Network device discovery method
By obtaining ARP tables in the LAN and detecting and adjusting them, combining weight evaluation mechanisms and multi-dimensional data analysis, efficient and accurate device discovery in complex and dynamically changing LAN environments is achieved, and the problem of inefficient device discovery in the prior art is solved.
Patent Information
- Application Number
- CN202510211010.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The prior art is difficult to accurately and efficiently detect equipment in complex and dynamically changing local area network environments, resulting in low management efficiency and high operation and maintenance costs.
By obtaining the ARP tables of the gateway and router in the target network, iteratively search and generate the device data mapping table, and detect and adjust based on the rule base, multi-level detection mechanism, device fingerprint and subnet mask matching algorithm, combined with the weight evaluation mechanism and multi-dimensional data analysis, intelligent device status and communication relationship recognition are achieved.
It reduces redundant data and invalid information, improves the accuracy and management efficiency of device discovery, and can adapt to changes in complex LAN environments in real time.
Smart Images

Figure CN119697086B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a network device discovery method. Background Art
[0002] With the continuous development of server cluster scale and IoT technology, modern LAN environment has become more and more complex. Traditional LAN monitoring and management methods can no longer meet the needs of monitoring the status of a large number of devices and sensing device changes. The addition, removal and communication mode of devices in the network frequently change, causing the network topology to become more dynamic and complex. The unpredictability and real-time changes of a large amount of device information make it difficult for traditional topology discovery methods to effectively acquire and manage data. The data collected by these traditional methods usually contains a lot of redundant and invalid information, which cannot accurately reflect the actual status of the device, thus affecting the optimization and management efficiency of the network. In addition, the inaccuracy and incompleteness of the data also increase the difficulty of network operation and maintenance, forcing the need for manual intervention to increase further.
[0003] In the prior art, there are many technical solutions for topology discovery and traffic monitoring of service clusters, but they all have certain limitations, including:
[0004] 1. Manually determine the effectiveness of the equipment;
[0005] shortcoming:
[0006] 1) It requires manual judgment of the information of each device, which is labor-intensive and inefficient, especially when there are a large number of devices;
[0007] 2) Manual judgment is easily affected by human factors, and there is a risk of misjudgment and missed judgment;
[0008] 3) The equipment status cannot be updated in real time, and the dynamic changes of the equipment cannot be reflected in time, resulting in management lags, increasing operation and maintenance costs and management difficulties;
[0009] 4) Manual methods are difficult to meet the needs of fast and accurate equipment monitoring in large-scale network environments, and cannot effectively cope with situations where equipment frequently changes.
[0010] 2. Traffic-based device analysis;
[0011] shortcoming:
[0012] 1) Relying on data packet capture and parsing, when faced with a large number of devices, it may result in excessive data volume, thus affecting network performance and even interrupting normal communication processes;
[0013] 2) Traffic analysis methods cannot provide detailed status information of devices, and the analysis results often contain a large amount of redundant and invalid data, resulting in a lack of accuracy in management decisions;
[0014] 3) Traffic analysis usually focuses on the network layer, which makes it difficult to gain in-depth understanding of the specific functions and status of devices, especially the real-time perception of dynamic changes in devices and unstable communication relationships, which has accuracy issues;
[0015] 4) For some devices or communication modes that change frequently in a short period of time, traffic analysis has a slow response speed and there is a risk of missed detection;
[0016] 3. Data discrimination method based on artificial intelligence;
[0017] shortcoming:
[0018] 1) It relies on complex algorithms and training models, which require a large amount of sample data and computing resources during implementation, and the model training and optimization process is relatively time-consuming;
[0019] 2) Artificial intelligence methods often have high requirements for data quality and diversity. In practical applications, they may face the situation of insufficient training data or inconsistent data quality, which will affect the accuracy of the results;
[0020] 3) This method requires a large amount of historical data and high-frequency real-time data input, but the response speed and prediction accuracy of artificial intelligence are still limited to sudden changes and uncertain characteristics of equipment;
[0021] 4) The complexity of the algorithm and the heavy computational load may put great pressure on network performance and device resources, especially in large-scale LAN environments. Summary of the invention
[0022] In view of the above, it is necessary to provide a network device discovery method to solve the problem of being unable to accurately and efficiently discover devices.
[0023] A network device discovery method, applied to a network device detector, the network device discovery method comprising:
[0024] In response to a device discovery instruction for a target network, obtaining a gateway and a router in the target network, establishing a session connection on the gateway, and obtaining an ARP table maintained by the router;
[0025] Performing an iterative search under the target network according to the ARP table, and generating a device data mapping table according to the retrieved data;
[0026] Performing a legitimacy check on the IP address in the device data mapping table based on the rule base to obtain a first test result;
[0027] Performing a legitimacy detection on the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result;
[0028] Performing a uniqueness test on the device data mapping table based on the device fingerprint to obtain a third test result;
[0029] Performing a subnet adaptability test on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth test result;
[0030] Based on a weight evaluation mechanism, adjusting the device data mapping table according to the first detection result, the second detection result, the third detection result, and the fourth detection result to obtain initial network device data of the target network;
[0031] Information is generated based on the initial network device data to obtain a network device view of the target network.
[0032] A network device discovery device, running on a network device detector, the network device discovery device comprising:
[0033] an acquisition unit, configured to, in response to a device discovery instruction for a target network, acquire a gateway and a router in the target network, establish a session connection on the gateway, and acquire an ARP table maintained by the router;
[0034] A generating unit, configured to perform iterative retrieval under the target network according to the ARP table, and generate a device data mapping table according to the retrieved data;
[0035] A detection unit, configured to perform a legitimacy detection of the IP address in the device data mapping table based on a rule base to obtain a first detection result;
[0036] The detection unit is further used to perform a legitimacy detection of the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result;
[0037] The detection unit is further used to perform a uniqueness detection on the device data mapping table based on the device fingerprint to obtain a third detection result;
[0038] The detection unit is further used to perform subnet adaptability detection on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth detection result;
[0039] an adjusting unit, configured to adjust the device data mapping table according to the first detection result, the second detection result, the third detection result, and the fourth detection result based on a weight evaluation mechanism to obtain initial network device data of the target network;
[0040] The generating unit is further configured to generate information based on the initial network device data to obtain a network device view of the target network.
[0041] A computer device comprises: a memory and a processor, wherein the memory stores at least one instruction, and the processor executes the instruction stored in the memory to implement the network device discovery method.
[0042] A computer-readable storage medium stores at least one instruction, and the at least one instruction is executed by a processor in a computer device to implement the network device discovery method.
[0043] It can be seen from the above technical solutions that the present invention can perform iterative retrieval under the target network according to the ARP table to generate a device data mapping table, providing a more comprehensive view, which is helpful to monitor its health status and network load; based on the rule base, the device data mapping table performs a legitimacy check on the IP address, based on the multi-level detection mechanism, the device data mapping table performs a legitimacy check on the MAC address, based on the device fingerprint, the device data mapping table performs a uniqueness check, based on the subnet mask matching algorithm, the device data mapping table performs a subnet adaptability check, and based on the weight evaluation mechanism and various detection results, the device data mapping table is adjusted, and the adaptive network device discovery algorithm combined with multi-dimensional data analysis can intelligently identify the status and communication relationship of devices in the network by real-time collection and analysis of network traffic data in a complex and dynamically changing LAN environment, thereby reducing redundant data, eliminating invalid information, and improving the accuracy of device discovery and management efficiency; based on the initial network device data, information is generated to obtain a network device view, so as to perform more accurate network device discovery. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a flow chart of a preferred embodiment of the network device discovery method of the present invention;
[0045] Figure 2 It is a functional module diagram of a preferred embodiment of the network device discovery device of the present invention;
[0046] Figure 3 It is a structural diagram of a computer device of a preferred embodiment of the network device discovery method of the present invention. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is described in detail below with reference to the accompanying drawings and specific embodiments.
[0048] like Figure 1 FIG. 1 is a flow chart of a preferred embodiment of the network device discovery method of the present invention. According to different requirements, the order of the steps in the flow chart can be changed, and some steps can be omitted.
[0049] The network device discovery method is applied to one or more computer devices, and the computer device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASIC), programmable gate arrays (FPGA), digital processors (DSP), embedded devices, etc.
[0050] The computer device may be any electronic product that can perform human-computer interaction with a user, such as a personal computer, a tablet computer, a smart phone, a personal digital assistant (PDA), a game console, an interactive network television (IPTV), a smart wearable device, etc.
[0051] The computer device may also include a network device and / or a user device, wherein the network device includes, but is not limited to, a single network server, a server group consisting of multiple network servers, or a cloud consisting of a large number of hosts or network servers based on cloud computing.
[0052] The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), as well as big data and artificial intelligence platforms.
[0053] The network where the computer device is located includes but is not limited to the Internet, a wide area network, a metropolitan area network, a local area network, a virtual private network (VPN), etc.
[0054] In this embodiment, the network device discovery method is applied to a network device detector, including:
[0055] S10, in response to a device discovery instruction for a target network, obtaining a gateway and a router in the target network, establishing a session connection on the gateway, and obtaining an ARP (Address Resolution Protocol) table maintained by the router.
[0056] In this embodiment, the network device detector may include a probe or a device similar to a probe, or a general computer.
[0057] Specifically, the method further includes:
[0058] When the network device detector is in hardware deployment mode, the network device detector is connected to an idle port of a forwarding node of the target network; wherein, when the forwarding node supports a wireless network protocol, the network device detector is wirelessly connected to the forwarding node;
[0059] When the network device detector is in software deployment mode, a detection algorithm of the network device detector is deployed on a directly connected device of the forwarding node.
[0060] The forwarding node may include an intermediate router, a three-layer switch, a gateway, a base station, etc.
[0061] The detection algorithm may include a network device detection algorithm program.
[0062] In this embodiment, the device discovery instruction may be automatically triggered when the target network is put into use, so as to achieve real-time monitoring of network devices in the target network.
[0063] In this embodiment, the target network may be a local area network or the like.
[0064] In this embodiment, after the session connection is established on the gateway, network data may be acquired through the SNMP (Simple Network Management Protocol) protocol, thereby obtaining the ARP table maintained by the router.
[0065] By establishing a session connection, it is possible to ensure that the data acquisition process is carried out in a unified communication context and that reliable information transmission is ensured.
[0066] S11, performing an iterative search in the target network according to the ARP table, and generating a device data mapping table according to the retrieved data.
[0067] In this embodiment, performing iterative search in the target network according to the ARP table and generating a device data mapping table according to the retrieved data includes:
[0068] Traversing the ARP table one by one to extract the MAC (Media Access Control Address) address and basic device attribute information corresponding to each IP (Internet Protocol Address) address in the ARP table;
[0069] A mapping table is constructed according to the MAC address corresponding to each IP address, and the basic attribute information of the device is added to the mapping table as additional information to obtain the device data mapping table.
[0070] The basic attribute information of the equipment may include, but is not limited to: equipment type, operating status and performance indicators, etc.
[0071] The ARP table is the starting point for constructing basic data of the entire network topology.
[0072] In the above embodiment, standardized data query means can be used to retrieve entries in the ARP table one by one and obtain basic attribute information of the device. These multi-type data provide a more comprehensive view for each device, which helps to monitor its health status and network load. At the same time, the collected key information is stored in the device mapping table, which saves the basic mapping information of all devices visible in the entire local area network, providing a data basis for subsequent analysis.
[0073] S12: Perform a validity check on the IP address in the device data mapping table based on the rule base to obtain a first detection result.
[0074] In this embodiment, the rule base-based detection of the legitimacy of the IP address in the device data mapping table to obtain the first detection result includes:
[0075] Determine IP address distribution characteristics, IP address format and address elimination rules based on the rule base;
[0076] A decision tree model is trained according to the IP address distribution characteristics, the IP address format and the address elimination rules to obtain an IP address classification model;
[0077] Input each IP address in the device data mapping table into the IP address classification model for processing to obtain a classification result for each IP address;
[0078] The first detection result is generated according to the classification result of each IP address.
[0079] The address removal rules include multicast addresses, reserved addresses, etc.
[0080] For example, the IP address classification model can detect IP addresses with abnormal risks for subsequent deletion. Specifically, IP addresses that do not meet the standards, IP addresses in uncommon address segments, and IP addresses with repeated or malformed device identifiers can be eliminated. In addition, by analyzing the distribution characteristics of IP addresses and comparing them with known private addresses and reserved address ranges, it is possible to quickly determine whether they are non-compliant items.
[0081] These abnormal IP addresses not only cannot support subsequent analysis, but may also introduce deviations in topology identification and statistical analysis.
[0082] S13, performing a legitimacy detection on the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result.
[0083] In this embodiment, the legitimacy detection of the MAC address in the device data mapping table based on the multi-level detection mechanism includes:
[0084] Detect whether there is a first abnormal MAC address in the device data mapping table; wherein the first abnormal MAC address includes an all-0 address (such as 00:00:00:00:00:00), an all-F address (such as FF:FF:FF:FF:FF:FF:FF), a broadcast address, an abnormal format address, and a pre-configured address to be excluded;
[0085] Acquire device historical behavior data, analyze the device historical behavior data to obtain a second abnormal MAC address, and detect whether the second abnormal MAC address exists in the device data mapping table; wherein the second abnormal MAC address includes a MAC address with abnormal data sending and receiving behavior.
[0086] The pre-configured addresses to be excluded may be manually added by the user as needed.
[0087] In the above embodiment, by detecting the first abnormal MAC address, it is possible to ensure that the address complies with valid specifications; by detecting the second abnormal MAC address, the normal behavior pattern of the device is evaluated based on the dynamic analysis of the historical behavior data of the device and in combination with the amount of packet reception and packet transmission. For example: Under normal circumstances, the data transmission volume of the device should be within a certain range. When the device suddenly exhibits high-frequency, continuous, and large-scale data transmission and reception behavior during a time period when there is usually no large amount of data transmission, the system will mark it as a potential anomaly, indicating that there may be a risk of forgery or conflict; according to the normal behavior pattern of the device (such as traffic fluctuations, communication frequency, etc.), the behavior deviation during each data transmission and reception is compared. If the device suddenly has frequent data transmission during uncommon periods, or abnormal traffic fluctuations, the system will issue a warning and indicate that there may be forged addresses, conflicts, or malicious behavior.
[0088] Through the above embodiments, static mode verification can filter out MAC addresses with incorrect formats or obviously invalid addresses (such as addresses with all 0s or all Fs), and dynamic behavior analysis can further identify possible forged or conflicting addresses based on the device's historical behavior data (such as response frequency and number of associated devices).
[0089] S14, performing a uniqueness detection on the device data mapping table based on the device fingerprint to obtain a third detection result.
[0090] In this embodiment, the uniqueness detection of the device data mapping table based on the device fingerprint includes:
[0091] (1) when there is an IP address corresponding to multiple MAC addresses in the device data mapping table, determining a MAC address corresponding to the online device among the multiple MAC addresses as a first reserved MAC address, and determining other MAC addresses among the multiple MAC addresses except the first reserved MAC address as a first duplicate MAC address;
[0092] For example: if a certain IP address corresponds to multiple different MAC addresses (perhaps because different devices are plugged into the same fixed IP port one after another and recorded by the router), the MAC address record of the online device will be retained, while the remaining duplicates will be removed;
[0093] (2) when a MAC address corresponds to multiple IP addresses in the device data mapping table, determining an IP address corresponding to the online device among the multiple IP addresses as a first reserved IP address, and determining other IP addresses among the multiple IP addresses except the first reserved IP address as a first duplicate IP address;
[0094] For example: if a MAC address corresponds to multiple IP addresses (perhaps the device has been reassigned an IP), the previous data will be checked first, the IP address of the online device will be retained (ping), and other duplicate IP records will be deleted;
[0095] (3) when there is a MAC address and an IP address that are the same in the device data mapping table, any of the same MAC address and IP address is determined as a reserved address, and the other address is determined as a duplicate address;
[0096] For example: If an IP address and a MAC address are exactly the same, and the data is simply repeated, keep any one of them;
[0097] (4) when the property of the port corresponding to the IP address or MAC address in the device data mapping table changes, detecting whether the IP address or MAC address of the port property change is an address to be deleted according to the configuration rule;
[0098] For example, when the nature of the connected port (LAN (local area network), WAN (widearea network, etc.)) changes, the IP address or MAC address that does not meet the requirements is deleted according to the rules;
[0099] (5) when there is a MAC address in the device data mapping table that has multiple IP address records in different subnets, obtaining the network topology location of the network device corresponding to the MAC address, and obtaining an IP address corresponding to the network topology location from the multiple IP addresses in the different subnets as the second reserved IP address, and obtaining other IP addresses except the second reserved IP address from the multiple IP addresses in the different subnets as the second duplicate IP address;
[0100] For example: Combine the subnet structure and network topology of the device to further ensure the uniqueness and global consistency of each device record. Specifically, if the same device (distinguished by MAC) has multiple IP records in different subnets (such as a router connected to another router, resulting in a lower-level subnet), determine the current network topology location of the device and select the one that meets the current situation to keep;
[0101] (6) When there is a risk MAC address with an unclear conflict risk in the device data mapping table, the risk MAC address corresponding to the high-frequency device is obtained from the network device corresponding to the risk MAC address according to the network topology structure and the packet receiving and sending frequency of the network device corresponding to the risk MAC address as the second reserved MAC address, and other risk MAC addresses other than the second reserved MAC address are obtained from the network device corresponding to the risk MAC address as the second duplicate MAC address;
[0102] For example, if a conflict cannot be determined clearly, high-frequency device information is retained based on the device's network topology or other signals (such as the frequency of sending and receiving packets).
[0103] In the above embodiment, the fingerprint comparison algorithm can quickly identify duplicate devices, and the most reliable record is retained through the priority rule. In the actual deduplication process, the module will also comprehensively analyze the subnet structure and topological relationship of the device to ensure global consistency after data cleaning.
[0104] S15, performing a subnet adaptability test on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth test result.
[0105] In this embodiment, the subnet adaptability detection of the device data mapping table based on the subnet mask matching algorithm includes:
[0106] Obtain the IP address and subnet mask corresponding to each device in the device data mapping table;
[0107] Calculate the subnet where each device is located based on the IP address and subnet mask corresponding to each device;
[0108] Obtain the subnet where the network device detector is located;
[0109] When it is detected that the subnet where a device is located is the same as the subnet where the network device detector is located, determining the detected device as a valid device;
[0110] When it is detected that the subnet where a device is located is different from the subnet where the network device detector is located, determining the detected device as an invalid device;
[0111] Marking the devices under the sub-router according to the configuration information of the sub-router network port;
[0112] When subnet configuration information is changed, the subnet where each device is located is recalculated according to the changed subnet configuration information.
[0113] Specifically, first obtain the IP address and its corresponding subnet mask of each device from the router, calculate the subnet where the device is located, obtain the subnet and mask information of the device, and then perform matching, and remove those devices that exist in the router but do not belong to the subnet where the current detection device is located, so as to ensure that the data table only contains valid devices in the current subnet. Devices connected to the sub-router (i.e., devices belonging to the lower-level network of the mother router) will mark these devices according to the configuration information of the sub-router network port (for example, marked as extralan or other preset tags), indicating that these devices belong to the lower-level subnet and are managed by the router. If the subnet configuration changes (for example, the router adds a subnet or changes the subnet mask), the matching logic can be adjusted in real time, and the matching relationship between the IP address and the subnet mask can be recalculated to ensure that all devices are correctly classified into the corresponding subnet, so that changes in the network structure can be reflected in real time.
[0114] Through the above embodiments, the IP address of each device can be masked to identify its subnet. The matching algorithm not only covers the traditional static network configuration, but also dynamically adapts to changes in the network environment. For example, when the subnet configuration changes, the matching logic can be adjusted in real time to ensure that all devices are correctly classified.
[0115] S16, based on a weight evaluation mechanism, adjusting the device data mapping table according to the first detection result, the second detection result, the third detection result and the fourth detection result to obtain initial network device data of the target network.
[0116] In this embodiment, the weight evaluation mechanism is based on which the device data mapping table is adjusted according to the first detection result, the second detection result, the third detection result, and the fourth detection result to obtain the initial network device data of the target network, including:
[0117] Get pre-configured weight evaluation indicators;
[0118] Determine the reliability and impact of each network device corresponding to each MAC address in the device data mapping table according to the weight evaluation index;
[0119] The device data mapping table is filtered according to the reliability and influence of the network device corresponding to each MAC address, the first detection result, the second detection result, the third detection result and the fourth detection result to obtain the initial network device data.
[0120] For example, for each weight evaluation indicator of the device (such as IP address, MAC address, behavior pattern, etc.), a weight value is assigned according to its reliability and impact. In the subsequent device cleaning process, these weights can be comprehensively considered to give priority to the attributes with greater impact.
[0121] In order to improve adaptability, we can also use cross-validation logic to more accurately determine the validity of data by correlating multiple attributes of the device, such as the relationship between IP address and subnet, the relationship between MAC address and device behavior, etc. This multi-dimensional verification mechanism enables the cleaning process to remain efficient and accurate in the face of complex data environments.
[0122] Determining the reliability and impact of the network device corresponding to each MAC address in the device data mapping table according to the weight evaluation index includes:
[0123] Obtain the initial weight of the network device corresponding to each MAC address; wherein the initial weight of the core network device is higher than the initial weight of the terminal device;
[0124] Furthermore, the initial weight of the network device corresponding to each MAC address is adjusted according to the attributes of different dimensions, specifically:
[0125] (1) When it is detected that the IP address of a first network device remains unchanged within the configured time, the initial weight of the first network device is increased according to a preset step size. For example, if the IP address of a device is stable and does not change for a long time, the reliability of the device is high, and the preset step size of 1 can be added to the initial weight of 90 to obtain a new weight of 91;
[0126] (2) When it is detected that a second network device belongs to a core network or a key subnet, the initial weight of the second network device is increased according to the preset step size. For example, if a device belongs to a core network or a key subnet, its influence is relatively high, and a preset step size of 1 can be added to the initial weight of 90 to obtain a new weight of 91. Of course, if the current weight of the device has been increased to 91 according to (1), it can be further increased by 1 based on the current weight of 91, that is, the weight can be gradually adjusted by comprehensively considering multiple dimensions (such as (1)-(7) in this embodiment);
[0127] (3) When it is detected that a third network device is an edge device, the initial weight of the third network device is reduced according to the preset step size. For example, if it is an edge device, the impact is relatively low, then the preset step size can be reduced by 1 based on the initial weight of 90 to obtain a new weight of 89;
[0128] (4) When it is detected that multiple network devices report the same MAC address within a preset time, the initial weights of the multiple network devices are reduced according to the preset step size. For example, MAC addresses are usually relatively stable, but if multiple devices report the same MAC address within a short period of time (which may be forged or conflicting), then the corresponding reliability is low, and the preset step size can be reduced by 1 based on the initial weight of 90 to obtain a new weight of 89;
[0129] (5) When it is detected that a fourth network device sends data at a rate higher than the configured frequency during non-working hours, the initial weight of the fourth network device is reduced according to the preset step size. For example, if a device is usually only active during working hours and it still frequently sends data during non-working hours, this may indicate that the device has abnormal behavior or is in an abnormal state, affecting the reliability of its behavior pattern. In this case, the preset step size can be reduced by 1 based on the initial weight of 90 to obtain a new weight of 89;
[0130] (6) When it is detected that the instantaneous amount of data sent and received by the fifth network device is greater than the configured amount of data, the initial weight of the fifth network device is reduced according to the preset step size. For example, the fluctuation of the device's uploaded data volume, received data volume, and number of sent or received packets can reflect the health status of the device. If the device has a small traffic fluctuation under normal circumstances, but suddenly there is a large-scale data upload or packet exchange, it may be an abnormal behavior. The preset step size can be reduced by 1 based on the initial weight of 90 to obtain a new weight of 89;
[0131] (7) When it is detected that the interface of the sixth network device is unstable, the initial weight of the sixth network device is reduced according to the preset step size. For example, the interface status of the device (such as normal connection, frequent disconnection, etc.) reflects the reliability of the device. If the interface status of the device changes frequently or is unstable, the attribute reliability of the device is low, and the preset step size can be reduced by 1 based on the initial weight of 90 to obtain a new weight of 89.
[0132] That is, the IP and MAC addresses of core routers, the behavior patterns of important devices, etc. will be assigned higher weight values. These attributes have greater stability and influence on the network, so they have priority in subsequent data processing and rule adjustment; certain terminal devices and frequently changing IP addresses will be assigned lower weight values. Changes in these devices will not have a significant impact on the overall health of the network, so their attributes have less impact in data cleaning and anomaly detection.
[0133] During system operation, if a device's behavior or attributes exhibit unusual patterns (such as excessive traffic or frequent interface disconnections), the weight values of its related attributes may be dynamically adjusted. When a device's behavior becomes unreliable, its influence is reduced, thereby reducing the device's impact on decision making and rule adjustments.
[0134] Of course, in other embodiments, the weight value of the attribute will be adjusted based on historical data. For example, if a device has been stable for a long time and has not shown abnormal behavior in multiple cycles, its weight value may gradually increase, further strengthening the credibility of the device, thereby affecting the overall quality evaluation of the LAN and the credibility label value after data cleaning.
[0135] By making a comprehensive judgment and evaluating the transmission quality and the impact of a certain device on the network based on the above information, the device information can be managed more reasonably.
[0136] In this embodiment, the detection process can also have adaptive optimization capabilities, and by introducing a dynamic rule update mechanism, continuous improvement of the judgment criteria can be achieved. During operation, the system will analyze in real time potential abnormal patterns that may appear in the device data, such as the characteristics of new invalid addresses, specific distribution patterns of repeated identifiers, or abnormal trends in device behavior, and adjust internal rules based on the analysis results. Specifically:
[0137] (1) When invalid IP addresses (such as broadcast addresses, reserved addresses, or addresses that do not meet format requirements) appear, they will be filtered immediately to ensure that these addresses are not recorded as valid devices;
[0138] (2) Use Ping or other methods to verify whether the device is active. If the device cannot be Pinged for a long time, mark it as "offline" and further record the device's IP address, subnet mask, LAN / WAN interface and other information for subsequent inspection;
[0139] (3) For devices that cannot be pinged, store relevant information (such as IP address, subnet mask, and connected LAN / WAN interface) in a configuration file. During the data cleaning process, call this configuration file and filter out these "dead" devices based on previous records to prevent them from entering the list of valid devices;
[0140] (4) Use the imported configuration files as part of the rule base to regularly check and update the list of invalid IPs or abnormal devices. In this way, the system will dynamically update the device identification rules based on these records, avoiding manual intervention;
[0141] (5) Use the device’s network behavior (such as frequently changing IP addresses, sudden high traffic, or abnormal communication frequency) as a criterion for anomaly detection and record device anomalies.
[0142] The core of the above adaptive algorithm is an optimization process based on feedback loops. During each detection process, the system will record and summarize all data features marked as invalid or abnormal, and compare these features with historical data to extract potential rules or patterns. For example, the module may find that certain specific address segments frequently have abnormalities within a specific time period. These features will be dynamically added to the cleaning rule base (furthermore, after these features are dynamically added to the cleaning rule base, the data to be returned to the interface can be marked with prompt labels, or labels such as "need to be filtered" can be manually marked in the configuration file so that such data can be directly cleaned through file rules later). Through this mechanism, the system can not only respond to known abnormal types, but also quickly adapt to changes in the network environment.
[0143] The adaptive optimization process also includes a periodic evaluation mechanism. The system will regularly review the cleaned data results and analyze the applicability and effectiveness of the rules. If some rules are found to be redundant or invalid, the system will actively adjust or delete the relevant rules to ensure that the subsequent cleaning mechanism is always efficient. Through this adaptive adjustment, the cleaning module can not only process the current data characteristics, but also has the ability to continuously evolve, providing a solid guarantee for complex dynamic networks.
[0144] After the above rigorous and comprehensive verification and optimization, the device data mapping table finally retains only high-confidence, non-duplicate and valid device data. These refined data lay a reliable and efficient foundation for subsequent data processing, network topology construction and traffic analysis, ensuring the system's management and decision-making capabilities in complex network environments. After filtering and refining, the device data mapping table retains high-confidence, non-duplicate, and invalid information-free device data, laying a reliable foundation for subsequent data processing, network topology construction and traffic analysis.
[0145] S17, generating information based on the initial network device data to obtain a network device view of the target network.
[0146] In this embodiment, the generating information based on the initial network device data to obtain the network device view of the target network includes:
[0147] Acquire interface description information of each network device from the initial network device data;
[0148] Determine the interface type of each network device according to the interface description information of each network device;
[0149] According to the interface type, traffic pattern, communication frequency, and device location of each network device in the initial network device data, matching is performed in a pre-configured device role table to obtain an initial predicted role for each network device; wherein the device role table is used to store a mapping relationship between a device role and the interface type, the traffic pattern, the communication frequency, and the device location;
[0150] Obtaining behavior data of each network device, and extracting traffic characteristics of each network device from the behavior data of each network device;
[0151] Check whether the interface type of each network device matches the corresponding traffic characteristics;
[0152] When it is detected that the interface type of a network device does not match the corresponding traffic feature, the weight of the interface type, traffic mode, communication frequency, and device location of the detected network device is adjusted to update the corresponding initial prediction role;
[0153] The role of each network device is iteratively optimized according to the adjusted weight until the predicted role of each network device after the current iteration is the same as the predicted role of each network device after the previous iteration, the iterative optimization is stopped, and the network device view is generated according to the predicted role of each network device after the current iteration.
[0154] In the above embodiment, after basic information collection and preliminary invalid data cleaning of the device, the deep-level features of the known device can be further mined through the information generation algorithm. Specifically, after basic information collection and preliminary invalid data cleaning of the device, the deep-level features of the device are further mined. Through data association analysis and multi-level feature extraction, the originally isolated device attributes are converted into network role information with contextual meaning, and the multi-dimensional data such as the traffic behavior, communication frequency, data packet transmission delay and port usage of the routing device port are comprehensively considered to construct a multi-dimensional feature map of the device behavior.
[0155] In this embodiment, the network device view and related information can be displayed on a designated display, such as real-time collection and analysis of key indicators such as device traffic, bandwidth usage, upstream and downstream data volume, and presented in intuitive ways such as charts and tables. Users can clearly observe the changing trend of network traffic and quickly understand the working status of the current device. When abnormal traffic, excessive network load or other potential risks are detected, the system will automatically trigger a warning message and prominently prompt it on the interface. In addition, based on preset thresholds and business needs, energy-saving strategy recommendations can also be provided to help users dynamically adjust network configuration and energy usage based on real-time data, providing network operations and maintenance personnel with a more efficient and flexible management experience.
[0156] It can be seen from the above technical solutions that the present invention can perform iterative retrieval under the target network according to the ARP table to generate a device data mapping table, providing a more comprehensive view, which is helpful to monitor its health status and network load; based on the rule base, the device data mapping table performs a legitimacy check on the IP address, based on the multi-level detection mechanism, the device data mapping table performs a legitimacy check on the MAC address, based on the device fingerprint, the device data mapping table performs a uniqueness check, based on the subnet mask matching algorithm, the device data mapping table performs a subnet adaptability check, and based on the weight evaluation mechanism and various detection results, the device data mapping table is adjusted, and the adaptive network device discovery algorithm combined with multi-dimensional data analysis can intelligently identify the status and communication relationship of devices in the network by real-time collection and analysis of network traffic data in a complex and dynamically changing LAN environment, thereby reducing redundant data, eliminating invalid information, and improving the accuracy of device discovery and management efficiency; based on the initial network device data, information is generated to obtain a network device view, so as to perform more accurate network device discovery.
[0157] like Figure 2, which is a functional module diagram of a preferred embodiment of the network device discovery device of the present invention. The network device discovery device 11 includes an acquisition unit 110, a generation unit 111, a detection unit 112, and an adjustment unit 113. The module / unit referred to in the present invention refers to a series of computer program segments that can be executed by a processor and can perform fixed functions, which are stored in a memory. In this embodiment, the functions of each module / unit will be described in detail in subsequent embodiments.
[0158] The acquisition unit 110 is used to acquire a gateway and a router in the target network in response to a device discovery instruction for the target network, establish a session connection on the gateway, and acquire an ARP table maintained by the router;
[0159] The generating unit 111 is used to perform iterative retrieval in the target network according to the ARP table, and generate a device data mapping table according to the retrieved data;
[0160] The detection unit 112 is used to perform a legitimacy detection of the IP address in the device data mapping table based on a rule base to obtain a first detection result;
[0161] The detection unit 112 is further configured to perform a legitimacy detection on the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result;
[0162] The detection unit 112 is further configured to perform a uniqueness detection on the device data mapping table based on the device fingerprint to obtain a third detection result;
[0163] The detection unit 112 is further configured to perform a subnet adaptability detection on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth detection result;
[0164] The adjusting unit 113 is configured to adjust the device data mapping table according to the first detection result, the second detection result, the third detection result and the fourth detection result based on a weight evaluation mechanism to obtain initial network device data of the target network;
[0165] The generating unit is further configured to generate information based on the initial network device data to obtain a network device view of the target network.
[0166] It can be seen from the above technical solutions that the present invention can perform iterative retrieval under the target network according to the ARP table to generate a device data mapping table, providing a more comprehensive view, which is helpful to monitor its health status and network load; based on the rule base, the device data mapping table performs a legitimacy check on the IP address, based on the multi-level detection mechanism, the device data mapping table performs a legitimacy check on the MAC address, based on the device fingerprint, the device data mapping table performs a uniqueness check, based on the subnet mask matching algorithm, the device data mapping table performs a subnet adaptability check, and based on the weight evaluation mechanism and various detection results, the device data mapping table is adjusted, and the adaptive network device discovery algorithm combined with multi-dimensional data analysis can intelligently identify the status and communication relationship of devices in the network by real-time collection and analysis of network traffic data in a complex and dynamically changing LAN environment, thereby reducing redundant data, eliminating invalid information, and improving the accuracy of device discovery and management efficiency; based on the initial network device data, information is generated to obtain a network device view, so as to perform more accurate network device discovery.
[0167] like Figure 3 FIG. 1 is a schematic diagram of the structure of a computer device according to a preferred embodiment of the present invention for implementing a method for discovering a network device.
[0168] The computer device 1 may include a memory 12, a processor 13 and a bus (the arrow in the figure indicates the bus), and may also include a computer program stored in the memory 12 and executable on the processor 13, such as a network device discovery program.
[0169] Those skilled in the art will appreciate that the schematic diagram is merely an example of the computer device 1 and does not constitute a limitation on the computer device 1. The computer device 1 may be a bus-type structure or a star-type structure. The computer device 1 may also include more or less other hardware or software than shown in the diagram, or a different arrangement of components. For example, the computer device 1 may also include input and output devices, network access devices, etc.
[0170] It should be noted that the computer device 1 is only an example, and other existing or future electronic products that are suitable for the present invention should also be included in the protection scope of the present invention and included here by reference.
[0171] The memory 12 includes at least one type of readable storage medium, and the readable storage medium includes a flash memory, a mobile hard disk, a multimedia card, a card-type memory (e.g., SD or DX memory, etc.), a magnetic memory, a disk, an optical disk, etc. In some embodiments, the memory 12 may be an internal storage unit of the computer device 1, such as a mobile hard disk of the computer device 1. In other embodiments, the memory 12 may also be an external storage device of the computer device 1, such as a plug-in mobile hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (SecureDigital, SD) card, a flash card (Flash Card), etc. equipped on the computer device 1. Further, the memory 12 may also include both an internal storage unit of the computer device 1 and an external storage device. The memory 12 may not only be used to store application software and various types of data installed in the computer device 1, such as the code of the network device discovery program, etc., but may also be used to temporarily store data that has been output or is to be output.
[0172] In some embodiments, the processor 13 may be composed of an integrated circuit, for example, a single packaged integrated circuit, or a plurality of packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and combinations of various control chips. The processor 13 is the control core (Control Unit) of the computer device 1, and uses various interfaces and lines to connect various components of the entire computer device 1, and executes various functions and processes data of the computer device 1 by running or executing programs or modules stored in the memory 12 (for example, executing a network device discovery program, etc.), and calling data stored in the memory 12.
[0173] The processor 13 executes the operating system of the computer device 1 and various installed applications. The processor 13 executes the applications to implement the steps in the above-mentioned embodiments of the network device discovery method, for example Figure 1 Steps shown.
[0174] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory 12 and executed by the processor 13 to implement the present invention. The one or more modules / units may be a series of computer-readable instruction segments capable of implementing specific functions, which are used to describe the execution process of the computer program in the computer device 1. For example, the computer program may be divided into an acquisition unit 110, a generation unit 111, a detection unit 112, and an adjustment unit 113.
[0175] The above-mentioned integrated unit implemented in the form of a software function module can be stored in a computer-readable storage medium. The above-mentioned software function module is stored in a storage medium, and includes a number of instructions for enabling a computer device (which can be a personal computer, a computer device, or a network device, etc.) or a processor to execute a part of the network device discovery method described in each embodiment of the present invention.
[0176] If the module / unit integrated in the computer device 1 is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware devices through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by a processor, the steps of each of the above-mentioned method embodiments can be implemented.
[0177] The computer program includes computer program code, which may be in source code form, object code form, executable file or some intermediate form, etc. The computer readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory, etc.
[0178] Furthermore, the computer-readable storage medium may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function, etc.; the data storage area may store data created according to the use of the blockchain node, etc.
[0179] The blockchain referred to in this invention is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm, etc. Blockchain is essentially a decentralized database, a string of data blocks generated by cryptographic methods. Each data block contains a batch of network transaction information, which is used to verify the validity of its information (anti-counterfeiting) and generate the next block. Blockchain can include the blockchain underlying platform, platform product service layer, and application service layer.
[0180] The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 The bus is represented by only one straight line, but it does not mean that there is only one bus or one type of bus. The bus is configured to realize the connection and communication between the memory 12 and at least one processor 13, etc.
[0181] Although not shown, the computer device 1 may also include a power source (such as a battery) for supplying power to various components. Preferably, the power source may be logically connected to the at least one processor 13 through a power management device, so that the power management device can realize functions such as charging management, discharging management, and power consumption management. The power source may also include any components such as one or more DC or AC power sources, recharging devices, power failure detection circuits, power converters or inverters, and power status indicators. The computer device 1 may also include a variety of sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be repeated here.
[0182] Furthermore, the computer device 1 may also include a network interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is usually used to establish a communication connection between the computer device 1 and other computer devices.
[0183] Optionally, the computer device 1 may further include a user interface, which may be a display, an input unit (such as a keyboard), or a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, and an OLED (Organic Light-Emitting Diode) touch device. The display may also be appropriately referred to as a display screen or a display unit, which is used to display information processed in the computer device 1 and to display a visual user interface.
[0184] It should be understood that the embodiment is for illustration only and the scope of the patent application is not limited to this structure.
[0185] It can be understood by those skilled in the art that Figure 3The structure shown does not constitute a limitation on the computer device 1, and may include fewer or more components than shown in the figure, or combine certain components, or arrange the components differently.
[0186] Combination Figure 1 , the memory 12 in the computer device 1 stores a plurality of instructions to implement a network device discovery method, and the processor 13 can execute the plurality of instructions to implement:
[0187] In response to a device discovery instruction for a target network, obtaining a gateway and a router in the target network, establishing a session connection on the gateway, and obtaining an ARP table maintained by the router;
[0188] Performing an iterative search under the target network according to the ARP table, and generating a device data mapping table according to the retrieved data;
[0189] Performing a legitimacy check on the IP address in the device data mapping table based on the rule base to obtain a first test result;
[0190] Performing a legitimacy detection on the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result;
[0191] Performing a uniqueness test on the device data mapping table based on the device fingerprint to obtain a third test result;
[0192] Performing a subnet adaptability test on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth test result;
[0193] Based on a weight evaluation mechanism, adjusting the device data mapping table according to the first detection result, the second detection result, the third detection result, and the fourth detection result to obtain initial network device data of the target network;
[0194] Information is generated based on the initial network device data to obtain a network device view of the target network.
[0195] Specifically, the specific implementation method of the processor 13 for the above instructions can refer to Figure 1 The description of the relevant steps in the corresponding embodiments will not be repeated here.
[0196] It should be noted that the data involved in this case were all obtained legally.
[0197] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.
[0198] The present invention can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0199] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0200] In addition, each functional module in each embodiment of the present invention may be integrated into one processing unit, each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional modules.
[0201] It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0202] Therefore, no matter from which point of view, the embodiments should be regarded as illustrative and non-restrictive, and the scope of the present invention is limited by the appended claims rather than the above description, so it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention. Any attached figure mark in the claims should not be regarded as limiting the claims involved.
[0203] In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in the present invention can also be implemented by one unit or device through software or hardware. The words first, second, etc. are used to indicate names, and do not indicate any particular order.
[0204] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the spirit and scope of the technical solution of the present invention.
Claims
1. A network device discovery method, applied to a network device detector, characterized in that: The network device discovery method comprises: In response to a device discovery instruction for a target network, obtaining a gateway and a router in the target network, establishing a session connection on the gateway, and obtaining an ARP table maintained by the router; Performing an iterative search under the target network according to the ARP table, and generating a device data mapping table according to the retrieved data; Performing a legitimacy check on the IP address in the device data mapping table based on the rule base to obtain a first test result; Performing a legitimacy detection on the MAC address in the device data mapping table based on a multi-level detection mechanism to obtain a second detection result; Performing a uniqueness test on the device data mapping table based on the device fingerprint to obtain a third test result; Performing a subnet adaptability test on the device data mapping table based on a subnet mask matching algorithm to obtain a fourth test result; Based on the weight evaluation mechanism, the device data mapping table is adjusted according to the first detection result, the second detection result, the third detection result and the fourth detection result to obtain the initial network device data of the target network, including: obtaining a pre-configured weight evaluation index; determining the reliability and influence of the network device corresponding to each MAC address in the device data mapping table according to the weight evaluation index; filtering the device data mapping table according to the reliability and influence of the network device corresponding to each MAC address, the first detection result, the second detection result, the third detection result and the fourth detection result to obtain the initial network device data; wherein, determining the reliability and influence of the network device corresponding to each MAC address in the device data mapping table according to the weight evaluation index includes: obtaining the initial weight of the network device corresponding to each MAC address; wherein the initial weight of the core network device is higher than the initial weight of the terminal device; when it is detected that there is a When the IP address of a network device remains unchanged within the configured time, the initial weight of the first network device is increased according to a preset step size; when it is detected that a second network device belongs to a core network or a key subnet, the initial weight of the second network device is increased according to the preset step size; when it is detected that a third network device is an edge device, the initial weight of the third network device is reduced according to the preset step size; when it is detected that multiple network devices report the same MAC address within the preset time, the initial weights of the multiple network devices are reduced according to the preset step size; when it is detected that a fourth network device sends data at a speed higher than the configured frequency during a non-working period, the initial weight of the fourth network device is reduced according to the preset step size; when it is detected that the instantaneous amount of data received and sent by a fifth network device is greater than the configured amount of data, the initial weight of the fifth network device is reduced according to the preset step size; when it is detected that the interface of a sixth network device is unstable, the initial weight of the sixth network device is reduced according to the preset step size; Generate information based on the initial network device data to obtain a network device view of the target network, including: obtaining interface description information of each network device from the initial network device data; determining the interface type of each network device according to the interface description information of each network device; matching the interface type, traffic pattern, communication frequency, and device location of each network device in the initial network device data in a pre-configured device role table to obtain an initial predicted role for each network device; wherein the device role table is used to store a mapping relationship between a device role and the interface type, the traffic pattern, the communication frequency, and the device location; obtaining behavior data of each network device The invention relates to a method for iteratively optimizing the role of each network device, and extracting the traffic characteristics of each network device from the behavior data of each network device; detecting whether the interface type of each network device matches the corresponding traffic characteristics; when it is detected that the interface type of a network device does not match the corresponding traffic characteristics, adjusting the weights of the interface type, traffic mode, communication frequency, and device location of the detected network device to update the corresponding initial prediction role; iteratively optimizing the role of each network device according to the adjusted weight until the predicted role of each network device after the current iteration is the same as the predicted role of each network device after the previous iteration, stopping the iterative optimization, and generating the network device view according to the predicted role of each network device after the current iteration.
2. The network device discovery method according to claim 1, characterized in that: The method further comprises: When the network device detector is in hardware deployment mode, the network device detector is connected to an idle port of a forwarding node of the target network; wherein, when the forwarding node supports a wireless network protocol, the network device detector is wirelessly connected to the forwarding node; When the network device detector is in software deployment mode, a detection algorithm of the network device detector is deployed on a directly connected device of the forwarding node.
3. The network device discovery method according to claim 1, characterized in that: The iterative search under the target network according to the ARP table and generating a device data mapping table according to the retrieved data includes: Traversing the ARP table one by one to extract the MAC address and basic device attribute information corresponding to each IP address in the ARP table; A mapping table is constructed according to the MAC address corresponding to each IP address, and the basic attribute information of the device is added to the mapping table as additional information to obtain the device data mapping table.
4. The network device discovery method according to claim 1, characterized in that: The first detection result obtained by performing a legality detection of the IP address on the device data mapping table based on the rule base includes: Determine IP address distribution characteristics, IP address format and address elimination rules based on the rule base; A decision tree model is trained according to the IP address distribution characteristics, the IP address format and the address elimination rules to obtain an IP address classification model; Input each IP address in the device data mapping table into the IP address classification model for processing to obtain a classification result for each IP address; The first detection result is generated according to the classification result of each IP address.
5. The network device discovery method according to claim 1, characterized in that: The checking of the legitimacy of the MAC address in the device data mapping table based on the multi-level detection mechanism includes: Detect whether there is a first abnormal MAC address in the device data mapping table; wherein the first abnormal MAC address includes an all-0 address, an all-F address, a broadcast address, an address with an abnormal format, and a pre-configured address to be excluded; Acquire device historical behavior data, analyze the device historical behavior data to obtain a second abnormal MAC address, and detect whether the second abnormal MAC address exists in the device data mapping table; wherein the second abnormal MAC address includes a MAC address with abnormal data sending and receiving behavior.
6. The network device discovery method according to claim 1, characterized in that: The performing uniqueness detection on the device data mapping table based on the device fingerprint comprises: When there is an IP address corresponding to multiple MAC addresses in the device data mapping table, determine the MAC address corresponding to the online device among the multiple MAC addresses as a first reserved MAC address, and determine the other MAC addresses among the multiple MAC addresses except the first reserved MAC address as a first repeated MAC address; When there is a MAC address corresponding to multiple IP addresses in the device data mapping table, determine the IP address corresponding to the online device among the multiple IP addresses as a first reserved IP address, and determine the other IP addresses among the multiple IP addresses except the first reserved IP address as a first duplicate IP address; When there is a MAC address and an IP address that are the same in the device data mapping table, any address of the same MAC address and IP address is determined as a reserved address, and the other address is determined as a duplicate address; When the property of a port corresponding to an IP address or a MAC address in the device data mapping table changes, detecting whether the IP address or the MAC address of the port property change is an address to be deleted according to the configuration rule; When there are multiple IP address records for a MAC address in different subnets in the device data mapping table, obtaining a network topology location of the network device corresponding to the MAC address, and obtaining an IP address corresponding to the network topology location from multiple IP addresses in different subnets as a second reserved IP address, and obtaining other IP addresses except the second reserved IP address from multiple IP addresses in different subnets as a second duplicate IP address; When there is a risk MAC address with an unclear conflict risk in the device data mapping table, the risk MAC address corresponding to the high-frequency device is obtained from the network device corresponding to the risk MAC address as the second reserved MAC address based on the network topology structure and the packet receiving and sending frequency of the network device corresponding to the risk MAC address, and other risk MAC addresses except the second reserved MAC address are obtained from the network device corresponding to the risk MAC address as the second duplicate MAC address.
7. The network device discovery method according to claim 1, characterized in that: The performing subnet adaptability detection on the device data mapping table based on the subnet mask matching algorithm includes: Obtain the IP address and subnet mask corresponding to each device in the device data mapping table; Calculate the subnet where each device is located based on the IP address and subnet mask corresponding to each device; Obtain the subnet where the network device detector is located; When it is detected that a device is located in the same subnet as the subnet where the network device detector is located, determining the detected device as a valid device; or When it is detected that the subnet where a device is located is different from the subnet where the network device detector is located, determining the detected device as an invalid device; Marking the devices under the sub-router according to the configuration information of the sub-router network port; When subnet configuration information is changed, the subnet where each device is located is recalculated according to the changed subnet configuration information.
Citation Information
Patent Citations
Network security situation evaluation method
CN102624696A
Distributed mass organization realizing method based on label interaction
CN103327075A