A method for identifying home terminals combining IPv6 session ownership and User-Agent fingerprinting

By combining IPv6 session attribution with User-Agent fingerprinting, the problem of traffic attribution and device deduplication for terminal identification in home networks is solved, achieving high-precision terminal identification and deduplication, and constructing a unique virtual human ID to support refined operation and maintenance and network security.

CN121056433BActive Publication Date: 2026-03-06PUBLIC SECURITY BUREAU OF CHANGZHOU CITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511563849.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-30
Publication Date
2026-03-06
Estimated Expiration
2045-10-30

AI Technical Summary

Technical Problem

In modern home networks, terminal identification methods based on IPv6 addresses and User-Agent fingerprints present identification challenges, especially the difficulty in attributing traffic due to IPv6 privacy addresses and the difficulty in deduplicating the same device. Existing technologies cannot effectively distinguish the traffic of multiple devices.

Method used

By combining IPv6 session attribution and User-Agent fingerprinting, traffic separation is achieved through the uniqueness of IPv6 temporary addresses. Furthermore, by combining terminal fingerprinting and behavioral analysis, a virtual human ID is constructed to achieve high-precision terminal identification and deduplication.

Benefits of technology

It achieves high coverage and high-precision identification of terminals in home networks, accurately classifies terminal devices and builds a unique virtual human ID for each device, supporting refined operation and maintenance and network security analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056433B_ABST
    Figure CN121056433B_ABST
Patent Text Reader

Abstract

This invention discloses a home terminal identification method combining IPv6 session ownership and User-Agent fingerprinting, belonging to the field of computer network data mining and user profiling technology. It includes constructing virtual human IDs based on IPv6 session ownership and constructing virtual human IDs based on User-Agent fingerprinting and behavioral conflict detection. The results of constructing virtual human IDs based on IPv6 session ownership and User-Agent fingerprinting and behavioral conflict detection are summarized to generate a more comprehensive list of unique virtual human IDs for home broadband accounts. This invention provides a technology for automated and high-precision identification and classification of various terminal devices in a metropolitan area network (MAN) home broadband environment through multi-dimensional analysis. This invention offers a set of terminal classification methods that include two independent, parallel, and complementary technical paths, aiming to expand the coverage of terminal identification and improve the accuracy of identification through analysis from different dimensions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer network data mining and user profiling technology, and in particular relates to a home terminal identification method that combines IPv6 session affiliation and User-Agent fingerprinting. Background Technology

[0002] With the widespread adoption of home broadband and the advent of the Internet of Things era, terminal devices in modern home networks are becoming increasingly diverse. Effectively classifying these terminals and constructing unique logical identifiers (virtual user IDs) is a crucial prerequisite for network operators to achieve refined operation and maintenance, ensure differentiated quality of service (QoS), conduct precise marketing, and enhance network security situational awareness.

[0003] However, terminal segmentation in real-world network environments faces numerous challenges. First, IPv6 coverage is not complete in metropolitan area networks, with a significant amount of IPv4 traffic still present. Furthermore, to protect user privacy, modern operating systems generally enable IPv6 privacy extensions (RFC 4941) by default, causing terminal devices to periodically use random, temporary interface identifiers to generate their IPv6 addresses. This renders long-term stable address-based tracing impractical and renders traditional methods relying on the EUI-64 algorithm to decipher MAC addresses largely ineffective.

[0004] Secondly, the HTTP User-Agent field, as another identification dimension, contains rich terminal information, but it has its own limitations: 1) The information format is not uniform and the content is messy, requiring complex standardization processing; 2) In the increasingly popular HTTPS encrypted traffic, this field is encrypted and cannot be directly parsed by intermediate network devices; 3) It only exists in Web traffic and has limited coverage.

[0005] Current technical problem 1: The challenge of traffic attribution and identity construction under IPv6 privacy addresses:

[0006] Problem Description: Modern operating systems have widely enabled IPv6 privacy extensions to protect user privacy. This causes the IPv6 addresses of terminal devices to change periodically and randomly. Traditional methods of terminal identification and tracking based on fixed IP addresses or MAC addresses (deciphered using the EUI-64 algorithm) are completely ineffective. Network operators, faced with IPv6 traffic originating from the same household, cannot determine how many active devices correspond to a series of constantly changing temporary addresses, nor can they accurately attribute this chaotic traffic to a specific device session.

[0007] Current technical problem two: the challenge of deduplicating identical devices based on User-Agent fingerprints.

[0008] Problem Description: While User-Agent information can identify a device's brand and model, forming a relatively stable "device fingerprint," a household often has multiple devices of the exact same brand and model (e.g., a husband and wife both using iPhone 15 Pro). In this case, relying solely on the User-Agent fingerprint will incorrectly aggregate the traffic from these two different phones, creating a chaotic "device profile" that cannot represent any single user. This leads to errors in device count and ineffective user behavior analysis.

[0009] Therefore, existing single-dimensional terminal segmentation technologies cannot perfectly cope with the current complex network environment. The market urgently needs a multi-dimensional and multi-faceted set of technical methods to improve the overall coverage and accuracy of terminal segmentation in metropolitan area network home broadband scenarios. Summary of the Invention

[0010] The technical problem to be solved by the present invention is to provide a home terminal identification method that combines IPv6 session ownership and User-Agent fingerprinting to address the shortcomings of the prior art. In a home broadband environment of a metropolitan area network (MAN), the method uses a multi-dimensional analysis method to automatically and accurately identify and classify various terminal devices in the user network.

[0011] To solve the above-mentioned technical problems, the present invention adopts the following technical solution:

[0012] A method for identifying home terminals that combines IPv6 session ownership with User-Agent fingerprinting, specifically including the following steps:

[0013] Virtual human IDs are built based on IPv6 session attribution to perform basic separation of all IPv6 traffic and to classify terminal sessions that do not generate User-Agents. By leveraging the temporary uniqueness of IPv6 private addresses during their lifecycle, mixed home network traffic is separated and attributed to independent, anonymous logical entities, and finally, virtual human IDs are constructed.

[0014] A virtual human ID is constructed based on User-Agent fingerprinting and behavioral conflict detection. This ID is used for accurate brand and model identification of the terminal that generates the User-Agent and for deduplication of identical devices. High-value information is extracted from HTTP / S traffic by building a stable...

[0015] Hardware fingerprinting combined with behavioral analysis enables accurate terminal identification and deduplication, constructing a virtual human ID;

[0016] This involves constructing virtual human IDs based on IPv6 session ownership and constructing virtual humans based on User-Agent fingerprints and behavioral conflict detection.

[0017] The ID results are aggregated to generate a more comprehensive list of unique virtual avatar IDs for home broadband accounts.

[0018] As a further preferred embodiment of the home terminal identification method combining IPv6 session ownership and User-Agent fingerprinting of the present invention, the virtual human ID construction method based on IPv6 session ownership specifically includes the following steps:

[0019] Step 1.1, Identify home network prefixes and temporary addresses: At the metropolitan area network data aggregation node, capture and identify traffic belonging to the same home broadband user. The user is identified by a relatively stable IPv6 network prefix over a period of time, and all active, complete IPv6 addresses are identified.

[0020] Step 1.2, Define Temporary Network Identifiers: Treat each complete, temporary IPv6 address as a temporary network identifier during its short lifespan;

[0021] Step 1.3, establish the association between temporary network identifiers and network identities: For each defined temporary network identifier, perform a key association building step; utilize the uniqueness and exclusivity of the identifier during its lifecycle to explicitly map it to a unique, anonymous network identity; bind a transient network identifier to a logical active entity, thereby confirming that all traffic originating from the identifier comes from the same source.

[0022] Step 1.4, output the virtual human ID based on traffic attribution: The association established in step 1.3 binds a unique, anonymous network identity to all its network activities, i.e., the traffic set; the network identity that has been fully attributed to traffic constitutes a unique virtual human ID.

[0023] As a further preferred embodiment of the home terminal identification method combining IPv6 session ownership and User-Agent fingerprinting of the present invention, the virtual human ID construction method based on User-Agent fingerprinting and behavior conflict detection specifically includes:

[0024] Step 2.1, User-Agent standardization and terminal fingerprint generation;

[0025] Step 2.2, establish the association between terminal fingerprint and active network identity: explicitly map the persistent network terminal fingerprint generated in Step 2.1, which represents the physical device attributes, to the active network identity of the session;

[0026] Step 2.3: Based on the terminal fingerprint aggregation session, form a device profile;

[0027] Step 2.4, Device conflict detection and terminal deduplication;

[0028] Step 2.5: Construct and output a unique virtual human ID.

[0029] As a further preferred embodiment of the home terminal identification method combining IPv6 session affiliation and User-Agent fingerprinting of the present invention, step 2.1, User-Agent standardization and terminal fingerprint generation specifically includes:

[0030] Step 2.11: Extract the User-Agent string from any network session of a home broadband user using Deep Packet Inspection (DPI);

[0031] Step 2.12: Accurately extract key fields such as terminal brand, terminal model, and long-term stable operating system from the messy User-Agent string;

[0032] Step 2.13: Normalize the extracted fields and combine them into a structured and stable network terminal fingerprint according to preset rules.

[0033] As a further preferred embodiment of the home terminal identification method combining IPv6 session affiliation and User-Agent fingerprinting of the present invention, in step 2.3, a device profile is formed based on the aggregation of sessions using the terminal fingerprint, specifically including:

[0034] Step 2.31: Create a data aggregation container using the fingerprint of the network terminal as the unique key;

[0035] Step 2.32: Based on the mapping relationship established in Step 2.2, all traffic data of network sessions with the same network terminal fingerprint are aggregated into the corresponding aggregation container.

[0036] As a further preferred embodiment of the home terminal identification method combining IPv6 session ownership and User-Agent fingerprinting of the present invention, step 2.4, device conflict detection and terminal deduplication, specifically includes:

[0037] Step 2.41: Perform in-depth analysis of the application behavior traffic aggregated within each device profile;

[0038] Step 2.42: Set up a behavior conflict model. If the combination of application behaviors in the profile shows great differences or logically mutually exclusive application patterns, it is determined to be a device conflict.

[0039] Step 2.43: When a device conflict occurs, determine that there are multiple physical entities behind the fingerprint of the network terminal, that is, the family has multiple devices of the same brand and model. Based on the clustering results of the behavior pattern, estimate and deduplicate the number of terminals.

[0040] Compared with the prior art, the present invention, employing the above technical solution, has the following technical effects:

[0041] 1. The present invention provides a home terminal identification method that combines IPv6 session affiliation and User-Agent fingerprinting. It can effectively utilize the uniqueness of IPv6 temporary addresses during their lifecycle to successfully separate mixed home IPv6 traffic and construct a traceable, network behavior-based virtual human ID for each independent, anonymous source of activity. In particular, it provides an identification basis for terminals that do not generate User-Agent information.

[0042] 2. The present invention provides a home terminal identification method that combines IPv6 session affiliation and User-Agent fingerprinting. Based on the identification of the terminal fingerprint, it can accurately identify and distinguish multiple identical devices in the home network by deeply analyzing the internal application behavior logic conflicts, thereby achieving true terminal deduplication and constructing a final and unique virtual human ID for each successfully distinguished physical entity. Attached Figure Description

[0043] Figure 1 This is a flowchart of the virtual human ID construction method based on IPv6 session ownership in Embodiment 1 of the present invention;

[0044] Figure 2 This is a flowchart of the virtual human ID construction method based on User-Agent fingerprint and behavior conflict detection in Embodiment 2 of the present invention. Detailed Implementation

[0045] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings:

[0046] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention. The present invention will be described in detail below with reference to the accompanying drawings and preferred embodiments. The purpose and effects of the present invention will become clearer. It should be understood that the specific embodiments described herein are merely illustrative of the present invention and are not intended to limit the present invention.

[0047] The main objective of this invention is to overcome the shortcomings of existing technologies and provide a set of terminal segmentation methods that include two independent, parallel, and complementary technical paths. This aims to expand the coverage of terminal identification and improve its accuracy through analysis from different dimensions. This invention includes the following two parallel technical methods:

[0048] Method 1: Anonymous Virtual Person ID Construction Method Based on IPv6 Session Ownership:

[0049] This invention utilizes the "temporary uniqueness" of IPv6 privacy addresses throughout their lifecycle to separate mixed home network traffic and attribute it to independent, anonymous logical entities, ultimately constructing a virtual human ID. Its core steps include:

[0050] Identifying Home Network Prefixes and Temporary Addresses: At the metropolitan area network data aggregation node, capture and identify traffic belonging to the same broadband user household, identified by a relatively stable IPv6 network prefix over a period of time. Under this prefix, identify all active, complete IPv6 addresses.

[0051] Define a temporary network identifier: Treat each complete, temporary IPv6 address as a "temporary network identifier" within its short lifespan (e.g., 24 hours).

[0052] Establishing the association between ephemeral network identifiers and network identities: For each defined "ephemeral network identifier," a crucial association-building step is performed. This step leverages the uniqueness and exclusivity of the identifier throughout its lifecycle to explicitly map it to a unique, anonymous network identity. This step binds a transient network identifier to a logical active entity (the network identity), thereby confirming that all traffic originating from that identifier comes from the same source.

[0053] Output a virtual avatar ID based on traffic attribution: Establish a relationship that binds a unique, anonymous network identity to all its network activities (traffic sets). This network identity, fully attributable to traffic, constitutes a unique "virtual avatar ID." The core value of this ID lies in:

[0054] Initial traffic separation and identity construction were achieved: the mixed traffic from the home exit was successfully separated into clean sets of sessions representing different physical devices, and each set was assigned a traceable logical ID.

[0055] It provides a foundation for analysis: each "virtual human ID" is an independently analyzable data unit, providing a solid foundation for subsequent refined operation and maintenance and network security testing.

[0056] Coverage of non-web terminals: It can create a unique virtual human ID for terminals that do not generate User-Agent (such as game consoles and certain IoT devices).

[0057] Method 2: A method for constructing virtual human IDs based on User-Agent fingerprint and behavior conflict detection:

[0058] This method focuses on extracting high-value information from HTTP / S traffic. By constructing a stable hardware fingerprint and combining it with behavioral analysis, it achieves accurate terminal identification and deduplication, ultimately constructing a virtual avatar ID. Its core steps include:

[0059] User-Agent Standardization and Terminal Fingerprint Generation:

[0060] Extract the User-Agent string from any network session of a home broadband user using methods such as Deep Packet Inspection (DPI).

[0061] We designed and applied a set of standardized parsing rules to accurately extract long-term stable key fields such as terminal brand, terminal model, and operating system from messy User-Agent strings.

[0062] The extracted fields are normalized and combined into a structured and stable "network terminal fingerprint" according to preset rules. For example, a fixed-format string composed of key fields can be generated: brand=Apple;model=iPhone15,Pro;os=iOS, and this string can be further hashed to generate a fixed-length feature value.

[0063] Establish the association between terminal fingerprints and active network identities:

[0064] For each network session for which a User-Agent is extracted, a crucial association building step is performed. The generated persistent "network endpoint fingerprint," representing physical device attributes, is explicitly mapped to the active network identity of that session.

[0065] Based on terminal fingerprint aggregation sessions, a device profile is formed:

[0066] A data aggregation container is created using the "networked terminal fingerprint" as the unique key.

[0067] Based on the established mapping relationship, traffic data from all network sessions with the same "network terminal fingerprint" (regardless of the IP address from which they originate) are aggregated into the corresponding aggregation container. This process re-aggregates the scattered sessions generated by a physical device at different times and using different IP addresses under its unique device fingerprint, forming a complete "device profile" or "device session stack".

[0068] Device conflict detection and terminal deduplication:

[0069] Perform in-depth analysis of the application behavior traffic aggregated within each "device profile".

[0070] A behavior conflict model is set up. If the combination of application behaviors within the profile shows great differences or logically mutually exclusive application patterns (for example, the traffic of "children's education app" and "professional stock trading app" appears frequently at the same time), it is judged as "device conflict".

[0071] When a "device conflict" occurs, it is determined that there are multiple physical entities behind the "network terminal fingerprint" (i.e., the household owns multiple devices of the same brand and model). Based on the clustering results of behavioral patterns, the number of terminals is estimated and deduplicated.

[0072] Construct and output a unique virtual human ID:

[0073] By integrating the analysis results, a unique "virtual human ID" is constructed for each independent physical terminal confirmed after conflict detection and deduplication. If there is no conflict, the terminal fingerprint directly corresponds to a virtual human ID; if there is a conflict and the terminal splits into N entities, a unique virtual human ID is constructed for each of these N entities, and these IDs and their associated device profiles are output.

[0074] The two methods of this invention can operate independently or work together to provide a complete view of home terminals. Method 1 is responsible for basic separation of all IPv6 traffic, especially effective in segmenting terminal sessions that do not generate User-Agents. Method 2 focuses on accurate brand and model identification and deduplication of identical devices for terminals that generate User-Agents. Finally, the results of the two methods can be combined to generate a more comprehensive list of unique virtual avatar IDs for home broadband accounts.

[0075] like Figure 1 As shown, Example 1: Application Method 1:

[0076] Scenario: A home broadband user whose IPv6 network prefix is ​​2001:db8:AAAA:: / 56.

[0077] Steps S101-S103: The system detects two temporary IPv6 addresses active under this prefix: Addr_A and Addr_B. The system treats Addr_A and Addr_B as independent "temporary network identifiers". Subsequently, the system associates Addr_A with its corresponding network identity (an anonymous logical entity) and attributes all traffic originating from Addr_A to that identity; the same operation is performed on Addr_B.

[0078] Step S104: The system treats the network identity associated with Addr_A and its traffic set as a whole and outputs it as Virtual Human ID VID_Behavior_001; and outputs the network identity associated with Addr_B and its traffic set as Virtual Human ID VID_Behavior_002.

[0079] like Figure 2 As shown, Example 2: Application Method 2:

[0080] Scenario: A family owns two identical iPhone 15 Pro phones (one belonging to the parent and one to the child). For a period of time, the parent's phone used IP_A (an IPv4 address) and IP_B (a temporary IPv6 address) to access the internet, while the child's phone used IP_C (another temporary IPv6 address).

[0081] Steps S201-S202: The system extracts the User-Agent containing ... (iPhone; CPU iPhone OS 18_x ...) from the traffic originating from IP_A, IP_B, and IP_C. After standardized parsing, all three generate the same "network terminal fingerprint": brand=Apple;model=iPhone15,Pro;os=iOS. The system then establishes a mapping relationship between this fingerprint and the network sessions of IP_A, IP_B, and IP_C respectively.

[0082] Step S203: The system creates a "device profile" container with the fingerprint brand=Apple;model=iPhone15,Pro;os=iOS as the key, and includes the traffic data of all network sessions with that fingerprint (i.e., sessions from IP_A, IP_B, IP_C) into this container.

[0083] Step S204: The conflict detection module begins analyzing all application behaviors within the "device profile". Analysis reveals that session traffic originating from IP_A and IP_B is concentrated on "WeChat Work" and "Stock Trading App", while session traffic originating from IP_C is concentrated on "TikTok" and "Game App". The behavior conflict model determines that these two sets of application behavior patterns are significantly and logically mutually exclusive, triggering a "device conflict" alarm.

[0084] Step S205: The system finally determines that the fingerprint brand=Apple;model=iPhone15,Pro;os=iOS corresponds to two independent physical terminals, and constructs a unique virtual human ID for these two distinguished entities, such as VID_UA_001 (associated with parent behavior profile) and VID_UA_002 (associated with child behavior profile).

[0085] It will be understood by those skilled in the art that the above descriptions are merely preferred examples of the invention and are not intended to limit the invention. Although the invention has been described in detail with reference to the foregoing examples, those skilled in the art can still modify the technical solutions described in the foregoing examples or make equivalent substitutions for some of the technical features. All modifications and equivalent substitutions made within the spirit and principles of the invention should be included within the scope of protection of the invention. All technical features in this embodiment can be freely combined according to actual needs.

[0086] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for home terminal identification combining IPv6 session home with User-Agent fingerprint, characterized in that: Specifically comprising the following steps: Based on IPv6 session attribution to build a virtual person ID, which is used for basic separation of all IPv6 traffic, and divides terminal sessions that do not generate User-Agent: using the temporary uniqueness of IPv6 privacy addresses within their life cycle, the mixed home network traffic is separated and attributed to independent, anonymous logical entities, and finally a virtual person ID is constructed; Based on User-Agent fingerprint and device conflict detection to build a virtual person ID, which is used for accurate brand model identification and same device deduplication of terminals that generate User-Agent: high-value information is extracted from HTTP / S traffic, accurate terminal identification and deduplication are realized by constructing stable hardware fingerprints and combining behavior analysis, and a virtual person ID is constructed; The results of building a virtual person ID based on IPv6 session attribution and building a virtual person ID based on User-Agent fingerprint and device conflict detection are summarized to generate a more comprehensive unique virtual person ID list for a home broadband account; Set a device conflict model, if the application behavior combination in the portrait shows great difference or there is a logically exclusive application mode, it is determined as a device conflict.

2. The method of claim 1, wherein the method is characterized by: The virtual person ID construction method based on IPv6 session attribution specifically comprises the following steps: Step 1.1, identify the home network prefix and temporary address: in the metropolitan area network data aggregation node, capture and identify the traffic attributed to the same home broadband user, the user is identified by a relatively stable IPv6 network prefix within a period of time, and all active and complete IPv6 addresses are identified; Step 1.2, define a temporary network identifier: each complete and temporary IPv6 address is regarded as a temporary network identifier within its short life cycle; Step 1.3, build the association between the temporary network identifier and the network identity: for each defined temporary network identifier, perform a key association construction step; using the uniqueness and exclusivity of the identifier within its life cycle, it is explicitly mapped to a unique and anonymous network identity; a transient network identifier is bound to a logical active entity, so as to confirm that all traffic originating from the identifier comes from the same source; Step 1.4, output the virtual person ID based on traffic attribution: the association relationship constructed in step 1.3 binds a unique and anonymous network identity with its entire network activity, i.e. traffic set; the network identity that is completely attributed to the traffic constitutes a unique virtual person ID.

3. The method of claim 1, wherein the method is characterized by: The virtual person ID construction method based on User-Agent fingerprint and device conflict detection specifically comprises: Step 2.1, User-Agent standardization and terminal fingerprint generation; Step 2.2, build the association between the terminal fingerprint and the active network identity: the persistent networking terminal fingerprint representing the physical device attribute generated in step 2.1 is explicitly mapped to the active network identity of the session; Step 2.3, aggregate sessions based on terminal fingerprints to form a device portrait; Step 2.4, Device conflict detection and terminal deduplication; Step 2.5, Construct and output unique virtual human ID.

4. The method of claim 3, wherein the home terminal is identified by combining the IPv6 session home with the User-Agent fingerprint. In step 2.1, User-Agent standardization and terminal fingerprint generation, specifically including: Step 2.11, Extract the User-Agent string from any network session of the home broadband user through deep packet inspection (DPI); Step 2.12, Accurately extract the terminal brand, terminal model, and operating system from the chaotic User-Agent string Key fields that are stable over a long period; Step 2.13, Normalize the extracted fields and combine them into a structured and stable networking terminal fingerprint according to the preset rules.

5. The method of claim 3, wherein the home terminal identification method is combined with IPv6 session home and User-Agent fingerprinting. In step 2.3, aggregate sessions based on terminal fingerprints to form device portraits, specifically including: Step 2.31, Create a data aggregation container using the networking terminal fingerprint as the unique key; Step 2.32, Based on the mapping relationship established in step 2.2, collect all network session traffic data with the same networking terminal fingerprint into the corresponding aggregation container.

6. The method of claim 3, wherein the method further comprises: determining whether the User-Agent string is associated with a specific home network; and if the User-Agent string is associated with the specific home network, then determining whether the User-Agent string is associated with a specific home network. In step 2.4, device conflict detection and terminal deduplication, specifically including: Step 2.41, Perform in-depth analysis of the application behavior traffic aggregated within each device portrait; Step 2.42, When a device conflict occurs, determine that there are multiple physical entities behind the networking terminal fingerprint, i.e., the family has multiple devices with the same brand and model, and estimate and deduplicate the number of terminals based on the clustering results of the behavior patterns.

Citation Information

Patent Citations

  • People flow detection method and system based on network flow multifield identification

    CN106878102A

  • An information association method and apparatus based on mobile equipment fingerprints

    CN107580323A