Equipment exception identification method and device, electronic equipment and storage medium

By building a feature library for the equipment in the engineering mode, identifying whether the target equipment is running in the engineering mode, the vulnerability problem of equipment abnormal identification is solved, and accurate identification of equipment abnormalities and risk prevention is achieved.

CN120499668APending Publication Date: 2025-08-15BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510622697.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The engineering model of existing equipment has loopholes, allowing modification of underlying equipment information, resulting in resource information leakage and lack of effective abnormal identification methods.

Method used

By collecting the characteristic information of the device before entering and exiting the project mode, a project mode feature library is built to identify whether the target device is running in the project mode, and abnormal identification is performed using feature matching and similarity calculation.

Benefits of technology

Accurately identify whether the equipment is operating in engineering mode, prevent resource information from being leaked, and improve the applicability and accuracy of equipment abnormal identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499668A_ABST
    Figure CN120499668A_ABST
Patent Text Reader

Abstract

The invention provides an equipment exception identification method and device, electronic equipment and a storage medium, and relates to the technical field of mobile communication, in particular to the technical field of mobile security risk control. According to the specific implementation scheme, the method comprises the steps of determining a first feature set of sample equipment during operation in an engineering mode based on first collection data before the sample equipment enters the engineering mode and second collection data of the sample equipment in the engineering mode; constructing an engineering mode feature library according to the first feature set; receiving a second feature set sent by the target device, wherein the second feature set at least comprises feature information of engineering mode related features; and according to the second feature set and the engineering mode feature library, identifying whether the target equipment runs in the engineering mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of mobile communication technology, specifically to the field of mobile security risk control technology, and more particularly to a device anomaly identification method, apparatus, electronic device, and storage medium. Background Art

[0002] The device's engineering mode is a software tool engineers use to debug device configurations. Accessible via a password, it allows engineers to set parameters like phone and network settings and debug underlying issues. However, many manufacturers' engineering modes contain vulnerabilities that allow them to modify underlying device information, potentially leaking resource information. Summary of the Invention

[0003] The present disclosure provides a method, apparatus, electronic device, and storage medium for identifying device anomalies.

[0004] According to one aspect of the present disclosure, a method for identifying device anomalies is provided, comprising: determining a first feature set when the sample device is operating in the engineering mode based on first collected data of the sample device before entering the engineering mode and second collected data of the sample device in the engineering mode; constructing an engineering mode feature library based on the first feature set; receiving a second feature set sent by a target device, the second feature set at least including feature information of features related to the engineering mode; and identifying whether the target device is operating in the engineering mode based on the second feature set and the engineering mode feature library.

[0005] According to one aspect of the present disclosure, another method for identifying device anomalies is provided, including: collecting feature information of features related to the target device and the engineering mode to obtain a second feature set; sending the second feature set to a server, and the second feature set is used to identify whether the target device is running in the engineering mode.

[0006] According to another aspect of the present disclosure, there is provided a device for identifying anomalies of an equipment, including: a determination module for determining a first feature set of the sample device when it is operating in the engineering mode based on first collected data of the sample device before entering the engineering mode and second collected data of the sample device in the engineering mode; a construction module for constructing an engineering mode feature library according to the first feature set; a receiving module for receiving a second feature set sent by a target device, the second feature set at least including feature information of features related to the engineering mode; and an identification module for identifying whether the target device is operating in the engineering mode according to the second feature set and the engineering mode feature library.

[0007] According to another aspect of the present disclosure, a device for identifying anomalies of an equipment is provided, including: an acquisition module for collecting feature information of features related to a target device and an engineering mode to obtain a second feature set; a sending module for sending the second feature set to a server, wherein the second feature set is used to identify whether the target device is running in the engineering mode.

[0008] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the device abnormality identification method described in the embodiment of the above aspect.

[0009] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, on which a computer program / instruction is stored. The computer instructions are used to enable the computer to execute the device abnormality identification method described in the embodiment of the above aspect.

[0010] According to another aspect of the present disclosure, a computer program product is provided, including a computer program / instruction, which, when executed by a processor, implements the device abnormality identification method described in the embodiment of the first aspect.

[0011] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.

[0013] Figure 1 A schematic diagram of a process for identifying device anomalies according to an embodiment of the present disclosure;

[0014] Figure 2 A schematic diagram of a process for constructing an engineering pattern feature library in a device anomaly identification method provided by an embodiment of the present disclosure;

[0015] Figure 3 A schematic diagram of a process for constructing an engineering pattern feature library according to an embodiment of the present disclosure;

[0016] Figure 4 A flowchart of another device anomaly identification method provided by an embodiment of the present disclosure;

[0017] Figure 5A flowchart of another device anomaly identification method provided by an embodiment of the present disclosure;

[0018] Figure 6 A schematic diagram of the structure of a device abnormality identification device provided by an embodiment of the present disclosure;

[0019] Figure 7 A schematic diagram of the structure of another device abnormality identification device provided by an embodiment of the present disclosure;

[0020] Figure 8 The present invention is a block diagram of an electronic device for implementing the device abnormality identification method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0021] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0022] It should be noted that the acquisition, storage, use, and processing of data in this disclosure are in compliance with relevant laws and regulations.

[0023] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this disclosure are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards.

[0024] The following describes the device anomaly identification method, apparatus, electronic device, and storage medium according to embodiments of the present disclosure with reference to the accompanying drawings.

[0025] Mobile security risk control technology refers to the use of technical means to identify, evaluate and prevent security threats in mobile communications, ensuring the security of user data, devices and networks. The core goal is to prevent information leakage, attacks and system intrusions.

[0026] Figure 1 A flowchart of a method for identifying device anomalies provided in an embodiment of the present disclosure.

[0027] like Figure 1 As shown, the device abnormality identification method may include:

[0028] S101 : Determine a first feature set of the sample device when it operates in the engineering mode based on first collected data of the sample device before the sample device enters the engineering mode and second collected data of the sample device in the engineering mode.

[0029] It should be noted that the execution entity of the device anomaly identification method in the embodiments of the present disclosure may be a hardware device with data processing capabilities and / or the necessary software to drive the operation of the hardware device. Optionally, the execution entity may include a server. Optionally, the server includes but is not limited to a network server, an application server, a server in a distributed system, or a server integrated with a blockchain. This is not specifically limited in the embodiments of the present disclosure.

[0030] It's understood that a device's engineering mode is a special system entry designed by device manufacturers for developing, testing, debugging, and optimizing hardware performance. It requires activation through specific commands or tools. Engineering mode allows you to modify the device's hardware, software, and device identification information.

[0031] In some embodiments, when the device is running in engineering mode, keywords and newly added files will appear in the system properties. When the device exits engineering mode, the keywords and newly added files will disappear. In other words, the keywords and newly added files can be used as feature information.

[0032] In some embodiments, first collected data before the sample device enters the engineering mode and second collected data in the engineering mode can be collected, and based on the first collected data and the second collected data, feature information of the sample device when running in the engineering mode can be determined, and a first feature set can be generated based on the feature information.

[0033] In some embodiments, the system properties of the sample device may be collected to determine keywords, and the file directory of the sample device may be collected to determine whether new files are added, thereby obtaining the first collected data and the second collected data.

[0034] S102: Construct an engineering pattern feature library based on the first feature set.

[0035] In some embodiments, the first feature set may be used as an engineering mode feature library. The engineering mode feature library may be obtained by adding feature information in the first feature set to an initial feature library.

[0036] In some embodiments, a plurality of engineering pattern feature libraries corresponding to different sample devices may be constructed. Optionally, the different sample devices may be sample devices of different device types, for example, different models or different systems.

[0037] S103: Receive a second feature set sent by the target device, where the second feature set at least includes feature information related to the engineering mode.

[0038] Understandably, users won't trigger engineering mode when using a target device. Operations that cause the target device to operate in engineering mode are often caused by the manufacturer or an unauthorized user. In other words, by acquiring feature information related to the target device and engineering mode, it's possible to identify whether the target device is operating in engineering mode based on this feature information, thereby determining whether the target device is exhibiting abnormal or risky behavior.

[0039] In some embodiments, an instruction message for collecting feature information can be sent to the target device, and the target device can collect feature information of features related to the engineering mode and generate a second feature set based on the feature information, so that the server can receive the second feature set sent by the target device.

[0040] In some embodiments, before receiving the second feature set, the server may also verify the security of the target device, and after the target device passes the security verification, the server may receive the second feature set sent by the target device to improve the security of data transmission.

[0041] S104 : Identify whether the target device is running in the engineering mode based on the second feature set and a pre-built engineering mode feature library.

[0042] In some embodiments, a pre-built engineering mode feature library includes feature information of a device operating in engineering mode. Whether the target device is operating in engineering mode is identified by determining whether the feature information in the second feature set exists in the pre-built engineering mode feature library.

[0043] Optionally, if the feature information in the second feature set exists in a pre-built engineering mode feature library, it can be identified that the target device is running in engineering mode; if the feature information in the second feature set does not exist in the pre-built engineering mode feature library, it can be identified that the target device is not running in engineering mode.

[0044] In some embodiments, the feature information in the second feature set may be matched with the feature information in the engineering mode feature library. If the match is successful, it may be determined that the feature information in the second feature set exists in the engineering mode feature library.

[0045] Optionally, the first vector corresponding to the feature information in the second feature set and the second vector corresponding to the feature information in the engineering pattern feature library can be determined, and then the similarity between the first vector and the second vector can be calculated. If the similarity is greater than the similarity threshold, it can be determined that the feature information in the second feature set and the feature information in the engineering pattern feature library are successfully matched.

[0046] For example, the feature information in the second feature set is Feature A, Feature B, and Feature C, and the feature information in the engineering pattern feature library is Feature 1, Feature 2, and Feature 3. If Feature A successfully matches Feature 2, it can be determined that the feature information in the second feature set exists in the engineering pattern feature library. If Feature A, Feature B, and Feature C do not successfully match Feature 1, Feature 2, and Feature 3, it can be determined that the feature information in the second feature set does not exist in the pre-built engineering pattern feature library.

[0047] In some embodiments, feature information of devices of different device types when operating in engineering mode can be collected to construct an engineering mode feature library. Alternatively, feature information of different types of devices when operating in engineering mode can be collected separately based on the device type to construct an engineering mode feature library corresponding to each device type.

[0048] Optionally, by determining the target device type corresponding to the target device, the engineering mode feature library corresponding to the target device type can be determined from multiple engineering mode feature libraries as the engineering mode feature library of the target device, so as to identify whether the target device is running in engineering mode based on the engineering mode feature library.

[0049] According to the device anomaly identification method provided by the embodiment of the present disclosure, by determining the first feature set of the sample device when it is running in engineering mode and constructing an engineering mode feature library based on the first feature set, the method then receives the second feature set sent by the target device and identifies whether the target device is running in engineering mode based on the second feature set and the engineering mode feature library. Thus, by obtaining feature information of the target device and the engineering mode-related features and performing identification based on this feature information, it is possible to accurately identify whether the target device is running in engineering mode. Furthermore, it is possible to determine whether the target device is abnormal or whether there is risky behavior based on whether the target device is running in engineering mode, thereby improving the applicability of identifying device anomalies.

[0050] Based on the above embodiments, the present disclosure can explain the construction process of the engineering pattern feature library, such as Figure 2 As shown, the construction process of the engineering pattern feature library may include:

[0051] S201 : Determine a first feature set of a sample device when it operates in an engineering mode.

[0052] It is understandable that when a device is running in engineering mode, keywords will appear in the system properties and new files will be added. These keywords and new files can be used as feature information. In other words, the system properties and file directories of the sample device can be collected to obtain the first feature set.

[0053] In some embodiments, in order to distinguish the feature information of the sample device before entering the engineering mode and in the engineering mode to improve the accuracy of recognition, the feature information of the sample device before entering the engineering mode and the feature information of the sample device in the engineering mode can be collected separately to obtain a first feature set.

[0054] That is, the system properties and file directories of the sample device before entering the engineering mode can be collected to obtain first collected data, and the system properties and file directories of the sample device in the engineering mode can be collected to obtain second collected data.

[0055] Optionally, whether keywords appear in the system attributes in the first collected data and the files contained in the file directory can be used as characteristic information of the sample device before entering the engineering mode, and whether keywords appear in the system attributes in the second collected data and the files contained in the file directory can be used as characteristic information of the sample device in the engineering mode.

[0056] Optionally, the first collected data and the second collected data also include characteristic information such as environment files and environment variables.

[0057] Furthermore, a first feature set can be obtained by comparing the first and second collected data. Specifically, by comparing the identical and different feature information in the first and second collected data, a comparison result is obtained, and the first and second collected data, as well as the comparison result, are used as the third feature set. This allows for clarifying the similarities or differences between the feature information of the sample device before entering engineering mode and in engineering mode, providing data support for constructing an accurate engineering mode feature library.

[0058] In some embodiments, the comparison between the first collected data and the second collected data may be an exclusive OR operation, and the third feature set is obtained by performing the exclusive OR operation on the first collected data and the second collected data. In other words, by performing the exclusive OR operation on the first collected data and the second collected data, the same feature information and different feature information in the first collected data and the second collected data can be determined as the result of the exclusive OR operation, and the first collected data, the second collected data, and the result of the exclusive OR operation are used as the third feature set.

[0059] For example, the first collected data includes features A, B, and C, and the second collected data includes features 1, 2, and 3. If the result of the XOR operation is that features A and 1 are the same, features B and 2 are different, and features C and 3 are different, then the third feature set includes features A, B, C, 1, 2, and 3, as well as the result of the XOR operation.

[0060] Furthermore, after obtaining the third feature set, the third feature set may be screened to obtain the first feature set, so that the feature information in the first feature set is the feature information of the sample device in the engineering mode.

[0061] In some embodiments, a screening task can be generated based on the third feature set and sent to a screening device, which then filters the third feature set based on the screening task to obtain a screening result. This allows the screening result fed back by the screening device to be received, and the first feature set to be obtained based on the screening result.

[0062] Optionally, the screening result may be used to indicate the removal of feature information that does not belong to the sample device in engineering mode. For example, continuing with the above example, the screening result may be to remove Feature 2 and Feature 1 from the third feature set to obtain a first feature set that includes Feature A, Feature B, Feature C, and Feature 1.

[0063] S202: Construct an engineering pattern feature library based on the first feature set.

[0064] In some embodiments, the first feature set may be used as an engineering mode feature library. The engineering mode feature library may be obtained by adding feature information in the first feature set to an initial feature library.

[0065] In some embodiments, an engineering mode feature library corresponding to different device type information can also be constructed, thereby improving the recognition speed of the target device based on the engineering mode feature library, expanding the recognition range, and further improving the accuracy of identifying the target device. Optionally, the device type information can be the system model of the device.

[0066] In some embodiments, the device type information of the sample devices is determined, and the first feature set is divided according to the device type information to obtain a fourth feature set corresponding to the device type information. For example, the device type information of the sample devices is model 1, model 2, and model 3. By obtaining the feature information corresponding to model 1, the feature information corresponding to model 2, and the feature information corresponding to model 3 from the first feature set and dividing the first feature set, a fourth feature set 1 corresponding to model 1, a fourth feature set 2 corresponding to model 2, and a fourth feature set 3 corresponding to model 3 can be obtained.

[0067] Furthermore, the engineering mode feature library corresponding to the device type information can be determined based on the fourth feature set. By adding the feature information in the fourth feature set to the initial feature library, the engineering mode feature library corresponding to the device type information can be obtained. For example, adding fourth feature set 1 to the initial feature library yields engineering mode feature library 1 corresponding to model 1; adding fourth feature set 2 to the initial feature library yields engineering mode feature library 2 corresponding to model 1; and adding fourth feature set 3 to the initial feature library yields engineering mode feature library 3 corresponding to model 1.

[0068] According to the device anomaly identification method provided by the embodiments of the present disclosure, by collecting a first feature set of a sample device operating in engineering mode, an engineering mode feature library can be constructed based on the first feature set. Thus, by acquiring feature information related to the sample device and engineering mode, the engineering mode feature library is constructed, providing data support for identifying target devices based on the engineering mode feature library. By constructing an engineering mode feature library corresponding to information on different device types, target devices of different types can be identified, improving the response speed and accuracy of identification.

[0069] Figure 3 Shown is a flowchart of building an engineering pattern feature library. Figure 3 The system includes information collection module 1 and information collection module 2, wherein information collection module 1 is used to collect system properties and file directories of the sample device before entering engineering mode; information collection module 2 is used to collect system properties and file directories of the sample device in engineering mode.

[0070] Information collection module 1 can obtain the first collected data by collecting the system properties and file directories of the sample device before entering the engineering mode. Information collection module 2 can obtain the second collected data by collecting the system properties and file directories of the sample device in the engineering mode. Then, an XOR operation is performed on the first collected data and the second collected data to obtain a third feature set, and the third feature set is filtered to obtain the first feature set. Based on the first feature set, an engineering mode feature library is constructed.

[0071] Figure 4 A flowchart of a method for identifying device anomalies provided in an embodiment of the present disclosure.

[0072] like Figure 4 As shown, the device abnormality identification method may include:

[0073] S401 : Determine a first feature set of the sample device when it operates in the engineering mode based on first collected data of the sample device before the sample device enters the engineering mode and second collected data of the sample device in the engineering mode.

[0074] S402: Construct an engineering pattern feature library based on the first feature set.

[0075] The relevant contents of steps S401-S402 can be found in the above embodiment and will not be repeated here.

[0076] S403: Send instruction information to the target device.

[0077] In some embodiments, the instruction information includes at least one or more feature identifiers related to the engineering mode to instruct the target device to perform feature collection. In other words, the instruction information can be generated based on the one or more feature identifiers related to the engineering mode.

[0078] In some embodiments, one or more feature identifiers related to the engineering mode of the target device can be determined based on the device type information of the target device to generate instruction information, thereby instructing the collection of feature information related to the engineering mode of the target device to obtain a second feature set. Using the instruction information, the target device can accurately collect feature information related to the engineering mode, avoiding the collection of irrelevant information.

[0079] In some embodiments, the target device can report its own device type information to the server. The server determines the device type information of the target device by receiving the information reported by the target device, and then matches the device type information of the target device with the device type information of the engineering mode feature library to determine the engineering mode feature library with the same device type information. Then, one or more feature identifiers related to the engineering mode that match the device type information can be determined from the engineering mode feature library.

[0080] Optionally, a feature identifier corresponding to each feature information may be obtained from the engineering mode feature library as one or more feature identifiers related to the engineering mode.

[0081] Furthermore, according to one or more feature identifiers related to the engineering mode, instruction information is generated and sent to the target device, thereby instructing the target device to perform feature collection.

[0082] S404: Receive a second feature set sent by the target device, where the second feature set at least includes feature information related to the engineering mode.

[0083] The relevant contents of step S404 can be found in the above embodiment and will not be repeated here.

[0084] S405 : Identify whether the target device is running in the engineering mode based on the second feature set and a pre-built engineering mode feature library.

[0085] In some embodiments, it is possible to determine whether the feature information in the second feature set exists in the engineering mode feature library to identify whether the target device is running in engineering mode, thereby enabling rapid identification of the target device and improving the simplicity of identifying the target device.

[0086] In some embodiments, in response to at least one feature information in the second feature set existing in the engineering mode feature library, it is identified that the target device is running in engineering mode; in response to the feature information in the second feature set not existing in the engineering mode feature library, it is identified that the target device is not running in engineering mode.

[0087] In some embodiments, when each device type information corresponds to an engineering mode feature library, it is possible to identify whether the target device is running in engineering mode based on the device type information of the target device and the engineering mode feature library, thereby improving the accuracy of identifying the target device.

[0088] In some embodiments, a target engineering mode feature library corresponding to the target device can be determined based on the device type information of the target device. This is accomplished by using the device type information of the target device as first device type information, using the device type information corresponding to the engineering mode feature library as second device type information, and matching the first device type information with the second device type information to determine the engineering mode feature library corresponding to the second device type information that successfully matches the first device type information as the target engineering mode feature library.

[0089] For example, there are Engineering Mode Feature Library 1, Engineering Mode Feature Library 2, and Engineering Mode Feature Library 3. The device type information 1 corresponding to Engineering Mode Feature Library 1 is Model A, the device type information 2 corresponding to Engineering Mode Feature Library 2 is Model C, and the device type information 3 corresponding to Engineering Mode Feature Library 3 is Model B. If the device type information of the target device is Model A, which is the same as Device Type Information 2, then the target Engineering Mode Feature Library is determined to be Engineering Mode Feature Library 2.

[0090] Furthermore, whether the target device is operating in engineering mode can be identified based on the second feature set and the target engineering mode feature library. That is, in response to at least one feature information in the second feature set being present in the target engineering mode feature library, it is identified that the target device is operating in engineering mode; in response to the feature information in the second feature set not being present in the target engineering mode feature library, it is identified that the target device is not operating in engineering mode.

[0091] In some embodiments, after determining that the target device is running in engineering mode, restrictions can be placed on the target device to limit its business operations and avoid leaking resource information. Optionally, risky behavior of the target device can be determined to restrict the target device based on the risky behavior.

[0092] In some embodiments, in response to identifying that the target device is operating in engineering mode, risky behavior of the target device is determined based on the second feature set. Optionally, a correspondence between feature information and risky behavior can be established in advance based on different feature information and different risky behaviors, and the correspondence can be queried based on the feature information in the second feature set to determine the risky behavior of the target device.

[0093] Furthermore, by analyzing the target device's operating status information, the target device's current business scenario can be determined, allowing for restricted operations based on the risky behavior and business scenario. Alternatively, the target device can be restricted based on whether the risky behavior impacts the current business scenario and, if determined to have impacted the business scenario, its operations can be restricted.

[0094] The current business scenario of the target device refers to the situation in which the target device is used to achieve a specific business goal or solve a specific business problem, including the purpose of use of the target device, the operating process, etc. For example, the business scenario is using the target device to access applications for browsing, social networking, shopping, etc.

[0095] According to the device anomaly identification method provided by the embodiment of the present disclosure, by sending an instruction message to the target device to instruct the target device to perform feature collection, a second feature set sent by the target device can be received, and based on the second feature set and a pre-built engineering mode feature library, whether the target device is running in engineering mode can be identified. Thus, by obtaining feature information of the target device and the engineering mode-related features and performing identification based on this feature information, it is possible to accurately identify whether the target device is running in engineering mode, and then determine whether the target device is abnormal or whether there is risky behavior based on whether the target device is running in engineering mode, thereby improving the applicability of identifying device anomalies.

[0096] Figure 5 A flowchart of a method for identifying device anomalies provided in an embodiment of the present disclosure.

[0097] like Figure 5 As shown, the device abnormality identification method may include:

[0098] S501 : Collect feature information of features related to the target device and the engineering mode to obtain a second feature set.

[0099] It should be noted that the execution entity of the device anomaly identification method in the embodiments of the present disclosure may be a hardware device with data processing capabilities and / or the necessary software to drive the operation of the hardware device. Optionally, the execution entity may include a user terminal and other smart devices. Optionally, user terminals include but are not limited to mobile phones, computers, intelligent voice interaction devices, etc. This is not specifically limited in the embodiments of the present disclosure.

[0100] In some embodiments, the second feature set includes at least feature information related to the engineering mode. Based on the indication information sent by the server, feature information of the target device related to the engineering mode can be collected, so that the second feature set can be generated based on the feature information.

[0101] In some embodiments, by receiving indication information sent by the server, the indication information includes at least one or more feature identifiers related to the engineering mode, thereby enabling accurate collection of feature information related to the engineering mode based on the feature identifiers. In other words, feature information related to the engineering mode of the target device can be collected based on the feature identifiers to obtain a second feature set.

[0102] It's understandable that when a device is running in engineering mode, keywords appear in the system properties and new files are added. These keywords and new files can be used as feature information. In other words, the system properties and file directories of the target device can be collected to obtain feature information related to engineering mode, making the feature information closely related to engineering mode.

[0103] It should be noted that the collection of feature information involved in the embodiments of the present disclosure is carried out with the user's authorization and strictly complies with relevant laws and regulations such as privacy and security. Only the feature information itself is collected and does not involve reading any user privacy information.

[0104] S502: Send a second feature set to the server, where the second feature set is used to identify whether the target device is running in engineering mode.

[0105] In some embodiments, the second feature set is sent to the server, which then identifies whether the target device is operating in engineering mode. Alternatively, the server can determine whether the feature information in the second feature set exists in an engineering mode feature library to identify whether the target device is operating in engineering mode, thereby enabling rapid identification of the target device and improving the simplicity of identifying the target device.

[0106] For example, if at least one feature information in the second feature set exists in the engineering mode feature library, it is identified that the target device is running in engineering mode; if the feature information in the second feature set does not exist in the engineering mode feature library, it is identified that the target device is not running in engineering mode.

[0107] According to the device anomaly identification method provided by the embodiments of the present disclosure, feature information related to the target device and engineering mode is collected to obtain a second feature set, and the second feature set is sent to the server to identify whether the target device is operating in engineering mode. Thus, the target device can be identified based on the characteristics of the device operating in engineering mode, which can improve the accuracy of identification. By identifying the target device on the server, the efficiency of target device identification can be improved.

[0108] Corresponding to the device abnormality identification methods provided in the above-mentioned embodiments, an embodiment of the present disclosure also provides a device abnormality identification device. Since the device abnormality identification device provided in the embodiment of the present disclosure corresponds to the device abnormality identification methods provided in the above-mentioned embodiments, the implementation methods of the above-mentioned device abnormality identification methods are also applicable to the device abnormality identification device provided in the embodiment of the present disclosure, and will not be described in detail in the following embodiments.

[0109] Figure 6 A schematic diagram of the structure of a device abnormality identification device provided in an embodiment of the present disclosure.

[0110] like Figure 6 As shown, the device anomaly identification apparatus 600 of an embodiment of the present disclosure includes a determination module 601 , a construction module 602 , a receiving module 603 and an identification module 604 .

[0111] A determination module 601 is configured to determine a first feature set of the sample device when it is operating in the engineering mode based on first collected data before the sample device enters the engineering mode and second collected data of the sample device in the engineering mode;

[0112] A construction module 602 is used to construct an engineering pattern feature library based on the first feature set;

[0113] A receiving module 603 is configured to receive a second feature set sent by a target device, where the second feature set includes at least feature information related to the engineering mode;

[0114] The identification module 604 is configured to identify whether the target device is running in the engineering mode based on the second feature set and the engineering mode feature library.

[0115] In one embodiment of the present disclosure, the determination module 601 is further used to: collect system properties and file directories of the sample device before it enters the engineering mode to obtain first collected data; collect system properties and file directories of the sample device in the engineering mode to obtain second collected data; and compare the first collected data with the second collected data to obtain a first feature set.

[0116] In one embodiment of the present disclosure, the determination module 601 is further used to: perform an XOR operation on the first collected data and the second collected data to obtain a third feature set; generate a screening task based on the third feature set, and send the screening task to the screening device; receive the screening results fed back by the screening device, and obtain the first feature set based on the screening results.

[0117] In one embodiment of the present disclosure, the construction module 602 is further used to: determine the device type information of the sample device; divide the first feature set according to the device type information to obtain a fourth feature set corresponding to the device type information; and determine the engineering mode feature library corresponding to the device type information based on the fourth feature set.

[0118] In one embodiment of the present disclosure, the receiving module 603 is further configured to send instruction information to the target device, where the instruction information at least includes one or more feature identifiers related to the engineering mode, so as to instruct the target device to perform feature collection.

[0119] In one embodiment of the present disclosure, the receiving module 603 is also used to: determine the device type information of the target device; determine one or more feature identifiers related to the engineering mode that match the device type information from the engineering mode feature library; generate indication information based on the one or more feature identifiers related to the engineering mode, and send the indication information to the target device.

[0120] In one embodiment of the present disclosure, the identification module 604 is further used to: in response to at least one feature information in the second feature set being present in the engineering mode feature library, identify that the target device is running in engineering mode; in response to the feature information in the second feature set not being present in the engineering mode feature library, identify that the target device is not running in engineering mode.

[0121] In one embodiment of the present disclosure, the identification module 604 is further used to: determine the target engineering mode feature library corresponding to the target device based on the device type information of the target device; and identify whether the target device is running in engineering mode based on the second feature set and the target engineering mode feature library.

[0122] In one embodiment of the present disclosure, the identification module 604 is further used to: in response to identifying that the target device is running in engineering mode, determine the risk behavior of the target device based on the second feature set; determine the current business scenario of the target device; and restrict operations on the target device based on the risk behavior and the business scenario.

[0123] According to the device anomaly identification device provided by the embodiment of the present disclosure, by determining the first feature set of the sample device when it is running in engineering mode and constructing an engineering mode feature library based on the first feature set, it is possible to identify whether the target device is running in engineering mode by receiving the second feature set sent by the target device and identifying whether the target device is running in engineering mode based on the second feature set and the engineering mode feature library. Therefore, by obtaining feature information of the target device and the features related to engineering mode and identifying based on this feature information, it is possible to accurately identify whether the target device is running in engineering mode, and then determine whether the target device is abnormal or whether there is risky behavior based on whether the target device is running in engineering mode, thereby improving the applicability of identifying device anomalies.

[0124] Figure 7 A schematic diagram of the structure of a device abnormality identification device provided in an embodiment of the present disclosure.

[0125] like Figure 7 As shown, the device anomaly identification apparatus 700 according to an embodiment of the present disclosure includes a collection module 701 and a sending module 702 .

[0126] The collection module 701 is used to collect feature information of features related to the target device and the engineering mode to obtain a second feature set;

[0127] The sending module 702 is configured to send a second feature set to the server, where the second feature set is used to identify whether the target device is running in the engineering mode.

[0128] In one embodiment of the present disclosure, the acquisition module 701 is further used to: receive indication information sent by the server, the indication information at least including one or more feature identifiers related to the engineering mode; based on the feature identifiers, collect feature information of features related to the target device and the engineering mode to obtain a second feature set.

[0129] In one embodiment of the present disclosure, the collection module 701 is further configured to collect system properties and file directories of the target device to obtain feature information related to the engineering mode.

[0130] According to the device anomaly identification device provided by the embodiments of the present disclosure, feature information related to the target device and the engineering mode is collected to obtain a second feature set, and the second feature set is sent to the server to identify whether the target device is operating in engineering mode. Thus, the target device can be identified based on the characteristics of the device operating in engineering mode, which can improve the accuracy of identification. By identifying the target device on the server, the efficiency of target device identification can be improved.

[0131] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0132] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0133] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are provided as examples only and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0134] like Figure 8 As shown, the device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to computer programs / instructions stored in a read-only memory (ROM) 802 or computer programs / instructions loaded from a storage unit 806 into a random access memory (RAM) 803. Various programs and data required for the operation of the device 800 can also be stored in the RAM 803. The computing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0135] Various components in device 800 are connected to I / O interface 805, including: an input unit 806 such as a keyboard, mouse, etc.; an output unit 807 such as various types of displays, speakers, etc.; a storage unit 808 such as a magnetic disk, optical disk, etc.; and a communication unit 809 such as a network card, modem, wireless communication transceiver, etc. The communication unit 809 allows device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0136] The computing unit 801 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as the device anomaly identification method. For example, in some embodiments, the device anomaly identification method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 806. In some embodiments, part or all of the computer program / instructions can be loaded and / or installed on the device 800 via the ROM 802 and / or the communication unit 809. When the computer program / instructions are loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the device anomaly identification method described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform the device anomaly identification method in any other appropriate manner (e.g., by means of firmware).

[0137] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs / instructions that are executable and / or interpreted on a programmable system comprising at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0138] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0139] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0140] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0141] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), the Internet, and a blockchain network.

[0142] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. The client-server relationship arises through computer programs / instructions running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0143] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.

[0144] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A method for identifying device anomalies, wherein: The method comprises: Determining a first feature set of the sample device when it operates in the engineering mode based on first collected data of the sample device before the sample device enters the engineering mode and second collected data of the sample device in the engineering mode; Constructing an engineering pattern feature library based on the first feature set; receiving a second feature set sent by the target device, wherein the second feature set includes at least feature information related to the engineering mode; According to the second feature set and the engineering mode feature library, it is identified whether the target device is running in the engineering mode.

2. The method according to claim 1, wherein The determining, based on the first collected data of the sample device before entering the engineering mode and the second collected data of the sample device in the engineering mode, a first feature set when the sample device operates in the engineering mode includes: Collecting system properties and file directories of the sample device before entering engineering mode to obtain the first collected data; Collecting system properties and file directories of the sample device in engineering mode to obtain the second collected data; The first feature set is obtained by comparing the first collected data with the second collected data.

3. The method according to claim 2, wherein: The obtaining the first feature set by comparing the first collected data with the second collected data includes: Performing an XOR operation on the first collected data and the second collected data to obtain a third feature set; generating a screening task based on the third feature set, and sending the screening task to a screening device; Receive the screening result fed back by the screening device, and obtain the first feature set based on the screening result.

4. The method according to claim 1, wherein The method further comprises: Determining device type information of the sample device; Dividing the first feature set according to the device type information to obtain a fourth feature set corresponding to the device type information; An engineering mode feature library corresponding to the device type information is determined according to the fourth feature set.

5. The method according to any one of claims 1 to 4, wherein Before receiving the second feature set sent by the target device, the method further includes: Sending instruction information to the target device, where the instruction information at least includes one or more feature identifiers related to the engineering mode, to instruct the target device to perform feature collection.

6. The method according to claim 5, wherein: The sending the instruction information to the target device includes: Determining device type information of the target device; Determining, from the engineering mode feature library, one or more feature identifiers associated with the engineering mode that match the device type information; The indication information is generated according to one or more characteristic identifiers related to the engineering mode, and the indication information is sent to the target device.

7. The method according to any one of claims 1 to 4, wherein The identifying, based on the second feature set and the engineering mode feature library, whether the target device is operating in the engineering mode includes: In response to at least one feature information in the second feature set being present in the engineering mode feature library, identifying that the target device is operating in the engineering mode; In response to feature information in the second feature set not existing in the engineering mode feature library, it is identified that the target device is not operating in the engineering mode.

8. The method according to claim 7, wherein: The identifying, based on the second feature set and the engineering mode feature library, whether the target device is operating in the engineering mode includes: Determining a target engineering mode feature library corresponding to the target device according to the device type information of the target device; According to the second feature set and a target engineering mode feature library, it is identified whether the target device is running in the engineering mode.

9. The method according to any one of claims 1 to 4, wherein The method further comprises: In response to identifying that the target device is operating in the engineering mode, determining a risky behavior of the target device based on the second feature set; Determining the current service scenario of the target device; Restrict operations on the target device based on the risky behavior and the business scenario.

10. A method for identifying device anomalies, wherein: The method comprises: Collecting feature information of features related to the target device and the engineering mode to obtain a second feature set; The second feature set is sent to the server, where the second feature set is used to identify whether the target device is running in the engineering mode.

11. The method according to claim 10, wherein: The collecting of feature information of features related to the target device and the engineering mode to obtain a second feature set includes: receiving indication information sent by the server, wherein the indication information at least includes one or more feature identifiers related to the engineering mode; According to the feature identifier, feature information of features related to the target device and the engineering mode is collected to obtain the second feature set.

12. The method according to claim 10 or 11, wherein: The collecting of feature information of features related to the target device and the engineering mode includes: The system attributes and file directories of the target device are collected to obtain feature information related to the engineering mode.

13. A device for identifying abnormalities in equipment, wherein: The device comprises: a determination module, configured to determine a first feature set when the sample device operates in the engineering mode based on first collected data before the sample device enters the engineering mode and second collected data of the sample device in the engineering mode; A construction module, configured to construct an engineering pattern feature library based on the first feature set; a receiving module, configured to receive a second feature set sent by a target device, wherein the second feature set at least includes feature information related to the engineering mode; An identification module is used to identify whether the target device is running in the engineering mode based on the second feature set and the engineering mode feature library.

14. A device for identifying abnormalities in equipment, wherein: The device comprises: an acquisition module, configured to acquire feature information of features related to the target device and the engineering mode to obtain a second feature set; The sending module is used to send the second feature set to the server, where the second feature set is used to identify whether the target device is running in the engineering mode.

15. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 12.

16. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-12.

17. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method according to any one of claims 1 to 12 is implemented.