Message identification method, network equipment and storage medium

By obtaining the target server address of the encrypted message and determining its corresponding target domain name, the problem of the router being unable to identify the application to which the encrypted message belongs is solved, and the accuracy of Internet access time statistics is improved.

CN120751037AActive Publication Date: 2025-10-03HONOR DEVICE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202410678456.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-28
Publication Date
2025-10-03
Estimated Expiration
2044-05-28

AI Technical Summary

Technical Problem

The router cannot identify the application to which the encrypted message belongs, resulting in inaccurate Internet access time statistics.

Method used

By obtaining the target server address of the encrypted message and determining its corresponding target domain name, the target application is identified, and the corresponding relationship between the server address and the domain name is used to identify the encrypted message.

Benefits of technology

The accuracy of statistics on the duration of Internet access on terminal devices is improved, and the possibility of missing encrypted message identification is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751037A_ABST
    Figure CN120751037A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a message identification method, network equipment and a storage medium. The message identification method comprises the steps that a target server address corresponding to a target message sent by terminal equipment is acquired, and the target message comprises a message with an encrypted message body; determining a target domain name corresponding to the target server address; and determining a target application in the terminal device based on the target domain name, wherein the target application is an application for sending the target message. According to the message identification method, the network device and the storage medium provided by the invention, the target message, especially the encrypted message, can be identified, so that the application to which the target message belongs can be determined, and the accuracy of statistics of the Internet surfing duration of the application of the terminal device is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a message identification method, network equipment and storage medium. Background Art

[0002] At present, terminal devices (such as mobile phones, tablets, etc.) can achieve wireless Internet access through routers. At the same time, the router can count the Internet access time of the terminal devices connected to the router, thereby realizing functions such as anti-addiction and child Internet protection. When the router counts the Internet access time of the terminal device, it often needs to count the interactive messages sent between the application of the terminal device and the server corresponding to the application. When the router needs to count the Internet access time of different applications of the terminal device, the router needs to identify the message sent by the terminal device to determine the application sending the message, so as to count the Internet access time of the application.

[0003] However, some applications in terminal devices send encrypted messages, and routers cannot decrypt the encrypted messages, resulting in the inability to determine the application to which the encrypted messages belong. As a result, the router will miss the application corresponding to the encrypted message when counting the Internet access time, affecting the accuracy of the router's statistics on the Internet access time of the terminal device's application. Summary of the Invention

[0004] In order to solve the above problems, the present application provides a message identification method, network device and storage medium, which can identify target messages, especially encrypted messages, so as to determine the application to which the target message belongs and improve the accuracy of the statistics of the application Internet access time of the terminal device.

[0005] In order to achieve the above-mentioned objectives, in the first aspect, the present application provides a message identification method, including: obtaining a target server address corresponding to a target message sent by a terminal device, the target message including a message body whose encrypted message body; determining a target domain name corresponding to the target server address; and determining a target application in the terminal device based on the target domain name, the target application being the application that sends the target message.

[0006] In this embodiment, the target server address in the unencrypted portion of the target message can be obtained to determine the target domain name corresponding to the target server address, and the target application to which the target message belongs can be determined based on the target domain name. This allows the target application corresponding to the target message to be identified without parsing the target message, improving target message recognition efficiency, reducing the possibility of missing target message identification, and improving the accuracy of the router's application usage time statistics.

[0007] In an optional embodiment, determining the target domain name corresponding to the target server address includes: determining the target domain name corresponding to the target server address based on the target server address and a first list, wherein the first list includes a plurality of correspondences between server addresses and domain names, and each server address corresponds to at least one domain name. In this way, the target domain name corresponding to the target server address can be determined based on the correspondences between the server addresses and domain names recorded in the first list.

[0008] In an optional embodiment, determining a target domain name corresponding to the target server address based on the target server address and the first list includes: querying the first list; and if the first list includes a domain name corresponding to the target server, determining the domain name corresponding to the target server address as the target domain name. In this way, the target domain name corresponding to the target server address can be directly determined, facilitating subsequent confirmation of the target application.

[0009] In an optional embodiment, the first list also includes an application identifier corresponding to each domain name, and the target domain name corresponding to the target server address is determined based on the target server address and the first list, further comprising: when the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are the same, selecting any domain name corresponding to the target server address as the target domain name. In this way, when the domain name corresponding to the target server address is not unique, it is possible to determine whether multiple domain names belong to the same application through the application identifier corresponding to the domain name. If the application identifiers corresponding to multiple domain names are the same, it means that the multiple domain names belong to the same application, and any domain name can be selected as the target domain name.

[0010] In an optional embodiment, the first list also includes an application identifier corresponding to each domain name, and the target domain name corresponding to the target server address is determined based on the target server address and the first list, and further includes: when the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, determining the multiple domain names corresponding to the target server address as pre-selected domain names; determining the target domain name based on the multiple pre-selected domain names and the second list, the second list includes multiple groups of domain names and server addresses and the status of the server addresses, and one domain name corresponds to at least one server address. In this way, when the domain name corresponding to the target server address is not unique, it can be determined whether the multiple domain names belong to the same application through the application identifier corresponding to the domain name. If the application identifiers corresponding to the multiple domain names are different, it means that the multiple domain names belong to different applications. The multiple domain names can be used as pre-selected domain names to narrow the application range corresponding to the target message, and then the target domain name among the pre-selected domain names is determined through the second list that records the correspondence between the domain name and the server address and the status of the server address.

[0011] In an optional embodiment, determining a target domain name based on multiple pre-selected domain names and a second list includes: querying the second list; determining the status of all server addresses corresponding to each of the multiple pre-selected domain names, where the server address status includes an active state and an idle state; and determining one of the multiple pre-selected domain names as the target domain name, where the status of all server addresses corresponding to the target domain name is an active state. In this way, the pre-selected domain name can be determined as the target domain name based on the status of the server addresses corresponding to each pre-selected domain name in the second list.

[0012] In an optional embodiment, the method for determining the status of the server address in the second list includes: monitoring system connection tracking information; when monitoring the system establishing connection tracking, determining that the status of the server address in the second list corresponding to the destination server address in the connection tracking is active; when monitoring the system deleting connection tracking, determining that the status of the server address in the second list corresponding to the destination server address in the connection tracking is idle. In this way, the status of the server addresses in the second list can be determined by monitoring the connection tracking, so as to facilitate the determination of the status of each server address.

[0013] In an optional embodiment, determining a target application in a terminal device based on a target domain name includes determining the target application based on the target domain name and an application identifier corresponding to the target domain name. This allows the target application to be determined based on the application identifier corresponding to the target domain name, improving identification efficiency and facilitating subsequent processing of online time statistics.

[0014] In an optional embodiment, the method further includes updating the service attributes of the target application in the connection tracking information corresponding to the target server address, where the service attributes include an application identifier and a service type. This allows the router to determine the application and service type to which the connection tracking belongs when subsequently collecting statistics on online time, thereby facilitating online time statistics for the application and service type to which the target message belongs, effectively counting the actual time the terminal device used the application, and thus avoiding omissions and inaccuracies.

[0015] In an optional embodiment, the method for determining the first list includes: reading a domain name response message, where the domain name response message is a response message sent by a domain name server in response to a domain name resolution request from a terminal device, and the domain name response message includes a correspondence between domain names and server addresses; and recording the server addresses and the domain names corresponding to the server addresses to form the first list. In this way, the correspondence between domain names and server addresses can be obtained using the domain name response message, thereby facilitating the formation of the first list.

[0016] In one optional embodiment, the first list includes a first hash table, wherein the server address is a key value of the first hash table, and at least one domain name is an associated value of the first hash table. The server address and the domain name corresponding to the server address form a first key-value pair of the first hash table. The first hash table includes multiple first hash buckets, each of which can store a first key-value pair. This facilitates storage of the correspondence between the server address and the domain name, facilitates subsequent queries, and improves query efficiency.

[0017] In an optional embodiment, a method for storing the first key-value pair in the first hash bucket includes: obtaining a first value based on the server address, where the first value is an integer; dividing the first value by the total number of the first hash bucket to obtain a remainder result; and storing the first key-value pair corresponding to the remainder result in the first hash bucket subscripted with the remainder result. In this way, the first key-value pair can be stored in the designated first hash bucket, thereby facilitating subsequent queries using the same method and improving query efficiency.

[0018] In an optional embodiment, the method for storing the first key-value pair in the first hash bucket further includes: if the first hash bucket indexed by the remainder result already stores other first key-value pairs, sequentially traversing the first hash buckets backward and storing the first key-value pair corresponding to the remainder result in the first unused first hash bucket. In this way, when different server addresses correspond to the same remainder result, different server addresses can be stored in different first hash buckets to resolve hash conflicts.

[0019] In an optional embodiment, the method for storing the key-value pairs in the first hash bucket further includes: if the number of first hash buckets storing the first key-value pairs exceeds a set threshold, increasing the number of first hash buckets. In this way, when the number of first key-value pairs is large, the first hash table can be expanded in a timely manner, thereby avoiding a situation where the number of first key-value pairs exceeds the number of first hash buckets, resulting in an inability to store the first key-value pairs.

[0020] In one optional embodiment, the second list includes a second hash table, wherein the domain name is a key value of the second hash table, and at least one server address and the status of the server address are associated values ​​of the second hash table. The domain name, the server address corresponding to the domain name, and the status of the server address form a second key-value pair of the second hash table. The second hash table includes multiple second hash buckets, each of which stores a second key-value pair. This facilitates storage of the correspondence between the domain name, the server address, and the server address status, and also facilitates subsequent queries, improving query efficiency.

[0021] In an optional embodiment, the target message includes a Secure Sockets Layer (SSL) encrypted message and / or a Transport Layer Security (TLS) encrypted message. In this way, the Secure Sockets Layer (SSL) encrypted message and / or the Transport Layer Security (TLS) encrypted message can be identified.

[0022] In order to achieve the above-mentioned purpose, in a second aspect, the present application provides a network device, comprising: a memory and one or more processors; the memory is coupled to the processor; wherein computer program code is stored in the memory, and the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the network device executes the message identification method provided in the first aspect above.

[0023] In order to achieve the above-mentioned purpose, in a third aspect, the present application provides a computer-readable storage medium, including computer instructions. When the computer instructions are executed on a network device, the network device executes the message identification method provided in the first aspect above.

[0024] In order to achieve the above-mentioned objectives, in a fourth aspect, the present application provides a computer program product, which, when executed on a computer, enables the computer to execute the message identification method provided in the first aspect above.

[0025] It can be understood that the beneficial effects that can be achieved by the technical solutions provided in the second to fourth aspects mentioned above can be referred to the beneficial effects in the first aspect and any of its optional implementations, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0027] Figure 1 This is a schematic diagram of a wireless Internet access scenario of a terminal device provided in this embodiment;

[0028] Figure 2 This is a schematic diagram of a terminal device's Internet access duration statistics function provided by this embodiment;

[0029] Figure 3 This is a schematic diagram of the first structure of a network device provided by this embodiment;

[0030] Figure 4 This is the first flow chart of a message identification method provided by this embodiment;

[0031] Figure 5 This is a second flow chart of a message identification method provided in this embodiment;

[0032] Figure 6 This is a schematic diagram of a domain name resolution process provided by this embodiment;

[0033] Figure 7 is a schematic diagram of the first list provided in this embodiment;

[0034] Figure 8 This is the third flow chart of a message identification method provided in this embodiment;

[0035] Figure 9 is a schematic diagram of the second list provided in this embodiment;

[0036] Figure 10 This is the fourth flow chart of a message identification method provided in this embodiment;

[0037] Figure 11 This is the fifth flow chart of a message identification method provided in this embodiment;

[0038] Figure 12 This is a second structural diagram of a network device provided in this embodiment;

[0039] Figure 13 It is a structural diagram of a message identification device provided in this embodiment. DETAILED DESCRIPTION

[0040] The following will clearly describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments of the present application, other embodiments obtained by ordinary technicians in this field without making any creative work are all within the scope of protection of this application.

[0041] Hereinafter, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature identified with "first," "second," etc., may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "plurality" means two or more.

[0042] In addition, in this application, directional terms such as "upper", "lower", "inner" and "outer" are defined relative to the orientation of the components in the drawings. It should be understood that these directional terms are relative concepts. They are used for relative description and clarification, and they can change accordingly according to changes in the orientation of the components in the drawings.

[0043] Figure 1This is a schematic diagram of a wireless Internet access scenario of a terminal device provided in this embodiment.

[0044] like Figure 1 As shown, currently, the terminal device 100 can connect to the router 200 through wireless communication technology, and use the router 200 to achieve wireless connection to the Internet 300, so as to achieve the Internet access function of the terminal device 100. Among them, the wireless communication technology includes but is not limited to: wireless local area networks (WLAN), wireless fidelity (Wi-Fi) network, Bluetooth (BT), fifth generation mobile communication technology (5G th Generation mobile networks or 5th generation wireless systems, referred to as 5G), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc.

[0045] It is worth noting that the terminal device 100 can be a mobile phone, a tablet computer, a handheld computer, a personal computer (PC), an ultra-mobile personal computer (UMPC), a netbook, a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) device, a virtual reality (VR) device, an artificial intelligence (AI) device, a wearable device, an in-vehicle device, etc. The embodiment of the present application does not impose any special restrictions on the specific type of the terminal device 100.

[0046] Specifically, the main interface 101 of the terminal device 100 can display multiple application icons, such as a clock icon, a calendar icon, a gallery icon, a memo icon, a file management icon, a browser icon, a smart life icon, etc. The main interface 101 can also be used to display power, time, network signal, etc.

[0047] For example, when the terminal device 100 receives a user click on the browser icon 1011 in the main interface 101, the terminal device 100 launches the browser application. The browser application of the terminal device 100 can establish communication with the server corresponding to the browser application through the router 200, and the data packets that need to be exchanged and transmitted between the browser application and the server corresponding to the browser application are also forwarded by the router 200. The data packets exchanged between the browser application and the server can also be called messages.

[0048] Furthermore, in addition to enabling wireless Internet access for the terminal device 100, the router 200 can also collect statistics on the Internet access information of the terminal device 100. In this way, the router 200 can also collect statistics on the Internet access time of the terminal device 100, allowing the user to understand and control the Internet access time of a specified terminal device 100 or a specified application.

[0049] Figure 2 This is a schematic diagram of an Internet access duration statistics function of a terminal device provided in this embodiment.

[0050] Combine Figure 1 and Figure 2 As shown, for example, the Internet usage duration statistics function of the terminal device 100 can be included in the smart life application.

[0051] like Figure 2 As shown in (a) of FIG, the main interface 101 of the terminal device 100 may include a smart life icon 1012. The terminal device 100 responds to the user's first click operation 401 to start the smart life application and causes the screen displayed by the terminal device 100 to be changed from Figure 2 The main interface 101 shown in (a) switches to Figure 2 The first click operation 401 is to click the smart life icon 1012 in the main interface 101. The smart life application interface 102 will display smart devices that can establish communication connections with the terminal device 100, such as TVs, speakers, projectors, and routers 200. At the same time, the smart life application interface 102 will also display the name, location, and online status of each smart device. Figure 2 For example, the living room router icon 1021 in (b) of FIG. 1 shows the name of the smart device as "Living Room Router," the online status as "Online," and the location of the router 200 as "Living Room." This allows the user to access basic information about the living room router through the terminal device 100.

[0052] In response to the user's second click operation 402 on the router icon 1021 in the living room, the terminal device 100 changes the screen displayed by the terminal device 100 from Figure 2 The smart life application interface 102 shown in (b) switches to Figure 2 The living room router interface 103 is shown in (c) of FIG. The second click operation 402 is clicking the living room router icon 1021 on the smart life application interface 102. The living room router interface 103 displays multiple function icons, including a children's internet function icon 1031. The children's internet function can provide child protection, such as anti-addiction protection, for devices connected to the living room router 200.

[0053] In response to the user's third click operation 403 on the children's online function icon 1031, the terminal device 100 changes the screen displayed on the terminal device 100 from Figure 2 The router interface 103 of the living room shown in (c) is switched to Figure 2 The third click operation 403 is to click on the child Internet function icon 1031 on the living room router interface 103. The child Internet function interface 104 includes a protected device option 1041 and an unprotected device option 1042. The protected device is a device that has established a communication connection with the living room router 200 and is in a child protection state, and the unprotected device is a device that has established a communication connection with the living room router 200 but is not in a child protection state. Figure 2 As can be seen from the child Internet function interface 104 shown in (d) in the figure, the "Honor V40" device is currently in a child protection state. When the user wants to know the specific protection information of the "Honor V40" device, the user can click the Honor V40 icon 1043.

[0054] In response to the user's fourth click operation 404 on the Honor V40 icon 1043, the terminal device 100 changes the screen displayed by the terminal device 100 from Figure 2 The children's Internet access function interface 104 shown in (d) is switched to Figure 2The Honor V40 device interface 105 shown in (e) in the figure. Among them, the fourth click operation 404 is to click the Honor V40 icon 1043 of the children's Internet function interface 104. The "One-click disconnection", "All allowed", "Internet time statistics", "Allowed Internet time period" and "Allowed Internet duration" function options will be displayed in the Honor V40 device interface 105. The "one-click disconnection" function can achieve network disconnection protection for devices that are in child protection status and have network connection. For example, when children are using the Honor V40 device, if the user wants to stop all Internet functions of the Honor V40 device, the Honor V40 device can be put into a disconnected state by clicking the "one-click disconnection" icon, thereby preventing the device user from continuing to surf the Internet. The "allow all" function can establish a network connection for a device that is in a child protection state and has lost network connection. For example, when the Honor V40 device is in a disconnected state, the Honor V40 can be connected to the network by clicking the "allow all" icon, thereby meeting the Internet needs of the Honor V40 device. "Internet time statistics" can make statistics on each application and the total Internet time in the Honor V40 device, so that users can understand the Internet time of the Honor V40 device and the Internet time of each application. The "Allow Internet Time Period" function allows users to control the time points when the Honor V40 device can access the Internet. For example, users can set the Honor V40 device to access the Internet from 17:00 to 19:00 every day, or users can set the Honor V40 device to access the Internet on weekends. The "Allow Internet Time" function allows users to control the time when the Honor V40 device can access the Internet. For example, users can set the Honor V40 device to access the Internet for 2 hours a day.

[0055] When the user wants to learn more about the Internet time statistics of the Honor V40 device, he can click the more options icon 1051 corresponding to "Internet time statistics". In response to the user's fifth click operation 405 on the more options icon 1051 corresponding to "Internet time statistics", the terminal device 100 changes the display screen of the terminal device 100 from Figure 2 The Honor V40 device interface 105 shown in (e) switches to Figure 2 The Internet time statistics details interface 106 shown in (f) in the figure. Among them, the fifth click operation 405 is to click the more options icon 1051 corresponding to the "Internet time statistics" on the Honor V40 device interface 105. The Internet time statistics details interface 106 displays the Internet time of the device in the "learning", "video", "social", "game" and "other" business types of applications, and also displays the statistics of the specific Internet time of the device in each application. In this way, the user can understand the specific time that the Honor V40 device uses each application when surfing the Internet, so as to achieve Internet control and protection of the Honor V40 device.

[0056] For example, an application with a business type of learning may include Applications for learning, etc. Applications with video business type may include Applications for watching videos, etc. Applications with social business type may include and Applications used for communication and conversation. Applications with game business types may include as well as etc. for playing games.

[0057] As can be seen from the above description, when a user wants to understand and configure the Internet usage of a device connected to the router 200, the user can use the application duration statistics function of the router 200 and display the statistical data on the terminal device 100 to implement the child protection function of the terminal device 100. To implement the Internet usage duration statistics function, the router 200 can use the interactive messages between the application of the terminal device 100 and the server corresponding to the application to implement the statistics of the Internet usage duration of the application.

[0058] Optionally, an identification module may be provided within the router 200. After receiving a message, the identification module may parse the message to identify the type of service and application to which the message belongs, and record the service identifier and application identifier in the relevant information of the connection to which the message belongs. Thus, when the router 200 calculates the Internet access time based on the information obtained from connection tracking, the corresponding Internet access time can be calculated from the service dimension and the application dimension. The service dimension is the type of service, such as game, video, shopping, and other types of services.

[0059] Specifically, when the router 200 receives a message sent by the application of the terminal device 100 to the server, the identification module can parse the message and determine the application that sent the message based on the content of the message. At the same time, in order to facilitate the statistics of the Internet access time of each application, each application has a different code (identity document, id) to represent the application through the code. When the application sends a message, it can add the application code of the sending message in the message to facilitate identification by the identification module. For example, the code id of the Baidu application is 53. When the Baidu application sends a message to the server, the message can include information about id=53. In this way, after the identification module recognizes the information about id=53, it can directly determine that the message is sent by the Baidu application.

[0060] Furthermore, after identifying the application code corresponding to the message, the identification module can update the application code into the connection tracking information. The router monitors the connection tracking information regularly to determine the Internet access time of the application.

[0061] For example, a piece of information recorded in a connection tracking record may be: ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, sport=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=131, sc_categ=4, sc_action=0.

[0062] The connection trace above can also be called a server flow (IP flow). "ipv4" indicates that the IPv4 protocol is used, which is the fourth version of the Internet Protocol. The "2" field indicates the network layer protocol type, where "2" represents the Transmission Control Protocol (TCP). "tcp" indicates that the transport layer uses the TCP protocol. "6" indicates the TCP version number used. "295" indicates the connection lifetime is 295 seconds. "ESTABLISHED" indicates that the connection has been established. "src=192.168.3.7" indicates that the source server address is 192.168.3.7. "dst=106.75.107.247" indicates that the destination server address is 106.75.107.247. "sport=38844" indicates that the source port number is 38844. "dport=6810" indicates that the destination port number is 6810. "[ASSURED]" indicates that the connection has been authenticated or confirmed. "mark=3491758080" indicates the connection identification number. "zone=0" indicates the security zone to which this connection belongs. "ifindex=34" indicates the network interface index number used by the connection. "ctaddr=32fedb78" indicates the connection address. "httpmark=0" indicates the HTTP identification number. "use=2" indicates the number of times this connection has been referenced. "sc_id=131" indicates the application identifier, which is used to determine which application the connection belongs to. "sc_categ=4" indicates the service type of the application, which is used to determine which service the connection belongs to. "sc_action=0" indicates that the application is in the released state, where the released state means that the application can access the Internet normally.

[0063] Based on the connection tracking information above, we can see that this connection tracking records the Internet access information of application ID = 131. The router can check every 10 seconds whether this connection tracking exists. If so, it can add 10 seconds to the Internet access time of application ID = 131. If not, it can stop counting the Internet access time of application ID = 131.

[0064] Additionally, in the connection tracking information, "sc_categ = 4" indicates the service type of the application. The router can use this information to record the online time of applications of different service types. The online time statistics for applications of each service type can be calculated by summing the online time of applications of the same service type, or by referring to the statistical methods for application online time statistics. This will not be further detailed here.

[0065] Exemplarily, the identification module may be a deep packet inspection and processing engine (DPI). Alternatively, the identification module may be an application identification engine, a data flow analysis engine, etc., which is not limited in this embodiment.

[0066] Furthermore, the messages sent by applications on the terminal device 100 may include plaintext messages and encrypted messages. Compared to plaintext messages, encrypted messages do not have any signatures, and the communication port is also random. Plaintext messages may be Uniform Resource Locator (URL) plaintext messages, Hypertext Transfer Protocol (HTTP) plaintext messages, etc. Encrypted messages may be Secure Sockets Layer (SSL) encrypted messages or Transport Layer Security (TLS) encrypted messages, etc. Game and online course applications on the terminal device 100 are more likely to send encrypted messages.

[0067] When router 200 receives a plaintext message, it can directly identify the plaintext message to determine the service type and application to which it belongs. However, when router 200 receives an encrypted message, its identification module is unable to parse the encrypted message and, therefore, is unable to determine the service type and application to which it belongs. As a result, the connection corresponding to the encrypted message and the connection tracking related information do not contain information such as the application code and service type. As a result, when calculating the online time statistics for the application that sent the encrypted message, the application may be omitted due to the inability to identify it, resulting in inaccurate online time statistics for the application.

[0068] In order to solve the above problems, the present application provides a message identification method that can identify target messages, especially encrypted messages, so as to determine the business type and application to which the target message belongs, and improve the accuracy of the statistics of the application's Internet access time.

[0069] Figure 3 This is a first structural diagram of a network device provided by this embodiment.

[0070] See also Figure 3 For example, the message identification method provided in this embodiment can be applied to a network device 500. The network device 500 can be a router, a switch, a network storage device, a network switching device, a network adapter (smart network card), etc. The specific type of the network device 500 is not limited in this embodiment.

[0071] The network device 500 includes a processing module 510 , a wireless communication module 520 , a storage module 530 , a power module 540 , a communication interface module 550 , a switch 560 , an identification module 570 and an antenna.

[0072] The processing module 510 may include one or more processors for processing the above-mentioned message identification method, so as to determine the service type and application to which the target message belongs, thereby improving the accuracy of statistics on the application's Internet access time.

[0073] Specifically, the processor can be a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural network processing unit (NPU), a data processing unit (DPU), a microprocessor or one or more integrated circuits for implementing the solution of the present application. For example, the processor includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. It can implement or execute the various logic blocks, modules and circuits described in conjunction with the disclosure of the embodiments of the present application. The processor can also be a combination that implements computing functions, for example, including a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0074] Furthermore, the processing module 510 may include any one of the aforementioned processors, or may include multiple processors. In some embodiments, the different processing units may be independent devices or integrated into one or more processors. The CPU is the final execution unit for information processing and program execution, and its primary tasks include processing instructions, executing operations, controlling time, and processing data. The CPU may include a controller, an arithmetic unit, a cache memory, and a bus for connecting these components.

[0075] The wireless communication module 520 can provide wireless communications such as Wi-Fi, frequency modulation (FM), Bluetooth, or NFC. The wireless communication module 520 can be one or more devices that integrate at least one communication processing module. The wireless communication module 520 receives electromagnetic waves via an antenna, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processing module 510. The wireless communication module 520 can also receive signals to be transmitted from the processing module 510, frequency modulate and amplify them, and convert them into electromagnetic waves for radiation through the antenna.

[0076] The storage module 530 can be used to store computer-executable program code, which includes computer instructions. The processing module 510 executes various functions and performs data processing by running the instructions stored in the storage module 530. The storage module 530 may include a program storage area and a data storage area. The program storage area may store applications required for at least one function (such as counting Internet access time, sending messages, etc.). The data storage area may store connection-related information, etc.

[0077] Specifically, the storage module 530 may include a read-only memory (ROM) or other type of static storage device that can store static information and instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program instructions in the form of instructions or data structures and can be accessed by a computer, but is not limited to these.

[0078] The storage module 530 may exist independently and be coupled to the processing module 510 , or the storage module 530 may be integrated into the processing module 510 , which is not limited in this embodiment.

[0079] The power module 540 can be used to receive power input, store electrical energy, and provide power to the processing module 510 , the wireless communication module 520 , the storage module 530 , and the like.

[0080] The communication interface module 550 is a device using any transceiver type for communicating with other devices or communication networks, and the communication network can be Ethernet, a radio access network (RAN), or a wireless local area network (WLAN). The communication interface module 550 can include a wired communication interface and a wireless communication interface. Specifically, the communication interface can be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a Wireless Local Area Network (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In an embodiment of the present application, the communication interface module 550 can be used for the network device 500 to communicate with other devices.

[0081] The switch 560 is used to trigger the network device 500 to be turned on or off.

[0082] The identification module 570 is used to identify the message and can execute the above method to identify the target message. The identification module 570 can be integrated into the processing module 510 or can be independent of other modules, which is not limited in this embodiment.

[0083] The network device 500 provided in this embodiment is used to perform the above-mentioned method and can achieve the same effect as the above-mentioned implementation method. When using an integrated unit, the network device can also include only a processing module, a storage module, and a communication module. The processing module can be used to control and manage the operation of the device. For example, it can be used to support the device in executing the steps performed by the processing unit. The storage module can be used to support the device in executing and storing program code and data. The communication module can be used to support the device in communicating with other devices.

[0084] Figure 4 This is the first flow chart of a message identification method provided by this embodiment.

[0085] See also Figure 4 This embodiment provides a message identification method, including:

[0086] Step S110: Obtain the target server address corresponding to the target message sent by the terminal device.

[0087] The target message includes a message whose message body is encrypted.

[0088] The target message sent by the terminal device often includes a message header and a message body. The target message includes the message body of the message encrypted, such as an encrypted message. Alternatively, the target message can also be a plaintext message, a command message, a response message, an event message, etc. The target message is not limited in this embodiment.

[0089] The message header of a target message includes the address of the target server to which the message is destined. To prevent messages from being sent to the wrong server, the target server address in the message header is typically unencrypted and can be retrieved directly. This allows routers to forward the message to the appropriate server based on the target server address in the message header, ensuring that the message is delivered to the correct server.

[0090] The target message's message body typically contains encrypted raw data. Once encrypted, the data becomes unreadable, and only a trusted entity with the decryption key can decrypt and recover the original data. This allows the application to be identified based on the data in the message body.

[0091] In this embodiment, when a target message sent by a terminal device is obtained, it is difficult to decrypt the message body, making it impossible to determine the application to which the target message belongs based on the data within the message body. Decrypting the message body by obtaining the decryption keys corresponding to various target messages and then identifying the target message would severely reduce target message identification efficiency and consume significant resources. Therefore, when identifying the application to which the target message belongs, the target server address, which has not been encrypted, can be first obtained from the target message, thereby enabling identification of the target message based on the target server address.

[0092] For example, the target message sent by the terminal device may be an application whose service type is a game in the terminal device (eg etc.), online course applications (such as etc.), etc. This embodiment does not limit the applications in the terminal device that can send target messages.

[0093] Optionally, the target message may be an SSL encrypted message or a TSL encrypted message. In this embodiment, the specific type of the encrypted message is not limited.

[0094] Step S120: Determine the target domain name corresponding to the target server address.

[0095] Typically, before an application on a terminal device sends an interactive message to a target server address, it first sends a domain name resolution request to a Domain Name System (DNS) server. The DNS server then queries the server address corresponding to the domain name in the resolution request and sends it to the application. This server address indicates the location of the server storing the target website content. This allows the application to determine which server address the interactive message should be sent to when communicating with the server.

[0096] For example, if the domain name in the domain name resolution request is "weixin.qq.com," the domain name server can resolve "weixin.qq.com" to the server address "220.196.132.101." After the domain name is resolved to the server address, the domain name server sends the server address "220.196.132.101" to the application. After the terminal device application obtains the server address, when communicating with the server, it uses "220.196.132.101" as the target server address in the message header, thereby sending the message to the designated server.

[0097] As can be seen from the above description, the target server address "220.196.132.101" is obtained based on the domain name "weixin.qq.com". In other words, the target server address corresponds to a domain name. Thus, after obtaining the target server address of the target message, the target domain name corresponding to the target server address can be determined based on the correspondence between server addresses and domain names. This target domain name is the domain name sent by the terminal device application in the domain name resolution request.

[0098] It's worth noting that when a terminal device application sends a domain name resolution request to a domain name server, it can first send a resolution request to the local domain name server. If the local domain name server has already cached the server address corresponding to the domain name, it can directly return this server address to the terminal device application. If the local domain name server does not have the server address corresponding to the domain name cached, the local domain name server will initiate a request to a higher-level domain name server until it finds the server address corresponding to the domain name.

[0099] Furthermore, the domain name resolution request sent by the application of the terminal device to the local domain name server may be forwarded to the local domain name server by the router.

[0100] In one implementation, the router can provide a built-in domain name server. When the router receives a domain name resolution request from an application on a terminal device, it can directly use the built-in domain name server to resolve the domain name, thereby realizing the function of a local domain name server.

[0101] In another implementation, a dedicated local domain name server can be set up. The router's configuration includes an address pointing to the local domain name server. When the router receives a domain name resolution request from a terminal application, it forwards the request to the local domain name server configured in the router based on the address of the local domain name server. Upon receiving the request, the local domain name server queries the corresponding domain name resolution result and returns the result to the router. The router then returns the domain name resolution result to the terminal device and application that initiated the request.

[0102] As can be seen from the above description, when the application of the terminal device sends a domain name resolution request, the router can obtain the domain name resolution result, thereby confirming the correspondence between the domain name and the server address. In this way, the router can obtain the target domain name corresponding to the target server address.

[0103] For example, if the terminal device When the application sends a domain name resolution request to the domain name server, the router forwards the resolution request to the local domain name server. The domain name requested for resolution in the domain name resolution request is "weixin.qq.com". The local domain name server resolves "weixin.qq.com" to the server address "220.196.132.101" and sends it to the router. The router then forwards the server address "220.196.132.101" to the terminal device. Application. In this way, the terminal device The target server address of the interactive message sent by the application to the server is "220.196.132.101", and the router can determine that the target domain name corresponding to the target server address is "weixin.qq.com" according to the record of the domain name resolution request.

[0104] Step S130: Determine a target application in the terminal device based on the target domain name.

[0105] The target application is the application that sends the target message. In other words, the target application is the application to which the target message belongs.

[0106] For example, a domain name usually consists of multiple parts separated by periods. For example, "weixin.qq.com" is a domain name that consists of three parts, including the top-level domain "com", the primary domain "qq" and the secondary domain "weixin". As can be seen from the primary domain and the secondary domain, the domain name corresponds to Application. It can be seen that when confirming the target application, the domain name corresponding to the target message can be used to determine the target application, thereby realizing the identification of the target message.

[0107] In this embodiment, the unencrypted target server address in the target message can be obtained to determine the target domain name corresponding to the target server address, and the target application to which the target message belongs can be determined based on the target domain name. This allows the target application corresponding to the target message to be identified without parsing the target message, improving the efficiency of target message identification, thereby reducing the possibility of missing target message identification and improving the accuracy of the router's application usage time statistics.

[0108] Figure 5 This is the second flow chart of a message identification method provided in this embodiment.

[0109] like Figure 5 As shown, in some embodiments, the message identification method includes:

[0110] Step S210: Obtain the target server address corresponding to the target message sent by the terminal device.

[0111] As can be seen from the description of step S110 above, the target server address of the target message is not encrypted and can be directly read, so that the target server address corresponding to the target message sent by the terminal device can be obtained.

[0112] For example, the message header of a target message may include "dst=106.119.193.231." Here, "dst=106.119.193.231" indicates that the target server address of the target message is 106.119.193.231. When a router obtains the target server address in a target message, it can directly identify the "dst" character and read the characters following it to obtain the target server address.

[0113] It is understandable that the message header may also include information such as the source address, the protocol version of the network layer, the protocol type of the transport layer, etc. In this embodiment, the information and specific form of the message header are not limited.

[0114] It is worth noting that the description of step S210 can refer to the above-mentioned step S110 and will not be repeated here.

[0115] Step S220: Query the first list.

[0116] The first list includes a plurality of correspondences between server addresses and domain names, and one server address corresponds to at least one domain name. Thus, the target domain name corresponding to the target server address can be determined through the first list.

[0117] Because the data within the target message's body is encrypted, there's no way to directly obtain the application and domain name information to which the target message belongs. To determine the target application of the target message, the domain names corresponding to each server address can be recorded in a first list in advance and stored in the router. When identifying the target message, the first list can be directly accessed and queried, allowing the first list to be used to determine the target domain name corresponding to the target server address of the target message.

[0118] In some embodiments, the method for determining the first list may include:

[0119] Step S221: Read the domain name response message.

[0120] The domain name response message is a response message sent by the domain name server in response to the domain name resolution request of the terminal device, and the domain name response message includes the correspondence between the domain name and the server address.

[0121] In this embodiment, when the terminal device is connected to the router to achieve wireless Internet access, it is necessary to continuously interact with the server during the process of using the application in the terminal device. During the interaction process, the application of the terminal device can send a target message to the server.

[0122] Before the terminal device uses the target message to communicate with the server, it will first initiate a domain name resolution request to the router. In one example, the router has a built-in domain name service and can directly respond to the domain name resolution request, thereby sending a domain name response message to the terminal device.

[0123] Figure 6 This is a schematic diagram of a domain name resolution process provided by this embodiment.

[0124] like Figure 6 In another example, if the router does not have a built-in domain name service, the router can forward the terminal device's domain name resolution request to the local domain name server in the gateway. After receiving the domain name resolution request, the gateway sends a domain name response message to the router, which then forwards the domain name response message to the terminal device.

[0125] In the above two examples, no matter whether the domain name response message is sent by the router or the gateway, the router can directly obtain the domain name response message.

[0126] For example, the domain name response message is the response information returned by the domain name server to the terminal device client after resolving the domain name in response to the domain name resolution request. In the domain name response message, a domain name and all server addresses corresponding to the domain name can be obtained.

[0127] Specifically, the content of the domain name response message may include:

[0128] "ml.mp.weixin.qq.com:type A,class IN,addr 220.196.132.101

[0129] ml.mp.weixin.qq.com:type A,class IN,addr 112.65.194.79

[0130] ml.mp.weixin.qq.com:type A,class IN,addr 116.128.135.25

[0131] ml.mp.weixin.qq.com:type A,class IN,addr 116.128.164.66”

[0132] In the above content, "ml.mp.weixin.qq.com" represents the domain name being queried, and "type A" indicates the query type. "A" indicates that the query is for the IPv4 address corresponding to the domain name, "class IN" indicates the query class, and "IN" represents the Internet class, indicating that this is a common domain name query on the internet. "addr 220.196.132.101" represents the query result, indicating that the IPv4 address corresponding to the domain name "ml.mp.weixin.qq.com" is "220.196.132.101." IPv4 addresses are Internet Protocol addresses used by version 4 of the Internet Protocol.

[0133] In Internet communications, a server typically has one or more server addresses to facilitate communication between other devices and the server. Furthermore, the domain name response message above indicates that there are four server addresses corresponding to the domain name "ml.mp.weixin.qq.com."

[0134] It is worth noting that, for other domain names, the server address recorded in the domain name response message may also be one. In this embodiment, there is no limit on the number of server addresses in the domain name resolution result.

[0135] Step S222: Record the server address and the domain name corresponding to the server address to form a first list.

[0136] In this embodiment, after obtaining the correspondence between the server address and the domain name, the server address and the domain name corresponding to the server address can be recorded to form a first list. This makes it easier to determine the target application based on the server address when identifying the target message later.

[0137] Exemplarily, the first list may be stored in a memory of the router, or in an identification module of the router, which is not limited in this embodiment.

[0138] Figure 7 It is a schematic diagram of the first list provided in this embodiment.

[0139] like Figure 7 As shown, in some embodiments, the first list may be a first hash table.

[0140] In the first hash table, the server address is a key value of the first hash table, and at least one domain name is an associated value of the first hash table. The server address and the domain name corresponding to the server address form a first key-value pair of the first hash table. The first hash table may include multiple first hash buckets, each of which may store a first key-value pair.

[0141] It is worth noting that the same server address can interact with applications on multiple terminal devices. In this way, the same server address can correspond to multiple different domain names.

[0142] Exemplarily, the domain name stored in the first hash bucket may be in the form of a regular expression, so that the domain name string can be processed and operated more conveniently.

[0143] For example, the domain name "bdstatic.com" can be represented using a regular expression as "\.bdstatic\.com$," where ".com$" matches strings ending with ".com," and "\.bdstatic\" matches the literal string ".bdstatic" within a string. Using regular expressions when matching domain names directly identifies key characters in the domain name, improving recognition efficiency and simplifying domain name representation for easier storage and querying.

[0144] In the first hash table, the subscripts of the first hash buckets range from 0 to (N-1), where N is the total number of first hash buckets. The subscript of the first first hash bucket is 0, the subscript of the last first hash bucket is N-1, and the subscripts of the first hash buckets between the first and last first hash buckets are incremented by one.

[0145] For example, if the total number of first hash buckets is 1024, the subscript of the first hash bucket is 0, the subscript of the last first hash bucket is 1023, and the subscripts of the first hash buckets between the first first hash bucket and the last first hash bucket are 2, 3, 4, ..., 1022 respectively.

[0146] Figure 8This is the third flow chart of a message identification method provided in this embodiment.

[0147] like Figure 8 As shown, since there are multiple first key-value pairs to be stored and the number of first hash buckets is also multiple, in order to improve the efficiency of storing the first key-value pairs in the first hash bucket, the following method can be used to store the first key-value pairs in the specified first hash bucket:

[0148] Step S2221: Obtain a first value based on the server address.

[0149] The first value is an integer.

[0150] When storing the server address in the first hash bucket, the location of the first hash bucket must be selected. In other words, the server address must be stored in the designated first hash bucket according to certain rules. This reduces the likelihood of different first key-value pairs being stored in the same first hash bucket. Furthermore, subsequent table lookups can be performed based on these storage rules, thereby improving query efficiency.

[0151] A server address typically consists of four decimal numbers, each ranging from 0 to 255, separated by periods. For example, the server address 106.119.193.231 is composed of 106, 119, 193, and 231, each of which is between 0 and 255. The four parts of a server address have a small numerical range and are prone to duplication. If one of them is used as the first value for selecting the first hash bucket position, it is easy for different server addresses to correspond to the same first hash bucket during storage, resulting in a hash collision.

[0152] Based on the above reasons, a server address can be converted into a corresponding integer, and the integer can be used as the first value, thereby reducing the possibility of hash collision.

[0153] For example, each decimal number in the server address can be converted into a binary number, and the obtained binary numbers can be connected to form a long string, and the long binary string can be converted into a decimal number to obtain an integer.

[0154] Specifically, for the server address 106.119.193.231, each part is 106, 119, 193, and 231. Converting 106 into a binary string yields 1101010, converting 119 into a binary string yields 1110111, converting 193 into a binary string yields 11000001, and converting 231 into a binary string yields 11100111. Concatenating these binary strings yields the long string corresponding to the server address: 110101011101111100000111100111. Converting this long string into decimal yields the integer 4545448783. Thus, the first value corresponding to the server address 106.119.193.231 is 4545448783.

[0155] It is understandable that in other implementations, the first value may be obtained by other calculation methods, which is not limited in this embodiment.

[0156] Step S2222: Divide the first value by the total number of the first hash bucket to obtain a remainder result.

[0157] The first value obtained by converting the server address may be relatively large, while the number of the first hash buckets may be relatively small, resulting in the first value being much larger than the index value of the first hash bucket. Therefore, the first value can be further processed to obtain the index value of the first hash bucket corresponding to the server address.

[0158] In this embodiment, the first value can be divided by the total number of the first hash bucket to obtain a remainder result corresponding to the server address. Since the remainder result is greater than or equal to zero and less than the total number of the first hash bucket, it is exactly within the subscript range of the first hash bucket. In this way, the first hash bucket specified by the server address can be selected based on the remainder result.

[0159] Specifically, if the first value is 4545448783 and the total number of the first hash bucket is 1024, 4545448783 ÷ 1024 = 4438914...847, then the remainder of dividing the first value by the total number of the first hash bucket is 847. In this way, the first hash bucket can be selected based on the remainder 847.

[0160] Step S2223: Store the first key-value pair corresponding to the remainder result in the first hash bucket whose subscript is the remainder result.

[0161] The remainder result corresponds to the server address, and the first key-value pair corresponding to the server address is also the first key-value pair corresponding to the remainder result. By storing the first key-value pair corresponding to the remainder result in the first hash bucket subscripted as the remainder result, the key-value pairs corresponding to different servers can be stored in different first hash buckets, thereby reducing the possibility of hash conflicts and facilitating subsequent query processes.

[0162] In some embodiments, the method of storing the first key-value pair in the designated first hash bucket further includes:

[0163] Step S2224: When the first hash bucket whose subscript is the remainder result has stored other first key-value pairs, traverse the first hash buckets backward in sequence and store the first key-value pair in the first unused first hash bucket.

[0164] The unused first hash bucket refers to a first hash bucket that does not store the first key-value pair.

[0165] In this embodiment, by converting the server address into a first numerical value and then using the first numerical value to obtain a remainder result, the same remainder result may be obtained for different server addresses, resulting in a hash conflict.

[0166] To avoid the above problem, if the first hash bucket indexed by the remainder result corresponding to the server address already stores the first key-value pair, the first hash buckets can be traversed backward until the first unused first hash bucket is found, and the first key-value pair is stored in the first hash bucket. This can solve the hash collision problem that occurs when forming the first list.

[0167] In some embodiments, the method of storing the first key-value pair in the designated first hash bucket further includes:

[0168] Step S2225: when the number of first hash buckets storing the first key-value pair exceeds a set threshold, increase the number of first hash buckets.

[0169] In this embodiment, during the process of recording and storing the first key-value pairs, there may be a large number of first key-value pairs and an insufficient number of first hash buckets, resulting in some first key-value pairs not being able to be stored in the first hash table.

[0170] To solve the above problem, when the number of first hash buckets storing first key-value pairs exceeds a set threshold, the number of first hash buckets can be increased, thereby expanding the capacity of the first hash table to prevent the situation where too many first key-value pairs cannot be stored.

[0171] For example, if the initial number of first hash buckets in the first hash table is 1024, when the number of first hash buckets storing first key-value pairs exceeds 768 (75% of the initial number), the first hash table may be expanded.

[0172] Optionally, the set threshold may be 50%, 75%, 80%, 85%, etc., of the initial number of the first hash bucket, which is not limited in this embodiment.

[0173] It is worth noting that, in other embodiments, other methods may be used to store the first key-value pair in the first hash bucket, which is not limited in this embodiment.

[0174] It is understandable that in other implementations, the first list may also be a table, an array, etc. in other forms, which is not limited in this embodiment.

[0175] Furthermore, the first list may be created and stored in the router in advance and may not be updated during subsequent queries. Alternatively, after the first list is created and stored in the router in advance, it may be updated synchronously during the target message identification process, which is not limited in this embodiment.

[0176] Step S230: When the first list includes a domain name corresponding to the target server address, determine the domain name corresponding to the target server address as the target domain name.

[0177] In this embodiment, the first list stores domain names corresponding to each server address. After obtaining the target server address corresponding to the target message and the first list, the domain name corresponding to the target server address can be searched in the first list to determine the target domain name corresponding to the target server address.

[0178] Exemplarily, when querying the first list, the query can be performed based on the method by which the server addresses are stored in the first list. First, the location of the first hash bucket storing the target server address must be determined. If the first hash bucket stores only one domain name corresponding to the target server address, then that domain name can be determined as the target domain name corresponding to the target server address. In other words, if the first hash bucket stores only one domain name corresponding to the target server address, then that domain name is the target domain name corresponding to the target message.

[0179] It is worth noting that the location of the first hash bucket storing the target server address can be determined by referring to the method of storing the first key-value pair in the specified first hash bucket in steps S2221 to S2223 above, which will not be repeated here.

[0180] In some embodiments, if the method of step S2224 is used in the process of storing the first key-value pair in the specified first hash bucket, then when querying the first list, if the server address in the first hash bucket determined according to steps S2221 to S2223 is not the target server address, you can continue to traverse backward until the first hash bucket storing the target server address is found.

[0181] Please refer again Figure 7 In some embodiments, in addition to storing server addresses and domain names, the first list also stores application identifiers corresponding to each domain name. An application may have multiple domain names, for example The domain name corresponding to the application can be "\.bdstatic\.com$" or "^hm\.baidu\.com$". To facilitate identification of applications by domain name, an application identifier can be added to each domain name, so that different domain names belonging to the same application have the same application identifier for easy identification.

[0182] For example, when the first list is a first hash table, the application identifier corresponding to each domain name can be stored in the same location as the domain name in the first hash bucket. In this way, when determining the target domain name, the application identifier corresponding to the target domain name can be obtained at the same time.

[0183] Optionally, the application identifier can be an application code id, and different applications can be represented by different application code ids. In this way, when the Internet access time of an application is counted, statistics can be directly performed by identifying the application code id, which is convenient for operation.

[0184] Specifically, The application code id of the application is 53. In this way, the domain name "\.bdstatic\.com$" and the domain name "^hm\.baidu\.com$" can correspond to the same application code id, indicating that both domain names are The domain name of the application.

[0185] It is worth noting that the application identifier may also be other identifiers, such as application name, letters, symbols, etc., which is not limited in this embodiment.

[0186] Step S240: When the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are the same, select any domain name corresponding to the target server as the target domain name.

[0187] As can be seen from the above description, when a server address corresponds to multiple domain names and the application identifiers corresponding to the multiple domain names are the same, it means that the multiple domain names belong to the same application. Therefore, the corresponding target application can be found by using any of the domain names as the target domain name.

[0188] For example, when the target server address is "211.91.68.249," the domain names corresponding to the target server address in the first list include "\.bdstatic\.com$" and "^hm\.baidu\.com$." Furthermore, the application code corresponding to both "\.bdstatic\.com$" and "^hm\.baidu\.com$" is id=53, indicating that they belong to the same application and that either one can be selected as the target domain name.

[0189] Step S250: When the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, determine the multiple domain names corresponding to the target server address as pre-selected domain names.

[0190] In this embodiment, when the first list includes multiple domain names corresponding to the target server address, and the application identifiers corresponding to the multiple domain names are different, it means that the target server address corresponds to the domain names of multiple different applications. The reason for this problem may be that different business resources are placed on the same cloud server (such as In other words, different applications may communicate with the same cloud server at different times. However, this cloud server has only one public network server address, which results in domain names belonging to multiple different applications being associated with the server address. This can interfere with target message identification due to the presence of homologous cloud service information.

[0191] In order to remove the interference of homologous cloud service information, multiple domain names corresponding to the target server address in the first list can be used as pre-selected domain names, and then the target domain name can be confirmed from the multiple pre-selected domain names, thereby narrowing the recognition range and improving recognition efficiency.

[0192] like Figure 7 As shown, exemplary, Figure 7 The domain names corresponding to the server address "106.119.193.231" are "\.xueersi\.com$" and ".huya\.com$". Among them, the application code id corresponding to the domain name "\.xueersi\.com$" is 78, which belongs to Application, the domain name ".huya\.com$" corresponds to the application code id = 34, belonging to Application. It can be seen that the server address "106.119.193.231" corresponds to the domain names of two different applications, indicating Application and The application's server resources may be deployed on the same cloud server node, but the target message can only be sent from an application corresponding to one of these domain names. Simply selecting any domain name as the target domain name may lead to incorrect identification of the target application corresponding to the target message, resulting in inaccurate online time statistics. If the target server address is "106.119.193.231," the target domain name corresponding to the target message cannot be directly determined based on the first list.

[0193] Based on the above situation, multiple domain names corresponding to the target server address in the first list can be first determined as pre-selected domain names, and then the target domain name corresponding to the target message can be confirmed from the pre-selected domain names, thereby narrowing the recognition scope of the target message and improving the recognition efficiency. The accuracy of the target message recognition can be improved through secondary confirmation to improve the accuracy of the Internet access time statistics.

[0194] Step S260: Determine a target domain name based on the multiple pre-selected domain names and the second list.

[0195] In this embodiment, after the pre-selected domain name is determined, the target domain name may be determined in combination with the second list.

[0196] The second list includes a plurality of correspondences between domain names, server addresses, and server address statuses, and one domain name corresponds to at least one server address.

[0197] Figure 9 is a schematic diagram of the second list provided in this embodiment.

[0198] like Figure 9 As shown, in some embodiments, the second list may be a second hash table.

[0199] In the second hash table, the domain name is a key value of the second hash table, at least one server address and the status of the server address are associated values ​​of the second hash table, and the domain name, the server address corresponding to the domain name, and the status thereof form a second key-value pair of the second hash table. The second hash table may include multiple second hash buckets, each of which may store a second key-value pair.

[0200] It is worth noting that the determination of the correspondence between the domain name and the server address can refer to the description of the above steps S221-S222, which will not be repeated here.

[0201] Furthermore, the manner of storing the second key-value pair in the second hash bucket may refer to the manner of storing the first key-value pair of the first hash table in the first hash bucket, which will not be described in detail here.

[0202] It is understandable that in other implementations, the second list may also be a table, an array, etc. in other forms, which is not limited in this embodiment.

[0203] Figure 10 This is the fourth flow chart of a message identification method provided in this embodiment.

[0204] like Figure 10 As shown, in this embodiment, the above step S260 can be implemented by the following method:

[0205] Step S261: Query the second list.

[0206] Exemplarily, the second list can be stored in a memory of the router, or in an identification module of the router. Thus, when determining a target domain name based on the preselected domain name and the second list, the second list can be directly accessed and queried. The storage location of the second list is not limited in this embodiment.

[0207] It is worth noting that the process of querying the second list according to the preselected domain name can refer to the process of querying the first list according to the target server address, which will not be repeated here.

[0208] Step S262: Determine the status of all server addresses corresponding to each of the plurality of pre-selected domain names.

[0209] Exemplarily, the state of the server address includes an active state and an idle state. When the server address is in the active state, it indicates that the server address is being used, and when the server address is in the idle state, it indicates that the server address is not being used.

[0210] Optionally, in the second list, "1" may be used to indicate that the server address is in an active state, and "0" may be used to indicate that the server address is in an idle state, thereby facilitating representation and judgment.

[0211] When an application on a terminal device is running, the application may obtain resources from different servers at the same time, causing an application to communicate with multiple different server addresses at the same time. In this way, multiple server addresses corresponding to the same domain name will all be in an active state. Based on this, when determining that the target server address corresponds to multiple domain names, the status of the server addresses corresponding to each domain name can be determined by querying the second list. If there is a pre-selected domain name corresponding to which all server addresses are in an active state, it means that the application corresponding to the pre-selected domain name is a running application, that is, the application that sends the target message, and the pre-selected domain name can be used as the target domain name.

[0212] Figure 11 This is the fifth flow chart of a message identification method provided in this embodiment.

[0213] like Figure 11 As shown, further, the status of each server address can be determined in the following way:

[0214] Step S2621: Monitor system connection tracking information.

[0215] In this embodiment, the router can use operating system, Operating systems can establish connection tracking during operation. After a network connection is established, connection tracking allows the router to identify the messages exchanged between the terminal device's application and the server, record connection-related information, and save the connection status. Connections and connection tracking have a one-to-one correspondence; a connection tracking identifies a connection between an application on a terminal device and the server corresponding to that application. This allows network connection status to be tracked and managed, allowing for monitoring network usage and identifying unusual activity by analyzing connection status and traffic information.

[0216] For example, when the connection tracking is: ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, port=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=131, sc_categ=4, sc_action=0, it can be seen that the connection with the destination server address 106.75.107.247 is in use, indicating that the destination server address 106.75.107.247 is in an active state. In this way, the status of the server address can be determined by monitoring the connection tracking.

[0217] Step S2622: when it is monitored that the system establishes connection tracking, it is determined that the state of the server address in the second list corresponding to the destination server address in the connection tracking is active.

[0218] In this embodiment, when a router receives a message, it can parse it. If the message does not belong to an existing connection, it indicates that the application is establishing a new connection. In this case, the router needs to create a new connection track and record new connection-related information. If the message is found to belong to an existing connection after parsing, the corresponding connection track can be directly updated.

[0219] If the system establishes connection tracking, it indicates that a new application is establishing a communication connection with the destination server address. The destination server address is in an active state, and the state corresponding to the server address in the second list can be adjusted to an active state.

[0220] For example, when determining the status of the server address in the second list, if the status of the server address needs to be adjusted from idle to active, the "0" in the server address status column in the second list can be adjusted to "1" to indicate that the server address is in active status.

[0221] Step S2623: When it is monitored that the system deletes the connection tracking, it is determined that the state of the server address in the second list corresponding to the destination server address in the connection tracking is idle.

[0222] In this embodiment, when an established connection within the router is about to be disconnected, the connection sends a message to the system indicating the impending disconnection. The system can delete the connection tracking corresponding to the connection, causing the destination server address in the connection tracking to lose network connectivity and become idle. When the system detects that the connection tracking has been deleted, the state corresponding to the server address in the second list corresponding to the destination server address can be adjusted to idle.

[0223] For example, when determining the status of the server address in the second list, if the status of the server address needs to be adjusted from active to idle, the "1" in the server address status column in the second list can be adjusted to "0" to indicate that the server address is in idle state.

[0224] Furthermore, the status of each server address in the second list can be updated in real time according to the creation and deletion of the connection group, so that when the target message is identified, the status of each server address at the current moment can be obtained, thereby reducing the possibility of misjudgment due to information delay.

[0225] Based on the above reasons, when determining which of multiple pre-selected domain names is the target domain name, it is first necessary to determine the server status corresponding to each pre-selected domain name.

[0226] Please combine Figure 7 and Figure 9 , exemplary, Figure 7 In the first list shown, the pre-selected domain names corresponding to the target server address "106.119.193.231" are "\.xueersi\.com$" and ".huya\.com$".

[0227] Query Figure 9The second list shows that the server addresses corresponding to the pre-selected domain name "\.xueersi\.com$" include "106.119.193.231," "36.25.248.117," and "211.91.68.241." The server address "106.119.193.231" is active, the server address "36.25.248.117" is idle, and the server address "211.91.68.241" is idle.

[0228] Query Figure 9 As shown in the second list, the server addresses corresponding to the pre-selected domain name ".huya\.com$" include "106.119.193.231" and "61.168.100.237." The server address "106.119.193.231" is active, and the server address "61.168.100.237" is also active.

[0229] Step S263: determining that one of the pre-selected domain names is a target domain name, and that the status of all server addresses corresponding to the target domain name is active.

[0230] In this embodiment, if all server addresses corresponding to the preselected domain name are in an active state, it indicates that the application corresponding to the preselected domain name is in a network connection, and the target message is a message sent by the application corresponding to the preselected domain name. Based on this, the preselected domain name with all server addresses in an active state can be determined as an active domain name.

[0231] For example, query Figure 9 As can be seen from the second list, all server addresses corresponding to the pre-selected domain name “.huya\.com$” are in active status, and it can be determined that the pre-selected domain name “.huya\.com$” is the target domain name.

[0232] Please refer again Figure 5 The method of steps S220-S260 can determine the target domain name corresponding to the target server address based on the target server address and the first list, so as to facilitate subsequent confirmation of the target application.

[0233] In some embodiments, the state information of the server address can also be added to the first list to facilitate the determination of the state of the target server address. The state of the server address can be used as a key value or as an associated value, which is not limited in this embodiment.

[0234] Step S270: Determine the target application based on the target domain name and the application identifier corresponding to the target domain name.

[0235] As can be seen from the above description, the first list not only includes the correspondence between server addresses and domain names, but also includes the application identifiers corresponding to each domain name. The application identifiers are uniquely associated with the applications, making them easier to identify. After determining the target domain name, the target application can be determined based on the target domain name and the application identifier corresponding to the target domain name. This improves the efficiency and accuracy of identifying the target application and also facilitates subsequent statistics on online time.

[0236] In one example, in the above steps S240 and S250, the target domain name can be determined directly based on the first list.

[0237] At this time, the target application may be determined based on the application identifier corresponding to the target domain name in the first list.

[0238] In another example, in step S260 described above, the target domain name needs to be determined in conjunction with the second list. When querying the first list to determine the preselected domain names, in addition to obtaining the preselected domain names, the application identifiers corresponding to each domain name can also be obtained. Thus, after determining the target domain name based on the second list, the application identifier corresponding to the target domain name can be directly obtained, thereby facilitating the determination of the target application based on the application identifier.

[0239] Step S280: Update the service attributes of the target application into the connection tracking information corresponding to the target server address.

[0240] The service attributes include application identification and service type.

[0241] As can be seen from the above description, when a router receives a message, it can parse it. If the message does not belong to an existing connection, it means that the application is establishing a new connection. In this case, the router needs to create a new connection track and record the new connection-related information. If the message is found to belong to an existing connection after parsing, it can directly update the corresponding connection track.

[0242] However, if the message received by the router is a target message, it will not be able to obtain the application information to which the target message belongs because it cannot parse the target message. As a result, the information in the new connection tracking established by the router will only include information such as the server address and port, but will not include relevant information about the target application corresponding to the target message.

[0243] For example, if the router cannot determine the application to which the target packet belongs, the connection tracking information established by the router may be "ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, port=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=0, sc_categ=0, sc_action=0." "sc_id=0" indicates that the application identifier is the default value; in other words, id=0 does not belong to any application. "sc_categ=0" indicates that the service type is the default value; in other words, categ=0 does not belong to any service type. Thus, connection tracking only indicates the existence of a network connection, but does not indicate which application activity the network connection belongs to. If the router uses the connection tracking to count the Internet access time, the connection tracking information will not be counted.

[0244] For the above reasons, after identifying the target application corresponding to the target message, the service attributes of the target application need to be updated in the connection tracking information corresponding to the target server address. The connection tracking corresponding to the target server address is the connection tracking in which the destination server address in the connection tracking is the same as the target server address.

[0245] For example, if according to the above identification process, it can be determined that the target application corresponding to the target message is Its application ID is 131, and its service type is gaming, corresponding to the service type sequence number "4." If the target packet corresponds to the connection track described above, then updating the target application's service attributes to the connection track yields "ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, sport=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=131, sc_categ=4, sc_action=0." This connection track indicates that the application with application ID 131 is currently online, and that the service type for this connection track is 4. In this way, when the router subsequently counts the Internet access time, it can determine the application and business type to which the connection tracking belongs, thereby facilitating the Internet access time statistics of the application and business type to which the target message belongs, so as to effectively count the actual time the terminal device uses the application, thereby avoiding omissions and inaccuracies.

[0246] Figure 12 This is a second structural diagram of a network device provided in this embodiment.

[0247] like Figure 12 As shown, in some embodiments, the network device 1200 may further include a main control board 1210 and an interface board 1220 .

[0248] Main control board 1210, also known as the main processing unit (MPU) or route processor card, is responsible for controlling and managing various components in network device 1200, including routing calculation, device management, device maintenance, and protocol processing. Main control board 1210 includes a main control CPU 1211 and a main control memory 1212.

[0249] Interface board 1220 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are interfaces for flexible Ethernet clients (FlexE Clients). Interface board 1220 includes an interface CPU 1221, a network processor 1222, a forwarding table memory 1223, and a physical interface card (PIC) 1224.

[0250] The interface central processing unit 1221 on the interface board 1220 is used to control and manage the interface board 1220 and communicate with the main control central processing unit 1211 on the main control board 1210 .

[0251] The network processor 1222 is used to implement packet forwarding processing. The network processor 1222 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP) 1222. In some embodiments, the forwarding chip can be implemented using an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).

[0252] Specifically, the network processor 1222 is used to forward received messages based on the forwarding table stored in the forwarding table memory 1223. If the destination address of the message is the address of the message processing device, the message is sent to the CPU (such as a central processing unit) for processing; if the destination address of the message is not the address of the message processing device, the next hop and outgoing interface corresponding to the destination address are found in the forwarding table based on the destination address, and the message is forwarded to the outgoing interface corresponding to the destination address. The processing of uplink messages may include: processing of the message input interface, forwarding table search; the processing of downlink messages may include: forwarding table search, etc. In some embodiments, the interface central processing unit 1221 may also perform the functions of a forwarding chip, such as implementing software forwarding based on a general-purpose CPU, so that a forwarding chip is not required in the interface board 1220.

[0253] Physical interface card 1224 implements physical layer connectivity. Raw traffic enters the interface board through this card, and processed messages are sent from this physical interface card. Physical interface card 1224, also known as a daughter card, can be installed on the interface board and is responsible for converting optical and electrical signals into messages, performing a validity check on these messages, and forwarding them to network processor 1222 for processing. In some embodiments, interface CPU 1221 can also perform the functions of network processor 1222, such as implementing software forwarding based on a general-purpose CPU, eliminating the need for a network processor in physical interface card 1224.

[0254] Illustratively, the network device 1200 further includes a switching fabric board 1230. The switching fabric board 1230 may also be referred to as a switch fabric unit (SFU). If the network device 1200 includes multiple interface boards 1220, the switching fabric board 1230 is used to exchange data between the interface boards 1220. For example, interface boards 1220 can communicate with each other via the switching fabric board 1230.

[0255] The main control board 1210 and the interface board 1220 are coupled. For example, the main control board 1210, the interface board 1220, and the switching network board 1230 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 1210, the interface board 1220, and another interface board 1220. Communication between the main control board 1210, the interface board 1220, and another interface board 1220 is achieved through the IPC channel.

[0256] Logically, the network device 1200 includes a control plane and a forwarding plane.

[0257] The control plane includes a main control board 1210 and an interface central processing unit 1221. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1223, a physical interface card 1224, and a network processor 1222. The control plane performs functions such as routing, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the status of network devices. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor forwards messages received by the physical interface card based on the forwarding table sent by the control plane. The forwarding table sent by the control plane can be stored in the forwarding table entry memory. In some embodiments, the control plane and forwarding plane can be completely separate and not located on the same network device.

[0258] It is worth noting that there may be one or more main control boards 1210, and if there are multiple boards, they may include a master main control board and a backup main control board. There may be one or more interface boards 1220. The higher the data processing capability of the network device 1200, the more interface boards 1220 are provided. The interface boards 1220 may also have one or more physical interface cards 1224. There may be no switching fabric boards 1230, one or more switching fabric boards, and multiple switching fabric boards can achieve load balancing and redundant backup.

[0259] In a centralized forwarding architecture, the network device 1200 may not require a switching fabric board 1230, with the interface board 1220 handling all system service data. In a distributed forwarding architecture, the network device 1200 may include at least one switching fabric board 1230, which enables data exchange between multiple interface boards 1220, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture's message processing devices are superior to those of a centralized architecture's message processing devices.

[0260] For example, the network device 1200 may have only one board, i.e., no switching network board 1230. The functions of the interface board 1220 and the main control board 1210 are integrated on this single board. In this case, the interface central processing unit 1221 on the interface board 1220 and the main control central processing unit 1211 on the main control board 1210 may be combined into a single central processing unit on this single board to perform the combined functions of the two. This type of network device has low data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture to be adopted depends on the specific network deployment scenario and is not limited here.

[0261] In this embodiment, the main control memory 1212 of the main control board 1210 may store a computer program or computer instructions for executing the above-described message identification method. Alternatively, the interface board 1220 may also store a computer program or computer instructions for executing the above-described message identification method. Upon receiving a target message sent by a terminal device, the network processor 1222 of the interface board 1220 may execute the stored computer program for message identification to identify the target message and thereby determine the application to which the target message belongs.

[0262] In some embodiments, the network device may also be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a fifth generation (5G) mobile communication system, a next generation base station in a sixth generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system; it may also be a module or unit that performs part of the functions of a base station, for example, a centralized unit (CU) or a distributed unit (DU). The CU here completes the functions of the radio resource control (RRC) protocol and the packet data convergence protocol (PDCP) of the base station, and can also complete the function of the service data adaptation protocol (SDAP); the DU completes the functions of the radio link control (RLC) layer and the medium access control (MAC) layer of the base station, and can also complete the functions of part of the physical (PHY) layer or all of the physical layer. For detailed descriptions of the above-mentioned protocol layers, please refer to the relevant technical specifications of the 3rd Generation Partnership Project (3GPP). The network device can be a macro base station, a micro base station or an indoor station, a relay node or a donor node, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.

[0263] Figure 13 It is a structural diagram of a message identification device provided in this embodiment.

[0264] like Figure 13 As shown, in some embodiments, the message identification device 1300 may be a management platform or a management tool for executing the above message identification method. The message identification device 1300 includes one or more processors 1310, a memory 1320, a communication interface 1330, and a bus 1340.

[0265] Specifically, the processor 1310 may include one or more CPUs. Each of these processors 1310 may be a single-core processor or a multi-core processor. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0266] The memory 1320 exists independently, for example, and is connected to the processor 1310 via the bus 1340. The memory 1320 may also be integrated with the processor 1310.

[0267] The communication interface 1330 uses any transceiver-like device to communicate with other devices or communication networks, and the communication network can be Ethernet, a radio access network (RAN), or a wireless local area network (WLAN), etc. The communication interface 1330 may include a wired communication interface and a wireless communication interface. Specifically, the communication interface may be an Ethernet interface, a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. In an embodiment of the present application, the communication interface 1330 may be used to communicate with external devices such as electronic devices, mobile hard drives, and USB flash drives.

[0268] Optionally, bus 1340 is used to transmit information between components of the network device. Bus 1340 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. Bus 1340 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 The fact that only one line is used does not mean that there is only one bus or one type of bus.

[0269] In some embodiments, the message identification device 1300 may further include an output device and an input device. The output device communicates with the processor and can display information in a variety of ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 1310 and can receive user input in a variety of ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensor device.

[0270] An embodiment of the present application further provides a computer storage medium, which includes computer instructions. When the computer instructions are executed on the above-mentioned network device, the network device executes each step in the above-mentioned method embodiment.

[0271] The embodiment of the present application further provides a computer program product. When the computer program product is run on a computer, the computer is caused to execute each step in the above method embodiment.

[0272] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0273] It is easy to understand that those skilled in the art can combine, split, reorganize, etc. the embodiments of the present application based on the several embodiments provided in the present application to obtain other embodiments, and these embodiments do not exceed the scope of protection of the present application.

[0274] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0275] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0276] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0277] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk. It should be noted that, after considering the specification and practicing the application disclosed herein, it will be easy for those skilled in the art to think of other embodiments of the present application. This application is intended to cover any variants, uses or adaptive changes of the present application, which follow the general principles of the present application and include common knowledge or customary technical means in the art that are not disclosed in this application. It is intended that the specification and examples be considered as exemplary only, with a true scope of the application being indicated by the claims.

[0278] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A message identification method, characterized in that: include: Obtaining a target server address corresponding to a target message sent by a terminal device, wherein the target message includes a message with an encrypted message body; Determine the target domain name corresponding to the target server address; A target application in the terminal device is determined based on the target domain name, where the target application is the application that sends the target message.

2. The message identification method according to claim 1, characterized in that: Determining the target domain name corresponding to the target server address includes: The target domain name corresponding to the target server address is determined based on the target server address and a first list, wherein the first list includes a plurality of correspondences between server addresses and domain names, and one server address corresponds to at least one domain name.

3. The message identification method according to claim 2, characterized in that: The determining the target domain name corresponding to the target server address based on the target server address and the first list includes: querying the first list; In a case where the first list includes the domain name corresponding to the target server, the domain name corresponding to the target server address is determined as the target domain name.

4. The message identification method according to claim 3, characterized in that: The first list also includes an application identifier corresponding to each of the domain names; The determining the target domain name corresponding to the target server address based on the target server address and the first list further includes: In the case that the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are the same, any one of the domain names corresponding to the target server address is selected as the target domain name.

5. The message identification method according to claim 3, characterized in that: The first list also includes an application identifier corresponding to each of the domain names; The determining the target domain name corresponding to the target server address based on the target server address and the first list further includes: In a case where the first list includes a plurality of domain names corresponding to the target server address and the application identifiers corresponding to the plurality of domain names are different, determining the plurality of domain names corresponding to the target server address as pre-selected domain names; The target domain name is determined based on a plurality of preselected domain names and a second list, wherein the second list includes a plurality of correspondences between the domain names and the server addresses and states of the server addresses, and one domain name corresponds to at least one server address.

6. The message identification method according to claim 5, characterized in that: Determining the target domain name based on the plurality of pre-selected domain names and the second list includes: querying the second list; Determining the status of all the server addresses corresponding to each of the plurality of preselected domain names, where the status of the server addresses includes an active state and an idle state; One of the preselected domain names among the plurality of preselected domain names is determined to be the target domain name, and the status of all the server addresses corresponding to the target domain name is the active status.

7. The message identification method according to claim 6, characterized in that: In the second list, a method for determining the status of the server address includes: Monitor system connection tracking information; In a case where the system is monitored to establish the connection tracking, determining that the server address status corresponding to the destination server address in the connection tracking in the second list is the active status; In a case where it is monitored that the system deletes the connection tracking, it is determined that the state of the server address in the second list corresponding to the destination server address in the connection tracking is the idle state.

8. The message identification method according to any one of claims 4 to 7, characterized in that: The determining the target application in the terminal device based on the target domain name includes: The target application is determined based on the target domain name and the application identifier corresponding to the target domain name.

9. The message identification method according to any one of claims 4 to 7, characterized in that: The method further comprises: The service attributes of the target application are updated into the connection tracking information corresponding to the target server address, where the service attributes include the application identifier and the service type.

10. The message identification method according to claim 2, characterized in that: The method for determining the first list includes: Reading a domain name response message, where the domain name response message is a response message sent by a domain name server in response to a domain name resolution request of the terminal device, and the domain name response message includes a correspondence between the domain name and the server address; The server address and the domain name corresponding to the server address are recorded to form the first list.

11. The message identification method according to claim 2, characterized in that: The first list includes a first hash table; The server address is a key value of the first hash table, at least one domain name is an associated value of the first hash table, and the server address and the domain name corresponding to the server address form a first key-value pair of the first hash table; The first hash table includes multiple first hash buckets, and each of the first hash buckets can store one of the first key-value pairs.

12. The message identification method according to claim 11, characterized in that: The method of storing the first key-value pair in the first hash bucket includes: Obtain a first value based on the server address, where the first value is an integer; Dividing the first value by the total number of the first hash buckets to obtain a remainder result; The first key-value pair corresponding to the remainder result is stored in the first hash bucket whose subscript is the remainder result.

13. The message identification method according to claim 12, characterized in that: The method of storing the first key-value pair in the first hash bucket further includes: If the first hash bucket subscripted as the remainder result already stores other first key-value pairs, the first hash buckets are traversed backward sequentially to store the first key-value pair corresponding to the remainder result in the first unused first hash bucket.

14. The message identification method according to claim 12, characterized in that: The method of storing the key-value pair in the first hash bucket further includes: When the number of the first hash buckets storing the first key-value pairs exceeds a set threshold, the number of the first hash buckets is increased.

15. The message identification method according to claim 5, characterized in that: The second list includes a second hash table; The domain name is a key value of the second hash table, at least one of the server addresses and the status of the server address are associated values ​​of the second hash table, and the domain name, the server address corresponding to the domain name, and the status of the server address form a second key-value pair of the second hash table; The second hash table includes a plurality of second hash buckets, and each second hash bucket stores a second key-value pair.

16. The message identification method according to claim 1, characterized in that: The target message includes a Secure Sockets Layer (SSL) encrypted message and / or a Transport Layer Security (TLS) encrypted message.

17. A network device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the network device executes the message identification method according to any one of claims 1 to 16.

18. A computer-readable storage medium, characterized in that The method comprises computer instructions, which, when executed on a network device, enable the network device to execute the message identification method according to any one of claims 1 to 16.

19. A computer program product, characterized in that When the computer program product is run on a computer, the computer is enabled to execute the message identification method according to any one of claims 1 to 16.

Citation Information

Patent Citations

  • Application identification method and device

    CN103685601A

  • Method, device, device and system for tracking application access

    CN109495464A

  • Method and device for transmitting message and configuring mapping table

    CN114079646A

  • Flow ratio statistical method and device, electronic equipment and storage medium

    CN116094963A

  • Link detection method and device

    CN117651006A