Resource identification method and related equipment
By constructing a resource sub-graph in the resource graph and using a deep learning model to determine the ownership of IP address nodes, the problem of low accuracy in IP address resource identification in the existing technology is solved, and higher recognition accuracy and model generalization ability are achieved.
Patent Information
- Application Number
- CN202510715308.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-09-12
AI Technical Summary
In the prior art, the IP address resource identification method of an object cannot accurately determine the true ownership of the IP address resource, resulting in poor identification accuracy.
By searching for IP address nodes connected to the target object in the preset resource graph, a resource sub-graph is constructed, and a pre-trained IP address resource identification model is used to determine whether the IP address node is the target node of the target object based on the confidence level. A graph encoder, deep neural network and activation function are used for feature extraction and nonlinear transformation to improve recognition accuracy.
The accuracy of IP address resource identification and the generalization ability of the identification model are improved, ensuring the accurate attribution of IP address resources.
Smart Images

Figure CN120639362A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and in particular to a resource identification method and related equipment. Background Art
[0002] With the rapid development of digitalization, the importance of identifying an object's IP address (Internet Protocol Address) resources has become increasingly prominent. As cybersecurity threats continue to escalate, objects face increasingly complex security challenges. Accurately identifying an object's IP address resources not only effectively prevents potential security risks but also provides real-time security monitoring and response capabilities, helping them protect sensitive data and network resources.
[0003] In existing technology, the method for identifying an object's IP address resources involves first identifying the object's suspicious IP address, then inputting the object's characteristics and the identified suspicious IP address's characteristics into a model to determine whether the IP address is the object's IP address resource. However, this process cannot accurately determine the true ownership of the IP address resource, resulting in poor IP address resource identification accuracy. Summary of the Invention
[0004] The present invention provides a resource identification method for improving the identification efficiency of IP address resources.
[0005] In a first aspect, the present application provides a method for identifying a resource, the method comprising:
[0006] In response to a resource identification instruction sent by a user, determining a target object of a resource to be determined, using the target object as an initial object node, and searching a preset resource map for each IP address node connected to the initial object node, wherein the resource map is used to describe the association relationship between each object and each IP address;
[0007] Searching for each other object node connected to the first IP address node in the resource map, wherein the first IP address node is any one of the IP address nodes;
[0008] Determining, based on the first IP address node and each target object node, resource subgraphs between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node;
[0009] Determining, based on each resource subgraph, whether the first IP address node is a target node of the target object, wherein the target node is the IP address corresponding to the target node belonging to the target object;
[0010] According to each target node of the target object, the IP address resource of the target object is obtained.
[0011] In the embodiment of the present application, by responding to the resource identification instruction sent by the user, the target object of the resource to be determined is determined, the target object is used as the initial object node, and each IP address node connected to the initial object node is searched in the preset resource map, and each other object node connected to any one of the IP address nodes is searched in the resource map to determine the resource sub-map. According to the resource sub-map corresponding to any one IP address node, it is determined whether the any one IP address node is the target node of the target object, and according to each target node of the target object, the IP address resource of the target object is obtained. Thus, in the embodiment of the present application, by determining each IP address node associated with the target object, and each IP address node will judge the ownership relationship between the IP address node and all objects associated with the IP address node, it is determined from multiple dimensions whether the IP address node belongs to the target object, so that the accuracy of the IP address resource determined by the target object can be guaranteed.
[0012] In a possible implementation, determining, based on the first IP address node and each target object node, a resource subgraph between the first IP address node and each target object node, includes:
[0013] In the resource graph, a search is performed with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource sub-graph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes.
[0014] In an embodiment of the present application, by searching in the resource map with the first IP address node as the starting node and the first target object node as the ending node, a resource sub-map between the first IP address node and the first target object node is obtained, thereby ensuring the accuracy of the determined resource map.
[0015] In a possible implementation, determining whether the first IP address node is the target node of the target object according to each resource sub-graph includes:
[0016] Inputting each resource subgraph into a pre-trained IP address resource identification model to obtain confidence scores between the first IP address node and each target object node, wherein the confidence scores represent the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node;
[0017] If the confidence between the first IP address node and the initial object node meets a first specified condition, determining the first IP address node as the target node of the target object;
[0018] Otherwise, it is determined that the first IP address node is not the target node of the target object.
[0019] In the embodiment of the present application, each resource sub-graph is input into a pre-trained IP address resource identification model to obtain the confidence levels between the first IP address node and each target object node. If the confidence level between the first IP address node and the initial object node is the highest among the confidence levels, the first IP address node is determined to be the target node of the target object. Therefore, in the embodiment of the present application, rather than simply determining the relationship between the first IP address node and the target object, the attribution confidence level is determined for all objects associated with the first IP address node, thereby improving the accuracy of the IP address resource determined for the target object.
[0020] In one possible implementation, the pre-trained IP address resource identification model includes a graph encoder, a deep neural network, and an activation function;
[0021] Inputting each resource sub-graph into a pre-trained IP address resource identification model to obtain confidences between the first IP address node and each target object node, respectively, includes:
[0022] Encoding a first resource sub-graph using the graph encoder to obtain a first feature vector of the first resource sub-graph, wherein the first resource sub-graph is any one of the resource sub-graphs;
[0023] Performing feature extraction on the feature vector using the deep neural network to obtain a second feature vector;
[0024] The activation function is used to perform a nonlinear transformation on the second feature vector to obtain the confidence levels between the first IP address node and the second target object node, wherein the second target object node is the target object node included in the first resource subgraph.
[0025] In the embodiment of the present application, by introducing deep metric learning technology, the complex relationship between IP addresses and multiple objects can be effectively captured, thereby improving the accuracy of IP address resource identification.
[0026] In one possible implementation, the graph encoder includes a long short-term memory network (LSTM) module, an average pooling layer, and a fully connected layer; the LSTM module, the average pooling layer, and the fully connected layer are sequentially connected in series;
[0027] The step of encoding the first resource sub-graph by using the graph encoder to obtain a first feature vector of the first resource sub-graph includes:
[0028] Using the LSTM module to perform feature extraction on the first resource sub-graph to obtain multiple feature vectors;
[0029] Aggregating the multiple feature vectors using the average pooling layer to obtain an aggregated feature vector;
[0030] The fully connected layer is used to perform a fully connected operation on the aggregated vector to obtain a first feature vector of the first resource sub-graph.
[0031] In the embodiment of the present application, a comprehensive multi-dimensional feature space is constructed, so that the similarity between objects and IP addresses can be accurately measured, thereby improving the recognition accuracy and the generalization ability of the model, and improving the accuracy of IP address resource identification.
[0032] In one possible implementation, the IP address resource identification model is trained in the following manner:
[0033] Obtaining a training sample, wherein the training sample includes each object and each IP address corresponding to each object;
[0034] Using a first IP address of a first object, searching for other object nodes connected to the first IP address in a preset resource map; wherein the first object is any one of the objects in the training sample, and the first IP address is any one of the IP addresses corresponding to the first object;
[0035] Determine the first IP address, the first object, and the other objects corresponding to the other object nodes as training subsamples corresponding to the first IP address;
[0036] Inputting the training subsample into the IP address resource identification model to obtain prediction confidences between the first IP address and each object to be identified, wherein each object to be identified includes the first object and the other objects;
[0037] Based on the prediction confidences, obtaining a sub-loss value corresponding to the first IP address;
[0038] Obtaining a total loss value of the IP address resource identification model according to each sub-loss value corresponding to each IP address of each object in the training sample;
[0039] If the total loss value does not meet the second specified condition, the model parameters of the IP address resource identification model are adjusted, and the process returns to the step of inputting the training sub-samples into the IP address resource identification model respectively until the total loss value meets the second specified condition, and the training of the IP address resource identification model is terminated.
[0040] In a second aspect, the present application provides a resource identification device, the device comprising:
[0041] A first search module is configured to, in response to a resource identification instruction sent by a user, determine a target object of a resource to be determined, use the target object as an initial object node, and search a preset resource graph for each IP address node connected to the initial object node, wherein the resource graph is used to describe the association relationship between each object and each IP address;
[0042] A second search module is configured to search the resource map for other object nodes connected to the first IP address node, wherein the first IP address node is any one of the IP address nodes;
[0043] a resource subgraph determining module, configured to determine, based on the first IP address node and each target object node, a resource subgraph between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node;
[0044] a judgment module, configured to determine, based on each resource sub-graph, whether the first IP address node is a target node of the target object, wherein the target node is a node whose IP address corresponding to the target node belongs to the target object;
[0045] The IP address resource determination module is used to obtain the IP address resource of the target object according to each target node of the target object.
[0046] In a possible implementation, the resource sub-graph determination module is specifically configured to:
[0047] In the resource graph, a search is performed with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource sub-graph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes.
[0048] In a possible implementation, the judgment module is specifically configured to:
[0049] Inputting each resource subgraph into a pre-trained IP address resource identification model to obtain confidence scores between the first IP address node and each target object node, wherein the confidence scores represent the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node;
[0050] If the confidence between the first IP address node and the initial object node meets a first specified condition, determining the first IP address node as the target node of the target object;
[0051] Otherwise, it is determined that the first IP address node is not the target node of the target object.
[0052] In one possible implementation, the pre-trained IP address resource identification model includes a graph encoder, a deep neural network, and an activation function;
[0053] The judgment module is further configured to:
[0054] Encoding a first resource sub-graph using the graph encoder to obtain a first feature vector of the first resource sub-graph, wherein the first resource sub-graph is any one of the resource sub-graphs;
[0055] Performing feature extraction on the feature vector using the deep neural network to obtain a second feature vector;
[0056] The activation function is used to perform a nonlinear transformation on the second feature vector to obtain the confidence levels between the first IP address node and the second target object node, wherein the second target object node is the target object node included in the first resource subgraph.
[0057] In one possible implementation, the graph encoder includes a long short-term memory network (LSTM) module, an average pooling layer, and a fully connected layer; the LSTM module, the average pooling layer, and the fully connected layer are sequentially connected in series;
[0058] The judgment module is further configured to:
[0059] Performing feature extraction on input data using a first LSTM module to obtain a feature vector, wherein the input data includes a feature vector output by a previous LATM module of the LATM module and / or a feature vector corresponding to two nodes connected by an edge at the same position as the first LSTM module in the first resource subgraph, and the first LATM module is any one of the multiple LSTM modules;
[0060] aggregating, using the average pooling layer, the feature vectors obtained by the tail LSTM modules in the first specified number of LSTM modules and the feature vectors obtained by the tail LSTM modules in the second specified number of LSTM modules to obtain an aggregated feature vector;
[0061] The fully connected layer is used to perform a fully connected operation on the aggregated vector to obtain a first feature vector of the first resource sub-graph.
[0062] In a possible implementation, the device further includes:
[0063] A training module is used to train the IP address resource identification model in the following manner:
[0064] Obtaining a training sample, wherein the training sample includes each object and each IP address corresponding to each object;
[0065] Using a first IP address of a first object, searching for other object nodes connected to the first IP address in a preset resource map; wherein the first object is any one of the objects in the training sample, and the first IP address is any one of the IP addresses corresponding to the first object;
[0066] Determine the first IP address, the first object, and the other objects corresponding to the other object nodes as training subsamples corresponding to the first IP address;
[0067] Inputting the training subsample into the IP address resource identification model to obtain prediction confidences between the first IP address and each object to be identified, wherein the objects to be identified include the other objects and the first object;
[0068] Based on the prediction confidences, obtaining a sub-loss value corresponding to the first IP address;
[0069] Obtaining a total loss value of the IP address resource identification model according to each sub-loss value corresponding to each IP address of each object in the training sample;
[0070] If the total loss value does not meet the second specified condition, the model parameters of the IP address resource identification model are adjusted, and the process returns to the step of inputting the training sub-samples into the IP address resource identification model respectively until the total loss value meets the second specified condition, and the training of the IP address resource identification model is terminated.
[0071] In a third aspect, an embodiment of the present application provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps in the resource identification method when executing the computer program.
[0072] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps in the resource identification method described above in the present application are implemented.
[0073] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which is stored in a computer-readable storage medium; when the processor of a memory access device reads the computer program from the computer-readable storage medium, the processor executes the computer program, causing the memory access device to execute the steps in the above-mentioned resource identification method of the present application.
[0074] For each aspect from the second to the fifth aspect and the technical effects that may be achieved by each aspect, please refer to the above description of the technical effects that can be achieved by various possible solutions in the first aspect, and no further details will be given here. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0076] Figure 1 One of the flow charts of a resource identification method provided in an embodiment of the present application;
[0077] Figure 2 A schematic diagram of a resource map provided in an embodiment of the present application;
[0078] Figure 3 A schematic diagram of a resource sub-graph provided in an embodiment of the present application;
[0079] Figure 4 A schematic diagram of an IP address resource identification model provided in an embodiment of the present application;
[0080] Figure 5 A schematic diagram of a process for determining the confidence levels between the first IP address node and each target object node provided in an embodiment of the present application;
[0081] Figure 6 A schematic diagram of the structure of a graph encoder provided in an embodiment of the present application;
[0082] Figure 7 A schematic diagram of the process of training an IP address resource identification model provided in an embodiment of the present application;
[0083] Figure 8 The second flowchart of the resource identification method provided in the embodiment of the present application;
[0084] Figure 9 A schematic diagram of a resource identification device provided in an embodiment of the present application;
[0085] Figure 10 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0086] In order to make the purpose, technical solutions and advantages of this application more clear, the application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments.
[0087] In the description of this application, "multiple" is understood to mean "at least two." "And / or" describes the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. A and B are connected, which can mean: A and B are directly connected, and A and B are connected through C. In addition, in the description of this application, words such as "first" and "second" are used only for the purpose of distinguishing descriptions and should not be understood as indicating or implying relative importance or order.
[0088] In existing technology, the method for identifying an object's IP address resources involves first identifying the object's suspicious IP address, then inputting the object's characteristics and the identified suspicious IP address's characteristics into a model to determine whether the IP address is the object's IP address resource. However, this process cannot accurately determine the true ownership of the IP address resource, resulting in poor IP address resource identification accuracy.
[0089] In this regard, an embodiment of the present application provides a resource identification method, which determines the target object of the resource to be determined by responding to a resource identification instruction sent by a user, takes the target object as the initial object node, searches for each IP address node connected to the initial object node in a preset resource map, and searches for each other object node connected to any one of the IP address nodes in the resource map, determines a resource sub-map, and determines whether any one of the IP address nodes is the target node of the target object based on the resource sub-map corresponding to the any one IP address node, and obtains the IP address resource of the target object based on each target node of the target object. Thus, in an embodiment of the present application, by determining each IP address node associated with the target object, and each IP address node will judge the ownership relationship between the IP address node and all objects associated with it, it is determined from multiple dimensions whether the IP address node belongs to the target object, which can ensure the accuracy of the IP address resource determined by the target object.
[0090] The present application is described in further detail below with reference to the accompanying drawings. Figure 1 FIG. 1 is a flow chart of a method for identifying an IP address resource provided in an embodiment of the present application. The specific implementation process of the method is as follows:
[0091] Step 101: In response to a resource identification instruction sent by a user, a target object of a resource to be identified is determined, the target object is used as an initial object node, and each IP address node connected to the initial object node is searched in a preset resource map, wherein the resource map is used to describe the association relationship between each object and each IP address;
[0092] In the embodiment of the present application, the resource identification instruction includes the target object.
[0093] Below, we first explain the method of constructing a resource map in the embodiment of this application:
[0094] a. Define the nodes and edges of the resource graph:
[0095] (1) Use a keyword extraction tool to extract keywords from the names of objects in the ICP database (Internet Content Provider Record Database) and keywords from the website data corresponding to each object. Nodes that can be constructed include: object name, website URL, keyword, etc. Edges that can be constructed include: object name-keyword, website URL-keyword, etc.
[0096] The website data corresponding to each object can be determined in the following ways:
[0097] Obtain the names of each object and the primary domain name corresponding to each object name from the ICP database; obtain the historical subdomains corresponding to each object's primary domain name from the DNS (Domain Name System) database. Prefix each obtained domain name (including the primary domain name and subdomain name) with "http: / / " and "https: / / " to obtain the URL (Uniform Resource Locator) corresponding to each domain name. Then, crawl each URL to obtain the website data corresponding to each domain name. This website data includes the website name and website content.
[0098] (2) The ICP database contains the relationship between object names, ICP numbers, and object primary domain names. Therefore, the nodes that can be constructed based on the ICP database include: object name, ICP number, domain name, etc. The edges that can be constructed include: object name-ICP number, ICP number-domain name, etc.
[0099] (3) The DNS database contains the mapping relationship between domain names and IPv4 / IPv6 records. Therefore, the nodes that can be constructed based on the DNS database include: domain name and IP address nodes. Among them, IPv4 records and IPv6 records can be regarded as IP address nodes. The edges that can be constructed include: domain name-IP address, domain name-domain name, etc.
[0100] (4) For the website database (including the website data of each object obtained above), the nodes that can be constructed include: URL, domain name, certificate, IP address, icon, etc. The edges that can be constructed include: URL-domain name, URL-certificate, URL-IP address, URL-icon, etc.
[0101] b. Through the nodes and edges constructed above, we can get the resource map, as shown below: Figure 2 shown.
[0102] It should be noted that: Figure 2 The resource map in the embodiment is only used for illustration and does not limit the resource map in the embodiment of the present application. The resource map in the embodiment of the present application can be set according to specific actual conditions.
[0103] For example, Figure 2 As shown, taking object 1 as the initial object node, the IP address nodes connected to the initial object node 1 in the resource graph include: IP address node a and IP address node b.
[0104] Step 102: Searching for other object nodes connected to the first IP address node in the resource graph, wherein the first IP address node is any one of the IP address nodes;
[0105] For example, Figure 2 As shown, the first IP address node is IP address node a, and the other object nodes connected to the first IP address node in the resource map are: object 2 and object 3.
[0106] Step 103: Based on the first IP address node and each target object node, determine a resource subgraph between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node;
[0107] In the embodiment of the present application, there is a resource sub-graph between each target object node and the first IP address node.
[0108] In one possible implementation, step 103 can be specifically implemented as follows: searching the resource graph with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource sub-graph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes.
[0109] like Figure 2 As shown, the first IP address node is IP address a and the first target object is object 1, then the resource sub-graph is as follows: Figure 3 shown.
[0110] Step 104: Determine, based on each resource sub-graph, whether the first IP address node is a target node of the target object, wherein the target node is the IP address corresponding to the target node belonging to the target object;
[0111] In one possible implementation, step 104 can be specifically implemented as follows: input each resource sub-graph into a pre-trained IP address resource identification model, respectively, to obtain each confidence between the first IP address node and each target object node, wherein the confidence is used to represent the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node; if the confidence between the first IP address node and the initial object node meets a first specified condition, then the first IP address node is determined to be the target node of the target object; otherwise, then the first IP address node is determined not to be the target node of the target object.
[0112] The first specified condition in the embodiment of the present application is that the confidence level is the maximum confidence level among the confidence levels, and the confidence level is greater than a specified threshold. The specified threshold in the embodiment of the present application can be set according to the specific actual situation, and the embodiment of the present application does not limit the specific value of the specified threshold.
[0113] like Figure 4 As shown, the pre-trained IP address resource identification model 400 in the embodiment of the present application includes a graph encoder 401, a deep neural network 402 and an activation function 403. Below, the specific process of inputting each resource sub-graph into the pre-trained IP address resource identification model to obtain the confidence between the first IP address node and each target object node is introduced. Figure 5 As shown in FIG, a specific process diagram may include the following steps:
[0114] Step 501: Encode a first resource sub-graph using the graph encoder to obtain a first feature vector of the first resource sub-graph, wherein the first resource sub-graph is any one of the resource sub-graphs;
[0115] like Figure 6 As shown, it is a structural diagram of a graph encoder. The graph encoder 600 includes a long short-term memory network LSTM module 601, an average pooling layer 602 and a fully connected layer 603; the LSTM module 601, the average pooling layer 602 and the fully connected layer 603 are connected in series in sequence.
[0116] In one possible implementation, step 501 can be specifically implemented as follows: using the LSTM module to extract features from the first resource sub-graph to obtain multiple feature vectors, using the average pooling layer to aggregate the multiple feature vectors to obtain an aggregated feature vector; using the fully connected layer to perform a full connection operation on the aggregated vector to obtain the first feature vector of the first resource sub-graph.
[0117] In the embodiment of the present application, the LSTM module is used to extract features from the first resource sub-graph to obtain multiple feature vectors, which is specifically implemented as follows:
[0118] Traverse the edges in any path in the first resource sub-graph in a specified order. For any traversed edge, input the feature data corresponding to the edge into the LSTM module to obtain a first feature vector, where the feature data corresponding to the edge includes the initial feature vectors corresponding to the two nodes connected by the edge and the first feature vector obtained from the previous edge of the edge in the first resource sub-graph; determine whether the edge is the last edge in any one of the paths. If not, continue to traverse the edges in any one of the paths in the specified order; if so, determine the first feature vector obtained from the edge as the feature vector.
[0119] In an embodiment of the present application, each path in the first resource sub-graph obtains a feature vector. The number of paths in the first resource sub-graph is the same as the number of multiple feature vectors obtained by the LSTM module. In an embodiment of the present application, using the average pooling layer to aggregate the multiple feature vectors to obtain an aggregated feature vector is actually using the average pooling layer to aggregate the feature vectors obtained from each path to obtain an aggregated feature vector.
[0120] The specified order in an embodiment of the present application is the order starting from the IP address node.
[0121] In an embodiment of the present application, the two nodes connected by each edge in the resource graph include the following:
[0122] <head = keyword, tail = URL>, <head = object name, tail = ICP number>, <head = ICP number, tail = object name>, <head = IC number, tail = domain>, <head = domain, tail = ICP number>, <head = domain, tail = IP address>, <head = IP address, tail = domain> <head = domain, tail = domain>, <head = URL, tail = domain>, <head = domain, tail = URL>, <head = URL, tail = certificate>, <head = certificate, tail = URL>, <head = URL, tail = IP address>, <head = IP address, tail = URL>, <head = URL, tail = icon>, <head = icon, tail = URL>.
[0123] The initial feature vectors corresponding to the two nodes connected by each edge in an embodiment of the present application are preset. In an embodiment of the present application, the initial feature vectors are not limited herein, and the specific values of the initial feature vectors in an embodiment of the present application can be set according to specific actual situations.
[0124] Therefore, in the embodiment of the present application, the type relationship between connected nodes is modeled, thereby reducing the number of nodes that need to be coded. This reduces model complexity, improves data processing efficiency, and ensures the accuracy of the model in identifying IP address ownership, allowing objects to more effectively identify resources.
[0125] Step 502: Using the deep neural network to perform feature extraction on the feature vector to obtain a second feature vector;
[0126] The deep neural network in the embodiment of the present application is DNN, but the structure of the deep neural network is not limited in the embodiment of the present application.
[0127] Step 503: Use the activation function to perform a nonlinear transformation on the second feature vector to obtain the confidence levels between the first IP address node and the second target object node, wherein the second target object node is the target object node included in the first resource sub-graph.
[0128] The activation function is not limited in the embodiments of the present application. The activation function in the embodiments of the present application can be set according to specific actual conditions.
[0129] Next, the training method of the IP address resource identification model in the embodiment of the present application is introduced. Figure 7 The above is a flow chart of training an IP address resource identification model, which may specifically include the following steps:
[0130] Step 701: Acquire a training sample, wherein the training sample includes each object and each IP address corresponding to each object;
[0131] Step 702: Using a first IP address of a first object, search for other object nodes connected to the first IP address in a preset resource graph; wherein the first object is any one of the objects in the training sample, and the first IP address is any one of the IP addresses corresponding to the first object;
[0132] Step 703: Determine the first IP address, the first object, and the other object nodes as training subsamples corresponding to the first IP address;
[0133] The first object in the embodiment of the present application is the object to which the first IP address belongs.
[0134] Step 704: Input the training subsample into the IP address resource identification model to obtain prediction confidences between the first IP address and each object to be identified, wherein the objects to be identified include the other objects and the first object.
[0135] Step 705: Obtaining a sub-loss value corresponding to the first IP address based on the prediction confidences;
[0136] In one possible implementation, step 705 may be specifically implemented as follows: obtaining a first sub-loss value based on each prediction confidence, and obtaining a second sub-loss value based on each prediction confidence; and adding the first sub-loss value and the second sub-loss value to obtain the sub-loss value. The sub-loss value corresponding to the first IP address may be obtained using formula (1):
[0137]
[0138] Where L1 is the first sub-loss value, N is the total number of IP addresses in the training sample, is the prediction confidence between the first IP address and the first target object, is the prediction confidence between the first IP address and other objects j, and k is the number of other objects.
[0139] The second sub-loss value in the embodiment of the present application can be obtained by formula (2):
[0140]
[0141] Wherein, L2 is the second sub-loss value.
[0142] Step 706: Obtaining a total loss value of the IP address resource identification model based on the sub-loss values corresponding to the IP addresses of the objects in the training sample;
[0143] In one possible implementation, step 706 can be specifically implemented as follows: for any object, the average value of each loss value of each IP address corresponding to the any object is determined as the loss value of the any object, and the average value of the loss values corresponding to each object is determined as the total loss value of the IP address resource identification model.
[0144] Step 707: Determine whether the total loss value meets the second specified condition. If yes, end the process. If not, proceed to step 708.
[0145] Step 708: After adjusting the model parameters of the IP address resource identification model, return to step 704.
[0146] The second specified condition in the embodiment of the present application is that the total loss value is greater than the first specified threshold and / or the difference between the total loss value and the total loss value obtained multiple times previously is not greater than the second specified value.
[0147] The embodiments of the present application do not limit the numerical value of multiple times and can be set according to specific actual conditions.
[0148] Step 105: Obtain the IP address resource of the target object according to each target node of the target object.
[0149] In a possible implementation, step 105 may be specifically implemented as: determining the IP address corresponding to each target node of the target object as the IP address resource of the target object.
[0150] The following combination Figure 8 The resource identification method in the embodiment of the present application is described in detail, which may include the following steps:
[0151] Step 801: In response to a resource identification instruction sent by a user, a target object of a resource to be identified is determined, and with the target object as an initial object node, each IP address node connected to the initial object node is searched in a preset resource map, wherein the resource map is used to describe the association relationship between each object and each IP address;
[0152] Step 802: Searching for other object nodes connected to the first IP address node in the resource graph, wherein the first IP address node is any one of the IP address nodes;
[0153] Step 803: Searching the resource graph with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource subgraph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes;
[0154] Step 804: Input each resource subgraph into a pre-trained IP address resource identification model to obtain confidence levels between the first IP address node and each target object node, wherein the confidence level represents the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node.
[0155] Step 805: Determine whether the confidence between the first IP address node and the initial object node meets a first specified condition. If so, execute step 806; if not, execute step 807.
[0156] Wherein, the target node is the IP address corresponding to the target node belonging to the target object;
[0157] Step 806: Determine the first IP address node as the target node of the target object;
[0158] Step 807: Determine that the first IP address node is not the target node of the target object;
[0159] Step 808: Obtain the IP address resource of the target object according to each target node of the target object.
[0160] Based on the same inventive concept, this application also provides a resource identification device, such as Figure 9 As shown, the apparatus 900 includes:
[0161] A first search module 910 is configured to, in response to a resource identification instruction sent by a user, determine a target object of a resource to be determined, use the target object as an initial object node, and search a preset resource graph for each IP address node connected to the initial object node, wherein the resource graph is used to describe the association between each object and each IP address;
[0162] A second search module 920 is configured to search the resource graph for other object nodes connected to the first IP address node, wherein the first IP address node is any one of the IP address nodes;
[0163] A resource subgraph determining module 930 is configured to determine, based on the first IP address node and each target object node, a resource subgraph between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node;
[0164] A judgment module 940 is configured to determine, based on each resource sub-graph, whether the first IP address node is a target node of the target object, wherein the target node is a node whose IP address corresponding to the target node belongs to the target object;
[0165] The IP address resource determination module 950 is configured to obtain the IP address resource of the target object according to each target node of the target object.
[0166] In a possible implementation, the resource sub-graph determination module 930 is specifically configured to:
[0167] In the resource graph, a search is performed with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource sub-graph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes.
[0168] In a possible implementation, the determination module 940 is specifically configured to:
[0169] Inputting each resource subgraph into a pre-trained IP address resource identification model to obtain confidence scores between the first IP address node and each target object node, wherein the confidence scores represent the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node;
[0170] If the confidence between the first IP address node and the initial object node meets a first specified condition, determining the first IP address node as the target node of the target object;
[0171] Otherwise, it is determined that the first IP address node is not the target node of the target object.
[0172] In one possible implementation, the pre-trained IP address resource identification model includes a graph encoder, a deep neural network, and an activation function;
[0173] The judgment module 940 is further configured to:
[0174] Encoding a first resource sub-graph using the graph encoder to obtain a first feature vector of the first resource sub-graph, wherein the first resource sub-graph is any one of the resource sub-graphs;
[0175] Performing feature extraction on the feature vector using the deep neural network to obtain a second feature vector;
[0176] The activation function is used to perform a nonlinear transformation on the second feature vector to obtain the confidence levels between the first IP address node and the second target object node, wherein the second target object node is the target object node included in the first resource subgraph.
[0177] In one possible implementation, the graph encoder includes a long short-term memory network (LSTM) module, an average pooling layer, and a fully connected layer; the LSTM module, the average pooling layer, and the fully connected layer are sequentially connected in series;
[0178] The judgment module 940 is further configured to:
[0179] Performing feature extraction on input data using a first LSTM module to obtain a feature vector, wherein the input data includes a feature vector output by a previous LATM module of the LATM module and / or a feature vector corresponding to two nodes connected by an edge at the same position as the first LSTM module in the first resource subgraph, and the first LATM module is any one of the multiple LSTM modules;
[0180] aggregating, using the average pooling layer, the feature vectors obtained by the tail LSTM modules in the first specified number of LSTM modules and the feature vectors obtained by the tail LSTM modules in the second specified number of LSTM modules to obtain an aggregated feature vector;
[0181] The fully connected layer is used to perform a fully connected operation on the aggregated vector to obtain a first feature vector of the first resource sub-graph.
[0182] In a possible implementation, the device further includes:
[0183] The training module 960 is configured to train the IP address resource identification model by:
[0184] Obtaining a training sample, wherein the training sample includes each object and each IP address corresponding to each object;
[0185] Using a first IP address of a first object, searching for other object nodes connected to the first IP address in a preset resource map; wherein the first object is any one of the objects in the training sample, and the first IP address is any one of the IP addresses corresponding to the first object;
[0186] Determine the first IP address, the first object, and the other objects corresponding to the other object nodes as training subsamples corresponding to the first IP address;
[0187] Inputting the training subsample into the IP address resource identification model to obtain prediction confidences between the first IP address and each object to be identified, wherein the objects to be identified include the other objects and the first object;
[0188] Based on the prediction confidences, obtaining a sub-loss value corresponding to the first IP address;
[0189] Obtaining a total loss value of the IP address resource identification model according to each sub-loss value corresponding to each IP address of each object in the training sample;
[0190] If the total loss value does not meet the second specified condition, the model parameters of the IP address resource identification model are adjusted, and the process returns to the step of inputting the training sub-samples into the IP address resource identification model respectively until the total loss value meets the second specified condition, and the training of the IP address resource identification model is terminated.
[0191] Based on the same inventive concept, an electronic device is also provided in the embodiment of the present application. The electronic device can realize the function of the aforementioned resource identification device, refer to Figure 10 , the electronic device includes:
[0192] At least one processor 1001, and a memory 1002 connected to the at least one processor 1001. The specific connection medium between the processor 1001 and the memory 1002 is not limited in the embodiment of the present application. Figure 10 In the example, the processor 1001 and the memory 1002 are connected via the bus 1000. Figure 10 The bus 1000 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 10 The diagram is represented by only one thick line, but this does not mean that there is only one bus or one type of bus. Alternatively, the processor 1001 may also be referred to as a controller, without limitation to the name.
[0193] In the embodiment of the present application, the memory 1002 stores instructions that can be executed by at least one processor 1001. The at least one processor 1001 can execute the resource identification method discussed above by executing the instructions stored in the memory 1002. The processor 1001 can implement Figure 9 The functions of each module in the device shown.
[0194] Among them, the processor 1001 is the control center of the device, which can use various interfaces and lines to connect the various parts of the entire control device, and monitor the device as a whole by running or executing instructions stored in the memory 1002 and calling data stored in the memory 1002, the various functions of the device and processing data.
[0195] In one possible design, processor 1001 may include one or more processing units. Processor 1001 may integrate an application processor and a modem processor. The application processor primarily processes the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 1001. In some embodiments, processor 1001 and memory 1002 may be implemented on the same chip. In some embodiments, they may also be implemented on separate chips.
[0196] The processor 1001 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the resource identification method disclosed in the embodiments of the present application can be directly embodied as a hardware processor for execution, or can be executed by a combination of hardware and software modules in the processor.
[0197] Memory 1002 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules. Memory 1002 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. Memory 1002 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 1002 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.
[0198] By designing and programming the processor 1001, the code corresponding to the resource identification method described in the above embodiment can be fixed into the chip, so that the chip can execute the code when running. Figure 1The steps of the resource identification method of the embodiment shown are as follows: How to design and program the processor 1001 is a technique well known to those skilled in the art and will not be described in detail here.
[0199] An embodiment of the present application also provides a computer-readable storage medium that stores computer-executable instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.
[0200] In some possible implementations, various aspects of the resource identification method provided in the present application can also be implemented in the form of a program product, which includes program code. When the above-mentioned program product is run on an electronic device, the above-mentioned program code is used to enable the above-mentioned electronic device to execute the steps of the resource identification method according to various exemplary embodiments of the present application described above in this specification.
[0201] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, devices, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0202] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0203] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0204] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0205] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0206] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for identifying a resource, characterized in that: The method comprises: In response to a resource identification instruction sent by a user, determining a target object of a resource to be determined, using the target object as an initial object node, and searching a preset resource map for each IP address node connected to the initial object node, wherein the resource map is used to describe the association relationship between each object and each IP address; Searching for each other object node connected to the first IP address node in the resource map, wherein the first IP address node is any one of the IP address nodes; Determining, based on the first IP address node and each target object node, resource subgraphs between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node; Determining, based on each resource subgraph, whether the first IP address node is a target node of the target object, wherein the target node is the IP address corresponding to the target node belonging to the target object; According to each target node of the target object, the IP address resource of the target object is obtained.
2. The method according to claim 1, characterized in that The determining, based on the first IP address node and each target object node, a resource subgraph between the first IP address node and each target object node, includes: In the resource graph, a search is performed with the first IP address node as the starting node and the first target object node as the ending node to obtain a resource sub-graph between the first IP address node and the first target object node, wherein the first target object node is any one of the target object nodes.
3. The method according to claim 1, characterized in that The determining, based on each resource sub-graph, whether the first IP address node is the target node of the target object includes: Inputting each resource subgraph into a pre-trained IP address resource identification model to obtain confidence scores between the first IP address node and each target object node, wherein the confidence scores represent the probability that the IP address corresponding to the first IP address node belongs to the object corresponding to the target object node; If the confidence between the first IP address node and the initial object node meets a first specified condition, determining the first IP address node as the target node of the target object; Otherwise, it is determined that the first IP address node is not the target node of the target object.
4. The method according to claim 3, characterized in that The pre-trained IP address resource identification model includes a graph encoder, a deep neural network and an activation function; Inputting each resource sub-graph into a pre-trained IP address resource identification model to obtain confidences between the first IP address node and each target object node, respectively, includes: Encoding a first resource sub-graph using the graph encoder to obtain a first feature vector of the first resource sub-graph, wherein the first resource sub-graph is any one of the resource sub-graphs; Performing feature extraction on the feature vector using the deep neural network to obtain a second feature vector; The activation function is used to perform a nonlinear transformation on the second feature vector to obtain the confidence levels between the first IP address node and the second target object node, wherein the second target object node is the target object node included in the first resource subgraph.
5. The method according to claim 4, characterized in that The graph encoder includes a long short-term memory network LSTM module, an average pooling layer and a fully connected layer; the LSTM module, the average pooling layer and the fully connected layer are sequentially connected in series; The step of encoding the first resource sub-graph by using the graph encoder to obtain a first feature vector of the first resource sub-graph includes: Using the LSTM module to perform feature extraction on the first resource sub-graph to obtain multiple feature vectors; Aggregating the multiple feature vectors using the average pooling layer to obtain an aggregated feature vector; The fully connected layer is used to perform a fully connected operation on the aggregated vector to obtain a first feature vector of the first resource sub-graph.
6. The method according to claim 3 or 4, characterized in that The IP address resource identification model is trained in the following manner: Obtaining a training sample, wherein the training sample includes each object and each IP address corresponding to each object; Using a first IP address of a first object, searching for other object nodes connected to the first IP address in a preset resource map; wherein the first object is any one of the objects in the training sample, and the first IP address is any one of the IP addresses corresponding to the first object; Determine the first IP address, the first object, and the other objects corresponding to the other object nodes as training subsamples corresponding to the first IP address; Inputting the training subsample into the IP address resource identification model to obtain prediction confidences between the first IP address and each object to be identified, wherein the objects to be identified include the other objects and the first object; Based on the prediction confidences, obtaining a sub-loss value corresponding to the first IP address; Obtaining a total loss value of the IP address resource identification model according to each sub-loss value corresponding to each IP address of each object in the training sample; If the total loss value does not meet the second specified condition, the model parameters of the IP address resource identification model are adjusted, and the process returns to the step of inputting the training sub-samples into the IP address resource identification model respectively until the total loss value meets the second specified condition, and the training of the IP address resource identification model is terminated.
7. A resource identification device, characterized in that: The device comprises: A first search module is configured to, in response to a resource identification instruction sent by a user, determine a target object of a resource to be determined, use the target object as an initial object node, and search a preset resource graph for each IP address node connected to the initial object node, wherein the resource graph is used to describe the association relationship between each object and each IP address; A second search module is configured to search the resource map for other object nodes connected to the first IP address node, wherein the first IP address node is any one of the IP address nodes; a resource subgraph determining module, configured to determine, based on the first IP address node and each target object node, a resource subgraph between the first IP address node and each target object node, wherein each target object node includes the initial object node and each other object node, and the number of each resource subgraph is the same as the number of each target object node; a judgment module, configured to determine, based on each resource sub-graph, whether the first IP address node is a target node of the target object, wherein the target node is a node whose IP address corresponding to the target node belongs to the target object; The IP address resource determination module is used to obtain the IP address resource of the target object according to each target node of the target object.
8. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the method according to any one of claims 1 to 6 when executing the computer program stored in the memory.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product, characterized in that The computer program product comprises: a computer program code, and when the computer program code is run on a computer, the computer is enabled to execute the method according to any one of claims 1 to 6.