A distributed terminal entity identity identification method and system based on multi-dimensional attributes

Through a distributed terminal entity identity identification method with multi-dimensional attributes, combined with stateless port detection and deep learning, a unique identity for the terminal is constructed, which solves the problem of terminal identity recognition and dynamic authorization in new energy power stations and realizes efficient security event monitoring and management.

CN118827141BActive Publication Date: 2025-10-10NARI INFORMATION & COMM TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410708927.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2025-10-10
Estimated Expiration
2044-06-03

AI Technical Summary

Technical Problem

Existing technologies make it difficult to achieve accurate identity recognition and dynamic authorization of terminals in new energy power stations, and face the risks of network attacks such as terminal forgery and data tampering. Traditional security protection is unable to cope with the situation of blurred network boundaries and automated attack methods.

Method used

A distributed terminal entity identity identification method based on multi-dimensional attributes is adopted. Through stateless port detection, deep learning Transformer model and channel state information, combined with terminal attributes and behavioral characteristics, a unique identity is constructed to achieve efficient identity recognition and fine-grained access control.

Benefits of technology

It improves the accuracy and security of terminal identity recognition, enhances the monitoring and management capabilities of network entities, and improves the security protection capabilities of new energy power stations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827141B_ABST
    Figure CN118827141B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of network security, and the method comprises the following steps: using a stateless port detection technology to identify the living devices in the network and determine the device living state, and optimizing the detection technology by scanning space; extracting network entity terminal characteristics and behavior element information; using a Transformer model in deep learning to implicitly represent the behavior characteristics of the network entity, combining with the attribute characteristics of the entity, constructing a unique network entity identity identification for identity verification. The present application realizes four-dimensional high-strength identity identification of network space terminal device security, personnel safety, application / service security and operation safety, multi-dimensional characterization and identity identification of network space access personnel, application and terminal device, realizes safe and efficient access of new energy power station distributed power supply terminal, fine-grained fine access control and rapid security event monitoring response, and supports the improvement of the security protection capability of new power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and in particular relates to a distributed terminal entity identity identification method and system based on multi-dimensional attributes. Background Art

[0002] With the continuous development of new energy sources such as wind, solar, and biomass, the number of terminals and system grid connection points has increased significantly. Static network boundary protection measures are unable to cover complex system structures and respond to ever-changing attack methods. New energy power station terminals are diverse and numerous, facing the risk of network attacks such as terminal counterfeiting and data tampering. As networks expand and boundaries become increasingly blurred, static address-based terminal identity authentication methods are difficult to guarantee the trustworthiness of terminals and lack monitoring of terminal behavior and dynamic authorization and access control. Therefore, ensuring the accurate identification of the unique identity of new energy terminals and the ability to dynamically authorize and control permissions have become the most important prerequisites for the development of source-grid interaction in new power systems.

[0003] Existing terminal authentication methods based on static addresses struggle to guarantee terminal trustworthiness and lack monitoring of terminal behavior, dynamic authorization, and access control, exposing new energy power plants to terminal security access risks. One approach uses a cryptographic hash function, taking the attribute values ​​of the new energy terminal entity as input and generating a fixed-length hash value as an identifier. Another approach utilizes distributed ledger technologies, such as blockchain, to store entity attribute information in a distributed network and use a unique identifier on the blockchain to represent the entity's identity. However, existing technologies also have several issues and shortcomings. First, the selection and combination of attributes can be subjective and inconsistent, potentially compromising the uniqueness of identifiers. Second, distributed ledger technology presents challenges in storing and transmitting large amounts of attribute data, as well as privacy and security concerns regarding on-chain data. Furthermore, the implementation and adoption of this technology requires extensive collaboration and standardization. With the rapid development of new energy, the demand for distributed new energy grid integration is increasing significantly. Traditional static, homogeneous, and deterministic security architectures struggle to cope with the blurring of network boundaries and automated attack vectors.

[0004] With the rapid development of both centralized and distributed renewable energy power generation facilities, the current protection of renewable energy power sources and their grid-connected systems presents significant risks. The static nature of these networks makes them vulnerable to group-based, large-scale cyberattacks. If attackers target renewable energy systems, this could impact the secure and stable supply of electricity. There is an urgent need to develop a new, efficient, convenient, and easily scalable protection model for renewable energy power station terminals, centralized control stations, and security facilities. Summary of the Invention

[0005] In view of the above-mentioned existing problems, the present invention is proposed. The present invention proposes a distributed terminal entity identification method and system based on multi-dimensional attributes. The method and system combine the multi-dimensional attributes of the terminal entity on the distributed power supply side to form a unique identifier to ensure accurate identity recognition of the entity in the network, thereby achieving safe and efficient access to the distributed power supply terminals of new energy power stations, fine-grained and refined access control, and rapid security event monitoring and response, supporting the improvement of the security protection capabilities of the new power system.

[0006] In order to solve the above technical problems, a distributed terminal entity identification method based on multi-dimensional attributes is proposed, including:

[0007] Identify surviving devices in the network and plan the order of detecting surviving devices through two scanning space dimensions; if the device is alive, extract the entity terminal characteristics and behavioral element information from the surviving network device; based on the extracted entity terminal characteristics and behavioral element information from the surviving network device, implicitly represent the behavioral characteristics of the network entity, and combine them with the attribute element characteristics of the entity terminal as different dimensions to construct a unique identity identifier for multi-dimensional identity characterization and identification.

[0008] As a preferred solution of the distributed terminal entity identity identification method based on multi-dimensional attributes described in the present invention, the identification of surviving devices in the network includes using stateless port detection to detect the target terminal, the scanner sends a SYN detection packet to the target terminal and does not block the message waiting for response, the SYN detection packet contains the message check code of the target terminal IP and the random detection coded data packet of this detection, and is placed in any field in the message, the target terminal receives the detection packet and the coded data packet, and replies with a response message SYN+ACK, the scanner receives the response message and sends RST to close the connection, the scanner extracts the identification information in the response message, including extracting the message check code value of the target IP and the target terminal IP for comparison, and checks whether the random detection coded data packet has any signs of tampering, and determines whether the current message belongs to the scanner response message and the port status, wherein SYN is a semi-connected request packet, SYN+ACK is a semi-connected confirmation plus request packet, and RST is a reset packet.

[0009] If the scanner receives a SYN+ACK response of the target terminal, it indicates that the port is open and the target terminal is alive, the target terminal is listening to the connection request on the port and checking whether the random probe coded data packet is tampered, a connection is established with the target terminal, and identity recognition is performed. If the scanner receives an RST response, it indicates that the port is closed and the target terminal is alive, the target terminal is not listening to the connection request on the current target port, and checking whether the random probe coded data packet is tampered, it is judged whether it is an unaffected port. If the port is not in the target terminal business process and the port is not authorized, the port is kept closed and the current port probe is cancelled. If the port is in the target terminal business process and the port is authorized, the probe packet and port request opening message are sent, and the port response is waited.

[0010] When the scanner receives a response, if the response time is not more than 3 seconds, it is considered that the target terminal is in an active alive state and has a strong alive state, and the connection with the target terminal is allowed. When the scanner receives a response, if the response time is more than 3 seconds, it is considered that the target terminal is not active in the alive state and has a weak alive state, and repeated detection and historical data confirmation are performed. After detecting and repairing faults, the probe packet and the coded data packet are re-sent. If the alive state is not active, the current port is abandoned and re-probed.

[0011] If the scanner does not receive any response, but the target terminal exists, it indicates that the port is filtered by the firewall and security device in the network, causing the probe packet or response packet to be discarded. At this time, the scanner sends the random probe coded data packet to the firewall or security device for registration, and re-sends the SYN probe packet to the target terminal. If there is still no response at this time, it is judged that the target device is not alive, the staff is notified to check and maintain, and the current port is abandoned and re-probed.

[0012] When the random probe coded data packet is changed and tampered, the system considers that the detection process has an attack behavior and has a security risk, which belongs to a dangerous stage. No identification information comparison is performed. The scanner sends an RST to close the connection and sends an instruction to close the target terminal to prevent attack data from entering.

[0013] When the random probe coded data packet is not tampered, the system considers that there is no attack behavior in the process, which belongs to a safe stage. The identification information is compared. If the message authentication code value of the target IP and the target terminal IP matches and the message authentication code value is consistent with the value in the probe packet, it is judged that the current response message belongs to the response message of the scanner. If the target IP in the response message does not match the target IP of the SYN probe packet sent by the scanner, or the message authentication code value is inconsistent with the value in the probe packet, it is judged that the response message does not belong to the response message of the scanner. In addition, if the response message exceeds the response time window T test, and is also judged as a response message that does not belong to the scanner.

[0014] As a preferred solution of the distributed terminal entity identification method based on multi-dimensional attributes described in the present invention, the planning of the detection order includes adopting a random probe generation technology to scan the two spatial dimensions of the target IP address and port, and adjacent probe data packets are not allowed to be sent to the same network segment and the same target address, and the detection order is planned:

[0015]

[0016] The detection function P(i,j) is calculated based on the probability density function of the two-dimensional normal distribution:

[0017]

[0018] The resulting function is expressed as:

[0019]

[0020] Where S(i,j) is the scan order function, which indicates the scan order of IP address i and port j; P(i,j) is the detection function, which indicates the probability of detecting IP address i and port j; R(i,j) is the result function, which indicates the result of detecting IP address i and port j; I is the number of target IP addresses, J is the number of ports, sin(·) and cos(·) are used to map IP addresses and ports to periodic functions, respectively, and η i ,η j 、 and ρ are the mean, standard deviation and correlation of IP address and port distribution respectively, θ i and θ j is the adjustment parameter.

[0021] Priority is sorted from large to small according to the value of S(i,j). The larger the S(i,j), the higher the scanning order of IP address i and port j. The optimal detection model is established to detect the targets in the whole network in order of priority:

[0022]

[0023] Among them, W(u,v) represents the optimal detection model. The higher the value, the better the detection effect, and the lower the value, the worse the detection effect. It is updated again. u and v represent the two scanning space dimensions of the target IP address and port respectively. u0 and v0 represent the initial values ​​of the scanning space respectively. N and M represent the number of detections in the IP address and port dimensions respectively. α n Indicates the efficiency or success rate of the nth detection of the IP address, β nrepresents the attenuation rate of the IP address detection signal in the IP address space, γ n Represents the specific characteristic value of the target IP address, δ n The adjustment coefficient used to adjust the shape of the IP address detection function, ∈ n Represents the degree to which the IP address detection signal is affected by environmental factors, ω n represents the center position of the IP address detection function, α m represents the efficiency or success rate of the mth detection in the port dimension, β m Describes the attenuation rate of the detection signal in the port space, γ m represents the specific characteristics of the target port in the port dimension, δ m The adjustment coefficient used to adjust the shape of the port dimension detection function, ∈ m Indicates the degree to which the port dimension detection signal is affected by environmental factors, ω m It represents the center position of the port dimension detection function, s represents the position of a specific IP address in the detection process in the IP address dimension, and t represents the position of a specific port in the detection process in the port dimension.

[0024] As a preferred solution of the distributed terminal entity identity identification method based on multi-dimensional attributes described in the present invention, the extraction of network entity terminal characteristics and behavior element information includes dividing the elements constituting the entity identity into two categories, the first category is terminal attribute elements, and the second category is terminal behavior elements.

[0025] The terminal attribute elements include operating system attributes and device type attributes. The operating system attributes include IP / MAC address, port number, and protocol type. The device type attributes are extracted through Nmap active scanning technology and ARE automated search framework, including function information, software and hardware information, manufacturer and model information.

[0026] The terminal behavior factors include the terminal's behavioral performance over a period of time. Network traffic analysis is used to detect the network behavior and traffic content attributes and data packet transmission rate of the power grid equipment's behavior pattern in the network. The channel state information (CSI) is extracted by the receiving end's specific hardware combined with the channel state information.

[0027] Four-dimensional high-strength identity identification is performed based on four types of terminal elements: network behavior and traffic content attributes, channel state information CSI, operating system attributes, and device type attributes.

[0028] As a preferred solution of the distributed terminal entity identification method based on multi-dimensional attributes described in the present invention, wherein: the construction of a unique network entity identity includes using the Transformer model in deep learning to implicitly represent the behavioral characteristics of the network entity, and extracting the terminal behavior element matrix (F1, F2, F3, ..., F m ) to fill the initial position mark, add a CLS mark at the beginning of the sequence to indicate the starting position of the sequence, and fill it to get (CLS, F1, F2, F3, ..., F m ), after the input data is vectorized, it is converted into a vector matrix (X CLS ,X1,X2,X3,……,X m ), where m is the time length for extracting terminal behavior.

[0029] Positional encoding is used to introduce position information into each input vector in the sequence. That is, the index value representing the time sequence is mapped to a vector through the position mapping function PosEnc(p,i). The index value is then added to the vector corresponding to the current position in the vector matrix to represent the input vector at the current position, thus introducing temporal features into the terminal behavior elements:

[0030]

[0031] The vector matrix of the time series feature is input into the Transformer model, and the vector passes through the hidden layer output of the Transformer model (C, T1, T2, T3, ..., T m ), where C is the implicit representation of terminal behavior obtained from model analysis. The implicit representation C is combined with the terminal attribute element features as different dimensions. After passing through a fully connected layer using an activation function, the output of the fully connected layer is used as the input of the output layer to complete the classification of the input data and construct the unique identity A of the network entity.

[0032] Channel state information is used to assist in generating a unique identity B. After obtaining the channel state information matrix, it is normalized. The amplitude and phase features are extracted from the normalized CSI data and used in the subsequent fully connected layer calculation to generate the identity B corresponding to the channel state information. Together with the identity A generated by the above process, the network entity portrait is constructed to form the final unique identity Z.

[0033] As a preferred solution of the distributed terminal entity identification method based on multi-dimensional attributes described in the present invention, wherein: the fully connected layer calculation includes:

[0034]

[0035] Among them, B is the identity corresponding to the generated channel state information, R is the amplitude feature, R k represents the magnitude of the kth data point, R min and R max are the minimum and maximum values ​​of the amplitude, Φ is the phase characteristic, Φ k represents the phase of the kth data point, Φ min and Φ max are the minimum and maximum phase values, L and K are the number of amplitude and phase data points, λ and κ are adjustment parameters, and R ref is the reference amplitude, is the phase characteristic Φ k The real part of the complex plane, R' k is the logarithmically transformed amplitude characteristic, R' k =log(1+R k ), Γ represents the enhancement of signals with smaller amplitudes, and ζ represents the distribution characteristics of the analysis phase.

[0036] Identity B and identity A together create a profile of the network entity, forming the final unique identity Z:

[0037]

[0038] Among them, Z is the final unique identity, f is the integration function that combines the various parts of information to form the final identity, μ is the mean of C, σ 2 is the variance of C, Ω represents all possible attribute combinations, Q is the number of attribute combinations, q is the index variable for summation, and ψ is a function that combines implicit representation and terminal attribute features:

[0039]

[0040] Among them, C q and A q are the implicit representation and identification of the i-th attribute combination, λ o is the weight parameter of the jth attribute, and O is the number of attribute features.

[0041] As a preferred scheme of the multi-dimensional attribute-based distributed terminal entity identity identification method, wherein: the multi-dimensional characterization of the identity and the identity recognition include collecting extended biological fingerprints, hardware and software feature information, running state, environmental context attribute and behavior feature information for user identity authentication, the system comprehensively evaluates all the collected data and utilizes the channel characteristics in wireless communication to perform multi-dimensional characterization, performs matching calculation on the characterization results and finally identifies the unique identity Z, if the identity Z passes the test and the matching score of the characterization results exceeds 0.8, the user successfully passes the identity authentication, if the identity Z fails the test and the matching score of the characterization results is less than 0.8, the identity authentication fails and access is denied, the system will start a secondary verification process, the system requires the user to provide additional identity proof including receiving an SMS verification code, performing biological identification verification, if the user completes the secondary verification successfully, access permission will be obtained, if the secondary verification fails, the system will record the event and lock the account, and perform fast security event detection response, the matching score threshold is increased when the channel condition is good, and the matching score threshold is reduced when the channel condition is poor.

[0042] Another object of the present application is to provide a multi-dimensional attribute-based distributed terminal entity identity identification system, in order to realize efficient and secure terminal entity identity recognition and management in a network environment, by integrating stateless port detection technology, deep learning, Transformer model, channel state information CSI and other multi-dimensional attribute information, the system solves the limitations of traditional identity recognition methods in complex network environments, such as difficulty in judging device state, unreliability of behavior characteristics and vulnerability of single identity identification.

[0043] The system accurately judges the survival state of network devices using stateless port detection technology, and improves detection efficiency through scanning space optimization detection technology. At the same time, the attributes and behavior characteristics of network entities are extracted and analyzed, the Transformer model in deep learning is used to implicitly represent the behavior characteristics, and the unique network entity identity is constructed by combining with the attribute characteristics.

[0044] The system improves the uniqueness and difficulty of identity identification, and the high-precision verification of user identity through multi-dimensional characterization and matching calculation, and the system ensures security while improving the efficiency and accuracy of identity recognition, achieving the effect of comprehensive monitoring and management of network entities, and providing strong technical support for network security and device management.

[0045] As a preferred scheme of the multi-dimensional attribute-based distributed terminal entity identity identification system, characterized by comprising a survival state judgment and detection planning module, a feature and behavior information extraction module, and an identity identification construction module.

[0046] The survival status judgment and detection planning module identifies surviving devices in the network and plans the detection order of the surviving devices through two scanning space dimensions.

[0047] The feature and behavior information extraction module extracts the entity terminal features and behavior element information from the surviving network device if the device is alive.

[0048] The identity identification construction module implicitly represents the behavioral characteristics of the network entity based on the extraction of entity terminal characteristics and behavioral element information in the network survival device, and combines them with the attribute element characteristics of the entity terminal as different dimensions to construct a unique identity identification of the network entity for multi-dimensional identity characterization and identity recognition.

[0049] A computer device includes a memory and a processor, wherein the memory stores a computer program, and is characterized in that when the processor executes the computer program, it implements the steps of a method for distributed terminal entity identity identification based on multi-dimensional attributes.

[0050] A computer-readable storage medium stores a computer program thereon, characterized in that when the computer program is executed by a processor, the steps of a method for distributed terminal entity identification based on multi-dimensional attributes are implemented.

[0051] The beneficial effects of the present invention are as follows: The present invention realizes four-dimensional high-strength identity identification of cyberspace terminal equipment security, personnel security, application / service security and operation security based on four types of attribute behavior characteristics, namely network behavior and traffic content attributes, channel state information CSI, operating system attributes and device type attributes; expands attributes and behavioral characteristics such as biometric fingerprints, software and hardware feature information, operating status, environmental context, and utilizes channel characteristics in wireless communications to realize multi-dimensional characterization and identity authentication of cyberspace access personnel, applications, and terminal devices.

[0052] It integrates the concept of zero trust and expands attributes and behavioral characteristics such as biometric fingerprints, software and hardware feature information, operating status, and environmental context; it utilizes channel characteristics in wireless communications to achieve multi-dimensional characterization and identity authentication of network space access personnel, applications, and terminal devices; it extracts more fully, and uses the Transformer model to effectively fuse and process these multimodal features, capturing the relationships and dependencies between input features; it has better robustness and scalability. Compared with existing technologies, it performs more sufficient feature extraction, and uses the Transformer model to effectively fuse and process these multimodal features, capturing the relationships and dependencies between input features.

[0053] The present application aims at solving the problem of the balance between safety and economy of new energy power station, and making up for the weakness of the defense system of distributed new energy power source side and its grid-connected system. BRIEF DESCRIPTION OF DRAWINGS

[0054] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced. Obviously, the drawings in the following description only constitute some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0055] Figure 1 A general flow chart of a distributed terminal entity identity identification method based on multi-dimensional attributes provided by one embodiment of the present application.

[0056] Figure 2 A distributed terminal entity identity unique identification step schematic diagram of a distributed terminal entity identity identification method based on multi-dimensional attributes provided by one embodiment of the present application.

[0057] Figure 3 A system function architecture diagram of a distributed terminal entity identity identification system based on multi-dimensional attributes provided by one embodiment of the present application. DETAILED DESCRIPTION

[0058] In order to make the above-mentioned objects, features and advantages of the present application more apparent and understandable, the specific embodiments of the present application will be described in detail in conjunction with the drawings in the specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present application.

[0059] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application. However, the present application can be practiced without the specific details, which are not described herein, and it will be apparent to those skilled in the art that the present application can be practiced with other different ways than those described herein, and the present application is not limited to the specific embodiments disclosed below.

[0060] Secondly, the term "one embodiment" or "an embodiment" as used herein means that a specific feature, structure or characteristic described can be included in at least one implementation of the present application. The term "in one embodiment" appearing in different places in the specification does not mean the same embodiment, nor does it mean that the embodiments are mutually exclusive or alternative to each other.

[0061] The application is described in detail in combination with the schematic diagram. In the detailed description of the embodiments of the application, the cross-sectional view of the device structure is locally enlarged without the general proportion for the convenience of illustration, and the schematic diagram is only an example, which should not limit the scope of protection of the application herein. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in actual production.

[0062] Meanwhile, in the description of the application, it should be noted that the terms "upper, lower, inner and outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the application. In addition, the terms "first, second or third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.

[0063] Unless otherwise specified and limited in the application, the terms "mounting, connection, connection" should be understood broadly, for example: it can be fixed connection, detachable connection or integral connection; it can also be mechanical connection, electrical connection or direct connection, it can also be indirectly connected through an intermediate medium, or it can be the communication between two elements. For those skilled in the art, the specific meaning of the above terms in the application can be understood according to the specific circumstances.

[0064] Embodiment 1

[0065] Reference Figure 1-Figure 2 For the first embodiment of the application, the embodiment provides a distributed terminal entity identity identification method based on multi-dimensional attributes, comprising:

[0066] S1: Identify the living devices in the network, and plan the order of the detection of the living devices through two scanning space dimensions.

[0067] The network entity open port detection is performed to determine the living devices. The network entity open port detection is performed by actively sending a detection request packet to the detected object, collecting and storing the response packets according to the rules, and determining whether the device is alive according to the response packets. In the detection method, there is a TCP-based connection detection, which needs to go through three processes of handshaking, detection and disconnection. However, due to the large number and complex types of intelligent terminal devices in the power Internet of Things, if the TCP-based connection detection is adopted, the efficiency will be greatly reduced.

[0068] Further, the identifying the living device in the network and judging the living state of the device comprises using stateless port detection target terminal, the scanner sends SYN detection packet to the target terminal and does not block the response message, the SYN detection packet contains the message check code of the target terminal IP and the random detection coding data packet of this detection, and is placed in any field of the message, the target terminal receives the detection packet and the coding data packet, and returns a response message SYN+ACK, the scanner receives the response message and sends RST to close the connection, the scanner extracts the identification information in the response message, including extracting the target IP and the message check code value of the target terminal IP for comparison, and checking whether the random detection coding data packet is tampered, judging whether the current message belongs to the response message of the scanner and the port state, wherein SYN is a half-connection request packet, SYN+ACK is a half-connection confirmation request packet, and RST is a reset packet.

[0069] If the scanner receives the SYN+ACK response of the target terminal, it indicates that the port is open and the target terminal is alive, the target terminal is listening to the connection request on the port and checking whether the random detection coding data packet is tampered, and the connection with the target terminal is established for identity recognition, if the scanner receives an RST response, it indicates that the port is closed and the target terminal is alive, the target terminal does not listen to the connection request on the current target port, and checks whether the random detection coding data packet is tampered, and judges whether it is an unaffected port, if the port is not in the target terminal business process and the port is not authorized, the port is kept closed and the current port detection is cancelled, if the port is in the target terminal business process and the port is authorized, the detection packet and the port request open message are sent, and the port response is waited.

[0070] When the scanner receives the response, if the response time is less than 3 seconds, it is considered that the target terminal is in an active living state, the living state is strong, and the connection with the target terminal is allowed, if the response time is more than 3 seconds, it is considered that the target terminal is in an inactive living state, the living state is weak, and repeated detection and historical data confirmation are performed, the fault is detected and repaired, and the detection packet and the coding data packet are re-sent, if the living state is inactive, the current port is abandoned and re-detected.

[0071] If the scanner does not receive any response, but the target terminal exists, it indicates that the port is filtered by the firewall and security device in the network, causing the detection packet or the response packet to be discarded, at this time, the scanner sends the random detection coding data packet to the firewall or the security device for registration, and re-sends the SYN detection packet to the target terminal, if there is still no response at this time, it is judged that the target device is not alive, the staff is informed to check and maintain, and the current port is abandoned and re-detected.

[0072] When the random detection code data packet changes and shows signs of tampering, the system considers that an attack behavior has occurred during the detection process, there is a security risk, and it is in a dangerous stage. Without comparing the identification information, the scanner sends an RST to close the connection and sends a command to close the target terminal to prevent the attack data from entering;

[0073] When there is no sign of tampering in the random detection code data packet, the system believes that there is no attack behavior in the process and it belongs to the safe stage. It compares the identification information, extracts the message check code value of the target IP and the target terminal IP, and the message check code value is consistent with the value in the detection packet. It is judged that the current response message belongs to the response message of the scanner. If the target IP in the response message does not match the target IP of the SYN detection packet sent by the scanner, or the message check code value is inconsistent with the value in the detection packet, it is judged that the response message does not belong to the response message of the scanner. In addition, if the response message exceeds the expected response time window T of the scanner test , and is also judged as a response message that does not belong to the scanner.

[0074] It should be noted that the random probe data packet contains randomly generated data to ensure that each probe data packet is unique, which can prevent the cache mechanism in the network from mistakenly matching the previous response to the current probe request: the random probe data packet can contain encrypted or unpredictable data, so that even if the probe packet is intercepted, it is difficult for the attacker to forge a valid response message, thereby improving the security of the detection process; by comparing the message check code value in the response message with the value in the original probe packet, it can be verified that the data has not been tampered with during transmission, ensuring the integrity of the data; the random probe data packet can help the scanner accurately match the original probe request corresponding to each response message when receiving multiple responses, thereby correctly judging the open status of each port; due to the unpredictability of the random probe data packet, it can reduce false alarms caused by noise in the network or responses from other non-target devices; in distributed scanning scenarios, random probe data packets can help balance the load between different scanners and avoid all scanners sending probe packets to the same target at the same time.

[0075] It should be noted that the planning of the detection order includes the use of random probe generation technology from the two scanning space dimensions of the target IP address and port. Adjacent probe packets are not allowed to be sent to the same network segment and the same target address. The planning of the detection order is as follows:

[0076]

[0077] The detection function P(i,j) is calculated based on the probability density function of the two-dimensional normal distribution:

[0078]

[0079] The result function is expressed as:

[0080]

[0081] where S(i,j) is a scan order function, representing the scan order of the i-th IP address and the j-th port; P(i,j) is a probe function, representing the probability of probing the i-th IP address and the j-th port; R(i,j) is a result function, representing the result of probing the i-th IP address and the j-th port; I is the number of target IP addresses, J is the number of ports, sin(·) and cos(·) are used to map IP addresses and ports to periodic functions, η i , η j , and ρ are the mean, standard deviation and correlation of IP address and port distributions, θ i and θ j are adjustment parameters.

[0082] According to the value of S(i,j) from large to small, the priority is sorted, the larger S(i,j) is, the earlier the scan order of the i-th IP address and the j-th port is, and the optimal probe model is established to probe the entire network target according to the priority order:

[0083]

[0084] where W(u,v) represents the optimal probe model, the higher the value is, the better the probe effect is, and the lower the value is, the worse the probe effect is, and is updated; u and v represent the target IP address and port two scan space dimensions respectively, u0 and v0 represent the initial value of the scan space, N and M represent the number of probes in the IP address and port dimensions respectively, α n represents the efficiency or success rate of the n-th probe in the IP address dimension, β n represents the decay rate of the IP address probe signal in the IP address space, γ n represents a specific characteristic value of the target IP address, δ n is a regulation coefficient for adjusting the shape of the IP address probe function, ∈ n represents the degree of influence of environmental factors on the IP address probe signal, ω n represents the center position of the IP address probe function, α m represents the efficiency or success rate of the m-th probe in the port dimension, β m describes the decay rate of the probe signal in the port space, γ m represents a specific characteristic of the target port in the port dimension, δ m is a regulation coefficient for adjusting the shape of the port dimension probe function, ∈ m represents the degree of influence of environmental factors on the port dimension probe signal, ω mIt represents the center position of the port dimension detection function, s represents the position of a specific IP address in the detection process in the IP address dimension, and t represents the position of a specific port in the detection process in the port dimension.

[0085] This method can effectively reduce the pressure on the scanner and the network, while reducing the load on the terminal, truly realizing the requirements of lightweight scanning.

[0086] S2: If the device is alive, extract the entity terminal characteristics and behavior element information from the surviving network device.

[0087] Furthermore, the extraction of network entity terminal characteristics and behavior element information includes dividing the elements constituting the entity identity into two categories, the first category being terminal attribute elements and the second category being terminal behavior elements.

[0088] The terminal attribute elements include operating system attributes and device type attributes. The operating system attributes include IP / MAC address, port number, and protocol type. The device type attributes are extracted through Nmap active scanning technology and ARE automated search framework, including function information, software and hardware information, manufacturer and model information.

[0089] The terminal behavior factors include the terminal's behavior performance over a period of time. Network traffic analysis is used to detect the network behavior and traffic content attributes and data packet transmission rate of the power grid equipment's behavior pattern in the network. The channel state information (CSI) is extracted by the receiving end's specific hardware combined with the channel state information.

[0090] Four-dimensional high-strength identity identification is performed based on four types of terminal elements: network behavior and traffic content attributes, channel state information CSI, operating system attributes, and device type attributes.

[0091] It should also be noted that the specific network entity identity elements we extracted are shown in Table 1:

[0092] Table 1 Identity element information table

[0093]

[0094]

[0095] The extraction level, extraction object, extraction information, and extraction method are as follows:

[0096] (1) Network behavior and traffic content attributes

[0097] The behavior of power grid equipment on the network is regular, and this unique regularity can form a device fingerprint for identification. Based on this, we use passive monitoring to extract relevant network traffic characteristics of power grid equipment, specifically including the following aspects:

[0098] IP / MAC addresses: Given the nature of power grid device interactions, the IP and MAC addresses of the initiators and recipients of these interactions, i.e., the communication partners of power grid devices, can exhibit certain regularities. Previous IoT-based research has shown that most IoT devices communicate with fewer than 10 servers per day, and the number of cloud servers they interact with is quite consistent across some IoT devices. Even the same IoT device model can communicate with the same number of cloud servers, while the cloud servers a device interacts with are often limited to a specific range. Given the similarities between power grid information assets and IoT devices, IP and MAC addresses are extracted from data packets as a network traffic signature.

[0099] Port number / protocol: The protocols and services used by power grid information assets also have certain regularity. The services used can be inferred based on common port numbers. Therefore, port numbers and protocols are extracted as one of the network traffic features.

[0100] Packet rate: The packet sending rate can usually also indicate the data processing characteristics of the device, so the packet sending rate is extracted as one of the network traffic characteristics.

[0101] (2) Operating system type attribute

[0102] In different operating systems, standard protocols often have some optional, customizable, or undefined content. These differences vary from operating system to operating system. Therefore, we use differences in the network protocol stack (TCP / IP / ICMP) to distinguish operating system types. For example, we can distinguish some operating systems by whether they respond to ICMP timestamp requests.

[0103] In addition, the TTL field returned by the Ping protocol specifies the number of networks an IP packet is allowed to traverse before being discarded by a router. Different host operating systems have different initial TTL values, which can also be used to distinguish operating system types.

[0104] (3) Device type attributes

[0105] Active scanning technology is used to extract device fingerprint information of power grid information assets. Based on the characteristics of power grid information equipment, device fingerprint features are mainly derived from the following aspects:

[0106] Functional Information: Every power grid device has specific functions when it leaves the factory. This means that, in terms of its operational behavior, controllers, for example, regularly collect data from underlying sensors, process it, and upload it. Therefore, a device function represents a fixed operating method and can be used as a criterion for device classification. Functional information can be used to roughly estimate the operations a device can perform and the operating environment in which it operates.

[0107] Software and hardware information: Each independently functioning smart grid device has its own hardware and software architecture. The software architecture typically includes the device's operating system and firmware version, while the hardware architecture includes the platform on which the device runs, and therefore can be used as one of the criteria for device identification.

[0108] Manufacturer and model information: This primarily includes information such as the manufacturer name and product model. Grid assets often contain numerous devices with identical functions and even configurations. Functional information alone cannot provide a granular distinction between devices. Furthermore, these devices often run firmware developed by different manufacturers. Therefore, when a critical vulnerability exists in a particular firmware, further detailed information is required to better locate these specific devices and provide security countermeasures.

[0109] S3: Based on the extraction of entity terminal characteristics and behavioral element information in network surviving devices, the behavioral characteristics of network entities are implicitly represented and combined with the attribute element characteristics of the entity terminal as different dimensions to construct a unique identity identifier for multi-dimensional identity characterization and identification.

[0110] The Transformer model based on deep learning implicitly represents the behavioral characteristics of network entities, and combines them with the attribute characteristics of network entities to perform unique identity identification. On the basis of obtaining the terminal security behavior elements, the present invention uses a deep learning-based method to obtain a dynamic behavior representation for identifying the terminal identity through the terminal security behavior elements, thereby realizing the mapping of the terminal behavior elements and the terminal identity. In this process, since the terminal behavior is reflected in the network traffic packets of the terminal and the server communication interaction, excluding the protocol type, port type and packet arrival time interval (IAT) in the traffic data, the temporal relationship between the traffic data samples is an important manifestation of the terminal behavior and an important feature for identifying the terminal identity. When using the deep learning model, it is necessary to consider the temporal relationship between the traffic data packets. Therefore, the Transformer model is used to construct the terminal security behavior fingerprint based on the terminal behavior elements.

[0111] Furthermore, the extracted terminal behavior factor matrix (F1, F2, F3, ..., F m ) to fill the initial position mark, add a CLS mark at the beginning of the sequence to indicate the starting position of the sequence, and fill it to get (CLS, F1, F2, F3, ..., F m ), after the input data is vectorized, it is converted into a vector matrix (X CLS ,X1,X2,X3,……,X m ), where m is the time length for extracting terminal behavior.

[0112] Positional encoding is used to introduce position information into each input vector in the sequence. That is, the index value representing the time sequence is mapped to a vector through the position mapping function PosEnc(p,i). The index value is then added to the vector corresponding to the current position in the vector matrix to represent the input vector at the current position, thus introducing temporal features into the terminal behavior elements:

[0113]

[0114] The vector matrix of the time series feature is input into the Transformer model, and the vector passes through the hidden layer output of the Transformer model (C, T1, T2, T3, ..., T m ), where C is the implicit representation of terminal behavior obtained from model analysis. The implicit representation C is combined with the terminal attribute element features as different dimensions. After passing through a fully connected layer using an activation function, the output of the fully connected layer is used as the input of the output layer to complete the classification of the input data and construct the unique identity A of the network entity.

[0115] The channel state information is used to assist in generating a unique identity B. Taking a 2×2 MIMO antenna as an example, the transmitting antennas are X1, X2, and the receiving antennas are Y1, Y2, then the channel state information matrix

[0116]

[0117] satisfy:

[0118]

[0119] After obtaining the channel state information matrix H, normalization is performed, and the amplitude and phase features are extracted from the normalized CSI data to participate in the subsequent full connection layer calculation, which includes:

[0120]

[0121] Among them, B is the identity corresponding to the generated channel state information, R is the amplitude feature, R k represents the magnitude of the kth data point, R min and R max are the minimum and maximum values ​​of the amplitude, Φ is the phase characteristic, Φ k represents the phase of the kth data point, Φ min and Φ max are the minimum and maximum phase values, L and K are the number of amplitude and phase data points, λ and κ are adjustment parameters, and R ref is the reference amplitude, is the phase characteristic Φ k The real part of the complex plane, R' kis the logarithmically transformed amplitude characteristic, R' k =log(1+R k ), Γ represents the enhancement of signals with smaller amplitudes, and ζ represents the distribution characteristics of the analysis phase.

[0122] Generate the identity B corresponding to the channel state information, and together with the identity A generated in the above process, create a profile of the network entity, forming the final unique identity Z:

[0123]

[0124] Among them, Z is the final unique identity, f is the integration function that combines the information of each part to form the final identity, μ is the mean of C, σ 2 is the variance of C, Ω represents all possible attribute combinations, Q is the number of attribute combinations, q is the index variable for summation, and ψ is a function that combines implicit representation and terminal attribute features:

[0125]

[0126] Among them, C q and A q are the implicit representation and identification of the i-th attribute combination, λ o is the weight parameter of the jth attribute, and O is the number of attribute features.

[0127] It should also be noted that multi-dimensional identity characterization and identification includes collecting and expanding biometric fingerprints, software and hardware feature information, operating status, environmental context attributes and behavioral feature information for user identity authentication. The system will comprehensively evaluate all collected data and use channel characteristics in wireless communications to perform multi-dimensional characterization, match the characterization results and perform identification on the final unique identity identifier Z. If the identity identifier Z test passes and the matching score of the characterization result exceeds 0.8, the user successfully passes the identity authentication. If the identity identifier Z test fails and the matching score of the characterization result is less than 0.8, the identity authentication fails and access is denied. The system will initiate a secondary verification process. The system requires the user to provide additional identity proof, including receiving a text message verification code and performing biometric verification. After the user completes the secondary verification, if the verification is successful, access permission will be obtained. If it fails, the system will record the event and lock the account, and perform a rapid security incident detection response. The matching score threshold will be increased when the channel conditions are good, and the matching score threshold will be lowered when the channel conditions are poor.

[0128] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

[0129] Example 2

[0130] An embodiment of the present invention provides a distributed terminal entity identity identification method based on multi-dimensional attributes. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through experiments.

[0131] A network environment consisting of 100 devices, including servers, personal computers, and mobile devices, was prepared. Each device was configured with a different operating system and application to simulate the diversity of the real world. Furthermore, an attack-simulating environment was developed to test the method's performance under security threats.

[0132] Stateless port probing technology is used to scan devices on the network. SYN probe packets are sent and responses are analyzed to determine device liveness. For open ports, the device is considered live and listening for connection requests. For closed ports, the device is also considered live but not listening for connection requests on the current port. A probability density function based on a two-dimensional normal distribution is used to calculate the probing function. Based on the calculated result, a probing sequence is planned, prioritizing high-probability IP addresses and ports.

[0133] Through network traffic analysis and channel state information (CSI), behavioral elements of terminals are extracted. Furthermore, Nmap and the ARE automated search framework are used to extract terminal attributes, such as operating system attributes and device type attributes. The Transformer model, a deep learning framework, implicitly represents the behavioral characteristics of network entities and combines them with the entity's attributes to construct a unique network entity identity. User biometric fingerprints, software and hardware characteristics, operating status, environmental context attributes, and behavioral characteristics are collected for user authentication. Channel characteristics in wireless communications are used for multi-dimensional characterization and matching calculations are performed with the constructed unique identity.

[0134] Table 1 Experimental data

[0135]

[0136] The data shows that the proposed method achieves shorter detection times on various devices than the existing technology. The server detection time is 150ms, while the existing technology requires 200ms. This demonstrates that the proposed method has a significant advantage in detection efficiency. This efficiency improvement is due to the application of stateless port detection technology and scan space optimization detection technology. The technology used in the present invention reduces unnecessary detection times and improves the targeted detection.

[0137] The accuracy of personal computer identification is 97.2%, while the existing technology is only 93.0%. This shows that the proposed method is more effective in accurately identifying network entities. Due to the application of the Transformer model in deep learning, it can more effectively implicitly represent the behavioral characteristics of network entities and combine them with the attribute characteristics of the entity to construct a more accurate unique network entity identity.

[0138] The security score of IoT devices is 8.7, while the existing technology is only 7.0. This shows that the proposed method is more effective in improving network security. This is because the proposed method collects more comprehensive feature information during the authentication process and uses multi-dimensional channel characteristics in wireless communication to improve the ability to identify and prevent security threats.

[0139] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

[0140] Example 3

[0141] The third embodiment of the present invention is different from the first two embodiments in that:

[0142] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0143] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0144] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0145] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0146] Example 4

[0147] Reference Figure 3 , which is the fourth embodiment of the present invention, provides a distributed terminal entity identity identification system based on multi-dimensional attributes, including a survival status judgment and detection planning module, a feature and behavior information extraction module, and an identity identification construction module.

[0148] The survival status judgment and detection planning module identifies surviving devices in the network and plans the detection order of the surviving devices through two scanning space dimensions.

[0149] Detection technology is optimized across two scanning spaces, sending specific probe packets and analyzing responses to determine the status of target endpoints, enabling effective network device management and potential security threat assessment.

[0150] The feature and behavior information extraction module extracts the physical terminal features and behavior element information from the surviving network device if the device is alive.

[0151] Extract the attribute elements and behavior element information of the network entity terminal. The attribute elements include operating system attributes and device type attributes, and the behavior elements include network traffic analysis and channel state information CSI, which are used to establish the behavior model of the terminal.

[0152] The identity identification construction module extracts the entity terminal characteristics and behavioral element information from the network survival device, implicitly represents the behavioral characteristics of the network entity, and combines them with the attribute element characteristics of the entity terminal as different dimensions to construct the unique identity of the network entity for multi-dimensional identity characterization and identity recognition.

[0153] The Transformer model in deep learning is used to implicitly represent the behavioral characteristics of network entities and combine them with the attribute characteristics of the entity to construct a unique network entity identity. By integrating timing features, location information and terminal attributes, a highly accurate network entity identity is generated for subsequent identity recognition processes.

[0154] The identity identification construction module also includes an authentication unit responsible for collecting the user's biometric fingerprint, software and hardware feature information, operating status, environmental context attributes and behavioral feature information for user authentication. The system will comprehensively evaluate all collected data and use the channel characteristics in wireless communication for multi-dimensional characterization. It will verify the user's identity by matching calculations with the constructed unique identity Z. If the verification fails, the system will initiate a secondary verification process and require the user to provide additional identity proof to ensure the security of the system.

[0155] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A distributed terminal entity identification method based on multi-dimensional attributes, characterized by: include, Identify surviving devices in the network and plan the order of detecting surviving devices using two scanning space dimensions; If the device is alive, extract the terminal attribute elements and terminal behavior elements from the surviving network device. The terminal attribute elements include operating system attributes and device type attributes. The terminal behavior elements include network behavior and traffic content attributes, and channel state information (CSI). Based on the extraction of terminal attribute elements and terminal behavior elements from network surviving devices, the terminal behavior characteristics are implicitly represented and combined with the terminal attribute element characteristics as different dimensions to construct the terminal's unique identity for multi-dimensional identity characterization and identification; The construction of the unique identity of the terminal includes implicitly representing the terminal behavior characteristics using the Transformer model in deep learning, and extracting the terminal behavior element matrix (F1, F2, F3, ..., F m ) to fill in the initial position mark, add the CLS mark indicating the starting position, and fill in the terminal behavior element matrix (CLS, F1, F2, F3, ..., F m ), m is the time length of the terminal behavior to be extracted, and the input data is vectorized and converted into a vector matrix (X CLS ,X1,X2,X3,……,X m ); Positional encoding is used to introduce position information into each input vector in the vector matrix. That is, the index value representing the time sequence is mapped to a vector through a position mapping function. The index value is then added to the vector corresponding to the current position in the vector matrix to represent the input vector at the current position, thus introducing temporal characteristics into the terminal behavior elements. The vector matrix of the time series feature is input into the Transformer model, and the hidden layer output (C, T1, T2, T3, ..., T m ), C is the implicit representation of terminal behavior. The obtained implicit representation C is combined with the terminal attribute element features as different dimensions. After passing through the fully connected layer using the activation function, the output of the fully connected layer is used as the input of the output layer to complete the classification of the input data and construct the unique identity A of the terminal; CSI is used to assist in generating a unique identity B. After obtaining the channel state information matrix, it is normalized. The amplitude and phase features are extracted from the normalized CSI data and used in the subsequent fully connected layer calculations to generate the identity B corresponding to the CSI. Together with the identity A, the terminal is profiled to form the final unique terminal identity Z.

2. A distributed terminal entity identification method based on multi-dimensional attributes according to claim 1, characterized in that: The identification of surviving devices in the network includes using a stateless port to detect the target terminal. The scanner sends a SYN probe packet to the target terminal and does not block to wait for a response message. The SYN probe packet contains the message check code of the target terminal IP and the random probe code data packet of this detection, and is placed in any field in the probe packet. The target terminal receives the probe packet and replies with a response message SYN+ACK. The scanner receives the response message and sends RST to close the connection. The scanner extracts identification information from the response message, and the identification information includes the message check code value of the target IP, and compares the message check code value of the target IP with the message check code value of the target terminal IP, and checks whether the random probe code data packet has any signs of tampering, determines whether the current response message belongs to the scanner response message, and determines the port status, wherein SYN is a semi-connection request packet, SYN+ACK is a semi-connection confirmation plus request packet, and RST is a reset packet; If the scanner receives a SYN+ACK response from the target terminal, it indicates that the port is open and the target terminal is alive. The target terminal is listening for connection requests on the port and checking whether the random probe code data packet has tampering signs, establishing a connection with the target terminal and performing identity identification. If the scanner receives a RST response, it indicates that the port is closed and the target terminal is alive. The target terminal is not listening for connection requests on the current target port, and checking whether the random probe code data packet has tampering signs to determine whether it is a non-affected port. If the port is not in the target terminal business process and the port is not authorized, the port will continue to be closed and the current port detection will be canceled. If the port is in the target terminal business process and the port is authorized, the probe packet and the port opening request message will continue to be sent, and the port response will be waited for. Among them, when the scanner receives a response and the response time does not exceed 3 seconds, it is considered that the target terminal is in an active state and has a strong survival state, and the connection with the target terminal is allowed; when the scanner receives a response and the response time exceeds 3 seconds, it is considered that the target terminal is in an inactive state and has a weak survival state, and repeated detection and historical data confirmation are performed. After the fault is detected and repaired, the detection packet is resent. If the survival state is inactive, the current port is abandoned and the detection is repeated; If the scanner does not receive any response, but the target terminal exists, it indicates that the port is filtered by the firewall or security device in the network, causing the probe packet or response message to be discarded. At this time, the scanner sends a random probe code data packet to the firewall or security device for registration, and resends the SYN probe packet to the target terminal. If there is still no response, it is determined that the target device is not alive, and the staff is notified for maintenance and inspection. The current port is abandoned and the probe is re-probed; When the random detection code data packet changes and shows signs of tampering, the system considers that an attack behavior has occurred during the detection process, there is a security risk, and it is in a dangerous stage. Without comparing the identification information, the scanner sends an RST to close the connection and sends a command to close the target terminal to prevent the attack data from entering; When there is no sign of tampering in the random detection code data packet, the system believes that there is no attack behavior in the process and it belongs to the safe stage. If the target IP and the target terminal IP match and the message check code value of the target IP is consistent with the message check code value of the target terminal IP, it is judged that the current response message belongs to the response message of the scanner; if the target IP in the response message does not match the target IP of the SYN detection packet sent by the scanner, or the message check code value of the target IP is inconsistent with the message check code value of the target terminal IP, it is judged that the response message does not belong to the response message of the scanner; if the response message exceeds the response time window T expected by the scanner test , and also judge the response message that does not belong to the scanner.

3. The distributed terminal entity identification method based on multi-dimensional attributes according to claim 2, characterized in that: The planning of the detection sequence includes using random probe generation technology to scan the target IP address and port from two spatial dimensions. Adjacent probe packets are not allowed to be sent to the same network segment and the same target address. The detection sequence is planned as follows: The detection function P(i,j) is calculated based on the probability density function of the two-dimensional normal distribution: The resulting function is expressed as: Where S(i,j) is the scan order function, which indicates the scan order of IP address i and port j; P(i,j) is the detection function, which indicates the probability of detecting IP address i and port j; R(i,j) is the result function, which indicates the result of detecting IP address i and port j; I is the number of target IP addresses, J is the number of ports, sin(·) and cos(·) are used to map IP addresses and ports to periodic functions, respectively, and η i ,η j 、 and ρ are the mean, standard deviation and correlation of IP address and port distribution respectively, θ i and θ j is the adjustment parameter; Priority is sorted from large to small according to the value of S(i,j). The larger the S(i,j), the higher the scanning order of IP address i and port j. The optimal detection model is established to detect targets in the entire network in order of priority: Among them, W(u,v) represents the optimal detection model. The higher the value, the better the detection effect, and the lower the value, the worse the detection effect. It is updated again. u and v represent the two scanning space dimensions of the target IP address and port respectively. u0 and v0 represent the initial values ​​of the scanning space respectively. N and M represent the number of detections in the IP address and port dimensions respectively. α n Indicates the efficiency or success rate of the nth detection of the IP address, β n represents the attenuation rate of the IP address detection signal in the IP address space, γ n Represents the specific characteristic value of the target IP address, δ n The adjustment coefficient used to adjust the shape of the IP address detection function, ∈ n Represents the degree to which the IP address detection signal is affected by environmental factors, ω n represents the center position of the IP address detection function, α m represents the efficiency or success rate of the mth detection in the port dimension, β m Describes the attenuation rate of the detection signal in the port space, γ m represents the specific eigenvalue of the target port in the port dimension, δ m The adjustment coefficient used to adjust the shape of the port dimension detection function, ∈ m Indicates the degree to which the port dimension detection signal is affected by environmental factors, ω m It represents the center position of the port dimension detection function, s represents the position of a specific IP address in the detection process in the IP address dimension, and t represents the position of a specific port in the detection process in the port dimension.

4. A distributed terminal entity identification method based on multi-dimensional attributes according to claim 3, characterized in that: The terminal attribute elements include operating system attributes and device type attributes; wherein the operating system attributes include IP / MAC address, port number, and protocol type; the device type attributes include function information, software and hardware information, manufacturer and model information extracted through Nmap active scanning technology and ARE automated search framework; The terminal behavior elements include network behavior and traffic content attributes, and channel state information (CSI). The network behavior and traffic content attributes are extracted by analyzing the behavior of the terminal over a period of time and detecting the behavior patterns of power grid equipment in the network using network traffic analysis. Four-dimensional high-strength identity identification is performed based on four types of terminal elements: network behavior and traffic content attributes, channel state information CSI, operating system attributes, and device type attributes.

5. The distributed terminal entity identification method based on multi-dimensional attributes according to claim 4, characterized in that: The position mapping function is PosEnc(p,i), which is specifically:

6. A distributed terminal entity identification method based on multi-dimensional attributes according to claim 5, characterized in that: The fully connected layer calculation for generating the identity B corresponding to the CSI is: Among them, R is the amplitude characteristic of CSI, R k represents the magnitude of the kth data point, R min and R max are the minimum and maximum amplitudes, Φ is the phase characteristic of CSI, Φ k represents the phase of the kth data point, Φ min and Φ max are the minimum and maximum phase values, L and K are the number of amplitude and phase data points, λ and ρ are adjustment parameters, and R ref is the reference amplitude, is the phase characteristic Φ k The real part of the complex plane, R' k is the logarithmically transformed amplitude characteristic, R' k =log(1+R k ), Γ represents the enhancement of smaller amplitude signals, and ζ represents the distribution characteristics of the analysis phase; Identity B and identity A together create a profile of the terminal, forming the final unique identity Z: Among them, Z is the final unique identity, f is the integration function that combines the various parts of information to form the final identity, μ is the mean of C, σ 2 is the variance of C, Ω represents all possible attribute combinations, Q is the number of attribute combinations, q is the index variable for summation, and ψ is a function that combines implicit representation and terminal attribute features: Among them, C q and A q are the implicit representation and identification of the qth attribute combination, λ o is the weight parameter of the oth attribute, and O is the number of attribute features.

7. A distributed terminal entity identification method based on multi-dimensional attributes according to claim 6, characterized in that: The multi-dimensional characterization and identification of identity include collecting and expanding biometric fingerprints, software and hardware feature information, operating status, attributes of environmental context and behavioral feature information for user identity authentication. The system will comprehensively evaluate all the collected data and use the channel characteristics in wireless communication to perform multi-dimensional characterization, match the characterization results and calculate the final unique identity identifier Z for identification. If the identity identifier Z test passes and the matching score of the characterization result exceeds 0.8, the user successfully passes the identity authentication. If the identity identifier Z test fails and the matching score of the characterization result is less than 0.8, the identity authentication fails and access is denied. The system will start a secondary verification process. The system requires the user to provide additional identity proof, including receiving a text message verification code and performing biometric verification. After the user completes the secondary verification, if the verification is successful, access permission will be obtained. If it fails, the system will record the event and lock the account, and perform a rapid security incident detection response. The matching score threshold is increased when the channel conditions are good, and the matching score threshold is lowered when the channel conditions are poor.

8. A system using the distributed terminal entity identification method based on multi-dimensional attributes according to any one of claims 1 to 7, characterized in that: It includes survival status judgment and detection planning module, feature and behavior information extraction module and identity identification construction module; The survival status judgment and detection planning module identifies surviving devices in the network and plans the detection order of surviving devices through two scanning space dimensions; The feature and behavior information extraction module extracts terminal attribute elements and terminal behavior elements from the surviving network device if the device is alive. The terminal attribute elements include operating system attributes and device type attributes. The terminal behavior elements include network behavior and traffic content attributes, and channel state information (CSI). The identity identification construction module implicitly represents the terminal behavior characteristics based on the extraction of terminal attribute elements and terminal behavior elements in network surviving devices, and combines them with the terminal attribute element characteristics as different dimensions to construct a unique identity identification of the terminal for multi-dimensional identity characterization and identity recognition.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Multi-modal feature fusion gait recognition method based on wireless signals

    CN114360069A

  • Static and dynamic identification combined wireless sensor network cluster routing method and device

    CN117692989A