Equipment fingerprint generation method and device, electronic equipment and storage medium

Through multi-data sources, the device feature data is collected and weighted, combined with dimensionality reduction and hashing operations, the defects of existing equipment fingerprint technology in terms of uniqueness, stability and generation efficiency are solved, and higher accuracy, stability and anti-interference capabilities are achieved.

CN120105397APending Publication Date: 2025-06-06刘杰
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510023396.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Existing equipment fingerprint technology has defects in uniqueness, stability and generation efficiency, especially when multiple devices share the same hardware configuration, the problem of innate features is more prominent, and the reliability of hardware features is reduced when they are tampered with or counterfeit.

Method used

By acquiring the initial device feature data of the target device collected from at least two data sources, performing stable consistency analysis, determining the effective device feature data, and weighting and integrating the effective device feature data through predefined allocation weights to generate a multi-dimensional device fingerprint feature vector. Then, through dimensionality reduction processing and hashing operations, the device fingerprint identification is generated.

Benefits of technology

It improves the accuracy, stability and anti-interference ability of the device fingerprint, reduces the computational complexity, improves the efficiency of the device fingerprint generation, and makes it more practical in complex application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105397A_ABST
    Figure CN120105397A_ABST
Patent Text Reader

Abstract

The invention provides an equipment fingerprint generation method and device, electronic equipment and a storage medium, and relates to the technical field of network equipment security. The method comprises the following steps: acquiring initial equipment feature data of target equipment acquired from at least two data sources; performing stability consistency analysis on the initial equipment feature data, and determining effective equipment feature data; performing weighted integration on the effective equipment feature data through a predetermined distribution weight to obtain a multi-dimensional equipment fingerprint feature vector; and according to the multi-dimensional device fingerprint feature vector, determining a dimension-reduced device fingerprint feature vector, and performing hash operation on the dimension-reduced device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device. According to the technical scheme, the accuracy, the stability and the anti-interference capability of the device fingerprint can be effectively improved, the calculation complexity of the device fingerprint is reduced, the generation efficiency of the device fingerprint is improved, and the practicability of the device fingerprint in various complex application scenes is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] As a method of generating a unique identifier based on device features, device fingerprint technology has important application value in the fields of device authentication, network security, and device behavior analysis. Related technologies usually generate device fingerprints by collecting hardware features or communication features of the target device, such as the device's chip serial number, the device's media access control address (MAC), network latency and other static attributes. These methods can meet the initial identification needs of devices in specific application scenarios, but their applicability and robustness have certain limitations.

[0003] In related technologies, the generation of device fingerprints usually relies on a single type of feature data. For example, the method of generating device fingerprints through hardware features is mainly based on fixed attributes of the device, such as the chip serial number or the MAC address of the network interface. However, this type of static feature may not be unique when multiple devices use the same hardware configuration; in addition, when the hardware features are tampered with or counterfeited, their reliability will be significantly reduced; similarly, the method of generating device fingerprints through communication features usually uses information such as the device's network delay, data packet size or transmission rate. However, since communication features are easily affected by dynamic changes in the network environment or attack behaviors, their stability and consistency are poor.

[0004] Secondly, in the relevant device fingerprint technology, the initially collected feature data often contains redundant or invalid features, and the generated device fingerprint may be unstable or non-unique, and a single feature source cannot fully express the diverse properties of the device, resulting in insufficient accuracy and anti-interference ability of the device fingerprint; and when processing feature vectors, the relevant technology has not effectively solved the problem of dimensional redundancy, resulting in a high computational complexity of the fingerprint generation process, which limits the scope of application of the device fingerprint.

[0005] Therefore, the method of generating device fingerprints through hardware features or communication features in the related art has certain defects in uniqueness, stability and generation efficiency.

[0006] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0007] The purpose of the embodiments of the present disclosure is to provide a device fingerprint generation method, a device fingerprint generation device, an electronic device, and a computer-readable storage medium, so as to improve the accuracy, stability, and anti-interference ability of the device fingerprint, reduce the calculation complexity of the device fingerprint, improve the generation efficiency of the device fingerprint, and ensure the practicality of the device fingerprint in various complex application scenarios.

[0008] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0009] According to a first aspect of an embodiment of the present disclosure, a method for generating a device fingerprint is provided, including:

[0010] Acquire initial device characteristic data of a target device collected from at least two data sources;

[0011] Performing stability and consistency analysis on the initial device characteristic data to determine effective device characteristic data;

[0012] Performing weighted integration on the valid device feature data by using a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector;

[0013] A reduced-dimensional device fingerprint feature vector is determined according to the multi-dimensional device fingerprint feature vector, and a hash operation is performed on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device.

[0014] According to a second aspect of an embodiment of the present disclosure, there is provided a device fingerprint generating apparatus, including:

[0015] A feature data acquisition module, used to acquire initial device feature data of a target device collected from at least two data sources;

[0016] An effective feature screening module, used to perform stability and consistency analysis on the initial device feature data to determine effective device feature data;

[0017] A feature vector fusion module, used to perform weighted integration on the valid device feature data through a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector;

[0018] The device fingerprint generation module is used to determine a reduced-dimensional device fingerprint feature vector based on the multi-dimensional device fingerprint feature vector, and perform a hash operation on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identification corresponding to the target device.

[0019] According to a third aspect of an embodiment of the present disclosure, there is provided an electronic device, comprising: a processor; and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the device fingerprint generation method in the first aspect is implemented.

[0020] According to a fourth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the device fingerprint generation method in the first aspect is implemented.

[0021] The technical solution provided by the embodiments of the present disclosure may have the following beneficial effects:

[0022] The device fingerprint generation method in the example embodiment of the present disclosure can avoid the problem of incomplete device features that may be caused by single device feature data by acquiring initial device feature data collected from multiple data sources, and introduce feature information of more dimensions on the basis of hardware features or communication features, so that the device fingerprint of the target device has richer feature expression capabilities, thereby reducing the possibility of non-unique device features; in addition, by introducing multi-source feature data in the initial stage, the description capability of fingerprint identification for diversified device attributes can be effectively improved, thereby enhancing the applicability to different device scenarios; by performing stability and consistency analysis on the initial device feature data, dynamic abnormal features caused by environmental changes, network fluctuations or human interference can be eliminated in the feature data, thereby improving the stability and consistency of the generated fingerprint identification, and by screening and consistency verification of the feature data, the reliability of the selected device feature data can be ensured. , so that the generated device fingerprint identification can be consistent in complex scenarios; by weighted integration of effective device feature data, it can fully reflect the weight distribution of each feature, so that the key features can play a more significant role in the fingerprint generation process, and can effectively avoid the limitations of a single feature source on device fingerprint generation in related technologies, so that the fingerprint identification has a higher uniqueness in multi-source feature fusion, and at the same time, it can also effectively reduce the interference of invalid device features on device fingerprint generation, and effectively improve the anti-interference ability of device fingerprint identification; by dimensionality reduction processing of multi-dimensional device fingerprint feature vectors, the influence of redundant dimensions on fingerprint generation efficiency can be reduced, the computational complexity can be significantly reduced, and the speed and storage efficiency of fingerprint generation can be improved. At the same time, the feature vector after dimensionality reduction can still retain the information integrity of the key feature dimension, so that the generated device fingerprint identification can maintain an accurate description of the device characteristics while being highly efficient.

[0023] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0025] Figure 1 A schematic diagram of a system architecture of an exemplary application environment in which a device fingerprint generation method and apparatus according to an embodiment of the present disclosure can be applied is shown.

[0026] Figure 2 The following is a schematic diagram showing a flow chart of a method for generating a device fingerprint according to some embodiments of the present disclosure.

[0027] Figure 3 The following schematically shows a flow chart of determining effective device characteristic data according to some embodiments of the present disclosure.

[0028] Figure 4 A schematic diagram of a process of performing stability analysis on initial device characteristic data according to some embodiments of the present disclosure is schematically shown.

[0029] Figure 5 A schematic diagram of a process of performing consistency analysis on dynamic device features according to some embodiments of the present disclosure is schematically shown.

[0030] Figure 6 The flowchart of generating a dimension-reduced device fingerprint feature vector according to some embodiments of the present disclosure is schematically shown.

[0031] Figure 7 A schematic diagram of a device fingerprint generating apparatus according to some embodiments of the present disclosure is schematically shown.

[0032] Figure 8 A schematic diagram of the structure of a computer system of an electronic device according to some embodiments of the present disclosure is schematically shown.

[0033] Fig. 9 A schematic diagram of a computer-readable storage medium according to some embodiments of the present disclosure is schematically shown.

[0034] In the drawings, the same or corresponding reference numerals represent the same or corresponding parts. DETAILED DESCRIPTION

[0035] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this specification. Instead, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0036] Furthermore, the drawings are only schematic illustrations and are not necessarily drawn to scale. The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically separate entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0037] Figure 1 A schematic diagram of a system architecture of an exemplary application environment in which a device fingerprint generation method and apparatus according to an embodiment of the present disclosure can be applied is shown.

[0038] like Figure 1 As shown, the system architecture 100 may include one or more of terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc. The terminal devices 101, 102, 103 may be various types of electronic devices, including but not limited to desktop computers, portable computers, smart phones, tablet computers, etc. It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. According to the implementation requirements, there may be any number of terminal devices, networks and servers. For example, the server 105 may be a server cluster composed of multiple servers.

[0039] The device fingerprint generation method provided in the embodiment of the present disclosure is generally executed by the terminal devices 101, 102, and 103, and accordingly, the device fingerprint generation device is generally set in the terminal devices 101, 102, and 103. However, it is easy for those skilled in the art to understand that the device fingerprint generation method provided in the embodiment of the present disclosure can also be executed by the server 105, and accordingly, the device fingerprint generation device can also be set in the server 105, which is not particularly limited in this exemplary embodiment.

[0040] In this example embodiment, a device fingerprint generation method is first provided. The device fingerprint generation method can be applied to a terminal device or a server. This example embodiment does not specifically limit this. The following description will take the server executing the method as an example. Figure 2 The following schematically shows a flow chart of a method for generating a device fingerprint according to some embodiments of the present disclosure. Figure 2 As shown, the device fingerprint generation method may include the following steps:

[0041] Step S210, obtaining initial device characteristic data of a target device collected from at least two data sources;

[0042] Step S220, performing stability consistency analysis on the initial device characteristic data to determine valid device characteristic data;

[0043] Step S230, weighted integration of the valid device feature data is performed using a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector;

[0044] Step S240: determining a reduced-dimensional device fingerprint feature vector according to the multi-dimensional device fingerprint feature vector, and performing a hash operation on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device.

[0045] Next, the device fingerprint generation method in this example embodiment will be further described.

[0046] In step S210, initial device characteristic data of a target device collected from at least two data sources is acquired.

[0047] In an example embodiment of the present disclosure, initial device feature data refers to feature data that can uniquely identify a target device and can be collected by a specific interface, sensor, protocol or tool during the operation of the target device. For example, the initial device feature data can be hardware features, operating system features, browser features, user behavior features and network communication features. Of course, it can also be a data set of the above device features, and this example embodiment is not limited to this. The data source can include but is not limited to the physical properties of the target device, the system operating environment, the user interaction behavior and the network communication mode. The process of obtaining the initial device feature data can be combined with the functional characteristics and collection conditions of the target device to ensure the comprehensiveness and accuracy of the initial device feature data.

[0048] Hardware features can be obtained through the system interface and hardware status monitoring tools of the target device. For example, the chip serial number can be read through the motherboard information interface, the clock offset data can be calculated by calling the system clock synchronization protocol, such as the Network Time Protocol (NTP), the device address (such as the MAC address) can be queried through the network interface configuration of the operating system, and the central processing unit characteristics can be parsed through the system hardware information library such as the Linux lscpu command or the Windows WMI (Windows Management Instrumentation) interface. The collection of hardware features can be further combined with the diagnostic tools or remote management protocols provided by the device, for example, remote collection can be achieved using IPMI (Intelligent Platform Management Interface). This embodiment does not specifically limit the specific types of hardware features.

[0049] The operating system characteristics can be obtained by querying the system configuration files and logs of the target device. For example, the operating system version information can be extracted through the system property files (such as Linux's / etc / os-release or Windows' registry), the language settings and time zone information can be queried through the system's regional configuration interface, and the user authority level can be obtained through the system user management module. In addition, the system call log and file system configuration information can be captured by a monitoring tool (such as the monitoring tool can be AuditD or Syslog) to further analyze the operating status and configuration characteristics of the target device. This embodiment does not limit the tools and methods for obtaining operating system characteristics.

[0050] Browser features can be extracted in real time through browser developer tools and plug-in interfaces. For example, screen resolution and browser version can be directly obtained through system interfaces, such as through JavaScript API, the list of installed plug-ins and language settings can be parsed through browser configuration files, and user agent information can be obtained through HTTP request headers; the browser running status can be monitored in real time through the browser's own developer mode interface, for example, relevant information can be obtained using window.navigator or chrome.runtime tools. This embodiment does not specifically limit the method for extracting browser features.

[0051] User behavior characteristics can be collected through the event listener and sensor interface of the target device. For example, touch trajectory data can be obtained through the touch screen driver of the device, mouse operation trajectory and keyboard input characteristics can be recorded through event listeners (such as JavaScript's mousemove, keydown), device operation behaviors (such as tilt angle, rotation speed and other operation behaviors) can be collected through the inertial measurement unit (IMU) module of the device, and interaction mode characteristics can be recorded by analyzing the user's operation path and usage frequency. This embodiment does not specifically limit the sensor type and collection method of user behavior characteristics.

[0052] Network communication characteristics can be collected through traffic monitoring tools and protocol analysis tools. For example, data packet size, transmission rate and network delay can be analyzed through network packet capture tools (such as Wireshark), channel occupancy can be obtained through wireless network analysis tools (such as Aircrack-ng), and abnormal behavior characteristics can be captured through intrusion detection systems (IDS, such as Snort or Suricata). This embodiment does not limit the specific method of collecting network communication characteristics.

[0053] The process of collecting initial device characteristic data through at least two data sources mentioned above can effectively ensure the comprehensiveness and diversity of the initial device characteristic data. The collected initial device characteristic data provides a complete data basis for subsequent stability and consistency analysis.

[0054] In step S220, a stability consistency analysis is performed on the initial device characteristic data to determine valid device characteristic data.

[0055] In an example embodiment of the present disclosure, stability and consistency analysis refers to a comprehensive stability and consistency verification of the initial device feature data, and ensures the reliability of the selected device features by eliminating abnormal or overly volatile data. Valid device feature data refers to a screened set of device feature data with high stability and consistency, which can accurately reflect the characteristics of the target device and avoid recognition errors caused by data fluctuations or interference.

[0056] Stability analysis refers to the separate processing of static device features and dynamic device features contained in the initial device feature data to eliminate invalid or highly volatile data in the initial feature data. For example, stability analysis of hardware features can be achieved through multiple sampling. Features such as chip serial number and device address should remain consistent in different sampling cycles. Clock offset needs to be determined by calculating the deviation of multiple sampling values. If the deviation exceeds the preset threshold, it is considered an unstable feature and eliminated. For stability analysis of operating system features, abnormal values ​​that do not meet the preset value range can be eliminated through value range detection. For example, the language setting should be in the list of languages ​​supported by the target area, and values ​​outside the range will be marked as abnormal. Similarly, stability analysis of browser features needs to verify its consistency with operating system features, such as whether the browser language setting matches the system language setting and whether there are unauthorized changes in the plug-in list.

[0057] Consistency analysis refers to the time series and logical association analysis of dynamic device features to ensure that these features can show reasonable consistency in multiple acquisitions. For example, cross-time window analysis of touch tracks and mouse tracks of user behavior features can eliminate abnormal behavior data that does not conform to the normal operation mode by calculating the trajectory change rate, curvature and position distribution in each time window; for keyboard input features, the distribution pattern of key interval time can be statistically analyzed to eliminate abnormal data generated by automated scripts or counterfeit devices; for consistency analysis of network communication features, the time correlation of communication behavior can be verified through traffic statistics and protocol analysis, for example, segmented statistics of packet transmission rate and network delay can be performed to eliminate abnormal data that does not conform to the normal distribution.

[0058] Consistency analysis can also be combined with a preset threat behavior model to further verify dynamic device features. For example, it can detect potential forged behavior features (such as trajectories with high repetition or low volatility) to eliminate abnormal data that may be introduced by counterfeit devices or attack behaviors. The application of threat behavior models can ensure the authenticity of dynamic feature data and further improve the quality of effective device feature data.

[0059] In step S230, the valid device feature data is weighted and integrated by using a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector.

[0060] In an example embodiment of the present disclosure, weighted integration refers to assigning weights to each feature component in the effective device feature data according to its importance, and generating a multi-dimensional device fingerprint feature vector by weighted fusion. This process can effectively ensure that the device feature vector can fully reflect the key characteristics of the target device, while avoiding interference or influence of irrelevant device features on the generation of device fingerprints.

[0061] Each feature component in the effective device feature data can be standardized first to eliminate the dimensional differences between the feature components. For example, for device feature data such as the chip serial number of hardware features, the time zone and language settings of operating system features, the resolution of browser features, the touch trajectory change rate of user behavior features, and the data packet size of network communication features, normalization processing is uniformly adopted so that the feature values ​​can be adjusted to the same numerical range. For example, the standardization method can adopt Min-Max Normalization or Z-score normalization to adapt to the distribution characteristics of different device feature components.

[0062] Based on the standardized device feature components, each feature component can be weighted and fused according to the predetermined allocation weight. The weight allocation can be set based on the contribution of the feature component to the uniqueness of the device. For example, hardware features are usually given higher weights due to their higher staticness and uniqueness, while network communication features may be assigned lower weights due to their larger dynamic changes. The allocation weights can be determined through statistical analysis (such as feature importance scoring) or expert experience, and the allocation strategy of the allocation weights can be dynamically adjusted in specific scenarios. This embodiment does not make any special restrictions on this.

[0063] By performing weighted calculation on the standardized valid device feature data, the weighted results of each feature component are mapped to the multi-dimensional feature component. This weighted process can ensure the prominent expression of important feature components in the device feature vector while suppressing the influence of minor features. It can be understood that the implementation of weighted integration is not limited to linear weighting. Nonlinear weighting, principal component weight allocation and other methods can be used in combination with scenario requirements to further optimize feature expression capabilities. The multi-dimensional device fingerprint feature vector after weighted integration covers the multi-source characteristics of the target device, has high resolution and high expressiveness, and lays the foundation for subsequent dimensionality reduction optimization.

[0064] In step S240, a reduced-dimensional device fingerprint feature vector is determined according to the multi-dimensional device fingerprint feature vector, and a hash operation is performed on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device.

[0065] In an example embodiment of the present disclosure, a reduced-dimensional device fingerprint feature vector refers to an efficient expression form obtained by optimizing and compressing a multi-dimensional device fingerprint feature vector, which retains feature dimensions that significantly contribute to the target device identification while eliminating redundant or low-contribution feature dimensions to reduce computational complexity and improve the efficiency of device fingerprint identification generation.

[0066] Before reducing the dimensionality of a multi-dimensional device fingerprint feature vector, it can be preprocessed. For example, the preprocessing can include mean zeroing and variance normalization. Mean zeroing can eliminate the offset effect of feature values ​​by adjusting the mean of each feature dimension to zero; variance normalization can avoid uneven feature weights caused by differences in feature distribution ranges by standardizing the variance of each feature dimension to a uniform scale.

[0067] The dimensionality reduction process of the multi-dimensional device fingerprint feature vector can be implemented based on principal component analysis (PCA). For example, the covariance matrix of the standard device fingerprint feature vector can be calculated first, and the contribution value of each feature dimension can be determined by analyzing the eigenvalues ​​and eigenvectors of the covariance matrix. The contribution value can reflect the importance of the feature dimension to the overall feature expression; then, the key feature dimensions can be screened out based on the comparison between the feature contribution value and the preset contribution value threshold. The key feature dimensions refer to the set of feature dimensions whose cumulative contribution values ​​reach a preset proportion (such as 95%).

[0068] The reduced-dimensional device fingerprint feature vector is generated by projecting the multi-dimensional device fingerprint feature vector onto the principal component space corresponding to the selected key feature dimension. The projection process can be completed through matrix operations. After the reduced-dimensional device fingerprint feature vector is generated, a unique identifier generation operation can be performed on it through a hash algorithm. For example, the hash algorithm can select an algorithm with high encryption strength such as SHA-256 to ensure that the generated device fingerprint identification has a fixed length, irreversibility and anti-collision. The hash operation process can convert the reduced-dimensional device fingerprint feature vector into a unique identifier to avoid recognition errors caused by data changes during transmission or storage of the feature value. The generation and hash operation of the reduced-dimensional device fingerprint feature vector can not only reduce the redundancy of the feature dimension, but also improve the efficiency and security of the device fingerprint generation process, so that the device fingerprint identification finally generated can provide efficient device authentication and identification functions in a variety of complex scenarios.

[0069] The contents of step S210 to step S240 are described in detail below.

[0070] In an example embodiment of the present disclosure, the initial device feature data may include static device features and dynamic device features. Among them, static device features refer to feature data that are inherent to the target device and do not change with time and operating environment. For example, static device features can be hardware features, operating system features, or browser features. This example embodiment does not specifically limit the feature data type of static device features. Dynamic device features refer to feature data related to the operating status and user behavior of the target device, and their characteristics may change with time or environment. For example, dynamic device features can be user behavior features or network communication features. This example embodiment does not specifically limit the feature data type of dynamic device features.

[0071] Specifically, you can Figure 3 The steps in the above are used to analyze the stability and consistency of the initial device characteristic data and determine the effective device characteristic data. Figure 3 As shown, it may specifically include:

[0072] Step S310, performing stability analysis on the static device characteristics and the dynamic device characteristics to obtain stable device characteristics;

[0073] Step S320: performing consistency analysis on the dynamic device features in the stable device features based on a preset threat behavior model to obtain valid device feature data.

[0074] Among them, stability analysis refers to evaluating the consistency and fluctuation range of the device characteristics of the target device in multiple acquisitions or time series to ensure the reliability of the feature data. The principle of stability analysis is that excessive volatility of the characteristics will reduce the accuracy of device fingerprint generation. Stability analysis aims to screen out feature data with consistency and a reasonable fluctuation range. Specific implementations may include multiple sampling deviation analysis of hardware features, value range detection of operating system features, consistency verification of browser features, time window analysis of user behavior features, and outlier detection of network communication features. In some optional implementations, the accuracy of multiple samplings can be optimized by adjusting the sampling frequency, or the volatility and stability of features can be automatically evaluated in combination with machine learning models.

[0075] Stable device features refer to feature sets screened out after stability analysis. These feature sets show high consistency in multiple sampling or time series analysis, and conform to the feature distribution range of the target device. The process of constructing stable device features can include eliminating feature data whose fluctuation values ​​exceed the threshold in static device features. For example, erroneous codes in chip serial number sampling or values ​​in the operating system language settings that do not conform to the target environment configuration can be eliminated; dynamic device features can eliminate unstable behavior data through time window analysis. For example, coordinate points with abnormal jumps in touch trajectories or uniform key intervals generated by the simulator in keyboard input can be eliminated. The formation process of stable device features can also be combined with specific scenario requirements. For example, the stability threshold can be dynamically adjusted according to the device's usage environment. This embodiment does not specifically limit the specific method for constructing stable device features.

[0076] A threat behavior model refers to a detection model designed based on established attack behavior characteristics or forged feature patterns, which is used to identify abnormal behaviors in dynamic device features. The principle of the threat behavior model is that attack behaviors usually exhibit fixed patterns or characteristics that are inconsistent with normal behavior characteristics, and potential abnormal data is eliminated by analyzing the degree of match between feature data and threat patterns. The threat behavior model can adopt a rule-based static model, for example, it can detect repeated operation tracks or forged traffic by setting a specific device feature range; it can also adopt a dynamic model based on machine learning, which can generate a classifier through a training data set to identify forged behavior, and can also build an independent malicious behavior database to match potential forged features, or dynamically adjust detection rules in combination with real-time data analysis.

[0077] Consistency analysis refers to an in-depth analysis of dynamic device features through time series segmentation and logical association verification, aiming to evaluate the time correlation and logical consistency of feature data. Time series segmentation can divide feature data into multiple segments according to a fixed time window, so as to analyze the changing trend and consistency of features segment by segment. Logical association verification refers to cross-verification of dynamic device features with static device features. For example, it can check whether the browser operation in the user behavior feature matches the configuration of the operating system, or whether the data packet distribution in the network communication feature meets the bandwidth limit of the hardware feature. The implementation of consistency analysis can be combined with dynamic rule matching or real-time monitoring algorithms to ensure the logical rationality of feature data.

[0078] Optionally, static device features may include hardware features, operating system features, and browser features, and dynamic device features may include user behavior features and network communication features; Figure 4 The steps in the above are used to analyze the stability of the static device characteristics and the dynamic device characteristics, and obtain the stable device characteristics. Figure 4As shown, it may specifically include: step S410, sampling the hardware features for multiple times, calculating the deviation value of each sampling result, and screening the hardware features in combination with a preset deviation threshold and the deviation value to obtain stable hardware features; step S420, performing a value range detection on the operating system features to eliminate feature data that does not belong to the preset value range to obtain stable operating system features; step S430, performing consistency verification on the browser features to eliminate feature data that changes frequently or contradicts the operating system features to obtain stable browser features; step S440, performing a cross-time window analysis on the user behavior features to eliminate feature data with stability lower than a preset statistical feature threshold through determined statistical features to obtain stable user behavior features; step S450, performing anomaly detection on the network communication features to eliminate feature data that does not conform to the mean and standard deviation of three times the standard deviation to obtain stable network communication features; step S460, constructing stable device features based on the stable hardware features, the stable operating system features, the stable browser features, the stable user behavior features and the stable network communication features.

[0079] In the process of multiple sampling of hardware features, relevant data can be obtained through the underlying interface or system log of the device. For example, the chip serial number can be directly read through the motherboard interface, the MAC address can be obtained through the system configuration of the network adapter, the clock offset can be calculated through the synchronization time protocol (such as NTP), and the CPU characteristics can be obtained through the system hardware detection tool (such as lscpu or WMI); after each sampling result is recorded, the stability of the device characteristics is evaluated by calculating the deviation value between each sampling and the mean. For example, the deviation value of each sampling result can be determined by the following expression:

[0080]

[0081] Among them, δ can represent the deviation value of each sampling result, x i It can represent the sampling value of the i-th sampling, It can represent the sampling mean, and n can represent the total number of sampling times. When the deviation value δ is less than the preset deviation threshold, it can be considered that the hardware features obtained by this sampling are stable, otherwise it is regarded as abnormal data and removed.

[0082] The selection of the preset deviation threshold can be dynamically adjusted in combination with the characteristics of the target device. For example, for high-precision devices, the deviation threshold can be set lower to meet higher stability requirements; for low-power devices or embedded systems, the threshold range can be appropriately relaxed to ensure data collection efficiency. In an optional implementation, multiple sampling results can be verified through hardware redundancy. For example, a multi-channel interface can be used to sample simultaneously and perform cross-validation, or the current features can be dynamically adjusted in combination with historical sampling data.

[0083] The principle of value range detection is to compare the collected operating system feature values ​​with the predefined legal value range, eliminate the feature data that exceeds the range, and ensure the accuracy and consistency of the operating system features. When implementing value range detection, you can first define the legal value range. For example, the legal value range of the operating system version can be the supported version list, the legal value range of the language setting can be the set of supported languages ​​in the region where the device is located, and the legal value range of the time zone information can be the time zone corresponding to the geographical location of the target device. The user permission level can be consistent with the security policy of the target device. For feature data that exceeds these ranges, it will be marked as abnormal and eliminated. The specific implementation can extract data through the configuration interface or system log tool that comes with the operating system. For example, the Linux system extracts version information through / etc / os-release and queries the language setting through locale. The Windows system can obtain relevant information through the registry or WMI interface.

[0084] Value range detection can also be combined with dynamic adjustment strategies. For example, the legal value range can be updated in real time according to changes in the network environment where the target device is located to adapt to changing application scenarios. In an optional implementation, the normal feature distribution of the target device can be automatically learned through a machine learning model, and a dynamic value range can be constructed based on this, or trend analysis can be performed in combination with historical data to predict the normal range of operating system characteristics.

[0085] The principle of consistency verification is to check the matching between browser features and operating system features to ensure that there is no logical contradiction between the two, and to eliminate abnormal data introduced by frequent modification or forgery operations in browser features. When verifying the consistency of browser features, you can obtain relevant configuration data of the browser. For example, you can use the browser developer tool to extract the resolution, version and language settings, obtain the list of installed plug-ins through the plug-in interface, and obtain the user agent information through the HTTP request header; then you can compare these data with the language settings, resolution range and operating environment of the operating system. For example, the browser language setting should be consistent with the operating system language, and the resolution should be within the support range of the target device; for the plug-in list, you can record the plug-in change frequency through multiple sampling, and mark it as abnormal if it changes frequently. Of course, you can also use the web crawler tool to obtain the public browser feature distribution model for comparing abnormal data, or adjust the consistency verification rules in real time through the dynamic rule engine to adapt to complex network environments and device behaviors.

[0086] The principle of cross-time window analysis is to segment user behavior data into multiple time windows, calculate statistical features and evaluate stability segment by segment, so as to eliminate unstable or abnormal behavior data. In the cross-time window analysis of touch trajectory, the change rate, direction change and curvature of the touch point in each time window can be calculated, and statistical features such as mean and standard deviation are used to measure the stability of the trajectory; in mouse operation analysis, the average distance of the mouse movement path in each window, click frequency, etc. can be recorded; in keyboard input analysis, the distribution pattern of key interval time can be used to evaluate the regularity and naturalness of input. Of course, it is also possible to dynamically adjust the time window size in combination with sliding window technology, or analyze the time series characteristics of user behavior through deep learning models such as Long Short-Term Memory (LSTM) to more accurately detect unstable data.

[0087] The principle of outlier detection is to evaluate the distribution characteristics of feature data through statistical methods and eliminate abnormal data that deviates from the normal range. When performing outlier detection on network communication features, network communication feature data can be collected, the mean and standard deviation can be calculated through statistical methods, and the normal range can be defined using the three-times standard deviation rule. Data outside the range will be marked as abnormal. For example, the normal range defined using the three-times standard deviation rule can be expressed by the following relationship:

[0088] μ-3σ≤x i ≤μ+3σ;

[0089] Among them, x ican represent the network communication characteristics of the ith sampling, μ can represent the mean of the network communication characteristics, and σ can represent the standard deviation of the network communication characteristics; if the network communication characteristics are within the normal range defined by the three-times standard deviation rule, they are determined to be normal data, and if the network communication characteristics exceed the normal range defined by the three-times standard deviation rule, they are determined to be abnormal data and eliminated. For example, the packet size can be within the range allowed by the target network protocol, and the transmission rate and network delay can conform to the normal mode of the network environment where the device is located; for channel occupancy, its rationality can be evaluated by monitoring the wireless signal strength and spectrum usage. Of course, the normal distribution of network communication characteristics can be predicted by time series anomaly detection models (such as ARIMA or Prophet), and outlier judgment can be made based on the predicted values, or combined with traffic analysis tools (such as Wireshark) to detect specific abnormal communication patterns.

[0090] By screening feature data according to the corresponding characteristics of hardware features, operating system features, browser features, user behavior characteristics and network communication characteristics, different stability analysis methods are used to build a stable device feature data set, effectively ensuring the stability, reliability and effectiveness of device feature data.

[0091] In an exemplary embodiment of the present disclosure, Figure 5 The steps in the above code are used to analyze the consistency of dynamic device features in stable device features based on the preset threat behavior model, and obtain valid device feature data. Figure 5 As shown, it may specifically include:

[0092] Step S510, segmenting the dynamic device features in the stable device features into time windows, determining the consistency coefficient of the dynamic device feature time series, and eliminating the dynamic device features in the stable device features whose consistency coefficient is less than a preset consistency threshold;

[0093] Step S520: input the screened stable device features into a preset threat behavior model to eliminate potential abnormal features in the stable device features to obtain valid device feature data.

[0094] Among them, dynamic device features refer to the feature data generated by the target device during use, which has the characteristics of dynamic change. For example, dynamic device features can include user behavior features and network communication features. The time correlation and consistency of these features are important indicators for verifying their stability and authenticity.

[0095] Time window segmentation refers to the process of dividing the time domain of dynamic device features so that the performance of dynamic device features in different time periods can be analyzed independently. In specific implementation, the length of the time window can be set according to the feature type of the dynamic device feature. For example, for touch trajectory and mouse operation features, millisecond-level time windows can be used to capture rapidly changing behavior data; for network communication features, second-level or multi-second-level time windows can be used to adapt to the characteristics of network transmission. After the time window is divided, statistical values ​​can be calculated for the dynamic device features in each window. For example, the change rate of the touch trajectory, the click frequency of the mouse operation, the key interval distribution of the keyboard input, and the data packet size and transmission rate of the network communication feature can be counted.

[0096] The calculation of the consistency coefficient is used to quantify the stability of dynamic device characteristics in time series. For example, the calculation of the consistency coefficient can be achieved through the following relationship:

[0097]

[0098] Among them, C can represent the consistency coefficient, It can represent the feature value of the i-th dynamic device feature in the t-th time window, and n can represent the number of dimensions of the dynamic device feature. It can represent the characteristic value of the ith dynamic device feature in the t+1th time window. When the consistency coefficient is less than the preset consistency threshold, it can be said that the dynamic device feature fluctuates greatly in the time series and is not stable, and should be removed from the stable device features. The preset consistency threshold can be dynamically adjusted according to specific application scenarios. For example, in scenarios with high security requirements, the consistency threshold can be set to a higher level to remove more potentially unstable features; in scenarios with high real-time requirements, the consistency threshold can be appropriately lowered to increase data utilization. Of course, it is also possible to model the time series of dynamic device features through machine learning algorithms. For example, the long short-term memory network (LSTM) or time series anomaly detection model can be used to automatically evaluate the time correlation of features, thereby replacing the calculation of the consistency coefficient. At the same time, in order to improve the adaptability of time window segmentation, the time window length can be dynamically adjusted in combination with the sliding window technology, so that it can more flexibly capture fast-changing or slowly changing dynamic features.

[0099] In specific implementation, the threat behavior model can adopt a rule-based approach. For example, a fixed threshold or pattern matching rule can be set to detect unnatural jumps in touch trajectories or repeated paths in mouse trajectories. It can also adopt a machine learning-based approach. For example, a support vector machine (SVM) or random forest model can be used to classify and detect abnormal key intervals in keyboard input features. For network communication features, the threat behavior model can identify forged data packet patterns or abnormal protocol field tampering behaviors through traffic analysis tools.

[0100] In practical applications, the input of the threat behavior model can be not only the dynamic device features after screening, but also the contextual information combined with the static device features, for example, verifying whether the packet size in the network communication features is consistent with the bandwidth limit of the target device, or checking whether the user behavior features are consistent with the use environment of the target device. Of course, the detection rules of the threat behavior model can also be updated in real time through online learning algorithms to adapt to new threat patterns, or combined with distributed threat detection systems to conduct collaborative detection of large-scale devices.

[0101] By calculating the time window segmentation and consistency coefficient, unstable data in dynamic device features can be effectively eliminated, and potential abnormal features can be further detected and eliminated through the threat behavior model, effectively improving the authenticity and consistency of the effective device feature data obtained, thereby ensuring the stability, uniqueness and accuracy of the subsequently generated device fingerprint identification.

[0102] In an exemplary embodiment of the present disclosure, the following steps may be combined to implement weighted integration of valid device feature data by using predetermined allocation weights to obtain a multi-dimensional device fingerprint feature vector, which may specifically include:

[0103] Each feature data in the effective device feature data can be standardized to obtain standardized effective device feature data, and each feature data component in the standardized effective device feature data can be weighted and fused according to a predetermined allocation weight to obtain a multi-dimensional feature component, and then a multi-dimensional device fingerprint feature vector can be constructed based on the multi-dimensional feature component.

[0104] Among them, standardization refers to adjusting the distribution of feature data to make it consistent in the numerical range, avoiding deviations in weight allocation or weighted fusion due to different value ranges of feature components. The core of standardization is to eliminate the dimensional differences of data to ensure that each feature can be fairly compared during weighted integration. For example, the method for implementing standardization can adopt minimum-maximum normalization, which can map the value range of feature data to a specified range such as [0,1]. This method is suitable for scenarios where the feature value range is known and there are no outliers; Z-score standardization can also be adopted. Z-score standardization can be adjusted to a normal distribution form with a mean of 0 and a standard deviation of 1 by calculating the standard distribution of feature values. Z-score standardization is suitable for scenarios where the feature value range is unknown or contains outliers. Of course, quantile normalization can also be used to adjust the distribution of feature data to reduce the impact of extreme values ​​on the results. This example embodiment does not specifically limit the method of standardization.

[0105] In actual implementation, the weight distribution can be determined through expert experience or data analysis methods. For example, the contribution of each feature component to the generation of device fingerprints can be evaluated through feature importance analysis (such as feature importance scoring in random forests), and weights can be assigned accordingly. In addition, the weights can be dynamically adjusted in combination with specific application scenarios. For example, in scenarios with higher security requirements, the weights of dynamic features can be increased to enhance anti-counterfeiting capabilities. For example, the weighted fusion process can be expressed as the following relationship:

[0106] V i =w 1 H i +w 2 O i +w 3 B i +w 4 U i +w 5 N i ;

[0107] Among them, V i It can represent the i-th multidimensional feature component of the multidimensional device fingerprint feature vector, H i , O i , B i , U i , N i The i-th feature data component, w, can represent hardware features, operating system features, browser features, user behavior features, and network communication features respectively. 1 , w 2 , w 3 , w 4 , w5 The distribution weights corresponding to each feature component can be represented respectively; weighted fusion can be achieved through matrix operations to improve computational efficiency.

[0108] A multi-dimensional device fingerprint feature vector refers to a feature expression generated by integrating multiple feature data, which can fully reflect the multi-source features of the target device. The process of constructing a multi-dimensional feature vector may include arranging the weighted fused multi-dimensional feature components into a vector structure with a fixed format.

[0109] By standardizing, weighting and fusing effective device feature data, and constructing multi-dimensional feature components, the dimension problem caused by differences in feature sources and the feature imbalance problem in the fusion process in the background technology are solved. Standardization eliminates the difference in the numerical range between different features and ensures the fairness of weighted fusion; the weighted fusion method dynamically allocates weights according to the importance of the features, effectively highlighting the contribution of key features while reducing the interference of secondary features; the construction of multi-dimensional feature components integrates multi-source feature data, giving the device fingerprint a higher feature expression capability and diversity.

[0110] In an exemplary embodiment of the present disclosure, Figure 6 The steps in the implementation of the multi-dimensional device fingerprint feature vector to determine the reduced-dimensional device fingerprint feature vector, refer to Figure 6 As shown, it may specifically include:

[0111] Step S610, performing mean zeroing and variance normalization processing on each feature dimension data in the multi-dimensional device fingerprint feature vector to obtain a standard device fingerprint feature vector;

[0112] Step S620, determining the covariance matrix corresponding to the standard device fingerprint feature vector, and determining the feature contribution value corresponding to each feature dimension of the standard device fingerprint feature vector according to the covariance matrix;

[0113] Step S630, determining a key feature dimension according to the feature contribution value and a preset contribution value threshold;

[0114] Step S640: Project the original feature vector corresponding to the key feature dimension into a predetermined principal component space to generate a reduced-dimensional device fingerprint feature vector.

[0115] The purpose of mean zeroing and variance normalization is to eliminate the numerical differences and distribution offsets between feature dimensions to ensure that each feature dimension has a balanced contribution in the subsequent dimensionality reduction process. The principle of mean zeroing is to adjust the data distribution center of each feature dimension to zero. For example, the mean zeroing process can be expressed by the following relationship:

[0116] x′=x-μ;

[0117] Among them, x′ can represent the eigenvalue of each feature dimension data in the standard device fingerprint feature vector after the mean is returned to zero, x can represent the original eigenvalue of each feature dimension data in the standard device fingerprint feature vector, and μ can represent the mean of the eigenvalues ​​of the feature dimension data in the standard device fingerprint feature vector.

[0118] The principle of variance normalization is to standardize the variance of data distribution to a uniform scale to eliminate the influence of different feature dimensions due to different distribution ranges. For example, the variance normalization process can be expressed by the following relationship:

[0119]

[0120] Wherein, x″ may represent the eigenvalue of each feature dimension data in the standard device fingerprint feature vector after the variance is normalized, and σ may represent the standard deviation of the eigenvalue of the feature dimension data in the standard device fingerprint feature vector.

[0121] The covariance matrix can be used to describe the linear correlation between feature dimension data, and its elements can represent the covariance between any two feature dimension data. For example, the covariance matrix can be represented by the following relationship:

[0122]

[0123] Among them, C ij It can represent the covariance between the i-th and j-th feature dimension data, and can represent the eigenvalues ​​of the i- and j-dimensional feature dimensions in the k-th sample respectively, and It can represent the feature mean, and n can represent the dimension of the standard device fingerprint feature vector.

[0124] The covariance matrix can be eigen-decomposed to calculate the feature contribution value of each feature dimension, which can represent the contribution of the feature dimension to the total variance of the data. The feature contribution value reflects the importance of the corresponding feature dimension to the overall data distribution, and can be sorted according to the size of the feature contribution value, and the feature dimension whose cumulative contribution value reaches a preset threshold (for example, the preset threshold can be 95% or 90%, and this embodiment is not limited thereto) is selected as the key feature dimension.

[0125] The principal component space refers to the orthogonal basis space obtained by eigendecomposition. After the data is projected into the principal component space, the dimension can be compressed while retaining the main information of the data. For example, the original eigenvector corresponding to the key feature dimension can be projected into the principal component space through the following relationship:

[0126] Z = X·W;

[0127] Among them, Z can represent the eigenvector after dimensionality reduction, X can represent the original eigenvector, and W can represent the eigenvector matrix corresponding to the key feature dimension; reducing the dimensionality of the eigenvector through matrix operations can significantly improve the computing efficiency and reduce the storage requirements.

[0128] In actual implementation, different dimensionality reduction methods can be used to replace principal component analysis (PCA). For example, factor analysis (FA) or linear discriminant analysis (LDA) can be used to reduce the dimensionality of multi-dimensional device fingerprint feature vectors to meet the needs of specific application scenarios. In addition, nonlinear dimensionality reduction methods (for example, nonlinear dimensionality reduction methods can be t-SNE or UMAP) can be combined to process nonlinearly distributed data features, which is not specifically limited in this example embodiment.

[0129] The offset and distribution difference of feature components are eliminated through mean zeroing and variance normalization. The key feature dimensions with large contribution values ​​are screened out through the analysis of the covariance matrix, and the original features are projected into the principal component space to generate the reduced-dimensional device fingerprint feature vector, which significantly reduces the redundancy and computational complexity of the feature dimensions. The mean zeroing and normalization of the features improve the balance and consistency of the data. The eigenvalue analysis of the covariance matrix and the screening of the cumulative contribution value avoid the influence of minor features on the fingerprint generation process. The dimensionality reduction operation retains the information of the main features and simplifies the data structure of the device fingerprint, making it have higher computational efficiency and storage applicability while maintaining its uniqueness.

[0130] It should be noted that, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.

[0131] In addition, in this exemplary embodiment, a device fingerprint generation apparatus is also provided. Figure 7 As shown, the device fingerprint generation apparatus 700 includes: a feature data acquisition module 710, an effective feature screening module 720, a feature vector fusion module 730 and a device fingerprint generation module 740. Among them:

[0132] The feature data acquisition module 710 is used to acquire initial device feature data of the target device collected from at least two data sources;

[0133] The effective feature screening module 720 is used to perform stability and consistency analysis on the initial device feature data to determine effective device feature data;

[0134] A feature vector fusion module 730 is used to perform weighted integration on the valid device feature data by using a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector;

[0135] The device fingerprint generating module 740 is used to determine a reduced-dimensional device fingerprint feature vector according to the multi-dimensional device fingerprint feature vector, and perform a hash operation on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device.

[0136] In some example embodiments of the present disclosure, based on the aforementioned scheme, the initial device feature data includes static device features and dynamic device features; the effective feature screening module 720 is configured as: a stability analysis unit, used to perform stability analysis on the static device features and the dynamic device features to obtain stable device features; a consistency analysis unit, used to perform consistency analysis on the dynamic device features in the stable device features based on a preset threat behavior model to obtain effective device feature data.

[0137] In some example embodiments of the present disclosure, based on the aforementioned scheme, the static device features include hardware features, operating system features and browser features, and the dynamic device features include user behavior features and network communication features; the stability analysis unit is configured to: perform multiple sampling on the hardware features, calculate the deviation value of each sampling result, and screen the hardware features in combination with a preset deviation threshold and the deviation value to obtain stable hardware features; perform value range detection on the operating system features to eliminate feature data that does not belong to the preset value range to obtain stable operating system features; perform consistency verification on the browser features to eliminate feature data that changes frequently or contradicts the operating system features to obtain stable browser features; perform cross-time window analysis on the user behavior features to eliminate feature data with stability lower than a preset statistical feature threshold through determined statistical features to obtain stable user behavior features; perform outlier detection on the network communication features to eliminate feature data that does not conform to three times the standard deviation of the mean and standard deviation to obtain stable network communication features; and construct stable device features based on the stable hardware features, the stable operating system features, the stable browser features, the stable user behavior features and the stable network communication features.

[0138] In some example embodiments of the present disclosure, based on the aforementioned scheme, the consistency analysis unit is configured to: perform time window segmentation on the dynamic device features in the stable device features, determine the consistency coefficient of the dynamic device feature time series, and eliminate the dynamic device features in the stable device features whose consistency coefficient is less than a preset consistency threshold; input the screened stable device features into a preset threat behavior model to eliminate potential abnormal features in the stable device features to obtain valid device feature data.

[0139] In some example embodiments of the present disclosure, based on the aforementioned scheme, the feature vector fusion module 730 is configured to: perform standardization processing on each feature data in the effective device feature data to obtain standardized effective device feature data; perform weighted fusion on each feature data component in the standardized effective device feature data according to a predetermined allocation weight to obtain a multi-dimensional feature component; and construct the multi-dimensional device fingerprint feature vector based on the multi-dimensional feature component.

[0140] In some example embodiments of the present disclosure, based on the aforementioned scheme, the device fingerprint generation module 740 is configured to: perform mean zeroing and variance normalization processing on each feature dimension data in the multi-dimensional device fingerprint feature vector to obtain a standard device fingerprint feature vector; determine the covariance matrix corresponding to the standard device fingerprint feature vector, and determine the feature contribution value corresponding to each feature dimension of the standard device fingerprint feature vector according to the covariance matrix; determine the key feature dimension according to the feature contribution value and a preset contribution value threshold; project the original feature vector corresponding to the key feature dimension to a predetermined principal component space to generate a reduced-dimensional device fingerprint feature vector.

[0141] In some example embodiments of the present disclosure, based on the aforementioned scheme, the feature data acquisition module 710 is configured to: capture the device chip serial number, clock offset, device address and central processing unit characteristics of the target device through the system interface and hardware status monitoring tool as the hardware characteristics of the target device; collect the operating system version information, language setting, time zone and user authority level of the target device, and obtain the system call log and file system configuration information to identify the operating environment of the target device as the operating system characteristics of the target device; extract the screen resolution, browser version, installed plug-in list, language setting and user agent information of the preset browser of the target device, and use the browser developer tool to monitor the running status of the browser in real time as the browser characteristics of the target device; collect the touch track, mouse operation track, keyboard input characteristics, device operation behavior and interaction mode generated in the process of using the target device through the system interface and event listener as the user behavior characteristics of the target device; collect the data packet size, transmission rate, network delay and channel occupancy of the target device during the communication process based on the network traffic monitoring tool, and capture the abnormal behavior characteristics of the target device in the network interaction as the network communication characteristics of the target device.

[0142] The specific details of each module of the above-mentioned device fingerprint generation apparatus have been described in detail in the corresponding device fingerprint generation method, so they will not be repeated here.

[0143] It should be noted that although several modules or units of the device fingerprint generation apparatus are mentioned in the above detailed description, such division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units for embodiment.

[0144] In addition, in an exemplary embodiment of the present disclosure, an electronic device capable of implementing the above-mentioned device fingerprint generation method is also provided.

[0145] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware embodiments, complete software embodiments (including firmware, microcode, etc.), or embodiments combining hardware and software aspects, which may be collectively referred to herein as "circuits", "modules" or "systems".

[0146] Refer to the following Figure 8 800 according to this embodiment of the present disclosure is described. Figure 8The electronic device 800 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0147] like Figure 8 As shown, the electronic device 800 is in the form of a general computing device. The components of the electronic device 800 may include, but are not limited to: the at least one processing unit 810, the at least one storage unit 820, a bus 830 connecting different system components (including the storage unit 820 and the processing unit 810), and a display unit 840.

[0148] The storage unit stores a program code, which can be executed by the processing unit 810, so that the processing unit 810 performs the steps according to various exemplary embodiments of the present disclosure described in the above “Exemplary Method” section of this specification. For example, the processing unit 810 can perform the following steps: Figure 2 Follow the steps shown in .

[0149] The storage unit 820 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 821 and / or a cache memory unit 822 , and may further include a read-only memory unit (ROM) 823 .

[0150] The storage unit 820 may also include a program / utility 824 having a set (at least one) of program modules 825, such program modules 825 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0151] Bus 830 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0152] The electronic device 800 may also communicate with one or more external devices 870 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 800, and / or communicate with any device that enables the electronic device 800 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 850. Furthermore, the electronic device 800 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 860. As shown, the network adapter 860 communicates with other modules of the electronic device 800 via a bus 830. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0153] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the embodiment of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiment of the present disclosure.

[0154] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the above method of the present specification is stored. In some possible embodiments, various aspects of the present disclosure may also be implemented in the form of a program product, which includes a program code, and when the program product is run on a terminal device, the program code is used to enable the terminal device to perform the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of the present specification.

[0155] refer to Fig. 9 As shown, a program product 900 for implementing the above-mentioned device fingerprint generation method according to an embodiment of the present disclosure is described, which can adopt a portable compact disk read-only memory (CD-ROM) and include program code, and can be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, a readable storage medium can be any tangible medium containing or storing a program, which can be used by or in combination with an instruction execution system, an apparatus or a device.

[0156] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0157] Program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0158] In addition, the above-mentioned figures are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, and are not intended to be limiting. It is easy to understand that the processes shown in the above-mentioned figures do not indicate or limit the time sequence of these processes. In addition, it is also easy to understand that these processes can be performed synchronously or asynchronously, for example, in multiple modules.

[0159] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the embodiment of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a touch terminal, or a network device, etc.) to execute the method according to the embodiment of the present disclosure.

[0160] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are indicated by the claims.

[0161] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A method for generating a device fingerprint, characterized in that: include: Acquire initial device characteristic data of a target device collected from at least two data sources; Performing stability and consistency analysis on the initial device characteristic data to determine effective device characteristic data; Performing weighted integration on the valid device feature data by using a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector; A reduced-dimensional device fingerprint feature vector is determined according to the multi-dimensional device fingerprint feature vector, and a hash operation is performed on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identifier corresponding to the target device.

2. The device fingerprint generation method according to claim 1, characterized in that: The initial device characteristic data includes static device characteristics and dynamic device characteristics; the performing stability consistency analysis on the initial device characteristic data to determine the effective device characteristic data includes: Performing stability analysis on the static device characteristics and the dynamic device characteristics to obtain stable device characteristics; Based on a preset threat behavior model, a consistency analysis is performed on the dynamic device features in the stable device features to obtain valid device feature data.

3. The device fingerprint generation method according to claim 2, characterized in that: The static device features include hardware features, operating system features and browser features, and the dynamic device features include user behavior features and network communication features; the stability analysis of the static device features and the dynamic device features to obtain stable device features includes: Sampling the hardware features multiple times, calculating the deviation value of each sampling result, and screening the hardware features in combination with a preset deviation threshold and the deviation value to obtain stable hardware features; Performing a value range detection on the operating system characteristics to eliminate feature data that does not fall within a preset value range, thereby obtaining a stable operating system characteristic; Performing consistency verification on the browser features to eliminate feature data that changes frequently or conflicts with the operating system features, and obtaining stable browser features; Performing cross-time window analysis on the user behavior characteristics, so as to eliminate feature data whose stability is lower than a preset statistical feature threshold through determined statistical characteristics, and obtain stable user behavior characteristics; Performing outlier detection on the network communication features to remove feature data that does not conform to the mean and three times the standard deviation of the standard deviation, so as to obtain stable network communication features; Stable device characteristics are constructed based on the stable hardware characteristics, the stable operating system characteristics, the stable browser characteristics, the stable user behavior characteristics and the stable network communication characteristics.

4. The device fingerprint generation method according to claim 3, characterized in that: The consistency analysis of the dynamic device features in the stable device features based on the preset threat behavior model to obtain valid device feature data includes: The dynamic device features in the stable device features are segmented into time windows, and the consistency coefficient of the dynamic device feature time series is determined, and the dynamic device features in the stable device features whose consistency coefficient is less than a preset consistency threshold are eliminated; The screened stable device features are input into a preset threat behavior model to eliminate potential abnormal features in the stable device features and obtain valid device feature data.

5. The device fingerprint generation method according to claim 1, characterized in that: The weighted integration of the effective device feature data by using the predetermined distribution weights to obtain a multi-dimensional device fingerprint feature vector includes: Performing standardization processing on each feature data in the effective device feature data to obtain standardized effective device feature data; Performing weighted fusion on each feature data component in the standardized effective device feature data according to a predetermined allocation weight to obtain a multi-dimensional feature component; The multi-dimensional device fingerprint feature vector is constructed based on the multi-dimensional feature components.

6. The device fingerprint generation method according to claim 1, characterized in that: The step of determining the reduced-dimensional device fingerprint feature vector according to the multi-dimensional device fingerprint feature vector includes: Performing mean zeroing and variance normalization processing on each feature dimension data in the multi-dimensional device fingerprint feature vector to obtain a standard device fingerprint feature vector; Determine a covariance matrix corresponding to the standard device fingerprint feature vector, and determine a feature contribution value corresponding to each feature dimension of the standard device fingerprint feature vector according to the covariance matrix; Determine the key feature dimension according to the feature contribution value and a preset contribution value threshold; The original feature vector corresponding to the key feature dimension is projected into a predetermined principal component space to generate a reduced-dimensional device fingerprint feature vector.

7. The device fingerprint generation method according to claim 1, characterized in that: The obtaining of initial device characteristic data of the target device collected from at least two data sources includes: Capturing a device chip serial number, clock offset, device address, and central processing unit characteristics of the target device as hardware characteristics of the target device through a system interface and a hardware status monitoring tool; Collecting operating system version information, language settings, time zone, and user permission level of the target device, and obtaining system call logs and file system configuration information to identify the operating environment of the target device as operating system characteristics of the target device; Extracting the screen resolution, browser version, installed plug-in list, language setting, and user agent information of the preset browser of the target device, and using the browser developer tool to monitor the running status of the browser in real time as the browser features of the target device; Collecting touch tracks, mouse operation tracks, keyboard input features, device operation behaviors and interaction modes generated during the use of the target device as user behavior features of the target device through a system interface and an event listener; Based on the network traffic monitoring tool, the data packet size, transmission rate, network delay and channel occupancy of the target device during the communication process are collected, and the abnormal behavior characteristics of the target device in the network interaction are captured as the network communication characteristics of the target device.

8. A device fingerprint generation device, characterized in that: include: A feature data acquisition module, used to acquire initial device feature data of a target device collected from at least two data sources; An effective feature screening module, used to perform stability and consistency analysis on the initial device feature data to determine effective device feature data; A feature vector fusion module, used to perform weighted integration on the valid device feature data through a predetermined allocation weight to obtain a multi-dimensional device fingerprint feature vector; The device fingerprint generation module is used to determine a reduced-dimensional device fingerprint feature vector based on the multi-dimensional device fingerprint feature vector, and perform a hash operation on the reduced-dimensional device fingerprint feature vector to generate a device fingerprint identification corresponding to the target device.

9. An electronic device, characterized in that: include: processor; as well as A memory, wherein computer-readable instructions are stored in the memory, and when the computer-readable instructions are executed by the processor, the device fingerprint generation method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor, the device fingerprint generation method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Method and system for generating digital fingerprint of power grid operation mode

    CN120670627A

  • Chrome extension permission risk assessment method based on dimensionality reduction driven belief rule base

    CN121959534A