Artificial intelligence driven local area network device identification method and system
By constructing a comprehensive device feature map and utilizing an artificial intelligence recognition model, the problems of low efficiency and low accuracy in traditional LAN device identification methods have been solved. This has enabled accurate device identification and dynamic network optimization, thereby improving the collaborative work efficiency of device clusters.
Patent Information
- Application Number
- CN202511115662.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-08-11
Smart Images

Figure CN120602337B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of artificial intelligence, in particular to a local area network device identification method and system based on artificial intelligence driving. BACKGROUND
[0002] In large commercial scenarios such as shopping centers and office building exhibition halls, a local area network environment often contains a large number of heterogeneous devices such as advertising screens, guide screens and interactive screens. These devices need to realize content synchronization, state monitoring and collaborative control through a local area network. Traditional local area network device identification methods rely on manual configuration or simple network scanning, and have problems of low identification efficiency and insufficient precision. The device types are various, such as video playback devices of different manufacturers, which result in large differences in protocol behaviors, making it difficult to extract features through fixed rules; when devices dynamically join or exit the network, a static identification model cannot update the association relationship in real time, resulting in lag or unreasonable configuration of networking adaptation parameters, which affects the collaborative working efficiency of the device cluster. Therefore, there is an urgent need for an identification method based on artificial intelligence technology to learn the communication behavior characteristics of the devices, realize dynamic and accurate device identification and networking optimization. SUMMARY
[0003] The purpose of the present application is to provide a local area network device identification method and system based on artificial intelligence driving.
[0004] In a first aspect, an embodiment of the present application provides a local area network device identification method based on artificial intelligence driving, comprising:
[0005] Obtaining communication records of a target device and a local area network environment;
[0006] Determining association device profile information of the target device from the communication records of the local area network environment;
[0007] Based on the association device profile information and the target device, obtaining a comprehensive device feature map, and loading the comprehensive device feature map to a target device identification model; the target device identification model comprises a preset device feature library, and the target device identification model is obtained based on the communication records of a known local area network.
[0008] Through the target device identification model, in the preset device feature library, searching for a preset device feature corresponding to each network communication entity in the comprehensive device feature map, performing feature fusion and pattern recognition on each searched preset device feature, and outputting a device identification feature of the comprehensive device feature map; the device identification feature is used to determine a networking adaptation parameter between the target device and the local area network environment.
[0009] In a possible implementation, the determining of the association device profile information of the target device from the communication records of the local area network environment comprises:
[0010] A current protocol behavior trajectory chain is generated based on the protocol fingerprint identifier of the current network communication entity, and the current protocol behavior trajectory chain is loaded into the protocol awareness encoder; the current network communication entity is the target device or the communication peer device in the communication record of the local area network environment, and the protocol awareness encoder includes an initial device feature set;
[0011] The protocol-aware encoder retrieves the initial device feature corresponding to the protocol fingerprint identifier of the current network communication entity from the initial device feature set, performs protocol semantic enhancement and feature topology compression on the retrieved initial device feature, and outputs the target device feature of the current network communication entity; the target device feature is obtained by feature space compression of the initial device feature of the network communication entity.
[0012] Based on the similarity of communication behavior between the target device and the communication peer device, the associated device file information of the target device is determined from the communication records of the local area network environment.
[0013] In one possible implementation, the method further includes:
[0014] Obtain a first protocol behavior trajectory chain and load the first protocol behavior trajectory chain into an initial protocol awareness encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol awareness encoder includes the initial device feature set;
[0015] Using the initial protocol-aware encoder, the initial device features corresponding to each protocol fingerprint identifier preceding the first trajectory step are retrieved from the initial device feature set. Protocol semantic enhancement and feature topology compression are performed on each retrieved initial device feature to obtain the predicted device features corresponding to the first trajectory step. Protocol semantic mapping is then performed on the predicted device features corresponding to the first trajectory step to obtain the initial network communication entity communication behavior spectrum corresponding to the first trajectory step. The initial network communication entity communication behavior spectrum includes the communication parameter values corresponding to each network communication entity to be verified in the set of network communication entities to be verified.
[0016] The communication parameter values of the initial network communication entity communication behavior spectrum are reduced to obtain the target device communication behavior spectrum corresponding to the first trajectory step size; the target device communication behavior spectrum includes the first association confidence level corresponding to each network communication entity to be verified in the network communication entity set to be verified, and the network communication entity set to be verified includes the network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain.
[0017] From the target device communication behavior spectrum, determine the first association confidence level corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain; the first trajectory step is determined from the temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain, and the first association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the first trajectory step and the leading network communication entity cluster corresponding to the first trajectory step.
[0018] Based on the first association confidence level corresponding to the protocol fingerprint identifier at each first trajectory step in the first protocol behavior trajectory chain, the first deviation value is obtained;
[0019] The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until the first training termination threshold is reached, thus obtaining the protocol-aware encoder.
[0020] In one possible implementation, the initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network. The coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantic enhancement, and the fully connected network is used to output a first association confidence score.
[0021] The step of adjusting the network weights of the initial protocol-aware encoder based on the first deviation value until a first training termination threshold is reached to obtain the protocol-aware encoder includes:
[0022] Based on the first deviation value, adjust the network weights of the feature mapping network, feedforward network, and fully connected network in the initial protocol-aware encoder until the first training termination threshold is reached to obtain the protocol-aware encoder.
[0023] In one possible implementation, the method further includes:
[0024] Obtain the network communication entity metadata corresponding to each network communication entity in the set of network communication entities to be verified.
[0025] By using a text encoder, feature extraction is performed on the metadata of the network communication entities to obtain the initial device features corresponding to each network communication entity to be verified.
[0026] The initial device feature set is obtained based on the initial device features corresponding to each network communication entity to be verified.
[0027] In one possible implementation, determining the associated device profile information of the target device from the communication records of the local area network environment based on the similarity of communication behavior between the target device and the communication peer device, respectively, includes:
[0028] Based on the communication behavior similarity between the target device and the communication peer device, and in descending order of communication behavior similarity, multiple associated network communication entities of the target device are determined from the communication records of the local area network environment.
[0029] Each associated network communication entity is arranged chronologically according to its communication timestamp with the local area network environment to obtain the associated device file information of the target device.
[0030] In one possible implementation, the method further includes:
[0031] Obtain the second protocol behavior trajectory chain and load the second protocol behavior trajectory chain into the initial device identification model; the second protocol behavior trajectory chain is obtained based on the communication records of the second known local area network, and the initial device identification model includes the preset device feature library;
[0032] Using the initial device identification model, preset device features corresponding to each protocol fingerprint identifier preceding the second trajectory step are retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain the predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, the second association confidence level corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step.
[0033] Based on the second association confidence level corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain, the second deviation value is obtained.
[0034] The network weights of the initial device recognition model are adjusted based on the second deviation value until the second training termination threshold is reached, thereby obtaining the target device recognition model.
[0035] In one possible implementation, the initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. The coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence score.
[0036] The step of adjusting the network weights of the initial device recognition model based on the second deviation value until the second training termination threshold is reached to obtain the target device recognition model includes:
[0037] Based on the second deviation value, adjust the network weights of the fusion recognition network and the fully connected network in the initial device recognition model until the second training termination threshold is reached to obtain the target device recognition model.
[0038] In one possible implementation, the step of performing feature fusion and pattern recognition on each retrieved preset device feature to output the device identification features of the comprehensive device feature map includes:
[0039] According to the network communication entity order of the comprehensive device feature map, each preset device feature retrieved is combined to obtain a preset device feature trajectory chain;
[0040] The preset device feature trajectory chain is subjected to feature fusion and pattern recognition to obtain a network communication entity fusion recognition feature trajectory chain; the network communication entity fusion recognition feature trajectory chain includes network communication entity fusion recognition features that match the number of network communication entities in the integrated device feature map.
[0041] From the network communication entity fusion identification feature trajectory chain, obtain the network communication entity fusion identification features at the network communication entity location of the target device, and use them as the device identification features of the integrated device feature map.
[0042] In a second aspect, embodiments of the present invention provide a server system, including a server, the server being used to perform the method described in the first aspect.
[0043] Compared to existing technologies, the beneficial effects provided by this invention include: The method and system for identifying local area network (LAN) devices based on artificial intelligence (AI) disclosed in this invention, relating to the field of AI, include: firstly, acquiring communication records between the target device and the LAN environment; determining associated device profile information of the target device from the communication records; constructing a comprehensive device feature map based on the associated device profile information and the target device, loading it into a target device identification model, which includes a preset device feature library and is trained based on communication records of known LANs; retrieving preset device features corresponding to network communication entities in the map through the model, and outputting device identification features through feature fusion and pattern recognition to determine the networking adaptation parameters of the target device and the LAN environment. This invention learns the communication behavior patterns of devices through AI technology, achieving accurate identification and dynamic networking optimization of devices in complex LAN environments, and improving the collaborative working efficiency of device clusters. Attached Figure Description
[0044] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be considered as limiting the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 A flowchart illustrating the steps of an AI-driven local area network device identification method provided in an embodiment of the present invention;
[0046] Figure 2 A schematic block diagram of the structure of a computer device provided in an embodiment of the present invention. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0048] The specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0049] In order to solve the technical problems mentioned in the background art Figure 1 This is a flowchart illustrating the AI-driven local area network (LAN) device identification method provided in this embodiment. The AI-driven LAN device identification method will be described in detail below.
[0050] Step S201: Obtain the communication records between the target device and the local area network environment;
[0051] Step S202: Determine the associated device file information of the target device from the communication records of the local area network environment;
[0052] Step S203: Based on the associated device file information and the target device, a comprehensive device feature map is obtained, and the comprehensive device feature map is loaded into the target device identification model; the target device identification model includes a preset device feature library, and the target device identification model is trained based on the communication records of a known local area network;
[0053] Step S204: Using the target device identification model, retrieve the preset device features corresponding to each network communication entity in the integrated device feature map from the preset device feature library, perform feature fusion and pattern recognition on each retrieved preset device feature, and output the device identification features of the integrated device feature map; the device identification features are used to determine the networking adaptation parameters between the target device and the local area network environment.
[0054] In this embodiment of the invention, for example, in large commercial scenarios (such as shopping malls, office building showrooms, etc.), the local area network (LAN) environment typically contains a large number of video playback devices (such as advertising screens, information guidance screens, interactive display screens, etc.). These devices need to be synchronously controlled, content distributed, and their status monitored through the LAN. As the management core of the LAN, the server first needs to obtain the communication records between the target device and the LAN environment. Taking a "4K advertising screen in the atrium on the first floor of a shopping mall" (with the unique device identifier "AD_SCREEN_001" and IP address 10.0.1.10) as the target device, the server collects the communication data of this device and all video playback devices within the environment through a traffic mirroring module deployed on the LAN core switch.
[0055] Communication records during device initialization and discovery are a key data source: After each video playback device on the local area network (such as “AD_SCREEN_001”, “GUIDE_SCREEN_002”, “INTERACTIVE_SCREEN_003”, etc.) starts up, it automatically runs the initialization program, opening the UDP listening port (such as the default port 5000) and the TCP server process (such as listening on port 8080). Taking “AD_SCREEN_001” as an example, its initialization process is as follows: After the device is powered on, the embedded system loads the driver. After the network module is initialized, it broadcasts a device discovery data packet to the local area network via the UDP protocol (broadcast address 255.255.255.255:5000). The data packet contains the device identifier (such as “AD_SCREEN_001”), device type (“4K advertising screen”), manufacturer information (“LG”), MAC address (“AA:BB:CC:DD:EE:FF”), and the current system timestamp (such as “2024-06-01 09:00:00”). Other devices (such as "GUIDE_SCREEN_002") listen on UDP port 5000. After receiving the data packet, they record the sender information in the local device list (in the format of "device ID-IP-MAC-device type-discovery time") and send a response packet (containing their own device information) to port 8080 of "AD_SCREEN_001" via TCP protocol, thus completing bidirectional device discovery.
[0056] The server captures communication records of the above process through a traffic mirroring module, specifically including: UDP broadcast packets (source IP 10.0.1.10, destination IP 255.255.255.255, port 5000), TCP handshake packets (such as "GUIDE_SCREEN_002" IP 10.0.1.11 sending a SYN request to 10.0.1.10:8080), and application layer data of device information exchange (such as device type, status code, etc. in JSON format). The server stores these records in a distributed database (such as MongoDB), storing them in a structured manner according to the fields "device identifier-timestamp-communication type-data packet content", for example, "AD_SCREEN_001|2024-06-0109:00:00|UDP_BROADCAST|device_id:"AD_SCREEN_001",type:"4K advertising screen",mac:"AA:BB:CC:DD:EE:FF").
[0057] The server needs to extract information about associated devices that have interacted with the target device "AD_SCREEN_001" from the global communication logs to form an associated device profile. This process relies on communication behavior characteristics and protocol fingerprint analysis during the device discovery phase.
[0058] First, the server generates a protocol behavior trace chain based on the protocol fingerprint identifiers of the target device and the communication peer device. The protocol fingerprint identifier is a unique identifier for the device's communication behavior, generated by combining the device type, protocol type, port number, and key fields. For example, the UDP broadcast behavior of "AD_SCREEN_001" corresponds to the fingerprint identifier "LG_4K_UDP_5000_MAC_AA", and the TCP response behavior of "GUIDE_SCREEN_002" corresponds to "Samsung_Guide_TCP_8080_MAC_BB". The server concatenates the interaction fingerprint identifiers of the target device with other devices in timestamp order to form the current protocol behavior trajectory chain. For example, the trajectory chain segment is: [LG_4K_UDP_5000_MAC_AA (t0) → Samsung_Guide_TCP_8080_MAC_BB (t1) → HUAWEI_Interactive_UDP_5000_MAC_CC (t2) → ...]. Where t0 is the time when "AD_SCREEN_001" sends a UDP broadcast, t1 is the time when "GUIDE_SCREEN_002" returns a TCP response, and t2 is the time when the third-floor interactive screen "INTERACTIVE_SCREEN_003" sends a UDP response.
[0059] Subsequently, the server loads the trajectory chain into a pre-trained protocol-aware encoder. This encoder contains an initial device feature set (storing basic features of known device types, such as the feature vector for "4K advertising screen" being [resolution: 3840x2160, protocol: UDP / TCP, power consumption: 150W, manufacturer: LG]). It retrieves the initial device features corresponding to each fingerprint identifier in the trajectory chain through the coding layer network, and performs protocol semantic enhancement through a feedforward network (such as mapping "UDP broadcast" behavior to the semantic label "active discovery"). Then, it compresses the feature topology through a feature mapping network (reducing the high-dimensional feature vector to a 256-dimensional dense vector), and finally outputs the target device features of the target device and the communication peer device (such as the target feature vector of "AD_SCREEN_001" being V1, and "GUIDE_SCREEN_002" being V2).
[0060] The server calculates the communication behavior similarity between target feature vectors (using a cosine similarity algorithm). For example, if the similarity between V1 and V2 is 0.85 (above the threshold of 0.7), they are determined to be strongly associated devices; if the similarity between V1 and the feature vector of a printer is 0.3, they are determined to be weakly associated. The server filters out the top N strongly associated devices in descending order of similarity (e.g., “GUIDE_SCREEN_002”, “INTERACTIVE_SCREEN_003”, “CONTROL_SERVER_001”), and arranges them according to the communication timestamp, forming associated device profile information. For example: Associated Device Profile:
[0061] Device 1: GUIDE_SCREEN_002 (Type: Guide Screen, IP: 10.0.1.11, First Communication Time: t1, Similarity: 0.85)
[0062] Device 2: INTERACTIVE_SCREEN_003 (Type: Interactive screen, IP: 10.0.2.05, First communication time: t2, Similarity: 0.82)
[0063] Device 3: CONTROL_SERVER_001 (Type: Control Server, IP: 10.0.0.01, First Communication Time: t3, Similarity: 0.90)
[0064] The server constructs a comprehensive device feature map based on the associated device profile information and the target device's own characteristics. This map uses the target device "AD_SCREEN_001" as the core node, with associated devices as secondary nodes. Directed edges are established between nodes based on communication parameters (such as interaction frequency, data volume, and protocol type). For example:
[0065] Core node: AD_SCREEN_001 (Features: 4K resolution, LG manufacturer, UDP broadcast frequency 5 times / minute)
[0066] Secondary node 1: GUIDE_SCREEN_002 (Edge attributes: TCP connection frequency 1 time / second, average data volume 1024B / packet)
[0067] Secondary node 2: CONTROL_SERVER_001 (Edge attributes: TCP long connection, control command transmission, data volume 512B / command)
[0068] The structure of the comprehensive device feature map is transformed into a tensor form (dimension N×256, where N is the number of nodes) and loaded into the target device recognition model. This model is trained based on communication records of a known commercial LAN (such as an office building with 500 video devices deployed), and has a built-in preset device feature library (storing standard features of 100+ types of video devices, such as the protocol fingerprint of "Sony 2K advertising screen" and the interaction mode of "Sharp touch screen").
[0069] The target device identification model first traverses a pre-defined device feature library through a coding layer network, retrieving the pre-defined device features corresponding to each network communication entity (target device and associated devices) in the comprehensive device feature map. For example, the model retrieves the pre-defined features of "AD_SCREEN_001" as "LG4K advertising screen standard feature vector" and "GUIDE_SCREEN_002" as "Samsung guide screen standard feature vector".
[0070] Subsequently, the model combines the retrieved preset device features into a preset device feature trajectory chain according to the node order of the integrated device feature map (core node → secondary node 1 → secondary node 2): [LG_4K_Standard → Samsung_Guide_Standard → Control_Server_Standard]. The fusion recognition network performs feature fusion (using an attention mechanism to assign higher weights to the control server node) and pattern recognition (learning temporal dependencies through an LSTM network) on this trajectory chain to obtain a fusion recognition feature trajectory chain for network communication entities (each node corresponds to a fusion recognition feature vector).
[0071] The server extracts the fusion identification feature vector of the core node (target device) from the fusion identification feature trajectory chain as the device identification feature. This feature vector contains key information such as the type, performance, and networking requirements of the target device. For example: Device identification features: [Device type: 4K advertising screen (confidence 0.98), communication protocol: UDP / TCP (priority TCP), bandwidth requirement: 50Mbps, synchronization accuracy: ±10ms, compatibility: supports Samsung / LG protocol interoperability].
[0072] The server maps device identification features to specific network adaptation parameters to optimize the collaborative operation between the target device and the local area network environment. For example:
[0073] Bandwidth allocation: Based on the "bandwidth requirement of 50Mbps", the server allocates a dedicated VLAN (VLANID:100) to "AD_SCREEN_001" through the SDN controller to ensure uplink bandwidth ≥50Mbps and avoid competing for resources with other low-priority devices (such as office computers);
[0074] Synchronization strategy: Based on "synchronization accuracy ±10ms", adjust the NTP server time synchronization frequency (from the default 1 hour / time to 1 minute / time) to ensure that the time difference with the playback of the advertisement content of "GUIDE_SCREEN_002" is ≤10ms;
[0075] Protocol compatibility: Based on the "Support Samsung / LG protocol interoperability", the protocol conversion module is enabled on the core switch to convert the LG proprietary control protocol into the MQTT protocol compatible with the Samsung guide screen, so as to realize cross-vendor device linkage control.
[0076] Through the above process, the server achieves accurate identification and dynamic network optimization of video playback devices in large-scale commercial scenarios, ensuring the stable and efficient operation of the device cluster.
[0077] In this embodiment of the invention, the server system includes one main server (configured with an Intel Xeon Gold 6348 CPU, 256GB of memory, and a 10TB SSD) and three edge computing nodes (deployed in the low-voltage electrical rooms on each floor). The main server is connected to the core switch via a 10Gbps fiber optic cable and is responsible for communication record storage, model training, and inference. The edge nodes collect local device communication data via gigabit Ethernet, preprocess it, and then upload it to the main server. The server runs a Linux operating system, deploys the target device recognition model using the PyTorch deep learning framework, uses a Kafka message queue to receive communication records in real time, and deploys the protocol-aware encoder and model inference service via Docker containerization, achieving 24 / 7 uninterrupted device recognition and network adaptation.
[0078] In this embodiment of the invention, the step of determining the associated device file information of the target device from the communication records of the local area network environment can be implemented through the following example.
[0079] For the target device and the peer device in the communication records of the local area network environment, the target device features of the network communication entity are extracted; the target device features are obtained by feature space compression of the initial device features of the network communication entity.
[0080] Based on the similarity of communication behavior between the target device and the communication peer device, the associated device file information of the target device is determined from the communication records of the local area network environment.
[0081] In this embodiment of the invention, for example, the server uses the target device "AD_SCREEN_001" (the 4K advertising screen in the atrium on the first floor) and the communication peer devices in the local area network communication records (such as video playback devices like "GUIDE_SCREEN_002" and "INTERACTIVE_SCREEN_003") as network communication entities, and extracts the target device features of each entity. The target device features are low-dimensional dense vectors obtained by compressing the feature space of the initial device features of the network communication entities, and need to be generated by combining the communication behavior data and basic attributes of the device initialization and discovery phases. First, the server parses the initial device features of the network communication entities from the communication records. The initial device characteristics include basic device attributes and communication behavior characteristics, specifically sourced from: Basic attributes: extracted from device initialization broadcast packets, such as the UDP broadcast packet of “AD_SCREEN_001” carrying fields such as: device identifier “AD_SCREEN_001”, device type “4K advertising screen”, manufacturer “LG”, resolution “3840x2160”, MAC address “AA:BB:CC:DD:EE:FF”, and system version “V2.3.1”; Communication behavior characteristics: extracted from traffic mirroring data, such as the communication behavior characteristics of “AD_SCREEN_001” including: UDP broadcast frequency (5 times / minute), TCP server port (8080), average packet size (1200 bytes), number of communication peers (12 devices), and protocol type ratio (UDP: 30%, TCP: 70%). The server converts the above initial device characteristics into structured data (e.g., key-value pairs) and maps them to a high-dimensional feature vector (dimension 512). Taking "AD_SCREEN_001" as an example, its initial device feature vector is: [V_initial=[Device type code:001, Manufacturer code:005, Resolution:3840x2160, UDP frequency:5, TCP port:8080, MAC hash:0xABCD...,...]]; Subsequently, the server performs spatial compression on the initial device feature vector through a pre-trained feature mapping network. This network adopts an autoencoder structure, taking a 512-dimensional initial vector as input, reducing it to 256 dimensions through an encoder (containing 3 fully connected layers with ReLU activation function), and then reconstructing the features through a decoder, optimizing the network parameters with the goal of minimizing the reconstruction error. During the compression process, the network retains key features (such as device type, protocol behavior, and manufacturer attributes) and removes redundant information (such as the system version minor revision number).The final output target device feature vector is a low-dimensional dense vector. For example, the target device feature vector of "AD_SCREEN_001" is: [V_target1=[0.23,0.56,0.11,...,0.89](dimensional 256)]. For the communication peer device (such as "GUIDE_SCREEN_002", the second-floor guide screen), the server performs the same process: from its UDP response packet (device identifier "GUIDE_SCREEN_002", type "guide screen", manufacturer "Samsung"), the server executes the same process. The initial device features are extracted from the target device's resolution (1920x1080) and TCP interaction records (response port 8080, average packet size 800 bytes, number of communication peers 8). After feature mapping network compression, the target device feature vector is obtained: [V_target2=[0.19,0.62,0.08,...,0.75](dimensional 256)]. The server calculates the communication behavior similarity between the target device and the communication peer device's target device feature vectors, filters strongly associated devices, and generates associated device profile information. The communication behavior similarity is used to quantify the matching degree between the two devices in protocol interaction mode and functional positioning. The cosine similarity algorithm is used for calculation, and the threshold is set to 0.7 (based on the video device collaboration requirements of commercial scenarios). First, the server uses the target device feature vector (V_target1) of the target device "AD_SCREEN_001" as a benchmark, traverses all communication peer devices in the communication records, and calculates the cosine similarity between the target device feature vector of each device and (V_target1). Taking "GUIDE_SCREEN_002" as an example, the cosine similarity between its vector (V_target2) and (V_target1) is 0.82. This result (0.82) is higher than the threshold of 0.7, so "GUIDE_SCREEN_002" is determined to be an associated device of the target device. Following this logic, the server completes the similarity calculation for all communication peer devices, filtering out devices with a similarity ≥ 0.7, including: "GUIDE_SCREEN_002" (second-floor guide screen, similarity 0.82); "INTERACTIVE_SCREEN_003" (third-floor interactive screen, similarity 0.78); and "CONTROL_SERVER_001" (LAN control server, similarity 0.91, responsible for content distribution). Subsequently, the server extracts the first communication timestamp between the above-mentioned associated devices and the target device from the communication records (based on the timestamp field of the TCP handshake packet), and sorts them in ascending order of timestamp to form the associated device profile information of the target device. The final profile information format is as follows; please refer to Table 1.
[0082] Table 1
[0083] Device identification Device type IP address First communication time Communication behavior similarity CONTROL_SERVER_001 Control server 10.0.0.1 2024-06-0109:00:12 0.91 GUIDE_SCREEN_002 Guide screen 10.0.1.15 2024-06-0109:00:25 0.82 INTERACTIVE_SCREEN_003 Interactive screen 10.0.2.8 2024-06-0109:00:40 0.78
[0084] This file contains a complete record of the target device's core associated devices within the local area network, providing crucial data support for the subsequent construction of a comprehensive device feature map.
[0085] In this embodiment of the invention, the extraction of target device features from the communication peer device in the communication records of the target device and the local area network environment can be performed through the following example.
[0086] A current protocol behavior trajectory chain is generated based on the protocol fingerprint identifier of the current network communication entity, and the current protocol behavior trajectory chain is loaded into the protocol awareness encoder; the current network communication entity is the target device or the communication peer device in the communication record of the local area network environment, and the protocol awareness encoder includes an initial device feature set;
[0087] The protocol-aware encoder retrieves the initial device features corresponding to the protocol fingerprint identifier of the current network communication entity from the initial device feature set, performs protocol semantic enhancement and feature topology compression on the retrieved initial device features, and outputs the target device features of the current network communication entity.
[0088] In an embodiment of the invention, for example, in a large commercial scenario (such as a shopping mall LAN), the server needs to extract target device features from the target device "AD_SCREEN_001" (a 4K advertising screen in the atrium on the first floor) and the communication peer device (such as the second-floor guidance screen "GUIDE_SCREEN_002" and the third-floor interactive screen "INTERACTIVE_SCREEN_003"). This process relies on the feature processing capabilities of protocol fingerprint analysis of device communication behavior and protocol-aware encoder. The specific steps are as follows: The server first generates a current protocol behavior trajectory chain based on the protocol fingerprint identifier of the current network communication entity. The current network communication entity includes the target device "AD_SCREEN_001" and the communication peer device (such as "GUIDE_SCREEN_002"). The protocol fingerprint identifier is a unique identifier of device communication behavior, generated by combining device type, protocol type, port number, key behavioral features, and vendor information, and must reflect the core interactive behaviors during the device initialization and discovery phases. Taking the target device "AD_SCREEN_001" as an example, its communication behavior during initialization includes: Behavior 1 (t0=09:00:00): After startup, it broadcasts a device discovery data packet to the local area network via UDP protocol (target port 5000). The broadcast packet contains the device identifier, MAC address (AA:BB:CC:DD:EE:FF), device type "4K advertising screen", and manufacturer "LG". The protocol fingerprint identifier for this behavior is defined as "LG_4K_AD_UDP_BC_5000_AA" (manufacturer_device type_protocol_behavior_port_MAC prefix); Behavior 2 (t1=09:00:02): Receiving After receiving the TCP connection request "GUIDE_SCREEN_002", the connection is responded to via the TCP server (port 8080), returning device status information (online, resolution 3840x2160). The protocol fingerprint identifier for this action is "LG_4K_AD_TCP_SRV_8080_AA". Action 3 (t2=09:00:05): Receives a UDP response packet "INTERACTIVE_SCREEN_003" (source port 5000), which contains interactive screen device information. The protocol fingerprint identifier for this action is "LG_4K_AD_UDP_RCV_5000_AA".The server concatenates the above protocol fingerprint identifiers in timestamp order (t0→t1→t2) to generate the current protocol behavior trajectory chain of "AD_SCREEN_001": Trajectory chain: [LG_4K_AD_UDP_BC_5000_AA (t0) → LG_4K_AD_TCP_SRV_8080_AA (t1) → LG_4K_AD_UDP_RCV_5000_AA (t2)]; For the communication peer device "GUIDE_SCREEN_002" (Samsung guide screen, MAC address BB:CC:DD:EE:FF:AA), its initialization and interaction behavior with the target device include: Behavior 1 ( t0+1s=09:00:01): Listen for the broadcast packet of "AD_SCREEN_001" on UDP port 5000 and record the sender information to the local device list. The protocol fingerprint identifier of this action is "Samsung_Guide_UDP_MON_5000_BB"; Action 2 (t1-1s=09:00:01): Initiate a connection request to "AD_SCREEN_001" on TCP port 8080, and send the device type "Guide Screen" and resolution 1920x1080. The protocol fingerprint identifier of this action is "Samsung_Guide_TCP_CLI_8080_BB". The server concatenates its fingerprint identifiers in timestamp order to generate the current protocol behavior trajectory chain of "GUIDE_SCREEN_002": Trajectory chain: [Samsung_Guide_UDP_MON_5000_BB (t0+1s) → Samsung_Guide_TCP_CLI_8080_BB (t1-1s)]; Subsequently, the server loads the above two trajectory chains (target device and communication peer device) into the pre-deployed protocol-aware encoder respectively. This encoder is a neural network model containing an initial device feature set. It stores basic feature templates for known video playback device types. For example, the initial feature template for "LG 4K advertising screen" is: Device type: 4K advertising screen, Manufacturer: LG, Supported protocols: UDP / TCP, UDP default port: 5000, TCP server port: 8080, Resolution: 3840x2160, Typical behavior: UDP broadcast + TCP response. The initial feature template for "Samsung guide screen" is: Device type: guide screen, Manufacturer: Samsung, Supported protocols: UDP / TCP, UDP listening port: 5000, TCP client port: 8080, Resolution: 1920x1080, Typical behavior: UDP listening + TCP request. The protocol-aware encoder transforms the trajectory chain into target device features through three levels of processing: a coding layer network, a feedforward network (protocol semantic enhancement), and a feature mapping network (feature topology compression).Step 1: Retrieve Initial Device Features. The encoder layer network performs a precise matching retrieval in the initial device feature set based on the protocol fingerprint identifier in the trajectory chain. Taking the trajectory chain "AD_SCREEN_001" as an example: In the first fingerprint of the trajectory chain "LG_4K_AD_UDP_BC_5000_AA", "LG_4K_AD" matches the template identifier "LG4K advertising screen" in the initial feature set, and "UDP_BC_5000" matches the initial device feature "UDP broadcast behavior (port 5000)" in this template, i.e., behavior type: active discovery, protocol: UDP, port: 5000, data field: device identifier + MAC + type; the second fingerprint "LG_4K_ The initial device feature of the "TCP server response behavior (port 8080)" in the matching template "AD_TCP_SRV_8080_AA" is: behavior type: passive response, protocol: TCP, port: 8080, data field: status + resolution. The initial device feature of the "UDP reception behavior (port 5000)" in the matching template "LG_4K_AD_UDP_RCV_5000_AA" is: behavior type: passive reception, protocol: UDP, port: 5000, data field: peer device information. The coding layer network combines the above three initial device features in the order of the trajectory chain to form an initial feature sequence (3×512 dimension, each feature is a 512-dimensional vector). The encoder's feedforward network performs protocol semantic enhancement on the initial feature sequence, transforming low-level protocol behaviors into high-level semantic labels and fusing them into the feature vector. The specific process is as follows: For the "UDP broadcast behavior" feature, the network maps the "active discovery" behavior to a semantic vector [1,0,0] (representing the "initiator" role) using a pre-defined semantic mapping table, and adds it to the end of the original feature vector; for the "TCP server response behavior," the "passive response" is mapped to a semantic vector [0,1,0] (representing the "responder" role), and fused into the feature vector; for the "UDP receiving behavior," the "passive receiving" is mapped to a semantic vector [0,0,1] (representing the "receiver" role), and fused into the feature vector. After enhancement, each initial feature vector is expanded from 512 dimensions to 515 dimensions (with the addition of 3-dimensional semantic labels), and the feature sequence is upgraded to 3×515 dimensions. The encoder's feature mapping network (using a 2-layer fully connected autoencoder structure) performs topological compression on the enhanced feature sequence, removing redundant dimensions and retaining core behavioral features and semantic associations. The network input is a 3×515 dimensional sequence, which is reduced to 3×256 dimensionality through the first fully connected layer (256 neurons, ReLU activation function), and the second fully connected layer (256 neurons) compresses the sequence into a single 256 dimensional dense vector (representing the overall behavioral features of the trajectory chain).During compression, the network ensures that key information (such as device type, protocol role, and vendor attributes) is not lost by minimizing reconstruction error (comparing feature similarity before and after compression). Finally, the protocol-aware encoder outputs the target device feature vector for “AD_SCREEN_001”: [V_target_AD001=[0.28,0.61,0.15,...,0.92] (dimension 256, containing compressed representations of device type, protocol role, and vendor features)]. For the communication peer device “GUIDE_SCREEN_002”, the server executes the same process: its trajectory chain [Samsung_Guide_UDP_MON_5000_BB→Samsung_Guide_TCP_CLI_ [8080_BB] retrieves the initial features (UDP listening + TCP request) of "Samsung Guide Screen" through the encoder. After semantic enhancement ("UDP listening" is mapped to [0,0,1] receiver, and "TCP request" is mapped to [1,0,0] initiator) and topology compression, the target device feature vector is output: [V_target_GUIDE002=[0.21,0.58,0.19,...,0.85](dimensional 256)]. The above target device feature vector will be used for subsequent communication behavior similarity calculation to provide a quantitative basis for determining the associated device file information.
[0089] In this embodiment of the invention, the following implementation methods are also provided.
[0090] Obtain a first protocol behavior trajectory chain and load the first protocol behavior trajectory chain into an initial protocol awareness encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol awareness encoder includes the initial device feature set;
[0091] Using the initial protocol-aware encoder, the initial device features corresponding to each protocol fingerprint identifier preceding the first trajectory step are retrieved from the initial device feature set. Protocol semantic enhancement and feature topology compression are performed on each retrieved initial device feature to obtain the predicted device features corresponding to the first trajectory step. Based on the predicted device features corresponding to the first trajectory step, the first association confidence level corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain is obtained. The first trajectory step is determined from the temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain. The first association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the first trajectory step and the leading network communication entity cluster corresponding to the first trajectory step.
[0092] Based on the first association confidence level corresponding to the protocol fingerprint identifier at each first trajectory step in the first protocol behavior trajectory chain, the first deviation value is obtained;
[0093] The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until the first training termination threshold is reached, thus obtaining the protocol-aware encoder.
[0094] In this embodiment of the invention, for example, in a large-scale commercial scenario, the protocol-aware encoder needs to be trained using communication records of a known local area network (LAN) before it can be used to extract target device features. Using a "LAN in an office building exhibition hall" (the first known LAN, deploying 50 video playback devices, including advertising screens and guide screens) as the training environment, the server trains the initial protocol-aware encoder using the historical communication records of this environment. The specific steps are as follows: The server extracts core interaction data from the communication records of the first known LAN during the device initialization and discovery phases, generating a first protocol behavior trajectory chain. This trajectory chain is constructed based on the communication behavior of the "main advertising screen in the exhibition hall" (device identifier "MAIN_AD_001", manufacturer Sony, type 4K advertising screen) within the LAN. Its communication records include device interaction logs from the past three months, covering the initialization and discovery process with 20 slave devices (such as "SUB_AD_002", "GUIDE_003", etc.). The first protocol behavior trajectory chain of "MAIN_AD_001" is arranged in chronological order by timestamps and is formed by concatenating protocol fingerprint identifiers. The protocol fingerprint identifier is generated based on device type, protocol behavior, port, and MAC prefix. For example: Fingerprint 1 (t0=08:00:00): UDP broadcast discovery packet after device startup (port 5000), fingerprint identifier "Sony_4K_UDP_BC_5000_AB" (manufacturer_type_protocol_behavior_port_MAC prefix); Fingerprint 2 (t1=08:00:02): Receives TCP connection request from advertising screen "SUB_AD_002" (port 8080), fingerprint identifier... The fingerprint identifier is “Sony_4K_TCP_RCV_8080_AB”; fingerprint 3 (t2=08:00:05): receives the UDP response packet of the guide screen “GUIDE_003” (port 5000), fingerprint identifier “Sony_4K_UDP_RCV_5000_AB”; fingerprint 4 (t3=08:00:08): sends a TCP status report to the control server (port 9090), fingerprint identifier “Sony_4K_TCP_SND_9090_AB”. According to the timestamp order, the first protocol behavior trajectory chain is defined as: trajectory chain: [F1(t0)→F2(t1)→F3(t2)→F4(t3)] (F1-F4 are the above fingerprint identifiers); the server loads this trajectory chain into the initial protocol awareness encoder.The encoder is an untrained neural network model containing an initial device feature set. It stores basic feature templates for all device types within the first known local area network. For example, the initial feature template for "Sony 4K advertising screen" is: Device type: 4K advertising screen, Manufacturer: Sony, Protocol support: UDP / TCP, UDP port: 5000, TCP port: 8080 / 9090, Typical behavior: UDP broadcast → TCP receive → UDP receive → TCP send; The template for "SUB_AD_002" (from advertising screen, Manufacturer: LG) is: Device type: from advertising screen, Manufacturer: LG, Protocol support: UDP / TCP, UDP listening port: 5000, TCP client port: 8080, Typical behavior: UDP listening → TCP request. The server determines the first trajectory step size from the temporal positions of the first protocol behavior trajectory chain (selecting all positions in the trajectory chain except the first fingerprint, i.e., F2, F3, and F4 corresponding to t1, t2, and t3 as step sizes), and predicts the device characteristics and interaction coupling degree of the current step size based on the preceding network communication entity cluster of each step size (the devices corresponding to all fingerprints before the step size). Taking the first trajectory step size "t2 (F3)" as an example (the current step size fingerprint is "Sony_4K_UDP_RCV_5000_AB", corresponding to the behavior: receiving the UDP response of "GUIDE_003"): preceding network communication entity cluster: trajectory chain segment [F1 (t0) → F2 (t1)] before step size t2, corresponding to the UDP broadcast behavior (F1) of "MAIN_AD_001" and the behavior of receiving the TCP request of "SUB_AD_002" (F2); retrieve initial device features: the coding layer network of the initial protocol sensing encoder retrieves the initial device features corresponding to F1 and F2 from the initial device feature set. F1 corresponds to the "UDP broadcast feature" of the "Sony 4K advertising screen": Behavior type: active discovery, protocol: UDP, port: 5000, data field: device identifier + MAC; F2 corresponds to the "TCP reception feature": Behavior type: passive response, protocol: TCP, port: 8080, data field: connection confirmation + resolution; Protocol semantic enhancement: The feedforward network performs semantic label fusion on the retrieved initial features. The "active discovery" of F1 is mapped to the semantic vector [1,0,0] (initiator), and the "passive response" of F2 is mapped to [0,1,0] (responder). The enhanced feature dimension is expanded from 512 dimensions to 515 dimensions; Feature topology compression: The feature mapping network (2-layer fully connected autoencoder) compresses the two enhanced feature vectors (F1, F2) into a 256-dimensional predicted device feature vector, representing the comprehensive interaction features of the pilot cluster; Generation of the first association confidence: The fully connected network maps the predicted device feature vector to the first association confidence (quantifying the interaction coupling degree between the current step size F3 and the pilot cluster).The confidence level is calculated by comparing the predicted features with the actual interaction features (pre-labeled as "high coupling", label confidence level 0.95) of "MAIN_AD_001" receiving the UDP response "GUIDE_003" in the first known local area network. The predicted confidence level output by the initial encoder is 0.62 (which deviates from the actual label). Following the same logic, the server calculates the first association confidence level for all first trajectory steps (t1, t2, t3) in the first protocol behavior trajectory chain, resulting in the confidence level sequence: [t1: 0.58, t2: 0.62, t3: 0.55] (all lower than the actual label confidence level of 0.9 ± 0.05). The server compares the first association confidence sequence with the actual label sequence (the real interaction coupling extracted from the first known local area network communication record, such as [t1:0.92, t2:0.95, t3:0.90]), and calculates the first deviation value as 0.118 using the mean squared error (MSE). The network weights of the initial protocol-aware encoder (the weights of the fully connected layers of the feature mapping network and the feedforward network) are adjusted using the backpropagation algorithm: the first deviation value is used as the loss function, and the Adam optimizer (learning rate 0.001) is used to update the weights, focusing on adjusting the dimensionality reduction parameters of the feature mapping network and the semantic enhancement weights of the feedforward network. The server repeats the above training process (loading a new first protocol behavior trajectory chain, calculating the deviation value, and adjusting the weights) until the first deviation value reaches the first training termination threshold (preset to ≤0.01). After 200 rounds of training, the first deviation value drops to 0.008, satisfying the termination condition. At this point, the initial protocol-aware encoder is optimized into a trained protocol-aware encoder, which can be used to extract accurate target device features of the target device.
[0095] In this embodiment of the invention, the step of obtaining the first association confidence level corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain based on the predicted device features corresponding to the first trajectory step can be implemented through the following example.
[0096] The prediction device features corresponding to the first trajectory step length are mapped using protocol semantics to obtain the initial network communication entity communication behavior spectrum corresponding to the first trajectory step length; the initial network communication entity communication behavior spectrum includes the communication parameter values corresponding to each network communication entity in the set of network communication entities to be verified.
[0097] The communication parameter values of the initial network communication entity communication behavior spectrum are reduced to obtain the target device communication behavior spectrum corresponding to the first trajectory step size; the target device communication behavior spectrum includes the first association confidence level corresponding to each network communication entity to be verified in the network communication entity set to be verified, and the network communication entity set to be verified includes the network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain.
[0098] From the target device communication behavior spectrum, determine the first association confidence level corresponding to the protocol fingerprint identifier at the first trajectory step size in the first protocol behavior trajectory chain.
[0099] In an embodiment of the invention, exemplarily, in a training scenario of a first known local area network (office building exhibition hall local area network), the server takes the first trajectory step size "t2 (fingerprint identifier F3: Sony_4K_UDP_RCV_5000_AB)" as an example (corresponding to the behavior of the main advertising screen "MAIN_AD_001" receiving the UDP response from the guide screen "GUIDE_003"), and generates the first association confidence score through three steps: protocol semantic mapping, communication parameter dimensionality reduction, and confidence score extraction. The "communication behavior spectrum" describes the logical relationship between device communication features and association strength using natural language. The specific process is as follows: The server performs protocol semantic mapping on the predicted device features (256-dimensional compressed features of the leading network communication entity cluster, including the UDP broadcast behavior of "MAIN_AD_001" and the behavior features of receiving TCP requests from the advertising screen "SUB_AD_002") corresponding to the first trajectory step size (t2). The mapping process is based on the semantic rule library built into the initial protocol-aware encoder, transforming the abstract feature vector into a specific communication parameter description for each entity in the set of network communication entities to be verified. The set of network communication entities to be verified consists of network communication entities corresponding to all protocol fingerprint identifiers in the first protocol behavior trajectory chain, including the main advertising screen "MAIN_AD_001", the secondary advertising screen "SUB_AD_002" (the communication peer of F2), the guide screen "GUIDE_003" (the communication peer of F3) and the control server "CONTROL_SERVER" (the subsequent interaction entity).The initial network communication entity communication behavior spectrum is a structured description of the communication characteristics of these entities, specifically as follows: Main advertising screen "MAIN_AD_001": As the core entity of the trajectory chain, it has the highest interaction frequency with the precursor cluster, reaching 8 times / minute, with an average data packet size of 1200 bytes, a protocol matching degree (overlap ratio with its own precursor behavior) of 1.0 (complete match), the shortest response latency (15ms), and a data field overlap degree (sharing ratio with its own communication fields) of 1.0 (complete overlap); Sub-advertising screen "SUB_AD_002": As an entity that has completed TCP interaction with the main advertising screen, its interaction frequency is 6 times / minute, with an average data packet size of 900 bytes, a protocol matching degree of 0.9 (high overlap with the TCP protocol of the precursor cluster), a response latency of 18ms, and a data field overlap degree of 0.9 (sharing device identifier, ...). The core fields include: MAC address, etc.); Guidance screen "GUIDE_003": As the entity whose current trajectory step size is to be verified, the interaction frequency is 5 times / minute, the average data packet size is 800 bytes, the protocol matching degree is 0.85 (supports UDP / TCP mixed protocol, with a high degree of overlap with the pilot cluster protocol type), the response latency is 20ms, and the data field overlap degree is 0.75 (includes shared fields such as device identifier and type, but lacks the resolution parameters unique to advertising screens); Control server "CONTROL_SERVER": As the entity for subsequent interaction, the current interaction frequency is low (3 times / minute), the average data packet size is 500 bytes, the protocol matching degree is 0.6 (mainly TCP control protocol, with low overlap with the UDP broadcast behavior of the pilot cluster), the response latency is 25ms, and the data field overlap degree is 0.5 (only includes the basic device ID field). The server performs dimensionality reduction on the multi-dimensional communication parameters (interaction frequency, packet size, protocol matching degree, etc.) in the initial network communication entity communication behavior spectrum, transforming them into a single "first association confidence score" to quantify the interaction coupling degree between each entity to be verified and the preceding network communication entity cluster. The dimensionality reduction process is achieved through weighted fusion, with weight allocation based on the degree of influence of the parameters on the interaction coupling degree: interaction frequency (0.3), protocol matching degree (0.3), data field overlap (0.2), average packet size (0.1), and response latency (0.1).The specific fusion process is as follows: Main advertising screen "MAIN_AD_001": After standardization (mapping to the 0-1 range), each parameter is weighted and summed. Interaction frequency (1.0) × 0.3 + protocol matching degree (1.0) × 0.3 + data field overlap degree (1.0) × 0.2 + data packet size (1.0) × 0.1 + response latency (1.0) × 0.1 = 1.0. Since it is its own entity, the first association confidence is corrected to 0.95. From advertising screen "SUB_AD_002": Interaction frequency (0.75) × 0.3 + protocol matching degree (0.9) × 0.3 + data field overlap degree (0.9) × 0.2 + data packet size (0.75) ×0.1 + Response latency (0.85) ×0.1 = 0.78; Guide screen “GUIDE_003”: Interaction frequency (0.5) ×0.3 + Protocol matching degree (0.85) ×0.3 + Data field overlap degree (0.75) ×0.2 + Data packet size (0.5) ×0.1 + Response latency (0.75) ×0.1 = 0.62; Control server “CONTROL_SERVER”: Interaction frequency (0.25) ×0.3 + Protocol matching degree (0.6) ×0.3 + Data field overlap degree (0.5) ×0.2 + Data packet size (0.25) ×0.1 + Response latency (0.5) ×0.1 = 0.45. The target device communication behavior spectrum obtained after dimensionality reduction is as follows: the first association confidence scores of each entity to be verified, from high to low, are: main advertising screen "MAIN_AD_001" (0.95), secondary advertising screen "SUB_AD_002" (0.78), guide screen "GUIDE_003" (0.62), and control server "CONTROL_SERVER" (0.45). This confidence score sequence quantifies the interaction coupling strength between each entity and the pilot cluster. From the target device communication behavior spectrum, the server locates the network communication entity corresponding to the protocol fingerprint identifier F3 ("Sony_4K_UDP_RCV_5000_AB") on the first trajectory step t2, namely the guide screen "GUIDE_003". According to the behavior spectrum description, the first association confidence score of this entity is 0.62. This value quantifies the interaction coupling between the guide screen and the pilot network communication entity cluster (UDP broadcast from the main advertising screen + TCP request from the secondary advertising screen), indicating that there is a medium to high degree of matching between the two in terms of protocol behavior patterns and device role positioning. This confidence level will serve as a key basis for training the initial protocol-aware encoder, used to subsequently calculate the first bias value and adjust network weights. Through the above steps, the server, without relying on tables, clearly presents the transformation process from multi-dimensional parameters to a single confidence level through a hierarchical description of the communication behavior spectrum in natural language, ultimately extracting the first association confidence level that can be used for model training.
[0100] In this embodiment of the invention, the initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network. The coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantic enhancement, and the fully connected network is used to output a first association confidence score.
[0101] The process of adjusting the network weights of the initial protocol-aware encoder based on the first deviation value until the first training termination threshold is reached to obtain the protocol-aware encoder can be implemented through the following example.
[0102] Based on the first deviation value, adjust the network weights of the feature mapping network, feedforward network, and fully connected network in the initial protocol-aware encoder until the first training termination threshold is reached to obtain the protocol-aware encoder.
[0103] In this embodiment of the invention, exemplarily, in the training scenario of a first known local area network (office building exhibition hall local area network), the initial protocol-aware encoder is a neural network model composed of an encoding layer network, a feedforward network, a feature mapping network, and a fully connected network. The server uses the first protocol behavior trajectory chain (the interaction trajectory of the main advertising screen "MAIN_AD_001", including protocol fingerprint identifiers F1 to F4) as training data, and adjusts the weights of the feature mapping network, feedforward network, and fully connected network through a first deviation value (the difference between the prediction confidence and the actual interaction coupling), finally obtaining the trained protocol-aware encoder. The following describes the training process of the first trajectory step size "t2 (fingerprint identifier F3: Sony_4K_UDP_RCV_5000_AB)" in detail: The four network layers of the initial protocol-aware encoder have a clear division of labor when processing the first protocol behavior trajectory chain: Encoding layer network: as the input interface of the model, it is responsible for retrieving the initial device features corresponding to the protocol fingerprint identifier from the initial device feature set. For example, for F1 (UDP broadcast behavior) in the trajectory chain, the coding layer network retrieves the "UDP broadcast initial features" of "Sony4K advertising screen" (including basic attributes such as behavior type "active discovery", protocol "UDP", and port "5000") from the initial device feature set by matching the fingerprint "Sony_4K_UDP_BC_5000_AB". This process does not involve weight adjustment and only relies on preset feature retrieval rules. The feedforward network is responsible for protocol semantic enhancement, transforming the initial device features into enhanced features with semantic labels through built-in semantic mapping rules. For example, the "active discovery" behavior in the "UDP broadcast initial features" is mapped to a semantic vector [1,0,0] (representing the "initiator" role) and fused into the initial feature vector, making the features more consistent with the logic of the actual communication scenario. The feedforward network contains multiple fully connected layers, whose weights determine the fusion strength of the semantic labels (e.g., the influence of the [1,0,0] vector on the overall features). Feature Mapping Network: Responsible for feature topology compression, it reduces high-dimensional enhanced features (e.g., 515-dimensional) to low-dimensional dense vectors (256-dimensional) through an autoencoder structure, retaining core interaction features (e.g., protocol type, device role) and removing redundant information (e.g., non-critical data fields). Its weights (e.g., the fully connected layer parameters of the encoder and decoder) directly affect the compression accuracy; improper weights can lead to the loss of key features. Fully Connected Network: As the output layer, it maps the compressed 256-dimensional feature vector to a first association confidence score (a value in the 0-1 range), quantifying the interaction coupling between the entity to be verified and the leading cluster. For example, mapping the compressed feature of "GUIDE_003" to a confidence score of 0.62, its weights (connection parameters of the output layer neurons) determine the mapping accuracy from the feature vector to the confidence score. The first bias value is the difference between the first association confidence score (predicted value) and the actual interaction coupling (true label).In the first known local area network, the actual interaction coupling degree between "MAIN_AD_001" and the guide screen "GUIDE_003" has been marked by historical communication records (the actual label is 0.95, because the two need to synchronize content frequently in the exhibition hall and have close interaction), while the prediction confidence of the initial encoder output is 0.62, and the two are significantly different. The server adjusts the weights through the following steps: taking the first trajectory step size t2 as an example, the first deviation value is calculated by the mean square error (MSE): deviation value = (0.62-0.95). 2 =0.1089. If the trajectory chain contains multiple step lengths (e.g., t1, t2, t3), the average of all step length deviations is taken as the overall first deviation value (e.g., the initial average deviation value is 0.118). The weights of the feature mapping network (the fully connected layer parameters of the encoder) directly affect the quality of the compressed features. During the initial compression process, due to improper weight settings, the "protocol matching degree" feature (a key factor affecting coupling) is weakened during dimensionality reduction, resulting in the compressed features failing to fully reflect the protocol overlap between "GUIDE_003" and the pilot cluster (UDP / TCP hybrid protocol). The server increases the weight of the neuron corresponding to the "protocol matching degree" through the backpropagation algorithm (e.g., from 0.2 to 0.4), thereby increasing the proportion of this dimension in the compressed features and strengthening the influence of protocol similarity on confidence. The weights of the feedforward network determine the fusion strength of the semantic labels. In the initial state, the "receiver" semantic label (vector [0,0,1]) corresponding to the "UDP response" behavior has a low weight (0.1), resulting in insufficient contribution of this semantic to the features. The server adjusts the weights of the fully connected layer in the feedforward network, increasing the weight of the "receiver" label to 0.3. This makes the "UDP response" behavior of "GUIDE_003" more prominent in the enhanced features, forming a semantic association with the "TCP response" behavior (F2) of the precursor cluster, indirectly improving the accuracy of coupling prediction. The output layer weights of the fully connected network determine the slope of the mapping from compressed features to confidence. The initial weights make the mapping from feature vectors to confidence conservative (e.g., when the proportion of highly coupled features in 256-dimensional features is 0.7, the confidence output is only 0.6). The server adjusts the output layer weights (e.g., adjusting the scaling factor of the weight matrix from 0.8 to 1.2) so that the same highly coupled features correspond to higher confidence, for example, mapping a feature with a proportion of 0.7 to 0.85 instead of 0.6. The server repeats the above adjustment process: after each round of adjustment, the first protocol behavior trajectory chain is re-inputted, features are retrieved through the coding layer network, semantics are enhanced through the feedforward network, the topology is compressed through the feature mapping network, the fully connected network outputs a new first association confidence, and then a new first bias value is calculated. For example: After the first round of adjustments, the confidence level of "GUIDE_003" increased from 0.62 to 0.75, and the deviation decreased to 0.04 (0.75-0.95). 2=0.04); After the fifth round of adjustments: the confidence level increased to 0.92, and the deviation was 0.0009 ((0.92-0.95)). 2 =0.0009), which is lower than the first training termination threshold (preset to 0.01). At this point, the server stops adjusting and solidifies the current weight parameters of the feature mapping network, feedforward network, and fully connected network, resulting in a trained protocol-aware encoder. This encoder can accurately extract the target device features of network communication entities, meeting the needs of subsequent identification of associated device archive information.
[0104] In this embodiment of the invention, the following implementation methods are also provided.
[0105] Obtain the network communication entity metadata corresponding to each network communication entity in the set of network communication entities to be verified.
[0106] By using a text encoder, feature extraction is performed on the metadata of the network communication entities to obtain the initial device features corresponding to each network communication entity to be verified.
[0107] The initial device feature set is obtained based on the initial device features corresponding to each network communication entity to be verified.
[0108] In an embodiment of the present invention, for example, in a large commercial scenario (such as a local area network in an office building exhibition hall), the server needs to construct an initial device feature set as the basic data for the protocol-aware encoder. This process is achieved through three steps: acquiring the metadata of the network communication entities to be verified, extracting features from the text encoder, and summarizing the feature set. Taking the set of network communication entities to be verified within the local area network (including the main advertising screen "MAIN_AD_001", the secondary advertising screen "SUB_AD_002", the guide screen "GUIDE_003", and the control server "CONTROL_SERVER") as an example, the specific process is as follows: The server collects the network communication entity metadata of the entities to be verified through two methods: one is the broadcast packets during the device initialization phase, and the other is the configuration database of the local area network management system. The metadata is structured text information, containing core device attributes: Main advertising screen "MAIN_AD_001": Metadata comes from its startup UDP broadcast packet, including device identifier "MAIN_AD_001", device type "4K advertising screen", manufacturer "Sony", supported protocol "UDP / TCP", UDP default port "5000", TCP server port "8080", MAC address "AB:CD:EF:12:34:56", and resolution "3840x2160"; Secondary advertising screen "SUB_AD_002": Metadata comes from the configuration database, including device identifier "SUB_AD_002", device type "secondary advertising screen", manufacturer "LG", supported protocol "TCP", TCP client port "8080", and MAC address "BC:DE:FG: 23:45:67”, resolution “1920x1080”; Guide screen “GUIDE_003”: Metadata comes from UDP response packet, including device identifier “GUIDE_003”, device type “guide screen”, manufacturer “Samsung”, supported protocol “UDP / TCP”, UDP listening port “5000”, TCP client port “8080”, MAC address “CD:EF:GH:34:56:78”, interaction mode “passive response”; Control server “CONTROL_SERVER”: Metadata comes from management system configuration, including device identifier “CONTROL_SERVER”, device type “control server”, manufacturer “Dell”, supported protocol “TCP”, server port “9090”, management IP “10.0.0.1”. The server calls a pre-trained text encoder (fine-tuned based on BERT model) to process the metadata, converting the text information into an initial device feature vector.The encoder performs word segmentation and vectorization on each field of the metadata: for category fields such as "device type" and "manufacturer", it maps them to discrete vectors through word embedding (e.g., "4K advertising screen" is mapped to [1,0,0], and "from advertising screen" is mapped to [0,1,0]); for numerical fields such as "port" and "resolution", it converts them into continuous values through normalization (e.g., TCP port 8080 is normalized to 0.808, and resolution 3840x2160 is mapped to [0.95,0.98]); for behavioral fields such as "protocol" and "interaction mode", it generates association vectors through semantic similarity calculation (e.g., "UDP / TCP" protocol combination is mapped to [0.8,0.9], representing the support strength for the two protocols). For example, the metadata of "MAIN_AD_001" is encoded to generate a 512-dimensional initial device feature vector, which includes core features such as type encoding, vendor weight, protocol support, and port normalization value; the vector of "GUIDE_003" highlights the "passive response" interaction mode (weight 0.75) and the UDP listening port (normalization value 0.5). The server summarizes the initial device feature vectors of all entities in the network communication entity set to be verified to obtain the initial device feature set. This set stores the 512-dimensional feature vector of each entity using the device identifier as an index. For example, the feature vector corresponding to "MAIN_AD_001" is: [Type encoding 1, vendor weight 0.85, UDP support 0.9, TCP port 0.808, resolution vector...,...]; the feature vector corresponding to "GUIDE_003" is: [Type encoding 3, vendor weight 0.7, UDP support 0.95, TCP port 0.808, interaction mode weight 0.75,...]. The initial device feature set is built into the protocol-aware encoder and is used for subsequent retrieval of initial device features, providing a basis for target device feature extraction.
[0109] In this embodiment of the invention, the step of determining the associated device profile information of the target device from the communication records of the local area network environment based on the similarity of communication behavior between the target device and the communication peer device, respectively, can be implemented through the following example.
[0110] Based on the communication behavior similarity between the target device and the communication peer device, and in descending order of communication behavior similarity, multiple associated network communication entities of the target device are determined from the communication records of the local area network environment.
[0111] Each associated network communication entity is arranged chronologically according to its communication timestamp with the local area network environment to obtain the associated device file information of the target device.
[0112] In an embodiment of the present invention, for example, in a large commercial scenario (such as a shopping mall LAN), the target device is “AD_SCREEN_001” (a 4K advertising screen in the atrium on the first floor, manufactured by LG). The characteristics of the target device are a 256-dimensional dense vector extracted by a protocol-aware encoder (containing core features such as device type “4K advertising screen”, protocol behavior “UDP broadcast + TCP response”, and manufacturer attribute “LG”). The server needs to calculate the similarity of communication behavior between the vector and the target device characteristics of the communication peer device within the local area network, filter the associated entities and sort them by timestamp, and generate associated device profile information. The specific process is as follows: The server extracts the communication peer devices that have interacted with "AD_SCREEN_001" from the communication records of the local area network environment, including: the second-floor guide screen "GUIDE_SCREEN_002" (Samsung, type "guide screen"), the third-floor interactive screen "INTERACTIVE_SCREEN_003" (Huawei, type "interactive screen"), the control server "CONTROL_SERVER_004" (Dell, type "control server"), and the office printer "PRINTER_005" (HP, non-video device). The server calculates the similarity of the target device's feature vectors with each communication peer device using a cosine similarity algorithm (each vector has a dimension of 256, and the value ranges from 0 to 1, with higher values indicating stronger interaction coupling): Similarity with "CONTROL_SERVER_004": The control server needs to distribute advertising content to "AD_SCREEN_001," and their protocol behaviors are highly matched (both support TCP long connections, and control command interactions are frequent), resulting in a similarity of 0.91 (above the threshold of 0.7, indicating a strong correlation); Similarity with "GUIDE_SCREEN_002": The guide screen and the advertising screen need to... The interactive screens, which synchronously play mall activity information and have similar interaction modes (both include UDP discovery and TCP status reporting), have a similarity of 0.82 (strong correlation). The similarity with "INTERACTIVE_SCREEN_003" is also similar: the interactive screen needs to receive content linkage instructions from the advertising screen, and the protocol matching is moderate (UDP response frequency is slightly low), resulting in a similarity of 0.75 (strong correlation). The similarity with "PRINTER_005" is also similar: the printer is an office device that only occasionally receives log printing requests from the advertising screen, and the protocol behavior is significantly different (only supports short TCP connections), resulting in a similarity of 0.32 (below the threshold, weak correlation, excluded). Servers are then filtered in descending order of similarity to identify strongly correlated network communication entities: control server "CONTROL_SERVER_004" (0.91), second-floor guide screen "GUIDE_SCREEN_002" (0.82), and third-floor interactive screen "INTERACTIVE_SCREEN_003" (0.75).The server extracts the first communication timestamp (based on the time field of the TCP handshake packet or UDP response packet) between the aforementioned associated entities and "AD_SCREEN_001" from the local area network communication records: Control server "CONTROL_SERVER_004": After "AD_SCREEN_001" completes initialization (09:00:00), it initiates a connection request through TCP port 9090 first, with the first communication timestamp being "09:00:03"; Second-floor guide screen "GUIDE_SCREEN_002": After listening to the UDP broadcast of "AD_SCREEN_001" (09:00:00), it sends a response packet through TCP port 8080, with the first communication timestamp being "09:00:05"; Third-floor interactive screen "INTERACTIVE_SCREEN_003": Due to network delays on the floor, it listens to the broadcast later, with the UDP response packet arriving at "09:00:08", and the first communication timestamp being "09:00:08". The server sorts associated entities in ascending order by the first communication timestamp, generating associated device file information for “AD_SCREEN_001”, including device identifier, type, IP address, communication behavior similarity, and first communication time: First: Control server “CONTROL_SERVER_004” (Type: Control server, IP: 10.0.0.1, Similarity: 0.91, First communication time: 09:00:03); Second: Second floor guide screen “GUIDE_SCREEN_002” (Type: Guide screen, IP: 10.0.1.15, Similarity: 0.82, First communication time: 09:00:05); Third: Third floor interactive screen “INTERACTIVE_SCREEN_003” (Type: Interactive screen, IP: 10.0.2.8, Similarity: 0.75, First communication time: 09:00:08). This file contains a complete record of the target device's core collaborating devices within the local area network, providing crucial information for subsequent construction of a comprehensive device feature map and optimization of network adaptation parameters.
[0113] In this embodiment of the invention, the following implementation methods are also provided.
[0114] Obtain the second protocol behavior trajectory chain and load the second protocol behavior trajectory chain into the initial device identification model; the second protocol behavior trajectory chain is obtained based on the communication records of the second known local area network, and the initial device identification model includes the preset device feature library;
[0115] Using the initial device identification model, preset device features corresponding to each protocol fingerprint identifier preceding the second trajectory step are retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain the predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, the second association confidence level corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step.
[0116] Based on the second association confidence level corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain, the second deviation value is obtained.
[0117] The network weights of the initial device recognition model are adjusted based on the second deviation value until the second training termination threshold is reached, thereby obtaining the target device recognition model.
[0118] In this embodiment of the invention, for example, in a large commercial scenario, the target device identification model needs to be trained using the communication records of a second known local area network (LAN) to have the ability to accurately identify the characteristics of LAN devices. The second known LAN is selected as "the LAN of the North Zone of a large shopping mall" (deploying 30 video playback devices, including advertising screens, guidance screens, interactive screens, and a control server, with communication records covering 6 months of device interaction logs). The server constructs a second protocol behavior trajectory chain based on the communication records of this LAN, and trains the initial device identification model to obtain the target device identification model. The specific process is as follows: The server selects the interaction data of the main advertising screen "AD_SCREEN_N01" (device identifier, LG 4K advertising screen) in the North Zone from the communication records of the second known LAN to construct the second protocol behavior trajectory chain. This trajectory chain is formed by concatenating protocol fingerprint identifiers according to timestamps. The protocol fingerprint identifiers are generated based on device type, protocol behavior, port, and manufacturer information. For example: F1 (t0=09:00:00): After device startup, a UDP broadcast discovery packet is sent (port 5000), fingerprint identifier "LG_4K_UDP_BC_5000_N01"; F2 (t1=09:00:03): Receives a TCP connection request from the North Area Guide Screen "GUIDE_N02" (Samsung, type "Guide Screen") (port 8080), fingerprint identifier "LG_4K". F3 (t2=09:00:06): Synchronizes content with the North Zone control server "CONTROL_N03" (Dell) via TCP (port 9090), fingerprint identifier "LG_4K_TCP_SYNC_9090_N01"; F4 (t3=09:00:09): Receives UDP status reports from the South Zone interactive screen "INTER_N04" (Huawei) (port 5000), fingerprint identifier "LG_4K_UDP_RPT_5000_N01". The second protocol behavior trajectory chain is defined as: [F1→F2→F3→F4] in timestamp order. The server loads this trajectory chain into the initial device identification model. The initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. It has a built-in preset device feature library that stores standard feature templates for 100+ types of video devices. For example, the "LG 4K Advertising Screen" template contains the protocol fingerprint "LG_4K_UDP_BC_5000" and the feature vector [Device type: 4K advertising screen, Protocol: UDP / TCP, Interaction mode: Active discovery + Passive response]; the "Samsung Guide Screen" template contains the fingerprint "Samsung_Guide_TCP_CLI_8080" and the feature vector [Device type: Guide screen, Protocol: TCP, Interaction mode: Passive discovery + Active request].The server determines the second trajectory step size from the temporal positions of the second protocol behavior trajectory chain (selecting positions other than the first fingerprint, i.e., F2, F3, and F4 corresponding to t1, t2, and t3). Based on the leading network communication entity cluster of each step size (the trajectory segment before the step size), the server calculates the second association confidence (quantifying the interaction coupling degree between the entity at the current step size and the leading cluster) through the model. Taking the second trajectory step size "t2 (F3: LG_4K_TCP_SYNC_9090_N01)" as an example (corresponding to the content synchronization behavior between the main advertising screen and the control server): The coding layer network of the initial device identification model, based on the trajectory segment [F1→F2] (pilot cluster) before the second trajectory step size t2, retrieves the preset device features corresponding to each protocol fingerprint identifier in the preset device feature library: F1 (LG_4K_UDP_BC_5000_N01) matches the "UDP broadcast preset feature" of "LG4K advertising screen": {behavior type: active discovery, protocol: UDP, port: 5000, feature vector V1}; F2 (LG_4K_TCP_RCV_8080_N01) matches the "TCP receive preset feature" of "LG4K advertising screen": {behavior type: passive response, protocol: TCP, port: 8080, feature vector V2}. The fusion recognition network performs fusion and pattern recognition on the retrieved preset device features (V1, V2): Feature fusion: An attention mechanism is used. Since F2 (TCP receive) and the current step size F3 (TCP synchronization) have the same protocol type, V2 is assigned a higher weight (0.6), and V1 has a weight of 0.4. The weighted sum is used to obtain the fused feature vector Vfusion = 0.4V1 + 0.6V2; Pattern recognition: The LSTM network learns the temporal dependency relationship of the fused features (the "broadcast → response" pattern of F1→F2), and outputs the predicted device feature Vpredicted (a 256-dimensional vector representing the comprehensive interaction features of the pilot cluster) corresponding to the second trajectory step size t2. The fully connected network maps Vpredicted to the second association confidence. In the preset device feature library, the standard interaction coupling degree label of the control server "CONTROL_N03" is 0.92 (due to the need for high-frequency synchronization content, the coupling degree is high). The prediction confidence of the initial model output is 0.65 (there is a deviation from the label), which is the second association confidence degree corresponding to the second trajectory step size t2. Following this logic, the server calculates the second association confidence score for all second trajectory step lengths: t1 (F2) corresponds to 0.58, t2 (F3) corresponds to 0.65, and t3 (F4) corresponds to 0.60. The server compares the second association confidence score sequence ([0.58, 0.65, 0.60]) with the actual label sequence of the second known local area network ([0.90, 0.92, 0.88]), and calculates the second deviation value as 0.076 using the mean squared error.The server adjusts the network weights of the initial device identification model based on the second deviation value, focusing on optimizing the fusion identification network and the fully connected network: Fusion identification network: Due to insufficient weight of F2 (TCP receive) to F3 (TCP synchronization) (initially 0.6), the fused features did not fully reflect the continuity of the TCP protocol. The V2 weight was increased to 0.8 to enhance the influence of TCP features. Fully connected network: The low output layer weights led to conservative prediction confidence. The weight matrix scaling factor was adjusted from 0.7 to 1.1 to give the same fused features higher confidence. After 200 iterations of training, the second deviation value decreased to 0.009 (≤ the second training termination threshold of 0.01). At this point, the initial device identification model was optimized into the target device identification model. This model can accurately identify the interaction features of LAN devices. For example, for the F3 step size of "AD_SCREEN_N01", the second association confidence increased to 0.91 (close to the actual label 0.92), meeting the device identification requirements. Through the above steps, the server completes the training of the target device identification model, providing reliable model support for subsequent identification of integrated device feature maps.
[0119] In this embodiment of the invention, the initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. The coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence level.
[0120] The process of adjusting the network weights of the initial device identification model based on the second deviation value until the second training termination threshold is reached to obtain the target device identification model can be implemented through the following example.
[0121] Based on the second deviation value, adjust the network weights of the fusion recognition network and the fully connected network in the initial device recognition model until the second training termination threshold is reached to obtain the target device recognition model.
[0122] In an embodiment of the invention, exemplarily, in a training scenario of a second known local area network (the local area network of the south area of a shopping mall, deploying 25 video devices), the initial device recognition model consists of an encoding layer network, a fusion recognition network, and a fully connected network. The server uses the second protocol behavior trajectory chain (the interaction trajectory of the south area main advertising screen "AD_SCREEN_S01", including protocol fingerprint identifiers F1 to F4) as training data, and adjusts the weights of the fusion recognition network and the fully connected network through a second deviation value (the difference between the predicted second association confidence and the actual interaction coupling), ultimately obtaining the target device recognition model. The following details the second trajectory step size "t2 (fingerprint identifier F3: LG_4K_TCP_SYNC_9090_S01, corresponding to the content synchronization behavior between the main advertising screen and the south area control server "CONTROL_S03")": The three-layer network of the initial device recognition model: Encoding layer network: As the input interface, it retrieves the preset device features corresponding to the protocol fingerprint from the preset device feature library. The weights of this layer are fixed (based on feature retrieval rules) and do not participate in the adjustment. For example, in trajectory chain F1 (LG_4K_UDP_BC_5000_S01, UDP broadcast behavior), the coding layer network retrieves the preset feature vector V1 of "LG4K advertising screen" (including protocol "UDP", behavior "active discovery", and port "5000"); for F2 (LG_4K_TCP_RCV_8080_S01, TCP receiving behavior), it retrieves the preset feature vector V2 (including protocol "TCP", behavior "passive response", and port "8080"). The fusion recognition network is responsible for feature fusion and pattern recognition. It assigns weights to different preset features through an attention mechanism (weights are adjustable), fuses them into a comprehensive feature, and then uses an LSTM network to learn the temporal pattern, outputting an intermediate feature vector. For example, for the leading cluster [F1→F2] of F3, the initial attention weights are V1 (0.5) and V2 (0.5), and after fusion, an intermediate vector M is obtained through LSTM. Fully connected network: The intermediate vector M is mapped to a second association confidence level (0-1), and the output layer weights (connection coefficients) determine the mapping accuracy. For example, the initial weights map M to 0.63 (the prediction confidence level of F3), while the actual interaction coupling degree label is 0.93 (the control server and the main advertising screen need to synchronize content frequently, resulting in high coupling). The server calculates the second deviation value: taking the second trajectory step size t2 as an example, the second deviation value = (0.63-0.93). 2=0.09; the trajectory chain contains three steps: t1, t2, and t3. The average second bias value is 0.08 (higher than the second training termination threshold of 0.01), requiring weight adjustment. The attention weights of the fusion recognition network determine the degree of influence of the leading features on the current step. In the initial weights, F1 (UDP broadcast) and F2 (TCP receive) have equal weights (0.5), but F3 (TCP synchronization) and F2 (TCP receive) have the same protocol type, so the weight of F2 needs to be increased. The server uses the backpropagation algorithm to increase the weight of V2 from 0.5 to 0.8 and decrease the weight of V1 to 0.2, making the fusion features more prominent in terms of the continuity of TCP behavior. After adjustment, the intermediate vector M contains stronger TCP protocol features, improving the matching degree with the interaction mode of the control server. The output layer weights of the fully connected network (such as the connection coefficient matrix W) determine the mapping slope from the intermediate vector M to the second association confidence. The initial weight W maps M to 0.63 (conservative). The server adjusts the scaling factor of W from 0.7 to 1.2 using gradient descent to enhance the mapping strength from features to confidence. After adjustment, the same intermediate vector M maps to 0.88 (closer to the actual label 0.93). The server repeats the above process: after each round of adjustment, the second protocol behavior trajectory chain is re-inputted, features are retrieved through the encoding layer, the fusion recognition network fuses the pattern, and the fully connected network outputs the confidence, calculating a new second bias value. For example: after the 10th round of training: the prediction confidence of F3 increases to 0.88, and the average second bias value decreases to 0.025; after the 30th round of training: the prediction confidence of F3 reaches 0.92, and the average second bias value is 0.009 (≤ the second training termination threshold of 0.01). At this point, the server stops adjusting, and the attention weights (V1: 0.2, V2: 0.8) of the fusion recognition network and the output layer weights (scaling factor 1.2) of the fully connected network are solidified to obtain the target device recognition model. This model can accurately identify the interaction coupling degree of local area network devices. For example, for the F3 step size of "AD_SCREEN_S01", the second association confidence level reaches 0.92 (close to the actual tag's 0.93), meeting the device identification requirements.
[0123] In this embodiment of the invention, the step of performing feature fusion and pattern recognition on each preset device feature retrieved and outputting the device identification features of the comprehensive device feature map can be implemented through the following example.
[0124] According to the network communication entity order of the comprehensive device feature map, each preset device feature retrieved is combined to obtain a preset device feature trajectory chain;
[0125] The preset device feature trajectory chain is subjected to feature fusion and pattern recognition to obtain a network communication entity fusion recognition feature trajectory chain; the network communication entity fusion recognition feature trajectory chain includes network communication entity fusion recognition features that match the number of network communication entities in the integrated device feature map.
[0126] From the network communication entity fusion identification feature trajectory chain, obtain the network communication entity fusion identification features at the network communication entity location of the target device, and use them as the device identification features of the integrated device feature map.
[0127] In an embodiment of the invention, for example, in a large commercial scenario (such as a local area network on the first floor of a shopping mall), the integrated device feature map uses the target device "AD_SCREEN_001" (a 4K advertising screen in the atrium on the first floor, device identifier) as the core node, and associated devices as secondary nodes. The node order is arranged as "target device → control server → guide screen → interactive screen" (based on descending order of relevance, the control server has the highest coupling with the target device, followed by the guide screen and the interactive screen). After the server retrieves the preset device features through the target device recognition model, it needs to extract the device recognition features through feature fusion and pattern recognition. The specific process is as follows: The server first determines the order of network communication entities from the integrated device feature map. The entity order in the map is as follows: target device "AD_SCREEN_001" → control server "CONTROL_SERVER_004" → second-floor guide screen "GUIDE_SCREEN_002" → third-floor interactive screen "INTERACTIVE_SCREEN_003" (arranged in descending order of communication behavior similarity in the associated device file information, with similarities of 0.91, 0.82, and 0.75 respectively). Subsequently, the server retrieves the preset device features corresponding to each entity from the preset device feature library through the coding layer network of the target device recognition model.The preset device feature library stores the standard feature vectors of known video device types, including core attributes such as device type, protocol behavior, interaction mode, etc.: Preset device features of the target device "AD_SCREEN_001": Matching the standard template of "LG 4K advertising screen", the feature vector is V_target = [Device type: 4K advertising screen (confidence 0.98), Protocol: UDP / TCP (UDP accounts for 30%, TCP accounts for 70%), Interaction mode: Active discovery + Passive response, Resolution: 3840x2160, Manufacturer: LG]; Preset device features of the control server "CONTROL_SERVER_004": Matching the standard template of "Dell control server", the feature vector is V_control = [Device type: Control server (confidence 0.99), Protocol: TCP (long connection), Interaction mode: Active synchronization + Content distribution, Service port: 9090, Manufacturer: Dell]; Preset device features of the second-floor guide screen "GUIDE_SCREEN_002": Matching the standard template of "Samsung guide screen", the feature vector is V_guide = [Device type: Guide screen (confidence 0.97), Protocol: UDP / TCP (UDP listening, TCP client), Interaction mode: Passive discovery + Active request, Resolution: 1920x1080, Manufacturer: Samsung]; Preset device features of the third-floor interactive screen "INTERACTIVE_SCREEN_003": Matching the standard template of "Huawei interactive screen", the feature vector is V_interactive = [Device type: Interactive screen (confidence 0.96), Protocol: UDP (status reporting) / TCP (instruction receiving), Interaction mode: Passive response + Event trigger, Resolution: 2560x1440, Manufacturer: Huawei]. The server combines the retrieved preset device feature vectors in sequence according to the entity order of the comprehensive device feature map (target device → control server → guide screen → interactive screen), and obtains the preset device feature trajectory chain: [V_target → V_control → V_guide → V_interactive] (the length of the trajectory chain is 4, which is consistent with the number of network communication entities in the map). The server performs feature fusion and pattern recognition on the preset device feature trajectory chain through the fusion recognition network of the target device recognition model. The fusion recognition network includes an attention mechanism module and an LSTM temporal pattern recognition module. The former is used to assign feature weights, and the latter is used to learn the interaction dependence relationship between entities. Feature fusion stage: The attention mechanism module assigns weights according to the interaction coupling degree between the entity and the target device. The control server and the target device need to synchronize advertising content frequently (coupling degree 0.91), and the weight is set to 0.35; The guide screen needs to synchronize activity information (coupling degree 0.82), and the weight is 0.3; The interactive screen only receives linkage instructions occasionally (coupling degree 0.75), and the weight is 0.2; The target device is the core node, and its own weight is 0.15.After weighting, each feature vector in the trajectory chain is summed using weighted averages: Target device feature V_target: weight 0.15, retaining its core attributes (such as 4K resolution, proactive discovery behavior); Control server feature V_control: weight 0.35, emphasizing "TCP long connection" and "content distribution" features to match the target device's content reception needs; Guide screen feature V_guide: weight 0.3, emphasizing "TCP client" and "passive discovery" features to complement the target device's TCP server behavior; Interactive screen feature V_inter: weight 0.2, emphasizing "UDP status reporting" features to reflect low-frequency interaction patterns. In the pattern recognition stage, the LSTM module learns the temporal dependencies of fused features according to the trajectory chain sequence, identifying typical interaction patterns between entities: Target device → Control server: "Active request - content distribution" mode (the target device requests content from the control server via TCP, and the server responds with distribution); Control server → Guide screen: "Synchronization command - status feedback" mode (the control server forwards the content synchronization command to the guide screen, and the guide screen returns the receiving status); Guide screen → Interactive screen: "Linkage trigger - event reporting" mode (after the guide screen triggers an interactive event, the interactive screen reports the execution result via UDP). The LSTM module outputs a network communication entity fusion recognition feature trajectory chain with the same length as the preset device feature trajectory chain, containing 4 fused recognition feature vectors, corresponding to the 4 network communication entities in the graph: [F-fused target → F-fused control → F-fused guide → F-fused interaction]. Each fused recognition feature vector (256 dimensions) retains the core attributes of a single entity and also includes interaction pattern features with other entities (e.g., F-fused target contains composite features of "4K resolution + content reception + active discovery"). The fused identification features in the network communication entity fusion identification feature trajectory chain correspond one-to-one with the network communication entities in the comprehensive device feature map, and the order is completely consistent (target device → control server → guide screen → interactive screen). The server locates the position of the target device "AD_SCREEN_001" from the trajectory chain—the first position of the trajectory chain, which is the fused identification feature vector F_future_target. F_future_target, as the device identification feature of the comprehensive device feature map, contains key information such as the type, performance, protocol preference, and networking requirements of the target device. Specifically, it is manifested as follows: Device type: 4K advertising screen (confidence 0.98, verified through the interaction feedback between the fused control server and the guide screen); Protocol preference: TCP priority (weight 0.7, due to the highest proportion of TCP long connections with the control server); Bandwidth requirement: 50Mbps (calculated based on the resolution and frame rate of 4K content transmission, fused with the content bitrate characteristics of the control server); Synchronization accuracy: ±10ms (needs to maintain content playback synchronization with the guide screen, fused with the response latency characteristics of the guide screen); Interaction mode: active discovery + passive response (fusion of its own UDP broadcast behavior and TCP request reception behavior).The device identification features will be directly used to determine the networking adaptation parameters (such as bandwidth allocation, protocol priority configuration, etc.) of the target device and the local area network environment, ensuring stable collaboration of the device cluster. Through the above steps, the server completes the transformation from preset device features to device identification features, achieving accurate profiling and identification of the target device.
[0128] In this embodiment of the invention, the preset device features in the preset device feature library are the target device features of the network communication entity, which are obtained by feature space compression of the initial device features of the network communication entity.
[0129] In this embodiment of the invention, for example, in a large commercial local area network (such as a shopping mall video equipment local area network), the preset device features stored in the preset device feature library are essentially the target device features of the network communication entity after feature space compression. Taking "LG 4K advertising screen" (network communication entity) as an example, the server first extracts its initial device features: including device type "4K advertising screen", manufacturer "LG", supported protocols "UDP / TCP", UDP port "5000", TCP port "8080", resolution "3840x2160", and other multi-dimensional information, forming a 512-dimensional high-dimensional feature vector. Subsequently, the server performs spatial compression on this initial feature vector through a feature mapping network (autoencoder structure), retaining core features such as device type, protocol behavior, and manufacturer attributes, and removing redundant information such as system version number, reducing the 512-dimensional vector to a 256-dimensional dense vector, i.e., the target device feature. This target device feature serves as a standard template for "LG 4K advertising screen" and is stored in the preset device feature library, becoming the preset device feature for subsequent retrieval.
[0130] In this embodiment of the invention, the following implementation methods are also provided.
[0131] Obtain the device characteristics of the target device and the local area network characteristics of the local area network environment;
[0132] The device identification features, the device features of the target device, and the local area network features of the local area network environment are loaded into the target networking adaptation model to obtain the networking adaptation parameters between the target device and the local area network environment.
[0133] In an embodiment of the present invention, for example, in a large commercial setting (such as a local area network on the first floor of a shopping mall), the target device "AD_SCREEN_001" (a 4K advertising screen in the atrium on the first floor) needs to achieve synchronous playback of advertising content, status monitoring and remote control through the local area network. After obtaining the device identification features through the target device identification model, the server also needs to combine the target device's own hardware attributes (device features) and the network resource status of the local area network (LAN features) to generate targeted network adaptation parameters through the target network adaptation model. This ensures efficient collaboration between the device and the LAN environment. The specific process is as follows: The server collects key features through two methods: The target device's device features come from the device's factory configuration database and initialization self-test information, including hardware attributes and basic functional parameters: Hardware specifications: resolution 3840x2160 (4K), maximum power consumption 150W, network interface type Gigabit Ethernet (RJ45), supports video encoding format H.265 / AVC; Basic configuration: default gateway 10.0.1.1, subnet mask 255.255.255.0, DNS server 10.0.0.2, embedded system version V3.2.1; Functional limitations: maximum bandwidth requirement for a single video stream is 50Mbps (4K@60fps), and the synchronization signal reception delay must be ≤10ms (to avoid playback stuttering). The LAN characteristics of the LAN environment are derived from the network management module and traffic monitoring system of the core switch, reflecting the network resources and topology: Resource configuration: Total LAN bandwidth 1Gbps (symmetrical uplink and downlink), 20 currently online devices (including 15 video devices and 5 office devices), and 600Mbps remaining bandwidth on the core switch ports (total bandwidth 1Gbps - existing load 400Mbps); Topology: Star topology, with target devices connected to the access layer switch (port 10.0.1.10), and the control server connected to the core layer (10.0.0.1), with forwarding via a three-layer router; Existing policies: Default VLAN 1 (no dedicated video VLAN), NTP time synchronization frequency 1 hour / time (synchronization accuracy ±50ms), and no differentiated bandwidth allocation (bandwidth shared by all devices). The server loads three types of features into the pre-trained target network adaptation model (a rule-based reasoning model trained on commercial LAN device adaptation cases, including a feature fusion layer and parameter mapping module): Device identification features (from the target device identification model output): Device type "4K advertising screen" (confidence 0.98), protocol preference "TCP preferred" (TCP accounts for 70%), bandwidth requirement 50Mbps, synchronization accuracy requirement ±10ms, compatibility "supports Samsung / LG protocol interoperability"; Device characteristics of the target device (hardware and basic configuration): Resolution 3840x2160, interface Gigabit Ethernet, single-stream bandwidth 50Mbps; LAN characteristics of the LAN environment (resources and topology): Remaining bandwidth 600Mbps, current synchronization accuracy ±50ms, no dedicated VLANs.The model vectorizes and weights three types of features through a feature fusion layer (device identification feature weight 0.5, device feature weight 0.3, LAN feature weight 0.2), and then matches them with a preset adaptation rule base (including "4K video device bandwidth guarantee rule" and "cross-vendor protocol conversion rule") through a parameter mapping module, outputting network adaptation parameters: VLAN division: A dedicated VLAN (VLAN ID 100) is assigned to the target device and associated video devices to isolate office equipment traffic and avoid bandwidth contention; Bandwidth allocation: A bandwidth guarantee policy is configured for the target device within VLAN 100, reserving uplink bandwidth of 50Mbps (to ensure 4K video stream transmission), with a burst bandwidth limit of 80Mbps (to cope with content update peaks); Synchronization strategy: The NTP time synchronization frequency is adjusted to 1 minute / time, and PTP precise time protocol is enabled (replacing ordinary NTP), improving the synchronization accuracy to ±5ms (meeting the ±10ms requirement); Protocol compatibility: The protocol conversion module is enabled on the core switch to convert the LG proprietary control protocol of the target device to the MQTT protocol compatible with Samsung guide screens, ensuring cross-vendor device linkage control. The above parameters are distributed from the server to the LAN core switch, access layer switch and target device to complete the network configuration optimization and ensure efficient collaboration between "AD_SCREEN_001" and the LAN environment.
[0134] This invention provides a computer device 100, which includes a processor and a non-volatile memory storing computer instructions. When the computer instructions are executed by the processor, the computer device 100 executes the aforementioned AI-driven local area network device identification method. Figure 2 As shown, Figure 2 This is a structural block diagram of a computer device 100 provided in an embodiment of the present invention. The computer device 100 includes a memory 111, a processor 112, and a communication unit 113.
[0135] To enable data transmission or interaction, the memory 111, processor 112, and communication unit 113 are electrically connected to each other, either directly or indirectly. For example, these components can be electrically connected to each other via one or more communication buses or signal lines.
[0136] For illustrative purposes, the foregoing description has been made with reference to specific embodiments. However, the foregoing illustrative discussions are not intended to be exhaustive or to limit the present disclosure to the precise forms disclosed. Numerous modifications and variations are possible in accordance with the foregoing teachings. These embodiments were chosen and described in order to best illustrate the principles of the present disclosure and its practical application, thereby enabling those skilled in the art to best utilize the disclosure and to employ various embodiments with different modifications to suit a particular intended application.
Claims
1. A method for identifying local area network devices based on artificial intelligence, characterized in that, include: Obtain communication records of the target device and the local area network environment; Determine the associated device file information of the target device from the communication records of the local area network environment; Based on the associated device file information and the target device, a comprehensive device feature map is obtained, and the comprehensive device feature map is loaded into the target device identification model; the target device identification model includes a preset device feature library, and the target device identification model is trained based on the communication records of a known local area network; Using the target device identification model, preset device features corresponding to each network communication entity in the comprehensive device feature map are retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to output the device identification features of the comprehensive device feature map. The device identification features are used to determine the networking adaptation parameters between the target device and the local area network environment.
2. The method according to claim 1, characterized in that, Determining the associated device file information of the target device from the communication records of the local area network environment includes: A current protocol behavior trajectory chain is generated based on the protocol fingerprint identifier of the current network communication entity, and the current protocol behavior trajectory chain is loaded into the protocol awareness encoder; the current network communication entity is the target device or the communication peer device in the communication record of the local area network environment, and the protocol awareness encoder includes an initial device feature set; The protocol-aware encoder retrieves the initial device feature corresponding to the protocol fingerprint identifier of the current network communication entity from the initial device feature set, performs protocol semantic enhancement and feature topology compression on the retrieved initial device feature, and outputs the target device feature of the current network communication entity; the target device feature is obtained by feature space compression of the initial device feature of the network communication entity. Based on the similarity of communication behavior between the target device and the communication peer device, the associated device file information of the target device is determined from the communication records of the local area network environment.
3. The method according to claim 2, characterized in that, The method further includes: Obtain a first protocol behavior trajectory chain and load the first protocol behavior trajectory chain into an initial protocol awareness encoder; the first protocol behavior trajectory chain is obtained based on communication records of a first known local area network, and the initial protocol awareness encoder includes the initial device feature set; Using the initial protocol-aware encoder, the initial device features corresponding to each protocol fingerprint identifier preceding the first trajectory step are retrieved from the initial device feature set. Protocol semantic enhancement and feature topology compression are performed on each retrieved initial device feature to obtain the predicted device features corresponding to the first trajectory step. Protocol semantic mapping is then performed on the predicted device features corresponding to the first trajectory step to obtain the initial network communication entity communication behavior spectrum corresponding to the first trajectory step. The initial network communication entity communication behavior spectrum includes the communication parameter values corresponding to each network communication entity to be verified in the set of network communication entities to be verified. The communication parameter values of the initial network communication entity communication behavior spectrum are reduced to obtain the target device communication behavior spectrum corresponding to the first trajectory step size; the target device communication behavior spectrum includes the first association confidence level corresponding to each network communication entity to be verified in the network communication entity set to be verified, and the network communication entity set to be verified includes the network communication entity corresponding to each protocol fingerprint identifier in the first protocol behavior trajectory chain. From the target device communication behavior spectrum, determine the first association confidence level corresponding to the protocol fingerprint identifier at the first trajectory step in the first protocol behavior trajectory chain; the first trajectory step is determined from the temporal position of each protocol fingerprint identifier in the first protocol behavior trajectory chain, and the first association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the first trajectory step and the leading network communication entity cluster corresponding to the first trajectory step. Based on the first association confidence level corresponding to the protocol fingerprint identifier at each first trajectory step in the first protocol behavior trajectory chain, the first deviation value is obtained; The network weights of the initial protocol-aware encoder are adjusted based on the first deviation value until the first training termination threshold is reached, thus obtaining the protocol-aware encoder.
4. The method according to claim 3, characterized in that, The initial protocol-aware encoder includes a coding layer network, a feature mapping network, a feedforward network, and a fully connected network. The coding layer network is used to retrieve initial device features, the feature mapping network is used for feature topology compression, the feedforward network is used for protocol semantic enhancement, and the fully connected network is used to output the first association confidence. The step of adjusting the network weights of the initial protocol-aware encoder based on the first deviation value until a first training termination threshold is reached to obtain the protocol-aware encoder includes: Based on the first deviation value, adjust the network weights of the feature mapping network, feedforward network, and fully connected network in the initial protocol-aware encoder until the first training termination threshold is reached to obtain the protocol-aware encoder.
5. The method according to claim 2, characterized in that, The method further includes: Obtain the network communication entity metadata corresponding to each network communication entity in the set of network communication entities to be verified. By using a text encoder, feature extraction is performed on the metadata of the network communication entities to obtain the initial device features corresponding to each network communication entity to be verified. The initial device feature set is obtained based on the initial device features corresponding to each network communication entity to be verified.
6. The method according to claim 2, characterized in that, The step of determining the associated device profile information of the target device from the communication records of the local area network environment based on the similarity of communication behavior between the target device and the communication peer device, according to their respective target device characteristics, includes: Based on the communication behavior similarity between the target device and the communication peer device, and in descending order of communication behavior similarity, multiple associated network communication entities of the target device are determined from the communication records of the local area network environment. Each associated network communication entity is arranged chronologically according to its communication timestamp with the local area network environment to obtain the associated device file information of the target device.
7. The method according to claim 1, characterized in that, The method further includes: Obtain the second protocol behavior trajectory chain and load the second protocol behavior trajectory chain into the initial device identification model; the second protocol behavior trajectory chain is obtained based on the communication records of the second known local area network, and the initial device identification model includes the preset device feature library; Using the initial device identification model, preset device features corresponding to each protocol fingerprint identifier preceding the second trajectory step are retrieved from the preset device feature library. Feature fusion and pattern recognition are performed on each retrieved preset device feature to obtain the predicted device feature corresponding to the second trajectory step. Based on the predicted device feature corresponding to the second trajectory step, the second association confidence level corresponding to the protocol fingerprint identifier at the second trajectory step in the second protocol behavior trajectory chain is obtained. The second trajectory step is determined from the temporal position of each protocol fingerprint identifier in the second protocol behavior trajectory chain. The second association confidence level is used to quantify the interaction coupling degree between the network communication entity corresponding to the second trajectory step and the leading network communication entity cluster corresponding to the second trajectory step. Based on the second association confidence level corresponding to the protocol fingerprint identifier at each second trajectory step in the second protocol behavior trajectory chain, the second deviation value is obtained. The network weights of the initial device recognition model are adjusted based on the second deviation value until the second training termination threshold is reached, thereby obtaining the target device recognition model.
8. The method according to claim 7, characterized in that, The initial device identification model includes a coding layer network, a fusion identification network, and a fully connected network. The coding layer network is used to retrieve preset device features, the fusion identification network is used for feature fusion and pattern recognition, and the fully connected network is used to output a second association confidence score. The step of adjusting the network weights of the initial device recognition model based on the second deviation value until the second training termination threshold is reached to obtain the target device recognition model includes: Based on the second deviation value, adjust the network weights of the fusion recognition network and the fully connected network in the initial device recognition model until the second training termination threshold is reached to obtain the target device recognition model.
9. The method according to claim 1, characterized in that, The process of performing feature fusion and pattern recognition on each retrieved preset device feature to output the device identification features of the comprehensive device feature map includes: According to the network communication entity order of the comprehensive device feature map, each preset device feature retrieved is combined to obtain a preset device feature trajectory chain; The preset device feature trajectory chain is subjected to feature fusion and pattern recognition to obtain a network communication entity fusion recognition feature trajectory chain; the network communication entity fusion recognition feature trajectory chain includes network communication entity fusion recognition features that match the number of network communication entities in the integrated device feature map. From the network communication entity fusion identification feature trajectory chain, obtain the network communication entity fusion identification features at the network communication entity location of the target device, and use them as the device identification features of the integrated device feature map.
10. A server system, characterized in that, Includes a server, said server being used to perform the method of any one of claims 1-9.
Citation Information
Patent Citations
Intelligent Internet of Things public security management and control system and method based on multi-source data fusion
CN120263824A
Network attack dynamic detection and security protection method and system based on artificial intelligence
CN120342748A