Method for identifying wireless access points based on event logs and electronic device
By acquiring the signal strength and event logs of the test terminal and the wireless access point, and combining them with the device status file and geographical location, the wireless access point is automatically identified, solving the problem of low AP device identification efficiency in the existing technology and achieving non-intrusive and efficient identification.
Patent Information
- Application Number
- CN202511014573.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-07-23
AI Technical Summary
In existing technologies, the identification of wireless access point (AP) devices lacks automated verification methods, requiring intrusive modifications to the devices, resulting in low identification efficiency and high costs, and making it difficult to implement in scenarios without control permissions.
By acquiring the test received signal strength indication values and event logs of the test terminal and the wireless access point to be identified, combined with the device status file, and using sliding time windows and fault-tolerant processing technology, the access relationship is constructed, the credibility of the initial device identification result is automatically verified, and supplementary identification is performed by combining geographical location information.
It improves the identification efficiency and accuracy of AP devices without requiring modifications, adapts to different network densities and coverage conditions, and balances convenience and accuracy.
Smart Images

Figure CN120529352B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless network management and device identification technology, and more specifically to a method and electronic device for wireless identification of wireless access points based on event logs. Background Technology
[0002] With the widespread adoption of wireless networks, wireless access points (APs) are being deployed on a large scale in various campuses. Network administrators need to verify the identity, location, and conduct compliance reviews of APs to ensure stable network operation and security. However, current AP identification methods not only lack automated verification mechanisms but may also require modifications to the AP devices to read device information via intrusive methods such as serial ports, thus reducing the efficiency of AP identification. Summary of the Invention
[0003] In view of the above problems, the present invention provides a method and electronic device for wireless identification of wireless access points based on event logs to improve the efficiency of identifying AP devices.
[0004] One aspect of the present invention provides a method for wireless identification of a wireless access point based on an event log, comprising: responding to an identification request for a wireless access point, acquiring a test received signal strength indication value between a test terminal and a wireless access point to be identified in a mobile state, and a test event log related to the test terminal and the wireless access point to be identified; matching the test event log with a device status file to obtain an initial device identification result for the wireless access point to be identified, the device status file including access status information of the wireless access point to be identified; determining the credibility of the initial device identification result based on the test received signal strength indication value according to the wireless communication mode between the test terminal and the wireless access point to be identified, and obtaining a target device identification result, wherein, if the wireless communication mode indicates wireless access and the credibility of the initial device identification result meets a predetermined value, the initial device identification result is used as the target device identification result; or if the wireless communication mode indicates no wireless access, sorting the initial device identification results according to the credibility of the initial device identification results, and selecting a target device identification result that meets a predetermined credibility condition from the sorted results of the initial device identification results; supplementing the target device identification result with the geographical location information of the wireless access point to obtain the identification result of the wireless access point.
[0005] According to an embodiment of the present invention, the device status file includes a real-time status file of the user terminal and a real-time status file of the wireless access point cluster. The user terminal includes a test terminal, and the wireless access point cluster includes wireless access points to be identified. The device status file is obtained as follows: the initial event log of the user terminal accessing the wireless access point cluster forwarded by the wireless controller is standardized to obtain a standardized event log, the initial event log including the test event log; the standardized event log is corrected to obtain the access relationship between the user terminal and the wireless access point cluster; the real-time status file of the user terminal and the real-time status file of the wireless access point cluster are constructed according to the access relationship, using the hardware address of the user terminal and the hardware address of the wireless access point in the wireless access point cluster as primary keys respectively.
[0006] According to an embodiment of the present invention, the standard event log is corrected to obtain the access relationship between the user terminal and the wireless access point cluster, including: constructing a sliding time window based on the hardware address of the user terminal, and generating a behavior chain based on the event log within the sliding time window; repairing the behavior chain to obtain a repaired behavior chain; performing a rationality check on the repaired behavior chain to obtain a check result; and processing the repaired behavior chain based on the check result to obtain the access relationship between the user terminal and the wireless access point cluster.
[0007] According to an embodiment of the present invention, repairing a behavior chain to obtain a repaired behavior chain includes: identifying a behavior chain that has undergone fault tolerance processing to obtain a target behavior chain; and, in the case where a predetermined number of event logs are missing in the target behavior chain, performing logical completion based on the semantics of the target behavior chain to obtain a repaired behavior chain.
[0008] According to an embodiment of the present invention, the repair behavior chain is processed based on the detection results to obtain the access relationship between the user terminal and the wireless access point cluster, including: when the detection results indicate that the user terminal connects to m1 different wireless access points within a predetermined time period, the user terminal is marked with a predefined semantic tag to obtain processed user terminal information, where m1 is greater than or equal to 0; when the detection results indicate that the user terminal simultaneously accesses m2 wireless access points at different physical locations, among the m2 wireless access points, the wireless access point with the largest received signal strength indication value relative to the user terminal is selected to obtain processed wireless access point information, where m2 is an integer greater than 1; based on the processed user terminal information and the processed wireless access point information, the access relationship between the user terminal and the wireless access point cluster is constructed.
[0009] According to an embodiment of the present invention, the test event log includes the hardware address of the test terminal; matching the test event log with the device status file to obtain the initial device identification result of the wireless access point to be identified includes: matching the hardware address of the test terminal with the real-time status file of the user terminal to obtain the hardware address of the wireless access point to be identified; matching the hardware address of the wireless access point to be identified with the real-time status file of the wireless access point cluster to obtain the device name of the wireless access point to be identified; and obtaining the initial device result based on the hardware address and device name of the wireless access point to be identified.
[0010] According to an embodiment of the present invention, determining the reliability of the initial device identification result based on the test received signal strength indication value according to the wireless communication method between the test terminal and the wireless access point to be identified includes: when the wireless communication method indicates wireless access, determining the reliability of the initial device identification result based on the test received signal strength indication value between the test terminal and the wireless access point to be identified, the changing trend of the test received signal strength indication value, the interaction between the test terminal and the wireless access point to be identified, and the behavior pattern of the test terminal; when the wireless communication method indicates no wireless access, determining the reliability of the initial device identification result based on the test received signal strength indication value between the test terminal and the wireless access point to be identified and the changing trend of the test received signal strength indication value.
[0011] According to an embodiment of the present invention, when the wireless communication mode indicates no wireless access, the method further includes: using an application loaded on the test terminal to scan the surrounding wireless access point cluster in the surrounding area, obtaining the hardware address of the surrounding wireless access point cluster, and the test received signal strength indication value of the test terminal and the wireless access points in the surrounding wireless access point cluster, wherein the surrounding area includes a spherical area with the test terminal as the center and a predetermined size as the radius.
[0012] According to an embodiment of the present invention, the method further includes: filling the information in the identification result of the wireless access point into an information display template according to the type of information in the identification result of the wireless access point to obtain an information display label; and displaying the information display label in a predetermined image file.
[0013] Another aspect of the present invention provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above-described method.
[0014] The method for wireless access point identification based on event logs provided in this invention, in response to an identification request, acquires the test received signal strength indicator value and test event log between the test terminal and the wireless access point to be identified while in a mobile state; matches the test event log with the device status file to obtain an initial device identification result; determines the credibility of the initial device identification result based on the test received signal strength indicator value according to the wireless communication method between the test terminal and the wireless access point to be identified, and obtains the target device identification result; and fills the target device identification result according to the geographical location of the wireless access point to be identified to obtain the identification result. Since the identification of the wireless access point to be identified can be achieved regardless of whether the test terminal is wirelessly connected to the wireless access point to be identified, these two identification methods balance accuracy and convenience, and can adapt to different network densities and coverage conditions. Furthermore, the automated verification of the credibility of the initial device identification result based on the received signal strength indicator value, and the determination of the target device identification result based on the credibility ranking when multiple initial device identification results are available, can effectively improve the efficiency of AP device identification. Attached Figure Description
[0015] The above-described features, other objects, and advantages of the present invention will become clearer from the following description of embodiments of the invention with reference to the accompanying drawings, in which:
[0016] Figure 1 The diagram illustrates an application scenario of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention.
[0017] Figure 2 A flowchart of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention is shown.
[0018] Figure 3 The diagram shows the installation location of the AP device.
[0019] Figure 4 The information shown is obtained in a scenario where the test terminal has been connected to or can be connected to the AP device to be identified.
[0020] Figure 5 The information shown is obtained in a scenario where the test terminal is not connected to or cannot connect to the AP device to be identified.
[0021] Figure 6A The distribution diagram of the AP devices in the original image file is shown.
[0022] Figure 6B This diagram illustrates an embodiment of the present invention of displaying information display labels on the interface of a visual management system.
[0023] Figure 7An architecture diagram of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention is shown.
[0024] Figure 8 The diagram illustrates a structural block diagram of an apparatus for wireless identification of wireless access points based on an event log according to an embodiment of the present invention.
[0025] Figure 9 The diagram illustrates a block diagram of an electronic device suitable for implementing a method for wireless identification of wireless access points based on event logs, according to an embodiment of the present invention. Detailed Implementation
[0026] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the invention. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the invention for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concept of the invention.
[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0029] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0030] With the large-scale deployment of access point (AP) devices, network administrators need to identify and conduct compliance reviews of these devices to ensure stable network operation and security. However, current methods for identifying AP devices have the following limitations: First, they rely on physical tags and manual registration, lacking automated verification methods; second, they have high requirements for hardware and software compatibility, requiring dedicated data collection tools or customized firmware, resulting in high deployment costs; and third, reading device information by modifying the AP device's serial port or using Simple Network Management Protocol (SNMP) is somewhat intrusive and difficult to implement in scenarios without control permissions.
[0031] Currently, mainstream wireless controllers (ACs) have the capability to output terminal access logs, recording behaviors such as terminal online status, roaming, and authentication. These logs are forwarded to a log platform via syslog protocols, forming a low-cost, wide-coverage behavioral data source. In existing networks, these system logs are primarily used for auditing, rather than for identifying the AP devices themselves. On the other hand, due to the coarse-grained logs (typically at the second level) and the limitations of UDP transmission, issues such as out-of-order events, packet loss, and latency exist, posing challenges to log-based behavior reconstruction and device identification. Therefore, how to build a stable and reliable AP device identification mechanism under conditions of coarse-grained logs, uncontrollable networks, and heterogeneous devices, and how to combine this with mobile terminals to achieve on-site AP device identification and tag matching, is a key issue in current wireless network operation and maintenance and intelligent identification.
[0032] In view of this, embodiments of the present invention provide a method for wireless identification of wireless access points based on event logs. This method utilizes terminal (Station, STA) access event logs generated by the AC (Access Controller) to achieve non-intrusive wireless identification of AP devices without modifying AP devices or using hardware data collection, thereby improving the efficiency and accuracy of AP device identification. This method integrates log analysis, behavioral modeling, and mobile terminal collaboration mechanisms, and is applicable to AP device management, operation and maintenance, and security auditing scenarios in various heterogeneous networks.
[0033] Figure 1 The diagram illustrates an application scenario of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention.
[0034] like Figure 1As shown, application scenario 100 according to this embodiment may include a user terminal 101, an AP device cluster 102, and a server 103. The user terminal 101 can interact with the server 103 by wirelessly linking with any AP device in the AP device cluster 102.
[0035] Terminal 101 can be any electronic device with a display screen and web browsing support, including but not limited to smartphones, tablets, laptops, and desktop computers. Various communication client applications can be installed on terminal 101, such as applications for identifying AP devices, shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (these are just examples). The terminal device in terminal 101 can also serve as a test terminal to identify AP devices in AP device cluster 102 and send the information obtained during the identification process to server 103. Server 103 processes the information to obtain the identification result of the wireless access point and returns the identification result to the terminal.
[0036] It should be noted that the method for wireless access point identification based on event logs provided in this embodiment of the invention can generally be executed by server 103. Correspondingly, the device for wireless access point identification based on event logs provided in this embodiment of the invention can generally be located in server 103. The method for wireless access point identification based on event logs provided in this embodiment of the invention can also be executed by a server or server cluster that is different from server 103 and capable of communicating with user terminal 101, AP device cluster 102, and / or server 103. Correspondingly, the device for wireless access point identification based on event logs provided in this embodiment of the invention can also be located in a server or server cluster that is different from server 103 and capable of communicating with user terminal 101, AP device cluster 102, and / or server 103.
[0037] It should be understood that Figure 1 The number of user terminals, AP device clusters, AP devices, and servers shown is merely illustrative. Depending on implementation needs, there can be any number of user terminals, AP device clusters, AP devices, and servers.
[0038] The following will be based on Figure 1 The described scene, through Figures 2-6B The method for wireless identification of wireless access points based on event logs according to embodiments of the present invention will be described in detail.
[0039] Figure 2 A flowchart of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention is shown.
[0040] like Figure 2As shown, the method for wireless identification of wireless access points based on event logs in this embodiment includes operations S210 to S240.
[0041] In operation S210, in response to the identification request of the wireless access point, the test received signal strength indication value between the test terminal and the wireless access point to be identified in the mobile state and the test event log related to the test terminal and the wireless access point to be identified are obtained.
[0042] During operation S220, the test event log is matched with the device status file to obtain the initial device identification result of the wireless access point to be identified. The device status file includes the access status information of the wireless access point to be identified.
[0043] In operation S230, based on the wireless communication method between the test terminal and the wireless access point to be identified, the reliability of the initial device identification result is determined based on the test received signal strength indication value, and the target device identification result is obtained.
[0044] In the case where wireless access is indicated by wireless communication, there is one wireless access point to be identified. If the credibility of the initial device identification result meets the predetermined value, the initial device identification result is used as the target device identification result.
[0045] In the case where wireless communication means no wireless access, there are at least two wireless access points to be identified. The initial device identification results are sorted according to their credibility, and the target device identification results that meet the predetermined credibility conditions are selected from the sorted results of the initial device identification results.
[0046] In operation S240, the target device identification result is supplemented based on the geographical location information of the wireless access point to obtain the wireless access point identification result.
[0047] In some embodiments, an access point (AP) device is a hardware device that enables Wireless Fidelity (Wi-Fi). Wi-Fi technology requires an AP (or a router with integrated AP functionality) to provide wireless network services. A Wi-Fi network can consist of a single AP device (e.g., in a home setting) or multiple AP devices (e.g., in an enterprise deployment), covering different areas. An AP device is a physical device responsible for providing wireless access; Wi-Fi is a technical standard that defines the implementation of wireless communication. AP devices enable devices to access the internet wirelessly through the Wi-Fi protocol, and the widespread adoption of Wi-Fi depends on the deployment of AP devices. Together, Wi-Fi and AP devices form the foundation of a wireless network.
[0048] Figure 3 The diagram shows the installation location of the AP device.
[0049] In some embodiments, the installation location of the AP device can be as follows: Figure 3 As shown, the AP device is installed on the ceiling, and lights for illumination and signal lights for indicating wireless signals can also be deployed around it. Using the method provided in this embodiment of the invention, seamless data collection from AP devices can be achieved on the ground, improving the convenience of identifying AP devices.
[0050] In some embodiments, the identification request can be an event or instruction initiated by the test STA or management system to identify the AP device. For example, if a target object (e.g., a user or intelligent robot) needs to identify the AP device information at location D, it can move to location D according to a map including that location and click a button to connect to or scan for nearby Wi-Fi or AP devices to trigger the identification request. In another embodiment, the identification request can also be triggered by periodically inspecting network devices according to a scheduled task of the management system. In yet another embodiment, the identification request can also be triggered when a new AP device signal is detected.
[0051] In some embodiments, the test STA can be a portable STA device, such as a mobile phone or a laptop computer, used to collect information about the wireless access point to be identified.
[0052] In some embodiments, the AP to be identified can be an AP device that needs to be identified, for example, if you want to know the AP device information at location D, the AP to be identified can be any AP device in the AP device cluster at location D.
[0053] In some embodiments, the Received Signal Strength Indicator (RSSI) value can represent the signal strength between the test STA and the AP device to be identified. The larger the RSSI value, the stronger the signal, indicating that the distance between the test STA and the AP device to be identified is closer. Multiple test RSSI values can be obtained by moving the test STA.
[0054] In some embodiments, the test event log can be an event log related to the test STA and the AP device to be identified. For example, when the test STA is connected to the AP device to be identified, the test event log can be an event log between the test STA and the AP device to be identified. This test event log can record online events triggered by the test STA, Internet Protocol (IP) allocation for network interconnection, and roaming events. The test log may include the test STA name, the test STA's Media Access Control Address (MAC), the online or offline event and timestamp, the AP device name to be identified, and the AP device's MAC. When the test STA is not connected to the AP device to be identified, the test event log can be an event log between the AP device to be identified and other STAs connected to the AP device to be identified. These other STAs are STAs other than the test STA, including the MAC of the AP device to be identified and the MACs of the other STAs connected to the AP device to be identified.
[0055] In some embodiments, the device status file may include a real-time status file (e.g., an AP device status table) for describing the access status information of the AP device. For example, it may contain information about STAs accessing the AP (multiple STA MAC addresses, RSSI, etc.) and the AP device name, using the AP MAC address as the key. The device status file may also include a real-time status file (e.g., a STA status table) for the user terminal. The STA status table, using the STA MAC address as the key, contains the MAC address of the accessed AP and connection information such as the AP's RSSI.
[0056] In some embodiments, an initial device identification result can be obtained by matching the test event log with the device status file. The initial device identification result may include the device name and MAC address of the AP device.
[0057] When testing the connection of a STA to an AP device, you can directly look up the device name of the AP device in the AP device status table based on the MAC address of the AP device in the test event log; alternatively, you can look up the device name and MAC address of the AP device in the AP device status table based on the STA's MAC address in the test event log; or you can look up the MAC address of the AP device in the STA status table based on the STA's MAC address in the test event log, and then look up the device name of the AP device in the AP device status table based on the found MAC address.
[0058] If the test STA is not connected to the AP device to be identified, the application installed on the test STA can scan for AP devices around the test STA and look up the device name of the AP device to be identified in the AP device status table based on the MAC address of the scanned AP devices.
[0059] In some embodiments, the test STA and the AP device to be identified can have two wireless connection methods, such as a wireless connection that is already established or an accessible connection. When the test STA and the AP device are already connected, the relationship between the STA and the AP device can be one-to-one. Alternatively, the test STA and the AP device can be in a wireless connectionless or physically inaccessible mode. In this case, the relationship between the STA and the AP device can be one-to-many. Different connection methods can employ different identification methods to obtain the AP device identification result. That is, the embodiments of the present invention can identify AP device information and obtain identification results in both of these modes.
[0060] In some embodiments, the reliability of the initial device identification result can be determined based on the RSSI value, thereby improving the accuracy of the initial device identification result.
[0061] For example, if the target object connects to AP1 device through the test STA, but this AP1 device may be the AP1 device at location D, and the target object has moved to location E, which is different from location D, but the AP1 device connected to by the test STA has not yet switched to the AP2 device closest to location E, if the reliability of the initial device identification result of the AP device is uncertain, even though the target object is at location E, if the identification continues based on this AP1 device, it may lead to misidentifying the AP1 device at location D as the AP2 device at location E, thus resulting in a misjudgment. Therefore, it is necessary to determine the reliability of the initial device identification result.
[0062] The reliability of the initial device identification result can be determined based on the RSSI value. Even if the target object is at location E, if the RSSI value between the nearest AP2 device and location E is weaker than the RSSI value between the AP1 device and location D, or if the RSSI value between the test STA and AP2 devices does not meet a predetermined value, it indicates that the AP device currently connected to the STA is not at location E, and the initial device identification result obtained using AP1 is unreliable. If the RSSI value between the test STA and AP2 devices meets the predetermined value, then the initial device identification result obtained using AP1 is reliable. The predetermined value can be adaptively adjusted according to actual needs. Determining the AP device based on the reliability of the RSSI value can improve the identification accuracy.
[0063] In some embodiments, if the test STA is not connected to an AP device, the test STA may scan for multiple AP devices. By identifying these AP devices, multiple initial device identification results can be obtained. Based on the RSSI values between the test STA and the multiple APs, the reliability of the multiple initial device identification results can be determined, and the initial device identification results are sorted according to their reliability. The target device identification result can be the initial device identification result that meets a predetermined reliability condition (e.g., has the highest reliability) selected from the sorted results of the initial device identification results.
[0064] In some embodiments, the geographic location information of the AP device can be obtained from a map file. By supplementing the target device identification result obtained from the above operations with the geographic location information of the AP device, the identification result of the AP device can be obtained.
[0065] The method for wireless access point identification based on event logs provided in this invention, in response to an identification request, acquires the test received signal strength indicator value and test event log between the test terminal and the wireless access point to be identified while in a mobile state; matches the test event log with the device status file to obtain an initial device identification result; determines the credibility of the initial device identification result based on the test received signal strength indicator value according to the wireless communication method between the test terminal and the wireless access point to be identified, and obtains the target device identification result; and fills the target device identification result according to the geographical location of the wireless access point to be identified to obtain the identification result. Since the identification of the wireless access point to be identified can be achieved regardless of whether the test terminal is wirelessly connected to the wireless access point to be identified, these two identification methods balance accuracy and convenience, and can adapt to different network densities and coverage conditions. Furthermore, the automated verification of the credibility of the initial device identification result based on the received signal strength indicator value, and the determination of the target device identification result based on the credibility ranking when multiple initial device identification results are available, can effectively improve the efficiency of AP device identification.
[0066] In some embodiments, the device status file mentioned above can be updated in real time. The device status file includes a real-time status file (STA status table) for the user terminal and a real-time status file (AP device status table) for the AP device cluster. The user terminal can be a terminal device connected to the AP device cluster, including not only test terminals used to identify AP devices but also terminal devices using the AP devices. The AP device cluster includes not only the AP devices to be identified by the test terminal but also AP devices used by the user terminal. In some embodiments, the AP devices to be identified can also be used by the user terminal, and the user terminal can also act as an AP device, enabling hotspot signals.
[0067] In some embodiments, the device status file can be obtained as follows: the initial event logs forwarded by the wireless controller for user terminals accessing the AP device cluster are standardized to obtain standardized event logs, the initial event logs including test event logs; the standardized event logs are corrected to obtain the access relationship between the user terminal and the wireless access point cluster; and the real-time status file of the user terminal and the real-time status file of the AP device cluster are constructed based on the access relationship, using the hardware address of the user terminal and the hardware address of the AP device in the AP device cluster as primary keys, respectively.
[0068] In some embodiments, the initial event log may be an unprocessed STA access event log forwarded by the AC device, and may include event logs of test terminals accessing the AP device to be identified. The server can support receiving STA access event logs forwarded by AC devices from various manufacturers. Considering the differences in output formats of different AC devices, the server can uniformly parse the multiple received initial event logs into a standard field structure, extract key fields such as STA MAC, AP device MAC, Service Set Identifier (SSID), event type (online, roaming, disconnected), timestamp, and interface information, and record them as standard event entities to obtain the standard event log.
[0069] In some embodiments, since the AC device only supports UDP protocol to obtain STA event logs to the server, the following problems may occur during the actual acquisition of initial event logs: the logs have second-level time precision (usually the local clock of the AP device, or the local time of the AC, with a granularity of seconds); events between the STA and multiple AP devices involve different timestamps and different sending sources; UDP transmission is uncontrollable, with packet loss, out-of-order delivery, and delayed transmission; the actual roaming process of the STA is very short (e.g., about 100ms in some AC measurements), while the log granularity is much coarser than this. Therefore, this invention avoids the above problems by processing standardized event logs.
[0070] In some embodiments, the process of correcting standardized event logs to obtain the access relationship between the user terminal and the wireless access point cluster may include the following operations: constructing a sliding time window based on the hardware address of the user terminal, and generating a behavior chain based on the event logs within the sliding time window; repairing the behavior chain to obtain a repaired behavior chain; performing a rationality check on the repaired behavior chain to obtain a check result; and processing the repaired behavior chain based on the check result to obtain the access relationship between the user terminal and the wireless access point cluster.
[0071] In some embodiments, the processing of standardized event logs can be divided into two processes: sliding window aggregation and fault-tolerant sorting, and behavioral semantic reasoning and confidence determination. Sliding window aggregation and fault-tolerant sorting may include constructing a sliding time window based on the hardware address of the user terminal, generating a behavioral chain based on the event logs within the sliding time window, and repairing the behavioral chain to obtain a repaired behavioral chain. Behavioral semantic reasoning and confidence determination may include performing a rationality check on the repaired behavioral chain to obtain a check result; processing the repaired behavioral chain based on the check result to obtain the access relationship between the user terminal and the wireless access point cluster.
[0072] In some embodiments, for sliding window aggregation and fault-tolerant sorting, the server can construct a sliding time window (e.g., 3 to 5 seconds) in units of STA MAC, collect all relevant log events (such as online, offline, roaming, IP switching, etc.) within this time period, and form a local behavior chain.
[0073] In some embodiments, the process of repairing the behavior chain to obtain a repaired behavior chain may include the following operations: identifying the behavior chain that has undergone fault tolerance processing to obtain a target behavior chain; and, if a predetermined number of event logs are missing in the target behavior chain, performing logical completion based on the semantics of the target behavior chain to obtain a repaired behavior chain.
[0074] In some embodiments, to address log out-of-order issues and time precision limitations, the server can rearrange the event logs within a window according to time and semantic priority, while also possessing a fault tolerance mechanism. Specifically, fault tolerance includes tolerating event sequence misalignment, such as "the old AP device going offline before the new AP device goes online." Typical behavior chains can be identified to obtain the target behavior chain (e.g., a roaming process as: "new AP device online → roaming → old AP device offline"). For the target behavior chain missing a predetermined number of logs (e.g., 1-2), "logical completion" based on the context of the target behavior chain is allowed to obtain a repair behavior chain. All state changes during these operations are "rollbackable," supporting subsequent event-driven state repair.
[0075] In some embodiments, based on the repaired event chain, the server can detect and judge the rationality of the behavior sequence based on predefined semantic tags (such as "roaming," "online," "switchover," and "offline") and a finite state machine model to obtain the detection result. For example, it can test whether the STA is connected to two different AP devices at the same time.
[0076] In some embodiments, the repair behavior chain is processed according to the detection results to obtain the access relationship between the user terminal and the wireless access point cluster, including: if the detection results indicate that the user terminal connects to m1 different AP devices within a predetermined time period, the user terminal is marked with a predefined semantic label to obtain processed user terminal information, where m1 is greater than or equal to 0; if the detection results indicate that the user terminal simultaneously accesses m2 AP devices at different physical locations, among the m2 AP devices, the AP device with the largest received signal strength indication value relative to the user terminal is selected to obtain processed AP device information, where m2 is an integer greater than 1; and based on the processed user terminal information and the processed AP device information, the access relationship between the user terminal and the wireless access point cluster is constructed.
[0077] In some embodiments, when m1 equals 0, that is, when the terminal does not connect to the AP device within a predetermined time (e.g., 2 seconds), the terminal can be marked with a predefined semantic tag (e.g., offline) to obtain the processed terminal information.
[0078] In some embodiments, when m1 equals 1, that is, when the terminal connects to a different AP device within a predetermined time (e.g., 2 seconds), the terminal can be marked with a predefined semantic tag (e.g., online) to obtain the processed terminal information.
[0079] In some embodiments, when m1 equals 2, that is, when the terminal connects to two different AP devices within a predetermined time (e.g., 2 seconds), the terminal can be marked with a predefined semantic tag (e.g., roaming) to obtain the processed terminal information.
[0080] In some embodiments, when m2 equals 2, i.e., when the terminal simultaneously accesses two AP devices at different physical locations (e.g., two buildings), the AP device with the highest RSSI value relative to the terminal is selected and retained among the two AP devices to obtain the processed AP device information. For example, multiple AP devices can be sorted by confidence level according to behavior (e.g., dwell time and associated handover order) and RSSI signal strength, and the AP device with the highest RSSI value can be selected to improve the accuracy of AP device identification.
[0081] According to embodiments of the present invention, the above-described processing of the initial event log can restore the STA's access status as much as possible under conditions of log disorder and missing data without relying on high-precision timestamps, thereby establishing an accurate and reliable access relationship between the STA and AP devices and improving the robustness and practicality of the wireless identification system.
[0082] In some embodiments, when the access relationship between the STA and the AP device is obtained, the STA status table and the AP device status table can be constructed based on the access relationship, using the MAC address of the STA and the MAC address of the AP device in the AP device cluster as primary keys respectively.
[0083] In some embodiments, the server can construct an AP device status table and a STA status table using the AP MAC address and STA MAC address as primary keys, respectively, to maintain bidirectional status information in the wireless network in real time.
[0084] The AP device status table can record the current list of connected terminals, active status, recent event time, SSID, deployment location, and tag information for each AP device.
[0085] The STA status table can record dynamic behaviors of each STA, such as the current or recently associated AP devices, status transition records, roaming trajectory, connection duration, and IP changes.
[0086] The dual-table structure of the AP device status table and STA status table supports real-time updates based on event logs, forming the core data source for system identification, confidence calculation, and front-end display. These AP and STA status tables can be persistently stored in a database or provided with high-performance interfaces through caching components such as a remote dictionary server (Redis), supporting applications such as global wide area network (WWAN) display, mobile identification linkage, and application programming interface (API) queries.
[0087] According to embodiments of the present invention, analysis based on existing event log data from the wireless controller AC can be performed without any hardware modifications or firmware upgrades to the AP device, and without relying on underlying serial port control or SNMP access permissions. It supports non-intrusive, "seamless" data collection from existing network devices, with no impact on the network during deployment, demonstrating good engineering feasibility. Furthermore, this method supports log input from multiple vendors and models of AC devices. Through log standardization and dynamic parsing capabilities, it can interface with various log structures, exhibiting strong versatility and scalability, high compatibility, and wide applicability.
[0088] According to embodiments of the present invention, this method possesses out-of-order fault tolerance capability and high identification accuracy. Addressing the UDP packet loss and out-of-order issues during log forwarding, this embodiment introduces a sliding window mechanism and a time-series fault-tolerant inference model to restore the actual access order and state transitions of terminals as much as possible, ensuring the rigor and repeatability of the identification logic. Furthermore, by maintaining a real-time device status table, it can dynamically reflect information such as access terminals, active status, and roaming relationships of AP devices, achieving near real-time updates and queries. This is suitable for dynamic network monitoring and maintenance scenarios, enabling real-time identification and status tracking.
[0089] In some embodiments, the test event log mentioned above may include the MAC address of the test STA. The process of matching the test event log with the device status file to obtain the initial device identification result of the wireless access point to be identified, as mentioned above, may include the following operations: matching the hardware address of the test terminal with the real-time status file of the user terminal to obtain the hardware address of the wireless access point to be identified; matching the hardware address of the wireless access point to be identified with the real-time status file of the wireless access point cluster to obtain the device name of the wireless access point to be identified; and obtaining the initial device result based on the hardware address and device name of the wireless access point to be identified.
[0090] In some embodiments, when the test STA has already connected to or can connect to the AP device to be identified, for example, after an application installed on the test STA actively connects to the AP device to be identified, the server obtains the MAC address of the AP device based on the online, IP allocation, or roaming events triggered by the test STA, combined with the STA status table. Based on the MAC address of the AP device, the server queries the AP device status table for the device name of the currently associated AP device, and pushes the obtained MAC address and device name of the AP device to the test STA for identification or registration. In this mode, because event changes can be explicitly triggered and obtained, the AP device identification effect is more accurate. However, it is difficult to quickly connect to or distinguish AP devices when AP devices are densely packed or inaccessible locations.
[0091] Figure 4 The information shown is obtained in a scenario where the test terminal has been connected to or can be connected to the AP device to be identified.
[0092] like Figure 4As shown, an application matching the event log-based wireless access point identification method of this invention, in a scenario where the STA has connected to or can connect to the AP device to be identified, may obtain the following information: the connection information of the mobile phone (i.e., the connection information of the test STA), the latest information of the STA in the background status table associated with the STA, and the STA's recent offline information. The RSSI information in the mobile phone connection information, the latest STA information, and the STA's recent offline information includes data from the STA to the AP and data from the AP to the STA obtained from the background; dBm is the unit of RSSI value. The MAC in the mobile phone connection information, the latest STA information, and the STA's recent offline information is the STA's MAC address. In the mobile phone connection information, the latest STA information, and the STA's recent offline information, "sta" and "STA" have the same meaning, and "ap" and "AP" have the same meaning.
[0093] In some embodiments, when the wireless communication method indicates no wireless access, the above method may further include the following operations: using the application loaded on the test terminal to scan the surrounding wireless access point cluster in the surrounding area, obtaining the hardware address of the surrounding wireless access point cluster, and the test received signal strength indication value of the test terminal and the wireless access points in the surrounding wireless access point cluster. The surrounding area may include a spherical area with the test terminal as the center and a predetermined size as the radius. The predetermined size can be adaptively adjusted according to actual needs.
[0094] In some embodiments, when the test STA cannot connect to the network or does not need to actually access the network, the application installed on the test terminal can scan the MAC and RSSI information of AP devices in the surrounding area and upload it to the server. The server then matches the MAC addresses of the AP devices with the AP device status table it maintains to obtain the device name of the AP device. Combining signal strength and trend analysis, it infers the probability of the target AP device and returns the identification result. This method is highly efficient and adaptable, especially suitable for AP-dense or network-limited scenarios, and is an effective supplement to the connection mode.
[0095] Figure 5 The information shown is obtained in a scenario where the test terminal is not connected to or cannot connect to the AP device to be identified.
[0096] An application matching the event log-based wireless access point identification method of this invention can, in scenarios where the test STA is not connected to or cannot connect to the AP device to be identified, scan the AP MAC information and background AP tag information obtained from surrounding AP devices, as shown in the example. Figure 5 As shown. Because an AP device has multiple RF chains, there will be multiple AP MAC addresses. All MAC addresses can be unified by a unique AP device name. Furthermore, the RSSI in the AP tag information can be used to determine confidence level. Figure 5 In the MHz, the channel frequency is represented. For example, 5240.MHz-6 indicates that the channel frequency is 5240.MHz, and it represents Wi-Fi 6 (sixth generation wireless network technology). For example, 5280.MHz-5 indicates that the channel frequency is 5280.MHz, and it represents Wi-Fi 5 (fifth generation wireless network technology).
[0097] Embodiments of this invention support multi-mode collaborative identification via mobile devices. By providing both connected identification and connectionless scanning methods, it balances accuracy and convenience, adapting to different network densities and coverage conditions. It supports quick identification of surrounding APs on-site via a terminal app, suitable for practical scenarios such as equipment acceptance, on-site verification, and maintenance inspections.
[0098] To improve the accuracy of AP device identification, this embodiment of the invention adopts a relative distance analysis model based on RSSI difference inference. The changes in RSSI values reported multiple times during the movement of the test STA are used to determine whether it is approaching or moving away from an AP device according to formula (1).
[0099] (1);
[0100] Where n is the path loss factor. The reference power is d, and the distance from the test STA to the AP device is d.
[0101] The distance change trend can be derived from the two measured RSSI values RSS1 and RSS2 using formula (2).
[0102] (2);
[0103] That is, if RSSI is enhanced, the test STA is approaching the AP device. This analysis does not depend on the path loss factor n or the reference power. Judging solely by relative changes helps identify the most likely target AP device in a disconnected state and obtain the target device identification result.
[0104] From formula (1), it can be seen that the distance d is inversely proportional to the signal strength RSSI. It is a direct proportional relationship, meaning that as the distance from STA to AP increases, RSSI decreases. Therefore, in formula (2) , refers to Proportional to , This represents the difference in distance from the two locations of the STA to the AP device. For example, if the two locations of the STA are location 1 and location 2, the RSSI measured by the STA at location 1 is RSSI1, and the RSSI measured by the STA at location 2 is RSSI2. Inputting RSSI1 into formula (1) yields the distance d1 between the STA and the AP device at location 1, and inputting RSSI2 into formula (1) yields the distance d2 between the STA and the AP device at location 2. This represents the difference in signal strength between STA and AP at positions 2 and 1. =d2-d1 represents the distance difference between the STA at position 2 and position 1 and the AP. The larger the signal strength difference, the larger the distance difference.
[0105] Based on the aforementioned RSSI values and their changing trends, in order to improve the reliability of the final AP device identification results, this embodiment of the invention further provides an AP confidence model to determine the confidence of the initial device identification results and to sort the confidence of the initial device identification results of multiple AP devices associated with the same test STA terminal to obtain the target device identification results.
[0106] Specifically, the process of determining the reliability of the initial device identification result based on the test received signal strength indication value, according to the wireless communication method between the test terminal and the wireless access point to be identified, may include the following operations: when the wireless communication method indicates wireless access, the reliability of the initial device identification result is determined based on the test received signal strength indication value between the test terminal and the wireless access point to be identified, the changing trend of the test received signal strength indication value, the interaction between the test terminal and the wireless access point to be identified, and the behavior pattern of the test terminal; when the wireless communication method indicates no wireless access, the reliability of the initial device identification result is determined based on the test received signal strength indication value between the test terminal and the wireless access point to be identified, and the changing trend of the test received signal strength indication value.
[0107] In some embodiments, at least one of the following factors may be used in determining the reliability of the initial device identification result:
[0108] (a) Test the RSSI values of the STA and AP devices (estimate the distance).
[0109] (b) RSSI continuous trend (closer or further away).
[0110] (c) Event activity (e.g., number of connections, roaming frequency) of the AP device and the test STA currently connected to the AP device within a predetermined time period. The predetermined time period can be adaptively adjusted according to actual needs.
[0111] (d) Test the behavior patterns of the STA across multiple AP devices (such as roaming, dwell time, and associated handover sequence).
[0112] When wireless communication indicates wireless access, the reliability of the initial device identification result can be determined according to formula (3). In the case where wireless communication indicates no wireless access, the reliability of the initial device identification result can be determined according to formula (4). .
[0113] (3);
[0114] (4);
[0115] in, The normalized RSSI value. To determine whether RSSI shows a continuous upward or downward trend, This refers to the frequency of recent event triggers between the AP and the test STA. This indicates whether the AP device roamed with the test STA within the predetermined time period. This information can be obtained from the event log. If roaming occurred, then... The value is 1 if no roaming has occurred. =0, - The weight parameters for each dimension can be set based on scenario experience or training data, and can be adaptively adjusted according to actual needs.
[0116] In practical applications, It can make quick judgments directly in open spaces. Then you need to specify the actual trend of change. and Used in connected mode to additionally determine the activity and stability between the STA and AP.
[0117] The system calculates The system sorts the credibility of the initial device identification results and selects the initial device identification result with the highest credibility as the target device identification result. At the same time, it provides credibility information for upstream systems or user interfaces to display, thereby realizing interpretable feedback on the results and multi-strategy fusion control.
[0118] This invention integrates a confidence mechanism based on signals and behaviors, and constructs a confidence model based on RSSI estimation, log event frequency, and movement trends. This model can comprehensively judge and rank multiple candidate AP devices, effectively improving the accuracy and robustness of identification, and supporting interpretable result output.
[0119] In some embodiments, when the target device identification result is supplemented by the geographical location information of the AP device to obtain the AP device identification result, the following operations can be performed: according to the type of information in the wireless access point identification result, the information in the wireless access point identification result is filled into the information display template to obtain the information display label; the information display label is displayed in a predetermined image file.
[0120] In some embodiments, the information type may include name type, MAC type, and geographic location type. The information display template may have three areas: a first area for filling in the AP device's device name, a second area for filling in the AP device's MAC address, and a third area for filling in the AP device's geographic location. By filling the information display template with the information from the recognition results according to the information type, an information display label can be obtained. This label can be displayed in an image file for the target object to browse.
[0121] Figure 6A The distribution diagram of the AP devices in the original image file is shown.
[0122] like Figure 6A The image shows the distribution of AP devices before AP device identification. Figure 6A There is an error issue with duplicate AP device information. For example, AP004 may be displayed in both the first display area 601 and the second display area 602. In other words, one display area should not be showing AP004, as the AP information displayed in that area is incorrect. Therefore, the event log-based wireless access point identification method provided in this embodiment of the invention is needed to achieve accurate identification of AP devices.
[0123] Figure 6B This diagram illustrates an embodiment of the present invention of displaying information display labels on the interface of a visual management system.
[0124] The information display tag 603 obtained by identifying the AP device using the method provided in this embodiment of the invention can be displayed as follows: Figure 6B As shown. The information display labels 603 of the AP devices are imported into the map 604 of the visual management system interface for display. The display results can be as follows: Figure 6B As shown. Clicking on any AP device on map 604 in the visualization management system interface will bring up an information display tab 603 for that AP device. The AP distribution display box 605 in the visualization system interface can display the number of AP devices on map 604, for example, 21 AP devices are distributed in area ** (for example only). The location selection box 606 in the visualization system interface allows you to select which location's map and AP device distribution you want to query.
[0125] In some embodiments, the identified target device identification results can be directly transmitted back to the backend as calibration data to complete or confirm the name, floor, location, and other tag information corresponding to the AP device's MAC address. The information display tags can be mapped onto building maps and used to mark locations in conjunction with the STA terminal's movement trajectory. This allows for the simultaneous collection and visualization of AP device deployment location data, enabling not only structured and spatial management of wireless devices but also demonstrating the practicality of the event log-based wireless access point identification method of this invention.
[0126] In some embodiments, the implementation based on the above method may include: moving to the vicinity of the AP device at the building entrance by browsing a building map; measuring the information of the AP device at the entrance (e.g., the MAC address and name of the AP device) according to the method described above; and marking the AP device information on the building map.
[0127] Figure 7 An architecture diagram of a method for wireless identification of wireless access points based on event logs according to an embodiment of the present invention is shown.
[0128] like Figure 7 As shown, AC 701 can manage multiple APs 702. STA 703 can interact with APs 702, such as in wireless connection mode and wireless connectionless mode. The interaction between STA 703 and APs 702 generates event logs, which can be processed by log processing service 704, such as performing out-of-order fault tolerance and timing correction. Based on the processing results, a status table is obtained, including an AP device status table and a STA device status table. By matching the event logs with at least one of the AP and STA device status tables, the target identification result of the AP device can be obtained. The information obtained based on this target identification result is then labeled and displayed on an external system 705, such as on a digital map or device management system, for the target object to browse. STA 703 can also query the geographical location of the AP device from external system 705 or write the AP device identification result to it. STA 703 can also query the name of the AP device from log processing service 704 or write the AP device identification result to it.
[0129] The embodiments of the present invention can complete the identification and labeling of AP devices without additional hardware investment. It has the advantages of low deployment cost, wide applicability, high identification efficiency and strong integrability, and has significant engineering application value and industrial promotion prospects.
[0130] The following example uses a wireless network in a campus. Multiple batches of AP and AC devices have been deployed within the campus, covering a wide range of brands and eras, with some being early models and others newer Wi-Fi 6 devices. The wireless network coverage is high, with over 3000 AP devices distributed across different areas (Area 1, Area 2, Area 3, Area 4, etc.) within the campus. However, the lack of tag data for these AP devices restricts the campus's intelligent development. This embodiment of the invention can identify AP devices and generate tags.
[0131] The management AC device of this server network system can enable STA access event log output, but only supports forwarding logs to an external log server in syslog format via UDP protocol. Log formats vary between different device manufacturers and versions, and the fields included are not entirely consistent; time precision is typically at the second level. While most APs have deployment location records, they lack structured label information such as device name, floor number, and functional area, making subsequent network asset inventory and on-site device identification difficult.
[0132] In this scenario, the specific implementation of the present invention is as follows:
[0133] System Deployment and Log Access. A log receiving service node is deployed in the core area of the campus network. It receives STA event logs from various AC devices via a UDP listening port, uses a custom parser to identify the log format, and standardizes the log data into a unified structure.
[0134] Event stream processing and state table construction. Due to packet loss and out-of-order issues in logs, the system uses a sliding time window mechanism and a finite state machine model to perform sequential error correction and conflict resolution on multiple events within a short period. The processed events are used to update the AP device state table in real time, which records information such as the most recently accessed terminal, active status, and most recent event time for each AP.
[0135] Mobile terminal identification operation. Maintenance personnel bring a mobile phone with the application installed to support the identification method provided in this embodiment of the invention to the site and identify the specific AP using the following two methods:
[0136] Connection method identification: The mobile phone attempts to connect to the AP device with the strongest signal on site. After a successful connection, the system can immediately receive the online or roaming event of the STA, obtain the MAC of the AP currently associated with the STA through the real-time status table, and then query and return the corresponding tags (such as the name of the teaching building, floor, device number, etc.).
[0137] Connectionless identification: If connectivity is limited, the application obtains the MAC and RSSI lists of the surrounding APs through the system interface. The system matches the relevant records in the AP device status table, estimates the relative distance between the test STA and each AP device based on the RSSI value, selects the most reliable initial identification result through the confidence model, and obtains the target device identification result.
[0138] Recognition Results Presentation. The recognition results are returned to the application frontend by the system and synchronized to the backend management platform. The backend can mark the location information of the AP device on the building drawings, realizing visual identification and confirmation. The platform supports screening and statistics by building, floor, device type, etc.
[0139] The method provided in this invention is applicable to handling information asymmetry issues in heterogeneous AP and AC device environments, making up for problems such as missing tag information and difficulties in manual identification. It has successfully helped the network center complete tag verification and unified coding for multiple batches of AP devices, providing a reliable foundation for subsequent device inspection, security audit, and network optimization.
[0140] It should be noted that, unless it is explicitly stated that there is a sequential order of execution between different operations, or that there is a sequential order of execution between different operations in terms of technical implementation, the execution order between multiple operations may not be significant, and multiple operations may be executed simultaneously.
[0141] Based on the above-described method for wireless access point identification based on event logs, this invention also provides a device for wireless access point identification based on event logs. The following will be combined with... Figure 8 The device is described in detail.
[0142] Figure 8 A structural block diagram of an apparatus for wireless identification of wireless access points based on an event log according to an embodiment of the present invention is shown.
[0143] like Figure 8 As shown, the device 800 for wireless identification of wireless access points based on event logs in this embodiment includes an acquisition module 810, a matching module 820, a determination module 830, and a supplement module 840.
[0144] The acquisition module 810 is used to acquire, in response to the identification request of the wireless access point, the test received signal strength indication value between the test terminal and the wireless access point to be identified in the mobile state, and the test event log related to the test terminal and the wireless access point to be identified.
[0145] The matching module 820 is used to match the test event log with the device status file to obtain the initial device identification result of the wireless access point to be identified. The device status file includes the access status information of the wireless access point to be identified.
[0146] The determining module 830 is used to determine the credibility of the initial device identification result based on the test received signal strength indication value according to the wireless communication method between the test terminal and the wireless access point to be identified, and to obtain the target device identification result. Specifically, if the wireless communication method indicates wireless access and the credibility of the initial device identification result meets a predetermined value, the initial device identification result is used as the target device identification result; or if the wireless communication method indicates no wireless access, the initial device identification results are sorted according to their credibility, and the target device identification result that meets the predetermined credibility condition is selected from the sorted results.
[0147] The supplementary module 840 is used to supplement the target device identification result based on the geographical location information of the wireless access point, so as to obtain the wireless access point identification result.
[0148] It should be noted that the device part for wireless identification of wireless access points based on event logs in the embodiments of the present invention corresponds to the method part for wireless identification of wireless access points based on event logs in the embodiments of the present invention. For a detailed description of the device part for wireless identification of wireless access points based on event logs, please refer to the method part for wireless identification of wireless access points based on event logs, which will not be repeated here.
[0149] According to embodiments of the present invention, any plurality of modules among the acquisition module 810, matching module 820, determining module 830, and supplementary module 840 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of the present invention, at least one of the acquisition module 810, matching module 820, determining module 830, and supplementary module 840 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 810, matching module 820, determining module 830, and supplementary module 840 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.
[0150] Figure 9 A block diagram of an electronic device suitable for implementing a method for wireless identification of wireless access points based on event logs, according to an embodiment of the present invention, is shown.
[0151] like Figure 9 As shown, an electronic device 900 according to an embodiment of the present invention includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage portion 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.
[0152] RAM 903 stores various programs and data required for the operation of electronic device 900. Processor 901, ROM 902, and RAM 903 are interconnected via bus 904. Processor 901 executes various operations of the method flow according to embodiments of the present invention by executing programs in ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 may also execute various operations of the method flow according to embodiments of the present invention by executing programs stored in said one or more memories.
[0153] According to an embodiment of the present invention, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to a bus 904. The electronic device 900 may also include one or more of the following components connected to the input / output (I / O) interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 905 as needed. A removable medium 911, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 910 as needed so that computer programs read from it can be installed into the storage section 908 as needed.
[0154] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.
[0155] According to embodiments of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present invention, a computer-readable storage medium may include ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903 described above.
[0156] Embodiments of the present invention also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the methods provided in the embodiments of the present invention.
[0157] When the computer program is executed by the processor 901, it performs the functions defined in the system / apparatus of this invention. According to embodiments of the invention, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0158] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 909, and / or installed from a removable medium 911. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0159] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it performs the functions defined in the system of this embodiment of the invention. According to embodiments of the invention, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0160] According to embodiments of the present invention, program code for executing the computer programs provided in the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0161] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0162] Those skilled in the art will understand that the features described in the various embodiments of the present invention can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention can be combined and / or combined in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or combinations fall within the scope of the present invention.
[0163] The embodiments of the present invention have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of the invention. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of the invention, and all such substitutions and modifications should fall within the scope of the invention.
Claims
1. A method for wireless identification of wireless access points based on event logs, characterized in that, The method includes: In response to an identification request to identify the name and hardware address of a wireless access point, the test received signal strength indication value of the test terminal in a mobile state and the wireless access point to be identified, as well as the test event log related to the test terminal and the wireless access point to be identified, are obtained. The test event log includes the hardware address of the wireless access point device to be identified. Based on the matching of the hardware address of the wireless access point device to be identified with the device status file, the initial device identification result of the wireless access point to be identified is obtained. The device status file includes the access status of the wireless access point to be identified and is updated in real time. The device status file includes a real-time status file of the user terminal and a real-time status file of the wireless access point cluster. The user terminal includes a test terminal, and the wireless access point cluster includes wireless access points to be identified. The device status file is obtained as follows: the initial event log of the user terminal accessing the wireless access point cluster forwarded by the wireless controller is standardized to obtain a standardized event log, the initial event log including the test event log; the standardized event log is corrected to obtain the access relationship between the user terminal and the wireless access point cluster; the real-time status file of the user terminal and the real-time status file of the wireless access point cluster are constructed based on the access relationship, using the hardware address of the user terminal and the hardware address of the wireless access point in the wireless access point cluster as primary keys respectively. The access relationship is obtained based on the repair behavior chain, which is obtained by semantically and logically completing the target behavior chain that lacks event logs. The target behavior chain is obtained by identifying the behavior chain that has undergone fault tolerance processing. The behavior chain is generated based on the event log of the sliding time window, which is constructed in units of the hardware address of the user terminal. Based on the wireless communication method between the test terminal and the wireless access point to be identified, the credibility of the initial device identification result is determined based on the test received signal strength indication value to obtain the target device identification result. The wireless communication method includes wireless access and non-wireless access. If wireless access is available and the credibility of the initial device identification result meets a predetermined value, the initial device identification result is used as the target device identification result; or if wireless access is not available, the initial device identification results are sorted according to their credibility, and the target device identification result that meets the predetermined credibility condition is selected from the sorted results. In the case of wireless access, the reliability of the initial device identification result is determined according to the following formula: ; In the absence of wireless access, the reliability of the initial device identification result is determined according to the following formula: ; in, The normalized RSSI value. To determine whether RSSI shows a continuous upward or downward trend, This refers to the frequency of recent event triggers between the AP and the test STA. This indicates whether the AP device roamed with the test STA within the predetermined time period. If roaming occurred, then... The value is 1 if no roaming has occurred. =0, - These are the weight parameters for each dimension; The target device identification result is supplemented by the geographical location of the wireless access point to obtain the identification result of the wireless access point. The target device identification result includes the name and hardware address of the wireless access point.
2. The method according to claim 1, characterized in that, The step of correcting the standardized event log to obtain the access relationship between the user terminal and the wireless access point cluster includes: A sliding time window is constructed using the hardware address of the terminal as a unit, and a behavior chain is generated based on the event log within the sliding time window; The behavior chain is repaired to obtain a repaired behavior chain; The rationality of the repair behavior chain is checked, and the results are obtained. Based on the detection results, the repair behavior chain is processed to obtain the access relationship between the user terminal and the wireless access point cluster.
3. The method according to claim 2, characterized in that, The step of processing the repair behavior chain based on the detection results to obtain the access relationship between the user terminal and the wireless access point cluster includes: If the detection result indicates that the user terminal connects to m1 different wireless access points within a predetermined time period, the user terminal is marked with a predefined semantic label to obtain the processed user terminal information, where m1 is greater than or equal to 0. When the detection result indicates that the user terminal is simultaneously connected to m2 wireless access points at different physical locations, the wireless access point information with the largest received signal strength indication value of the user terminal is selected from among the m2 wireless access points to obtain the processed wireless access point information, where m2 is an integer greater than 1. Based on the processed terminal information and the processed wireless access point information, an access relationship between the terminal and the wireless access point cluster is constructed.
4. The method according to claim 1, characterized in that, The test event log includes the hardware address of the test terminal; Based on the matching of the test event log and the device status file, the initial device identification result of the wireless access point to be identified is obtained, including: The hardware address of the test terminal is matched with the real-time status file of the user terminal to obtain the hardware address of the wireless access point to be identified. The hardware address of the wireless access point to be identified is matched with the real-time status file of the wireless access point cluster to obtain the device name of the wireless access point to be identified. The initial device identification result is obtained based on the hardware address and device name of the wireless access point to be identified.
5. The method according to claim 1, characterized in that, The step of determining the reliability of the initial device identification result based on the test received signal strength indication value according to the wireless communication method between the test terminal and the wireless access point to be identified includes: When the wireless communication method indicates that wireless access has been established, the reliability of the initial device identification result is determined based on the test received signal strength indication value between the test terminal and the wireless access point to be identified, the changing trend of the test received signal strength indication value, the interaction between the test terminal and the wireless access point to be identified, and the behavior pattern of the test terminal. When the wireless communication method indicates no wireless access, the reliability of the initial device identification result is determined based on the test received signal strength indication value between the test terminal and the wireless access point to be identified, and the changing trend of the test received signal strength indication value.
6. The method according to claim 1, characterized in that, In the absence of wireless access, the method further includes: Using the application installed on the test terminal, the surrounding area is scanned to obtain the hardware address of the surrounding wireless access point cluster, as well as the test received signal strength indication value of the test terminal and the wireless access points in the surrounding wireless access point cluster. The surrounding area includes a spherical region with the test terminal as the center and a predetermined size as the radius.
7. The method according to claim 1, characterized in that, The method further includes: Based on the type of information in the identification result of the wireless access point, the information in the identification result of the wireless access point is filled into the information display template to obtain the information display label; The information display label is displayed in a predetermined image file.
8. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for estimating ap position using log data, and device and terminal for same
CN103181224A