A message identification method, network device and storage medium
By obtaining the target server address of the encrypted message and determining its domain name, the problem of routers being unable to identify encrypted message applications is solved, and accurate statistics on internet access time are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-28
- Publication Date
- 2026-04-03
AI Technical Summary
The router cannot identify the application to which the encrypted message belongs, resulting in inaccurate statistics on internet usage time.
By obtaining the target server address of the encrypted message, the corresponding target domain name can be determined, thereby identifying the target application and using the correspondence between the server address and the domain name to identify the message.
It improves the efficiency and accuracy of encrypted message recognition, ensuring the accuracy of online time statistics.
Smart Images

Figure CN120751037B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a message identification method, network device and storage medium. Background Technology
[0002] Currently, terminal devices (such as mobile phones and tablets) can access the internet wirelessly through routers. Routers can also track the internet usage time of connected devices, enabling features like preventing internet addiction and protecting children's online access. When tracking internet usage time, routers often rely on the interaction messages between the device's applications and their corresponding servers. Specifically, when tracking the internet usage time of different applications on a terminal device, the router needs to identify the sending application from the messages to determine the application's usage time.
[0003] However, some applications on terminal devices send encrypted messages, which the router cannot decrypt. This makes it impossible to determine the application to which the encrypted message belongs, and consequently, the router may miss the application corresponding to the encrypted message when counting internet access time, affecting the accuracy of the router's statistics on the application's internet access time on terminal devices. Summary of the Invention
[0004] To address the aforementioned issues, this application provides a message identification method, network device, and storage medium capable of identifying target messages, especially encrypted messages, thereby determining the application to which the target message belongs and improving the accuracy of statistics on the internet usage time of terminal devices.
[0005] To achieve the above objectives, in a first aspect, this application provides a message identification method, comprising: obtaining the target server address corresponding to a target message sent by a terminal device, wherein the target message includes a message with an encrypted message body; determining the target domain name corresponding to the target server address; and determining the target application in the terminal device based on the target domain name, wherein the target application is the application that sent the target message.
[0006] In this embodiment, the target server address of the unencrypted portion of the target packet can be obtained to determine the target domain name corresponding to the target server address, and the target application to which the target packet belongs can be determined through the target domain name. This allows for the identification of the target application corresponding to the target packet without parsing the target packet, improving the efficiency of target packet identification and reducing the possibility of missing target packets, thereby improving the accuracy of the router's statistics on application usage time.
[0007] In one optional implementation, determining the target domain name corresponding to the target server address includes: determining the target domain name corresponding to the target server address based on the target server address and a first list, wherein the first list includes multiple sets of correspondences between server addresses and domain names, and each server address corresponds to at least one domain name. In this way, the target domain name corresponding to the target server address can be determined through the correspondences between server addresses and domain names recorded in the first list.
[0008] In one optional implementation, determining the target domain name corresponding to the target server address based on the target server address and a first list includes: querying the first list; and if the first list includes a domain name corresponding to the target server, determining the domain name corresponding to the target server address as the target domain name. This allows for direct determination of the target domain name corresponding to the target server address, facilitating subsequent confirmation of the target application.
[0009] In one optional implementation, the first list further includes application identifiers corresponding to each domain name. Determining the target domain name corresponding to the target server address based on the target server address and the first list further includes: if the first list includes multiple domain names corresponding to the target server address and the application identifiers of these multiple domain names are the same, selecting any one of the domain names corresponding to the target server address as the target domain name. This allows for determining whether multiple domain names belong to the same application based on the application identifiers of the domain names when the domain names corresponding to the target server address are not unique. If multiple domain names have the same application identifier, it indicates that the multiple domain names belong to the same application, and any one of the domain names can be selected as the target domain name.
[0010] In one optional implementation, the first list further includes application identifiers corresponding to each domain name. Determining the target domain name corresponding to the target server address based on the target server address and the first list further includes: if the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to these multiple domain names are different, determining these multiple domain names as pre-selected domain names; determining the target domain name based on the multiple pre-selected domain names and a second list, where the second list includes multiple sets of correspondences between domain names and server addresses and the status of server addresses, and each domain name corresponds to at least one server address. This allows for determining whether multiple domain names belong to the same application by using the application identifiers corresponding to the domain names when the domain name corresponding to the target server address is not unique. If the application identifiers corresponding to multiple domain names are different, it indicates that the multiple domain names belong to different applications, and multiple domain names can be used as pre-selected domain names to narrow down the application scope corresponding to the target message. Then, the target domain name among the pre-selected domain names is determined using the second list that records the correspondences between domain names and server addresses and the status of server addresses.
[0011] In one optional implementation, determining the target domain name based on multiple pre-selected domain names and a second list includes: querying the second list; determining the status of all server addresses corresponding to each of the multiple pre-selected domain names, where the server address status includes active and idle states; and determining one of the multiple pre-selected domain names as the target domain name, where all server addresses corresponding to the target domain name are in an active state. This allows determining which pre-selected domain name is the target domain name based on the status of the server addresses corresponding to each pre-selected domain name in the second list.
[0012] In one optional implementation, the method for determining the status of server addresses in the second list includes: monitoring system connection tracking information; if a system connection tracking is detected, determining that the server address in the second list corresponding to the destination server address in the connection tracking is active; if a system connection tracking is detected being deleted, determining that the server address in the second list corresponding to the destination server address in the connection tracking is idle. In this way, the status of server addresses in the second list can be determined by monitoring connection tracking, facilitating the assessment of the status of each server address.
[0013] In one optional implementation, determining the target application on the terminal device based on the target domain name includes: determining the target application based on the target domain name and the application identifier corresponding to the target domain name. This allows for the determination of the target application based on the application identifier corresponding to the target domain name, improving identification efficiency and facilitating subsequent processing of internet usage time statistics.
[0014] In an optional implementation, the method further includes updating the service attributes of the target application to the connection tracking information corresponding to the target server address. The service attributes include an application identifier and a service type. This allows the router to determine the application and service type to which the connection tracking belongs when subsequently calculating internet access duration. This facilitates the calculation of internet access duration for the target packet based on the application and service type, effectively tracking the actual time the terminal device uses the application and avoiding omissions and inaccuracies.
[0015] In one optional implementation, the method for determining the first list includes: reading a domain name response message, wherein the domain name response message is a response message sent by a domain name server in response to a domain name resolution request from a terminal device, and the domain name response message includes the correspondence between domain names and server addresses; recording the server addresses and the domain names corresponding to the server addresses to form the first list. In this way, the correspondence between domain names and server addresses can be obtained using the domain name response message, thereby facilitating the formation of the first list.
[0016] In one optional implementation, the first list includes a first hash table, where the server address is the key and at least one domain name is the associated value. The server address and the corresponding domain name form a first key-value pair in the first hash table. The first hash table includes multiple first hash buckets, each of which can store one first key-value pair. This facilitates the storage of the mapping between server addresses and domain names and also facilitates subsequent queries, improving query efficiency.
[0017] In one optional implementation, the method of storing the first key-value pair in the first hash bucket includes: obtaining a first value based on the server address, wherein the first value is an integer; dividing the first value by the total number of the first hash buckets to obtain a remainder; and storing the first key-value pair corresponding to the remainder in the first hash bucket whose index is the remainder. This allows the first key-value pair to be stored in a specified first hash bucket, facilitating subsequent queries using the same method and improving query efficiency.
[0018] In an optional implementation, the method of storing the first key-value pair in the first hash bucket further includes: if the first hash bucket containing the remainder result already stores other first key-value pairs, sequentially traversing the first hash buckets and storing the first key-value pair corresponding to the remainder result in the first unused first hash bucket. This allows different server addresses to be stored in different first hash buckets when different server addresses correspond to the same remainder result, thus resolving the hash collision problem.
[0019] In one optional implementation, the method of storing key-value pairs in the first hash bucket further includes: increasing the number of first hash buckets when the number of first hash buckets storing the first key-value pairs exceeds a set threshold. This allows the first hash table to be expanded promptly when the number of first key-value pairs is large, thereby preventing a situation where the number of first key-value pairs exceeds the number of first hash buckets, resulting in the inability to store the first key-value pairs.
[0020] In one optional implementation, the second list includes a second hash table, where the domain name is the key, and at least one server address and the status of the server address are associated values. The domain name, its corresponding server address, and the server address's status form a second key-value pair in the second hash table. The second hash table includes multiple second hash buckets, each storing one second key-value pair. This facilitates the storage of the correspondence between domain names, server addresses, and server address statuses, and also facilitates subsequent queries, improving query efficiency.
[0021] In one alternative implementation, the target message includes a Secure Sockets Layer (SSL) encrypted message and / or a Transport Layer Security (TLS) encrypted message. This enables the identification of SSL encrypted messages and / or TLS encrypted messages.
[0022] To achieve the above objectives, in a second aspect, this application provides a network device, including: a memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, which, when executed by the processor, cause the network device to perform the message identification method provided in the first aspect above.
[0023] To achieve the above objectives, in a third aspect, this application provides a computer-readable storage medium including computer instructions that, when executed on a network device, cause the network device to perform the message identification method provided in the first aspect above.
[0024] To achieve the above objectives, in a fourth aspect, this application provides a computer program product that, when run on a computer, causes the computer to execute the message recognition method provided in the first aspect above.
[0025] It is understood that the beneficial effects that the technical solutions provided in the second to fourth aspects described above can be achieved by referring to the beneficial effects of the first aspect and any of its optional embodiments, which will not be repeated here. Attached Figure Description
[0026] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is a schematic diagram of a wireless internet access scenario for a terminal device provided in this embodiment;
[0028] Figure 2 This is a schematic diagram of the online time statistics function of a terminal device provided in this embodiment;
[0029] Figure 3 This is a schematic diagram of the first structure of a network device provided in this embodiment;
[0030] Figure 4 This is the first flowchart of a message identification method provided in this embodiment;
[0031] Figure 5 This is the second flowchart of a message identification method provided in this embodiment;
[0032] Figure 6 This is a schematic diagram of a domain name resolution process provided in this embodiment;
[0033] Figure 7 This is a schematic diagram of the first list provided in this embodiment;
[0034] Figure 8 This is the third flowchart of a message identification method provided in this embodiment;
[0035] Figure 9 This is a schematic diagram of the second list provided in this embodiment;
[0036] Figure 10 This is the fourth flowchart of a message identification method provided in this embodiment;
[0037] Figure 11 This is the fifth flowchart of a message identification method provided in this embodiment;
[0038] Figure 12 This is a schematic diagram of a second structure of a network device provided in this embodiment;
[0039] Figure 13 This is a schematic diagram of the structure of a message identification device provided in this embodiment. Detailed Implementation
[0040] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are all within the protection scope of this application.
[0041] In the following description, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0042] Furthermore, in this application, directional terms such as "upper," "lower," "inner," and "outer" are defined relative to the indicated placement of the components in the accompanying drawings. It should be understood that these directional terms are relative concepts, used for relative description and clarification, and can change accordingly depending on the placement of the components in the accompanying drawings.
[0043] Figure 1This is a schematic diagram of a wireless internet access scenario for a terminal device provided in this embodiment.
[0044] like Figure 1 As shown, currently, terminal device 100 can connect to router 200 via wireless communication technology, and utilize router 200 to achieve wireless connection to the Internet 300, thereby enabling terminal device 100 to access the Internet. The wireless communication technologies include, but are not limited to: wireless local area networks (WLAN), wireless fidelity (Wi-Fi), Bluetooth (BT), and fifth-generation mobile communication technology (5G). th 5G (5th generation mobile networks or 5th generation wireless systems) refers to technologies such as Global Navigation Satellite System (GNSS), Frequency Modulation (FM), Near Field Communication (NFC), and Infrared (IR).
[0045] It is worth noting that the terminal device 100 can be a mobile phone, tablet computer, handheld computer, personal computer (PC), ultra-mobile personal computer (UMPC), netbook, as well as cellular phone, personal digital assistant (PDA), augmented reality (AR) device, virtual reality (VR) device, artificial intelligence (AI) device, wearable device, vehicle device, etc. The embodiments of this application do not impose special restrictions on the specific type of the terminal device 100.
[0046] Specifically, the main interface 101 of the terminal device 100 can display multiple application icons, such as clock icons, calendar icons, gallery icons, memo icons, file management icons, browser icons, smart living icons, etc. The main interface 101 can also be used to display battery level, time, network signal, etc.
[0047] For example, when terminal device 100 receives an operation from a user clicking the browser icon 1011 on the main interface 101, terminal device 100 launches the browser application. The browser application of terminal device 100 and the server corresponding to the browser application can establish communication through router 200, and the data packets that need to be exchanged and transmitted between the browser application and the server corresponding to the browser application are also forwarded through router 200. The data packets exchanged between the browser application and the server can also be referred to as messages.
[0048] Furthermore, in addition to enabling wireless internet access for terminal device 100, router 200 can also collect statistics on the internet access information of terminal device 100. Thus, router 200 can also perform internet access duration statistics for terminal device 100, allowing users to monitor and control the internet access duration of a specific terminal device 100 or a specific application.
[0049] Figure 2 This is a schematic diagram of the online time statistics function of a terminal device provided in this embodiment.
[0050] Combination Figure 1 and Figure 2 As shown, for example, the online time statistics function of terminal device 100 can be included in smart living applications.
[0051] like Figure 2 As shown in (a), the main interface 101 of the terminal device 100 may include a smart life icon 1012. In response to the user's first click operation 401, the terminal device 100 launches the smart life application, and the screen displayed on the terminal device 100 changes from... Figure 2 The main interface 101 shown in (a) switches to Figure 2 The smart living application interface 102 is shown in (b) above. The first click operation 401 is clicking the smart living icon 1012 within the main interface 101. The smart living application interface 102 displays smart devices capable of establishing communication connections with the terminal device 100, such as televisions, speakers, projectors, and routers 200. Simultaneously, the smart living application interface 102 also displays the name, location, and online status of each smart device. Figure 2 Taking the living room router icon 1021 in (b) as an example, the living room router icon 1021 displays the smart device's name as "Living Room Router," its online status as "Online," and the location of the router 200 as "Living Room." In this way, users can access basic information about the living room router through the terminal device 100.
[0052] In response to the user's second click operation 402 on the router icon 1021 in the living room, the terminal device 100 changes the screen displayed on the terminal device 100. Figure 2 The smart living application interface 102 shown in (b) switches to... Figure 2 The living room router interface 103 is shown in (c). The second click operation 402 involves clicking the living room router icon 1021 on the smart living application interface 102. The living room router interface 103 displays multiple function icons, including a child internet access function icon 1031. The child internet access function can implement child protection for devices connected to the living room router 200, such as anti-addiction protection.
[0053] In response to the user's third click operation 403 on the child internet access function icon 1031, the terminal device 100 changes the screen displayed on the terminal device 100 from... Figure 2 The router interface 103 in the living room shown in (c) is switched to... Figure 2 The child internet access interface 104 is shown in (d). The third click operation 403 is clicking the child internet access function icon 1031 on the living room router interface 103. The child internet access interface 104 includes a protected device option 1041 and an unprotected device option 1042. A protected device is a device that has established a communication connection with the living room router 200 and is in child protection mode; an unprotected device is a device that has established a communication connection with the living room router 200 but is not in child protection mode. Figure 2 As shown in (d) of the parental control interface 104, the "Honor V40" device is currently in parental protection mode. Users can click the Honor V40 icon 1043 to view specific protection information for the "Honor V40".
[0054] In response to the user's fourth click operation 404 on the Honor V40 icon 1043, the terminal device 100 changes the screen displayed on the terminal device 100. Figure 2 The child internet access interface 104 shown in (d) is switched to... Figure 2The Honor V40 device interface 105 is shown in (e). The fourth click operation 404 is clicking the Honor V40 icon 1043 on the parental control interface 104. The Honor V40 device interface 105 displays the following options: "One-Click Disconnect," "Allow All," "Internet Access Time Statistics," "Allowed Internet Access Periods," and "Allowed Internet Access Duration." The "One-Click Disconnect" function disconnects the device from the internet while it is in parental control mode and has a network connection. For example, if a child wants to stop all internet access functions of the Honor V40 device while it is in parental control mode, they can click the "One-Click Disconnect" icon to disconnect the device from the internet, thus preventing the user from continuing to access the internet. The "Allow All" function allows devices in parental control mode that have lost their network connection to establish a network connection. For example, if the Honor V40 device is disconnected from the internet, clicking the "Allow All" icon allows it to establish a network connection, thus fulfilling the device's internet access needs. The "Internet Usage Time Statistics" feature tracks the total internet usage time for each application on the Honor V40 device, allowing users to easily understand their device's overall internet usage and the usage time for each application. The "Allowed Internet Usage Time" feature allows users to control the specific times their Honor V40 device can access the internet. For example, users can set internet access from 5:00 PM to 7:00 PM daily, or restrict it to weekends. The "Allowed Internet Usage Duration" feature allows users to control the duration of internet access, such as setting it to 2 hours per day.
[0055] When a user wants to learn more about the internet browsing time statistics of the Honor V40 device, they can click the "More Options" icon 1051 corresponding to "Internet Browsing Time Statistics". In response to the user's fifth click 405 on the "More Options" icon 1051, the terminal device 100 changes its display screen from... Figure 2 The Honor V40 device interface shown in (e) 105 is switched to... Figure 2 The online time statistics details interface 106 is shown in (f). The fifth click operation 405 is clicking the "More Options" icon 1051 corresponding to "Online Time Statistics" on the Honor V40 device interface 105. The online time statistics details interface 106 displays the device's online time for applications in several service types: "Learning," "Video," "Social," "Games," and "Others," and also displays the specific online time statistics for each application. This allows users to understand the specific time spent using each application while browsing the internet on the Honor V40 device, facilitating internet control and protection for the device.
[0056] For example, an application with a business type of learning may include Applications used for learning. Video applications, for example, can include... Applications used for watching videos. Applications with a social business type may include... and Applications used for communication and dialogue. Applications whose business type is gaming may include... as well as Applications used for playing games, etc.
[0057] As explained above, when a user wants to understand and configure the internet access status of devices connected to router 200, they can utilize the application duration statistics function of router 200 and display the statistical data on terminal device 100 to implement the parental control function of terminal device 100. To achieve the internet access duration statistics function, router 200 can use the interaction messages between the application on terminal device 100 and the corresponding server to calculate the internet access duration of that application.
[0058] Optionally, an identification module can be configured within the router 200. Upon receiving a packet, the identification module can parse the packet to identify the type of service and application it belongs to, and record the service identifier and application identifier in the relevant information of the connection to which the packet belongs. Therefore, when the router 200 calculates internet usage time based on connection tracking information, it can calculate the corresponding internet usage time from both service and application dimensions. The service dimension refers to the type of service, such as games, video, shopping, and others.
[0059] Specifically, when router 200 receives a message sent to the server by an application from terminal device 100, the identification module can parse the message to determine the application that sent it based on its content. Simultaneously, to facilitate the statistical analysis of internet usage time for each application, each application has a unique identifier (id) to represent it. When sending a message, an application can add its identifier to the message for the identification module to recognize. For example, the identifier for the Baidu application is id=53. When the Baidu application sends a message to the server, it can include information with id=53. Thus, after recognizing id=53, the identification module can directly determine that the message originated from the Baidu application.
[0060] Furthermore, after identifying the application code corresponding to the packet, the identification module can update the application code in the connection tracking information. The router periodically monitors the connection tracking information to determine the application's online duration.
[0061] For example, a connection tracking record could contain the following information: ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, sport=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=131, sc_categ=4, sc_action=0.
[0062] The connection trace described above can also be called a server flow (IP flow). "ipv4" indicates that the IPv4 protocol is used; IPv4 is the fourth version of the Internet Protocol. The "2" field indicates the network layer protocol type, where "2" represents Transmission Control Protocol (TCP). "tcp" indicates that the transport layer uses the TCP protocol. "6" indicates the TCP version number used. "295" indicates the connection's lifetime is 295 seconds. "ESTABLISHED" indicates the connection has been established. "src=192.168.3.7" indicates the source server address is 192.168.3.7. "dst=106.75.107.247" indicates the destination server address is 106.75.107.247. "sport=38844" indicates the source port number is 38844. "dport=6810" indicates the destination port number is 6810. "[ASSURED]" indicates that the connection has been authenticated or acknowledged. "mark=3491758080" represents the connection identifier. "zone=0" indicates the security zone to which this connection belongs. "ifindex=34" represents the network interface index number used by this connection. "ctaddr=32fedb78" represents the connection address. "httpmark=0" represents the HTTP identifier. "use=2" indicates the number of times this connection has been referenced. "sc_id=131" represents the application identifier, used to determine which application the connection belongs to. "sc_categ=4" represents the application's service type, used to determine the type of service the connection belongs to. "sc_action=0" indicates that the application is in a permitted state, meaning the application can access the internet normally.
[0063] Based on the connection tracking information above, it can be seen that the connection tracking records the internet access information of application ID=131. The router can check the existence of this connection tracking every 10 seconds. If it exists, it can increase the internet access time of application ID=131 by 10 seconds; if it does not exist, it can stop the statistics on the internet access time of application ID=131.
[0064] Furthermore, in the connection tracking information, "sc_categ=4" indicates the application's service type. The router can record this information when calculating the online time of applications of different service types. The method for calculating the online time of applications of the same service type can be to sum the online time of applications with the same service type, or it can refer to the methods for calculating the online time of applications; these will not be elaborated upon here.
[0065] For example, the identification module can be a Deep Packet Inspection Engine (DPI). Alternatively, the identification module can also be an application identification engine, a data stream analysis engine, etc., which are not limited in this embodiment.
[0066] Furthermore, the messages sent by the application on terminal device 100 can include plaintext messages and encrypted messages. Encrypted messages have no unique identifiers compared to plaintext messages, and the communication port is randomized. Plaintext messages can be Uniform Resource Locator (URL) plaintext messages, Hypertext Transfer Protocol (HTTP) plaintext messages, etc. Encrypted messages can be Secure Sockets Layer (SSL) encrypted messages or Transport Layer Security (TLS) encrypted messages, etc. Game and online learning applications on terminal device 100 are more likely to send encrypted messages.
[0067] When router 200 receives a plaintext message, it can directly identify the plaintext message to determine the service type and application to which it belongs. However, when router 200 receives an encrypted message, its identification module cannot parse the encrypted message, thus failing to determine the service type and application to which it belongs. Consequently, the connection information corresponding to the encrypted message and the connection tracking information lack information such as application encoding and service type. Therefore, when statistically analyzing the internet access time of the application that sent the encrypted message, it may miss some due to the inability to identify the encrypted message, leading to inaccurate statistics on the application's internet access time.
[0068] To address the aforementioned issues, this application provides a message identification method capable of identifying target messages, especially encrypted messages, thereby determining the service type and application to which the target message belongs and improving the accuracy of online time statistics for applications.
[0069] Figure 3 This is the first structural schematic diagram of a network device provided in this embodiment.
[0070] Please see Figure 3 For example, the message identification method provided in this embodiment can be applied to network device 500. Network device 500 may be a router, switch, network storage device, network switching device, and network adapter (smart network card), etc. In this embodiment, the specific type of network device 500 is not limited.
[0071] The network device 500 includes: a processing module 510, a wireless communication module 520, a storage module 530, a power supply module 540, a communication interface module 550, a switch 560, an identification module 570, and an antenna.
[0072] The processing module 510 may include one or more processors to process the above-described message identification method, thereby determining the service type and application to which the target message belongs and improving the accuracy of online time statistics for the application.
[0073] Specifically, the processor can be a general-purpose central processing unit (CPU), digital signal processor (DSP), network processor (NP), graphics processing unit (GPU), neural-network processing unit (NPU), data processing unit (DPU), microprocessor, or one or more integrated circuits for implementing the solutions of this application. For example, the processor includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A PLD may be, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the embodiments of this application. The processor can also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0074] Furthermore, the processing module 510 may include any one of the processors described above, or it may include multiple processors described above. In some embodiments, different processing units may be independent devices, or they may be integrated into one or more processors. The CPU is the final execution unit for information processing and program execution, and its main tasks include processing instructions, executing operations, controlling time, and processing data. The CPU may include a controller, an arithmetic logic unit (ALU), a cache memory, and a bus for connecting these components.
[0075] The wireless communication module 520 can provide wireless communication such as Wi-Fi, frequency modulation (FM), Bluetooth, or NFC. The wireless communication module 520 can be one or more devices integrating at least one communication processing module. The wireless communication module 520 receives electromagnetic waves via an antenna, performs frequency modulation and filtering of the electromagnetic wave signal, and sends the processed signal to the processing module 510. The wireless communication module 520 can also receive signals to be transmitted from the processing module 510, perform frequency modulation and amplification on them, and convert them into electromagnetic waves for radiation via the antenna.
[0076] Storage module 530 can be used to store computer executable program code, including computer instructions. Processing module 510 performs various functions and data processing by running the instructions stored in storage module 530. Storage module 530 may include a program storage area and a data storage area. The program storage area can store the application program required for at least one function (such as counting internet usage time, sending messages, etc.). The data storage area can store connection-related information, etc.
[0077] Specifically, the storage module 530 may include a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, or random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program instructions in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0078] The storage module 530 may exist independently and be coupled to the processing module 510, or the storage module 530 may be integrated into the processing module 510. In this embodiment, no limitation is made.
[0079] The power module 540 can be used to receive power input, store electrical energy, and supply power to the processing module 510, the wireless communication module 520, the storage module 530, etc.
[0080] The communication interface module 550 is a device that uses any transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), or Wireless Local Area Network (WLAN). The communication interface module 550 may include a wired communication interface and a wireless communication interface. Specifically, the communication interface may be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a WLAN interface, a cellular network communication interface, or a combination thereof. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. In this embodiment, the communication interface module 550 can be used by the network device 500 to communicate with other devices.
[0081] Switch 560 is used to trigger the opening or closing of network device 500.
[0082] The identification module 570 is used to identify messages and can execute the above method to identify target messages. The identification module 570 can be integrated into the processing module 510 or independent of other modules, and this embodiment is not limited thereto.
[0083] The network device 500 provided in this embodiment is used to execute the above method and can achieve the same effect as the above implementation method. When using integrated units, the network device may also include only a processing module, a storage module, and a communication module. The processing module can be used to control and manage the device's actions; for example, it can support the device in executing the steps performed by the processing unit. The storage module can support the device in executing stored program code and data. The communication module can support communication between the device and other devices.
[0084] Figure 4 This is the first flowchart of a message identification method provided in this embodiment.
[0085] Please see Figure 4 This embodiment provides a message identification method, including:
[0086] Step S110: Obtain the target server address corresponding to the target message sent by the terminal device.
[0087] The target message includes messages with their message bodies encrypted.
[0088] The target message sent by the terminal device typically includes a message header and a message body. The target message includes the message body of the message after encryption, such as an encrypted message. Alternatively, the target message can also be a plaintext message, a command message, a response message, an event message, etc. In this embodiment, the target message is not limited.
[0089] The header of the destination packet includes the address of the target server to which the packet needs to be delivered. To avoid sending the destination packet to the wrong server, the target server address in the header is usually unencrypted and can be directly obtained. This allows the router to forward the destination packet to the appropriate server based on the target server address in the header, ensuring that the packet is delivered to the correct server.
[0090] The message body of a target message typically includes the original data, which has been encrypted. Once encrypted, the data is in an unreadable form. Only a trusted entity with the decryption key can decrypt it and restore the original data content, and then determine the application to which the target message belongs based on the data content in the message body.
[0091] In this embodiment, when a target message sent by a terminal device is received, it is difficult to decrypt the message body, making it impossible to determine the application to which the target message belongs based on the data within the message body. Decrypting the message body by obtaining the decryption keys corresponding to various target messages and then identifying the target message would severely impact the identification efficiency and consume significant resources. Therefore, when identifying the application to which a target message belongs, the address of the target server (which is not encrypted) within the target message can be obtained first, thereby enabling the identification of the target message through the target server address.
[0092] For example, the target message sent by the terminal device can be an application within the terminal device whose service type is game (e.g., Online learning applications (such as...) This embodiment does not limit the applications within the terminal device that can send target messages.
[0093] Optionally, the target message can be an SSL encrypted message or a TSL encrypted message. In this embodiment, the specific type of encrypted message is not limited.
[0094] Step S120: Determine the target domain name corresponding to the target server address.
[0095] Typically, before an application on a terminal device sends an interaction message to the target server address, it first sends a domain name resolution request to a domain name system (DNS) server. The DNS server can then query the server address corresponding to the domain name in the resolution request and send it to the application. This server address indicates the location of the server storing the target website's content. In this way, when the application communicates with the server, it can determine which server address to send the interaction message to.
[0096] For example, if the domain name in the domain name resolution request is "weixin.qq.com", the domain name server can resolve "weixin.qq.com" to the server address "220.196.132.101". After the domain name is resolved to the server address, the domain name server sends the server address "220.196.132.101" to the application. After obtaining the server address, the application on the terminal device uses "220.196.132.101" as the target server address in the message header when communicating with the server, so as to send the message to the specified server.
[0097] As explained above, the target server address "220.196.132.101" is obtained based on the resolution of the domain name "weixin.qq.com". In other words, the target server address corresponds to a domain name. Therefore, after obtaining the target server address of the target message, the target domain name corresponding to the target server address can be determined based on the mapping between server addresses and domain names. This target domain name is the domain name in the domain name resolution request sent by the application on the terminal device.
[0098] It's worth noting that when an application on a terminal device sends a domain name resolution request to a domain name server, it can first send the request to the local domain name server. If the local domain name server has already cached the server address corresponding to the domain name, it can directly return that server address to the application on the terminal device. If the local domain name server does not cache the server address corresponding to the domain name, it will initiate a request to a higher-level domain name server until it finds the server address corresponding to the domain name.
[0099] Furthermore, the domain name resolution request sent by the terminal device to the local domain name server can be forwarded to the local domain name server by the router.
[0100] In one implementation, the router can provide a built-in domain name service. When the router receives a domain name resolution request from an application on a terminal device, it can directly use the built-in domain name service to resolve the domain name, thereby realizing the function of a local domain name server.
[0101] In another implementation, a dedicated local name server can be set up, and the router's configuration will include an address pointing to this local name server. When the router receives a domain name resolution request from an application on a terminal device, it can forward the request to the local name server configured in the router's settings, based on the address of the local name server. Upon receiving the request, the local name server will query the corresponding domain name resolution result and return it to the router, which then returns the result to the requesting terminal device and application.
[0102] As explained above, when a terminal device's application sends a domain name resolution request, the router can obtain the domain name resolution result, thereby confirming the correspondence between the domain name and the server address. In this way, the router can obtain the target domain name corresponding to the target server address.
[0103] For example, if the terminal device When an application sends a domain name resolution request to a domain name server, the router forwards the request to the local domain name server. In this case, the domain name requested in the resolution request is "weixin.qq.com". The local domain name server resolves "weixin.qq.com" to the server address "220.196.132.101" and sends it to the router. The router then forwards the server address "220.196.132.101" to the terminal device. Application. Thus, the terminal device The target server address of the interactive message sent by the application to the server is "220.196.132.101", and the router can determine the target domain name corresponding to the target server address as "weixin.qq.com" based on the domain name resolution request record.
[0104] Step S130: Determine the target application in the terminal device based on the target domain name.
[0105] Here, the target application is the application that sends the target message. In other words, the target application is the application to which the target message belongs.
[0106] For example, a domain name typically consists of multiple parts separated by periods. For instance, "weixin.qq.com" is a domain name that consists of three parts: the top-level domain ".com", the main domain "qq", and the subdomain "weixin". From the main domain and subdomain, it can be seen that this domain name corresponds to... Application. It can be seen that when identifying the target application, the domain name corresponding to the target message can be used to determine the target application, thereby achieving the identification of the target message.
[0107] In this embodiment, the target server address can be obtained from the unencrypted target packet to determine the target domain name corresponding to the target server address, and the target application to which the target packet belongs can be determined through the target domain name. This allows for the identification of the target application corresponding to the target packet without parsing the target packet, improving the efficiency of target packet identification and reducing the possibility of missing target packets, thereby improving the accuracy of the router's statistics on application usage time.
[0108] Figure 5 This is the second flowchart of a message identification method provided in this embodiment.
[0109] like Figure 5 As shown, in some embodiments, the message identification method includes:
[0110] Step S210: Obtain the target server address corresponding to the target message sent by the terminal device.
[0111] As can be seen from the description of step S110 above, the target server address of the target message is not encrypted and can be read directly, thereby enabling the acquisition of the target server address corresponding to the target message sent by the terminal device.
[0112] For example, the header of the target message may include the information "dst=106.119.193.231". Here, "dst" represents the target server address. In this case, "dst=106.119.193.231" indicates that the target server address of the target message is 106.119.193.231. When the router obtains the target server address from the target message, it can directly identify the "dst" character and read the characters following it to obtain the target server address.
[0113] It is understood that the message header may also include information such as the source address, the protocol version of the network layer, and the protocol type of the transport layer. In this embodiment, the information and specific form in the message header are not limited.
[0114] It is worth noting that the explanation of step S210 can refer to step S110 above, and will not be repeated here.
[0115] Step S220: Query the first list.
[0116] The first list includes multiple sets of mappings between server addresses and domain names, with each server address corresponding to at least one domain name. Thus, the target domain name corresponding to the target server address can be determined using the first list.
[0117] Since the data content within the message body of the target packet is encrypted, it is impossible to directly obtain the application and corresponding domain name information of the target packet. To determine the target application of the target packet, the domain names corresponding to each server address can be pre-recorded in a first list and stored in the router. When identifying the target packet, the first list can be directly accessed and queried, thereby determining the target domain name corresponding to the target server address of the target packet.
[0118] In some embodiments, the method for determining the first list may include:
[0119] Step S221: Read the domain name response message.
[0120] Among them, the domain name response message is the response message sent by the domain name server in response to the domain name resolution request of the terminal device. The domain name response message includes the correspondence between the domain name and the server address.
[0121] In this embodiment, when a terminal device connects to a router to access the internet wirelessly, it needs to continuously interact with the server while using applications on the terminal device. During this interaction, the terminal device's applications can send target packets to the server.
[0122] Before communicating with the server using the target message, the terminal device first sends a domain name resolution request to the router. In one example, the router has a built-in domain name service and can directly respond to the domain name resolution request, thereby sending a domain name response message to the terminal device.
[0123] Figure 6 This is a schematic diagram of a domain name resolution process provided in this embodiment.
[0124] like Figure 6 As shown in another example, if the router does not have a built-in domain name service, the router can forward the domain name resolution request from the terminal device to the local domain name server in the gateway. After receiving the domain name resolution request, the gateway sends a domain name response message to the router, which then forwards the domain name response message to the terminal device.
[0125] In both examples above, the router can directly obtain the domain name response message regardless of whether it is sent by the router or the gateway.
[0126] For example, a domain name response message is the response information returned by a domain name server to a terminal device client after resolving a domain name resolution request. The domain name response message contains a domain name and all the server addresses corresponding to that domain name.
[0127] Specifically, the content of the domain name response message may include:
[0128] "ml.mp.weixin.qq.com:type A,class IN,addr 220.196.132.101
[0129] ml.mp.weixin.qq.com:type A,class IN,addr 112.65.194.79
[0130] ml.mp.weixin.qq.com:type A,class IN,addr 116.128.135.25
[0131] ml.mp.weixin.qq.com:type A,class IN,addr 116.128.164.66”
[0132] In the above content, "ml.mp.weixin.qq.com" represents the domain name to be queried, "type A" indicates the type of query. "A" indicates that the query is for the IPv4 address corresponding to the domain name, "class IN" indicates the category of the query, and "IN" indicates the internet category, indicating that this is a common domain name query on the internet. "addr 220.196.132.101" indicates the query result, which means that the IPv4 address corresponding to the domain name "ml.mp.weixin.qq.com" is "220.196.132.101". Here, IPv4 address is the Internet Protocol address used by Internet Protocol version 4 (IPv4).
[0133] In internet communication, a server typically has one or more server addresses to facilitate communication between other devices and the server. Furthermore, based on the domain name response message mentioned above, there are four server addresses corresponding to the domain name "ml.mp.weixin.qq.com".
[0134] It is worth noting that for other domain names, the server address recorded in the domain name response message can also be only one. In this embodiment, the number of server addresses in the domain name resolution result is not limited.
[0135] Step S222: Record the server address and the domain name corresponding to the server address to form the first list.
[0136] In this embodiment, after obtaining the correspondence between server addresses and domain names, the server addresses and their corresponding domain names can be recorded to form a first list. This facilitates the identification of the target application based on the server address when identifying target packets later.
[0137] For example, the first list may be stored in the router's memory or in the router's identification module, and this embodiment is not limited thereto.
[0138] Figure 7 This is a schematic diagram of the first list provided in this embodiment.
[0139] like Figure 7 As shown, in some embodiments, the first list can be a first hash table.
[0140] In the first hash table, the server address is the key, and at least one domain name is the associated value. The server address and the corresponding domain name form the first key-value pair in the first hash table. The first hash table may include multiple first hash buckets, and each first hash bucket may store one first key-value pair.
[0141] It's worth noting that the same server address can interact with applications on multiple terminal devices. Thus, the same server address can correspond to multiple different domain names.
[0142] For example, the domain names stored in the first hash bucket can be in the form of regular expressions. This makes it easier to process and manipulate the domain name strings.
[0143] For example, the domain name "bdstatic.com" can be represented using regular expressions as "\.bdstatic\.com$", where ".com$" matches strings ending with ".com", and "\.bdstatic\" matches the literal string ".bdstatic" appearing in the matched string. Using regular expressions for domain name matching allows for direct identification of key characters, improving recognition efficiency, simplifying domain name representation, and facilitating storage and retrieval.
[0144] In the first hash table, the indices of each first hash bucket range from 0 to (N-1), where N is the total number of first hash buckets. The index of the first first hash bucket is 0, the index of the last first hash bucket is N-1, and the indices of the first hash buckets between the first and last first hash buckets are incremented by one sequentially.
[0145] For example, if the total number of first hash buckets is 1024, then the index of the first hash bucket is 0, the index of the last first hash bucket is 1023, and the indices of the first hash buckets between the first and last first hash buckets are 2, 3, 4, ..., 1022.
[0146] Figure 8This is the third flowchart of a message identification method provided in this embodiment.
[0147] like Figure 8 As shown, since there are multiple first key-value pairs that need to be stored, and there are also multiple first hash buckets, in order to improve the efficiency of storing the first key-value pairs in the first hash bucket, the following method can be used to store the first key-value pairs into the specified first hash bucket:
[0148] Step S2221: Obtain the first value based on the server address.
[0149] The first value is an integer.
[0150] When storing a server address in the first hash bucket, the location of the first hash bucket needs to be selected. In other words, the server address needs to be stored in a designated first hash bucket according to certain rules. This reduces the possibility of different first key-value pairs being stored in the same first hash bucket. Furthermore, during subsequent table lookups, searches can be performed based on the storage rules, thereby improving query efficiency.
[0151] Server addresses are typically composed of four decimal digits, each ranging from 0 to 255, separated by periods. For example, the server address 106.119.193.231 is composed of 106, 119, 193, and 231, each between 0 and 255. The range of the four parts in a server address is relatively small, and repetition is easy. If one of these parts is used as the first value for selecting the first hash bucket position, it's easy for different server addresses to correspond to the same first hash bucket during storage, resulting in hash collisions.
[0152] For the reasons mentioned above, a server address can be converted into a corresponding integer and used as the first value, thereby reducing the possibility of hash collisions.
[0153] For example, each decimal digit in the server address can be converted to a binary number, and the resulting binary numbers can be concatenated to form a long string. This long binary string can then be converted back to a decimal number to obtain an integer.
[0154] Specifically, for the server address 106.119.193.231, each part is 106, 119, 193, and 231. Converting 106 to binary gives 1101010, 119 gives 1110111, 193 gives 11000001, and 231 gives 11100111. Concatenating these binary strings forms the long string corresponding to the server address: 110101011101111100000111100111. Converting this long string to decimal gives the integer 4545448783. Therefore, the first value corresponding to the server address 106.119.193.231 is 4545448783.
[0155] It is understood that in other implementations, the first value can be obtained through other calculation methods, and this embodiment is not limited thereto.
[0156] Step S2222: Divide the first value by the total number of the first hash buckets to obtain the remainder.
[0157] The initial value obtained by converting the server address might be quite large, while the number of hash buckets might be relatively small, causing the initial value to be much larger than the index of the first hash bucket. Therefore, the initial value can be further processed to obtain the index of the first hash bucket corresponding to the server address.
[0158] In this embodiment, the first value can be divided by the total number of the first hash buckets to obtain a remainder corresponding to the server address. Since the remainder is greater than or equal to zero and less than the total number of the first hash buckets, it falls within the index range of the first hash buckets. Thus, the first hash bucket specified by the server address can be selected based on the remainder.
[0159] Specifically, if the first value is 4545448783 and the total number of the first hash buckets is 1024, then 4545448783 ÷ 1024 = 4438914...847. The remainder when the first value is divided by the total number of the first hash buckets is 847. Therefore, the first hash bucket can be selected based on the remainder of 847.
[0160] Step S2223: Store the first key-value pair corresponding to the remainder result in the first hash bucket with the index of the remainder result.
[0161] The remainder result corresponds to the server address, and the first key-value pair corresponding to the server address is also the first key-value pair corresponding to the remainder result. By storing the first key-value pair corresponding to the remainder result in the first hash bucket with the index of the remainder result, it is possible to store the key-value pairs corresponding to different servers in different first hash buckets, thereby reducing the possibility of hash collisions and facilitating subsequent query processes.
[0162] In some embodiments, the method of storing the first key-value pair in a designated first hash bucket further includes:
[0163] Step S2224: If the first hash bucket with the index of the remainder result already contains other first key-value pairs, traverse the first hash buckets sequentially and store the first key-value pairs in the first unused first hash bucket.
[0164] The unused first hash bucket refers to the first hash bucket that does not store the first key-value pair.
[0165] In this embodiment, when the server address is converted into a first value and then the remainder result is obtained using the first value, the same remainder result may be obtained for different server addresses, leading to hash collisions.
[0166] To avoid the aforementioned problem, if the first hash bucket corresponding to the remainder result at the index of the server address already contains the first key-value pair, then we can continue traversing the first hash buckets until we find the first unused first hash bucket and store the first key-value pair in that first hash bucket. This resolves the hash collision problem that occurs when forming the first list.
[0167] In some embodiments, the method of storing the first key-value pair in a designated first hash bucket further includes:
[0168] Step S2225: If the number of first hash buckets storing first key-value pairs exceeds a set threshold, increase the number of first hash buckets.
[0169] In this embodiment, during the process of recording and storing the first key-value pairs, there may be a situation where the number of first key-value pairs is large while the number of first hash buckets is insufficient, which may result in some first key-value pairs being unable to be stored in the first hash table.
[0170] To address the aforementioned issue, if the number of first hash buckets storing the first key-value pairs exceeds a set threshold, the number of first hash buckets can be increased, thereby expanding the first hash table to prevent an overabundance of first key-value pairs that cannot be stored.
[0171] For example, if the initial number of the first hash buckets in the first hash table is 1024, the first hash table can be expanded when the number of the first hash buckets storing the first key-value pairs exceeds 768 (75% of the initial number).
[0172] Optionally, the threshold can be set to 50%, 75%, 80%, 85% of the initial number of the first hash bucket, etc., and is not limited in this embodiment.
[0173] It is worth noting that in other embodiments, the first key-value pair may be stored in the first hash bucket in other ways, and this embodiment is not limited to that.
[0174] It is understood that in other implementations, the first list may also be other forms of tables, arrays, etc., and is not limited in this embodiment.
[0175] Furthermore, the first list can be pre-created and stored in the router, and does not need to be updated during subsequent queries. Alternatively, after the first list is pre-created and stored in the router, it can be updated synchronously during the identification of target packets; this is not limited in this embodiment.
[0176] Step S230: If the first list includes a domain name corresponding to the target server address, determine that the domain name corresponding to the target server address is the target domain name.
[0177] In this embodiment, the first list stores the domain names corresponding to each server address. After obtaining the target server address corresponding to the target message and the first list, the domain name corresponding to the target server address can be queried in the first list to determine the target domain name corresponding to the target server address.
[0178] For example, when querying the first list, the query can be performed based on the method of storing the server address in the first list. First, it is necessary to determine the location of the first hash bucket storing the target server address. If the first hash bucket stores only one domain name corresponding to the target server address, then that domain name can be identified as the target domain name corresponding to the target server address. In other words, if the first hash bucket stores only one domain name corresponding to the target server address, then that domain name is the target domain name corresponding to the target message.
[0179] It is worth noting that the location of the first hash bucket containing the target server address can be determined by referring to the method of storing the first key-value pair to the specified first hash bucket in steps S2221 to S2223 above, which will not be repeated here.
[0180] In some embodiments, if the method of step S2224 is used in the process of storing the first key-value pair into the specified first hash bucket, then when querying the first list, if the server address in the first hash bucket determined according to steps S2221 to S2223 is not the target server address, the traversal can continue until the first hash bucket storing the target server address is found.
[0181] Please refer to it again. Figure 7 In some embodiments, the first list stores not only server addresses and domain names, but also application identifiers corresponding to each domain name. An application may have multiple domain names, for example... The domain name corresponding to the application can be "\.bdstatic\.com$" or "^hm\.baidu\.com$". To facilitate application identification through domain name, an application identifier can be added to each domain name, so that different domain names belonging to the same application have the same application identifier, thus making identification easier.
[0182] For example, if the first list is a first hash table, the application identifier corresponding to each domain name can be stored in the same location as the domain name in the first hash bucket. This way, when determining a target domain name, the application identifier corresponding to that target domain name can be obtained simultaneously.
[0183] Optionally, the application identifier can be an application code ID, and different applications can be represented using different application code IDs. In this way, when calculating the online time of an application, the statistics can be directly performed by identifying the application code ID, which is convenient for operation.
[0184] Specifically, The application's application code id = 53. Therefore, the domain names "\.bdstatic\.com$" and "^hm\.baidu\.com$" can correspond to the same application code id, indicating that both domain names are... The domain name of the application.
[0185] It is worth noting that the application identifier can also be other identifiers, such as application name, letters, symbols, etc., which are not limited in this embodiment.
[0186] Step S240: If the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are the same, select any one of the domain names corresponding to the target server as the target domain name.
[0187] As explained above, when a server address corresponds to multiple domain names and the application identifiers of these domain names are the same, it means that the multiple domain names belong to the same application. Therefore, using any one of these domain names as the target domain name will allow you to find the corresponding target application.
[0188] For example, when the target server address is "211.91.68.249", in the first list, the domains corresponding to the target server address include the domain "\.bdstatic\.com$" and the domain "^hm\.baidu\.com$". Furthermore, the application code corresponding to both domains "\.bdstatic\.com$" and "^hm\.baidu\.com$" is id=53, indicating that "\.bdstatic\.com$" and "^hm\.baidu\.com$" belong to the same application, and either one can be selected as the target domain.
[0189] Step S250: If the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, determine the multiple domain names corresponding to the target server address as pre-selected domain names.
[0190] In this embodiment, if the first list includes multiple domain names corresponding to the target server address, and the application identifiers corresponding to these multiple domain names are different, it indicates that the target server address corresponds to domain names of multiple different applications. The reason for this problem may be that different business resources are placed on the same cloud server (e.g., (This is done through third-party cloud providers). In other words, different applications may communicate with the same cloud server at different times. However, this cloud server has only one public server address, which means that domain names belonging to multiple different applications can all be associated with this server address, thus creating a situation where information from the same cloud service can interfere with the identification of target packets.
[0191] To remove interference from information from the same cloud service source, multiple domain names corresponding to the target server address in the first list can be used as pre-selected domain names, and then the target domain name can be confirmed from the multiple pre-selected domain names, thereby narrowing the identification range and improving identification efficiency.
[0192] like Figure 7 As shown, exemplarily, Figure 7 The server address "106.119.193.231" corresponds to the domains ".xueersi.com$" and ".huya.com$". The domain ".xueersi.com$" corresponds to application code id=78, which belongs to... The application, with the domain ".huya\.com$" corresponding to application code id=34, belongs to... Applications. It can be seen that the server address "106.119.193.231" corresponds to the domain names of two different applications, indicating... Applications and The application's server resources may be deployed on the same cloud server node, but the target message can only be sent by the application corresponding to one of the domain names. Directly selecting any domain name as the target domain name may lead to incorrect identification of the target application corresponding to the target message, resulting in errors in the statistics of internet usage time. When the target server address is "106.119.193.231", it is not possible to directly determine which target domain name corresponds to the target message based on the first list.
[0193] Based on the above, multiple domain names corresponding to the target server address in the first list can be identified as pre-selected domain names. Then, the target domain name corresponding to the target message can be confirmed from the pre-selected domain names, thereby narrowing the scope of target message identification and improving identification efficiency. In turn, the accuracy of target message identification can be improved through secondary confirmation, thereby improving the accuracy of online time statistics.
[0194] Step S260: Determine the target domain name based on multiple pre-selected domain names and a second list.
[0195] In this embodiment, after determining the pre-selected domain names, the target domain name can be determined by combining the second list.
[0196] The second list includes multiple sets of correspondences between domain names and server addresses, as well as the status of the server addresses, with each domain name corresponding to at least one server address.
[0197] Figure 9 This is a schematic diagram of the second list provided in this embodiment.
[0198] like Figure 9 As shown, in some embodiments, the second list can be a second hash table.
[0199] In the second hash table, the domain name is the key, and at least one server address and its status are the associated values. The domain name, its corresponding server address, and its status form the second key-value pair in the second hash table. The second hash table may include multiple second hash buckets, and each second hash bucket can store one second key-value pair.
[0200] It is worth noting that the determination of the correspondence between domain names and server addresses can refer to the explanation of steps S221-S222 above, which will not be repeated here.
[0201] Furthermore, the method of storing the second key-value pair in the second hash bucket can be the same as the method of storing the first key-value pair in the first hash table in the first hash bucket, which will not be elaborated here.
[0202] It is understood that in other implementations, the second list may also be other forms of tables, arrays, etc., and is not limited in this embodiment.
[0203] Figure 10 This is the fourth flowchart of a message identification method provided in this embodiment.
[0204] like Figure 10 As shown, in this embodiment, step S260 can be implemented by the following method:
[0205] Step S261: Query the second list.
[0206] For example, the second list can be stored in the router's memory or in the router's identification module. This allows the second list to be directly accessed and queried when determining the target domain name based on the pre-selected domain name and the second list. In this embodiment, the storage location of the second list is not limited.
[0207] It is worth noting that the process of querying the second list based on the pre-selected domain name can refer to the process of querying the first list based on the target server address, as described above, and will not be repeated here.
[0208] Step S262: Determine the status of all server addresses corresponding to each of the multiple pre-selected domain names.
[0209] For example, the status of a server address includes an active state and an idle state. When a server address is active, it means that the server address is being used; when a server address is idle, it means that the server address is not being used.
[0210] Optionally, in the second list, "1" can be used to indicate that the server address is active and "0" can be used to indicate that the server address is idle, thus facilitating representation and judgment.
[0211] When an application is running on a terminal device, it may simultaneously request resources from different servers, resulting in the application communicating with multiple different server addresses at the same time. Thus, multiple server addresses corresponding to the same domain name will all be active. Based on this, when determining that a target server address corresponds to multiple domain names, the status of the server addresses corresponding to each domain name can be determined by querying a second list. If all server addresses corresponding to a pre-selected domain name are active, it indicates that the application corresponding to that pre-selected domain name is a running application, i.e., the application sending the target message, and this pre-selected domain name can be used as the target domain name.
[0212] Figure 11 This is the fifth flowchart of a message identification method provided in this embodiment.
[0213] like Figure 11 As shown, the status of each server address can be further determined in the following way:
[0214] Step S2621: Listen for system connection tracking information.
[0215] In this embodiment, the router can use operating system, The operating system can establish connection tracking during operation. After a network connection is established, the router can identify the interaction messages sent between the application on the terminal device and the server on that connection, record connection-related information, and save the connection state. There is a one-to-one correspondence between a connection and a connection tracker; one connection tracker identifies a connection between an application on the terminal device and the server corresponding to that application. In this way, connection tracking can be used to track and manage network connection states, thereby enabling the monitoring of network usage and the identification of abnormal activity by analyzing connection status and traffic information.
[0216] For example, when the connection trace is: ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, sport=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=131, sc_categ=4, sc_action=0, it can be seen that the connection to the destination server address 106.75.107.247 is in use, indicating that the destination server address 106.75.107.247 is active. Thus, the status of the server address can be determined by monitoring the connection trace.
[0217] Step S2622: If a system connection establishment tracking is detected, determine that the server address in the second list corresponding to the destination server address in the connection tracking is in an active state.
[0218] In this embodiment, when the router receives a packet, it can parse the packet. If the packet does not belong to an existing connection, it indicates that the application is establishing a new connection. In this case, the router needs to create a new connection trace and record new connection-related information. If, after parsing the packet, it is found that the packet belongs to an existing connection, the corresponding connection trace can be updated directly.
[0219] If system connection establishment tracking is detected, it indicates that a new application is establishing a communication connection with the destination server address. This destination server address is active, and the status of the server address corresponding to the destination server address in the second list can be adjusted to active status.
[0220] For example, when determining the status of a server address in the second list, if the status of a server address needs to be changed from idle to active, the "0" in the server address status column of the second list can be changed to "1" to show that the server address is active.
[0221] Step S2623: If the system detects that connection tracking has been deleted, determine that the server address in the second list corresponding to the destination server address in the connection tracking is in an idle state.
[0222] In this embodiment, when an established connection within the router is about to be disconnected, the connection sends a message to the system indicating that it is about to be disconnected. The system can then delete the connection tracking corresponding to that connection, and the destination server address in the connection tracking loses its network connection, thus becoming idle. When the system detects the deletion of the connection tracking, the status of the server address in the second list corresponding to the destination server address can be adjusted to idle.
[0223] For example, when determining the status of a server address in the second list, if the status of a server address needs to be changed from active to idle, the "1" in the server address status column of the second list can be changed to "0" to show that the server address is in an idle state.
[0224] Furthermore, the status of each server address in the second list can be updated in real time based on the creation and deletion of connection groups, so that when identifying target packets, the status of each server address at the current moment can be obtained, thereby reducing the possibility of misjudgment due to information delay.
[0225] For the reasons mentioned above, when determining which of the multiple pre-selected domain names is the target domain name, it is first necessary to determine the server status corresponding to each pre-selected domain name.
[0226] Please combine Figure 7 and Figure 9 Exemplary Figure 7 In the first list shown, the target server address "106.119.193.231" corresponds to the pre-selected domain names "\.xueersi\.com$" and ".huya\.com$".
[0227] Query Figure 9As shown in the second list, the server addresses corresponding to the pre-selected domain name "\.xueersi\.com$" include "106.119.193.231", "36.25.248.117", and "211.91.68.241". Among them, server address "106.119.193.231" is active, server address "36.25.248.117" is idle, and server address "211.91.68.241" is idle.
[0228] Query Figure 9 As shown in the second list, the server addresses corresponding to the pre-selected domain name ".huya\.com$" include "106.119.193.231" and "61.168.100.237". Server address "106.119.193.231" and server address "61.168.100.237" are both active.
[0229] Step S263: Determine one of the multiple pre-selected domain names as the target domain name, and ensure that all server addresses corresponding to the target domain name are in an active state.
[0230] In this embodiment, if all server addresses corresponding to a preselected domain name are in an active state, it indicates that the application corresponding to the preselected domain name is connected to the network, and the target packet is a packet sent by the application corresponding to the preselected domain name. Based on this, preselected domain names whose server addresses are all in an active state can be determined as active domain names.
[0231] For example, query Figure 9 As shown in the second list, all server addresses corresponding to the preselected domain ".huya\.com$" are active, confirming that the preselected domain ".huya\.com$" is the target domain.
[0232] Please refer to it again. Figure 5 The methods described in steps S220-S260 above can determine the target domain name corresponding to the target server address based on the target server address and the first list, so as to facilitate subsequent confirmation of the target application.
[0233] In some embodiments, server address status information can also be added to the first list to facilitate determining the status of the target server address. The server address status can be used as a key or as an association value; this is not limited in this embodiment.
[0234] Step S270: Determine the target application based on the target domain name and the application identifier corresponding to the target domain name.
[0235] As explained above, the first list includes not only the mapping between server addresses and domain names, but also the application identifiers corresponding to each domain name. Each application identifier has a unique correspondence with an application and is easy to identify. After determining the target domain name, the target application can be identified based on the target domain name and its corresponding application identifier. This improves the efficiency and accuracy of target application identification and also facilitates subsequent statistics on internet usage time.
[0236] In one example, in steps S240 and S250 above, the target domain name can be determined directly based on the first list.
[0237] At this point, the target application can be determined based on the application identifier corresponding to the target domain name in the first list.
[0238] In another example, in step S260 above, the target domain name needs to be determined by combining the second list. When querying the first list to determine the pre-selected domain names, in addition to obtaining the pre-selected domain names, the application identifiers corresponding to each domain name can also be obtained. Thus, after determining the target domain name based on the second list, the application identifier corresponding to the target domain name can be directly obtained, thereby facilitating the identification of the target application through the application identifier.
[0239] Step S280: Update the business attributes of the target application to the connection tracking information corresponding to the target server address.
[0240] The business attributes include the application identifier and the business type.
[0241] As explained above, when a router receives a packet, it can parse the packet. If the packet does not belong to an existing connection, it means the application is establishing a new connection. In this case, the router needs to create a new connection trace and record new connection-related information. If, after parsing the packet, it finds that the packet belongs to an existing connection, it can directly update the corresponding connection trace.
[0242] However, if the message received by the router is a target message, it will be unable to parse the target message and therefore cannot know the application information to which the target message belongs. As a result, the information in the new connection trace established by the router will only include information such as server address and port, but will not include information related to the target application corresponding to the target message.
[0243] For example, if the router cannot determine the application to which the target packet belongs, the connection tracking information established by the router may be "ipv4, 2, tcp, 6, 295, ESTABLISHED, src=192.168.3.7, dst=106.75.107.247, sport=38844, dport=6810, [ASSURED], mark=3491758080, zone=0, ifindex=34, ctaddr=32fedb78, httpmark=0, use=2, sc_id=0, sc_categ=0, sc_action=0". Here, "sc_id=0" indicates that the application identifier is the default value; in other words, id=0 does not belong to any application. "sc_categ=0" indicates that the service type is the default value; in other words, category=0 does not belong to any service type. Thus, connection tracking can only indicate the existence of a network connection, but it cannot indicate which application the network connection belongs to. If the router uses connection tracking to count internet usage time, then it will be unable to collect information about that connection tracking.
[0244] For the reasons stated above, after identifying the target application corresponding to the target message, it is necessary to update the business attributes of the target application in the connection tracking information corresponding to the target server address. Specifically, the connection tracking corresponding to the target server address refers to connection tracking where the destination server address is the same as the target server address.
[0245] For example, based on the above identification process, it can be determined that the target application corresponding to the target message is... Its application code id = 131, the business type is game, and the corresponding business type sequence number is "4". When the connection trace corresponding to the target packet is the above connection trace, then after updating the business attributes of the target application to the connection trace, we can get "ipv4, 2, tcp, 6, 295, ESTABLISHED, src = 192.168.3.7, dst = 106.75.107.247, sport = 38844, dport = 6810, [ASSURED], mark = 3491758080, zone = 0, ifindex = 34, ctaddr = 32fedb78, httpmark = 0, use = 2, sc_id = 131, sc_categ = 4, sc_action = 0". It can be seen that this connection trace indicates that the application with application code id = 131 is currently engaging in internet browsing, and the business type to which this connection trace belongs is 4. In this way, when the router subsequently performs statistics on internet access duration, it can determine the application and service type to which the connection belongs, thus facilitating the statistics on internet access duration for the application and service type to which the target packet belongs. This allows for the effective counting of the actual time the terminal device uses the application, thereby avoiding omissions and inaccuracies.
[0246] Figure 12 This is a schematic diagram of a second structure of a network device provided in this embodiment.
[0247] like Figure 12 As shown, in some embodiments, network device 1200 may further include main control board 1210 and interface board 1220.
[0248] The main control board 1210, also known as the main processing unit (MPU) or route processor card, is used to control and manage the various components in the network device 1200, including route calculation, device management, device maintenance, and protocol processing functions. The main control board 1210 includes a main control central processing unit 1211 and a main control memory 1212.
[0249] Interface board 1220 is also called a line processing unit (LPU), linecard, or service board. Interface board 1220 provides various service interfaces and implements packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces, POS (packet over SONET / SDH) interfaces, etc., with Ethernet interfaces including, for example, flexible Ethernet clients (FlexE Clients). Interface board 1220 includes: an interface central processing unit 1221, a network processor 1222, a forwarding table entry memory 1223, and a physical interface card (PIC) 1224.
[0250] The interface central processing unit 1221 on the interface board 1220 is used to control and manage the interface board 1220 and communicate with the main control central processing unit 1211 on the main control board 1210.
[0251] The network processor 1222 is used to implement packet forwarding processing. The network processor 1222 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP) 1222. In some embodiments, the forwarding chip can be implemented using an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA).
[0252] Specifically, the network processor 1222 forwards received packets based on the forwarding table stored in the forwarding table entry memory 1223. If the destination address of the packet is the address of the packet processing device, the packet is sent to the CPU (such as a central processing unit) for processing. If the destination address of the packet is not the address of the packet processing device, the next hop and outgoing interface corresponding to the destination address are found in the forwarding table according to the destination address, and the packet is forwarded to the outgoing interface corresponding to the destination address. Uplink packet processing may include: packet inbound interface processing, forwarding table lookup; downlink packet processing may include: forwarding table lookup, etc. In some embodiments, the interface central processing unit 1221 may also perform the functions of a forwarding chip, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for a forwarding chip in the interface board 1220.
[0253] The physical interface card 1224 is used to implement physical layer interfacing functions. Raw traffic enters the interface board through this card, and processed packets are sent out from it. The physical interface card 1224, also called a daughter card, can be installed on the interface board and is responsible for converting photoelectric signals into packets, performing validity checks on the packets, and forwarding them to the network processor 1222 for processing. In some embodiments, the interface central processing unit 1221 can also perform the functions of the network processor 1222, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for a network processor in the physical interface card 1224.
[0254] For example, network device 1200 also includes a switching fabric board 1230. The switching fabric board 1230 may also be referred to as a switch fabric unit (SFU). In cases where network device 1200 has multiple interface boards 1220, the switching fabric board 1230 is used to perform data exchange between the interface boards 1220. For example, interface boards 1220 can communicate with each other via the switching fabric board 1230.
[0255] The main control board 1210 and the interface board 1220 are coupled. For example, the main control board 1210, the interface board 1220, and the switching network board 1230 communicate with each other via a system bus connected to the system backplane. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 1210, the interface board 1220, and another interface board 1220, and communication between the main control board 1210, the interface board 1220, and another interface board 1220 occurs through the IPC channel.
[0256] Logically, network device 1200 includes a control plane and a forwarding plane.
[0257] The control plane includes a main control board 1210 and an interface central processing unit 1221, while the forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1223, a physical interface card 1224, and a network processor 1222. The control plane performs functions such as router operation, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the status of network devices. The control plane distributes the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor uses the forwarding tables distributed by the control plane to look up and forward messages received by the physical interface card. The forwarding tables distributed by the control plane can be stored in the forwarding table entry memory. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0258] It's worth noting that there may be one or more main control boards 1210, and when there are multiple boards, they can include a primary main control board and a backup main control board. There may be one or more interface boards 1220; the stronger the data processing capability of the network device 1200, the more interface boards 1220 it provides. There may also be one or more physical interface cards 1224 on the interface boards 1220. There may be no switching network boards 1230, or there may be one or more; when there are multiple boards, they can work together to achieve load sharing and redundancy backup.
[0259] In a centralized forwarding architecture, network device 1200 may not require a switching board 1230, with interface board 1220 handling the entire system's service data processing. In a distributed forwarding architecture, network device 1200 can have at least one switching board 1230, enabling data exchange between multiple interface boards 1220, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture packet processing device are greater than those of a centralized architecture packet processing device.
[0260] For example, network device 1200 can also be a single board, without a switching board 1230. The functions of interface board 1220 and main control board 1210 are integrated on this single board. In this case, the interface central processing unit 1221 on interface board 1220 and the main control central processing unit 1211 on main control board 1210 can be combined into a single central processing unit on this single board to execute the combined functions of the two. This type of network device has lower data exchange and processing capabilities (e.g., low-end switches or routers). The specific architecture adopted depends on the specific network deployment scenario, and no restrictions are made here.
[0261] In this embodiment, the main control memory 1212 of the main control board 1210 may store computer programs or computer instructions for executing the above-described message identification method. Alternatively, the interface board 1220 may also store computer programs or computer instructions for executing the above-described message identification method. After receiving a target message sent by the terminal device, the network processor 1222 of the interface board 1220 can execute the stored computer program for message identification to identify the target message and thus determine the application to which the target message belongs.
[0262] In some embodiments, the network device may also be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next-generation NodeB (gNB) in a 5th-generation (5G) mobile communication system, a next-generation base station in a 6th-generation (6G) mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system; it may also be a module or unit that performs some of the functions of a base station, for example, it may be a central unit (CU) or a distributed unit (DU). The CU here performs the functions of the radio resource control (RRC) protocol and packet data convergence protocol (PDCP) of the base station, and can also perform the functions of the service data adaptation protocol (SDAP). The DU performs the functions of the radio link control (RLC) layer and medium access control (MAC) layer of the base station, and can also perform some or all of the physical (PHY) layer functions. For specific descriptions of the above-mentioned protocol layers, please refer to the relevant technical specifications of the 3rd Generation Partnership Project (3GPP). The network equipment can be a macro base station, a micro base station, an indoor station, a relay node, or a donor node, etc. The embodiments of this application do not limit the specific technology or specific equipment form used in the network equipment.
[0263] Figure 13 This is a schematic diagram of the structure of a message identification device provided in this embodiment.
[0264] like Figure 13 As shown, in some embodiments, the message identification device 1300 may be a management platform or management tool for executing the message identification method described above. The message identification device 1300 includes one or more processors 1310, a memory 1320, a communication interface 1330, and a bus 1340.
[0265] Specifically, processor 1310 may include one or more CPUs. Each of these processors 1310 may be a single-core processor or a multi-core processor. Here, "processor" may refer to one or more devices, circuits, and / or processing cores used for processing data (such as computer program instructions).
[0266] The memory 1320 may exist independently, for example, and be connected to the processor 1310 via bus 1340. The memory 1320 may also be integrated with the processor 1310.
[0267] Communication interface 1330 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), or Wireless Local Area Network (WLAN). Communication interface 1330 may include wired and wireless communication interfaces. Specifically, the communication interface may be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a WLAN interface, a cellular network communication interface, or a combination thereof. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. In this embodiment, communication interface 1330 can be used to communicate with external devices such as electronic devices, portable hard drives, and USB flash drives.
[0268] Optionally, bus 1340 is used to transmit information between components of the network device. Bus 1340 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. Bus 1340 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 13 The symbol is represented by only one line, but this does not mean that there is only one bus or one type of bus.
[0269] In some embodiments, the message identification device 1300 may further include an output device and an input device. The output device communicates with the processor and can display information in various ways. For example, the output device may be a liquid crystal display (LCD), a light-emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device communicates with the processor 1310 and can receive user input in various ways. For example, the input device may be a mouse, keyboard, touchscreen device, or sensing device, etc.
[0270] This application also provides a computer storage medium that includes computer instructions. When the computer instructions are executed on the network device, the network device performs the steps in the above method embodiments.
[0271] This application also provides a computer program product that, when run on a computer, causes the computer to perform the steps in the above method embodiments.
[0272] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0273] It is readily understood that, based on the several embodiments provided in this application, those skilled in the art can combine, split, or reorganize the embodiments of this application to obtain other embodiments, none of which exceed the protection scope of this application.
[0274] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0275] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0276] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0277] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks. It should be noted that those skilled in the art, after considering the specification and practicing the application disclosed herein, will readily conceive of other embodiments of this application. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary technical means in the art not disclosed in this application. The description and examples are to be considered exemplary only, and the true scope of this application is indicated by the claims.
[0278] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A message identification method, characterized in that, include: Obtain the target server address corresponding to the target message sent by the terminal device, wherein the target message includes a message with an encrypted message body; Determining the target domain name corresponding to the target server address includes: querying a first list, which includes multiple sets of correspondences between server addresses and domain names, and each server address corresponds to at least one domain name. The first list also includes application identifiers corresponding to each domain name. If the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, querying a second list to determine the status of the server address and determining the target domain name, the second list includes multiple sets of correspondences between the domain names and the server address and the status of the server address, and each domain name corresponds to at least one server address. The target application in the terminal device is determined based on the target domain name, and the target application is the application that sent the target message.
2. The message identification method according to claim 1, characterized in that, The step of determining the target domain name corresponding to the target server address further includes: If the first list includes a domain name corresponding to the target server, then the domain name corresponding to the target server address is determined to be the target domain name.
3. The message identification method according to claim 2, characterized in that, Also includes: If the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are the same, then any one of the domain names corresponding to the target server address is selected as the target domain name.
4. The message identification method according to claim 2, characterized in that, When the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, querying the second list to determine the status of the server address and determine the target domain name includes: If the first list includes multiple domain names corresponding to the target server address and the application identifiers corresponding to the multiple domain names are different, then the multiple domain names corresponding to the target server address are determined as pre-selected domain names; The second list is queried, and the target domain name is determined based on multiple pre-selected domain names and the second list.
5. The message identification method according to claim 4, characterized in that, The querying of the second list, based on multiple pre-selected domain names and the second list, determines the target domain name, including: Query the second list; Determine the status of all server addresses corresponding to each of the multiple preselected domain names, wherein the status of the server addresses includes active status and idle status; One of the multiple pre-selected domain names is determined as the target domain name, and all the server addresses corresponding to the target domain name are in the active state.
6. The message identification method according to claim 5, characterized in that, The method for determining the status of the server address in the second list includes: Monitor system connection tracking information; Upon detecting that the system has established the connection tracking, the status of the server address corresponding to the destination server address in the connection tracking in the second list is determined to be the active status; If the system detects that the connection tracking has been deleted, the status of the server address corresponding to the destination server address in the connection tracking in the second list is determined to be the idle state.
7. The message identification method according to any one of claims 3-6, characterized in that, The step of determining the target application in the terminal device based on the target domain name includes: The target application is determined based on the target domain name and the application identifier corresponding to the target domain name.
8. The message identification method according to any one of claims 3-6, characterized in that, The method further includes: Update the business attributes of the target application to the connection tracking information corresponding to the target server address. The business attributes include the application identifier and the business type.
9. The message identification method according to claim 1, characterized in that, The method for determining the first list includes: Read the domain name response message, which is a response message sent by the domain name server in response to the domain name resolution request of the terminal device, and the domain name response message includes the correspondence between the domain name and the server address; Record the server address and the domain name corresponding to the server address to form the first list.
10. The message identification method according to claim 1, characterized in that, The first list includes a first hash table; The server address is a key value of the first hash table, and at least one of the domain names is an associated value of the first hash table. The server address and the domain name corresponding to the server address form a first key-value pair in the first hash table. The first hash table includes multiple first hash buckets, and each first hash bucket stores one of the first key-value pairs.
11. The message identification method according to claim 10, characterized in that, The method for storing the first key-value pair in the first hash bucket includes: A first value is obtained based on the server address, and the first value is an integer; Divide the first value by the total number of the first hash buckets to obtain the remainder; The first key-value pair corresponding to the remainder result is stored in the first hash bucket with the index of the remainder result.
12. The message identification method according to claim 11, characterized in that, The method of storing the first key-value pair in the first hash bucket further includes: If the first hash bucket with the index of the remainder result already contains other first key-value pairs, the first hash buckets are traversed sequentially backward, and the first key-value pair corresponding to the remainder result is stored in the first unused first hash bucket.
13. The message identification method according to claim 11, characterized in that, The method of storing the key-value pairs in the first hash bucket further includes: If the number of first hash buckets storing the first key-value pairs exceeds a set threshold, the number of first hash buckets is increased.
14. The message identification method according to claim 1, characterized in that, The second list includes a second hash table; The domain name is the key value of the second hash table, at least one server address and the state of the server address are the associated values of the second hash table, and the domain name, the server address corresponding to the domain name and the state of the server address form a second key-value pair of the second hash table; The second hash table includes multiple second hash buckets, each of which stores one of the second key-value pairs.
15. The message identification method according to claim 1, characterized in that, The target message includes Secure Sockets Layer (SSL) encrypted messages and / or Transport Layer Security (TLS) encrypted messages.
16. A network device, characterized in that, include: A memory and one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, which, when executed by the processor, cause the network device to perform the message identification method as described in any one of claims 1-15.
17. A computer-readable storage medium, characterized in that, It includes computer instructions that, when executed on a network device, cause the network device to perform the message identification method as described in any one of claims 1-15.
18. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the message identification method as described in any one of claims 1-15.
Citation Information
Patent Citations
Application identification method and device
CN103685601A
Link detection method and device
CN117651006A