Terminal identification method and device, electronic equipment and storage medium

By extracting plaintext information in terminal data packets and using semantic recognition models for identification, the problem of low recognition rate caused by terminal recognition dependence on feature database in the prior art is solved, and efficient and universal terminal attribute recognition is achieved.

CN119946609APending Publication Date: 2025-05-06RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311442795.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, terminal recognition depends on feature database, resulting in a low recognition rate, and feature database needs to be continuously maintained and updated, which is time-consuming and labor-intensive.

Method used

By obtaining the data packets sent by the terminal, the terminal attribute feature information contained in the plain text information is extracted, and the trained semantic recognition model is used for semantic recognition, and the terminal's attribute information is directly obtained.

Benefits of technology

There is no need to build a feature library in advance, and it can identify terminal attribute information in real time, which improves recognition rate and efficiency, and can identify multiple attributes such as terminal type, manufacturer, model, operating system, etc.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946609A_ABST
    Figure CN119946609A_ABST
Patent Text Reader

Abstract

The invention discloses a terminal identification method and device, electronic equipment and a storage medium, which are used for solving the problem that the identification rate is low as terminal identification depends on a feature library, and the method comprises the following steps: acquiring a data message sent by a terminal; extracting plaintext information in the data message, wherein the plaintext information comprises information for identifying attribute characteristics of the terminal; semantic recognition is conducted on the plaintext information based on the semantic recognition model, a semantic recognition result is obtained, and the semantic recognition result comprises attribute information of the terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a terminal identification method, device, electronic device and storage medium. Background Art

[0002] With the rapid development of information technology and the popularization of IoT technology, the number of network devices is increasing, and the diversification of device types has brought huge management challenges. These devices connected to the network can be collectively referred to as terminals, which can include smartphones, personal computers, and IoT devices. For the convenience of operation and maintenance and network security, it is necessary to identify the terminals connected to the network to identify the terminal's type, manufacturer, model, operating system and other attribute information.

[0003] In the related art, the terminal is identified based on fingerprint features, which is mainly based on information in the data message sent by the terminal, such as MAC (Media Access Control) address, host name (Host name), Option 60 field (Vendor Class Identifier) ​​and Option 50 field (Request List) in the DHCP (Dynamic Host Configuration Protocol) message, user agent (UA) string and other information to establish a feature library (also known as fingerprint library), build a correspondence between fingerprint features and terminal attributes (type, manufacturer, model, operating system, etc.), and identify the terminal accessing the network according to the correspondence between fingerprint features and terminal attributes. However, this method relies on the feature library. If the fingerprint feature of a terminal does not exist in the feature library, its attributes cannot be identified. The number of terminals on the market is huge, the coverage of the feature library is too low, and new terminals are continuously launched on the market. The feature library needs to be continuously maintained and updated, which is time-consuming and labor-intensive, and the recognition rate is low. Summary of the invention

[0004] In order to solve the problem that the recognition rate of a terminal is low due to the reliance on a feature library for terminal recognition, the embodiments of the present application provide a terminal recognition method, device, electronic device, and storage medium.

[0005] In a first aspect, an embodiment of the present application provides a terminal identification method, including:

[0006] Get the data message sent by the terminal;

[0007] Extracting plaintext information from the data message, wherein the plaintext information includes information identifying attribute characteristics of the terminal;

[0008] The plaintext information is semantically recognized based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes attribute information of the terminal.

[0009] In one implementation, extracting the plaintext information in the data message specifically includes:

[0010] Obtaining protocol type information in the data message;

[0011] Determine the message field corresponding to the protocol type according to the preset correspondence between the protocol type and the message field;

[0012] Extract the plaintext information in the message field.

[0013] In one embodiment, the semantic recognition model is a trained natural language processing (NLP) model;

[0014] The plaintext information is semantically recognized based on the semantic recognition model to obtain a semantic recognition result, which specifically includes:

[0015] The plaintext information extracted from the message field is input into the trained NLP model for semantic recognition to obtain attribute information of the terminal.

[0016] In one embodiment, the protocol type includes at least one of the following: Hypertext Transfer Protocol HTTP, Dynamic Host Configuration Protocol DHCP, Link Layer Discovery Protocol LLDP, Session Initiation Protocol SIP and Multicast Domain Name System mDNS protocol;

[0017] If the protocol type is HTTP, the message fields corresponding to the protocol type include: a user agent UserAgent field;

[0018] If the protocol type is DHCP, the message fields corresponding to the protocol type include Option 12 field and Option 60 field;

[0019] If the protocol type is LLDP, the message fields corresponding to the protocol type include a system name SystemName field, a system description System Description field, and a manufacturer name Manufacturer Name field;

[0020] If the protocol type is SIP, the message field corresponding to the protocol type includes a user agent UserAgent field;

[0021] If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type include a Srv field and a Model field.

[0022] In a second aspect, an embodiment of the present application provides a terminal identification device, including:

[0023] An acquisition unit, used for acquiring a data message sent by a terminal;

[0024] An extraction unit, configured to extract plain text information from the data message, wherein the plain text information includes information identifying attribute characteristics of the terminal;

[0025] The recognition unit is used to perform semantic recognition on the plain text information based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes attribute information of the terminal.

[0026] In one embodiment, the extraction unit is specifically used to obtain the protocol type information in the data message; determine the message field corresponding to the protocol type according to the preset correspondence between the protocol type and the message field; and extract the plaintext information in the message field.

[0027] In one embodiment, the semantic recognition model is a trained natural language processing (NLP) model;

[0028] The recognition unit is specifically used to input the plaintext information extracted from the message field into the trained NLP model for semantic recognition to obtain the attribute information of the terminal.

[0029] In one embodiment, the protocol type includes at least one of the following: Hypertext Transfer Protocol HTTP, Dynamic Host Configuration Protocol DHCP, Link Layer Discovery Protocol LLDP, Session Initiation Protocol SIP and Multicast Domain Name System mDNS protocol;

[0030] If the protocol type is HTTP, the message fields corresponding to the protocol type include: a user agent UserAgent field;

[0031] If the protocol type is DHCP, the message fields corresponding to the protocol type include Option 12 field and Option 60 field;

[0032] If the protocol type is LLDP, the message fields corresponding to the protocol type include a system name SystemName field, a system description System Description field, and a manufacturer name Manufacturer Name field;

[0033] If the protocol type is SIP, the message field corresponding to the protocol type includes a user agent UserAgent field;

[0034] If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type include a Srv field and a Model field.

[0035] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the terminal identification method described in the present application when executing the program.

[0036] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps in the terminal identification method described in the present application are implemented.

[0037] The beneficial effects of this application are as follows:

[0038] The terminal identification method, device, electronic device and storage medium provided in the embodiments of the present application obtain data packets sent by the terminal, extract plaintext information in the data packets, the plaintext information contains information identifying the attribute characteristics of the terminal, and semantically identify the plaintext information based on the semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes the attribute information of the terminal. In the embodiments of the present application, there is no need to pre-build a feature library to establish a correspondence between fingerprint features and terminal attributes. Instead, the data packets sent by the terminal can be obtained in real time, and the plaintext information containing the attribute characteristics identifying the terminal can be extracted from the data packets. The plaintext information can be semantically identified by the trained semantic recognition model to directly obtain the attribute information of the terminal. That is to say, the identification of the terminal attributes is converted into the identification of the text semantics of the plaintext information containing the attribute characteristics identifying the terminal. The terminal identification method provided in the embodiments of the present application is a more general terminal identification method, which can accurately identify the attribute information of any terminal based on the data packets sent by it, thereby improving the recognition rate and recognition efficiency.

[0039] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0041] Figure 1 A schematic diagram of an application scenario of the terminal identification method provided in an embodiment of the present application;

[0042] Figure 2 A schematic diagram of the implementation process of the terminal identification method provided in the embodiment of the present application;

[0043] Figure 3 A schematic diagram of the implementation process of extracting plaintext information from a data message provided in an embodiment of the present application;

[0044] Figure 4 A schematic diagram of the structure of a terminal identification device provided in an embodiment of the present application;

[0045] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] With the rapid development of information technology and the popularization of IoT technology, the number of network devices is increasing, and the diversification of device types has brought huge management challenges. These devices connected to the network can be collectively referred to as terminals, which can include smartphones, personal computers, and IoT devices. For the convenience of operation and maintenance and network security, it is necessary to identify the terminals connected to the network to identify the terminal's type, manufacturer, model, operating system and other attribute information.

[0047] In the related art, the terminal is identified based on fingerprint features, which is mainly based on information in the data message sent by the terminal, such as MAC (Media Access Control) address, host name (Host name), Option 60 field (Vendor Class Identifier) ​​and Option 50 field (Request List) in the DHCP (Dynamic Host Configuration Protocol) message, user agent (UA) string and other information to establish a feature library (also known as fingerprint library), build a correspondence between fingerprint features and terminal attributes (type, manufacturer, model, operating system, etc.), and identify the terminal accessing the network according to the correspondence between fingerprint features and terminal attributes. However, this method relies on the feature library. If the fingerprint feature of a terminal does not exist in the feature library, its attributes cannot be identified. The number of terminals on the market is huge, the coverage of the feature library is too low, and new terminals are continuously launched on the market. The feature library needs to be continuously maintained and updated, which is time-consuming and labor-intensive, and the recognition rate is low.

[0048] Another way to identify terminals is based on machine learning. It requires pre-collecting terminal-related information to build a data set for model training, and then identifying the terminal type through the trained classification model. However, only the terminal types included in the data set can be identified, and the coverage is limited. Moreover, this method can generally only identify the terminal type, but cannot identify other attribute information of the terminal, such as manufacturer, model, operating system, etc.

[0049] Based on this, the embodiments of the present application provide a terminal identification method, device, electronic device and storage medium, which obtain data packets sent by the terminal, extract plaintext information in the data packets, the plaintext information contains information that identifies the attribute characteristics of the terminal, and semantically identify the plaintext information based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes the attribute information of the terminal. In the embodiments of the present application, there is no need to pre-build a feature library to establish a correspondence between fingerprint features and terminal attributes. Instead, the data packets sent by the terminal can be obtained in real time, and the plaintext information containing the attribute characteristics of the terminal can be extracted from the data packets. The plaintext information can be semantically identified by a trained semantic recognition model, and the attribute information of the terminal can be directly obtained. That is to say, the terminal The identification of terminal attributes is converted into the identification of text semantics of plaintext information containing characteristics that identify terminal attributes. The terminal identification method provided in the embodiment of the present invention is a more general terminal identification method. The attribute information of any terminal can be accurately identified based on the data message sent by it, thereby improving the recognition rate and efficiency. In addition, compared with the method of identifying terminals based on machine learning, which can only identify the terminal type but cannot identify other attribute information of the terminal, such as manufacturer, model, operating system and other information, in the implementation of this application, the attribute information of the identified terminal is not limited to the type of the terminal, and the terminal attribute information corresponding to all terminal attribute characteristics contained in the data message sent by the terminal can be effectively identified, such as the type, manufacturer, model, operating system and other information of the terminal.

[0050] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application may be combined with each other if there is no conflict.

[0051] First reference Figure 1, which is a schematic diagram of an application scenario of the terminal identification method provided in an embodiment of the present application, which is a network topology diagram, and its structure includes: a terminal 100, a controller 101, an access device 102, namely: an access switch 102, an aggregation switch 103 (namely: an office area floor aggregation switch 103-1, a conference room floor aggregation switch 103-2 and a security aggregation switch 103-3), a core switch 104, a firewall 105, and an egress router 106, wherein the controller 101 can be, but is not limited to, an SDN (Software Defined Network) controller, and can also be other devices, such as a server, which is not limited in the embodiment of the present application. The terminal 100 sends a data message to the access switch 102 connected to it. The switch 102 uploads the data message sent by the terminal 100 to the aggregation switch 103 connected to it. The aggregation switch 103 uploads the data message to the core switch 104, which sends it to the egress router 106 through the fire zone 105. The egress router 106 then sends it to the device to which the destination IP (Internet Protocol) address corresponding to the data message belongs according to the set routing rules.

[0052] In one embodiment, when the access switch 102 receives a data message sent by the terminal 100, the access switch 102 can upload the received data message sent by the terminal 100 to the controller 101. After the controller 101 obtains the data message sent by the terminal 100, it extracts the plaintext information in the data message, where the plaintext information includes information that identifies the attribute characteristics of the terminal. Based on the trained semantic recognition model, that is, the trained NLP (English: Natural Language Processing) model, semantic recognition is performed on the plaintext information to obtain the attribute information of the terminal.

[0053] In one implementation, the controller 101 may also obtain the data message sent by the terminal 102 in the following manner: after the access switch 102 receives the data message sent by the terminal 100 , it sends the data message sent by the terminal 100 to the aggregation switch 103 , which then uploads it to the controller 101 .

[0054] In one embodiment, the controller 101 can also obtain the data packet sent by the terminal 102 in the following manner: when the access switch 102 receives the data packet sent by the terminal 100, it sends the data packet sent by the terminal 100 to the aggregation switch 103, and the aggregation switch 103 sends the data packet to the core switch 104, which is then uploaded to the controller 101 by the core switch 104.

[0055] During implementation, any of the above methods can be used to upload the data message sent by the terminal to the controller according to the actual network topology. The embodiment of the present application only takes the example of the access device 102 uploading the data message sent by the terminal 100 to the controller 101 for explanation.

[0056] Based on the above application scenarios, the following will refer to the attached Figures 2-3 The exemplary embodiments of the present application are described in more detail. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present application, and the implementation of the present application is not limited in any way. On the contrary, the implementation of the present application can be applied to any applicable scenario.

[0057] like Figure 2 As shown, it is a schematic diagram of an implementation flow of a terminal identification method provided in an embodiment of the present application. The terminal identification method can be applied to the above-mentioned controller 101, and specifically may include the following steps:

[0058] S21. The controller obtains the data message sent by the terminal.

[0059] During specific implementation, the access device receives a data message sent by a terminal, the data message carries terminal identification information, and the terminal identification information may be MAC address information of the terminal. The data message sent by the terminal and received by the access device is uploaded to the controller.

[0060] After the access device receives the data packet sent by the terminal, it can also extract the MAC address information of the terminal in the data packet, and send the terminal's MAC address information and data packet to the controller through the Openflow protocol or gRPC (English: google Remote Procedure Call) protocol. In this way, after the controller receives the data packet sent by the terminal uploaded by the access device, there is no need to extract the terminal's MAC address information in the data packet again. The Openflow protocol is a standard protocol between the controller and the switch.

[0061] S22. Extract plain text information from the data message, where the plain text information includes information that identifies terminal attribute characteristics.

[0062] In specific implementation, after receiving the data message sent by the terminal uploaded by the access device, the controller parses the data message and extracts the plaintext information in the data message, wherein the data message also carries the protocol type information, and the plaintext information contains information identifying the terminal attribute characteristics.

[0063] The protocol type includes at least one of the following: HTTP (English: Hypertext Transfer Protocol), DHCP (English: Dynamic Host Configuration Protocol), LLDP (English: Link Layer Discovery Protocol), SIP (English: Session initialization Protocol) and multicast domain name system mDNS (English: Multicast Domain Name System) protocol, etc., which are not limited in the embodiments of the present application. The terminal attribute characteristics may include at least one of the following characteristics: terminal type characteristics, terminal manufacturer characteristics, terminal model characteristics, terminal operating system characteristics, terminal browser characteristics, etc., which are not limited in the embodiments of the present application.

[0064] Specifically, you can follow the Figure 3 The process shown in the figure extracts the plaintext information in the data message, including the following steps:

[0065] S31. Obtain protocol type information carried in the data message.

[0066] In specific implementation, the controller includes a terminal identification component (or terminal identification module). When the controller receives a data packet sent by the terminal uploaded by the access device, the controller sends the data packet to the terminal identification component. If the access device reports the MAC address information of the terminal when reporting the data packet sent by the terminal to the controller, the controller sends the data packet and the MAC address information of the terminal to the terminal identification component. Then, the terminal identification component in the controller parses the data packet and extracts the protocol type information in the data packet.

[0067] Specifically, if the controller sends a data message and the MAC address information of the terminal to the terminal identification component, the terminal identification component can extract the protocol type information in the data message; if the controller only sends a data message to the terminal identification component but does not send the MAC address information of the terminal, the terminal identification component can extract the protocol type information and the MAC address information of the terminal in the data message.

[0068] S32. Determine the message field corresponding to the protocol type carried in the data message according to the preset correspondence between the protocol type and the message field.

[0069] In specific implementation, the message fields carrying information identifying terminal attribute characteristics in data messages of different protocol types are different. Therefore, the controller pre-stores the correspondence between preset protocol types and message fields as a basis for determining the message fields carrying information identifying terminal attribute characteristics in data messages.

[0070] Specifically, if the protocol type is HTTP, the message fields corresponding to the protocol type may include: User Agent field, the User Agent field of the HTTP message may include but is not limited to information identifying the browser characteristics of the terminal, such as the browser version and browser kernel used by the terminal.

[0071] If the protocol type is DHCP, the message fields corresponding to the protocol type may include the Option 12 field and the Option 60 field. The Options field in the DHCP message can be used to store control information and parameters that are not defined in the common protocol. The Option 12 field of the DHCP message contains information that identifies the host name characteristics of the terminal. The host name characteristics may include model characteristics, type characteristics, etc. The Option 60 field of the DHCP message contains information that identifies the manufacturer characteristics of the terminal.

[0072] If the protocol type is LLDP, the message fields corresponding to the protocol type may include a System Name field, a System Description field, and a Manufacturer Name field. The System Name field of the LLDP message contains information identifying the operating system characteristics of the terminal, the System Description field contains information identifying the relevant descriptive characteristics of the terminal (that is, the description of the terminal), and the Manufacturer Name field contains information identifying the manufacturer (that is, the manufacturer) characteristics of the terminal. LLDP is a device discovery protocol at the L2 (Layer 2) data link layer defined in 802.1ab. It is used to exchange basic information between network devices in a local area network so as to mutually discover and identify adjacent devices and their capability parameters. LLDP enables a network device connected to the network to send its main capabilities, management address, device identification, interface identification and other information to other network devices connected to the same local area network. When a network device receives this information from other network devices on the network, it stores this information in the form of MIB (Management Information Base). This MIB information can be used to discover the physical topology of the device and manage configuration information. LLDP is only designed for information notification, not a configuration or control protocol. It is used to notify the information of a network device and obtain information of other network devices, thereby obtaining relevant MIB information.

[0073] If the protocol type is SIP, the message field corresponding to the protocol type may include a User Agent field, and the User Agent field of the SIP message may include, but is not limited to, information identifying the type and model characteristics of the terminal. SIP is an application layer control protocol for multimedia communications over an IP network, used to create, modify, and terminate a session involving one or more participants.

[0074] If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type may include a Srv field and a Model field. The Srv field of the mDNS protocol message may include, but is not limited to, information including host name characteristics, port number characteristics, and other characteristics of the terminal corresponding to the service, and the Model field may include, but is not limited to, information including descriptive characteristics of the terminal (i.e., a description of the terminal).

[0075] The controller stores the correspondence between the above-mentioned protocol types and message fields. When the terminal identification component in the controller extracts the protocol type information carried in the data message sent by the terminal, it determines the message field corresponding to the protocol type of the data message based on the stored preset correspondence between the protocol type and the message field.

[0076] S33. Extract the plain text information in the message field.

[0077] In a specific implementation, after the terminal identification component in the controller determines the message field corresponding to the protocol type of the data message, it extracts the plain text information in each message field.

[0078] S23. Perform semantic recognition on the plain text information based on the semantic recognition model to obtain a semantic recognition result, where the semantic recognition result includes attribute information of the terminal.

[0079] In specific implementation, the plaintext information in the extracted message field is input into the trained NLP model for semantic recognition to obtain the attribute information of the terminal.

[0080] Specifically, after the terminal identification component in the controller extracts the plaintext information in each message field corresponding to the protocol type of the data message, the extracted plaintext information in each message field is combined, and the plaintext information in each message field can be concatenated and input into the trained NLP model for semantic recognition, and the attribute information of the terminal is output.

[0081] In the embodiment of the present application, the NLP model is used to perform semantic recognition on the input text information. The training of the NLP model can adopt a conventional training method, and the training process is as follows:

[0082] Data collection: First, large-scale text data is required for training general NLP models. NLP models can be but are not limited to BERT (Bidirectional Encoder Representations from Transformers), GPT (Generative Pre-Trained Transformer), LLaMA (Large Language Model MetaAI, an open and efficient large-scale basic language model released by Meta AI), ChatGPT (Chat Generative Pre-trained Transformer) and other models. The embodiments of the present application are not limited to this. The source of text data can be various text sources on the Internet, including but not limited to articles, news, social media, books, etc.

[0083] Data preprocessing: Preprocess the collected text data, including word segmentation, removal of stop words, data cleaning, etc., so that the model can better understand and generate text.

[0084] Select model architecture: Select an appropriate deep learning model architecture. You can use a transformer (English: Transformer) or its variants, which is not limited in this embodiment of the present application.

[0085] Initialize model weights: You can use random initialization to initialize the selected model.

[0086] Self-supervised learning: You can use self-supervised learning tasks such as language modeling to train models to understand and generate text. The model needs to predict the next word or subword in a text sequence.

[0087] Loss function: The cross entropy loss function is used to measure the gap between the model's prediction and the actual text.

[0088] Backpropagation and optimization: Use gradient descent or its variants to update the model's weights according to the gradient of the loss function to reduce the loss. Model training requires a lot of computing resources and can be performed on a GPU (Graphics Processing Unit) or TPU (Tensor Processing Unit).

[0089] Large-scale training: Training large language models requires large-scale computing resources, including large numbers of GPU or TPU cores and storage. Model training may take days or even weeks, depending on the size of the model and the size of the dataset.

[0090] Hyperparameter tuning: Adjust the model’s hyperparameters, including learning rate, batch size, number of model layers, number of hidden units, etc. The choice of these hyperparameters will affect the performance and training speed of the model.

[0091] In the embodiment of the present application, the model can be fine-tuned for the terminal recognition task to improve the recognition rate. The training text data used can be: the plain text information of the data message and the corresponding terminal attribute information, and the correlation between the output terminal attributes, for example: the operating system of the switch of XX manufacturer is RGOS; the manufacturer of SVP3000 IP phone is XXX.

[0092] In the case where the plain text information in the extracted message field does not contain information identifying the manufacturer characteristics of the terminal, in one implementation, the OUI (Organizationally Unique Identifier) ​​in the MAC address information of the terminal can be extracted, and the OUI database of the IEEE (Institute of Electrical and Electronics Engineers) can be queried through the OUI to find the manufacturer corresponding to the OUI. Among them, the MAC address is 6 bytes (48 bits) long, and the first 24 bits of the MAC address are the OUI, which is allocated to each network manufacturer by the IEEE and allocated by the manufacturer.

[0093] Here are a few examples to illustrate:

[0094] Taking the terminal as a smart phone as an example, the data message sent by the terminal includes a DHCP message and an HTTP message. The plaintext information extracted from the Option 60 field of the DHCP message is: vendor = HUAWEI: android: LYA, and the plaintext information extracted from the Option 12 field of the DHCP message is: host name = HUAWEI_Mate_20_Pro-358141c; the plaintext information extracted from the User Agent field of the HTTP message is: useragent = Mozilla / 5.0(X11; Linux x86_64) AppleWebKit / 537.36(KHTML, like Gecko) Chrome / 60.0.3112.32 Safari / 537.36. The plaintext information extracted from the DHCP message and the plaintext information extracted from the HTTP message are combined and input into the trained NLP model to obtain the attribute information of the terminal. The input of the NLP model can be: "A terminal, whose message information is as follows: dhcp vendor = HUAWEI: android: LYA, host name=HUAWEI_Mate_20_Pro-358141c, http useragent=Mozilla / 5.0(X11; Linux x86_64)AppleWebKit / 537.36(KHTML,like Gecko)Chrome / 60.0.3112.32Safari / 537.36, What are the attributes of this terminal? The type should be subdivided as much as possible. If an attribute is not certain, please fill in unknown. Please answer in the following format: Type: Manufacturer: Model: Operating system:", the recognition result output by the NLP model is: "Type: Smartphone, Manufacturer: Huawei (HUAWEI), Model: Mate 20Pro, Operating system: Android (based on Linux kernel)".

[0095] Taking the terminal as an IP phone as an example, the data message sent by the terminal includes a SIP message. The plain text information extracted from the User Agent field of the message is: user agent = IPPHONE SVP300050.133.3.45 0c:11:05:03:21:5a. Then, the plain text information extracted from the SIP message is input into the trained NLP model to obtain the attribute information of the terminal. The input of the NLP model can be: "A certain terminal, its SIP message information is as follows: user agent = IPPHONESVP3000 50.133.3.450c:11:05:03:21:5a, what are the attributes of this terminal? The type should be subdivided as much as possible. If you are not sure about an attribute, please fill in unknown. Please answer in the following format: Type: Manufacturer: Model: Operating System:", the recognition result output by the NLP model is: "Type: IP phone, Manufacturer: Unknown, Model: SVP3000, Operating System: Unknown". The manufacturer is not identified. You can also extract the OUI in the MAC address of the IP phone. According to the IEEE OUI database, you can find the manufacturer corresponding to the OUI in the MAC address of the IP phone to get the manufacturer information of the IP phone.

[0096] Taking the terminal as a switch as an example, the data message sent by the terminal includes an LLDP message. The plaintext information extracted from the SystemDescription field of the message is: System Description = Ruijie GibabitEthernet Switch with PoE (S2900-24GT4SFP / 2GT-PL) By Ruijie Networks. The plaintext information extracted from the LLDP message is input into the trained NLP model to obtain the attribute information of the terminal. The input of the NLP model can be: "A certain terminal, its LLDP message information is as follows: System Description = Ruijie GibabitEthernet Switch with PoE (S2900-24GT4SFP / 2GT-PL) By Ruijie Networks, what are the attributes of this terminal? The type should be subdivided as much as possible. If an attribute cannot be determined, please fill in unknown. Please answer in the following format: Type: Manufacturer: Model: Operating system:", the recognition result output by the NLP model is: "Type: Ethernet switch, manufacturer: Ruijie Networks (Ruijie Networks), Model: S2900-24GT4SFP / 2GT-PL, Operating System: Unknown".

[0097] The embodiment of the present application provides a terminal identification method, in which a controller obtains a data message sent by a terminal, extracts plaintext information in the data message, the plaintext information contains information identifying the attribute characteristics of the terminal, and performs semantic recognition on the plaintext information based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes the attribute information of the terminal. In the embodiment of the present application, there is no need to pre-build a feature library to establish a correspondence between fingerprint features and terminal attributes. Instead, the data message sent by the terminal can be obtained in real time, and the plaintext information containing the attribute characteristics identifying the terminal can be extracted from the data message. By performing semantic recognition on these plaintext information through a trained semantic recognition model, the attribute information of the terminal can be directly obtained. That is to say, the identification of the terminal attributes is converted into The terminal identification method provided in the embodiment of the present invention is a more general terminal identification method, which can accurately identify the attribute information of any terminal based on the data message sent by it, thereby improving the recognition rate and efficiency. Moreover, compared with the terminal identification method based on machine learning, which can only identify the terminal type but cannot identify other attribute information of the terminal, such as manufacturer, model, operating system and other information, in the implementation of the present application, the attribute information of the identified terminal is not limited to the type of the terminal, and the terminal attribute information corresponding to all terminal attribute features contained in the data message sent by the terminal can be effectively identified, such as the type, manufacturer, model, operating system and other information of the terminal.

[0098] Based on the same inventive concept, the embodiment of the present application also provides a terminal identification device. Since the principle of solving the problem by the above-mentioned terminal identification device is similar to that of the above-mentioned terminal identification method, the implementation of the above-mentioned device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0099] like Figure 4 As shown, it is a schematic diagram of the structure of the terminal identification device provided in an embodiment of the present application, which may include:

[0100] An acquisition unit 41 is used to acquire a data message sent by a terminal;

[0101] An extraction unit 42, configured to extract plain text information from the data message, wherein the plain text information includes information identifying attribute characteristics of the terminal;

[0102] The recognition unit 43 is used to perform semantic recognition on the plain text information based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes attribute information of the terminal.

[0103] In one implementation, the extraction unit 42 is specifically configured to obtain protocol type information in the data message; determine the message field corresponding to the protocol type according to a preset correspondence between the protocol type and the message field; and extract plaintext information in the message field.

[0104] In one embodiment, the semantic recognition model is a trained natural language processing (NLP) model;

[0105] The recognition unit 43 is specifically used to input the plain text information extracted from the message field into the trained NLP model for semantic recognition to obtain the attribute information of the terminal.

[0106] In one embodiment, the protocol type includes at least one of the following: Hypertext Transfer Protocol HTTP, Dynamic Host Configuration Protocol DHCP, Link Layer Discovery Protocol LLDP, Session Initiation Protocol SIP and Multicast Domain Name System mDNS protocol;

[0107] If the protocol type is HTTP, the message fields corresponding to the protocol type include: a user agent UserAgent field;

[0108] If the protocol type is DHCP, the message fields corresponding to the protocol type include Option 12 field and Option 60 field;

[0109] If the protocol type is LLDP, the message fields corresponding to the protocol type include a system name SystemName field, a system description System Description field, and a manufacturer name Manufacturer Name field;

[0110] If the protocol type is SIP, the message field corresponding to the protocol type includes a user agent UserAgent field;

[0111] If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type include a Srv field and a Model field.

[0112] Based on the same technical concept, the embodiment of the present application also provides an electronic device 500, referring to Figure 5 As shown, the electronic device 500 is used to implement the terminal identification method described in the above method embodiment. The electronic device 500 of this embodiment may include: a memory 501, a processor 502, and a computer program stored in the memory and executable on the processor, such as a terminal identification program. When the processor executes the computer program, the steps in the above terminal identification method embodiments are implemented.

[0113] The specific connection medium between the memory 501 and the processor 502 is not limited in the embodiment of the present application. Figure 5 In the embodiment, the memory 501 and the processor 502 are connected via a bus 503. The bus 503 is connected to the processor 502 via a bus 503. Figure 5The connection between other components is shown by bold lines, which is only for schematic illustration and is not intended to be limiting. The bus 503 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0114] The memory 501 may be a volatile memory, such as a random-access memory (RAM); the memory 501 may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 501 may be any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 501 may be a combination of the above memories.

[0115] The processor 502 is used to implement the terminal identification method provided in the embodiment of the present application.

[0116] An embodiment of the present application also provides a computer-readable storage medium that stores computer-executable instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.

[0117] In some possible implementations, various aspects of the terminal identification method provided in the present application may also be implemented in the form of a program product, which includes a program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the terminal identification method according to various exemplary implementations of the present application described above in this specification.

[0118] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0119] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0120] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0121] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0122] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0123] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A terminal identification method, characterized in that: include: Get the data message sent by the terminal; Extracting plaintext information from the data message, wherein the plaintext information includes information identifying attribute characteristics of the terminal; The plaintext information is semantically recognized based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes attribute information of the terminal.

2. The method according to claim 1, characterized in that Extracting the plaintext information in the data message specifically includes: Obtaining protocol type information in the data message; Determine the message field corresponding to the protocol type according to the preset correspondence between the protocol type and the message field; Extract the plaintext information in the message field.

3. The method according to claim 2, characterized in that The semantic recognition model is a trained natural language processing (NLP) model; The plaintext information is semantically recognized based on the semantic recognition model to obtain a semantic recognition result, which specifically includes: The plaintext information extracted from the message field is input into the trained NLP model for semantic recognition to obtain attribute information of the terminal.

4. The method according to claim 2, characterized in that The protocol type includes at least one of the following: Hypertext Transfer Protocol HTTP, Dynamic Host Configuration Protocol DHCP, Link Layer Discovery Protocol LLDP, Session Initiation Protocol SIP and Multicast Domain Name System mDNS protocol; If the protocol type is HTTP, the message fields corresponding to the protocol type include: a user agent field; If the protocol type is DHCP, the message fields corresponding to the protocol type include Option 12 field and Option 60 field; If the protocol type is LLDP, the message fields corresponding to the protocol type include a system name System Name field, a system description System Description field, and a manufacturer name Manufacturer Name field; If the protocol type is SIP, the message field corresponding to the protocol type includes a user agent field; If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type include a Srv field and a Model field.

5. A terminal identification device, characterized in that: include: An acquisition unit, used for acquiring a data message sent by a terminal; An extraction unit, configured to extract plain text information from the data message, wherein the plain text information includes information identifying attribute characteristics of the terminal; The recognition unit is used to perform semantic recognition on the plain text information based on a semantic recognition model to obtain a semantic recognition result, wherein the semantic recognition result includes attribute information of the terminal.

6. The device according to claim 5, characterized in that The extraction unit is specifically used to obtain the protocol type information in the data message; determine the message field corresponding to the protocol type according to the preset correspondence between the protocol type and the message field; and extract the plaintext information in the message field.

7. The device according to claim 6, characterized in that The semantic recognition model is a trained natural language processing (NLP) model; The recognition unit is specifically used to input the plaintext information extracted from the message field into the trained NLP model for semantic recognition to obtain the attribute information of the terminal.

8. The device according to claim 6, characterized in that The protocol type includes at least one of the following: Hypertext Transfer Protocol HTTP, Dynamic Host Configuration Protocol DHCP, Link Layer Discovery Protocol LLDP, Session Initiation Protocol SIP and Multicast Domain Name System mDNS protocol; If the protocol type is HTTP, the message fields corresponding to the protocol type include: a user agent field; If the protocol type is DHCP, the message fields corresponding to the protocol type include Option 12 field and Option 60 field; If the protocol type is LLDP, the message fields corresponding to the protocol type include a system name System Name field, a system description System Description field, and a manufacturer name Manufacturer Name field; If the protocol type is SIP, the message field corresponding to the protocol type includes a user agent field; If the protocol type is the mDNS protocol, the message fields corresponding to the protocol type include a Srv field and a Model field.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the terminal identification method according to any one of claims 1 to 4 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the terminal identification method according to any one of claims 1 to 4 are implemented.