Equipment fingerprint extraction method and equipment fingerprint transmission method
By reading the operating system, kernel version and CPU architecture information of IoT devices, combined with DNS tunneling, the accuracy and stability of fingerprint extraction of IoT devices are solved, and efficient and stable device identification and monitoring are achieved.
Patent Information
- Application Number
- CN202510319992.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-07-18
AI Technical Summary
The prior art has problems of insufficient accuracy, poor stability and limited applicability in fingerprint extraction of IoT devices, especially in heterogeneous environments and diversified protocols, which are difficult to achieve efficient and accurate device identification.
By reading the operating system, kernel version, CPU architecture and file attributes of the target device, generating the device fingerprint, and using DNS tunnel for compliance transmission, the device fingerprint is achieved accurately extracted and stable transmission of the device fingerprint.
Without additional resources, it provides accurate and stable equipment fingerprint extraction and transmission capabilities. It is suitable for a variety of IoT device environments, with anti-interference and concealment, and is suitable for large-scale network surveying and mapping and network security monitoring.
Smart Images

Figure CN120342660A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things security and relates to a method for extracting device fingerprints and a method for transmitting device fingerprints. Background Art
[0002] Device fingerprint is an important topic in the field of Internet of Things security. The rapid development of Internet of Things technology has promoted the wide application of intelligent devices. From smart homes to industrial control systems, various Internet of Things devices have been deeply integrated into people's daily life and production environment. However, with the explosion of the number of Internet of Things devices and the diversification of application scenarios, the management difficulty has been greatly increased. Network threats such as vulnerability exploitation, botnets, and data theft in the Internet of Things have further affected the stability and security of the Internet of Things. Through device fingerprints, efficient discovery and management of a large number of Internet of Things devices can be achieved, and at the same time, comprehensive perception and prevention of potential security risks can be realized, which plays an important role in ensuring the security of the Internet of Things ecosystem. Therefore, fingerprint extraction for Internet of Things devices is of great significance.
[0003] At present, device fingerprint extraction for Internet of Things mainly relies on network traffic combined with machine learning technology. The network traffic generated by different Internet of Things devices during communication has unique behavioral patterns, such as protocol type, packet size distribution, time interval characteristics, etc. By analyzing these patterns, fingerprints of devices can be generated for identifying device types or manufacturers. However, the above methods have certain limitations: First, the recognition granularity of machine learning models is limited. Different devices may exhibit similar network behaviors, especially when using the same communication protocol or vendor - common firmware, fingerprint extraction may be confused and high precision cannot be guaranteed. Second, the network environment (such as latency, packet loss, bandwidth limitation, etc.) may interfere with traffic characteristics and affect the accuracy and stability of fingerprint extraction. In addition, there are a wide variety of protocols used by Internet of Things devices (such as MQTT, CoAP, HTTP, Proprietary protocols, etc.), and there are technical challenges in uniformly extracting fingerprint features for all protocols, and it is difficult to form a general - purpose extraction method for diverse devices. Finally, limited by the heterogeneous environment and trimmed systems of Internet of Things devices, existing methods are difficult to back - transmit data from the target system internally to support improving fingerprint accuracy. Therefore, how to implement a method for extracting and transmitting Internet of Things device fingerprints with strong generality, good stability, and high precision is an urgent problem to be solved at present. Summary of the Invention
[0004] In view of the above problems, the present invention proposes a method for extracting device fingerprints and a method for transmitting device fingerprints. On the premise of being able to obtain the permissions of the target device, by reading the content of specific files or the responses of specified commands, and traversing the established attributes of all files in the specified directory, the construction and transmission of Internet of Things device fingerprints are realized without the need for additional operating environments and computing resources. Generally, an Internet of Things device fingerprint refers to a set of unique and distinguishable feature identifiers generated based on hardware characteristics, software attributes, or operating environment information. In the present invention, the representative constituent elements of the fingerprint include the operating system, kernel version, CPU architecture, and file system features. A suitable regular module is set to quickly extract the above elements for device fingerprint construction. Facing the heterogeneous environment and trimmed systems of Internet of Things devices, a suitable transformation module is set to convert the device fingerprint into a legal DNS record form, and then a DNS tunnel is constructed using the existing conditions of the system to realize the backhaul of the device fingerprint.
[0005] The present invention provides a method for extracting device fingerprints, including:
[0006] Obtain the feature information of the target device, where the feature information includes all information of at least one of the operating system, kernel name, kernel version, and CPU architecture, and extract fingerprint elements from the feature information;
[0007] Obtain the specified directory of the target device to generate another fingerprint element;
[0008] Aggregate the two fingerprint elements to obtain the device fingerprint of the target device.
[0009] Further, the specified directory is at least one of / bin, / lib, and / usr / lib.
[0010] Further, the other fingerprint element includes the directory tree branch factor of the specified directory.
[0011] Further, the aggregation is performed using the JSON data specification.
[0012] Further, when any fingerprint element is missing, set the fingerprint element with the default value unknown.
[0013] The present invention also provides a method for transmitting device fingerprints, including:
[0014] Configure the data receiving address of the fingerprint receiving end;
[0015] Perform a compliance operation on the device fingerprint according to the data receiving address to obtain a compliant device fingerprint;
[0016] Transmit the compliant device fingerprint to the fingerprint receiving end and extract the device fingerprint, thereby completing the device fingerprint transmission.
[0017] Further, the compliance operation adopts DNS compliance.
[0018] Further, the transmission is completed through a DNS tunnel by using the PING system instruction.
[0019] The present invention also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the computer program is executed by the processor to implement the steps of the above method.
[0020] The present invention also provides a storage medium storing a computer program, and the received computer program implements the steps of the above method when executed.
[0021] The beneficial effects of the present invention are as follows:
[0022] Due to the massive heterogeneous environment and system trimming characteristics of Internet of Things devices, by directly reading system information and file attributes, without the support of additional software or hardware resources, it can provide accurate and stable detection capabilities for large-scale network mapping or monitoring systems, is applicable to a variety of Internet of Things device environments and does not require cross-compilation adaptation. The device fingerprint transmission is completed through a legal DNS protocol, with strong anti-interference, concealment and versatility, and has important practical significance in scenarios such as Internet of Things device identification and network security monitoring. Description of the Drawings
[0023] Figure 1 It is a schematic flow chart of fingerprint extraction.
[0024] Figure 2 It is a schematic flow chart of fingerprint transmission. Detailed Embodiments
[0025] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention and make the objectives, features and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and embodiments.
[0026] The embodiments of the present invention provide a device fingerprint extraction method and a device fingerprint transmission method, taking the TP-Link TL-WR841N router as an example of the target device.
[0027] In the first aspect of this embodiment, an Internet of Things device fingerprint extraction and transmission method is provided, and the specific process is as Figure 1 shown, including the following steps:
[0028] Step S110: Obtain the permission of the target device D and read the established file F = {f1, f2,..., f n}, including / etc / os-release, / etc / lsb-release, / proc / version, / etc / hostname, / proc / cpuinfo; execute the established commands C = {c1, c2,..., c n}, including uname, lscpu, dmesg. Then obtain the content I containing the full information of the operating system, kernel name, kernel version, and CPU architecture respectively os 、I kn 、I kv 、I arch .
[0029] # Read file content
[0030] cat / etc / os-release
[0031] # Output Ios: NAME="OpenWrt" VERSION="19.07.8" ID="openwrt" [...]
[0032] cat / proc / version
[0033] # Output Ikn: Linux version 5.4.143 (builder@buildhost) (gcc version 8.4.0) [...]
[0034] # Execute system command
[0035] uname -a
[0036] # Output Ikv: Linux OpenWrt 5.4.143 #0 SMP Wed Sep 1 16:43:58 2021 mips GNU / Linux
[0037] lscpu
[0038] # Output Iarch: Architecture: mips | Byte Order: Little Endian | CPU(s): 1 | Model: MIPS24Kc V7.4
[0039] Step S120: Extract fingerprint elements from the content I of the full information os 、I kn 、I kv 、I arch according to the regular expression: operating system fingerprint element F os 、kernel name fingerprint element F kn 、kernel version fingerprint element Fkv 1. CPU architecture fingerprint element F arch .
[0040] # Match Ios, Ikn, Ikv, Iarch through regular expressions
[0041] Fos = OpenWrt
[0042] Fkn = Linux
[0043] Fkv = 5.4.143
[0044] Farch = mips
[0045] Step S130: Obtain the specified directories " / bin, / lib, and / usr / lib" of the target device D. Select " / bin, / lib, and / usr / lib" as typical user read-only directories because they are typical user read-only directories that contain system-required binary files and library files. These directories usually do not change due to user operations, so they can better reflect the characteristics of the firmware version.
[0046] Calculate the number of files, the cumulative value of file sizes, the directory tree branching factor, and the maximum depth of the directory hierarchy in the specified directory, and connect the above metrics with dots (.) to generate the firmware feature fingerprint element Ffirm with multi-dimensional firmware characteristics. This method is simple and direct, facilitating the comparison of the characteristics of different firmwares. Number of files: the total number of all files in the specified directory; Cumulative value of file sizes: the total size of all files in bytes; Directory tree branching factor: the average number of subdirectories per directory, that is, the average out-degree of nodes in the directory tree, which reflects the complexity of the directory structure; Maximum depth of the directory hierarchy: the length of the path from the root directory to the deepest leaf node in the directory tree, reflecting the depth of the directory hierarchy.
[0047] In another embodiment, the specified directory can use its subset or other user read-only directories, and make flexible adaptive adjustments according to the user's computing efficiency requirements or specific application scenarios. Compared with the method without firmware feature fingerprint elements, calculating Ffirm can more accurately identify different firmware versions on the same model device. This is crucial for security and maintenance and is applicable to detecting outdated or vulnerable firmware versions.
[0048] # Use system commands such as find, ls, awk to count the number of files, the cumulative value of file sizes, the directory tree branching factor, and the maximum depth of the directory hierarchy in the / bin, / lib, and / usr / lib directories.
[0049] Ffirm = 1337.412354274.12.6
[0050] Step S140: Detect Fos 、F kn 、F kv 、F arch and F firm各 Whether the fingerprint element is missing, if missing, it is illegal, and the corresponding missing fingerprint element is set to the default value F default =Unknown settings.
[0051] #No missing cases
[0052] Step S150: F os 、F kn 、F kv 、F arch and F firm Fingerprint elements are aggregated according to the JSON data specification, and the device fingerprint F of the target device is extracted based on the designed key-value pairs. D ={“OS”:F os , “Kernel”: F kn ,”Kernel_version”:F kv ”Arch”:F arch ”Firm”:F firm}.
[0053] F D ={"OS":"OpenWrt","Kernel":"Linux","Kernel_version":"5.4.143","Arch":"mi
[0054] ps","Firm":"1337.412354274.12.6"}
[0055] Step 160: Fingerprint the device F D , write it to the specified file and save it.
[0056] The second aspect of the present invention provides a device fingerprint transmission method, the specific process is as follows Figure 2 As shown, the following steps are included:
[0057] Step S210: Read data from the specified file to obtain the device fingerprint F to be transmitted D .
[0058] Step S220: Generate a data receiving address at the fingerprint receiving end, that is, a third-level domain name belonging to a specific DNS primary domain, thereby receiving DNS requests and resolving compliant DNS records.
[0059] #Configure the fingerprint receiving module to generate a third-level domain name for this fingerprint reception
[0060] recv.example.cn
[0061] Step S230: DNS compliance of the device fingerprint F D . Replace the interfering characters such as spaces, hyphens, underscores, dots, slashes, etc. in the fingerprint with their corresponding English abbreviations: space, hyp, uds, dot, line, and then sequentially assign the fingerprint elements F D in the device fingerprint F os , F kn , F kv , F arch , F firm to different levels of subdomains to obtain the compliant DNS record form F DNS = F os .F kn .F kv .F arch .F firm .recv.example.cn for effective backhaul and parsing.
[0062] # Replace the fingerprint to obtain the domain name carrying fingerprint data that complies with the DNS record specification
[0063] F DNS = OpenWrt.Linux.5dot4dot143.mips.1337dot412354274dot12dot6.recv.example.cn
[0064] Step S240: Use the PING system instruction to transmit F DNS to the fingerprint receiver through the DNS tunnel.
[0065] # Construct and execute the instruction
[0066] ping -c 1 OpenWrt.Linux.5dot4dot143.mips.1337dot412354274dot12dot6.recv.example.cn
[0067] Step S250: Process the data F p received by the fingerprint receiving module U r through the fingerprint parsing module U DNS , and extract the fingerprint elements from each level of subdomain name to form the device fingerprint F D = {"OS": F os , "Kernel": F kn , "Kernel_version": F kv , "Arch": F arch , "Firm": Ffirm}, to implement the transmission of device fingerprints.
[0068] # DNS query request received
[0069] OpenWrt.Linux.5dot4dot143.mips.1337dot412354274dot12dot.recv.example.cn
[0070] # Process the above data FDNS and extract the restored device fingerprint FD step by step
[0071] FD = {"OS": "OpenWrt", "Kernel": "Linux", "Kernel_version": "5.4.143", "Arch": "m ips", "Firm": "1337.412354274.12.6"}
[0072] To evaluate the efficiency of the method FPT of the present invention in extracting device fingerprint features, a comparative experiment for different target devices was conducted in this embodiment, and the results are shown in Table 1.
[0073] Table 1
[0074]
[0075]
Claims
1. A method for extracting device fingerprints, comprising: Obtaining the feature information of the target device, where the feature information includes the full amount of information of at least one of the operating system, kernel name, kernel version, and CPU architecture, and extracting fingerprint elements from the feature information; Obtaining the specified directory of the target device and generating another fingerprint element; Aggregating the two fingerprint elements to obtain the device fingerprint of the target device.
2. The method according to claim 1, wherein The specified directory is at least one of / bin, / lib, and / usr / lib.
3. The method according to claim 2, wherein The other fingerprint element includes the directory tree branch factor of the specified directory.
4. The method according to claim 1, characterized in that, The aggregation is performed using the JSON data specification.
5. The method according to any one of claims 1-4, characterized in that, When any fingerprint element is missing, set the fingerprint element with the default value "unknown".
6. A method for transmitting device fingerprints applicable to any of the methods described in claims 1-5, comprising: Configuring the data receiving address of the fingerprint receiving end; Performing a compliance operation on the device fingerprint according to the data receiving address to obtain a compliant device fingerprint; Transmitting the compliant device fingerprint to the fingerprint receiving end and extracting the device fingerprint, thereby completing the device fingerprint transmission.
7. The method according to claim 6, wherein The compliance operation adopts DNS compliance.
8. The method according to claim 7, wherein Using the PING system instruction to complete the transmission through the DNS tunnel.
9. An electronic device, comprising a memory and a processor, where the memory stores a computer program, and the computer program is executed by the processor to implement the steps of the methods described in claims 1-8.
10. A storage medium stores a computer program, and the computer program implemented when executed implements the steps of the methods described in claims 1-8.