Access mode detection method, device, equipment, system and medium

By collecting data characteristics of terminal devices at the access layer and identifying the access method of private terminal devices in the park network, management difficulties and security risks caused by private connection of users in the park network are solved, and a more timely and comprehensive detection effect is achieved.

CN120389870APending Publication Date: 2025-07-29HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410129645.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-29
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

There is a phenomenon of user private connection in the park network, resulting in network management difficulties and security risks. The existing centralized anti-private connection method is untimely detection and poor security performance.

Method used

The data characteristics of the terminal device are collected at the access layer, including message characteristics, flow behavior characteristics, network characteristics or device physical characteristics. Through these characteristics, the access method of the terminal device is identified to achieve more timely and comprehensive private access detection.

Benefits of technology

It improves the accuracy and timeliness of private access detection, and can quickly identify terminal devices that share and disguise addresses of multiple users to ensure network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389870A_ABST
    Figure CN120389870A_ABST
Patent Text Reader

Abstract

The invention discloses an access mode detection method, device, equipment, system and medium, and relates to the technical field of communication. The method comprises the steps that data features of data transmitted by access equipment are collected, the data features indicate features of terminal equipment transmitting the data, the terminal equipment is connected with the access equipment, and the data features comprise at least one of message features, flow behavior features, network features or equipment physical features; and determining an access mode of the terminal equipment based on the data characteristics. The data features of the data transmitted by the access device of the access layer are collected, so that the access mode can be detected when the data arrives at the access layer, and compared with a centralized anti-private access method, the detection of the data which arrives at the access layer but does not arrive at the core layer can be compensated, and the detection of the access mode is more timely and more comprehensive. And moreover, the types of the collected data features are more, so that the probability of detecting the private connection terminal equipment is higher, and the detection accuracy of the access mode is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and particularly to a method, apparatus, device, system, and medium for detecting access modes. Background Art

[0002] In the field of communication technologies, terminal devices in a campus network can access the network only through authorized authentication. However, there is a widespread phenomenon of unauthorized connection by users in the campus network, which makes it difficult to manage the campus network. Herein, unauthorized connection means accessing the network without authorized authentication. For example, accessing multiple terminal devices privately by connecting a router without authorization brings security risks to the network; or accessing multiple terminal devices privately by sharing the wireless network of a terminal device results in unauthorized use of the network by users; or expanding network interfaces by connecting a hub without authorization may cause network loops and even make the network unavailable.

[0003] In the related art, a centralized anti-unauthorized connection method is adopted, where the traffic of the core layer switch is mirrored to an unauthorized connection detection engine, and the unauthorized connection detection engine analyzes the mirrored traffic to detect unauthorized terminal devices based on the analysis results. When an unauthorized terminal device is detected, an access control list (ACL) is sent to the core layer switch so that the core layer switch blocks the terminal device according to the ACL.

[0004] In the above centralized anti-unauthorized connection method, since the traffic needs to reach the core layer switch for detection and the traffic needs to be mirrored from the core layer switch to the unauthorized connection detection engine for further detection, there are problems of untimely detection and poor security performance. Summary of the Invention

[0005] This application provides a method, apparatus, device, system, and medium for detecting access modes, which are used to detect the access modes of terminal devices connected to a network.

[0006] In a first aspect, this application provides a method for detecting an access mode. The method includes: collecting data characteristics of data transmitted by an access device, where the data characteristics indicate the characteristics of the terminal device transmitting the data, the terminal device is connected to the access device, and the data characteristics include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics; determining the access mode of the terminal device based on the data characteristics.

[0007] In this method, since the data characteristics transmitted by the access devices at the access layer are collected, the detection of the access mode can be performed when the data reaches the access layer. Compared with the centralized anti-illegal connection method in the related art, it can make up for the detection of the data that reaches the access layer but does not reach the core layer, making the detection of the access mode more timely and comprehensive. Moreover, the types of data characteristics that can be collected by the access layer are relatively numerous, making the probability of detecting the illegally connected terminal device greater and improving the accuracy of the detection of the access mode.

[0008] In a possible implementation manner, the data characteristics include multiple packet characteristics; determining the access mode of the terminal device based on the data characteristics may include identifying the operating system under the access port of the terminal device based on the multiple packet characteristics; when the operating systems under the access port are different, determining the access mode of the terminal device as illegal connection. Wherein, the access port of the terminal device is the port on the access device connected to the terminal device.

[0009] In this way, the operating system under the access port is identified through the packet characteristics. Different operating systems indicate that there are multiple operating systems accessing the network through the access port. Multiple operating systems represent multiple independently running user programs, that is, there is a phenomenon of multi-user sharing under this access port. In the case where the access mode is not illegal connection, one port of the access device corresponds to one operating system. Therefore, by identifying different operating systems, the access mode of the terminal device can be quickly and accurately detected as illegal connection.

[0010] In a possible implementation manner, identifying the operating system under the access port of the terminal device based on the multiple packet characteristics may include identifying the address information under the access port of the terminal device based on the multiple packet characteristics; when the address information under the access port is the same, identifying the operating system under the access port of the terminal device based on the multiple packet characteristics; the method further includes, when the address information under the access port is different, determining the access mode of the terminal device as illegal connection.

[0011] In this way, first, the address information under the access port is identified through the packet characteristics. Different address information indicates that there are multiple user terminals with different addresses accessing the network through this access port. In the case where the access mode is not illegal connection, one port of the access device corresponds to one user terminal. Therefore, by identifying different address information, the access mode of the terminal device can be quickly and accurately detected as illegal connection. When the address information is the same, there may be two cases. The first case is that the access mode of the terminal device connected to the access port is not illegal connection. The second case is that multiple user terminals disguise themselves as the same address information for data transmission. Furthermore, when it is determined that the address information is the same, the operating system is further identified for illegal connection detection to ensure the accuracy of the illegal connection detection.

[0012] In a possible implementation, the data feature includes a traffic behavior feature; determining the access mode of the terminal device based on the data feature may include obtaining the deviation distance between the traffic behavior feature and a reference feature, where the reference feature is the traffic behavior feature of the data transmitted by a terminal device with a non-illegal access mode; in the case where the deviation distance is greater than the deviation threshold, determining the access mode of the terminal device as illegal access.

[0013] Since the traffic behavior feature of the data transmitted by a terminal device with a non-illegal access mode is different from that of the data transmitted by a terminal device with an illegal access mode. For example, a terminal device with a non-illegal access mode corresponds to a single terminal, and a terminal device with an illegal access mode corresponds to multiple terminals. The traffic behavior feature of the data transmitted by a single terminal device is different from that of the data transmitted by multiple terminal devices. Therefore, by comparing the deviation between the traffic behavior feature of the data transmitted by the collected terminal device and the traffic behavior feature of the data transmitted by a terminal device with a non-illegal access mode, the access mode of the terminal device as illegal access can be detected quickly and accurately.

[0014] In a possible implementation, the data feature includes at least one of a network feature or a device physical feature; determining the access mode of the terminal device based on the data feature may include identifying the type of the terminal device based on at least one of the network feature or the device physical feature; in the case where the type of the terminal device is a router or a hub, determining the access mode of the terminal device as illegal access.

[0015] Wherein, a router or a hub is a device for connecting multiple terminals together. Since in the case of a non-illegal access mode, the terminal device connected by the access device corresponds to a single terminal, therefore, by identifying a router or a hub, the access mode of the terminal device as illegal access can be detected quickly and accurately. Moreover, on the basis of being able to detect that the access mode of the terminal device is illegal access, it is also possible to determine whether the illegal access type is an illegal router or an illegal hub, making the result of the illegal access detection more accurate. This illegal access type can also provide help for the subsequent implementation of blocking illegal access.

[0016] In a possible implementation, after determining the access mode of the terminal device based on the data feature, in the case where the access mode of the terminal device is illegal access, the data transmission of the terminal device can be blocked. To avoid network security problems caused by the terminal device with illegal access and facilitate network management and maintenance. Optionally, the access device can directly block the data transmission of the terminal device, or send the illegal access information of the terminal device to the management device, and the management device blocks the data transmission of the terminal device based on the illegal access information. Thus, two blocking paths are provided, making the blocking means more flexible. Among them, blocking by the access device can save the overhead of the management device, and blocking by the management device can reduce the amount of data processed by the access device.

[0017] In a possible implementation manner, the methods for blocking data transmission of a terminal device include but are not limited to: closing the access port of the terminal device so that the access port no longer receives data; or, adding the address information of the terminal device to a blacklist, where the blacklist is used to block data transmission of the terminal device corresponding to the address information in the blacklist, so that the access device can stop forwarding data including the address information; or, logging off the user in the online state on the terminal device so that the terminal device exits the network, that is, the terminal device cannot send data to the access device. Thus, three methods for blocking data transmission of the terminal device are provided, enabling flexible selection of different blocking methods according to different scenarios.

[0018] In a possible implementation manner, the data transmitted by the access device is data flowing from the terminal side to the network side, that is, the data flow direction of the collected data is the upstream direction from the terminal side to the network side. This enables the method to accurately perform unauthorized connection detection on the upstream data, avoid misjudgment caused by detecting downstream data, and improve the accuracy of unauthorized connection detection.

[0019] In a possible implementation manner, before collecting the data characteristics of the data transmitted by the access device, a private connection detection configuration command sent by the management device is received, and then based on the private connection detection configuration command, the collection of the data characteristics of the data transmitted by the access device is triggered. In this way, the collection of data characteristics can be flexibly triggered according to the private connection detection configuration command, that is, private connection detection is triggered, and different private connection detection configuration commands can be set according to different user requirements, making the implementation of private connection detection more in line with user needs.

[0020] In a possible implementation manner, the methods for collecting the data characteristics of the data transmitted by the access device include collecting data characteristics during the transmission of the data, that is, collecting along with the flow; or, first copying the data transmitted by the access device to obtain copied data, and then collecting the data characteristics of the copied data. Thus, two methods for collecting data characteristics are provided, making the collection of data characteristics more flexible. Among them, collecting along with the flow can improve the collection efficiency of data characteristics, and collecting copied data can avoid affecting the data transmission.

[0021] In a possible implementation manner, the access device is the first-hop forwarding device for the data sent by the terminal device, that is, the terminal device is directly connected to the access device. In this way, the access device is a device near the network edge on the terminal side. By performing unauthorized connection detection at the network edge, unauthorized connection detection of all data entering the network can be achieved, improving the comprehensiveness of unauthorized connection detection and the security of the network. Moreover, the data transmitted at the network edge has not been processed by network device forwarding, and more characteristics indicating the terminal device can be retained. Therefore, the data characteristics collected based on the data transmitted at the network edge are more comprehensive.

[0022] Second aspect, the present application provides a detection method for another access mode. The method includes: receiving the unauthorized connection information of the terminal device sent by the access device, where the unauthorized connection information indicates that the access mode of the terminal device is unauthorized connection; and sending an unauthorized connection warning message.

[0023] In this method, when the terminal device is unauthorizedly connected, an unauthorized connection warning message can be sent in a timely manner, enabling the user to process the unauthorizedly connected terminal device in a timely manner, thereby improving the network security.

[0024] In a possible implementation manner, after receiving the unauthorized connection information of the terminal device sent by the access device, the transmission of data by the terminal device can also be blocked. This is to avoid network security problems caused by the unauthorizedly connected terminal device and ensure the security of the data in the network.

[0025] In a possible implementation manner, the manner of blocking the transmission of data by the terminal device includes but is not limited to: sending a shutdown command to the access device, where the shutdown command is used for the access device to close the access port of the terminal device; or, sending a blacklist to the access device, where the blacklist includes the address information of the terminal device, and the blacklist is used for the access device to block the transmission of data by the terminal device corresponding to the address information in the blacklist; or, sending a logout command to the access device, where the logout command is used for the access device to log out the user on the terminal device that is in the online state. In this way, three blocking methods are provided, and a suitable blocking method can be flexibly selected based on different scenarios.

[0026] In a possible implementation manner, after receiving the unauthorized connection information of the terminal device sent by the access device, it further includes: visually presenting the unauthorized connection information of the terminal device, where the unauthorized connection information includes at least one of the MAC (medium access control) address, internet protocol (IP) address, access port, access time, unauthorized connection type, or unauthorized connection determination reason. In this way, the unauthorized connection information is visually presented, enabling the user to clearly and intuitively see the unauthorized connection situation and facilitating the user's network operation and maintenance management.

[0027] In a possible implementation manner, before receiving the unauthorized connection information of the terminal device sent by the access device, a private connection detection configuration command is also sent to the access device, so that the access device triggers the acquisition of the data characteristics of the data transmitted by the access device based on the private connection detection configuration command, and determines the access mode of the terminal device based on the data characteristics.

[0028] Third aspect, a detection device for an access mode is provided. The device includes:

[0029] A collection module, configured to collect data features of data transmitted by an access device, where the data features indicate features of a terminal device transmitting the data, the terminal device is connected to the access device, and the data features include at least one of packet features, flow behavior features, network features, or device physical features;

[0030] A determination module, configured to determine an access mode of the terminal device based on the data features.

[0031] In a possible implementation manner, the data features include multiple packet features; the determination module is configured to identify an operating system under an access port of the terminal device based on the multiple packet features; when the operating systems under the access port are different, determine that the access mode of the terminal device is unauthorized access.

[0032] In a possible implementation manner, the determination module is configured to identify address information under an access port of the terminal device based on the multiple packet features; when the address information under the access port is the same, identify an operating system under the access port of the terminal device based on the multiple packet features;

[0033] The determination module is further configured to, when the address information under the access port is different, determine that the access mode of the terminal device is unauthorized access.

[0034] In a possible implementation manner, the data features include flow behavior features; the determination module is configured to obtain a deviation distance between the flow behavior features and reference features, where the reference features are flow behavior features of data transmitted by a terminal device with a non-unauthorized access mode; when the deviation distance is greater than a deviation threshold, determine that the access mode of the terminal device is unauthorized access.

[0035] In a possible implementation manner, the data features include at least one of network features or device physical features; the determination module is configured to identify a type of the terminal device based on at least one of the network features or device physical features; when the type of the terminal device is a router or a hub, determine that the access mode of the terminal device is unauthorized access.

[0036] In a possible implementation manner, the apparatus further includes: a blocking module, configured to block data transmission of the terminal device when the access mode of the terminal device is unauthorized access. Alternatively, the apparatus further includes: a sending module, configured to send unauthorized access information of the terminal device to a management device when the access mode of the terminal device is unauthorized access, where the unauthorized access information is used for the management device to block data transmission of the terminal device.

[0037] In a possible implementation manner, the blocking module is configured to close an access port of the terminal device; or add address information of the terminal device to a blacklist, where the blacklist is used to block data transmission of a terminal device corresponding to the address information in the blacklist; or log off a user in an online state on the terminal device.

[0038] In a possible implementation, the data transmitted by the access device is data flowing from the terminal side to the network side.

[0039] In a possible implementation, the apparatus further includes: a receiving module, configured to receive a private connection detection configuration command sent by a management device; in this case, a collection module, configured to collect data characteristics of the data transmitted by the access device based on the private connection detection configuration command.

[0040] In a possible implementation, the apparatus further includes: a replication module, configured to replicate the data transmitted by the access device to obtain replicated data; in this case, a collection module, configured to collect data characteristics of the replicated data.

[0041] In a possible implementation, the access device is the first-hop forwarding device for the data sent by the terminal device.

[0042] In a fourth aspect, there is provided a detection apparatus for another access method, the apparatus including:

[0043] a receiving module, configured to receive private connection information of a terminal device sent by an access device, where the private connection information indicates that the access method of the terminal device is a private connection;

[0044] an alarm module, configured to issue a private connection alarm message.

[0045] In a possible implementation, the apparatus further includes: a blocking module, configured to block data transmission of the terminal device.

[0046] In a possible implementation, the blocking module is configured to send a shutdown instruction to the access device, where the shutdown instruction is used for the access device to close the access port of the terminal device; or, send a blacklist to the access device, where the blacklist includes the address information of the terminal device, and the blacklist is used for the access device to block data transmission of the terminal device corresponding to the address information in the blacklist; or, send a logout instruction to the access device, where the logout instruction is used for the access device to log out the user in the online state on the terminal device.

[0047] In a possible implementation, the apparatus further includes: a visualization display module, configured to visually display the private connection information of the terminal device, where the private connection information includes at least one of a MAC address, an IP address, an access port, an access time, a private connection type, or a private connection determination reason.

[0048] In a possible implementation, the apparatus further includes: a sending module, configured to send a private connection detection configuration command to the access device, where the private connection detection configuration command is used for the access device to collect data characteristics of the data transmitted by the access device and determine the access method of the terminal device based on the data characteristics.

[0049] Fifth aspect, a detection device for access mode is provided. The device includes a memory and a processor; at least one computer instruction is stored in the memory, and the at least one computer instruction is loaded and executed by the processor, so that the detection device for access mode implements the access mode detection method in the first aspect or any possible implementation manner of the first aspect, or so that the detection device for access mode implements the access mode detection method in the second aspect or any possible implementation manner of the second aspect.

[0050] Sixth aspect, a detection system for access mode is provided. The system includes an access device and a management device. The access device is used to execute the access mode detection method in the first aspect or any possible implementation manner of the first aspect, and the management device is used to execute the access mode detection method in the second aspect or any possible implementation manner of the second aspect.

[0051] Seventh aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the instruction is loaded and executed by the processor, so that the computer implements the access mode detection method in the above aspects.

[0052] Eighth aspect, a computer program (product) is provided. When the computer program is executed by a computer, it can cause the processor or the computer to execute the access mode detection method in the above aspects.

[0053] Ninth aspect, a chip is provided, including a processor, which is used to call and run the instruction stored in the memory, so that the computer installed with the chip executes the access mode detection method in the above aspects.

[0054] Tenth aspect, another chip is provided, including: an input interface, an output interface, a processor and a memory. The input interface, the output interface, the processor and the memory are connected through an internal connection path. The processor is used to execute the code in the memory. When the code is executed, it causes the computer installed with the chip to execute the access mode detection method in the above aspects.

[0055] It should be understood that the beneficial effects obtained by the technical solutions and corresponding possible implementation manners of the third aspect to the tenth aspect of this application can refer to the technical effects of the first aspect and the second aspect and their corresponding possible implementation manners above, and will not be elaborated here. Description of the Drawings

[0056] Figure 1 It is a schematic diagram of a campus network connection structure provided by an embodiment of this application;

[0057] Figure 2 It is a schematic diagram of a network connection scenario corresponding to a related technology provided by an embodiment of this application;

[0058] Figure 3 A flowchart of a method for detecting an access mode provided in an embodiment of the present application;

[0059] Figure 4 A schematic diagram of a detection scenario for an access method provided in an embodiment of the present application;

[0060] Figure 5 An interactive diagram of an access mode detection method provided in an embodiment of the present application;

[0061] Figure 6 A schematic diagram of a detection scenario for another access method provided in an embodiment of the present application;

[0062] Figure 7 A schematic diagram of a detection scenario for another access method provided in an embodiment of the present application;

[0063] Figure 8 A schematic diagram of the structure of a detection device for an access mode provided in an embodiment of the present application;

[0064] Figure 9 A schematic diagram of the structure of a detection device for another access mode provided in an embodiment of the present application;

[0065] Figure 10 A schematic diagram of the structure of a network device provided in an embodiment of the present application;

[0066] Figure 11 A schematic diagram of the structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0067] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.

[0068] In the field of communications technology, private connections within campus networks are becoming increasingly common. These connections can disrupt the normal operation of campus networks and complicate network management. These include, but are not limited to, connecting multiple devices to the network through private routers, exploiting shared wireless networks to privately access and unauthorized use, and expanding the number of network ports through private hubs.

[0069] See also Figure 1A schematic diagram of a campus network connection structure is shown. The terminal device 105 in the campus network is connected to the external network 101 through the access layer switch 104, the aggregation layer switch 103, and the core layer switch 102. Among them, the core layer switch 102 is used for routing selection and high-speed forwarding, providing an optimized and reliable backbone transmission structure. The aggregation layer switch 103 is the aggregation point of multiple access layer switches 104 and is used to realize data forwarding between the access layer and the core layer. The access layer switch 104 is used to connect the terminal device 105 to the network, and the access layer switch 104 has the characteristics of low cost and high port density.

[0070] Exemplarily, Figure 1 the following three unauthorized connection methods are shown. First, the unauthorized connected terminal device 105 is a hub (HUB) 1051. The hub 1051 is connected to multiple unauthorized connected terminals 106, which may cause network loops and even make the network unavailable. A network loop means that data continuously circulates and forwards in the network path instead of being correctly sent to the destination, occupying a large amount of network resources, thereby causing a decline in network performance and even network paralysis. For example, the unauthorized connected terminal 106 includes but is not limited to devices such as mobile phones, tablet computers, desktop computers, printers, or projectors.

[0071] Second, the unauthorized connected terminal device 1052 wirelessly shares the network to other unauthorized connected terminals 106. Third, the unauthorized connected terminal device 105 is a router 1053. For the second and third unauthorized connection methods, sharing the network and connecting the router 1053 will cause users to use the network without authorization through the shared network or the router 1053, affecting the security of the data in the campus network. In addition, for the third unauthorized connection method, if the router 1053 is connected to the access point (AP) through a wireless network ( Figure 1 not shown in the figure), the signal emitted by the router 1053 will interfere with the wireless connection between the AP and other terminal devices 105, resulting in a decline in the user's network usage experience. Among them, the AP is an access layer switch 104 and can also be called a wireless access point.

[0072] The above unauthorized connection phenomena pose a threat to the stability and security of the campus network. Therefore, a method is needed to identify the unauthorized connected terminal devices in the network to control the unauthorized connected terminal devices and maintain the normal operation of the network.

[0073] In the related art, see Figure 2, the core layer switch 102 is connected to the unauthorized access detection device 301 and the management device 302. The administrator configures traffic mirroring for the core layer switch 102 through the management device 302, that is, configures the mirroring criteria for the data on the core layer switch 102, for example, the location of the mirroring and the amount of mirrored data, etc. The management device 302 sends an enabling command to the unauthorized access detection device 301 to control the unauthorized access detection device 301 to start running through the enabling command. Furthermore, the core layer switch 102 mirrors the transmitted data to the unauthorized access detection device 301; the unauthorized access detection device 301 performs unauthorized access detection on the mirrored data based on the source IP, determines the unauthorized access information of the unauthorized access terminal device, and synchronizes the unauthorized access information to the management device 302. The user can view the unauthorized access information through the management device 302 and configure blocking of unauthorized access according to the unauthorized access information. For example, the management device 302 issues a blocking ACL to the core layer switch 102, and the core layer switch 102 blocks the data transmission of the unauthorized access terminal device based on the blocking ACL.

[0074] However, in the related art, traffic needs to reach the core layer switch 102 for detection. For data that does not reach the core layer switch 102, for example, data sent by any terminal device 105 and forwarded to another terminal device 105 via the access layer switch 104, the aggregation layer switch 103, and the access layer switch 104, unauthorized access detection cannot be performed, making it difficult to ensure network security at the aggregation layer and below the aggregation layer. Moreover, the traffic needs to be mirrored from the core layer switch 102 to the unauthorized access detection device 301 and then detected by the unauthorized access detection device 301, and the data mirroring process takes a long time, resulting in untimely processing of unauthorized access.

[0075] An embodiment of the present application provides a detection method for an access method. Taking an access device executing this method as an example for description, the access device can be an access layer switch, an access gateway, or an AP. For example, the access device can be Figure 1 the access layer switch 104 shown. As Figure 3 shown, this method includes but is not limited to the following steps 501 and step 502.

[0076] Step 501, collect data characteristics of the data transmitted by the access device. The data characteristics indicate the characteristics of the terminal device transmitting the data. The terminal device is connected to the access device. The data characteristics include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics.

[0077] In the embodiments of the present application, an access device is connected to a terminal device, and the access device can receive data sent by the terminal device to the network side. Collecting the data characteristics of the data transmitted by the access device includes collecting the data characteristics of the data sent by the terminal device received by the access device, and further, the data characteristics can indicate the characteristics of the terminal device. Optionally, the types of characteristics included in the data characteristics are not limited in the embodiments of the present application, and may include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics.

[0078] Among them, the packet characteristic refers to the characteristic carried in the packet of the transmitted data. Optionally, the packet characteristic includes at least one of user agent (UA) information, transfer control protocol (TCP) / IP protocol stack fingerprint, or domain name service (DNS) domain name fingerprint. The user agent (UA) information is an identifier for identifying a browser or other application on the terminal side. By analyzing the UA information, information such as the browser type, version, operating system, and hardware on the terminal side can be determined. The DNS domain name fingerprint is used to identify and confirm the identity information of the domain name by analyzing the characteristics of the DNS record. Different operating systems generate DNS records in different ways, and the type and version of the operating system can be judged according to the generation method of the DNS record.

[0079] The TCP / IP protocol stack fingerprint is information for identifying a network protocol. By analyzing the TCP / IP protocol stack fingerprint, the protocol stack of the operating system can be determined. There are slight differences between the protocol stacks of different operating systems, and this difference can be called the fingerprint of the network protocol stack. For the TCP / IP protocol family, this difference is manifested in the flag fields of the data packet header, such as different values of window size, acknowledgment (ACK) sequence number, and time to live (TTL). Therefore, different operating systems using different protocol stacks can be identified through the TCP / IP protocol stack fingerprint.

[0080] The network characteristic refers to the characteristic carried in the network transmission process. Optionally, the network characteristic includes at least one of link layer discovery protocol (LLDP) fingerprint and media access control address organizationally unique identifier (MAC OUI) fingerprint.

[0081] LLDP fingerprint is a standard protocol used to identify automatically discovered terminal devices and the attributes of terminal devices. The LLDP fingerprint contains information such as the manufacturer, device model, and device description of the terminal device. By comparing the information in the LLDP fingerprint with a known database of device manufacturers and device models for matching, the type and attributes of the terminal device can be identified, such as a hub or a router, etc. The MAC OUI fingerprint is the OUI part of the MAC address. The MAC address is the unique identifier of a network device, which is assigned by the manufacturer of the terminal device. By comparing the OUI part of the MAC address with a known database of device manufacturers for matching, the type of the terminal device can be identified.

[0082] Flow behavior characteristics refer to the characteristics presented by the data stream during the transmission process. Optionally, the flow behavior characteristics include at least one of the transmission frequency or the sending interval of the data stream. Since there are deviations in the flow behavior of the data stream sent by non-illegally connected terminal devices and the flow behavior of the data stream sent by illegally connected terminal devices, the flow behavior characteristics can be used to identify the access method of the terminal device. And the data sent by the terminal device received by the access device is not reshaped and sorted, maintaining the original sequence of the data sent by the terminal device, that is, retaining the flow behavior characteristics of the terminal device accessing the network. Furthermore, the flow behavior characteristics of the data transmitted by the access device collected can indicate the characteristics of the terminal device.

[0083] Device physical characteristics refer to the characteristics of the signal when the device transmits data. Optionally, the device physical characteristics include at least one of the slope of the transient signal amplitude of the data frame, voltage, mean value of the pressure difference, variance of the pressure difference, kurtosis of the pressure difference, or mean square value of the pressure difference. The device physical characteristics of different types of terminal devices are different, and different types of terminal devices can be identified through the device physical characteristics.

[0084] In a possible implementation manner, the method for collecting data characteristics of the data transmitted by the access device includes collecting data characteristics during the transmission of the data, that is, collecting along with the flow; or, first copying the data transmitted by the access device to obtain copied data, and then collecting the data characteristics of the copied data. Since the copied data is a complete copy of the original data and contains all the data content of the original data, collecting the data characteristics of the copied data is to collect the data characteristics of the original data. Thus, two methods for collecting data characteristics are provided, making the collection of data characteristics more flexible. Among them, collecting along with the flow can improve the collection efficiency of data characteristics, and collecting copied data can avoid affecting the transmission of data.

[0085] In the embodiment of the present application, the access device is the first-hop forwarding device for the data sent by the terminal device, that is, the terminal device is directly connected to the access device. In this way, the access device is a device near the network edge on the terminal side. By performing unauthorized connection detection at the network edge, it is possible to detect unauthorized connections for all data entering the network, improving the comprehensiveness of unauthorized connection detection and the security of the network. Moreover, the data transmitted at the network edge has not been forwarded by network devices, which can retain more features indicating the terminal device. Therefore, the data features collected based on the data transmitted at the network edge are more comprehensive.

[0086] In a communication network, data can be transmitted bidirectionally between the terminal side and the network side. Among them, the data flowing from the terminal side to the network side is called uplink data, and the data flowing from the network side to the terminal side is called downlink data. The data transmitted collected by the access device is the data flowing from the terminal side to the network side, that is, the data flow direction of the collected data is the uplink direction from the terminal side to the network side. Exemplarily, the access device identifies uplink data according to the data flow direction and collects the data features of the transmitted uplink data; or, the access device identifies the uplink port for receiving uplink data according to the data flow direction and collects the data features of the data received by the uplink port.

[0087] Thus, the method can accurately perform unauthorized connection detection for uplink data, avoid misjudgment caused by detecting downlink data, and improve the accuracy of unauthorized connection detection. For example, avoid misjudgment caused by downlink data sent by a DNS server or a server virtual machine.

[0088] In a possible implementation manner, the process of collecting the data features of the data transmitted by the access device includes collecting the data features of the data transmitted by the access device based on the unauthorized connection detection configuration command. The unauthorized connection detection configuration command usually contains specific configuration information on how to perform unauthorized connection detection, such as which data features to collect, how to process and analyze the data, etc. The access device can perform corresponding data feature collection work according to the unauthorized connection detection configuration command. For example, when receiving the unauthorized connection detection configuration command, it starts to collect data features according to the instructions of the unauthorized connection detection configuration command. The collection of data features can include traffic analysis, protocol parsing, packet capture, etc., and the collection of data depends on the requirements of the configuration command.

[0089] Step 502, determine the access mode of the terminal device based on the data features.

[0090] In the embodiment of the present application, the access modes of the terminal device are divided into two types: unauthorized connection and non-unauthorized connection. Unauthorized connection refers to accessing the network in an unauthorized or network regulation-violating manner, such as unauthorized device connection, malicious intrusion, etc.; non-unauthorized connection is accessing the network after authorized authentication.

[0091] Since data characteristics may include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics, therefore, when data characteristics include different combinations of characteristics, the implementation manners of determining the access mode of the terminal device based on the data characteristics are also different, including but not limited to the following several kinds.

[0092] Manner 1: The data characteristics include packet characteristics.

[0093] Optionally, the process of determining the access mode of the terminal device based on the data characteristics includes identifying the operating system under the access port of the terminal device based on multiple packet characteristics; when the operating systems under the access port are different, determining the access mode of the terminal device as unauthorized access. Wherein, the access port of the terminal device is the port on the access device connected to the terminal device. Identifying the operating system under the access port through packet characteristics, different operating systems indicate that multiple operating systems access the network through the access port, and multiple operating systems represent multiple independently running user programs, that is, there is a multi-user sharing phenomenon under this access port. And when the access mode is not unauthorized access, one port of the access device corresponds to one operating system. Therefore, by identifying different operating systems, it is possible to quickly and accurately detect that the access mode of the terminal device is unauthorized access.

[0094] Among them, the packet characteristics include but are not limited to at least one of UA information, TCP / IP protocol stack fingerprint, or DNS domain name fingerprint, and can reflect the operating system information of the terminal device. Exemplarily, the manner of identifying the operating system under the access port of the terminal device based on multiple packet characteristics includes, for multiple packet characteristics of the data received under the access port of the terminal device, matching the multiple packet characteristics with the packet characteristics of known operating systems, and determining the operating system with successful matching as the operating system under the access port.

[0095] Optionally, determining the access mode of the terminal device based on the data characteristics may include identifying the address information under the access port of the terminal device based on multiple packet characteristics; when the address information under the access port is the same, identifying the operating system under the access port of the terminal device based on multiple packet characteristics, and if the operating systems under the access port are different, determining the access mode of the terminal device as unauthorized access; when the address information under the access port is different, directly determining the access mode of the terminal device as unauthorized access.

[0096] Among them, the packet characteristics also include the address information of the data sender, and the address information includes at least one of IP address or MAC address. For example, for the data received under the access port of the terminal device, if the address information of the sender of each data is the same, it is determined that the address information under the access port is the same; if there is data with different address information of the sender, it is determined that the address information under the access port is different.

[0097] In this method, the address information on the access port is first identified through packet characteristics. Different address information indicates that multiple user terminals with different addresses access the network through this access port. When the access method is not unauthorized access, one port of the access device corresponds to one user terminal. Therefore, by identifying different address information, the access method of the terminal device can be quickly and accurately detected as unauthorized access. In the case of the same address information, there may be two situations. The first situation is that the access method of the terminal device connected to the access port is not unauthorized access. The second situation is that multiple user terminals disguise themselves as the same address information for data transmission. Therefore, when it is determined that the address information is the same, the unauthorized access detection is further performed by identifying the operating system to ensure the accuracy of the unauthorized access detection. Herein, the user terminal may also be referred to as the terminal device.

[0098] For the case of a hub accessing the network in an unauthorized manner, since the hub cannot modify the address information of the terminal device accessing the network through the hub, by identifying the address information under the same access port, the situation of the hub accessing the network in an unauthorized manner can be simply and quickly identified. In practical applications, if the network allows the hub to access the network in an unauthorized manner, the detection method of only identifying different operating systems can be selected; if the network does not allow the hub to access the network in an unauthorized manner, the detection method of first identifying different address information and then identifying different operating systems can be selected to improve the efficiency of identifying an unauthorized hub.

[0099] Method 2: The data characteristics include flow behavior characteristics.

[0100] Optionally, the process of determining the access method of the terminal device based on the data characteristics includes obtaining the deviation distance between the flow behavior characteristics and the reference characteristics, where the reference characteristics are the flow behavior characteristics of the data transmitted by the terminal device with a non-unauthorized access method; when the deviation distance is greater than the deviation threshold, it is determined that the access method of the terminal device is unauthorized access. Herein, the deviation threshold can be set according to experience or flexibly adjusted according to the application scenario, which is not limited in the embodiments of the present application.

[0101] Since the flow behavior characteristics of the data transmitted by the terminal device with a non-unauthorized access method are different from those of the data transmitted by the terminal device with an unauthorized access method. For example, the terminal device with a non-unauthorized access method corresponds to a single terminal, and the terminal device with an unauthorized access method corresponds to multiple terminals. The flow behavior characteristics of the data transmitted by a single terminal device are different from those of the data transmitted by multiple terminal devices. Therefore, by comparing the deviation between the flow behavior characteristics of the data transmitted by the collected terminal device and the flow behavior characteristics of the data transmitted by the terminal device with a non-unauthorized access method, the access method of the terminal device can be quickly and accurately detected as unauthorized access.

[0102] Taking the behavior characteristics including the transmission frequency and the sending interval as an example, the transmission frequency and the sending interval of the non-illegally connected terminal device are used as the reference frequency and the reference interval, and the first deviation distance between the transmission frequency in the collected data characteristics and the reference frequency, and the second deviation distance between the sending interval in the collected data characteristics and the reference interval are obtained; the deviation distance of the behavior characteristics is determined based on the first deviation distance and the second deviation distance. Optionally, the average value of the first deviation distance and the second deviation distance is determined as the deviation distance of the behavior characteristics, or the larger value of the first deviation distance and the second deviation distance is determined as the deviation distance of the behavior characteristics. The deviation distance can be in the form of a percentage. For example, if the collected sending interval is 1 second and the reference interval is 0.8 second, the deviation distance can be calculated as (1 - 0.8) / 0.8 * 100% = 25%. If the deviation threshold is 20%, since the deviation distance of 25% is greater than the deviation threshold of 20%, it is determined that the access mode of the terminal device is illegally connected.

[0103] In the third method, the data characteristics include at least one of network characteristics or device physical characteristics.

[0104] Optionally, the process of determining the access mode of the terminal device based on the data characteristics includes identifying the type of the terminal device based on at least one of the network characteristics or the device physical characteristics; in the case where the type of the terminal device is a router or a hub, it is determined that the access mode of the terminal device is illegally connected.

[0105] Among them, a router or a hub is a device for connecting multiple terminals together. Since in the case of a non-illegally connected access mode, the terminal device connected to the access device corresponds to one terminal, therefore, by identifying the router or the hub, the access mode of the terminal device can be quickly and accurately detected as illegally connected. And on the basis of being able to detect that the access mode of the terminal device is illegally connected, it is also possible to determine whether the illegal connection type is an illegally connected router or an illegally connected hub, making the result of the illegal connection detection more accurate, and this illegal connection type can also provide help for the subsequent implementation of blocking illegal connections.

[0106] Taking the network characteristics including LLDP fingerprints and MAC OUI fingerprints as an example, identifying the type of the terminal device based on the network characteristics includes matching the collected LLDP fingerprints and MAC OUI fingerprints with a first database, where the first database includes the corresponding relationship between the LLDP fingerprints and MAC OUI fingerprints and the terminal type; determining the type of the terminal device according to the matching result. Taking the device physical characteristics including the amplitude of the data frame transient signal, voltage, and pressure difference as an example, identifying the type of the terminal device based on the device physical characteristics includes matching the slope of the amplitude of the data frame transient signal, voltage, and pressure difference of the collected data with a second database, where the second database includes the corresponding relationship between the slope of the amplitude of the data frame transient signal, voltage, and pressure difference and the terminal type; determining the type of the terminal device according to the matching result.

[0107] Thus, through at least one of the above-mentioned Method 1 to Method 3, the access mode of the terminal device can be determined according to any one of the data characteristics. Among them, for any one of the data characteristics mentioned in the above embodiments, if the access mode of the terminal device is determined to be unauthorized access based on any one or more characteristics, then the access mode of the terminal device is unauthorized access.

[0108] In the embodiments of the present application, the access mode can be determined based on any one or more characteristics, and the processes of determining the access mode by any two characteristics can be carried out simultaneously or non-simultaneously. If they are not carried out simultaneously, the two processes of determining the access mode can be carried out in any order. For example, first determine the access mode based on the packet characteristics, and then determine the access mode based on the flow behavior characteristics; or first determine the access mode based on the flow behavior characteristics, and then determine the access mode based on the packet characteristics. In addition, if the access mode is determined based on multiple characteristics, the results of the access modes determined based on multiple characteristics can be mutually verified. If the access mode determined based on any one of the collected characteristics is non-unauthorized access, it is determined that the access mode of the terminal device is non-unauthorized access.

[0109] When it is determined based on the above-mentioned Step 501 and Step 502 that the access mode of the terminal device is unauthorized access, the unauthorized access terminal device can be blocked, that is, the data transmission of the terminal device is blocked. Optionally, the access device sends a blocking instruction or a blocking signal to block the data transmission of the terminal device.

[0110] In a possible implementation manner, the methods for blocking the data transmission of the terminal device include but are not limited to: closing the access port of the terminal device so that the access port no longer receives data; or adding the address information of the terminal device to a blacklist, where the blacklist is used to block the data transmission of the terminal device corresponding to the address information in the blacklist, so that the access device can no longer forward the data including the address information; or logging off the user in the online state on the terminal device so that the terminal device exits the network, that is, the terminal device cannot send data to the access device. Thus, three methods for blocking the data transmission of the terminal device are provided, enabling flexible selection of different blocking methods according to different scenarios.

[0111] Among them, the blocking method of closing the access port of the terminal device can be called port shutdown. Adding the address information of the terminal device to the blacklist can be adding the MAC address of the terminal device to the blacklist, and this blocking method can be called MAC black hole, so that when the terminal device corresponding to the MAC address accesses through other ports of the access device, it will also be blocked due to the blacklist. The blocking method of logging off the user in the online state on the terminal device can be called user authentication logout, and the logged-off user needs to perform the online authentication operation again to access the network.

[0112] In an embodiment of the present application, the blocking method can be determined based on the unauthorized connection type of the terminal device. For example, if the terminal device is an unauthorized router, the blocking method can be to shut down the selected group port; if the terminal device is a shared wireless network, the blocking method can be to log off the user through authentication. The selection of the blocking method is only for illustrative purposes, and the specific selection method can be determined based on user configuration.

[0113] For ease of understanding, an embodiment of the present application provides a detection scenario for the access method. Refer to Figure 4 , Figure 4 which includes an administrator, an access device, and a terminal device. The access device includes a collection module, a perception module, and a processing module. The collection module, the perception module, and the processing module are only for illustrative purposes. The specific implementation method is not limited to these three modules and can be flexibly adjusted as needed.

[0114] As Figure 4 shown, in step 601, the administrator configures the unauthorized connection detection configuration command for the processing module of the access device. In step 602, the processing module controls the collection module to start collecting data characteristics. In step 603, the terminal device sends data to the access device. In step 604, the collection module collects data characteristics according to the data sent by the terminal device. In step 605, the collection module sends the data characteristics to the perception module. In step 606, the perception module determines whether the access method of the terminal device is an unauthorized connection according to the data characteristics. In step 607, the information of the unauthorized terminal device is sent to the processing module. In step 608, the data sent by the terminal device is blocked. In step 609, the terminal device cannot connect to the network. In step 610, the processing module sends an alarm message to the administrator. In step 611, the administrator can view the unauthorized terminal information and the blocking result through the access device.

[0115] In summary, since the data characteristics of the data transmitted by the access devices at the access layer are collected in the embodiments of the present application, the detection of the access method can be performed when the data reaches the access layer. Compared with the centralized anti-illegal connection method in the related art, it can make up for the detection of the data that reaches the access layer but does not reach the core layer, making the detection of the access method more timely and comprehensive. Moreover, there are many types of data characteristics that can be collected at the access layer, making the probability of detecting the illegally connected terminal devices greater and improving the accuracy of the detection of the access method. The method provided in the embodiments of the present application can identify the types of terminal devices, making the results of the illegal connection detection more accurate, and the illegal connection type can also provide help for the subsequent implementation of blocking the illegal connection. The data characteristics provided in the embodiments of the present application are relatively comprehensive, and the access methods determined by different data characteristics can be mutually verified, thereby improving the accuracy of access method identification. In addition, the embodiments of the present application provide two data characteristic collection methods, making the collection of data characteristics more flexible. Among them, the in-flow collection can improve the collection efficiency of data characteristics, and the replicated data collection can avoid affecting the data transmission.

[0116] Taking the interaction between the access device and the management device to execute this method as an example, as Figure 5 shown, the method provided in the embodiments of the present application includes but is not limited to the following steps 701-step 704. Among them, the access device can be Figure 1 the access layer switch 104 shown in the figure, the management device is connected to the access device, and the management device is used to interact with the administrator.

[0117] Step 701, the management device sends an illegal connection detection configuration command to the access device.

[0118] Among them, the management device can be the central console or server used by the network administrator to configure and control network devices, and the illegal connection detection configuration command can be flexibly configured by the administrator according to needs.

[0119] Step 702, the access device receives the illegal connection detection configuration command, collects the data characteristics of the data transmitted by the access device based on the illegal connection detection configuration command, and determines the access method of the terminal device based on the data characteristics.

[0120] Based on the illegal connection detection configuration command issued by the management device, the access device triggers the collection of the data characteristics of the data transmitted by the access device and determines the access method of the terminal device based on the data characteristics. In this way, according to the illegal connection detection configuration command, the collection of data characteristics can be flexibly triggered, that is, the illegal connection detection is triggered, and different illegal connection detection configuration commands can be set according to different user requirements, making the implementation of the illegal connection detection more in line with user needs.

[0121] For the implementation manner of step 702, reference can be made to the relevant introductions in the above steps 501 and 502, which will not be elaborated here.

[0122] Step 703: When the access device determines that the access mode of the terminal device is unauthorized access, it sends the unauthorized access information of the terminal device to the management device.

[0123] The unauthorized access information can indicate that the access mode of the terminal device is unauthorized access. Optionally, the unauthorized access information may include at least one of the MAC address, IP address, access port, access time, unauthorized access type, or reason for unauthorized access determination.

[0124] Step 704: The management device receives the unauthorized access information of the terminal device and issues an unauthorized access warning message.

[0125] The embodiments of the present application do not limit the manner of issuing the unauthorized access warning message. Optionally, the management device generates an alarm record and records relevant information about the unauthorized access, such as the occurrence time, occurrence location, and identification of the terminal device involved. The management device will send the unauthorized access warning message to the administrator or visually display it on the management device so that the administrator can take corresponding measures in a timely manner. Exemplarily, it can be sent via email, text message, instant message, or a specific alarm system. This enables the administrator who receives the unauthorized access warning message to take corresponding measures based on the information content, such as isolating the unauthorized access device, investigating the network status, and contacting the administrator, to ensure the normal operation and security of the network.

[0126] In a possible implementation, after receiving the unauthorized access information of the terminal device, the management device also blocks the terminal device from transmitting data. The methods of blocking the terminal device from transmitting data include, but are not limited to: sending a shutdown instruction to the access device, where the shutdown instruction is used for the access device to close the access port of the terminal device; or, sending a blacklist to the access device, where the blacklist includes the address information of the terminal device, and the blacklist is used for the access device to block the terminal device corresponding to the address information in the blacklist from transmitting data; or, sending a logout instruction to the access device, where the logout instruction is used for the access device to log out the user on the terminal device who is in the online state. In this way, three blocking methods are provided, enabling flexible selection of a suitable blocking method based on different scenarios. In addition, the management device continuously monitors the network status to ensure that unauthorized access is effectively controlled. When blocking the data transmitted by the terminal device, the management device issues a notice to inform the user that a logout measure has been taken, and visually displays the blocking method and the terminal device involved.

[0127] In a possible implementation, after receiving the unauthorized access information of the terminal device, the unauthorized access information of the terminal device is visually displayed. Taking the unauthorized access information including the MAC address, IP address, access port, access time, unauthorized access type, and reason for unauthorized access determination as an example.

[0128] For the MAC address, each terminal device has a unique MAC address, which is used to identify the identity of the terminal device. For the IP address: The IP address is the unique identifier of the terminal device in the network and is used to locate and manage the terminal device. For the access port, the access port can determine through which port the terminal device is privately connected. For the access time, recording the access time of the terminal device can evaluate the time period during which the terminal device is privately connected, and corresponding countermeasures can be taken for specific time periods. For the type of private connection, targeted blocking measures can be taken according to the type of private connection. For the reason for private connection determination, it indicates the reason or basis for the access device to determine that the terminal device is a privately connected terminal device. The reason for private connection determination can help users understand the nature and severity of the private connection.

[0129] The ways to visually display private connection information can include charts, tables, dashboards or other visualization tools. The visualization tools can present the private connection information to users in an intuitive and easy-to-understand way, helping users quickly understand the general situation and details of the privately connected terminal devices. By visually displaying the private connection information, users can quickly understand the impact and distribution of the private connection, so as to better formulate and implement countermeasures. For example, isolating the privately connected terminal devices, issuing alarms, notifying relevant personnel or taking other appropriate actions. Visual display can also help users conduct long-term data analysis and trend prediction to prevent and respond to terminal devices with private connection as the future access method.

[0130] For ease of understanding, the embodiments of the present application provide a detection scenario for another access method. Refer to Figure 6 , Figure 6 It includes an administrator, an access device, a management device and a terminal device. The access device includes a collection module, a perception module and a processing module. The collection module, the perception module and the processing module are only for illustrative purposes, and the specific implementation methods are not limited to these three modules and can be flexibly adjusted as needed.

[0131] Such as Figure 6As shown, in step 901, the administrator configures the unauthorized connection detection configuration command through the visual interface of the management device. In step 902, the management device sends the unauthorized connection detection configuration command to the processing module of the access device. In step 903, the processing module controls the acquisition module to start collecting data features. In step 904, the terminal device sends data to the access device. In step 905, the acquisition module collects data features based on the data sent by the terminal device. In step 906, the acquisition module sends the data features to the perception module. In step 907, the perception module determines whether the access mode of the terminal device is an unauthorized connection based on the data features. In step 908, the unauthorized connection information of the unauthorized connected terminal device is sent to the processing module. In step 909, the processing module blocks the data transmission of the terminal device. In step 910, the terminal device cannot connect to the network. In step 911, the processing module sends the unauthorized connection information and the blocking result to the management device. In step 912, the management device sends an alarm message to the administrator. In step 913, the administrator can view the unauthorized connection information and the blocking result through the visual interface of the management device.

[0132] The perception module or the processing module given in the embodiments of the present application can also be configured in the management device, thereby reducing the workload of the access device. Exemplarily, see Figure 7 , Figure 7 provides a detection scenario for another access mode, Figure 7 including an administrator, an access device, a management device, and a terminal device. The access device includes an acquisition module and a perception module. The management device includes a management module and a processing module. The acquisition module, the perception module, the processing module, and the management module are only for illustrative purposes, and the specific implementation manner is not limited to these four modules and can be flexibly adjusted as needed.

[0133] As Figure 7 shown, in step 1001, the administrator configures the unauthorized connection detection configuration command through the visual interface of the management device. In step 1002, the management module sends the unauthorized connection detection configuration command to the acquisition module of the access device. In step 1003, the terminal device sends data to the access device. In step 1004, the acquisition module collects data features based on the data sent by the terminal device. In step 1005, the acquisition module sends the data features to the perception module. In step 1006, the perception module determines whether the access mode of the terminal device is an unauthorized connection based on the data features. In step 1007, the unauthorized connection information of the unauthorized connected terminal device is sent to the management module. In step 1008, the management module sends an alarm message to the administrator. In step 1009, the administrator views the unauthorized connection information through the visual interface of the management device. In step 1010, the management module sends a blocking message to the processing module. In step 1011, the processing module blocks the data sent by the terminal device according to the blocking message. In step 1012, the terminal device cannot connect to the network.

[0134] In summary, in the embodiment of the present application, the access device is connected to the management device, and the visual management of the privately connected terminal device is realized through the management device.

[0135] The above has introduced the detection method of the access mode provided by the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides a detection device for the access mode. This device is used to Figure 8 execute the detection method of the access mode performed by the access device in the above description through the Figure 3 shown respective modules, such as Figure 8 the method shown. As

[0136] The acquisition module 1101 is used to acquire the data characteristics of the data transmitted by the access device. The data characteristics indicate the characteristics of the terminal device transmitting the data. The terminal device is connected to the access device. The data characteristics include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics;

[0137] The determination module 1102 is used to determine the access mode of the terminal device based on the data characteristics.

[0138] In an exemplary embodiment, the data characteristics include multiple packet characteristics; the determination module 1102 is used to identify the operating system under the access port of the terminal device based on the multiple packet characteristics; when the operating systems under the access port are different, determine that the access mode of the terminal device is private connection.

[0139] In an exemplary embodiment, the determination module 1102 is used to identify the address information under the access port of the terminal device based on the multiple packet characteristics; when the address information under the access port is the same, identify the operating system under the access port of the terminal device based on the multiple packet characteristics;

[0140] The determination module 1102 is further used to determine that the access mode of the terminal device is private connection when the address information under the access port is different.

[0141] In an exemplary embodiment, the data characteristics include flow behavior characteristics; the determination module 1102 is used to obtain the deviation distance between the flow behavior characteristics and the reference characteristics. The reference characteristics are the flow behavior characteristics of the data transmitted by the terminal device with a non-private access mode; when the deviation distance is greater than the deviation threshold, determine that the access mode of the terminal device is private connection.

[0142] In an exemplary embodiment, the data feature includes at least one of a network feature or a device physical feature; a determination module 1102, configured to identify the type of the terminal device based on at least one of the network feature or the device physical feature; in a case where the type of the terminal device is a router or a hub, determining that the access mode of the terminal device is unauthorized access.

[0143] In an exemplary embodiment, the apparatus further includes: a blocking module, configured to block data transmission of the terminal device in a case where the access mode of the terminal device is unauthorized access. Alternatively, the apparatus further includes: a sending module, configured to send unauthorized access information of the terminal device to a management device in a case where the access mode of the terminal device is unauthorized access, where the unauthorized access information is used for the management device to block data transmission of the terminal device.

[0144] In an exemplary embodiment, the blocking module is configured to close the access port of the terminal device; or add the address information of the terminal device to a blacklist, where the blacklist is used to block data transmission of the terminal device corresponding to the address information in the blacklist; or log off the user in the online state on the terminal device.

[0145] In an exemplary embodiment, the data transmitted by the access device is data flowing from the terminal side to the network side.

[0146] In an exemplary embodiment, the apparatus further includes: a receiving module, configured to receive an unauthorized access detection configuration command sent by the management device; in this case, an acquisition module 1101, configured to acquire data features of the data transmitted by the access device based on the unauthorized access detection configuration command.

[0147] In an exemplary embodiment, the apparatus further includes: a copying module, configured to copy the data transmitted by the access device to obtain copied data; in this case, an acquisition module 1101, configured to acquire data features of the copied data.

[0148] In an exemplary embodiment, the access device is the first-hop forwarding device for the data sent by the terminal device.

[0149] It should be understood that, when the above Figure 8 shown apparatus realizes its functions, the beneficial effects it has are the same as Figure 3 the beneficial effects of the method shown. Figure 8 When the apparatus shown realizes its functions, only the above division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments and will not be elaborated here.

[0150] An embodiment of the present application also provides a detection device for an access method. This device is used to Figure 9 perform the access method detection method executed by the access device in the above description through each module shown, such as Figure 5 the method shown. As Figure 9 shown, the access method detection device provided by the embodiment of the present application includes the following modules.

[0151] A receiving module 1201, configured to receive the unauthorized connection information of the terminal device sent by the access device, where the unauthorized connection information indicates that the access method of the terminal device is unauthorized connection;

[0152] An alarm module 1202, configured to issue an unauthorized connection alarm message.

[0153] In an exemplary implementation manner, the device further includes: a blocking module, configured to block the terminal device from transmitting data.

[0154] In an exemplary implementation manner, the blocking module is configured to send a shutdown instruction to the access device, where the shutdown instruction is used for the access device to close the access port of the terminal device; or, send a blacklist to the access device, where the blacklist includes the address information of the terminal device, and the blacklist is used for the access device to block the terminal device corresponding to the address information in the blacklist from transmitting data; or, send a logout instruction to the access device, where the logout instruction is used for the access device to log out the user in the online state on the terminal device.

[0155] In an exemplary implementation manner, the device further includes: a visualization display module, configured to visually display the unauthorized connection information of the terminal device, where the unauthorized connection information includes at least one of a MAC address, an IP address, an access port, an access time, an unauthorized connection type, or a reason for unauthorized connection determination.

[0156] In an exemplary implementation manner, the device further includes: a sending module, configured to send an unauthorized connection detection configuration command to the access device, where the unauthorized connection detection configuration command is used for the access device to collect data characteristics of the data transmitted by the access device and determine the access method of the terminal device based on the data characteristics.

[0157] It should be understood that when the device shown above Figure 9 realizes its functions, the beneficial effects it has are the same as Figure 5 the beneficial effects of the method shown. Figure 9When the device shown implements its functions, only the division of the above-mentioned functional modules is used for illustration. In practical applications, the above-mentioned functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device provided in the above embodiment and the method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment and will not be elaborated here.

[0158] The embodiment of the present application provides a detection device for an access method. The device includes a memory and a processor; at least one computer instruction is stored in the memory, and the at least one computer instruction is loaded and executed by the processor so that the detection device for the access method can implement Figure 3 or Figure 5 the detection method for the access method shown.

[0159] See Figure 10 , Figure 10 which shows a schematic structural diagram of a network device 1300 provided by the present application. Figure 10 The network device 1300 shown is used to perform the operations involved in the detection method for the access method shown above. Figure 4 The network device 1300 is, for example, a switch, etc. The network device 1300 can be implemented by a general bus architecture.

[0160] As Figure 10 shown, the network device 1300 includes at least one processor 1301, a memory 1303, and at least one communication interface 1304.

[0161] The processor 1301 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solutions of this application. For example, the processor 1301 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logic blocks, modules, and circuits described in connection with the disclosed content of the embodiments of the present invention. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.

[0162] Optionally, the network device 1300 further includes a bus. The bus is used to transfer information between the components of the network device 1300. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 10 only one line is shown in the figure, but it does not mean that there is only one bus or one type of bus.

[0163] The memory 1303 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, such as a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, such as an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1303 exists independently, for example, and is connected to the processor 1301 via a bus. The memory 1303 can also be integrated with the processor 1301.

[0164] The communication interface 1304 uses any device such as a transceiver to communicate with other devices or communication networks, and the communication network can be an Ethernet, a radio access network (RAN) or a wireless local area network (WLAN), etc. The communication interface 1304 can include a wired communication interface and can also include a wireless communication interface. Specifically, the communication interface 1304 can be an Ethernet interface, a fast ethernet (FE) interface, a gigabit ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface or a combination thereof. In the embodiments of the present application, the communication interface 1304 can be used for the network device 1300 to communicate with other devices.

[0165] In a specific implementation, as an embodiment, the processor 1301 can include one or more CPUs, such as Figure 100 and CPU1 are shown in FIG. Each of these processors can be a single-core CPU processor or a multi-core CPU processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0166] In a specific implementation, as an embodiment, the network device 1300 may include multiple processors, such as Figure 10 1 and 1305. Each of these processors can be a single-core CPU or a multi-core CPU. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0167] In a specific implementation, as an embodiment, the network device 1300 may further include an output device and an input device. The output device communicates with the processor 1301 and can display information in a variety of ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 1301 and can receive user input in a variety of ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0168] In some embodiments, the memory 1303 is used to store program code 1310 for executing the solution of the present application, and the processor 1301 can execute the program code 1310 stored in the memory 1303. That is, the network device 1300 can implement the access mode detection method provided in the method embodiment through the processor 1301 and the program code 1310 in the memory 1303. The program code 1310 may include one or more software modules. Optionally, the processor 1301 itself may also store program code or instructions for executing the solution of the present application.

[0169] In a specific embodiment, the network device 1300 of the embodiment of the present application may correspond to the access device in each of the above method embodiments, and the processor 1301 in the network device 1300 reads the instruction in the memory 1303 so that Figure 10 The illustrated network device 1300 is capable of performing all or part of the operations performed by an access device.

[0170] Other optional embodiments are not described herein for the sake of brevity.

[0171] In a specific embodiment, the network device 1300 in the embodiments of the present application may correspond to the management device in each of the above method embodiments. The processor 1301 in the network device 1300 reads the instructions in the memory 1303, so that Figure 10 the network device 1300 shown is capable of performing all or part of the operations performed by the management device.

[0172] Other optional embodiments are not described herein for the sake of brevity.

[0173] The network device 1300 may also correspond to the above Figure 8 or Figure 9 shown access mode detection device. Each functional module in the access mode detection device is implemented by the software of the network device 1300. In other words, the functional modules included in the access mode detection device are generated after the processor 1301 of the network device 1300 reads the program code 1310 stored in the memory 1303.

[0174] Among them, Figure 3 or Figure 5 each step of the access mode detection method shown is completed by the integrated logic circuit of the hardware in the processor of the network device 1300 or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or by a combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. For the sake of avoiding repetition, it is not described in detail here.

[0175] See Figure 11 , Figure 11 which shows a schematic structural diagram of a network device 1400 provided by another exemplary embodiment of the present application. Figure 11 The network device 1400 shown is used to perform all or part of the operations involved in the access mode detection method described above Figure 3 or Figure 5 shown. The network device 1400 is, for example, a switch, a router, etc. The network device 1400 can be implemented by a general bus architecture.

[0176] As Figure 11 shown, the network device 1400 includes: a main control board 1410 and an interface board 1430.

[0177] The main control board is also known as the main processing unit (MPU) or the route processor card. The main control board 1410 is used for controlling and managing various components in the network device 1400, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 1410 includes: a central processing unit 1411 and a memory 1412.

[0178] The interface board 1430 is also known as the line processing unit (LPU), line card, or service board. The interface board 1430 is used to provide various service interfaces and implement packet forwarding. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc. The Ethernet interface is, for example, a flexible ethernet clients (FlexE Clients). The interface board 1430 includes: a central processing unit 1431, a network processor 1432, a forwarding table entry memory 1434, and a physical interface card (PIC) 1433.

[0179] The central processing unit 1431 on the interface board 1430 is used to control and manage the interface board 1430 and communicate with the central processing unit 1411 on the main control board 1410.

[0180] The network processor 1432 is used to implement the detection of access modes. The form of the network processor 1432 can be a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 1432 is used to forward the received packets based on the forwarding table entries stored in the forwarding table entry memory 1434. If the destination address of the packet is the address of the network device 1400, the packet is sent to the CPU (such as the central processor 1431) for processing; if the destination address of the packet is not the address of the network device 1400, the next hop and the output interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the output interface corresponding to the destination address. Among them, the processing of the upstream packets can include: the processing of the packet input interface and the forwarding table lookup; the processing of the downstream packets can include: the forwarding table lookup and so on. In some embodiments, the central processor can also perform the functions of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that there is no need for a forwarding chip in the interface board.

[0181] The physical interface card 1433 is used to implement the docking function of the physical layer. The original traffic enters the interface board 1430 from here, and the processed packets are sent out from the physical interface card 1433. The physical interface card 1433 is also called a daughter card and can be installed on the interface board 1430. It is responsible for converting the optical and electrical signals into packets, performing a legality check on the packets, and then forwarding them to the network processor 1432 for processing. In some embodiments, the central processor 1431 can also perform the functions of the network processor 1432, such as implementing software forwarding based on a general-purpose CPU, so that there is no need for the network processor 1432 in the physical interface card 1433.

[0182] Optionally, the network device 1400 includes multiple interface boards. For example, the network device 1400 further includes an interface board 1440, and the interface board 1440 includes: a central processor 1441, a network processor 1442, a forwarding table entry memory 1444, and a physical interface card 1443. The functions and implementation methods of the components in the interface board 1440 are the same as or similar to those in the interface board 1430, and will not be elaborated here.

[0183] Optionally, the network device 1400 further includes a switch fabric board 1420. The switch fabric board 1420 may also be referred to as a switch fabric unit (SFU). In the case where the network device 1400 has multiple interface boards, the switch fabric board 1420 is used to complete data exchange between the interface boards. For example, the interface board 1430 and the interface board 1440 may communicate through the switch fabric board 1420.

[0184] The main control board 1410 is coupled to the interface board. For example, the main control board 1410, the interface board 1430, the interface board 1440, and the switch fabric board 1420 are interconnected through a system bus and a system backplane. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 1410 and the interface board 1430 and the interface board 1440, and the main control board 1410 communicates with the interface board 1430 and the interface board 1440 through the IPC channel.

[0185] Logically, the network device 1400 includes a control plane and a forwarding plane. The control plane includes the main control board 1410 and the central processing unit 1411. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1434, a physical interface card 1433, and a network processor 1432. The control plane performs functions such as acting as a router, generating a forwarding table, processing signaling and protocol messages, configuring and maintaining the state of the network device, etc. The control plane distributes the generated forwarding table to the forwarding plane. In the forwarding plane, the network processor 1432 looks up the packets received by the physical interface card 1433 based on the forwarding table distributed by the control plane and forwards them. The forwarding table distributed by the control plane may be stored in the forwarding table entry memory 1434. In some embodiments, the control plane and the forwarding plane may be completely separated and not on the same network device.

[0186] It should be noted that there may be one or more main control boards. When there are multiple main control boards, they may include an active main control board and a standby main control board. There may be one or more interface boards. The stronger the data processing capacity of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching fabric board, or there may be one or more switching fabric boards. When there are multiple switching fabric boards, they can jointly implement load sharing and redundant backup. In a centralized forwarding architecture, the network device may not require a switching fabric board, and the interface board undertakes the processing function of the service data of the entire system. In a distributed forwarding architecture, the network device may have at least one switching fabric board, and data exchange between multiple interface boards is achieved through the switching fabric board, providing a large-capacity data exchange and processing capacity. Therefore, the data access and processing capacity of the network device with a distributed architecture is greater than that of the network device with a centralized architecture. Optionally, the form of the network device may also be a single board, that is, there is no switching fabric board, and the functions of the interface board and the main control board are integrated on this single board. At this time, the central processing unit on the interface board and the central processing unit on the main control board can be combined into a single central processing unit on this single board to execute the functions after their superposition. The data exchange and processing capacity of this form of network device is relatively low (for example, network devices such as low-end switches or routers). Which architecture to specifically adopt depends on the specific networking deployment scenario and is not limited here.

[0187] In a specific embodiment, the network device 1400 corresponds to the detection device for the access method described above Figure 8 or Figure 9 shown.

[0188] It should be understood that the above-mentioned processor may be a CPU, or may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It should be noted that the processor may be a processor that supports the advanced RISC machines (ARM) architecture.

[0189] Furthermore, in an optional embodiment, the above-mentioned memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.

[0190] The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0191] An embodiment of the present application further provides a detection system for an access mode. The system includes an access device and a management device. The access device is connected to the management device. The access device is used to perform Figure 3 or Figure 5 the operations performed by the access device in the access mode detection method shown. The management device is used to perform Figure 5 the operations performed by the management device in the access mode detection method shown.

[0192] An embodiment of the present application further provides a computer-readable storage medium. At least one instruction is stored in the storage medium. The instruction is loaded and executed by a processor to enable a computer to implement Figure 3 or Figure 5 the access mode detection method shown.

[0193] An embodiment of the present application further provides a computer program (product). When the computer program is executed by a computer, it can cause a processor or a computer to execute Figure 3 or Figure 5 the access mode detection method shown.

[0194] The embodiments of the present application further provide a chip, including a processor, which is configured to call and run instructions stored in a memory, so that a computer installed with the chip executes Figure 3 or Figure 5 the detection method of the access mode shown.

[0195] The embodiments of the present application further provide another chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory. When the code is executed, a computer installed with the chip executes Figure 3 or Figure 5 the detection method of the access mode shown.

[0196] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media integrated. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk), etc.

[0197] Those of ordinary skill in the art can realize that, in combination with the method steps and modules described in the embodiments disclosed herein, they can be implemented by software, hardware, firmware, or any combination thereof. To clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0198] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disk, or the like.

[0199] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the methods of the embodiments of the present application can be described in the context of machine-executable instructions, such as in program modules executed in devices included in a target real or virtual processor. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In various embodiments, the functions of the program modules can be combined or split among the described program modules. The machine-executable instructions for the program modules can be executed within a local or distributed device. In a distributed device, the program modules can be located in both local and remote storage media.

[0200] The computer program code for implementing the methods of the embodiments of the present application can be written in one or more programming languages. These computer program codes can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the computer or other programmable data processing devices, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the computer, partially on the computer, as an independent software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.

[0201] In the context of the embodiments of the present application, the computer program code or relevant data can be carried by any suitable carrier, so that the device, apparatus, or processor can execute the various processes and operations described above. Examples of the carrier include signals, computer-readable media, and the like.

[0202] Examples of signals can include electrical, optical, radio, acoustic, or other forms of propagated signals, such as carrier waves, infrared signals, etc.

[0203] A machine-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More specific examples of a machine-readable storage medium include an electrical connection with one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0204] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and modules can be referred to the corresponding processes in the foregoing method embodiments, and will not be described herein again.

[0205] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual coupling or direct coupling or communication connection can be an indirect coupling or communication connection through some interfaces, devices, or modules, and can also be in the form of electrical, mechanical, or other connections.

[0206] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present application.

[0207] In addition, the functional modules in the various embodiments of the present application can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules.

[0208] When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0209] In this application, terms such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, the first deviation distance can be referred to as the second deviation distance, and similarly, the second deviation distance can be referred to as the first deviation distance.

[0210] It should also be understood that in various embodiments of this application, the magnitudes of the sequence numbers of each process do not imply the sequence of execution. The execution sequence of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0211] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "a plurality of" refers to two or more. For example, a plurality of first data packets refers to two or more first data packets. In this article, the terms "system" and "network" are often used interchangeably.

[0212] It should be understood that the terms used in the description of various examples in this article are only for describing specific examples and are not intended to be restrictive. As used in the description of various examples and the appended claims, the singular forms "a", "an", and "the" are also intended to include the plural forms unless the context clearly indicates otherwise.

[0213] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a correlative relationship describing associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this application generally represents an "or" relationship between the associated objects before and after.

[0214] It should also be understood that the term "comprises" (also referred to as "includes", "including", "comprises", and / or "comprising") when used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groupings.

[0215] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined..." or "if [stated condition or event] is detected" can be interpreted to mean "when determining..." or "in response to determining..." or "when [stated condition or event] is detected" or "in response to detecting [stated condition or event]".

[0216] It should be understood that determining B based on A does not mean determining B solely based on A. B can also be determined based on A and / or other information.

[0217] It should also be understood that the "one embodiment", "an embodiment", and "a possible implementation" mentioned throughout the specification mean that the specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of this application. Therefore, the "in one embodiment" or "in an embodiment", "a possible implementation" that appear throughout the specification do not necessarily refer to the same embodiment. Additionally, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner.

[0218] The above description is only an alternative embodiment of this application and is not intended to limit this application. Any modifications, equivalent replacements, improvements, etc. made within the principle of this application should be included within the protection scope of this application.

Claims

1. A detection method for an access mode, characterized in that, The method includes: Collecting data features of data transmitted by an access device, where the data features indicate features of a terminal device that transmits the data, the terminal device is connected to the access device, and the data features include at least one of packet features, flow behavior features, network features, or device physical features; Determining an access mode of the terminal device based on the data features.

2. The method according to claim 1, wherein The data features include a plurality of the packet features; the determining the access mode of the terminal device based on the data features includes: Identifying an operating system under an access port of the terminal device based on the plurality of packet features; When the operating systems under the access port are different, determining that the access mode of the terminal device is unauthorized access.

3. The method according to claim 2, characterized in that, The identifying the operating system under the access port of the terminal device based on the plurality of packet features includes: Identifying address information under the access port of the terminal device based on the plurality of packet features; When the address information under the access port is the same, identifying the operating system under the access port of the terminal device based on the plurality of packet features; The method further includes: When the address information under the access port is different, determining that the access mode of the terminal device is unauthorized access.

4. The method according to claim 1, characterized in that The data features include the flow behavior features; The determining the access mode of the terminal device based on the data features includes: Obtaining a deviation distance between the flow behavior feature and a reference feature, where the reference feature is a flow behavior feature of data transmitted by a terminal device with an access mode of non-unauthorized access; When the deviation distance is greater than a deviation threshold, determining that the access mode of the terminal device is unauthorized access.

5. The method according to claim 1, wherein The data features include at least one of the network features or the device physical features; the determining the access mode of the terminal device based on the data features includes: Identifying a type of the terminal device based on at least one of the network features or the device physical features; When the type of the terminal device is a router or a hub, determining that the access mode of the terminal device is unauthorized access.

6. The method according to any one of claims 1-5, characterized in that After the determining the access mode of the terminal device based on the data features, it further includes: When the access mode of the terminal device is unauthorized access, blocking the terminal device from transmitting data; Or, when the access mode of the terminal device is unauthorized access, sending unauthorized access information of the terminal device to a management device, where the unauthorized access information is used for the management device to block the terminal device from transmitting data.

7. The method according to claim 6, wherein The blocking the terminal device from transmitting data includes: Closing the access port of the terminal device; Or, adding the address information of the terminal device to a blacklist, where the blacklist is used to block the terminal device corresponding to the address information in the blacklist from transmitting data; Or, logging off a user in an online state on the terminal device.

8. The method according to any one of claims 1 to 7, characterized in that, The data transmitted by the access device is data flowing from the terminal side to the network side.

9. The method according to any one of claims 1-8, characterized in that, The collecting the data features of the data transmitted by the access device includes: Receiving a private connection detection configuration command sent by a management device; Collecting the data features of the data transmitted by the access device based on the private connection detection configuration command.

10. The method according to any one of claims 1-9, characterized in that, The data characteristics of the data transmitted by the acquisition access device include: Copy the data transmitted by the access device to obtain copied data; Collect the data characteristics of the copied data.

11. According to the method described in any one of claims 1-10, characterized in that, The access device is the first-hop forwarding device for the data sent by the terminal device.

12. A detection method for an access mode, characterized in that, The method includes: Receive the unauthorized connection information of the terminal device sent by the access device, where the unauthorized connection information indicates that the access mode of the terminal device is unauthorized connection; Send out an unauthorized connection warning message.

13. The method according to claim 12, wherein After receiving the unauthorized connection information of the terminal device sent by the access device, it further includes: Block the data transmission of the terminal device.

14. The method according to claim 13, wherein The blocking of the data transmission of the terminal device includes: Send a shutdown instruction to the access device, where the shutdown instruction is used for the access device to close the access port of the terminal device; Or, send a blacklist to the access device, where the blacklist includes the address information of the terminal device, and the blacklist is used for the access device to block the data transmission of the terminal device corresponding to the address information in the blacklist; Or, send a logout instruction to the access device, where the logout instruction is used for the access device to log out the user on the terminal device that is in the online state.

15. The method according to any one of claims 12 - 14, characterized in that, After receiving the unauthorized connection information of the terminal device sent by the access device, it further includes: Visually display the unauthorized connection information of the terminal device, where the unauthorized connection information includes at least one of Media Access Control (MAC) address, Internet Protocol (IP) address, access port, access time, unauthorized connection type, or reason for unauthorized connection determination.

16. The method according to any one of claims 12 - 15, characterized in that, Before receiving the unauthorized connection information of the terminal device sent by the access device, it further includes: Send an unauthorized connection detection configuration command to the access device, where the unauthorized connection detection configuration command is used for the access device to collect the data characteristics of the data transmitted by the access device and determine the access mode of the terminal device based on the data characteristics.

17. A detection device for an access mode, characterized in that, The device includes: An acquisition module, configured to acquire the data characteristics of the data transmitted by the access device, where the data characteristics indicate the characteristics of the terminal device transmitting the data, the terminal device is connected to the access device, and the data characteristics include at least one of packet characteristics, flow behavior characteristics, network characteristics, or device physical characteristics; A determination module, configured to determine the access mode of the terminal device based on the data characteristics.

18. A detection device for an access method, characterized in that, The device includes: A receiving module, configured to receive the unauthorized connection information of the terminal device sent by the access device, where the unauthorized connection information indicates that the access mode of the terminal device is unauthorized connection; An alarm module, configured to send out an unauthorized connection warning message.

19. A detection device for an access mode, characterized in that, The device includes a memory and a processor; at least one computer instruction is stored in the memory, and the at least one computer instruction is loaded and executed by the processor to enable the device to implement the access mode detection method according to any one of claims 1-11, or to enable the device to implement the access mode detection method according to any one of claims 12-16.

20. A detection system for an access method, characterized in that, The system includes an access device and a management device, where the access device is used to implement the access mode detection method according to any one of claims 1-11, and the management device is used to implement the access mode detection method according to any one of claims 12-16.

21. A computer-readable storage medium, characterized in that, At least one instruction is stored in the computer storage medium, and the at least one instruction is loaded and executed by a processor to enable the computer to implement the detection method of the access mode described in any one of claims 1-11, or to enable the computer to implement the detection method of the access mode described in any one of claims 12-16.

22. A computer program product, characterized in that, The computer program product includes: computer program code, and the computer program code is loaded and executed by a computer to enable the computer to implement the detection method of the access mode described in any one of claims 1-11, or to enable the computer to implement the detection method of the access mode described in any one of claims 12-16.

Citation Information

Cited By

  • Access mode detection method, apparatus, device, system and medium

    WO2025161562A1