Device anomaly determination method, apparatus, device, and readable storage medium
By obtaining the access data of the target gateway, performing multiple rounds of candidate device screening and similarity calculation, and using the confidence network model to automatically identify the abnormal status of the terminal device, the problem of low efficiency in privacy and security detection of terminal devices is solved, and efficient device status identification is achieved.
Patent Information
- Application Number
- CN202411678925.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-21
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2044-11-21
AI Technical Summary
In the existing technology, the privacy security detection efficiency of terminal devices is low, it is difficult to fully cover all possible hidden camera devices, and it is impossible to efficiently identify the shooting device.
By obtaining the access data of the target gateway, performing multiple rounds of candidate device screening operations, calculating the similarity of traffic data, and using the trained confidence network model to determine the device status, suspected abnormal devices can be automatically identified.
It improves the efficiency of device status detection, can fully cover all access devices, and avoids the inefficiency and insufficient coverage of traditional detection methods.
Smart Images

Figure CN119766470B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of data processing, and particularly relates to a device anomaly determination method and device, equipment and a readable storage medium. BACKGROUND
[0002] With the development of communication technology, terminal devices have been popularly applied in various industries. Due to the openness and unsupervision of the use scenarios of terminal devices, the terminal devices not only bring convenience to users, but also pose a serious threat to privacy security. In public places or private scenarios, cameras may be installed actively or passively for monitoring, thereby causing great privacy security invasion problems. Especially for wireless cameras, since they do not need wiring, they are easier to hide, and the privacy invasion problem is more serious.
[0003] In the related art, the traditional detection method often relies on physical inspection or manual patrol. This method is not only inefficient, but also difficult to comprehensively cover all possible hidden cameras, and cannot efficiently identify the shooting device. SUMMARY
[0004] The present application provides a device anomaly determination method, device, equipment and readable storage medium to solve the problem of low detection efficiency in related art, and the difficulty to comprehensively cover all possible hidden cameras, and the inability to efficiently identify the shooting device.
[0005] In a first aspect, the present application provides a device anomaly determination method, comprising:
[0006] obtaining access data of a target gateway, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway;
[0007] performing multiple rounds of candidate device screening operations and determining a target candidate device screened out by the last candidate device screening operation; wherein each candidate device screening operation is used to screen new candidate devices from the candidate devices obtained in the last round according to the traffic data in the corresponding execution time period of the current round and the screening condition, and in the first round, the candidate devices are screened from the access devices;
[0008] calculating the similarity between the traffic data of the target candidate device and the traffic data of other access devices in a preset time period;
[0009] inputting the similarity into a trained confidence network model, and determining the confidence of the target candidate device through the confidence network model; the confidence represents the determination degree of the target candidate device being in an abnormal state;
[0010] According to the confidence level of the target candidate device, a device state of the target candidate device is determined, the device state including an abnormal state and a normal state.
[0011] In a second aspect, the present application provides a device anomaly determination apparatus, the apparatus comprising:
[0012] An acquisition module is configured to acquire access data of a target gateway, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway.
[0013] A first determination module is configured to perform a plurality of rounds of candidate device screening operations and determine a target candidate device screened out in the last round of candidate device screening operation, wherein each round of candidate device screening operation is configured to screen out a new candidate device from a candidate device screened out in a previous round according to traffic data in a time period corresponding to the current round and a screening condition, and in the first round, the candidate device is screened out from the access device.
[0014] A calculation module is configured to calculate a similarity between traffic data of the target candidate device and traffic data of other access devices in a preset time period.
[0015] An input module is configured to input the similarity into a trained confidence level network model and determine a confidence level of the target candidate device through the confidence level network model, wherein the confidence level represents a determination degree of whether the target candidate device is in an abnormal state.
[0016] A second determination module is configured to determine a device state of the target candidate device according to the confidence level of the target candidate device, wherein the device state includes an abnormal state and a normal state.
[0017] In a third aspect, the present application provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method of the first aspect.
[0018] In a fourth aspect, the present application provides a readable storage medium, wherein when instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method of the first aspect.
[0019] The technical solution provided by the embodiments of the present application can have the following beneficial effects:
[0020] The access data of the target gateway is acquired, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway; a plurality of rounds of candidate device screening operations are performed, and a target candidate device screened out by the last candidate device screening operation is determined; wherein each candidate device screening operation is used to screen a new candidate device from a candidate device screened out by a previous round according to traffic data in a corresponding execution time period of the current round and a screening condition, and the candidate device is screened out from the access device in the first round; similarity of traffic data of the target candidate device and traffic data of other access devices in a preset time period is calculated; the similarity is input into a trained confidence network model, and a confidence of the target candidate device is determined by the confidence network model; the confidence represents a determination degree of the target candidate device being in an abnormal state; and a device state of the target candidate device is determined according to the confidence of the target candidate device, wherein the device state comprises an abnormal state and a normal state. In this way, the target candidate device in a suspected abnormal state can be automatically identified by traffic data of an access gateway, and the device state of the target candidate device can be directly output by a trained confidence network model, so that all accessed devices can be comprehensively covered based on traffic data, the device state can be automatically identified, the detection efficiency of detecting whether the device state is abnormal can be improved, and the problems of low detection efficiency and incomplete coverage caused by relying on physical inspection or manual inspection in traditional detection methods can be avoided. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the embodiments or the related art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0022] Figure 1 is a flowchart of a device abnormality determination method provided by an embodiment of the present application;
[0023] Figure 2 is a flowchart of another device abnormality determination method provided by an embodiment of the present application;
[0024] Figure 3 is a block diagram of a device abnormality determination apparatus provided by an embodiment of the present application;
[0025] Figure 4 is a structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0026] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be clearly and completely described below, obviously, the described embodiments are some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work belong to the protection scope of the present application.
[0027] Before introducing the device anomaly determination method, device, equipment and storage medium provided by the present disclosure, first introduce the application scenarios involved in each embodiment of the present disclosure. The present disclosure can be applied to the scene of detecting the device of the access gateway, and the device anomaly determination method provided by the embodiments of the present disclosure can be applied to the gateway device, wherein the gateway device is used to provide network service for the accessed electronic device.
[0028] At present, with the development of communication technology, terminal devices have been popularly applied in various industries. Due to the openness and unsupervision of the use scene of terminal devices, terminal devices not only bring convenience to users, but also pose a serious threat to privacy security. In public places or private scenes, cameras may be installed actively or passively for monitoring, thereby causing great privacy security invasion problems. Especially wireless cameras, as they do not need wiring, they are easier to hide, and the privacy invasion problem is more serious.
[0029] However, in the related art, the traditional monitoring means often relies on physical inspection or manual patrol, which is not only inefficient, but also difficult to cover all possible hidden camera devices. With the popularity of shooting devices and the continuous progress of technology, shooting devices are more and more concealed, and it is more difficult to directly discover them by naked eye, which poses a serious threat to the privacy security of users.
[0030] In order to solve the above problems, the present disclosure provides a device anomaly determination method, device, equipment and readable storage medium, which can automatically identify the target candidate device in suspected state anomaly through the traffic data of the access gateway, and further directly output the device state of the target candidate device through the trained confidence network model. In this way, all accessed devices can be covered based on traffic data, and the device state can be automatically identified, which can improve the detection efficiency of detecting whether the device state is abnormal, avoid the low detection efficiency and the problem of not being able to cover comprehensively caused by relying on physical inspection or manual patrol in the traditional detection method.
[0031] The touch area correction method provided by the embodiments of the present application will be described in detail below in combination with the accompanying drawings and specific embodiments and their application scenarios.
[0032] Figure 1 is a flowchart of a device anomaly determination method provided by an embodiment of the present application, likeFigure 1 As shown, the method can comprise the following steps.
[0033] In step S101, access data of a target gateway is acquired.
[0034] The access data comprises traffic data corresponding to an access device accessing the target gateway. The target gateway can comprise an edge-side gateway, which can be understood as a gateway connected to the access device.
[0035] Optionally, the edge-side gateway can be a router. The number of edge-side gateways can be one, two or more. The correspondence between the edge-side gateway and the terminal device can be one-to-one, one-to-many or many-to-many, which is not limited in the present disclosure.
[0036] Considering that after the shooting device shoots the video data, it usually needs to access the network to upload and share the video data it has shot, therefore, in the area to be checked and detected, the traffic data of the gateway device accessing the area can be detected and analyzed, so as to detect the network activity in the area, especially the abnormal network traffic mode, which can be related to the network communication behavior of the hidden camera.
[0037] Specifically, after the access device generates network traffic data, the network traffic data generated by the access device can be used as the access data of the target gateway. That is, after obtaining the network traffic data generated by the access device, the network traffic data can be sent to the edge-side gateway corresponding to the access device.
[0038] Therefore, in this step, the access device can be successfully accessed to the target gateway, and the access device traffic data after access can be collected through the target gateway, wherein the access device traffic data after access includes but is not limited to the number of preset data packet types transmitted between the access device and the target gateway, the cumulative data traffic and the broadband usage rate.
[0039] Specifically, the target gateway can collect the traffic data after the access device accesses at a preset frequency, for example, the target gateway can collect the traffic data after the access device accesses every 5 seconds.
[0040] For example, the traffic data corresponding to the access device accessing the target gateway can be acquired in the following way:
[0041] Method one, hardware probe-based monitoring technology.
[0042] Specifically, the hardware probe is a hardware device used to acquire network traffic. When used, it is connected in series in the link where the traffic needs to be captured, and the traffic information is acquired by splitting the digital signal on the link.
[0043] One hardware probe monitors the traffic information of one subnet (usually one link). For the monitoring of the whole network traffic, a distributed scheme is needed, in which a probe is deployed on each link, and a background server and a database are used to collect the data of all the probes, and to analyze the whole network traffic and make long-term reports.
[0044] The second method is the traffic monitoring technology based on SNMP (Simple Network Management Protocol).
[0045] Specifically, the traffic information collection based on SNMP is essentially that the test instrument extracts some variables related to specific device and traffic information from the MIB (Management Information Base) provided by the network device.
[0046] The network traffic information collected based on SNMP can include the number of input bytes, the number of input non-broadcast packets, the number of input broadcast packets, the number of input packet drops, the number of input packet errors, the number of input unknown protocol packets, the number of output bytes, the number of output non-broadcast packets, the number of output broadcast packets, the number of output packet drops, the number of output packet errors, and the output queue length.
[0047] The third method is the traffic monitoring technology based on Netflow (Network Flow).
[0048] Specifically, the Netflow traffic information collection is the network traffic information collection based on the Netflow mechanism provided by the network device. Netflow is used by routers and switches to count network traffic, and the results are sent to third-party traffic report generators and long-term databases. Once the detailed traffic data on routers and switches are collected, the count basis can be provided for network traffic statistics, network usage pricing, network planning, virus traffic analysis, network monitoring, and other applications.
[0049] The above technical solutions can effectively monitor and manage network traffic.
[0050] In step S102, a plurality of rounds of candidate device screening operations are performed, and a target candidate device screened out by the last candidate device screening operation is determined.
[0051] Each candidate device screening operation is used to screen new candidate devices from the candidate devices obtained in the previous round according to the traffic data in the time period corresponding to the current round and the screening condition, and the candidate devices are screened out from the access device in the first round.
[0052] In some embodiments, the first access data of the target gateway can be obtained, and a first time period can be set. If it is detected that the access data includes downlink traffic in the first time period, it can be determined that a user stays in the room where the target gateway is located. Then, a plurality of rounds of candidate device screening operations can be performed, and the target candidate device can be determined as the candidate device screened out in the last round of candidate device screening operation.
[0053] Optionally, the first time period can be set first, and if it is detected that the downlink traffic lasts for a first preset time period in the traffic data in the first time period, it can be determined that the first device accesses the target gateway, and the network address of the first device can be obtained. Then, a plurality of rounds of candidate device screening operations can be performed, and the target candidate device can be determined as the candidate device screened out in the last round of candidate device screening operation.
[0054] In each round of candidate device screening operation, if it is detected that the candidate traffic data lasts for a preset time period and is greater than or equal to a preset traffic threshold in the obtained traffic data in the execution time period corresponding to the current round, the candidate network address of the device corresponding to the candidate traffic data can be obtained. If the candidate network address corresponding to the candidate traffic data is consistent with the candidate network address screened out in the last round, the candidate device obtained in the last round can be taken as the new candidate device screened out in the current round, which is the candidate device screened out from the first device in the first round.
[0055] For example, if the access data of the target gateway is obtained, for example, if all the traffic data of the target gateway in the time period from 12:00 on the current day to 12:00 on the next day is obtained, the time period from 18:00 on the current day to 11:00 on the next day can be taken as the first time period. Then, if it is detected that the access data includes downlink traffic, it can be determined that a user stays in the room where the target gateway is located according to the access data in the first time period.
[0056] Then, if it is determined that a user stays in the room where the target gateway is located, the candidate device screening operation can be performed according to the access data in the first time period to screen the candidate device from the access device according to the screening condition. Then, all the traffic data of the target gateway in the time period from 12:00 on the second day of the user stay day to 12:00 on the next day can be obtained, and the candidate device screening operation can be repeatedly performed to screen the new candidate device from the candidate device determined on the previous day according to the screening condition. In the following days, the candidate device screening operation can be repeatedly performed according to the above steps, and after the preset rounds of candidate device screening operations are repeatedly performed, the candidate device screened out in the last round of candidate device screening operation can be taken as the target candidate device.
[0057] The target candidate device can be an access device highly suspected of having an abnormal state.
[0058] In another possible implementation, in the case that access data of the target gateway is obtained, the access data of the target gateway can be divided into access data corresponding to multiple time periods according to a preset time interval. For example, all traffic data of the target gateway in a time period from 12:00 on the user check-in day to 12:00 on the fourth day after the check-in day can be divided into a first time period from 18:00 on the day to 11:00 on the next day, a second time period from 12:00 on the next day to 12:00 on the third day after the check-in day, and a third time period from 12:00 on the third day after the check-in day to 12:00 on the fourth day after the check-in day, and the like. Then, according to the access data in the first time period, it is first determined whether the user checks into the room in which the target gateway is arranged, and in the case that it is determined that the user checks in, candidate device screening is performed according to the access data in the first time period to screen candidate devices from the access device according to a screening condition, candidate device screening is performed according to the access data in the second time period to screen new candidate devices from the candidate devices determined the day before according to the screening condition, and candidate device screening is repeatedly performed in the following several time periods. After the candidate device screening is repeatedly performed for a preset number of rounds, the candidate devices screened in the last candidate device screening are taken as target candidate devices, which can be access devices highly suspected of having an abnormal state.
[0059] In this way, the devices accessing the gateway can be hierarchically detected in combination with the time window and the traffic characteristics, the detection accuracy is gradually enhanced, the false positive rate can be reduced, and the accuracy of device abnormality identification can be improved.
[0060] In step S103, similarity of traffic data of the target candidate device and traffic data of other access devices in a preset time period is calculated.
[0061] After the access devices accessing the target gateway are hierarchically detected in the manner described above, the target candidate devices highly suspected of having an abnormal state can be determined according to analysis of the traffic data. However, considering that multiple access devices are arranged in the room in which the target gateway is arranged, in order to avoid that a normal access device in the room is mistakenly taken as a target candidate device due to a detection error, similarity of traffic data of the target candidate device and traffic data of other access devices in a preset time period can be calculated to further determine whether the device state of the target candidate device is abnormal.
[0062] Optionally, within the preset time period, the traffic sequence corresponding to the target candidate device can be determined based on the traffic value corresponding to the target candidate device at each moment, and the traffic sequence corresponding to the other access device can be determined based on the traffic value corresponding to the other access device at each moment.
[0063] The traffic sequence includes the traffic value corresponding to each moment.
[0064] Then, the edit distance of each traffic sequence matrix can be calculated.
[0065] The traffic sequence matrix includes any two different traffic sequences, the traffic sequences between each traffic sequence matrix are not repeated, and the edit distance is used to represent the similarity between the two traffic sequences in the traffic sequence matrix.
[0066] In some embodiments, considering that the traffic sequence lengths of different networked devices may be different, the calculated edit distance can be normalized, which can improve the output efficiency of the confidence network model in subsequent steps.
[0067] Therefore, the sequence lengths of the two traffic sequences in the traffic sequence matrix can be obtained respectively first; then the ratio of the edit distance and the maximum sequence length can be used as the normalized edit distance.
[0068] The maximum sequence length is the maximum length of the two sequence lengths.
[0069] In step S104, the similarity is input into a trained confidence network model, and the confidence of the target candidate device is determined by the confidence network model.
[0070] Among them, the confidence level represents the degree of certainty that the target candidate device is in an abnormal state. After the devices connected to the gateway are graded and detected through the above steps, the traffic data of the target candidate device and the traffic data of other access devices can be further calculated. The similarity within a preset time period can be used to determine the difference between the traffic data of the target candidate device and the traffic data of other access devices within the same time period through the trained confidence network model. In this way, edit distance clustering analysis can be used to quickly locate and mark potential unknown hidden camera devices, and all connected devices can be fully covered based on traffic data. The device status can be automatically identified, which can improve the detection efficiency of whether the device status is abnormal.
[0071] In step S105 , the device status of the target candidate device is determined according to the confidence level of the target candidate device.
[0072] The device status includes an abnormal status and a normal status.
[0073] By adopting the technical scheme, the access data of the target gateway is acquired, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway; a plurality of rounds of candidate device screening operations are performed, and a target candidate device screened out by the last candidate device screening operation is determined; wherein each candidate device screening operation is used to screen a new candidate device from a candidate device obtained in a previous round according to traffic data in a time period corresponding to the current round and a screening condition, and the candidate device is screened from the access device in the first round; the similarity between the traffic data of the target candidate device and traffic data of other access devices in a preset time period is calculated; the similarity is input into a trained confidence network model, and the confidence of the target candidate device is determined by the confidence network model; the confidence represents a determination degree of the target candidate device being in an abnormal state; and the device state of the target candidate device is determined according to the confidence of the target candidate device, wherein the device state comprises an abnormal state and a normal state.
[0074] In this way, the target candidate device in a suspected abnormal state can be automatically identified by the traffic data of the access gateway, and the device state of the target candidate device can be directly output by the trained confidence network model, so that all the accessed devices can be comprehensively covered based on the traffic data, and the device state can be automatically identified, which can improve the detection efficiency of detecting whether the device state is abnormal, and avoid the problems of low detection efficiency and incomplete coverage caused by relying on physical inspection or manual inspection in the traditional detection method.
[0075] Figure 2 FIG. 6 is a flowchart of another device abnormality determination method provided by an embodiment of the present application, as shown in FIG. 6, the method can include the following steps. Figure 2
[0076] In step S201, access data of a target gateway is acquired.
[0077] The access data comprises traffic data corresponding to an access device accessing the target gateway. The target gateway can comprise an edge gateway, wherein the edge gateway can be understood as a gateway connected with the access device. Optionally, the edge gateway can be a router. The number of edge gateways can be one, two or more. The corresponding relationship between the edge gateway and the terminal device can be one-to-one, one-to-many or many-to-many, which is not limited in the present disclosure.
[0078] Considering that after the shooting device shoots the video data, it usually needs to access the network to upload and share the video data shot and acquired, therefore, in a region to be checked and detected, the traffic data of the gateway device accessing the region can be detected and analyzed, so that the network activity in the region can be detected, especially the abnormal network traffic mode, which can be related to the network communication behavior of the hidden camera device.
[0079] Therefore, in this step, the access device access post-flow data can be collected through the target gateway in the case that the access device successfully accesses the target gateway, wherein the access post-device flow data includes but is not limited to the number of preset packet types transmitted between the access device and the target gateway, the cumulative data flow usage, and the broadband usage rate.
[0080] Specifically, the target gateway can collect the access post-flow data of the access device at a preset frequency, for example, the target gateway can collect the access post-flow data of the access device every 5 seconds.
[0081] In step S202, in the flow data in the first time period, if the downlink flow lasting for a first preset time length is detected, it is determined that the first device accesses the target gateway, and the network address of the first device is obtained.
[0082] Considering that in the hotel check-in scenario, the hotel room itself is provided with multiple network-enabled devices, which have accessed the target gateway, therefore, if all the rooms in the hotel are detected by the present scheme, there will be false detection, resulting in low detection efficiency, therefore, the target gateway can be first determined whether there are devices other than the network-enabled devices provided in the room itself, and in the case that the downlink flow lasting for a first preset time length is detected, it is considered that the user has checked in, and the detection of the present scheme is performed, which can effectively improve the detection efficiency.
[0083] In this step, in the case that the access data of the target gateway is obtained, the access data of the target gateway can be divided into access data corresponding to multiple time periods according to a preset time interval. For example, all the flow data of the target gateway in the time period from 12:00 on the check-in day to 12:00 on the fourth day after the check-in day can be divided into the first time period from 18:00 on the check-in day to 11:00 on the next day, the second time period from 12:00 on the check-in day to 12:00 on the next day, the third time period from 12:00 on the next day to 12:00 on the third day after the check-in day, and the fourth time period from 12:00 on the third day after the check-in day to 12:00 on the fourth day after the check-in day, and the like, and then the candidate device screening operation is performed according to the access data in the first time period to screen the candidate device from the access device according to the screening condition.
[0084] Specifically, the flow data in the first time period can be detected, and in the case that at least 5 minutes of downlink flow is detected, it is determined that the first device accesses the target gateway.
[0085] Then, the network address of the first device can be obtained.
[0086] The network address can be expressed in a URL (Uniform Resource Locator) address.
[0087] In step S203, a plurality of rounds of candidate device screening operations are performed, and a candidate device screened out by the last candidate device screening operation is determined as the target candidate device.
[0088] In each of the candidate device screening operations, if candidate traffic data that lasts for a preset time length and is greater than or equal to a preset traffic threshold is detected in the acquired traffic data in the current round of execution time period, a candidate network address of a device corresponding to the candidate traffic data is acquired; and if the candidate network address corresponding to the candidate traffic data is consistent with a candidate network address screened out in a previous round, a candidate device obtained in the previous round is taken as a new candidate device screened out in the current round. In the first round, the candidate device is screened out from the first device.
[0089] In a possible implementation, the execution time period can include a first time period, a second time period, a third time period and a fourth time period, and the target candidate device can be determined by the following steps.
[0090] S1, it is determined that the first device accesses the target gateway, and a network address of the first device is acquired.
[0091] For example, if downlink traffic lasting for at least 5 minutes is detected in the traffic data in the first time period, it can be preliminarily determined that the room where the target gateway is located is in a state of having a guest staying, and a network address of the first device corresponding to the downlink traffic is acquired.
[0092] S2, traffic analysis is performed on the traffic data in the first time period, and if first uplink traffic lasting for a second preset time length and being greater than or equal to a first preset traffic threshold is detected in the traffic data in the first time period, a first network address of a device corresponding to the first uplink traffic is acquired.
[0093] In this step, after it is determined that the room where the target gateway is located is in a state of having a guest staying, traffic analysis is performed on the traffic data in the first time period, and after it is determined that the first uplink traffic lasting for more than 30 minutes and having a data amount of 30 MB is detected in the first time period, a first network address of a device corresponding to the first uplink traffic is acquired.
[0094] S3, if the first network address is consistent with the network address of the first device, the first device is taken as a candidate device.
[0095] In this step, if the first network address is consistent with the network address of the first device, the first device can be taken as a slightly suspicious candidate device.
[0096] S4, traffic analysis is performed on the traffic data in the second time period, and in the traffic data in the second time period, if a second uplink traffic that lasts for a second preset time length and is greater than or equal to a second preset traffic threshold is detected, a second network address of a device corresponding to the second uplink traffic is acquired.
[0097] In this step, in the traffic data in the second time period, if the second uplink traffic that lasts for more than 30 minutes and has a data amount reaching 50 MB is detected, the second network address of the device corresponding to the second uplink traffic can be acquired.
[0098] S5, in the case that the second network address is consistent with the first network address, the first device continues to be taken as a candidate device.
[0099] In this step, if the second network address is consistent with the first network address, the first device can be taken as a moderately suspicious candidate device.
[0100] S6, traffic analysis is performed on the traffic data in the third time period, and in the traffic data in the third time period, if a third uplink traffic that lasts for a second preset time length and is greater than or equal to a third preset traffic threshold is detected, a third network address of a device corresponding to the third uplink traffic is acquired.
[0101] In this step, in the traffic data in the third time period, if the third uplink traffic that lasts for more than 30 minutes and has a data amount reaching 80 MB is detected, the third network address of the device corresponding to the third uplink traffic can be acquired.
[0102] S7, in the case that the third network address is consistent with the second network address, the first device continues to be taken as a candidate device.
[0103] In this step, if the third network address is consistent with the second network address, the first device can be taken as a highly suspicious candidate device.
[0104] S8, traffic analysis is performed on the traffic data in the fourth time period, and in the traffic data in the fourth time period, if a fourth uplink traffic that lasts for a third preset time length and is greater than or equal to a first preset traffic threshold is detected, a fourth network address of a device corresponding to the fourth uplink traffic is acquired.
[0105] The fourth time period can be a time period including the first time period, the second time period, and the third time period, and the corresponding traffic data can be total access data acquired by the target gateway.
[0106] In this step, in the flow data in the fourth time period, if the fourth uplink flow lasting for 2 hours is detected, and the data amount reaches 30 MB, the fourth network address of the equipment corresponding to the fourth uplink flow can be obtained.
[0107] S9, in the case where the fourth network address is consistent with the third network address, the first equipment is taken as a target candidate equipment.
[0108] In this step, if the fourth network address is consistent with the third network address, the first equipment can be taken as a target candidate equipment.
[0109] By using the above technical solution, the equipment of the access gateway can be detected in stages by combining the time window and the flow characteristics, the detection accuracy is gradually enhanced, the false positive rate can be reduced, and the accuracy of equipment anomaly identification can be improved.
[0110] In step S204, in the preset time period, a flow sequence corresponding to the target candidate equipment is determined according to the flow value corresponding to the target candidate equipment at each time, and a flow sequence corresponding to the other access equipment is determined according to the flow value corresponding to the other access equipment at each time.
[0111] The flow sequence includes the flow value corresponding to each time.
[0112] In step S205, the edit distance of each flow sequence matrix is calculated.
[0113] The flow sequence matrix includes any two different flow sequences, the flow sequences between each flow sequence matrix are not repeated, and the edit distance is used to represent the similarity of two flow sequences in the flow sequence matrix.
[0114] Specifically, an example of calculating the edit distance of each flow sequence matrix can be provided as follows:
[0115] D1, m=length(sequenceA), n=length(sequenceB);
[0116] D2, create matrix D[0..m,0..n];
[0117] D3, if sequenceA[i-1]==sequenceB[j-1]:substitutionCost=0;
[0118] else:substitutionCost=1D[i,j]=minimum(D[i-1,j]+1,D[i,j-1]+1,D[i-1,j-1]+substitutionCost);
[0119] D4, return D[m,n];
[0120] Among them, the lengths of the two traffic sequences can be obtained through step D1, and then a traffic sequence matrix D with (m+1) rows and (n+1) columns can be created through step D2. Then, the traffic sequence matrix D can be filled through step D3 to convert one sequence into another sequence and obtain the minimum number of operations required, where the operations can include insertion, deletion, replacement, etc. The value of the lower right corner of the filled traffic sequence matrix D is finally obtained, that is, the edit distance.
[0121] In another possible implementation, considering that the traffic sequence lengths of different networked devices may be different, the calculated edit distance can be normalized, which can improve the output efficiency of the confidence network model in subsequent steps.
[0122] Therefore, the sequence lengths of the two traffic sequences in the traffic sequence matrix can be obtained respectively first; then the ratio of the edit distance and the maximum sequence length can be used as the normalized edit distance.
[0123] The maximum sequence length is the maximum length of the two sequence lengths.
[0124] Specifically, the normalized edit distance can be calculated by the following formula:
[0125] EDR(A,B)=ED(A,B) / max(len(A),len(B));
[0126] Where ED(A,B) is the edit distance between traffic sequence A and traffic sequence B, len(A) and len(B) are the sequence lengths of traffic sequence A and traffic sequence B, respectively, and EDR(A,B) is the normalized edit distance between traffic sequence A and traffic sequence B.
[0127] Specifically, an example can be provided for obtaining the edit distance of all traffic sequence matrices based on the traffic sequence of each device:
[0128] F1. NetworkedDevices=getAllNetworkedDeviceTrafficSequences(); n=length(NetworkedDevices);
[0129] F2, create matrix distanceMatrix[1..n,1..n];
[0130] F3, deviceA = networkingDevices[i]; deviceB = networkingDevices[j]; editDistance = calculateEditDistance(deviceA.trafficSequence, deviceB.trafficSequence); distanceMatrix[i,j] = editDistance; distanceMatrix[j,i] = editDistance;
[0131] F4, return distanceMatrix;
[0132] Wherein, the traffic sequence of all access devices can be obtained through step F1, and then the traffic sequence matrix of all access devices can be obtained through step F2, and then the edit distance between all traffic sequence matrices can be calculated through step F3, and finally the edit distance matrix of all traffic sequence matrices can be obtained through step F4.
[0133] In step S206, the similarity is input into the trained confidence network model, and the confidence of the target candidate device is determined through the confidence network model.
[0134] Wherein, the confidence represents the determination degree of the target candidate device being in an abnormal state.
[0135] Optionally, the identification of the traffic sequence matrix corresponding to the edit distance and the edit distance can be input into the trained confidence network model, and a plurality of confidence values output by the confidence network model are obtained, wherein the confidence probability value includes the identification of the corresponding traffic sequence matrix; and in the case that the target candidate device is included in the device corresponding to the traffic sequence matrix, the confidence corresponding to the traffic sequence matrix is taken as the confidence of the target candidate device.
[0136] In this step, the HDBSCAN (Hierachical Density-Based Spatial Clustering of Applications with Noise, Hierarchical Density-Based Spatial Clustering of Applications with Noise) algorithm can be used for clustering first to obtain a plurality of device categories and the probability value corresponding to the device category, wherein the device category can represent the risk level of determining the device to be in an abnormal state, and the probability value corresponding to the device category is used to represent the possibility of the device being in the risk level.
[0137] Specifically, the device group corresponding to each traffic sequence matrix can be identified, and each traffic sequence matrix can be input into the HDBSCAN algorithm model to obtain a plurality of device categories output by the HDBSCAN algorithm model and a probability value corresponding to the device category.
[0138] Since each device category can include a plurality of device groups, the probability value corresponding to the device category and the ratio of the number of device groups included in the device category can be used as the confidence of the device group.
[0139] In step S207, the device state of the target candidate device is determined according to the confidence of the target candidate device.
[0140] The device state includes an abnormal state and a normal state.
[0141] Specifically, in a case where the confidence of the target candidate device is greater than or equal to a preset threshold, the device state of the target candidate device is determined as the abnormal state; and in a case where the confidence of the target candidate device is less than the preset threshold, the device state of the target candidate device is determined as the normal state.
[0142] Optionally, since each device group includes two devices, when the confidence of the target candidate device is determined by the confidence of the device group, the confidence of the device group in which the target candidate device is located can be used as the confidence of the target candidate device.
[0143] By using the above technical solution, the target candidate device in a suspected state of abnormality can be automatically identified based on the traffic data of the access gateway, and the device state of the target candidate device can be directly output by the trained confidence network model, so that all connected devices can be comprehensively covered based on the traffic data, and the device state can be automatically identified, which can improve the detection efficiency of detecting whether the device state is abnormal, and avoid the problems of low detection efficiency and incomplete coverage caused by relying on physical inspection or manual inspection in traditional detection methods.
[0144] Figure 3 is a block diagram of a device abnormality determination apparatus provided by an embodiment of the present application, as shown in Figure 3 The apparatus 300 includes:
[0145] An acquisition module 301 acquires access data of a target gateway, wherein the access data includes traffic data corresponding to an access device accessing the target gateway.
[0146] The first determining module 302 is configured to perform a plurality of rounds of candidate device screening operations, and determine a target candidate device screened out by a last round of candidate device screening operation; wherein each time the candidate device screening operation is configured to screen out a new candidate device from a candidate device obtained in a previous round according to traffic data in a corresponding execution time period of the current round and a screening condition, and in the first round, the candidate device is screened out from the access device;
[0147] The calculating module 303 is configured to calculate a similarity between the traffic data of the target candidate device and traffic data of other access devices in a preset time period;
[0148] The inputting module 304 is configured to input the similarity into a trained confidence network model, and determine a confidence of the target candidate device by the confidence network model; the confidence represents a determination degree of the target candidate device being in an abnormal state;
[0149] The second determining module 305 is configured to determine a device state of the target candidate device according to the confidence of the target candidate device, wherein the device state includes an abnormal state and a normal state.
[0150] Optionally, the first determining module 302 includes:
[0151] The first determining sub-module is configured to, in the traffic data in the first time period, if detecting downlink traffic lasting a first preset time length, determine that a first device accesses the target gateway, and obtain a network address of the first device;
[0152] The second determining sub-module is configured to perform a plurality of rounds of candidate device screening operations, and determine a candidate device screened out by a last round of candidate device screening operation as the target candidate device;
[0153] In each time, the candidate device screening operation is configured to: in the obtained traffic data in a corresponding execution time period of the current round, if detecting candidate traffic data lasting a preset time length and being greater than or equal to a preset traffic threshold, obtain a candidate network address of a device corresponding to the candidate traffic data; and in a case where the candidate network address corresponding to the candidate traffic data is consistent with a candidate network address screened out in a previous round, take a candidate device obtained in the previous round as a new candidate device screened out in the current round, and in the first round, the candidate device is screened out from the first device.
[0154] Optionally, the execution time period includes a first time period, a second time period, a third time period and a fourth time period; and the second determining sub-module is configured to:
[0155] In the flow data in the first time period, if the first uplink flow greater than or equal to the first preset flow threshold is detected for a second preset time period, a first network address of a device corresponding to the first uplink flow is acquired, and in a case where the first network address is consistent with a network address of the first device, the first device is taken as a candidate device;
[0156] In the flow data in the second time period, if the second uplink flow greater than or equal to the second preset flow threshold is detected for a second preset time period, a second network address of a device corresponding to the second uplink flow is acquired, and in a case where the second network address is consistent with the first network address, the first device is continuously taken as a candidate device;
[0157] In the flow data in the third time period, if the third uplink flow greater than or equal to the third preset flow threshold is detected for a second preset time period, a third network address of a device corresponding to the third uplink flow is acquired, and in a case where the third network address is consistent with the second network address, the first device is continuously taken as a candidate device;
[0158] In the flow data in the fourth time period, if the fourth uplink flow greater than or equal to the first preset flow threshold is detected for a third preset time period, a fourth network address of a device corresponding to the fourth uplink flow is acquired, and in a case where the fourth network address is consistent with the third network address, the first device is taken as a target candidate device.
[0159] Optionally, the calculation module 303 comprises:
[0160] The third determination sub-module is configured to determine, in the preset time period, a flow sequence corresponding to the target candidate device according to a flow value corresponding to the target candidate device at each time point, and determine a flow sequence corresponding to the other access device according to a flow value corresponding to the other access device at each time point; the flow sequence comprises a flow value corresponding to each time point;
[0161] The calculation sub-module is configured to calculate an edit distance of each flow sequence matrix, the flow sequence matrix comprising any two different flow sequences, flow sequences between each flow sequence matrix being different, and the edit distance being used to represent a similarity of two flow sequences in the flow sequence matrix.
[0162] Optionally, the calculation module 303 further comprises:
[0163] The acquisition sub-module is configured to acquire sequence lengths of two flow sequences in the flow sequence matrix respectively;
[0164] The fourth determining sub-module is configured to take the ratio of the edit distance and the maximum sequence length as the normalized edit distance, the maximum sequence length being the maximum length of the two sequence lengths.
[0165] Optionally, the similarity includes an edit distance; and the input module 304 includes:
[0166] The fifth determining sub-module is configured to take the edit distance and the identifier of the traffic sequence matrix corresponding to the edit distance as inputs of the trained confidence network model, to obtain a plurality of confidence values output by the confidence network model, the confidence probability value including the identifier of the corresponding traffic sequence matrix.
[0167] The sixth determining sub-module is configured to take the confidence of the traffic sequence matrix as the confidence of the target candidate device in the case where the target candidate device is included in the device corresponding to the traffic sequence matrix.
[0168] Optionally, the second determining module 305 includes:
[0169] The seventh determining sub-module is configured to determine that the device state of the target candidate device is an abnormal state in the case where the confidence of the target candidate device is greater than or equal to a preset threshold.
[0170] The eighth determining sub-module is configured to determine that the device state of the target candidate device is a normal state in the case where the confidence of the target candidate device is less than the preset threshold.
[0171] The above device can automatically identify a target candidate device in a suspected state of abnormality based on traffic data of an access gateway, and further directly output the device state of the target candidate device through a trained confidence network model, so that all connected devices can be comprehensively covered based on traffic data, and the device state can be automatically identified, thereby improving the detection efficiency of detecting whether the device state is abnormal, and avoiding the problems of low detection efficiency and incomplete coverage caused by relying on physical inspection or manual inspection in traditional detection methods.
[0172] As to the device in the above embodiments, the specific manners in which various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described here in detail.
[0173] The present application also provides an electronic device, referring to Figure 4 , comprising a processor 401, a memory 402, and a computer program 4021 stored in the memory and executable on the processor, wherein the processor implements the device anomaly determination device of the above-mentioned embodiments when executing the program.
[0174] The application further provides a readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device can execute the device exception determination apparatus of the foregoing embodiments.
[0175] For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts are described in the part of the method embodiments.
[0176] It should be noted that the various information and data obtained in the embodiments of the application are obtained with the authorization of the information / data holder.
[0177] The algorithms and displays presented herein are not inherently related to any particular computer, virtual system, or other apparatus. Various general purpose systems can be used with programs in accordance with the teachings herein, or it can prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for a variety of these systems will be apparent from the description above. In addition, the present application is not intended to be limited to any particular programming language. It will be appreciated that there are many programming languages that can be used to implement the teachings herein, and any such programming language can be used in connection with the various aspects of the application.
[0178] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order to not obscure the understanding of this description.
[0179] Similarly, it is to be understood that the brunt of the application and the one or more of the various inventive aspects thereof are sometimes grouped together in a single embodiment, drawing or description thereof for the purpose of brevity in the foregoing detailed description. However, it is not the intention to in any way limit the claimed application to a particular embodiment disclosed. Rather, it is intended to cover all adaptations, modifications, and alterations of the claimed application, whether implemented now or in the future, that not only correspond to the generic description of the claimed application set out in the following claims, but also include all the specific embodiments thereof disclosed in the foregoing description that can be in the nature of the subject matter of the claims. It is intended that each of the claims (independent or dependent) to be interpreted in the broadest possible liberal manner consistent with the description of the claimed application in the claims. Accordingly, the claims are not intended to be limited to the preferred embodiments described herein.
[0180] Those skilled in the art will appreciate that the modules in the apparatuses in the embodiments can be adapted and placed in one or more apparatuses other than those in the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and furthermore can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, all combinations of all features disclosed in this specification (including accompanying claims, abstract and drawings) and all processes or units of any methods or apparatuses disclosed herein can be adopted. Unless explicitly stated otherwise, each feature disclosed in this specification (including accompanying claims, abstract and drawings) can be replaced by an alternative feature providing the same, equivalent or similar function.
[0181] Embodiments of the various components of the sequencing apparatus according to the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art will appreciate that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the sequencing apparatus according to the present application. The present application can also be implemented as a program for executing part or all of the methods described herein on a device or apparatus. Such a program implementing the present application can be stored on a computer readable medium or can have one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier medium, or in any other form.
[0182] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps not listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of hardware comprising several distinct elements, and by means of a suitably programmed computer. In the claims, the word 'first','second', and 'third', etc. does not imply any order. These words are to be interpreted as names.
[0183] The user information (including but not limited to user device information, user personal information, etc.) and related data involved in the present application are information authorized by the user or authorized by each party.
[0184] Those skilled in the art can clearly understand the specific working process of the system, device and unit described above for the convenience and brevity of description, which can refer to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0185] The above only describes the preferred embodiments of the present application, and is not intended to limit the present application. Any modification, equivalent replacement and improvement within the spirit and principle of the present application shall be included in the protection scope of the present application.
[0186] The above only describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which shall be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. An apparatus abnormality determination method characterized by comprising: The method comprises: obtaining access data of a target gateway, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway; performing multiple rounds of candidate device screening operations and determining a target candidate device screened out by the last candidate device screening operation; wherein each candidate device screening operation is configured to screen out a new candidate device from a candidate device screened out by a previous round according to traffic data in a corresponding execution time period of the current round and a screening condition, and the candidate device screened out in the first round is screened out from the access device; calculating a similarity between traffic data of the target candidate device and traffic data of other access devices within a preset time period; inputting the similarity into a trained confidence network model and determining a confidence of the target candidate device through the confidence network model; the confidence represents a determination degree of the target candidate device being in an abnormal state; determining a device state of the target candidate device according to the confidence of the target candidate device, wherein the device state comprises an abnormal state and a normal state; the performing multiple rounds of candidate device screening operations and determining a target candidate device screened out by the last candidate device screening operation comprises: in the traffic data in the first time period, if downlink traffic lasting a first preset time length is detected, it is determined that a first device accesses the target gateway, and a network address of the first device is obtained; performing multiple rounds of candidate device screening operations and determining a target candidate device screened out by the last candidate device screening operation; wherein each candidate device screening operation is configured to: in the obtained traffic data in a corresponding execution time period of the current round, if candidate traffic data lasting a preset time length and being greater than or equal to a preset traffic threshold is detected, a candidate network address of a device corresponding to the candidate traffic data is obtained; and in the case that the candidate network address corresponding to the candidate traffic data is consistent with a candidate network address screened out by a previous round, a candidate device screened out by the previous round is taken as a new candidate device screened out by the current round, and the candidate device screened out in the first round is screened out from the first device.
2. The method of claim 1, wherein, the execution time period comprises a first time period, a second time period, a third time period and a fourth time period; the performing multiple rounds of candidate device screening operations and determining a target candidate device screened out by the last candidate device screening operation comprises: in the traffic data in the first time period, if first uplink traffic lasting a second preset time length and being greater than or equal to a first preset traffic threshold is detected, a first network address of a device corresponding to the first uplink traffic is obtained, and in the case that the first network address is consistent with the network address of the first device, the first device is taken as a candidate device; In the flow data in the second time period, if the second uplink flow greater than or equal to the second preset flow threshold is detected for a second preset duration, the second network address of the device corresponding to the second uplink flow is obtained, and in the case that the second network address is consistent with the first network address, the first device is continued as a candidate device; In the flow data in the third time period, if the third uplink flow greater than or equal to the third preset flow threshold is detected for a second preset duration, the third network address of the device corresponding to the third uplink flow is obtained, and in the case that the third network address is consistent with the second network address, the first device is continued as a candidate device; In the flow data in the fourth time period, if the fourth uplink flow greater than or equal to the first preset flow threshold is detected for a third preset duration, the fourth network address of the device corresponding to the fourth uplink flow is obtained, and in the case that the fourth network address is consistent with the third network address, the first device is taken as a target candidate device.
3. The method of claim 1, wherein, The similarity between the flow data of the target candidate device and the flow data of other access devices in a preset time period includes: In the preset time period, the flow sequence corresponding to the target candidate device is determined according to the flow value corresponding to the target candidate device at each time, and the flow sequence corresponding to the other access devices is determined according to the flow value corresponding to the other access devices at each time; the flow sequence includes the flow value corresponding to each time; The edit distance of each flow sequence matrix is calculated, the flow sequence matrix includes any two different flow sequences, the flow sequences between each flow sequence matrix are not repeated, and the edit distance is used to represent the similarity of two flow sequences in the flow sequence matrix.
4. The method of claim 3, wherein, The method further includes: The sequence lengths of two flow sequences in the flow sequence matrix are obtained respectively; The ratio of the edit distance to the maximum sequence length is taken as the normalized edit distance, and the maximum sequence length is the maximum length of the two sequence lengths.
5. The method of claim 1, wherein, The similarity includes the edit distance; The similarity is input into a trained confidence network model, and the confidence of the target candidate device is determined through the confidence network model; The confidence represents the determination degree of the target candidate device in the abnormal state, including: The identification of the flow sequence matrix corresponding to the edit distance and the edit distance are taken as the input of the trained confidence network model, and a plurality of confidences output by the confidence network model are obtained, the confidence includes the identification of the corresponding flow sequence matrix; In the case that the target candidate device is included in the device corresponding to the flow sequence matrix, the confidence corresponding to the flow sequence matrix is taken as the confidence of the target candidate device.
6. The method according to any one of claims 1-5, characterized in that, The determination of whether the target candidate device is an abnormal device according to the confidence of the target candidate device includes: In the case that the confidence of the target candidate device is greater than or equal to a preset threshold, the device state of the target candidate device is determined as an abnormal state. In a case where the confidence of the target candidate device is less than the preset threshold, the device state of the target candidate device is determined as the normal state.
7. An apparatus abnormality determination device characterized by comprising: The apparatus comprises: An acquisition module acquires access data of a target gateway, wherein the access data comprises traffic data corresponding to an access device accessing the target gateway; A first determination module is configured to perform a plurality of rounds of candidate device screening operations and determine a target candidate device screened out in the last round of candidate device screening operation; wherein each round of candidate device screening operation is configured to screen new candidate devices from candidate devices screened out in the previous round according to traffic data in a time period corresponding to the current round and screening conditions, and in the first round, candidate devices are screened out from the access devices; A calculation module is configured to calculate a similarity between traffic data of the target candidate device and traffic data of other access devices in a preset time period; An input module is configured to input the similarity into a trained confidence network model and determine a confidence of the target candidate device through the confidence network model; the confidence represents a determination degree of the target candidate device being in an abnormal state; A second determination module is configured to determine a device state of the target candidate device according to the confidence of the target candidate device, wherein the device state comprises an abnormal state and a normal state; The performing a plurality of rounds of candidate device screening operations and determining a target candidate device screened out in the last round of candidate device screening operation comprises: in traffic data in a first time period, if downlink traffic lasting a first preset time length is detected, it is determined that a first device accesses the target gateway, and a network address of the first device is acquired; a plurality of rounds of candidate device screening operations are performed, and a candidate device screened out in the last round of candidate device screening operation is determined as the target candidate device; wherein each round of candidate device screening operation is configured to: in acquired traffic data in a time period corresponding to the current round, if candidate traffic data lasting a preset time length and being greater than or equal to a preset traffic threshold is detected, a candidate network address of a device corresponding to the candidate traffic data is acquired; and in a case where the candidate network address corresponding to the candidate traffic data is consistent with a candidate network address screened out in the previous round, a candidate device screened out in the previous round is taken as a new candidate device screened out in the current round, and in the first round, a candidate device is screened out from the first device.
8. An electronic device, comprising: comprises: A processor, a memory, and a computer program stored on the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1-6 when executing the program.
9. A readable storage medium, characterized by, When instructions in the storage medium are executed by the processor of the electronic device, the electronic device can perform the method according to any one of claims 1-6.
Citation Information
Patent Citations
Abnormal equipment detection method and device, electronic equipment and readable storage medium
CN112887333A
Abnormal equipment identification method and device, equipment, medium and program product
CN115426161A