Mobile hotspot network element number sensing method based on Hash matching

The hash matching method is used to identify the belonging of traffic packets in the fine-grained window, which solves the problem of fineness and real-time perception of the number of mobile hotspot network elements, and realizes the accurate identification of the number of devices and the precise construction of data set labels.

CN120282139APending Publication Date: 2025-07-08SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510427068.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing method of perceiving the number of mobile hotspot network elements is insufficient in terms of precision and real-time, and it is difficult to accurately identify the access, exit and silent state of the device, resulting in misjudgment.

Method used

Using a hash matching method, the hash algorithm is used to identify the specific belonging of the traffic packet in a fine-grained window, and combining the sliding window and the flow tag recording module to achieve accurate perception of the number of devices.

Benefits of technology

It improves the accuracy and real-timeness of device quantity identification, builds refined dataset labels, supports offline and online modes, and is suitable for a variety of network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282139A_ABST
    Figure CN120282139A_ABST
Patent Text Reader

Abstract

The invention discloses a mobile hotspot network element quantity sensing method based on Hash matching. The method specifically comprises three functional modules, namely a data processing module, a Hash matching module and a flow label recording module. The data processing module adopts an off-line or on-line mode to package hotspot subnet traffic and exit traffic, designs a sliding window structure, and calculates a hash value of a data packet under each fine-grained window for subsequent matching analysis; the Hash matching module is used for judging the transmission direction of a data packet, ignoring the change caused by NAT (Network Address Translation), calculating the same Hash value by using a specific Hash algorithm, and providing a core basis for double-end matching; and the flow label recording module continuously records the data flow of which the affiliation is determined, performs hash matching on the data packet copy under the fine-grained window, and determines the number of devices under the current fine-grained window according to a matching result or flow affiliation information. According to the invention, a basis can be provided for improving measurement tasks such as service quality, anomaly detection, attack detection and the like for network service operators and network supervision departments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network measurement, and particularly relates to a method for perceiving the number of mobile hotspot network elements based on hash matching. Background Art

[0002] In the field of network security, the mobile hotspot technology can convert the internal network IP of the background device into the public network IP of the foreground device to enable communication between the internal network device and the Internet, hide the topology of the internal network externally, reduce direct communication from the external network, and provide a channel for attackers to illegally conceal access to the Internet. Furthermore, it can become a powerful tool in the hands of attackers for network mapping and lateral movement purposes.

[0003] From the perspective of business requirements, operators have a certain degree of control over their networks and the devices connected to their networks, which enables them to implement policies and technical measures to restrict or manage hotspot usage according to their own business models and network management requirements. Legal compliance: Operators must comply with regulations governing the provision and charging of hotspot services, which may affect their policies; Fair use: Operators are committed to providing fair network services to all users, and malicious use of hotspots to consume excessive resources will make it difficult to maintain fair network services; Network management: The network bandwidth available to operators is limited, and unrestricted hotspot usage may lead to network congestion, negatively affecting the quality of service for all users; Traffic packages: Many operators offer tiered traffic packages that limit monthly data usage, and allowing unrestricted hotspot usage may cause users to bypass these limitations, resulting in financial losses for operators.

[0004] At the network management level, the mobile hotspot behavior perception method can assist in requirements such as data parsing, traffic management, security policies, performance optimization, and VPN access: optimizing traditional traffic identification and analysis methods to avoid confusing the traffic of hotspot foreground and background devices; ensuring that traffic management policies can be accurately applied to the traffic of hotspot background devices to achieve effective utilization of network resources; ensuring that security policies can be accurately applied to the traffic of hotspot background devices to reduce network attacks and security vulnerabilities; assisting network administrators in optimizing network performance, such as traffic shaping and priority setting for the traffic of hotspot background devices to achieve priority transmission of critical application data; ensuring that remote users of hotspot background devices can correctly access internal network resources through VPN.

[0005] The existing methods for perceiving the number of mobile hotspot network elements mainly rely on active detection (such as DHCP statistics, MAC address listening) or network management APIs, while passive measurement methods have more advantages in privacy protection and passive detection scenarios. In recent years, passive measurement methods based on machine learning and deep learning have become a research hotspot. By using traffic characteristics (such as total traffic, number of sessions, packet interval), temporal characteristics (such as traffic volatility, active duration), and wireless signal characteristics (such as RSSI distribution, management frame analysis), a data-driven model can be constructed to achieve the perception of the number of connected devices. Supervised learning methods (such as regression models, deep neural networks) can be used for device number prediction, while unsupervised learning (such as clustering, autoencoders) can be used for speculation under the condition of unlabeled data. Temporal models such as LSTM and Transformer can further improve the timeliness and accuracy of prediction.

[0006] However, the traditional methods for perceiving the number of mobile hotspot network elements still have the limitation of low fineness. In the process of constructing the dataset, most studies simply map the entire PCAP traffic packet to the same number label due to the inability to determine the specific attribution of each traffic packet within the unit time window, resulting in rather serious accuracy problems. The background devices accessing the hotspot do not always occupy the network bandwidth, and there are some periods of silence during which they do not participate in data exchange within the hotspot subnet. Therefore, the discrimination of the number of network elements should be a dynamic process, and misjudgments caused by factors such as device access, exit, and silence need to be considered.

[0007] Therefore, accurately obtaining the real-time device number under a fine-grained window and constructing refined dataset labels are a major challenge for realizing the perception of the number of mobile hotspot network elements. Summary of the Invention

[0008] In view of the above problems, the present invention proposes a method for perceiving the number of mobile hotspot network elements based on hash matching. This method can achieve real-time comparison of hotspot subnet traffic and external export traffic through hash matching, accurately locate the specific attribution of each traffic packet within a fine-grained time window, construct refined dataset labels, and help solve the problem of perceiving the number of mobile hotspot network elements. The core problem of this invention is to accurately obtain the real-time device number under a fine-grained window through a hash algorithm and ensure extremely high real-time performance, reliability, and accuracy. The specific steps of this method are divided into a data processing module, a hash matching module, and a flow label recording module. The data processing module encapsulates the hotspot subnet traffic and export traffic in an offline or online mode, designs a sliding window structure composed of a flow label window and a fine-grained window, and calculates the hash value of the data packet under each fine-grained window for subsequent matching analysis; the hash matching module discriminates the transmission direction of the data packet, ignores the changes caused by NAT conversion, and calculates the same hash value using a specific hash algorithm, providing a core basis for double-end matching; the flow label recording module continuously records the identification information of the data stream whose device attribution has been determined in the flow label window, and performs hash matching on two copies of the data packet under the fine-grained window. According to the matching result or the flow attribution information, the device number under the current fine-grained window is determined. The present invention can be used in various types of network environments, providing a basis for network service operators and network supervision departments to improve service quality, anomaly detection, attack detection, and other measurement tasks.

[0009] To achieve the object of the present invention, the technical solution of the present invention is as follows: A method for perceiving the number of mobile hotspot network elements based on hash matching, which can obtain the real-time device number of the mobile hotspot under a fine-grained window by using a data processing module, a hash matching module, and a flow label recording module. The method includes the following steps:

[0010] Step (1) In the network environment to be measured and corresponding measurement tasks, through an offline mode or an online mode, encapsulate the hotspot subnet traffic and external export traffic, design a sliding window composed of a flow label window and a fine-grained window, and calculate the hash value of the data packet under each fine-grained window;

[0011] Step (2) The hash matching module discriminates the transmission direction of the data packet, ignores all changes generated by the same data packet before and after NAT conversion, calculates the same hash value through a specific hash algorithm, and provides a core judgment basis for double-end matching;

[0012] Step (3) The flow label recording module continuously records the identification information of the data stream whose device attribution has been determined in the flow label window, and performs hash matching on two copies of the data packet under the fine-grained window. According to whether the matching is successful or whether the belonging flow has a determined attribution, the judgment of the device number under the current fine-grained window is completed;

[0013] After all the data in the current fine-grained window have been processed, the statistical result of the real-time device quantity is output, and then a refined dataset label can be constructed to help realize the perception of the number of mobile hotspot network elements.

[0014] Further, the step (1) specifically includes the following sub-steps:

[0015] (1.1) Determine the fine-grained window time t and the flow label window time T ( where t i = t);

[0016] (1.2) Select the offline mode or the online mode according to the task requirements;

[0017] (1.3) The offline mode can be applied to most scenarios: capture data and generate the PCAP traffic packet P on the foreground device and the background device respectively, abstract the foreground device traffic as F mod , and at the same time regard the traffic of all background devices as a whole in chronological order and abstract it as F ori ;

[0018] (1.4) If the foreground device is a Windows platform, the online mode can be selected: listen to the physical network card of the foreground device and the virtual network card named Microsoft Wi-Fi Direct Virtual Adapter#n (n is the network card serial number) respectively to form a real-time data stream, and record them as F mod and F ori ;

[0019] (1.5) Determine the IP addresses (IP mod and IP ori ) and the subnet masks (SNM mod and SNM ori ) of the corresponding networks in F mod and SNM ori ) of the foreground device in F

[0020] (1.6) Set the window size to T, the step size to t, and a non-overlapping sliding window (i.e., the flow label window). Each time the window slides, enumerate the corresponding fine-grained windows in F mod and F ori respectively;

[0021] (1.7) For each data packet p mod or p ori in the fine-grained window, there is f tag = (p.ip, p.port, proto), where p.ip and p.port for p mod are the IP mod and its corresponding port, for pori For IP ori The IP address and its corresponding port of the peer end;

[0022] (1.8) Calculate the hash value h of p mod or p ori and save it in the form of (h, f tag ) to H mod or H ori and hand it over to the flow label recording module for subsequent processing.

[0023] Compared with the prior art, the step (1) has several significant advantages in traffic processing and label generation: by introducing the dual mechanisms of the fine-grained window and the flow label window, the collaborative analysis of short-term behaviors and long-term trends is realized; it supports both offline and online modes, adapts to various actual scenarios, especially in the online mode, it can collect hot spot sharing traffic in a low-invasive real-time manner; by abstracting the foreground and background device traffic into independent data streams respectively, and combining IP and subnet information for accurate identification, the accuracy of label generation is improved; at the same time, the hash matching method is used to store the flow label, which greatly improves the efficiency and scalability of traffic processing, and overall enhances the practicality and robustness of the system in a real and complex network environment.

[0024] Further, the step (2) specifically includes the following sub-steps:

[0025] (2.1) Receive the incoming data packet p;

[0026] (2.2) Set both the source MAC address and the destination MAC address of p to 00:00:00:00:00:00, set the IP protocol, TCP protocol, and UDP protocol checksums to 0, and set the TTL to 0;

[0027] (2.3) If p ∈ F mod , then respectively according to whether IP mod is equal to the source IP or the destination IP of p, determine it as an outbound packet or an inbound packet;

[0028] (2.4) If p ∈ F ori , then with the help of SNM ori , respectively according to whether IP ori and the source IP or the destination IP of p are in the same subnet, determine it as an inbound packet or an outbound packet;

[0029] (2.5) If p is an outbound packet, set the source IP of p to 0.0.0.0 and the source port to 0; if p is an inbound packet, set the destination IP of p to 0.0.0.0 and the destination port to 0;

[0030] (2.6) Calculate the hash value of the modified p through a preset hash algorithm and output it.

[0031] In a mobile hotspot network environment, the network traffic between the foreground device and the background device undergoes network address translation processing, which makes the traditional correlation analysis method based on the original traffic characteristics ineffective. According to the modification of each keyword field in the Ethernet, IP, TCP, and UDP protocols by NAT in different traffic direction scenarios, step (2) eliminates the variable field differences caused by NAT through a normalized hash matching method, realizing accurate traffic correlation across NAT boundaries.

[0032] Further, step (3) specifically includes the following sub-steps:

[0033] (3.1) For each fine-grained window in the flow label window, obtain H under this fine-grained window mod and H ori ;

[0034] (3.2) Enumerate each (h mod , f mod ) element in H tag , and look for whether there exists (h ori , f ori ) in H tag such that h ori = h mod ;

[0035] (3.3) If it exists, it indicates that the device with p.ip in f ori , f tag in the hot subnet participates in hot data transmission under this fine-grained window. Save this p.ip to the IP list, and at the same time save f tag in (h mod , f tag ) to L tag tag , and finally delete the current element from H mod tag ;

[0036] (3.4) If it does not exist, query whether there exists f tag in the current enumerated (h mod , f tag ) in L tag . If it exists, delete the current element from H mod mod ;

[0037] (3.5) Count the number of IPs in the IP list, which is the number of devices participating in hot subnet data transmission under the current fine-grained window. If H modIf it is not empty, increment the number of devices by one (for foreground devices);

[0038] (3.6) Slide the sliding window backward by one fine-grained window and delete L tag f that does not belong to the current flow label window in L tag ;

[0039] (3.7) Output the real-time device quantity in units of fine-grained windows.

[0040] In the actual application test, the hash matching success rate of this method is stably maintained at about 98%, but there are still a small number of data packets that cannot achieve accurate dual-end matching. Through in-depth analysis, it is found that the root cause is that there is a bottleneck in the traffic capture performance of the background device, resulting in some data packets being missed during the acquisition process. To address this issue, step (3) designs a flow label recording module: when a data packet successfully matches the device attribution through the hash algorithm, synchronously record the flow feature information to which the data packet belongs; when subsequent data packets that cannot complete the dual-end determination due to the lack of matching copies appear, retrieve the recorded flow feature information for attribution determination; regularly clear the expired flow attribution information. Through the collaborative working mechanism of hash matching and flow attribution tracking, the accuracy rate of device attribution statistics finally achieved can be increased to an ideal level of nearly 100%, which can be used to determine the multi-device attribution of single-export traffic, accurately obtain the real-time device quantity under fine-grained windows, and thus construct a refined data set label.

[0041] Furthermore, in step (4), at the end of the measurement task, output the final result in step (3) to obtain the statistical result of the real-time device quantity, and then a refined data set label can be constructed to help realize the perception of the number of mobile hot spot network elements.

[0042] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method for perceiving the number of mobile hot spot network elements based on hash matching as described above.

[0043] A computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, they implement the method for perceiving the number of mobile hot spot network elements based on hash matching as described above.

[0044] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0045] (1) The present invention proposes a method for perceiving the number of mobile hotspot network elements based on hash matching, accurately locating the specific attribution of each traffic packet within a fine-grained time window, constructing a refined dataset label, helping to solve the problem of perceiving the number of mobile hotspot network elements, and providing a basis for network service operators and network supervision departments to improve service quality, anomaly detection, attack detection and other measurement tasks.

[0046] (2) The present invention includes designing a data processing flow, supporting many usage scenarios such as offline mode and online mode, uniformly encapsulating the traffic of the hotspot subnet and the external export traffic, and designing a sliding window composed of a flow label window and a fine-grained window, so as to provide a fine-grained discrimination result.

[0047] (3) The present invention includes designing a hash matching method, which discriminates the transmission direction of the data packet, ignores various changes generated before and after NAT conversion of the same data packet, has strong robustness, and provides a core judgment basis for double-end matching.

[0048] (4) The present invention includes designing a flow label matching algorithm, which further reduces the errors caused by possible hash conflicts during data matching and possible packet loss during traffic collection by recording the traffic attribution identifiers that have been matched within the flow label window.

[0049] (5) The method for perceiving the number of mobile hotspot network elements based on hash matching proposed by the present invention can be widely applied to the network environment using NAT technology and is applicable to different measures, having a good application prospect. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 (a) is the framework of the method for perceiving the number of mobile hotspot network elements based on hash matching;

[0051] Figure 2 (b) is the flowchart of the data processing module;

[0052] Figure 3 (c) is the flowchart of the hash matching module;

[0053] Figure 4 (d) is the flowchart of the flow label recording module. DETAILED DESCRIPTION OF THE INVENTION

[0054] The following will detail the technical solutions provided by the present invention in combination with specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.

[0055] Embodiment: A method for perceiving the number of mobile hotspot network elements based on hash matching provided by the present invention has a structural framework as Figure 1 shown, and includes the following steps:

[0056] (1) In the network environment to be measured and under the corresponding measurement tasks, encapsulate the hotspot subnet traffic and the external egress traffic through the offline mode or the online mode, design a sliding window composed of a flow label window and a fine-grained window, and calculate the hash value of the data packets under each fine-grained window.

[0057] The specific process of this step is as Figure 2 shown, and the relevant description is as follows:

[0058] (1.1) Determine that the fine-grained window time t = 1s and the flow label window time T = 30s;

[0059] (1.2) According to the task requirements, select the offline mode or the online mode. In this example, the online mode is adopted;

[0060] (1.3) Listen to the physical network card of the foreground device and the virtual network card named Microsoft Wi-Fi Direct Virtual Adapter #2 respectively to form real-time data streams, which are respectively denoted as F mod and F ori ;

[0061] (1.4) Determine the IP addresses (IP mod = 10.210.13.145 and IP ori = 192.168.137.1) of the foreground device in F mod and F ori and the subnet masks (SNM mod = 255.255.0.0 and SNM ori = 255.255.255.0) of the corresponding networks;

[0062] (1.5) Set the window size to T = 30s, the step size to t = 1s, and a non-overlapping sliding window (i.e., the flow label window). Each time the window slides, enumerate the corresponding fine-grained windows in F mod and F ori respectively;

[0063] (1.6) For each data packet p mod or p ori under the fine-grained window, there is f tag = (p.ip, p.port, proto), where p.ip and p.port for p mod are the IP mod and its corresponding port, and for p ori are the IP address of the peer of IP ori and its corresponding port. For example, for p mod there is f tag=(10.210.13.145,61524,6), for p ori There is tag =(192.168.137.2,54865,6);

[0064] (1.7) Calculate p through the hash matching module mod or p ori The hash value h is (h,f tag ) in the form of H mod or H ori and is handed over to the flow label recording module for subsequent processing.

[0065] (2) The hash matching module determines the transmission direction of the data packet, ignores the changes that occur to the same data packet before and after NAT conversion, and calculates the same hash value through a specific hash algorithm, providing the core judgment basis for dual-end matching.

[0066] The specific process of this step is as follows Figure 3 The relevant description is as follows:

[0067] (2.1) Receive incoming data packet p;

[0068] (2.2) Set the source MAC address and destination MAC address of p to 00:00:00:00:00:00, set the IP protocol, TCP protocol, and UDP protocol checksums to 0, and set TTL to 0;

[0069] (2.3) If p∈F mod , then according to IP mod If the source IP or destination IP is equal to p, it is judged as an outbound packet or an inbound packet. For example, when p.dst_ip = 10.210.13.145, p is an inbound packet;

[0070] (2.4) If p∈F ori , then with the help of SNM ori , respectively according to IP ori If the source IP or destination IP of p is in the same subnet, it is judged as an inbound packet or an outbound packet. For example, when p.src_ip = 192.168.137.2, p is an inbound packet;

[0071] (2.5) If p is an outbound packet, set the source IP of p to 0.0.0.0 and the source port to 0; if p is an inbound packet, set the destination IP of p to 0.0.0.0 and the destination port to 0;

[0072] (2.6) The hash value of the modified p is calculated and output using the preset hash algorithm.

[0073] (3) The flow label recording module continuously records the identification information of the data streams whose device ownership has been determined in the flow label window, and performs hash matching on two copies of the data packets in the fine-grained window. Based on whether the matching is successful or the ownership of the flow has been determined, the judgment of the number of devices in the current fine-grained window is completed.

[0074] The specific process of this step is as Figure 4 shown, and the relevant description is as follows:

[0075] (3.1) For each fine-grained window in the flow label window, obtain the H mod and H ori ;

[0076] (3.2) Enumerate each (h mod , f mod ) element in H tag , and search in H ori to see if there exists (h ori , f tag ) such that h ori = h mod . For example, in H mod and H ori there are respectively:

[0077] (d41d8cd98f00b204e9800998ecf8427e, (10.210.13.145, 61524, 6)),

[0078] (d41d8cd98f00b204e9800998ecf8427e, (192.168.137.2, 54865, 6));

[0079] (3.3) If it exists, it indicates that in this fine-grained window, the device with p.ip = 192.168.137.2 in f ori in the hot spot subnet participated in the hot spot data transmission. Save this p.ip to the IP list, and at the same time save f tag in (h tag , f mod ) = (10.210.13.145, 61524, 6) to L tag , and finally delete the current element from H tag ; tag mod tag ;

[0080] (3.4) If it does not exist, query whether there exists the f mod in the current enumerated (h mod , f tag ) in L tag, if it exists, delete the current element from H mod ;

[0081] (3.5) Count the number of IPs in the IP list, which is the number of devices participating in the hot subnet data transmission under the current fine-grained window. If H mod is not empty, increment the number of devices by one (for the foreground device);

[0082] (3.6) Slide the window backward by one fine-grained window and delete f tag in L that does not belong to the current flow label window tag ;

[0083] (3.7) Output the real-time number of devices in units of fine-grained windows.

[0084] After all the data in the current fine-grained window has been processed in step (4), output the statistical result of the real-time number of devices, and then a refined dataset label can be constructed to help realize the perception of the number of mobile hot network elements.

[0085] The technical means disclosed in the solution of the present invention are not limited to the technical means disclosed in the above embodiments, but also include technical solutions composed of any combination of the above technical features. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and retouches can be made, and these improvements and retouches are also regarded as the protection scope of the present invention.

Claims

1. A method for perceiving the number of mobile hotspot network elements based on hash matching, characterized in that The method includes the following steps: Step (1) In the network environment to be measured and under the corresponding measurement tasks, encapsulate the hot-spot subnet traffic and the outbound traffic through the offline mode or the online mode, design a sliding window composed of a flow label window and a fine-grained window, and calculate the hash value of the data packets under each fine-grained window; Step (2) The hash matching module discriminates the transmission direction of the data packets, ignores various changes generated before and after NAT conversion for the same data packet, and calculates the same hash value through a specific hash algorithm, providing the core judgment basis for dual-end matching; Step (3) The flow label recording module continuously records the identification information of the data streams whose device ownership has been determined in the flow label window, and performs hash matching on two copies of the data packets under the fine-grained window. According to whether the matching is successful or whether the belonging stream has a determined ownership, the judgment of the number of devices under the current fine-grained window is completed; Step (4) After all the data in the current fine-grained window have been processed, output the statistical result of the real-time number of devices, and then a refined data set label can be constructed to help realize the perception of the number of mobile hot-spot network elements.

2. A method for perceiving the number of mobile hot-spot network elements based on hash matching according to claim 1, characterized in that The specific steps of step (1) are as follows: (1.1) Determine the fine-grained window time t and the flow label window time T( where t i = t); (1.2) Select the offline mode or the online mode according to the task requirements; (1.3) The offline mode can be applied to most scenarios: data capture is completed on the foreground device and the background device respectively to generate a PCAP traffic packet P, and the foreground device traffic is abstracted as F mod , and at the same time, the traffic of all background devices is regarded as a whole in chronological order and abstracted as F ori ; (1.4) If the foreground device is a Windows platform, the online mode can be selected: listen to the physical network card of the foreground device and the virtual network card named Microsoft Wi-Fi Direct Virtual Adapter#n (n is the network card serial number) respectively, form a real-time data stream, and record them as F mod and F ori ; (1.5) Determine the IP addresses of the front-end devices in F mod and F ori ), and the subnet masks (SNM mod and SNM ori ) of the corresponding networks; mod and SNM ori ) (1.6) Set the window size to T, the step size to t, and a non-overlapping sliding window (i.e., the flow label window). Each time the window slides, enumerate the corresponding fine-grained windows in F mod and F ori respectively; For each data packet p under a fine-grained window mod or p ori , there is f tag = (p.ip, p.port, porto), where p.ip and p.port for p mod are the IP mod and its corresponding port, and for p ori are the IP ori of the peer IP address and its corresponding port; (1.8) Calculate p through the hash matching module mod or p ori to obtain the hash value h, and save it in the form of (h, f tag ) to H mod or H ori , and then hand it over to the stream label recording module for subsequent processing.

3. A method for perceiving the number of mobile hotspot network elements based on hash matching according to claim 1, characterized in that, The specific method of step (2) is as follows: (2.1) Receive the incoming data packet p; (2.2) Set the source MAC address and the destination MAC address of p to 00:00:00:00:00:00, set the IP protocol, TCP protocol, and UDP protocol checksums to 0, and set the TTL to 0; (2.3) If p ∈ F mod , then respectively according to the source IP or destination IP mod equal to p, determine it as an outbound packet or an inbound packet; (2.4) If p ∈ F ori , then by means of SNM ori , respectively in accordance with IP ori and the source IP or destination IP of p is in the same subnet, it is determined as an inbound packet or an outbound packet; (2.5) If p is an outbound packet, set the source IP of p to 0.0.0.0 and the source port to 0; if p is an inbound packet, set the destination IP of p to 0.0.0.0 and the destination port to 0; (2.6) Calculate the hash value of the modified p through a preset hash algorithm and output it.

4. A method for perceiving the number of mobile hotspot network elements based on hash matching according to claim 1, characterized in that The specific method of step (3) is as follows: (3.1) For each fine-grained window in the flow label window, obtain H under this fine-grained window mod and H ori ; (3.2) Enumerate each (h mod , f mod ) element in H tag and check if there exists (h ori , f ori ) in H tag such that h ori = h mod ; (3.3) If it exists, it indicates that within this fine-grained window, the device with the IP address p.ip in the hot subnet, where the IP address is (h ori , f tag ), has participated in hot data transmission. Save this p.ip to the IP list. At the same time, save f tag in (h mod , f tag ) to L tag . Finally, delete the current element from H tag ; mod ​ If it does not exist, query L tag to see if the currently enumerated (h mod , f tag ) contains f tag . If it does, delete the current element from H mod ; (3.5) Count the number of IPs in the IP list, which is the number of devices participating in the hot subnet data transmission under the current fine-grained window. If H mod is not empty, then increment the number of devices by one (for the foreground device); (3.6) Slide the sliding window backward by one fine-grained window and delete L tag f that does not belong to the current flow label window in tag ; (3.7) Output the real-time number of devices in units of fine-grained windows.

5. The method for perceiving the number of mobile hotspot network elements based on hash matching according to claim 1, wherein Step (4) is executed at the end of the entire measurement task, and the final result in step (3) is output.

6. A mobile hotspot network element quantity perception system based on hash matching, characterized in that A system for implementing the method for perceiving the number of mobile hot-spot network elements based on hash matching according to any one of claims 1-5, the system includes three functional modules: a data processing module, a hash matching module, and a flow label recording module. The data processing module encapsulates the hot-spot subnet traffic and the outbound traffic in the offline or online mode, and designs a sliding window structure to calculate the hash value of the data packets under each fine-grained window for subsequent matching analysis; The hash matching module discriminates the transmission direction of the data packets, ignores the changes caused by NAT conversion, and uses a specific hash algorithm to calculate the same hash value, providing the core basis for dual-end matching; the flow label recording module continuously records the data streams whose ownership has been determined, and performs hash matching on the data packet copies under the fine-grained window, and determines the number of devices under the current fine-grained window according to the matching result or the stream ownership information.

7. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the program, it implements the method for perceiving the number of mobile hotspot network elements based on hash matching as described in any one of the above-mentioned claims 1 to 5.

8. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the computer instruction is executed by the processor, it implements the method for perceiving the number of mobile hotspot network elements based on hash matching as described in any one of claims 1-6.