Method and related device for investigating illegal content distribution based on multiple information bases

By acquiring IP address information, domain name information, and certificate information of CDN traffic anomalies, and combining this with IP registration and domain name information, the problem of insufficient accuracy in detecting illegal content distribution in existing technologies has been solved, achieving more efficient detection of illegal content distribution.

CN119652589BActive Publication Date: 2026-07-21CHINA TELECOM CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2024-12-03
Publication Date
2026-07-21

Smart Images

  • Figure CN119652589B_ABST
    Figure CN119652589B_ABST
Patent Text Reader

Abstract

The application discloses an analysis method for checking illegal content distribution based on multiple information libraries and related equipment, and relates to the technical field of network security. The analysis method for checking illegal content distribution based on multiple information libraries comprises the following steps: firstly, obtaining IP address information of traffic anomaly, wherein the IP address information of traffic anomaly comprises IP filing information; secondly, obtaining domain name information corresponding to the IP address of traffic anomaly; thirdly, performing certificate chain analysis on the IP address information of traffic anomaly to obtain certificate information; and finally, determining whether illegal content distribution exists based on the IP filing information, the certificate information and the domain name information. The application starts with the IP address information of traffic anomaly, which can narrow the scope of investigation. Furthermore, the IP filing information, the domain name information and the certificate information of the IP address information of traffic anomaly are obtained, and the three key information, i.e. the IP filing information, the certificate information and the domain name information, are combined to determine whether illegal content distribution exists, which can improve the detection accuracy of illegal content distribution behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to an analysis method and related equipment for investigating the distribution of illegal content based on multiple information databases. Background Technology

[0002] With the rapid development of the internet, Content Delivery Network (CDN) technology is increasingly widely used in content distribution. A CDN is a distributed server system that improves the speed and availability of internet content delivery by deploying servers across multiple geographical locations. By caching content on edge servers closer to users, CDNs reduce the distance between users and origin servers, thus accelerating content loading. However, unauthorized content distribution using CDNs exists in internet applications, leading to resource abuse and cybersecurity risks.

[0003] The relevant technologies mainly screen for illegal content distribution by monitoring CDN traffic, but this method has the problem of insufficient detection accuracy. Summary of the Invention

[0004] The main objective of this application is to provide an analysis method and related equipment for investigating the distribution of illegal content based on multiple information databases, aiming to improve the detection accuracy of illegal content distribution behavior.

[0005] To achieve the above objectives, one aspect of this application proposes an analysis method for investigating the distribution of illegal content based on multiple information databases, comprising the following steps:

[0006] Obtain IP address information with abnormal traffic, including IP registration information;

[0007] Obtain the domain name information corresponding to the IP address with the abnormal traffic;

[0008] Certificate chain parsing is performed on the IP address information of the abnormal traffic to obtain certificate information;

[0009] Based on the IP registration information, the certificate information, and the domain name information, it is determined whether there is any illegal content distribution.

[0010] In some embodiments, the domain name information includes domain name ownership information and canonical name ownership information, and obtaining the domain name information corresponding to the IP address with abnormal traffic includes:

[0011] The domain name ownership information and the canonical name ownership information corresponding to the IP address with the abnormal traffic are determined by the domain name gene database, wherein the domain name gene database is used to characterize a global domain name information database including IP address information and domain name registration information;

[0012] The determination of whether illegal content distribution exists based on the IP registration information, the certificate information, and the domain name information includes:

[0013] Based on the IP registration information, the certificate information, the domain name ownership information, and the standardized name ownership information, it is determined whether there is any illegal content distribution.

[0014] In some embodiments, before obtaining the IP address information of abnormal traffic, the method further includes:

[0015] Obtain network traffic data;

[0016] The network traffic data is subjected to offline statistical analysis at a preset time period to obtain the analysis results;

[0017] Based on the analysis results, the IP address information of the abnormal traffic was determined.

[0018] In some embodiments, before obtaining the IP address information of abnormal traffic, the method further includes:

[0019] Obtain domain name system log data;

[0020] Based on the Domain Name System log data, the domain name and the corresponding IP address information are determined.

[0021] In some embodiments, the certificate information includes certificate user information, and the step of parsing the certificate chain of the IP address information with abnormal traffic to obtain the certificate information includes:

[0022] Certificate chain parsing is performed on the IP address information of the abnormal traffic to obtain the certificate user information;

[0023] The determination of whether illegal content distribution exists based on the IP registration information, the certificate information, and the domain name information includes:

[0024] Based on the IP registration information, the certificate user information, and the domain name information, it is determined whether there is any illegal content distribution.

[0025] In some embodiments, the IP filing information includes the IP filing entity, the domain name information includes domain name ownership information and canonical name ownership information, and the certificate information includes certificate user information. Determining whether illegal content distribution exists based on the IP filing information, the certificate information, and the domain name information includes:

[0026] Based on the IP registration authority, the domain name ownership information, the standardized name ownership information, and the certificate user information, it is determined whether there is any illegal content distribution.

[0027] In some embodiments, determining whether illegal content distribution exists based on the IP registration authority, the domain name ownership information, the canonical name ownership information, and the certificate user information includes:

[0028] If one or more of the information regarding the IP registration authority, the domain name ownership information, the standardized name ownership information, and the certificate user information are inconsistent, a compliance assessment will be conducted on the inconsistent information to obtain the assessment result.

[0029] The assessment results will determine whether any illegal content has been distributed.

[0030] In some embodiments, the assessment result includes a violation assessment result, wherein the compliance assessment of inconsistent information to obtain the assessment result includes:

[0031] Obtain content delivery network qualification information and content delivery network resource subleasing information;

[0032] If the Content Delivery Network (CDN) qualification indication information indicates that the inconsistent information does not possess the CDN qualification, or the CDN resource subleasing indication information indicates that the inconsistent information is a resource subleasing, then the violation assessment result is output.

[0033] In some embodiments, after determining whether illegal content distribution exists based on the IP registration information, the certificate information, and the domain name information, the method further includes:

[0034] The IP registration information, certificate information, domain name information, and information on whether illegal content is distributed will be stored and / or a visual analysis report will be generated.

[0035] To achieve the above objectives, another aspect of this application proposes an analysis device for investigating the distribution of illegal content based on multiple information databases, the device comprising:

[0036] The first acquisition module is used to acquire IP address information of abnormal traffic, including IP registration information.

[0037] The second acquisition module is used to acquire the domain name information corresponding to the IP address with abnormal traffic;

[0038] The certificate chain parsing module is used to parse the certificate chain of the IP address information with abnormal traffic to obtain certificate information;

[0039] The violation analysis module is used to determine whether there is any illegal content distribution based on the IP registration information, the certificate information, and the domain name information.

[0040] To achieve the above objectives, another aspect of this application proposes an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the above-described analysis method for investigating the distribution of illegal content based on multiple information databases.

[0041] To achieve the above objectives, another aspect of this application provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute the above-described analysis method for investigating the distribution of illegal content based on multiple information databases.

[0042] The embodiments of this application include at least the following beneficial effects:

[0043] This application provides an analysis method and related equipment for investigating the distribution of illegal content based on multiple information databases. In this embodiment, firstly, IP address information with abnormal traffic is obtained, including IP registration information; secondly, the domain name information corresponding to the IP address with abnormal traffic is obtained; thirdly, certificate chain parsing is performed on the IP address information with abnormal traffic to obtain certificate information; finally, the existence of illegal content distribution is determined based on the IP registration information, certificate information, and domain name information. This embodiment starts with IP address information with abnormal traffic, which can narrow the scope of investigation. Furthermore, by obtaining the IP registration information, domain name information, and certificate information of the IP address with abnormal traffic, and combining these three key pieces of information—IP registration information, certificate information, and domain name information—to determine whether illegal content distribution exists, the accuracy of detecting illegal content distribution behavior can be improved.

[0044] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0045] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0046] Figure 1 This is a flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided in some embodiments of this application;

[0047] Figure 2 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided by some embodiments of this application;

[0048] Figure 3 This is a flowchart of a method for determining abnormal traffic IP address information provided in some embodiments of this application;

[0049] Figure 4 This is a flowchart of a domain name information determination method provided in some embodiments of this application;

[0050] Figure 5 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided by some embodiments of this application;

[0051] Figure 6 yes Figure 1 The flowchart for step 104 in the document;

[0052] Figure 7 yes Figure 1 Another flowchart for step 104 in the process;

[0053] Figure 8 This is a flowchart illustrating the data acquisition and storage process provided in some embodiments of this application;

[0054] Figure 9 This is a flowchart of data acquisition and analysis provided in some embodiments of this application;

[0055] Figure 10 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided in some embodiments of this application;

[0056] Figure 11 This is a schematic block diagram of a module of an analysis device for investigating the distribution of illegal content based on multiple information databases, provided in some embodiments of this application;

[0057] Figure 12 These are schematic diagrams of the hardware structure of electronic devices provided in some embodiments of this application. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the reference to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments. The implementation methods described in the following exemplary embodiments do not represent all implementation methods consistent with the embodiments of this application; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this application as detailed in the appended claims.

[0059] It is understood that the terms “first,” “second,” etc., used in this application may be used herein to describe various concepts, but unless otherwise stated, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if,” “when,” or “in response to a determination” as used herein may be interpreted as “when…” or “when…” or “in response to a determination.”

[0060] As used in this application, the terms "at least one", "multiple", "each", "any", etc., "at least one" includes one, two or more, "multiple" includes two or more, "each" refers to each of the corresponding multiples, and "any" refers to any one of the multiples.

[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0062] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0063] To facilitate understanding of the inventive concept of this application, before providing a detailed description of the embodiments of this application, the English abbreviations (terms) / related concepts involved in the embodiments of this application will be explained first. The English abbreviations (terms) / related concepts involved in the embodiments of this application are subject to the following interpretation.

[0064] Domain name: A domain name is used to identify the name of a computer or network on the Internet. A complete domain name typically consists of a top-level domain (TLD) and a second-level domain (SLD). For example, example.com contains the second-level domain "example" and the top-level domain "com". Domain names not only make it easier for users to remember and identify a website, but they can also reflect information such as the nature of the website, its industry, or its geographical location.

[0065] Domain Certificate: A domain certificate is a digital certificate, also known as a domain SSL certificate (SSL stands for Secure Sockets Layer). It is a digital credential used to prove ownership of a domain name and to provide encrypted communication services. Like a domain's "ID card," it verifies the legitimacy of the domain owner and ensures data security during network communication.

[0066] Registration: Registration is a comprehensive concept encompassing IP address registration and domain name registration. IP address registration is the process by which Internet Service Providers (ISPs) or Internet Content Providers (ICPs) register and report their IP address information to the relevant regulatory authorities. Domain name registration is the process of registering and reporting domain name information (including domain owner, domain purpose, etc.) to the relevant national regulatory authorities.

[0067] CDN (Content Delivery Network) is a technology that uses globally deployed node servers to build an intelligent virtual network, enabling content to be distributed based on proximity, thus improving transmission speed and stability. CDNs can direct user requests to the nearest node server based on the user's location, network conditions, and load, effectively reducing data transmission distance and network latency, accelerating content loading, and enhancing user experience. Simultaneously, CDNs improve website stability, continuing to provide static content and ensuring website availability even when the origin server fails. By optimizing content delivery paths, CDNs solve internet congestion problems and improve website response speeds, making them a crucial technology for many websites and online services.

[0068] DNS: DNS (Domain Name System) is a fundamental service of the Internet. Its main function is to translate easy-to-remember domain names into IP addresses that computers can understand. This way, when users visit a website, they only need to enter the domain name, without having to remember complex IP addresses. For example, when you enter "www.example.com", DNS will translate it into the corresponding IP address, such as "192.168.1.1", so that computers can locate and access the website.

[0069] NetFlow: NetFlow is a widely used network traffic data statistics standard. NetFlow systems provide detailed traffic analysis by capturing information such as the timestamps of the first and last packets of a flow, the number of bytes exchanged and the total number of packets, and a summary of the flags used in a TCP connection. This data can help identify anomalous traffic patterns in the network, potential network security threats such as DDoS attacks, and facilitate traffic optimization and network planning.

[0070] CR device: CR device refers to the core router. The core router is a key device located at the center of the network, mainly responsible for forwarding data traffic between different ISP (Internet Service Provider) networks.

[0071] CNAME: CNAME (Canonical Name) is a record type in the Domain Name System (DNS) used to map a domain name (or subdomain) to another domain name. CNAME records are typically used to point a domain name to another domain name, rather than directly to an IP address.

[0072] With the rapid development of the Internet, Content Delivery Network (CDN) technology is increasingly widely used in content distribution. A CDN is a distributed server system that improves the speed and availability of Internet content delivery by deploying servers across multiple geographical locations. By caching content on edge servers closer to users, CDNs reduce the distance between users and origin servers, thereby accelerating content loading.

[0073] However, unauthorized content distribution via CDNs still exists in internet applications, leading to resource abuse and cybersecurity risks. This is mainly reflected in the following aspects:

[0074] 1. Resource theft: Some people may use CDN services to steal other people's legitimate content, such as unauthorized videos, music or software download links, in order to illegally obtain economic benefits.

[0075] 2. Dissemination of prohibited content: CDNs are used as distribution channels for illegal, harmful, or prohibited content, such as pornographic materials, malicious software, malicious advertisements, or content involving copyright infringement.

[0076] 3. Network attacks: Malicious users may use CDNs to launch distributed denial-of-service (DDoS) attacks, distributing traffic to multiple sources to conceal their true identity and increase the power of the attack.

[0077] 4. Information theft: Hackers or criminals can manipulate CDN services to steal users' sensitive personal information, account credentials, or other confidential data.

[0078] 5. Unauthorized advertising: Some unscrupulous advertisers may abuse CDN services to interfere with users' browsing experience through malicious advertising plugins or pop-ups, or to fraudulently guide users to dangerous websites.

[0079] 6. Hacking infrastructure: Criminals may use CDN services as the infrastructure for hacking attacks, including hosting malware, command and control servers, and conducting phishing activities.

[0080] 7. Tampering with website content: Malicious users can manipulate CDN services to tamper with website content, including modifying page information, inserting malicious code, or engaging in fraudulent activities, thereby causing harm to users.

[0081] 8. Bypassing geographical restrictions: Some users may use CDNs to bypass geographical restrictions and access content or services in restricted areas. This may involve pirated content, illegal activities, or bypassing copyright protection mechanisms.

[0082] 9. Piracy and intellectual property infringement: CDN services may be abused to distribute pirated software, movies, music and other copyrighted content, thereby infringing on the intellectual property rights of original authors.

[0083] 10. Anti-competitive behavior: Some companies may abuse CDN services to engage in anti-competitive behavior, such as blocking competitors' content delivery or interfering with users' access to competitors' websites in order to gain an unfair competitive advantage.

[0084] The main technology for screening illegal content distribution is through monitoring CDN traffic. However, this method has problems such as limited detection range, insufficient accuracy, and difficulty in large-scale screening.

[0085] In view of this, this application proposes an analysis method and related equipment for investigating the distribution of illegal content based on multiple information databases. This scheme obtains IP address information with abnormal traffic, including IP registration information; secondly, it obtains the domain name information corresponding to the IP addresses with abnormal traffic; thirdly, it performs certificate chain parsing on the IP address information with abnormal traffic to obtain certificate information; finally, it determines whether illegal content distribution exists based on the IP registration information, certificate information, and domain name information. This application's embodiment first starts with IP address information with abnormal traffic, which can narrow down the investigation scope. Furthermore, by obtaining the IP registration information, domain name information, and certificate information of the IP addresses with abnormal traffic, and combining these three key pieces of information—IP registration information, certificate information, and domain name information—to determine whether illegal content distribution exists, the accuracy of detecting illegal content distribution behavior can be improved.

[0086] The method provided in this application embodiment can be applied to the electronic device provided in this application embodiment, wherein the electronic device can be a terminal or a server.

[0087] The terminal can be a tablet computer, a laptop computer, a desktop computer, etc., but is not limited to these.

[0088] A server can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks, and big data and artificial intelligence platforms.

[0089] It should be noted that in each specific implementation of this application, when it is necessary to process data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of this data will comply with relevant laws, regulations, and standards.

[0090] The implementation steps of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided in this application, will be described in detail below with reference to the accompanying drawings.

[0091] Please refer to Figure 1 , Figure 1 This is a flowchart of an analysis method for investigating the distribution of illegal content based on multiple databases, provided by some embodiments of this application. It should be noted that the steps shown in the flowcharts can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be performed in a different order than that shown here.

[0092] The method of the embodiments of this application includes the following steps:

[0093] Step 101: Obtain IP address information with abnormal traffic, including IP registration information;

[0094] Step 102: Obtain the domain name information corresponding to the IP address with abnormal traffic;

[0095] Step 103: Perform certificate chain parsing on the IP address information with abnormal traffic to obtain certificate information;

[0096] Step 104: Determine whether there is any illegal content distribution based on IP registration information, certificate information, and domain name information.

[0097] For example, the filing information of IP addresses with abnormal traffic can be obtained from the IP filing database, including the filing entity, filing number, filing time, etc.; the certificate information of IP addresses with abnormal traffic can be obtained, including SSL / TLS certificates, and their validity, issuing authority, validity period, etc. can be confirmed; the domain name information corresponding to IP addresses with abnormal traffic can be obtained, including the domain name registration information, such as registrant, registration time, expiration time, etc.

[0098] Further verify whether the filing entity is legitimate and consistent with the actual operating entity; check whether the filing number is genuine and valid and matches the filing entity.

[0099] Verify that the certificate was issued by a trusted CA by checking the certificate's validity period to ensure it has not expired, and verify that the domain name in the certificate matches the domain name actually used.

[0100] Verify the legitimacy of the domain registrant through the domain genealogy database and whether it is consistent with the filing entity; check the domain's registration time, expiration time, and whether there are frequent change records.

[0101] Based on the above analysis results, it can be determined whether there is any illegal content distribution.

[0102] Steps 101 to 104 as shown in this embodiment first start with the IP address information of abnormal traffic, which can narrow down the scope of investigation. Furthermore, the IP filing information, domain name information and certificate information of the IP address information of abnormal traffic are obtained. By combining the three key pieces of information, namely IP filing information, certificate information and domain name information, it can be determined whether there is illegal content distribution, which can improve the detection accuracy of illegal content distribution behavior.

[0103] The specific implementation methods for each of the above steps are described below.

[0104] Before obtaining information about IP addresses with abnormal traffic, it's necessary to identify and pinpoint these IP addresses based on traffic data. See the appendix for specific methods. Figure 3 , Figure 3 This is a flowchart of a method for determining abnormal IP address information based on some embodiments of this application.

[0105] The method for determining IP address information due to abnormal traffic includes the following steps:

[0106] Step 301: Obtain network traffic data;

[0107] Step 302: Perform offline statistical analysis on network traffic data at a preset time period to obtain the analysis results;

[0108] Step 303: Determine the IP address information of the abnormal traffic based on the analysis results.

[0109] Alternatively, traffic data can be collected using Netflow.

[0110] For example, CR devices covering the entire administrative region of country A can collect IP-based traffic across all ports using the NetlowV5 or NetflowV9 protocols, and the collected data can be parsed and stored in JSON format. JSON (JavaScript Object Notation) is a lightweight data exchange format that is easy for humans to read and write, and also easy for machines to parse and generate. It should be understood that the collected data can also be saved in other easily analyzable data formats, such as XML (eXtensible Markup Language), YAML (YAML Ain't Markup Language), or MessagePack formats; this application does not impose any limitations on this.

[0111] The NetlowV5 protocol is easy to implement due to its fixed template and limited fields; the NetlowV9 protocol's templated design makes it very flexible, adapting to ever-changing network environments and new traffic analysis needs, thus providing more functionality and flexibility.

[0112] Netflow can collect traffic data to provide detailed traffic information, including source and destination IP addresses, source port, destination port, collection time, source Autonomous System number (source AS number), destination AS number, protocol type, data packets and bytes, etc. This information helps to understand the distribution and trends of network traffic.

[0113] It should be understood that embodiments of this application may also utilize other traffic data collection tools, such as SolarWindsHybrid Cloud Observability (which supports real-time monitoring of network traffic and detection of potential problems) or ManageEngine NetFlow Analyzer (which provides real-time network traffic reports and detailed traffic analysis), and this application does not limit this to such methods.

[0114] Optionally, the acquired network traffic data can be subjected to offline statistical analysis at a preset time period to obtain analysis results.

[0115] The preset time period can be flexibly set according to available computing resources or the amount of traffic acquired. For example, the preset time period can be set to 1 day or 2 days. Specifically, the acquired traffic data can be partitioned by day and offline statistical analysis can be performed on a daily basis.

[0116] For example, traffic analysis tools or scripts can be used to analyze the collected data. Specifically, one can focus on the traffic size, i.e., check for abnormally large traffic; traffic patterns, i.e., analyze traffic patterns, such as sudden increases or decreases in traffic; protocols and ports, i.e., check for abnormal protocol or port activity; check for abnormally long or short traffic durations or unusual traffic flows, such as a sudden large flow of internal network traffic to the external network.

[0117] Based on the analysis results, IP addresses exhibiting abnormal traffic can be identified, such as IP addresses with unusually high traffic, IP addresses associated with known malicious activity, or IP addresses with abnormal protocol or port activity. Furthermore, information related to these IP addresses can be obtained, such as IP registration information. This allows for precise location of the IP address back to the registered customer.

[0118] The embodiments provided in this application acquire network traffic data, perform offline statistical analysis on the network traffic data through a preset time period, obtain analysis results, and determine IP address information with abnormal traffic based on the analysis results, providing a decision-making basis for subsequent determination of whether there is illegal content distribution.

[0119] While acquiring network traffic data, it can also simultaneously acquire Domain Name System (DNS) log information.

[0120] Please refer to Figure 4 , Figure 4 This is a flowchart of a domain name information determination method provided in some embodiments of this application.

[0121] The method for determining domain name information includes the following steps:

[0122] Step 401: Obtain Domain Name System log data;

[0123] Step 402: Based on the Domain Name System log data, determine the domain name and the corresponding IP address information.

[0124] For example, DNS log data from each province can be collected to a centralized data storage device through collection servers deployed by the operator in each province, partitioned by day, and the DNS log data can be subjected to offline statistical analysis on a daily basis.

[0125] Domain Name System (DNS) log data includes, but is not limited to, the following information: domain name, CNAME, resolved IP, port, collection time, and requesting IP.

[0126] Information such as domain names, CNAME records, and IP addresses can be obtained by resolving DNS log data.

[0127] For example, obtaining Domain Name System (DNS) log data can be achieved by connecting a splitter to the link between the DNS switch and the CR (Log Controller), or by mirroring the link between the DNS switch and the CR to transmit the collected data to a centralized storage device, where the data is stored on HDFS (Hadoop Distributed File System). HDFS is primarily used for storing and managing large-scale datasets. It is a distributed file system capable of reliably storing large datasets on inexpensive hardware and providing high-throughput data access capabilities.

[0128] After obtaining network traffic data and domain name system log information, the distribution of illegal content can be judged based on the above information and some specific information.

[0129] This specific information can include IP registration information, certificate information, and domain name information.

[0130] The following sections introduce the specific methods for obtaining IP registration information, certificate information, and domain name information.

[0131] In step 101, the IP address information of abnormal traffic is obtained, including IP registration information.

[0132] The above embodiments have described a method for determining IP address information of abnormal traffic (see steps 301 to 303).

[0133] Based on the identified IP address information indicating abnormal traffic, further information about the IP address's ownership can be obtained through the IP address registration system.

[0134] IP registration information typically includes basic information about the registering entity, IP address source information, and IP address allocation and usage information. For example, the basic information about the registering entity may include the entity's name (e.g., a technology company); the entity's address (e.g., No. [Number], [Road], [District], City B); the entity's nature (e.g., a private enterprise); and contact information.

[0135] This application embodiment can determine the IP owner (registration unit) of the IP with abnormal traffic by obtaining the IP registration information of the abnormal traffic, and provide a basis for decision-making in subsequent judgment of illegal content distribution behavior.

[0136] In step 102, the domain name information corresponding to the IP address with abnormal traffic is obtained.

[0137] The above embodiments have described a method for determining domain name information, which associates domain name and IP address information.

[0138] It should be understood that DNS log data includes, but is not limited to, information such as domain name, CNAME, resolved IP, port, collection time, and requesting IP. Therefore, domain name and CNAME information can be resolved based on DNS log data, and domain name genealogy databases can be used to determine domain name ownership information and CNAME ownership information.

[0139] In some embodiments of this application, the domain name information includes domain name ownership information and CNAME ownership information. The domain name ownership information and CNAME ownership information corresponding to IP addresses with abnormal traffic can be determined by a domain name gene database. The domain name gene database is used to characterize a global domain name information database that includes IP address information and domain name registration information.

[0140] It should be understood that the domain name database is a global domain name information database, which includes IP address information, domain name registration information, and may also include ICP filing information from the Ministry of Industry and Information Technology (MIIT). In other words, a global domain name information database can be established based on the operator's IP address filing system, domain name registration information, and MIIT ICP filing information. Domain name registration information mainly includes the following aspects: domain name owner information, registrar information, domain name server information, and domain name DNS information (the mapping between hostname and IP address), etc. MIIT ICP filing information mainly includes information about the organizer, website information, website access information, etc. CNAME attribution information can be indirectly obtained through ICP filing information.

[0141] Therefore, the domain name ownership information (domain owner information) and canonical name (CNAME) ownership information can be determined by using the domain name gene database based on the IP address with abnormal traffic.

[0142] Please see Figure 2 , Figure 2 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided by some embodiments of this application. Figure 2 The steps in the example include:

[0143] Step 201: Obtain IP address information with abnormal traffic, including IP registration information;

[0144] Step 202: Determine the domain name ownership information and canonical name ownership information corresponding to the IP addresses with abnormal traffic through the domain name gene database;

[0145] Step 203: Perform certificate chain parsing on the IP address information with abnormal traffic to obtain certificate information;

[0146] Step 204: Determine whether there is any illegal content distribution based on IP registration information, certificate information, domain name ownership information, and standardized name ownership information.

[0147] For example, the filing information of IP addresses with abnormal traffic can be obtained from the IP filing database, including the filing entity, filing number, filing time, etc.; the certificate information of IP addresses with abnormal traffic can be obtained, including SSL / TLS certificates, and their validity, issuing authority, validity period, etc. can be confirmed; and the domain name ownership information and CNAME ownership information corresponding to the IP addresses with abnormal traffic can be determined through the domain name gene database.

[0148] Further verify whether the filing entity is legitimate and consistent with the actual operating entity; check whether the filing number is genuine and valid and matches the filing entity.

[0149] Confirm that the certificate was issued by a trusted CA, check the certificate's validity period to ensure it has not expired, and verify that the domain name in the certificate matches the domain name actually used.

[0150] Confirm whether the domain registrant (domain ownership information) is legal and consistent with the filing entity; check whether the CNAME ownership information is legal and consistent with the filing entity, etc.

[0151] Based on the above analysis, it can be determined whether there is any illegal content distribution. For example, if there is a discrepancy between the registered entity and the domain name, or if the certificate's user organization is inconsistent with the domain's ownership information, further analysis can be conducted to determine if there is a legitimate relationship between the two. If no legitimate relationship exists, then illegal content distribution is considered to have occurred.

[0152] This application embodiment determines whether there is illegal content distribution by using IP registration information, certificate information, domain name ownership information, and standardized name ownership information, which can improve the accuracy of illegal content distribution detection.

[0153] In step 103, certificate chain parsing can be performed on the IP address information with abnormal traffic to obtain certificate information.

[0154] For example, certificate chain parsing can be performed on high-traffic IP addresses identified by Netflow statistics to obtain information such as the organization using the SSL certificate, the user's common name, the issuing organization, and the validity period.

[0155] Specifically, the collected Netflow data can be analyzed to identify high-traffic IP addresses. These IP addresses may be critical nodes in the network. For the identified high-traffic IP addresses, their corresponding SSL certificates can be obtained. For example, for a web server, an SSL / TLS handshake can be initiated to obtain an SSL certificate. The obtained certificate may be a certificate chain, including the server certificate, intermediate certificates, and root certificate. This certificate chain needs to be parsed to extract information from each certificate, including key information such as the issuing organization, user common name, issuing organization, and validity period. For non-web services, specific clients or tools may be needed to obtain SSL certificates. For example, for SMTP services, the command "openssl s_client-starttls smtp-connect server.com:25" can be used to obtain the certificate.

[0156] In some implementations, the certificate information includes certificate user information, which can be obtained by parsing the certificate chain based on the IP address information with abnormal traffic.

[0157] Please see Figure 5 , Figure 5 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided by some embodiments of this application. Figure 5 The steps in the example include:

[0158] Step 501: Obtain IP address information with abnormal traffic, including IP registration information;

[0159] Step 502: Obtain the domain name information corresponding to the IP address with abnormal traffic;

[0160] Step 503: Perform certificate chain parsing on the IP address information with abnormal traffic to obtain the certificate user information;

[0161] Step 504: Determine whether there is any illegal content distribution based on IP registration information, certificate user information, and domain name information.

[0162] The specific implementation methods for steps 501 to 503 can be found in the description in the above embodiments.

[0163] Determining whether illegal content distribution exists based on IP registration information, certificate user information, and domain name information involves comparing the website information in the IP registration information with the certificate user information to check for inconsistencies or contradictions. Content reviews are conducted on the registered website and websites associated with the certificate user to check for illegal content. The IP registration information, certificate user information, and domain name information are checked for compliance with relevant laws, regulations, and industry standards to determine whether illegal content distribution has occurred.

[0164] The embodiments provided in this application determine whether there is illegal content distribution by using IP registration information, certificate user information, and domain name information. By performing correlation analysis on IP registration information, certificate user information, and domain name information, the accuracy of illegal content distribution detection can be improved.

[0165] In step 104, it is determined whether there is any illegal content distribution based on IP registration information, certificate information, and domain name information.

[0166] IP registration information typically includes basic information about the registration entity, IP address source information, and IP address allocation and usage information.

[0167] Certificate information typically includes the organization using the certificate, the user's common name, the issuing organization, and the validity period.

[0168] Domain information can include the domain name, CNAME, domain ownership information, and CNAME ownership information.

[0169] The presence of illegal content distribution can be determined by checking IP registration information, certificate information, and domain name information.

[0170] For example, it can be confirmed whether the IP registration entity is legitimate and consistent with the actual operating entity; and the registration number can be checked to ensure it is authentic and valid and matches the registration entity.

[0171] Verify that the certificate was issued by a trusted CA, check the certificate's validity period to ensure it has not expired, and verify that the certificate's user organization is consistent with the domain name registrant.

[0172] Confirm whether the domain registrant (domain ownership information) is legal and consistent with the filing entity; check whether the CNAME ownership information is legal and consistent with the filing entity, etc.

[0173] Based on the above analysis, it can be determined whether there is any illegal content distribution. For example, if there is a discrepancy between the entity registered and the entity that filed the certificate, or if the user organization of the certificate does not match the registrant information of the domain name, further analysis can be conducted to determine if there is a legitimate relationship between the two. If no legitimate relationship exists, then illegal content distribution is considered to have occurred.

[0174] In some implementations, IP filing information includes the IP filing entity, domain name information includes domain name ownership information and CNAME ownership information, and certificate information includes certificate user information. It is possible to determine whether there is any illegal content distribution based on the IP filing entity, domain name ownership information, canonical name ownership information, and certificate user information.

[0175] Optionally, if there is one or more inconsistencies in the IP registration entity, domain name ownership information, canonical name ownership information, and certificate user information, a compliance assessment needs to be conducted on the inconsistencies to obtain the assessment results, and the existence of illegal content distribution needs to be determined based on the assessment results.

[0176] After obtaining information on the IP registration authority, domain name ownership, standardized name ownership, and certificate user, this information can be further verified to ensure its authenticity. If one or more of this information is inconsistent, the reasons for the inconsistency need to be analyzed, and the legality and compliance of the reasons need to be assessed to determine whether there has been any illegal content distribution.

[0177] In some implementations, a compliance assessment is performed on inconsistent information to obtain the assessment result. This may involve obtaining content delivery network qualification indication information and content delivery network resource subleasing indication information. If the inconsistent content delivery network qualification indication information indicates that the information does not have content delivery network (CDN) qualifications, or if the inconsistent content delivery network resource subleasing indication information indicates that the information is a resource subleasing, then a violation assessment result is output.

[0178] Inconsistencies could arise between the IP registration authority and certificate user information, or between the IP registration authority and domain ownership information. If inconsistencies exist, further analysis is needed. For example, determine if one party possesses CDN qualifications, or if one party is involved in CDN secondary distribution. If one party possesses CDN qualifications or is engaged in CDN secondary distribution, it constitutes legitimate proxying and conforms to normal content distribution behavior. If it lacks CDN qualifications or is directly subletting resources, it may be an illegal proxy.

[0179] Please see Figure 6 , Figure 6 yes Figure 1 The flowchart for step 104 in the process.

[0180] Figure 6In this process, after obtaining information on the IP registration entity, domain name ownership, canonical name ownership, and certificate user, the system determines if there are any inconsistencies among these information. If all information is consistent, meaning the IP registration entity, domain name ownership, canonical name ownership, and certificate user information all point to the same user, then the distribution behavior is considered compliant. If the IP registration entity, domain name ownership, canonical name ownership, and certificate user information all point to multiple users, then there are inconsistencies among these information. Furthermore, it needs to be determined whether the inconsistent information possesses CDN qualifications. If it does, the distribution behavior is considered compliant; otherwise, it is considered non-compliant.

[0181] Figure 7 yes Figure 1 The flowchart for step 104 in the diagram describes another way to determine whether content distribution behavior is compliant.

[0182] Figure 7 After obtaining information on the IP registration entity, domain name ownership, canonical name ownership, and certificate user, the system determines if there are any inconsistencies among these information. If all information is consistent (i.e., the IP registration entity, domain name ownership, canonical name ownership, and certificate user information all point to the same user), the distribution behavior is considered compliant. If the IP registration entity, domain name ownership, canonical name ownership, and certificate user information point to multiple users, then inconsistencies exist. Further, it needs to be determined whether the inconsistencies involve CDN secondary distribution. If CDN secondary distribution is involved, the distribution behavior is considered compliant; if it does not involve CDN secondary distribution but rather direct resource subleasing, then the distribution behavior is considered non-compliant.

[0183] The embodiments provided in this application determine whether illegal content distribution exists based on IP registration information, certificate information, and domain name information. Specifically, it determines whether illegal content distribution exists by checking whether the IP registration entity, domain name ownership information, canonical name ownership information, and certificate user information all point to the same user. This allows focusing on the problem itself, directly investigating CDN violations through the most core information, reducing false positives, and improving the accuracy of violation detection. By comparing IP registration information and domain name ownership information, unauthorized CDN resale activities can be quickly discovered and marked, reducing network security risks.

[0184] In some embodiments of this application, IP registration information, certificate information, domain name information, and information on whether illegal content is distributed can also be stored and / or a visual analysis report can be generated.

[0185] It should be understood that the process of identifying IP address and domain name information related to abnormal traffic may involve precisely matching information such as source IP, destination IP, source port, destination port, collection time, source Autonomous System Number (AS number), and destination AS number from Netflow data with information such as domain name, resolved IP, port, collection time, and requesting IP from DNS logs. This involves using the correlation between timestamps, IP addresses, and ports as the core basis to associate traffic data with domain-related data, and conducting a comprehensive analysis and matching of IP addresses, domain name information, and traffic. This process involves data storage and analysis.

[0186] Please refer to Figure 8 , Figure 8 This is a flowchart of data acquisition and storage provided in some embodiments of this application.

[0187] Figure 8 In the process, the input data traffic is divided into two paths. One path flows through the CR device and into the Netflow acquisition server to collect and analyze the traffic composition information. The other path flows through the DNS server and into the DNS acquisition server to collect and analyze the DNS information. After that, the collected and analyzed data is stored in the data storage module.

[0188] For example, for DNS collection, a splitter can be connected in series between the DNS switch and the CR, or the link from the DNS switch to the CR can be mirrored to transmit the collected data to a centralized storage device, and the data is stored on HDFS.

[0189] For NetFlow data collection, traffic composition information of network egress devices can be collected through the NetFlowV5 or NetFlowV9 protocols, and the data is stored on HDFS.

[0190] Figure 9 The data collection and analysis process. Figure 9 In this process, one traffic stream passes through the CR core router, is collected by Netflow, received by Kafka (an open-source distributed stream processing platform), and then analyzed by Flink. The other traffic stream passes through the DNS server, is collected by DNS, then transferred via FTP, passes through data nodes, and is analyzed by Flink. The Flink analysis results are then displayed.

[0191] Kafka is a distributed stream processing platform primarily used to build real-time data streaming pipelines and stream processing applications. It receives data collected by Netflow and stores it in Kafka topics. This data can then be transmitted to other systems, such as Flink Analytics, for real-time data processing and analysis.

[0192] Flink analytics is primarily used for processing real-time data streams and batch datasets. It provides a distributed, high-performance stream processing framework applicable to scenarios such as real-time data processing, event-driven applications, data integration, and data warehousing. Flink analytics can perform real-time computation, aggregation, filtering, and transformation on data, and output the results to various storage systems. In this embodiment, Flink is used to perform computation and analysis on data collected via Netflow and DNS data to obtain the analysis results.

[0193] The above describes the storage and analysis process of the collected data in the embodiments of this application.

[0194] When storing and / or generating visual analysis reports on IP registration information, certificate information, domain name information, and information on whether illegal content is being distributed, key information can be stored and / or displayed based on the data collected, stored, and analyzed above.

[0195] The visualization display can include data visualization, information visualization and other methods. Data visualization can be displayed using chart types (bar chart, line chart, pie chart, histogram, etc.), interactive methods (filtering, aggregation, sorting), 3D visualization and dynamic visualization, etc. Information visualization can be displayed using infographics and information boxes, visual design elements (color, texture and pattern, etc.), data mapping, network and relationship diagrams, etc. This application does not limit the scope of the visualization.

[0196] For example, data on the distribution of illegal content can be visualized, specifically displaying one or more of the following information: IP address, IP address, certificate chain platform, domain name, domain name owner, CNAME, CNAME owner, traffic, and whether it involves the distribution of illegal content.

[0197] The embodiments provided in this application store and / or generate visual analysis reports on IP registration information, certificate information, domain name information, and information on the distribution of illegal content. This ensures data persistence, which is beneficial for subsequent data queries, audits, and compliance checks. It also helps to transform complex data into easy-to-understand charts and graphs, improving user experience. The generation of visual analysis reports can be automated, generated and sent to relevant personnel on a regular basis, saving time spent on manual report creation and improving work efficiency.

[0198] The solutions of the embodiments of the present invention will be described in detail and explained below with reference to specific application examples:

[0199] This application provides an analysis method for investigating the distribution of illegal content based on multiple information databases. This method is used to investigate unauthorized content distribution behavior using CDN in the network. It can proactively investigate illegal CDN behavior in a massive data environment and improve the level of network security management.

[0200] Specifically, please refer to Figure 10 , Figure 10 This is another flowchart of an analysis method for investigating the distribution of illegal content based on multiple information databases, provided in some embodiments of this application.

[0201] Figure 10 In this context, NetFlow and DNS data collection for traffic data can be implemented. For example, a splitter can be connected in series on the link between the DNS switch and the CR (Cybernetic Relay), or the link from the DNS switch to the CR can be mirrored to collect and transmit data to a centralized storage device. The collected data is then stored on HDFS to achieve DNS data collection for traffic. Alternatively, traffic composition information from network egress devices can be collected using the NetFlowV5 or NetFlowV9 protocols and stored on HDFS to achieve NetFlow data collection for traffic. The collected data can then be used to identify IP information associated with abnormal traffic, such as high-volume IP addresses.

[0202] For data collected by Netflow, IP registration resolution can be performed using the registration system that manages IP addresses nationwide by telecom operators. This system can resolve the usage of high-traffic IPs by analyzing customer information, including obtaining IP address attribution information.

[0203] The collected DNS information is used to perform domain name resolution, including resolving domain names, CNAME information, etc. in the DNS logs; the domain name gene database is used to determine the domain name owner and the CNAME owner.

[0204] Perform certificate chain parsing on high-traffic IP addresses from Netflow statistics, including obtaining information such as the organization using the SSL certificate, the user's common name, the issuing organization, and the validity period, and establish comprehensive network data associations.

[0205] Next, combining Netflow and DNS log data, matching is performed based on IP, time, port, etc., outputting fully correlated data of traffic data with domain names, CNAME, certificate chain platforms, etc. The source IP, destination IP, source port, destination port, collection time, source AS number, destination AS number, and other entries in the Netflow data are precisely matched with the domain name, resolved IP, port, collection time, request IP, etc., in the DNS logs. Using the correlation between timestamps, IP addresses, and ports as the core basis, traffic data and domain-related data are accurately correlated, enabling comprehensive analysis and matching of IP addresses, domain information, and traffic.

[0206] This system integrates and analyzes DNS logs, domain name databases, IP registration databases, and certificate chain platform information. Based on customer information, it outputs inconsistencies in customer information across various data sources to assess the existence of illegal CDN behavior and ultimately outputs a conclusion on whether a violation has occurred. Through in-depth integration and comprehensive logical analysis of various data involved in the analysis and judgment of inconsistent customer information entries, certificate chain resolution results, domain name resolution data, and illegal content distribution, the system comprehensively evaluates the legality and compliance of CDN proxy behavior, generating a conclusive report containing key information such as whether illegal CDN behavior exists, the type of illegal behavior, the specific domains involved, the IP address range, relevant customer information, and the severity of the illegal behavior.

[0207] For example, the collected data is analyzed. Through the IP registration database, the following high-traffic IP information is obtained: Digital Life Department 61.172.*.* (IP address); through the certificate chain platform resolution module, the following certificate chain platform information is obtained: User Common Name (CN) download.ks-cdn.com; User Organization (O) City A Technology Co., Ltd.; Issuing Organization (O) Sectigo Limited; Issuance Date: [Date and Time]; Expiry Date: [Date and Time]; through the domain name base gene database, the following domain name information is obtained: zell.dl.playstation.net B Entertainment Co., Ltd.; through the domain name base gene database, the following CNAME information is obtained: kjyundn.com City A Technology Co., Ltd.

[0208] Based on the above information, namely IP registration, certificate chain platform, domain name, and CNAME customer attribution information, it can be concluded that City A Technology Co., Ltd. used the IP of the Digital Life Department to act as a proxy for the services of Entertainment Co., Ltd.

[0209] Further, it needs to be determined whether City A Technology Co., Ltd. and the Digital Life Department have CDN qualifications and whether they are engaged in CDN secondary distribution. If they have CDN qualifications or are engaged in CDN secondary distribution, they are considered legitimate agents. If they do not have CDN qualifications or are directly subletting resources, then they may be engaging in illegal agency activities. In this case, City A Technology Co., Ltd. used the resources of the Digital Life Department for CDN distribution, which is suspected of being secondary resale and is judged to be an illegal content distribution business.

[0210] Furthermore, by precisely matching the source IP, destination IP, source port, destination port, collection time, source AS number, and destination AS number in the Netflow data with DNS logs, traffic data and domain-related data are accurately associated, enabling a comprehensive and accurate matching of IP addresses, domain information, and traffic. The results are directly saved to the database for page display. An example is shown in Table 1.

[0211] Table 1 CDN Violation Information Table

[0212]

[0213] The above is an introduction to an embodiment of the analysis method for investigating the distribution of illegal content based on multiple information databases provided in this application.

[0214] The implementation of the analysis device for investigating the distribution of illegal content based on multiple information databases, provided in this application, will now be described in detail with reference to the accompanying drawings.

[0215] Regarding the analysis method for investigating the distribution of illegal content based on multiple information databases provided in the above embodiments, this application also provides an analysis device for investigating the distribution behavior of illegal content based on multiple information databases, used to implement the above method, such as... Figure 11 As shown, Figure 11 This is a schematic block diagram of a module for an analysis device based on multiple databases to investigate the distribution of illegal content, according to an embodiment of this application. The illegal content distribution behavior analysis device 1100 includes:

[0216] The first acquisition module 1101 is used to acquire IP address information of abnormal traffic, including IP registration information.

[0217] The second acquisition module 1102 is used to acquire the domain name information corresponding to the IP address with abnormal traffic;

[0218] The certificate chain parsing module 1103 is used to parse the certificate chain of IP address information with abnormal traffic to obtain certificate information;

[0219] The violation analysis module 1104 is used to determine whether there is any illegal content distribution based on IP registration information, certificate information, and domain name information.

[0220] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0221] like Figure 12 As shown, this application embodiment also provides an electronic device, the electronic device 1200 including a memory 1201, one or more processors 1202 (… Figure 12 (Only one is shown in the image) and a computer program stored in memory 1201 and executable on processor 1202. Memory 1201 stores software programs and units. Processor 1202 executes various functional applications and data processing by running the software programs and units stored in memory 1201 to obtain resources corresponding to the aforementioned preset events. Optionally, processor 1202 implements the aforementioned analysis method for investigating the distribution of illegal content based on multiple information databases by running the aforementioned computer program stored in memory 1201.

[0222] Memory 1201 serves as a non-transitory computer-readable medium, used for storing non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory 1201 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory 1201 may optionally include memory remotely located relative to the processor, which can be connected to the processor 1202 via a network.

[0223] It is understood that the content of the above method embodiments is applicable to the embodiments of this electronic device. The specific functions implemented by the embodiments of this electronic device are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0224] This application also provides a computer program product, which includes a computer program. When the computer program is executed by one or more processors, it can implement the steps of the analysis method for investigating the distribution of illegal content based on multiple information databases as described above.

[0225] It is understood that the content of the above method embodiments is applicable to this computer program product. The specific functions implemented by the embodiments of this computer program product are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0226] The analysis method, apparatus, electronic device, medium, and computer program product for investigating the distribution of illegal content based on multiple information databases provided in this application embodiment first obtains IP address information with abnormal traffic, including IP registration information; second, it obtains the domain name information corresponding to the IP address with abnormal traffic; third, it performs certificate chain parsing on the IP address information with abnormal traffic to obtain certificate information; finally, it determines whether illegal content distribution exists based on the IP registration information, certificate information, and domain name information. This application embodiment starts with IP address information with abnormal traffic, which can narrow the scope of investigation. Furthermore, it obtains the IP registration information, domain name information, and certificate information of the IP address with abnormal traffic. By combining these three key pieces of information—IP registration information, certificate information, and domain name information—it can determine whether illegal content distribution exists, thus improving the accuracy of detecting illegal content distribution behavior. By combining the domain name database, certificate chain, and IP registration database, it achieves multi-dimensional correlation analysis of illegal content distribution behavior, improving the accuracy and reliability of violation detection. By matching NetFlow data, it obtains information such as IP, domain name, domain name ownership, traffic, flow direction, protocol type, application port, and connection duration, ensuring the comprehensiveness of the detection information.

[0227] The embodiments provided in this application achieve precise IP address location through an IP address registration database system, reducing false positive rates and improving the accuracy of violation detection; by collecting and analyzing NetFlow and DNS log data, it can quickly identify and respond to illegal CDN behavior in the network, improving overall network security protection capabilities; through accurate IP location and domain name registration information comparison, it can quickly discover and mark unauthorized CDN resale behavior, reducing network security risks; through automated monitoring and analysis processes, it reduces manual intervention and improves the efficiency of network management and violation detection; through effective violation detection and prevention, it maintains the fairness and security of network services, enhancing users' trust and reliance on the services.

[0228] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0229] Although specific embodiments are described herein, those skilled in the art will recognize that many other modifications or alternative embodiments are also within the scope of this disclosure. For example, any of the functions and / or processing capabilities described in connection with a particular device or component can be performed by any other device or component. Furthermore, while various exemplary embodiments and architectures have been described according to embodiments of this disclosure, those skilled in the art will recognize that many other modifications to the exemplary embodiments and architectures described herein are also within the scope of this disclosure.

[0230] The foregoing description, with reference to block diagrams and flowcharts of systems, methods, systems, and / or computer program products according to exemplary embodiments, has described certain aspects of this disclosure. It should be understood that one or more blocks in the block diagrams and flowcharts, as well as combinations of blocks in the block diagrams and flowcharts, can be implemented by executing computer-executable program instructions, respectively. Similarly, according to some embodiments, some blocks in the block diagrams and flowcharts may not need to be executed in the order shown, or may not all need to be executed. Furthermore, additional components and / or operations beyond those shown in the blocks in the block diagrams and flowcharts may exist in some embodiments.

[0231] Therefore, blocks in block diagrams and flowcharts support combinations of means for performing a specified function, combinations of elements or steps for performing a specified function, and program instruction means for performing a specified function. It should also be understood that each block in a block diagram and flowchart, and combinations of blocks in block diagrams and flowcharts, can be implemented by a dedicated hardware computer system or a combination of dedicated hardware and computer instructions that performs a specific function, element, or step.

[0232] The program modules, applications, etc., described herein may include one or more software components, including, for example, software objects, methods, data structures, etc. Each such software component may include computer-executable instructions that, in response to execution, cause at least a portion of the functionality described herein (e.g., one or more operations of the exemplary methods described herein) to be performed.

[0233] Software components can be coded using any of a variety of programming languages. An exemplary programming language could be a low-level programming language, such as assembly language associated with a specific hardware architecture and / or operating system platform. Software components including assembly language instructions may need to be converted into executable machine code by an assembler before being executed by the hardware architecture and / or platform. Another exemplary programming language could be a higher-level programming language that is portable across multiple architectures. Software components including higher-level programming languages ​​may need to be converted into an intermediate representation by an interpreter or compiler before execution. Other examples of programming languages ​​include, but are not limited to, macro languages, shell or command languages, job control languages, scripting languages, database query or search languages, or report writing languages. In one or more exemplary embodiments, a software component containing instructions from one of the above-described programming language examples can be executed directly by the operating system or other software components without first being converted into another form.

[0234] Software components can be stored as files or other data storage structures. Software components of similar type or related function can be stored together in a specific directory, folder, or library. Software components can be static (e.g., pre-defined or fixed) or dynamic (e.g., created or modified at runtime).

[0235] The embodiments of this application have been described in detail above with reference to the accompanying drawings. However, this application is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of this application.

Claims

1. An analytical method for investigating the distribution of illegal content based on multiple information databases, characterized in that, Includes the following steps: Obtain IP address information with abnormal traffic, including IP registration information; The domain name ownership information and canonical name ownership information corresponding to the IP address with abnormal traffic are determined by the domain name gene database, wherein the domain name gene database is used to characterize a global domain name information database including IP address information and domain name registration information; Certificate chain parsing is performed on the IP address information of the abnormal traffic to obtain certificate information; The IP filing information includes the IP filing entity, and the certificate information includes certificate user information. If one or more of the information regarding the IP registration authority, the domain name ownership information, the standardized name ownership information, and the certificate user information are inconsistent, a compliance assessment will be conducted on the inconsistent information to obtain an assessment result; based on the assessment result, it will be determined whether there is any illegal content distribution. The assessment results include violation assessment results, and the compliance assessment of inconsistent information to obtain assessment results includes: Obtain content delivery network qualification information and content delivery network resource subleasing information; If the Content Delivery Network (CDN) qualification indication information indicates that the inconsistent information does not possess the CDN qualification, or the CDN resource subleasing indication information indicates that the inconsistent information is a resource subleasing, then the violation assessment result is output.

2. The analysis method for investigating the distribution of illegal content based on multiple information databases according to claim 1, characterized in that, Before obtaining the IP address information of abnormal traffic, the method further includes: Obtain network traffic data; The network traffic data is subjected to offline statistical analysis at a preset time period to obtain the analysis results; Based on the analysis results, the IP address information of the abnormal traffic was determined.

3. The analysis method for investigating the distribution of illegal content based on multiple information databases according to claim 1, characterized in that, Before obtaining the IP address information of abnormal traffic, the method further includes: Obtain domain name system log data; Based on the Domain Name System log data, the domain name and the corresponding IP address information are determined.

4. The analysis method for investigating the distribution of illegal content based on multiple information databases according to claim 1, characterized in that, The certificate chain parsing of the IP address information of the abnormal traffic to obtain certificate information includes: Certificate chain parsing is performed on the IP address information of the abnormal traffic to obtain the certificate user information.

5. The analysis method for investigating the distribution of illegal content based on multiple information databases according to claim 1, characterized in that, After determining whether there is any illegal content distribution based on the assessment results, the method further includes: The IP registration information, certificate information, domain name ownership information, standardized name ownership information, and information on whether illegal content is distributed will be stored and / or a visual analysis report will be generated.

6. An analysis device for investigating the distribution of illegal content based on multiple information databases, characterized in that, The device includes: The first acquisition module is used to acquire IP address information with abnormal traffic, the IP address information with abnormal traffic includes IP registration information, the IP registration information includes the IP registration unit; The second acquisition module is used to determine the domain name ownership information and canonical name ownership information corresponding to the IP address with abnormal traffic through the domain name gene library, wherein the domain name gene library is used to characterize a global domain name information database including IP address information and domain name registration information; The certificate chain parsing module is used to parse the certificate chain of the IP address information with abnormal traffic to obtain certificate information, which includes certificate user information. The violation analysis module is used to perform a compliance assessment on inconsistencies in one or more of the information regarding the IP registration authority, the domain name ownership information, the standardized name ownership information, and the certificate user information, and to obtain an assessment result; based on the assessment result, it is determined whether there is any illegal content distribution. The assessment results include violation assessment results, and the compliance assessment of inconsistent information to obtain assessment results includes: Obtain content delivery network qualification information and content delivery network resource subleasing information; If the Content Delivery Network (CDN) qualification indication information indicates that the inconsistent information does not possess the CDN qualification, or the CDN resource subleasing indication information indicates that the inconsistent information is a resource subleasing, then the violation assessment result is output.

7. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the analysis method for investigating the distribution of illegal content based on multiple information databases as described in any one of claims 1 to 5.

8. A computer program product, characterized in that, The computer program product includes computer program code, which, when run on a computer, causes the computer to execute the analysis method for investigating the distribution of illegal content based on multiple information databases as described in any one of claims 1 to 5.