Identification method of communication device and related device

By learning the messages of the devices to be detected online, and generating detection messages with the same protocol type is solved, the problem of excessive interactions between the detection devices and the devices to be detected is achieved, and network pressure is reduced and protocol type is accurately detected.

CN120034469APending Publication Date: 2025-05-23HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311571301.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In the internal network of the enterprise, the number of times the detection device interacts with the device to be detected is too high, resulting in an increase in network pressure and the specific protocol type of the device to be detected cannot be effectively detected.

Method used

By learning the message sent by the second device to the first device online, a detection message with the same port number, protocol type and payload is generated, reducing the number of interactions between the detection device and the device to be detected.

Benefits of technology

It effectively reduces the number of times the detection device interacts with the device to be detected, reduces network pressure, and can accurately detect the types of supported protocols of the device to be detected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034469A_ABST
    Figure CN120034469A_ABST
Patent Text Reader

Abstract

The invention discloses a communication device identification method and a related device, relates to the technical field of communication, and can reduce the number of times of interaction between detection equipment and to-be-detected equipment. In the method, a first communication device obtains information of a first message sent by a second device to a first device, the information of the first message comprising a first port number, a first protocol type and a first payload; a first communication device sends a first detection message to a first device, wherein the first detection message comprises a first port number, a first protocol type and a first payload.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technology, and in particular, to a communication device identification method and related devices. Background Art

[0002] With the deep integration of new technologies and businesses such as cloud computing, big data, and the Internet of Things, the boundary-based security architecture of enterprise internal networks is facing challenges, which in turn makes enterprise internal networks prone to vulnerabilities.

[0003] For example, an enterprise takes inventory of the device information of the assets in the internal network. When a vulnerability occurs in a certain type of device, based on this device information, the enterprise can quickly understand how many devices in its internal network are affected by the vulnerability. When taking inventory of assets, the port number of the device to be detected can be determined, and then all protocol types corresponding to the port number can be found in the device fingerprint library. Since it is impossible to know the specific protocol type supported by the device to be detected, the detection device must generate a detection message based on each corresponding protocol type in the fingerprint library, so it needs to interact with the device to be detected multiple times, which increases the network pressure.

[0004] Therefore, when detecting a device to be detected, how to reduce the number of interactions between the detection device and the device to be detected is a technical problem that needs to be solved urgently. Summary of the invention

[0005] The embodiments of the present application provide a communication device identification method and related devices, which can reduce the number of interactions between a detection device and a device to be detected.

[0006] The first aspect of the present application provides a method for online learning of detection messages, which is applied to a first communication device. The method includes: the first communication device obtains information of a first message sent by a second device to a first device, the information of the first message includes a first port number, a first protocol type and a first payload; the first communication device sends a first detection message to the first device, the first detection message includes a first port number, a first protocol type and a first payload.

[0007] In this scheme, the first detection message is obtained by learning the first message sent by the second device to the first device. Specifically, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message. Because the protocol type of the first detection message is the same as the protocol type of the first message, the first device supports the protocol type of the first message, which means that the first device also supports the protocol type of the first detection message. Therefore, the present application can obtain the protocol type supported by the first device by online learning of the messages exchanged between the first device and the second device, thereby obtaining the first detection message with the same protocol type. The detection device detects and identifies the device to be detected based on the detection message obtained by the above method, and there is no need to send a corresponding detection message to the device to be detected based on each possible protocol type, which effectively reduces the number of interactions between the detection device and the device to be detected, thereby reducing network pressure.

[0008] In a possible implementation of the first aspect, the first communication device obtains information of a second message sent by the first device to the second device, and the information of the second message includes a second payload; when the following conditions are met, the first detection message is a valid message, and the condition includes: after sending the first detection message, the first communication device receives a third message sent by the first device, and the third message includes the second payload.

[0009] In this solution, when the third message also includes the second payload, it means that the first detection message learned based on the first message can trigger the first device to send a message containing the second payload, just like the first message, which can illustrate the validity of the first detection message. Therefore, the first communication device determines whether the first detection message is valid by checking whether the received third message includes the second payload, so that those valid detection messages can be retained according to the verification result, and invalid detection messages can be discarded, thereby improving the validity of the final detection message.

[0010] In a possible implementation manner of the first aspect, a destination Internet Protocol (IP) address of the first detection message is a destination IP address of the first message or an IP address of a device to be detected.

[0011] In a possible implementation manner of the first aspect, a destination Media Access Control Address (MAC) address of the first detection message is a destination MAC address of the first message or a MAC address of the device to be detected.

[0012] In this solution, when the first detection message is the same as the destination IP address of the first message, the first detection message can be sent to the first device, and the validity of the first detection message can be determined based on the third message sent by the first device. When the first detection message is the IP address of the device to be detected, the first detection message can be sent to the device to be detected, thereby detecting the device to be detected. When the first detection message is the same as the destination MAC address of the first message, the first detection message can be sent to the first device, and the validity of the first detection message can be determined based on the third message sent by the first device. When the first detection message is the MAC address of the device to be detected, the first detection message can be sent to the device to be detected, thereby detecting the device to be detected.

[0013] In a specific design, the first port number is the destination port number of the first message.

[0014] In a specific design, the destination port number of the first detection message is the destination port number of the first message or the port number of the device to be detected. The port number of the device to be detected can be the port number of the server of the device to be detected or the port number of the application in the device to be detected.

[0015] In a possible implementation of the first aspect, the first communication device obtains information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; the first communication device sends a second detection message to the first device, and the second detection message includes a second port number, a second protocol type, and a third payload.

[0016] In this scheme, the first detection message is generated by learning the first message sent by the second device to the first device, and the second detection message is generated by learning the fourth message sent by the second device to the first device. Therefore, when the first detection message is invalid, detection can be performed through the second detection message. Furthermore, since the information carried in the fourth message and the second message may be different, the second detection message finally obtained may also be different from the first detection message. This increases the diversity of the detection messages in this scheme, making this scheme applicable to more diverse scenarios.

[0017] In a specific design, the destination IP address of the second detection message is the destination IP address of the fourth message or the IP address of the device to be detected.

[0018] In a specific design, the destination MAC address of the second detection message is the destination MAC address of the fourth message or the MAC address of the device to be detected.

[0019] In a possible implementation of the first aspect, the first communication device obtains information of a fifth message sent by a fourth device to a third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; the first communication device sends a third detection message to the third device, and the third detection message includes the third port number, the third protocol type, and the fourth payload.

[0020] In this solution, since the fourth device may belong to a different category of device from the second device, and the third device may also belong to a different category of device from the first device, the detection message is generated by learning the messages of different categories of devices, so that this solution can be applied to the detection of different categories of devices.

[0021] In a specific design, the third device and the first device are the same device, or the IP addresses of the third device and the first device belong to the same network segment.

[0022] In a specific design, the fourth device and the second device are the same device, or the IP addresses of the fourth device and the second device belong to the same network segment.

[0023] In a specific design, the destination IP address of the third detection message is the destination IP address of the fifth message or the IP address of the device to be detected.

[0024] In a specific design, the destination MAC address of the third detection message is the destination MAC address of the fifth message or the MAC address of the device to be detected.

[0025] In a specific design, the first communication device sends a fourth detection message to the first device, and the fourth detection message includes the first port number, the first protocol type and the first payload.

[0026] In this solution, the first detection message and the fourth detection message are generated by learning the first message, so that when the first detection message is invalid, the first communication device can detect the device to be detected through the fourth detection message.

[0027] In a specific design, the destination IP address of the fourth detection message is the destination IP address of the first message or the IP address of the device to be detected.

[0028] In a specific design, the destination MAC address of the fourth detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0029] In a possible implementation manner of the first aspect, the destination IP address of the first message is a multicast or broadcast IP address or the IP address of the first device; and / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

[0030] This solution does not limit the first message to only be a message that can only support point-to-point communication, such as a Transmission Control Protocol (TCP) message. The first message in this solution can also be a message that can be multicast or broadcast, such as a SIP message. Therefore, the destination IP address of the first message may be a multicast or broadcast IP address or the IP address of the first device, and the same applies to the destination MAC address of the first message.

[0031] In a possible implementation of the first aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol. In a specific implementation, the first protocol includes: Open Network Video Interface Forum (ONVIF) protocol, Session Initiation Protocol (SIP), Multicast Domain Name Service (mDNS) protocol, or a protocol defined by the manufacturer of the first device and the device to be detected. In a specific implementation, the first protocol may also include: TCP, User Datagram Protocol (UDP), IP or Hypertext Transfer Protocol (HTTP).

[0032] In this solution, the first detection message and the first message are both first protocol messages because the protocol format of the first message is learned when the first detection message is generated, and a first detection message capable of detecting the device is constructed based on the protocol format of the first message. Constructing a detection message based on the protocol format of the message actually sent during the device interaction process can make the detection message in this solution more practical.

[0033] In a possible implementation manner of the first aspect, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0034] In this solution, the first detection message is based on the first protocol, and the first message is based on the second protocol. At this time, it is only necessary to ensure that the device to be detected supports the first protocol, and to ensure that the first device supports both the first protocol and the second protocol. Therefore, it can be applied to the scenario where the device to be detected does not support the first protocol but only supports the second protocol.

[0035] In this solution, the first detection message can be an ONVIF protocol message, a SIP message or an mDNS protocol message. Among them, ONVIF protocol messages are generally messages that devices exchange when performing video services, SIP messages are generally messages that devices exchange when performing conversations, and mDNS protocol messages are generally messages used by hosts in a local area network to achieve mutual communication, so the first detection message can detect devices in these scenarios. It can be seen that the first detection message in this solution can be applied to a variety of scenarios. The first detection message can also be based on the protocol defined by the manufacturer of the device to be detected. If the first detection message is sent to different types of devices to be detected, and the messages sent by the devices to be detected from different manufacturers are received. Because the protocols defined on different manufacturers are different, the information carried in the messages sent by the devices to be detected from different manufacturers will be relatively different, so that the manufacturer and other device information of the device to be detected can be determined based on these highly different information.

[0036] In a possible implementation manner of the first aspect, the first communication device mirrors the first message from a fifth device, and the fifth device is an intermediate device between the first device and the second device; the first communication device obtains information of the first message based on the first message.

[0037] In a specific design, the first communication device can obtain the first message through port mirroring or traffic mirroring.

[0038] In a specific design, the fifth device is a network device, for example, the network device includes but is not limited to: a switch, a router or a firewall.

[0039] In a specific design, when the first communication device is a network device, the first communication device can directly mirror the first message through a local port without the aid of an intermediate device.

[0040] In a specific design, the first communication device can read the first message to obtain information of the first message.

[0041] In a specific design, the first communication device receives information of the first message sent by the fifth device.

[0042] In a possible implementation manner of the first aspect, the first communication device receives information of the second message sent by the fifth device.

[0043] In a specific design, the fifth device mirrors the second message and sends the information of the second message to the first communication device.

[0044] In a specific design, the first communication device mirrors the second message from the fifth device to obtain information of the second message, wherein the fifth device is an intermediate device between the first device and the second device.

[0045] In a specific design, the first communication device can obtain the second message through port mirroring or traffic mirroring.

[0046] In a possible implementation of the first aspect, the first communication device obtains multiple messages sent by the first device to the second device; the first communication device matches the key field of each message in the multiple messages with a field library; the first communication device obtains information of the second message based on the message in the multiple messages that successfully matches the field library.

[0047] In a specific design, after acquiring the plurality of messages, the first communication device may extract the key fields in the messages based on a data mining algorithm. For example, the data mining algorithm includes but is not limited to: term frequency-inverse document frequency (TF-IDF), TextRank, or linear discriminant analysis (LDA).

[0048] In a possible implementation of the first aspect, the field library is used to describe device information. In a specific implementation, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0049] In a specific design, the key field may be a field that appears more frequently in the message, and the fields in the field library describe the commonalities in the device information.

[0050] In a specific design, the first communication device can match the key field with the field library in the following manner: use a similarity algorithm to calculate the similarity between the key field and the field in the field library; when the similarity is higher than a threshold, it is considered that the key field matches successfully; when the similarity is equal to or lower than the threshold, it is considered that the key field matches unsuccessfully.

[0051] In a possible implementation of the first aspect, the first communication device responds to the second payload including device information of the first device, and the first communication device obtains information of the first message based on information of the second message; the first communication device generates the first detection message based on the information of the first message.

[0052] In this solution, when the second payload includes the device information of the first device, it means that the first message carries the device information. During the communication between the first device and the second device, the second device sends the first message to the first device, triggering the second device to send the second message to the first device. Therefore, the first communication device needs to obtain the first message, and then obtain the first detection message by learning the first message, so as to trigger the first device to send a message containing device information similar to the second message through the first detection message.

[0053] In a possible implementation manner of the first aspect, the first communication device obtains information of the first message based on a source IP address of the second message and a destination IP address of the second message, wherein the information of the second message includes: a source IP address of the second message and a destination IP address of the second message, the source IP address of the second message being the IP address of the first device, and the destination IP address of the second message being the IP address of the second device; and / or the first communication device obtains information of the first message based on a source MAC address of the second message and a destination MAC address of the second message, wherein the information of the second message includes: a source MAC address of the second message and a destination MAC address of the second message, the source MAC address of the second message being the MAC address of the first device, and the destination MAC address of the second message being the MAC address of the second device.

[0054] In this solution, since the first message is a message sent by the second device to the first device, and the second message is a message sent by the first device to the second device, the source IP address of the first message is the destination IP address of the second message, and the destination IP address of the first message is the source IP address of the second message. Therefore, the source IP address and the destination IP address of the second message can be determined according to the first message. When the first communication device obtains multiple messages, the first message can be found from the multiple messages according to the source IP address and the destination IP address.

[0055] In a possible implementation manner of the first aspect, the first communication device sends the first detection message to the device to be detected; receives a sixth message sent by the device to be detected; and parses device information of the device to be detected from the sixth message.

[0056] In this solution, after generating the first detection message, the first communication device can detect the device to be detected through the first detection message, without sending the first detection message to other devices, and then using other devices to detect the device to be detected. This method reduces the time overhead caused by the first communication device exchanging the first detection message with other devices, and also saves network resources.

[0057] In a possible implementation manner of the first aspect, the first communication device sends the second detection message to the device to be detected; receives a seventh message sent by the device to be detected; and parses device information of the device to be detected from the seventh message.

[0058] In a possible implementation manner of the first aspect, the first communication device sends the third detection message to the device to be detected; receives an eighth message sent by the device to be detected; and parses device information of the device to be detected from the eighth message.

[0059] In a specific design, the first communication device receives a fourth detection message sent by a fifth device, sends the fourth detection message to the device to be detected, receives a ninth message sent by the device to be detected, and parses device information of the device to be detected from the ninth message.

[0060] In a specific design, the first communication device can also send the first detection message to the network segment to which the IP address of the device to be detected belongs, receive the tenth message sent by the device to be detected, and parse the device information of the device to be detected from the tenth message.

[0061] The second aspect of the present application provides a method for identifying a communication device, which is applied to a second communication device, including: the second communication device receives the network segment to which the IP address of the device to be detected belongs, and then sends a first detection message to the network segment, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the second communication device receives the second message sent by the device to be detected, and then parses the device information of the device to be detected from the second message.

[0062] In this solution, the second communication device can send the first detection message to the network segment to which the IP address of the device to be detected belongs. Even if the specific IP address of the device to be detected is unknown, and only the network segment to which the IP address of the device to be detected belongs is known, this solution still detects the device to be detected. It can be seen that the identification method of the communication device of the present application can broaden the scenario of device detection.

[0063] In a possible implementation of the second aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol. In a specific implementation, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturer of the first device and the device to be detected. In a specific implementation, the first protocol may also include: TCP, UDP, IP or HTTP.

[0064] In a possible implementation manner of the second aspect, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0065] In this solution, the first detection message is based on the first protocol, and the first message is based on the second protocol. At this time, it is only necessary to ensure that the device to be detected supports the first protocol, and to ensure that the first device supports the first protocol and the second protocol at the same time. Therefore, it can be applied to the scenario where the device to be detected does not support the first protocol but only supports the second protocol.

[0066] In this solution, the first detection message can be an ONVIF protocol message, a SIP message or an mDNS protocol message. Among them, ONVIF protocol messages are generally messages that devices exchange when performing video services, SIP messages are generally messages that devices exchange when performing conversations, and mDNS protocol messages are generally messages used by hosts in a local area network to achieve mutual communication, so the first detection message can detect devices in these scenarios. It can be seen that the first detection message in this solution can be applied to a variety of scenarios. The first detection message can also be based on the protocol defined by the manufacturer of the device to be detected. If the first detection message is sent to different types of devices to be detected, and the messages sent by the devices to be detected from different manufacturers are received. Because the protocols defined on different manufacturers are different, the information carried in the messages sent by the devices to be detected from different manufacturers will be relatively different, so that the manufacturer and other device information of the device to be detected can be determined based on these highly different information.

[0067] In a possible implementation manner of the second aspect, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the above-mentioned network segment.

[0068] In a possible implementation manner of the second aspect, the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0069] In this solution, when the first detection message is the same as the destination IP address of the first message, the first detection message can be sent to the first device, and whether the first detection message is valid is determined based on the message sent by the first device. When the first detection message is the IP address of the device to be detected, the first detection message can be sent to the device to be detected, thereby detecting the device to be detected. When the first detection message is the same as the destination MAC address of the first message, the first detection message can be sent to the first device, and whether the first detection message is valid is determined based on the two messages sent by the first device. When the first detection message is the MAC address of the device to be detected, the first detection message can be sent to the device to be detected, thereby detecting the device to be detected.

[0070] In a possible implementation of the second aspect, the second communication device sends a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the second communication device receives a fourth message sent by the device to be detected; and parses the device information of the device to be detected from the fourth message.

[0071] In this scheme, the first detection message is similar to the first message sent by the second device to the first device, and the second detection message is similar to the third message sent by the second device to the first device. Since the information carried in the third message and the second message may be different, the second detection message may also be different from the first detection message, so that different devices to be detected can be detected using diverse detection messages.

[0072] In a possible implementation of the second aspect, the second communication device sends a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the second communication device receives the sixth message sent by the device to be detected; and parses the device information of the device to be detected from the sixth message.

[0073] In this scheme, since the fourth device may belong to a different category of device from the second device, and the third device may also belong to a different category of device from the first device, the third detection message and the first detection message are similar to messages of different categories of devices, respectively, so that the second communication device can detect devices of different categories through the third detection message and the first detection message.

[0074] In a specific design, the second communication device sends a fourth detection message to the network segment, and the port number, protocol type and payload of the fourth detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device.

[0075] In this scheme, in addition to sending the first detection message to the network segment, the second communication device also sends a fourth detection message to the network segment. The first detection message and the fourth detection message are similar to the first message. Therefore, when the first detection message is invalid, the second communication device can detect the device to be detected through the fourth detection message.

[0076] The third aspect of the present application provides a message sending method, which is applied to a third communication device, including: the third communication device receives a first detection message sent by a third device, the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the third communication device sends a first detection message to the third device, and the first detection message includes the device information of the device to be detected.

[0077] In this solution, the third communication device does not need to receive the detection message formulated by the third device based on each possible protocol type, but only needs to receive the first detection message formulated by the third device based on the protocol type of the first message, thereby effectively reducing the number of interactions between the third communication device and the third device, thereby reducing network pressure.

[0078] The fourth aspect of the present application provides a communication device, which includes a receiving module, a processing module and a sending module, and is used to perform all or part of the operations described in the first aspect, the second aspect or the third aspect. The communication device can be a network device such as a router or a switch, or a partial component of a network device for performing related operations, such as a line card, an interface board, etc., or a chip system for performing related operations, and the chip system can include one or more chips. When the communication device is a chip system, the receiving module and the sending module can be, for example, an interface circuit of a chip, and the processing module can be, for example, a processing circuit of a chip.

[0079] For example, when executing the method described in the first aspect, the processing module is used to obtain information of a first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type and a first payload; the receiving module is used to send a first detection message to the first device, wherein the first detection message includes the first port number, the first protocol type and the first payload.

[0080] In a possible implementation of the fourth aspect, the processing module is also used to obtain information of a second message sent by the first device to the second device, and the information of the second message includes a second payload; when the following conditions are met, the first detection message is a valid message, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

[0081] In a possible implementation manner of the fourth aspect, the destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0082] In a possible implementation of the fourth aspect, the processing module is also used to obtain information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type and a third payload; the sending module is also used to send a second detection message to the first device, wherein the second detection message includes the second port number, the second protocol type and the third payload.

[0083] In a possible implementation of the fourth aspect, the processing module is further used to obtain information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; the sending module is further used to send a third detection message to the third device, wherein the third detection message includes the third port number, the third protocol type, and the fourth payload.

[0084] In a possible implementation manner of the fourth aspect, the destination IP address of the first message is a multicast or broadcast IP address or the IP address of the first device; and / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

[0085] In a possible implementation manner of the fourth aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0086] In a possible implementation manner of the fourth aspect, the first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0087] In a possible implementation manner of the fourth aspect, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0088] In a possible implementation manner of the fourth aspect, the processing module is further used to mirror the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; and obtain information of the first message according to the first message.

[0089] In a possible implementation manner of the fourth aspect, the receiving module is further used to receive information of the second message sent by the fifth device.

[0090] In a possible implementation of the fourth aspect, the processing module is also used to obtain multiple messages sent by the first device to the second device; match the key fields of each message in the multiple messages with the field library; and obtain information of the second message based on the message in the multiple messages that successfully matches the field library.

[0091] In a possible implementation manner of the fourth aspect, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0092] In a possible implementation of the fourth aspect, the processing module is further used to, in response to the second payload including device information of the first device, obtain information of the first message according to information of the second message; and generate the first detection message according to the information of the first message.

[0093] In a possible implementation manner of the fourth aspect, the processing module is further used to obtain information of the first message based on the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or obtain information of the first message based on the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

[0094] In a possible implementation of the fourth aspect, the sending module is further used to send the first detection message to the device to be detected; the receiving module is further used to receive the sixth message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the sixth message.

[0095] In a possible implementation of the fourth aspect, the sending module is further used to send a second detection message to the device to be detected; the receiving module is further used to receive a seventh message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the seventh message.

[0096] In a possible implementation of the fourth aspect, the sending module is further used to send a third detection message to the device to be detected; the receiving module is further used to receive an eighth message sent by the device to be detected; and the processing module is further used to parse the device information of the device to be detected from the eighth message.

[0097] For example, when executing the method described in the second aspect, the receiving module is used to receive the network segment to which the IP address of the device to be detected belongs; the sending module is also used to send a first detection message to the network segment, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the receiving module is also used to receive the second message sent by the device to be detected; the processing module is used to parse the device information of the device to be detected from the second message.

[0098] In a possible implementation manner of the fourth aspect, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0099] In a possible implementation manner of the fourth aspect, the first detection message is the first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0100] In a possible implementation manner of the fourth aspect, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0101] In a possible implementation of the fourth aspect, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0102] In a possible implementation of the fourth aspect, the sending module is also used to send a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the receiving module is also used to receive a fourth message sent by the device to be detected; the processing module is also used to parse the device information of the device to be detected from the fourth message.

[0103] In a possible implementation of the fourth aspect, the sending module is also used to send a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the receiving module is also used for the sixth message sent by the device to be detected; the processing module is also used to parse the device information of the device to be detected from the sixth message.

[0104] For example, when executing the method described in the third aspect, the receiving module is used to receive a first detection message sent by a third device, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the sending module is used to send the first message to the third device, and the first message includes device information of the device to be detected.

[0105] In a fifth aspect, the present application provides a communication device, including a processor and a communication interface. The processor and the communication interface are used to execute the method described in any possible implementation of the first aspect, the second aspect or the third aspect.

[0106] In a specific design, the processor is coupled to a memory, for example, the memory is used to store programs or instructions. The at least one processor is used to execute the program or instructions so that the device implements all or part of the operations of the method described in any possible implementation of the first aspect, the second aspect or the third aspect.

[0107] In a sixth aspect, the present application provides a computer-readable storage medium, which stores a program or instruction. When the program or instruction runs on a processor, the method described in any possible implementation of the first aspect, the second aspect or the third aspect is executed.

[0108] In a seventh aspect, the present application provides a computer program product, including a program or an instruction, which, when executed on a processor, implements all or part of the operations of the method described in any possible implementation of the first aspect, the second aspect, or the third aspect. In a specific implementation, the computer program product may be the computer-readable storage medium mentioned in the sixth aspect.

[0109] An eighth aspect of the present application provides a communication system, which includes the communication device of the fourth aspect or the communication device of the fifth aspect.

[0110] Among them, the technical effects brought about by any design method in the fourth to eighth aspects can refer to the technical effects brought about by the above-mentioned first to third aspects and their different design methods, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0111] Figure 1 A schematic diagram of the system architecture of a communication device identification method provided in an embodiment of the present application;

[0112] Figure 2 A flowchart of a method 100 for online learning detection messages provided in an embodiment of the present application;

[0113] Figure 3 A schematic diagram of the structure of message 1 and detection message 1 provided in an embodiment of the present application;

[0114] Figure 4 A flow chart of a communication device identification method 200 provided in an embodiment of the present application;

[0115] Figure 5 A schematic diagram of the collaboration between the devices in Example 1;

[0116] Figure 6 This is a flow chart of Example 1;

[0117] Figure 7 A schematic diagram of the collaboration between the devices in Example 2;

[0118] Figure 8 This is a flow chart of Example 2;

[0119] Fig. 9 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;

[0120] Fig.10 Another structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0121] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the implementation methods of the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0122] The following are some terms related to the embodiments of the present application for explanation.

[0123] 1. The terminal device involved in the embodiments of the present application includes a device that provides voice to a user, a device that provides data connectivity to a user, or a device that provides voice and data connectivity to a user. For example, it may include a handheld device with a wireless connection function, or a processing device connected to a wireless modem. It can also be referred to as a terminal. The terminal can communicate with the core network via a radio access network (RAN), exchange voice or data with the RAN, or exchange voice and data with the RAN. The terminal may include user equipment (UE), wireless terminal, mobile terminal, device-to-device (D2D) terminal, vehicle to everything (V2X) terminal, road side unit (RSU), machine-to-machine / machine-type communications (M2M / MTC) terminal, Internet of Things (IoT) terminal, subscriber unit, subscriber station, mobile station (mobilestation), remote station (remote station), access point (AP), remote terminal (remote terminal), access terminal, user agent, or user device, etc. It may include a mobile phone (or "cellular" phone), a computer with a mobile terminal, a portable, pocket-sized, handheld, or computer-built-in mobile device, etc. It may include personal communication service (PCS) phones, cordless phones, telephones, wireless local loop (WLL) stations, personal digital assistants (PDAs), and other devices. It may also include restricted devices, devices with low power consumption, or devices with limited storage capacity, or devices with limited computing power, etc. It may include information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning systems (GPS), laser scanners, etc.

[0124] As an example but not limitation, in the embodiments of the present application, the terminal device may also be a wearable device. Wearable devices may also be referred to as wearable smart devices or smart wearable devices, etc., which are a general term for the application of wearable technology to intelligently design and develop wearable devices for daily wear, such as glasses, gloves, watches, clothing and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also powerful functions achieved through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include full-featured, large-size, and independent of smartphones to achieve complete or partial functions, such as smart watches or smart glasses, etc., as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various types of smart bracelets, smart helmets, and smart jewelry for vital sign monitoring.

[0125] The various terminals introduced above, if located on a vehicle, such as placed in a vehicle or installed in a vehicle, can be considered as vehicle-mounted terminals, which are also called on-board units (OBU).

[0126] In the embodiment of the present application, the device for realizing the function of the terminal may be a terminal, or a chip system capable of supporting the terminal to realize the function, and the chip system may be installed in the terminal. In the embodiment of the present application, the chip system may include at least one chip, or other discrete devices.

[0127] 2. The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" means one or more, and "plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or its similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, "at least one of A, B and C" includes A, B, C, AB, AC, BC or ABC. And, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the order, timing, priority or importance of multiple objects.

[0128] The following is an example of the system architecture of the embodiment of the present application.

[0129] like Figure 1 As shown, Figure 1A schematic diagram of a possible, non-limiting system architecture provided by this application. The solution provided by this application can be applied to Figure 1 System 1000 is shown.

[0130] System 1000 includes communication device 101, switch 1, switch 2, switch 3 and notebook 102. It should be noted that communication device 101 includes a device to be detected, and communication device 101 can be a terminal device or a network device. Notebook 102 is an example of a detection device, and the detection device can also be other terminal devices or network devices. Among them, communication device 101 can be, for example, Figure 1 The terminals shown are printers, IP phones, cameras, mobile phones, etc. Among them, some terminals communicate with switch 3 through switch 1, and some terminals communicate with switch 3 through switch 2. Switch 3 can mirror the received message to notebook 102.

[0131] It should be noted that switch 1, switch 2 and switch 3 are examples of intermediate devices between each communication device 101 and the notebook. The intermediate device is a network device, for example, the network device includes: a firewall or a router. In addition, the system 1000 usually includes multiple switches, but may also include only one switch, for example, the system 1000 includes only one switch 1. In this case, the communication device 101 reports a message to the switch 1, and then the switch 1 mirrors the message to the notebook 102.

[0132] When the notebook 102 detects the device to be detected, one possible implementation is to determine the port number of the device to be detected, and then search for all protocol types corresponding to the port number in the device fingerprint library. Since it is impossible to know the specific protocol type supported by the device to be detected, the notebook 102 must generate a detection message based on each corresponding protocol type in the fingerprint library, so it is necessary to interact with the device to be detected multiple times, which increases the network pressure. In addition, the protocol types included in the fingerprint library are only TCP / IP and other messages that can only communicate point-to-point. Therefore, when the IP address of the device to be detected is unknown, the device to be detected cannot be detected.

[0133] Therefore, when detecting a device to be detected, how to reduce the number of interactions between the detecting device and the device to be detected, and how to detect the device to be detected when the IP address of the device to be detected is unknown are technical problems that need to be solved urgently.

[0134] In order to solve the problem of excessive number of interactions between the detection device and the device to be detected, the embodiment of the present application provides a method 100 for online learning of detection messages, which can be applied to Figure 1 When method 100 is applied to Figure 1In the scenario shown, the device 2 in the method 100 may be, for example, Figure 1 The communication device 101 shown in the method 100 may be, for example, Figure 1 The notebook 102 or switch 3 shown. The method 100 generates a first detection message by learning a first message sent by the device 2 to the device 1. In the method 100, it is not necessary to generate a detection message based on each protocol, but only to generate a detection message based on the protocol adopted by the first message, thereby reducing the number of interactions between the detection device and the device to be detected.

[0135] Combine the following Figure 2 , to specifically introduce the method 100 provided in the embodiment of the present application. Figure 2 As shown, the method 100 for online learning detection messages provided in the embodiment of the present application includes the following steps:

[0136] Step 201, the communication device 1 obtains the message information of the message 1 sent by the device 2 to the device 1, and the message information includes the port number 1, the protocol type 1 and the payload 1;

[0137] Step 202 : The communication device 1 sends a detection message 1 to the device 1 , where the detection message 1 includes the port number 1 , the protocol type 1 and the payload 1 .

[0138] The communication device 1 may be a terminal device, for example Figure 1 The notebook 102 shown may also be a network device, for example Figure 1 The switch 3 shown. When the communication device 1 is a network device, the network device may include but is not limited to: a switch, a router or a firewall. It should be noted that the above protocol type 1 is the type of protocol based on the message 1. For example, if the message 1 is a SIP message, the protocol type 1 is SIP.

[0139] It should be noted that payload is used to carry the original data of the message. The name of payload may be different in different protocols. For example, in UDP messages, payload is called UDP data; in SIP messages, payload is called message body.

[0140] It should be noted that the message information of message 1 may not include port number 1 and protocol type 1, but include information indicating port number 1 and protocol type 1. For example, the message information of message 1 includes information indicating the method for obtaining port number 1.

[0141] It should be noted that, in the embodiment of the present application, message 1 is not limited to a message that can only support point-to-point communication, such as a TCP message. Message 1 in the embodiment of the present application can also be a message that can be multicast or broadcast, such as a SIP message. Therefore, message 1 can be sent in the form of unicast, multicast or broadcast. Accordingly, the destination IP address and the destination media access control (media access control, mac) address of message 1 can be in the following forms:

[0142] In a possible implementation, the destination IP address of the message 1 may be a multicast or broadcast IP address, or may be the IP address of the device 1 .

[0143] In a possible implementation, the destination MAC address of the message 1 may be a multicast or broadcast MAC address, or may be the MAC address of the device 1 of the message 1 .

[0144] In addition, the port number 1 mentioned above may be the destination port number of the message 1 , that is, the port number of the device 1 .

[0145] In step 201, message 1 may be obtained in a variety of implementations:

[0146] In a possible implementation, the communication device 1 mirrors the message 1 from the device 5 , where the device 5 is an intermediate device between the device 1 and the device 2 ; the communication device 1 obtains the message information of the message 1 according to the message 1 .

[0147] In yet another possible implementation, the communication device 1 receives the message information of the message 1 sent by the device 5 .

[0148] In the first implementation manner, after mirroring message 1, device 5 sends message 1 to communication device 1. After receiving message 1, communication device 1 can read message 1 to obtain message information of message 1. In the second implementation manner, after mirroring message 1, device 5 can read message information of message 1 and then send the message information to communication device 1. Device 5 can also directly mirror message information of message 1 and then send the message information to communication device 1.

[0149] Optionally, the device 5 is a network device. In addition, the communication device 1 does not necessarily have to obtain the message 1 through the device 5. When the communication device 1 is a network device, the communication device 1 can directly mirror the message 1 through a local port.

[0150] It can be understood that in order to better learn message 1 to detect the device to be detected, the composition of detection message 1 should be as consistent as possible with the composition of message 1. Therefore, the port number, protocol type and payload included in the detection message 1 in step 202 are consistent with the port number, protocol type and payload of message 1.

[0151] The above step 202 describes part of the information that the detection message 1 needs to include. As for other information included in the detection message 1, the following possibilities exist:

[0152] Optionally, the destination port number of the detection message 1 may be the destination port number of the message 1. The destination port number of the detection message 1 may also be the port number of the device to be detected, the port number of the server of the device to be detected, or the port number of an application in the device to be detected.

[0153] In a possible implementation, the destination IP address of the detection message 1 is the destination IP address of the message 1 or the IP address of the device to be detected;

[0154] In a possible implementation, the destination MAC address of the detection message 1 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0155] It should be noted that the above-mentioned device to be detected may be a terminal device or a network device.

[0156] In addition, there are many situations regarding the protocol based on the detection message 1. Specifically:

[0157] In a possible implementation, the detection message 1 and the message 1 are both protocol 1 messages, and the device to be detected and the device 1 both support protocol 1.

[0158] In another possible implementation, the detection message 1 is a protocol 1 message, the message 1 is a protocol 2 message, the device to be detected supports the protocol 1, and the device 1 supports both the protocol 1 and the protocol 2.

[0159] In the first implementation, it can be understood that since device 2 can communicate with device 1 through message 1, device 1 must support the protocol based on message 1. Therefore, detection message 1 can be generated based on the protocol format of message 1, and device 1 must also support the protocol based on detection message 1.

[0160] As for the detection message 1 and the specific protocol based on the message 1, it can be in the following ways:

[0161] In a possible implementation, the protocol 1 includes: ONVIF, SIP, mDNS protocol, or a protocol defined by the manufacturers of the device 1 and the device to be detected.

[0162] The above-mentioned "protocols defined by the manufacturers of device 1 and the device to be detected" refer to some proprietary protocols defined by the manufacturers of device 1 and the device to be detected in order to improve product performance, etc. For example, the model of device 1 is M, and manufacturer A, which produces device 1, customizes the proprietary protocol of model M devices so that model M devices can communicate quickly with each other.

[0163] The above implementation method only lists some protocols. The embodiments of the present application are not limited to the above protocols. Protocol 1 can also be various types of IoT protocols, such as UDP, IP, etc.

[0164] Compared to the method of generating detection messages only through general protocols, the embodiments of the present application can generate detection messages based on dedicated protocols. Since proprietary protocols are unique to each manufacturer, the probability of duplication with device-related information defined by other manufacturers is relatively small. Therefore, when a detection message generated based on a proprietary protocol is sent to a device to be detected, the device-related information carried in the message sent by the device to be detected will be relatively different, so that the device information of the device to be detected can be determined based on these device-related information with large differences.

[0165] Combination Figure 3 To illustrate the information included in the detection message 1, Figure 3 For example, if message 1 is a SIP message, detection message 1 is also a SIP message. Message 1 is sent to device 1, so the destination address is the address of device 1, and the address of device 1 can be either the IP address of device 1 or the MAC address. Correspondingly, the destination address of detection message 1 is the address of device 1 or the address of the device to be detected. And the message bodies of both are payload 1. For another example, detection message 1 and message 1 are both UDP messages. Message 1 is sent to device 1, so the destination port number is the port number of device 1. Correspondingly, the destination port number of detection message 1 is the port number of device 1 or the port number of the device to be detected. And the data parts of both are payload 1.

[0166] Since it is impossible to ensure that all detection messages generated based on message 1 can effectively detect the device to be detected, it is necessary to verify the detection message. Specifically, it can be implemented in the following ways:

[0167] In a possible implementation, information of message 2 sent by device 1 to device 2 is obtained, and the information of message 2 includes payload 2; when the following conditions are met, the detection message 1 is a valid message, and the conditions include: after sending the detection message 1, message 3 sent by device 1 is received, and message 3 includes payload 2.

[0168] It is understandable that when device 1 and device 2 are in the process of communicating, device 2 sends message 1 to device 1, and device 2 replies to device 1 with message 2. The standard for verifying whether the learning process of detection message 1 is effective is whether detection message 1 can trigger device 1 to send a message similar to message 2, i.e., message 3, like device 2. Since device information is usually carried in the payload, and the embodiment of the present application needs to detect device information, when the payload included in message 3 is consistent with the payload included in message 2, it can be said that the detection message is valid.

[0169] When the communication device 1 obtains multiple messages, not all of these messages need to be learned. As mentioned above, the embodiment of the present application needs to detect device information. Therefore, what the embodiment of the present application needs to learn is the message that can trigger the device to send device information. Taking device 1 and device 2 as an example, device 2 sends message 1 to device 1, and device 1 replies to device 2 with message 2. If message 2 includes device information, then by learning message 1 to generate detection message 1, and sending the detection message 1 to device 1, device 1 can be triggered to return a message similar to message 2 containing device information. Based on this, first obtain message 2 containing device information from multiple messages. Specifically, it can be implemented in the following way:

[0170] In one possible implementation, multiple messages sent by the device 1 to the device 2 are obtained; the key field of each message in the multiple messages is matched with a field library; and the information of the message 2 is obtained based on the message in the multiple messages that successfully matches the field library.

[0171] It should be further explained that the purpose of the above implementation method is to find a message including device information among multiple messages. Therefore, the key field in the message is first determined. The key field is a field that appears more frequently in message 1. Then, the key field is matched with the field library. The fields in the field library describe the commonalities in the device information. Therefore, if the match is successful, it means that the key field is a field that describes the device information, so it can be determined that the message including the key field is a message carrying the device information.

[0172] Optionally, after obtaining multiple messages, key fields in these messages can be extracted based on data mining algorithms. For example, natural language processing technologies such as TF-IDF can be used to analyze the text in the message and extract key fields to obtain key fields such as category, manufacturer, model, etc. that appear in the message.

[0173] In a possible implementation, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0174] It should be noted that the fields in the field library describe the commonality in the device information. For example, the key field of device 1 is A1, which means that this device is the first generation of the A series device. The key field of device 2 is A2, which means that device 2 is the second generation of the A series device. The commonality of AI and A2 is that they are both A plus numeric characters. The field in the field library is AX, where X represents all possible numeric characters. Therefore, no matter when key fields such as A1 and A2 appear in the message, they can be successfully matched with AX in the field library, thereby determining that A1 and A2 are fields used to describe the model information of the device. When a new generation of A model devices appears, such as A model 70, it can still be matched with the field library, and the corresponding detection message is still generated based on this. Therefore, this solution can still be applicable to the detection of a new generation of A model devices. It can be seen that this solution still has good expansion capabilities for newly emerging devices to be detected, or unknown devices, and can still be used for the detection of such devices. In addition, in the embodiment of the present application, the field library only stores fields such as the name field of the device brand and the name field of the device model, without storing regular expressions and rules for determining device information. It can be seen that the field library of the embodiment of the present application has a small amount of data and can save memory resources.

[0175] After obtaining message 2, communication device 1 needs to obtain message information of message 1. Specifically, it can be implemented in the following manner:

[0176] In a possible implementation, in response to payload2 including device information of device 1, communication device 1 obtains message information of message 1 according to information of message 2; communication device 1 generates detection message 1 according to the message information of message 1.

[0177] In a possible implementation, the communication device 1 obtains the message information of the message 1 according to the source IP address of the message 2 and the destination IP address of the message 2, wherein the information of the message 2 includes: the source IP address of the message 2 and the destination IP address of the message 2, the source IP address of the message 2 is the IP address of the device 1, and the destination IP address of the message 2 is the IP address of the device 2;

[0178] In one possible implementation, communication device 1 obtains message information of message 1 based on the source MAC address of message 2 and the destination MAC address of message 2, wherein the information of message 2 includes: the source MAC address of message 2 and the destination MAC address of message 2, the source MAC address of message 2 is the MAC address of device 1, and the destination MAC address of message 2 is the MAC address of device 2.

[0179] In the above implementation, message 1 is a message sent from device 2 to device 1, message 2 is a message sent from device 1 to device 2, the source IP address of message 1 is the destination IP address of message 2, and the destination IP address of message 1 is the source IP address of message 2. Therefore, the source IP address and the destination IP address of message 1 can be determined according to message 2. When the communication device 1 obtains multiple messages, message 1 can be found from the multiple messages according to the source IP address and the destination IP address. Similarly, the communication device 1 can also obtain message 2 according to the source MAC address and the destination MAC address of message 1, or obtain message 2 according to the source port and the destination port of message 1. In addition, the protocol types of message 1 and message 2 are also the same, and message 2 can be obtained in combination with the protocol type of message 1.

[0180] In addition to generating the detection message 1, the communication device 1 may also generate other detection messages to deal with the situation where the detection message 1 is invalid, specifically, including the following situations:

[0181] In addition to generating detection message 1 through learning message 1, communication device 1 can also generate detection message 2 through learning message 1. Specifically:

[0182] Optionally, the communication device 1 sends a detection message 2 to the device 1 , where the detection message 2 includes a port number 1 , a protocol type 1 and a payload 1 .

[0183] Optionally, the destination IP address of the detection message 2 is the destination IP address of the message 1 or the IP address of the device to be detected.

[0184] Optionally, the destination MAC address of the detection message 2 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0185] The communication device 1 can also obtain other messages sent by the device 2 to the device 1, and generate the detection message 3 by learning the message. Specifically:

[0186] In a possible implementation, the communication device 1 obtains a message 4 sent by the device 2 to the device 1, wherein the message 4 includes a port number 2, a protocol type 2 and a payload 3; the communication device 1 sends a detection message 3 to the device 1, wherein the detection message 3 includes the port number 2, the protocol type 2 and the payload 3.

[0187] Optionally, the destination IP address of the detection message 3 is the destination IP address of the message 4 or the IP address of the device to be detected.

[0188] Optionally, the destination MAC address of the detection message 3 is the destination MAC address of the message 4 or the MAC address of the device to be detected.

[0189] It can be understood that detection message 1 is similar to message 1 sent by device 2 to device 1, and detection message 3 is similar to message 4 sent by device 2 to device 1. Since the information carried in message 4 may be different from that carried in message 2, detection message 3 may also be different from detection message 1. This increases the diversity of detection messages in the present scheme, making the present scheme applicable to a wider variety of scenarios.

[0190] The communication device 1 can also obtain messages in the communication process of other devices, and generate detection messages by learning the messages. Specifically:

[0191] In a possible implementation, the communication device 1 obtains a message 5 sent by the device 4 to the device 3, wherein the message 5 includes a port number 3, a protocol type 3 and a payload 4; the communication device 1 sends a detection message 4 to the device 3, wherein the detection message 4 includes the port number 3, the protocol type 3 and the payload 4.

[0192] In this solution, since device 4 may belong to a different category from device 2, and device 3 may also belong to a different category from device 1, the detection message obtained by learning messages of devices of different categories can be applied to the detection of devices of different categories.

[0193] Optionally, the destination IP address of the detection message 4 is the destination IP address of the message 5 or the IP address of the device to be detected.

[0194] Optionally, the destination MAC address of the detection message 4 is the destination MAC address of the message 5 or the MAC address of the device to be detected.

[0195] Optionally, device 3 can be the same device as device 1, or the IP addresses of device 3 and device 1 belong to the same IP network segment. When device 3 and device 1 are the same device, messages sent to device 1 by devices other than device 2 can be obtained, and detection messages 4 can be generated based on these messages. Device 4 can be the same device as device 2, or the IP addresses of device 4 and device 2 belong to the same IP network segment. When device 4 and device 2 are the same device, messages sent to devices other than device 1 by device 2 can be obtained, and detection messages 4 can be generated based on these messages. It can be understood that it is only necessary to ensure that there is a difference between device 4 and device 2, or that there is a difference between device 3 and device 1, and it is not necessary to ensure that there is a difference between device 4 and device 2 and between device 3 and device 1.

[0196] In method 100, detection message 1 is obtained by learning message 1 sent by device 2 to device 1. Specifically, the port number, protocol type and payload of detection message 1 are the same as the port number, protocol type and payload of message 1. Since device 2 can communicate with device 1 through message 1, device 1 must support the protocol on which message 1 is based, and also support the protocol on which detection message 1 is based. Therefore, the embodiment of the present application only needs to learn message 1 to generate detection message 1 and send the detection message 1, without sending the corresponding detection message to the device to be detected based on each possible protocol type, thereby reducing the number of interactions with the device to be detected, thereby reducing network pressure.

[0197] In order to solve the problem that the device to be detected cannot be detected when the IP address of the device to be detected is unknown, the embodiment of the present application provides a detection method 200, which can be applied to Figure 1 When method 200 is applied to Figure 1 In the scenario shown, the device 2 in the method 200 may be, for example, Figure 1 The communication device 101 shown, the device 1 in the method 200 may be, for example, Figure 1 The communication device 101 shown in the figure, the communication device 2 in the method 200 may be, for example, Figure 1 The laptop 102 or switch 3 shown. In the method 200, the detection of the device to be detected is achieved by obtaining the IP segment to which the IP address of the device to be detected belongs and sending a detection message to the IP segment. In the method 200, the detection can be completed only by knowing the IP segment to which the device to be detected belongs. Even if the IP address of the device to be detected is unknown, the device to be detected can still be detected.

[0198] It should be noted that the method 200 may use the detection message learned in the method 100 to detect the device to be detected. The method 200 may also use the detection message obtained in other ways to detect the device to be detected, and this application does not limit this.

[0199] See also Figure 4 , Figure 4 Schematic diagram of the flow of the communication device identification method 200 provided in the embodiment of the present application. Figure 4 As shown, the method 200 provided in the embodiment of the present application includes the following steps 401 to 404.

[0200] Step S401: The communication device 2 receives the network segment to which the IP address of the device to be detected belongs;

[0201] It should be noted that the communication device 2 may be the communication device 1 in the method 100, that is, the communication device 1 not only learns the detection message 1 online, but also detects the device to be detected through the detection message 1. The communication device 2 may not be the communication device 1 in the method 100. At this time, the detection message 1 of the communication device 2 may be sent by the communication device 1 or by other devices.

[0202] It should be noted that the above-mentioned detection message 2 is not the same as the detection message 1 in method 100, and the communication device will send a new message to the device to be detected. The reason why the detection message 1 is still used here to refer to the detection message is that the detection message 1 in this stage has the same content as the detection message 1 in the detection message online learning stage.

[0203] It should be noted that this solution can also obtain the IP address of the device to be detected. Optionally, the communication device 2 can receive the IP address of the device to be detected and then send a detection message 1 to the device to be detected. Specifically, the communication device 2 can use the IP address as the target IP address of the detection message 1, so that the detection message 1 can be sent to the device to be detected.

[0204] Step S402: the communication device 2 sends a detection message 1 to the network segment, the port number, protocol type and payload of the detection message 1 are the same as the port number, protocol type and payload of the message 1 sent by the device 2 to the device 1;

[0205] The protocols based on the above detection messages also have multiple implementation methods:

[0206] In a possible implementation, the detection message 1 and the message 1 are both protocol 1 messages, and the device to be detected and the device 1 both support protocol 1.

[0207] In another possible implementation, the detection message 1 is a protocol 1 message, the message 1 is a protocol 2 message, the device to be detected supports the protocol 1, and the device 1 supports both the protocol 1 and the protocol 2.

[0208] In the first implementation, it can be understood that since device 2 can communicate with device 1 through message 1, device 1 must support the protocol based on message 1. Therefore, detection message 1 can be generated based on the protocol format of message 1. At this time, device 1 must also support the protocol based on detection message 1, so that communication with device 1 can be carried out through detection message 1.

[0209] As for the detection message 1 and the specific protocol based on the message 1, it can be implemented in the following manner:

[0210] In a possible implementation, the protocol 1 includes: ONVIF, SIP, mDNS protocol, or a protocol defined by the manufacturers of the device 1 and the device to be detected.

[0211] In a possible implementation, detection message 1 is a message based on protocol 1, message 1 is a message based on protocol 2, the device to be detected supports protocol 1, and device 1 supports both protocol 1 and protocol 2.

[0212] In a possible implementation, protocol 1 includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of device 1 and the device to be detected.

[0213] For a detailed description of the above implementation, reference may be made to the description of the protocol of the detection message 1 and the protocol of the message 1 in the method 100 .

[0214] Optionally, protocol 1 may also include: TCP, UDP, IP or HTTP.

[0215] Since this solution does not limit the protocol type of message 1 to TCP / IP or other protocols that only support point-to-point communication, message 1 can also be based on a protocol that supports multicast or broadcast. For example, SIP, accordingly, the destination IP address of detection message 1 can also be multiple IP addresses, specifically:

[0216] In a possible implementation, the destination IP address of the detection message 1 is the destination IP address of the message 1 or each IP address included in the above network segment.

[0217] It is understandable that when the detection message 1 is the same as the destination IP address of message 1, the detection message 1 can be sent to device 1, and the validity of the detection message 1 is determined according to message 2 sent by device 1. When the detection message 1 is the IP address of the device to be detected, the detection message 1 can be sent to the device to be detected, so as to detect the device to be detected.

[0218] In a possible implementation, the destination MAC address of the detection message 1 is the destination MAC address of the message 1 or the MAC address of the device to be detected.

[0219] In addition to sending the detection message 1, the communication device 2 can also send other detection messages to the device to be detected:

[0220] In one possible implementation, the communication device 2 sends the detection message 2 to the network segment, and the port number, protocol type and payload of the detection message 2 are the same as those of the message 1 sent by the device 2 to the device 1; the communication device 1 receives the message 3 sent by the device to be detected; and the device information of the device to be detected is parsed from the message 3.

[0221] In one possible implementation, the communication device 2 sends the detection message 2 to the network segment, and the port number, protocol type and payload of the detection message 2 are the same as the port number, protocol type and payload of the message 4 sent by the device 2 to the device 1; the communication device 1 receives the message 5 sent by the device to be detected; and the device information of the device to be detected is parsed from the message 5.

[0222] In one possible implementation, the communication device 2 sends the detection message 3 to the network segment, and the port number, protocol type and payload of the detection message 4 are the same as the port number, protocol type and payload of the message 6 sent by the device 3 to the device 4; the communication device 1 receives the message 7 sent by the device to be detected; and the device information of the device to be detected is parsed from the message 7.

[0223] When the communication device 2 receives multiple detection messages, optionally, when the category of the device to be detected is known, the multiple detection messages are first divided according to the applicable category, and then the corresponding detection message is matched and sent according to the category of the device to be detected. For example, if the device to be detected is a device of manufacturer A, a detection message suitable for detecting the device of manufacturer A is matched, and the detection message is sent to the device to be detected. Optionally, when the category of the device to be detected is unknown, all learned detection messages are sent to the device to be detected.

[0224] Step S403: the communication device 2 receives the message 2 sent by the device to be detected;

[0225] It is understandable that when the communication device 2 sends multiple detection messages, such as the detection message 1 and the detection message 2 mentioned above, the communication device 2 may receive multiple messages 2. In addition, when the communication device 2 does not receive the message 2 sent by the device to be detected, the communication device 2 can send other detection messages to the device to be detected.

[0226] Step S404: the communication device 2 parses the device information of the device to be detected from the message 2.

[0227] Optionally, the above device information includes but is not limited to: the manufacturer of the device, the model of the device or the type of the device.

[0228] It should be noted that there is a field in message 2 for indicating device information. After reading the field, the communication device 2 obtains the device information. The communication device 2 can also use data mining to analyze the text of message 2 to obtain the device information of the device to be detected.

[0229] In this solution, the communication device 2 can send a detection message 1 to the network segment to which the IP address of the device to be detected belongs. Even if the specific IP address of the device to be detected is unknown, and only the network segment to which the IP address of the device to be detected belongs is known, this solution still detects the device to be detected. It can be seen that the identification method of the communication device of the present application can broaden the scenarios for device detection.

[0230] For ease of understanding, the above method 100 and method 200 will be introduced below with reference to specific examples.

[0231] Embodiment 1 is a specific example of the communication device 1 in method 100 being a network terminal identification (NTID) module. The NTID in Embodiment 1 is only a specific naming method for describing the function of the online learning detection message. NTID is only an example of a naming method. Other naming methods can also be used to describe the function. NTID and other naming methods are within the scope of protection of this application. The NTID module can be a computer program product, which can be configured in a network device, such as a switch, or in a terminal device, such as a notebook. Figure 5 This is a specific example of how the NTID module is configured in a switch. Figure 5 In the example, the NTID module of the switch includes multiple submodules, each of which includes instructions or programs. When the instructions or programs of the submodules are run on the processor of the switch, the following operations are implemented:

[0232] Message receiving submodule: receives the message mirrored from the communication device.

[0233] Probe message online learning submodule: performs online learning on mirror messages to generate probe messages.

[0234] The detection message storage submodule stores the detection messages learned by the detection message online learning submodule in the memory of the switch or in an external memory.

[0235] Message sending submodule: sends detection messages.

[0236] Data processing submodule: performs data processing on the messages obtained from the communication device.

[0237] Figure 6 is a schematic diagram in Example 1, Figure 6 The specific process includes:

[0238] Step 601, the NTID module mirrors the message from the communication device;

[0239] It should be noted that the above communication device includes a terminal device and a network device. The NTID module can receive a message mirrored from the communication device through a message receiving submodule, and then send the message to the detection message online learning submodule or the data processing submodule, so that the detection message online learning submodule or the data processing submodule executes step 602.

[0240] Step 602, the NTID module determines the key fields in each message;

[0241] In step 602, "each message" refers to each message obtained in step 601. In step 602, the NTID module can analyze the text of each message and extract key fields based on a data mining algorithm, such as a TF-IDF algorithm, to obtain key fields such as category, manufacturer, and model that appear in each message.

[0242] Step 603: The NTID module calculates the similarity between the key field and the fields in the field library;

[0243] The key field in step 603 is the key field extracted in step 602, and the field library is a local field library or a cloud field library. The field library includes fields used to describe the commonality of device information, such as computer model plus numeric characters. The NTID module uses a similarity algorithm to calculate the similarity between the key field and the field in the field library. If the similarity is higher than the threshold, it proves that the key field is a field describing device information, and continues to step 604; if the similarity is lower than or equal to the threshold, it is considered that the field is not a field describing device information, and returns to step 601.

[0244] Step 604: The NTID module reads the message 1 with high similarity, and obtains information such as the source IP address and destination IP address of the message 1;

[0245] When the similarity between the key field calculated in step 603 and the field in the field library is higher than the threshold, the message 1 to which the key field belongs is read.

[0246] Step 605, the NTID module obtains message 2 according to the source IP address, destination IP address and other information of message 1;

[0247] Assuming that message 1 is a message sent from device A to device B, message 2 is a message sent from device B to device A. More specifically, the source IP address of message 1 is the address of device A, and the destination IP address is the address of device B. The source IP address of message 2 is the address of device B, and the destination IP address is the address of device A. Therefore, the source IP address and destination IP address of message 2 can be determined based on the source IP address and destination IP address of message 1, and message 2 can be obtained according to the source IP address and destination IP address. Similarly, communication device 1 can also obtain message 2 according to the source MAC address and destination MAC address of message 1, or obtain message 2 according to the source port and destination port of message 1. In addition, the protocol types of message 1 and message 2 are also the same, and message 2 can be obtained in combination with the protocol type of message 1.

[0248] Step 606: The NTID module generates a detection message;

[0249] After obtaining message 2, the NTID module generates a detection message by learning message 2. Specifically, the port number, payload and protocol type of the detection message are consistent with those of message 2.

[0250] Step 607: The NTID module sends a detection message to the corresponding communication device;

[0251] The “corresponding communication device” in step 607 refers to the communication device that receives message 2 .

[0252] After step 607, the message sent by the corresponding communication device may not be received, that is, step 608 cannot be performed. At this time, the process returns to step 601 and re-learns the detection message.

[0253] Step 608: The NTID module receives a message sent by the corresponding communication device;

[0254] The purpose of step 607 and step 608 is to verify the validity of the detection message. The principle is to send a detection message to the communication device that receives message 2. If the message sent by the communication device can be received, and the key words in the message are extracted through algorithms such as data mining, and the key fields are consistent with the key fields determined in step 602, it means that the detection message can trigger the communication device to send a message containing device information like message 2, so the detection message is valid, and step 609 is continued; if the message sent by the communication device cannot be received, or the message sent by the communication device does not contain the key fields consistent with those in step 602, it means that the detection message is invalid, and then return to step 601 to re-learn the detection message.

[0255] Step 609: The NTID module stores the detection message, or sends the detection message to other devices.

[0256] After the detection message is verified to be valid through step 607 and step 608, the detection message can be stored in the detection message storage submodule of the NTID, or sent to other devices, such as a communication device that detects the device to be detected.

[0257] After step 609, the NTID module may repeatedly execute steps 601 to 609, continuously mirror new messages from the communication device, and then learn the detection message based on the new message.

[0258] Example 2

[0259] Embodiment 2 is a specific example in which the communication device 2 in method 200 is an NTID module. The NTID in Embodiment 2 is only a specific naming method used to describe the device identification function. NTID is only an example of a naming method. Other naming methods can also be used to describe the function. NTID and other naming methods are within the protection scope of this application. The NTID module can be a computer program product, which can be configured in a switch or a notebook. Figure 7 This is a specific example of the NTID module being configured in a switch. As shown in 7, the NTID module receives the detection message sent by the notebook and detects the device to be detected through the detection message. In Example 2, the NTID module of the switch includes multiple submodules, each of which includes instructions or programs. When the instructions or programs of the submodules are run on the processor of the switch, the following operations are implemented:

[0260] Message receiving submodule: receives the detection message sent by the notebook, and receives the message returned by the device to be detected after sending the detection message to the device to be detected.

[0261] Probe message storage submodule: stores the probe message sent by the notebook in the memory of the switch or in an external memory.

[0262] Message sending submodule: sends detection messages.

[0263] Data processing submodule: performs data processing on the messages returned by the detection device.

[0264] Figure 8 This is a schematic diagram in Example 2. Figure 8 The specific process includes:

[0265] Step 801, the notebook sends a detection message to the NTID module;

[0266] In Example 2, when the notebook learns the detection message through method 100, the notebook and the communication device for learning the detection message can be connected to the switch. The NTID module of the switch can mirror the message for the communication device to the notebook, and the notebook learns these messages to obtain the detection message, and then the notebook sends the detection message to the NTID module.

[0267] Step 802: The NTID module receives the network segment to which the IP address of the device to be detected belongs;

[0268] The network segment to which the IP address of the device to be detected belongs can be sent to the NTID module by the network management.

[0269] Step 803: The NTID module sends a detection message to the network segment;

[0270] The network segment in step 803 is the “network segment to which the IP address of the device to be detected belongs” in step 802, and the NTID module can periodically send detection messages to the network segment.

[0271] Step 804, the NTID module receives the message sent by the detection message;

[0272] The switch can divert the messages sent by the device to be detected to the NTID module

[0273] Step 805: The NTID module processes the message to obtain device information of the device to be detected.

[0274] The NTID module may extract device information from the text of the message based on a data mining algorithm, such as a TF-IDF algorithm.

[0275] The above describes the embodiment of the present application from the perspective of the method. The following describes the communication device in the embodiment of the present application from the perspective of specific device implementation.

[0276] Fig. 9 Schematic diagram of a communication device provided in an embodiment of the present application. Fig. 9 As shown, the communication device 900 includes a receiving module 901, a processing module 902 and a sending module 903. As an example, the communication device 900 can implement the functions of the communication device 1 in the above method 100, and thus can also achieve the beneficial effects of the above method 100.

[0277] Specifically, the processing module 902 is used to obtain information of a first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type and a first payload; the receiving module 901 is used to send a first detection message to the first device, wherein the first detection message includes a first port number, a first protocol type and a first payload.

[0278] In one possible implementation, the processing module 902 is also used to obtain information of a second message sent by the first device to the second device, and the information of the second message includes a second payload; when the following conditions are met, the first detection message is a valid message, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

[0279] In a possible implementation, the destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0280] In one possible implementation, the processing module 902 is further used to obtain information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; the sending module 903 is further used to send a second detection message to the first device, wherein the second detection message includes a second port number, a second protocol type, and a third payload.

[0281] In one possible implementation, the processing module 902 is also used to obtain information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; the sending module 903 is also used to send a third detection message to the third device, wherein the third detection message includes a third port number, a third protocol type, and a fourth payload.

[0282] In one possible implementation, the destination IP address of the first message is a multicast or broadcast IP address or an IP address of the first device;

[0283] In a possible implementation manner, and / or the destination MAC address of the first message is a multicast or broadcast MAC address or a MAC address of the first device.

[0284] In a possible implementation manner, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0285] In a possible implementation, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0286] In a possible implementation manner, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0287] In a possible implementation, the processing module 902 is further configured to mirror the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; and obtain information of the first message according to the first message.

[0288] In a possible implementation, the receiving module 901 is further configured to receive information of a second message sent by a fifth device.

[0289] In one possible implementation, the processing module 902 is also used to obtain multiple messages sent by the first device to the second device; match the key field of each message in the multiple messages with the field library; and obtain information of the second message based on the message in the multiple messages that successfully matches the field library.

[0290] In a possible implementation, the field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

[0291] In a possible implementation, the processing module 902 is further configured to, in response to the second payload including device information of the first device, obtain information of the first message according to information of the second message; and generate a first detection message according to the information of the first message.

[0292] In one possible implementation, the processing module 902 is further used to obtain information of the first message based on the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or obtain information of the first message based on the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

[0293] In a possible implementation, the sending module 903 is further used to send a first detection message to the device to be detected; the receiving module 901 is further used to receive a sixth message sent by the device to be detected; and the processing module 902 is further used to parse device information of the device to be detected from the sixth message.

[0294] In a possible implementation, the sending module 903 is further used to send a second detection message to the device to be detected; the receiving module 901 is further used to receive a seventh message sent by the device to be detected; and the processing module 902 is further used to parse device information of the device to be detected from the seventh message.

[0295] In a possible implementation, the sending module 903 is further used to send a third detection message to the device to be detected; the receiving module 901 is further used to receive an eighth message sent by the device to be detected; and the processing module 902 is further used to parse device information of the device to be detected from the eighth message.

[0296] As another example, the communication device 900 can implement the functions of the communication device 2 in the above method 200, and thus can also achieve the beneficial effects possessed by the above method 200.

[0297] Specifically, the receiving module 901 is used to receive the network segment to which the IP address of the device to be detected belongs; the sending module 903 is also used to send a first detection message to the network segment, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the receiving module 901 is also used to receive the second message sent by the device to be detected; the processing module 902 is used to parse the device information of the device to be detected from the second message.

[0298] In a possible implementation manner, the first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

[0299] In a possible implementation, the first detection message is a first protocol message, the first message is a second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

[0300] In a possible implementation manner, the first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by manufacturers of the first device and the device to be detected.

[0301] In a possible implementation, the destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; and / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

[0302] In one possible implementation, the sending module 903 is also used to send a second detection message to the network segment, and the port number, protocol type and payload of the second detection message are the same as the port number, protocol type and payload of the third message sent by the second device to the first device; the receiving module 901 is also used to receive a fourth message sent by the device to be detected; the processing module 902 is also used to parse the device information of the device to be detected from the fourth message.

[0303] In one possible implementation, the sending module 903 is also used to send a third detection message to the network segment, and the port number, protocol type and payload of the third detection message are the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; the receiving module 901 is also used for the sixth message sent by the device to be detected; the processing module 902 is also used to parse the device information of the device to be detected from the sixth message.

[0304] As another implementation example, the communication device 900 can implement the function of the device to be detected in the method 200, and thus can also achieve the beneficial effects possessed by the above-mentioned method 200.

[0305] Specifically, the receiving module 901 is used to receive a first detection message sent by a third device, and the port number, protocol type and payload of the first detection message are the same as the port number, protocol type and payload of the first message sent by the second device to the first device; the sending module 903 is used to send a first message to the third device, and the first message includes device information of the device to be detected.

[0306] Fig.10 1 is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of the present application. Fig.10 As shown, the communication device 1000 includes: a processor 1001 and a memory 1002 .

[0307] The memory 1002 is used to store computer-readable instructions; the processor 1001 is used to call the computer-readable instructions and execute all or part of the operations of the above-mentioned method 100 or method 200 according to the instructions of the computer-readable instructions.

[0308] In a specific implementation, the communication device 1000 may include a communication interface 1003, wherein the memory 1002, the processor 1001 and the communication interface 1003 are connected to each other for communication. The communication interface 1003 is used to implement the transceiver operation, and the processor 1001 is used to implement operations other than the transceiver operation.

[0309] In the embodiment of the present application, the processor may be, for example, but not limited to, any one or more of the following combinations: a central processing unit (CPU), a network processor (NP), a tensor processing unit (TPU), a neural network processor (NPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD). The PLD may be a complex programmable logic device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. The processor may refer to one processor or may include multiple processors. The processor may include one or more processing cores, and the processor executes various functional applications and data processing by running a computer program. The processor may be connected to a memory and a communication interface via a communication bus.

[0310] In an embodiment of the present application, the memory may include a volatile memory, such as a random access memory (RAM). The memory may also include a non-volatile memory, such as a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD). The memory may also include a combination of the above-mentioned types of memories. The memory may refer to one memory or may include multiple memories. In a specific embodiment, a computer-readable instruction is stored in the memory, and the computer-readable instruction includes multiple software modules, such as the receiving module 901, the processing module 902 and the sending module 903 described above. After executing each software module, the processor may perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor according to the instructions of the software module. After the processor executes the computer-readable instruction in the memory, it may perform all or part of the operations that the communication device can perform according to the instructions of the computer-readable instruction.

[0311] In an embodiment of the present application, there may be multiple communication interfaces, and the communication interfaces are used to communicate with other devices. The communication interface may include a wired communication interface, a wireless communication interface, or a combination thereof. Among them, the wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof, etc.

[0312] In the above embodiments, it can be implemented in whole or in part by hardware, firmware or any combination thereof. When software is involved in the specific implementation process, it can be embodied in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium (eg, an SSD), etc.

[0313] The following is an example of the system of the embodiment of the present application.

[0314] An embodiment of the present application further provides a communication system, including: a plurality of communication devices, wherein the plurality of communication devices may include, for example, a communication device for implementing part or all of the operations of any of the above methods.

[0315] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.

[0316] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.

[0317] The term "and / or" in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.

[0318] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for online learning detection messages, It is characterized in that The method comprises: Acquire information of a first message sent by the second device to the first device, wherein the information of the first message includes a first port number, a first protocol type, and a first payload; A first detection message is sent to the first device, where the first detection message includes the first port number, the first protocol type, and the first payload.

2. The method for online learning detection message according to claim 1, It is characterized in that The method further comprises: Acquire information of a second message sent by the first device to the second device, where the information of the second message includes a second payload; The first detection message is a valid message when the following conditions are met, and the conditions include: after sending the first detection message, a third message sent by the first device is received, and the third message includes the second payload.

3. The method for online learning detection message according to claim 1 or 2, It is characterized in that The destination IP address of the first detection message is the destination IP address of the first message or the IP address of the device to be detected; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

4. The method for online learning detection message according to any one of claims 1 to 3, It is characterized in that The method further comprises: Acquire information of a fourth message sent by the second device to the first device, wherein the information of the fourth message includes a second port number, a second protocol type, and a third payload; A second detection message is sent to the first device, where the second detection message includes the second port number, the second protocol type, and the third payload.

5. The method for online learning detection message according to any one of claims 1 to 4, It is characterized in that The method further comprises: Acquire information of a fifth message sent by the fourth device to the third device, wherein the information of the fifth message includes a third port number, a third protocol type, and a fourth payload; Send a third detection message to the third device, where the third detection message includes the third port number, the third protocol type, and the fourth payload.

6. The method for online learning detection message according to any one of claims 1 to 5, It is characterized in that The destination IP address of the first message is a multicast or broadcast IP address or an IP address of the first device; And / or the destination MAC address of the first message is a multicast or broadcast MAC address or the MAC address of the first device.

7. The method for online learning detection message according to any one of claims 1 to 6, It is characterized in that The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

8. The method for online learning detection message according to any one of claims 1 to 6, It is characterized in that The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

9. The method for online learning detection message according to claim 7 or 8, It is characterized in that The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

10. The method for online learning detection message according to any one of claims 1 to 9, It is characterized in that The obtaining information of the first message sent by the second device to the first device includes: mirroring the first message from a fifth device, where the fifth device is an intermediate device between the first device and the second device; The information of the first message is obtained according to the first message.

11. The method for online learning detection message according to any one of claims 1 to 10, It is characterized in that The acquiring information of the second message sent by the first device to the second device includes: Receive information of the second message sent by the fifth device.

12. The method for online learning detection message according to any one of claims 1 to 11, It is characterized in that The acquiring information of the second message sent by the first device to the second device includes: Acquire multiple messages sent by the first device to the second device; Matching a key field of each message in the plurality of messages with a field library; The information of the second message is obtained according to the message that successfully matches the field library among the multiple messages.

13. The method for online learning detection message according to claim 12, It is characterized in that The field library includes one or more of the following fields: a name field of a device brand, a name field of a device model, a device category field, or a serial number of a device.

14. The method for online learning detection message according to any one of claims 2 to 13, It is characterized in that Before sending the first detection message, the method further includes: In response to the second payload including the device information of the first device, acquiring the information of the first message according to the information of the second message; Generate the first detection message according to the information of the first message.

15. The method for online learning detection message according to claim 14, It is characterized in that The acquiring the information of the first message according to the information of the second message includes: acquiring information of the first message according to the source IP address of the second message and the destination IP address of the second message, wherein the information of the second message includes: the source IP address of the second message and the destination IP address of the second message, the source IP address of the second message is the IP address of the first device, and the destination IP address of the second message is the IP address of the second device; and / or The information of the first message is obtained according to the source MAC address of the second message and the destination MAC address of the second message, wherein the information of the second message includes: the source MAC address of the second message and the destination MAC address of the second message, the source MAC address of the second message is the MAC address of the first device, and the destination MAC address of the second message is the MAC address of the second device.

16. The method for online learning detection message according to any one of claims 1 to 15, It is characterized in that After sending the first detection message to the first device, the method further includes: Sending the first detection message to the device to be detected; Receiving a sixth message sent by the device to be detected; The device information of the device to be detected is parsed from the sixth message.

17. The method for online learning detection message according to any one of claims 4 to 16, It is characterized in that After sending the second detection message to the first device, the method further includes: Sending the second detection message to the device to be detected; Receiving a seventh message sent by the device to be detected; The device information of the device to be detected is parsed from the seventh message.

18. The method for online learning detection message according to any one of claims 5 to 17, It is characterized in that After sending the third detection message to the third device, the method further includes: Sending the third detection message to the device to be detected; Receiving an eighth message sent by the device to be detected; The device information of the device to be detected is parsed from the eighth message.

19. A method for identifying a communication device, It is characterized in that The method comprises: Receive the network segment to which the IP address of the device to be detected belongs; Sending a first detection message to the network segment, wherein the port number, protocol type, and payload of the first detection message are the same as the port number, protocol type, and payload of the first message sent by the second device to the first device; Receiving a second message sent by the device to be detected; The device information of the device to be detected is parsed from the second message.

20. The communication device identification method according to claim 19, It is characterized in that The first detection message and the first message are both first protocol messages, and the device to be detected and the first device both support the first protocol.

21. The communication device identification method according to claim 19, It is characterized in that The first detection message is the first protocol message, the first message is the second protocol message, the device to be detected supports the first protocol, and the first device supports both the first protocol and the second protocol.

22. The communication device identification method according to claim 20 or 21, It is characterized in that The first protocol includes: ONVIF protocol, SIP, mDNS protocol, or a protocol defined by the manufacturers of the first device and the device to be detected.

23. The communication device identification method according to any one of claims 19 to 22, It is characterized in that The destination IP address of the first detection message is the destination IP address of the first message or each IP address included in the network segment; And / or the destination MAC address of the first detection message is the destination MAC address of the first message or the MAC address of the device to be detected.

24. The communication device identification method according to any one of claims 19 to 23, It is characterized in that The method further comprises: Sending the second detection message to the network segment, the port number, protocol type and payload of the second detection message being the same as the port number, protocol type and payload of the third message sent by the second device to the first device; Receiving a fourth message sent by the device to be detected; The device information of the device to be detected is parsed from the fourth message.

25. The method for identifying a communication device according to any one of claims 19 to 24, It is characterized in that The method further comprises: Sending the third detection message to the network segment, the port number, protocol type and payload of the third detection message being the same as the port number, protocol type and payload of the fifth message sent by the third device to the fourth device; Receiving a sixth message sent by the device to be detected; The device information of the device to be detected is parsed from the sixth message.

26. A method for sending a message, It is characterized in that The method comprises: Receive a first detection message sent by a third device, where the port number, protocol type, and payload of the first detection message are the same as the port number, protocol type, and payload of the first message sent by the second device to the first device; A first message is sent to the third device, where the first message includes device information of the device to be detected.

27. A communication device, It is characterized in that include: Communications interface and processor; The communication interface and the processor perform the method of any one of claims 1 to 18.

28. A communication device, It is characterized in that include: Communications interface and processor; The communication interface and the processor perform the method of any one of claims 19 to 25.

29. A communication device, It is characterized in that include: Communications interface and processor; The communication interface and the processor perform the method of claim 26.

30. A communication device, It is characterized in that include: A transceiver unit, configured to perform the transceiver operation in the method according to any one of claims 1 to 18; A processing unit, used to perform operations other than the sending and receiving operations in the method described in any one of claims 1 to 18.

31. A communication device, It is characterized in that include: A transceiver unit, configured to perform the transceiver operation in the method according to any one of claims 19 to 25; A processing unit, used to perform operations other than the sending and receiving operations in the method described in any one of claims 19 to 25.

32. A communication device, It is characterized in that include: A transceiver unit, used to perform the transceiver operation in the method of claim 26. A processing unit, configured to execute operations other than the sending and receiving operations in the method of claim 26.

33. A computer program product comprising instructions, It is characterized in that When a computer runs the computer program product, the computer is caused to perform the method according to any one of claims 1 to 26.

34. A communication system, It is characterized in that The system comprises the communication device of claim 27 or 30, the communication device of claim 28 or 31 and the communication device of claim 29 or 32.

Citation Information

Cited By

  • Identification method for communication apparatus and related apparatus

    EP4800998A1

  • Identification method for communication apparatus and related apparatus

    WO2025107947A1