Local area network equipment identification method and system based on artificial intelligence driving

By constructing a comprehensive device feature map and using artificial intelligence models for feature fusion and pattern recognition, the problems of low efficiency and insufficient accuracy in traditional LAN device identification methods are solved, and efficient collaborative work of device clusters is achieved.

CN120602337AActive Publication Date: 2025-09-05SHANGHAI MINGQI NETWORK TECH CO LTD

Patent Information

Application Number
CN202511115662.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-09-05
Estimated Expiration
2045-08-11

AI Technical Summary

Technical Problem

Traditional LAN device identification methods are inefficient and lack accuracy, making it difficult to adapt to the lag in network adaptation parameter configuration when devices dynamically join or exit the network, affecting the efficiency of device cluster collaboration.

Method used

An artificial intelligence-driven LAN device identification method is adopted to construct a comprehensive device feature map by obtaining the communication records of the target device and the LAN environment. The preset device feature library and the target device identification model are used to perform feature fusion and pattern recognition to determine the network adaptation parameters.

Benefits of technology

It achieves accurate identification of devices and dynamic networking optimization in complex LAN environments, improving the collaborative work efficiency of device clusters.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602337A_ABST
    Figure CN120602337A_ABST
Patent Text Reader

Abstract

The invention discloses a local area network device identification method and system based on artificial intelligence driving, and relates to the field of artificial intelligence, and the method comprises the steps: firstly obtaining a communication record of a target device and a local area network environment; determining associated equipment archive information of the target equipment from the communication record; constructing a comprehensive equipment characteristic spectrum based on the associated equipment archive information and the target equipment, and loading the comprehensive equipment characteristic spectrum to a target equipment identification model which comprises a preset equipment characteristic library and is obtained based on communication record training of a known local area network; and through a preset device feature corresponding to the network communication entity in the model retrieval atlas, outputting a device identification feature through feature fusion and mode identification, so as to determine networking adaptation parameters of the target device and the local area network environment. According to the method, the communication behavior rule of the equipment is learned through an artificial intelligence technology, accurate identification and dynamic networking optimization of the equipment in a complex local area network environment are realized, and the cooperative work efficiency of an equipment cluster is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence, and in particular to a method and system for identifying local area network devices based on artificial intelligence. Background Art

[0002] In large commercial scenarios such as shopping malls and office building exhibition halls, the local area network environment often contains a large number of heterogeneous devices such as advertising screens, guide screens, and interactive screens. These devices need to achieve content synchronization, status monitoring, and collaborative control through the local area network. Traditional local area network device identification methods rely on manual configuration or simple network scanning, which has problems with low recognition efficiency and insufficient accuracy. The diversity of device types, such as video playback devices from different manufacturers, leads to large differences in protocol behavior, making it difficult to extract features through fixed rules; when devices dynamically join or leave the network, the static recognition model cannot update the association relationship in real time, resulting in delayed or unreasonable configuration of network adaptation parameters, affecting the collaborative work efficiency of the device cluster. Therefore, there is an urgent need for an identification method based on artificial intelligence technology that can achieve dynamic and accurate device identification and network optimization by learning the communication behavior characteristics of devices. Summary of the Invention

[0003] The purpose of the present invention is to provide a local area network device identification method and system based on artificial intelligence driving.

[0004] In a first aspect, an embodiment of the present invention provides a method for identifying local area network devices based on artificial intelligence, comprising: Obtain communication records between the target device and the LAN environment; Determining associated device profile information of the target device from the communication records of the local area network environment; Based on the associated device profile information and the target device, a comprehensive device feature map is obtained, and the comprehensive device feature map is loaded into a target device identification model; the target device identification model includes a preset device feature library, and the target device identification model is trained based on communication records of a known local area network; Through the target device identification model, the preset device features corresponding to each network communication entity in the comprehensive device feature map are retrieved in the preset device feature library, feature fusion and pattern recognition are performed on each retrieved preset device feature, and the device identification features of the comprehensive device feature map are output; the device identification features are used to determine the networking adaptation parameters between the target device and the local area network environment.

[0005] In a possible implementation, determining the associated device profile information of the target device from the communication records of the local area network environment includes: generating a current protocol behavior trace chain based on a protocol fingerprint identifier of a current network communication entity, and loading the current protocol behavior trace chain into a protocol-aware encoder; the current network communication entity is the target device or a communication peer device in the communication record of the local area network environment, and the protocol-aware encoder includes an initial device feature set; Retrieving, by the protocol-aware encoder, from the initial device feature set, the initial device feature corresponding to the protocol fingerprint identifier of the current network communication entity, performing protocol semantic enhancement and feature topology compression on the retrieved initial device feature, and outputting the target device feature of the current network communication entity; the target device feature is obtained by performing feature space compression on the initial device feature of the network communication entity; Based on the similarity of communication behaviors between the target device characteristics of the target device and the communication peer device, the associated device profile information of the target device is determined from the communication records of the local area network environment.

[0006] In one possible implementation, the method further includes: Obtaining a first protocol behavior trajectory chain, and loading the first protocol behavior trajectory chain into an initial protocol-aware encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol-aware encoder includes the initial device feature set; By means of the initial protocol perception encoder, in the initial device feature set, the initial device feature corresponding to each protocol fingerprint identifier before the first trajectory step in the first protocol behavior trajectory chain is retrieved, protocol semantic enhancement and feature topology compression are performed on each retrieved initial device feature to obtain a predicted device feature corresponding to the first trajectory step, and protocol semantic mapping is performed on the predicted device feature corresponding to the first trajectory step to obtain an initial network communication entity communication behavior spectrum corresponding to the first trajectory step; the initial network communication entity communication behavior spectrum includes communication parameter values ​​corresponding to each network communication entity to be verified in the network communication entity set to be verified; performing communication parameter value dimensionality reduction on the initial network communication entity communication behavior spectrum to obtain a target device communication behavior spectrum corresponding to the first trajectory step; the target device communication behavior spectrum includes a first association confidence corresponding to each to-be-verified network communication entity in the to-be-verified network communication entity set, and the to-be-verified network communication entity set includes a network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain; Determining, from the target device communication behavior spectrum, a first association confidence corresponding to a protocol fingerprint identifier at a first trajectory step in the first protocol behavior trajectory chain; the first trajectory step is determined from a temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain; the first association confidence is used to quantify a degree of interaction coupling between a network communication entity corresponding to the first trajectory step and a leading network communication entity cluster corresponding to the first trajectory step; Obtaining a first deviation value based on first correlation confidences corresponding to the protocol fingerprint identifiers at each first trajectory step in the first protocol behavior trajectory chain; The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until a first training termination threshold is reached, thereby obtaining the protocol-aware encoder.

[0007] In one possible implementation, the initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network, wherein the coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantics enhancement, and the fully connected network is used to output a first association confidence; The step of adjusting the network weight of the initial protocol-aware encoder based on the first deviation value until a first training termination threshold is reached to obtain the protocol-aware encoder includes: Based on the first deviation value, the network weights of the feature mapping network, the feedforward network and the fully connected network in the initial protocol-aware encoder are adjusted until a first training termination threshold is reached to obtain the protocol-aware encoder.

[0008] In one possible implementation, the method further includes: Obtaining network communication entity metadata corresponding to each network communication entity to be verified in the set of network communication entities to be verified; Performing feature extraction on the network communication entity metadata using a text encoder to obtain initial device features corresponding to each of the network communication entities to be verified; The initial device feature set is obtained based on the initial device features corresponding to each of the network communication entities to be verified.

[0009] In one possible implementation, determining the associated device profile information of the target device from the communication records of the local area network environment based on the similarity of communication behaviors between the target device characteristics of the target device and the communication peer device includes: Based on the communication behavior similarity between the target device characteristics of the target device and the communication peer device, determining multiple associated network communication entities of the target device from the communication records of the local area network environment in descending order of the communication behavior similarity; Each associated network communication entity is arranged in time sequence according to the communication timestamp with the local area network environment to obtain the associated device file information of the target device.

[0010] In one possible implementation, the method further includes: Obtaining a second protocol behavior trajectory chain, and loading the second protocol behavior trajectory chain into an initial device identification model; wherein the second protocol behavior trajectory chain is obtained based on communication records of a second known local area network, and the initial device identification model includes the preset device feature library; Using the initial device identification model, the preset device feature corresponding to each protocol fingerprint identifier preceding the second trajectory step in the second protocol behavior trajectory chain is retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain a predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, a second association confidence corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence is used to quantify the degree of interactive coupling between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step. Obtaining a second deviation value based on the second correlation confidence corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain; The network weight of the initial device identification model is adjusted based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model.

[0011] In one possible implementation, the initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. The coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence. The adjusting the network weight of the initial device identification model based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model includes: Based on the second deviation value, the network weights of the fusion recognition network and the fully connected network in the initial device recognition model are adjusted until a second training termination threshold is reached to obtain the target device recognition model.

[0012] In a possible implementation, performing feature fusion and pattern recognition on each retrieved preset device feature and outputting the device identification feature of the comprehensive device feature map includes: Combining each retrieved preset device feature according to the network communication entity order of the comprehensive device feature map to obtain a preset device feature trajectory chain; Performing feature fusion and pattern recognition on the preset device feature trajectory chain to obtain a network communication entity fusion identification feature trajectory chain; the network communication entity fusion identification feature trajectory chain includes network communication entity fusion identification features that match the number of network communication entities in the comprehensive device feature map; From the network communication entity fusion identification feature trajectory chain, the network communication entity fusion identification feature at the network communication entity position of the target device is obtained as the device identification feature of the comprehensive device feature map.

[0013] In a second aspect, an embodiment of the present invention provides a server system, including a server, wherein the server is configured to execute the method described in the first aspect.

[0014] Compared with the existing technology, the beneficial effects provided by the present invention include: using a local area network device identification method and system based on artificial intelligence drive disclosed by the present invention, which relates to the field of artificial intelligence, including: first obtaining the communication records of the target device and the local area network environment; determining the associated device profile information of the target device from the communication records; constructing a comprehensive device feature map based on the associated device profile information and the target device, and loading it into the target device identification model, which contains a preset device feature library and is trained based on the communication records of a known local area network; retrieving the preset device features corresponding to the network communication entity in the map through the model, and outputting the device identification features through feature fusion and pattern recognition, which are used to determine the networking adaptation parameters between the target device and the local area network environment. The present invention uses artificial intelligence technology to learn the laws of device communication behavior, realize accurate identification and dynamic networking optimization of devices in a complex local area network environment, and improve the collaborative work efficiency of the device cluster. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly describes the drawings required for use in the embodiments. It should be understood that the following drawings illustrate only certain embodiments of the present invention and should not be construed as limiting the scope of the present invention. Those skilled in the art can, without inventive effort, derive other relevant drawings from these drawings.

[0016] Figure 1 A schematic diagram of the steps of the artificial intelligence-driven local area network device identification method provided in an embodiment of the present invention; Figure 2 A schematic block diagram of the structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more apparent, the technical solutions of the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present invention. It should be understood that the described embodiments are only a portion of the embodiments of the present invention, not all of them. Generally, the components of the embodiments of the present invention described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations.

[0018] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0019] In order to solve the technical problems in the above background technology, Figure 1 The present invention provides a flow chart of an artificial intelligence-driven local area network device identification method. The artificial intelligence-driven local area network device identification method is introduced in detail below.

[0020] Step S201, obtaining communication records between the target device and the local area network environment; Step S202, determining the associated device profile information of the target device from the communication records of the local area network environment; Step S203: Based on the associated device profile information and the target device, a comprehensive device feature map is obtained, and the comprehensive device feature map is loaded into a target device identification model; the target device identification model includes a preset device feature library, and the target device identification model is trained based on communication records of a known local area network; Step S204: Retrieve the preset device features corresponding to each network communication entity in the comprehensive device feature map from the preset device feature library through the target device identification model, perform feature fusion and pattern recognition on each retrieved preset device feature, and output the device identification features of the comprehensive device feature map; the device identification features are used to determine the networking adaptation parameters between the target device and the local area network environment.

[0021] In an embodiment of the present invention, for example, in a large commercial scenario (such as a comprehensive shopping mall, an office building exhibition hall, etc.), the local area network environment usually contains a large number of video playback devices (such as advertising screens, information guide screens, interactive display screens, etc.), and these devices need to achieve synchronous control, content distribution, and status monitoring through the local area network. As the management core of the local area network, the server first needs to obtain the communication records between the target device and the local area network environment. Taking the "4K advertising screen on the first floor atrium" of a shopping mall (the device is uniquely identified as "AD_SCREEN_001" and the IP address is 10.0.1.10) as the target device, the server collects the communication data of the device and all video playback devices in the environment through the traffic mirroring module deployed in the local area network core switch.

[0022] Communication records during the device initialization and discovery phases are a key data source: When each video playback device on the LAN (such as "AD_SCREEN_001," "GUIDE_SCREEN_002," and "INTERACTIVE_SCREEN_003") starts up, it automatically runs an initialization program, starting a UDP listening port (e.g., port 5000 by default) and a TCP server process (e.g., port 8080). Taking "AD_SCREEN_001" as an example, its initialization process is as follows: After the device is powered on, the embedded system loads the driver. After the network module is initialized, a device discovery packet is broadcast to the LAN via UDP (broadcast address 255.255.255.255:5000). This packet contains the device identifier (e.g., "AD_SCREEN_001"), device type ("4K Advertising Screen"), manufacturer information ("LG"), MAC address ("AA:BB:CC:DD:EE:FF"), and the current system timestamp (e.g., "2024-06-01 09:00:00"). Other devices (such as "GUIDE_SCREEN_002") listen on UDP port 5000. After receiving the data packet, they record the sender information in the local device list (the format is "Device ID-IP-MAC-Device Type-Discovery Time") and send a response packet (containing their own device information) to port 8080 of "AD_SCREEN_001" through the TCP protocol, completing two-way device discovery.

[0023] The server uses a traffic mirroring module to capture communication records during the preceding process, including UDP broadcast packets (source IP 10.0.1.10, destination IP 255.255.255.255, port 5000), TCP handshake packets (for example, GUIDE_SCREEN_002's IP 10.0.1.11 sending a SYN request to 10.0.1.10:8080), and application-layer data related to device information exchange (such as device type and status code in JSON format). The server stores these records in a distributed database (such as MongoDB) structured by the fields "device identifier - timestamp - communication type - packet content," for example, "AD_SCREEN_001|2024-06-01 09:00:00|UDP_BROADCAST|device_id:"AD_SCREEN_001",type:"4K Advertising Screen",mac:"AA:BB:CC:DD:EE:FF"."

[0024] The server needs to extract information about associated devices that interact with the target device "AD_SCREEN_001" from the global communication records to form an associated device profile. This process relies on communication behavior characteristics and protocol fingerprint analysis during the device discovery phase.

[0025] First, the server generates a protocol behavior trajectory chain based on the protocol fingerprint identifiers of the target device and the communicating peer device. The protocol fingerprint identifier is a unique identifier of the device's communication behavior, generated by combining the device type, protocol type, port number, and key fields. For example, the UDP broadcast behavior of "AD_SCREEN_001" corresponds to the fingerprint identifier "LG_4K_UDP_5000_MAC_AA", and the TCP response behavior of "GUIDE_SCREEN_002" corresponds to "Samsung_Guide_TCP_8080_MAC_BB". The server concatenates the interaction fingerprint identifiers of the target device and other devices in timestamp order to form a current protocol behavior trajectory chain. For example, the trajectory chain fragment is: [LG_4K_UDP_5000_MAC_AA (t0) → Samsung_Guide_TCP_8080_MAC_BB (t1) → HUAWEI_Interactive_UDP_5000_MAC_CC (t2) → ...], where t0 is the time when "AD_SCREEN_001" sends the UDP broadcast, t1 is the time when "GUIDE_SCREEN_002" returns the TCP response, and t2 is the time when the third-floor interactive screen "INTERACTIVE_SCREEN_003" sends the UDP response.

[0026] The server then loads the trajectory chain into a pre-trained protocol-aware encoder. This encoder contains an initial device feature set (storing basic features of known device types, such as the feature vector for "4K advertising screen" is [resolution: 3840x2160, protocol: UDP / TCP, power consumption: 150W, manufacturer: LG]). The encoder layer network retrieves the initial device features corresponding to each fingerprint identifier in the trajectory chain. A feedforward network performs protocol semantic enhancement (for example, mapping "UDP broadcast" behavior to the semantic label "active discovery"). A feature mapping network then compresses the feature topology (reducing high-dimensional feature vectors to 256-dimensional dense vectors). The encoder ultimately outputs the target device features for both the target device and the communicating peer device (for example, the target feature vector for "AD_SCREEN_001" is V1, and for "GUIDE_SCREEN_002" is V2).

[0027] The server calculates the communication behavior similarity between target feature vectors (using the cosine similarity algorithm). For example, if the similarity between V1 and V2 is 0.85 (higher than the threshold of 0.7), they are considered strongly associated devices. The similarity between V1 and a printer device feature vector is 0.3, indicating a weak association. The server selects the top N strongly associated devices (such as "GUIDE_SCREEN_002," "INTERACTIVE_SCREEN_003," and "CONTROL_SERVER_001") in descending order of similarity and arranges them in chronological order by communication timestamp to form an associated device profile. For example, the associated device profile: Device 1: GUIDE_SCREEN_002 (Type: Guide Screen, IP: 10.0.1.11, First Communication Time: t1, Similarity: 0.85) Device 2: INTERACTIVE_SCREEN_003 (Type: Interactive Screen, IP: 10.0.2.05, First Communication Time: t2, Similarity: 0.82) Device 3: CONTROL_SERVER_001 (Type: Control Server, IP: 10.0.0.01, First Communication Time: t3, Similarity: 0.90) The server constructs a comprehensive device feature graph based on the associated device profile information and the target device's own characteristics. This graph uses the target device "AD_SCREEN_001" as the core node, and associated devices as secondary nodes. Directed edges are constructed between nodes based on communication parameters (such as interaction frequency, data volume, and protocol type). For example: Core node: AD_SCREEN_001 (features: 4K resolution, LG manufacturer, UDP broadcast frequency 5 times / minute) Secondary node 1: GUIDE_SCREEN_002 (edge ​​attributes: TCP connection frequency 1 time / second, average data volume 1024B / packet) Secondary node 2: CONTROL_SERVER_001 (edge ​​attributes: TCP persistent connection, control command transmission, data volume 512B / command) The structure of the comprehensive device feature map is converted into a tensor (of dimension N × 256, where N is the number of nodes) and loaded into the target device recognition model. This model is trained based on communication records from a known commercial LAN (e.g., an office building with 500 video devices deployed). It also includes a pre-set device feature library (storing standard features for over 100 types of video devices, such as the protocol fingerprint of a Sony 2K advertising screen and the interaction mode of a Sharp touch screen).

[0028] The target device identification model first traverses the preset device feature library through the coding layer network, retrieving the preset device features corresponding to each network communication entity (target device and associated devices) in the comprehensive device feature map. For example, the model retrieves the preset feature vector for "AD_SCREEN_001" as the "LG4K Advertising Screen Standard Feature Vector," and the preset feature vector for "GUIDE_SCREEN_002" as the "Samsung Guide Screen Standard Feature Vector."

[0029] The model then combines the retrieved preset device features into a preset device feature trajectory chain (LG_4K_Standard → Samsung_Guide_Standard → Control_Server_Standard) according to the node order of the integrated device feature map (core node → secondary node 1 → secondary node 2). The fusion recognition network then performs feature fusion (using an attention mechanism to assign higher weights to control server nodes) and pattern recognition (using an LSTM network to learn temporal dependencies) on this trajectory chain, resulting in a fusion recognition feature trajectory chain for network communication entities (each node corresponds to a fusion recognition feature vector).

[0030] The server extracts the fused identification feature vector of the core node (target device) from the fused identification feature trajectory chain as the device identification feature. This feature vector contains key information such as the target device type, performance, and networking requirements. For example, device identification features include: [Device type: 4K advertising screen (confidence 0.98), Communication protocol: UDP / TCP (priority TCP), Bandwidth requirement: 50Mbps, Synchronization accuracy: ±10ms, Compatibility: Supports Samsung / LG protocol interoperability].

[0031] The server maps device identification features to specific network adaptation parameters to optimize the collaboration between the target device and the LAN environment. For example: Bandwidth allocation: Based on the bandwidth requirement of 50 Mbps, the server allocates a dedicated VLAN (VLAN ID: 100) to AD_SCREEN_001 through the SDN controller, ensuring that the uplink bandwidth is ≥ 50 Mbps and avoiding resource competition with other low-priority devices (such as office computers). Synchronization strategy: Based on the "synchronization accuracy ±10ms", adjust the NTP server synchronization frequency (from the default 1 hour / time to 1 minute / time) to ensure that the playback time difference with the "GUIDE_SCREEN_002" advertising content is ≤10ms; Protocol compatibility: Based on "support for Samsung / LG protocol interoperability", the protocol conversion module is enabled in the core switch to convert LG's proprietary control protocol into the MQTT protocol compatible with Samsung guide screens, enabling cross-manufacturer device linkage control.

[0032] Through the above process, the server achieves accurate identification and dynamic networking optimization of video playback devices in large-scale commercial scenarios, ensuring stable and efficient operation of the device cluster.

[0033] In this embodiment of the present invention, the server system consists of one main server (equipped with an Intel Xeon Gold 6348 CPU, 256GB of memory, and a 10TB SSD) and three edge computing nodes (deployed in weak current rooms on each floor). The main server is connected to the core switch via 10Gbps fiber and is responsible for communication record storage, model training, and inference. The edge nodes collect local device communication data via Gigabit Ethernet, pre-process it, and upload it to the main server. The server runs the Linux operating system and uses the PyTorch deep learning framework to deploy the target device recognition model. It uses a Kafka message queue to receive communication records in real time. The protocol-aware encoder and model inference service are deployed in a Docker containerized manner, enabling 24 / 7 uninterrupted device recognition and network adaptation.

[0034] In the embodiment of the present invention, the step of determining the associated device profile information of the target device from the communication records of the local area network environment may be implemented through the following examples.

[0035] Extracting target device features of a network communication entity from communication records between the target device and a communication peer device in the local area network environment; the target device features are obtained by compressing the initial device features of the network communication entity through feature space compression; Based on the similarity of communication behaviors between the target device characteristics of the target device and the communication peer device, the associated device profile information of the target device is determined from the communication records of the local area network environment.

[0036] In this embodiment of the present invention, for example, the server uses the target device "AD_SCREEN_001" (the 4K advertising screen in the first-floor atrium) and the corresponding communication devices in the local area network communication records (such as video playback devices such as "GUIDE_SCREEN_002" and "INTERACTIVE_SCREEN_003") as network communication entities and extracts the target device features of each entity. The target device features are low-dimensional dense vectors obtained by compressing the feature space of the initial device features of the network communication entity. They are generated by combining the communication behavior data and basic attributes during the device initialization and discovery phases. First, the server parses the initial device features of the network communication entity from the communication records. Initial device characteristics include basic device attributes and communication behavior characteristics. They are derived from the following sources: Basic attributes are extracted from the device initialization broadcast packet. For example, the UDP broadcast packet for "AD_SCREEN_001" carries the following fields: device ID "AD_SCREEN_001", device type "4K advertising screen", manufacturer "LG", resolution "3840x2160", MAC address "AA:BB:CC:DD:EE:FF", and system version "V2.3.1". Communication behavior characteristics are extracted from traffic mirroring data. For example, the communication behavior characteristics of "AD_SCREEN_001" include: UDP broadcast frequency (5 times / minute), TCP server port (8080), average packet size (1200 bytes), number of communicating peers (12 devices), and protocol type ratio (UDP: 30%, TCP: 70%). The server converts these initial device characteristics into structured data (e.g., key-value pairs) and maps them into high-dimensional feature vectors (dimension 512). Taking "AD_SCREEN_001" as an example, its initial device feature vector is: [V_initial = [Device type code: 001, Manufacturer code: 005, Resolution: 3840x2160, UDP frequency: 5, TCP port: 8080, MAC hash: 0xABCD...,...]]; the server then spatially compresses the initial device feature vector using a pretrained feature mapping network. This network uses an autoencoder structure, taking a 512-dimensional initial vector as input. The encoder (consisting of three fully connected layers with a ReLU activation function) reduces the dimensionality to 256 dimensions. The decoder then reconstructs the features, optimizing network parameters to minimize reconstruction error. During the compression process, the network retains key features (such as device type, protocol behavior, and manufacturer attributes) while removing redundant information (such as the system version minor revision number).The target device feature vector finally output is a low-dimensional dense vector. For example, the target device feature vector of "AD_SCREEN_001" is: [V_target1=[0.23,0.56,0.11,...,0.89] (dimension 256)]; For the communication peer device (such as "GUIDE_SCREEN_002", the second-floor guide screen), the server executes the same process: from its UDP response packet (device identifier "GUIDE_SCREEN_002", type "guide screen", manufacturer "Samsung") ”, resolution “1920x1080”) and TCP interaction records (response port 8080, average packet size 800 bytes, number of communicating peers 8). After feature mapping network compression, the target device feature vector is obtained: [V_target2=[0.19,0.62,0.08,...,0.75] (dimension 256)]. The server calculates the communication behavior similarity between the target device and the target device feature vectors of the communicating peer devices to screen strongly associated devices and generate associated device profile information. Communication behavior similarity is used to quantify the degree of match between the two devices in terms of protocol interaction mode and functional positioning. It is calculated using the cosine similarity algorithm with a threshold set to 0.7 (preset based on the collaborative requirements of video devices in commercial scenarios). First, the server uses the target device feature vector (V_target1) of the target device "AD_SCREEN_001" as the benchmark, traverses all communicating peer devices in the communication record, and calculates the cosine similarity between each target device feature vector and (V_target1). Taking "GUIDE_SCREEN_002" as an example, the cosine similarity between its vectors (V_target2) and (V_target1) is 0.82. This result (0.82) exceeds the threshold of 0.7, making "GUIDE_SCREEN_002" an associated device of the target device. Following this logic, the server calculates the similarity of all communicating peer devices and selects devices with a similarity ≥ 0.7, including: "GUIDE_SCREEN_002" (the second-floor guide screen, similarity 0.82); "INTERACTIVE_SCREEN_003" (the third-floor interactive screen, similarity 0.78); and "CONTROL_SERVER_001" (the LAN control server, similarity 0.91, responsible for content distribution). The server then extracts the timestamps of the first communication between these associated devices and the target device from the communication log (based on the timestamp field in the TCP handshake packet) and arranges them in ascending timestamp order to form a profile of the associated devices of the target device. The final profile information format is as follows; please refer to Table 1 for details.

[0037] Table 1 Device identification Device Type IP address First communication time Communication behavior similarity CONTROL_SERVER_001 Control Server 10.0.0.1 2024-06-0109:00:12 0.91 GUIDE_SCREEN_002 Guide screen 10.0.1.15 2024-06-0109:00:25 0.82 INTERACTIVE_SCREEN_003 Interactive screen 10.0.2.8 2024-06-0109:00:40 0.78 This archival information fully records the core associated devices of the target device in the local area network, providing key data support for the subsequent construction of a comprehensive device feature map.

[0038] In the embodiment of the present invention, the extraction of target device features of the network communication entity from the communication records between the target device and the communication peer device in the local area network environment can be implemented through the following examples.

[0039] generating a current protocol behavior trace chain based on a protocol fingerprint identifier of a current network communication entity, and loading the current protocol behavior trace chain into a protocol-aware encoder; the current network communication entity is the target device or a communication peer device in the communication record of the local area network environment, and the protocol-aware encoder includes an initial device feature set; Through the protocol-aware encoder, the initial device features corresponding to the protocol fingerprint identifier of the current network communication entity are retrieved from the initial device feature set, the retrieved initial device features are subjected to protocol semantic enhancement and feature topology compression, and the target device features of the current network communication entity are output.

[0040] In an embodiment of the present invention, for example, in a large commercial scenario (such as a shopping mall local area network), the server needs to extract target device features for the target device "AD_SCREEN_001" (4K advertising screen in the atrium on the first floor) and the communicating peer device (such as the guide screen "GUIDE_SCREEN_002" on the second floor and the interactive screen "INTERACTIVE_SCREEN_003" on the third floor). This process relies on the protocol fingerprint analysis of the device communication behavior and the feature processing capabilities of the protocol perception encoder. The specific steps are as follows: the server first generates the current protocol behavior trajectory chain based on the protocol fingerprint identifier of the current network communication entity. The current network communication entity includes the target device "AD_SCREEN_001" and the communicating peer device (such as "GUIDE_SCREEN_002"). The protocol fingerprint identifier is a unique identifier of the device communication behavior. It is generated by combining the device type, protocol type, port number, key behavior characteristics and manufacturer information, and must reflect the core interactive behavior of the device initialization and discovery phase. Taking the target device "AD_SCREEN_001" as an example, its communication behaviors during the initialization process include: Behavior 1 (t0=09:00:00): After startup, it broadcasts a device discovery data packet to the local area network through the UDP protocol (destination port 5000). The broadcast packet contains the device identifier, MAC address (AA:BB:CC:DD:EE:FF), device type "4K advertising screen", and manufacturer "LG". The protocol fingerprint identifier of this behavior is defined as "LG_4K_AD_UDP_BC_5000_AA" (manufacturer_device type_protocol_behavior_port_MAC prefix); Behavior 2 (t1=09:00:02): Receiving After making a TCP connection request to "GUIDE_SCREEN_002", the TCP server (port 8080) responds to the connection and returns device status information (online, resolution 3840x2160). The protocol fingerprint identifier of this behavior is "LG_4K_AD_TCP_SRV_8080_AA". Behavior 3 (t2=09:00:05): Receives a UDP response packet from "INTERACTIVE_SCREEN_003" (source port 5000), which contains interactive screen device information. The protocol fingerprint identifier of this behavior is "LG_4K_AD_UDP_RCV_5000_AA".The server concatenates the above protocol fingerprint identifiers in timestamp order (t0→t1→t2) to generate the current protocol behavior trajectory chain of "AD_SCREEN_001": trajectory chain: [LG_4K_AD_UDP_BC_5000_AA (t0)→LG_4K_AD_TCP_SRV_8080_AA (t1)→LG_4K_AD_UDP_RCV_5000_AA (t2)]; for the communication peer device "GUIDE_SCREEN_002" (Samsung guide screen, MAC address BB:CC:DD:EE:FF:AA), its initialization and interaction behaviors with the target device include: Behavior 1 ( t0+1s=09:00:01): The broadcast packet of "AD_SCREEN_001" is listened to through UDP port 5000, and the sender information is recorded in the local device list. The protocol fingerprint identifier of this behavior is "Samsung_Guide_UDP_MON_5000_BB". Behavior 2 (t1-1s=09:00:01): A connection request is initiated to TCP port 8080 of "AD_SCREEN_001", sending the device type "Guide Screen" and the resolution 1920x1080. The protocol fingerprint identifier of this behavior is "Samsung_Guide_TCP_CLI_8080_BB". The server concatenates their fingerprint identifiers in timestamp order to generate the current protocol behavior trajectory chain of "GUIDE_SCREEN_002": Trajectory chain: [Samsung_Guide_UDP_MON_5000_BB (t0+1s) → Samsung_Guide_TCP_CLI_8080_BB (t1-1s)]; then, the server loads the above two trajectory chains (target device and communication peer device) into the pre-deployed protocol-aware encoder respectively. This encoder is a neural network model that contains an initial device feature set and stores basic feature templates for known video playback device types. For example, the initial feature template for "LG 4K Advertising Screen" is: Device Type: 4K Advertising Screen, Manufacturer: LG, Supported Protocols: UDP / TCP, UDP Default Port: 5000, TCP Server Port: 8080, Resolution: 3840x2160, Typical Behavior: UDP Broadcast + TCP Response; the initial feature template for "Samsung Guide Screen" is: Device Type: Guide Screen, Manufacturer: Samsung, Supported Protocols: UDP / TCP, UDP Listening Port: 5000, TCP Client Port: 8080, Resolution: 1920x1080, Typical Behavior: UDP Listen + TCP Request. The protocol-aware encoder converts trajectory chains into target device features through a three-level process: an encoding layer network, a feedforward network (for protocol semantics enhancement), and a feature mapping network (for feature topology compression).Step 1: Retrieve the initial device feature. The encoding layer network of the encoder performs an exact match search in the initial device feature set based on the protocol fingerprint identifier in the trajectory chain. Take the trajectory chain of "AD_SCREEN_001" as an example: the "LG_4K_AD" in the first fingerprint of the trajectory chain "LG_4K_AD_UDP_BC_5000_AA" matches the template identifier of "LG4K Advertising Screen" in the initial feature set, and "UDP_BC_5000" matches the initial device feature of "UDP Broadcast Behavior (Port 5000)" in the template, that is, behavior type: active discovery, protocol: UDP, port: 5000, data field: device identifier + MAC + type; the second fingerprint "LG_4K_ The fingerprint "AD_TCP_SRV_8080_AA" matches the initial device signature of the "TCP server response behavior (port 8080)" in the template, namely, behavior type: passive response, protocol: TCP, port: 8080, and data field: status + resolution. The third fingerprint "LG_4K_AD_UDP_RCV_5000_AA" matches the initial device signature of the "UDP receive behavior (port 5000)" in the template, namely, behavior type: passive receive, protocol: UDP, port: 5000, and data field: peer device information. The encoding layer network combines the three retrieved initial device signatures in trajectory chain order to form an initial feature sequence (with a dimension of 3×512, each feature is a 512-dimensional vector). The encoder's feedforward network performs protocol semantics on the initial feature sequence, converting low-level protocol behaviors into high-level semantic labels and integrating them into the feature vector. The specific process is as follows: For the "UDP broadcast behavior" feature, the network uses a preset semantic mapping table to map "active discovery" behavior to a semantic vector [1,0,0] (representing the "initiator" role) and append it to the end of the original feature vector. For the "TCP server response behavior," "passive response" is mapped to a semantic vector [0,1,0] (representing the "responder" role) and integrated into the feature vector. For the "UDP receive behavior," "passive reception" is mapped to a semantic vector [0,0,1] (representing the "receiver" role) and integrated into the feature vector. After enhancement, each initial feature vector is expanded from 512 dimensions to 515 dimensions (with the addition of a 3-dimensional semantic label), and the feature sequence is upgraded to 3×515 dimensions. The encoder's feature mapping network (using a two-layer fully connected autoencoder structure) performs topological compression on the enhanced feature sequence, removing redundant dimensions while retaining the core behavioral features and semantic associations. The network input is a 3×515-dimensional sequence, which is reduced to 3×256 dimensions by the first fully connected layer (with 256 neurons and ReLU activation function). The second fully connected layer (with 256 neurons) compresses the sequence into a single 256-dimensional dense vector (representing the overall behavioral characteristics of the trajectory chain).During the compression process, the network ensures that key information (such as device type, protocol role, and vendor attributes) is not lost by minimizing reconstruction error (comparing feature similarities before and after compression). Ultimately, the protocol-aware encoder outputs the target device feature vector for "AD_SCREEN_001": [V_target_AD001=[0.28,0.61,0.15,...,0.92] (256-dimensional, containing a compressed representation of device type, protocol role, and vendor attributes)]. For the communicating peer device "GUIDE_SCREEN_002," the server executes the same process: its trajectory chain [Samsung_Guide_UDP_MON_5000_BB→Samsung_Guide_TCP_CLI_ 8080_BB] retrieves the initial features of the "Samsung Guide Screen" (UDP listening + TCP request) through the encoder. After semantic enhancement ("UDP listening" is mapped to [0,0,1] receiver, and "TCP request" is mapped to [1,0,0] initiator) and topological compression, the target device feature vector is output: [V_target_GUIDE002=[0.21,0.58,0.19,...,0.85] (dimension 256)]; the above target device feature vector will be used for subsequent communication behavior similarity calculations to provide a quantitative basis for determining the associated device profile information.

[0041] In the embodiments of the present invention, the following implementation modes are also provided.

[0042] Obtaining a first protocol behavior trajectory chain, and loading the first protocol behavior trajectory chain into an initial protocol-aware encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol-aware encoder includes the initial device feature set; Retrieving, from the initial device feature set, the initial device feature corresponding to each protocol fingerprint identifier preceding the first trajectory step in the first protocol behavior trajectory chain by means of the initial protocol-aware encoder, performing protocol semantic enhancement and feature topology compression on each retrieved initial device feature to obtain a predicted device feature corresponding to the first trajectory step, and obtaining, based on the predicted device feature corresponding to the first trajectory step, a first association confidence corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain; the first trajectory step is determined from a temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain, and the first association confidence is used to quantify the degree of interactive coupling between the network communication entity corresponding to the first trajectory step and a leading network communication entity cluster corresponding to the first trajectory step; Obtaining a first deviation value based on first correlation confidences corresponding to the protocol fingerprint identifiers at each first trajectory step in the first protocol behavior trajectory chain; The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until a first training termination threshold is reached, thereby obtaining the protocol-aware encoder.

[0043] In an exemplary embodiment of the present invention, in a large-scale commercial scenario, a protocol-aware encoder must be trained using communication records from known local area networks (LANs) before it can be used to extract target device features. Using the "LAN in an office building's exhibition hall" (a first known LAN, deployed with 50 video playback devices, including advertising screens and guide screens) as the training environment, a server trains an initial protocol-aware encoder using historical communication records from this environment. The specific steps are as follows: The server extracts core interaction data from the device initialization and discovery phases from the communication records of the first known LAN, generating a first protocol behavior trajectory chain. This trajectory chain is constructed based on the communication behavior of the "main advertising screen" (device identifier "MAIN_AD_001," manufacturer Sony, type 4K advertising screen) within the LAN. Its communication records contain three months of device interaction logs, covering the initialization and discovery process with 20 slave devices (such as "SUB_AD_002" and "GUIDE_003"). The first protocol behavior trajectory chain for "MAIN_AD_001" is arranged in chronological order by timestamps and is constructed by concatenating protocol fingerprint identifiers. The protocol fingerprint identifier is generated based on the device type, protocol behavior, port and MAC prefix. For example: Fingerprint 1 (t0=08:00:00): UDP broadcast discovery packet (port 5000) after the device starts, fingerprint identifier "Sony_4K_UDP_BC_5000_AB" (manufacturer_type_protocol_behavior_port_MAC prefix); Fingerprint 2 (t1=08:00:02): Receive TCP connection request from advertising screen "SUB_AD_002" (port 8080), fingerprint identifier Fingerprint 3 (t2 = 08:00:05): Receives a UDP response packet (port 5000) from the guide screen "GUIDE_003" (fingerprint identifier "Sony_4K_UDP_RCV_5000_AB"); Fingerprint 4 (t3 = 08:00:08): Sends a TCP status report (port 9090) to the control server (fingerprint identifier "Sony_4K_TCP_SND_9090_AB"). In timestamp order, the first protocol behavior trajectory chain is defined as: Trajectory chain: [F1 (t0) → F2 (t1) → F3 (t2) → F4 (t3)] (F1-F4 are the fingerprint identifiers mentioned above). The server loads this trajectory chain into the initial protocol-aware encoder.The encoder is an untrained neural network model that contains an initial device feature set and stores basic feature templates of all device types in the first known local area network. For example, the initial feature template of "Sony4K Advertising Screen" is: Device Type: 4K Advertising Screen, Manufacturer: Sony, Protocol Support: UDP / TCP, UDP Port: 5000, TCP Port: 8080 / 9090, Typical Behavior: UDP Broadcast → TCP Receive → UDP Receive → TCP Send; the template of "SUB_AD_002" (slave advertising screen, manufacturer LG) is: Device Type: Slave Advertising Screen, Manufacturer: LG, Protocol Support: UDP / TCP, UDP Listening Port: 5000, TCP Client Port: 8080, Typical Behavior: UDP Listen → TCP Request. The server determines the first trajectory step from the temporal locations of the first protocol behavior trajectory chain (selecting all locations in the trajectory chain except the first fingerprint, i.e., F2, F3, and F4 corresponding to t1, t2, and t3, as steps). It then predicts the device characteristics and cross-coupling degree of the current step based on the preceding network communication entity cluster for each step (the devices corresponding to all fingerprints preceding the step). For example, for the first trajectory step "t2 (F3)" (the current step fingerprint is "Sony_4K_UDP_RCV_5000_AB" and the corresponding behavior is receiving the UDP response from "GUIDE_003"): the preceding network communication entity cluster is the trajectory chain segment before step t2 [F1 (t0) → F2 (t1)], corresponding to the UDP broadcast behavior (F1) of "MAIN_AD_001" and the TCP request behavior (F2) of "SUB_AD_002"). Initial device characteristics are retrieved: The encoding layer network of the initial protocol-aware encoder retrieves the initial device characteristics corresponding to F1 and F2 from the initial device feature set. F1 corresponds to the "UDP broadcast feature" of the "Sony 4K advertising screen": Behavior type: active discovery, protocol: UDP, port: 5000, data field: device identifier + MAC address; F2 corresponds to the "TCP receive feature": Behavior type: passive response, protocol: TCP, port: 8080, data field: connection confirmation + resolution. Protocol semantic enhancement: The feedforward network integrates semantic labels with the retrieved initial features. F1's "active discovery" is mapped to the semantic vector [1, 0, 0] (initiator), and F2's "passive response" is mapped to [0, 1, 0] (responder). The enhanced feature dimension is expanded from 512 to 515 dimensions. Feature topology compression: The feature mapping network (a two-layer fully connected autoencoder) compresses the two enhanced feature vectors (F1 and F2) into a 256-dimensional predicted device feature vector, representing the comprehensive interaction characteristics of the leading cluster. Generating the first association confidence: The fully connected network maps the predicted device feature vector to the first association confidence, which quantifies the degree of interaction coupling between the current step size F3 and the leading cluster.This confidence is calculated by comparing the predicted features with the actual interaction features of the UDP response from "MAIN_AD_001" to "GUIDE_003" on the first known local area network (pre-labeled as "high coupling" with a label confidence of 0.95). The initial encoder output predicted confidence of 0.62 (which deviates from the actual label). Following the same logic, the server calculates the first association confidence for all first trajectory steps (t1, t2, t3) in the first protocol behavior trajectory chain, resulting in the following confidence sequence: [t1: 0.58, t2: 0.62, t3: 0.55] (all lower than the actual label confidence of 0.9 ± 0.05). The server compares the first association confidence sequence with the actual label sequence (the actual interaction coupling extracted from the first known LAN communication record, e.g., [t1: 0.92, t2: 0.95, t3: 0.90]). Using the mean squared error (MSE), the server calculates a first deviation value of 0.118. The network weights of the initial protocol-aware encoder (the weights of the fully connected layers of the feature mapping network and the feedforward network) are adjusted using a backpropagation algorithm. Using the first deviation value as the loss function, the Adam optimizer (learning rate 0.001) is used to update the weights, focusing on adjusting the dimensionality reduction parameters of the feature mapping network and the semantic enhancement weights of the feedforward network. The server repeats the training process (loading the new first protocol behavior trajectory chain, calculating the deviation value, and adjusting the weights) until the first deviation value reaches the first training termination threshold (preset to ≤0.01). After 200 rounds of training, the first deviation value drops to 0.008, meeting the termination criterion. At this point, the initial protocol-aware encoder is optimized to the trained protocol-aware encoder, which can be used to extract precise target device features for the target device.

[0044] In an embodiment of the present invention, obtaining the first association confidence corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain based on the predicted device feature corresponding to the first trajectory step may be implemented through the following example.

[0045] Performing protocol semantic mapping on the predicted device features corresponding to the first trajectory step length to obtain an initial network communication entity communication behavior spectrum corresponding to the first trajectory step length; the initial network communication entity communication behavior spectrum includes communication parameter values ​​corresponding to each to-be-verified network communication entity in the to-be-verified network communication entity set; performing communication parameter value dimensionality reduction on the initial network communication entity communication behavior spectrum to obtain a target device communication behavior spectrum corresponding to the first trajectory step; the target device communication behavior spectrum includes a first association confidence corresponding to each to-be-verified network communication entity in the to-be-verified network communication entity set, and the to-be-verified network communication entity set includes a network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain; A first association confidence corresponding to a protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain is determined from the target device communication behavior spectrum.

[0046] In an embodiment of the present invention, for example, in a training scenario within a first known local area network (an office building exhibition hall), the server uses the first trajectory step "t2 (fingerprint identifier F3: Sony_4K_UDP_RCV_5000_AB)" as an example (corresponding to the main advertising screen "MAIN_AD_001" receiving a UDP response from the guide screen "GUIDE_003") and generates a first correlation confidence score through three steps: protocol semantic mapping, communication parameter dimensionality reduction, and confidence extraction. The "communication behavior spectrum" describes the logical relationship between device communication characteristics and correlation strength using natural language. The specific process is as follows: the server performs protocol semantic mapping on the predicted device features corresponding to the first trajectory step (t2) (the 256-dimensional compressed features of the leading network communication entity cluster, including the UDP broadcast behavior of "MAIN_AD_001" and the TCP request behavior of the slave advertising screen "SUB_AD_002"). This mapping process, based on the semantic rule base built into the initial protocol-aware encoder, converts the abstract feature vector into a specific communication parameter description for each entity in the set of network communication entities to be verified. The set of network communication entities to be verified consists of the network communication entities corresponding to all protocol fingerprint identifiers in the first protocol behavior trajectory chain, including the main advertising screen "MAIN_AD_001", the slave advertising screen "SUB_AD_002" (the communication counterpart of F2), the guide screen "GUIDE_003" (the communication counterpart of F3) and the control server "CONTROL_SERVER" (subsequent interaction entity).The communication behavior spectrum of the initial network communication entity is a structured description of the communication characteristics of these entities, which is specifically as follows: Main advertising screen "MAIN_AD_001": As the core entity of the trajectory chain, it has the highest interaction frequency with the leading cluster, reaching 8 times / minute, with an average data packet size of 1200 bytes, a protocol matching degree (the overlap ratio with its own leading behavior) of 1.0 (complete match), the shortest response delay (15ms), and a data field overlap (the sharing ratio with its own communication field) of 1.0 (complete overlap); Slave advertising screen "SUB_AD_002": As an entity that has completed TCP interaction with the main advertising screen, the interaction frequency is 6 times / minute, the average data packet size is 900 bytes, the protocol matching degree is 0.9 (high overlap with the TCP protocol of the leading cluster), the response delay is 18ms, and the data field overlap is 0.9 (shared device identification, MAC address and other core fields); Guide screen "GUIDE_003": As the entity whose current trajectory step is to be verified, the interaction frequency is 5 times / minute, the average data packet size is 800 bytes, the protocol matching degree is 0.85 (supports UDP / TCP mixed protocol, and has a high degree of overlap with the pilot cluster protocol type), the response delay is 20ms, and the data field overlap is 0.75 (including shared fields such as device identification and type, but lacks resolution parameters unique to advertising screens); Control server "CONTROL_SERVER": As the entity for subsequent interactions, the current interaction frequency is low (3 times / minute), the average data packet size is 500 bytes, the protocol matching degree is 0.6 (mainly based on TCP control protocol, with low overlap with the UDP broadcast behavior of the pilot cluster), the response delay is 25ms, and the data field overlap is 0.5 (only includes the basic device ID field). The server reduces the multi-dimensional communication parameters (interaction frequency, packet size, protocol compatibility, etc.) in the initial network communication entity communication behavior spectrum, converting them into a single "first association confidence" to quantify the degree of interaction coupling between each entity to be verified and the leading network communication entity cluster. The dimensionality reduction process is achieved through weighted fusion, with weights assigned based on the degree of influence of the parameters on the interaction coupling: interaction frequency (0.3), protocol compatibility (0.3), data field overlap (0.2), average packet size (0.1), and response latency (0.1).The specific fusion process is as follows: Main advertising screen "MAIN_AD_001": All parameters are normalized (mapped to the range of 0-1) and then weighted summed: interaction frequency (1.0) × 0.3 + protocol matching (1.0) × 0.3 + data field overlap (1.0) × 0.2 + data packet size (1.0) × 0.1 + response delay (1.0) × 0.1 = 1.0. Because it is its own entity, the first association confidence is corrected to 0.95; Slave advertising screen "SUB_AD_002": interaction frequency (0.75) × 0.3 + protocol matching (0.9) × 0.3 + data field overlap (0.9) × 0.2 + data packet size (0.75) × 0.1 + response delay (0.85) × 0.1 = 0.78; Guide screen "GUIDE_003": interaction frequency (0.5) × 0.3 + protocol matching (0.85) × 0.3 + data field overlap (0.75) × 0.2 + data packet size (0.5) × 0.1 + response delay (0.75) × 0.1 = 0.62; Control server "CONTROL_SERVER": interaction frequency (0.25) × 0.3 + protocol matching (0.6) × 0.3 + data field overlap (0.5) × 0.2 + data packet size (0.25) × 0.1 + response delay (0.5) × 0.1 = 0.45. The target device communication behavior spectrum obtained after dimensionality reduction shows the following: the first association confidence of each entity to be verified, from high to low, is: main advertising screen "MAIN_AD_001" (0.95), slave advertising screen "SUB_AD_002" (0.78), guide screen "GUIDE_003" (0.62), and control server "CONTROL_SERVER" (0.45). This confidence sequence quantifies the strength of the interaction coupling between each entity and the leading cluster. From the target device communication behavior spectrum, the server locates the network communication entity corresponding to the protocol fingerprint identifier F3 ("Sony_4K_UDP_RCV_5000_AB") at the first trajectory step t2, namely the guide screen "GUIDE_003". Based on the behavior spectrum, the first association confidence of this entity is 0.62, which quantifies the degree of interaction coupling between the guide screen and the leading network communication entity cluster (UDP broadcasts from the main advertising screen and TCP requests from the slave advertising screens), indicating a medium to high degree of match between the two in terms of protocol behavior patterns and device role positioning. This confidence level will serve as a key basis for training the initial protocol-aware encoder, subsequently used to calculate the first bias value and adjust network weights. Through these steps, the server, without relying on tables, clearly presents the transformation process from multi-dimensional parameters to a single confidence level through a hierarchical description of the communication behavior spectrum in natural language, ultimately extracting the first associated confidence level that can be used for model training.

[0047] In an embodiment of the present invention, the initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network. The coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantics enhancement, and the fully connected network is used to output a first association confidence. The adjusting the network weights of the initial protocol-aware encoder based on the first deviation value until a first training termination threshold is reached to obtain the protocol-aware encoder can be implemented through the following example.

[0048] Based on the first deviation value, the network weights of the feature mapping network, the feedforward network and the fully connected network in the initial protocol-aware encoder are adjusted until a first training termination threshold is reached to obtain the protocol-aware encoder.

[0049] In an exemplary embodiment of the present invention, in a training scenario within a first known local area network (an office building exhibition hall), the initial protocol-aware encoder is a neural network model consisting of a coding layer network, a feedforward network, a feature mapping network, and a fully connected network. The server uses the first protocol behavior trajectory chain (the interaction trajectory of the main advertising screen "MAIN_AD_001," including protocol fingerprint identifiers F1 to F4) as training data. The server adjusts the weights of the feature mapping network, the feedforward network, and the fully connected network based on a first deviation value (the difference between the predicted confidence and the actual interaction coupling degree), ultimately yielding a trained protocol-aware encoder. The following details the training process for the first trajectory step "t2 (fingerprint identifier F3: Sony_4K_UDP_RCV_5000_AB)": The four network layers of the initial protocol-aware encoder have clear divisions of labor when processing the first protocol behavior trajectory chain: The coding layer network, serving as the model's input interface, is responsible for retrieving the initial device features corresponding to the protocol fingerprint identifiers from the initial device feature set. For example, for F1 (UDP broadcast behavior) in the trajectory chain, the encoding layer network retrieves the "UDP broadcast initial features" for the "Sony 4K advertising screen" from the initial device feature set by matching the fingerprint "Sony_4K_UDP_BC_5000_AB." This process does not involve weight adjustment and relies solely on pre-set feature retrieval rules. The feedforward network is responsible for protocol semantic enhancement, converting the initial device features into enhanced features with semantic labels using built-in semantic mapping rules. For example, the "active discovery" behavior in the "UDP broadcast initial features" is mapped to the semantic vector [1,0,0] (representing the "initiator" role) and fused into the initial feature vector, making the features more consistent with the logic of actual communication scenarios. The feedforward network comprises multiple fully connected layers, whose weights determine the strength of semantic label fusion (for example, the influence of the [1,0,0] vector on the overall feature). The feature mapping network is responsible for feature topology compression. Using an autoencoder structure, it reduces high-dimensional, reinforced features (e.g., 515-dimensional) into low-dimensional, dense vectors (256-dimensional), preserving core interaction features (e.g., protocol type, device role) while removing redundant information (e.g., non-critical data fields). Its weights (e.g., parameters of the fully connected layers of the encoder and decoder) directly impact compression accuracy; improper weighting can lead to loss of key features. The fully connected network, serving as the output layer, maps the compressed 256-dimensional feature vectors to first-association confidence scores (a value between 0 and 1), quantifying the degree of interaction coupling between the entity to be verified and the leading cluster. For example, the compressed features of "GUIDE_003" are mapped to a confidence score of 0.62. The weights (connection parameters of the output layer neurons) determine the accuracy of the mapping from feature vectors to confidence scores. The first deviation is the difference between the first-association confidence score (predicted value) and the actual interaction coupling score (true label).In the first known local area network, the actual interaction coupling between "MAIN_AD_001" and the guide screen "GUIDE_003" has been annotated using historical communication records (the true label is 0.95, due to the frequent synchronization of content and close interaction between the two in the exhibition hall). However, the initial encoder output prediction confidence is 0.62, indicating a significant deviation. The server adjusts the weights using the following steps: Taking the first trajectory step t2 as an example, the first deviation value is calculated using the mean squared error (MSE): Deviation value = (0.62 - 0.95). 2 = 0.1089. If the trajectory chain contains multiple steps (such as t1, t2, and t3), the average of all step deviations is taken as the overall first deviation value (for example, the initial average deviation value is 0.118). The weights of the feature mapping network (parameters of the fully connected layers of the encoder) directly affect the quality of the compressed features. During the initial compression process, due to improper weight setting, the "protocol matching" feature (a key factor affecting coupling) was weakened during dimensionality reduction, resulting in the compressed features not fully reflecting the protocol overlap between "GUIDE_003" and the leading cluster (UDP / TCP mixed protocol). The server uses the backpropagation algorithm to increase the weight of the neuron corresponding to "protocol matching" (for example, from 0.2 to 0.4), increasing the proportion of this dimension in the compressed features and strengthening the influence of protocol similarity on confidence. The weights of the feedforward network determine the strength of semantic label fusion. Initially, the "receiver" semantic label (vector [0,0,1]) corresponding to the "UDP response" behavior has a low weight (0.1), resulting in a weak contribution of this semantic to the feature. The server adjusts the weights of the fully connected layer of the feedforward network, increasing the weight of the "receiver" label to 0.3. This makes the "UDP response" behavior of "GUIDE_003" more prominent in the enhanced features, forming a semantic association with the "TCP response" behavior (F2) of the leading cluster, indirectly improving the accuracy of the coupling prediction. The weights of the output layer of the fully connected network determine the slope of the mapping from compressed features to confidence scores. The initial weights make the mapping from feature vectors to confidence scores conservative (for example, when the proportion of high-coupling features in a 256-dimensional feature set is 0.7, the confidence score is only 0.6). The server adjusts the weights of the output layer (for example, by adjusting the scaling factor of the weight matrix from 0.8 to 1.2) to increase the confidence score for the same high-coupling features. For example, a feature with a proportion of 0.7 is mapped to 0.85 instead of 0.6. The server repeats this adjustment process: after each round of adjustment, the first protocol behavior trajectory chain is re-input. The encoding layer network retrieves features, the feedforward network enhances semantics, the feature mapping network compresses the topology, and the fully connected network outputs a new first association confidence score. A new first deviation value is then calculated. For example, after the first round of adjustments, the confidence of "GUIDE_003" increased from 0.62 to 0.75, and the deviation value decreased to 0.04 (0.75-0.95). 2=0.04); After the fifth round of adjustments: the confidence level increased to 0.92, and the deviation value was 0.0009 ((0.92-0.95) 2 =0.0009), falling below the first training termination threshold (preset to 0.01). At this point, the server stops adjusting and solidifies the current feature mapping network, feedforward network, and fully connected network weight parameters, resulting in a trained protocol-aware encoder. This encoder accurately extracts target device features of network communication entities, meeting the requirements for subsequent identification of associated device profile information.

[0050] In the embodiments of the present invention, the following implementation modes are also provided.

[0051] Obtaining network communication entity metadata corresponding to each network communication entity to be verified in the set of network communication entities to be verified; Performing feature extraction on the network communication entity metadata using a text encoder to obtain initial device features corresponding to each of the network communication entities to be verified; The initial device feature set is obtained based on the initial device features corresponding to each of the network communication entities to be verified.

[0052] In an exemplary embodiment of the present invention, in a large commercial scenario (such as an office building exhibition hall local area network), the server needs to construct an initial device feature set as the basic data for the protocol-aware encoder. This process is achieved through three steps: obtaining metadata of the network communication entity to be verified, extracting features from the text encoder, and summarizing the feature set. Taking the set of network communication entities to be verified within the local area network (including the main advertising screen "MAIN_AD_001", the secondary advertising screen "SUB_AD_002", the guide screen "GUIDE_003", and the control server "CONTROL_SERVER") as an example, the specific process is as follows: the server collects the network communication entity metadata of the entity to be verified through two channels: first, the broadcast packets during the device initialization phase, and second, the configuration database of the local area network management system. The metadata is structured text information, including the core attributes of the device: Main advertising screen "MAIN_AD_001": The metadata comes from the UDP broadcast packet when it starts, including the device identifier "MAIN_AD_001", device type "4K advertising screen", manufacturer "Sony", supported protocol "UDP / TCP", UDP default port "5000", TCP server port "8080", MAC address "AB:CD:EF:12:34:56", and resolution "3840x2160"; Slave advertising screen "SUB_AD_002": The metadata comes from the configuration database, including the device identifier "SUB_AD_002", device type "slave advertising screen", manufacturer "LG", supported protocol "TCP", TCP client port "8080", and MAC address "BC:DE:FG: 23:45:67", resolution "1920x1080"; guide screen "GUIDE_003": metadata comes from the UDP response packet, including device ID "GUIDE_003", device type "Guide Screen", manufacturer "Samsung", supported protocols "UDP / TCP", UDP listening port "5000", TCP client port "8080", MAC address "CD:EF:GH:34:56:78", and interaction mode "passive response"; control server "CONTROL_SERVER": metadata comes from the management system configuration, including device ID "CONTROL_SERVER", device type "Control Server", manufacturer "Dell", supported protocols "TCP", server port "9090", and management IP address "10.0.0.1". The server calls a pre-trained text encoder (based on BERT model fine-tuning) to process the metadata and convert the text information into an initial device feature vector.The encoder performs word segmentation and vectorization on each metadata field: Category fields such as "Device Type" and "Manufacturer" are mapped into discrete vectors through word embedding (for example, "4K Advertising Screen" is mapped to [1, 0, 0], and "Slave Advertising Screen" is mapped to [0, 1, 0]); numerical fields such as "Port" and "Resolution" are converted into continuous values ​​through normalization (for example, TCP port 8080 is normalized to 0.808, and resolution 3840x2160 is mapped to [0.95, 0.98]); and behavioral fields such as "Protocol" and "Interaction Mode" are associated with vectors through semantic similarity calculation (for example, the "UDP / TCP" protocol combination is mapped to [0.8, 0.9], representing the strength of support for both protocols). For example, the metadata for "MAIN_AD_001" is encoded to generate a 512-dimensional initial device feature vector, containing core features such as type code, vendor weight, protocol support, and normalized port values. The vector for "GUIDE_003" emphasizes the "passive response" interaction mode (weight 0.75) and the UDP listening port (normalized value 0.5). The server aggregates the initial device feature vectors for all entities in the network communication entity set to be verified to form an initial device feature set. This set, indexed by the device ID, stores the 512-dimensional feature vectors for each entity. For example, the feature vector for "MAIN_AD_001" is: [Type code 1, Vendor weight 0.85, UDP support 0.9, TCP port 0.808, Resolution vector...,...]; the feature vector for "GUIDE_003" is: [Type code 3, Vendor weight 0.7, UDP support 0.95, TCP port 0.808, Interaction mode weight 0.75,...]. The initial device feature set is the built-in data of the protocol-aware encoder and is called for subsequent retrieval of the initial device features, providing a basis for extracting the target device features.

[0053] In an embodiment of the present invention, the method of determining the associated device profile information of the target device from the communication records of the local area network environment based on the similarity of the communication behaviors between the respective target device features of the target device and the communication peer device can be implemented through the following examples.

[0054] Based on the communication behavior similarity between the target device characteristics of the target device and the communication peer device, determining multiple associated network communication entities of the target device from the communication records of the local area network environment in descending order of the communication behavior similarity; Each associated network communication entity is arranged in time sequence according to the communication timestamp with the local area network environment to obtain the associated device file information of the target device.

[0055] In an embodiment of the present invention, for example, in a large commercial scenario (such as a shopping mall local area network), the target device is "AD_SCREEN_001" (4K advertising screen in the atrium on the first floor, manufacturer LG), and its target device feature is a 256-dimensional dense vector extracted by a protocol-aware encoder (including core features such as device type "4K advertising screen", protocol behavior "UDP broadcast + TCP response", and manufacturer attribute "LG"). The server needs to calculate the similarity of communication behavior based on the vector and the target device characteristics of the communication peer device in the local area network, filter the related entities and sort them by timestamp, and generate the related device profile information. The specific process is as follows: The server extracts the communication peer devices that interact with "AD_SCREEN_001" from the communication records of the local area network environment, including: the second-floor guide screen "GUIDE_SCREEN_002" (Samsung, type "Guide Screen"), the third-floor interactive screen "INTERACTIVE_SCREEN_003" (Huawei, type "Interactive Screen"), the control server "CONTROL_SERVER_004" (Dell, type "Control Server"), and the office printer "PRINTER_005" (HP, non-video device). The server uses the cosine similarity algorithm to calculate the similarity of the target device feature vectors between the target device and each communicating peer device (the vector dimension is 256, the value range is 0-1, the higher the value, the stronger the interactive coupling): Similarity with "CONTROL_SERVER_004": The control server needs to distribute advertising content to "AD_SCREEN_001", and the protocol behaviors of the two are highly matched (both support TCP long connections and control instructions interact frequently). The similarity calculation result is 0.91 (higher than the threshold of 0.7, strong correlation); Similarity with "GUIDE_SCREEN_002": The guide screen and the advertising screen need The interactive mode for synchronously playing shopping mall event information is similar (both include UDP discovery and TCP status reporting), with a similarity of 0.82 (strong association). Similarity with "INTERACTIVE_SCREEN_003": The interactive screen needs to receive content linkage commands from the advertising screen, with a moderate protocol match (slightly low UDP response frequency), and a similarity of 0.75 (strong association). Similarity with "PRINTER_005": The printer is an office device that only occasionally receives log print requests from the advertising screen, with significant protocol differences (supporting only short TCP connections), and a similarity of 0.32 (below the threshold, weak association, excluded). The server filters out strongly associated network communication entities in descending order of similarity: control server "CONTROL_SERVER_004" (0.91), second-floor guide screen "GUIDE_SCREEN_002" (0.82), and third-floor interactive screen "INTERACTIVE_SCREEN_003" (0.75).The server extracts the first communication timestamps (based on the time field of the TCP handshake packet or UDP response packet) of the above-mentioned associated entities and "AD_SCREEN_001" from the LAN communication records: Control server "CONTROL_SERVER_004": After "AD_SCREEN_001" completes initialization (09:00:00), it takes the lead in initiating a connection request through TCP port 9090, with the first communication timestamp of "09:00:03"; Second-floor guide screen "GUIDE_SCREEN_002": After monitoring the UDP broadcast of "AD_SCREEN_001" (09:00:00), it sends a response packet through TCP port 8080, with the first communication timestamp of "09:00:05"; Third-floor interactive screen "INTERACTIVE_SCREEN_003": Due to floor network delay, it monitors the broadcast later, and the UDP response packet arrives at "09:00:08", with the first communication timestamp of "09:00:08". The server sorts the associated entities in ascending order by the timestamp of the first communication and generates the associated device profile information of "AD_SCREEN_001", which includes the device identification, type, IP address, communication behavior similarity and the time of the first communication: First place: control server "CONTROL_SERVER_004" (Type: Control Server, IP: 10.0.0.1, Similarity: 0.91, First Communication Time: 09:00:03); Second place: Second floor guide screen "GUIDE_SCREEN_002" (Type: Guide Screen, IP: 10.0.1.15, Similarity: 0.82, First Communication Time: 09:00:05); Third place: Third floor interactive screen "INTERACTIVE_SCREEN_003" (Type: Interactive Screen, IP: 10.0.2.8, Similarity: 0.75, First Communication Time: 09:00:08). This archival information fully records the core collaborative devices of the target device in the local area network, providing a key basis for the subsequent construction of a comprehensive device feature map and optimization of network adaptation parameters.

[0056] In the embodiments of the present invention, the following implementation modes are also provided.

[0057] Obtaining a second protocol behavior trajectory chain, and loading the second protocol behavior trajectory chain into an initial device identification model; wherein the second protocol behavior trajectory chain is obtained based on communication records of a second known local area network, and the initial device identification model includes the preset device feature library; Using the initial device identification model, the preset device feature corresponding to each protocol fingerprint identifier preceding the second trajectory step in the second protocol behavior trajectory chain is retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain a predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, a second association confidence corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence is used to quantify the degree of interactive coupling between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step. Obtaining a second deviation value based on the second correlation confidence corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain; The network weight of the initial device identification model is adjusted based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model.

[0058] In an embodiment of the present invention, for example, in a large-scale commercial scenario, the target device identification model needs to be trained through the communication records of a second known local area network in order to have the ability to accurately identify the characteristics of local area network devices. The second known local area network is selected as the "local area network in the north district of a large shopping mall" (deployed with 30 video playback devices, including advertising screens, guide screens, interactive screens and control servers, and the communication records cover 6 months of device interaction logs). The server constructs a second protocol behavior trajectory chain based on the communication records of the local area network, trains the initial device identification model to obtain the target device identification model, and the specific process is as follows: the server selects the interaction data of the main advertising screen "AD_SCREEN_N01" (device identifier, LG4K advertising screen) in the north district from the communication records of the second known local area network to construct the second protocol behavior trajectory chain. The trace chain is composed of protocol fingerprint identifiers connected by timestamps. The protocol fingerprint identifier is generated based on the device type, protocol behavior, port and manufacturer information. For example: F1 (t0=09:00:00): UDP broadcast discovery packet (port 5000) after the device is started, fingerprint identifier "LG_4K_UDP_BC_5000_N01"; F2 (t1=09:00:03): Receive TCP connection request (port 8080) from the North District Guide Screen "GUIDE_N02" (Samsung, type "Guide Screen"), fingerprint identifier "LG_4K _TCP_RCV_8080_N01"; F3 (t2 = 09:00:06): Synchronizes content with the North Region control server "CONTROL_N03" (Dell) via TCP (port 9090), with the fingerprint identifier "LG_4K_TCP_SYNC_9090_N01"; F4 (t3 = 09:00:09): Receives UDP status reports from the South Region interactive screen "INTER_N04" (Huawei) (port 5000), with the fingerprint identifier "LG_4K_UDP_RPT_5000_N01". In timestamp order, the second protocol behavior trace chain is defined as: [F1 → F2 → F3 → F4]. The server loads this trace chain into the initial device identification model. The initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network, and has a built-in preset device feature library - storing standard feature templates for more than 100 types of video devices. For example, the "LG4K Advertising Screen" template contains the protocol fingerprint "LG_4K_UDP_BC_5000" and the feature vector [Device Type: 4K Advertising Screen, Protocol: UDP / TCP, Interaction Mode: Active Discovery + Passive Response]; the "Samsung Guide Screen" template contains the fingerprint "Samsung_Guide_TCP_CLI_8080" and the feature vector [Device Type: Guide Screen, Protocol: TCP, Interaction Mode: Passive Discovery + Active Request].The server determines the second trajectory step from the temporal sites of the second protocol behavior trajectory chain (selecting sites other than the first fingerprint, i.e., F2, F3, and F4 corresponding to t1, t2, and t3), and calculates the second association confidence (quantifying the degree of interaction coupling between the current step entity and the leading cluster) based on the leading network communication entity cluster of each step (the trajectory fragment before the step) through the model. Taking the second trajectory step "t2 (F3: LG_4K_TCP_SYNC_9090_N01)" as an example (corresponding to the content synchronization behavior between the main advertising screen and the control server): the encoding layer network of the initial device identification model is based on the trajectory segment [F1→F2] (pioneer cluster) before the second trajectory step t2, and retrieves the preset device features corresponding to each protocol fingerprint identifier in the preset device feature library: F1 (LG_4K_UDP_BC_5000_N01) matches the "UDP broadcast preset feature" of "LG4K advertising screen": {Behavior type: active discovery, protocol: UDP, port: 5000, feature vector V1}; F2 (LG_4K_TCP_RCV_8080_N01) matches the "TCP reception preset feature" of "LG4K advertising screen": {Behavior type: passive response, protocol: TCP, port: 8080, feature vector V2}. The fusion recognition network fuses and recognizes patterns in the retrieved preset device features (V1 and V2). Feature fusion uses an attention mechanism. Because F2 (TCP receive) shares the same protocol type as the current step size F3 (TCP synchronization), V2 is assigned a higher weight (0.6). V1 has a weight of 0.4. The weighted summation yields the fused feature vector Vfed = 0.4V1 + 0.6V2. Pattern recognition uses an LSTM network to learn the temporal dependencies of the fused features (the "broadcast → response" pattern of F1 → F2). The network then outputs the predicted device feature Vprediction (a 256-dimensional vector representing the comprehensive interaction features of the leading cluster) corresponding to the second trajectory step size t2. The fully connected network maps Vprediction to a second correlation confidence. In the preset device feature library, the standard interaction coupling label for the control server "CONTROL_N03" is 0.92 (due to the high coupling required for high-frequency content synchronization). The initial model outputs a prediction confidence of 0.65 (which deviates from the label). This value is the second correlation confidence for the second trajectory step size t2. Following this logic, the server calculates the second association confidence for all second trajectory steps: t1 (F2) corresponds to 0.58, t2 (F3) corresponds to 0.65, and t3 (F4) corresponds to 0.60. The server compares the second association confidence sequence ([0.58, 0.65, 0.60]) with the actual tag sequence ([0.90, 0.92, 0.88]) of the second known local area network and calculates the second deviation value as 0.076 using the mean square error.The server adjusts the network weights of the initial device identification model based on the second deviation value, focusing on optimizing the fusion identification network and the fully connected network. In the fusion identification network, due to the insufficient weight of F2 (TCP reception) over F3 (TCP synchronization) (initially 0.6), the fused features did not fully reflect the continuity of the TCP protocol. Therefore, the weight of V2 was increased to 0.8 to enhance the influence of TCP features. In the fully connected network, due to the low weights in the output layer, the prediction confidence was conservative. Therefore, the weight matrix scaling factor was adjusted from 0.7 to 1.1 to achieve higher confidence for the same fused features. After 200 rounds of iterative training, the second deviation value dropped to 0.009 (≤ the second training termination threshold of 0.01). At this point, the initial device identification model was optimized to the target device identification model. This model accurately identifies the interaction features of LAN devices. For example, for the F3 step size of "AD_SCREEN_N01," the second association confidence increased to 0.91 (close to the actual label of 0.92), meeting the device identification requirements. Through these steps, the server completes the training of the target device identification model, providing reliable model support for subsequent comprehensive device feature map recognition.

[0059] In an embodiment of the present invention, the initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. The coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence. The adjusting the network weight of the initial device identification model based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model can be implemented through the following example.

[0060] Based on the second deviation value, the network weights of the fusion recognition network and the fully connected network in the initial device recognition model are adjusted until a second training termination threshold is reached to obtain the target device recognition model.

[0061] In this embodiment of the present invention, for example, in a training scenario on a second known local area network (a shopping mall's south district LAN, deployed with 25 video devices), the initial device identification model consists of a coding layer network, a fusion identification network, and a fully connected network. The server uses the second protocol behavior trajectory chain (the interaction trajectory of the south district main advertising screen "AD_SCREEN_S01," including protocol fingerprint identifiers F1 to F4) as training data. The server adjusts the weights of the fusion identification network and the fully connected network using a second deviation value (the difference between the predicted second association confidence and the actual interaction coupling degree), ultimately generating the target device identification model. The following details the three layers of the initial device identification model, using the second trajectory step "t2 (fingerprint identifier F3: LG_4K_TCP_SYNC_9090_S01, corresponding to the content synchronization behavior between the main advertising screen and the south district control server "CONTROL_S03"): The coding layer network serves as the input interface, retrieving preset device features corresponding to the protocol fingerprint from a preset device feature library. The weights of this layer are fixed (based on feature retrieval rules) and are not adjusted. For example, for trajectory F1 (LG_4K_UDP_BC_5000_S01, UDP broadcast behavior), the encoding layer network retrieves the preset feature vector V1 for "LG4K advertising screen" (including protocol "UDP", behavior "active discovery", and port "5000"). For F2 (LG_4K_TCP_RCV_8080_S01, TCP receive behavior), the preset feature vector V2 (including protocol "TCP", behavior "passive response", and port "8080") is retrieved. The fusion recognition network is responsible for feature fusion and pattern recognition. It assigns weights (adjustable) to different preset features through an attention mechanism. After fusion into a comprehensive feature, the LSTM network learns the temporal pattern and outputs an intermediate feature vector. For example, for the leading cluster [F1→F2] of F3, the initial attention weights are V1 (0.5) and V2 (0.5). After fusion, the LSTM network generates the intermediate vector M. Fully connected network: The intermediate vector M is mapped to the second association confidence (0-1). The output layer weight (connection coefficient) determines the mapping accuracy. For example, the initial weight maps M to 0.63 (the prediction confidence of F3), while the actual interaction coupling label is 0.93 (the control server and the main advertising screen need to synchronize content frequently, resulting in a high degree of coupling). The server calculates the second deviation value: Taking the second trajectory step length t2 as an example, the second deviation value = (0.63-0.93) 2= 0.09; the trajectory chain consists of three steps, t1, t2, and t3, with an average second deviation of 0.08 (above the second training termination threshold of 0.01), requiring weight adjustment. The attention weights of the fusion recognition network determine the influence of the leading features on the current step. Initially, F1 (UDP broadcast) and F2 (TCP receive) have equal weights (0.5), but F3 (TCP synchronization) and F2 (TCP receive) share the same protocol type, requiring a stronger weight for F2. The server uses the backpropagation algorithm to increase the weight of V2 from 0.5 to 0.8 and reduce the weight of V1 to 0.2, allowing the fused features to better emphasize the continuity of TCP behavior. After this adjustment, the intermediate vector M contains stronger TCP protocol characteristics and better matches the interaction pattern with the control server. The output layer weights of the fully connected network (e.g., the connection coefficient matrix W) determine the slope of the mapping from the intermediate vector M to the second association confidence. The initial weight W maps M to 0.63 (relatively conservative). The server uses gradient descent to adjust the scaling factor of W from 0.7 to 1.2, strengthening the mapping strength between features and confidence. After this adjustment, the same intermediate vector M maps to 0.88 (closer to the actual label of 0.93). The server repeats the above process: after each round of adjustment, the second protocol behavior trajectory chain is re-input, features are retrieved through the encoding layer, the fusion recognition network fusion mode is calculated, and the fully connected network outputs the confidence, and a new second deviation value is calculated. For example, after the 10th round of training, the prediction confidence of F3 increases to 0.88, and the average second deviation value decreases to 0.025. After the 30th round of training, the prediction confidence of F3 reaches 0.92, and the average second deviation value is 0.009 (≤ the second training termination threshold of 0.01). At this point, the server stops adjustment and solidifies the attention weights of the fusion recognition network (V1: 0.2, V2: 0.8) and the output layer weights of the fully connected network (scaling factor 1.2), resulting in the target device recognition model. The model can accurately identify the interactive coupling degree of LAN devices. For example, for the F3 step length of "AD_SCREEN_S01", the second association confidence reaches 0.92 (close to the actual label 0.93), which meets the device identification requirements. In the embodiment of the present invention, the feature fusion and pattern recognition are performed on each retrieved preset device feature to output the device identification feature of the comprehensive device feature map, which can be implemented through the following examples.

[0062] Combining each retrieved preset device feature according to the network communication entity order of the comprehensive device feature map to obtain a preset device feature trajectory chain; Performing feature fusion and pattern recognition on the preset device feature trajectory chain to obtain a network communication entity fusion identification feature trajectory chain; the network communication entity fusion identification feature trajectory chain includes network communication entity fusion identification features that match the number of network communication entities in the comprehensive device feature map; From the network communication entity fusion identification feature trajectory chain, the network communication entity fusion identification feature at the network communication entity position of the target device is obtained as the device identification feature of the comprehensive device feature map.

[0063] In an embodiment of the present invention, for example, in a large commercial scenario (such as a local area network on the first floor of a shopping mall), the integrated device feature map uses the target device "AD_SCREEN_001" (a 4K advertising screen in the first-floor atrium, device identification) as the core node, with associated devices as secondary nodes. The nodes are arranged in the order of "target device → control server → guide screen → interactive screen" (based on descending correlation, the control server has the highest degree of coupling with the target device, followed by the guide screen and interactive screen). After the server retrieves the preset device features using the target device identification model, it extracts the device identification features through feature fusion and pattern recognition. The specific process is as follows: the server first determines the order of network communication entities from the integrated device feature map. The order of entities in this graph is: target device "AD_SCREEN_001" → control server "CONTROL_SERVER_004" → second-floor guide screen "GUIDE_SCREEN_002" → third-floor interactive screen "INTERACTIVE_SCREEN_003" (arranged in descending order by the similarity of communication behaviors in the associated device profiles: 0.91, 0.82, and 0.75, respectively). The server then retrieves the corresponding preset device features from the preset device feature library using the encoding layer network of the target device recognition model.The preset device feature library stores the standard feature vectors of known video device types, including core attributes such as device type, protocol behavior, interaction mode, etc.: The preset device features of the target device "AD_SCREEN_001": match the "LG4K advertising screen" standard template, and the feature vector is V_target = [device type: 4K advertising screen (confidence 0.98), protocol: UDP / TCP (UDP ratio 30%, TCP ratio 70%), interaction mode: active discovery + passive response, resolution: 3840x2160, manufacturer: LG]; The preset device features of the control server "CONTROL_SERVER_004": match the "Dell control server" standard template, and the feature vector is V_control = [device type: control server (confidence 0.99), protocol: TCP (long connection), interaction mode: active synchronization + content distribution, service port: 9090, manufacturer: Dell]; The preset device features of the second-floor guide screen "GUIDE_SCREEN_002": match the "Samsung guide screen" standard template, and the feature vector is V_guide = [device type: guide screen (confidence 0.97), protocol: UDP / TCP (UDP listening, TCP client), interaction mode: passive discovery + active request, resolution: 1920x1080, manufacturer: Samsung]; The preset device features of the third-floor interactive screen "INTERACTIVE_SCREEN_003": match the "Huawei interactive screen" standard template, and the feature vector is V_interactive = [device type: interactive screen (confidence 0.96), protocol: UDP (status reporting) / TCP (instruction receiving), interaction mode: passive response + event trigger, resolution: 2560x1440, manufacturer: Huawei]. The server combines the retrieved preset device feature vectors in sequence according to the entity order of the comprehensive device feature map (target device → control server → guide screen → interactive screen), and obtains the preset device feature trajectory chain: [V_target → V_control → V_guide → V_interactive] (the length of the trajectory chain is 4, which is the same as the number of network communication entities in the map). The server performs feature fusion and pattern recognition on the preset device feature trajectory chain through the fusion recognition network of the target device recognition model. The fusion recognition network includes an attention mechanism module and an LSTM time series pattern recognition module. The former is used to assign feature weights, and the latter is used to learn the interaction dependence relationship between entities. Feature fusion stage: The attention mechanism module assigns weights according to the interaction coupling degree between the entity and the target device. The control server and the target device need to synchronize the advertising content frequently (coupling degree 0.91), and the weight is set to 0.35; the guide screen needs to synchronize the activity information (coupling degree 0.82), and the weight is 0.3; the interactive screen only receives linkage instructions occasionally (coupling degree 0.75), and the weight is 0.2; the target device is the core node, and its own weight is 0.15.After weight allocation, each feature vector in the trajectory chain is weighted and summed: target device feature V: weight 0.15, retaining its core attributes (such as 4K resolution and active discovery behavior); control server feature V: weight 0.35, strengthening the "TCP long connection" and "content distribution" features, matching the content reception requirements of the target device; guide screen feature V: weight 0.3, strengthening the "TCP client" and "passive discovery" features, complementing the TCP server behavior of the target device; interactive screen feature V: weight 0.2, strengthening the "UDP status reporting" feature, reflecting the low-frequency interaction mode. In the pattern recognition stage, the LSTM module learns the temporal dependencies of fused features sequentially along the trajectory chain, identifying typical interaction patterns between entities: target device → control server: an "active request-content distribution" pattern (the target device requests content from the control server via TCP, and the server responds with distribution); control server → guide screen: a "synchronization command-status feedback" pattern (the control server forwards content synchronization commands to the guide screen, which returns a receipt status); and guide screen → interactive screen: a "linked trigger-event reporting" pattern (after the guide screen triggers an interaction event, the interactive screen reports the execution result via UDP). The LSTM module outputs a network communication entity fusion identification feature trajectory chain with the same length as the preset device feature trajectory chain. This chain contains four fusion identification feature vectors, corresponding to the four network communication entities in the graph: [Frongmu → Frongcontrol → Frongguidance → Fronginteraction]. Each fusion identification feature vector (256 dimensions) retains the core attributes of a single entity and also includes interaction pattern features with other entities (for example, Frongmu contains the composite features of "4K resolution + content reception + active discovery"). The fused identification features in the trajectory chain of network communication entity fusion identification features correspond one-to-one with the network communication entities in the integrated device feature map, in the exact same order (target device → control server → guide screen → interactive screen). The server locates the target device "AD_SCREEN_001" from the trajectory chain—the first position in the trajectory chain, which is the fused identification feature vector Frongmu. Frongmu, as a device identification feature in the integrated device feature map, contains key information such as the target device's type, performance, protocol preference, and networking requirements. Specifically, the following are: Device Type: 4K advertising screen (confidence level 0.98, verified through interactive feedback between the fusion control server and the guide screen); Protocol Preference: TCP First (weight 0.7, due to the highest proportion of TCP persistent connections with the control server); Bandwidth Requirement: 50 Mbps (calculated based on the resolution and frame rate of 4K content transmission, incorporating the content bitrate characteristics of the control server); Synchronization Accuracy: ±10 ms (requires content playback synchronization with the guide screen, incorporating the response latency characteristics of the guide screen); Interaction Mode: Active Discovery + Passive Response (integrating its own UDP broadcast behavior with the received TCP request behavior).This device identification feature is then used to determine the target device's networking adaptation parameters (such as bandwidth allocation and protocol priority configuration) within the LAN environment, ensuring stable collaboration within the device cluster. Through these steps, the server completes the conversion from pre-set device features to device identification features, enabling accurate profiling and identification of the target device.

[0064] In an embodiment of the present invention, the preset device features in the preset device feature library are target device features of the network communication entity, and the target device features of the network communication entity are obtained by performing feature space compression on the initial device features of the network communication entity.

[0065] In an embodiment of the present invention, for example, in a large commercial local area network (such as a shopping mall video equipment LAN), the preset device features stored in the preset device feature library are essentially target device features of network communication entities that have undergone feature space compression. Taking an "LG 4K advertising screen" (network communication entity) as an example, the server first extracts its initial device features: multi-dimensional information such as device type "4K advertising screen," manufacturer "LG," supported protocols "UDP / TCP," UDP port "5000," TCP port "8080," and resolution "3840x2160," forming a 512-dimensional high-dimensional feature vector. The server then spatially compresses this initial feature vector using a feature mapping network (autoencoder architecture), retaining core features such as device type, protocol behavior, and manufacturer attributes while removing redundant information such as the system version number. This 512-dimensional vector is reduced to a dense 256-dimensional vector, the target device feature. This target device feature serves as a standard template for the "LG 4K advertising screen" and is stored in the preset device feature library, becoming the preset device feature for subsequent searches.

[0066] In the embodiments of the present invention, the following implementation modes are also provided.

[0067] Acquiring device characteristics of the target device and local area network characteristics of the local area network environment; The device identification feature, the device feature of the target device, and the local area network feature of the local area network environment are loaded into a target networking adaptation model to obtain networking adaptation parameters between the target device and the local area network environment.

[0068] In an embodiment of the present invention, for example, in a large commercial scenario (such as a local area network on the first floor of a shopping mall), the target device "AD_SCREEN_001" (a 4K advertising screen in the atrium on the first floor) needs to achieve synchronous playback of advertising content, status monitoring and remote control through the local area network. After obtaining the device identification features through the target device identification model, the server must also combine the hardware properties of the target device itself (device features) and the network resource status of the LAN (LAN features) to generate targeted networking adaptation parameters through the target networking adaptation model to ensure efficient collaboration between the device and the LAN environment. The specific process is as follows: The server collects key features through two channels: The device characteristics of the target device come from the device factory configuration database and initialization self-test information, including hardware properties and basic functional parameters: Hardware specifications: resolution 3840x2160 (4K), maximum power consumption 150W, network interface type Gigabit Ethernet (RJ45), support for video encoding format H.265 / AVC; basic configuration: default gateway 10.0.1.1, subnet mask 255.255.255.0, DNS server 10.0.0.2, embedded system version V3.2.1; functional limitations: the maximum bandwidth requirement for a single video stream is 50Mbps (4K@60fps), and the synchronization signal reception delay must be ≤10ms (to avoid playback stuttering). The LAN characteristics of the LAN environment come from the network management module and traffic monitoring system of the core switch, reflecting the network resource and topology status: Resource configuration: total LAN bandwidth of 1 Gbps (symmetrical upstream and downstream), 20 currently online devices (including 15 video devices and 5 office devices), and the remaining bandwidth of the core switch port is 600 Mbps (total bandwidth 1 Gbps minus the existing load of 400 Mbps); Topology: star topology, the target device is connected to the access layer switch (port 10.0.1.10), and the control server is connected to the core layer (10.0.0.1), with forwarding via three-layer routing in the middle; Existing policy: default VLAN 1 (no dedicated video VLAN is allocated), NTP time synchronization frequency is 1 hour / time (synchronization accuracy ±50ms), and there is no differentiated bandwidth allocation (all devices share the bandwidth). The server loads three types of features into the pre-trained target networking adaptation model (a rule-based inference model trained based on commercial LAN device adaptation cases, including a feature fusion layer and a parameter mapping module): device identification features (from the output of the target device identification model): device type "4K advertising screen" (confidence 0.98), protocol preference "TCP first" (TCP accounts for 70%), bandwidth requirement 50Mbps, synchronization accuracy requirement ±10ms, and compatibility "supports Samsung / LG protocol interoperability"; device characteristics of the target device (hardware and basic configuration): resolution 3840x2160, interface Gigabit Ethernet, single-stream bandwidth 50Mbps; LAN characteristics of the LAN environment (resources and topology): remaining bandwidth 600Mbps, current synchronization accuracy ±50ms, and no dedicated VLAN.The model uses the feature fusion layer to quantize and weightedly fuse the three types of features (device identification feature weight 0.5, device feature weight 0.3, and LAN feature weight 0.2). It then uses the parameter mapping module to match the preset adaptation rule library (including "4K video device bandwidth guarantee rules" and "cross-vendor protocol conversion rules") and output networking adaptation parameters: VLAN division: A dedicated VLAN (VLAN ID 100) is allocated for the target device and associated video devices to isolate office equipment traffic and avoid bandwidth contention; bandwidth allocation: A bandwidth guarantee policy is configured for the target device within VLAN 100, reserving 50 Mbps of uplink bandwidth (to ensure 4K video streaming) and an upper limit of 80 Mbps for burst bandwidth (to cope with content update peaks); synchronization strategy: The NTP synchronization frequency is adjusted to 1 minute / time, and the PTP precise time protocol is enabled (instead of ordinary NTP), improving the synchronization accuracy to ±5 ms (meeting the ±10 ms requirement); protocol compatibility: The protocol conversion module is enabled in the core switch to convert the target device's LG proprietary control protocol to the MQTT protocol compatible with Samsung guide screens, ensuring cross-vendor device linkage control. The above parameters are distributed to the LAN core switch, access layer switch, and target device through the server to optimize the network configuration and ensure efficient collaboration between "AD_SCREEN_001" and the LAN environment.

[0069] The embodiment of the present invention provides a computer device 100, which includes a processor and a non-volatile memory storing computer instructions. When the computer instructions are executed by the processor, the computer device 100 executes the aforementioned LAN device identification method based on artificial intelligence driving. Figure 2 As shown, Figure 2 This is a structural block diagram of a computer device 100 provided in an embodiment of the present invention. The computer device 100 includes a memory 111 , a processor 112 , and a communication unit 113 .

[0070] To achieve data transmission or interaction, the memory 111, processor 112, and communication unit 113 are electrically connected to each other directly or indirectly. For example, these components can be electrically connected to each other via one or more communication buses or signal lines.

[0071] For illustrative purposes, the foregoing description has been made with reference to specific embodiments. However, the above illustrative discussion is not intended to be exhaustive or to limit the present disclosure to the precise forms disclosed. Numerous modifications and variations are possible in light of the above teachings. These embodiments have been selected and described in order to best illustrate the principles of the present disclosure and its practical application, thereby enabling those skilled in the art to best utilize the present disclosure and to utilize various embodiments with various modifications as appropriate for the specific application contemplated.

Claims

1. A local area network device identification method based on artificial intelligence driving, characterized in that: include: Obtain communication records between the target device and the LAN environment; Determining associated device profile information of the target device from the communication records of the local area network environment; Based on the associated device profile information and the target device, a comprehensive device feature map is obtained, and the comprehensive device feature map is loaded into a target device identification model; the target device identification model includes a preset device feature library, and the target device identification model is trained based on communication records of a known local area network; Through the target device identification model, the preset device features corresponding to each network communication entity in the comprehensive device feature map are retrieved in the preset device feature library, feature fusion and pattern recognition are performed on each retrieved preset device feature, and the device identification features of the comprehensive device feature map are output; the device identification features are used to determine the networking adaptation parameters between the target device and the local area network environment.

2. The method according to claim 1, characterized in that The determining of the associated device profile information of the target device from the communication records of the local area network environment includes: generating a current protocol behavior trace chain based on a protocol fingerprint identifier of a current network communication entity, and loading the current protocol behavior trace chain into a protocol-aware encoder; the current network communication entity is the target device or a communication peer device in the communication record of the local area network environment, and the protocol-aware encoder includes an initial device feature set; Retrieving, by the protocol-aware encoder, from the initial device feature set, the initial device feature corresponding to the protocol fingerprint identifier of the current network communication entity, performing protocol semantic enhancement and feature topology compression on the retrieved initial device feature, and outputting the target device feature of the current network communication entity; the target device feature is obtained by performing feature space compression on the initial device feature of the network communication entity; Based on the similarity of communication behaviors between the target device characteristics of the target device and the communication peer device, the associated device profile information of the target device is determined from the communication records of the local area network environment.

3. The method according to claim 2, characterized in that The method further comprises: Obtaining a first protocol behavior trajectory chain, and loading the first protocol behavior trajectory chain into an initial protocol-aware encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol-aware encoder includes the initial device feature set; By means of the initial protocol perception encoder, in the initial device feature set, the initial device feature corresponding to each protocol fingerprint identifier before the first trajectory step in the first protocol behavior trajectory chain is retrieved, protocol semantic enhancement and feature topology compression are performed on each retrieved initial device feature to obtain a predicted device feature corresponding to the first trajectory step, and protocol semantic mapping is performed on the predicted device feature corresponding to the first trajectory step to obtain an initial network communication entity communication behavior spectrum corresponding to the first trajectory step; the initial network communication entity communication behavior spectrum includes communication parameter values ​​corresponding to each network communication entity to be verified in the network communication entity set to be verified; performing communication parameter value dimensionality reduction on the initial network communication entity communication behavior spectrum to obtain a target device communication behavior spectrum corresponding to the first trajectory step; the target device communication behavior spectrum includes a first association confidence corresponding to each to-be-verified network communication entity in the to-be-verified network communication entity set, and the to-be-verified network communication entity set includes a network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain; Determining, from the target device communication behavior spectrum, a first association confidence corresponding to a protocol fingerprint identifier at a first trajectory step in the first protocol behavior trajectory chain; the first trajectory step is determined from a temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain; the first association confidence is used to quantify a degree of interaction coupling between a network communication entity corresponding to the first trajectory step and a leading network communication entity cluster corresponding to the first trajectory step; Obtaining a first deviation value based on first correlation confidences corresponding to the protocol fingerprint identifiers at each first trajectory step in the first protocol behavior trajectory chain; The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until a first training termination threshold is reached, thereby obtaining the protocol-aware encoder.

4. The method according to claim 3, characterized in that The initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network, wherein the coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantics enhancement, and the fully connected network is used to output a first association confidence; The step of adjusting the network weight of the initial protocol-aware encoder based on the first deviation value until a first training termination threshold is reached to obtain the protocol-aware encoder includes: Based on the first deviation value, the network weights of the feature mapping network, the feedforward network and the fully connected network in the initial protocol-aware encoder are adjusted until a first training termination threshold is reached to obtain the protocol-aware encoder.

5. The method according to claim 2, characterized in that The method further comprises: Obtaining network communication entity metadata corresponding to each network communication entity to be verified in the set of network communication entities to be verified; Performing feature extraction on the network communication entity metadata using a text encoder to obtain initial device features corresponding to each of the network communication entities to be verified; The initial device feature set is obtained based on the initial device features corresponding to each of the network communication entities to be verified.

6. The method according to claim 2, characterized in that The determining, based on the communication behavior similarity between the target device characteristics of the target device and the communication peer device, the associated device profile information of the target device from the communication records of the local area network environment includes: Based on the communication behavior similarity between the target device characteristics of the target device and the communication peer device, determining multiple associated network communication entities of the target device from the communication records of the local area network environment in descending order of the communication behavior similarity; Each associated network communication entity is arranged in time sequence according to the communication timestamp with the local area network environment to obtain the associated device file information of the target device.

7. The method according to claim 1, characterized in that The method further comprises: Obtaining a second protocol behavior trajectory chain, and loading the second protocol behavior trajectory chain into an initial device identification model; wherein the second protocol behavior trajectory chain is obtained based on communication records of a second known local area network, and the initial device identification model includes the preset device feature library; Using the initial device identification model, the preset device feature corresponding to each protocol fingerprint identifier preceding the second trajectory step in the second protocol behavior trajectory chain is retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain a predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, a second association confidence corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence is used to quantify the degree of interactive coupling between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step. Obtaining a second deviation value based on the second correlation confidence corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain; The network weight of the initial device identification model is adjusted based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model.

8. The method according to claim 7, characterized in that The initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network, wherein the coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence; The adjusting the network weight of the initial device identification model based on the second deviation value until a second training termination threshold is reached to obtain the target device identification model includes: Based on the second deviation value, the network weights of the fusion recognition network and the fully connected network in the initial device recognition model are adjusted until a second training termination threshold is reached to obtain the target device recognition model.

9. The method according to claim 1, characterized in that The step of performing feature fusion and pattern recognition on each retrieved preset device feature and outputting the device identification feature of the comprehensive device feature map includes: Combining each retrieved preset device feature according to the network communication entity order of the comprehensive device feature map to obtain a preset device feature trajectory chain; Performing feature fusion and pattern recognition on the preset device feature trajectory chain to obtain a network communication entity fusion identification feature trajectory chain; the network communication entity fusion identification feature trajectory chain includes network communication entity fusion identification features that match the number of network communication entities in the comprehensive device feature map; From the network communication entity fusion identification feature trajectory chain, the network communication entity fusion identification feature at the network communication entity position of the target device is obtained as the device identification feature of the comprehensive device feature map.

10. A server system, characterized in that: The method comprises a server configured to execute the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Intelligent Internet of Things public security management and control system and method based on multi-source data fusion

    CN120263824A

  • Network attack dynamic detection and security protection method and system based on artificial intelligence

    CN120342748A

  • Building electromechanical BIM model information rapid retrieval method and system

    CN120372035A

  • Conference record data searching method and system based on AI

    CN120448597A

  • Scene flow digital twin method and system based on dynamic trajectory flow

    WO2023207437A1

Cited By

  • Equipment type detection method

    CN121530884A