.

[0080] It should be noted that those skilled in the art can clearly understand that the specific implementation process of the DPI-based IoT terminal detection system 200 and its various units can be found in the corresponding descriptions in the foregoing method embodiments. For the sake of convenience and brevity, these details will not be repeated here.

[0081] The aforementioned DPI-based IoT terminal detection system can be implemented as a computer program, which can be used in, for example... Figure 11 It runs on the computer device shown.

[0082] Please see Figure 11 , Figure 11 This is a schematic block diagram of a computer device provided in an embodiment of this application. The computer device 900 is a device equipped with a DPI-based Internet of Things (IoT) terminal detection system.

[0083] See Figure 11 The computer device 900 includes a processor 902, a memory, and an interface 907 connected via a system bus 901, wherein the memory may include a storage medium 903 and internal memory 904.

[0084] The storage medium 903 may store an operating system 9031 and a computer program 9032. When the computer program 9032 is executed, it enables the processor 902 to execute a DPI-based Internet of Things (IoT) terminal detection method.

[0085] The processor 902 provides computing and control capabilities to support the operation of the entire computer device 900.

[0086] The internal memory 904 provides an environment for the operation of the computer program 9032 in the storage medium 903. When the computer program 9032 is executed by the processor 902, the processor 902 can execute a DPI-based Internet of Things terminal detection method.

[0087] This interface 905 is used for communication with other devices. Those skilled in the art will understand that... Figure 11 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device 900 to which the present application is applied. The specific computer device 900 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0088] The processor 902 of each of the DPI data acquisition platform, real-time data processing platform and row-divide-and-conquer decision platform is used to run a computer program 9032 stored in the memory to implement any embodiment of the above-described DPI-based IoT terminal detection method.

[0089] It should be understood that in the embodiments of this application, the processor 902 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0090] It will be understood by those skilled in the art that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a storage medium, which is a computer-readable storage medium. The computer program is executed by at least one processor in the wireless communication system to implement the process steps of the embodiments of the above methods.

[0091] Therefore, the present invention also provides a storage medium. This storage medium can be a computer-readable storage medium. The storage medium stores a computer program. When executed by a processor, the computer program causes the processor to perform any of the embodiments of the DPI-based IoT terminal detection method described above.

[0092] The storage medium can be any computer-readable storage medium capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), magnetic disk, or optical disk.

[0093] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, wireless communication software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0094] In the embodiments provided by this invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of each unit is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0095] The steps in the method of this invention can be adjusted, merged, or reduced in order according to actual needs. The units in the system of this invention can be merged, divided, or reduced according to actual needs. Furthermore, the functional units in the various embodiments of this invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0096] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This wireless communication software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal wireless communication device, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0097] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0098] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Since these modifications and variations fall within the scope of the claims and their equivalents, this invention also intends to include these modifications and variations.

[0099] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A DPI-based method for detecting IoT terminals, characterized in that, include: The DPI data acquisition platform collects the binary raw code stream from IoT terminals, and decodes, synthesizes, associates various protocols, and backfills customer information into the binary raw code stream to form a DPI data file. The real-time data processing platform uses a file block pruning and extraction algorithm to prune the DPI data file to obtain effective content, and then parses the effective content to form a data stream. The parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model to identify IoT terminals based on the data stream and obtain identification evaluation results; The real-time data processing platform uses a file chunking and pruning extraction algorithm to prune the DPI data file to obtain valid content, and then parses the valid content to form a data stream, including: The real-time data processing platform constructs a label tree based on the file block pruning and extraction algorithm, and sets weights and fractal thresholds for each block stage in the file block pruning and extraction algorithm from bottom to top; The real-time data processing platform performs block pruning on the DPI data file according to the set weights and fractal thresholds until all useless information nodes are removed to obtain effective content. During the block pruning process, the fractal thresholds are continuously adjusted. The valid content is parsed to generate multi-stream business data streams, and the multi-stream business data streams are integrated to form an initial data stream; Add content-class variables to store parsing operators to dynamically parse the initial data stream to form the data stream.

2. The DPI-based IoT terminal detection method according to claim 1, characterized in that, The DPI data acquisition platform includes a acquisition probe, a DPI data synthesis module, a convergence and splitting device, and a storage module. The DPI data acquisition platform acquires binary raw bitstreams accessed by IoT terminals, and decodes, synthesizes, associates various protocols, and backfills customer information into the binary raw bitstreams to form a DPI data file, including: The acquisition probe collects binary raw code streams from the core network element interface of the Internet of Things terminal user plane and signaling plane, and decodes and synthesizes the binary raw code streams to obtain a synthesized code stream, which is then sent to the DPI data synthesis module. The DPI data synthesis module performs protocol association and customer information backfilling on the synthesized bitstream to form the target bitstream. The convergence and splitting device sends the target bitstream to the storage module for saving, thereby generating the DPI data file.

3. The DPI-based IoT terminal detection method according to claim 1, characterized in that, The addition of content-class variables to store parsing operators for dynamically parsing the initial data stream to form the data stream includes: Configure temporary data stream variables in the initial data stream, and add content-class variables to store the parsed stream processing operators; The parsing logic for obtaining the current data by parsing the temporary variables of the data stream is used to update the stream processing operator; Hash key-value pairs are generated based on the names corresponding to the initial data stream, and the key-value pairs and the stream processing operators are stored in a hash list; The stream processing result is calculated based on the stream processing operator, and the key value in the hash key-value pair is used to update the stream processing result until all the stream processing operators have been traversed to obtain the target hash key-value pair. The target hash key-value pairs are parsed to generate structured parsed data, and the structured parsed data is used as the data stream.

4. The DPI-based IoT terminal detection method according to claim 1, characterized in that, The parallel divide-and-conquer decision platform uses a parallel decision tree classification algorithm model based on the data stream to identify IoT terminals and obtain identification evaluation results, including: The parallel divide-and-conquer decision-making platform establishes an access application feature engineering based on the data stream, wherein the access application feature engineering includes the access terminal name, access terminal OS, access terminal CPU, access browser, access application category, access protocol, access time, access traffic, and access data packet size. The access application feature engineering is input into the parallel decision tree classification algorithm model to identify IoT terminals and obtain identification evaluation results.

5. The DPI-based IoT terminal detection method according to claim 4, characterized in that, The parallel decision tree classification algorithm model includes a tree building module, an update module, a classification module, and an evaluation module; The step of inputting the access application feature engineering into the parallel decision tree classification algorithm model to identify IoT terminals and obtain identification evaluation results includes: The training samples are input into the tree building module, so that the tree building module splits the access application feature engineering by adding leaf nodes according to preset constraint rules to build an initial tree; The access application feature engineering is input into the update module, so that the update module updates the initial tree according to the nodes in the access application feature engineering to obtain an updated tree; Unclassified samples are input into the classification module to classify the updated tree to obtain a classification tree; The classification tree and test samples are input into the evaluation module to obtain the recognition evaluation results.

6. A DPI-based IoT terminal detection system, characterized in that, include: The data acquisition unit is configured in the DPI data acquisition platform, the block pruning unit is configured in the real-time data processing platform, and the recognition unit is configured in the parallel divide-and-conquer decision-making platform. The acquisition unit is used by the DPI data acquisition platform to acquire the binary raw code stream of the Internet of Things terminal, and to decode, synthesize, associate various protocols, and backfill customer information into the binary raw code stream to form a DPI data file. The block pruning unit is used by the real-time data processing platform to perform block pruning on the DPI data file based on the file block pruning extraction algorithm to obtain effective content, and to parse the effective content to form a data stream; The identification unit is used by the parallel divide-and-conquer decision platform to identify IoT terminals based on the data stream using a parallel decision tree classification algorithm model to obtain identification evaluation results; The segmented pruning unit includes: The construction setting unit is used by the real-time data processing platform to construct a label tree based on the file block pruning and extraction algorithm, and to set weights and fractal thresholds for each block stage in the file block pruning and extraction algorithm from bottom to top. The pruning unit is used by the real-time data processing platform to perform block pruning on the DPI data file according to the set weight and the fractal threshold until all useless information nodes are removed to obtain effective content. The fractal threshold is continuously adjusted during the block pruning process. The first parsing unit is used to parse the valid content to generate a multi-stream business data stream, and to integrate the multi-stream business data stream to form an initial data stream. The second parsing unit is used to add content-class variables to store parsing operators to dynamically parse the initial data stream to form the data stream.

7. A DPI-based IoT terminal detection system, characterized in that, The system includes a DPI data acquisition platform, a real-time data processing platform, and a row-divide-and-conquer decision platform. Each of the DPI data acquisition platform, the real-time data processing platform, and the row-divide-and-conquer decision platform includes a memory and a processor. The memory stores a computer program. When the processor of the DPI data acquisition platform, the real-time data processing platform, and the row-divide-and-conquer decision platform executes the computer program, it implements the method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The storage medium stores a computer program that, when executed by a processor, can implement the method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Parallel AP propagating XML big data clustering integration method

    CN103942318A

  • User portrait identification method based on DPI analysis and decision tree model

    CN113312531A