Network device type detection method and related hardware
By obtaining network message characteristics and matching and prediction, the problem of low detection efficiency of IPv6 device type is solved, efficient detection of IPv6 device type is realized, reducing detection of non-existent devices, and improving detection efficiency and resource utilization.
Patent Information
- Application Number
- CN202510387154.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-04
AI Technical Summary
The existing network detection technology cannot efficiently conduct traversal detection of IPv6 network device types, especially in the case of insufficient IPv6 network address space sparsity and insufficient computing power, the active detection efficiency is low, and effective detection of the type to which IPv6 devices cannot be realized.
By obtaining the communication characteristics of network packets, using preset communication characteristics to match, determining the device type, and predicting the device type based on the target device type prediction method, combining passive traffic analysis and active detection, determining the type of IPv6 device.
In the case where all IPv6 devices cannot be traversed and detected, more types of IPv6 devices that have not yet been mastered are efficiently detected, reducing detection of non-existent devices, improving detection efficiency and reducing resource waste.
Smart Images

Figure CN120263670A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet technologies, and particularly to a method for detecting network device types and related hardware. Background Art
[0002] This section aims to provide background or context for the embodiments of the present application described in the claims. The description herein is not admitted to be prior art merely because it is included in this section.
[0003] The Internet is an important part of today's human social activities. Physically, the Internet is composed of a large number of heterogeneous network devices globally connected by cables or wireless communication systems; logically, the data exchange and communication between devices on the Internet rely on basic network protocols, and the Internet Protocol (IP) plays a fundamental and core role in the Internet. Each device connected to the Internet is assigned a unique IP address, enabling the devices to be accurately distinguished. The widely used fourth version of the IP protocol (IPv4) address consists of 32 bits in length and can provide approximately 4.3 billion non-repeating IP addresses. However, up to now, the IPv4 addresses have been allocated completely. Against the backdrop of the global digitalization, mobile Internet, and Internet of Things development, the global demand for IP addresses continues to grow rapidly. IPv4 can no longer provide new IP addresses for the continuously growing demand for IP addresses.
[0004] The sixth version of the IP protocol (IPv6) is the next-generation IP protocol designed by the Internet Engineering Task Force (IETF) to replace IPv4. The IPv6 address consists of 128 bits and can provide approximately 3.4×10 38 non-repeating IP addresses. The IPv6 protocol can provide a sufficient number of IP addresses in the foreseeable future to meet the development needs of information technology in the foreseeable future. Due to the huge network carrying capacity of IPv6, coupled with its secure and efficient network transmission and greater innovation space, it has become the recognized next-generation Internet solution.
[0005] Network space mapping is an important part of network security implementation. Among them, network space asset detection is the basis of network space mapping, which can help network administrators comprehensively understand the types, status, distribution, etc. of network space assets, and provide important intelligence data for network security management, asset vulnerability analysis, attack surface management, and threat tracing. Among them, in network space asset mapping, detecting the type of network device is the primary step.
[0006] The existing network space asset detection technologies can be divided into two categories: active detection and passive detection. Active detection technology is a detection technology that uses a detection tool program to actively send detection data packets to the target device, and identifies, analyzes, and collects asset information of the target device through the data fingerprint of the response data packet of the target device. Passive detection technology is a detection technology that passively listens to network traffic data packets through network sniffing, and identifies, analyzes, and collects asset information through Deep Packet Inspection (DPI) technology and asset fingerprint technology. Active detection will affect the network system of the target device because it will send a large number of detection data packets. Compared with active detection technology, passive detection technology will not affect the network system.
[0007] The detection technology for IPv4 networks has been very mature. Through a high-concurrency and distributed architecture, the existing network detection technology can perform traversal scanning within an acceptable time to achieve network space asset detection. However, for the IPv6 protocol, due to the extremely large IPv6 network address space, when actually allocating IPv6 addresses currently, the IPv6 addresses allocated to users have a very high sparsity (for example, the address space allocated to users can even reach 64-bit available space prefix / 64). Therefore, in the process of detecting the type of network device, the efficiency of using active detection is too low, and the computing power of current devices cannot achieve traversal scanning. Therefore, it is impossible to detect the type of IPv6 devices by performing traversal active detection on all Internet devices. Summary of the Invention
[0008] The embodiments of the present invention provide a method for detecting the type of network device and related hardware, which are used to solve the problem of efficiently detecting the type information of IPv6 devices that have not been mastered in the case where it is impossible to perform traversal active detection on the type of IPv6 devices, and reducing the situation of detecting non-existent IPv6 devices.
[0009] The embodiments of the present invention provide a method for detecting the type of network device, including:
[0010] Obtaining at least one first communication feature of at least one feature category of network packets sent and / or received by a first device;
[0011] Matching the first communication feature with a preset second communication feature of the same category, and determining the target device type corresponding to the first device according to the matching situation;
[0012] Predicting a third communication feature based on the first communication feature by using a target device prediction method corresponding to the target device type, and taking the target device type as the device type of a second device that conforms to the third communication feature.
[0013] Optionally, determining the target device type corresponding to the first device according to the matching situation includes at least one of the following:
[0014] If the communication feature includes an IP address, and the first IP address in the first communication feature matches the target second IP address in the second communication feature successfully, determine that the target device type corresponding to the first device is the device type corresponding to the target second IP address; wherein, the first IP address is the source IP address and / or the target IP address;
[0015] If the communication feature includes a port, and the first port in the first communication feature matches the target second port in the second communication feature successfully, determine that the target device type corresponding to the first device is the device type corresponding to the target second port; wherein, the first port is the source port and / or the target port;
[0016] If the communication feature includes a communication protocol and communication protocol connection configuration information, and the first communication protocol in the first communication feature matches the target second communication protocol in the second communication feature successfully, and the first communication protocol connection configuration information in the first communication feature matches the target second communication protocol connection configuration information in the second communication feature successfully, determine that the target device type corresponding to the first device is the device type jointly corresponding to the target second communication protocol and the target second communication protocol connection configuration information.
[0017] Further optionally, the method further includes:
[0018] If the first communication features of all feature categories fail to match the second communication features of the same category, send a port probe message for probing at least one preset fourth port to the first device;
[0019] Determine the target device type corresponding to the first device according to the response status of the first device to the port probe message.
[0020] Optionally, the first communication feature at least includes a first IP address, and the first IP address is the source IP address and / or the destination IP address; the device type includes a network service device type;
[0021] Predicting the third communication feature by using the target device prediction method corresponding to the target device type based on the first communication feature, and using the target device type as the device type of the second device conforming to the third communication feature includes:
[0022] If the target device type is a network service device type, convert the first IP address into a first numerical value according to a preset conversion rule, determine at least one second numerical value whose difference from the first numerical value belongs to a preset difference range, determine third IP addresses corresponding to the second numerical values respectively according to the preset conversion rule, determine second devices corresponding to the third IP addresses respectively, and use the network service device type as the device type corresponding to each of the second devices.
[0023] Further optionally, the method further includes:
[0024] Proactively detect the first device and / or the second device to determine corresponding network space asset information;
[0025] Among them, the proactive detection methods for devices of different device types are different.
[0026] Further optionally, if the first communication feature includes multiple feature categories, after determining the target device type corresponding to the first device according to the matching situation, the method further includes:
[0027] If the first communication feature of any feature category matches the second communication feature of the same category successfully, use the first communication features of at least some feature categories other than the successfully matched feature category as the newly added second communication features of the corresponding feature categories, and update the preset second communication features.
[0028] Based on the same inventive concept, an embodiment of the present invention further provides a network device type detection device, including:
[0029] A feature extraction module, configured to obtain first communication features of at least one feature category of at least one network packet sent and / or received by a first device;
[0030] A first device type determination module, configured to match the first communication feature with a preset second communication feature of the same category, and determine the target device type corresponding to the first device according to the matching situation;
[0031] A second device type determination module, configured to predict a third communication feature by using a target device prediction method corresponding to the target device type based on the first communication feature, and use the target device type as the device type of a second device that conforms to the third communication feature.
[0032] Based on the same inventive concept, an embodiment of the present invention further provides an electronic device, including: a processor and a memory for storing instructions executable by the processor;
[0033] Wherein, the processor is configured to execute the instructions to implement the network device type detection method described above.
[0034] Based on the same inventive concept, an embodiment of the present invention further provides a computer-readable storage medium storing computer program code, which, when running on a computer, causes the computer to execute the network device type detection method described above.
[0035] Based on the same inventive concept, an embodiment of the present invention further provides a computer program product, which includes computer program code that, when running on a computer, causes the computer to execute the network device type detection method described above.
[0036] The beneficial effects of the present invention are as follows:
[0037] For the network device type detection method and related hardware provided by the embodiments of the present invention, first, the target device type corresponding to the first device is determined according to the first communication feature of the network packets sent and received by the first device, and then the third communication feature is predicted according to the target device prediction method corresponding to the target device type. For the second device corresponding to the third communication feature, it is determined that the device type to which it belongs is also the target device type corresponding to the first device. In this way, when it is impossible to perform a traversal detection on all network devices in the Internet, through passive traffic analysis, based on a small number of detected first devices, the second devices associated with the first device can be predicted, and it can be determined that the second devices also belong to the target device type corresponding to the first device, so that the type information of more unmastered IPv6 devices can be detected with higher efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 It is one of the flowcharts of the network device type detection method provided by the embodiments of the present invention;
[0039] Figure 2 It is another flowchart of the network device type detection method provided by the embodiments of the present invention;
[0040] Figure 3 It is a schematic structural diagram of the network device type detection device provided by the embodiments of the present invention;
[0041] Figure 4 It is a schematic structural diagram of the electronic device provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] To make the above objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described below in conjunction with the accompanying drawings and embodiments. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the embodiments described herein; on the contrary, these embodiments are provided to make the present invention more comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the drawings represent the same or similar structures, and thus the repeated description thereof will be omitted. The words expressing positions and directions described in the present invention are illustrative with reference to the drawings, but can be changed according to needs, and all changes are included within the protection scope of the present invention. The drawings of the present invention are only used to illustrate the relative position relationship and do not represent the actual scale.
[0043] It should be noted that specific details are set forth in the following description to facilitate a thorough understanding of the present invention. However, the present invention can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below. The subsequent description of the specification is a preferred embodiment for implementing the present application, but the description is for the purpose of illustrating the general principles of the present application and is not intended to limit the scope of the present application. The protection scope of the present application shall be subject to what is defined by the appended claims.
[0044] It should be declared that in the technical solution of the present invention, the acquisition, transmission, storage, use, etc. of data all comply with the requirements of relevant national laws and regulations.
[0045] The following specifically describes a network device type detection method and related hardware provided by an embodiment of the present invention in conjunction with the accompanying drawings.
[0046] An embodiment of the present invention provides a network device type detection method, as Figure 1 shown, including:
[0047] S110. Obtain first communication features of at least one feature category of at least one network packet sent and / or received by a first device.
[0048] In the specific implementation process, on the premise of complying with the relevant regulations of the national relevant laws and regulations, network data transmission devices such as routers and switches can be used to monitor the network packets sent and / or received by the first device, and then extract features from the original network packets obtained by the monitoring to obtain the first communication features of at least one feature category; alternatively, network data transmission devices such as routers and switches can also be used to extract features from the transmitted network packets by using network analysis technology during the transmission process of the network packets sent and / or received by the first device to obtain the first communication features of at least one feature category. For example, for routers or switches of Cisco, "Netflow" can be used to extract the first communication features of at least one feature category from network packets; for routers or switches of Huawei, "NetStream" can be used to extract the first communication features of at least one feature category from network packets; for routers or switches of other models, sFlow can be used to extract the first communication features of at least one feature category from network packets, and the embodiments of the present invention do not make excessive limitations here. By using network analysis technology to extract and save features from the network packets transmitted by the first device during the transmission process of the network packets sent and / or received by the network data transmission device, compared with extracting features after monitoring and storing the network packets, the amount of data that needs to be stored can be effectively reduced.
[0049] In the specific implementation process, the communication features (including the first communication features and the second and third communication features to be involved below) include at least one of the following:
[0050] Source IP address, source port, destination IP address, destination port, communication protocol, communication protocol connection configuration information, network packet data volume, total number of network packets sent within a preset duration, total number of network packets received within a preset duration, total number of destination IP addresses involved in the network packets sent within a preset duration, total number of source IP addresses involved in the network packets received within a preset duration, total data volume of the network packets sent within a preset duration, total data volume of the network packets received within a preset duration.
[0051] Since the IPv6 address cannot be actively traversed and detected with the existing device computing power, the embodiments of the present invention mainly aim at the detection of network device types of the IPv6 protocol. Therefore, the source IP address and the destination IP address can be in the IPv6 format address; of course, the embodiments of the present invention can also be applied to the detection of network device types of the IPv4 protocol. Therefore, the source IP address and the destination IP address can also be in the IPv4 address, and the embodiments of the present invention do not make excessive limitations here.
[0052] S120. Match the first communication feature with a preset second communication feature of the same category, and determine the target device type corresponding to the first device according to the matching result.
[0053] In the embodiments of the present invention, devices can be classified into different device types according to needs. For example, devices can be classified into mobile user terminal devices (including smart phones, wearable devices, laptops, etc.), fixed-position user terminal devices (such as desktop computers, etc.), fixed-position servers, etc. according to portability and computing performance. Another example is that devices can be classified into network service device types (including web servers, etc.) and non-network service device types (such as ordinary user terminal devices, etc.) according to the functions implemented by the devices. The embodiments of the present invention do not make excessive limitations here.
[0054] Optionally, step S120. Match the first communication feature with a preset second communication feature of the same category, and determine the target device type corresponding to the first device according to the matching result includes at least one of the following:
[0055] (1) The communication feature includes an IP address, that is, the first communication feature includes a first IP address, and the second communication feature includes at least one second IP address. Among them, the first IP address is the source IP address and / or the destination IP address. For example, if the network packet monitored for the first device is a network packet sent by the first device to other devices, then the first IP address is the source IP address; if the network packet monitored for the first device is a network packet received by the first device from other devices, then the first IP address is the destination IP address.
[0056] Then:
[0057] If the first IP address in the first communication feature matches the target second IP address in the second communication feature successfully, determine that the target device type corresponding to the first device is the device type corresponding to the target second IP address.
[0058] For example, the second IP addresses include the IP address corresponding to device type A, the IP address corresponding to device type B, and the IP address corresponding to device type C. If the first IP address matches the second IP address corresponding to device type A successfully, determine that the target device type corresponding to the first device is device type A.
[0059] (2) The communication features include ports, that is, the first communication feature includes a first port, and the second communication feature includes at least one second port. Among them, the first port is the source port and / or the destination port. For example, if the network packet obtained by monitoring the first device is a network packet sent by the first device to other devices, then the first port is the source port; if the network packet obtained by monitoring the first device is a network packet received by the first device from other devices, then the first port is the destination port. Then:
[0060] If the first port in the first communication feature matches successfully with the destination second port in the second communication feature, then determine that the target device type corresponding to the first device is the device type corresponding to the destination second port.
[0061] For example, the second ports include ports corresponding to device type A, ports corresponding to device type B, and ports corresponding to device type C. If the first port matches successfully with the second port corresponding to device type A, then determine that the target device type corresponding to the first device is device type A.
[0062] (3) The communication features include communication protocols and communication protocol connection configuration information, that is, the first communication feature includes a first communication protocol and first communication protocol connection configuration information, and the second communication feature includes at least one second communication protocol and at least one second communication protocol connection configuration information. Then:
[0063] If the first communication protocol in the first communication feature matches successfully with the target second communication protocol in the second communication feature, and the first communication protocol connection configuration information in the first communication feature matches successfully with the target second communication protocol connection configuration information in the second communication feature, then determine that the target device type corresponding to the first device is the device type jointly corresponding to the target second communication protocol and the target second communication protocol connection configuration information.
[0064] For example, the second communication protocol and the second communication protocol connection configuration information include the communication protocol and communication protocol connection configuration information corresponding to device type A, the communication protocol and communication protocol connection configuration information corresponding to device type B, and the communication protocol and communication protocol connection configuration information corresponding to device type C. If the first communication protocol matches successfully with the second communication protocol corresponding to device type A, and the first communication protocol connection configuration information matches successfully with the second communication protocol connection configuration information corresponding to device type A, then determine that the target device type corresponding to the first device is device type A.
[0065] For example, the second communication protocol includes the Transmission Control Protocol (TCP). The second communication protocol connection configuration information includes the connection request flag SYN = 1 and the connection response flag ACK = 1 carried in the connection response message during the second handshake in the TCP connection process. The TCP protocol corresponds to device type A. If the first communication protocol in the first communication feature is the TCP protocol and the first communication protocol connection configuration information contains SYN = 1 and ACK = 1, then it can be determined that the network packet corresponding to the first communication feature is the second handshake connection response packet during the TCP protocol connection between the first device and other devices, and the target device type corresponding to the first device is device type A.
[0066] Furthermore, if during the process of matching the first communication feature with the second communication feature of the same category by adopting at least one of the above - mentioned implementation manners, if all the first communication features of all feature categories fail to match the second communication features of the same category, then an active detection can be further initiated for the first device to detect the target device type to which the first device belongs. Specifically, it can further include the following steps:
[0067] Send a port detection packet for detecting at least one preset fourth port to the first device, and determine the response status of the first device to the port response packet.
[0068] Determine the target device type corresponding to the first device according to the response status of the first device to the port detection packet.
[0069] For example, for the target fourth port, if the response status of the first device to the port detection packet of the target fourth port is a positive response status, then determine that the target device type corresponding to the first device is the device type corresponding to the target fourth port. Among them, the target fourth port is any fourth port. The positive response status is the response status of the first device to the port detection packet when the fourth port is open.
[0070] For example, the device type includes two types: the first device type and the second device type. Then:
[0071] If it is determined that the response status of the first device to the port detection packet of the fourth port is a positive response status, then determine that the target device type corresponding to the first device is the first device type, where the positive response status is the response status of the first device to the port detection packet when the second port is open.
[0072] If it is determined that the response status of the first device to the port detection packet of the fourth port is a negative response status, then determine that the target device type corresponding to the first device is the second device type; where the negative response status is the response status of the first device to the port detection packet when the second port is closed.
[0073] In the specific implementation process, the positive response status and negative response status of the fourth port are related to the functions and communication protocols corresponding to the fourth port. For example, for the TCP protocol, when the first device enables the fourth port corresponding to the TCP protocol and receives a port detection message implemented in the form of the first handshake message for requesting to establish a TCP connection, it will return a port response message for the second handshake; when the first device closes the fourth port corresponding to the TCP protocol and receives a port detection message implemented in the form of the first handshake message for requesting to establish a TCP connection, it will return a port response message for rejecting the connection. Then, it can be determined that the response status of the first device is a positive response status by receiving the port response message for the second handshake returned by the first device within a set time period, and it can be determined that the response status of the first device is a negative response status by receiving the port response message for rejecting the connection returned by the first device within a set time period or not receiving the port response message returned by the first device within a set time period. For the User Datagram Protocol (UDP), when the first device enables the fourth port corresponding to the UDP and receives a port detection message implemented in the form of a message for requesting to establish a UDP connection, it will not take any active action; when the first device closes the fourth port corresponding to the UDP and receives a port detection message implemented in the form of a message for requesting to establish a UDP connection, it will return a port response message indicating that the port is closed. Then, it can be determined that the response status of the first device is a positive response status by not receiving the port response message indicating that the port is closed returned by the first device within a set time period, and it can be determined that the response status of the first device is a negative response status by receiving the port response message indicating that the port is closed returned by the first device within a set time period. For the Post Office Protocol - Version 3 (POP3), when the first device enables the fourth port corresponding to the POP3 and receives a port detection message implemented in the form of a message for requesting to establish a POP3 connection, it will return a port response message indicating successful connection; when the first device closes the fourth port corresponding to the POP3 and receives a port detection message implemented in the form of a message for requesting to establish a POP3 connection, it will not take any active action. Then, it can be determined that the response status of the first device is a positive response status by receiving the port response message indicating successful connection returned by the first device within a set time period, and it can be determined that the response status of the first device is a negative response status by not receiving the port response message indicating successful connection returned by the first device within a set time period.
[0074] In the specific implementation process, the second port can be directly used as the fourth port; the fourth port can also be different from the second port. For example, all ports of the first device can be set as the fourth port. The embodiments of the present invention do not make too many limitations here.
[0075] S130. Predict the third communication feature using the target device prediction method corresponding to the target device type based on the first communication feature, and use the target device type as the device type of the second device that conforms to the third communication feature.
[0076] Optionally, the communication feature at least includes an IP address, that is, the first communication feature includes a first IP address, and the second communication feature includes at least one second IP address. Among them, the first IP address is the source IP address and / or the target IP address. The device type includes a network service device type (such as a web server, etc.).
[0077] Considering that for network service devices, in order to be stably connected by clients, their IP addresses usually use fixed IP addresses that do not change. In addition, for network service platforms, in order to achieve purposes such as load balancing, multiple different network service devices are usually set up for the same network service at the same time. Since the IP addresses assigned by network operators to network service platforms are usually consecutive IP addresses within a certain range, and for the convenience of management and maintenance, the IP addresses of multiple different network service devices used to implement the same network service are set to have the characteristic of being numerically concentrated.
[0078] Based on this, if the target device type is a network service device type, the step S130 specifically includes: converting the first IP address into a first value according to a preset conversion rule, determining at least one second value whose difference from the first value belongs to a preset difference range, determining the third IP address corresponding to each second value according to the preset conversion rule, determining the second device corresponding to each third IP address, and using the network service device type as the device type corresponding to each second device.
[0079] Specifically, the preset conversion rule can be:
[0080]
[0081] Among them, x is the value obtained by converting the IP address according to the preset conversion rule (for the first IP address, x is the first value; for the third IP address, x is the second value), i is the serial number of the network segment of the IP address from right to left, d is the network segment capacity of the IP address (for IPv4 addresses, since the digital value range of each network segment is [0, 255], the network segment capacity d = 256; for IPv6 addresses, since the digital value range of each network segment is [0 HEX ,FFFF HEX , the network segment capacity d = 65536), and s i is the number corresponding to the i-th network segment in the IP address.
[0082] For example, if the first IP address (in hexadecimal HEX format) is: 2001:0db8:85a3:0000:0000:8a2e:0370:7334, then the first value x1 corresponding to the first IP address is:
[0083] x1 = 65536 0 × 7334 HEX + 65536 1 × 0370 HEX + 65536 2 × 8a2e HEX
[0084] + 65536 3 × 0000 HEX + 65536 4 × 0000 HEX + 65536 5 × 85a3 HEX
[0085] + 65536 6 × 0db8 HEX + 65536 7 × 2001 HEX
[0086] = 42540766452641154071740215577757643572
[0087] If the preset difference range is [-5, +5], then the values within the range [x1 - 5, x1 + 5] can be used as the second value x2, and each second value x2 is respectively converted into a third IP address according to the above preset conversion rule, the second device corresponding to each third IP address is determined, and the network service device type is used as the device type corresponding to each second device.
[0088] In this way, by predicting the second device through the above method, the implementation method is relatively simple and efficient.
[0089] Furthermore, if the device types include two types: network service device type (referred to as the first device type for easy distinction in the following text) and non-network service device type (referred to as the second device type for easy distinction in the following text). Considering that for devices of the second device type such as ordinary user terminal devices, their IP addresses are usually randomly assigned by network operators or dynamically assigned using a certain allocation algorithm, and the distribution of IP addresses is relatively scattered, which is different from the characteristic that the IP addresses of devices of the first device type are continuously assigned and relatively concentrated within a certain range.
[0090] Based on this, if the target device type is the second device type, step S130 specifically includes: using a statistical-based IP address clustering prediction algorithm or an IP address prediction algorithm based on a machine learning model to predict at least one third IP address according to the first IP address, determining the second devices corresponding to each third IP address, and taking the second device type as the device type corresponding to each second device.
[0091] In a specific implementation process, if the target device type is the second device type, algorithms such as EnrtopyIP algorithm, 6-Tree algorithm, 6Gen algorithm, 6GAN algorithm, 6GCVAE algorithm, 6VecLM algorithm, 6EDL-N algorithm, etc. can be used to predict at least one third IP address according to the first IP address.
[0092] In this way, in the embodiment of the present invention, first, the target device type corresponding to the first device is determined according to the first communication feature of the network packets sent and received by the first device, and then the third communication feature is predicted according to the target device prediction method corresponding to the target device type. For the second device corresponding to the third communication feature, it is determined that the device type to which it belongs is also the target device type corresponding to the first device. In this way, in the case where it is impossible to perform a traversal detection on all network devices in the Internet, through passive traffic analysis, based on a small number of detected first devices, the second devices associated with the first device can be predicted, and it is determined that the second devices also belong to the target device type corresponding to the first device, so that it is possible to detect the type information of more unmastered IPv6 devices with higher efficiency.
[0093] Further optionally, the method further includes:
[0094] S140. Actively detect the first device and / or the second device to determine the corresponding network space asset information.
[0095] In a specific implementation process, the corresponding network space asset information can be determined by sending an active detection message to the active detection port of the first device / second device and according to the response status feature of the first device / second device. For example, an active detection message of the TCP / IP protocol can be sent to the response port of the first device / second device, and the operating system fingerprint features such as the Time To Live (TTL) value and the arrangement order of the message flag bits in the response message returned by the first device / second device can be used to determine the operating system running on the first device / second device.
[0096] After actively detecting the network space asset information of the corresponding device, the network space asset information can be saved to the database for subsequent analysis and use.
[0097] Optionally, the active detection methods for devices of different device types may be the same or different.
[0098] For example, for an implementation where the device types include a first device type and a second device type, for the first device and / or the second device of the first device type, more detailed cyber space asset information can be actively detected for the devices of the first device type, including the hardware type of the device (such as microcomputer, minicomputer, midrange computer, mainframe, etc.), the operating system running on the device, the services running on the device, the application components running on the device, the functions implemented by the device, etc. For the first device and / or the second device of the second device type, only a small amount of cyber space asset information can be actively detected for the devices of the second device type, such as only including the hardware type of the device (such as Internet of Things terminal, smart phone, desktop computer, etc.) and the operating system running on the device.
[0099] In the specific implementation process, since different ports may be involved in actively detecting different cyber space asset information during the active detection process. Therefore, if the active detection methods for devices of different device types are different, different active detection methods can be set by setting different active detection destination ports for the active detection messages. For example, for an implementation where the device types include a first device type and a second device type, it can be preset that the active detection destination port of the first device type is different from the active detection destination port of the second device type.
[0100] Optionally, the active detection methods for the first device and the second device may be the same or different.
[0101] For example, for an implementation where the device types include a first device type and a second device type, if the first port in the first communication feature matches successfully with the target second port in the second communication feature for the first device, then the first port can be used as the active detection destination port of the first device; if the first port in the first communication feature fails to match with the second port in the second communication feature during the process of the first device determining the target device type to which the first device belongs, then the second port can be used as the active detection destination port of the first device. For the second device of the first device type, the active detection destination ports respectively corresponding to at least one first device with the highest similarity between the IP address and the third IP address of the second device are used as the active detection destination ports of the second device (that is, the active detection destination ports of the second device of the first device type are the union of the active detection destination ports respectively corresponding to at least one first device with the highest similarity between the IP address and the third IP address of the second device); for the second device of the second device type, the second port is used as the active detection destination port.
[0102] In this way, by adopting different active detection methods to further actively detect the first device and the second device, the cyber space asset information corresponding to the device can be detected in more detail. By determining the second device through the embodiments of the present invention and actively detecting the second device, compared with blindly determining an unknown second device for active detection, the number of occurrences of active detection of non-existent unknown devices can be reduced, thereby improving the efficiency of active detection and greatly saving the use of detection resources. In addition, if different active detection methods are adopted for devices of different device types for further active detection, while detecting more detailed cyber space asset information for devices of important device types, less active detection can be performed on devices of non-important device types to reduce the impact on the network, while reducing the interference with the normal operation of devices of non-important device types and reducing the risk of being blocked.
[0103] Further optionally, if the first communication feature includes multiple feature categories, after the step S120 of matching the first communication feature with the preset second communication feature of the same category and determining the target device type corresponding to the first device according to the matching situation ( Figure 1 taking the example after the step S140 as an illustration), the method further includes:
[0104] S150. If the first communication feature of any feature category matches the second communication feature of the same category successfully, then use the first communication features of at least some feature categories other than the successfully matched feature category as the newly added second communication features corresponding to the feature categories, and update the preset second communication feature.
[0105] For example, if the first communication feature includes a first IP address and a first port, when the first IP address matches the second IP address in the second communication feature successfully, then use the first port as the newly added second port to update the second port set in the preset second communication feature. In this way, it can provide a more comprehensive and more timely reference for feature matching of the first communication features of other network packets in the future.
[0106] The following gives a specific embodiment to illustrate the network device type detection method provided by the embodiments of the present invention. Among them, in this embodiment, the device types are divided into the first device type and the second device type as described above. This embodiment can execute the corresponding steps periodically (for example, every 3 days), and execute the corresponding steps for each network packet involved in the current cycle when the execution time arrives. Among them, as Figure 2 shown, for any network packet among the network packets involved in the current cycle, the steps of this embodiment specifically include:
[0107] S210. Obtain a first communication feature OriginSet of at least one feature category of network packets sent and / or received by a first device. The first communication feature OriginSet is obtained by the network data transmission device extracting features from the network packets sent and / or received by the first device through Netflow in the current cycle. The first communication feature OriginSet includes: a first IP address (if the network packet is a network packet sent by the first device, the first IP address is the source IP address of the network packet; if the network packet is a network packet received by the first device, the first IP address is the destination IP address of the network packet), a first port (if the network packet is a network packet sent by the first device, the first port is the source port of the network packet; if the network packet is a network packet received by the first device, the first port is the destination port of the network packet), a first communication protocol, and first communication protocol connection configuration information.
[0108] S221. Determine whether the first IP address matches the second IP address DetectServerIPv6Set in the second communication feature.
[0109] If the first IP address successfully matches the target second IP address in the second communication feature, execute step S227; if the first IP address fails to match both the second IP addresses in the second communication feature, execute step S222.
[0110] S222. Determine whether the first port matches the second port DetectServerPortSet in the second communication feature.
[0111] If the first port successfully matches the target second port in the second communication feature, execute the said step S227; if the first port fails to match both the second ports in the second communication feature, execute step S223.
[0112] S223. Determine whether the first communication protocol matches the second communication protocol in the second communication feature.
[0113] If the first communication protocol successfully matches the target second communication protocol in the second communication feature, execute S224; if the first communication protocol fails to match both the second communication protocols in the second communication feature, execute step S225.
[0114] S224. Determine whether the first communication protocol connection configuration information matches the second communication protocol connection configuration information in the second communication feature.
[0115] If the first communication protocol connection configuration information matches the target second communication protocol connection configuration information in the second communication characteristics successfully, execute step S227; if the first communication protocol connection configuration information fails to match the second communication protocol connection configuration information in the second communication characteristics, execute step S225.
[0116] For example, the second communication protocol only includes the TCP protocol, and the second communication protocol connection configuration information includes SYN = 1 and ACK = 1 and the port number of the network packet is less than 1024.
[0117] S225. Send a port detection message for detecting the second port to the first device.
[0118] S226. Determine the response status of the port response message of the first device for the second port.
[0119] If it is determined that the response status of the port detection message of the first device for at least one second port is a positive response status, execute step S227; if it is determined that the response status of the port detection message of the first device for all second ports is a negative response status, execute step S228.
[0120] S227. Determine that the target device type corresponding to the first device is the first device type, and determine the active detection destination port corresponding to the first device. Execute step S231.
[0121] Among them, if it is determined according to step S222 that the first port matches the target second port in the second communication characteristics successfully, set the active detection destination port corresponding to the first device to the first port; if step S222 is not executed, or it is determined according to step S222 that the first port fails to match the second port in the second communication characteristics, set the active detection destination port corresponding to the first device to the second port.
[0122] S228. Determine that the target device type corresponding to the first device is the second device type, and set the preset fourth port as the active detection destination port corresponding to the first device. Execute step S232.
[0123] In the specific implementation process, for all network packets involved in the current cycle, the results obtained from step S227 and step S228 can be recorded as the set MarkSet, and the object corresponding to each first device is {IP address, active detection destination port setting, device type}.
[0124] S231. Convert the first IP address into a first numerical value according to a preset conversion rule, determine at least one second numerical value whose difference from the first numerical value belongs to a preset difference range, determine the third IP address corresponding to each second numerical value according to the preset conversion rule, determine the second device corresponding to each third IP address, and use the first device type as the device type corresponding to each second device. For any third IP address, determine the m first IP addresses with the highest similarity to the third IP address, and set the active detection destination port of the first devices corresponding to the m first IP addresses to the active detection destination port corresponding to the second device corresponding to the third IP address. Execute step S241.
[0125] S232. Adopt an IP address clustering prediction algorithm based on statistics or an IP address prediction algorithm based on a machine learning model to predict at least one third IP address according to the first IP address, determine the second device corresponding to each third IP address, and use the second device type as the device type corresponding to each second device. For any second device, set the second port to the active detection destination port corresponding to the second device. Execute step S242.
[0126] In the specific implementation process, for all network packets involved in the current cycle, the results of all first devices and second devices can be recorded as the set TargetSet, and the object corresponding to each device is {IP address, active detection destination port setting, device type}.
[0127] S241. Actively detect the active detection destination port of the first device to determine the device hardware type, operating system running on the device, service running on the device, application component running on the device, and functions implemented by the device. And actively detect the active detection destination port of the second device to determine the device hardware type, operating system running on the device, service running on the device, application component running on the device, and functions implemented by the device. Execute step S250.
[0128] S242. Actively detect the active detection destination port of the first device to determine the device hardware type and operating system running on the device. And actively detect the active detection destination port of the second device to determine the device hardware type and operating system running on the device.
[0129] In the specific implementation process, for all network packets involved in the current cycle, the active detection destination port corresponding to each IP address and the active detection network space asset information item can be determined according to each member object {IP address, active detection destination port setting, device type} in the set TargetSet.
[0130] S250. If the first communication feature of any feature category matches successfully with the second communication feature of the same category, then use the first communication features of at least some of the feature categories other than the successfully matched feature category as the newly added second communication features corresponding to the feature categories, and update the preset second communication features.
[0131] Based on the same inventive concept, an embodiment of the present invention further provides a network device type detection device, as Figure 3 shown, including:
[0132] A feature extraction module M1, configured to obtain the first communication features of at least one feature category of at least one network packet sent and / or received by a first device;
[0133] A first device type determination module M2, configured to match the first communication features with the preset second communication features of the same category, and determine the target device type corresponding to the first device according to the matching situation;
[0134] A second device type determination module M3, configured to predict third communication features by using a target device prediction method corresponding to the target device type based on the first communication features, and use the target device type as the device type of a second device that conforms to the third communication features.
[0135] Optionally, the determining the target device type corresponding to the first device according to the matching situation includes at least one of the following:
[0136] If the communication feature includes an IP address, and the first IP address in the first communication feature matches successfully with the target second IP address in the second communication feature, then determine that the target device type corresponding to the first device is the device type corresponding to the target second IP address; where the first IP address is the source IP address and / or the target IP address;
[0137] If the communication feature includes a port, and the first port in the first communication feature matches successfully with the target second port in the second communication feature, then determine that the target device type corresponding to the first device is the device type corresponding to the target second port; where the first port is the source port and / or the target port;
[0138] If the communication feature includes a communication protocol and communication protocol connection configuration information, and the first communication protocol in the first communication feature matches successfully with the target second communication protocol in the second communication feature, and the first communication protocol connection configuration information in the first communication feature matches successfully with the target second communication protocol connection configuration information in the second communication feature, then determine that the target device type corresponding to the first device is the device type jointly corresponding to the target second communication protocol and the target second communication protocol connection configuration information.
[0139] Further optionally, the first device type determination module M2 is further configured to:
[0140] If the first communication features of all feature categories fail to match the second communication features of the same category, send a port detection message for detecting at least one preset fourth port to the first device;
[0141] Determine the target device type corresponding to the first device according to the response status of the first device to the port detection message.
[0142] Optionally, the first communication feature at least includes a first IP address, and the first IP address is a source IP address and / or a destination IP address; the device type includes a network service device type;
[0143] The second device type determination module M3 is specifically configured to:
[0144] If the target device type is a network service device type, convert the first IP address into a first numerical value according to a preset conversion rule, determine at least one second numerical value whose difference from the first numerical value belongs to a preset difference range, determine the third IP addresses corresponding to the respective second numerical values according to the preset conversion rule, determine the second devices corresponding to the respective third IP addresses, and use the network service device type as the device type corresponding to the respective second devices.
[0145] Optionally, the apparatus further includes:
[0146] A cyber space asset information detection module M4, configured to actively detect the first device and / or the second device to determine the corresponding cyber space asset information;
[0147] Wherein, the active detection methods for devices of different device types are different.
[0148] Optionally, the apparatus further includes:
[0149] A second communication feature update module M5, configured to, if the first communication feature includes multiple feature categories, after determining the target device type corresponding to the first device according to the matching situation, if the first communication feature of any feature category matches the second communication feature of the same category, use the first communication features of at least some feature categories other than the feature category that matches successfully as the newly added second communication features corresponding to the respective feature categories, and update the preset second communication features.
[0150] It should be understood that the disclosed network device type detection device can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the device or module can be in electrical, mechanical or other forms. The modules described as separate components may or may not be physically separated. The components displayed as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the embodiments of the present application, each functional module can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a readable storage medium.
[0151] Since the specific working principle of the network device type detection device is the same as that of the network device type detection method described above, reference can be made to the corresponding implementation of the content of the network device type detection method described above, and details are not repeated here.
[0152] Based on the same inventive concept, an embodiment of the present application provides an electronic device, as Figure 4 shown. The device includes a processor 110 and a memory 120. Among them, the processor 110 is configured to execute the instructions to implement the network device type detection method.
[0153] In the specific implementation process, the device may vary greatly due to configuration or performance differences, and may include one or more processors 110, a memory 120, and a readable storage medium 130. One or more application programs 131 or data 132 are included in the memory 120 and / or the readable storage medium 130. One or more operating systems 133, such as Windows, Mac OS, Linux, IOS, Android, Unix, FreeBSD, etc., may also be included in the memory 120 and / or the readable storage medium 130. Among them, the memory 120 and the readable storage medium 130 can be transient storage or persistent storage. The application program 131 may include one or more of the above modules ( Figure 4(not shown in the figure), each module may include a series of instruction operations. Further, the processor 110 may be configured to communicate with the readable storage medium 130 and execute a series of instruction operations in the readable storage medium 130 on the device. The device may also include one or more power supplies ( Figure 4 (not shown in the figure); one or more network interfaces 140, the network interface 140 includes a wired network interface 141 and / or a wireless network interface 142; one or more input / output interfaces 143.
[0154] Based on the same inventive concept, an embodiment of the present application provides a readable storage medium, the readable storage medium stores a computer program, when the computer program is executed by a computer, the computer is caused to execute the network device type detection method.
[0155] The readable storage medium may be any available medium that a computer can store or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a high-definition digital video disc (DVD), a video compact disc (VCD)), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.
[0156] Since the principle of the above-readable storage medium for solving the problem is consistent with the network device type detection method, the implementation of the above-readable storage medium can refer to the implementation of the method, and the repeated parts will not be described again.
[0157] Based on the same inventive concept, an embodiment of the present application further provides a computer program product, the computer program product includes: computer program code, when the computer program code runs on a computer, the computer is caused to execute the network device type detection method.
[0158] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a readable storage medium or transmitted from one readable storage medium to another readable storage medium. For example, the computer instructions may be transmitted from a website, a computer, a server, or a data center to another website, a computer, a server, or a data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.).
[0159] Since the principle of the above computer program product for solving problems is the same as that of the network device type detection method, the implementation of the above computer program product can refer to the implementation of the method, and the repeated parts will not be described again.
[0160] The network device type detection method and related hardware provided by the embodiments of the present invention first determine the target device type corresponding to the first device according to the first communication characteristics of the network packets sent and received by the first device, and then predict the third communication characteristics according to the target device prediction method corresponding to the target device type. For the second device corresponding to the third communication characteristics, it is determined that the device type to which it belongs is also the target device type corresponding to the first device. In this way, when it is impossible to perform traversal detection on all network devices in the Internet in the IPv6 environment, through passive traffic analysis, based on a small number of detected first devices, the second devices associated with the first devices can be predicted, and it is determined that the second devices also belong to the target device type corresponding to the first device, so as to be able to detect the type information of more unmastered IPv6 devices with higher efficiency and reduce the situation of detecting non-existent IPv6 devices.
[0161] Those skilled in the art should understand that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0162] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to the application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0163] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0164] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0165] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.
Claims
1. A method for detecting network device types, characterized in that, Including: Obtaining first communication features of at least one feature category of at least one network packet sent and / or received by a first device; Matching the first communication features with preset second communication features of the same category, and determining a target device type corresponding to the first device according to the matching situation; Predicting third communication features by using a target device prediction method corresponding to the target device type based on the first communication features, and using the target device type as the device type of a second device that conforms to the third communication features.
2. The method according to claim 1, wherein The determining the target device type corresponding to the first device according to the matching situation includes at least one of the following: If the communication features include an IP address, and a first IP address in the first communication features matches a target second IP address in the second communication features successfully, determining that the target device type corresponding to the first device is the device type corresponding to the target second IP address; where the first IP address is a source IP address and / or a target IP address; If the communication features include a port, and a first port in the first communication features matches a target second port in the second communication features successfully, determining that the target device type corresponding to the first device is the device type corresponding to the target second port; where the first port is a source port and / or a target port; If the communication features include a communication protocol and communication protocol connection configuration information, and a first communication protocol in the first communication features matches a target second communication protocol in the second communication features successfully, and a first communication protocol connection configuration information in the first communication features matches a target second communication protocol connection configuration information in the second communication features successfully, determining that the target device type corresponding to the first device is the device type jointly corresponding to the target second communication protocol and the target second communication protocol connection configuration information.
3. The method according to claim 2, wherein The method further includes: If the first communication features of all feature categories fail to match the second communication features of the same category, sending a port detection packet for detecting at least one preset fourth port to the first device; Determining the target device type corresponding to the first device according to the response status of the first device to the port detection packet.
4. The method according to claim 1, wherein The first communication features at least include a first IP address, and the first IP address is a source IP address and / or a destination IP address; the device type includes a network service device type; The predicting the third communication features by using the target device prediction method corresponding to the target device type based on the first communication features, and using the target device type as the device type of the second device that conforms to the third communication features includes: If the target device type is a network service device type, convert the first IP address into a first numerical value according to a preset conversion rule, determine at least one second numerical value whose difference from the first numerical value belongs to a preset difference range, determine the third IP address corresponding to each of the second numerical values according to the preset conversion rule, determine the second device corresponding to each of the third IP addresses, and use the network service device type as the device type corresponding to each of the second devices.
5. The method according to claim 1, wherein The method further includes: Proactively detect the first device and / or the second device to determine the corresponding network space asset information; Among them, the proactive detection methods for devices of different device types are different.
6. The method according to any one of claims 1 to 5, characterized in that If the first communication feature includes multiple feature categories, after determining the target device type corresponding to the first device according to the matching situation, the method further includes: If the first communication feature of any feature category matches the second communication feature of the same category successfully, use the first communication features of at least some feature categories other than the successfully matched feature category as the newly added second communication features of the corresponding feature categories, and update the preset second communication features.
7. A network device type detection device, characterized in that, It includes: A feature extraction module, configured to obtain the first communication features of at least one feature category of at least one network packet sent and / or received by the first device; A first device type determination module, configured to match the first communication feature with the preset second communication feature of the same category, and determine the target device type corresponding to the first device according to the matching situation; A second device type determination module, configured to predict the third communication feature using the target device prediction method corresponding to the target device type based on the first communication feature, and use the target device type as the device type of the second device that conforms to the third communication feature.
8. An electronic device, characterized in that, It includes: A processor and a memory for storing instructions executable by the processor; Among them, the processor is configured to execute the instructions to implement the network device type detection method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program code, and when the computer program code runs on a computer, it causes the computer to execute the network device type detection method according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes: computer program code, and when the computer program code runs on a computer, it causes the computer to execute the network device type detection method according to any one of claims 1-6.